Author name: 9u50fv

authorities-carry-out-global-takedown-of-infostealer-used-by-cybercriminals

Authorities carry out global takedown of infostealer used by cybercriminals


Authorities, along with tech companies including Microsoft and Cloudflare, say they’ve disrupted Lumma.

A consortium of global law enforcement agencies and tech companies announced on Wednesday that they have disrupted the infostealer malware known as Lumma. One of the most popular infostealers worldwide, Lumma has been used by hundreds of what Microsoft calls “cyber threat actors” to steal passwords, credit card and banking information, and cryptocurrency wallet details. The tool, which officials say is developed in Russia, has provided cybercriminals with the information and credentials they needed to drain bank accounts, disrupt services, and carry out data extortion attacks against schools, among other things.

Microsoft’s Digital Crimes Unit (DCU) obtained an order from a United States district court last week to seize and take down about 2,300 domains underpinning Lumma’s infrastructure. At the same time, the US Department of Justice seized Lumma’s command and control infrastructure and disrupted cybercriminal marketplaces that sold the Lumma malware. All of this was coordinated, too, with the disruption of regional Lumma infrastructure by Europol’s European Cybercrime Center and Japan’s Cybercrime Control Center.

Microsoft lawyers wrote on Wednesday that Lumma, which is also known as LummaC2, has spread so broadly because it is “easy to distribute, difficult to detect, and can be programmed to bypass certain security defenses.” Steven Masada, assistant general counsel at Microsoft’s DCU, says in a blog post that Lumma is a “go-to tool,” including for the notorious Scattered Spider cybercriminal gang. Attackers distribute the malware using targeted phishing attacks that typically impersonate established companies and services, like Microsoft itself, to trick victims.

“In 2025, probably following Redline’s disruption and Lumma’s own development, it has ranked as the most active module, indicating its growing popularity and widespread adoption among cybercriminals,” says Victoria Kivilevich, director of threat research at security firm Kela.

Microsoft says that more than 394,000 Windows computers were infected with the Lumma malware between March 16 and May 16 this year. And Lumma was mentioned in more than 21,000 listings on cybercrime forums in the spring of 2024, according to figures cited in a notice published today by the Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA). The malware has been spotted bundled in fake AI video generators, fake “deepfake” generation websites, and distributed by fake CAPTCHA pages.

Law enforcement’s collaboration with Microsoft’s DCU and other tech companies like Cloudflare focused on disrupting Lumma’s infrastructure in multiple ways, so its developers could not simply hire new providers or create parallel systems to rebuild.

“Cloudflare’s role in the disruption included blocking the command and control server domains, Lumma’s Marketplace domains, and banning the accounts that were used to configure the domains,” the company wrote in a blog post on Wednesday. “Microsoft coordinated the takedown of Lumma’s domains with multiple relevant registries in order to ensure that the criminals could not simply change the name servers and recover their control.”

While infostealing malware has been around for years, its use by cybercriminals and nation-state hackers has surged since 2020. Typically, infostealers find their way onto people’s computers through downloads of pirated software or through targeted phishing attacks that impersonate established companies and services, like Microsoft itself, to trick victims. Once on a computer it is able to grab sensitive information—such as usernames and passwords, financial information, browser extensions, multifactor authentication details and more—and send it back to the malware’s operators.

Some infostealer operators bundle and sell this stolen data. But increasingly the compromised details have acted as a gateway for hackers to launch further attacks, providing them with the details needed to access online accounts and the networks of multi-billion dollar corporations.

“It’s clear that infostealers have become more than just grab-and-go malware,” says Patrick Wardle, CEO of the Apple device-focused security firm DoubleYou. “In many campaigns they really act as the first stage, collecting credentials, access tokens, and other foothold-enabling data, which is then used to launch more traditional, high-impact attacks such as lateral movement, espionage, or ransomware.”

The Lumma infostealer first emerged on Russian-language cybercrime forums in 2022, according to the FBI and CISA. Since then its developers have upgraded its capabilities and released multiple different versions of the software.

Since 2023, for example, they have been working to integrate AI into the malware platform, according to findings from the security firm Trellix. Attackers want to add these capabilities to automate some of the work involved in cleaning up the massive amounts of raw data collected by infostealers, including identifying and separating “bot” accounts that are less valuable for most attackers.

One administrator of Lumma told 404Media and WIRED last year that they encouraged both seasoned hackers and new cybercriminals to use their software. “This brings us good income,” the administrator said, referring to the resale of stolen login data.

Microsoft says that the main developer behind Lumma goes by the online handle “Shamel” and is based in Russia.

