All posts by FreeNews

Three-year-old boy drowns in Bartica

(Kaieteur News) – A three-year-old boy reportedly drowned in the Essequibo River at Agatash Village, Region Seven, during the early afternoon hours on Friday. The child has been identified as Keron Atkinson. According to reports, he was in the company of his seven-year-old cousin when he went underwater. Police, relatives and villagers reportedly joined efforts to […]

The post Three-year-old boy drowns in Bartica appeared first on Kaieteur News.

US imposes sanctions on ICC hours after former judge wins Nobel Peace Prize

(Reuters) – US President Donald Trump’s administration-imposed sanctions on ​the International Criminal Court on Friday, hours after one of its former judges won the Nobel Peace Prize, putting Washington on a diplomatic collision course with European allies. The court the move as an “assault on the rule of law and on the very foundations of […]

The post US imposes sanctions on ICC hours after former judge wins Nobel Peace Prize appeared first on Kaieteur News.

Linden Teacher killed in two-vehicle collision

(Kaieteur News) – The Linden teaching fraternity has been plunged into mourning following the death of 48-year-old Leslyn Major, who was killed in a tragic accident on Friday afternoon at Empire Drive, Ameila’s Ward, Linden, Region 10. The circumstances surrounding the accident are unclear at this time but initial reports reaching Kaieteur News state that it […]

The post Linden Teacher killed in two-vehicle collision appeared first on Kaieteur News.

Two characters open up a world of typosquatting opportunities in Chromium browsers

