In the past, serious PC gaming was solely under the desktop computer domain. But when the pandemic hit, bringing with it the corresponding disruption to the global supply chain, chip shortages, and enforced work from home, the computer gaming industry experienced a shift in demand.
Ronald.phillips
Shared posts
7 Reasons Why Laptop Gaming Is Taking Over From Desktop Gaming
Covid-19 Infection Can Reactivate the Latent Retroviruses In Human DNA
Read more of this story at Slashdot.
Major Linux PolicyKit Security Vulnerability Uncovered: Pwnkit
Read more of this story at Slashdot.
Doom works in DOS!
> Except it doesn't play MIDI music as SBA/HDA doesn't have HW wawetable...
But, I've played MIDI tunes with IDH, for example with the Russian DSS player for DOS or Open Cubic player for DOS. These play from the original 8 MB GUS wavetable / soundfont patches which are read into RAM and a Wavetable audio card is simulated using those 127 .WAV samples (instrument patches).
ZDoom doesn't offer this capability.
12-Year-Old Polkit Flaw Lets Unprivileged Linux Users Gain Root Access
Half-Life 2 Overcharged is coming to Steam in February 2022
Modders ‘BriJee’ and ‘Mike Nov’ announced that Half-Life 2 Overcharged will release on Steam in February 2022. In order to celebrate this announcement, the modders released a new gameplay trailer that you can find below. Half-Life 2 Overcharged is a mod that aims to fix, improve and enhance numerous features and gameplay elements of Valve’s … Continue reading Half-Life 2 Overcharged is coming to Steam in February 2022 →
The post Half-Life 2 Overcharged is coming to Steam in February 2022 appeared first on DSOGaming.
Tonga Shock Wave Created Tsunamis In Two Different Oceans
Read more of this story at Slashdot.
First responder experiences health issues after members of the Army of the 12 Monkeys truck crash five days ago. I was hoping for giant meteor, but this will work [Followup]
Polkit Vulnerability Provides Root Privileges on Linux Systems
Qualys security researchers warn of an easily exploitable privilege escalation vulnerability in polkit’s pkexec, a SUID-root program found in all Linux distributions.
Initial Access Broker Involved in Log4Shell Attacks Against VMware Horizon Servers
This Jackass Stunt Was So Expensive, They Had To Scrap It

Watching the trailer for "Jackass Forever," you'd think that this band of merry stuntpeople had infinitely loose purse strings in order to enable the rowdy madness that director Jeff Tremaine teases for the upcoming reality-based comedy film: there are exploding toilets, ball taps from heavyweights, and, of course, someone gets shot out of a cannon in their underwear. Danger is the business of these hooligans, and business is booming.
The troupe — who, in "Forever," are comprised of creator Johnny Knoxville, Steve-O, Wee Man, Chris Pontius, Dave England, "Danger" Ehren, Preston Lacy, Sean "Poopies" McInerney, Jasper Dolphin, Zach Holmes, Rachel Wolfson, Eric Manaka, and Compston "Darkshark" Wilson, plus celebrity guests — have come a long way from the early days at '90s skateboard culture magazine Big Brother, where the high-liability rumblings began with Knoxville offering to do nutso stunts like testing tasers on himself. A zeitgeist TV series, countless spin-off shows, five movies, and a video game later, and the "Jackass" franchise has secured a hard-earned but beloved spot in the pop culture consciousness.
In a GQ interview from May of 2021, Knoxville revealed that along the way to fame and bone-busting notoriety, some stunts were so risky that they had trouble getting them insured, and were thusly left in the drafts while less expensive stunts came to fruition on the big screen. The "Jackass" crew's first feature effort in 2002, aptly titled "Jackass: The Movie" operated on a modest budget of $5 million. It contained the expected slapstick and mayhem: Steve-O snorted lines of wasabi sauce, while Pontius took an open-paw slap to the face from a mountain lion. But one planned humiliation never made it to audiences. According to Knoxville, Pasadena native Chris Pontius was supposed to take part in the rural religious rite of snake handling, by strolling into a Pentecostal church and greeting death like an old friend. Johnny tells GQ:
We wanted some silly bit. I think it was, like, Pontius was going to dress like the devil and handle snakes in one of the Pentecostal churches. And it was going to be, like, $5 million to insure. We're like, 'Okay, we're not doing that bit!' You hear that we're going to be number one, and it's just ridiculous. What a ridiculous feeling. What a silly film to be number one.
Do Not Try This At Home, Dummy
Pontius is no stranger to reptiles or boneheaded decisions: as longtime "Jackass" character Bunny the Lifeguard (he has many, to include the gyrating Party Boy and Pontius the Barbarian), the "Wildboyz" co-host has previously tussled with alligators, and even had the tip of his penis bitten by a snake. Nothing is ever really off the table for the Jackass crew until the budget has a say, it seems.
In the same piece, Steve-O says that he raised concerns about his friend Knoxville going up against a bull (again) for the new installment, but failed to persuade the daredevil to do anything but move forward full speed ahead. The result: a broken rib, a broken wrist, a concussion, a brain hemorrhage, and — most important to Knoxville — some great footage for "Jackass Forever." It's the same entertainer's drive that brought forth some of the most bonkers stunts the millennial generation had ever seen, from Johnny's short bout with the 350-plus pound fighter Butterbean (which ended in a brutal concussion for exactly who you'd expect) to Steve-O's excruciatingly metal "Off Road Tattoo." No bar is too low for the rambunctious boys of the Jackass crew, but sometimes a budget can be.
"Jackass Forever" arrives in theaters on February 4, 2022.
Read this next: The 15 Best Kaiju Films Ranked
The post This Jackass Stunt Was So Expensive, They Had to Scrap it appeared first on /Film.
I'm Starting To Think The Ozark Writers Hate Ruth Langmore

Okay, I'll bite: did Julia Garner run over an "Ozark" writer's dog, or what? There must be a reasonable explanation for this because Ruth Langmore (Garner) is one of this show's most tortured characters and it's starting to feel downright mean. Obviously, bad things are bound to happen on a show like "Ozark" — most of the characters are involved with mobs and violent drug cartels. The context clues speak for themselves — this is a sad show where sad things happen! You can tell because the lighting is dim and the series is tinted blue! But sometimes it feels like Ruth endures like 95% of this shows sadness and it really hurts.
Fans of the series know one thing for sure: "Ozark" is headed nowhere good. This show is destined for a tragic ending and Season 4 Part 1 goes out of its way to prove that. Half the characters spend the season fantasizing about what comes next and Part 2 being just around the corner means everything will probably go wrong. But deep down, I always believed that at the end of this exceptionally bleak tunnel of sadness, we could rely on one teeny tiny source of light: Ruth Langmore. Our favorite foul-mouthed criminal might be tied to the disastrous Byrdes but she's clever, crafty, and bound to succeed eventually ... right?!
Spoilers for "Ozark" season 4 part 1.
Ruth's Final Chapter

