Adobe has released an emergency security update for Acrobat Reader to fix a vulnerability, tracked as CVE-2026-34621, that has been exploited in zero-day attacks since at least December.
The flaw allows malicious PDF files to bypass sandbox restrictions and invoke privileged JavaScript APIs, potentially leading to arbitrary code execution. The exploit observed in attacks enables reading and stealing arbitrary files. No user interaction is required beyond opening the malicious PDF.
Specifically, the exploit abuses APIs like util.readFileIntoStream() to read arbitrary local files and RSS.addFeed() to exfiltrate data and fetch additional attacker-controlled code.
The security issue was discovered by Haifei Li, founder of the EXPMON exploit detection system, after someone submitted for analysis a PDF sample named “yummy_adobe_exploit_uwu.pdf.”
Haifei Li says that someone submitted the sample to EXPMON on March 26, but it had been sent to VirusTotal three days before, where only five out of 64 security vendors flagged it as malicious at the time.
Advertisement
The researcher decided to manually investigate the issue after the exploit detection system activated its “detection in depth” feature, an advanced detection capability Haifei Li specifically developed for Adobe Reader, he says in a blog post last week.
Security researcher Gi7w0rm spotted attacks in the wild that leveraged Russian-language documents with oil and gas industry lures.
Following the receipt of Li’s report, Adobe published a security bulletin over the weekend, assigning the vulnerability the CVE-2026-34621 tracker.
Although the flaw was initially rated critical (9.6) with a network attack vector, Adobe subsequently lowered the severity to 8.6 after changing the vector to local.
Advertisement
The vendor listed the following Windows and macOS products as impacted:
Acrobat DC versions 26.001.21367 and earlier (fixed in version 26.001.21411)
Acrobat Reader DC versions 26.001.21367 and earlier (fixed in version 26.001.21411)
Acrobat 2024 versions 24.001.30356 and earlier (fixed in version 24.001.30362 on Windows, and version 24.001.30360 on Mac)
Adobe recommends that users of the above software update their applications through ‘Help > Check for Updates,’ which triggers an automated update.
Alternatively, users may download an Acrobat Reader installer from Adobe’s official software portal.
No workarounds or mitigations were listed in the bulletin, so applying the security updates is the only recommended action.
However, users should always be wary of PDF files sent from unsolicited sources and open them in sandboxed environments when suspicious.
Advertisement
Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.
This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.
Despite indie darling Stardew Valley only being built by a single developer, you certainly wouldn’t know it by the amount of support the game has received since its launch in 2016. Regular updates, ports to other platforms, and even a fully-fledged online multiplayer mode make the game feel essentially endless. In fact, it’s one of Digital Trends’ top 50 video games of all time.
With Stardew Valley’s 1.6 update adding that multiplayer mode, fans have been begging for cross-platform play, as well as cross-progression. So, if you’re looking to recruit some fellow agriculture enthusiasts or some farming friends, read on to find out whether or not you can pull them from across console, PC, and mobile.
Is Stardew Valley cross-platform?
While developer ConcernedApe has worked in an awful lot of new content, at the time of writing (October 2025) Stardew Valley still does not offer cross-platform support, so you’ll need to play with friends on the same platform.
One reason for this could be that, since it launched in 2016, Stardew Valley predates the big cross-platform push spearheaded by the likes of Fortnite.
Advertisement
As a result, you’ll need to play on PlayStation 4, PlayStation 5, Xbox One, Xbox Series X, Nintendo Switch, or PC with other players on the same system, but you can at least enjoy multiplayer thanks to the 1.6 update.
Back in 2018, one fan asked ConcernedApe if cross-platform play is likely to come to the farming sim.
“Unfortunately, there will not be crossplay. Apparently, the technical barriers are very high. It’s still something I really want to add and I promise to look into it more closely, but first priority is getting the update out there,” he responded, and the trail has gone quiet since.
ConcernedApe
As for cross-save, that’s not here either. You can’t save on your PC and pick up where you left off on your Xbox, for example, or jump between Nintendo Switch and PlayStation.