“Shamel markets different tiers of service for Lumma via Telegram and other Russian-language chat forums,” Microsoft’s Masada wrote on Wednesday. “Depending on what service a cybercriminal purchases, they can create their own versions of the malware, add tools to conceal and distribute it, and track stolen information through an online portal.”

Kela’s Kivilevich says that in the days leading up to the takedown, some cybercriminals started to complain on forums that there had been problems with Lumma. They even speculated that the malware platform had been targeted in a law enforcement operation.

“Based on what we see, there is a wide range of cybercriminals admitting they are using Lumma, such as actors involved in credit card fraud, initial access sales, cryptocurrency theft, and more,” Kivilevich says.

Among other tools, the Scattered Spider hacking group—which has attacked Caesars Entertainment, MGM Resorts International, and other victims—has been spotted using the Lumma stealer. Meanwhile, according to a report from TechCrunch, the Lumma malware was allegedly used in the build-up to the December 2024 hack of education tech firm PowerSchool, in which more than 70 million records were stolen.

“We’re now seeing infostealers not just evolve technically, but also play a more central role operationally,” says DoubleYou’s Wardle. “Even nation-state actors are developing and deploying them.”

Ian Gray, director of analysis and research at the security firm Flashpoint, says that while infostealers are only one tool that cybercriminals will use, their prevalence may make it easier for cybercriminals to hide their tracks. “Even advanced threat actor groups are leveraging infostealer logs, or they risk burning sophisticated tactics, techniques, and procedures (TTPs),” Gray says.

Lumma isn’t the first infostealer to be targeted by law enforcement. In October last year, the Dutch National Police, along with international partners, took down the infrastructure linked to the RedLine and MetaStealer malware, and the US Department of Justice unsealed charges against Maxim Rudometov, one of the alleged developers and administrators of the RedLine infostealer.

Despite the international crackdown, infostealers have proven too useful and effective for attackers to abandon. As Flashpoint’s Gray puts it, “Even if the landscape ultimately shifts due to the evolution of defenses, the growing prominence of infostealers over the past few years suggests they are likely here to stay for the foreseeable future. Usage of them has exploded.”

This story originally appeared at wired.com.

Photo of WIRED

Wired.com is your essential daily guide to what’s next, delivering the most original and complete take you’ll find anywhere on innovation’s impact on technology, science, business and culture.

Authorities carry out global takedown of infostealer used by cybercriminals Read More »

i-helped-a-lost-dog’s-airtag-ping-its-owner:-an-ode-to-replaceable-batteries

I helped a lost dog’s AirTag ping its owner: An ode to replaceable batteries

Out of all the books I read for my formal education, one bit, from one slim paperback, has lodged the deepest into my brain.

William Blundell’s The Art and Craft of Feature Writing offers a “selective list of what readers like.” It starts with a definitive No. 1: “Dogs, followed by other cute animals and well-behaved small children.” People, Blundell writes, are your second-best option, providing they are doing or saying something interesting.

I have failed to provide Ars Technica readers with a dog story during nearly three years here. Today, I intend to fix that. This is a story about a dog, but also a rare optimistic take on a ubiquitous “smart” product, one that helped out a very good girl.

Note: The images in this post are not of the aforementioned dog, so as to protect their owner’s privacy. The Humane Rescue Alliance of Washington, DC, provided photos of adoptable dogs with some resemblance to that dog.

Hello, stranger

My wife and I were sitting with our dog on our front porch on a recent weekend morning. We were drinking coffee, reading, and enjoying DC’s tiny window of temperate spring weather. I went inside for a moment; when I came back, my dog was inside, but my wife was not. Confused, I cracked open the door to look out. A dog, not my own, stuck its nose into the door gap, eager to sniff me out.

“There’s a dog here?” my wife said, partly to herself. “She just ran up on the porch. I have no idea where she came from.”

Rexi, a pitbull leaning to the right, onto someone wearing jeans.

Rexi, a nearly 3-year-old mixed breed, is being fostered and ready for adoption at the Humane Rescue Alliance. The author’s wife thinks Rexi looks the most like their unexpected dog visitor.

Rexi, a nearly 3-year-old mixed breed, is being fostered and ready for adoption at the Humane Rescue Alliance. The author’s wife thinks Rexi looks the most like their unexpected dog visitor. Credit: Humane Rescue Alliance

I secured my dog inside, then headed out to meet this fast-moving but friendly interloper. She had a collar, but no leash, and looked well-groomed, healthy, and lightly frantic. The collar had a silicone band on it, holding one of Apple’s AirTags underneath. I pulled out the AirTag, tapped it against my phone, and nothing happened.

