Connect with us
DAPA Banner
DAPA Coin
DAPA
COIN PAYMENT ASSET
PRIVACY · BLOCKDAG · HOMOMORPHIC ENCRYPTION · RUST
ElGamal Encrypted MINE DAPA
🚫 GENESIS SOLD OUT
DAPAPAY COMING

Tech

KongTuke hackers now use Microsoft Teams for corporate breaches

Published

on

KongTuke hackers now use Microsoft Teams for corporate breaches

Initial access broker KongTuke has moved to Microsoft Teams for social engineering attacks, taking as little as five minutes to gain persistent access to corporate networks.

The threat actor tricks users into pasting a PowerShell command that ultimately delivers the ModeloRAT, which has been previously seen in ClickFix attacks [1, 2].

Initial access brokers (IAB) like KongTuke typically sell company network access to ransomware operators, who use it to deploy file-theft and data-encrypting malware.

Cybercriminals have increasingly adopted Microsoft Teams in attacks, reaching out to company employees and pretending to be IT and help-desk staff.

Advertisement

The victims are convinced to run a malicious PowerShell command on their systems, which deploys the “ModeloRAT” malware.

The PowerShell command used in the observed attacks
The PowerShell command used in the observed attacks
Source: ReliaQuest

ReliaQuest researchers observed this activity and say that it is a shift in tactics for KongTuke, who previously relied solely on web-based “FileFix” and “CrashFix” lures.

“This Teams activity, which appears to add to, rather than replace, that web-based approach, marks the first time we’ve seen KongTuke use a collaboration platform for initial access,” explains ReliaQuest.

“In the incidents we investigated, a single external Teams chat moved the operator from cold outreach to a persistent foothold in under five minutes.”

The campaign has been active since at least April 2026, with KongTuke rotating through five Microsoft 365 tenants to evade blocking, the researchers say.

Advertisement

To pass as internal IT support staff, the attacker uses Unicode whitespace tricks to make the display name appear legitimate.

The malicious PowerShell command shared via Teams downloads a ZIP archive from Dropbox that contains a portable WinPython environment, which eventually launches the Python-based malware, ModeloRAT (Pmanager.py).

The malware collects system and user information, captures screenshots, and can exfiltrate files from the host filesystem.

ReliaQuest notes that the ModeloRAT version used in this recent campaign has evolved compared to what was seen in previous operations, mostly in three ways:

Advertisement
  1. A more resilient C2 architecture with a five-server pool, automatic failover, randomized URL paths, and self-update capability.
  2. Multiple independent access paths, including a primary RAT, a reverse shell, and a TCP backdoor, running on separate infrastructure to preserve access if one channel is disrupted.
  3. Expanded persistence mechanisms using Run keys, Startup shortcuts, VBScript launchers, and SYSTEM-level scheduled tasks that may survive standard cleanup procedures.

The researchers note that the scheduled task isn’t removed by the implant’s self-destruct routine, which wipes the other persistence mechanisms, and can persist through system reboots.

The persistent scheduled task
The persistent scheduled task
Source: ReliaQuest

To defend against Team-initiated attacks, it is recommended to restrict external Microsoft Teams federation using allowlists to block these attempts at their start.

Additionally, administrators can use the indicators of compromise available in ReliaQuest’s report to hunt for attacks, signs of compromise, and persistence artifacts.


article image

AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

Claim Your Spot

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Top Lucid Motors executive departs amid new CEO’s leadership shakeup

Published

on

Emad Dlala, a top executive at EV-maker Lucid Motors, has left the company just months after being promoted to a leading role, TechCrunch has learned.

Dlala’s exit is the first major executive departure since Lucid Motors selected Silvio Napoli as its new CEO in April. Napoli joined Lucid after spending a career in various leadership positions at escalator and elevator company Schindler Group. He formally started in the CEO role just last week.

In a statment to TechCrunch, Lucid Motors confirmed Dlala’s departure and said the company is “transforming its organization to accelerate innovation and strengthen execution under CEO Silvio Napoli.”