Arguably the closest you’ll get is using Steam’s Cloud Save functionality to play on PC and then pick up on a laptop or Steam Deck, but that won’t be a solution that suits everyone.
Advertisement
Haunted Chocolatier, the next game from ConcernedApe, is certainly looking promising, so here’s hoping cross-platform play and cross-save make it into that one at least. And hey, who knows? Maybe the dev will surprise us with crossplay and cross-save in the future.
Current status in 2026
The most relevant recent change is not full crossplay, but experimental multiplayer on mobile. Stardew Valley’s official mobile multiplayer guide confirms that Android and iOS now have a hidden experimental multiplayer feature tied to the 1.6 mobile release.
Which Stardew Valley platforms can play together?
Windows, Mac, and Linux: Yes
PlayStation with PlayStation: Yes
Xbox with Xbox: Yes
Switch with Switch: Yes
PC with console: No
PlayStation with Xbox or Switch: No
Console with mobile: No standard crossplay
Mobile with PC: Experimental only, with setup required
So if the goal is easy co-op with friends, the safest advice is still painfully boring: buy the game on the same platform.
What about Stardew Valley mobile multiplayer?
This is the one part of the answer that now needs nuance.
According to the official Stardew Valley mobile multiplayer guide, Android and iOS have a hidden experimental multiplayer mode. It isn’t enabled like standard multiplayer, and it comes with extra steps. Players need to be on the same game version, connect by IP, and often be on the same local network unless they’re using more advanced setup methods such as port forwarding. The official guide also warns that the feature is experimental and may have bugs or save-related issues.
Advertisement
That means mobile multiplayer exists, but it isn’t polished, full-featured crossplay. It’s closer to an official experimental workaround than a seamless “buy anywhere, play anywhere” system.
Does Stardew Valley have cross-save?
No. Stardew Valley still doesn’t offer broad, official cross-save or cross-progression across its major platform ecosystems. A save on Switch, for example, isn’t meant to flow neatly into Xbox, PlayStation, or PC in the way players now expect from fully connected live-service games.
Why doesn’t Stardew Valley have full crossplay?
Part of the answer is timing. Stardew Valley launched in 2016, long before full cross-platform support became an expected multiplayer feature for almost every popular co-op game. Multiplayer support expanded over time, and the current game supports up to eight players in multiplayer in supported environments, but that still doesn’t mean broad crossplay across every platform family.
In other words, Stardew Valley has multiplayer, but not the universal version modern players expect.
Advertisement
Stardew Valley cross-platform status in 2026
Stardew Valley still isn’t fully cross-platform in 2026. PC players can play together across Windows, Mac, and Linux. Console players generally need to stay within their own platform ecosystem. Mobile now has an official experimental multiplayer option, including the ability to connect in ways that blur the old boundaries a bit, but it’s still limited, hidden, and far from full crossplay.
If the goal is to start a farm with friends and avoid technical nonsense, everyone should still plan to buy the same version on the same platform. It’s not glamorous advice, but it beats discovering too late that your multiplayer plans were built on wishful thinking and turnips.
Autonomous agents are compressing software delivery timelines from weeks to days. The enterprises that scale agents safely will be the ones that build using spec-driven development.
There’s a moment in every technology shift where the early adopters stop being outliers and start being the baseline. We’re at that moment in software development, and most teams don’t realize it yet.
A year ago, vibe coding went viral. Non-developers and junior developers discovered they could build beyond their abilities with AI. It lowered the floor. It made prototyping much quicker, but it also introduced a surplus of slop. What the industry then needed was something that raised the ceiling — something that improved code quality and worked the way the most expert developers work. Spec-driven development did that. It laid the foundation for trustworthy autonomous coding agents.
Advertisement
Specs are the trust model for autonomous development
Most discussions of AI-generated code focus on whether AI can write code. The harder question is whether you can trust it. The answer runs directly through the spec.