While my wife posted on our neighborhood’s various social outlets (Facebook, Nextdoor, and a WhatsApp group for immediate neighbors), I went into the garage and grabbed a CR2032 battery. That’s not something everyone has, but I have a few AirTags, along with a bit of a home automation habit. After some pressing, twisting, and replacing, the AirTag beeped and returned to service.

I helped a lost dog’s AirTag ping its owner: An ode to replaceable batteries Read More »

paris-agreement-target-won’t-protect-polar-ice-sheets,-scientists-warn

Paris Agreement target won’t protect polar ice sheets, scientists warn

“I think we’ve known for a long time that we’re interfering with the climate system in a very dangerous way,” he said. “And one of the points of our paper is to demonstrate that one part of the climate system, the ice sheets, are showing some very disturbing signals right now.”

Some of the most vulnerable places are far from any melting ice sheets, including Belize City, home to about 65,000 people, where just 3 feet of sea level rise would swamp 500 square miles of land.

In some low-lying tropical regions around the equator, sea level is rising three times as fast as the global average. That’s because the water is expanding as it warms, and as the ice sheets melt, their gravitational pull is reduced, allowing more water to flow away from the poles toward the equator.

“At low latitudes, it goes up more than the average,” Bamber said. “It’s bad news for places like Bangladesh, India, Vietnam, and the Nile Delta.”

Global policymakers need to be more aware of the effects of a 1.5° C temperature increase, Ambassador Carlos Fuller, long-time climate negotiator for Belize, said of the new study.

Belize already moved its capital inland, but its largest city will be inundated at just 1 meter of sea-level rise, he said.

“Findings such as these only sharpen the need to remain within the 1.5° Paris Agreement limit, or as close as possible, so we can return to lower temperatures and protect our coastal cities,” Fuller said.

While the new study is focused on ice sheets, Durham University’s Stokes notes that recent research shows other parts of the Earth system are already at, or very near, tipping points that are irreversible on a timescale relevant to human civilizations. That includes changes to freshwater systems and ocean acidification.

“I think somebody used the analogy that it’s like you’re wandering around in a dark room,” he said. “You know there’s a monster there, but you don’t know when you’re going to encounter it. It’s a little bit like that with these tipping points. We don’t know exactly where they are. We may have even crossed them, and we do know that we will hit them if we keep warming.”

Paris Agreement target won’t protect polar ice sheets, scientists warn Read More »

gemini-2.5-is-leaving-preview-just-in-time-for-google’s-new-$250-ai-subscription

Gemini 2.5 is leaving preview just in time for Google’s new $250 AI subscription

Deep Think graphs I/O

Deep Think is more capable of complex math and coding. Credit: Ryan Whitwam

Both 2.5 models have adjustable thinking budgets when used in Vertex AI and via the API, and now the models will also include summaries of the “thinking” process for each output. This makes a little progress toward making generative AI less overwhelmingly expensive to run. Gemini 2.5 Pro will also appear in some of Google’s dev products, including Gemini Code Assist.

Gemini Live, previously known as Project Astra, started to appear on mobile devices over the last few months. Initially, you needed to have a Gemini subscription or a Pixel phone to access Gemini Live, but now it’s coming to all Android and iOS devices immediately. Google demoed a future “agentic” capability in the Gemini app that can actually control your phone, search the web for files, open apps, and make calls. It’s perhaps a little aspirational, just like the Astra demo from last year. The version of Gemini Live we got wasn’t as good, but as a glimpse of the future, it was impressive.

There are also some developments in Chrome, and you guessed it, it’s getting Gemini. It’s not dissimilar from what you get in Edge with Copilot. There’s a little Gemini icon in the corner of the browser, which you can click to access Google’s chatbot. You can ask it about the pages you’re browsing, have it summarize those pages, and ask follow-up questions.

Google AI Ultra is ultra-expensive

Since launching Gemini, Google has only had a single $20 monthly plan for AI features. That plan granted you access to the Pro models and early versions of Google’s upcoming AI. At I/O, Google is catching up to AI firms like OpenAI, which have offered sky-high AI plans. Google’s new Google AI Ultra plan will cost $250 per month, more than the $200 plan for ChatGPT Pro.

Gemini 2.5 is leaving preview just in time for Google’s new $250 AI subscription Read More »

trump-admin-lifts-hold-on-offshore-wind-farm,-doesn’t-explain-why

Trump admin lifts hold on offshore wind farm, doesn’t explain why

On Monday, however, the company announced that the hold had been lifted and construction would resume. But as with the hold itself, the reasons for its end remain mysterious. The Bureau of Ocean Energy Management page for the project was only updated with a new letter on Tuesday. That letter indicates a review of its approval is ongoing, but construction can resume during the review.

