Shared posts

28 Apr 20:15

System Shock Q&A – The Difficult Journey of Remaking a Classic, from Guatemala to Atari

by Alessio Palumbo

System Shock

In an age where remakes and remasters dominate much of the game release schedule throughout the year, one of the most seminal games of all time, System Shock, is finally about to come back to the market as a whole new product.

Despite the May 30th launch date on PC, there's not much fanfare around it, perhaps due to the project's known problems and delays (it was first announced in 2015). In a 45-minute-long conversation over Zoom, I recently had the opportunity to go through the whole behind-the-scenes process of remaking System Shock from its very inception with Stephen Kick, Game Director and co-founder of Nightdive Studios, and Larry Kuperman, Director of Business Development.

It was a long and interesting chat, during which we also touched upon the current schedule for the console ports, some possible post-launch additions like New Game+, what's next after this remake, the impact of the recent acquisition by Atari, and even a brief update on the live action TV adaptation. Strap in.

Let's begin by addressing the elephant in the room. People have been waiting to play this System Shock remake for a very long time due to multiple delays. What happened?

Stephen Kick: System Shock has been in development not for seven years but closer to 11 years. Back in 2012, I was still working at Sony as a character artist and my girlfriend at the time, who was also a character artist, decided that she was pretty much done with the video game industry after a pretty short stint and convinced me to pack up everything we owned into a Honda Civic and drive across the border in Mexico.

It was cool. It was really scary. We spent the next ten months going through the entirety of Mexico and Central America. One night, when I was in Guatemala, I decided to play some classic video games. They were what originally inspired me to become part of the industry and are still a big love of mine. I tried to boot up System Shock 2 and I couldn't get it to run, so I went, like any normal person would do, to GOG.com. I figured it's one of the best games ever made; it's got to be available for purchase.

I discovered that it was the most requested title in GOG's catalog. So, I decided to do some digging and found that the rights had been transferred to the Meadowbrook Insurance Group. I reached out to their general counsel and discovered that they had not only the rights but had recently acquired the trademark and were looking for some way to commercialize the game so they could hold on to those rights.

At first, they asked me if I wanted to do a System Shock game. But, being miles into a jungle with $5,000 to my name, it was out of the question. I recommended that we just re-release the games on digital storefronts like GOG and Steam. There was a very quick back and forth with the contract. I had to convince friends and family to lend me enough money to pay for the license and the game went on sale on Valentine's Day 2013.

It was a smash hit, and it opened up the possibility of going out and spending my time doing the same for other games you can no longer commercially purchase or run on modern machines.

Larry Kuperman: That starts off Nightdive Studios. A year later, right after GDC 2014, I joined the company. My first task was to acquire the remaining System Shock rights so we could do more with the games. That took well over a year of working with that insurance company's attorneys.

I will tell you that for a long time, I have had weekly phone calls every Friday. I kept calling the attorney, saying, are we ready to do business? Finally, we acquired the remaining rights.

The next question is, what do we do with it? That takes us up to the point where we announced that we would do a remake of the original System Shock game. In order to do that, we needed to do a Kickstarter.

That was quite successful, right?

Larry Kuperman: Yes, and one of the reasons it was so successful was we had a clear vision. We put together a team and we created a demo running in Unity. The fact that we were showing what people were backing and what we hoped the finished version would look like led to the success of Kickstarter's success. We reached and exceeded our goal on that and then began the work of actually creating the game.

People from that original team were called to other things, so we had to put together a new team to fulfill that vision. The first thing that we did not anticipate happening was we had really come up against the wall for what Unity could do at the time. We always knew that we wanted the game to be on PC, but also on Xbox and PlayStation consoles. We wanted to have a consistent frame rate across all devices. At that time, I know it's improved since then, but at that time, that really was pushing Unity beyond the limits of what it could do.

That was the first change. We transitioned over from working in Unity to working in Unreal, which would be able to help us realize that vision. That also was a setback and there was some delay, but we eventually had a team in place again after hiring some new people. Throughout all of that time, we were posting updates to the System Shock community via the Kickstarter page.

As the team was working on the game, there was a temptation that I think is universal when you work on remakes of classic IPs, which is to put your own signature and imprint on the game to make things work according to your vision.

That's when it began to drift off from what we had shown originally and what we had promised to people. The feedback that we began to get was that this isn't what people wanted, that it was something different from what we had shown and promised. That led to a number of heated discussions with the team.

We were also quickly burning through the money we had raised on Kickstarter, so there was a financial concern about it. At any rate, at that point, we knew that things were not working the way we wanted them.

'News came out that we were abandoning the game and had squandered everybody's money. None of that was accurate.' - Larry Kuperman

I guess that was in early 2018 when you announced System Shock would go on hiatus.

Larry Kuperman: Correct. It's funny, I thought everyone knew that that hiatus meant a pause, not an ending. But the news came out that we were abandoning the game, that we were terrible people and had squandered everybody's money. None of that was accurate.

The team had gone off in a direction that we did not want them to. We took responsibility for it and ultimately, we probably should have been more hands-on than we were at the time. We learned a lesson from that. Very quickly, we put together a new team and by GDC of that year, we actually showed off a demo running in Unreal that was much closer to and very true to the System Shock vision of what we had originally shown.

Time goes on; we're continuing to work on the game. It was not only Nightdive, certainly, it was worldwide and industrywide, but of course, then came COVID. There was social unrest, there was a pandemic, there were acquisitions, and people were being hired away by other companies who had allowed them to work on our project as well. Then that company was bought by somebody else. There was a lot of that during the COVID period. That said, our team continued to be productive and it continued to work forward on the game, but by that time, it was taking longer than our fans wanted.

It's natural for gaming fans that they want every game to be done today if not yesterday, right? The other thing that people perhaps were not aware of is where was the money coming from that was paying this development team.

Nightdive was funding all of the development by that point. Fortunately, we have a successful business, and we were doing other things. We have multiple teams, and so we were producing the games that are perhaps best associated with Nightdive, like Turok 1 and 2, we had Strife, we had multiple other titles and the revenues from that were funding the continued development of System Shock. That brings us up pretty close to where we are today.

Along the way, we began working with a publisher, Plaion. That has been a very positive relationship for us. The game is now in the final stages of being polished. Much of the work that is going on behind the scenes now has to do with localization.

This is a big stretch for us. Typically, we have only supported the European languages, EFIGS as people say, English, French, Italian, German, and Spanish. We are supporting System Shock with something like 14 languages. We're planning on having worldwide distribution and we want as many fans regardless of where they live regardless of their language, to be able to play and enjoy the game.

Once the PC version is finished, we've already had prototypes of the console versions, those are already in testing. But we want to make sure that the game is as close to perfect as we can make it for all versions so that people can play it on PC, Xbox, and PlayStation.

Just a quick follow-up on that. Are you still planning to release System Shock on last-generation consoles or will it be just PlayStation 5 and the Xbox Series S|X?

Larry Kuperman: It's going to be on both generations, particularly with our audience which is retro gaming enthusiasts. That's our core audience. Although of course, this game will certainly expand Nightdive's audience,  many of them have not upgraded and we want people to be able to play it regardless of how they want to play it.

What are the odds of a Nintendo Switch port?

Larry Kuperman: It's probably a bit early to talk about that, but it's certainly something that has been discussed. The only thing that I can say at this point is to stay tuned.

'We feel like we've struck a really great balance with the inventory system.' - Stephen Kick

Fair enough. It was a long development phase, for sure. Can you discuss what kind of changes you have made compared to the original game and maybe also which ones were inspired by the community's feedback through the Steam demos you have released over the years?

Stephen Kick: We implemented a number of changes from the original just to make the game more user-friendly. One thing that kind of inspired this whole project was the addition of mouse look in the original. It didn't have that when it initially came out in 1994. Instead, you had to drag the mouse to the edge of the screen to look around.

We worked with a modder in the System Shock community to inject the ability to have mouse look. We immediately found out that the game had been changed so dramatically that it became accessible to just about everybody at that point. We had new players come in and really enjoy themselves immensely. That kind of sparked the initial idea of, wow, that's all that it took to make this game more playable and more accessible and just more fun.

Well, what if we did this, what if we did that? The next iteration was getting the source code of the game and porting it to our test engine and adding even more features to make it more accessible. High-resolution support, widescreen support, stuff that would normally be pretty standard in any remaster. Then from there, our discussions went well, this game is really underrepresented. It inspired so much that we owe it to the legacy of not only System Shock but of Origin and Looking Glass and Irrational to bring this game back for people to truly appreciate it. That's when we brought on, like Larry said, the initial Unity team and we did the prototype. That's when we knew that we had something very special.

Aside from just adding mouse look, one of the other major things that we changed was the overall user interface and the user experience. In the original, it was very obtuse and made it hard to understand what was going on.

If you weren't savvy or you weren't aware, you wouldn't notice that certain panels that had vital information would kind of switch around on you and just be all over the place. That was by design, but again, that was something that we wanted to standardize. We took the lessons that were learned between System Shock 1 and 2, which came out in 1999, 5 years later, and we brought that back to the original game.

Now we've got more or less a hybrid of the two inventory systems. We feel like we've struck a really great balance between a modern game and something old-school that's reminiscent of those old games. What we have now is essentially something more like the Resident Evil remake where you've got a grid-based inventory and everything is clearly visible and you can move things around.

Long answer to your short question, but the user interface, the inventory system, all those have changed.

I think you also introduced the dismemberment system, correct?

Stephen Kick: Yeah. There wasn't any dismemberment or anything like that in the original, but there were graphics, let's just say to suggest that some really gory, nasty things had happened to the people on Citadel Station.

We wanted to pay homage to that by implementing a dismemberment system so that corpses and enemies reacted accordingly when subjected to explosives.

'Cyberspace is now a major part of the critical path' - Stephen Kick

Can you talk about how you've modified Cyberspace?

Stephen Kick: This goes back to your initial question too about things that we changed. Cyberspace was definitely the subject of a lot of upgrades and changes from the original, which while a very novel and very fun mini-game, was just hard to control and hard to understand where you were going and what the objective was.

