Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Maine has taken its public data breach reporting portal offline after fraudulent breach disclosures were published on the state’s website, prompting a review of procedures to prevent abuse in the future.
Yesterday, BleepingComputer reported that fake data breach disclosures had been submitted to Maine’s official breach notification portal impersonating Discord and the multiplayer social virtual reality platform VRChat.
At the time, VRChat told BleepingComputer the filing was fraudulent and had been submitted using the name of a fictitious employee.
In a statement published Friday, the Maine Attorney General’s Office acknowledged that data breach “hoaxes” were submitted through the state’s reporting system.
“The Office of the Maine Attorney General has been made aware of an apparent abuse of our data breach reporting system,” the statement reads.
“After conversations with VRChat, one of two affected companies, it has become clear that the reported data breaches were hoaxes submitted by an unknown entity unrelated to either company. These false reports have been removed from the database. We have no knowledge of any recent legitimate data breach reports from either VRChat or Discord.”
The Attorney General’s Office says it has now temporarily disabled public access to the breach notification database while it reviews reporting procedures to reduce similar abuse in the future.
Prior to the shutdown, submitted breach notices were automatically published to the public database.
“We don’t have any independent knowledge of the breaches, the submitting entity fills out the information and it goes directly onto the site. We will review the one you’ve flagged, thank you,” Maine Attorney General’s Office told BleepingComputer.
The notice states that companies can continue to submit breach notifications through the reporting service, but members of the public seeking copies of disclosures must now contact the Attorney General’s Office directly.
Maine’s data breach portal is commonly used by journalists, researchers, and threat intelligence firms to monitor newly disclosed security incidents and determine whether organizations are reporting cyberattacks or data breaches affecting consumers.
The incident demonstrates how automatically published breach disclosures can be abused to spread misinformation and damage a company’s reputation.
The fraudulent VRChat filing claimed the company suffered a data breach impacting over 2.4 million people and included a fabricated employee contact name in the disclosure.
After BleepingComputer contacted VRChat about the filing, the company confirmed the disclosure was fake and stated it had not submitted the notice to Maine authorities.
BleepingComputer also contacted Discord about the fraudulent notice submitted to the site but did not receive a response.
It is unclear how many additional fraudulent breach notices may have been submitted through the portal before the state suspended public access to the database.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Steven Bartlett has built one of the world’s biggest podcasts on the idea that the right people, obsessively managed, make the machine. Now four of those people have walked out the door. The star host of “The Diary of a CEO” has lost four core staffers in five months, Business Insider reported.
The exits are not junior. One is Jack Sylvester, who calls himself a co-founder of the show and built its YouTube presence to more than 18 million subscribers. Also gone: executive producer Jem Erith, trailers director Anthony Smith, and Grace Miller, whose job title was “head of failure and experimentation.”
Former colleagues did not undersell them. One described Sylvester and Erith as the “inner circle” behind the “heavy lifting” of the podcast. “They’re the reason it gets delivered twice a week,” another said of the four.
Everyone is being nice about it. Bartlett’s company, FlightStory, said the departures were planned over almost a year and that the staff left on good terms. All four posted warm goodbyes. “I owe Steve more than I could ever put into words,” Sylvester wrote, while admitting he did not know what was next.
Bartlett returned the compliment, saying nobody had a bigger impact on the show. Sylvester told Business Insider he was looking for his next move after the podcast left its early growth phase. Turnover is normal at fast-growing startups, and Bartlett’s previous company, Social Chain, spun off plenty of founders.
The timing is the story. The nine-year-old show is pushing hard into the US just as its longtime team thins out. Bartlett has moved to Los Angeles and opened a studio there. He is closing on Joe Rogan in YouTube subscribers, and regularly beats him on views.
Around the podcast, he is building a media company. FlightStory has about 150 staff and took in roughly $47m last year, and recently raised an eight-figure round. It now runs a speakers arm and a distribution unit for other creators. It is also exploring a paid membership to squeeze more from its superfans.
Bartlett is also a self-styled operating guru. He is known for obsessing over details, down to the carbon-monoxide level in the studio. He also screens hires with a “Culture Test” that scores how they would handle workplace scenarios. Losing four people who aced that test, all at once, is a curious look for a leadership brand.
There is a harder edge to the DOAC story, too. A BBC World Service investigation found a problem, according to reporting on the probe. Many of the show’s health episodes carried claims that ran against the scientific evidence.
It examined 23 health-related episodes and flagged an average of 14 harmful claims across most of them.
Bartlett has since added fact-check labels to some YouTube episodes where guests make contentious claims. The tension is the interesting bit. He has moved from interviewing chief executives to platforming wellness and self-help voices, the format that drives the biggest numbers and the loudest criticism.