The Department of the Interior has not addressed the change and has not responded to a request for comment. A post by Interior Secretary Burgum doesn’t mention Empire Wind but does suggest the governor of New York will approve a pipeline: “I am encouraged by Governor Hochul’s comments about her willingness to move forward on critical pipeline capacity.”

That suggests there was a deal that allowed Empire Wind to resume construction in return for a pipeline for fossil fuels. The New York Times suggests that this is a reference to the proposed Constitution Pipeline, which was planned to move natural gas from Pennsylvania to eastern New York but was cancelled in 2020 due to state opposition.

But Governor Kathy Hochul has not made any comments about a willingness to move forward on any pipelines. Instead, Hochul’s statement on Empire Wind is very vague, saying that she “reaffirmed that New York will work with the Administration and private entities on new energy projects that meet the legal requirements under New York law.”

So while it’s good news that construction on Empire Wind has restarted, the whole process has been problematic, driven by apparently arbitrary decisions that the government has refused to justify.

Trump admin lifts hold on offshore wind farm, doesn’t explain why Read More »

adobe-to-automatically-move-subscribers-to-pricier,-ai-focused-tier-in-june

Adobe to automatically move subscribers to pricier, AI-focused tier in June

Subscribers to Adobe’s multi-app subscription plan, Creative Cloud All Apps, will be charged more starting on June 17 to accommodate for new generative AI features.

Adobe’s announcement, spotted by MakeUseOf, says the change will affect North American subscribers to the Creative Cloud All Apps plan, which Adobe is renaming Creative Cloud Pro. Starting on June 17, Adobe will automatically renew Creative Cloud All Apps subscribers into the Creative Cloud Pro subscription, which will be $70 per month for individuals who commit to an annual plan, up from $60 for Creative Cloud All Apps. Annual plans for students and teachers plans are moving from $35/month to $40/month, and annual teams pricing will go from $90/month to $100/month. Monthly (non-annual) subscriptions are also increasing, from $90 to $105.

Further, in an apparent attempt to push generative AI users to more expensive subscriptions, as of June 17, Adobe will give single-app subscribers just 25 generative AI credits instead of the current 500.

Current subscribers can opt to move down to a new multi-app plan called Creative Cloud Standard, which is $55/month for annual subscribers and $82.49/month for monthly subscribers. However, this tier limits access to mobile and web app features, and subscribers can’t use premium generative AI features.

Creative Cloud Standard won’t be available to new subscribers, meaning the only option for new customers who need access to many Adobe apps will be the new AI-heavy Creative Cloud Pro plan.

Adobe’s announcement explained the higher prices by saying that the subscription tier “includes all the core applications and new AI capabilities that power the way people create today, and its price reflects that innovation, as well as our ongoing commitment to deliver the future of creative tools.”

Like today’s Creative Cloud All Apps plan, Creative Cloud Pro will include Photoshop, Illustrator, Premiere Pro, Lightroom, and access to Adobe’s web and mobile apps. AI features include unlimited usage of image and vector features in Adobe apps, including Generative Fill in Photoshop, Generative Remove in Lightroom, Generative Shape Fill in Illustrator, and 4K video generation with Generative Extend in Premiere Pro.

Adobe to automatically move subscribers to pricier, AI-focused tier in June Read More »

universal-releases-one-last-jurassic-world-rebirth-trailer

Universal releases one last Jurassic World Rebirth trailer

The first trailer dropped in February, serving primarily as a means of introducing the basic premise and the main characters—and playing up the return to where it all started: the original Jurassic Park. It’s been fairly isolated because, as one character says, “No one’s dumb enough to go where we’re going.” But anything for science and the benefit of humanity, right? Even if it means trying to steal DNA from a pterosaur egg (possibly Quetzalcoatlus northropi) before the angry mother—aka “a flying carnivore the size of an F-16″—returns. In fact, the island is home to “the worst of the worst,” i.e., the most dangerous of the cloned dinosaurs, including the infamous raptors and a new aquatic dinosaur species, the mosasaur.

Some of the same footage and expository dialogue appear in this latest trailer, which honestly gives away much of the movie—although how many fresh twists could there be after so many decades? You know by now what you’re getting with this franchise. The trailer opens with a laboratory emergency in which a worker in a hazmat suit is fatally trapped inside an isolation chamber with what looks like a hungry T-rex. The poor dude pleads with his colleague to open the door before being eaten.

