Categories
The News And Times – thenewsandtimes.com

Top US Senate Democrat Schumer warns against Republican “brinkmanship“ on spending


2023-09-01T15:45:56Z

U.S. Senate Majority Leader Chuck Schumer speaks to reporters in the U.S. Capitol in Washington, U.S., June 13, 2023. REUTERS/Kevin Lamarque/File Photo

Top U.S. Senate Democrat Chuck Schumer on Friday said House Republicans would be to blame if lawmakers are unable to reach a deal to keep the government funded past Sept. 30, triggering the fourth partial shutdown of federal agencies in a decade.

“We cannot afford the brinkmanship or hostage-taking we saw from House Republicans earlier this year when they pushed our country to the brink of default to appease the most extreme members of their party,” Schumer said in an open letter to colleagues on Friday.

“When the Senate returns next week, our focus will be on funding the government and preventing House Republican extremists from forcing a government shutdown.”

The Senate returns to Washington on Tuesday with the House of Representatives coming a week later, leaving lawmakers little time to agree on a deal to keep the federal government funded past the months’ end. Republicans say sharp cuts in spending are needed to stem the nation’s growing $31.4 trillion national debt.

The Republican-controlled House of Representatives, bending to the will of a small group of hardline conservatives, is pushing to cut discretionary spending to a fiscal 2022 level of $1.47 trillion, $120 billion less than top House Republican Kevin McCarthy and Democratic President Joe Biden agreed to earlier this year.

* The White House on Thursday urged Congress to hammer out a short-term funding measure called a “continuing resolution” to avoid a shutdown starting Oct. 1.

* There is disagreement within the House Republican caucus about the depth of the proposed cuts, with one moderate Republican likening them to a “root canal.”

* Goldman Sachs analysts said earlier this month that they view a shutdown as “more likely than not.”

The post Top US Senate Democrat Schumer warns against Republican “brinkmanship“ on spending first appeared on The News And Times – thenewsandtimes.com.


Categories
The News And Times – thenewsandtimes.com

Roads and airports will be crowded this weekend. Here’s how to prepare


People travel through the Austin-Bergstrom International Airport on Thursday.

The FAA says this could be the third-busiest travel weekend of the year so far, while AAA warns we could see more traffic on the roads than in years. Here’s what to know if you’re flying or driving.

(Image credit: Brandon Bell/Getty Images)

npr-rss-pixel.png?story=1197167786

The post Roads and airports will be crowded this weekend. Here’s how to prepare first appeared on The News And Times – thenewsandtimes.com.


Categories
The News And Times – thenewsandtimes.com

Rishi Sunak’s director of communications Amber de Botton quits role


800.jpg?width=1200&height=630&quality=85

Ex-ITV journalist, who lasted less than a year in role, says No 10 is ‘demanding and high-pressure place to work’

Rishi Sunak’s director of communications has quit her role, as Downing Street’s mini-reshuffle took an internal turn.

The former ITV journalist, Amber de Botton, who was brought in to salvage the government’s sinking reputation when Sunak took over from Liz Truss as prime minister, announced on Friday she had “decided it is the right time to move on”.

Continue reading…

The post Rishi Sunak’s director of communications Amber de Botton quits role first appeared on The News And Times – thenewsandtimes.com.


Categories
The News And Times – thenewsandtimes.com

Putin, Prigozhin and the shadow of Anastasia – Eurasia Review


The post Putin, Prigozhin and the shadow of Anastasia – Eurasia Review first appeared on The News And Times – thenewsandtimes.com.


Categories
The News And Times – thenewsandtimes.com

Russia-led alliance holds military drills in Belarus – The Washington Post


The post Russia-led alliance holds military drills in Belarus – The Washington Post first appeared on The News And Times – thenewsandtimes.com.


Categories
The News And Times – thenewsandtimes.com

Tuition Discounts on the Rise, but Are They Going to Neediest Applicants?