None of that is slowing the growth. Like the wider creator economy, DOAC is a business built on one person’s name, scaling faster than the team around it.
The departures raise a real question. Can a show defined by its inner circle keep its edge once that circle is gone? Like so many media empires before it, DOAC now has to prove the brand outlasts the moment.
When gaming chair maker Secretlab announced the release of its very first home office chair, I wasn’t shocked.
There’s been a gradual trend with office chair makers like Herman Miller teaming up with Logitech to create a gamer-focused version of the Embody, alongside brands like FlexiSpot and Eureka Ergonomic launching its own line of gaming chairs.
On the flips-side, companies like Boulies, which has a long gaming heritage with its Master series, have branched out into office chairs (I still think the EP200 is the best value all-rounder, after over a year of constant use). With the rise of hybrid and remote working, it seemed like just a matter of time before Secretlab got in on the action.
Latest Videos FromTechRadar
I’ve been using mine for over a month now, and, as resident office furniture expert here at TechRadar Pro, I think the company nailed it. It’s a world away from the magisterial Titan Evo, and I suspect Evo fans may not appreciate what the Atlas is doing here. But it’s one of the top office chairs I’ve used precisely because it’s such a terrible gaming chair.
I’m obsessed with gaming chairs that look right at home in an office. I’ve covered stealth gaming and office chairs for years. Those understated seats that don’t draw attention on a Zoom call with the boss, but are perfect for late-night play sessions (the Corsair TC100 Relaxed is a good budget example).
On that score, the Secretlab Atlas is a total success. Now, it’s not a gaming chair. But you can see it’s taken inspiration from the Titan Evo. Sit them side by side and it’s clear they share the same brand heritage, with those cleanly carved and subtle contours.
However, the design skips on two aggressive elements you’ll find on pretty much every gaming chair: the racing-style bucket seat bolsters and the shoulder wings. Both are designed to lock you into position that’s perfect for precision play on controller or M+K.
But an office worker needs that unrestricted extra space, allowing upper body movement. Fingers flying over the keyboard, constantly sweeping the mouse, and pivoting at the desk.
So, instead, it’s got a sleek look – Secretlab calls it “our lightest silhouette yet”, and I totally agree here. Because of that style, I find it works very well in the home office, even smaller ones. I carted it downstairs so my wife could use it in the dining room when she was working from home.
The Atlas blended in so well, feeling more like home furniture than any bulky leatherette bucket chair ever could. Weirdly, despite the higher backrest, it’s far less noticeable than her office-engineered Boulies OP180 was.
Professionally styled in Dune, Cookies & Cream, and Black³, the base model Secretlab Atlas features a SoftWeave Plus Fabric covering over cold-cure foam for a firm, ergonomic fit. It’s available in Regular and Large to accommodate your height and weight class.
All the best office chairs my team and I have reviewed have one thing in common: adjustability.
Given Secretlab’s experience, it’s no surprise that the Atlas has plenty to help tailor the sit. That includes mechanisms for tweaking the seat depth, backrest, and armrests, as well as synchronous tilt.
What this means in practice is that you can lean back with your feet on the ground, and the backrest and seat move as one for continued support. Effectively, it’s designed to keep your hips open to relieve pressure on your lower back.
It’s a world away from the traditional gaming setup, where the backrest tilts and reclines independently. It’s absolutely perfect for laying back, playing games, watching movies. But this mechanism also sends you into a horizontal slouch – one of the main reasons why so many modern chairs come with built-in footrests.
However, it’s not as adjustable as many of the office chairs I’ve tested out. When our gaming editor Dash Wood spoke to Vincent Sin, the company’s head of product development and industrial design, he explained: “What we found is that more often than not, with task chairs that have a lot of adjustments, it’s very confusing and people often will get it wrong. And I would say that’s worse than having something that automatically adjusts for you.”
But this brings me to the one adjustable element I actually would change. The chair does feel low to the ground – a view echoed in our Secretlab Atlas review.
The Large model does offer slightly more height over the Regular version, but I still think extra height range would’ve stripped away the only real complaint I have here. As an average man of average height, it’s not a deal-breaker for me. But it’s definitely something I’ve noticed during my time with it compared to other office chairs.
Also missing is the adjustable or dynamic lumbar support I tend to see on more premium office and gaming chairs. The Titan Evo famously uses the 4-Way L-Adapt Lumbar Support System, giving you control over the lower back support.