The rest of the trailer consists of our intrepid team—and the unfortunate shipwrecked family—dealing with various species of very dangerous dinosaurs, with ScarJo leading the way on the action. (But pro tip: maybe don’t put a baby dinosaur in your backpack, m’kay?) One assumes there will be several casualties and many narrow escapes before the survivors emerge with the much-needed DNA samples. And of course, there are plenty of stunning panoramic shots of this amazing world and the fantastic creatures in it.

Jurassic World Rebirth hits theaters on July 2, 2025.

poster art showing a woman scaling a cliff via rope while a hungry flying dinosaur opens its huge jaws just below her

Credit: Universal Pictures

Universal releases one last Jurassic World Rebirth trailer Read More »

biotech-company-regeneron-to-buy-bankrupt-23andme-for-$256m

Biotech company Regeneron to buy bankrupt 23andMe for $256M

Biotechnology company Regeneron will acquire 23andMe out of bankruptcy for $256 million, with a plan to keep the DNA-testing company running without interruption and uphold its privacy-protection promises.

In its announcement of the acquisition, Regeneron assured 23andMe’s 15 million customers that their data—including genetic and health information, genealogy, and other sensitive personal information—would be safe and in good hands. Regeneron aims to use the large trove of genetic data to further its own work using genetics to develop medical advances—something 23andMe tried and failed to do.

“As a world leader in human genetics, Regeneron Genetics Center is committed to and has a proven track record of safeguarding the genetic data of people across the globe, and, with their consent, using this data to pursue discoveries that benefit science and society,” Aris Baras, senior vice president and head of the Regeneron Genetics Center, said in a statement. “We assure 23andMe customers that we are committed to protecting the 23andMe dataset with our high standards of data privacy, security, and ethical oversight and will advance its full potential to improve human health.”

Baras said that Regeneron’s Genetic Center already has its own genetic dataset from nearly 3 million people.

The safety of 23andMe’s dataset has drawn considerable concern among consumers, lawmakers, and regulators amid the company’s downfall. For instance, in March, California Attorney General Rob Bonta made the unusual move to urge Californians to delete their genetic data amid 23andMe’s financial distress. Federal Trade Commission Chairman Andrew Ferguson also weighed in, making clear in a March letter that “any purchaser should expressly agree to be bound by and adhere to the terms of 23andMe’s privacy policies and applicable law.”

Biotech company Regeneron to buy bankrupt 23andMe for $256M Read More »

f1-in-imola-reminds-us-it’s-about-strategy-as-much-as-a-fast-car

F1 in Imola reminds us it’s about strategy as much as a fast car


Who went home happy from Imola and why? F1’s title race heats up.

IMOLA, ITALY - MAY 17: Charles Leclerc of Monaco driving the (16) Scuderia Ferrari SF-25 on track during during Qualifying ahead of the F1 Grand Prix of Emilia-Romagna at Autodromo Internazionale Enzo e Dino Ferrari on May 17, 2025 in Imola, Italy

In Italy there are two religions, and one of them is Ferrari. Credit: Ryan Pierse/Getty Images

In Italy there are two religions, and one of them is Ferrari. Credit: Ryan Pierse/Getty Images

Formula 1’s busy 2025 schedule saw the sport return to its European heartland this past weekend. Italy has two races on the calendar this year, and this was the first, the (deep breath) “Formula 1 AWS Gran Premio Del Made in Italy e Dell’Emilia-Romagna,” which took place at the scenic and historic (another deep breath) Autodromo Enzo e Dino Ferrari, better known as Imola. It’s another of F1’s old-school circuits where overtaking is far from easy, particularly when the grid is as closely matched as it is. But Sunday’s race was no snoozer, and for a couple of teams, there was a welcome change in form.

Red Bull was one. The team has looked a bit shambolic at times this season, with some wondering whether this change in form was the result of a number high-profile staff departures toward the end of last season. Things looked pretty bleak during the first of three qualifying sessions, when Yuki Tsunoda got too aggressive with a curb and, rather than finding lap time, found himself in a violent crash that tore all four corners off the car and relegated him to starting the race last from the pit lane.

2025 has also been trying for Ferrari. Italy expects a lot from the red team, and the replacement of Mattia Binotto with Frédéric Vasseur as team principal was supposed to result in Maranello challenging for championships. Signing Lewis Hamilton, a bona fide superstar with seven titles already on his CV, hasn’t exactly reduced the amount of pressure on Scuderia Ferrari, either.