For a quick glimpse at Ruth's uniquely devastating life, just take a look at her season 4 storyline. This is the first season where she's severed ties with the Byrdes and honestly gets her life back on track. She's still in the drug business of course, but on her own terms. There's no cartel lawyers torturing her via waterboarding, no mafia guys roughing her up, no family member emotionally berating her and no one around to constantly threaten her life ... mostly. She's mourning the death of her boyfriend, Ben Davis (Tom Pelphrey) which is pretty agonizing, but all things considered, Ruth has it pretty easy for most of the season. As in, easy by "Ozark" standards.
Like everyone else, Ruth spends the final season fantasizing about her future. At first, she aims for a fresh start by buying the "Lazy-O." Taking over the motel she was fired from back in season 1 is mostly a ruse to launder money through a legitimate, cash-friendly business, but she also gives an impassioned speech that might have some truth to it: "I want to own a piece of this town. When city people come on vacation, I want to be the face they see. My place representing." She's mostly trying to calm the nerves of the former owner, but her words have weight behind them — Ruth wants something of her very own.
But when going into the heroin business with Darlene Snell (Lisa Emery) inevitably falls apart, plans change. Throughout the season, Ruth slowly comes to the realization that doubling down on her corner of "s***hole America" might not be best. So why not leave? At first, it's because she simply doesn't have the money. She used it up buying the "Lazy-O" and has little leftover. Sadly, it's not the first time she's been ready to leave but too broke to follow through. She tells Marty, "God's a motherf***er, isn't he? Built me smart enough to know how f***ed up my life is, but not quite smart enough to haul my ass out of it." As he so often does, Marty offers to help. The results are mixed: Marty only offered for his own benefit but ultimately things work out after Ruth puts herself in peril, gets slapped by a lunatic drug lord, and fights her way out of the bad situation.
But Wait — It Gets Worse

Even when Ruth has the money to leave, the obstacles are never-ending. She can't abandon what remains of her family: Wyatt (Charlie Tahan) and Three (Carson Holmes). Three would be easy enough to convince — the only thing tying her teenage cousin to the Ozarks is his family and a high school girlfriend. But Wyatt has settled down with Darlene and her foster child, Zeke. Lucky for her, this problem seems to solve itself when Darlene freaks Wyatt out by murdering the head of the KC Mob. Wyatt isn't emotionally built for burying this many bodies so he makes plans to run with Ruth and Three ... then he goes back on it.
Wyatt doubles so far back that he instead resolves to marry Darlene, so they can raise Zeke together. Tearfully, Ruth begs him to leave Darlene but when she sees she won't win, lets him decide for himself. Then things go from worse to absolutely unbearable. Wyatt, who Ruth has often lamented is the only person left that she loves, is murdered. He's collateral damage because Javi (Alfonso Herrera) wants Darlene dead and Wyatt happens to be present when he arrives. Ruth finds their bodies.
It's not often that you see a character's plight and think to yourself wow, this might be worse than the time she got waterboarded but here we are. This is the nail in the coffin of Ruth's happiness. She's officially lost the only thing she had left. (I mean ... there's still Three, but "Ozark" sometimes forgets he exists, and anyway, her relationship with Wyatt was her most important.) So now Ruth is out for revenge and hunting down Javi puts her on a collision course with death.
And listen up, "Ozark" writers, I think I get it! Julia Garner is a masterful performer! She earned two consecutive Emmys for this performance and it's probably because when she cries or delivers tragic monologues, our hearts shatter! But why can't she win an Emmy for being happy?! Maybe there's still a way for Part 2 to forget all this bad stuff and send Ruth on a five-star cruise far far away from the sadness. And just think — putting Ruth on another boat means ample opportunity to kick another grown man in the balls and haul him over the edge. This time without deadly consequences! Whatever it takes for Julia Garner to not sob her way through the final seven episodes, please.
Read this next: Shows Like Breaking Bad That You Can Binge Watch Today
The post I'm Starting To Think The Ozark Writers Hate Ruth Langmore appeared first on /Film.
Microsoft's Product Chief Sees PC Revival as Durable
Read more of this story at Slashdot.
Is Jackass Forever The Final Movie? Here's What Knoxville Thinks

