Modalità di lettura

Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

A Decryptads summary of the advertising partnerships declared by espn.com.

The newly launched decryptads.com says it is constantly scraping the files that websites and apps make publicly available to disclose the companies that are permitted to run ads or collect user data. These files include:

ads.txt: all of the adtech companies and data brokers that may run ads or harvest data from the site;
app-ads.txt: entities that can harvest data from or display ads on mobile and smart TV apps;
buyers.json/sellers.json: the entities buying, selling or reselling ad inventory for a given site or app.

Zach Edwards is chief research officer for DecryptAds and a threat researcher at the security company Infoblox. Edwards said he and two other founders decided the service was needed because the adtech data in these files is generally only useful when it can be cross-referenced to build a more complete picture of the advertising ecosystem for each website or app.

“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said. “It’s really built for a lot of privacy and security use cases that have been dramatically underserved.”

Those use cases, he said, include tracking down the source of malicious ads that try to foist malware on targeted users, identifying ad networks located in adversarial nations, and detecting the fast growing swarms of AI-generated slop websites and apps. And as decryptads.com demonstrates, these potential security and privacy threats are near impossible to detect just by viewing a single apps.txt or app-ads.txt file.

“Supply-chain integrity issues rarely live in a single file,” the site explains. “They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized-seller list.”

A search in DecryptAds for the hugely popular sports network espn.com reveals 143 ad partners and 19 registered data broker domains are listed within its ads.txt and app-ads.txt files. That data broker information is gradually becoming available because four states — California, Oregon, Texas and Vermont — have recently passed laws requiring data brokers to register if they buy or sell data on consumers from those states. DecryptAds reports that almost half of those data brokers are collecting geolocation data from espn.com visitors who aren’t blocking ads, while another three disclose that they collect device fingerprints and sensitive personal information.

A visual representation of the complex ad supply chain declared by espn.com. Image: decryptads.com.

HIGH-RISK AD PARTNERS

DecryptAds also makes it easy to learn the beneficiaries and national origins of the advertising firms lurking in apps and websites, displaying a conspicuous warning when adtech partners of an app or website are based in “geo-risk” areas like China and Russia, or in countries with strong financial and political ties to both — such as Cyprus and the United Arab Emirates (UAE).

According to DecryptAds, espn.com works with four different advertising entities that are based in either Russia, China or the UAE, including the adtech firm Between Digital, which lists a New York address. However, the dossier on Between Digital flags them as a Russian firm, showing that their publisher offers (PDF) are processed through Alfa Bank, Russia’s largest private commercial bank and one of several financial institutions placed under U.S. sanctions in 2022 after Russia invaded Ukraine. KrebsOnSecurity sought comment from both Between Digital and the company’s founder, and will update this story in the event that either replies.

A search for several top U.S. military news websites — including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com and federaltimes.com — shows they all allow Between Digital to serve ads and track users, as well as two entities in the UAE and another in the ownership secrecy haven of Panama. DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

The “Geo Risk” section of decryptads.com.

Pivoting on Between Digital’s app-ads.txt file reveals hundreds of domains featuring simple web-based games that are frequently interrupted by ads. Edwards said Between Digital’s own declarations show the company is listed as both a publisher and a reseller on approximately two-thirds of their portfolio.

“It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest,” Edwards told KrebsOnSecurity. “The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files.”

The Opera Web browser remains quite popular, and probably many users are unaware that since 2016 it has been majority owned and controlled by the Chinese company Kunlun Tech (the operational headquarters of Opera remain in Oslo, Norway).

Opera.com’s profile at DecryptAds identifies 27 registered data brokers collecting information, including 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia and one each in Hong Kong and Ukraine. DecryptAds makes clear, however, that these companies represent just seven percent of the adtech partners specified in Opera.com’s ads.txt and app-ads.txt files.

LEGAL DOSSIERS

One feature of DecryptAds that sent this author down multiple hours-long research rabbit holes is its Legal Dossier lookup, which takes several minutes for each search but eventually churns out oodles of useful information about who owns a particular domain or app, when it was registered, and any aliases or relationships it may have to adtech companies and other websites or apps.