Instead, the Atlas uses a simplified Re-Curve backrest. Again, Sin said this design choice was intentional. “People don’t know that having too much lumbar support is also a bad thing.” Instead, the company pressure-mapped sitters to figure out where back support is needed and where it isn’t.
Now, I’m not entirely convinced by that. I still think adjustable support is essential, especially for those who need lower back pain relief. I suspect economics and aesthetics are playing a bigger role here than anyone is prepared to admit.
For a chair costing over $500 / £400, I was a little concerned when I first parked myself into the Secretlab Atlas.
The results, though, surprised me. Maybe Secretlab are right: we are over-engineering modern office chairs.
So far, so gaming and office chair. But there’s one major change with the Secretlab Atlas that I think makes it an ideal task chair, but absolutely useless for gaming.
It’s firm.
I think a lot of people expect office chairs to feel like a well-worn armchair or a couch. Soft, cushiony, like sinking into a foamy cloud.
That squishiness feels good for an hour or two while working. And it’s perfect for gaming – you want to feel snug, even during the sweatiest of battles. But it’s not recommended for an 8-hour workday, 5 days a week where you’re upright, typing away, maintaining your posture.
Now, I’m not saying you need to sit on a concrete slab at your desk. And the Atlas definitely doesn’t feel that way. I appreciate support it has as I work, and actually look forward to sitting on it.
I’m not the only one convinced by it.
My pregnant wife is suffering chronic back pain during her pregnancy. She’s hijacked the Secretlab Atlas because her softer office chair just made the pain worse. The Atlas eased the pressure. Her verdict (politely sanitized for this family-friendly publication: “It’s ridiculously comfortable.”
The Atlas is basically designed for a very different sitting profile. You’ll immediately notice the difference coming from a Titan Evo or similar. So, it’s not the best gaming chair, but it was never meant to be.
DJI has now given the Osmo Pocket 4P a wider global release after initially limiting its most capable pocket camera to China. It is now available across the UK, Europe, Canada, and Australia, but the US remains missing from the list.
The Standard Combo starts at £529 or €599 and includes the camera, a fill light, carrying pouch, and a handle with a tripod thread. In Canada, DJI lists the same bundle at US$619, as prices on its Canadian storefront are displayed in US dollars. The Vlog Combo costs £605, €689, or US$669 in Canada and adds a Mic Mini 2, Mini Tripod, larger carrying bag, and the Osmo FrameTap remote.
The Osmo Pocket 4P uses a 1-inch primary sensor paired with a 20mm equivalent f/2.0 lens. It supports up to 17 stops of dynamic range using DJI’s new 10-bit D-Log 2 profile, giving creators more room to adjust highlights, shadows, and colors during editing.

The bigger addition is a second 1/1.28-inch sensor paired with a 60mm equivalent f/1.8 telephoto lens. It delivers 3x optical zoom and gives creators another framing option for portraits, products, and distant subjects without relying entirely on digital cropping. The wide camera records slow-motion video at up to 4K/240 fps, while the telephoto reaches 4K/200 fps. A 2-inch OLED screen offers 1,000 nits of brightness, and DJI claims up to 210 minutes of battery life.
DJI has not announced US pricing or a release date for the Pocket 4P. The company’s recent launches continue to face roadblocks as the FCC tightens restrictions around DJI and foreign-made technology. Older products such as the Osmo Pocket 3 remain available because they received authorization before the crackdown.
The government has since expanded the same Covered List approach to foreign-made robots, including future robot vacuums and Roombas. For US creators, the Pocket 4P is therefore another DJI product they can see launched almost everywhere else but cannot officially buy at home.
Flock Safety’s aggressive expansion into the law enforcement market has been coupled with nearly constant negative coverage of its tech and its practices. Multiple cities have paused or cancelled their agreements with Flock following public outcry over the surveillance tech.
Flock’s willingness to allow law enforcement agencies to search a nationwide network of cameras has generated plenty of negative headlines of their own, including the fact that Texas cops were using Flock to track someone (possibly) seeking an abortion after she’d already left the state.
Flock’s statements in its defense are, well, super-defensive. It claims it can’t control what cops do with its tech. That’s somewhat true, but it’s also true that Flock has made zero effort to limit abusive access until it’s been forced to by its government customers or outside pressure.
Flock also claims its tech has contributed to investigations and reducing crime. This is probably true but it doesn’t mean all that much when pretty much any extensive surveillance network is going to generate some additional arrests. It’s the trade-off that’s the problem and Flock doesn’t seem to care at all about the millions of people subjected to its surveillance. Martial law would likely lower crime rates, but that’s not a an acceptable justification for martial law.