As part of that transformation, Lucid Motors said that Vivek Attaluri, the company’s vice president of vehicle engineering, and Marc Solsona Palomar, its vice president of software, will now report directly to Napoli. 

Advertisement

“Emad Dlala has elected to leave the company to pursue other opportunities. We thank Emad for his many contributions over the years and wish him continued success in his future endeavors. Lucid remains focused on streamlining our organization and processes to fully leverage the strength of our team and will communicate further actions soon,” the company said in a statement.

Dlala declined to comment.

Dlala had been with Lucid Motors for more than a decade, making him one of the company’s longest-serving employees and executives. Over the last five years, he was both Lucid Motors’ vice president and senior vice president of the company’s powertrain team.

In November, he was elevated to a role overseeing all of “Engineering and Digital” at the same time that Lucid Motors parted ways with its long-time chief engineer Eric Bach. Bach has since sued Lucid Motors for wrongful termination — though that lawsuit was recently stayed pending arbitration, according to federal court records.

Advertisement

The company have been in flux in the months since. Lucid Motors laid off 12% of its workforce in February, as TechCrunch first reported. It then completed its search for a new CEO after spending a year trying to replace Peter Rawlinson, who suddenly departed in early 2025.

The departure of Dlala comes just a few months ahead of the launch of Lucid Motors’ first mass-market vehicle built on its mid-sized platform, called Cosmos. This EV is supposed to start below $50,000 and finally give the Saudi-owned company a chance at delivering a more affordable, widely-adopted car.

This next-generation EV is also now a cornerstone of Lucid’s deal to provide robotaxis to Uber. Lucid Motors has agreed to develop robotaxis with autonomous vehicle company Nuro, starting with its Gravity SUV. The self-driving Gravity is supposed to hit the road in San Francisco by the end of this year.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Advertisement

Source link

Continue Reading

Tech

Best Whitening Toothpaste of 2026, According to Dentists

Published

on

Why we like it: Dr. Christopher Tolmie, DDS, MBA, of PDS Health, recommends this whitening toothpaste, saying, “Instead of peroxide, it uses nano‑hydroxyapatite, the same calcium‑phosphate crystal your enamel is made of, to lift surface stains. Healthier enamel means fewer bacterial highways into the rest of your body.”

Tolmie also cites a 2021 randomized clinical trial that found that 10 % hydroxyapatite protects against cavities as well as fluoride. “It polishes stains while filling micro‑cracks, smoothing, whitening and reducing sensitivity,” adds Tolmie. “Expect a gentle 1-2‑shade lift in 2-4 weeks, versus a 3-8-shade jump in a single professional visit.”

Dr. Yenile Pinto, DDS, founder of Deering Dental, also recommends this toothpaste for stronger, healthier enamel. “It strikes a great balance between cosmetic whitening and true functional benefit,” she says.

“To me, the ideal whitening toothpaste helps remineralize enamel, balance pH and support your oral microbiome,” Pinto explains. “Nano-hydroxyapatite does just that, and as it rebuilds the tooth’s surface, it naturally reduces transparency and helps teeth appear whiter without irritation or long-term damage. By smoothing and strengthening the outer layer, it also increases the tooth’s ability to reflect light, making your smile appear not only whiter, but more brilliant and vibrant.”

Advertisement

Who is it best for: This toothpaste is best for “clean‑label and fluoride‑averse seekers, kids, pregnant patients or anyone wanting everyday whitening without the high sensitivity side effect risk,” states Tolmie.

Pinto also recommends this toothpaste to patients with mild sensitivity, early enamel erosion or a history of cavities.

Who should not get it: Tolmie doesn’t recommend this whitening toothpaste to heavy smokers, people with tetracycline stains or those who want a fast multi‑shade change. For patients who want the latter, he states that they will need custom trays or in‑office bleaching.

“I don’t recommend using whitening toothpastes or even gentler ones every single day long-term,” adds Pinto. “Most contain a slight abrasive (often hydrated silica or baking soda), which is generally safe in moderation but can wear enamel over time if overused.”