Again, we looked to games that came out well after the original System Shock that did it differently and, you know, better. We brought that back to the original. Now you've got something more akin to Descent where you're controlling like a ship and you have six degrees of freedom to move around in the space, to navigate it. The objectives are clear, the directions and where you can go are clear and it's proven to be much more than just a mini-game. It's a major part of the critical path for the remake.

We've touched on things that we've changed. There's a lot we didn't change on purpose, as old-school games did a lot less hand-holding than many modern games. You're gonna be challenged, you're going to have to figure things out.

The only I'll give is listen to those audios. One of the things that I've enjoyed is that people miss things or they go past something, they don't know what to do, they'll die in the game but then they immediately restart to go back. That's what we want; the game has to be challenging. It has to have that right level of frustration that makes you want to try another time to overcome obstacles.

Do you think the length will be the same as the original System Shock?

Stephen Kick: It's definitely a lot longer. One of the things we had to change was the placement of the audio logs because in the original the movement speed and just the pacing are much slower due to how cumbersome the movement was. We had to adjust the spacing of all the audio logs because in this modern game, you're moving at a quicker pace and you're able to explore a lot more easily, so you're picking up a lot more logs all at once and the player is just sitting there listening to something instead of playing the game.

We had to spread that out quite a bit, but a new player can expect somewhere between 16 to 20 hours of gameplay if they want to explore and do everything. There's even difficulty modes that we've implemented where if you want a real challenge, there's a timer that has a real-time effect in the game where you'll lose the game if you don't beat it within like eight hours.

There's some variables that we've introduced that are going to either elongate your playtime experience or make it artificially shorter to add to the challenge.

Will there be something like a New Game+ mode?

Stephen Kick: There may be a New Game+ that we introduce after launch. As it is right now, just like the original, there's a difficulty mode that you can alter.

You've got variables for the four parts of the game. There's combat, hacking, puzzles, and cyberspace. Each of those has three levels of difficulty that you can change at the beginning of the game, depending on the kind of experience you want.

Larry Kuperman: We're concerned that the users can customize it to how they wish to play. I think that that also adds a whole new level of replayability.

Speaking of replayability, what about PC modding? Is it something you will support, or just leave it to the community?

Stephen Kick: It's something that we would like to support in the future. System Shock is not gonna be moddable out of the box due to using the Unreal Engine, but I'm sure some individuals will find a way to modify the game not long after launch.

Larry Kuperman: Let me give you a slightly different answer to that. We're not going to be doing that at launch, but if some of our fans would choose to implement that that is not something that we would in any way stop or impede.

Fair enough. I've read some feedback from the forums, Reddit, et cetera. A few people weren't too happy about the pixelated look. Is there any chance you'd make it optional in the settings?

Larry Kuperman: The art style was a very deliberate choice on our part. We brought back Rob Waters, who was the original artist. In terms of the pixelated look, Nightdive is all about the preservation of classic games and the way they looked and felt. It was a very deliberate choice.

We want players to recognize that at the core, this is a homage to the great games that have influenced so much of today's gaming environment.

We listen very closely to our backers, particularly our Kickstarter backers and people on all the forums. We've seen that on Reddit as well. We understand if you're purely a modern gamer, if you're somebody who has never played any of the classic games, the art style is going to appear unusual to you.

On the other hand, if you are somebody who has come up through those games or has familiarity with the way classic games looked and felt, you're going to look at the art style on it and go, I get it. It's a recognition that this is a remake of a title that originally came out in 1994, and we don't want people to forget that.

On that note. Do you believe remaking this story about Shodan in this age where AI is really close to entering every aspect of our lives is a particularly good time to introduce the classic IP to the newer generations?

Larry Kuperman: I think that's very accurate. It would be great if I said that the timing of this game, which is about a rogue AI, coming out at a time when half the universe is concerned about the development of a rogue AI, was intentional on our part. It wasn't, but this is certainly the right game for this time.

Will you support NVIDIA DLSS and/or AMD FSR and Intel XeSS?

Stephen Kick: We are gonna support DLSS 2, that's already available in the demo out there now. We are evaluating DLSS 3. As for ray tracing, that is something that we're gonna have to look at a little more closely, Due to the art style that we've got, ray tracing is not gonna have any noticeable improvement over the lighting that we've got.

You're also making System Shock 2 Enhanced Edition, right? Some people would like to know if you will add the controller support from this remake to that game as well.

Stephen Kick: That's the plan. The idea is that System Shock 2 Enhanced Edition will be cross-platform, so you'll be able to play it on Xbox, PlayStation, and Nintendo Switch like all of the other remasters we do on that team.

'Atari wants us to keep doing what we've been doing, only more of it.' - Larry Kuperman

Is the controller support going to be available on PC as well?

Larry Kuperman: Yes, absolutely.

Going back to the System Shock remake console ports, will they be out this year?

Larry Kuperman: That's something that we've been working very closely with our publisher to achieve. We expect them to be on the shelves for the holiday season.

I'm hoping you can discuss the news of Nightdive's $10 million buyout from Atari. How does this affect System Shock and your future as a studio?

Larry Kuperman: We've had a long relationship with some of the key people at Atari. People should be aware that Chairman and CEO Wade Rosen, for example, has been involved with Nightdive Studios for years, in a very hands-off capacity, for the reason that he's a big supporter of what we do.

There was a lot of thought that went into this partnership. One of the motivations on our part was we've now partnered with a company that wants us to keep on with what we have been doing only to do more of it, to put that on a bigger stage.

Does this acquisition take off a bit of pressure on the success of System Shock?

Larry Kuperman: It both takes off some pressure and since this will be the first title that will be coming out under the new banner, so to speak, it adds another layer of pressure as well.

Let's say that the System Shock remake launches as you hope, as a success. What's next? A lot of people are already doing wishlists for a System Shock 2 remake. Have been thinking about it?

Larry Kuperman: We have. I'm not ready to make that commitment. Our team is really heads down focused on the System Shock game that we have to get out.

But of course, the question about what will be the next game has come up a couple of times. We currently have three other titles in production from our other team. We're gonna have a very busy 2023.

We have our calendar set for 2024. That said, the success of this game will in many ways dictate what the future is for other titles in the franchise or other titles outside of that franchise.

One last question - is there any news on that System Shock live-action TV adaptation announced a couple of years ago?

Larry Kuperman: It did not pan out as intended. We are currently working with a team, but nothing is final as of yet.

Thank you for your time.

Written by Alessio Palumbo
28 Apr 17:09

Do Electric Vehicles Have Differential Oil Like Combustion Cars?

by Alex Ramos

Electric vehicles are known to require less routine maintenance compared to internal combustion vehicles. With EVs, you can say goodbye to regular engine oil changes, but what about differential oil? Do electric vehicles even have differentials, and do they require oil changes?

28 Apr 00:45

Untangling the Complexity of SaaS Ownership in the Enterprise

by Lenny Zeltser

Before SaaS, employees had to rely on IT and other teams to procure software, which gave the organization a direct way of controlling such purchases and deployments. Now, employees can sign up for SaaS applications without involving anyone in the company. All it takes is a few clicks and (sometimes) a credit card for people to start using such products. In moments, SaaS apps can start processing sensitive business data with no consideration for security, governance, oversight, and other requirements that are at the top of the minds of CISOs and CIOs.

The lack of internal bottlenecks empowers people to quickly get the tools they need to get work done. However, Finance, IT, Legal, and other teams lack the visibility to ensure that SaaS apps are provisioned and managed responsibly and securely. No longer the gatekeepers, these teams must revisit the approaches to guiding and overseeing the company’s use of SaaS.

What can we do to support the use of SaaS within the enterprise, but do so in a responsible way?

Security, IT, and SaaS "Ownership"

There are several reasons why SaaS ownership is challenging for IT and security teams.

Employees can start using SaaS applications without any involvement from IT and security teams. As a result, these teams are often unaware that the applications are being used and don’t know about the associated risks. For example, we might not realize that a SaaS provider now processes sensitive data and cannot configure the appropriate security measures with the app. On their own, end-users often lack the expertise to configure the apps in a way consistent with the organization’s policies. 

Another challenge is the lack of a clear understanding of the roles and responsibilities of “owning” a SaaS application:

  • Who is responsible for adding new users to it and assigning them the appropriate permissions?
  • Who will revoke access when the need arises?
  • Who will handle renewal and other licensing discussions?

End-users who initially purchase a SaaS product might expect IT or other teams to handle all or some of these responsibilities, but these teams might not share this understanding.

In addition, modern SaaS applications rarely function as data siloes. They often integrate with other software. The individuals who bring SaaS into the organizations often do not consider such interdependencies and dataflows. Late-stage discovery of such externalities can put unexpected burdens on IT and security teams and prevent the SaaS application from achieving its full potential.

Clarifying SaaS Expectations

IT and security teams should document the roles and responsibilities of deploying and maintaining a SaaS application. Explain what aspects of the IT team will own, such as the app’s configuration and security oversight. We should clarify what responsibilities might reside with the end-users. For example, depending on how the app integrates with the company’s identity management system, IT can automatically provision users with the proper privileges into the SaaS app; in other cases, designated people outside IT might need to do this.

Also, we should clarify the company’s expectations of SaaS applications:

  • What security requirements does the organization impose on its SaaS providers?
  • How might these requirements differ based on the sensitivity of the data they process?
  • What are the service-level expectations, Single Sign-On (SSO) requirements, etc.?
  • What other internal teams, such as Legal and Finance, might need to be involved and when?

We should document these expectations so that people looking at SaaS know what they need to do or communicate to SaaS providers.

In addition, we should recognize that unsanctioned SaaS products will find their way into the organization. Consider what approaches and tools we might use to discover their existence, so IT and security teams can bring the necessary oversight to their usage to protect the organization and support end-users. (Axonius, where I lead the security program, offers a solution for this.)

Collaborating with SaaS Stakeholders

One way to start the discussion of SaaS ownership is to identify common interests. Most likely, all stakeholders want to have a SaaS application that is correctly deployed and properly licensed. It should be available to the right people with the expected functionality. The stakeholders will probably agree that the app should be responsibly secured and not expose the organization to unexpected or undesirable risks.