For example, last month KrebsOnSecurity wrote about researchers from Bitsight who found that an extremely popular line of TV streaming sticks called H96 quietly rent out each user’s Internet connection to strangers. Bitsight also discovered that when these devices aren’t being used to stream pirated video content, they are spoofing themselves as mobile phones clicking ads on AI-generated slop websites.

Bitsight concluded that the same Chinese company that made several of the malicious apps common to all of these H96 streaming sticks — the Fengwo Group — also also ran the network of ads and AI slop websites being clicked on by tens of thousands of these devices that are pretending to be mobile phones.

Examples of ad landing pages linked to the Fengwo Group. These sites were designed to show ads only to H96 devices that were spoofing their device type as mobile phones. Image: Bitsight.

A DecryptAds legal dossier on the (now dormant) Fengwo Group domain name for the AI slop website pictured on the left in the screenshot above (medicalbeautyhub dot com) shows it shares a seller ID (1674071) with a gaming website — giacoloredstones[.]com — which features yet another seller ID (103488000).

Pivoting on that latter seller ID reveals hundreds of active websites within Russia’s Yandex ad system featuring extremely low-quality games or simple utilities that pepper visitors with ads.

QUIET REMOVALS

Edwards said that when advertising networks suspect a given advertiser is engaged in unauthentic clicks or displaying malicious ads, very often those networks will quietly remove the offender from their list of approved partners without letting anyone else know about their suspicions.

This practice, he said, makes it easier for dodgy adtech firms to avoid accountability and continue victimizing others. To address that visibility gap, DecryptAds features a quiet removals feed that records and correlates all of the sellers.json removals across ad exchanges for the same seller domain or name.

A screenshot of the Quiet Removals Feed at decryptads.com.

“The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public,” Edwards said. “The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once.”

MALVERTISING AND AI SLOP

Malvertising, the term given to the practice of inserting malicious ads that foist malware or redirect visitors to phishing pages, remains an all-too-frequent occurrence in the modern adtech industry. But Edwards said these malicious ads are far more commonly found now on newly generated AI slop websites than on high traffic destinations that typically employ a variety of technologies and third party tools to quickly flag bad ads.

“None of these slop AI content farms are paying for that kind of protection,” he said. “They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on espn.com or huffpost.com, but rather [on] some lower quality content farm and someone just went there because it came up in a search.”

Edwards said the AI slop websites are populated with machine-generated blog posts and images, and cover a wide array of themes from home improvement and decorating to food recipes, hunting, cars and consumer technology. He said organizations that get hit with malicious ads are often at a loss for what to do next, unaware that in most cases the answer is one of the entities listed inside the website’s ads.txt or app-ads.txt file.

“A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis,” he said.

Edwards maintains that truly getting a handle on the malvertising and AI slop problems will require more data-sharing by the major ad networks. Specifically, he says those platforms do not broadly share what’s known as the “supply chain object” or SCO, structured data attached to each advertising bid request that lets buyers see every seller, reseller and intermediary involved in passing an ad impression from the publisher to the final buyer.

“That SCO tells you who sold it or resold it, and who was the final entity that bought the impression that served that malware payload,” Edwards explained. “You may see the malicious zero-click redirection, but without the supply chain object — which is only served server side — you won’t know who targeted your people with malware and won’t have a way to try and prevent it properly. But if we can encourage the adtech industry to expose that SCO, it will get easier to find the culprit behind any one bad ad.”

DecryptAds also offers an application programming interface (API) that allows researchers to automate queries and integrate the site’s functionality into popular AI platforms.

WHAT CAN YOU DO?

The only sane reaction to the examples described above is to block all online ads outright. This approach is broadly endorsed by security experts because it also makes it more difficult for adtech firms and data brokers to build detailed profiles on you and track your movements around the web and in the real world.

However, much depends on how you normally prefer to browse the Internet, and how much trust you place in third party browser plugins and extensions. For those primarily surfing via a regular desktop or laptop Web browser, uBlock Origin Lite is an excellent free and well-maintained open source option. uBlock Origin also should work with mobile browsers like Firefox, but apparently only on Android-based devices.

