Samsung’s best wireless earbuds so far, improving on the Galaxy Buds 3 Pro with a stronger noise-cancelling performance, more balanced sound, better call quality, and solid battery life. If you have a Galaxy Ultra smartphone, you can buy with confidence
Wide, spacious, clear sound
Strong noise-cancelling
Comfortable fit
Improved call quality
Solid battery life
Need a Galaxy smartphone to get the best performance
Controls are still fiddly
Key Features
Advertisement
Review Price:
£219
SSC-UHQ
Advertisement
Higher quality, 24-bit/96kHz sound over Bluetooth
360 Audio with Head Tracking
Advertisement
Have music follow your movements
Super Clear Call
Advertisement
Clearer calls with Samsung smartphones
Introduction
Every year there’s a new Samsung Galaxy smartphone, and more often than not, alongside them is a new pair of headphones – in this case, it’s the Galaxy Buds Pro 4.
The Galaxy Buds Pro 4 don’t receive as much fanfare as the smartphones (in this case the Samsung Galaxy S26 Ultra), less the headline and more a sub-header; but similarly to how Apple approaches its true wireless pairs, the Galaxy Buds are a partner to the smartphones rather than an entity that exists on its own.
Advertisement
The Galaxy Buds have been getting better – aside from the strange burst of designs a few years ago – are these the best yet?
Advertisement
Design
Plush level of comfort
IP57 rating
White, black and pink gold finishes
Samsung has toned down the AirPods-vibe though, at the end of the day, these are a pair of stem-based wireless earbuds – there’s not much you can do with the actual design.
But Samsung has tried and the Galaxy Buds 4 Pro do look nice, the silver ‘real metal blade’ finish of the stem feels suitably premium. Comfort levels are very good. I’ve worn these for hours and not felt any discomfort. Small, medium and large ear tips are provided, with medium as default.
Image Credit (Trusted Reviews)
I do, however, find that the seal for these earbuds can come loose while walking. Even munching on food can cause the fit to loosen and require a push back in.
Advertisement
Advertisement
Samsung continues with gesture/pinch controls. I’ve never been a big fan and I can’t say the Galaxy Buds 4 Pro have persuaded me to think otherwise. I find it fiddly, and often when I’ve tried to play/pause a track I’ve ended up lowering the volume. I often just use the controls in-app than use the onboard controls – it’s much easier for me.
Image Credit (Trusted Reviews)
The charging case differs from the Galaxy Buds 3 Pro and is different from the Galaxy Buds 4 launched alongside the Pro version. Compared to the 3 Pro, this new case is more compact but also slightly taller – the see-through case is a nice visual touch. Rated at IP57, these earbuds put out a stiff hand against water, dirt and dust (more so than most premium true wireless), though the case doesn’t sound like it has any protection.
Colours come in white and black, but buy directly from Samsung and there’s the option of a Pink Gold (which looks like it costs the same).
Noise-Cancellation
Galaxy AI-supported features
26 hours battery life with ANC
Galaxy Wearable app for customisation
In general, the Galaxy Buds 4 Pro’s adaptive noise-cancellation is good, very good even, especially in terms of how consistent the performance is.
Advertisement
Whether I’m on the Victoria Line, a train, a bus, an aeroplane, the DLR or walking outside with traffic going past, the level of quiet and calm has always been very high. The barometer I have with ANC headphones is whether I need to raise the volume to mask more noise and I never felt the need to do that with the Galaxy Buds 4 Pro.
Advertisement
Cars are reduced to hums, the Underground is no longer a constant noise machine, and compared to the Galaxy Buds 3 Pro, these do thin out noise better.
Image Credit (Trusted Reviews)
The transparency mode sounds clear – big and broad in terms of what you can hear, and it sounds natural enough, though again perhaps not to the same levels of Sony and Bose produce.
Call quality is very good. With Samsung Galaxy phones there’s a Super Clear Call feature that enhances clarity and reduces noise, but even using a OnePlus smartphone the performance was very good.
Advertisement
Advertisement
Background noise was reduced and though my voice did sound muffled – at times it was hard for the other person to hear some words – but overall the performance is good for use when you’re outside.
Features
Galaxy smartphone exclusive features
Wear app for non-Galaxy smartphones
The Galaxy Buds 4 Pro aren’t short of features, though you’ll need to have a Galaxy smartphone to get the most out of them, especially one that’s been updated to the One UI 8.5, as that has access to features not present in previous versions.
Like with Apple’s AirPods, the Galaxy Buds’ UI is built into the Samsung smartphone UX, but for everyone else, you’ll need to download the Galaxy Wear app.
Image Credit (Trusted Reviews)
Wirelessly there’s Bluetooth 6.1, which brings some enhancements over Bluetooth 5 (everything is just better, in simple terms), and I’ve found the connection to be strong wherever I am (and that’s without a phone that supports Bluetooth 6). Instability and interference have barely been an issue.
