Physicists searching for a better understanding of quantum gravity stumbled upon something unexpected: the defining signatures of string theory.
Apple revealed that it blocked over $11 billion in fraudulent App Store transactions over the last six years, more than $2.2 billion in potentially fraudulent App Store transactions in 2025 alone.
In a Wednesday press release, the tech giant said it rejected over 2 million problematic app submissions last year and blocked more than 1.1 billion fraudulent account creations.
Apple also terminated 193,000 developer accounts due to fraud concerns, rejected more than 138,000 developer enrollments, and deactivated an additional 40.4 million customer accounts suspected of fraud and abuse.
Google has accidentally leaked details about an unfixed issue in Chromium that keeps JavaScript running in the background even when the browser is closed, allowing remote code execution on the device.
The flaw was reported by security researcher Lyra Rebane and acknowledged as valid in December 2022, as per the thread on Chromium Issue Tracker.
An attacker could exploit the problem to create a malicious webpage with a Service Worker, such as a download task, that never terminates. Rebane says that this could allow an attacker to execute JavaScript code on the visitors’ devices.
Cybersecurity researchers have disclosed details of a vulnerability in the Linux kernel that remained undetected for nine years.
The vulnerability, tracked as CVE-2026–46333 (CVSS score: 5.5), is a case of improper privilege management that could permit an unprivileged local user to disclose sensitive files and execute arbitrary commands as root on default installations of several major distributions like Debian, Fedora, and Ubuntu. It’s also codenamed ssh-keysign-pwn.
According to Qualys, which discovered the flaw, the problem is rooted in the kernel’s __ptrace_may_access function and was introduced in November 2016.
Drupal has released security updates for a “highly critical” security vulnerability in Drupal Core that could be exploited by attackers to achieve remote code execution, privilege escalation, or information disclosure.
The vulnerability, now tracked as CVE-2026–9082, carries a CVSS score of 6.5 out of 10.0, per CVE.org. Drupal said the vulnerability resides in a database abstraction API that is used in Drupal Core to validate queries and ensure they are sanitized against SQL injection attacks.
“A vulnerability in this API allows an attacker to send specially crafted requests, resulting in arbitrary SQL injection for sites using PostgreSQL databases,” it said. “This can lead to information disclosure, and in some cases privilege escalation, remote code execution, or other attacks.”
Further Reading.
Embodied Neurocomputation:
A Framework for Interfacing Biological Neural.
Cultures with Scaled Task-Driven Validation.
https://arxiv.org/html/2605.13315v1
Computing with Living Neurons: Chaos-Controlled Reservoir Computing with Knowledge Transplant.
https://ui.adsabs.harvard.edu/abs/202…
Goal-directed learning in cortical organoids.
https://www.sciencedirect.com/science…
A feedback-driven brain organoid platform enables automated.
maintenance and high-resolution neural activity monitoring.
https://www.sciencedirect.com/science…
Human assembloid model of the ascending neural sensory pathway.
https://www.nature.com/articles/s4158…
Encoding Tactile Stimuli for Braille Recognition with Organoids.
https://arxiv.org/abs/2508.
Researchers have shown for the first time that malfunctioning mitochondria — the cell’s energy generators — may directly cause cognitive decline in neurodegenerative diseases. By creating a new tool that temporarily boosts mitochondrial activity in the brain, scientists restored memory performance in mouse models of dementia. The discovery hints that energy failure inside neurons could happen before brain cells die, potentially offering a new target for future Alzheimer’s treatments.