Frederic Vasseur, Team Principal of Scuderia Ferrari, is at the Formula 1 AWS Gran Premio del Made in Italy e dell'Emilia-Romagna 2025 in Imola, Italy, on May 17, 2025, at Autodromo Internazionale Enzo e Dino Ferrari.

Ferrari team principal Frédéric Vasseur. Credit: Alessio Morgese/NurPhoto via Getty Images

Lewis Hamilton was much closer to teammate Charles Leclerc this weekend, which will be encouraging to everyone. After Hamilton’s exclusion from the Chinese Grand Prix, he has had to run a higher ride height, which has cost him speed relative to his younger teammate. Now it looks like he’s getting a handle on the car and lost out to Leclerc by 0.06 seconds in Q1 and 0.16 seconds in Q2. Unfortunately, Leclerc’s time was only good for 11th, and Hamilton’s was only good for 12th.

Sunday brought smiles for the Red Bull and Ferrari teams. In the hands of Verstappen, the Red Bull was about as fast as the black-and-orange McLarens, and while second was the best Verstappen could do in qualifying, the gap to McLaren’s Oscar Piastri was measured in the hundredths of seconds.

Verstappen’s initial start from the line looked unremarkable, too—the Mercedes of George Russell seemed more of a threat to the pole man. But Verstappen saw an opportunity and dove around the outside almost before Piastri even registered he was there, seizing the lead of the race. Once the Red Bull driver was in clean air, he was able to stretch the gap to Piastri.

IMOLA, ITALY - MAY 18: Oscar Piastri of Australia driving the (81) McLaren MCL39 Mercedes leads Max Verstappen of the Netherlands driving the (1) Oracle Red Bull Racing RB21 George Russell of Great Britain driving the (63) Mercedes AMG Petronas F1 Team W16 Lando Norris of Great Britain driving the (4) McLaren MCL39 Mercedes Fernando Alonso of Spain driving the (14) Aston Martin F1 Team AMR25 Mercedes and the rest of the field at the start during the F1 Grand Prix of Emilia-Romagna at Autodromo Internazionale Enzo e Dino Ferrari on May 18, 2025 in Imola, Italy.

Oscar Piastri is seen here in the lead, but it wouldn’t last more than a corner. Credit: Mark Thompson/Getty Images

Getting past someone is notoriously hard at Imola. In a 2005 classic, Fernando Alonso held off Michael Schumacher’s much faster car for the entire race. Even though the cars are larger and heavier now and more closely matched, overtaking was still possible, like Norris’ pass on Russell.

Undercut? Overcut?

But when overtaking is as hard as it is at a track like Imola, teams will try to use strategy to pass each other with pit stops. Each driver has to make at least one pit stop, as drivers are required to use two different tire compounds during the race. But depending on other factors, like how much the tires degrade, a team might decide to do two or even three stops—the lap time lost in the pits by stopping more often can be less than the time lost running on worn-out rubber.

In recent years, the word “undercut” has crept into F1 vocab, and no, it doesn’t refer to the hairstyles favored by the more flamboyant drivers in the paddock. To undercut a rival means to make your pit stop before them and then, on fresh tires and with a clear track ahead, set fast lap after fast lap so that when your rival makes their stop, they emerge from the pits behind you.

The undercut doesn’t always work, but in Imola, it initially looked like it did. Charles Leclerc stopped on lap 10 and leapfrogged Russell’s Mercedes, as well as his former Ferrari teammate and now Williams driver Carlos Sainz. Since Piastri wasn’t closing on Verstappen up front, McLaren decided to bring him in for an early stop.

IMOLA, ITALY - MAY 18: Race winner Max Verstappen of the Netherlands and Oracle Red Bull Racing celebrates on the podium during the F1 Grand Prix of Emilia-Romagna at Autodromo Internazionale Enzo e Dino Ferrari on May 18, 2025 in Imola, Italy.

Verstappen’s wins this season are far from inevitable. Credit: Clive Rose/Getty Images

But his advantage on new tires was not enough to eat into Verstappen’s margin, and he did not emerge in clean air but rather had to overtake car after car on track as he sought to regain his position ahead of those who hadn’t stopped. Sometimes, a strategy is the wrong one.

McLaren’s other driver, Lando Norris, couldn’t make a dent on Red Bull’s race, either. Having recognized the two-stop undercut wouldn’t work, Norris had stayed out, but he was almost 10 seconds behind Verstappen when it was finally time to change tires on lap 29. Shortly afterward, Esteban Ocon pulled his Haas to the side of the track with a powertrain failure, triggering a virtual safety car. With all the cars required to drive around at a prescribed, reduced pace, Verstappen was able to take his pit stop while only losing half as much time as anyone who stopped under green flag conditions.