Advertisement
The headphones support an interesting array of codecs for the Bluetooth fans out there, with SBC, AAC, LC3, and Samsung’s own SSC and SSC-UHQ, the latter acting as Samsung’s high quality codec of choice against Sony’s LDAC and Qualcomm’s aptX. SSC is only available on Samsung Galaxy phones though.
Advertisement
You can toggle it on in the app/settings and it lets loose 24-bit/96kHz audio over a Bluetooth connection – though don’t take that to mean it’s lossless. It’s very likely to be lossy (which means detail is lost).
Image Credit (Trusted Reviews)
There’s 360 Audio with Head Tracking that builds on top of immersive audio formats such as Dolby Atmos music. The head tracking works well when listening to Sarah Kinsley’s Truth of Pursuit and Brent Faiyaz’s Other Side on Tidal, but there’s possibly the slightest lag when moving my head and waiting for music to respond.
Otherwise, I’m rather impressed in terms of clarity – immersive audio tends to sound less detailed and softer but the Galaxy Buds 4 Pro do a good job of keeping clarity levels high.
There are Head Gestures for accepting and rejecting calls (just added to One UI 8.5). and Earbud fit test (much less annoying than the Sony Sound Connect version): customisation of controls, battery life indicators and swapping through noise-cancelling modes, EQ options and Audio Broadcast (Auracast by another name). There are voice controls (mainly through Bixby) and accessibility controls if needed.
Advertisement
Advertisement
Want to translate words from a different language? You can read a transcript of what the earbuds hear, translated to your language via Galaxy AI, speaking of which, Samsung seems to have calmed down the AI narrative and rightly so. I don’t need to be told about AI, I just need it to work in the way it’s meant to.
Image Credit (Trusted Reviews)
You can switch to nearby devices without having to jump into pairing mode, though the fine print indicates these need to be connected to your Samsung account. With that in mind, Bluetooth multipoint is a slight mystery in that it is supported (with Samsung devices) and isn’t (with anything other than Samsung). I can’t have the Galaxy Buds 4 Pro connected to a Galaxy smartphone or OnePlus model at the same time.
Lose the earbuds and you can locate them through Samsung Find, although it seems to think I’m not in my house but next door – close enough I suppose. The Adapt Sound feature is not what I initially thought it’d be. It tunes the sound for how old you are, boosting frequencies based on your age. You can add a personalised sound profile by going through audio tests to determine your hearing.
Battery Life
Six hours per charge
Wireless charging
Samsung claims the Galaxy Buds 4 Pro are capable of six hours with ANC on, which doesn’t sound the most progressive (and isn’t), with a total of 26 hours with the charging case (without ANC it’s 7 and 30 hours).
Advertisement
Perhaps Samsung have erred on the safe side but I’ve found battery life pretty strong. An hour’s listening saw both earbuds fall to 87%, which would put the Galaxy Buds 4 Pro at around 8 hours, not six.
Advertisement
There’s fast-charging for those in a fix, and wireless charging support as well.
Sound Quality
Clear, detailed, spacious sound
Wide soundstage
Balanced, warm approach
Not too dissimilar to the Galaxy Buds 3 Pro, the Galaxy Buds 4 Pro feature a two-way speaker that’s been redesigned from before.
There’s now a wider woofer alongside a precision tweeter, with the aim of delivering deep, textured sub-bass to extended highs with a “faster transient response, a rich midrange body and sharp detail”. Each driver has its own amplifier, which should lead to reduced distortion.
Paired with a non-Galaxy smartphone and the results are… fine. The Galaxy Buds 4 Pro sound on the rich side but the bass isn’t the most assertive, the highs don’t come across as the brightest and they’re not the most dynamic or energetic sounding pair I’ve ever heard.
Advertisement
Advertisement
Image Credit (Trusted Reviews)
Some of the traits carry over when paired to a Galaxy smartphone, but to unlock the highest level of performance from the Galaxy Buds 4 Pro, you need to toggle on the SSC-UHQ feature. With that, these earbuds ascend to a higher level.
Which is not to say they match the Sony WF-1000XM6, which beat the Galaxy Buds 4 Pro for insight, detail and energy, but they have qualities of their own that aren’t to be dismissed.
The soundstage is very wide. Bass never hogs the limelight but I’d vote for having a bit more depth and energy to the low frequencies. With a track like Hard Life’s Skeletons, the bass performance leaves me wanting a bit more in terms of energy.
But it’s the clarity of these earbuds that impresses, as well as the natural tone they strike whether it’s with more upbeat K-pop tracks like ILLIT’s Magnetic or slower, more downtempo tracks like Amy Winehouse’s Back to Black – the wide soundstage, crisp tone to highs and levels of insight and detail with vocals stand out.