Spec-driven development starts with a deceptively simple idea: before an AI agent writes a single line of code, it works from a structured, context-rich specification that defines what the system is supposed to do, what its properties are, and what “correct” actually means. That specification is an artifact the agent reasons against throughout the entire development process — fundamentally different from pre-agentic AI approaches of writing documentation after the fact.
Enterprise teams are building on this foundation. The Kiro IDE team used Kiro to build Kiro IDE — an agentic coding environment with native spec-driven development — cutting feature builds from two weeks to two days. An AWS engineering team completed an 18-month rearchitecture project, originally scoped for 30 developers, with six people in 76 days using Kiro. An Amazon.com engineering team rolled out “Add to Delivery” — a feature that lets shoppers add items after checkout — two months ahead of schedule by using Kiro and spec-driven development. Alexa+, Amazon Finance, Amazon Stores, AWS, Fire TV, Last Mile Delivery, Prime Video, and more all integrate spec-driven development as part of their build approaches.
That shift changes everything downstream.
Advertisement
Verifiable testing is what makes autonomous agents safe to run
The spec becomes an automated correctness engine. When a developer is generating 150 check-ins per week with AI assistance, no human can manually review that volume of code. Instead, code built against a concrete specification can be verified through property-based testing and neurosymbolic AI techniques that automatically generate hundreds of test cases derived directly from the spec, probing edge cases no human would think to write by hand. These tests prove that the code satisfies the spec’s defined properties, going well beyond hand-written test suites to provably correct behavior.
Verifiable testing enables the shift from one-shot programming to continuous autonomous development. Traditional AI-assisted development operates as a single shot: you give the agent a spec, the agent produces output, and the process ends. Today’s agents continuously correct themselves, feeding build and test failures back into their own reasoning, generating additional tests to probe their own output, and iterating until they produce something both functional and verifiable. The spec is the anchor that keeps that loop from drifting. Instead of developers constantly checking in to see if the agent is making the right decisions, the agent can check itself against the spec to make sure it is on the right path.
The autonomous agent of the future will write its own specs, using specifications as the mechanism for self-correction, for verification, for ensuring that what it produces matches the intended behavior of the system.
Multi-agent, autonomous, and running right now
The developers setting the pace today operate in a fundamentally different way. Developers spend significant time building their spec, as well as writing steering files used by the spec to make sure the agent knows what and how to build — more time than their agent may spend building the actual software. They run multiple agents in parallel to critique a problem from different perspectives, as well as run multiple specs, each written for a different component of the system they are building. They let agents run for hours, sometimes days. They use thousands of Kiro credits because the output justifies it.
Advertisement
A year ago, agents would lose context and fall apart after 20 minutes. Now, every week you can run them longer than the week before. Agentic capabilities have improved significantly in the last six months that genuinely complex problems are tractable. Newer LLMs are more token-efficient than the previous generation, so for the same spend, you get dramatically more done.
The challenge is that doing this well requires deep expertise. The tools, methodologies, and infrastructure exist, but orchestrating them is hard. The goal with Kiro is to bring these capabilities with deep expertise to every developer, not just the top one percent who’ve figured it out.
Infrastructure is catching up to ambition
Agents will be ten times more capable within a year. That’s the rate of improvement we’re seeing week over week.
The infrastructure to support that level of capability is converging at the same time. Agents are now running in the cloud rather than locally, executing in parallel at scale with secure, reliable communication between agent systems. Organizations can now run agentic workloads the way they’d run any enterprise-grade distributed system — with governance, cost controls, and reliability guarantees that serious software demands. Spec-driven development is the architecture of tomorrow’s autonomous systems.
Advertisement
Developers are no longer restricted by how they want to solve the problem. The developers who thrive in this world are the ones building that foundation now: using spec-driven development, prioritizing testability and verification from the start, working with agents as collaborators, and thinking in systems instead of syntax.
Deepak Singh is VP of Kiro at AWS.
Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact sales@venturebeat.com.