Adblock Plus is a decent option for iPhone and iPad users. For power users, Adblock and uBlock Origin both support custom blocking rules from easylist.to, which publishes a frequently updated list that removes most advertisements from webpages.

The well established browser extension NoScript blocks all non-approved Javascript code, and it generally does a fine job blocking most ads from loading. However, script blockers like NoScript may not be suitable for average users who don’t enjoy constantly having to referee which scripts should be allowed to load so that each site displays properly.

More technically inclined/adventuresome readers should strongly consider a hardware approach to blocking ads at the local network level, because that is easily the cheapest, most secure and scalable way to do it. A tiny, low-cost and broadly available computer known as a Raspberry Pi can be turned into a powerful ad blocker for all devices on a local network when fitted with a microSD memory card and a free program called Pi-hole. Once you’ve set it up properly and changed your router’s network settings to use the Pi-hole’s DNS sinkhole and DHCP servers, it should prevent ads from displaying on any devices connected to that network.

Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to install on their devices. Many websites now push users to install a mobile app, supposedly in order to more fully access and enjoy the site’s services and content. But in my experience, they’re not doing this because the user experience is somehow way better on the app (as LinkedIn tries to convince us non-app users several times a week via email). On the contrary, I find most mobile apps to be horribly designed, annoying, and/or completely unnecessary, and when given the option I will almost always choose to interact with a website or service directly in a Web browser.

No, the cold truth is that big web destinations tend to get pushy with their apps because they make it easier for these companies to keep you on their platforms longer and to collect (and in many cases resell) far more precise data about who, what and where their users are. Also, companies pushing customers the hardest to install mobile apps always seem to liberally opt everyone in to having their data used to train large language models these days. So be cautious about the apps you install on your mobile devices (including any smart TVs!), and poke around their listings at DecryptAds if you want to learn more about their privacy practices and any relationships they may have to adtech firms.

  •  

Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

Image: Shutterstock, Mallika Home Studio.

August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes. Microsoft has attributed the recent patch deluge to vulnerability discoveries aided by artificial intelligence, and experts roundly agree that Windows users should get used to the idea of Patch Tuesdays (the second Tuesday of each month) covering hundreds of newly discovered security flaws.

Fully 42 of the 398 flaws that Microsoft patched today earned Redmond’s most-dire “critical” rating, meaning they are severe enough that malware or malcontents could exploit them to gain remote control over a Windows computer with little to no help from the user.

The sole known “zero day” bug fixed by Microsoft this month is CVE-2026-68820, a privilege escalation weakness in a core Windows component called afd.sys, which the security firm Automox describes as “the driver behind Windows socket connections on effectively every endpoint.”

“This isn’t a front-door bug,” Automox’s Landon Miles wrote in a Patch Tuesday blog post. “It’s step two in a chain: an attacker phishes their way into a low-privilege foothold, then uses the driver flaw to take the box. The 7.0 score reflects the high attack complexity, because race conditions are fiddly. The exploit has to be thrown over and over until the timing lands. Someone is clearly landing it anyway.”

CVE-2026-62832 is another privilege escalation flaw that Microsoft has labeled likely to be exploited; this flaw, in the Windows User Profile Service, may be related to the recent “LegacyHive” public disclosure from the prolific bug hunter known as Nightmare Eclipse. The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.

Other major software makers are likewise increasing their patch volumes and cadence thanks to AI, including Adobe which last month moved to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month. Cisco, Google, Mozilla and Oracle also are shipping updates far more frequently and abundantly.

By all accounts, AI is quite good at finding security holes in software. But for now at least, patching the resulting bugpocalypse remains a heavily human-centric endeavor, and the jury is still out on whether AI technologies will turn out to be as good at fixing vulnerabilities as they are at finding and exploiting them. This is an important question when one considers that these same AI technologies also are suggesting fixes for the vulnerabilities they find.