Image Credit (Trusted Reviews)
Advertisement
Andreas Ihlebæk’s Come Summer is a track I play to try and catch headphones out – the highs sound bright, but it can expose a lack of precision and detail, sounding soft and almost too bright if headphones get it wrong. The Galaxy Buds 4 Pro stay on the right side of balanced, bringing brightness and variation to the highs while maintaining higher levels detail and clarity.
Advertisement
However, are the Galaxy Buds 4 Pro better sounding than the Galaxy Buds 3 Pro? Initially there’s a question mark around that. The approach both take is similar but the Galaxy Buds 4 Pro eke out a little more insight and detail from tracks, administering a slightly more natural tone. It isn’t enough to necessarily trade the older model for the newer ones, but if you’re coming from the Galaxy Buds 2, this level of sound is a jump up
Should you buy it?
If you’ve got a Galaxy phone
Enable the SSC-UHQ feature and the Galaxy Buds Pro 4 show off their best selves.
Advertisement
You don’t have a toe in the Samsung ecosystem
Advertisement
No Samsung Galaxy phone? Then much like with the Galaxy Buds 3 Pro, there’s not much point even glancing at these headphones.
Final Thoughts
I had to have a good think in terms of how to approach the scoring for these headphones. They are better paired with a Galaxy smartphone, in particular the Ultra series, and the way Samsung markets these headphones, there’s little reason to buy them if you’re not a Galaxy owner.
So the score relates to the experience you’d get with a Galaxy smartphone, much like AirPods work best with an iPhone.
The Galaxy Buds 4 Pro sound good, they could be a little more bolder and exciting but I’ve enjoyed them. It’s not quite Sony WF-1000XM6 or Status Pro X level, but for Samsung owners with the SSC-UHQ codec enabled, they’re a good listen.
The noise-cancelling impresses, the fit is comfortable, battery life is solid and the call quality is good. Overall, this is a strong effort from Samsung, and their best true wireless earbuds yet.
Advertisement
How We Test
The Samsung Galaxy Buds 4 Pro were tested over the course of a month.
They were used on public transport and aeroplanes to test the noise-cancellation, while a pink noise test was carried to test against other headphones. In cities such as London and Munich to test real-world performance.
A battery drain was carried to test the battery life, while calls were made to test the call quality
Tested for a month
Tested with real world use
Battery drain carried out
Advertisement
FAQs
Does the Samsung Galaxy Buds 4 Pro support fast charging?
Advertisement
Along with wireless charging, the Galaxy Buds 4 Pro support fast-charging via a USB input, with a 10-minute charge providing an hour of playback
An international law enforcement action called Operation Alice has shut down over 373,000 dark web sites that offered fake CSAM packages.
The investigation, led by Germany and supported by Europol, began in mid-2021 and focused on a platform called “Alice with Violence CP,” operated by a 35-year-old suspect based in China.
These sites advertised child sexual abuse material (CSAM) and cybercrime-as-a-service offerings, including stolen credit card data and access to compromised systems.
Seizure banner on one of the scam sites Source: Europol
According to Europol, the sites used showed previews of claimed CSAM “packages” to trick users into entering their email addresses and paying between EUR 17 and EUR 250 in Bitcoin, receiving nothing in return.
“Each package had an estimated cost of between EUR 17 and EUR 215, and promised data volumes ranging from a few gigabytes to several terabytes of CSAM,” explains Europol.
Advertisement
“However, these were purely fraudulent sites where CSAM was advertised and previewed but never delivered.”
The fraudulent CSAM platform fooled around 10,000 users into paying roughly $400,000 to the operator of the sites. Of those, the authorities have identified 440 users in 23 countries, and are currently investigating 100 of them.
Although these people never received the illegal material, they still tried to purchase CSAM, financially supporting child abuse and demonstrating criminal intent. Even attempting to buy such material is prosecuted in many jurisdictions.
At its peak, the scam network’s infrastructure comprised 287 servers, with a significant portion (105) located in Germany, all of which have now been seized. German authorities have also issued an international arrest warrant for the Chinese operator.
Advertisement
Europol highlights its broader child protection work, including the Help4U support platform launched in November 2025, and its “Stop Child Abuse – Trace an Object” initiative, which invites people to identify the origin of objects seen in CSAM material that may lead to the identification of perpetrators, and the saving of children from abuse.
Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.
Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.
