Shared posts

24 Mar 20:33

Adding Okra To Drinking Water Removes Microplastics

by BeauHD
An anonymous reader quotes a report from New Atlas: If you've ever eaten okra, then you'll know that the stuff can be pretty gooey. According to new research, that quality could allow a compound from the plant to be used in a less toxic method of removing microplastics from drinking water. [...] After some experimentation, it was found that polysaccharides from okra paired with those from fenugreek worked best at removing microplastics from seawater, while those same okra polysaccharides paired with those from tamarind were best for use on freshwater. All in all, depending on factors such as the ratio of the polysaccharides and the water source, the plant-based flocculants performed either as well as or better than polyacrylamide. And importantly, they could be used in existing water treatment plants, without any alterations to the facilities or processes. The scientists are now investigating how well other combinations of plant-derived polysaccharides will work on specific types of plastic microparticles, in water from a variety of sources. The findings have been reported via EurekAlert. The American Chemical Society Meeting Newsroom channel on YouTube also produced a video about the research.

Read more of this story at Slashdot.

24 Mar 03:04

The Absolute Best Fantasy Movies on Max - CNET

by Adam Benjamin
HBO Max rebranded itself as just Max, but it still has some of the most iconic fantasy movies around, plus a few underrated gems.
23 Mar 23:58

Arizona Is First State To Launch Drivers' License In Apple Wallet

by BeauHD
Arizona residents can now add their drivers' license, or state ID, to Apple Wallet, which lets them use an iPhone, or Apple Watch, to check in at selected TSA checkpoints. Apple Insider reports: As Apple continues to discuss bringing digital drivers' licenses to US states, Arizona has become the first to take the system live for its residents. "We're thrilled to bring the first driver's license and state ID in Wallet to Arizona today," said Jennifer Bailey, Apple's vice president of Apple Pay and Apple Wallet, in a statement, " and provide Arizonans with an easy, secure, and private way to present their ID when traveling, through just a tap of their iPhone or Apple Watch." "We look forward to working with many more states and the TSA to bring IDs in Wallet to users across the US," she continued. At launch, Wallet can be only be used at an unspecified number of TSA security checkpoints at Phoenix Sky Harbor International Airport. Apple also announced that the states of Colorado, Hawaii, Mississippi, Ohio, and the territory of Puerto Rico plan to bring the technology to its residents. This is in addition to seven other states that Apple previously announced.

Read more of this story at Slashdot.

23 Mar 22:13

A Closer Look at the LAPSUS$ Data Extortion Group

by BrianKrebs

Microsoft and identity management platform Okta both this week disclosed breaches involving LAPSUS$, a relatively new cybercrime group that specializes in stealing data from big companies and threatening to publish it unless a ransom demand is paid. Here’s a closer look at LAPSUS$, and some of the low-tech but high-impact methods the group uses to gain access to targeted organizations.

First surfacing in December 2021 with an extortion demand on Brazil’s Ministry of Health, LAPSUS$ made headlines more recently for posting screenshots of internal tools tied to a number of major corporations, including NVIDIA, Samsung, and Vodafone.

On Tuesday, LAPSUS$ announced via its Telegram channel it was releasing source code stolen from Microsoft. In a blog post published Mar. 22, Microsoft said it interrupted the LAPSUS$ group’s source code download before it could finish, and that it was able to do so because LAPSUS$ publicly discussed their illicit access on their Telegram channel before the download could complete.

One of the LAPSUS$ group members admitted on their Telegram channel that the Microsoft source code download had been interrupted.

“This public disclosure escalated our action allowing our team to intervene and interrupt the actor mid-operation, limiting broader impact,” Microsoft wrote. “No customer code or data was involved in the observed activities. Our investigation has found a single account had been compromised, granting limited access. Microsoft does not rely on the secrecy of code as a security measure and viewing source code does not lead to elevation of risk.”

While it may be tempting to dismiss LAPSUS$ as an immature and fame-seeking group, their tactics should make anyone in charge of corporate security sit up and take notice. Microsoft says LAPSUS$ — which it boringly calls “DEV-0537” — mostly gains illicit access to targets via “social engineering.” This involves bribing or tricking employees at the target organization or at its myriad partners, such as customer support call centers and help desks.

“Microsoft found instances where the group successfully gained access to target organizations through recruited employees (or employees of their suppliers or business partners),” Microsoft wrote. The post continues:

“DEV-0537 advertised that they wanted to buy credentials for their targets to entice employees or contractors to take part in its operation. For a fee, the willing accomplice must provide their credentials and approve the MFA prompt or have the user install AnyDesk or other remote management software on a corporate workstation allowing the actor to take control of an authenticated system. Such a tactic was just one of the ways DEV-0537 took advantage of the security access and business relationships their target organizations have with their service providers and supply chains.”

The LAPSUS$ Telegram channel has grown to more than 45,000 subscribers, and Microsoft points to an ad LAPSUS$ posted there offering to recruit insiders at major mobile phone providers, large software and gaming companies, hosting firms and call centers.

Sources tell KrebsOnSecurity that LAPSUS$ has been recruiting insiders via multiple social media platforms since at least November 2021. One of the core LAPSUS$ members who used the nicknames “Oklaqq” and “WhiteDoxbin” posted recruitment messages to Reddit last year, offering employees at AT&T, T-Mobile and Verizon up to $20,000 a week to perform “inside jobs.”

LAPSUS$ leader Oklaqq a.k.a. “WhiteDoxbin” offering to pay $20,000 a week to corrupt employees at major mobile providers.

Many of LAPSUS$’s recruitment ads are written in both English and Portuguese. According to cyber intelligence firm Flashpoint, the bulk of the group’s victims (15 of them) have been in Latin America and Portugal.

“LAPSUS$ currently does not operate a clearnet or darknet leak site or traditional social media accounts—it operates solely via Telegram and email,” Flashpoint wrote in an analysis of the group. “LAPSUS$ appears to be highly sophisticated, carrying out increasingly high-profile data breaches. The group has claimed it is not state-sponsored. The individuals behind the group are likely experienced and have demonstrated in-depth technical knowledge and abilities.”

Microsoft said LAPSUS$ has been known to target the personal email accounts of employees at organizations they wish to hack, knowing that most employees these days use some sort of VPN to remotely access their employer’s network.

“In some cases, [LAPSUS$] first targeted and compromised an individual’s personal or private (non-work-related) accounts giving them access to then look for additional credentials that could be used to gain access to corporate systems,” Microsoft wrote. “Given that employees typically use these personal accounts or numbers as their second-factor authentication or password recovery, the group would often use this access to reset passwords and complete account recovery actions.”

In other cases, Microsoft said, LAPSUS$ has been seen calling a target organization’s help desk and attempting to convince support personnel to reset a privileged account’s credentials.

“The group used the previously gathered information (for example, profile pictures) and had a native-English-sounding caller speak with the help desk personnel to enhance their social engineering lure,” Microsoft explained. “Observed actions have included DEV-0537 answering common recovery prompts such as “first street you lived on” or “mother’s maiden name” to convince help desk personnel of authenticity. Since many organizations outsource their help desk support, this tactic attempts to exploit those supply chain relationships, especially where organizations give their help desk personnel the ability to elevate privileges.”

LAPSUS$ recruiting insiders via its Telegram channel.

SIM-SWAPPING PAST SECURITY

Microsoft said LAPSUS$ also has used “SIM swapping” to gain access to key accounts at target organizations. In a fraudulent SIM swap, the attackers bribe or trick mobile company employees into transferring a target’s mobile phone number to their device. From there, the attackers can intercept any one-time passwords sent to the victim via SMS or phone call. They can also then reset the password for any online account that allows password resets via a link sent over SMS.

“Their tactics include phone-based social engineering; SIM-swapping to facilitate account takeover; accessing personal email accounts of employees at target organizations; paying employees, suppliers, or business partners of target organizations for access to credentials and multifactor authentication (MFA) approval; and intruding in the ongoing crisis-communication calls of their targets,” Microsoft wrote.

Allison Nixon is chief research officer at Unit 221B, a cybersecurity consultancy based in New York that closely tracks cybercriminals involved in SIM-swapping. Working with researchers at security firm Palo Alto Networks, Nixon has been tracking individual members of LAPSUS$ prior to their forming the group, and says the social engineering techniques adopted by the group have long been abused to target employees and contractors working for the major mobile phone companies.

“LAPSUS$ may be the first to make it extremely obvious to the rest of the world that there are a lot of soft targets that are not telcos,” Nixon said. “The world is full of targets that are not used to being targeted this way.”

Microsoft says LAPSUS$ also has been known to gain access to victim organizations by deploying the “Redline” password-stealing malware, searching public code repositories for exposed passwords, and purchasing credentials and session tokens from criminal forums.

That last bit is interesting because Nixon said it appears at least one member of LAPSUS$ also was involved in the intrusion at game maker Electronic Arts (EA) last year, in which extortionists demanded payment in exchange for a promise not to publish 780 GB worth of source code. In an interview with Motherboard, the hackers claimed to have gained access to EA’s data after purchasing authentication cookies for an EA Slack channel from a dark web marketplace called Genesis.

“The hackers said they used the authentication cookies to mimic an already-logged-in EA employee’s account and access EA’s Slack channel and then trick an EA IT support staffer into granting them access to the company’s internal network,” wrote Catalin Cimpanu for The Record.

Why is Nixon convinced LAPSUS$ was behind the EA attack? The “WhiteDoxbin/Oklaqq” identity referenced in the first insider recruitment screenshot above appears to be the group’s leader, and it has used multiple nicknames across many Telegram channels. However, Telegram lumps all aliases for an account into the same Telegram ID number.

Back in May 2021, WhiteDoxbin’s Telegram ID was used to create an account on a Telegram-based service for launching distributed denial-of-service (DDoS) attacks, where they introduced themself as “@breachbase.” News of EA’s hack last year was first posted to the cybercriminal underground by the user “Breachbase” on the English-language hacker community RaidForums, which was recently seized by the FBI.

WHO IS LAPSUS$?

Nixon said WhiteDoxbin — LAPSUS$’s apparent ringleader — is the same individual who last year purchased the Doxbin, a long-running, text-based website where anyone can post the personal information of a target, or find personal data on hundreds of thousands who have already been “doxed.”

Apparently, Doxbin’s new owner failed to keep the site functioning smoothly, because top Doxbin members had no problems telling WhiteDoxbin how unhappy they were with his stewardship.

“He wasn’t a good administrator, and couldn’t keep the website running properly,” Nixon said. “The Doxbin community was pretty upset, so they started targeting him and harassing him.”

Nixon said that in January 2022, WhiteDoxbin reluctantly agreed to relinquish control over Doxbin, selling the forum back to its previous owner at a considerable loss. However, just before giving up the forum, WhiteDoxbin leaked the entire Doxbin data set (including private doxes that had remained unpublished on the site as drafts) to the public via Telegram.

The Doxbin community responded ferociously, posting on WhiteDoxbin perhaps the most thorough dox the community had ever produced, including videos supposedly shot at night outside his home in the United Kingdom.

According to the denizens of Doxbin, WhiteDoxbin started out in the business of buying and selling zero-day vulnerabilities, security flaws in popular software and hardware that even the makers of those products don’t yet know about.

“[He] slowly began making money to further expand his exploit collection,” reads his Doxbin entry. “After a few years his net worth accumulated to well over 300BTC (close to $14 mil).”

WhiteDoxbin’s Breachbase identity on RaidForums at one point in 2020 said they had a budget of $100,000 in bitcoin with which to buy zero-day flaws in Github, Gitlab, Twitter, Snapchat, Cisco VPN, Pulse VPN and other remote access or collaboration tools.

“My budget is $100000 in BTC,” Breachbase told Raidforums in October 2020. “Person who directs me to someone will get $10000 BTC. Reply to thread if you know anyone or anywhere selling this stuff. NOTE: The 0day must have high/critical impact.”

KrebsOnSecurity is not publishing WhiteDoxbin’s alleged real name because he is a minor (currently aged 17), and because this person has not officially been accused of a crime. Also, the Doxbin entry for this individual includes personal information on his family members.

Nixon said that prior to launching LAPSUS$, WhiteDoxbin was a founding member of a cybercriminal group calling itself the “Recursion Team.” According to the group’s now-defunct website, they mostly specialized in SIM swapping targets of interest and participating in “swatting” attacks, wherein fake bomb threats, hostage situations and other violent scenarios are phoned in to police as part of a scheme to trick them into visiting potentially deadly force on a target’s address.

“The team is made up of Cyber-enthusiasts who major in skills including security penetration, software development, and botting,” reads the now-defunct Recursion Team website. “We plan to have a bright future, and we hope you do too!”

Update, March 24, 11:11 a.m. ET: The BBC is quoting City of London Police as saying seven people between the ages of 16 and 21 have been arrested in connection with an investigation into a hacking group. All have been released under investigation.

23 Mar 22:01

The Real-Life Mobster Who Inspired The Sopranos

by Ryan Leston

Landmark American crime drama "The Sopranos" is renowned for its authenticity. The story of Tony Soprano (James Gandolfini) tackling his mental health issues while balancing family life and his duties as a mob boss made for some of the most gripping television of all time. Often thought to be one of the greatest TV shows ever made, it's obvious that "The Sopranos" is grounded in reality.

Sure, we've seen plenty of mob movies of the years, with "The Godfather" and "Goodfellas" among the very best, but nothing quite captured the crushing dread of organized crime like "The Sopranos."

"Those who want respect, give respect."

That's how it was in the hit HBO series, and it's a mantra that forms the backbone of the real-life Cosa Nostra. It's all about respect, and it can be difficult to get it when you have to balance the conflicting needs of your family with those of the mafia family you control. That's where "The Sopranos" really excels — depicting the internal struggles of a mobster just trying to hold it all together. The truly remarkable part? It's not entirely fictitious.

Here's the guy who inspired it all.

Vincent 'Vinny Ocean' Palermo

Former New Jersey mob boss Vincent Palermo is said to be the inspiration behind Tony Soprano, and it's easy to see why.

Born on June 4, 1944, he was raised in a traditional American-Italian family in Brooklyn, New York. After earning the nickname "Vinny Ocean" while working in a New Jersey fish market, he married into the DeCavalcante crime family. And so began a long and memorable career in the New Jersey mafia, as he became involved in loansharking, illegal gambling, and even racketeering.

Much like Tony Soprano, he eventually became a capo. He was given his own crew of soldiers following the death of a real estate developer, Fred Weiss, a murder in which Palermo was involved. He later became the de facto boss of the DeCavalcante family after a power struggle within, mirroring Tony Soprano's rise to the top.

Even the mob themselves saw similarities. FBI recordings of the DeCavalcante family found them discussing the show:

"Hey, what's this f****** thing, Sopranos? What the f*** are they? Is that supposed to be us? Every show you watch, more and more, you pick up somebody ... There's a pork store. Yeah, in Jersey, right? They got a topless joint over there. Jesus."

The recordings, and their discussion of "The Sopranos," were used in court to convict four men of murder, racketeering, extortion, illegal gambling, bribery, and organized crime.

Palermo even owned a strip club called Wiggles, the inspiration for the Bada Bing! strip joint in "The Sopranos."

'Family – They're The Only Ones You Can Depend On'

Tony Soprano is all about his family — a devoted father who even took in his wife's first cousin (once removed) and treats him as his own. This relationship between Tony and Christopher Moltisanti (Michael Imperioli) forms a key part of "The Sopranos" and can be seen in the real-life mob boss, Vincent Palermo. He was said to be very protective of children and a devoted family man, driving his daughters each week to Brownies and watching "Annie" with them regularly. He also took in a troubled teenager named Richard and became his godfather, allowing the boy to stay with his family every weekend to study the Catholic sacraments.

And when it comes to family, the similarities extend to their crime families, too.

Much like the DiMeo crime family in "The Sopranos," the DeCavalcante family had its own fair share of power struggles. Again, the show echoes real-life — Junior Soprano is the DiMeo crime boss in name only, while Tony is the guy who really runs the show. This was identical to the DeCavalcante crime family, who were headed up by Giovanni Riggi in absentia during his time in jail ... but by the mid-'90s were actually being run by Palermo.

If that's not evidence enough that Vincent Palermo is the real Tony Soprano, then the murder of a disgraced mob boss really seals the deal.