Researchers at 1Password recently examined what happens when different large language models (LLMs) generate vulnerability patches for newly disclosed, complex vulnerabilities. They found the LLMs produced patches that failed to fix the flaw or added a new weakness in the process (or both) more than half the time.

Ed Skoudis, president of the SANS Technology Institute, said his team has seen excellent results using AI to generate patches, provided there are humans in the loop to test the suggested fixes and push for iterative improvements.

“AI is rapidly becoming astonishingly good at finding vulnerabilities, but this research shows that fixing them is a very different problem,” Skoudis wrote in a SANS newsletter today. “Don’t expect one-shot AI patching to work reliably. Instead, iterate, test, challenge, improve, and verify. AI can be an extraordinary patching partner, but today it still needs a skilled human at the keyboard.”

Tyler Reguly at Fortra says while reports of Microsoft patching hundreds of vulnerabilities in one go have prompted some organizations to try to patch faster, it’s important to bear in mind that only one of the almost 400 bugs addressed today is known to be actively exploited. Reguly suggested security leaders check in with their teams to see how they’re handling the increasing workloads, which often involve testing fixes before deploying them in production environments.

“If you’re a chief security officer talk to your teams about how they are shifting or modifying their workflows to better accommodate the patching shift that we’re seeing and support them across various organizational units by enabling the changes they want to see made,” Reguly said. “There’s no need to rush these updates, no matter what various vendors and organizations try to tell you. You need to make sure that you are rolling out safe updates that will not negatively impact your systems.”

Speaking of the humans behind the keyboards, don’t neglect to backup your system and/or data before applying this month’s monster patch load. The day after each month’s Patch Tuesday is sometimes derisively referred to as Reboot Wednesday, but it generally doesn’t hurt to wait a few days to apply these huge update bundles because it sometimes takes a couple of days for the occasional misbehaving patch to get ironed out properly by Microsoft.

For a clickable, per-patch breakdown by severity and urgency, check out this roundup from the SANS Internet Storm Center.

  •  

NASA, GE Aerospace Work Enables Hybrid-Electric Flight Demonstration

4 min read

Preparations for Next Moonwalk Simulations Underway (and Underwater)

Modified Saab 340, a hybrid-electric aircraft in flight.
A modified Saab 340B aircraft in flight powered in part by a hybrid electric system built by GE Aerospace, along with NASA, BETA Technologies, and Boeing.
GE Aerospace

An aircraft powered by a megawatt-class hybrid-electric engine developed in collaboration with NASA and built by GE Aerospace, demonstrated flight of an innovation that can inform new generations of fuel-saving aircraft power systems.

Mounted to a Saab 340B aircraft, the engine flew at Farnborough International Air Show in the United Kingdom. It was the public debut of a system that has in recent months made historic test flights, becoming the first hybrid electric-powered aircraft to fly above 30,000 feet.

“This achievement reflects what NASA does best in aeronautics: we explore bold possibilities, validate them through rigorous research and testing, and work with industry to turn breakthrough ideas into technologies that bring real value for the American people,” said Laurie Grindle, director of the Aeronautics Division within the agency’s Research and Technology Mission Directorate at NASA Headquarters in Washington.

The testing leveraged work done through NASA’s former Electrified Powertrain Flight Demonstration project and the agency’s ongoing Subsonic Vehicle Technologies and Tools project – years of collaborative research that included key testing at NASA test facilities. 

The engine integrates electric motors, a gas turbine, and energy storage capabilities. It was designed to demonstrate the capacity to power an aircraft around the size of a regional-class jet, reducing fuel burn and costs without sacrificing performance. The unit’s technology and designs are expected to be used to help develop future hybrid systems that could lower airline operating costs. 

The demonstration flight came after years of rapid development for the technology. For NASA, it also validates work that stretches back to a time when hybrid aviation propulsion seemed almost beyond the horizon of possibility.

This achievement reflects what NASA does best in aeronautics: we explore bold possibilities, validate them through rigorous research and testing, and work with industry to turn breakthrough ideas into technologies that bring real value for the American people.