Researchers say two characters available to typosquatters and phisherfolk can trick Chromium browsers into displaying lookalike URLs as genuine web addresses. Wangling a domain name to look an awful lot like that of a popular website is nothing new. We’ve all encountered phishing sites such as macrosoft[.]com and applle[.]com before in our daily struggles against spam. However, as browsers mature, new characters are always being made available for use. This opens up new opportunities for those whose languages contain characters/homoglyphs that aren’t ASCII-compliant, but it also introduces new ways for attackers to abuse display logic quirks in programs like Chrome and Edge. According to Ian Muscat and Leanne Briffa of Have I Been Squatted, there are still characters available to cyber-imposters that can reliably fool web users into trusting URLs that they certainly should not. The latest glyphs bypassing browser safety checks allow tricksters to run websites from a clearly fake domain name (when displayed in Punycode), although they appear just like the real deal in Unicode. The characters of note, in this case, are ө, which is found in various Cyrillic languages such as Kazakh, Mongolian, and Tatar, and the Latin K with hook, ƙ, used in Hausa and Karai-karai. Both are visually similar to the letters e/o, i, and k, respectively, and allowed the researchers to register 20 lookalike domain names. These included: aррӏө[.]com sрасөх[.]com oƙta[.]com niƙe[.]com Below are the URLs’ Punycode equivalents – how browsers should display them safely: xn--80a6aa68c8d.com xn--80a5aeq0fr0c.com xn--ota-f6a.com xn--nie-g6a.com You can try them out; they’re registered by Have I Been Squatted and are safe to visit. They take you to research demo pages set up by the researchers, and each page explains how exactly they bypass browser protections. Crucially, they all bypass the key security measures deployed by Chromium-based browsers. How the bypasses work Browsers deploy two main defense layers. The first is a set of seven sequential checks run by Chromium’s SafeToDisplayAsUnicode function, which check for a range of common spoofing methods. Vendors began introducing these checks in 2017 after researcher Xudong Zheng registered аррӏе.com – a domain consisting of all-Cyrillic characters. Chromium’s checks, which factor in a hardcoded list of known Cyrillic characters known to be used in place of Latin letters, can be seen as “all or nothing.” Built to detect all-Cyrillic strings, the measure only takes action against domain names if every character in the string is on its hardcoded list. If one character is missing, the check is bypassed. Characters such as ө, ї, and ү, are known as “breakers,” as these are not present in the lookalike list, as of Chrome 154 (released to stable channel on September 22). Failing any of the seven display checks tells the browser that the characters are unsafe to display as Unicode and to instead display the Punycode, revealing just how dissimilar they are to the genuine domains they try to imitate. The second measure browsers take is to compare the domain name against a list of popular websites to see if it is trying to imitate one of them. In Chromium, these checks are handled by the GetSimilarTopDomain() function. This step converts a supplied domain name into a “skeleton,” stripping its characters of diacritics, such as accents (ó becomes o), and checking the skeleton URL against a hardcoded list of popular websites. Chromium checks against almost 8,500, and if the skeleton matches any of them, then it displays Punycode. However, the Latin K with hook, ƙ, does not have an accent, and is added to the skeleton as a Latin k with an added combining mark, bypassing the security check. In this case, the skeleton is formed as: [o k ‘ t a . c o r n]. (The skeleton maps “m” to “rn”). Likewise, with аррӏө.com, the Cyrillic barred o retains its bar in the skeleton as a combining mark, meaning it does not match the genuine Apple domain. Its skeleton is formed as: [a p p l o – . c o r n]. Browsers are always working to stymie these tools of imposterment. Chrome 148 put an end to attackers being able to use ҏ and ӿ as breakers to imitate their Latin lookalikes, for example. The two main security checks are not the only lines of defense. Chromium also deploys warnings at the time of navigation called Safety Tips. An example domain that would bypass the two main checks is ínstagarm[.]com. The inflection on the beginning character is removed and what’s left is essentially the real Instagram domain with two letters swapped. The Instagarm domain does not match any of the hardcoded sites, nor does it contain any banned characters. In this case, Chrome will display one of two popups, asking the user if they meant to visit the genuine domain, warning that the current direction of travel appears fake. However, there are limits to this extra security layer. The warnings only trigger when an imitation domain is an exact-character match, a one-edit match, or a match with an adjacent swap from the genuine URL. Two or more changes, like with аррӏө[.]com, which has all-Cyrillic characters preceding the “.com,” will not trigger these warnings. The warnings will also not trigger with domains consisting of fewer than five characters. Domains such as oƙta.com, which is only one edit from the real Okta, may not trigger defenses because of the one-edit rule and the fact that it is only four characters. Safety Tips also checks the skeleton against the sites users visit regularly, not just the hardcoded list of trusted sites. Frequently visited sites may trigger the same warnings, but for users who do not have a comprehensive visit history, the defense layer may fail. The defenses described here only apply to browsers. Email clients are even less picky with imitation domain strings. Websites like Gmail displayed each of the 20 domains HIBS fed the clients, which were a mix of lookalikes and genuine internationalized domain names (IDNs), as an attacker would want it to, all in Unicode. Outlook Web showed all 20 as Punycode, even the harmless ones, suggesting neither apply the right checks to properly inform users. To quantify the scale of the issue, the researchers looked at ICANN’s list of every .com domain. There are around 167 million of them, approximately 733,000 of which are IDNs, those that contain non-ASCII characters and are stored in Punycode form. The researchers took each of the IDNs and swapped their non-ASCII characters for ASCII equivalents to determine how many matches there were. They found around 162,000 pairs – IDNs that resemble plain ASCII domains. It should be said that this does not mean there are circa 162,000 typosquatted domains, just that many yield lookalikes. Some may be registered by businesses for defensive purposes; others may be owned by the same business that wants to operate multiple websites catering to different languages. However, organizations should be aware of the means available to typosquatters, and monitor registered domains accordingly. ®