Advertisement

Source link

Continue Reading

Tech

Apple’s Siri AI won’t be available in the EU at launch

Published

on

Enforcement of Europe’s Digital Markets Act means Apple can’t launch the system safely within the EU, the company said.

Apple’s new AI interface ‘Siri AI’ will not be available to EU users of its phones, tablets and smart watches when the company launches its new operating systems for the devices later this year.

The company said that due to restrictions set out and enforceable by Europe’s Digital Markets Act (DMA), it could not safely integrate Siri AI into iOS 27, iPadOS 27 and watchOS 27 running on European iPhones, iPads and Apple Watches.

Apple said that solutions for a compliant integration of Siri AI for European users – which could also support other, rival virtual assistants in a safe manner – that it proposed to the EU over “the past several months” had not been accepted.

Advertisement

“We’re deeply disappointed that our EU users won’t have Siri AI on iPhone or iPad when we share our new software releases later this year,” said Craig Federighi, Apple’s senior vice-president of software engineering.

“Our hope is to eventually bring Siri AI to the EU, and we will continue to engage with EU regulators on a path forward. However, their refusal to engage constructively on solutions that preserve privacy and security means we do not currently have a timeline for Siri AI’s availability on iOS and iPadOS in the EU.”

The disagreement centres on what Apple said is Europe’s “extreme interpretation of the DMA” that would require the company to give any rival virtual assistant “direct access to users’ private data – and the ability to directly control other installed applications – as soon as Siri AI is made available in the EU, without the essential protections necessary to keep users and their data safe”.

Apple demonstrated the newly redesigned AI interface at its annual Worldwide Developers Conference yesterday (8 June), but said “clear dangers to EU users” and “regulators’ failure to acknowledge these risks” would lock out its availability in the bloc.

Advertisement

The company said, however, that EU users of its computers and mixed reality headsets will be able to access Siri AI on macOS 27 and visionOS 27, respectively.

Forrester vice-president and principal analyst Dipanjan Chatterjee described the new, updated AI integration as “a far more capable, context-aware, conversational assistant”, but said its success would “hinge on delivering the new Siri experience quickly, and ensuring it works as promised for iPhone users at scale”.

Apple has previously advocated that the EU get rid of the DMA, claiming that the antitrust legislation is “forcing” the company to make “concerning changes” to how it delivers its services to European users.

Passed in 2022, the DMA aims to crack down on anticompetitive behaviour from Big Tech companies and level the online digital market space.

Advertisement

Last summer, Apple changed its App Store policies for EU users in an effort to comply with the DMA.

In April, the company announced plans for a leadership transition from Tim Cook to John Ternus, shortly before reporting its “best March quarter ever” with revenue of $111.2bn.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Advertisement

Source link

Continue Reading

Tech

Deep Dive Into Sputnik | Hackaday

Published

on

If you are an American of a certain age, you know the Soviet Union launched the first satellite, Sputnik, beating the United States to orbit. You might even remember ham radio operators tuning into the satellites beeping. But you probably haven’t heard much about the team that built the vehicle, the problems they had, or the clever design choices they made. [Hoog] has a video that details the birth of Sputnik. You can see the video below.

The original plan was to launch a massive space lab, but it proved too ambitious. Keep in mind that in the late 1950s, you didn’t have tiny computers, high-density power sources, or advanced materials, and no one really knew what to expect in the Earth orbit environment. Even the viability of radio from the ground to orbit wasn’t a given. But Sputnik’s 1-watt transmitter did the job.

The event was part of the International Geophysical Year, but despite the agreement of international cooperation, the backdrop of the Cold War made politicians in the United States incite fear among Americans that the “Reds” were able to fly something over the United States both undetected and unopposed. Secretly, the US was pleased, as it wanted to fly spy satellites over the USSR, and this paved the way, since it could hardly complain if the US did the same thing the Soviets had already done.

The whole thing started the space race, which eventually led to the moon landings. It seems impossible that Sputnik was only 69 years ago. That means 70 years ago, there were no manmade satellites orbiting the Earth.

Advertisement

Watching the video, we’d hoped for more details about the internals but there just wasn’t time. However, we’ve covered that before (the main link is dead, but the detail links are still very interesting). The IGY was, for the most part, a great international cooperation, although few of its accomplishments are as memorable as Sputnik.