Like Mike Myers, Jason Vorhees, Freddy Krueger, or really any horror hunk rising up back from the dead, Johnny Knoxville isn't quite ready to let the "Jackass" franchise die. The MTV show turned film series that also birthed a million other MTV shows (and, unsurprisingly, a video game), will break its 12-year hiatus (if you don't count "Jackass: Bad Grandpa," and I don't) when the latest movie in the franchise debuts in February 2022. Although the title "Jackass Forever" paradoxically sounds like a goodbye, Knoxville has no interest in closing that door. When he says "Jackass Forever," he sure as hell means it.
In an interview with Variety about the upcoming fourth film in the franchise, Knoxville cut right to the chase, saying, "Someone wrote it was the last one, but we never said it was the last one..."
And by someone, I can only imagine he's talking about himself. In an interview with GQ in May 2021, Knoxville confirmed that the fourth "Jackass" would be his, "last contribution to the franchise." And while that statement is vague enough that he could say both things and still be correct, there could technically be a fifth "Jackass" without Knoxville, it's hard to imagine the franchise without him. Is "Jackass" still "Jackass" without Johnny? Or does it become "Jackass"-adjacent like "Wildboyz" or "Viva La Bam"? To ponder this is to peer into the very heart of the franchise, all while knowing that one day, we will, sadly, get the answer.
Jackass 5ever
Regardless, I think the truth of the matter lies in a quote from his fellow "Jackass" stuntman Steve-O in the same GQ interview: "Every movie that we ever made was the f***ing last one. And not just the last one, but declared as the last one."
Knoxville's further statements to Variety seem to back that up, even if he's not quite as candid:
"I mean, it could go on ... we could do another one if we wanted ... I don't know if we want to, but we could let the old guys come in and have fun, but put it more on the young cast. I don't know. After [the first two films], we're like 'Never.' And then there we made a third one and now we make a fourth one. So, we're never saying never."
There are a lot of ways you can view Knxoville's back and forth. Maybe the lead-up to the film's release has reinvigorated him. Maybe he just needed some time after his injuries from the fourth movie before he could start considering a "Jackass" film. Or maybe he'll never be able to really say no. Maybe Johnny Knoxville will be playing this game with us for another 10, 20, or 30 years. If so, that's fine. He's earned the right to dangle it over our heads. Who else would put themselves through that many concussions for us?
(Besides, I guess, every football player, but this isn't a sporty website. You know where you are.)
Read this next: Top 15 Best Natural Disaster Movies
The post Is Jackass Forever the Final Movie? Here's What Knoxville Thinks appeared first on /Film.
I Wanna Be the Guy
You might think that the best time to examine a trendsetting video game would be at the height of its relevance and popularity, but sometimes it’s just as interesting to look at works whose moment has, for the most part, passed. I Wanna Be the Guy may be known today mainly for the legions of fangames – of wildly varying quality – that it spawned, the Retsupurae memes regarding how clichéd it became as a subject of Let’s Plays, and for potentially popularizing the kind of trial-and-error – or more accurately, trial-and-death – gameplay that has impressed and infuriated players in equal measure (well, possibly just a tad more infuriated) for the last few decades. But behind all of the jokes, the rage-filled videos of people falling for the game’s traps, and its memetic status as the intentionally unfairly difficult video game, it could be argued that I Wanna Be the Guy is legitimately one of the most influential games of the 21st Century.
For freeware games, it brought attention and legitimacy to an entire subset of work that had previously been written off as unprofessional, or not worth the same level of recognition as ‘official’ games. For mainstream games, it was a sadistic love letter to older consoles and franchises that a generation of programmers had been brought up on. And for indie games, I Wanna Be the Guy was one of the first titles to implement a challenge that was based not on conventional difficulty, but by predicting which paths a player would take, which patterns they would recognize, and how they would react to spur-of-the-moment threats, all so that they could be manipulated into losing in the most unexpectedly comedic fashion again, and again, and again.
Released for free in October 2007 by Michael “Kayin” O’Reilly, the hardest part of describing I Wanna Be the Guy– or to say its name in full, I Wanna Be the Guy: The Movie: The Game – is not just cribbing entirely from Kayin’s own webpage, which accurately describes it as “a sardonic loveletter to the halcyon days of early American videogaming, packaged as a nail-rippingly difficult platform adventure”. While the game has many recognizable influences from the most notoriously-hard old-school titles of the time, the one particular game that inspired Kayin the most was a Japanese Flash game titled “Jinsei Owata no Daibouken”, which translates to English as “The Big Adventure of Owata’s Life”. Much like I Wanna Be the Guy, this game was a combination of overtly difficult platforming and unexpected traps that would be impossible to dodge without prior knowledge, but Kayin believed that this concept could be improved upon. Ironically, Jinsei Owata no Daibouken was unfinished when Kayin had first played it, and it wouldn’t be finished until I Wanna Be the Guy was already released, and as such, the final area of the Flash game that had motivated Kayin to create I Wanna Be the Guy ended up being a parody of I Wanna Be the Guy itself, the very game it had inspired.
A good way to outline the kind of challenge you will be facing in I Wanna Be the Guy is to simply describe the first trap you are likely to encounter. When taking the upper path, The Kid walks under some trees bearing delicious fruit, and when you step underneath a fruit, it plummets down at faster speeds that you can probably react to and kills you in one hit. Having learned your lesson, you reload your save and try again, this time making your way carefully through the deluge of falling fruit by tentatively getting close enough to trigger them to fall and then safely retreating. Not all of the apples fall, which makes it harder to judge when you need to move, but it’s not the most challenging task in the world. Satisfied to have beaten the first obstacle in your path, you double-jump up to the higher platform that is clearly the way forwards. The apple beneath the platform falls up and kills you.
… The apple falls up, and kills you. Well, they’re more like giant cherries.
This is frustrating, unfair, a little bit funny, and genuinely excellent game design. I Wanna Be the Guy takes advantage of common video game tropes, or any patterns you might pick up from recurring traps, and then subverts them in order to kill you again. To some, this understandably feels like trolling, but it can also feel like a joke that the creator is sharing with you; taking famous, established concepts from familiar video game series, such as not being able to die in a cutscene before a boss fight, not placing an initially unavoidable trap at the end of a particularly challenging section, or not being hurt by items that are clearly part of the background, and turning all of these ideas on their head to highlight how comically unfair it would be if these rules no longer applied.
Not every trap you encounter will be this manipulative or intelligent, but behind every single one of them was the accurate prediction that you would likely be caught off-guard, and more often than not, Kayin was correct. It would certainly be a stretch to say for sure that this kind of predictive design was unique to the game, or that it was the sole inspiration for other indie games that put similar tricks to good use, but this also isn’t that far away from the fourth wall breaking tricks seen in Pony Island or Undertale, or introducing you to a trap by first having it kill you, as seen many times in the Dark Souls series.
What helps I Wanna Be the Guy to remain playable in defiance of this mockingly unfair difficulty, is the frequency of save points. The game has four difficulty settings; Hard, the default which provides save points roughly every two rooms, Very Hard, which reduces them considerably, Medium, which provides several more but labels them ‘WUSS’ and adds a pretty pink bow to The Kid’s sprites (Kayin has stated that while there was no ill intent, they regret the implications of this decision), and Impossible, which removes every single save point in the game. Kayin’s initial reaction to someone beating the game on Impossible difficulty – that is, a completely deathless run through the entire game – was understandably “holy crap your [sic] not serious are you”.
The inclusion of save points and the omission of any kind of lives system are why I Wanna Be the Guy remains so fun to play. Compared to many of the games it parodies – Castlevania,Mega Man,Ghosts ‘n Goblins – I Wanna Be the Guy is undeniably much easier and more forgiving than the titles it pays homage to. Once you’ve learned where all of the traps are – presumably by falling for them – then the timing and reflexes required to survive are no more difficult than the majority of other games. The most difficult parts of the game by far are the sections where traps take a back seat to more traditionally challenging platforming gameplay, which Kayin also excelled at designing.
Once you’ve gotten past the difficulty, Kayin’s creativity truly begins to shine.The game plays like a tribute borne out of sincere appreciation and nostalgia for the NES/SNES era of video games, and while the majority of the gameplay is fairly standard platforming with a double-jump, there are standout moments in the game where you’re traversing through the first screen of The Legend of Zelda, using Link as a platform while trying not to get stabbed by him, hopping into the Vic Viper from Gradius for a brief unexpected shoot ‘em-up section, or my personal favourite, falling into a game of Tetris and having to survive amongst the falling blocks whilst making your way to the top quickly enough to escape before you run out of time, and are promptly crushed by a giant Dr. Mario pill. It’s brilliant.
The creativity continues into the boss fights, featuring encounters with Mother Brain from Metroid, a kaiju-sized Mike Tyson from Punch-Out, and Dracula as he appeared in Castlevania: Symphony of the Night, complete with the opening speech redubbed in the Kid’s squeaky high-pitched voice, and the wine glass that Dracula contemptuously tosses aside actually killing you unless you move out of the way.It’s clear that Kayin has a lot of love for retro video games, and it shows. Despite the bosses, enemies and source material frequently being made the subject of mockery – upon defeat, Dracula screams “Behold my true form, and despair!” and anti-climactically turns into a Waddle Doo from Kirby, which is killed in one hit – it’s never as crude as you might expect from a mid-2000s freeware game.
The soundtrack for the game mainly consists of recognizable tunes from Mega Man, Metroid, Mario, Castlevania, Zelda and the like, but Kayin also threw in a few curveballs. The boss fight against a giant robotic Birdo from Super Mario Bros 2 is backed by one of the boss themes from Ikaruga of all places, the Castle of the Guy uses the work of legendary composer Rob Hubbard, in particular the theme to the Commodore 64 game Monty on the Run, and if you look up the soundtrack to Guilty Gear Isuka, most of the comments will be about I Wanna Be the Guy, as it’s where the game’s menu theme and the background music of the first area come from, as well as the memorable eight-second guitar riff that plays every time you die. Ironically, this memetically-frustrating music is actually a victory theme from the game it comes from.
It’s hard to gauge the reception to I Wanna Be the Guy with no sales figures or review scores, but its influence was clearly felt far and wide. The Kid appears as an unlockable character in the similarly hard-as-nails indie platformer Super Meat Boy, and the homebrew NES game Battle Kid: Fortress of Peril and its sequel – both excellent in their own right, and even more difficult – were directly inspired by the title. Kayin released two other titles in the series; I Wanna Save the Kids, a Lemmings-esque game based on guiding several defenseless ‘the kids’ safely home, and I Wanna Be the Guy: Gaiden, an official three-level sequel that gives The Kid a grappling hook à la Bionic Commando.
This just barely scratches the surface of I Wanna Be the Guy follow-ups though; there are thousands of fangames made by developers who wanted to put their own spin on the formula, or pay tribute to the games that were most nostalgic to them. I Wanna Be the Boshy is a frequent feature at Games Done Quick events, I Wanna Be the Fangame was developed by ‘Tijitdamijit’, one of the first players to beat I Wanna Be the Guy on Impossible difficulty, I Wanna Run the Marathon was designed to be unveiled for the first time at a marathon that specifically only features I Wanna Be the Guy fangames, and this is just the tip of the iceberg. In other fangames, you can encounter boss battles against Phoenix Wright, Pac-Man, Missingno, Giygas from Earthbound, the Dopefish from Commander Keen, and even a gigantic John Madden who pelts you with footballs.
If you’re worried that you’ve missed the boat on trying the game, a Kayin-endorsed fan-remaster, I Wanna Be the Guy Remastered was released in December 2020, for free, just like the original. Remastered fixed the unintended crashes that the original sometimes suffered, as well as making a few quality-of-life improvements and even adding in a few extra traps to keep familiar players on their toes. As a result, if you’re curious about I Wanna Be the Guy, there has never been a better time to try it for yourself and see exactly how it irritated the hell out of so many players, and why so many of them kept playing. I Wanna Be the Guy doesn’t earn a recommendation for sheer novelty, or for landing its jokes well, but because it remains a uniquely entertaining experience whose influence on indie gaming is still felt to this day.
I Wanna Be the Guy was first posted on January 26, 2022 at 4:28 pm.
©2017 "Hardcore Gaming 101". Use of this feed is for personal non-commercial use only. If you are not reading this article in your feed reader, then the site is guilty of copyright infringement. Please contact me at kurt@hardcoregaming101.net
Have We All Been Using Mouthwash at the Wrong Time?