Next, we can outline what one-time and ongoing tasks should happen for the organization to meet the identified objectives. With these responsibilities at hand, we can discuss who is best positioned to handle them, how, and when. We can also assign responsibilities according to the RACI model, which calls for agreeing on who should be responsible, accountable, consulted, and informed about the tasks.

27 Apr 22:33

Why Sigourney Weaver Is Done Playing Ellen Ripley In The Alien Franchise

by Drew Tinnin

When screenwriter and filmmaker Dan O'Bannon wrote the original "Alien," he couldn't have imagined that his own personal experience dealing with Crohn's disease -- which helped inspire the chest-burster Xenomorph -- would go on to spawn six of the most thought-provoking sci-fi horror movies in cinema history. O'Bannon's own fears eventually transferred over to the character of Ellen Ripley (Sigourney Weaver), who became terrified of suffering the same horrible fate as Kane (John Hurt) aboard the Nostromo.

Over the course of Ridley Scott's "Alien," James Cameron's "Aliens," and David Fincher's "Alien 3," Ripley's worst fear was finally realized when she dove into a fiery pit, just as a chest-burster struggled to get free from her grasp. Returning as a clone in Jean-Pierre Jeunet's "Alien: Resurrection," Ripley's humanity was then stripped away in favor of a disconnected superhero version of the character that took away everything fans loved about her in the first place. Even after that ambitious but failed attempt to continue Ripley's storyline, Weaver has always been the face of the franchise. And now, it appears as though any chance of ever seeing her in the role that made her famous is growing more and more unlikely.

Weaver hasn't officially been a part of the series since Scott took the films in an entirely different direction with "Prometheus" and "Alien: Covenant" -- the prequels that were supposedly going to lead up to the events of the original "Alien." Bigger ideas about the origin of life and Scott's continuing fascination with artificial intelligence made his prequel films more philosophical in nature, although that also made it harder to imagine how a character like Ripley might fit into the bigger "Alien" picture going forward. Weaver seems acutely aware of this fact, which is why she plans to formally retire as Ripley for good.

'That Ship Has Sailed'

In an interview with Total Film magazine, Sigourney Weaver was asked the unavoidable question that she's basically been asked every time she promotes something new nowadays: Will she return as Ripley in a future "Alien" film? Her answer was decidedly final on the matter. It seems as if Weaver is ready to let the next generation take up the controls:

"There are all kinds of younger actors taking this kind of role. And there was an 'Alien' [film] that I really wanted to do with Neill Blomkamp and we didn't get to do that, but, you know, that ship has sailed."

Please don't remind us of the "Alien 5" idea that wound up never happening! If you recall, Blomkamp ("District 9") wanted to essentially reboot the franchise, ignoring the beginning of David Fincher's "Alien 3" -- wherein Hicks and Newt are already dead on arrival when Ripley crash-lands on the prison planet Fiorina 161. A few years back, some concept art began trickling out, giving fans a sense of what could have been if Hicks and Ripley had been re-united onscreen. Weaver seemed genuinely excited about the chance to do another direct sequel to "Aliens" but the project was eventually put on the back-burner while Ridley Scott proceeded with his own prequels. The project remains one of the most fascinating "What if?" scenarios in "Alien" history, but time has unfortunately moved on.

In any case, Weaver appears perfectly content to keep Ripley in the rearview at this stage: "I'm very happy doing what I'm doing. I put in my time in space!" She certainly has.

'I Was Very Lucky'

Honestly, after the bizarre experience Sigourney Weaver probably had to endure during the production of "Alien: Resurrection," she definitely needed a nice long break from the character. The underwhelming response to Jean-Pierre Jeunet's experimental take on the material didn't exactly reignite the franchise, and the same can be said for Ridley Scott's last entry, "Covenant" (itself more of a mashup between the grand design put forth with "Prometheus" and the remixed action beats of the first "Alien").

With Fede Alvarez now working on an "Alien" film reportedly featuring all-new characters, Weaver acknowledged how fortunate she was that Scott, and by extension Dan O'Bannon, created such a memorable female archetype that still has so much cultural impact to this day. "They made Ripley a woman, without making her this helpless creature," she told Total Film. "Because I think I was very lucky. These were men who were creating this woman character, but they liked and respected strong women."

The world of "Alien" will always be Scott's baby and Weaver will forever be associated with her Oscar-nominated role. Still, it will be fascinating to see if Noah Hawley (of "Fargo" and "Legion" fame) can bring the property back to its horror roots in his upcoming, long-awaited TV series that's still expected to arrive in 2024. Perhaps Weaver will make a cameo or even direct an episode? The show should absolutely include some female directors , and it would make so much sense to see Weaver be involved in some way creatively -- although seeing Ripley again is highly unlikely, considering the series reportedly takes place years before she was alive. Scott is also involved as a producer, although he's already said "It'll never be as good as the first one." And you know what? He's probably right.

Read this next: 20 Movies About Aliens That You Definitely Need To Watch

The post Why Sigourney Weaver is Done Playing Ellen Ripley in the Alien Franchise appeared first on /Film.

27 Apr 18:32

Breaking Down All The Rings Of Power From Amazon's Lord Of The Rings Series

by Jeremy Mathai

"One Ring to rule them all ..."

Fans aren't likely to forget the haunting words narrated by Cate Blanchett's elf queen Galadriel which open 2001's "The Lord of the Rings: The Fellowship of the Ring," adapted from author J.R.R. Tolkien's original text. In short order, director Peter Jackson had summed up much of the backstory that newcomers would need to hit the ground running and understand the plight of Middle-earth under the threat of the Dark Lord Sauron's return. But as much as the trilogy relied upon the fate of the One Ring, it mostly left all those other Rings of Power strictly on the sidelines.

That's where Prime Video's "The Lord of the Rings: The Rings of Power" series came in, filling in the gaps from thousands of years earlier in the canon to tell the sprawling tale of how the heroes of Middle-earth dealt with Sauron the last time he appeared. As of the season 1 finale, the series will also deal with the creation of the first of those Rings.

Although liberties were taken regarding plot specifics, like a younger Galadriel (played by Morfyyd Clark) obsessively following the trail of Sauron or the existence of Charlie Vickers' duplicitous Halbrand, the broad strokes remain in line with the accounts laid down by Tolkien in the appendices found at the end of "The Return of the King." As implied by the title, the debut season carefully documented the series of events that would eventually motivate Galadriel, her loyal friend Elrond (Robert Aramayo), and the great elven craftsman Celebrimbor (Charles Edwards) to combine their various powers into crafting three particular rings.

But what is their significance? How many more are there still to be made? How do they tie into Sauron's grand plan? Let's dive in and find out.

'Three Rings For The Elven-Kings Under The Sky ...'

In Tolkien's various stories and notes, the forging of the three rings for the elves comes about slightly differently than depicted in "The Rings of Power" -- though plenty of parallels remain. At this point in history, Sauron has disguised himself under the "fair" and unassuming visage of Annatar, an elvish name meaning "Lord of Gifts," which explains the cheeky emphasis of that word in the season finale. Although that alias hasn't yet been spoken aloud in the Prime Video series, it's clear that this is meant to be the show's interpretation of the same events.

According to Tolkien, Sauron emerges from centuries of hiding in the wake of Morgoth's defeat during the First Age (for context, "The Rings of Power" is set during the Second Age) and befriends the great elven smiths of Eregion -- including the greatest of them all, Celebrimbor. Despite the concerns of certain elves like Galadriel and Elrond, Annatar passes on his expert knowledge of ring-making and the ability to imbue their wearers with the power to transform Middle-earth with healing, preservation, and protection. However, as with the series, it's important that Sauron isn't directly involved in the crafting of the three major elvish rings. Whereas Tolkien describes Celebrimbor as crafting the three only after Annatar departs the region, "The Rings of Power" ties Galadriel's realization of Halbrand's true identity as Sauron into his hasty departure before the rings could be finished. Upon completion, Galadriel, Elrond, and Celebrimbor should now be able to stave off the diminishing power of their people.

Their unique origin in "The Rings of Power" also extends to the order of their creation. In the books, the elvish rings are created last of all the rings of power. Here, they're crafted first.

'Seven For The Dwarf-Lords In Their Halls Of Stone ...'

That brings us to the mighty dwarves, whom we've seen throughout "The Rings of Power" season 1 through the eyes of Elrond's old friend, Prince Durin (Owain Arthur). In the series, they've yet to receive their own batch of seven rings gifted by Annatar to seven different great lords. Unlike the elven rings, however, these are crafted under Sauron's supervision and explicitly meant to corrupt whoever wears them. But Annatar underestimates the hardiness of dwarves, who seem impervious -- on the surface, at least -- to their power. Yet that doesn't mean they wield no influence whatsoever, as they exacerbate their lust for gold and riches (this, shall we say, isn't one of Tolkien's finer moments in terms of reinforcing questionable stereotypes) and even contain the power to exponentially increase the precious ore they mine.

While Sauron's grand plan involves collecting all the rings under his power, he finds this particularly difficult with the dwarves. By the time "The Lord of the Rings" begins, most of the dwarven rings have either been consumed by dragons or simply lost in the intervening ages. Only two ultimately make it back into his clutches, one of which belonged to the father of Thorin Oakenshield (portrayed by Richard Armitage in Jackson's "The Hobbit").

It's hard to know exactly how season 2 will depict Sauron's treachery with the dwarves, especially since the secret is now out, and none ought to trust Halbrand again. Will Sauron find another disguise, leading to yet another season-long guessing game as to who he might be this time around? Or, famously stubborn as they are, will Durin's father and people simply ignore Galadriel's warnings and trust Halbrand anyway, accepting his favor and dooming themselves to centuries of trouble?

'Nine For Mortal Men Doomed To Die ...'