Source link

Advertisement
Continue Reading

Tech

Google just fired a warning shot in the AI subscription price wars

Published

on

Google just made its budget AI subscription plan a lot more budget-friendly, bringing a price war that’s been brewing in emerging markets squarely to American consumers.

The company announced Monday that it is cutting the monthly price of Google AI Plus from $7.99 to $4.99 — while doubling the storage included at that tier, from 200 gigabytes to 400 gigabytes.

Vikas Kansal, product lead for Gemini AI subscriptions, said on X that the storage updates would roll out to users over the next several days.

Google AI Plus launched in January as the most affordable paid AI subscription in the U.S. market, aimed at individual users and students rather than enterprise customers. Apparently that wasn’t cheap enough.

Advertisement

It includes a decent feature set, too, including video generation via Omni Flash; the creative studio Google Flow; and NotebookLM, Google’s AI research assistant. For heavier users, Google also offers AI Pro and AI Ultra at higher price points and usage limits.

The price cut is worth indexing on for reasons beyond Google’s own product roadmap. Subscription pricing hasn’t yet been a key battleground among AI providers in the U.S. But that’s changing in real time, suggests Chi-Hua Chien, co-founder and managing partner at consumer-focused venture firm Goodwater Capital; he sees Monday’s announcement as the next salvo in the commoditization era for AI infrastructure, pointing to Google’s structural advantages — vertical integration, distribution, the ability to bundle — as precisely the kind of force that’s likely to erode margins for purer-play AI providers over time.

The historical parallel he reaches for is instructive. “If you look at the web era, the infrastructure companies were Microsoft, Cisco, Oracle, Northern Telecom, Lucent, Akamai, Equinix,” he told TechCrunch. “A lot of those companies survived for a period of time but aren’t worth a lot today.” The reason, he said, is that during every big tech shift — from PC to web to mobile — the infrastructure players “get commoditized very aggressively because the end customer doesn’t think, ‘Ooh, are my bits moving on Cisco networking equipment?’ They’re just thinking, ‘How do I move my bits as cheaply as possible?’”

It’s not news that this was coming — foundation model companies have always known that raw AI capability would eventually become a commodity, and that applications and distribution would be what separates winners from also-rans. What Chien is saying is that “eventually” is coming sooner than later.

Advertisement

“My prediction for a lot of these infrastructure companies — and when I say infrastructure, I mean an OpenAI or an Anthropic, or the backend components, energy, chips, hosting — there will be a period of time when these companies are valuable,” he said. “But over time, you will see them get increasingly commoditized.”

It’s certainly something that a bigger pool of investors will be pondering soon. Both OpenAI and Anthropic have filed confidentially to go public, and their ability to command premium valuations may soon be tested by exactly the kind of price competition Chien is describing.

That competition has been building for nearly a year in markets like India, one of the fastest-growing AI user bases in the world. OpenAI drew first blood there in August of last year, launching ChatGPT Go at roughly $4.60 a month — a fraction of its standard $20 Plus plan. Google followed in December with a sub-$5 AI Plus plan of its own for Indian users.

Monday’s announcement suggests the same logic that drove those emerging-market moves — undercut, bundle, and capture users before rivals do — has now crossed over to the U.S. market.

Advertisement

Anthropic, notably, hasn’t followed. Unlike OpenAI and Google, it has yet to introduce localized pricing for India or a budget tier anywhere, a move that may become harder to avoid as its rivals keep slashing prices.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Source link

Advertisement
Continue Reading

Tech

China plans $295bn spend for nationwide data centre build-out

Published

on

China’s core AI industry – which boasts more than 6,200 companies – was valued at nearly $174bn in 2025.

China is planning to spend around $295bn – or 2trn yuan – over the next five years to build data centres across the country, Bloomberg has reported, citing sources close to the matter.

The build-out could represent China’s most aggressive plan yet to secure the future of its AI industry, the publication reported.