EC users should be afraid of a US kill switch – not some new software

You’d swear from the over-the-top reactions that someone is threatening to take European Commission workers’ dogs out back and shoot them. Why the freakout? Because the EC is deploying a self-hosted alternative to Microsoft Teams to keep staff communicating if Microsoft’s service becomes unavailable. To be clear, the Commission isn’t replacing Teams with Element Pro; it’s setting up a backup. That’s it. That’s all. But according to a Politico report, users are having fits. Element is “absolute shit,” rants one. Another proclaims: “The US would ‘instantly win the war’ if it ever decided to switch off its technology.” Uh, guy, that’s exactly the point. If US providers cut off European users, whether by choice or government order, many EU governments and companies would face serious disruption. That’s exactly why Europe needs an open source, sovereign backup. That’s the entire point of this exercise. Take away all the hysteria, and you’re left with a rather mundane business-continuity initiative. Don’t think for a minute that Trump wouldn’t have a snit and order tech giants to block services to officials. Just ask Kimberly Prost, a Canadian International Criminal Court judge, who, besides losing tech services, also lost her credit cards, access to Amazon and Google services. “Alexa wouldn’t talk to me,” she says – punishment indeed. Now imagine Russia and its allies start attacking the Baltic states. Oh, wait, Putin is already doing that. Then it gets heated, and Trump decides to side with his good friend Putin. What happens to American tech companies’ services in Estonia, Latvia, and Lithuania? I can answer that in two words: “Nothing good.” That said, the EC of course is not dumping Microsoft services. No, it has configured Element Pro to run on the Commission’s own infrastructure. An internal memo described the service as an “internal backup” that gives the EU’s executive branch an alternative channel for internal messaging, audio and video calls, file transfers, and project discussion rooms. Let me spell it out for you. This is a Commission initiative. It’s not an EU-wide order to abandon Microsoft software. I’d love that myself, but that’s not what’s happening here. Teams will remain the principal platform, while Element provides a fallback intended to reduce dependence on an externally operated communications service. Got it? I hope so! Mind you, there are other good reasons to dump Microsoft Teams. I’m not a fan. For my sins I have to use it and every other groupware program out there. And, I might add, I’ve been using them since Lotus Notes rolled out the door in 1990. Digital sovereignty isn’t just a good idea. It’s essential. Or, as an EC July staff memo put it: “In practice, this means having greater control over our data and systems so that we can reduce risks and limit disruption to our work, wherever possible.” Exactly so. Element’s architecture is well suited to digital sovereignty. Built on Matrix, an open standard for real-time communications, the platform supports self-hosting, decentralized operation, and interoperability with other Matrix-based systems. Element also supports end-to-end encrypted messaging and calls. You see, the sovereignty argument isn’t just about getting an EU-based technology stack. After all, Element is a British company. No, what really makes Element a winner for the EC is that it’s mature groupware that lets them deploy and run the system on their own infrastructure rather than relying on Microsoft’s cloud. As for the crybaby users, suck it up. No one ever likes change. If the EC switches over to Element lock, stock, and barrel, I suspect much of today’s outrage will be forgotten in six months. I’ve seen this time and time again. Some short-term inconvenience is a reasonable price for greater control over essential communications in an uncertain world. A complete switch isn’t the plan now. I think it should be. ® Bootnote Element told The Register: “Governments and defense organizations are migrating to sovereign alternatives to ensure they can still operate effectively in extreme circumstances. As IT strategy and IT functions move quickly, less adaptive end-users may well feel discomfort as the US Big Tech solutions they’ve been used to are replaced by sovereign alternatives. Hopefully this is the largest inconvenience most people experience over the coming decade. “We’ve only had positive and constructive feedback from our actual customers; the leaders and IT functions that are driving sovereignty. “There’s inevitably a few unhappy change-resistant users in large deployments, but we work in lockstep with our customers to gather feedback and incorporate it, especially during the trial phase. From what we see in the field, open source alternatives like Element are ready for primetime as a much needed alternative to dependency on the big tech vendors.”

Stack Overflow survey finds devs hooked on AI, but not totally sold on its judgment