The Fall Of 'Johnny Boy' D'Amato

After DeCavalcante boss Giovanni Riggi was sent down in 1989, John "Johnny Boy" D'Amato became the crime family's acting boss. All may have seemed well, but trouble was brewing beneath the surface with a Family scandal about to reach boiling point. After a vicious argument, D'Amato's girlfriend told the Family that he was bisexual. According to her, D'Amato had been frequenting Manhattan sex clubs, meeting with both male and female swingers. A later testimony by hitman Anthony Capo revealed the Family was worried that if the other Mafia families found out about D'Amato's "gay" behavior, it would cause them to lose respect for the Family.

That sealed it — 'Johnny Boy' D'Amato had to go.

A coup took place in 1992, with several Family members involved in the killing of D'Amato. And while Palermo himself was thought to be involved, he would later take the stand as a state witness against his former associates.

What does this have to do with "The Sopranos?" Well, in the episode "Boca," Tony's uncle, Junior (Dominic Chianese) is praised for his oral sex skills by his girlfriend, Bobbi Sanfillipo (Robyn Peterson). But he can't let word of this get out.

"They think if you suck p****, you'll suck anything. It's a sign of weakness."

Luckily for Junior, this didn't result in his death. But he equally lost the respect of his Family when Tony makes veiled references to his uncle's oral sex prowess. It's a treacherous power play that undermines Junior ... and pushes Junior to make some unwise decisions.

What Happened To Vincent Palermo?

The DeCavalcante crime family may have strong allies with the Five Families, but they're not above the law. Soon enough, the FBI was crawling all over Vincent Palermo's operations, in a move that echoed "The Sopranos."

After a botched robbery of the Bank of America in 1998, DeCavalcante associate Ralph Guarino was arrested by the FBI and ultimately recruited as an informant. Just a year later, the FBI had enough on Vincent Palermo to arrest him — possibly even on capital offenses. Vincent "Vinny Ocean" Palermo became a state witness.

Palermo confessed to the murder of Fred Weiss, among others. Worse still, he implicated other DeCavalcante family members in a catalog of organized crimes. After taking to the stand, Palermo and his family were forced to enter the Witness Protection Program.

Unlike Tony Soprano, who may have met a sticky end in the finale of "The Sopranos," Palermo was last seen operating another strip club in Houston, Texas under the name "James Cabella." By 2013, he was forced to file for bankruptcy.

Not quite a Hollywood ending ... but it beats getting whacked by the Family.

Read this next: Every Martin Scorsese Feature Ranked From Worst To Best

The post The Real-Life Mobster Who Inspired The Sopranos appeared first on /Film.

23 Mar 21:15

John Wayne Almost Walked Away From One Of His Most Beloved Roles

by Travis Yates

Early Hollywood Westerns, a staple of the classical film era, largely stereotyped Native Americans as bloodthirsty savages. The growing popularity of post-World War II social problem films had the film industry reflecting on its portrayals of minorities, including Native Americans. The man synonymous with the Western introduced a film in 1956 that sent ripples throughout all of Hollywood and reinvented the genre.

John Ford's 1956 film "The Searchers" looked like a typical western. It pitted "Cowboys vs. Indians" in a familiar landscape, the wide-open desert plains of the Monument Valley area of Arizona and Utah. But its content was vastly different than any Western we'd seen before.

In "The Searchers," Ford presents complex themes and a racist protagonist played by an actor that audiences had become programmed to root for — "The Duke" himself, John Wayne. The role became career-defining for Wayne — not that he needed it –— because of the depth of the film. It begs the question: How much of an impact would "The Searchers" have had without "The Duke" involved? We almost found out.

The Legacy Of The Searchers

The legacy of "The Searchers" is that it is a social problem film as much as it is a Western, exploring the inherent racism of Western heroes. The film turns a mirror towards its own stubborn, racist characters, mostly though Ethan Edwards, played by Wayne. Edwards is an explicitly racist former Confederate soldier, motivated by killing Comanches while searching for his kidnapped niece. When he learns she is living among the Comanche, he threatens to kill her, justifying it with, "Livin' with Comanches ain't being alive."

Ford presents a version of John Wayne that challenges masculinity rather than defines it. The typically strong, stoic hero portrayed by Wayne instead slips into a baneful, obsessive hunter intent on killing not only his enemy but his own kin. Ethan Edwards' hatred for "the other" is greater than the love of his family, something even the staunchest Wayne fan surely struggles with.

The impact of "The Searchers" has permeated throughout Hollywood masculinity. It inspired a new wave of adult-themed Westerns that would continue to challenge social conventions, including Ford's own 1962 film "The Man Who Shot Liberty Valance." The narrative of Martin Scorsese's "Taxi Driver" heavily echoes "The Searchers." And Edwards' redeeming line, "Let's go home, Debbie" precedes Rocky Balboa's "If I can change, and you can change, we all can change!" plea for foreign relations harmony in "Rocky IV" by nearly thirty years.

It's hard to believe that John Wayne's portrayal of Ethan Edwards, called by Martin Scorsese in THR as "the greatest performance of a great American actor," almost didn't happen.

Wayne Almost Wasn't In The Film

On the film's 60th anniversary, Newsweek revealed that John Wayne almost wasn't in "The Searchers." After being cast in the film he was offered the starring role in the Western "Seven Men from Now." Because Ford and Wayne had such a close relationship — the two collaborated on more than a dozen films — Ford gave Wayne the chance to back out of "The Searchers." Wayne kept his obligation and turned down the other film.

Randolph Scott was ultimately cast as the lead in "Seven Men from Now" and though the film opened to positive reviews, Newsweek points out, "It doesn't come close to the legendary stats of 'The Searchers.'"

Film critic Roger Ebert described Ethan Edwards as one of the most compelling character Ford and Wayne ever created. Ebert writes:

Did they know how vile Ethan's attitudes were? I would argue that they did, because Wayne was in his personal life notably free of racial prejudice, and because Ford made films with more sympathetic views of Indians ... I think it took a certain amount of courage to cast Wayne as a character whose heroism was tainted. Ethan's redemption is intended to be shown in that dramatic shot of reunion with Debbie, where he takes her in his broad hands, lifts her up to the sky, drops her down into his arms, and says, 'Let's go home, Debbie.'"

The film made such an impact that the American Film Institute ranks it as the 12th ranked film of all time and it was selected for preservation in the National Film Registry by the Library of Congress. And we got the performance of a lifetime out of John Wayne because he stuck to his guns and stayed loyal to a friend like only "The Duke" could do.

Read this next: The 20 Best Westerns Of All Time

The post John Wayne Almost Walked Away From One of His Most Beloved Roles appeared first on /Film.

23 Mar 21:10

Kill Bill's Martial Arts Training Was As Brutal As It Gets

by Ryan Leston

It's no secret that "Kill Bill: Volume 1" set a standard when it comes to American martial arts movies. A stylish revenge thriller packed full of iconic fight scenes, "Kill Bill" was fuelled by Tarantino's unique, non-linear filmmaking style, and it certainly wowed critics and audiences at the time.

The film stars Uma Thurman as The Bride, an unnamed woman who was left for dead at the altar. Now, years later, it's time to track down her aggressors -- her former colleagues in a deadly assassination squad -- one by one and get the revenge she so eagerly desires. It's a phenomenal film with obvious inspirations in classic martial arts cinema. The Bride's yellow biker suit is clearly based on Bruce Lee's iconic look from "Game of Death," and there's even a cool animated sequence that pays homage to anime classics. But one thing that really stood out was the film's impressive martial arts sequences.

Deadly Viper Assassination Squad member Vivica A. Fox recounted in her autobiography, "Every Day I'm Hustling" (via TIME), that Quentin Tarantino was deadly serious about getting the martial arts right.

"There would be no quick cuts or getting away with special effects to make us look like real warriors," she explained. "I had to commit to six months of training, and all of the actors needed to become experts in martial arts to make his vision real on the screen."

What they embarked upon was one of the most grueling training regimes they had encountered.

"It's Mercy, Compassion, And Forgiveness I Lack."

For "Kill Bill," Tarantino was taking no shortcuts -- his stars would have to learn martial arts. For real. If they were going to become the world's very best assassins, he wanted them to know exactly what they were doing, and that meant a rigorous regime of physical and martial arts training.

"The training itself was brutal," wrote Fox. "We'd do fight choreography, knife throwing, samurai lessons and hit the treadmill and weights in between. They liked me because I could do them high kicks from being a cheerleader."

Although Fox had just one fight scene, her training regime was intense. After The Bride regains consciousness following a four-year coma, she decides to track down her fellow assassins to get her revenge. The fight with Vernita Green (Vivica A. Fox) is the first we see on screen. 

To prepare for that brutal showdown, Fox was put through the wringer. She recounted, "For three months, Uma Thurman, Lucy Liu, Daryl Hannah, David Carradine, and I spent eight hours a day studying martial arts at a gym they put together in Culver City. It was nine to five, Monday through Friday. If you didn't walk in the door between 8:55 and 8:59, you were in trouble at 9:01. I thought I was in the damn Olympics or something."

Clearly, Tarantino pushed his stars as hard as he could to get the most impressive martial arts performances out of them ... but he may have pushed them a bit too hard.

"That Woman Deserves Her Revenge ..."

Martial arts roles require a lot of training to get everything right. You only have to look at Marvel's "Iron Fist" to see what happens when it all goes wrong. But while Fox was determined to bring her A-game, it looks as though Tarantino wasn't initially impressed.

At the end of every week, the famed director would gather around his actors and assess their performances. Apparently, it wasn't always a constructive review. Fox revealed, "The first week Quentin cut into us, telling us we had to work harder. Okay, I can work harder."

But while Fox upped her game, Tarantino seemingly still wasn't impressed. "Second week, we got the same thing after we busted our asses," she said. "He said we weren't giving it our all." 

"Third Friday, I was so proud of all that our team had accomplished," wrote Fox. "I was sitting between cute little Lucy and sweet Uma, and I was ready for a high five for all of us. Instead, Quentin tore into us. Something about us lollygagging in the morning, taking too long to suit up, and gabbing over coffee. He said we should get here at 8:30, a half-hour early, if we wanted to do all that."

Clearly, Tarantino took the process very seriously and demanded a lot from his stars. But the proof, as they say, is in the butt-kicking.

"You And I Have Unfinished Business."

By the time The Bride tracks down Vernita Green, the former assassin is living a normal, suburban life with her young daughter. What unfolds is a vicious knife fight that sees the two former allies go toe-to-toe in brutal, bloody combat throughout Green's average American home.

"It took four days to film our fight scene," Fox remembered. "And on the last day, I took a long bath when it was over. I sat in the tub and counted all the bruises on my arms and legs. I got up to 30. And I did so with gratitude."

The scene itself plays out perfectly. Choreographer Woo-Ping Yuen, who previously worked on "The Matrix" films, put together an impressive knife fight that's underpinned by Green's new role as more of a domestic goddess than a goddess of war. Ultimately, Fox felt that her sacrifices were worth it.

"I was proud of my battle scars," she recounted. "I had done a Tarantino film, and nobody could take that accomplishment from me. Quentin is a fabulous director and I'd love to work with him again. I appreciate those endless hours in the Culver City torture chamber. It was his way of breaking us down to build us back up."

Across the board, "Kill Bill" showcases some truly spectacular martial arts performances -- not least of which from its star, Uma Thurman. If the face-off between The Bride and Green wasn't enough, a spectacular fight scene with the Crazy 88 elevates the film to legendary status.

"Let's pretend we're little kids and we're making a Super 8 movie in our backyard, and you don't have all this s**t," Tarantino told his film crew. "How would you achieve this effect? Ingenuity is important here!"

It looks as though Tarantino pushed everyone to think outside the box and deliver their very best, not just his actors. The result is that "Kill Bill" is a modern classic -- an American martial arts movie that practically defines the genre.

Read this next: The 18 Best Action Movie Actors Ranked

The post Kill Bill's Martial Arts Training Was As Brutal As It Gets appeared first on /Film.

23 Mar 21:07

Can You Run Visual Basic 6 Apps on Windows 11?

by Shan Abdul

The number of VB6 users has declined over the last decade, but a small proportion of developers still use VB6 apps.

23 Mar 21:07

God of War Patch 1.0.9 can improve performance by up to 20% in CPU-heavy areas

by John Papadopoulos

Santa Monica Studio and Jetpack Interactive have released a new patch for the PC version of God of War. According to the release notes, Update 1.0.9 implements small object culling to help reduce the number of objects that the CPU can process. As such, it can improve performance by up to 20% in CPU-heavy areas. … Continue reading God of War Patch 1.0.9 can improve performance by up to 20% in CPU-heavy areas →

The post God of War Patch 1.0.9 can improve performance by up to 20% in CPU-heavy areas appeared first on DSOGaming.

23 Mar 20:57

David Spade Returns To Stand-Up With Netflix Special Nothing Personal

by Witney Seibold

David Spade first entered the world of stand-up comedy while attending college at Arizona State University. Spade, finding he was making a decent living with stand-up, dropped out of college and took his comedy on the road. He would eventually be "discovered" by a talent scout at the Improv in Hollywood, CA, and subsequently cast as a giggling skateboard punk in director Jim Drake's immortal classic "Police Academy 4: Citizens on Patrol." He was in his early 20s. 

From there, Spade went on to appear in a long string of hit comedy films — some of them critically lauded, some not — like "PCU," "Black Sheep," and "Lost & Found," which he co-wrote. Spade would also play the title characters in "Joe Dirt," "Dick Roberts: Former Child Star," and "The Emperor's New Groove." Many of his films have been made under the auspices of Happy Madison productions, Adam Sandler's production company. His most recent live-action outing was 2020's "The Wrong Missy" for Netflix (reportedly one of the service's most popular films ever), and his most recent voice acting credit was in "Hotel Transylvania: Transformania" in which he played Griffin, the Invisible Man. He also hosted his own late-night talk show, "Lights Out with David Spade," and he currently hosts "Bachelor in Paradise." 

David Spade has not appeared in a stand-up special for eight years, his last one being 2014's "My Fake Problems" for Comedy Central. Netflix announced today that Spade, 57, will be appearing in a new special, called "Nothing Personal," which will premiere on the streaming service on April 26, 2022. 

The Synopsis

"Nothing Personal" will be directed by Ryan Polito, a veteran of stand-up and TV specials. The official synopsis for "Nothing Personal" from Netflix reads: 

Hot off the beach from his guest-hosting duties on Bachelor In Paradise, David Spade makes his Netflix comedy special debut with 'Nothing Personal.' From sharing his disdain for crabs to his unique approach to turning down drugs, David proves that no topic is off-limits.

Spade's style of comedy is that of deadpan sarcasm. He has a unique talent for expressing utter disdain for a person or a topic with a well-timed eye roll. Few comedians have nailed comedic smarminess and delicious arrogance as well as Spade. Given his acting career, Spade can also play broad, farcical comedy honed by his appearance on 77 episodes of "Saturday Night Live."

"The Wrong Missy" is currently on Netflix, and "Police Academy 4" can be rented online.

Read this next: The 10 Best Comedies Of The Last 10 Years

The post David Spade Returns to Stand-Up With Netflix Special Nothing Personal appeared first on /Film.

23 Mar 20:56

Fans made a native 'Legend of Zelda: Ocarina of Time' PC port

by Jon Fingas

You won't have to use the Switch Virtual Console (or a good emulator) to make the most of Legend of Zelda: Ocarina of Time on modern hardware. VGCreports fans at Harbour Masters have developed a native PC port (available on Discord) that supports many up-to-the-minute features, including HD (and ultra-wide) graphics, modding, keyboard input and even Switch-style gyroscope aiming. You could make good use of a Steam Deck in your latest round of gaming nostalgia, to put it another way.

And yes, Harbour Masters claims it can avoid Nintendo's legal team. The Ocarina of Time PC port revolves around Ship of Harkinian, a tool that turns a user-supplied (and hopefully legal) Nintendo 64 ROM for the game into a usable program. As the software doesn't include any of Nintendo's content, the developer supposedly can't pursue Harbour Masters over copyright violations.

The conversion should improve, too. The creators are working on 60 frames per second graphics, twin stick controls, text-to-speech upgraded models and higher-resolution texture packs. Mac and Linux support is also said to be in the pipeline, as is a PC adaptation of Majora's Mask.