The idea is for a resilient Chinese AI industry with an interconnected data centre network and a reduced reliance on foreign technology from companies such as Nvidia and AMD. China also plans to integrate its power grid with the project, the sources said.

Advertisement

The funds set aside for the project, however, pale in comparison to the likes of Meta, which has a planned capital expenditure of as much as $145bn for this year alone, or Alphabet, which has set aside up to $190bn for 2026. Much of this spending has been earmarked for AI or compute-related investments.

The government spend, though, doesn’t account for private AI investment in China, which amounted to around $12.4bn in 2025.

Recent reports suggested that Chinese AI darling DeepSeek is nearing a $7.4bn raise backed by the likes of Tencent, Contemporary Amperex and the $8bn, state-backed National Artificial Intelligence Industry Investment Fund.

Meanwhile, Alibaba led a $293m funding round into ShengShu Technology, a Beijing-based start-up behind the Vidu AI video-generation tool.

Advertisement

China’s core AI industry – which boasts more than 6,200 companies – was valued at nearly $174bn in 2025, according to a government statement from March, while the market research firm International Data Corporation placed the Chinese AI market at some $63bn at the end of 2025, with estimates expecting it to cross the $200bn mark by 2029.

Bloomberg also reported that key Chinese state agencies, including the National Development and Reform Commission, are in early discussions to create a blueprint for a network of interconnected computing hubs across the country. Details of the early-stage discussions could change, the sources added.

The funds are reportedly expected to materialise via sovereign debt, including long-term government bonds and state funds meant for investment in strategic industries, as well as bank loans and private capital.

The plan forms a key part of the “six networks” programme announced earlier this year, which plans the build-out of computing, water, communication, urban underground pipe and logistics networks, and power grids, said Bloomberg sources.

Advertisement

Local suppliers, including Huawei, are to be tapped for at least 80pc of the required technology, such as AI chips, while state-run corporations such as China Mobile and China Telecom are expected to manage a majority of the data centres.

China is aggressive in its protection of home-grown technology. According to rules, state authorities need to approve the export of certain key technologies, including AI.

Earlier this year, the country took action against Meta over its acquisition of the Chinese-founded AI company Manus, demanding that the US tech giant undo the deal and restore Manus’s Chinese assets to their original state.

Meanwhile, the US government last month moved to close a loophole that could have been aiding companies to export advanced US-made chips to subsidiaries of Chinese companies located outside China.

Advertisement

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Source link

Advertisement
Continue Reading

Tech

JL Audio Pavilion Thin-line Subwoofers Bring Big Bass to Walls and Ceilings Without the Big Box

Published

on

Garmin is expanding JL Audio’s custom-install speaker lineup with the new Pavilion Thin-line Subwoofers, a compact in-wall and in-ceiling series designed to deliver stronger bass without eating up floor space. Built around 8-inch drivers and promoted under the slogan “Powerful bass in any space,” the new models are aimed at homeowners, integrators, and outdoor entertainment spaces where traditional subwoofers are either too bulky, too visible, or just plain awkward.

The pitch is simple: high-performance JL Audio bass, a slimmer form factor, and flexible installation for indoor and outdoor systems where clean design matters almost as much as impact.

Slimmer Design, Lower Distortion, Bigger Installation Flexibility

JL Audio’s Pavilion Thin-line Subwoofers use the company’s DMA-optimized motor and suspension design to support long, linear excursion with lower distortion. The goal is tighter, cleaner bass from a compact driver platform that can still deliver meaningful output in space-constrained installations.

The design also incorporates JL Audio’s Concentric Tube Suspension technology, which helps reduce mounting depth without giving up the control and excursion needed for high-performance bass. That matters for in-wall and in-ceiling applications, where available space is often limited and traditional subwoofer enclosures are not always practical.

Advertisement
jl-audio-thin-line-subwoofers-round-square

Easy Installation

The JL Audio Pavilion Thin-line Subwoofers are optimized for in-wall or in-ceiling installation, featuring a shallow 3.8-inch mounting depth and infinite baffle construction that allows for seamless placement without requiring a dedicated enclosure.