Stop Killing Games is backing a new bill from Chris Ward, a member of the California State Assembly since 2020. Introduced earlier this year, the Protect Our Games Act would require gaming companies to make clear commitments to long-term support for “server-connected” video games. The bill has undergone a significant… Read Entire Article Source link
“The new Linux kernel was released and it’s kind of a big deal,” writes longtime Slashdot reader rexx mainframe. “Here is what you can expect.” Linuxiac reports: A key update in Linux 7.0 is the removal of the experimental label from Rust support. That (of course) does not make Rust a dominant language in kernel development, but it is still an important step in its gradual integration into the project. Another notable security-related change is the addition of ML-DSA post-quantum signatures for kernel module authentication, while support for SHA-1-based module-signing schemes has been removed.
The kernel now includes BPF-based filtering for io_uring operations, providing administrators with improved control in restricted environments. Additionally, BTF type lookups are now faster due to binary search. At the same time, this release continues ongoing cleanup in the kernel’s lower layers. The removal of linuxrc initrd code advances the transition to initramfs as the sole early-userspace boot mechanism.
Linux 7.0 also introduces NULLFS, an immutable and empty root filesystem designed for systems that mount the real root later. Plus, preemption handling is now simpler on most architectures, with further improvements to restartable sequences, workqueues, RCU internals, slab allocation, and type-based hardening. Filesystems and storage receive several updates as well. Non-blocking timestamp updates now function correctly, and filesystems must explicitly opt in to leases rather than receiving them by default. Phoronix has compiled a list of the many exciting changes.
The Bose QuietComfort Headphones excel at noise-cancelation, but they’re far from a one-trick pony. With outstanding sound quality, a super-comfortable design, and an easy-to-use interface, they hit all the right notes across the board.
This limited-time deal sees the ANC masters drop back to the price we saw at Black Friday. Just note that this outstanding deal is only on the grey and pink colorways, although if you want the more traditional black alternative, then they’re only $19 more.
Advertisement
Today’s best Bose headphones deal
In our Bose QuietComfort Headphones review, we gave the popular audio product a very respectable four out of five stars. Our reviewer loved their “supreme comfort, fuss-free set-up and solid ANC”, so even though they’re not perfect, they’re still pretty impressive, especially at this reduced price.
If you’re often working in public places, then you’ll be pleased to hear that the ANC is second to none. There are also a couple of different audio modes, like ‘Quiet’ for improved noise cancelation and ‘Aware’ for more transparency. These can be toggled using the action button on the left earcup.
From a comfort point of view, Bose has opted for memory foam earcups wrapped in soft vegan leather and a well-padded headband. All of this equates to a seriously comfortable user experience.
Dozens of civil rights organizations have to warn of the dangers in to the company’s smart glasses. More than 70 groups have banded together to form a coalition to urge Zuckerberg to abandon plans to incorporate the tech, on the grounds that it would empower stalkers, sexual predators and other bad actors.
This coalition includes organizations like the ACLU, the Electronic Privacy Information Center, Fight for the Future, Access Now and many others. The letter isn’t asking for safeguards. These groups want the feature to be completely eliminated, stating the idea behind facial recognition of this type is so dangerous that it “cannot be resolved through product design changes, opt-out mechanisms or incremental safeguards.” This tracks, as there would be no real way for bystanders to know or consent to being identified.
“People should be able to move through their daily lives without fear that stalkers, scammers, abusers, federal agents and activists across the political spectrum are silently and invisibly verifying their identities and potentially matching their names to a wealth of readily available data about their habits, hobbies, relationships, health and behaviors,” the letter states.
The organizations have urged Meta to disclose any known instances of its wearables being used for stalking, harassment or domestic violence. They also want the company to disclose past or ongoing discussions with federal law enforcement agencies, including ICE, about the use of Meta smart glasses and other wearables, .
Advertisement
There is certainly some cause for worry here. Meta that suggested it would roll out this technology “during a dynamic political environment where many civil society groups that we would expect to attack us would have their resources focused on other concerns.” That’s corporate speak for “we’ll do it when nobody is watching.” The coalition has called this “vile behavior” that looks to take advantage of “rising authoritarianism.”