And now we come to some of the most famous rings of them all (excepting the One Ring, of course). Tolkien, Jackson's "The Lord of the Rings," and "The Rings of Power" have all taken pains to portray the race of men as the most susceptible to evil of all the peoples of Middle-earth. This is proven most emphatically through what's believed to be the Númenórean lords who were most easily seduced by Annatar. Similar to the dwarven rings, these helped their bearers achieve great wealth and power ... but like the One Ring itself, they also unnaturally extended their lifespans until they eventually withered away into invisibility and fell under Sauron's sway entirely. Known henceforth as Ringwraiths, they would eventually plague our fellowship of heroes on their quest to destroy the One Ring thousands of years later, but that's getting ahead of ourselves.

Excitingly, it's possible that we'll soon be introduced to the flawed figureheads whom Sauron will bestow his gifts upon in future seasons of "The Rings of Power." Having already established the island kingdom of Númenor, the series should have no trouble at all introducing these more sinister individuals in stark juxtaposition to other supporting characters, such as the noble Elendil (Lloyd Owen). The table-setting has already begun, evidenced by the impending fall of Númenór due to their leaders' profound fear of death. What better way to exploit this weakness than by offering some rings of power that can prolong life indefinitely?

Although all of these events take place over the course of hundreds of years in Tolkien's writings, "The Rings of Power" will have to continue to drastically condense its timeline for adaptation purposes. Either way, expect some major events in season 2.

'One For The Dark Lord On His Dark Throne ...'

And, of course, we can't forget the One Ring to rule them all. By far the biggest development in season 1 of "The Rings of Power" has to be the Halbrand/Sauron reveal dovetailing with the transformation of the Southlands into the land of Mordor, where the shadows lie. While fans can consider the eruption of Mount Doom and its subsequent terraforming of the surrounding area as a sort of Easter egg further connecting the series to the events of "The Lord of the Rings," it actually serves an incredibly important practical purpose, as well.

As part of Sauron's devious scheme, all the 19 total rings of power (known as the "lesser rings") are meant to come under the control of his secret One Ring, created with the express purpose of turning all of Middle-earth's most powerful people into his puppets. But in order to craft the most powerful object the world has ever seen (at least since the Silmarils, that is), Sauron would need a forge to match. No dark magic in all the land could compete with Mount Doom itself, the beating black heart of the evil land, and the location where the One Ring was forged.

You might remember a little trilogy of movies called "The Lord of the Rings" that depicted why this ring was so important in the first place. But long before, Sauron's scheme paid off as the rings allowed him to wage open war on all of Middle-earth. "The Rings of Power" has some time to go before plunging into this conflict to come, but the seeds have been planted and now we await the forging of the other rings of power.

"The Rings of Power" season 2 comes to Prime Video sometime in 2024.

Read this next: 13 Fantasy Shows Like The Lord Of The Rings: The Rings Of Power You Should Check Out

The post Breaking Down All The Rings of Power from Amazon's Lord of the Rings Series appeared first on /Film.

27 Apr 18:31

Five Common Mistakes People Make When Checking for Ticks

by Beth Skwarecki

We may earn a commission from links on this page.

As tick populations grow (thanks, climate change) and tick-borne diseases like Lyme become more widespread, tick checks have become routine for many of us. But do you really know what it means to “check yourself for ticks”? Chances are, you’re missing some important parts of the process.

You only need a tick check when you've been in the woods

Are you conscientious about tick checks when you're camping, but only when you're camping? Ticks live in more places than just the woods, and most parts of the U.S. are home to at least one tick species. Check these tick maps from the CDC to get a sense of whether they’re in your area and which tick species to look out for. Dog ticks are found just about everywhere. Some tick species are only found in the eastern half of the country, while Rocky Mountain ticks and western blacklegged ticks are generally found out west.

Ticks live in grassy, brushy, and wooded areas, the CDC notes. Growing up in Pennsylvania, I always thought of the woods and farm fields as the places you pick up ticks. But years later, I now know there are ticks in my own backyard, as well as parks and other areas that don’t fit the stereotype I had in my head. I’ll do a tick check whenever I’ve spent time near tall grass, leaf litter, woods, or brush—which includes pretty much anywhere I go in the summer. Don’t forget to check your kids for ticks, too.

Skipping the shower

If you think of a "tick check" as an isolated chore, it's easy to forget. But if you make sure to take a shower after you've been outdoors, it gives you an opportunity for a thorough check as you're undressing, and will possibly wash off ticks even if your check wasn't so thorough (or if you forgot to do it entirely). The CDC points out that taking a shower within two hours of getting home from an outdoor outing has been shown to reduce your chances of getting Lyme disease, and probably also reduces your chances of other tickborne diseases as well.

Ticks crawl around for a few hours before they find a place to attach, so there’s a good chance that unattached ticks will wash off during the shower, whether you see them or not. As a bonus, you also have several hours to wash off the oils from poison ivy before it triggers a rash. A shower is always on my to-do list after coming home from a trail run. The other benefit of taking a shower after you get home is that it gives you a chance to get naked—and that’s when the real tick check begins.

Missing critical areas of your body

The first place I always check is my lower legs. Ticks need to stay close to the ground while they’re waiting for a person to walk by, so you won’t find them climbing trees and dropping down from above—that’s a myth. They chill on the ground, then climb a stalk of grass. If they haven’t found a victim, they will return to the ground to rehydrate for a bit. That means they’ll usually contact your lower legs first, so if you just got back from your hike, check your ankles, shins, and knees right away.

Over the course of the next few hours, they’ll climb upward. It’s not uncommon to find ticks on your upper body, or even in your hair, if they've had enough time to climb. So check these harder-to-see spots, which I’ll list from bottom to top:

  • The backs of your knees

  • Between your legs (use a mirror...sorry!)

  • Inside your belly button

  • In your armpits

  • Behind your ears

  • In your hair

A mirror or a partner can help you to see those out-of-the-way places. If you have kids, check them over while you help them get ready for a shower, or when you change their diaper.

Not knowing what you're looking for

Look up the species of ticks that live in your area, and make sure you know how big they are and what they look like. Ticks grow as they go through their life cycle, with the smallest being about the size of a poppyseed. Adult ticks can be anywhere from the size of a sesame seed to the size of a corn kernel, depending on the species and whether they have fed.

Before ticks attach, they crawl around, and you might mistake them for other kinds of bugs (and vice versa). There are lots of little bugs you can pick up from outside that aren’t ticks. If you want to take an educated guess at whether the little guy you found is a tick, check the number of legs. Ticks are arachnids, so they have eight legs.

You may find an attached tick during your check—or, if you’re unlucky, sometime the next day after you should have done your check. An attached tick doesn’t usually hurt. You might just notice a little scab or mole where there wasn’t one before, and when you take a closer look at it, you discover it’s got legs. Ew. Go get the tweezers or your handy-dandy tick removal device. (I’m partial to the TickKey.)

Once a tick is done feeding, it will drop off. If you have a pet dog and don’t keep up with their flea and tick medication, you may occasionally find what looks like a gray or green corn kernel in the dog bed. That’s what this is. A tick that is not attached to you isn’t usually a health risk if you find it in your house; chances are, it will dry out and die. But just to be safe, you can launder any clothes or bedding in hot water and/or put them in the dryer on high. Next time, keep your pet up to date on tick control medication, and do those tick checks on everyone when you get home.

Not having a plan for what to do when you find a tick

If you find a tick crawling on you, that's easy—wash it off, brush it off (if you're outside), or squish it and throw it in the trash. But what if you find one that's already attached? That's when you have to know the right way to remove a tick.

Forget the blown-out matches, soap, or alcohol—you don't want to do anything that makes the tick release itself, since they'll vomit their stomach contents into your bloodstream, which worsens the risk of catching a tick-borne disease. Instead, pull the tick off your skin with fine-tipped tweezers, or with a specialized device like a TickKey or Tick Twister. I keep a TickKey in my bathroom at home, and bring another with me when I travel. You slip the little keyhole slot over the tick, and pull—something even most squeamish folks can probably handle.

27 Apr 18:26

Zelda: Breath of the Wild Switch icons are back for a few weeks

by Chris Carter

The Legend of Zelda logo is a pretty good one

Nintendo has been adding various icons as bonuses for My Nintendo users, which range all across their suite of first party games (and beyond). Whenever a big game drops you can bet Nintendo will peddle some icons for it: and in case you missed the last Zelda: Breath of the Wild round, there's another one on the way.

Announced by Nintendo, a "second chance" run of Zelda: Breath of the Wild icons are available now. The first wave is scheduled to go away (back into the vault) on May 3, 2023, and the second wave will kick off on that same day through May 10. Out of all these, the Guardian one is fairly unique, and the general "Zelda" logo will slot in nicely for a lot of folks for years to come: even if Breath of the Wild fades into memory.

As a reminder, if you want physical rewards, you can find our full Platinum Point guide here, which has been updated with details on weekly missions: bookmark it for when you need quick points for a reward. A handful of points is incredibly easy to get, as that’s basically just 15 minutes with Super Mario Run, or a quick sign-on to the 3DS or Wii U 3Shop. Also remember that any shipments are bundled together, so you can pay a flat rate for multiple items instead of paying it each time. Just know that items go out of stock on My Nintendo frequently, and some are never restocked.

[caption id="attachment_375774" align="alignnone" width="640"] Image via Nintendo[/caption]

Second chance Zelda: Breath of the Wild icons Wave 1 (April 26-May 3, 2023):

  • Zelda
  • Link (attacking pose)
  • Link (looking pose)
  • Guardian

Second chance Zelda: Breath of the Wild icons Wave 2 (May 3-May 10, 2023):

  • Zelda
  • Link (bow)
  • Zelda logo
  • Link (with horse)

The post Zelda: Breath of the Wild Switch icons are back for a few weeks appeared first on Destructoid.

27 Apr 18:20

Nintendo’s Copyright Strikes Push Away Its Biggest Fans

by Will Bedingfield
Earlier this month the company sought to remove videos of a YouTuber playing a new Zelda mod. It’s a move that goes against the spirit of interactivity that fuels the medium.
27 Apr 18:19

7 Vitamins That Could Promote Hair Growth and Give You Long Locks

by Sean Jackson
These vitamins have the potential to promote hair growth and combat hair loss.
27 Apr 17:34

Chinese Cyberspies Delivered Malware via Legitimate Software Updates

by Ionut Arghire

Chinese APT Evasive Panda has been observed targeting local members of an international NGO with the MgBot backdoor, delivered via legitimate software updates.