Whether or not this port is legally safe, it reflects fans' determination to preserve Ocarina of Time and other Nintendo classics without relying on official emulation or re-releases. Enthusiasts ported Super Mario 64 in 2019, for instance. While this work isn't as vital as it once was with the existence of solutions like the Virtual Console, it does provide gamers more control over where and how they play the titles from their childhood.

23 Mar 20:48

Joel Hodgson Had A Good Reason For Reviving Mystery Science Theater 3000

by Witney Seibold

"Mystery Science Theater 3000" officially ended its run in 1999, but never really went away. 

The "watching bad movies with several funny friends" premise was simply too good to leave behind, and every cast member on the show participated in "MST3K"-like projects for years thereafter. The show's creator, Joel Hodgson, teamed up with Mary Jo Pehl, Trace Beaulieu, Frank Conniff, and J. Elvis Weinstein to create "Cinematic Titanic," a riffing show wherein the cast was seen in silhouette, like on "MST3K," and were beholden to an evil, ill-defined corporate entity. Meanwhile, Mike Nelson, Bill Corbett, and Kevin Murphy formed "The Film Crew" wherein the trio was forced to make commentary tracks by a deranged billionaire. The Film Crew, along with Pehl and Bridget Nelson, would also be the primary participants in the successful Rifftrax enterprise, which provided humorous commentaries on old, bad movies, but also sold downloadable audio files to be played alongside big-budget Hollywood blockbusters (quite an innovative idea). 

Both "Rifftrax" and "Cinematic Titanic" also toured, performing riffs live. The "Rifftrax" shows, still performed semi-regularly, were often broadcast in theaters via Fathom Events. 

Joel Hodgson infamously left "Mystery Science Theater 3000" in 1993 due to his discomfort on camera, and his repeated arguments with the show's producer Jim Mallon over who should have creative control over the enterprise (per A.V. Club). Since his departure, affection for "MST3K" only grew. A new generation of comedians came to the fore and began kvelling openly about how much Hodgson's show had influenced them, and a new generation of kids were introduced to the show via the Shout! Factory's comprehensive DVD releases and free streaming service, which runs "MST3K" reruns 24 hours a day. 

Many producers approached Hodgson over the years about reviving "MST3K," but he was never interested. According to an interview with The L.A. Times, Hodgson didn't want to make a show all about himself. But interest persisted, and Hodgson eventually revealed that he would regret it if he never got a new show off the ground. "Mystery Science Theater 3000" re-launched on Netflix in 2017.

The New Show

The executives at Netflix asked Hodgson to re-create "MST3K" exactly as it had been in the early 1990s, seemingly interested in mere nostalgia. Hodgson wasn't so interested in that. Besides, he felt he was too old to get everything started again. From the L.A. Time interview:

"We're in our 50s, why not let somebody in their 30s do it like when we started? Most of the narrative out there was, 'Just re-create it exactly as we remember it.' I felt like that that's not the real spirit of it. I didn't want to make a love letter to the past, and instead make a love letter to the future, maybe."

Hodgson had met comedian Jonah Ray on the Nerdist podcast, and felt his self-effacing humor was more appropriate for a new version. The evil mad scientist Dr. Clayton Forrester (previously played by Trace Beaulieu) was to be replaced by his child Dr. Kinga Forrester, played by the internet's "It" girl Felicia Day. TV's Frank (previously Frank Conniff) was replaced by Son of TV's Frank played by Patton Oswalt. The setting of the mad scientist lair was shifted from deep underground to the surface of the moon. Crow T. Robot, Tom Servo, and GPC would return, all voiced by new actors. There would also be a live band of minions. 

Hodgson was happy to get it all up and running and modestly assert some control over his creation before it was done incorrectly, or before he was run over by a car: 

"More than anything, I felt like I was really going to regret it if I died before I got to spin it over and get this new group going. That was on my mind a lot. I'm going to really regret it if I get hit by a car or something. With only two days of shooting left, it's unlikely I'll get hit by a car so I feel really grateful. And even if I got killed they could do a rough edit, it would be pretty close."

The Netflix Years

Attracting talent wasn't an issue. Day and Oswalt were both fans, and Elliott Kalan, the former head writer on "The Daily Show with Jon Stewart," became the head writer on the show. Other screenwriters came over from hit shows like "Community" and "Rick and Morty." The Netflix launch was well-received, and the cast found a groove pretty quickly. It likely helped that Hodgson was there to give his blessing, and that the cast had such good chemistry. Heavily funded by Kickstarter campaigns, the show was also eagerly anticipated by many, many fans. 

The new "Mystery Science Theater 3000" ran for 14 episodes and featured such awful movies as the glorious 1978 "Star Wars" knockoff "Starcrash," the Danish monster film "Reptilicus," and the bizarre 1983 chimpanzee movie "Carnival Magic." A second season -- staged as a six-film marathon -- was released in 2018, where audience would finally see "Mac and Me" the way it was meant to be seen -- through the lens of sarcasm. 

When I personally asked Hodgson once about how better-known "bad" films on his show might have fans, and that some of them may not be as bad as all that, he looked me dead in the eye and asked "Really?" 

A thirteenth season of "MST3K" is currently in the works, and it will feature such classics as "El Santo and the Treasure of Dracula," and "Robot Wars." It will be available not on Netflix, but on their very own streaming channel, called The Gizmoplex.

Read this next: Batman Movies Ranked From Worst To Best

The post Joel Hodgson Had a Good Reason For Reviving Mystery Science Theater 3000 appeared first on /Film.

23 Mar 20:11

Without The Golden Girls, We Might Not Have Reservoir Dogs

by Travis Yates

Hollywood is a funny place. The stories behind how films get made are often times worthy of their own movie. Some projects languish in developmental hell for years without ever being made, and others lead to downright bizarre tales. In Quentin Tarantino's case, he can point to a beloved TV sitcom to credit for the debut film that launched his career in Hollywood.

"The Golden Girls" is one of the most beloved sitcoms in television history. The groundbreaking show featured witty writing, edgy characters, and tackled real-life issues facing older women during the late 1980s. The series starred four over-50 women, something unheard of in television, then and now. "The Golden Girls" gave Dorothy, Rose, Blanche, and Sophia the agency to navigate life as aging women on their own.

So how does Quentin Tarantino figure into all of this? Believe it or not, Tarantino has "The Golden Girls" to thank for the production of "Reservoir Dogs" and his meteoric rise as a Hollywood director.

His Love Of Elvis Played A Role

According to Empire, Tarantino hatched the idea for "Reservoir Dogs" while working at a Los Angeles video store. A shelf full of heist films caught his attention, and he thought it would be an interesting genre to redo. In just three weeks he hammered out a script for "Reservoir Dogs." Subverting genre expectations, the script follows events that take place before and after a failed heist, but not the heist itself. Tarantino also paid homage to a French neo-noir classic, a style he would become known for.

With script in hand, the screenwriter had to figure out how to get the movie made. According to Tarantino, the plan was to produce the film himself, funded in part by residual checks from his appearance as an Elvis impersonator on two episodes of "The Golden Girls" in 1988. Can you spot Tarantino in the sea of Elvis impersonators?

Tarantino would discuss the experience with Jimmy Fallon during an appearance on "The Tonight Show." The writer/director told Fallon that he dressed as Elvis in the 1980s, even getting his hair cut at a rockabilly barbershop (only in Hollywood), and his headshot led to the appearance on "The Golden Girls." Because the episode was turned into two parts and put on a "best of" compilation of the show, the money was enough to sustain Tarantino during the pre-production of "Reservoir Dogs."

But the project would also receive an influx of cash from a very unlikely source.

It Gave Tarantino A Chance To Work With His Hero

Tarantino had raised $30,000 to make the film, but before production began the script serendipitously found its way into the hands of Harvey Keitel. Tarantino's producer passed the script along to an acting teacher and it eventually found its way to Keitel. He was enamored with the script and contacted Tarantino to let him know that not only did he want to appear in the film but also wanted to be a producer on the project.

Tarantino reflected on his good fortune:

"It was wild, because Harvey had been my favorite actor since I was 16 years old. I'd seen him in 'Mean Streets' and 'Taxi Driver' and stuff. I didn't write the part for Harvey because I thought it'd probably be, you know, my uncle Pete."

Keitel put his money where his mouth was, contributing his own cash to the film's budget and financing a casting trip to New York. The move paid off as a fantastic ensemble cast of Keitel, Michael Madsen, Chris Penn, Steve Buscemi, Eddie Bunker, Lawrence Tierney, and Tim Roth was assembled. Tarantino pulled double duty as actor and director.

The result was an iconic movie and watershed moment for independent filmmaking. Tarantino would become the face of the 1990s independent film movement that included Kevin Smith, Richard Linklater, and Paul Thomas Anderson. Since "Reservoir Dogs" Tarantino has become one of the most influential filmmakers of his generation. It's a success story that the gals from "The Golden Girls" would no doubt love to tell at the kitchen table over cheesecake.

Read this next: The 14 Best Film Acting Debuts Of All Time

The post Without The Golden Girls, We Might Not Have Reservoir Dogs appeared first on /Film.

23 Mar 17:58

GWJ Conference Call 806

by Amoebic
Tunic

Tunic, Not for Broadcast: Prologue (PC), Azul, 7 Wonders: Architects, The Expanse, Earth, Interview with Jenn from Restoration Games and Key to the Kingdom, Berried Treasure, Unmatched, New York Zoo, Isle of Cats.

23 Mar 17:56

The Legend of Zelda: Ocarina of Time Native PC Port Is Now Available for Dowload

by Francesco De Meo

The Legend of Zelda: Ocarina of Time

A native PC port of The Legend of Zelda: Ocarina of Time including features not found in the original release is now available for download.

The port, which is called Ship of Harkinian, uses reverse-engineered code and adds, as already mentioned, some features not available in the original, such as mouse and keyboard controls support, improved graphics, and widescreen support.

The development team showcased The Legend of Zelda: Ocarina of Time native PC port in a new video that can be watched on YouTube. During the video, the team also provided a sneak peek at features that will be available after launch, such as higher framerate support and more.

More on The Legend of Zelda: Ocarina of Time PC port Ship of Harkinian and how to download it can be found on the project's official Discord server.

The Legend of Zelda: Ocarina of Time is the first 3D entry in the popular series by Nintendo, and is generally considered as one of the best video games of all time. The game has been released on multiple Nintendo consoles over time, including Nintendo Switch as part of the Nintendo Switch Online offerings, but has only been remade once for the Nintendo 3DS console, complete with some additional features not found in the original.

 In this game, Link sets off on a legendary journey through time to stop Ganondorf, the Gerudo King of Thieves who is seeking the Triforce, a holy relic that gives its holder ultimate power. The graphical upgrades and three-dimensional depth breathe new life into the expansive world of Hyrule. An improved and intuitive interface, coupled with the easier navigation offered by playing in a world with 3D visuals, give players better control as they solve puzzles, travel through time and explore this immersive world.

The post The Legend of Zelda: Ocarina of Time Native PC Port Is Now Available for Dowload by Francesco De Meo appeared first on Wccftech.

23 Mar 17:54

Eero's newest mesh routers include a WiFi 6E model

by Jon Fingas

Eero is relatively late to WiFi 6E, but it's showing up in style — and making WiFi 6 more practical in the process. The Amazon brand has launched two new mesh routers led by the Eero Pro 6E (pictured below). The hardware takes advantage of the 6GHz band to offer up to a 1.3Gbps wireless connection for as many as 100 devices. Each unit has both 2.5Gbps and 1Gbps Ethernet jacks, and should cover up to 2,000 square feet each. Don't worry if you don't have the super-fast internet service to do it justice, though, as we've had some hands-on time with a more affordable option.

The equally new Eero 6+ (above) is 'just' a dual-band WiFi 6 model with two 1Gbps Ethernet ports, 1,500 square feet of coverage per router and a 75-device cap, but it now has access to a 160MHz radio channel that promises faster wireless data. Eero pitches this as the best choice for anyone with reasonably fast internet up to a gigabit.

We've briefly tried the 6+, and it works like much you'd expect if you're familiar with Eero. It has no trouble wringing the most out of a 500Mbps cable internet plan despite the modem and devices living on different floors of a modestly-sized house. The Amazon tie-ins both simplify setup (including reconnecting if you change the network name or password) and controlling the router with Alexa. You can ask the voice assistant to halt internet access for specific users, for instance. Just be aware that this doesn't have the tri-band wireless some rivals use to lighten the load on a busy network, so you may want to pass if you have multiple heavy users who can't afford slowdowns.

Eero Pro 6E WiFi mesh router
Eero Pro 6E
Eero

The pricing is in line with the performance. You can buy the Eero Pro 6E now in a $499 two-pack or $699 three-pack. A single unit is available to pre-order for $299. The Eero 6+ is decidedly easier to justify for most people, based on our experience. It's selling now at a $239 for a two-pack and $299 for a three-pack, with pre-orders open for a $139 one-device kit. And if you don't mind using 2020-era hardware, the earlier Eero 6 has dropped to $89 for one router, $139 for two and $199 for three.

23 Mar 17:52

Nicolas Cage Originally Had A Bigger Role In Fast Times At Ridgemont High

by Bill Bria

Amy Heckerling's film version of Cameron Crowe's book "Fast Times at Ridgemont High" is a teen movie with more on its mind than just raunchy humor and raging hormones. Heckerling recalls seeing the film as a commentary on the changing economic and social realities for teens, observing that pressures to do things like get jobs and lose their virginity "threw them into a grown-up world before they were ready," and the title directing references  how "things were happening too fast for them."

This approach made casting the movie a tricky proposition. Heckerling wanted to avoid the usual Hollywood sleight-of-hand where actors in their late 20's (or older) were cast as teenagers, but also needed principal cast members who had enough acting experience to carry the film. Thus, "Fast Times" stacked its cast full of up-and-comers who were just barely out of high school themselves. While future stars Jennifer Jason Leigh, Phoebe Cates and Sean Penn all ended up with leading roles, one soon-to-be-celebrity barely appears in the movie: Nicolas Cage. In fact, the actor almost landed a leading role himself, a part that would've been his had he not been, ironically, an actual teenager at the time.

He Shall Get No Leading Role Before His Time

Cage, who was still going by his birth name of Nicolas Coppola when "Fast Times" was being made (yes, he's related to filmmaker Francis Ford Coppola, in case you didn't know), was one of only a few actors under serious consideration by Heckerling for the role of Brad Hamilton, the ill-fated fast food clerk who was eventually played by Judge Reinhold (above). In addition to his readily apparent charisma and natural acting talent, Cage was considered for Brad due to telling Heckerling and the producers that he was 18 years old.

Unfortunately, that was a lie—born in 1964, Cage was really just 17 years old when the film began shooting in 1981. While "Fast Times" has a handful of underage actors in small roles, Cage could no longer be considered for a leading part when producers discovered his actual age, as child labor laws in California would not allow a minor to work the long hours required for a lead. Thus, Heckerling granted the older Reinhold the part of Brad, and Cage was relegated to a small supporting role as "Brad's Bud."

Goodbye, Goodbye 'Coppola'; Hello 'Cage'

Cage barely appears on-screen in the theatrical cut of "Fast Times," but he can be seen hanging around Brad at school, behind the grill at All-American Burger, and cheering in the audience at a football game. He actually has some lines to say in two deleted scenes that were used in the movie's television edit, but even those moments are limited. Cage must have grown frustrated on the set of the film, for in addition to his diminished role, he had to endure fellow cast and crew members giving him grief about his birth name and its Hollywood pedigree.

Fortunately, soon after "Fast Times" the actor decided to permanently change his last name to "Cage," helping him establish his own identity and legacy away from his famous relatives. Just a year after his "Ridgemont High" experience, the now legally adult Cage won the leading role of Randy in Martha Coolidge's "Valley Girl," which would go on to become another well-regarded and influential teen comedy. 

Cage's career only skyrocketed from there, with the actor quickly becoming a major star and consistently appearing in an eclectic array of films, up to and including last year's critically acclaimed "Pig." Despite his career ultimately being so impressive, it's intriguing to consider how "Fast Times at Ridgemont High" could've been Cage's breakout film had he not been just another teen trying to grow up too fast.

Read this next: The Best Movies Of 2021

The post Nicolas Cage Originally Had a Bigger Role in Fast Times at Ridgemont High appeared first on /Film.