Based on an unscientific survey of my husband, largest WhatsApp chat, and everyone I work with, 100% of respondents use mouthwash after brushing. But common wisdom might have many people using mouthwash at the wrong time. And it’s a lot of people: According to Statista, nearly 200 million Americans used mouthwash in…
How to reduce your chance of dying from Covid by 99%? Get vaxxed and boosted

Author and physician Eric Topol made a chart using data from the CDC COVID-19 Response Epidemiology Task Force that shows how much more you are likely to die from Covd if you don't get vaccinated. @OurWorldinData redrew the chart to make it look prettier:
How to reduce your chance of dying from Covid by 99%?
Windows 11 is Getting Android Apps, Taskbar Improvements, and More Next Month
Read more of this story at Slashdot.
The Deleted Jackass: Number Two Scene That Featured Luke Wilson

You ever hear about the time the "Jackass" boys gently requested to zap Luke Wilson's balls?
It was a beautiful, balmy day in an undisclosed location -- the production team worried about fan interference and so kept details of their whereabouts under wraps during shooting. The reckless boys of the "Jackass" crew -- by now Johnny Knoxville, Bam Margera, Steve-O, Chris Pontius, Ryan Dunn, Dave England, Jason "Wee-Man" Acuña, Danger Ehren, and Preston Lacy -- were enjoying the fruits of success. The reality comedy series "Jackass" had only lasted three seasons in the early aughts, but gathered enough purchase in the pop culture conversation to launch an entire franchise based on the hasty stunts and gross-out hooliganism of a core group of madmen with a death wish. Following the commercial success of "Jackass: The Movie" in 2002, the fruit was ripe for plucking and a sequel was inevitable.
For "Jackass: Number Two," director and executive producer Jeff Tremaine had his crew shooting some incredible moments: Steve-O chugs beer through a tube inserted into his butthole; director John Waters makes Wee Man "disappear" with the wave of a magic wand and a friend; and some of the boys narrowly escape a bull goring whilst clinging for life onto rickety seesaws. There are often scenes and pranks that are left on the cutting room floor due to budget constraints or controversy, but one deleted scene from "Jackass: Number Two" has a special guest appearance from "Bottle Rocket" star Luke Wilson.
'Any Chance Of You Putting It On Your Balls?'
This bit of tomfoolery started with Knoxville, Pontius, and Jackass regular Loomis Fall, who launch the segment, "The Shock Phone." In it, a WWII-era field phone is rigged to deliver a nasty little electric current to whomever is foolish enough to allow its leads to be attached to them. First up is Loomis, who is shocked speechless after getting a jolt to his fingertips. Bam Margera follows, getting a zap to his toes and pleading to his friends, "Ohh, don't do it!" Not to be outdone and unable to turn down any dare ever, Steve-O reluctantly takes his voltage to the bare lips like a champ before the phone receiver is finally handed to Luke Wilson.
"Any chance of you putting it on the balls?" Knoxville asks. Wilson curtly declines, but offers his hand up to Johnny with a casual practicality. As the current courses its way through the Emmy award-winning actor's hands (with the leads clamped onto the webbing between his fingers, no less), his face registers a curious pain level not unlike the existential anguish he displays as the dispirited Richie in Wes Anderson's "The Royal Tenenbaums," no demoralizing Elliott Smith needle drop needed. Ultimately, though, it gave him the pick-me-up he needed that day. "Wow, I actually feel energized after that," he says. One can see why it was deleted: in order to be a worthy Jackass stunt, someone really should have put the leads on their own testicles. Even a taint placement would be acceptable, as it was with the muscle stimulant electrode party of "Jackass: The Movie." Ultimately, the scene was deleted from the film ahead of its September 2006 premiere, but the final product does have Wee Man lured into sitting on an electrified stool, so how mad can we really be?
Read this next: The 15 Best '90s Comedies Ranked
The post The Deleted Jackass: Number Two Scene That Featured Luke Wilson appeared first on /Film.
The Envoys: Season 1 – Review [Paramount+]
The post The Envoys: Season 1 – Review [Paramount+] appeared first on Heaven of Horror.
Sundance 2022 Review: EMILY THE CRIMINAL, Another Aubrey Plaza Showcase
Astronomers spy powerful deep-space object unlike anything seen before - CNET
The Siege Of Mandalore And The Night Of A Thousand Tears Explained

This article contains spoilers for the new episode of "The Book of Boba Fett."
"The Book of Boba Fett" took a welcome break from Boba's turf war on Tatooine this week to catch up with everyone's favorite space dad: Din Djarin. Appropriately titled "The Return of the Mandalorian," the episode set the stage for Din to join Boba in his battle with the Pyke Syndicate while touching upon a tragic event from Mandalore's past that was previously referenced but otherwise left unexplained on "The Mandalorian." In doing so, "The Book of Boba Fett" also answered a question that's been hanging in the air ever since Din took the Darksaber from Moff Gideon in the "Mandalorian" season 2 finale.
"Return of the Mandalorian" picked up with Din tracking down and killing a bounty with the aid of the Darksaber, only to injure himself with his own weapon like the lovable himbo he is. Upon his reunion with the surviving members of The Tribe (whom he located using the information he got after collecting on said bounty), the Armorer gave Din a crash-course in the history of the powerful lightsaber and its grim legacy. This is also where "The Book of Boba Fett" flashed back to the Galactic Empire's massacre of Mandalore's people on what would come to be known as the Night of a Thousand Tears.
The Great Purge Of Mandalore