Following a slew of mostly average to quite good pre-launch reviews for Crimson Desert, Pearl Abyss’ stock price fell almost 30%. It seems many had expected the game to receive Baldur’s Gate 3-level praise. Read Entire Article Source link
The 3DFX Voodoo was not the first dedicated 3D graphics chipset by any means, but it became the favourite for gamers among the early mass-market GPUs. It would be found on a 3D-processing-only PCI card that sat on the feature connector of your SVGA card. The Voodoo took any game that supported its Glide API into the world of (for the time) smooth and beautiful 3D. They’re worth a bit now, but if you don’t fancy forking out for mid-’90s silicon in 2026, there’s another option. [Francisco Ayala Le Brun] has implemented the 3DFX Voodoo 1 in SpinalHDL for FPGAs.
The write-up goes into the Voodoo’s architecture. Where the parts of a modern GPU are programmable for the various functions it can do, in this part they are dedicated hardware functions for the various graphics tricks the chip can perform. Implementing such an architecture on an FPGA led to bugs and timing problems, and the write-up deals with that in detail.
The whole thing can be found in a GitHub repository if you’re curious, and is definitely worth a read for anyone interested in 1990s retrocomputing. 3DFX themselves would eventually be swallowed by Nvidia, a rival whose offerings would overtake them at the end of the ’90s, but they still represent a somewhat special moment. Don’t forget, if you have the real thing, you can probably upgrade its memory.
Microsoft Azure Monitor alerts are being abused to send callback phishing emails that impersonate warnings from the Microsoft Security Team about unauthorized charges on your account.
Azure Monitor is Microsoft’s cloud-based monitoring service that collects and analyzes data from Azure resources, applications, and infrastructure. It enables users to track performance, notify about billing changes, detect issues, and trigger alerts based on various conditions.
Over the past month, numerous people have reported receiving Azure Monitor alerts warning of suspicious charges or invoice activity on their accounts, urging them to call an enclosed phone number.
“Alert rule description MICROSOFT CORPORATION BILLING AND ACCOUNT SECURITY NOTICE (REF: MS-FRA-6673829-KP). Our system has detected a potentially unauthorized charge on your account. Transaction Details: Merchant: Windows Defender. Transaction ID: PP456-887A-22B. Amount: 389.90 USD. Date: 03/05/2026l,” reads the fake billing alert.
Advertisement
“For your protection, this transaction has been temporarily placed on hold by our Fraud Detection Team. To prevent possible account suspension or additional fees, please verify this transaction immediately. If you did NOT authorize this payment, contact our 24/7 Microsoft Account Security Support at +1 (864) 347-2494 or +1 (864) 347-4846.”
“We apologize for any inconvenience and appreciate your prompt response. Microsoft Account Security Team.”
Microsoft Azure Monitor alert used in a callback phishing scam Source: BleepingComputer
Unlike other phishing campaigns, these messages are not spoofed, but are sent directly by the Microsoft Azure Monitor platform using the legitimate azure-noreply@microsoft.com email address.
As the emails are sent through Microsoft’s legitimate email platforms, they pass SPF, DKIM, and DMARC email security checks, making them appear more trustworthy.
The threat actors are conducting this campaign by creating alerts in Azure Monitor for easily triggered conditions, such as new orders, payments, generated invoices, and other billing events.
Advertisement
When creating alerts, you can enter any message you want in the description field, which the attackers use to put their callback phishing message.
Description field when creating an Azure Monitor alert Source: Microsoft
These alerts are then configured to send emails to what is believed to be a mailing list under the attacker’s control, which forwards the email to all the targeted people in the attack.
This also preserves the original Microsoft headers and authentication results, helping the emails bypass spam filters and user suspicion.
BleepingComputer has seen multiple alert categories used in this campaign, mostly using invoice and payment-themed rules designed to resemble automated billing notifications:
Azure monitor alert rule order-22455340 was resolved for invoice22455340
Azure monitor alert rule Invoice Paid INV-d39f76ef94 was resolved for invd39f76ef94
Azure monitor alert rule Payment Reference INV-22073494 was resolved for purchase22073494
Azure monitor alert rule Funds Successfully Received-ec5c7acb41 was triggered for subec5c7acb41
Azure monitor alert rule MemorySpike-9242403-A4 was triggered
Azure monitor alert rule DiskFull-3426456-A6 was triggered for locker3426456
The campaign relies on creating a sense of urgency, which in this case is the unusual $389 Windows Defender charge, to trick the users into calling the listed phone number.
While BleepingComputer did not call the number in this scam, previous callback phishing campaigns led to credential theft, payment fraud, or the installation of remote access software.
Advertisement
As these emails use a more enterprise or corporate theme, they may be intended to gain initial access to corporate networks for follow-on attacks.
Users should treat any Azure or Microsoft alert that includes a phone number or urgent request to resolve billing issues with suspicion.
Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.
Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.
The Government of Mexico City has launched Xoli, a chatbot that will provide information on services, tourism, and cultural offerings. It’s available now via WhatsApp in both English and Spanish.