Nearly a third of developers who use AI daily spend four hours or more of their working day with it, according to Stack Overflow’s latest survey. The survey received 30,903 responses from developers and technologists across 169 countries. Among the 10,926 daily AI users who answered the time-use question, about 80 percent reported using the tools for at least an hour a day. The research by developer Q&A site Stack Overflow also found skepticism from developers toward using AI in their roles. Only about 7 percent of developers said they trusted AI output for important work decisions, while 48 percent trusted it when they could easily verify the output. Seventy-nine percent considered source attribution important or very important when deciding whether to trust an AI-generated technical answer. Stack Overflow CEO Prashanth Chandrasekar said developers were highly skeptical as a group. “As AI agents become rapidly more autonomous, that skepticism now acts as a critical safeguard. As agents take on more work, developers need to know where an answer came from, what context informed the information that was produced or a decision that was made, and the most crucial piece – that they can actually verify its accuracy and relevance. Trust is not a given when it comes to developers; it is earned through transparency, source attribution, and rich technical context.” The survey found that coding assistants or coding agents are used by 66 percent of respondents, general-purpose chat tools by 63 percent, and automated agent workflows by 26 percent. Seventeen percent of respondents said they did not use AI tools. Stack Overflow’s commercial relationships with AI companies have proved contentious. In early 2024, it introduced OverflowAPI, offering paid access to its question-and-answer content and requiring participating AI providers to attribute answers to relevant posts. A couple of months later, users began to revolt against its partnership with OpenAI, which allowed the LLM builder to train AI models using 15 years of users’ contributions. The Q&A site was also set to benefit from the deal by getting access to OpenAI’s technology. A number of users said they’d rather remove their posts and risk their reputation scores than have their contributions train OpenAI models. The survey also found that 52 percent of respondents had learned a new coding skill or programming language this year. AI code-generation tools were among the most common learning resources, behind technical documentation. ®

Microsoft leans on open weight model from Chinese AI lab to challenge Jev

Microsoft has joined the Jev fan club, an accidental group of companies that share a common desire to be recognized for their own decision models. Jev, announced by TypeSafe AI three weeks ago, is a large language model (LLM) tuned to respond to certain types of questions with a limited range of responses, rated by probability. Due to its speed, relative affordability, and response constraints, it’s well-suited for a variety of business applications where open-ended text of uncertain accuracy might be undesirable. One of the selling points of Jev is that decision models don’t hallucinate in the way that standard LLMs do. But decision models can make errors and their popularity has already prompted researchers to explore how those errors might be magnified. Nonetheless, they have their uses. The attention lavished on Jev prompted other companies to declare that they too have decision models to offer, even though machine learning researchers have long been able to create classifier models for probability-based decisions. OpenAI said its Decisions API has entered public beta. Cloudflare chimed in with its Clef model. Strands trotted out Strands Decider 2B, “a small, open source, decision model.” Liquid AI introduced d1. Perplexity launched its Decisions API. Snowflake talked up its own decision model. Then there’s Surogate Rune and H2O.ai’s H2O-Lightning-4B, a decision model built on Qwen3.5-4B. All told, more than 100 such models are now vying for attention. Now it’s Microsoft’s turn. “Decision models are quickly emerging as an important new category in AI,” said Achint Srivastava, VP of software engineering in the Office of the CTO at Microsoft, in a blog post on Friday. “Unlike LLMs, which are designed to generate text or reason through complex problems, decision models are purpose-built to deliver structured outputs that software can immediately act on. And once you understand that capability – making decisions and classifying things at very low cost with high performance – all kinds of useful tasks get unlocked.” Microsoft’s entrant into the race is called Microsoft-Decision-1, which is offered via Microsoft Foundry and, soon, via OpenRouter. Redmond’s decision model, like H2O’s, is based on a Qwen model, Qwen3.5-9B in this instance. The Qwen model family is developed by Alibaba Cloud, the cloud computing arm of Chinese tech giant Alibaba. Microsoft, for reasons not disclosed, said it will soon rebase the Decision-1 on its models and those from OpenAI. The US software giant claims its model is 2.5x faster than H2O-Lightning-4B and 2.8x faster than Jev in its latency test, leads the pack in accuracy (83.5 percent) on 36 benchmarks, ranks second (behind Quyet-1.0-Large) in confidence score (92.2 percent), and is more than 20x cheaper than OpenAI’s GPT-6 Sol in text classification tasks. Input tokens cost $0.042 per million tokens and output tokens are free. “Now that agentic AI is a reality, we’ve seen that cost plays a major role in how people decide to use AI,” said Srivastava. “And it’s increasingly important to choose the right model for the right job.” ®