23 Mar 17:52

How Jackie Chan's Disappointment In Drunken Master Changed The Sequel

by Mike Williams

If you love martial arts films, then the 1978 film "Drunken Master" should be on your watchlist. The film is all-time martial arts classic, starring Jackie Chan as Chinese folk hero Wong Fei-Hung. It put Jackie Chan on the map in Asia, the first step towards him becoming the superstar he is today.

"Drunken Master" was the second collaboration between Chan and director Yuen Woo-ping, following "Snake in the Eagle's Shadow," which released earlier that year. It's credited with not only popularizing the Drunken Boxing style of Chinese martial arts, it's also one of the earliest showcases of Chan's specific flavor of action comedy. The popularity of "Drunken Master" and his subsequent films saw Chan taking on the role of creative lead for "Drunken Master II," where he was able to fix some of the issues he had with the original's overall presentation. 

Woo-ping would follow this success with many other classics, including "Iron Monkey" and "Tai Chi Master," before finding international success as the action choreographer of "The Matrix" and "Crouching Tiger, Hidden Dragon." "Drunken Master" not only blew up the careers of two veterans in action filmmaking, it also inspired countless other movies, games, and television shows.

Keeping The Kids In Mind

Yuen Woo-Ping would not return to direct the sequel, however. "Drunken Master II," also known as "The Legend of Drunken Master," was released many years later in 1994. By that point, Chan was a bonafide star, having written, directed, and starred in "The Fearless Hyena," "Police Story," and "Police Story II." When the time came for a sequel to "Drunken Master," it only made sense for Chan to have a greater hand in the direction of the film. While "Drunken Master II" was directed by Lau Kar-leung, Chan was able to steer the story in a direction that he felt better suited his vision.

1978's "Drunken Master" featured Chan as a younger, impetuous Wong Fei-Hung who learns martial arts as a way to grow emotionally. It's a deft mix of comedy and martial arts action, with every fight showcasing Chan's comical expressions, amazing moves, and wildly over-the-top pratfalls. The sequel came far later and features an older Fei-Hung struggling with a temper and a style of kung fu that requires the consumption of copious amounts of alcohol. Chan wanted to use the later film to present a better message for younger viewers. 

"When I saw 'Drunken Master' after I became popular -- it is a great movie, but I was a little disappointed," Chan explained in an interview for the 35th anniversary of the first film posted at Films Extras. "Because I taught kids about drinking liquor and I hit people through the movie. So when I directed the last half of 'Drunken Master 2,' I adjusted the wrong parts of the story right away. Too much drinking and fighting are wrong."

There's No True Drunken Master III

While Fei-Hung has to drink to unlock the peak of his style of kung fu in "Drunken Master II," his demeanor and general drunkenness are treated as a flaw in the film. Picking fights is the impetus for the film's plot, with Wong's family items being switched with those being smuggled out of China by antagonistic British officials during a duel that didn't need to happen. Likewise, Fei-Hung's drunkenness gets him into more fights and almost causes his father to lose his land.

What hasn't changed is the general craft of the film and Chan's martial arts prowess. With the weight of experience, the older Chan is faster and more precise in the sequel. He's also more adept at playing up the physical comedy of a situation, like an early fight scene where Fei-Hung is desperately looking for more things to drink and becoming more unorthodox in his style as he succeeds. The final fight between a more driven Fei-Hung, who is pushed to drink by necessity, and a taekwondo-wielding henchman played by Ken Lo is a brutal ballet of wild kicks and ethyl alcohol. It's also one of the best fights ever put to film. As a kid who grew up on these films, I have to say I missed all of the messaging about not drinking amidst the excellent fight scenes. Sorry, Mr. Chan.

Later in the interview, Chan notes that the changes made to "Drunken Master II" were indicative of his overall feelings about filmmaking. While the martial arts and comedy remain at the forefront, his later films present more wholesome themes of friendship, family, and loyalty. Kicking people is cool, but you don't have to be a bad guy to do it.

Read this next: The 25 Best Kids' Movies Of All Time

The post How Jackie Chan's Disappointment in Drunken Master Changed the Sequel appeared first on /Film.

23 Mar 17:49

A Single Legacy IPv6 Address On Your Network Can Spoil Your Security

by Jeremy Hellstrom

There is a new research paper out from a collaboration of academics with good taste in titles explains how a single device on your network using a legacy EUI-64 IPv6 address can…

23 Mar 17:48

Even A Die-Hard Trekkie Wouldn't Recognize The First Version Of A Classic Villain

by Devin Meenan

Ask any "Star Trek" fan who the best villain in the series is, and you'll almost always get the same answer: Khan Noonien Singh. A genetically engineered superhuman, Khan and his augmented brethren ruled much of the world in the late 20th century ("Trek" couldn't be right every time it predicted the future!). Khan embodies mankind's history of bloody war and conquest, making him a perfect foil for the optimistic ideals of "Star Trek." 

Sociology professors/bona fide Trekkies John and Maria Jose Tenuto researched the development of Khan from numerous primary sources and they were kind enough to share their findings in an interview with Gizmodo. The history of the making of the greatest villain in "Star Trek" history is as detailed and complex as you'd hope.

Planting The Space Seed

Per the Tenutos' scholarship, Khan's debut episode "Space Seed" was first pitched by Carey Wilbur. Wilbur was a prolific TV writer during the medium's early days, with credits on dozens of shows, but "Space Seed" was his only "Star Trek" credit. In Wilbur's draft, the character who would become Khan is a man of Nordic descent named Harold Erickson. As in the finished episode, Erickson and his ilk left Earth long ago aboard the SS Botany Bay and drifted through space for centuries. When the Enterprise discovers the ship, the crew awaken the villain to an unfamiliar world. 

The similarities between Erickson and Khan end there. Erickson is a mere criminal who lacks the gravitas and thematic resonance of Khan; he's not a brutal dictator hiding behind charisma, just an opportunistic thug. Erickson and Khan share the same goal of seizing the Enterprise, but whereas Khan has the grand design of a new empire, Erickson just wants to be a space pirate.

Writer Gene L. Coon played a major role in revising Erickson into Khan. Coon felt the Enterprise crew needed worthy adversaries; his episode "An Errand Of Mercy" introduced the Klingons. He felt that with some tweaks, Erickson could be a Moriarty to Kirk's Sherlock Holmes; an equal and opposite to the Captain, rather than just another bad guy. In Coon's draft, John Erickson is the cover identity for Ragnar Thorwald, a warlord from Earth's past. Coon also introduces the villain's enhanced strength and intelligence, making him much more dangerous than how Wilbur first conceived of him.

Montalbán Enters The Picture

Casting director Joseph D'Agosta selected Ricardo Montalbán for the part, who was an incredible performer, but not the blond Viking who the writers had envisioned. In a wonderful decision, they changed the character instead of the casting. The multi-cultural casting of "Star Trek" was revolutionary; making a genius superman, the supposed apex of humanity, into a Sikh Indian was one of the series' most radical moves. A major misstep of Khan's most recent appearance, 2013's "Star Trek: Into Darkness," was casting the pale-as-snow Benedict Cumberbatch. "Space Seed" wasn't perfect (Montalbán is a Mexican man playing an Indian one), but it's still more forward-facing than that much younger film.  

Montalbán's casting didn't just change Khan's ethnicity -- it also rewrote his persona. Instead of a barbarian like Erickson, Khan was charming in spite of his ruthlessness. He even seduces Enterprise historian Lt. Marla McGivers (Madlyn Rhue) into helping him. As Tenuto put it, "once they knew that Montalbán was taking the role, you can see a shift in the dialogue to become more romantic." Roddenberry put on the finishing touch by selecting the villain's final name in tribute to his old WWII buddy, Kim Noonien Singh

Setting The Stage For Khan's Return

At the end of "Space Seed," a defeated Khan chooses exile on planet Ceti Alpha V.  Khan cites Milton's "Paradise Lost," "it is better to rule in Hell than to serve in Heaven." Khan never returned before "Star Trek" went off the air, for the 1960s were the days before TV serialization. However, you probably already know that "Space Seed" was not the end of his story. To understand how "Star Trek II: The Wrath Of Khan" came about, you must first understand its predecessor.

10 years after "Star Trek: The Original Series" ended, the original cast reunited for "Star Trek: The Motion Picture." That movie received unenthusiastic reviews and middling box office returns. As a result, the sequel came with a slashed budget ($44 million to $12 million). Roddenberry's original pitch did not feature Khan; instead, it was a spin on the classic episode "The City On The Edge Of Forever." In Roddenberry's "Star Trek II," the Enterprise crew would go back in time after disruptions to their present; they discover they need to ensure the assassination of JFK to protect history.

Paramount rejected Roddenberry's pitch and removed him from any role of true authority on the film. They then hired "Trek" novices Nicholas Meyer and Harv Bennett to direct and produce, respectively. According to "From Sawdust To Stardust," Terry Lee Rioux's biography of DeForest Kelley (aka Dr. Leonard "Bones" McCoy), Bennett suggested reusing Khan after watching "Space Seed." Despite the decreased budget, "The Wrath of Khan" became the shot in the arm that "Star Trek: The Motion Picture" failed to be and heralded four more sequels plus the franchise's return to television. The 1982 film is also why Trekkies remember Khan as more than just a good villain of the week.

An Ahab For The 23rd Century

Aging and the passage of time are the major themes in "The Wrath of Khan." Instead of trying to hide how the cast had grown older, the film embraced it. "Khan" takes place on Captain Kirk's 50th birthday, and the once-proud hero is downtrodden, feeling that he's too worn out to be the adventurer he was in his youth. So, it's only fitting that an old foe from Kirk's glory days is the villain.

Shortly after Khan's people settled on Ceti Alpha V, an interplanetary disaster rendered the planet uninhabitable. While Kirk forgot about Khan, Khan never forgot about Kirk. When the film begins, he's waited 15 years to take his revenge and finally gets an opportunity when the starship Reliant visits the augments' desert prison. After seizing the Reliant, Khan becomes a cosmic Captain Ahab. He even paraphrases "Moby Dick" to explain his pursuit: "[Kirk] tasks me. He tasks me and I shall have him! I'll chase him 'round the moons of Nibia and 'round the Antares Maelstrom and 'round perdition's flames before I give him up!"

Khan dies quoting Melville too, "To the last, I grapple with thee; From Hell's heart, I stab at thee; For hate's sake, I spit my last breath at thee." Unlike Ahab though, who inflicted only some minor wounds on the great white whale, Khan pierces Kirk's very soul with his last act. Spock sacrifices himself to get the Enterprise to safety, and Kirk has to watch his best friend breathe his last breath. In that moment, Khan did worse than kill Kirk: he hurt him.

A Dark Mirror Of Human Advancement

How ironic that in a series that chronicles adventures across the galaxy, the perfect villain is still a human being. In "Space Seed," Spock delivers a concise explanation for the augments' conquest of 20th century Earth: "superior ability breeds superior ambition." Yet despite his superior genetics, Khan embodies some of the most basic and violent aspects of humanity. Like all dictators, he built a regime on subjugation, and throughout "The Wrath Of Khan," he repeatedly sacrifices sense in his quest for vengeance. 

Khan's contradictory nature, evolved yet primal, makes him the perfect foil for the ideals of the Federation and "Star Trek" itself. "Trek" charts an optimistic future based on diplomacy, exploration, and understanding. While 23rd-century humans have risen above their worst impulses, we in the present have a ways to go. If the human race is to evolve and overcome, we must leave behind men like Khan.  

The behind-the-scenes story of Khan Noonien Singh is a tribute to the importance of collaboration in art. Wilbur provided the pitch, but Khan became Khan thanks to Coon and Roddenberry's revisions and Montalbán's mesmerizing performance. It's impossible to know if a two-bit criminal like Harold Erickson would've become as iconic a villain as Khan Noonien Singh. I wouldn't bet on it though.

Read this next: The 12 Best Star Wars Books Ever Written

The post Even A Die-Hard Trekkie Wouldn't Recognize the First Version of a Classic Villain appeared first on /Film.

23 Mar 17:44

Apple Studio Display review: For Mac-loving eyes only

by Devindra Hardawar

Much like the Mac Studio, Apple's new Studio Display is something its devoted fans have been begging for for years. LG's Ultrafine 5K display was, well, just fine, but it wasn't Apple-quality hardware. And while the company's Pro XDR 6K display has practically every feature you'd want, it also costs an eye-watering $6,000. It sure would be nice if Apple just sold the 5K screen from the 27-inch iMac on its own!

Enter the Studio Display. It's a bit brighter than the 5K iMac, but otherwise it's pretty much the same 27-inch screen we've seen for years. To make up for the lack of modern features — like the faster ProMotion refresh rate and Mini-LED backlighting we saw on the latest MacBook Pros — Apple stuffed in an A13 Bionic chip to drive its webcam and speaker features. It's not exactly a smart display as we'd define one, but it's certainly smarter than most screens. Unfortunately, the Studio Display's high $1,599 starting price makes it out of reach for everyone but the Apple faithful.

What's truly maddening, though, is that Apple is seemingly oblivious to the display market in 2022. If you want a height adjustable stand, for example, you'll have to shell out an additional $400 at the time of purchase. (This is the same company that priced the ProDisplay XDR's stand at $1,000, don't forget.) That feature is practically standard today, save for some truly budget offerings. Making height adjustment cost extra on such an expensive monitor is simply inexcusable. There's also a VESA mount option, but you can only opt for that when you're buying the screen. Heaven forbid your needs change after the fact.

And if you want Apple's nano-texture glass option, which helps to reduce reflections in bright environments, be prepared to spend an additional $300. Putting that screen technology along with a height adjustable stand brings the total cost of the Studio Display to $2,299. Sigh. That's just hard to stomach when I also have Alienware's QD-OLED 34-inch ultrawide monitor on my desk — it's pretty much the ultimate gaming screen, with a 175Hz refresh rate, 1,000 nits of peak brightness and actual HDR compatibility. And when compared to the Studio Display, the Alienware QD-OLED is practically a bargain at $1,299.

Apple Studio Display
Devindra Hardawar/Engadget

I get it, the Studio Display isn't made for me. And really, it's not meant for anyone who'd consider a non-Apple product. It's a monitor built expressly for the company's devotees—the sort of user who demands a 5K screen that can accurately render MacOS, and who scoffs at the cheap plastic frames that plague the competition. I've talked to several Mac fanatics who are still running the company's defunct Thunderbolt monitor, and avoided upgrading to the issue-plagued LG UltraFine 5K, who immediately preordered the Studio Display. For them, there just isn't another option.

Despite my frustrations with so many aspects of the Studio Display, it's still a very nice looking 5K LED screen. Its wide P3 gamut support allows colors to pop off the screen, which is particularly noticeable when working with high-resolution photos. The Studio Display isn't technically an HDR screen, but it can still take advantage of the wider color range from HDR streams. Its 600 nits of brightness was also more than enough for my dimly lit office — that's a good thing if you're planning to use one right by a sunny window. And even though it's an aging LED, at least it's using an IPS panel, so colors still looked great from extreme viewing angles.

Apple Studio Display
Devindra Hardawar/Engadget

Naturally, the Studio Display also looks and feels like a premium Apple device, with a smooth aluminum case and an attractive design that's striking from every angle. Around the back, there’s a single Thunderbolt 3 USB-C connection that can charge a MacBook Pro and deliver audio/data at the same time, along with three USB-C ports for accessories. So sure, Mac-heads may be overpaying a ton, but at least they're getting a very usable monitor that'll last for years.

Sometimes, though, using the Studio Display sometimes felt like I was trapped in a David Lynch-esque nightmare, where the beautiful veneer was covering subtle horrors. Black levels never looked better than a dim gray, for example, because the screen relies on a single LED backlight. A modern LCD screen in the same price range typically has dozens to hundreds of backlight zones. (The Mini-LED backlights on the new MacBook Pros have thousands of local dimming zones!) OLED displays, meanwhile, don’t even have to deal with backlight since their pixels can turn on and off individually, delivering far better contrast than the Studio Display.

I also couldn't help but notice that scrolling through text and webpages just never looked as smooth as it does on my iPhone 13 Pro and other Apple ProMotion screens. Once you live with high refresh rates day-to-day, it's hard to go back to any screen running at a mere 60Hz.