The platform was designed to meet the demand of the millions of visitors expected to arrive during the 2026 FIFA World Cup. However, the authorities assure that the tool will remain active once the sporting event is over, with the aim of promoting economic activities and facilitating access to public services in the capital.
In a press conference, Clara Brugada, head of the Mexico City government, stated that Xoli “will be the technological instrument that will allow us to link culture, tourism, recreation, and entertainment with the population.”
Chat With Xoli
The tool was developed entirely by the capital’s government, as a result of the collaboration between the Digital Agency for Public Innovation and the local Ministries of Tourism and Culture.
Advertisement
The chatbot is already available on mobile devices and will operate continuously, seven days a week, 24 hours a day. To use it, just open WhatsApp, start a chat with the number 55 6565 9395, and send the word “Hola.”
Xoli (pronounced sho-lee) will immediately ask if you want to continue in English or Spanish. After selecting the preferred language, users will be able to access a menu with various categories of information, including culture, tourism, gastronomy, and mobility, or just ask a question about anything in the city.
In the context of the 2026 World Cup, there will be a specific section with information about the competition, including special events, match details, broadcasts of games in public places, and ticket purchase options.
Screenshot of Xoli, Mexico City’s tourist chatbot for the 2026 World Cup.
Advertisement
Cortesía Xoli
The capital’s government highlighted that this technology contributes to the city’s consolidation as “a more innovative and accessible city,” by speeding up access to official information, offering timely responses and strengthening tourism promotion strategies.
Alejandra Frausto, head of Mexico City’s Ministry of Tourism, pointed out that close to 3,000 tourist, recreational, and cultural activities are carried out daily in the capital. In seasons of high demand, this figure can increase to 5,000 events a day. “Translating this data into reliable and accessible information involves a great effort, but it is now possible thanks to this chatbot,” he says.
A Good Sport
The launch of Xoli adds to the technological efforts driven by the federal government to turn the upcoming World Cup into an engine of development for commerce, sports, tourism, and culture throughout the country.
Late last year, Mexican president Claudia Sheinbaum presented the Mexico 2026 Social World Cup plan, which calls for more than 177 festivities and 5,000 activities linked to the tournament, as well as 74 tournaments and soccer cups aimed at students, workers, and the general public. The program also includes around 1,500 actions within the Vive Saludable (Live Healthy) initiative, aimed at promoting healthy lifestyles, as well as the rehabilitation of 4,200 public sports fields and spaces.
Advertisement
Among the actions announced is the creation of the Conoce México app developed jointly by the Agency for Digital Transformation and Telecommunications (ATDT) and the Ministry of Tourism. This app will allow fans, both national and foreign, to get updated information on matches, venues, routes, services, and cultural activities.
The war withIran and ensuing blockade in the Strait of Hormuz, a critical shipping lane, has spiked oil prices and sent governments scrabbling for their reserves. How high will prices go, and how bad could it get?
On Friday night, United Airlines CEO Scott Kirby published a memo to his employees showing that his very fuel-dependent business is prepping for a very long fallout. “Our plans assume oil goes to $175/barrel and doesn’t get back down to $100/barrel until the end of 2027,” he wrote.
Jet fuel accounts for between a quarter and a third of airlines’ operating costs. Prices have doubled from $70 a barrel since the war started four weeks ago, threatening to seriously cut into airlines’ profitability. Kirby said that his airline has a strategy: United will cut some 5 percent of its planned flight schedule during the second and third quarters of this year, with trims coming especially in off-peak periods like red-eyes and less popular travel days: Tuesdays, Wednesdays, and Saturdays.
“Honestly, I think there’s a good chance it won’t be that bad,” Kirby wrote in the memo, “but … there isn’t much downside for us to prepare for that outcome.”
Advertisement
United’s moves are significant for not only the travel industry but the wider global economy, analysts say. If it all plays out the way Kirby predicts, “this would be incredibly unwelcome news to everyone who is not in the oil refining business,” says Jason Miller, a professor of supply chain management at Michigan State University’s Eli Broad College of Business.
Airlines might be a particularly notable canary in the economic coal mine because their business leans even more heavily on oil prices, and especially refined oil prices, than most. Air transportation ranks just below asphalt paving as the US industry that spends the greatest share of its non-labor costs on refined petroleum products, Miller has calculated. Kirby’s predictions, while dire, are in line with what others in the commodity market are predicting, Miller says.
“Economically, this energy shock is hitting at the worst time possible,” Miller says. Add its effects to a sluggish job market and a global economy shaken by the US’s erratic tariff regime, and economists start to think about recession. The Iran war and the ensuing energy crisis “have played out longer than many expected it to,” Miller says. Kirby’s memo is an acknowledgment that “Hormuz may not be open for business very quickly.”
