#public-domain
Cities should have the ability to eminent domain their buildings to turn into public housing. Just compensation? We’ll forego fining you for all the other violations you’ve no doubt committed as a landlord.
"Some landlords are even using deportation fears as leverage. Goldberg’s neighbor abandoned their rent-controlled unit voluntarily after their landlord threatened to report their marriage as fraudulent for the purposes of acquiring a green card, she said. “They left in fear.”
An AI boom is sending San Francisco rents through the roof: ‘nowhere left for people to go’
According to city’s rent board, eviction notices are up 44% and tenants are on edge over landlords swooping in over their homes
www.theguardian.com
October 8, 2026 at 6:15 PM
I'm a fan of the WindowsHModular project (github.com/Leandros/Win...), which solves some of these issues. It also makes sandboxing the windows headers much easier and only using the pieces actually required.
GitHub - Leandros/WindowsHModular: A modular Windows.h Header. Licensed under Public Domain & MIT.
A modular Windows.h Header. Licensed under Public Domain & MIT. - Leandros/WindowsHModular
github.com
October 8, 2026 at 5:53 PM
New game, made in #BLIT386! Lasermania (port from Atari 8bit, L.K. Avalon 1990, public domain), ported by Michal Hotovec: demo.michalhotovec.com/lasermania/ #gamedev #WebGPU
October 8, 2026 at 5:45 PM
Aerosmith will return for two Hollywood Bowl concerts on Oct. 29 and Nov. 1 — their first proper live shows since retiring from touring in 2024. Guests include Slash, Heart, RUN DMC and Billy Idol.

Photo: U.S. Navy/Rob Rubio, public domain.

Follow Carson TV World.
October 8, 2026 at 5:20 PM
Mark Millar is such a piece of sh*t! He knows that even when the characters are public domain, DC & Marvel will still try to sue his ass, and that's probably what he wants. He's just a desperate attention seeker.

Also, I hate sharing stuff from BC, but yeah..
bleedingcool.com/comics/mark-...
Mark Millar Has An Artist And Timeframe To Do Superman, Batman & More
Mark Millar has paid an artist and has a timeframe for Superman, Batman, Wonder Woman, Flash, Green Lantern, Captain America films and comics
bleedingcool.com
October 8, 2026 at 5:17 PM
If you are an elected official being paid by taxpayers to represent them then all records of any actions you undertake within that role (official or not) should be public domain for all time.
October 8, 2026 at 5:15 PM
Hey! Did you know that the original Night of the Living Dead is in the public domain?

You can watch the whole movie on its Wikipedia article for free! Just go to the Plot section!

en.wikipedia.org/wiki/Night_o...
Night of the Living Dead - Wikipedia
en.wikipedia.org
October 8, 2026 at 5:07 PM
Lon Chaney played both Valjean and Javert in the 1925 Universal version. Two men in one actor, which is close to what Hugo was doing on the page anyway.
October 8, 2026 at 5:06 PM
so his plan is effective and a success...
if you're an egomaniacal sociopath.
the letters "RFK" used in conjunction
should be public domain...
and stripped from him.
it's an insult to his father
his mother
his family
and their respected legacies as public servants.
Jr is a self serving profiteer.
October 8, 2026 at 5:01 PM
Cosmicism ePUB bundle just launched: some public domain HPL, but also other interesting things, like antholgies ed Ellen Datlow, Houellebecq's H P Lovecraft Against The World, Against Life, Tyson's Necronomicon, Harms & Gonce's The Necronomicon Files, and others.
Cthulhu Mythos & Cosmic Horror Book Bundle | eBook Bundle | Fanatical
Unlock up to 40 terrifying books, including masterpieces by...
www.fanatical.com
October 8, 2026 at 4:42 PM
On This Day in Trumpery: October 8
A Plot to Kidnap a Governor
October 8, 2026 at 4:03 PM
Want to get ready for Spooky Season? You should listen to these short stories! Librivox is a group of volunteer readers that do stories that are in the public domain. Set up a little fire when it gets chilly and listen to some spoky stories!