LAURIE A. GRINDLE

LAURIE A. GRINDLE

Director of the Aeronautics Division within the agency's Research and Technology Mission Directorate

“This is the culmination of more than 15 years of work, and we did that because it’s going to have an impact for aircraft that will help reduce energy use and help U.S. companies and the public,” said Ralph Jansen, aerospace engineer at NASA’s Glenn Research Center in Cleveland. “It’s about having a vision that no one believes can happen and then doing the work to define and execute the research and development needed to make it happen.”  

This accomplishment was possible because of the collaborative effort of hundreds of people working on Electrified Powertrain Flight Demonstration and Subsonic Vehicle Technologies and Tools projects across NASA centers, in conjunction with GE Aerospace and its partner companies.

Hybird-Electric Evolves

In recent years, aviation has seen a boom in small aircraft and drones powered by electrical systems drawing from batteries. But large passenger and cargo planes require complex engines capable of supplying massive amounts of power. So more than a decade ago when NASA began contemplating hybrid systems, just the possibility of using electric motors to supplement some energy was a daunting engineering challenge. 

NASA spent about seven years performing preliminary research, working with small businesses and other partners to consider technological obstacles and the potential commercial viability of hybrid systems. During that time, the agency addressed several barriers to implementation including the power, thermal, and battery technology, and the integration of the power system, engine, and aircraft.

Through the agency’s Electrified Powertrain Flight Demonstration award, GE Aerospace and NASA worked with researchers to develop lighter and more efficient power systems and shrink key components – sometimes dramatically. 

NASA and GE Aerospace also leveraged agency facilities and resources to further their research. In 2022, GE Aerospace tested an integrated version of its propulsion system at NASA’s Electric Aircraft Testbed at the agency’s Neil A. Armstrong Test Facility in Sandusky, Ohio. Testing allowed the system to operate in conditions simulating 45,000 feet in altitude, the range in which commercial single-aisle aircraft fly. 

The team added components, including electric motors, power converters, propellers, and a GE Aerospace commercial engine, followed by more ground tests and eventual flight tests. For the researchers who’d spent years on the concept, seeing the engine powering an aircraft in flight was a major step in a long journey.

“I’ve got to say, I was pretty touched seeing it fly. It was just awesome,” Jansen said.  “It’s just like a regular plane, which is probably the best thing of all.”

NASA’s current support for this research is through the Aeronautics Division of its Research and Technology Mission Directorate.

  •  

NASA Pushes New Wing Design to Find Structural Limits

3 Min Read

NASA Pushes New Wing Design to Find Structural Limits

A wide view of a test structure in a laboratory shows a full test assembly secured inside a steel rig. Hydraulic lines, sensors, and support equipment surround the structure, with additional lab equipment visible in the background.
The 15-foot Structural Wing Experiment Evaluating Truss-bracing test article is fully installed in the Flight Loads Laboratory at NASA’s Armstrong Flight Research Center in Edwards, California, on Wednesday, May 20, 2026. The model is part of NASA’s research to develop technologies for future ultra-efficient aircraft.
Credits: NASA/Carla Escamilla

NASA researchers recently put a new wing design, appearing long and thin with a lightweight structural design, through a series of grueling tests to find its structural limits. What they found left them encouraged about the wing’s potential, even when they pushed it past its intended limits.

The 15-foot Structural Wing Experiment Evaluating Truss-bracing (SWEET-15) test article is part of NASA’s research to develop future ultra-efficient aircraft. The design incorporates a long wing supported by an aerodynamic strut, based on NASA’s earlier Transonic Truss‑Braced Wing concept.

The research team is working to understand whether SWEET-15’s design and its new lightweight structural designs could help commercial airliners save fuel. But first, they need to understand how it behaves under the kinds of force wings experience in flight.