The effects of the fuel price spikes are already affecting the travel industry. Last week, American Airlines CEO Robert Isom said the company had spent an additional $400 million on fuel. Airlines have reported strong demand in the past weeks, with United’s Kirby noting in his memo that the past 10 weeks had seen the airline take in the most revenue on bookings ever. But it remains to be seen whether lots of people are actually enthusiastic about travel, or flyers spooked about geopolitics and fears of high ticket prices moved early to lock in their plans before oil costs got higher. Isom noted that, if oil prices remain high, “we’re certainly going to be nimble in terms of capacity, to make sure that supply and demand stay in balance.”
Advertisement
How bad it could get for airlines—and its passengers—depends not just on how long oil prices stay elevated, but how long the businesses’ questions about the crisis remain unanswered.
“If we stay in this uncertainty for a long time, this is adding to the complexity,” says Ahmed Abdelghany, who studies airline operations as a professor in Embry-Riddle Aeronautical University’s College of Business. “The longer it goes, the more problematic to the airlines that remain.”
An anonymous Substack post published this week accuses compliance startup Delve of “falsely” convincing “hundreds of customers they were compliant” with privacy and security regulations, potentially exposing those customers to “criminal liability under HIPAA and hefty fines under GDPR.”
Delve is a Y Combinator-backed startup that last year announced raising a $32 million Series A at a $300 million valuation. (The round was led by Insight Partners.) On Friday, the startup attempted to refute the accusations on its blog, calling the Substack post “misleading” and saying it “contains a number of inaccurate claims.”
The Substack post is credited to “DeepDelver,” who described themselves as working at a (now former) Delve client. In response to emailed questions from TechCrunch, DeepDelver said that they and their collaborators “chose to remain anonymous out of fear for retaliation by Delve.”
In their post, DeepDelver recounted receiving an email in December claiming the startup had “leaked a spreadsheet with confidential client reports.” While Delve CEO Karun Kaushik apparently assured customers in a subsequent email that they were in compliance and that no external party gained access to sensitive data, DeepDelver said they and other customers had become suspicious.
Advertisement
“Having the shared experience of being underwhelmed with the Delve experience, and having the overall sense that something fishy was going on, we decided to pool resources and investigate together,” they wrote.
Their conclusion? That Delve “achieves its claim of being the fastest platform by producing fake evidence, generating auditor conclusions on behalf of certification mills that rubber stamp reports, and skipping major framework requirements while telling clients they have achieved 100% compliance.”
DeepDelver went into considerable detail about those claims, accusing the startup of providing customers with “fabricated evidence of board meetings, tests, and processes that never happened,” then forcing those customers to “choose between adopting fake evidence or performing mostly manual work with little real automation or AI.”
Techcrunch event
Advertisement
San Francisco, CA | October 13-15, 2026
DeepDelver also claimed that virtually all of Delve’s clients seem to have gone through two audit firms, Accorp and Gradient, which they described as “part of the same operation,” one that operates primarily in India, with only a nominal presence in the United States.
Advertisement
Those firms, they said, are just rubber-stamping reports that were generated by Delve. As a result, DeepDelver said the startup “inverts” the normal compliance structure: “By generating auditor conclusions, test procedures, and final reports before any independent review occurs, Delve places itself in the role of both implementer and examiner. This is not a technicality. It is a structural fraud that invalidates the entire attestation.”
In addition to accusing Delve of misleading its customers, DeepDelver said the startup is helping those customers “mislead the public by hosting trust pages that contain security measures that were never implemented.”
DeepDelver said that while their company was discussing its issues with Delve, the startup “sent us multiple boxes of donuts […] to keep us happy.” Nonetheless, DeepDelver’s employer supposedly unpublished its trust page and no longer relies on the startup for compliance.
Delve responded to the accusations by saying it does not issue compliance reports at all. Instead, it’s an “automation platform” that ingests information about compliance, then provides auditors with access to that information.
Advertisement
“Final reports and opinions are issued solely by independent, licensed auditors, not Delve,” the company said.
Delve also said that its customers “can opt to work with an auditor of their choosing or opt to work with one from Delve’s network of independent, accredited third-party audit firms.” Those auditors, the startup said, are “established firms used broadly across the industry, including by other compliance platforms.”
In response to the accusation that it’s providing customers with “fake evidence,” Delve countered that it’s simply offering “templates to help teams document their processes in accordance with compliance requirements, as do other compliance platforms.”
“Draft templates are not the same as ‘pre-filled evidence,’” the company said.
Advertisement
Delve added that it is “actively investigating any leaks” and is “still reviewing the Substack.”
When asked about Delve’s response, DeepDelver told TechCrunch that they were “baffled by the laziness, clumsiness and brazenness of it.”