U.S. colleges often slash thousands of dollars off the “sticker price” to entice students to enroll. The more options a student has, the bigger the discount a college needs to offer. However, the savings have disproportionately gone to white and Asian applicants.

“Put merit in quotation marks,” says one admissions official. “It’s not really about rewarding students for their wonderful performance in high school, as much as it is trying to change that student’s enrollment decision.”

Read more from Jill Barshay in The Hechinger Report. (July 2023)

The post Tuition Discounts on the Rise, but Are They Going to Neediest Applicants? first appeared on The News And Times – thenewsandtimes.com.


Categories
The News And Times – thenewsandtimes.com

Putin Tells Schoolchildren Russia is ‘Invincible’ During World War II Revisionism Lessons


3fcdea6a4e7978920ef18df275dd7ff0.jpg?w=1

The classes, “Important Conversations” were introduced after the start of the Kremlin’s assault on Ukraine to boost patriotic sentiment.

The post Putin Tells Schoolchildren Russia is ‘Invincible’ During World War II Revisionism Lessons first appeared on The News And Times – thenewsandtimes.com.


Categories
The News And Times – thenewsandtimes.com

Bow Ties, Bomb Threats and No Flowers – Wartime Kyiv’s First Day Back at School


6408ffa536d2652271b1121976aaedef.jpeg?w=

Despite a bomb threat on their first day of school, and the now common missile and drone attacks from Russia, children in Kyiv were happy to be back in their classrooms

The post Bow Ties, Bomb Threats and No Flowers – Wartime Kyiv’s First Day Back at School first appeared on The News And Times – thenewsandtimes.com.


Categories
The News And Times – thenewsandtimes.com

North Korea-linked APT Labyrinth Chollima behind PyPI supply chain attacks


ReversingLabs researchers linked the VMConnect campaign to the North Korea-linked APT group Labyrinth Chollima.

ReversingLabs researchers believe that the North Korea-linked APT group Labyrinth Chollima is behind the VMConnect campaign. Threat actors uploaded a series of malicious packages to the PyPI (Python Package Index) repository, including a rogue package posing as the VMware vSphere connector module vConnector named VMConnect targeting IT professionals.

The state-sponsored hackers uploaded the malicious packages in early August.

The APT group uploaded two dozen malicious Python packages to the Python Package Index (PyPI) repository. The researchers were not able to obtain samples of the second-stage malware used in this campaign.

“The packages mimicked popular open-source Python tools, including vConnector, a wrapper module for pyVmomi VMware vSphere bindings; eth-tester, a collection of tools for testing Ethereum-based applications; and databases, a tool that gives asynchronous support for a range of databases.” states the report published by ReversingLabs. “an analysis of the malicious packages used and their decrypted payloads reveals links to previous campaigns attributed to Labyrinth Chollima, an offshoot of Lazarus Group, a North Korean state-sponsored threat group”

The researchers also identified three more malicious Python packages that are believed to be a continuation of the VMConnect campaign: tablediter, request-plus, and requestspro.

tablediter was mimicking the legitimate prettytable Python tool that developers use for printing tables in an attractive ASCII format. Prettytable has more than 9 million monthly downloads, for this reason threat actors are targeting its users with a typosquatting attack. 

tablediter is very similar to previously discovered malicious packages in the VMConnect campaign. The most significant difference is that the malicious functionality is not executed when the package is installed, but it is triggered when the package is used in a project. The malicious code is not executed through the __init__.py file during the package installation, instead, it was added to a function called add_row, which is a part of the tablediter class defined in the tablediter.py file. The code will be executed during testing of the application on a developer’s workstation or during execution by a user working with published software that has incorporated the malicious tablediter dependency. 

Labyrinth Chollima PYPI

Upon executing the package, the code calls a method from a file, bounding.py, that is located in the edt subdirectory. Then this method receives a parameter that represents an XOR key used to decrypt the content of a hex-encoded string enclosed in the package.

For the other two packages of the trio, request-plus, and requestspro, threat actors appended the “plus” and “pro” suffixes to the name to make them appear as legitimate packages with additional capabilities.