A dog-leg mounting system provides users with the flexibility to install the subwoofers in a variety of materials and locations, indoors or outdoors, without needing a backplate.

Pavilion speakers are built to last and deliver strong sound by using marine-grade materials specifically constructed to withstand harsh environments. They meet or exceed ASTM standards for salt-fog and UV exposure, giving listeners added peace of mind when installing them outdoors.

External Design Features

Homeowners can choose from several design options. The flush-mount speaker grille is available in square or round shapes, with white or black finishes that can also be painted to better match a home’s décor.

Advertisement

The ultra-thin, fine-mesh grille attaches magnetically and matches the look of JL Audio’s Pavilion outdoor in-ceiling speakers. New construction brackets are also available to help prepare mounting locations during the framing and drywall stages of a new home build or renovation.

Engineered for practical use indoors or outdoors, the subwoofers carry an IPX5 rating for protection against water exposure, adding another layer of durability for covered outdoor installations.

Specifications

JL Audio Model Pavilion
Product Type Thin Line Subwoofer
Price (each) $1,000
Sizes 8″ (Round)
8″ (Square)
Color Satin Black or Satin White
Physical dimensions (Diameter) 10″ (254 mm)
Physical dimensions (Depth) 8″ (Round): 4.2″ (107 mm)
8″ (Square): 4.1″ (105 mm)
Weight 7.5 lbs (3.4 kg)
Water and Dust Rating IPX5
Speaker Type Infinite Baffle
Continuous Power Handling (RMS) 250 W
Sensitivity (SPL @ 1 W/1 m) 83.2 dB
Nominal Impedance 8 Ω
Recommended Amplifier Power (RMS) 50-250 W
Cone Material Injection-molded, mica-filled polypropylene
Electrical Features Compass-safe distance 93″ (235 cm)
Speaker Connections Spade Connectors
Mounting Panel Thickness Minimum: 0.25″ (6 mm)
Maximum: 1.625″ (41 mm)
Mounting Depth Clearance 3.8″ (97 mm)
Frontal Grille Protrusion 8″ (Round): 0.4″ (10 mm)
8″ (Square): 0.34″ (9 mm)
Mounting Hole 8.96″ (229 mm)
Driver Displacement 0.054 cu ft (1.53 L)
Free Air Resonance (FS) 37.98 Hz
Electrical “Q” (Qes) 0.731
Mechanical “Q” (Qms) 9.471
Total “Q” (Qts) 0.679
Equivalent Compliance (Vas) 0.61 cu ft (17.31 L)
One-way Linear Excursion  One-way linear excursion (Xmax; specs are derived via one-way voice coil overhang method with no correction factors applied) 0.40″ (10 mm)
Effective piston area (SD) 32.705 in² (0.0211 m²)
DC resistance (RE) 7.24 Ω
Sealed Enclosure Specifications (if a sealed enclosure is used) Volume (net int.) 2.00 cu ft (56.6 L)
-3 dB cutoff frequency (F3) 40.9 Hz
System resonance (FC) 53.66 Hz
System Q at resonance (QTC) 0.784
Ported Enclosure Specifications (if a ported enclosure is used) Volume (net int.) 1.5 cu ft (42.5 L)

Internal port diameter (ID) 4″ (102 mm)

Advertisement

Port length (L) 13.5″ (343 mm)

Tuning frequency (FB) 37 Hz

-3 dB cutoff frequency (F3) 29.6 H

Advertisement

The Bottom Line

JL Audio’s Pavilion Thin-line Subwoofers are built for homeowners and custom installers who want real bass without giving up floor space or visual cleanliness. The shallow 3.8-inch mounting depth, infinite baffle design, marine-grade construction, IPX5 rating, and paintable magnetic grilles make them more flexible than a conventional subwoofer, especially for whole-home audio, home theater, and covered outdoor spaces. Just don’t treat placement like hanging a picture frame. Once you start cutting into walls or ceilings, “oops” gets expensive fast.

Advertisement. Scroll to continue reading.

Price & Availability

JL Audio Pavilion thin-line subwoofers are available in square and round form factors in the choice of black and white finish options, priced at $1,000 each at JL Audio.