Victory required a little more. Kimi Antonelli’s Mercedes also ground to a halt in a position that required a full safety car. With some on fresh rubber and others not, there were battles aplenty, but Verstappen wasn’t involved in any and won by seven seconds over Norris, with the recovering Piastri a few more seconds down the road.

Meanwhile, Hamilton had been having a pretty good Sunday of his own. Although he started 12th, he finished fourth, to the delight of the partisan, flag-waving crowd. Some of that was thanks to Leclerc coming together with the Williams of Alex Albon; after that on-track scuffle was sorted, Albon lay fifth, with Leclerc at sixth. Albon was right to feel aggrieved that he lost fourth place but equalled his best finish of the year.

IMOLA, ITALY - MAY 18: Ferrari fans wave their flags in a grandstand prior to the F1 Grand Prix of Emilia-Romagna at Autodromo Internazionale Enzo e Dino Ferrari on May 18, 2025 in Imola, Italy.

A fine fourth and a sixth were redemption for the Tifosi. Credit: Bryn Lennon – Formula 1/Formula 1 via Getty Images

Leclerc needed to cede the place to Albon, but at the same time, his complaint about the amount of rules lawyering that now accompanies every bit of wheel-to-wheel action is getting a bit tedious. If F1 isn’t careful, the rulebook will end up being too constraining, with drivers playing to the letter even if it’s bad for the sport and the show. And sixth place was still a decent result from 11th; the championships already look out of reach for Ferrari for 2025, but at least it’s in no danger of being overtaken by Williams in the tables, even if that is a threat on track.

McLaren is already at 279 points in the constructors’ championship, 132 points ahead of next-best Mercedes, so the constructors’ cup is looking somewhat secure. Things are a lot closer in the drivers’ standings, with Piastri on 146, Norris on 133, and Verstappen still entirely in the fight with 124 points.

Next weekend, it’s time for the Monaco Grand Prix.

Photo of Jonathan M. Gitlin

Jonathan is the Automotive Editor at Ars Technica. He has a BSc and PhD in Pharmacology. In 2014 he decided to indulge his lifelong passion for the car by leaving the National Human Genome Research Institute and launching Ars Technica’s automotive coverage. He lives in Washington, DC.

F1 in Imola reminds us it’s about strategy as much as a fast car Read More »

do-these-buddhist-gods-hint-at-the-purpose-of-china’s-super-secret-satellites?

Do these Buddhist gods hint at the purpose of China’s super-secret satellites?

Mission patches are a decades-old tradition in spaceflight. They can range from the figurative to the abstract, prompting valuable insights or feeding confusion. Some are just plain weird.

Ars published a story a few months ago on spaceflight patches from NASA, SpaceX, Russia, and the NRO, the US government’s spy satellite agency, which is responsible for some of the most head-scratching mission logos.

Until recently, China’s entries in the realm of spaceflight patches often lacked the originality found in patches from the West. For example, a series of patches for China’s human spaceflight missions used a formulaic design with a circular shape and a mix of red and blue. The patch for China’s most recent Shenzhou crew to the country’s Tiangong space station last month finally broke the mold with a triangular shape after China’s human spaceflight agency put the patch up for a public vote.

But there’s a fascinating set of new patches Chinese officials released for a series of launches with top secret satellites over the last two months. These four patches depict Buddhist gods with a sense of artistry and sharp colors that stand apart from China’s previous spaceflight emblems, and perhaps—or perhaps not—they can tell us something about the nature of the missions they represent.

Guardians of the Dharma

The four patches show the Four Heavenly Kings, protector deities in Buddhism who guard against evil forces in the four cardinal directions, according to the Kyoto National Museum. The gods also shield the Dharma, the teachings of the Buddha, from external threats.

These gods have different names, but in China, they are known as Duōwén, Zēngzhǎng, Chíguó, and Guăngmù. Duōwén is the commander and the guardian of the north, the “one who listens to many teachings,” who is often depicted with an umbrella. Zēngzhǎng, guardian of the south, is a god of growth shown carrying a sword. The protector of the east is Chíguó, defender of the nation, who holds a stringed musical instrument. And guarding the west is Guăngmù, an all-seeing god usually depicted with a serpent.