The post Chinese Cyberspies Delivered Malware via Legitimate Software Updates appeared first on SecurityWeek.

27 Apr 11:00

Evil Dead gets a Game of the Year edition

by ncarter@gamingnexus.com

Evil Dead: The Game apparently won Game of the Year from uhh... somewhere I guess because it's getting a new Game of the Year edition.

The GOTY edition comes with the base game plus a ton of DLC including skins, survivors, demons, and items that were added after launch. The GOTY edition also includes a new "Who's Your Daddy Bundle" which includes a new survivor, demon and outfit. 

Evil Dead: The Game - Game of the Year Edition is available now for PS4, PS5, Xbox One, Series X and PC.

27 Apr 10:59

'Game Changer' Method Lets Scientists Peer Into -- and Fly Through -- Mouse Bodies

by BeauHD
sciencehabit shares a report from Science Magazine: A research team has turned the bodies of dead mice into vivid 3D maps of anatomy, with tissues, nerves, and vessels highlighted in color. The technique, which renders the corpses transparent and then exposes them to fluorescent antibodies that label distinct cell types, could help everything from drug development to understanding the spread of cancer, its creators and other scientists say. The developers, at the Helmholtz Munich research institute, call their technique wildDISCO -- wild because it can work on any "wild type," or normal, mice, and DISCO for 3D imaging of solvent-cleared organs. Building on their previous success at making mouse bodies transparent, the new technique removes cholesterol from the bodies so that a vast array of existing antibodies can penetrate deep into the animals. "wildDISCO is a game changer -- it allows us to see the hidden highways and byways in the body," says Muzlifah Haniffa, a dermatologist and immunologist at the Wellcome Sanger Institute and Newcastle University's Biosciences Institute who was not involved in the research. The method should let scientists map a mouse at the cellular level and explore previously hidden links between tissues, like neural connections between organs, says neuroscientist Ali Erturk, director of Helmholtz Munich, who led the work, posted recently as a preprint. His group in Germany has already posted eye-catching videos of "flying" through the 3D anatomy of a mouse with different tissues labeled.

Read more of this story at Slashdot.

27 Apr 02:40

Unofficial patch v1.08

Unofficial patch v1.08
This is the latest unofficial patch for Rune: Halls of Valhalla. This patch contains some bug fixes and crash fixes, as well as redirection of in-game downloads. As with any unofficial ptach, install this at your own risk. Rune: Halls of Valhalla Version 1.08 Client LIMITATION OF LIABILITY: TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT WILL CREATORS OR ITS SUPPLIERS OR RESELLER
27 Apr 02:35

EvilExtractor Network Forensics

by Erik Hjelmvik

I analyzed a PCAP file from a sandbox execution of the Evil Extractor stealer malware earlier today. This stealer collects credentials and files of interest from the victim’s computer and exfiltrates them to an FTP server. It is designed to autonomously collect and exfiltrate data rather than receiving commands from an operator through a command-and-control channel. The EvilExtractor creators market this feature as a “golden bullet”.

Real hackers don’t use reverse shells right? If you have only one bullet, would you waste with reverse shell? Try Evil Extractor to have golden bullet.

I downloaded the Evil Extractor capture file from Triage to a Windows Sandbox environment, to avoid accidentally infecting my computer when extracting artifacts from the PCAP. I then opened it up in the free version of NetworkMiner.

NetworkMiner shows that after checking its public IP on ipinfo.io EvilExtractor makes an unencrypted HTTP connection to a web server on 193.42.33.232 to download KK2023.zip. This zip archive contains a file called “Lst.exe” which is used to steal browser data, cookies and credentials according to Fortinet.

EvilExtractor HTTP Downloads
Image: Files downloaded from TCP port 80

Twenty seconds later an FTP connection is established to 89.116.53.55 on TCP port 21. The username and password used to authenticate to the FTP server was “u999382941” and “Test1234”.

EvilExtractor FTP CredentialsEvilExtractor FTP Requests

On the FTP server EvilExtractor creates a directory named after the country and hostname of the victim's PC, such as “(Sweden)DESKTOP-VV03LJ”, in which it creates the following three sub directories:

  • 1-Password-Cookies
  • 2-Credentials
  • 3-Files
EvilExtractor FTP exfil of cookies and credentials

After uploading browser cookies, browser history and cached passwords from Chrome, Firefox and Edge to the “1-Password-Cookies” directory EvilExtractor sends a file called “Credentials.txt” to the “2-Credentials” directory. The contents of this text file looks something like this:

Public IP: [redacted]
Location: [lat],[long]
Computer Name: [redacted]
Username: Admin
RAM: 4 GB
OS Name: Microsoft Windows 10 Pro
OS Bit: 64-bit
Keyboard Language: en-US
GPU: [redacted]
CPU: Intel [redacted]
MAC Address: [redacted]
Extracted WIFI: [redacted]

The stealer also exfiltrates files with mpeg, docx, jpeg, pptx, zip, avi and rar extensions from the victim PC to the “3-Files” directory on the FTP server. The directory structure of the victim’s PC is maintained on the FTP server, so that files from the victim's desktop end up in a folder called “Desktop” on the FTP server.

EvilExtractor FTP exfil of files

The stealer later downloaded a keylogger module (Confirm.zip) and a webcam module (MnMs.zip), but no additional data was exfiltrated from this particular victim PC after that point.

IOC List

  • Web server: 193.42.33.232:80
  • FTP server: 89.116.53.55:21
  • EvilExtractor: 9650ac3a9de8d51fddab092c7956bdae
  • KK2023.zip: f07b919ff71fb33ee0f77e9e02c5445b
  • Lst.exe: 163d4e2d75f8ce6c838bab888bf9629c
  • Confirm.zip: 30532a6121cb33afc04eea2b8dcea461
  • Confirm.exe: 0c18c4669e7ca7e4d21974ddcd24fdca
  • MnMs.zip: bda0bda512d3e2a81fc9e4cf393091eb
  • MnMs.exe: fb970c4367609860c2e5b17737a9f460

Users with an account on Triage can download the analyzed PCAP file from here: https://tria.ge/230424-vv9wvsfb2v/behavioral2

Update 2023-04-27

Jane tweeted a link to an execution of this same sample on ANY.RUN. This execution showed very similar results as the one on Triage, but with an interesting twist. Not only did the ANY.RUN execution exfiltrate images and documents from the Desktop and Downloads folders, it also exfiltrated “vv9wvsfb2v_pw_infected.zip”, which contained the EvilExtractor EXE file that was being run!

EvilExtractor FTP exfil of files

The PCAP from the ANY.RUN execution can be downloaded from here: https://app.any.run/tasks/43a11a79-4d1f-406c-86d7-158efb5ede01/

27 Apr 02:28

All Games Becoming Live Service Games Would Be Boring, Sony’s Shuhei Yoshida Says

by Francesco De Meo

Shuhei Yoshida

A future where all games would be live service games would be a boring future, according to former Sony Interactive Entertainment Worldwide Studios president Shuhei Yoshida.

Speaking with The Guardian in a lengthy interview that addresses a variety of other topics, one of the most recognizable faces from Sony Interactive Entertainment spoke about live service games, highlighting how he wishes the industry would continue to support and chase creative ideas and people who work on such ideas, as a future where games would become all the same, or live service games would be a bit boring for him.

While this statement may sound strange, coming from someone who's working in a company that has been increasing its effort in creating live service titles, it really isn't, considering Shuhei Yoshida was leading Sony Interactive Entertainment Worldwide Studios when Journey released, a very creative and unusual game which spearheaded a new wave of indie titles. In the interview with The Guardian, Shuhei Yoshida recalls how the launch of the game is one of the highlights of his career.

Creativity is still going to make a difference in the future of the video games industry, even in the era of AI-powered tools, according to Shuhei Yoshida. AI can produce some very strange things, he said, but these tools must be used properly. As such, AI will change the nature of learning for game developers, making it more efficient and allowing for more beautiful things to be made, possibly making creativity even more important in a future where a developer does not even need to learn how to code and program.

While many are the very creative games that get released, not many of them manage to achieve the same level of popularity as tried and true franchises and select live service games, so Shuhei Yoshida's feelings on the future of the industry are definitely warranted. Technology advancements will allow for even more creative titles, but if the market will actually embrace them enough to prevent the live service model from being the only feasible release model, only time will tell.

Written by Francesco De Meo
27 Apr 02:22

Healthy security habits to fight credential breaches: Cyberattack Series

Fifty percent of Microsoft cybersecurity recovery engagements relate to ransomware,1 and 61 percent of all breaches involve credentials.2 In this second report in our ongoing Cyberattack Series, we look at the steps taken to discover, understand, and respond to a push-bombing request that targeted a legitimate user, allowing an attacker to authenticate and register their own mobile device.

Credential-based attacks begin with the process of stealing or obtaining credentials illegitimately. Often attackers target individuals who they believe have the credentials they need, then conduct social and dark web research on them. Phishing emails and websites created to target corporate targets only need to succeed once to gain credentials that can be sold to and shared with other bad actors.

Push-bombing is when an attacker uses a bot or script to trigger multiple access attempts with stolen or leaked credentials. The attempts trigger a rush of push notifications to the target user’s device, which should be denied. But multiple attempts can confuse a target and cause them to mistakenly allow authentication. Other times, multifactor authentication fatigue can weigh on the target, causing them to believe the access attempts are legitimate. Just one mistaken “allow” is all it takes for an attacker to gain access to an organization’s applications, networks, or files.

On average, people receive between 60 and 80 push notifications each day, with some of us viewing more than 200.3 The time it takes to swipe, tap, flag, click, save, and close every ding, buzz, pop-up, text, and tab takes a toll. Researchers believe the onslaught of notifications is causing us to get tired faster and lose focus, leaving us especially prone to distraction as the day wears on.4 This is what attackers count on. If an attacker gains the credentials to operate like a registered, legitimate user, identifying the intrusion and tracing their possible paths of destruction becomes paramount.