Before we go any further, it's worth noting that "The Siege of Mandalore" can refer to one of two events, depending on the context. The first one, also known as the Battle of Mandalore, took place at the end of the Clone Wars and saw the Mandalorian resistance (led by Bo-Katan Kryze) team up with the Galactic Republic to retake control of Mandalore from Darth Maul and the Shadow Collective (as depicted in the final season of the animated "Clone Wars" TV show). However, when Moff Gideon mentioned the Siege of Mandalore to Din on "The Mandalorian," what he was really talking about was the Great Purge of Mandalore shown in "Return of the Mandalorian."
After the Battle of Mandalore and the fall of the Republic, the Galactic Empire took control of Mandalore through military force, removing Bo-Katan from power and once again robbing her of her birthright. Years later, as seen on the animated series "Star Wars Rebels," the Mandalorian warrior-turned-Rebel-fighter Sabine Wren would gift the Darksaber to Bo-Katan after recovering it (okay, stealing it) from Maul on Dathomir. This allowed Bo-Katan to unite the other Mandalorian clans in an effort to reclaim their home world from the Empire.
Of course, in a turn of tragic irony, this proved to be Bo-Katan's downfall. When the Empire realized it could no longer maintain control of Mandalore in the face of this newly-formed resistance, it resorted to obliterating the planet's most densely populated regions (including its capital city, Sundari) during the Night of a Thousand Tears, before later recovering as much of the world's remaining beskar as it could find. "Had our sect not been cloistered on the moon of Concordia, we would have not survived the Great Purge," the Armorer explains to Din while recounting these events.
The Curse Of The Darksaber

Because of all this, the members of The Tribe (and the Children of the Watch at large) see Bo-Katan as a cautionary tale of what will happen if a Mandalorian fails to honor the ancient creed dictating that ownership of the Darksaber can only be won through combat (with the Armorer going so far as to call it "a curse unto the nation," under those circumstances). This, in turn, explains why Bo-Katan refused to accept the Darksaber when Din offered it to her in the "Mandalorian" season 2 finale, much to the delight of the newly-defeated Moff Gideon (who, unsurprisingly, wasn't above indulging in a bit of schadenfreude).
Even so, this still begs the question: Why didn't any of this stuff about the Darksaber come up back when Sabine gifted the weapon to Bo-Katan (who barely paused before accepting it)? The in-universe explanation might be that Bo-Katan and the others either didn't really know all that much about the Darksaber's history or simply didn't take the prophesied curse from the Darksaber's ancient creed seriously. (And why should they have?) In terms of the real world, though, it's probably safe to assume "The Book of Boba Fett" and "The Mandalorian" executive producer Dave Filoni merely hadn't planned things out quite that far ahead back when he was the supervising director on "Rebels." Either way, you can consider this plot thread airtight once again. (No doubt, Ben Wyatt would approve.)
New episodes of "The Book of Boba Fett" premiere Wednesdays on Disney+.
Read this next: The 10 Most Essential Episodes Of 'Star Wars Rebels'
The post The Siege of Mandalore and the Night of a Thousand Tears Explained appeared first on /Film.
Here's All The Concept Art From The Book Of Boba Fett Episode 5

The following article contains spoilers for the latest episode of "The Book of Boba Fett." You have been warned!
Well, there's no sense beating around the bush. How'd everyone enjoy the season 3 premiere of "The Mandalorian"? All joking aside, the concluding moments of last week's episode of "The Book of Boba Fett" certainly set up the (re)appearance of Pedro Pascal's Din Djarin ... but I'm not sure anyone expected creator Jon Favreau and director Bryce Dallas Howard (who continues to kill it behind the director's chair after a couple of warm-ups on "The Mandalorian") to dedicate a whole full-length episode to the fan-favorite Mando, putting Boba Fett (Temuera Morrison) on the backburner entirely. Based on the immediate reception to the episode, that appears to be a creative choice that paid off wonderfully, though I'm not sure what that says about the show's title character that everyone's favorite episode happens to be the one that, you know, he doesn't actually show up in.
In any case, Din Djarin's return to bounty hunting and his continued quest centered on Grogu certainly livened things up as we near the home stretch on "The Book of Boba Fett." As risky as it may have been to (briefly) derail our focus from Boba's struggles to become Tatooine's next greatest crime lord, it's hard to argue with the results. The episode is packed with new Mandalorian lore (Manda-lore-ian???), some of the show's best action to date, heaps of prequel trilogy nostalgia, and -- of course -- the traditional concept art featured in the end-credits sequence. Join us for yet another tour through the eye-popping artwork that rivals the actual visuals from the episode!
(Dark) Saber-Rattling

It's always nice to catch up with an old friend after some time apart, isn't it? Particularly in these lonely and socially distanced pandemic times, you might find that they can be a little different from when you remembered, having found new hobbies or developed new interests in the time since you last saw each other. And then there's Din Djarin, who's apparently just gone right back to his old bounty hunting ways, growling friendly ultimatums from behind his impenetrable mask such as, "I can either bring you in warm or cold." Charming, as always. We meet up with him again as he's on the search for another target, brandishing his fancy new Darksaber that he earned from defeating Moff Gideon (Giancarlo Esposito) in the Season 2 finale of "The Mandalorian."

Mando's back ... to finish the fight. I never would've expected to get "Halo" vibes from the modern era of "Star Wars," but here we are. After securing his Klatooinian bounty, Din Djarin heads to an unknown ringworld to collect what he's owed. These early segments of the episode deliver some downright spectacular imagery of a thriving city in the middle of deep space, instantly adding a sense of scope and scale and world-building that feels entirely at odds with the almost suffocating focus on the dirt and grime of Tatooine so far in this series. If there's any immediate difference between the two shows, that might be it. Mando has the luxury of planet-hopping wherever his adventures happen to take him. Boba, meanwhile, is stuck in the sand (literally!) navigating some highly repetitive subplots. Honestly, no wonder he and Fennec are trying to recruit his services once more.

We're never told the name of the Huttese-speaking crime lord Mando meets on the ringworld, but the scene in the episode is notably different from this concept art. The relatively sparse meeting is filled with several extras and minor characters observing the tense exchange in the actual episode, adding much more atmosphere to the proceedings and doing much to make this previously-unseen corner of the galaxy truly feel alive. The aliens themselves appear slightly different as well, appearing to be the same species but sporting a more evocative blue skin than the sickly green in the artwork.
Loyalty And Solidarity ... Up To A Point

This is the way. After receiving the information he needed to track down the covert hiding spot of the last remaining members of his Mandalorian tribe, Din Djarin meets up with the familiar (and mysterious) armorer seen throughout "The Mandalorian." Badly hurt from the opening action scene, Mando limps his way towards the armorer sitting serenely in repose, back turned towards him as she observes a stunning backdrop of stars in the emptiness of space. The episode does justice to this concept art, giving this scattered tribe of Mandalorians a new and memorable location after being forced to abandon their last one during the course of events covered in "The Mandalorian."