Apple Studio Display
Devindra Hardawar/Engadget

The Studio Display's six-speaker sound system is one of the most impressive things I've ever heard from a monitor, especially with the faux-surround sound from Dolby Atmos tracks, but it's also paired with a surprisingly grimy 12-megapixel webcam. Its output consistently looked like it was covered in a layer of Vaseline, no matter if I was using it in a well-lit or dim environment. (And yes, I made sure the lens area wasn't dirty somehow.) Apple says it's working on a fix for the Studio Display's webcam quality, but I'm just shocked they didn't notice any issues until now.

Having Center Stage built into the Display was useful, especially if I was moving around a lot during a video call, but I can't fully judge its quality until Apple fixes the camera issues. I'm more intrigued by the potential behind the Studio Display's A13 chip, though. Twitter user "Khaos Tian" noticed that the monitor actually has 64GB of onboard storage, same as the base model of the A13-equipped iPhone 11.

Apple Studio Display
Devindra Hardawar/Engadget

It could just be that it was easier for Apple to throw in the same storage, instead of bundling the A13 with a smaller disk. But a part of me can't help but wonder what Apple could do with that hardware. Imagine transforming the Studio Display into a true smart screen, with the ability to take FaceTime calls and stream media over AirPlay without being physically connected to a Mac. Apple is far too risk averse to throw in major new features down the line, but I'm interested to see if hardware tinkerers can work some sort of magic on the Studio Display.

I don’t blame Mac fans for being excited about the Studio Display. When you’ve been stuck in a figurative desert for years, you’d be grateful for any kind of salvation. I just wish Apple was as devoted to its loyal followers as they are to the brand. Mac users are used to paying a premium, but they still deserve a screen with modern technology and a stand that can reach eye-level without a pile of books underneath.

23 Mar 17:43

It's A Miracle The Bride Of Frankenstein Ever Made It Past The Censors

by Andrew Housman

There's a long history of horror films causing public controversy that stems back to the early days of the genre, including the Universal classic monster movies. "Bride of Frankenstein" was subject to so much meddling from the Hays Office that it's a wonder the film was not only released but kept its reputation as a historically classic film from the era of pre-war horror.

Even before the release of "Bride of Frankenstein, the original "Frankenstein" film was under threat of censorship. Although "Frankenstein" was a pre-code feature released in 1930 before the code went into full effect in 1934, state censor boards in New York, Massachusetts, and Pennsylvania had serious issues with the scene in which the monster accidentally drowns a little girl in a lake as well as Dr. Frankenstein's declaration comparing himself to God. Reissues of the film released after the Hays Code era cut these controversial moments, and the lost footage wasn't restored until home video releases in the 1980s and '90s. "Bride of Frankenstein," on the other hand, was subject to even more censorship by the strict and watchful eye of the Hays Code censors.

Beginning Issues

The struggle over "Bride of Frankenstein" started when the Hays Office objected to the film's original script written by John L. Balderston. Director James Whale, who was used to dealing with censors during his term directing the previous "Frankenstein," eventually rejected Balderston's work because he thought its tone was overly dreary. However, the ordeal was a sign of what was yet to come. Whale kept Balderston's opening, a conversation between author Mary Shelley, her husband Percy, and the poet Lord Byron. This scene drew the ire of Hays Code censors due to its implied condemnation of the sanctity of marriage. Specifically, the line "We are all three infidels, scoffers of marriage ties ..." was cut, and this is before the Monster even shows up!

Joseph Breen, head of the Hays Office, knew that he was going to be censoring the new "Frankenstein" picture based on how much controversy the first entry experienced. As he explains in a quote featured in film historian David J. Skal's book "Screams of Reason: Mad Science and Modern Culture":

"Your studio is, of course, too well aware of the difficulty which attended the release of the first Frankenstein picture... based principally on the two elements of undue gruesomeness and alleged irreverent attitude..."

Breen referenced "ten separate scenes in which the monster either strangles or tramples people to death," though the final cut of the film shows Frankenstein's Monster strangle only one person at the beginning of the story. Besides the editing out of all this murder and infidelity, the censorship board also targeted instances of alleged blasphemy.

Crucifixions And Queer-Codedness

The censors were already monitoring "Bride of Frankenstein" for any signs of religious issues due to the infamous "Now I know what it feels like to be God" line in the original "Frankenstein." This time around, comparisons to God were cut out of the script while they were still in written form. In addition, a scene in which the monster runs through a graveyard and tries to "rescue" Jesus from a crucifix was ultimately scrapped. Interestingly, another scene in which the villagers tie the monster up to a pole was spared despite its obvious crucifixion imagery.

The most surprising slip past the censor board, however, was the homosexual subtext that Whale, who was one of the very few openly gay people working in Hollywood, cleverly hid. Skal mentions that the idea that Dr. Frankenstein's mentor, Dr. Pretorious, wants to create a new monster together certainly has its not-so-hidden messages about same-sex partnerships. If that wasn't enough, Pretorius mentions that while Dr. Frankenstein was "piecing together dead tissue," he was growing his homunculi experiments "as Nature does — from seeds," a bit of suggestive language to prove the point more.

An Uncensored Legacy

Even after the Hays Office finally approved "Bride of Frankenstein," the film still met backlash from individual states and countries abroad. Ohio, where the state censorship board demanded heavy cuts related to female characters, seemed particularly offended. China wanted to cut four important scenes, while Hungary, Palestine, and Trinidad straight-out banned the film. Sweden proposed editing a whopping 25 scenes out of the film — so much content that Universal refused to hold screenings there.

Still, "Bride of Frankenstein" has endured, becoming more iconic as film historians have analyzed the creativity with which James Whale slyly avoided the wrath of the censors. The film is a snapshot of an earlier era when filmmakers had to consider now outdated rules and practices when piecing together their works. Whale was still able to incorporate themes and imagery that technically broke no Hays Code rules, allowing room for plenty of analysis and thoughtful criticism. In particular, the film's slyly hidden gay subtext made for one of the earliest pieces of queer horror cinema. There may be sizeable amount of story ideas and footage that never saw the light of day in "Bride of Frankenstein," but that doesn't detract from the classic scenes that survived the Hays Code.

Read this next: The 20 Best '60s Horror Movies Ranked

The post It's a Miracle The Bride of Frankenstein Ever Made It Past the Censors appeared first on /Film.

23 Mar 17:41

Windows 11 version 22H2 finally comes to the Beta channel, and there’s a ton of new features

by João Carrasqueira

Today, Microsoft is releasing Windows 11 build 22581 to Windows Insiders in both the Dev and Beta channels. That’s right – this is the first Windows 11 version 22H2 build to make its way to the Beta channel, and that means there are a ton of new features to try out.

Up until now, the Beta channel has been testing the same updates as the Release Preview channel, which are just cumulative updates. But for the past few months, Windows Insiders in the Dev channel have been getting more and more new features, so that’s all available in the Beta channel now.

New Windows 11 features in the Beta channel

What does that include? For starters, a ton of improvements for tablets. There’s a new tablet-optimized taskbar, which collapses to a smaller size when there’s no keyboard or mouse connected. This taskbar only shows system information like the battery, Wi-Fi, and sound icons. You can swipe up to reveal the full taskbar, and in fact, new swipe gestures are a big thing with this update, too. You can now swipe up from the taskbar to open the Start menu and swipe down to close it. You can swipe right from the Start menu to go to the All apps list or the full Recommended list, and more. Swiping sideways with three fingers can switch between recent apps, swiping down can minimize all the open apps,and there’s a new feature to prevent opening the notifications panel when using a full-screen app.

Windows 11 tablet taskbar modes

The taskbar has received some other upgrades, including the ability to drag-and-drop files between apps on the taskbar, a feature that was removed with the original Windows 11 release. Additionally, if you share a window in Microsoft Teams for work or school, you’ll now see an indicator on the taskbar to highlight the window you’re sharing.

The Start menu has received some important upgrades, too. You can now create and rename folders in the Pinned section to organize your apps more easily, and you can choose whether you want to see more pinned apps or more recommended items.

Start menu with folders

File Explorer is another area that’s been significantly improved. You can now see previews of the files inside a folder before opening it, and the Quick Access page now lets you pin recent files to the top of the list. Additionally, context menus have been improved with new options available in the new Fluent menus. You can now pin files to Quick Access, install fonts and certificates, and more without clicking the “Show more options” button. The Fluent context menus are also available when right-clicking the Recycle Bin now. File Explorer also integrates better with OneDrive so you can see your total available cloud storage in the menu at the top.

In its quest to modernize the look of Windows 11, Microsoft has updated the Task Manager and Print Queue with a more modern design and support for both light and dark themes. The volume and brightness sliders that appear when using hardware buttons have also been updated for the first time since Windows 8. Plus, many app icons have been updated with Fluent Design, including Quick Assist. You’ll also see the translucent Mica material used in more places, like the header of the Run window.

There’s a new feature called Live Captions, which automatically adds captions to English-spoken content in real-time, making it easier for users with hearing impairments to enjoy content on their PC. This uses on-device speech-to-text, so an internet connection isn’t required for it to work.

Microsoft has also expanded upon Focus assist and split it between two features: Do Not Disturb, which is more like Focus assist itself; and Focus, which is a more integrated approach to the Focus sessions feature in the Clock app. Using Focus automatically enables Do Not Disturb, but it also has features like the timer and background music from the Clock app.

The Settings app has also received a ton of improvements. The Apps & features page has been split into Installed apps and Advanced app settings pages, HDR calibration is available directly in the HDR settings page (under Display), and you can now uninstall updates from the Update history page in Settings app. The biggest changes are for personalization. Keyboard themes now apply to the voice dictation and emoji panels, and you can preview all of them at once; you can use Windows Spotlight images as your desktop background (they used to only be available on the lock screen); you can customize emoji that have multiple people by changing the skin tone of each person.

Windows 11 input theming

Those are just the biggest changes that are now available in the Beta channel, and they should all be part of Windows 11 version 22H2. Microsoft does warn that this isn’t guaranteed, but you can expect the majority of these changes to make it to the public release later this year.

What’s new in the Dev channel

If you’re in the Dev channel, this build is less exciting, but the new tablet-optimized taskbar is now available for everyone. Additionally, a bug where you’d see a line above only a portion of the taskbar has been fixed so it’s visible across the entire taskbar. Microsoft has also updated the design for when you hover Win32 system tray icons in the taskbar, and speaking of which, you can no longer drag-and-drop these icons from the “Show hidden icons” button to the taskbar, or vice-versa. You now have to go to the taskbar settings (right-click the taskbar) to change the pinned icons. You can also hide the “Show hidden icons” button if you want a cleaner taskbar.

Aside from that, it’s mostly fixes this week. It’s a long list, but you can see them all below:

Fixes in Windows 11 build 22581

[Taskbar]

  • Made a fix for another issue causing taskbar previews to use the wrong fonts for the window title in languages other than English.
  • Drag and drop to taskbar should now work with auto-hidden taskbar.
  • When dragging something to pin to the taskbar, the message on the dragged item (for example, displaying an X if it’s not supported) will now have rounded corners.
  • Mitigated an issue where swiping to collapse the tablet-optimized taskbar might unexpectedly invoke the widgets board.

[Start menu]

  • Fixed an issue that was sometimes causing the search box in the top of Start to flicker.
  • Mitigated an underlying issue where if you swiped to open the All apps list, sometimes it would think that you’d tapped one of the letter headers in the All apps list.
  • Updated the context menu when right clicking a pinned app to say “Move to front” rather than “Move to top”, so it’s more clear what will happen.

[Focus]

  • A Clock app update (version 11.2202.24.0 and higher) has rolled out that fixes the issue where the Clock app was unable to update the Windows Focus state when configuring focus sessions in the Clock app.

[File Explorer]

  • Fixed a few cases where icons were missing next to entries in the context menu and command bar (for example, for the Next Desktop Background entry in the context menu when right clicking on the desktop).
  • Made some small adjustments to some of the icons used in the context menu and command bar, including the copy icon.
  • Folders whose only content is other folders will now show an icon with a slip of paper to indicate there is content inside the folder instead of an empty folder icon.
  • Addressed an underlying issue that could cause File Explorer to crash when using the Group By option.

There are also still some known issues in this release. This includes the update not being available for Beta channel Insiders using Lenovo PCs in China, for some reason. Here’s the full list:

Known issues in Windows 11 build 22581

[General]

  • [BETA CHANNEL] We will not be offering new builds to Windows Insiders in China on Lenovo PCs in the Beta Channel for the time being.
  • Windows Insiders running Windows 10 who join the Dev or Beta Channels to get the latest builds may encounter a download error code 0xc8000402 while trying to download the latest build. As a workaround, please join the Release Preview Channel first, install Windows 11 from there (Build 22000.xxxx), and then switch to the Dev or Beta Channel to receive the latest Insider Preview build. This issue is understood and will be fixed in an upcoming build.

[Taskbar]

  • The taskbar doesn’t always automatically collapse after launching an app or tapping outside of the expanded taskbar on 2-in-1 devices.
  • Some areas of the OS are not yet tracking the height of the expanded taskbar on 2-in-1 devices so you may see overlapping components, such as Widgets overlapping with the taskbar.

[File Explorer]

  • Opening suggested results shown while entering search terms in File Explorer’s search box may not work.
  • We’re working fixing issues regarding icon sizing, visual bugs, and text clipping in the flyout showing OneDrive storage.

[Widgets]

  • Sometimes when pinning from the Feed, the pinned widget is placed at the top instead of below other pinned widgets. If this happens this will autocorrect within 30 minutes, moving the recently pinned widget to the expected default location. Or you can sign out of your Widgets board and immediately signing back in should correct the problem.
  • After rearranging widgets in the widgets board, some users experience problems with widgets in the pinned section rendering incorrectly. If this happens, signing out of your widgets board and immediately signing back in should correct the problem.
  • The Widgets panel may not load as expected when using the swipe from left edge of screen touch motion. You may launch by clicking the Widgets icon or using the Win + W key combination.

[Narrator]

  • Natural voices are breaking up sporadically in the latest build. Restart Narrator to resolve the
    issue.

[Live captions]

  • Certain apps in full screen (e.g., video players) prevent live captions from being visible.
  • Certain apps positioned near the top of the screen and closed before live captions is run will relaunch behind the live captions window positioned at top. Use the system menu (ALT + Spacebar) while the app has focus to move the app’s window further down.
  • The very top of maximized apps (e.g., title bar window management buttons) can’t be reached with touch while live captions is positioned at the top.

If you’re ready to try out the latest improvements, you can check for updates as usual to get the bits. If you want to get the first taste of Windows 11 version 22H2, check out our guide on how to join the Windows Insider Program and get into the Beta channel. If you’re in the Dev channel and you want to get back to a stable build, this is your chance to switch to the Beta channel. Soon, the Dev channel will move on to higher builds and you won’t be able to leave without resetting your PC.

The post Windows 11 version 22H2 finally comes to the Beta channel, and there’s a ton of new features appeared first on xda-developers.

23 Mar 17:40

Adrien Brody's Small Part In The Thin Red Line Started Out As A Lead

by Joshua Meyer

Over the years, a number of well-known actors attached to Terrence Malick films have seen their roles reduced or even cut entirely after shooting them. While other directors might be inclined to pre-edit scenes as they go, Malick is known for shooting hundreds of hours of footage and then sifting through all of it later as he finds his films in the editing room -- sometimes dramatically reworking them and letting performances from famous names fall by the wayside.

Adrien Brody presents what is perhaps the most extreme case of this in that he was supposed to be the lead in "The Thin Red Line," and it wasn't until he was doing press for the film that he learned his role had suddenly shrunk to a minor one among an ensemble cast led by Jim Caviezel. In the 1998 movie, set in Guadalcanal during World War II, Brody plays Corporal Fife, a major character in the James Jones novel on which the film is based. Referring to Malick as "Terry," Brody himself later recounted his experience on "The Thin Red Line" to The Independent (by way of Cinephilia & Beyond), where he said:

"I was so focused and professional, I gave everything to it, and then to not receive everything... in terms of witnessing my own work. It was extremely unpleasant because I'd already begun the press for a film that I wasn't really in. Terry obviously changed the entire concept of the film. I had never experienced anything like that."

Malick Has A History Of Cutting Actors From His Films

Brody's co-star, John Cusack, who wound up having a much larger role than him in "The Thin Red Line," described Malick's approach to filmmaking as "wildly intuitive and impressionistic." At the time, he said Malick "wrote a script based on the novel" and was "making a film based on the script" but "not shooting the script," just its essence. This led to other actors like Mickey Rourke, Bill Pullman, and Lukas Haas being left on the cutting-room floor, where Billy Bob Thornton's voiceover narration also went.