librivox.org/group/466?pr....
Works in "Short Ghost and Horror Story Collections" | LibriVox
LibriVox
librivox.org
October 8, 2026 at 4:01 PM
🍿 Movie Quote of the Day
“If there are lines on my face, they have been etched there by time and thought and experience.”
Attributed to Ruth Chatterton, film actress and novelist
---
📸: Publicity photo by The New Movie Magazine, now in the Public Domain
📝: #movies, #films, #RuthChatterton, #cinema
October 8, 2026 at 4:00 PM
Reading his comments, I get the impression he doesn't know *what's* going into the public domain with those characters. He seems to think he can just launch a full-fledged Superman series, and that's simply not the case
October 8, 2026 at 3:18 PM
Hackers Use Web3 and Blockchain C2 to Hide Supply Chain Attacks Targeting Cloud Credentials
Hackers Use Web3 and Blockchain C2 to Hide Supply Chain Attacks Targeting Cloud Credentials
Threat actors are increasingly turning public blockchain networks into a command-and-control (C2) layer for software supply chain malware, helping them rotate infrastructure without changing the malicious code already running on developer systems. The method gives criminals a resilient way to direct infected packages toward new data-theft servers while making traditional domain blocklists less effective. The risk is especially serious for cloud-focused organizations. Poisoned open-source packages can run inside developer laptops and CI/CD pipelines, where they may access temporary cloud identity tokens, deployment secrets, service-account keys, GitHub credentials and other high-value data. A recent ChainDrop npm worm investigation showed how compromised trusted publishing paths can turn ordinary dependency updates and project settings into a route for credential theft. Analysts at Unit 42 identified the ChainDrop malware as a self-propagating npm worm that infected more than 400 packages. The researchers found that it collected cloud credentials, npm and GitHub tokens, SSH keys, Kubernetes tokens, Terraform state files, Vault tokens and secrets stored in developer environments. It also searched the memory of GitHub Actions runner processes for short-lived OpenID Connect, or OIDC, tokens and runner secrets. Hackers Use Web3 and Blockchain C2 In a normal malware operation, attackers hard-code a domain or IP address into the malware. That creates a clear target for defenders: security teams can block the address, registrars can suspend the domain, and package platforms can scan the code for it. Blockchain C2 changes that model. Instead of containing a fixed C2 address, the malware queries a smart contract or blockchain transaction and retrieves the current destination at runtime. Attack flow (Source – Unit42) ChainDrop used this approach through an Ethereum smart contract. Unit 42 said the worm queried the contract to obtain the address used for data theft, then moved its C2 from npm-cache[.]com to awqhnjewqjkl[.]icu through a single Ethereum transaction. The change did not require the attackers to republish packages or push a fresh malware version to victims. This technique is commonly called EtherHiding. It does not mean the blockchain itself is malicious; instead, criminals misuse its public and decentralized design as an address book, payload store or dead-drop service. A previous EtherHiding malware delivery report described how smart contracts can return encoded JavaScript payloads and let operators change delivery content without modifying a compromised website. ChainDrop Targets Development Workflows The ChainDrop infection begins with an altered npm package containing a preinstall command. That command launches setup.mjs , which downloads the legitimate Bun JavaScript runtime if it is absent and uses it to run an obfuscated payload. Bun was not compromised; the threat actors simply used the legitimate runtime to execute their code. Once active, the malware checks local files, environment variables and cloud metadata services for credentials. It also looks at running build processes, an important detail because CI/CD systems often use temporary credentials that do not remain on disk. Those tokens can still give attackers a direct path to cloud APIs, deployment environments or source-code systems while they are valid. ChainDrop also established persistence through developer tools. It wrote a VS Code task that can run when a folder opens and added a Claude Code SessionStart hook. That means a developer could trigger the malware simply by opening a project or starting an AI coding session. The same risk appears in the developer tool configuration exposure reported around the wider ChainDrop campaign, where trusted local project files became an execution route. NullReceiver IPv4 address resolution extraction workflow (Source – Unit42) A second campaign, tracked as PolinRider, shows that this model is moving beyond npm. Researchers linked the campaign to North Korea-aligned activity and found malicious loaders in npm, Packagist, Go modules and Chrome extensions. The loaders used blockchain and public RPC services connected to TRON, Aptos and BNB Smart Chain to obtain encrypted follow-on payloads. The campaign hid its code in files that appeared normal to many developers, including vite.config.js , fake .woff2 font files and .vscode/tasks.json . This approach matters because many dependency scanning tools focus on package manifests and lockfiles, not editor settings, workspace automation or repository configuration. The earlier hidden JavaScript loader campaign also showed how PolinRider used such files to deliver DEV#POPPER and OmniStealer payloads. For defenders, blockchain traffic from build runners and developer endpoints should be treated as a meaningful signal when the organization has no Web3 business need. Teams should review package lifecycle scripts, inspect repository configuration files, isolate CI runners, restrict outbound connections from build systems and rotate every credential reachable from an affected host. Indicators of compromise (IoCs):- IoC Type Indicator Detection Context Ethereum smart contract 0xE1f2395ee43e45A1556EC6438a88c31B83493103 ChainDrop C2 resolver contract queried through Ethereum RPC services Ethereum transaction 0xc55920f1bd0531b6738153068a666c080ddded47e6256f1fd980d51c0b507c91 Transaction used to rotate the ChainDrop C2 domain Ethereum wallet 0x55F9780ef31cD Wallet reported as the deployer of the C2 resolver contract C2 domain npm-cache[.]com Earlier active ChainDrop exfiltration endpoint C2 domain pypi-get[.]com Domain stored in the original resolver contract list C2 domain js-mirror[.]com Domain stored in the original resolver contract list C2 domain awqhnjewqjkl[.]icu Rotated ChainDrop C2 domain observed after the Ethereum transaction File artifact .claude/math_init.js Obfuscated ChainDrop JavaScript payload File artifact .claude/settings.json Claude Code SessionStart persistence configuration File artifact .claude/setup.mjs Dropper copy used in persistence chain File artifact .vscode/setup.mjs Dropper copy linked to VS Code persistence File artifact .vscode/tasks.json VS Code task configured to run when a project folder opens File artifact .github/workflows/codeql_analysis.yml Malicious workflow template used to serialize GitHub secrets String marker thebeautifulmarchoftime GitHub commit-history fallback marker for C2 resolution String marker IfYouBlockThisAPIKeyItWillCrashTheLiveProductionServersOfAllThirdPartyClients Marker used in commit messages containing stolen tokens Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC The post Hackers Use Web3 and Blockchain C2 to Hide Supply Chain Attacks Targeting Cloud Credentials appeared first on Cyber Security News .
cybersecuritynews.com
October 8, 2026 at 2:58 PM