A group of people work together in a large workshop, handling and inspecting a long metallic structure laid across padded tables. Tools, materials, and protective equipment are spread across the workspace.
Lab technicians Phil Tofts, Chris McLain, and Jeff Howell and NASA engineers Erin Anderson and Richard Larson prepare the 15-foot Structural Wing Experiment Evaluating Truss-bracing model in the Flight Loads Laboratory at NASA’s Armstrong Flight Research Center in Edwards, California, on Thursday, Dec. 11, 2025. The model is part of NASA’s research to develop technologies for future ultra-efficient aircraft. 
NASA/Christopher LC Clark

The SWEET-15 design originated with combining five different advanced composite manufacturing and assembly technologies that enabled the novel structural design. The 15-foot-long test article was then designed and fabricated at NASA’s Langley Research Center in Hampton, Virginia, before traveling to NASA’s Armstrong Flight Research Center in Edwards, California, for testing.

Over several months, NASA engineers intentionally bent the test wing in the Flight Loads Laboratory at NASA Armstrong. Numerous strain and load sensors, including fiber-optic strain sensors, were placed throughout the structure to track how the wing responded as forces increased.

The data from the sensors confirmed the predictions made by NASA’s computer models. According to initial findings, the wing withstood the anticipated in-flight forces without issue. The results provided the team with confidence in the new manufacturing approaches and methods for connecting wing parts used in SWEET-15, which could support future efficient aircraft designs. The manufacturing approach, developed at NASA Langley used the Integrated Structural Assembly of Advanced Composites robot, aims to produce lighter and stronger composite structures for aerospace vehicles.

A long beam is suspended in a laboratory while personnel observe and guide its placement. Overhead support equipment, cables, and lab infrastructure surround the test area.
Lab technicians Jeff Howell, left and Chris Mount install the 15-foot Structural Wing Experiment Evaluating Truss-bracing model in the Flight Loads Lab at NASA’s Armstrong Flight Research Center in Edwards, California, Wednesday, February 11, 2026. The model is part of NASA’s research to develop technologies for future ultra-efficient aircraft.
NASA/Christopher LC Clark

The test concluded with a deliberate test-to-failure, where engineers increased loads beyond the wing’s design limits to determine how and where it would fail. The structure ultimately failed at roughly 127% of its design limit load, with visible damage appearing near the back edge of the wing and in the upper wing cover. This element of testing provided valuable insight into how the joints connecting the wing to its main strut and a secondary one, called a jury strut, behave under forces beyond the expected flight envelope.

This marks the first time a representative composite truss-braced wing configuration has undergone this type of structural evaluation.  It was made possible only through NASA collaboration across centers and projects, with researchers utilizing agency resources such as the Fiber Optic Sensing System developed to gather data on both aircraft and spacecraft.

A man wearing ear protection works closely with multiple hydraulic and instrumentation units connected to a large beam mounted on a test structure. Numerous cables, hoses, and measurement devices extend from the setup.
NASA research engineer Walter Hargis regulates the 15-foot Structural Wing Experiment Evaluating Truss-bracing model in the Flight Loads Laboratory at NASA’s Armstrong Flight Research Center in Edwards, California, on Tuesday, March 31, 2026. The model is part of NASA’s research to develop technologies for future ultra-efficient aircraft. 
NASA/Ryan Kline

To prepare for the testing, engineers at NASA Langley designed, analyzed, and manufactured the wing and completed safety preparations and lab setup.

Researchers will now analyze the data collected during testing to inform future airframe designs and support NASA’s ongoing efforts to develop more efficient aviation technologies.

The work is being conducted through NASA’s Subsonic Flight Demonstrator project in the agency’s Research Technology Mission Directorate. The successful testing of multiple innovative components marks a milestone in NASA’s aeronautics research.

To learn more, visit:

https://www.nasa.gov/aeronautics/

  •  

Microsoft Patches a Record 570 Security Flaws

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

A picture of a windows laptop in its updating stage, saying do not turn off the computer.

Nearly 60 of the bugs quashed in July’s Patch Tuesday earned a “critical” severity rating, meaning miscreants or malware could use them to seize remote control over a Windows device with little or no help from the user. Microsoft also addressed three zero-day flaws, including two that are already being exploited in the wild.

Two of the zero-day weaknesses allow an attacker to elevate their user rights on a Windows system, as do approximately 250 other elevation of privilege flaws fixed this month; they include CVE-2026-56155 — an Active Directory Federation Services bug — and CVE-2026-56164, a Microsoft Sharepoint vulnerability.