Do these Buddhist gods hint at the purpose of China’s super-secret satellites? Read More »

the-2025-vw-tiguan-caters-to-us-tastes-at-an-affordable-price

The 2025 VW Tiguan caters to US tastes at an affordable price

In the modern era, cars keep getting bigger and bigger between generations. Or at least, they’re certainly not getting smaller. That’s especially true in America, where bigger is always better and the vehicles in the current crop of “compact” crossovers are now nearly as large as full-size SUVs from a decade ago. Don’t ask about curb weights, either, as more powerful drivetrains, including widespread adoption of hybrid-electric components, add significant mass, as highlighted by the new BMW M5 “sport sedan.” 

Within that fray, however, the new Volkswagen Tiguan stands apart. VW purposefully refined the third-gen Tiguan to cater better to American consumer needs, which meant dropping the third row to create more interior volume for the front and rear seats. The wheelbase still measures the same length at 109.9 inches (2,791 mm), but shorter overhangs mean the overall length actually shrinks by nearly two inches. Yet more efficient packaging on the inside also results in a marginal passenger volume increase of about two percent.

To help keep pricing attractive at below $30,000 to start, VW also decided to skip out on a hybrid variant, but the new EA888evo5 2.0 L turbocharged-four nonetheless delivers more power and improved fuel economy. And all of the above actually contributes to the Tiguan losing weight while evolving from the second to third generation, shaving about 160 lbs (72.5 kg), depending on trim.

There’s some ID.4 in here, but also a big helping of generic. Michael Teo Van Runkle

Generic outside, great inside

Volkswagen USA recently invited Ars to join a rainy test drive of the Tiguan’s SE and SEL R-Life trims in Bozeman, Montana. At first glance, the new exterior definitely hews more closely to current crossover trends, which the Tiguan arguably helped to inaugurate back in the late-2000s. There’s also a healthy dose of Volkswagen ID.4 design language throughout, especially at the nose. The interior truly steps up to a new level, though. I started out in an almost-base Tiguan SE, which means front-wheel drive and minimal options, not even onboard navigation.

Like most buyers, though, I connected my iPhone via Wireless CarPlay, which effectively makes onboard nav obsolete. And the SE’s 12.9-inch touchscreen atop the dash provides all the necessary tech, as premium materials throughout clearly prioritize touchpoints to enhance the impression of quality.

The 2025 VW Tiguan caters to US tastes at an affordable price Read More »

xai-says-an-“unauthorized”-prompt-change-caused-grok-to-focus-on-“white-genocide”

xAI says an “unauthorized” prompt change caused Grok to focus on “white genocide”

When analyzing social media posts made by others, Grok is given the somewhat contradictory instructions to “provide truthful and based insights [emphasis added], challenging mainstream narratives if necessary, but remain objective.” Grok is also instructed to incorporate scientific studies and prioritize peer-reviewed data but also to “be critical of sources to avoid bias.”

Grok’s brief “white genocide” obsession highlights just how easy it is to heavily twist an LLM’s “default” behavior with just a few core instructions. Conversational interfaces for LLMs in general are essentially a gnarly hack for systems intended to generate the next likely words to follow strings of input text. Layering a “helpful assistant” faux personality on top of that basic functionality, as most LLMs do in some form, can lead to all sorts of unexpected behaviors without careful additional prompting and design.

The 2,000+ word system prompt for Anthropic’s Claude 3.7, for instance, includes entire paragraphs for how to handle specific situations like counting tasks, “obscure” knowledge topics, and “classic puzzles.” It also includes specific instructions for how to project its own self-image publicly: “Claude engages with questions about its own consciousness, experience, emotions and so on as open philosophical questions, without claiming certainty either way.”

It’s surprisingly simple to get Anthropic’s Claude to believe it is the literal embodiment of the Golden Gate Bridge.

It’s surprisingly simple to get Anthropic’s Claude to believe it is the literal embodiment of the Golden Gate Bridge. Credit: Antrhopic

Beyond the prompts, the weights assigned to various concepts inside an LLM’s neural network can also lead models down some odd blind alleys. Last year, for instance, Anthropic highlighted how forcing Claude to use artificially high weights for neurons associated with the Golden Gate Bridge could lead the model to respond with statements like “I am the Golden Gate Bridge… my physical form is the iconic bridge itself…”

Incidents like Grok’s this week are a good reminder that, despite their compellingly human conversational interfaces, LLMs don’t really “think” or respond to instructions like humans do. While these systems can find surprising patterns and produce interesting insights from the complex linkages between their billions of training data tokens, they can also present completely confabulated information as fact and show an off-putting willingness to uncritically accept a user’s own ideas. Far from being all-knowing oracles, these systems can show biases in their actions that can be much harder to detect than Grok’s recent overt “white genocide” obsession.

xAI says an “unauthorized” prompt change caused Grok to focus on “white genocide” Read More »