The packages gather information about the infected machine and send it to the C2 server in the form of a POST HTTP request.

The C2 server responds with a Base64/XOR obfuscated Python module with execution parameters. The module also includes the download URL for the next stage payload, which researchers couldn’t retrieve.

The researchers noticed that the module includes the URL for the next stage payload.

“The team believes the module gets executed after decoding and then downloads the next stage of the malware. As was the case in the earlier iteration of the VMConnect campaign, the C2 server associated with the campaign did not provide additional commands by default, but rather waited for a suitable target, making it difficult to assess the full scope of the campaign.” continues the report.

The attribution to the Lazarus subgroup Labyrinth Chollima is based on similarities in the malicious code employed in the campaign. The ‘builder.py’ file in the malicious packages contains the same payload decoding routine that the JPCERT discovered in another file called ‘py_Qrcode’ attributed to the Lazarus subgroup tracked as DangerousPassword.

“Based on those attributions and the described code similarities between the packages discovered in the VMConnect campaign and the campaign described in the research published by JPCERT/CC, the ReversingLabs research team has reached the conclusion that the same threat actor is behind both attacks and, therefore, that the VMConnect malicious campaign activity can be linked to the North Korean state-sponsored Lazarus Group” concludes the report.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, North Korea)

The post North Korea-linked APT Labyrinth Chollima behind PyPI supply chain attacks appeared first on Security Affairs.

The post North Korea-linked APT Labyrinth Chollima behind PyPI supply chain attacks first appeared on The News And Times – thenewsandtimes.com.


Categories
The News And Times – thenewsandtimes.com

Futures rise ahead of August payrolls report


2023-09-01T11:29:17Z

Traders work on the floor of the New York Stock Exchange (NYSE) in New York City, U.S., July 19, 2023. REUTERS/Brendan McDermid/File Photo

U.S. stock index futures were higher on Friday ahead of a keenly awaited reading that could show job growth likely slowed in August, bolstering expectations of a pause in the Federal Reserve’s interest rate hikes.

The Labor Department’s closely watched report, due at 8:30 a.m. ET is expected to show nonfarm payrolls likely increased by 170,000 jobs last month, following 187,000 additions in July.

The unemployment rate, however, is forecast to stay unchanged at 3.5%.

“There have been indicators that the U.S. jobs market is finally starting to lose some of its tightness, and if the NFP print confirms this trend, it will be one less thing for the FOMC to worry,” said Tim Waterer, chief market analyst at KCM Trade.

The payrolls report will follow recent data showing a fall in job openings and softer-than-expected private employment growth.

An inflation reading has also supported hopes of the Fed hitting a pause on its market-punishing tightening campaign, pushing the tech-heavy Nasdaq (.IXIC) up to a four-week high.

Other data points are also on the radar for the day, with the S&P Global Manufacturing Final PMI due at 9:45 a.m. ET and the ISM Manufacturing PMI due at 10 a.m. ET. Both readings are for August.

Money markets see an 89% chance of a rate-hike pause in the September policy meeting and a 56% chance of a pause in the November meeting, according to the CME FedWatch Tool.

Broadcom (AVGO.O) fell 4.2% premarket as the chipmaker projected current-quarter revenue below expectations on softening enterprise demand.

At 7:09 a.m. ET, Dow e-minis were up 121 points, or 0.35%, S&P 500 e-minis were up 14.75 points, or 0.33%, and Nasdaq 100 e-minis were up 22.25 points, or 0.14%.

Dell Technologies (DELL.N) jumped 10.1% after the personal computer maker raised its annual forecasts for revenue and profit as it benefits from the artificial intelligence boom.

Lululemon Athletica (LULU.O) gained 2.1% after the yogawear maker said on Thursday its third quarter was “off to a solid start” and lifted its annual profit and revenue forecasts for a second time.

The post Futures rise ahead of August payrolls report first appeared on The News And Times – thenewsandtimes.com.