Brody, at least, still has some limited screen time in "The Thin Red Line," whereas Rourke's performance, for instance, only lives on in deleted scenes. It's an experience actors in other Malick films have shared well into the 21st century. As Indiewire notes, Rachel Weisz, Michael Sheen, Amanda Peet, Barry Pepper, and Jessica Chastain were all cut from Malick's 2012 film, "To the Wonder." More actors seem to know, now, what they are getting into when they sign on for a Malick project, with many of them being happy just to work with him and observe his unique process, even if their performances get cut.

For "The Tree of Life," comments from cinematographer Emmanuel Lubezki once led us to estimate that Malick had shot almost 365 hours of footage for that film, which he would ultimately edit down to 2 hours and 18 minutes. This would mean he only used about 1/150th of the footage he shot. That's an unusually high ratio of unused footage, but it gives you an idea of how much material Malick might be working with when he edits.

It's one thing to read Malick stories, but even among stars in roundtable discussions, his unorthodox working methods have become the stuff of Hollywood legend. As you can see in the video below, what happened to Adrien Brody in "The Thin Red Line" came up during one such Oscars Roundtable, which Christopher Plummer, Viola Davis, George Clooney, Tilda Swinton, Michael Fassbender, and Charlize Theron participated in for Newsweek back in 2012.

The Brody Story Is Legendary Even Among Stars

Plummer and Clooney had appeared in "The New World" and "The Thin Red Line," respectively. Plummer said that Brody didn't find out about the reduction of his role in "The Thin Red Line" until he was at the movie's premiere. Clooney, who had more direct, firsthand knowledge of the film's production, said that he thought it actually happened at a press junket. Either way, that's extremely late notice, and it's hard to believe that Malick (or someone on his behalf) didn't reach out to Brody sooner to let him know before he appeared in Vanity Fair profiles and started doing other promotions for the film.

Clooney recalled how Malick reshaped "The Thin Red Line" around Caviezel, while Plummer related his own experience of having an emotional scene reduced to background noise in "The New World." "The problem with Terry, which I soon found," Plummer said, "is that he needs a writer, desperately."

Plummer also mentioned his co-star, Colin Farrell, joking to him about ospreys, and it seems this stemmed from Farrell's own experience of being overlooked by Malick while shooting a scene in favor of a bird that wandered onto the set. While Plummer acknowledged that Malick had a tendency to write and then "overwrite," it seems that, in some cases, Malick has also been radically rewriting and restructuring his films in the editing room at the expense of some actors' performances -- with Brody being one of those.

That hasn't stopped names like Christian Bale from wanting to work with Malick again. For them, maybe, Malick's artistic ends justify his means. Fassbender, too, even after sitting there at that roundtable and hearing all these stories, would still go on to work with Malick in "Song to Song."

Read this next: The 20 Greatest War Films Of All Time

The post Adrien Brody's Small Part in The Thin Red Line Started Out as a Lead appeared first on /Film.

23 Mar 03:33

DEV-0537 criminal actor targeting organizations for data exfiltration and destruction

by Katie McCafferty

March 24, 2022 update – As Microsoft continues to track DEV-0537’s activities, tactics, and tools, we’re sharing new detection, hunting, and mitigation information to give you additional insights on remaining vigilant against these attacks.

In recent weeks, Microsoft Security teams have been actively tracking a large-scale social engineering and extortion campaign against multiple organizations with some seeing evidence of destructive elements. As this campaign has accelerated, our teams have been focused on detection, customer notifications, threat intelligence briefings, and sharing with our industry collaboration partners to understand the actor’s tactics and targets. Over time, we have improved our ability to track this actor and helped customers minimize the impact of active intrusions and in some cases worked with impacted organizations to stop attacks prior to data theft or destructive actions. Microsoft is committed to providing visibility into the malicious activity we’ve observed and sharing insights and knowledge of actor tactics that might be useful for other organizations to protect themselves. While our investigation into the most recent attacks is still in progress, we will continue to update this blog when we have more to share.

The activity we have observed has been attributed to a threat group that Microsoft tracks as DEV-0537, also known as LAPSUS$. DEV-0537 is known for using a pure extortion and destruction model without deploying ransomware payloads. DEV-0537 started targeting organizations in the United Kingdom and South America but expanded to global targets, including organizations in government, technology, telecom, media, retail, and healthcare sectors. DEV-0537 is also known to take over individual user accounts at cryptocurrency exchanges to drain cryptocurrency holdings.

Unlike most activity groups that stay under the radar, DEV-0537 doesn’t seem to cover its tracks. They go as far as announcing their attacks on social media or advertising their intent to buy credentials from employees of target organizations. DEV-0537 also uses several tactics that are less frequently used by other threat actors tracked by Microsoft. Their tactics include phone-based social engineering; SIM-swapping to facilitate account takeover; accessing personal email accounts of employees at target organizations; paying employees, suppliers, or business partners of target organizations for access to credentials and multifactor authentication (MFA) approval; and intruding in the ongoing crisis-communication calls of their targets.

The social engineering and identity-centric tactics leveraged by DEV-0537 require detection and response processes that are similar to insider risk programs–but also involve short response timeframes needed to deal with malicious external threats. In this blog, we compile the tactics, techniques, and procedures (TTPs) we’ve observed across multiple attacks and compromises. We also provide baseline risk mitigation strategies and recommendations to help organizations harden their organization’s security against this unique blend of tradecraft.

Analysis

The actors behind DEV-0537 focused their social engineering efforts to gather knowledge about their target’s business operations. Such information includes intimate knowledge about employees, team structures, help desks, crisis response workflows, and supply chain relationships. Examples of these social engineering tactics include spamming a target user with multifactor authentication (MFA) prompts and calling the organization’s help desk to reset a target’s credentials.

Microsoft Threat Intelligence Center (MSTIC) assesses that the objective of DEV-0537 is to gain elevated access through stolen credentials that enable data theft and destructive attacks against a targeted organization, often resulting in extortion. Tactics and objectives indicate this is a cybercriminal actor motivated by theft and destruction.

While this actor’s TTPs and infrastructure are constantly changing and evolving, the following sections provide additional details on the very diverse set of TTPs we have observed that DEV-0537 is using.

Initial access

DEV-0537 uses a variety of methods that are typically focused on compromising user identities to gain initial access to an organization including:

  • Deploying the malicious Redline password stealer to obtain passwords and session tokens
  • Purchasing credentials and session tokens from criminal underground forums
  • Paying employees at targeted organizations (or suppliers/business partners) for access to credentials and MFA approval
  • Searching public code repositories for exposed credentials

Using the compromised credentials and/or session tokens, DEV-0537 accesses internet-facing systems and applications. These systems most commonly include virtual private network (VPN), remote desktop protocol (RDP), virtual desktop infrastructure (VDI) including Citrix, or identity providers (including Azure Active Directory, Okta). For organizations using MFA security, DEV-0537 used two main techniques to satisfy MFA requirements–session token replay and using stolen passwords to trigger simple-approval MFA prompts hoping that the legitimate user of the compromised account eventually consents to the prompts and grants the necessary approval.

In some cases, DEV-0537 first targeted and compromised an individual’s personal or private (non-work-related) accounts giving them access to then look for additional credentials that could be used to gain access to corporate systems. Given that employees typically use these personal accounts or mobile phone numbers as their second-factor authentication or password recovery, the group would often use this access to reset passwords and complete account recovery actions.

Microsoft also found instances where the group successfully gained access to target organizations through recruited employees (or employees of their suppliers or business partners). DEV-0537 advertised that they wanted to buy credentials for their targets to entice employees or contractors to take part in its operation. For a fee, the willing accomplice must provide their credentials and approve the MFA prompt or have the user install AnyDesk or other remote management software on a corporate workstation allowing the actor to take control of an authenticated system. Such a tactic was just one of the ways DEV-0537 took advantage of the security access and business relationships their target organizations have with their service providers and supply chains. 

Partial screenshot of a messaging application showing a text message from LAPSUS$ with the following heading:

We recruit employees/insider at the following!!!!
Figure 1. Screenshot of an ad recruiting employees to give out access to their employer’s network

In other observed activity, DEV-0537 actors performed a SIM-swapping attack to access a user’s phone number before signing into the corporate network. This method allows the actors to handle phone-based authentication prompts they need to gain access to a target.

Once standard user credentials or access was obtained, DEV-0537 typically connected a system to an organization’s VPN. In some cases, to meet conditional access requirements, DEV-0537 registered or joined the system to the organization’s Azure Active Directory (Azure AD).

Reconnaissance and privilege escalation

Once DEV-0537 obtained access to the target network using the compromised account, they used multiple tactics to discover additional credentials or intrusion points to extend their access including:

  • Exploiting unpatched vulnerabilities on internally accessible servers including JIRA, Gitlab, and Confluence
  • Searching code repositories and collaboration platforms for exposed credentials and secrets

They have been consistently observed to use AD Explorer, a publicly available tool, to enumerate all users and groups in the said network. This allows them to understand which accounts might have higher privileges. They then proceeded to search collaboration platforms like SharePoint or Confluence, issue-tracking solutions like JIRA, code repositories like GitLab and GitHub, and organization collaboration channels like Teams or Slack to discover further high-privilege account credentials to access other sensitive information.

DEV-0537 is also known to exploit vulnerabilities in Confluence, JIRA, and GitLab for privilege escalation. The group compromised the servers running these applications to get the credentials of a privileged account or run in the context of the said account and dump credentials from there. The group used DCSync attacks and Mimikatz to perform privilege escalation routines. Once domain administrator access or its equivalent has been obtained, the group used the built-in ntdsutil utility to extract the AD database.

In some cases, DEV-0537 even called the organization’s help desk and attempted to convince the support personnel to reset a privileged account’s credentials. The group used the previously gathered information (for example, profile pictures) and had a native-English-sounding caller speak with the help desk personnel to enhance their social engineering lure. Observed actions have included DEV-0537 answering common recovery prompts such as “first street you lived on” or “mother’s maiden name” to convince help desk personnel of authenticity. Since many organizations outsource their help desk support, this tactic attempts to exploit those supply chain relationships, especially where organizations give their help desk personnel the ability to elevate privileges.

Exfiltration, destruction, and extortion

Based on our observation, DEV-0537 has dedicated infrastructure they operate in known virtual private server (VPS) providers and leverage NordVPN for its egress points. DEV-0537 is aware of detections such as impossible travel and thus picked VPN egress points that were geographically like their targets. DEV-0537 then downloaded sensitive data from the targeted organization for future extortion or public release to the system joined to the organization’s VPN and/or Azure AD-joined system.

DEV-0537 has been observed leveraging access to cloud assets to create new virtual machines within the target’s cloud environment, which they use as actor-controlled infrastructure to perform further attacks across the target organization.

If they successfully gain privileged access to an organization’s cloud tenant (either AWS or Azure), DEV-0537 creates global admin accounts in the organization’s cloud instances, sets an Office 365 tenant level mail transport rule to send all mail in and out of the organization to the newly created account, and then removes all other global admin accounts, so only the actor has sole control of the cloud resources, effectively locking the organization out of all access. After exfiltration, DEV-0537 often deletes the target’s systems and resources. We’ve observed deletion of resources both on-premises (for example, VMware vSphere/ESXi) and in the cloud to trigger the organization’s incident and crisis response process.

The actor has been observed then joining the organization’s crisis communication calls and internal discussion boards (Slack, Teams, conference calls, and others) to understand the incident response workflow and their corresponding response. It is assessed this provides DEV-0537 insight into the victim’s state of mind, their knowledge of the intrusion, and a venue to initiate extortion demands. Notably, DEV-0537 has been observed joining incident response bridges within targeted organizations responding to destructive actions. In some cases, DEV-0537 has extorted victims to prevent the release of stolen data, and in others, no extortion attempt was made and DEV-0537 publicly leaked the data they stole.

Impact

Early observed attacks by DEV-0537 targeted cryptocurrency accounts resulting in compromise and theft of wallets and funds. As they expanded their attacks, the actors began targeting telecommunication, higher education, and government organizations in South America. More recent campaigns have expanded to include organizations globally spanning a variety of sectors. Based on observed activity, this group understands the interconnected nature of identities and trust relationships in modern technology ecosystems and targets telecommunications, technology, IT services and support companies–to leverage their access from one organization to access the partner or supplier organizations. They have also been observed targeting government entities, manufacturing, higher education, energy, retailers, and healthcare.

Microsoft will continue to monitor DEV-0537 activity and implement protections for our customers. The current detections and advanced detections in place across our security products are detailed in the following sections.

Actor actions targeting Microsoft

This week, the actor made public claims that they had gained access to Microsoft and exfiltrated portions of source code. No customer code or data was involved in the observed activities. Our investigation has found a single account had been compromised, granting limited access. Our cybersecurity response teams quickly engaged to remediate the compromised account and prevent further activity. Microsoft does not rely on the secrecy of code as a security measure and viewing source code does not lead to elevation of risk. The tactics DEV-0537 used in this intrusion reflect the tactics and techniques discussed in this blog. Our team was already investigating the compromised account based on threat intelligence when the actor publicly disclosed their intrusion. This public disclosure escalated our action allowing our team to intervene and interrupt the actor mid-operation, limiting broader impact.

Recommendations

Strengthen MFA implementation

Multifactor authentication (MFA) is one of the primary lines of defense against DEV-0537. While this group attempts to identify gaps in MFA, it remains a critical pillar in identity security for employees, vendors, and other personnel alike. See the following recommendations to implement MFA more securely:

Do:

  • Require MFA for all users coming from all locations including perceived trusted environments, and all internet-facing infrastructure–even those coming from on-premises systems.
  • Leverage more secure implementations such as FIDO Tokens, or Microsoft Authenticator with number matching. Avoid telephony-based MFA methods to avoid risks associated with SIM-jacking.
  • Use Azure AD Password Protection to ensure that users aren’t using easily guessed passwords. Our blog about password spray attacks outlines additional recommendations.
  • Leverage passwordless authentication methods such as Windows Hello for Business, Microsoft Authenticator, or FIDO tokens to reduce risks and user experience issues associated with passwords.
  • Implement user and sign-in risk-based policies that block high impact user actions like device enrollment and MFA registration.
  • Break glass accounts should be stored offline and not be present in any sort of online password vaulting solution.
  • Use automated reports and workbooks such as Azure Monitor workbooks for reports for detailed analysis on risk distribution, risk detection trends, and opportunities for risk remediation.
  • Remind employees that enterprise or workplace credentials should not be stored in browsers or password vaults secured with personal credentials

Do NOT:

  • Use weak MFA factors such as text messages (susceptible to SIM swapping), simple voice approvals, simple push (instead, use number matching), or secondary email addresses.
  • Include location-based exclusions. MFA exclusions allow an actor with only one factor for a set of identities to bypass the MFA requirements if they can fully compromise a single identity.
  • Allow credential or MFA factor sharing between users.

Require healthy and trusted endpoints

  • Require trusted, compliant, and healthy devices for access to resources to prevent data theft.
  • Turn on cloud-delivered protection in Microsoft Defender Antivirus to cover rapidly evolving attacker tools and techniques, block new and unknown malware variants, and enhance attack surface reduction rules and tamper protection.

Leverage modern authentication options for VPNs

VPN authentication should leverage modern authentication options such as OAuth or SAML connected to Azure AD to enable risk-based sign-in detection. Modern authentication enables blocking authentication attempts based on sign-in risk, requiring compliant devices for sign in, and tighter integration with your authentication stack to provide more accurate risk detections. Implementation of modern authentication and tight conditional access policies on VPN has been shown to be effective against DEV-0537’s access tactics.

Strengthen and monitor your cloud security posture

DEV-0537 leverages legitimate credentials to perform malicious actions against customers. Since these credentials are legitimate, some activity performed might seem consistent with standard user behavior. Use the following recommendations to improve your cloud security posture:

Screenshot of Microsoft Azure AD Identity Protection
Figure 2. Using Azure AD Identity Protection to review risk detections

Improve awareness of social engineering attacks

Microsoft recommends raising and improving awareness of social engineering tactics to protect your organization. Educate members of your technical team to watch out for and report any unusual contacts with colleagues. IT help desks should be hypervigilant about suspicious users and ensure that they are tracked and reported immediately. We recommend reviewing help desk policies for password resets for highly privileged users and executives to take social engineering into consideration.