“They are trying to snake their way out [of] being held accountable by denying having ‘pre-filled evidence’ but calling it ‘templates’ instead, effectively shifting the blame to customers for adopting the ‘templates’ as is,” DeepDelver said. “They’re claiming they are not the ones to ‘issue’ the report, which is easy to claim if you define issuing a report as providing the final stamp.”
They added that there are “a number of very serious allegations” that Delve did not address at all: “The India accusation, the lack of AI (they only talk about ‘automations’), and the trust (lol) page containing controls that were never implemented.”
Advertisement
Apparently DeepDelver isn’t done with its criticism, as it promised, “Part II will follow soon.”
In addition, following the initial Substack post, an X user named James Zhou said they were able to gain access to sensitive information from Delve, such as employee background checks and equity vesting schedules. Dvuln founder Jamieson O’Reilly shared more details from what O’Reilly said was a conversation with Zhou about “several gaping security holes in Delve’s external attack surface.”
TechCrunch sent an email seeking additional comment to the media contact address listed on Delve’s website. The email bounced, but after this article was published, I received a calendar invite for a “Delve demo” later this week.
This post was initially published on March 21, 2026. It has been updated with emailed answers from DeepDelver, additional information about purported security vulnerabilities provided by Jamieson O’Reilly, and additional details about Delve’s response to TechCrunch.
If you want professional-grade power tools, you’re going to have to pay a premium price. At least, that’s how it goes with many of the top power tool brands. And of that bunch, few brands come with higher prices than Milwaukee. The brand certainly has its fans, but there’s no way around it: Milwaukee leverages its good reputation to justify charging high-end prices for its power tools. As tool prices climb across the industry, more and more people would probably appreciate a way to get Milwaukee power tool performance without Milwaukee power tool prices.
If that’s you, you might want to check out Harbor Freight. In recent years, this hardware store has greatly expanded its lineup of professional-grade equipment through its in-house brands like Hercules. In fact, their Hercules line is meant to compete directly with higher-end tools sold by brands like Milwaukee… all while keeping prices much, much lower than the big-name brands. To show you what we’re talking about, we’ve found five of the best Harbor Freight alternatives to Milwaukee’s more expensive versions.
Advertisement
1. Hercules random orbit sander
No matter if you’re doing some woodworking, a home renovation, or finishing a furniture project, you’re probably going to need to do some sanding. Cordless random orbit sanders are one way to do so. The Hercules 20V Brushless Cordless 5-inch Random Orbit Sander sells for $54.99 at Harbor Freight, which undercuts the price of the Milwaukee Tool M18 brushless 5-inch random orbit sander, priced around $149 at Home Depot.
And even with that cost difference, the Hercules model is still built with many of the same modern performance features expected of a Milwaukee-type tool. Its brushless motor gives you variable-speed control capable of delivering up to 12,000 orbits per minute. When paired with a Hercules 5 amp-hour battery or larger, the sander can deliver up to 40 minutes of continuous operation. The sander also includes an ergonomic rubberized grip to reduce vibration, and it uses an eight-hole dust collection system paired with a dust bag to help keep your work surface cleaner.
Advertisement
2. Hercules hammer drill/driver
Hammer drills are a cornerstone tool for both construction professionals and home renovators, especially when projects involve drilling into masonry, concrete, or other dense materials. And while Milwaukee has options for you (like the M18 FUEL hammer drill), you can expect to pay upwards of $229 at places like Home Depot. Meanwhile, Harbor Freight has the Hercules 20V Brushless 1/2-inch Compact Hammer Drill/Driver for $79.99 instead.
Advertisement
This tool can give you up to 1,200 inch-pounds of maximum torque, so you can drive large fasteners or drill holes into dense materials like it’s nothing. It’s also capable of up to 32,000 blows per minute in hammer mode. That rapid percussive action helps the drill break through concrete and masonry more efficiently than a standard drill ever could. Under typical conditions, Harbor Freight says the Hercules can drill up to 110 holes in concrete on a single charge.
Advertisement
3. Hercules trigger-grip angle grinder
Angle grinders are another popular power tool that people might look to Milwaukee for. For example, the 15-amp large-angle grinder from Milwaukee Tool sells for $299 at Home Depot. Compare that to the Hercules 15-amp 7-inch/9-inch Trigger-Grip Angle Grinder going for $129 at Harbor Freight. That’s more than 50% savings if you’re willing to swap the popular red tool for this lesser-known blue one.
The Hercules grinder is powered by a 15-amp motor that can produce speeds up to 6,500 revolutions per minute. You also get a trigger-grip handle for more leverage and control compared with traditional side-handle-only grinders. The handle includes an optional lock-on function that lets the tool run longer without you constantly applying pressure to the trigger. The Hercules grinder also includes tool-free guards for both 7-inch and 9-inch grinding wheels. It’s all protected by an all-metal aluminum gear case with a reinforced plastic housing to reduce that annoying vibration.