Late last year, a large enterprise customer asked Microsoft Incident Response to investigate an incursion into their on-premises Active Directory environment. Due to the risk of ongoing threats and the need for continued vigilance, the organization and attacker will be kept anonymous for this incident, and we will refer to it as “the inCREDible attack.” This credential-based incident highlights the critical need for establishing healthy habits in our security maintenance processes to combat the regular, repeated, and overwhelming credential attacks faced by today’s organizations.

In this report, we examine the factors contributing to the threat actor’s initial incursion and explore what could have happened without prompt, tactical mitigation efforts. Then we detail the required workstreams, recommended timing, and activities involved with regaining control and establishing a plan going forward. We’ll also explore four core steps customers can take to “eat their vegetables” and establish healthy habits that help minimize the risk of attack. And then we share five elements of a defense-in-depth approach that can help businesses maintain a robust defense against ransomware attacks.

Many attacks can be prevented—or at least made more difficult—through the implementation and maintenance of basic security controls. Organizations that “eat their vegetables” can strengthen their cybersecurity defenses and better protect against attacks. That means establishing a solid inventory of all technology assets, continually patching operating systems and software, and implementing comprehensive centralized log collection—all while following a well-defined retention policy. Read the report to go deeper into the details of the push-bombing attack, including the response activity, and lessons that other organizations can learn from this inCREDible case.

What is the Cyberattack Series?

With this Cyberattack Series, customers will discover how Microsoft incident responders investigate unique and notable exploits. For each attack story, we will share:

  • How the attack happened
  • How the breach was discovered
  • Microsoft’s investigation and eviction of the threat actor
  • Strategies to avoid similar attacks

Read the first blog in the Cyberattack Series, Solving one of NOBELIUM’s most novel attacks.

Learn more

To learn more about Microsoft Incident Response, visit our website or reach out to your Microsoft account manager or Premier Support contact.

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and Twitter (@MSFTSecurity) for the latest news and updates on cybersecurity.


1Microsoft Digital Defense Report 2022, Microsoft. 2022.

22022 Data Breach Investigation Report, Verizon. 2022.

3Batching smartphone notifications can improve well-being, Nicholas Fitz, et al. December 2019.

4Phone Notifications are Messing with your Brain, Molly Glick. April 29, 2022.

The post Healthy security habits to fight credential breaches: Cyberattack Series appeared first on Microsoft Security Blog.

27 Apr 02:15

Browser Security Survey: 87% of SaaS Adopters Exposed to Browser-borne Attacks

by info@thehackernews.com (The Hacker News)
The browser serves as the primary interface between the on-premises environment, the cloud, and the web in the modern enterprise. Therefore, the browser is also exposed to multiple types of cyber threats and operational risks.  In light of this significant challenge, how are CISOs responding? LayerX, Browser Security platform provider, has polled more than 150 CISOs across multiple verticals and
27 Apr 02:14

Red Dead Redemption 2’s great grandparent is a must-play

by Ed Smith
Red Dead Redemption 2’s great grandparent is a must-play

Red Dead Redemption 2 remains the watermark for western games, and for the abilities of Rockstar Games itself. But it's the product of a storied history. You can trace it back to the original Red Dead Redemption, the early 3D Grand Theft Autos like GTA 3, and even other cowboy games like Call of Juarez. Perhaps the biggest inspiration behind Red Dead Redemption 2, however - the game that first proved it was all possible - is Gun. Developed by Tony Hawk’s Pro Skater studio Neversoft, you can experience this vital piece of gaming history yourself, and for cheap, thanks to a new GOG sale.

MORE FROM PCGAMESN: The best story games on PC, Best western games, Best sandbox games
27 Apr 02:05

World-building with Scythe Dev Team’s Jon of the Shred

by Zoey Handley

Scythe Dev Team Header

I wish there was a hole I could just crawl into and die

One of the titles that had the greatest impact on my consciousness in the past few years was Happy’s Humble Burger Farm. What seemed like a novel concept on the surface turned out to have a lot of beef underneath. Centering a horror game around cooking is engrossing enough, but it then gets tied up in interesting ways and dunked into an unconventional world full of mystery and horror. The narrative tells the story of trying to escape from an obvious simulation, but the world in which this simulation exists is an entity worth exploring on its own.

Immediately after stepping into the game, you’re hit from all sides with flavor lore. The TV plays an almost unending list of shows, the coffee table prominently displays a book on the history of the Barnyard Buds, and a Walkman sits nearby to fill your ears with radio skits that inject fat into the world around you. None of it is necessary to understand Happy’s Humble Burger Farm’s main plot, but actually digging through it is a trip on its own.

It’s obvious someone really loves the lore and creating it because there’s a lot more of it than a five-ish hour game really needs. That’s because the Scythe Saga Universe is a sprawling concept originally dreamed up by Jon of the Shred (Jon Reilly) back in 2005. I wanted to get to know more about where this came from, so I got in touch and talked shop. Now I’m sharing that shop with you.

[caption id="attachment_375462" align="alignnone" width="640"]Scythe Dev Team Happy's Humble Burger Barn Screenshot by Destructoid[/caption]

Beef underneath

The Scythe Saga Universe didn’t actually originate as an idea for a video game. It was a world to base a rock opera in. “I’ve been developing all of this stuff personally since 2005 when I was just a teenager developing a rock opera,” Jon told me. “I kinda wanted all my music to be set in its own world. That ballooned out into a record label in 2012. My buddy Kaleb joined, and when he joined, he brought art and music of his own to the table. It was me and him that went forward and started a dev team with his childhood friend Blake, but it was the three of us making games that really made it a universe. Before that, it was just concept albums, like what if Dark Side of the Moon had 90 sequels.”

The short-form horror genre has taken off recently, carving a niche within a niche. Most of the time, the inspiration comes from horror movies themselves. Chillah’s Art stays in line with Japanese horror, while Puppet Combo loves their grotesque ‘80s slashers. While there is some of that inspiration, especially in Scythe’s Northbury Grove games, it’s less identifiable in Happy’s Humble Burger Farm.

“A really good comparison point is Mortal Kombat because of how they take so many different genres, and they manage to wrap it into their own unique take on how all this stuff could co-exist.” With mystical monks, sorcerors, movie stars, monsters, and special ops, the Mortal Kombat series does manage to juggle a lot of different genres. “I just really like how they’re able to connect so many different types of stuff that I love and create their own universe for it. It all feels earned.”

With slasher killers, evil corporations, and even a defined solar system to explore, the Scythe mythos already offers opportunity to a lot of different interests. For the DreadX Collection, Scythe Dev Team provided Carthanc, a game about futuristic archeology. It was set thousands of years after another game of theirs, To the End of Days, which depicted the end of the titular world, Carthanc. This is depicted as a completely different planet in the same solar system that Happy’s Humble Burger Farm takes place on. In HHBF, and even as far back as Northbury Grove, you can find mention of it within diagrams of the solar system.

[caption id="attachment_375464" align="alignnone" width="640"]Happy's Humble Burger Farm Paragon Screenshot by Destructoid[/caption]

Goldeneye meets Twisted Metal

Despite the grandness and depth of the Scythe universe, you don’t need to have knowledge of it to understand the plot of the individual games. Happy’s Humble Burger Farm is about escaping a simulation. What happened in the earlier title, Happy’s Humble Burger Barn, may be directly connected, but the important details are given to you, and playing the previous game just means you have a wider insight into what’s happening. “I like to reward people with that deep lore if they’re paying attention, but it’s not necessary to fully enjoy the experience. They’re all standalone as well.

“The universe was so expansive that, by the time we started making video games, any genre we wanted to cover already existed in a pocket of this universe.” According to Mr. Of the Shred, Happy’s Humble Burger Barn started off as a first-person vehicular combat game. “Goldeneye meets Twisted Metal.” Which somehow morphed into “a drive-thru at a restaurant.” After the gameplay, Kaleb and Blake brought Jon in to “tie it into the Universe and make it scary.”

In many ways, it sounds a bit like creating a Dungeons and Dragons campaign, where there are certain standards and places to draw from for whatever story you want to tell. The big difference here is that Scythe Dev Team is drawing from lore that they themselves created.

[caption id="attachment_375463" align="alignnone" width="640"]Scythe Dev Team Carthanc Screenshot by Destructoid[/caption]

Sticking with you

In terms of inspiration, Jon doesn’t turn to video games. “For my writing, my music, my sound design, I’m more inspired by film.” He specifically mentions director John Carpenter as a big draw. Despite that, Scythe Dev Team tries to invoke the sense of exploration found in games like The Legend of Zelda: Ocarina of Time, where there’s a sense of wonderment at what’s unfolding around you.

Jon follows through to the extent that he doesn’t play other short-form indie developments like those from Puppet Combo. “I don’t go out of my way to play these games ‘cause I don’t want to get inspiration from them or take their ideas inspiration from them.”

I brought up the similarities between Happy’s Humble Burger Farm and Five Nights at Freddy’s. Notably, they’re set in restaurants where you’re harrowed by mascots. I asked if he played them. “What’s funny is no,” he said. “I never played any of them. I don’t know if anyone else [at Scythe Dev Team] did. When Tinybuild picked us up for Burger Farm, they told us, ‘You should use these mascots; why wouldn’t you?’ and we were, like, ‘Yeah, okay, if you’re telling us it’s a good idea, we’re going to go with it.’”

“Kaleb came up with Happy, and I came up with the rest of the Barnyard Buds based on that. My inspiration was The Animals of Farthing Wood, which is some old cartoon where the animals die viciously. It’s like Walking Dead meets Winnie the Pooh. It’s really strange.” He went on to mention Plague Dogs, Watership Down, Bambi, Land Before Time, Lion King. “They all had dark subject matter that would make them stick with you.”

“That was the Barnyard Buds. The whole joke was that meets McDonald’s.”

[caption id="attachment_375471" align="alignnone" width="640"]Toe your best friend Screenshot by Destructoid[/caption]

The Scythian Future

Beyond the games, Scythe Dev Team does a lot of augmented reality game stuff. There are numerous in-character sites related to the universe, including Maverick Cooper News and Justice for Toe. They’re currently leading into their next game, Project Meganet, which is to be a VR title. To help with this, they’re gradually releasing microgames in a series such as Love at First Squeak.