There's no place like home, eh? Even the wandering Mandalorians know how to give a family welcome, immediately setting about to heal Djarin's festering wound ... though not without dressing him down a bit for carrying that fancy beskar spear. Similar to the Jedi creed, apparently beskar is meant for defensive purposes, not for attack. Accordingly, Mando agrees to melt it down instead for some sort of gift intended for Grogu. That's where the shared customs between Mandalorians and the Jedi end, however, as Mando points out that their code of "loyalty and solidarity" is entirely at odds with the Jedi rejecting all attachments and bonds. Then again, that creed apparently has a loophole for when ownership of the Darksaber is in question, as Mando finds out the hard way.

Man, why can't everyone just get along? Mando barely gets settled in before he's once again fighting for his life, fending off a fellow Mandalorian who wants that Darksaber for himself. The thrilling fight is conducted on an impossibly small strip of walkway suspended over, well, nothing. The vacuum of space beckons to anyone who dares fall off, as both fighters dispense with their trusty jetpacks to show that they really mean business. Spoiler alert: Mando wins handily, though he still doesn't appear to know exactly how to wield that weapon rather than "fight against it." Expect this thread to be picked up either in next week's episode or the next season of "The Mandalorian."
All Hail Amy Sedaris!

Hey, look! Everybody's favorite mechanic is back and as feisty as ever! After technically making her first appearance in the background of a shot a few episodes ago in "The Book of Boba Fett," Peli Motto and her pit droids make their grand return to help out Mando at a time of need once again. I suppose if you're going to sneak an episode of "The Mandalorian" into the ongoing storyline of "The Book of Boba Fett," it only makes sense to commit to the bit and bring back as much of his supporting cast of characters as possible. Along with a very familiar looking pal in the form of a BD unit (to those who've played "Star Wars Jedi: Fallen Order," at least), Peli Motto finds herself fending off a particularly nasty little threat when Mando arrives.

Talk about the nick of time. Tatooine is the home of many outlandish creatures, but the dreaded womp rats always have a knack for turning up unwelcome. They've even earned the ire of Luke Skywalker himself a time or two in the past, in fact. This time, one particularly pesky rat attempts to make a meal out of the poor (but adorable!) BD unit, before setting its sights on Peli Motto herself. The episode doesn't give us as clear of a look at the invasive pest as this concept art does, but that only makes it more humorous when it grabs the hapless mechanic from behind an engine block and tries its hardest to ruin her entire day. It's not quite the toughest challenge Mando faces during the episode, but it's a good thing he shows up when he does anyway.

With the intruder dealt with, Mando sets about dealing with the reason he's on Tatooine in the first place. The frizzy-haired mechanic has promised him a replacement for his Razor Crest ship, which was wrecked during the course of the action in "The Mandalorian." This piece of artwork shows him dutifully hard at work repairing the antique that will apparently serve as his next vehicle, which requires no shortage of fixing and replacement parts. Thanks to Peli motto, the distracted BD droid, and a couple of intrepid Jawas, Mando manages to restore the new ship to something resembling its former glory.
And speaking of which...
Now THAT'S Podracing

The grand reveal of the N-1 Starfighter, native of the planet of Naboo and somehow having made its way to the distant sands of Tatooine, forms the bulk of the latter half of the episode. Upon restoring it to flight capabilities, Din Djarin promptly takes a tour through nostalgia land and revisits a certain famous sequence from "The Phantom Menace," retreading the same ground that a young Anakin Skywalker once navigated in the race of his life. Though lacking the distinctive sound effects from that thrilling George Lucas sequence (and a couple of Sand People taking some potshots at the racers, just for the heck of it), it's still a welcome little detour ... even if it sort of feels like Mando must've actually watched the prequels in order to know about that location in the first place.

Earlier in the episode, Mando travels to Tatooine on a starliner and briefly interacts with an inquisitive little Rodian child (that's "Baby Greedo," for the less hardcore fans out there) who seems to remind him of Grogu. Apparently on his way off-world again, Din Djarin once again crosses paths with that same kid, though this time during his joyride among the stars as he tests out what his nifty new N-1 is capable of in space. Interestingly enough, this concept art seems to indicate that the child was originally envisioned as a human, clutching an X-Wing toy and wearing a Rebel helmet, to boot. At some point in the creative process, apparently this was changed to focus on a Rodian instead, the alien species that is also included in the artwork just one seat in front. Given how weirdly human-centric all this new "Star Wars" stories continue to be, I fully support this minor change.

Oh right, we're watching an episode of "The Book of Boba Fett"! The concluding moments jarringly remind us of that fact, bringing back Ming-Na Wen's Fennec Shand (who is, ironically, an original character from "The Mandalorian") to refocus our attention on Boba Fett's plight with the incoming Pyke Syndicate. It remains unclear just what difference one bounty hunter, capable though he is, will make in the war to come, but we're as eager as you are to find out. Likely to Boba's chagrin, Mando seems to want to visit Grogu first before doing anything else, so we'll have to wait until next week to see how this all shakes out.
Read this next: The 12 Best Boba Fett Moments In Star Wars Shows And Movies
The post Here's All The Concept Art From The Book Of Boba Fett Episode 5 appeared first on /Film.
White House Attempts To Strengthen Federal Cybersecurity After Major Hacks
Read more of this story at Slashdot.
Charlie Brown's voice actor, Peter Robbins, died from suicide

Peter Robbins, who was the voice of Charlie Brown in Peanuts cartoon TV specials in the 1960s, died last week from suicide. He was 65. Robbins began voicing Charlie Brown in 1963 and was such a fan of Peanuts that he had a tattoo of Charlie Brown and Snoopy hugging each other. — Read the rest
Evolved phishing: Device registration trick adds to phishers’ toolbox for victims without MFA
We have recently uncovered a large-scale, multi-phase campaign that adds a novel technique to traditional phishing tactics by joining an attacker-operated device to an organization’s network to further propagate the campaign. We observed that the second stage of the campaign was successful against victims that did not implement multifactor authentication (MFA), an essential pillar of identity security. Without additional protective measures such as MFA, the attack takes advantage of the concept of bring-your-own-device (BYOD) via the ability to register a device using freshly stolen credentials.
The first campaign phase involved stealing credentials in target organizations located predominantly in Australia, Singapore, Indonesia, and Thailand. Stolen credentials were then leveraged in the second phase, in which attackers used compromised accounts to expand their foothold within the organization via lateral phishing as well as beyond the network via outbound spam.
Connecting an attacker-controlled device to the network allowed the attackers to covertly propagate the attack and move laterally throughout the targeted network. While in this case device registration was used for further phishing attacks, leveraging device registration is on the rise as other use cases have been observed. Moreover, the immediate availability of pen testing tools, designed to facilitate this technique, will only expand its usage across other actors in the future.
MFA, which prevents attackers from being able to use stolen credentials to gain access to devices or networks, foiled the campaign for most targets. For organizations that did not have MFA enabled, however, the attack progressed.