Advertisement
4. Hercules reciprocating saw
Reciprocating saws are a must-have for demolition, remodeling, or rough-cutting applications. Milwaukee’s M18 FUEL reciprocating saw costs $249 at Home Depot. That’s not the brand’s most expensive power tool, to be clear, but it’s still not cheap. The Hercules 20V Brushless Cordless Reciprocating Saw, however, is priced at $79.99 at Harbor Freight, which is quite a steep price drop.
The saw can deliver up to 3,000 strokes per minute via its variable-speed trigger. It also uses a pivoting shoe with three depth adjustment positions to give you more control over the cut. (Beyond the extra control, adjusting the shoe means extending the blade life by exposing different parts of the blade during repeated cuts.) Blade changes are nice and easy thanks to a keyless single-action mechanism that lets you swap things out without any additional tools. The reciprocating saw also includes a super safe electric brake that stops the blade immediately after the trigger is released.
Advertisement
5. Hercules right angle drill
Right angle drills are great for working in those tight spaces where traditional drills just won’t fit. But if you want one from Milwaukee, you’ll have to pay $329 for it at Home Depot. On the other hand, Hercules can get you a 20V Brushless Cordless 1/2-inch Variable-Speed Right Angle Drill for only $94.99 at Harbor Freight. It’s one of the most dramatic differences between Milwaukee and Hercules pricing that we’ve seen.
It comes with a variable-speed trigger for adjustable drilling speed based on the material you’re drilling. (That’ll also help prevent the drill from overheating and avoid any bit damage that can come from switching between softer materials and denser wood or construction lumber.) It also includes a built-in LED work light that shines on the drilling area. All in all, you’re looking at more than 120 holes drilled per battery charge. Combine that with the fact that it’s a third of the price of the Milwaukee version, what’s not to like?
Elon Musk has announced the Terafab project, a joint venture between Tesla, SpaceX and xAI, to build the “largest chip manufacturing facility ever.” In his usual grandiose fashion, Musk claims Terafab is the next step towards harnessing the power of the sun and creating a “galactic civilization.”
Musk, CEO of all three companies, announced plans for the Terafab in a livestream on X. As the name implies, the project’s ultimate goal is to produce a terawatt of computing power each year so that it can match the companies’ growing demand for chips. Musk explained during the livestream that he’s grateful to existing supply chain partners like Samsung, TSMC and Micron, but the current capacity of chip manufacturers only adds up to about two percent to what Tesla and SpaceX needs in terms of future computing power needs.
“We either build the Terafab or we don’t have the chips,” Musk said during the event. “And we need the chips so we’re going to build the Terafab.”
The Terafab project, estimated to cost at least $20 billion, will start with the Advanced Technology Fab in Austin, Texas, where Tesla is already headquartered. Musk said that the two types of chips will be produced in the Terafab: one for terrestrial purposes, like to power Full Self-Driving or Optimus robots, and another more high-powered, durable chip to be used in space. If you’re wondering what Musk has in store for space, the SpaceX CEO filed an application with the Federal Communications Commission to launch a million satellites to create an “orbital data center” earlier this year. As promising as this sounds, it’s worth noting that Musk has previously overpromised and underdelivered on other projects, like the Hyperloop, a $40,000 Cybertruck and fully autonomous driving.
AI coding company Cursor launched a new model this week called Composer 2, which it promoted as offering “frontier-level coding intelligence.”
However, an X user posting under the name Fynn soon claimed that Composer 2 was “just Kimi 2.5” with additional reinforcement learning — Kimi 2.5 being an open source model recently released by Moonshot AI, a Chinese company backed by Alibaba and HongShan (formerly Sequoia China).
As evidence, Fynn pointed to code that seemed to identify Kimi as the model.
However, Cursor’s vice president of developer education Lee Robinson soon acknowledged, “Yep, Composer 2 started from an open-source base!” But he said, “Only ~1/4 of the compute spent on the final model came from the base, the rest is from our training.” As a result, he said Composer 2’s performance on various benchmarks is “very different” from Kimi’s.
Robinson also insisted that Cursor’s use of Kimi was consistent with the terms of its license, a point the Kimi account on X repeated in a subsequent post congratulating Cursor, where it said Cursor used Kimi “as part of an authorized commercial partnership” with Fireworks AI.
Techcrunch event
Advertisement
San Francisco, CA | October 13-15, 2026
“We are proud to see Kimi-k2.5 provide the foundation,” the Kimi account said. “Seeing our model integrated effectively through Cursor’s continued pretraining & high-compute RL training is the open model ecosystem we love to support.”
Cursor co-founder Aman Sanger acknowledged, “It was a miss to not mention the Kimi base in our blog from the start. We’ll fix that for the next model.”
You must be logged in to post a comment Login