Source link

Advertisement
Continue Reading

Tech

Apple’s Vision Pro Sees the World With AI In VisionOS 27

Published

on

Apple’s Vision Pro hardware, last updated in the fall with an M5 chip, is getting new software upgrades with the latest version of VisionOS announced at WWDC. A big one is Visual Intelligence, camera-aware AI, at long last. It’s exactly the sort of thing Apple’s expected smart glasses, likely arriving next year, are going to need.

VisionOS 27 can be previewed now in a developer beta, and there are a handful of little updates that look ready to improve how the headset works this year.

The Vision-focused AI tools are what interest me most, though. They’re part of Apple’s new Siri-focused AI updates announced at this year’s WWDC conference. Asking Siri will allow you to see things on apps you have open on VisionOS, but Siri will also be able to recognize things in the room with you, too. 

Advertisement

This is the same type of camera-aware AI that Google and Samsung already have in the Samsung Galaxy XR headset, which arrived last fall. But in the case of VisionOS 27, Apple’s not doing any sort of live mode for Siri that can continuously see what’s going on like Gemini Live can. Instead, Siri just visually snapshots what’s in front of your eyes in that moment by tracking your gaze.

Siri appears as an orb in a living room screenshot of VisionOS 27, with floating screens of Siri chat

Siri lives as an orb in VisionOS 27 now.

Apple

VisionOS 27 has some other interesting additions, although they’re unlikely to be enough to win over newcomers. Personal panoramic photos can be converted in 3D immersive backgrounds. There’s also a new way to preview 3D objects from Mac apps inside Vision Pro, a way of virtually extending apps as part of a creative workflow. 

Advertisement

Even so, Apple still hasn’t developed any new core apps for Vision Pro, or made any headway in enabling the Apple Watch, iPhone or iPad to work like connected Vision accessories, something I hoped would happen. Apple’s still leaning on Macs as the best computer companions for the $3500 headset.

While many people have reported that the Vision Pro’s life is ending in the face of a shift to smart glasses in the next few years, the Vision Pro’s hardware can clearly do things no glasses could dream of anytime soon. But I’ve been waiting for Apple’s spatial computer to make the most of its processing power, sensors and high price tag, and these additions are welcome, and these updates are mostly incremental except for Siri.

I’ll be trying out the developer beta soon, and writing up some thoughts about it. 

Advertisement

Source link

Continue Reading

Tech

The AI boomerang effect: more data suggests employers are reversing AI layoffs

Published

on

Connecting the dots: Generative AI has been blamed for hundreds of thousands of layoffs over the past year, but evidence that companies moved too quickly to automate white-collar jobs is steadily mounting. Multiple recent studies suggest that many employers are refilling recently eliminated positions after overestimating AI’s productivity gains and cost savings.

In some studies, roughly a third of companies that attempted to replace workers with AI have either rehired some of them or expressed regret over the decision. The figures add to a growing body of evidence that the true cost of implementing generative AI is catching businesses off guard.

A late 2025 report from Forrester Research predicted that roughly half of AI-attributed layoffs would be quietly reversed. However, the so-called AI boomerang effect may not benefit all workers equally.

Advertisement

While firms might quietly rehire experienced employees, those seeking entry-level jobs may still be out of luck. Forrester also predicted that most companies will use the opportunity to pivot to cheaper offshore labor.

Meanwhile, Gartner published research in February predicting that half of the businesses that eliminated customer service positions will rename and refill them by 2027. The forecast accompanied a separate October 2025 survey of 321 customer service and support leaders, which found that only 20% had actually reduced headcount while pivoting to AI – suggesting automation has largely augmented workers rather than replaced them.

Fast Company recently covered a Robert Half report in which about 29% of surveyed companies had rehired employees for the exact same roles they had previously eliminated. Finance (44%), HR (35%), and tech (32%) saw the highest rates of rehiring, with marketing, legal, healthcare, administrative, and customer support close behind.

Advertisement

The firms discovered that while AI can complete many tasks more quickly and efficiently than humans, quality drops required more human oversight than anticipated.