Phishing continues to be the most dominant means for attacking enterprises to gain initial entry. This campaign shows that the continuous improvement of visibility and protections on managed devices has forced attackers to explore alternative avenues. The potential attack surface is further broadened by the increase in employees who work-from-home which shifts the boundaries between internal and external corporate networks. Attackers deploy various tactics to target organizational issues inherent with hybrid work, human error, and “shadow IT” or unmanaged apps, services, devices, and other infrastructure operating outside standard policies.
These unmanaged devices are often ignored or missed by security teams at join time, making them lucrative targets for compromising, quietly performing lateral movements, jumping network boundaries, and achieving persistence for the sake of launching broader attacks. Even more concerning, as our researchers uncovered in this case, is when attackers manage to successfully connect a device that they fully operate and is in their complete control.
To fend off the increasing sophistication of attacks as exemplified by this attack, organizations need solutions that deliver and correlate threat data from email, identities, cloud, and endpoints. Microsoft 365 Defender coordinates protection across these domains, automatically finding links between signals to provide comprehensive defense. Through this cross-domain visibility, we were able to uncover this campaign. We detected the anomalous creation of inbox rules, traced it back to an initial wave of phishing campaign, and correlated data to expose the attackers’ next steps, namely device registration and the subsequent phishing campaign.

This attack shows the impact of an attacker-controlled unmanaged device that may become part of a network when credentials are stolen and Zero Trust policies are not in place. Microsoft Defender for Endpoint provides a device discovery capability that helps organizations to find certain unmanaged devices operated by attackers whenever they start having network interactions with servers and other managed devices. Once discovered and onboarded, these devices can then be remediated and protected.

In this blog post, we share the technical aspects of a large-scale, multi-phase phishing campaign. We detail how attackers used the first attack wave to compromise multiple mailboxes throughout various organizations and implement an inbox rule to evade detection. This was then followed by a second attack wave that abused one organization’s lack of MFA protocols to register the attackers’ unmanaged device and propagate the malicious messages via lateral, internal, and outbound spam.
First wave and rule creation
The campaign leveraged multiple components and techniques to quietly compromise accounts and propagate the attack. Using Microsoft 365 Defender threat data, we found the attack’s initial compromise vector to be a phishing campaign. Our analysis found that the recipients received a DocuSign-branded phishing email, displayed below:

The attacker used a set of phishing domains registered under .xyz top-level domain. The URL domain can be described with the following regular expression syntax:
UrlDomain matches regex @”^[a-z]{5}\.ar[a-z]{4,5}\.xyz”
The phishing link was uniquely generated for each email, with the victim’s email address encoded in the query parameter of the URL. After clicking the link, the victim was redirected to a phishing website at newdoc-lnpye[.]ondigitalocean[.]app, which imitated the login page for Office 365. The fake login page was pre-filled with the targeted victim’s username and prompted them to enter their password. This technique increased the likelihood that the victim viewed the website as being legitimate and trustworthy.

Next, we detected that the victim’s stolen credentials were immediately used to establish a connection with Exchange Online PowerShell, most likely using an automated script as part of a phishing kit. Leveraging the Remote PowerShell connection, the attacker implemented an inbox rule via the New-InboxRule cmdlet that deleted certain messages based on keywords in the subject or body of the email message. The inbox rule allowed the attackers to avoid arousing the compromised users’ suspicions by deleting non-delivery reports and IT notification emails that might have been sent to the compromised user.
During our investigation of the first stage of this campaign, we saw over one hundred compromised mailboxes in multiple organizations with inbox rules consistently fitting the pattern below:
| Mailbox rule name | Condition | Action |
| Spam Filter | SubjectOrBodyContainsWords: “junk;spam;phishing;hacked;password;with you” | DeleteMessage, MarkAsRead |
While multiple users within various organizations were compromised in the first wave, the attack did not progress past this stage for the majority of targets as they had MFA enabled. The attack’s propagation heavily relied on a lack of MFA protocols. Enabling MFA for Office 365 applications or while registering new devices could have disrupted the second stage of the attack chain.
Device registration and second wave phishing
One account belonging to an organization without MFA enabled was further abused to expand the attackers’ foothold and propagate the campaign. More specifically, the attack abused the organization’s lack of MFA enforcement to join a device to its Azure Active Directory (Azure AD) instance, or possibly to enroll into a management provider like Intune to enforce the organization’s policies based on compliant devices.
In this instance, the attackers first installed Outlook onto their own Windows 10 machine. This attacker-owned device was then successfully connected to the victim organization’s Azure AD, possibly by simply accepting Outlook’s first launch experience prompt to register the device by using the stolen credentials. An Azure AD MFA policy would have halted the attack chain at this stage. Though for the sake of comprehensiveness, it should be noted that some common red team tools, such as AADInternals and the command Join-AADIntDeviceToAzureAD, can be used to achieve similar results in the presence of a stolen token and lack of strong MFA policies.
Azure AD evaluates and triggers an activity timestamp when a device attempts to authenticate, which can be reviewed to discover freshly registered devices. In our case, this includes a Windows 10 device either Azure AD joined or hybrid Azure AD joined and active on the network. The activity timestamp can be found by either using the Get-AzureADDevice cmdlet or the Activity column on the devices page in the Azure portal. Once a timeframe is defined and a potential rogue device is identified, the device can be deleted from Azure AD, preventing access to resources using the device to sign in.
The creation of the inbox rule on the targeted account coupled with the attackers’ newly registered device meant that they were now prepared to launch the second wave of the campaign. This second wave appeared to be aimed at compromising additional accounts by sending lateral, internal, and outbound phishing messages.
By using a device now recognized as part of the domain coupled with a mail client configured exactly like any regular user, the attacker gained the ability to send intra-organizational emails that were missing many of the typical suspect identifiers. By removing enough of these suspicious message elements, the attacker thereby significantly expanded the success of the phishing campaign.
To launch the second wave, the attackers leveraged the targeted user’s compromised mailbox to send malicious messages to over 8,500 users, both in and outside of the victim organization. The emails used a SharePoint sharing invitation lure as the message body in an attempt to convince recipients that the “Payment.pdf” file being shared was legitimate.