I don’t have VR, so that kind of sucks for me. However, it’s not going to be the end of the Scythe sage. “The whole universe – the games – will all eventually come to a head, and everything will connect in ways that people don’t expect,” Jon explains. “There is a storyline that we’re following for the greater universe that we’ve alluded to so much, but no one would possibly know it’s going to happen until we do the big twist to contextualize all the hints we’ve left.”

Hopefully, we don’t get there too quickly. For now, you can get Happy’s Humble Burger Farm wherever fine video games are sold, but for some of Scythe Dev Team’s earlier titles, you’ll need to grab them off of itch.io.

The post World-building with Scythe Dev Team’s Jon of the Shred appeared first on Destructoid.

26 Apr 20:03

Meet the People Who Use 'Notion' To Plan Their Whole Lives

by BeauHD
An anonymous reader quotes a report from MIT Technology Review: Joshua Bergen is a very productive person. His secret is the workspace app Notion. Bergen, a product manager living in Vancouver, uses it to plan trips abroad in meticulous detail, with notes and timelines. He uses it to curate lists of the movies and TV shows he's watched, and records what he thought of them. It's also a handy way to keep tabs on his 3D-printing projects, map snowboarding runs, and quickly update his cute list of the funny things his kid has said. It might sound strange, but Bergen is one of a growing number of people using Notion, software intended for work, to organize their personal lives. They're using it in a myriad of different ways, from tracking their meditation habits and weekly schedules to logging their water intake and sharing grocery lists. So why has a platform built to accommodate "better, faster work" struck such a chord when there are countless other planning apps out there? Part of the reason Notion has such a devoted fan base is its flexibility. At its heart, Notion is designed to combine the various programs a business might use for functions like HR, sales, and product planning in a single hub. It uses simple templates that let users add or remove features, and remote workers can easily collaborate on notes, databases, calendars, and project boards. This high level of customizability sets Notion apart from other work apps. It's also what's made it so popular among people looking to map out their free time. It started to gain traction around 2018 in YouTube's thriving productivity subculture, where videos of fans swapping time management tips and guides to organizing their lives regularly rack up millions of views. Since then, its following has snowballed. More than 275,000 people have joined a dedicated subreddit, tens of thousands of users share free page templates in private Facebook groups, and TikTok videos advising viewers on how to make their Notion pages look pretty have been watched hundreds of millions of times. "You don't have to change your habits to how rigid software is. The software will change how your mind works," says Akshay Kothari, Notion's cofounder and chief operating officer. "I think that's actually been a big reason why you see so much love in the community: because people feel like the things they build are theirs." While platforms like Notion are great for people who enjoy feeling organized, spending too much time optimizing and organizing our lives can be counterproductive when we prioritize creating to-do lists over completing the actual tasks on them, says Gabriele Oettingen, a psychology professor at New York University. It's a phenomenon known as the planning fallacy. Using Notion to track whether you're drinking enough water or going jogging, or using it to plan assignments, doesn't necessarily mean you're actually getting those things done. "In a way, Notion might help me to get structure, but it might not work to get me going," she says.

Read more of this story at Slashdot.

26 Apr 14:45

A Mandoline Slicer Will Make You a Better Cook

by Claire Lower

Mandoline slicers have a scary reputation. And yes, they’re sharp as heck, and can do major damage if you don’t respect the blade. But inviting one into your kitchen is one of the easiest ways to cut down on prep time and improve your cooking.

Read more...

26 Apr 14:40

When Subby flew into Singapore in 2002, he was quite amused that the boarding pass had the words 'Death to drug traffickers under Singapore law' on the back. Turns out they really, really weren't kidding [Scary]

26 Apr 02:00

Bulgaria Approves Draft Law That Turns Pirate Site Operators Into Criminals

by BeauHD
A draft law that aims to criminalize and prosecute those who "create conditions for online piracy" has been approved by Bulgaria's Council of Ministers. The proposed amendments are Bulgaria's response to heavy criticism from the United States, most publicly via the USTR's Special 301 Reports. It's hoped that prison sentences of up to six years will send a deterrent message. TorrentFreak reports: Last week the Council of Ministers approved draft amendments to the Criminal Code that aim to protect authors, rightsholders, and state revenue. "Crimes against intellectual property should be perceived as acts with a high degree of public danger, not only considering the rights and interests of the individual author, which they affect, but also considering the financial losses for the holders of these rights, which also affects the revenues in the state budget," the explanatory notes read. The stated aim of the bill is to solve identified weaknesses by upgrading substantive law to counter computer-related crimes against intellectual property. The text references those who "build or maintain" an information system or provide a service to the information society for the purpose of committing crimes. The notes offer further clarification. "The bill aims to prosecute those who create conditions for online piracy -- for example, by building and maintaining torrent tracker sites, web platforms, chat groups in online communication applications for the online exchange of pirated content, and any other activities that may fall within the definition of 'information society service' within the meaning of the Electronic Commerce Act (pdf) and which are carried out with the specified criminal purpose." The Bulgarian government notes that the amendments are part of its response to criticism in the USTR's Special 301 Report. [When countries are placed on the USTR's 'Watch List' for failing to combat piracy, most can expect years of pressure punctuated by annual Special 301 Reports declaring more needs to be done. Bulgaria was on the Watch List in 2015 when the USTR reported "incremental progress" in the country's ability to tackle intellectual property infringement, albeit nowhere near enough to counter unsatisfactory prosecution rates. In 2018 the United States softened its position toward Bulgaria, removing it from the Watch List on the basis that the government would probably deliver.] The fact that Bulgaria has been absent from the 'Watch List' for the last five years is down to "specific commitments" made by the authorities, with progress being monitored closely by the United States in respect of Bulgaria's future status. The draft approved by the Council of Ministers last week envisions sentences of up to six years imprisonment and a fine of up to $5,600. According to the draft, there is no intent to prosecute individual users who simply consume pirated content.

Read more of this story at Slashdot.

26 Apr 01:21

Microsoft Edge is Leaking the Sites You Visit To Bing

by msmash
Microsoft's Edge browser appears to be sending URLs you visit to its Bing API website. Reddit users first spotted the privacy issues with Edge last week, noticing that the latest version of Microsoft Edge sends a request to bingapis.com with the full URL of nearly every page you navigate to. Microsoft tells The Verge it's investigating the reports. From a report: "Searching for references to this URL give very few results, no documentation on this feature at all," said hackermchackface, the Reddit user who first discovered the issue. While Reddit users weren't able to uncover why Microsoft Edge is sending the URLs you visit to its Bing API site, we asked Rafael Rivera, a software engineer and one of the developers behind EarTrumpet, to investigate, and he discovered it's part of a poorly implemented new feature in Edge. "Microsoft Edge now has a creator follow feature that is enabled by default," says Rivera in a conversation with The Verge. "It appears the intent was to notify Bing when you're on certain pages, such as YouTube, The Verge, and Reddit. But it doesn't appear to be working correctly, instead sending nearly every domain you visit to Bing."

Read more of this story at Slashdot.

26 Apr 01:21

ASUS Issues Statement on Ryzen 7000X3D Processor Issues, Possible Voltage Issues with AMD EXPO

by Gavin Bonshor

Yesterday we reported that MSI announced a wave of firmware updates designed to address and alleviate potential issues with users on AM5 using AMD's Ryzen 7000X3D processors with 3D V-Cache. One of the main changes with MSI's latest UEFI firmware for AM5 included voltage restrictions when using Ryzen 7000X3D series CPUs so that these chips couldn't be overvolted as the V-Cache packaging is somewhat sensitive to additional power.

Further to MSI's announcement, ASUS has released a statement to experienced engineer and extreme overclocker Roman 'Der8auer' Hartung, which addresses the potential issue with using AMD's EXPO memory profiles in conjunction with the Ryzen 7000X3D series chips. One of the key elements that seemingly surrounds the problem is the use of AMD's EXPO memory overclocking profiles.

ASUS's Director of Global Product Marketing and Technical Marketing, Rajinder Gill, said in a statement to Der8auer, "The EFI updates posted on Friday contain some dedicated thermal monitoring mechanisms we've implemented to help protect the boards and CPUs. We removed older BIOSes for that reason and also because manual Vcore control was available on previous builds." Rajinder also said, "We're also working with AMD on defining new rules for AMD Expo and SoC voltage. We'll issue new updates for that ASAP. Please bear with us."


ASUS ROG Crosshair X670E Hero AM5 Motherboard for AMD Ryzen 7000 Series CPUs

Looking at the narrative of the statement provided to Der8uaer from Rajinder, we can confirm that ASUS has indeed removed older iterations of its firmware for its AM5 motherboards. Looking at the EMEA side of things, at the time of writing, the latest firmware update to be posted on the ASUS product pages is dated 04/21/2023, which indicates ASUS recently updated the firmware, but the update isn't the latest one in question.


Roman 'Der8auer' Hartung's Ryzen 9 7900X also has a bulge.

The one thing these issues have in common is that AMD's EXPO memory profiles have been applied, claims Roman 'Der8auer' Hartung, and even highlighted that his Ryzen 9 7900X processor also fell foul the the 'bulging issue.' This is particularly interesting as this isn't an X3D series chip with 3D V-Cache, although we're not aware of any other reports of non-X3D Ryzen 7000 chips being affected at this time.

Enabling EXPO memory profiles on Ryzen 7000 processors does several things to the processor that pushes it beyond the technical specification of the chip. Chief among these is raising the SoC voltage and some other primary voltages, such as VDDIO, which are used to feed the IOD. Like any ASIC, there are limits to how high voltages can be safely pushed, and this is one theory behind the cause of the recent run of damaged Ryzen reports. Though how this might be connected to the issue being centered around Ryzen X3D chips – where the voltage-sensitive V-Cache is on the CCDs and their separate voltage plane – is unclear at this time.

In any case, this does underscore why AMD's EXPO memory overclocking profiles void the warranty on these chips, as there's more to EXPO than just ramping up memory frequencies and applying more voltage to the DRAM itself.