CVE-2026-50661 is a security feature bypass in Windows BitLocker that could allow attackers to gain access to encrypted data if they have physical access to the device. Microsoft said this bug has been detailed publicly, but that it is not aware of any active exploitation.

In a blog post on July 9, Microsoft Executive Vice President Pavan Davuluri wrote that Windows users will notice “a higher volume of security updates included in each security release” as a result of AI aiding in the discovery of vulnerabilities.

“The pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code, with new mechanisms that can accelerate both discovery and analysis,” Davuluri wrote.

Jack Bicer, director of vulnerability research at Action1, called attention to CVE-2026-48561, a remote code execution flaw in Microsoft Copilot (with a 9.6 CVSS threat score) that allows an unauthorized attacker to execute code over the network. Microsoft says an attacker could exploit this bug by hosting a malicious website that causes Microsoft Edge for Android to automatically send crafted prompts to Copilot when a user visits the site.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws. Microsoft has long labeled security bugs using its “exploitability index,” which is Redmond’s best guess as to how likely it is that attackers will be able to figure out a reliable way to exploit a given vulnerability.

But Satnam Narang, senior staff research engineer at Tenable, argues that Microsoft’s exploitability index needs to do a better job of shifting with the machine speed of discovery. For example, Microsoft originally gave this month’s SharePoint zero-day an exploitability rating of “less likely,” although the flaw was added to CISA’s Known Exploited Vulnerabilities list on July 1.

“Anthropic’s Red Team’s own findings for known vulnerabilities (n-days) revealed how fragile this system has become, with its Mythos Preview model being able to produce proof-of-concept exploits for 13 of 14 vulnerabilities that were rated ‘Exploitation Less Likely’ or ‘Exploitation Unlikely,'” Narang said. “What this means is that our way of looking at Patch Tuesday has changed, because the exploitability index is centered around humans, not AI tools, and as these tools continue to improve, defense needs to improve alongside it.”

Chris Goettl at Ivanti observed that the record patch numbers from Microsoft come as a number of other major software makers are increasing their patch cadence, including Adobe which announced today it is moving to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month (Adobe also cited AI for accelerating their patch cycles). Cisco, Mozilla and Oracle also are shipping updates more frequently, while Google’s patch batches in June 2026 totaled more than 900 security fixes, Goettl noted.

Backing up your Windows system and/or data is always a good idea before applying operating system updates. Given the volume of patches addressed this month it may be wise for end users to wait a few days before applying these fixes. It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

Further reading:

Action1’s Patch Tuesday blog

Automox’s rundown

  •  

ASPA Is Live. Can You See It Working?

ASPA objects can be registered today with ARIN and RIPE NCC. Validators support RTR v2. But if you're an operator, can you actually see what ASPA is doing - or would do - on your network? We built a tool to find out.
  •  

China and Russia Should Cooperate to Help the United States Achieve an “Orderly Decline”

The year 2026 opens with a succession of US manoeuvres that continue to shake the global balance, while subterranean currents roil the international scene: the military attack on Venezuela has…

The post China and Russia Should Cooperate to Help the United States Achieve an “Orderly Decline” appeared first on Another World.

  •  

China’s Posture After Venezuela: Accelerated De-Dollarisation and Conflict Preparation

The US operation in Venezuela on 3 January 2026 marked a turning point in Chinese strategy towards Washington. Beijing interpreted the failure of Chinese-manufactured JY-27A radars to detect F-35s and…

The post China’s Posture After Venezuela: Accelerated De-Dollarisation and Conflict Preparation appeared first on Another World.

  •  

Carrier Pigeons and Financial Cartels: How Banking Dynasties Decide Which Nations Can Afford to Fight

December 2025 delivered one of those declarations that typically belong to conspiracy theory territory, except this time it emanated directly from someone with every interest in maintaining silence: Dame Hannah…

The post Carrier Pigeons and Financial Cartels: How Banking Dynasties Decide Which Nations Can Afford to Fight appeared first on Another World.

  •  
❌