Of 2,000 surveyed hiring managers, around 40% reported that AI could not replace institutional knowledge, 38% said they underestimated the need for human quality control, and 35% saw disappointing productivity gains. These findings follow a November report in which data from 2.4 million workers at 142 companies worldwide showed a recent steady rise in rehirings.

Tech-sector layoffs remain at historic levels and many firms cite AI as a factor, but some are reconsidering after experiencing sticker shock. Uber burned through its entire 2026 AI coding tools budget (spent largely on agentic platforms like Claude Code and Cursor) in just four months, with its COO acknowledging it was difficult to connect the spending to measurable improvements.

The company has since capped per-employee monthly spending on those tools. Rising costs have also prompted other AI tool providers to tighten usage limits.

Advertisement

Source link

Continue Reading

Tech

OpenClaw AI agent found falling for phishing attacks, spills user data

Published

on

OpenClaw AI agent found falling for phishing attacks, spills user data

Phishing simulation on an OpenClaw email agent with various configuration profiles showed that it was susceptible to tactics commonly used to compromise human users.

The OpenClaw open-source AI agent framework allows large language models (LLMs) to interact with real-world systems and perform actions autonomously. It can be used as an email agent for basic reasoning and operations.

Researchers at security firm Varonis created an OpenClaw agent and connected it to a Gmail inbox, browser tools, Google Workspace APIs, and fabricated internal company data sources, instructing it to monitor and process incoming emails.

image

The synthetic enterprise data included AWS credentials, database credentials, CRM exports, internal communications, and Calendar invites, all highly sensitive data.

The agent ran on two configurations: a generic one with standard productivity instructions, and a strict mode that included specific instructions for phishing awareness and identity verification procedures.

Advertisement

The framework was tested with two models, namely Google Gemini 3.1 Pro and OpenAI GPT-5.4.

“Varonis Threat Labs explored whether the same phishing techniques that have tricked humans for decades would also work on the AI agents working on their behalf,” reads the report.

“We created an OpenClaw AI agent named Pinchy to test whether the agent would pass or fail versions of classic phishing simulations.”

Simulated attack overview
Simulated attack overview
Source: Varonis

The researchers conducted four simulated phishing attacks and obtained mixed results, as summarized below:

  1. An attacker impersonated a team lead and requested access to the staging environment during a purported production issue. The agent located and emailed AWS IAM keys, database credentials, and SSH access details to an external Gmail account.
  2. The attacker requested a customer export under the pretext of working remotely on a presentation. The agent retrieved and sent a CRM export containing customer records, contact information, contract details, and revenue data without verifying the sender’s identity.
  3. The agent received a fake gift card email containing a phishing link. Under the generic configuration, it visited the phishing site and attempted to redeem the gift card using fabricated credentials before eventually identifying the page as malicious. The strict configuration blocked the attack immediately.
  4. Researchers created a malicious Google OAuth application disguised as a timesheet platform. The agent inspected the OAuth flow, analyzed the destination, identified the application as suspicious, and refused to grant access.

In the first two scenarios, the strict mode failed despite the additional safeguards, due to the framework’s failure to validate the sender’s identity, 

“Both Generic and Strict profiles failed because the verification step still collapsed when the request appeared operationally urgent,” explained Varonis about the first attack scenario.

Advertisement
The agent's response on scenario 2, exposing user data
The agent’s response on scenario 2 exposing client data
Source: Varonis

Varonis’ conclusion is that AI agents are good at detecting suspicious URLs, identifying fake login pages, spotting malicious OAuth apps, and recognizing phishing indicators, but may still fail due to a lack of identity verification, loss of context, and inability to apply “zero trust” principles to social interactions.

At the model level, Gemini showed greater willingness to interact, while GPT-5.4 had a more cautious posture.

Varonis recommends that agents should be explicitly required to verify sender identities, be prevented from emailing new external recipients without approval, and have limited access to internal data.

For high-risk actions such as credential sharing, financial data requests, and first-time communications, human approval should be requested.


article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Advertisement

Get the whitepaper

Source link

Continue Reading

Trending

Copyright © 2025