Further to Rajinder's statement given to Der8auer, ASUS's Senior Technical Marketing Manager, Juan Jose Guerrero, posted the following statement on Twitter Tuesday afternoon:

"Several AMD Ryzen 7000X3D owners have reported CPU and motherboard failures. We acknowledge the incidents/issues and have been communicating with AMD to analyze the possible causes. We have also contacted affected users to provide support and collect additional information.

Ryzen 7000X3D processors do not allow for CPU ratio or CPU core voltage tuning (CPU overclocking) but do allow for performance tuning and DRAM overclocking via PBO2 and EXPO memory. To support EXPO and/or memory overclocking at DDR5-6000 and beyond, SoC voltage has to be sufficiently increased to ensure compatibility and stability. The amount of voltage required varies between CPU samples. Some processors are more sensitive to overvoltage than others, and some are capable at running higher memory frequencies without needing as much voltage.

As confirmed with AMD, any intentional manipulation of these settings can damage the processor, socket, and motherboard. To mitigate this, we have been working with AMD to define new rules for EXPO memory and SoC voltage. To help protect the CPU and motherboard, we are issuing new EFI updates to limit the maximum available SoC voltage to 1.3V.

We recommend updating your motherboard UEFI BIOS to the latest release. Please also ensure the CPU is cooled adequately. Our recommendation is to use at least a 240mm AIO liquid cooler or high-performance air cooler. If you have been affected, please do not hesitate to contact ASUS support for your region.

As we mentioned in our article yesterday about MSI addressing CPU voltage on their own AM5 motherboards, vendors are looking to address any more potential issues, following a small-but-concerning number of reports circulating on Reddit that their Ryzen 7000X3D processors are burning out and killing the motherboard in the process. ASUS's statement and the summary of the firmware on the official product page indicate that ASUS is worried about SoC voltage, and as such, the new firmware locks it down to 1.30 V. Which ASUS states is to 'protect the CPU and motherboard.' 


Screenshot of the ROG Crosshair X670E Extreme BIOS/Support page on the official product page (China).

On the Chinese product page for the ROG Crosshair X670E Extreme, the firmware has been updated as of today (at the time of writing) to 04/25/2023, and the firmware version in question (1302) does seemingly address the SoC voltage.

Further to ASUS's and MSI's statements, AMD has officially responded with a statement of their own:

It reads, "We are aware of a limited number of reports online claiming that excess voltage while overclocking may have damaged the motherboard socket and pin pads. We are actively investigating the situation and are working with our ODM partners to ensure voltages applied to Ryzen 7000X3D CPUs via motherboard BIOS settings are within product specifications. Anyone whose CPU may have been impacted by this issue should contact AMD customer support."

Of course, these issues of Ryzen 7000X3D series processors burning out aren't just limited to those using MSI and ASUS motherboards. Since the initial reports, users have reported additional issues on various models and brands across threads on Reddit. The potential for damage is one of the primary reasons AMD locked down the X3D series processors so that users couldn't manually overclock them. Even the first iteration, the Ryzen 7 5800X3D, was also locked down.

One thing remains clear: AMD and its motherboard partners are now officially investigating the matter, and users with affected Ryzen 7000 CPUs are advised to contact AMD customer support directly.

26 Apr 01:18

Xbox Hardware Sales Down a Third Year-on-Year, Xbox Game Pass Sees Only Minor Growth

by Nathan Birch

Microsoft Xbox Series X and S Next-Gen

Microsoft has released their earnings for the quarter ending March 31, 2023 (their fiscal year runs from July 1 until the end of June the next year) and, overall, it was a good quarter for the company. Revenue for the quarter was $52.9 billion, up 7 percent compared to the same quarter last year. Unfortunately for Xbox boosters, the gaming division was not one of the standout parts of the company. In fact, some of the figures posted were downright concerning.

In Q3 2023, Xbox hardware revenue (almost entirely derived from Xbox Series X/S at this point) was down a whopping 30 percent year-on-year. That’s a rather startling figure considering sales of the rival PS5 are on fire right now, with Sony setting new sales records seemingly every month. The conventional wisdom is that a high tide lifts all boats, but apparently that’s not the case with the Xbox Series X/S. Now that folks can more easily buy a PS5 it seems they’re not interested in picking up an Xbox Series X/S as an alternative.

Meanwhile, on the games front, Xbox content and services was up slightly (3 percent) mostly driven by Xbox Game Pass subscriptions. That may sound like a positive, and it is to a degree, but such a slim increase can’t be the kind of growth Microsoft is looking for from Game Pass considering how many eggs they’ve put in this basket. This past quarter saw the release of GoldenEye 007 and the shadow-launch of the acclaimed exclusive Hi-Fi Rush, but apparently, those games’ effect on subscription revenue wasn’t huge. We already know Game Pass badly missed subscriber targets in fiscal year 2022 and it seems the service may be on track to do the same in FY2023.

Microsoft is currently trying to get their proposed acquisition of Call of Duty publisher Activision Blizzard past regulators. If they can achieve that, their gaming fortunes will look quite different, but for now, they seem to be struggling to put the pieces together.

This current quarter (Q4 2023) will see the release of some major Xbox published titles, including Minecraft Legends and Redfall, so hopefully, Microsoft’s next earnings report will be a better one for the gaming division. Microsoft CFO Amy Hood provided an optimistic Q4 outlook during Microsoft's earning call, predicting "mid-to-high single-digit growth" in Xbox revenue year-on-year due to third and first-party releases and Game Pass. Whether that comes to pass, remains to be seen.

What are your thoughts on the latest results from Xbox? Is there anything Microsoft can do to spur Xbox Series X/S sales? Is Game Pass going to continue to grow or remain more-or-less stalled out where it is?

Written by Nathan Birch
26 Apr 01:12

Yellowjackets Sophie Nelisse Accidently Took Jackie's Ear Home With Her

by BJ Colangelo

This article contains spoilers for "Yellowjackets."Even if you've never watched a single second of Showtime's hit series "Yellowjackets," you probably know that the show deals with a high school girl's soccer team stranded in the wilderness and a whole lot of cannibalism. Maybe it's because I'm a Sicko™ who watched "Cannibal Holocaust" a little too young, but "Yellowjackets" has currently featured a pretty acceptable amount of cannibalism. I mean, if you consider anything more than "one" to be an acceptable number.Season 2 kicked off with the show's first foray into eating human flesh, when pregnant teen Shauna (Sophie Nélisse) ate the frozen ear off of the corpse of her best friend, Jackie (Ella Purnell), who froze to death in the season 1 finale. 

The moment was shocking, disgusting, and weirdly poetic, as Shauna's love for her best friend seemed to extend to her desire to make Jackie a part of her. The show's creative team has already spoken about how her act of eating the ear was hotly debated in the writer's room, with co-creator Bart Nickerson saying: "And then the other thing is — and I usually don't want to do this, talk about what almost was — but I just think it's hilarious the amount of time that we spent both in breaking writing and then in editing, deciding how much of the ear — like, should it go in the mouth, should it not go in the mouth? Should there be a chew?"

No one in the "Yellowjackets" cast interacts with Jackie's ear other than Shauna, which is probably why no one noticed when Sophie Nélisse accidentally took it home with her as an unintentional keepsake. Not the one she ate, of course.

'What Is This Weird, Squishy Thing?'

During a recent interview with Esquire, Sophie Nélisse admitted that she absentmindedly put the ear in her pocket after shooting one day, and didn't find it until months later. "I was going through my pocket and I was like, 'What is this weird squishy thing ... Oh my god, it's the ear,'" she said. The ear in question was made out of silicone, which is fortunate considering much of the edible flesh in "Yellowjackets" is made out of candy.

"You'll see eventually in the show there's other things that we eat that are actually made out of gummy bear," she told Esquire. "They're actually so tasty, but they look so real and gooey and gross that our brains can't really disassociate and step back away from it. It feels disgusting eating it—even though it's actually quite yummy. It's literally a giant gummy bear." Co-star Samantha Hanratty, who plays Misty Quigley, is a proud vegan and has confirmed that some of what she's provided is made of Beyond Meat or vegan-friendly gummies.

As for the ear? Nélisse said she keeps it hidden away in her room. " It'd be a bit of a red flag if someone came into my room and there's this whole little ear on my countertop. So, it's hidden away in a little souvenir box." Aw, it's just like the heart box from "Snow White." How sweet!

Read this next: Every Yellowjackets Main Character, Ranked

The post Yellowjackets Sophie Nelisse Accidently Took Jackie's Ear Home With Her appeared first on /Film.

25 Apr 18:14

HX DOS Extender 2.17+ with modern sound card support

Reply from Japheth, 25.04.2023, 12:58:

> What can I do now ?

1) Forget this old stuff!
2) Use the latest HX ( v2.20 )
3) Download vsbhda ( a fork of SBEMU )
4) replace the hdpmi32i.exe binary of HX v2.20 with the one contained in vsbhda.zip
4a) optionally install the JemmEx.exe binary contained in vsbhda.zip ( not really required for DosBox ).
5) install vsbhda
6) run DosBox

Both HX and VSBHDA can be easily found at github.
25 Apr 18:09

Beyond Traditional Security: NDR's Pivotal Role in Safeguarding OT Networks

by The Hacker News
Why is Visibility into OT Environments Crucial? The significance of Operational Technology (OT) for businesses is undeniable as the OT sector flourishes alongside the already thriving IT sector. OT includes industrial control systems, manufacturing equipment, and devices that oversee and manage industrial environments and critical infrastructures. In recent years, adversaries have recognized the
25 Apr 18:09

Ransomware Hackers Using AuKill Tool to Disable EDR Software Using BYOVD Attack

by Ravie Lakshmanan
Threat actors are employing a previously undocumented "defense evasion tool" dubbed AuKill that's designed to disable endpoint detection and response (EDR) software by means of a Bring Your Own Vulnerable Driver (BYOVD) attack. "The AuKill tool abuses an outdated version of the driver used by version 16.32 of the Microsoft utility, Process Explorer, to disable EDR processes before deploying