Like the first stage of the campaign, we found that the URL used in the second wave phishing emails matched the first’s wave structure and also redirected to the newdoc-lnpye[.]ondigitalocean[.]app phishing website imitating the Office 365 login page. Victims that entered their credentials on the second stage phishing site were similarly connected with Exchange Online PowerShell, and almost immediately had a rule created to delete emails in their respective inboxes. The rule had identical characteristics to the one created during the campaign’s first stage of attack.
Generally, the vast majority of organizations enabled MFA and were protected from the attackers’ abilities to propagate the attack and expand their network foothold. Nonetheless, those that do not have MFA enabled could open themselves up to being victimized in potential future attack waves.
Remediating device persistence: when resetting your password is not enough
Analysis of this novel attack chain and the additional techniques used in this campaign indicates that the traditional phishing remediation playbook will not be sufficient here. Simply resetting compromised accounts’ passwords may ensure that the user is no longer compromised, but it will not be enough to eliminate ulterior persistence mechanisms in place.
Careful defenders operating in hybrid networks need to also consider the following steps:
- Revocation of active sessions and any token associated with the compromised accounts
- Deletion of any mailbox rules eventually created by the actor
- Disable and removal of any rogue device joined to Azure AD by the actor
If these additional remediation steps are not taken, the attacker could still have valuable network access even after successfully resetting the password of the compromised account. An in-depth understanding of this attack is necessary to properly mitigate and defend against this new type of threat.
Defending against multi-staged phishing campaigns
The latest Microsoft Digital Defense Report detailed that phishing poses a major threat to both enterprises and individuals, while credential phishing was leveraged in many of the most damaging attacks in the last year. Attackers targeting employee credentials, particularly employees with high privileges, typically use the stolen data to sign into other devices and move laterally inside the network. The phishing campaign we discussed in this blog exemplifies the increasing sophistication of these attacks.
In order to disrupt attackers before they reach their target, good credential hygiene, network segmentation, and similar best practices increase the “cost” to attackers trying to propagate through the network. These best practices can limit an attacker’s ability to move laterally and compromise assets after initial intrusion and should be complemented with advanced security solutions that provide visibility across domains and coordinate threat data across protection components.
Organizations can further reduce their attack surface by disabling the use of basic authentication, enabling multi-factor authentication for all users, and requiring multi-factor authentication when joining devices to Azure AD. Microsoft 365 global admins can also disable Exchange Online PowerShell for individual or multiple end users via a list of specific users or filterable attributes, assuming that the target accounts all share a unique filterable attribute such as Title or Department. For additional security, customers can enforce our new Conditional Access control requiring MFA to register devices, which can be combined with other CA conditions like device platform or trusted networks.
Microsoft 365 Defender correlates the alerts and signals related to initial phishing generated by suspicious inbox rule creation as well as suspicious device registration into a single easy to comprehend Incident.

Microsoft Defender for Office 365 protects against email threats using its multi-layered email filtering stack, which includes edge protection, sender intelligence, content filtering, and post-delivery protection, in addition to including outbound spam filter policies to configure and control automatic email forwarding to external recipients. Moreover, Microsoft Defender for Office 365 uses Safe Links feature to proactively protect users from malicious URLs in internal messages or in an Office document at time of click. Safe Links feature to proactively protect users from malicious URLs in internal messages or in an Office document at time of click.
Advanced hunting queries
Hunting for emails with phishing URL
let startTime = ago(7d);
let endTime = now();
EmailUrlInfo
| where Timestamp between (startTime..endTime)
| where UrlDomain matches regex @"^[a-z]{5}\.ar[a-z]{4,5}\.xyz"
| project NetworkMessageId,Url
| join (EmailEvents
| where Timestamp between (startTime..endTime))
on NetworkMessageId
Hunting for suspicious Inbox Ruleslet startTime = ago(7d);
// Hunting for suspicious Inbox Rules
let startTime = ago(7d);
let endTime = now();
CloudAppEvents
| where Timestamp between(startTime .. endTime)
| where ActionType == "New-InboxRule"
| where RawEventData contains "Spam Filter"
| where RawEventData has_any("junk","spam","phishing","hacked","password","with you")
| where RawEventData contains "DeleteMessage"
| project Timestamp, AccountDisplayName, AccountObjectId, IPAddress
Hunting for rogue device registrations
// Hunting for rogue device registrations let startTime = ago(7d); let endTime = now(); CloudAppEvents | where Timestamp between(startTime .. endTime) | where ActionType == "Add registered owner to device." | where RawEventData contains "notorius" | where AccountDisplayName == "Device Registration Service" | where isnotempty(RawEventData.ObjectId) and isnotempty(RawEventData.ModifiedProperties[0].NewValue) and isnotempty(RawEventData.Target[1].ID) and isnotempty(RawEventData.ModifiedProperties[1].NewValue) | extend AccountUpn = tostring(RawEventData.ObjectId) | extend AccountObjectId = tostring(RawEventData.Target[1].ID) | extend DeviceObjectId = tostring(RawEventData.ModifiedProperties[0].NewValue) | extend DeviceDisplayName = tostring(RawEventData.ModifiedProperties[1].NewValue) | project Timestamp,ReportId,AccountUpn,AccountObjectId,DeviceObjectId,DeviceDisplayName
The post Evolved phishing: Device registration trick adds to phishers’ toolbox for victims without MFA appeared first on Microsoft Security Blog.
How The Jackass Crew Pulled Off A Stunt With Brad Pitt

If there's one thing the "Jackass" franchise does right — joke's on you, though, they do everything right — it's their celebrity cameos. The team knows how to pack a punch with the appearances they select and, in turn, those appearances make their already-exciting projects that much more compelling. One of the best examples of this is legendary actor Brad Pitt's two turns on the beloved stunt-and-smash series, because of course it is, knowing Pitt and his wacky sense of humor.
In 2018, "Jackass" team captain, master of ceremonies, and star Johnny Knoxville opened up about pulling off a stunt with the "Once Upon a Time ... in Hollywood" star while appearing on (my favorite interview series) "Hot Ones" — and apparently, the movie star was more than ready to go crazy with the crew.
"Is it true that you had to talk Brad Pitt off the ledge when he wanted to do a prank that was just bigger than the one you guys had planned for him?" Sean Evans, "Hot Ones" host since 2015, asked Knoxville. The stunt performer revealed:
"[Pitt] showed up ready. We had him in two bits; One, we kidnapped him in front of Pink's Hot Dogs, which went really well, and the first time—we had him for one night. We were doing these go-karts, bombing the hill on Vine. And we were all like, oh, we really don't want him to get hurt, because he's Brad Pitt and he's... But he did not care, he was ready to do it. He was the first one in the middle of the street, we're like, 'No, no, no, no! Don't do that!' But he didn't care."
The Most Underrated Team-Up Ever?
You're probably wondering how Brad Pitt himself got roped into the whole "Jackass" beautiful mess in the first place — and I'm here to tell you that story, nay, legend, so that you can take this campfire tale with you in your travels and impress your friends. Trust me, it's the kind of celebrity trivia that actually rules.
Picture it: It was early 2002 and "Jackass," the original TV show of course, was a raging success. The series was coming to a close with its third season — and that's when Knoxville met Pitt at "Jackass" executive producer (and later, prolific director) Spike Jonze's house.
"He was saying he really wanted to do something with us," Knoxville told MTV News in September 2006. "We were filming the last episode. At the time, we didn't even have any ideas — just that he wanted to be on the show."
From there, Knoxville and his cronies came up with "The Abduction," a one-minute bit in the show's final episode in which Pitt is, you guessed it, abducted by men in ski masks while waiting in line at Pink's Hot Dogs in Hollywood. The men put a shocked Pitt into a van and drove off while bystanders watched, and a few even tried to help to no avail.
Additionally, Pitt got to try his hand at being a jackass in a second sketch, during which he and the guys dressed in monkey suits and rode in shopping carts until they careened forcefully into curbs, bushes, and anything else in their path. Talk about a perfectly chaotic way to cap a perfectly chaotic series.
Read this next: 14 Awesome Comedies That Never Got Sequels
The post How the Jackass Crew Pulled Off a Stunt With Brad Pitt appeared first on /Film.