Embed a culture of security awareness in your organization by educating employees about help desk verification practices. Encourage them to report suspicious or unusual contacts from the help desk. Education is the number one defense against social engineering attacks such as this one and it is important to make sure that all employees are aware of the risks and known tactics.

Establish operational security processes in response to DEV-0537 intrusions

DEV-0537 is known to monitor and intrude in incident response communications. As such, these communication channels should be closely monitored for unauthorized attendees and verification of attendees should be performed visually or audibly.

We advise organizations to follow very tight operational security practices when responding to an intrusion believed to be DEV-0537. Organizations should develop an out-of-band communication plan for incident responders that is usable for multiple days while an investigation occurs. Documentation of this response plan should be closely held and not easily accessible.

Microsoft continues to track DEV-0537’s activities, tactics, malware, and tools. We will communicate any additional insights and recommendations as we investigate their actions against our customers.

Detecting, hunting, and responding to DEV-0537 activities

Microsoft security products provide several detections that can help identify activities resembling DEV-0537 tactics. We’re also sharing several Microsoft 365 Defender, Microsoft Defender for Cloud Apps, and Microsoft Sentinel hunting and detection queries that are linked in the following sections. We suggest reviewing the following detections and using the highlighted queries to enhance the investigation of potential activity in your environment.

Initial access

Microsoft Sentinel hunting queries

Sign-in from VPS providers – This query looks for successful sign-ins from known VPS provider network ranges with suspicious token-based sign-in patterns. This is not an exhaustive list of VPS provider ranges but covers some of the most prevalent providers observed. 

Investigate unknown sign-in attempts from uncommon or unusual VPS providers.

Sign-in activity from NordVPN providers – This query looks for sign-in activity from NordVPN providers using the feed leveraging NordVPN API and is updated daily.

Investigate unknown sign-in attempts from VPN providers such as NordVPN unless it is commonly seen in your organization.

User sign-in IP address teleportation – This query looks at sign-in logs to identify user accounts that have signed in from two different countries or regions within a specified time window. By default, this is a 10-minute window either side of the previous sign-in.

Investigate the users signing in from multiple locations within a short span of time. It might detect users roaming onto VPNs. You can also exclude known VPN IP address ranges in the query.

Reconnaissance

Microsoft 365 Defender built-in detection: Multiple searches for sensitive data in SharePoint sites

This detection looks for instances where a user searched for sensitive data on SharePoint sites that an attacker can use as internal information to leverage in later attacks if the user’s account is compromised.

Investigate the user account performing the queries to determine if it was compromised. Determine what, if any, sensitive information was accessed to assess the impact.

Note: Data used in this detection requires advanced audit to be enabled in Microsoft Defender 365 that includes the SearchQueryInitiatedSharePoint event type.

Privilege escalation

Microsoft 365 Defender built-in detection: Risky user created global admin

This detection will alert users based on the risk score proved by Azure AD Identity Protection when a new global admin was created by a user that had a risky sign-in. An attacker might have compromised the user account to perform lateral movement.

Investigate the new global admin account to determine if it was created legitimately and if the user account that performed the action was compromised.

Microsoft 365 Defender hunting queries

Multiple admin role removal operations done by a single user – This query looks for multiple users that had their administrator role removed by a single user within a certain period.

Investigate if the user account that removed the admin roles was compromised or if the actions were legitimate. If determined to be compromised, disable the account and reset the password. Restore access to affected accounts as needed.

‘ElevateAccess’ operation followed risky sign-in – This query looks for users who had a risky sign-in (based on Azure AD Identity Protection risk score) and then performed an ‘ElevateAccess’ action. ‘ElevateAccess’ operations can be used by global admins to obtain permissions over Azure resources.

Investigate the risky sign-ins and the following ‘ElevateAccess’ operation and disable the account if it was determined to be compromised.

Microsoft Sentinel hunting queries

User-assigned privileged role – This query identifies when a new privileged role is assigned to a user or when any account eligible for a role is given privileged access.

Investigate if the assignment of privileged access is unexpected or does not align to the role of the account holder. See Things to monitor in your security operations for privileged accounts for details.

User added to Azure AD privileged groups (near real-time (NRT) rule) – This query looks for instances when a user is added to any privileged groups. 

Investigate any unusual additions to privileged groups, particularly administrator roles. For details, see Azure AD audit activity reference and administrator role permissions in Azure AD.

Multiple admin membership removals from newly created admin – This query detects when newly created global admin removes multiple existing global admins which can be an attempt by adversaries to lock down the organization and retain sole access. 

Investigate reasoning and intention of multiple membership removal by new global admins and take necessary actions accordingly.

For Microsoft Sentinel customers who have onboarded Okta logs, the following queries can assist in investigating DEV-0537 activity across those logs:

Microsoft Sentinel + Okta logs hunting queries

Admin privilege granted (Okta) – This query searches for successful grant of administrator permissions to user/groups. Adversaries often attempt to assign administrator permission to users/group to maintain access as well as to elevate privileges. 

Verify the behavior is known and filter out any expected activity and triage unknown. See Okta API event types for details. 

Create API token (Okta) – This query searches for attempts to create new API token. Okta API tokens are used to authenticate requests to Okta APIs.

Investigate attempts to create new API token creation or authentication attempts. See Okta API event types for details. 

Initiate impersonation session (Okta) – This query searches for impersonation events used in LAPSUS$ activity. User.session.impersonation are rare events, normally triggered when an Okta Support person requests admin access for troubleshooting.

Review user.session.impersonation events and correlate that with legitimate opened Okta support tickets to determine if these are anomalous. See Okta API event types and Cloudflare’s investigation of the January 2022 Okta compromise for details. 

Rare MFA operations (Okta) – MFA helps prevent credential compromise. This query searches for rare MFA operations like deactivating, updating, resetting, and attempts to bypass MFA.

Adversaries often attempt these operations to compromise networks and high-value accounts.

Verify that the behavior is known and filter out anything that is expected. See Okta API event types for details. 

Persistence

Microsoft 365 Defender hunting queries

Device registration after risky sign-in – This query looks for a new device registration in Azure AD preceded by a medium or high-risk sign-in session for the same user within a maximum of six hours.

Investigate the user account to determine if it is compromised. Disable user account, reset user password, and remove devices registered in Azure AD if compromised.

MFA method added after risky sign-in – This query looks for a new MFA method added to an account that was preceded by a medium or high-risk sign-in session for the same user within a maximum of six hours.

Investigate the user account to determine if it is compromised. If compromised, disable the user account, reset user password, and remove the MFA method added by threat actor.

Exfiltration, destruction, and extortion

Microsoft Defender for Cloud Apps built-in detection: Delete multiple VMs in a single session

This detection profiles your environment and triggers alerts when users delete multiple VMs in a single session, relative to the baseline in your organization. This might indicate an attempted breach.

Investigate the user account performing the deletion operations to determine if it was compromised or if the activities were performed legitimately and not part of a destructive attack.

Microsoft 365 Defender query

Upload multiple code repositories to external cloud domains – This query looks for accounts that uploaded multiple code repositories to external web domain.

Investigate if the accounts are compromised. If compromised, disable the accounts and reset the passwords. Assess the impact of what information was obtained, looking for any passwords, secrets, certificates, and others that the attacker might be able to leverage.

Note: This query uses ‘FileUploadedToCloud’ event which is only available for customers that enabled Microsoft Defender for Endpoint integration with Microsoft Defender for Cloud Apps. See Integrate Microsoft Defender for Endpoint with Defender for Cloud Apps for details)

Microsoft Sentinel hunting queries

Mass cloud resource deletions time series anomalies – This query generates baseline pattern of cloud resource deletions by a user and alert on an anomaly when any unusual spike is detected.

Investigate the anomalies from unusual or privileged users, they could be indication of a cloud infrastructure takedown by an adversary. 

Mail redirect via ExO transport rule – This query identifies when Exchange Online transport rule configured to forward emails.

Investigate detections to determine if a malicious actor has configured a new mailbox to collect mail from multiple user accounts.

Time series anomaly for data size transferred to public internet – This query identifies anomalous or unusual data transfers to public networks. This detection identifies large deviations from a baseline pattern based on detection algorithms from the Sentinel-integrated Kusto Query Language (KQL) anomaly detection. The higher the score, the further it is from the baseline value. The output is aggregated to provide a summary view of unique source IP to destination IP address and port bytes sent traffic observed in the flagged anomaly hour. The source IP addresses which were sending less than bytessentperhourthreshold have been excluded, the value of which can be adjusted as needed. You might have to run queries for individual source IP addresses from SourceIPlist to determine if anything looks suspicious. Investigate any sudden increase in data transferred to unknown public networks as an indication of data exfiltration attempts.

The post DEV-0537 criminal actor targeting organizations for data exfiltration and destruction appeared first on Microsoft Security Blog.

22 Mar 23:49

Invasion Season 1 Ending Explained: The Visitors Haven't Left

by Valerie Ettenhofer

Apple TV+'s series "Invasion" is not your typical alien show. The series takes place all across the globe as seemingly random people are impacted by first contact from extraterrestrials. The series' budget appears to be as massive as its scope, but its stories mostly stay grounded thanks to a few standout performances and an emotional score by Max Richter.

The first season of "Invasion" was apparently a success, as Apple has already ordered a second one. "I'm super excited about what we're planning for season two, expanding our universe in the most intimate and epic ways," series co-creator Simon Kinberg said when the news of the renewal first broke. Indeed, the show that initially seemed like it could've been a limited series turned out to be a bit more sprawling, tying up some loose ends but leaving others unraveled at the end of its first 10 episodes.

Mitsuki Makes Contact

For the most part, "Invasion" is your typical sci-fi fare, so its first season ending isn't so much existential or profound as it is simply narratively interesting. The show follows five key characters across the world, although one who featured prominently in promotional materials was unceremoniously killed way back in episode 1: Sam Neill's Sheriff Jim Bell Tyson, an Oklahoma man on the verge of retirement, is among the first to encounter the extra-terrestrial creatures, and is swiftly dispatched by them, never to be seen again.

The other four key players are schoolboy Caspar (Billy Barratt), soldier Trevante (Shamier Anderson), doctor-turned-housewife Aneesha (Golshifteh Farahani), and astronaut comms specialist Mitsuki (Shiori Kutsuna). It's the latter who ultimately unlocks the key to the whole interplanetary endeavor when her dead lover –- or an alien cosplaying as her –- makes contact with Mitsuki in the penultimate episode. In a sweet moment, Mitsuki asks the disembodied voice of Hinata (Rinko Kikuchi) what happened when the pair first went home together, and it responds by playing a David Bowie song in reference to the couple's discussion of the musician.

The sincere moment is cut short, however, when it's revealed that Mitsuki is communicating with (probably) the alien force as a form of distraction while the United States nukes the crap out of the invaders. Although her fellow scientists confirm she's talking to a synthetic version of her girlfriend, Mitsuki isn't convinced, and in the final episode, she returns to the satellite station to try one more time to get in contact with her lost love.

Mitsuki's plot hits the hardest of any in the first season of "Invasion," and her grief feels very real, but so does her hope. If the aliens can somehow know that she and Hinata talked about David Bowie after their first date, that either means they've harnessed Hinata's brain power, or they can read Mitsuki's thoughts. The third option, of course, is that Hinata is somehow alive, and communicating with her through the alien technology.

Caspar Ends Up In A Liminal Space

Not everyone makes it through the early stages of the invasion unscathed, though. Seizure-prone UK schoolkid Caspar turns out to have a strong link to the aliens, and whenever he has an episode, he seems to see the future. He meets up with Trevante in London, and the pair decide to induce a seizure on purpose to see if they can stop the alien invasion. It's unclear whether its this procedure or, you know, the nuclear bomb that does the trick, but the invasion does stop when Caspar falls into a seizure. Unfortunately, he doesn't get to see the world come back to life again post-invasion. Caspar is left with no brain activity, and Trevante –- whose life in deployment hasn't allowed him much time to process anything –- mourns his death.

Of course, "Invasion" wouldn't get a second season if it didn't have a story teed up for kickoff, and it starts planting the seeds for its continuing plot at the very end of its finale. We see Caspar on a table in the morgue, but we also see him -– in his own mind? In an alternate dimension? -- being given a compass that leads him to what seems to be a pulsating, bioluminescent landscape. Stranger yet, the man giving him the compass is Hinata's father. "You can see where you are and where you're going," he says. "You can see how the world pulls."

Caspar isn't the only person to end the season in a strange, liminal space. After finally making it home to his wife, Trevante goes on a much-deserved vacation, only to be overcome with emotions when he sees a spacecraft hovering in the distance. Meanwhile, Aneesha and her family end up at an abandoned fire station, sans her husband Ahmed, who seems to have sacrificed himself when the family got caught in the woods. Aneesha suddenly awakens in the middle of the night, and her son, Luke, clings to the iridescent material he found that seems to act as a sort of Kryptonite for these aliens.

The Group Still Feels The Invaders

This is an ending that's much more suggestive than it is explicit: it's all but impossible to know exactly what's going on, but "Invasion" seems to want it that way. The four people we started the series with seemed random at first, but each one played a key role in vanquishing the aliens. It's noteworthy that we don't see any news footage at the series' end marking the space invaders' return. Instead, the focus is on the overwhelmingly personal experiences of the people witnessing them.

In fact, the season ends on a note that's so personal, it's hard to tell if the remnants of the invasion are real for everyone, or only visible to those who ended up closest to the species the first time around. Caspar and Mitsuki's plots seem to indicate the show is ready to head into a more metaphysical direction, which would be a welcome turn after the slow burn "War of the Worlds"-like first season. Until "Invasion" returns, we'll be left to ponder the impact these visitors have left on earth, wonder if Sam Neill will return as a creepy alien vessel, and play that painfully gorgeous score on repeat.

Read this next: The 10 Best Sci-Fi Movie Villains

The post Invasion Season 1 Ending Explained: The Visitors Haven't Left appeared first on /Film.

22 Mar 23:48

Bill Murray Had An Ulterior Motive For Taking His Ghostbusters Role

by Miyako Pleines

Bill Murray is a man with an illustrious acting career. He's done everything from taking on the role of the gopher-obsessed groundskeeper Carl Spackler in "Caddyshack" to decidedly more serious roles like washed up movie star Bob Harris in "Lost in Translation." He's got the range and the talent to deliver his quintessential deadpan humor one minute, only to pivot to a more raw, vulnerable side the next. 

One of Murray's most serious roles is that of Larry Darrell in the 1984 adaptation of W. Somerset Maugham's story, "The Razor's Edge." In the film, Murray plays a World War I veteran whose life is considerably altered after his commanding officer gives his life to save Larry's. Reeling from survivor's guilt, Larry embarks on a multi-country search for meaning as he struggles to understand his purpose in the world. It is a devastating story and not one that is frequently referenced when talking about Murray and his most famous works. Surprisingly, it also played an important role in the production of another extremely famous Bill Murray film — "Ghostbusters." 

That's right, everyone's favorite ghost-busting team owes a little bit of its existence to Murray's deep devotion to making "The Razor's Edge."

What Do Slimer And World War I Have In Common?

The way Bill Murray got involved with the production of "The Razor's Edge" goes like this: One day, the director of the film, John Byrum, visited his friend Margaret Kelly in the hospital. She had just given birth, and he had come to visit and deliver a book, "The Razor's Edge," (because that's the book you want to read after just having had a baby!). Byrum was hoping to film his version of the story, but he needed a place to start. Thankfully, the starting point came in the form of Bill Murray, then-husband to Kelly, who called Byrum up right away telling him he was interested in getting involved. He allegedly greeted Byrum on the phone by saying, "This is Larry, Larry Durrell," the book's main character. From that point on, the deal was set and Byrum and Murray set off on a road trip across America (insert your favorite Jack Kerouac reference here) to write the script. Unfortunately, upon their return they found that no one was really that interested in making their movie a reality. 