The technology in question is called Name Tag, for obvious reasons. It uses AI to pull up information about people in a field of view to smart glasses displays. That’s about as dystopian as it gets.
The company has reportedly been working on . There’s one that would only identify people that are currently connected to a Meta platform and another that would identify anyone with a public account on a service like Instagram. It doesn’t look like there’s any way, as of yet, to use this tech to identify strangers on the street who don’t have a Meta account of any kind. In other words, the company should expect a if this rolls out.
Name Tag is currently scheduled for release at some point this year, but it’s not set in stone just yet. Public outcry has gotten Meta to back off from facial recognition in the past. The company after pushback from civil liberties groups and years of costly litigation. Meta paid out billions of dollars to settle biometric privacy lawsuits in and and another for a separate privacy case partially tied to facial recognition software.
Australia’s world-first social media ban on users under the age of 16 isn’t keeping kids off the platforms as well as the government hoped. Read Entire Article Source link
Apple is now on its second round of developer betas for iOS 26.5, iPadOS 26.5, watchOS 26.5, tvOS 26.5, visionOS 26.5, and macOS Tahoe 26.5.
Apple’s hardware that works with the 26-generation operating systems – Image Credit: Apple
The second developer betas for iOS 26.5, iPadOS 26.5, watchOS 26.5, tvOS 26.5, visionOS 26.5, and macOS Tahoe 26.5 replace the first, which arrived on March 30. However, Apple re-released the developer beta for iOS 26.5 on March 24, with a new build number.
Caviar has packed over two decades’ worth of technology into a single smartphone, the iPhone 2007 Edition, which is an extravagant custom version of the iPhone 17 Pro. This ultra-limited edition of the flagship smartphone incorporates an actual piece of the 2007 iPhone 2G directly into its frame, a part literally pulled from Apple’s first handset.
The chassis is composed of titanium, which is coated in a sleek PVD black that nods subtly to the colors of 2007. The silver bits cover the majority of the surface, while the lower part transitions to black, which provides visual interest. Delicate lines carved on the rear are a careful recreation of the original mainboard’s circuit designs, and they all appear to connect at a single central point.
【Ultra-Thin Yet 10,000 mAh Capacity】Are you still struggling to find a slim power bank that can meet your charging needs? Look no further! TORRAS…
【Portable Charger with Magnetic Function】The slim power bank is a portable charger with powerful magnetic attraction, allowing for easy attachment…
【Super Fast Charging】Tired of waiting for your power bank to charge? This power bank fast charging supports 22.5W wired fast charging and 15W…
A transparent capsule shaped like the Apple logo lies in the center of the rear panel. Inside this sealed capsule is a certified piece of the 2007 iPhone 2G motherboard, securely stored away and entirely undamaged. The fragment is packaged in what appears to be a hermetically sealed little chamber. To top it all off, each device includes Steve Jobs’ signature inscribed around the frame, as well as a unique serial number etched into the titanium up to number 11.
Every last detail ties in neatly to that historic hardware. The etchings that imitate the first smartphone’s technological schematics provide a nice visual connection to the capsule. Buyers of the iPhone 2007 Edition even receive a personalized screensaver. This one is custom-made for this collection and begins loading as soon as the phone is turned on. The phone comes in a luxury branded box with a characteristic Caviar key finished in 24-karat gold plating – the works. It comes with certified certificates that indicate the motherboard is a genuine 2007 iPhone 2G fragment, directly from the source.
Pricing starts at $10,770 for the 256GB iPhone 17 Pro and goes up to $12,700 for the two-terabyte iPhone 17 Pro Max. Production is intentionally limited to just 11 pieces globally, making each one extremely uncommon. Orders are now open, with worldwide shipping handled by trusted couriers. It will take at least a week to arrive after a 1-4 business day wait for final assembly and inspection. [Source]
You must be logged in to post a comment Login