In an interview for Rolling Stone, Murray explains how he was finally able to convince Hollywood to make his and Byrum's film, "Dan Aykroyd called me up with this 'Ghostbusters' idea, and I said, 'Yeah, this is great.' He sent me about seventy-five pages, and within an hour there was a deal," Murray says. Fairly soon after, all the major studios were trying to get their hands on the "Ghostbusters script." Seeing his opportunity, Murray decided to try and strike a deal. He told Aykroyd that he was hoping to finish "The Razor's Edge" before committing to another project but was having trouble generating any interest. Aykroyd suggested using "The Razor's Edge" as a bargaining chip, telling Murray to inform Columbia studios that the films were a packaged deal of sorts. If they wanted to make "Ghostbusters," they were going to have to make "The Razor's Edge," as well. Not wanting to lose out on "Ghostbusters" — I mean, it's "Ghostbusters!" — the studio agreed, and "A Razor's Edge" began shooting. 

The Trouble With Moving Between Dimensions

Because the two movies are so drastically different from each other (one is a devastating portrait of the aftereffects of war, while the other involves, well, slimy ghosts and a giant marshmallow man), it was hard for Murray to shift easily between the two mindsets required to make the films work. Columbia Pictures was eager to get started on "Ghostbusters," but Murray was exhausted from filming "The Razor's Edge" in India. He told Rolling Stone, "I wanted to take 10 days off. I was so tired that I couldn't even get out of the hotel room in Delhi for four or five days. I didn't really do anything except sleep," but Columbia was adamant that he return as soon as possible to start bustin' ghosts and gettin' slimed.  

When Murray eventually made it onto the set of "Ghostbusters," he found himself disoriented by the stark contrast between India where much of "A Razor's Edge" was filmed and Hollywood. He said, "I kept thinking to myself, '10 days ago I was up there working with the high lamas in a gompa, and here I am removing ghosts from drugstores and painting slime on my body.'" Ironically, the major differences between India and America's Hollywood caused Murray to have his own "Razor's Edge" inspired internal conflict. "It was kind of tough to get into it for about a month." he said, questioning why he was even there on the set of "Ghostbusters" in the first place. 

Eventually, Murray readjusted to the Hollywood way of things and was able to go on to shoot the rest of "Ghostbusters" without issue. Well, perhaps for Murray himself, but for Dr. Peter Venkman and the rest of the crew? It was going to take a lot of focus and proton pack energy to get Zuul back where the god rightfully belonged.

Read this next: The 14 Best Bill Murray Movies Ranked

The post Bill Murray Had an Ulterior Motive For Taking His Ghostbusters Role appeared first on /Film.

22 Mar 23:47

Not Everyone Was Embarrassed To Have Their Films On Mystery Science Theater 3000

by Anya Stanley

For most filmmakers, a film is a labor of love; the product of countless hours of manpower, painstaking attention to detail, and thorough teamwork. As such, a director might be precious about their work. When it's mocked or the analysis seems especially off, said director might take to social media and get into spats with critics. It's happened on occasion. Some directors, however, are built differently.

"Mystery Science Theater 3000" is a show that critiques with love, and always has since its first episode aired on KTMA-TV in Minneapolis, in November of 1988. The show has undergone several iterations and hopped several channels over its 218 episode run, but the structure follows a host (first played by series creator and showrunner Joel Hodgson, then others) trapped by a pair of mad scientists called "The Mads" on an orbital vessel, Satellite of Love. There, he is compelled to watch B-movies (in most cases, the B is for Brutally Bad) while they note his reaction to each one. To keep his sanity, Joel fashions together some robots for company: Tom Servo, Crow T. Robot, and Gypsy. Together, the group watches the movies and riffs on them to hilarious effect. Past episodes have featured the likes of "Sharknado" and "Manos: The Hands of Fate," and not all of these films' creators appreciated the feature-length roasting.

In Wired's oral history of the series, Hodgson, host Mike Nelson, and assorted cast and crew reminisce about the early days of the show in the '90s, when the show received steady fan mail that contained praise and condemnation alike. Nelson explained:

"Sometimes we'd open them up and say, 'Oh, mine's a "Why the hell are you guys talking over my movie?'" letter.' It was really exciting to get one of those. Most of the time we heard that sort of complaint secondhand, because nobody's going to call you up and say, 'How dare you make fun of my really, really crappy movie that everyone acknowledges is crappy?' But privately you would hear, 'Oh, I worked with this director, and I brought up MST3K, and he started yelling'"

But again, some directors are built differently. One of the funniest MST3K episodes was the product of a director sending their film directly to Hodgson. A 1988 creature feature that's totally not a "Gremlins" and "Critters" nick but is definitely a "Gremlins" and "Critters" nick: Rick Sloane's "Hobgoblins."

'I Knew Then That We Were In Trouble.'

"Hobgoblins" is a through and through low-budget indie, for better and for worse. The story has a lot going on, but its central gimmick is a horde of magical furry hobgoblins (aliens who crash-landed on a Hollywood studio lot and then escaped) who can make their victims hallucinate their wildest fantasies before the mythical creatures kill them. This leads to a sort of "Trouble With Tribbles" situation, with the little scamps running any which-a-way and slaughtering citizens at will. Writer-director Rick Sloane not only loved his work, he loved it so much that he found a way to make sure it stays in the public eye for way longer than the box office would have allowed: He sent his movies to the MST3K production company Best Brains for one of their televised evaluations.

Sloane elaborates:

"I actually submitted three movies to them. I really avoided giving them 'Hobgoblins,' because I had a bad feeling that they were going to grab that one. But I know 'Hobgoblins' is bad. I mean, I was there when we made it. On the very first day of photography, when the script called for a puppet fight, we threw a puppet on one of the actors. But the puppets couldn't do anything, so the actors were pulling them on and off themselves. I knew then that we were in trouble.

"Eventually, I submitted the film to them, and they had it 12 hours before calling me and saying they wanted the movie. The night the MST3K episode aired, I phoned all my friends and told them to watch. But if I had seen it first, I wouldn't have told anybody when it was on [Laughs]. They improved that movie — they made it watchable. But I've never been fond of the fake interview they did with me over the end credits. They drag down a cardboard cutout and say, 'Let's do an interview with director Rick Sloane,' and ask, 'Is it true you have rat droppings for brains?'"

A Good Sport

Sloane loved the episode, which aired on Jun 27, 1998, during the show's stint at the Sci-Fi Channel (now SyFy). In fact, he enjoyed the ribbing so much that when he developed the 2009 sequel "Hobgoblins 2," Sloane penned music for the film based on a goofy ditty sung by Mike Nelson and the bots, from the same episode. This writer is paraphrasing, but the central theme of the lyrics states that "Hobgoblins everywhere!"

In recent news, "Mystery Science Theater 3000," long departed from cable tv, was revived and predictably canceled by Netflix in quick succession, but found a second life via crowdfunding. The show just entered its 13th season on the Gizmoplex, a streaming service crafted just for the show and all things MST3K. The season premiered on March 4th exclusively for backers following a robust Kickstarter campaign, but the rest of us will have to wait until May 6, 2022 to get our fix from the peanut gallery.

Read this next: The 15 Best '80s Comedies Ranked

The post Not Everyone Was Embarrassed to Have Their Films On Mystery Science Theater 3000 appeared first on /Film.

22 Mar 23:46

How Nosferatu Rewrote The Rules Of Vampires

by Witney Seibold

It's generally accepted that a vampire can only die under several specific circumstances: direct sunlight, a wooden stake through the heart, a bath in holy water, etc. The means of bloodsucker dispatch do sometimes require the procedure to be more elaborate, such as in "Tales from the Crypt Presents: Bordello of Blood," where the vampire queen Lilith (Angie Everhart) needed her heart removed from her body and then sliced into four equal pieces. But the movies have taught us a few near-universal rules for making the undead dead. No fifth-grader with a passing knowledge of film history will be unprepared for vampire battle. 

While stories of demon-like creatures that drink blood and/or are immortal can be traced back to the most ancient civilizations, the modern folkloric version of the vampire -- the night-dwelling, blood-drinking, unkillable, fanged creature -- didn't begin until the early-to-mid 18th century in southeastern Europe, and were connected with paranoia about demons infiltrating small towns for malevolent purposes. Like in the Salem Witch Trials (1692 - '93), some communities in New England even undertook arcane rituals to rid themselves of what they believed to be vampiric interlopers in their communities. 

But when it comes to modern vampires, the true moment of codification came with the release of F.W. Murnau's horror classic "Nosferatu" in 1922. It is from this film that several pieces of popularly-repeated vampire details originated. 

F.W. Murnau Vs. The Bram Stoker Estate

Prana Film, the German studio that made "Nosferatu," was founded in 1921 by Enrico Dieckmann and an artist named Albin Grau, who had a taste for the occult. The idea of Prana Film was to house a long series of occult and supernatural feature films, but the studio folded quickly after making just one. According to the 1993 biography by Christiane Mückenberger, Grau claimed that he was inspired to make a vampire film after hearing a "true" vampire story from a Serbian farmer while Grau was serving as a soldier during World War I. Grau and Dieckmann, who infamously had not secured the film rights to the popular 1897 novel "Dracula" by Bram Stoker, put their Dracula movie "Nosferatu" into production in 1921, with F.W. Murnau directing, and shooting locations secured in Slovakia

Because it was clearly an adaptation of Stoker's works, and because Prana didn't have legal permission to make the film, Stoker's widow successfully sued the company and all copies of "Nosferatu" were ordered destroyed. Luckily for film historians, copies of the film did survive, and "Nosferatu" is available to this day.

"Nosferatu" screenwriter Henrik Galeen apparently didn't actually read Stoker's novel, so while the story remains the same, many of the details differ. The names have all changed, for one, with Count Dracula becoming Count Orlok, and so on. In the novel, Dracula is a short old man with a mustache who becomes temporarily younger after drinking the blood of his victims. In "Nosferatu," Orlok (played by Max Schreck) is a lanky, rat-like creature whose terrifying countenance embodies pestilence and death. Indeed, the design of Count Orlok has led to claims of antisemitism on the part of the filmmakers; Orlok's nose and claws were popular in negative Jewish caricatures at the time, and the character's "invasion of Germany" narrative mirrors similar fears expressed in antisemitic pamphlets of the early 1920s. 

The rules of vampires were also laid down: In "Nosferatu," the vampire must travel with coffins full of earth, presumably, as one intertitle explains, the soil that a vampire was initially buried under. A more notable deviation from Stoker was the conceit that a vampire can only operate at night -- Stoker's Dracula was free to come and go at all hours. It was actually "Nosferatu" that popularized the notion that vampires have an aversion to sunlight. 

F.W. Murnau's Sunrise

The finale of "Nosferatu" involves Orlok sneaking into the bedchamber of Ellen Hutter (Greta Schröder) at her invitation. Ellen had read from a book that a vampire can be defeated if a pure-hearted woman can distract it with her innocence and beauty. Orlok intended to drink Ellen's blood and get out, but was so moved by her good looks, that he stayed by her bedside all night. At sunrise, when the day's first light came in through the open window, the vampire was disintegrated. 

The concept in "Nosferatu" was of a moral bent. It wasn't necessarily ultraviolet solar radiation that seared through the vampire's flesh, but innocence and purity tearing through diseased evil. A vampire is traditionally an unholy monster, one that shies away from crosses and other holy symbols. This stems from the above-mentioned lore that a vampire is a kind of a demon. In "Nosferatu," the vampire is more or less the embodiment of pestilence, the horseman of the apocalypse. Orlok spreads disease wherever he goes, and is made to look like plague vermin. The only way to combat such a creature is with purity so strong that it can erase death. Orlok, then, was not killed by sunlight, but by the combined holy power of an innocent woman and the Easter-like Christian-resurrection life symbol of the rising sun. Is the "innocent woman" imagery condescending and sexist? Yes. Is the ending to the film kind of corny? Yes. Does it work as a corking piece of horror cinema? You bet. The last look on Count Orlok's face when he realizes he has been duped is an "oh s***" moment for the ages. 

Whatever the symbolism, the literal image of a vampire being evaporated by sunlight lodged itself into the popular consciousness, and after 1922, it became widely accepted that sunlight kills vampires. 

Holy Water Super Soakers And Sun Lamps

This notion of a vampire's allergy to sunlight -- like a lot of vampire lore introduced in the movies -- became very literal very quickly. An unholy, violent, life-taking creature will, moving forward, not be undone by the concepts of holiness, calm, and innocence, but by the actual mechanical qualities of holy water in squirt guns, crosses made by any two planks of wood, and ultraviolet sunlamps. Fighting vampires soon became a military matter, requiring only the correct weapons and the bravery to wield them. Actual religious belief, innocence, and piety were shed as concerns so long as you had a Catholic priest and a Super Soaker. 

Nine years later, director Tod Browning would make his own version of "Dracula," this time with rights from the Stoker estate secured. It solidified another version of what Dracula (and many other vampires) would look and sound like for generations: the elegant, yet masculine, sexy foreign aristocrat decked out in a tuxedo and cape. Moving forward, vampires were either monstrous, disease-spreading rodents a la "Nosferatu," or handsome Eastern European men like Bela Lugosi. Throughout them all, vampires would be undone by sunlight, requiring their vitamin D supply from the blood they drink. 

The most notable vampire unaffected by sunlight is Edward Cullen from Stephenie Meyer's "Twilight" book series. In the lore of the "Twilight" novels, vampires stay out of the sun, but only because direct sunlight causes their skin to sparkle like diamonds, making them too beautiful to live. Points to Meyer for effectively reworking a trope begun in 1922. 

Read this next: The 95 Best Horror Movies Ever

The post How Nosferatu Rewrote the Rules of Vampires appeared first on /Film.

22 Mar 23:45

How Mork & Mindy Inspired One Of Robin Williams' Darkest Roles

by Danielle Ryan

Robin Williams was many things to many people: he was a stand-up comedian, a family-favorite comedy actor, a serious thespian who tore into the depths of human depravity, and so much more. Williams' career really kicked off with "Mork & Mindy," a spin-off of the highly successful series "Happy Days." He starred as the alien Mork from the planet Ork, and was joined in his weekly misadventures by his roommate and friend, Mindy (Pam Dawber). The series ran for four seasons before being unceremoniously canceled in 1982. 

Williams would go on to have an incredibly successful career in acting, but that moment of having your television show canceled out from under you always stuck with him. In an interview with Edward Norton discussing their 2002 dark comedy "Death to Smoochy," the late comedian revealed that "Mork & Mindy" and its cancellation had a profound influence on how he played his character, fallen kids' show host Rainbow Randolph. 

The Terrifying Truth Of Children's Television

If you've never seen or heard of "Death to Smoochy," it is a vastly underrated cult comedy about a greasy slimeball of a children's TV show host (Williams) who gets replaced by a squeaky-clean doofus in a rhino costume (Norton). Catherine Keener stars as the network executive who works with (and falls for) them both, and Danny DeVito's direction is about as pitch-perfect as can be for this twisted little gem. Norton's character is a pure, sweet goofball (inspired by Jimmy Stewart in "Mr. Smith Goes to Washington"), while Williams gets to be truly horrible. For fans who had grown up watching the actor on "Mork & Mindy," the voice of the Genie in "Aladdin," or even as the cross-dressing "Mrs. Doubtfire," the vulgarity, cruelty, and pure villainy of Rainbow Randolph was pretty shocking. 

In his interview with Norton, Williams explained that he was working pretty heavily in children's and family television early in his career, and he didn't even get told "Mork & Mindy" was canceled, instead reading about it while working on another children's production:

"They didn't call. I was doing this thing, 'The Tale of the Frog Prince', with Eric Idle, and bingo! The trades basically said, "Mork & Mindy cancelled." I was so angry and hurt, and I was dressed as a frog. [both laugh] It hit me hard. So I have experienced that, I have lived that part."

While Williams didn't try to kidnap the stars of whatever show replaced his, the cancelation did give him some insight into the mind of Randolph. As he said in the same interview, "Well, having done television and having known the other side of the business — the backstabbing — it's full of sociopaths, who try to kill their rivals, like Randolph."

His unhinged performance is one of his most magnetic, balancing mania with a surprising touch of heart. We don't just laugh at and hate Randolph, we also feel sorry for him. Williams' experiences helped give weight to those moments and cemented Randolph as a truly complex and fascinating figure and not just another pop-culture parody. 

If you have a library card, you can rent "Death to Smoochy" on Hoopla, and you should, because this cinematic classic deserves way more love. 

Read this next: The 20 Best Heist Movies Of All Time

The post How Mork & Mindy Inspired One of Robin Williams' Darkest Roles appeared first on /Film.