The problem with ALPR tech being ubiquitous is that it isn’t really making police work better or smarter. Instead, it just seems to be allowing cops to be wrong faster and at scale. And police officials who love this tech will always remind us that there’s a price to be paid to live in a safe society. What they never admit is that they keep changing the price tag with each new rollout of surveillance tech.
Flock’s contribution to the problem means it’s just going to keep making headlines. And while Flock may not be a direct contributor to what’s discussed here, these things wouldn’t have happened if it weren’t for Flock.
First, there’s this story, which involves automotive journalist Joel Felder and the Range Rover he was test driving. His loaner from Range Rover kept getting flagged by Flock as stolen. That Felder is alive to tell his story is more due to his race and location than the so-called police work that resulted in him being ambushed by Minneapolis cops in mall parking lot.
On an otherwise normal Sunday afternoon in late June, I’d decided to take the $155,000 Range Rover I was testing that week out to run some errands with my wife. Little did I know that choice would complete a technological chain linking surveillance cameras, AI, and law enforcement that led to me and my wife being surrounded by police, hands on their guns, in a Kohl’s parking lot in suburban Minnesota.
After dropping off our Amazon returns, we’d just gotten back in the Range Rover and reversed maybe two feet out of the spot when four cop cars came flying out of nowhere and boxed us in. The officers jumped out and started shouting. It’s a situation that can quickly and frequently turn bad, so as unprepared as I was, I followed their orders, got out with my hands up, and tried to figure out what the hell was happening.
It turns out cops in the area had been tracking the Range Rover for days, following alerts from Flock. But they kept losing the trail when Felder returned home. When he passed a Flock camera near his stop, Plymouth, MN police showed up to accost him.
The main problem was something either Flock or the PD could have taken a closer look at. The Range Rover loaner had New Jersey plates. And on NJ plates, two digits are printed smaller than the rest of them.
The New Jersey plates that were allegedly stolen from the LA dealer were 34 03 DTM, not 34 10 DTM. But when the police report was created and the plate was entered into Flock’s system, it was just recorded as 34 DTM. Just the five large characters, no little number in the middle. And Flock’s AI tech wasn’t registering that non-standard little number when it began picking up the Range Rover around town. It just saw 34 DTM in large type and started alerting the local police.
Which means this is also a nationwide problem, on top of being a specifically New Jersey problem. The automated plate readers are reading these plates wrong, meaning any plate starting with 34 and ending with DTM would automatically be flagged as stolen. Who knows how bad that’s going in New Jersey (we’ll wait for those headlines to roll in!), but it’s already a bit of problem in Minnesota, and not just for this particular The Drive contributor.
In fact, four other 34 ## DTM cars were being tracked around Minnesota that week, according to Officer Ganshyn. I was just the first one to get nabbed. The only way to stop it would be for the LAPD to correct their initial report and update Flock’s system, which Jaguar Land Rover was now racing to make happen following the phone call.
And just to let you know how the cop problem possibly outweighs the Flock problem, I’ll let these Plymouth (a suburb of Minneapolis) cops speak for themselves:
“You’re lucky we’re in Plymouth. If you were in Minneapolis, they definitely would’ve come at you with guns drawn.”
Cool cool cool.
No doubt this also kept the gun-play to a minimum, according to the Plymouth PD report:
“I observed the driver, who was a white male wearing shorts and a green shirt, as he was putting something in the back seat of the car. I could also see a white female getting into the front passenger seat…”
But Flock’s contribution to public danger isn’t limited to stolen plates. Its system also tracks vehicles of people who are suspected to have stolen something other than the vehicle they’re riding in. Here’s what happened to an unlucky Colorado resident who found herself on the wrong side of this surveillance tech:
Chrisanna Elser got a summons from Columbine Valley police accusing her of stealing a package. The evidence? A license-plate-reader camera that placed her truck near the scene. The problem? She wasn’t there. According to Denverite, Elser had to dig up her own timestamped truck video and a neighbor’s doorbell camera footage to prove it. Nobody verified the camera’s implication before the summons landed. The camera spoke, and the system listened — no further questions asked.
Elser was forced to prove her own innocence as a cop stood in her doorway. Fortunately, she had the evidence on her phone. Otherwise, who knows what would have happened? Certainly not the officer who did nothing more than convert the faulty data into a summons.
When Elser tried to get the officer to watch the time-stamped video from her truck, the officer told her he simply wasn’t interested in anything she had to show him that might prove her innocence:
On her doorstep, the officer issued a summons, without ever looking at the surveillance video Elser had.
“We can show you exactly where we were,” she told him.
“I already know where you were,” he replied.
It took Elser five weeks to get the charges dropped and it took escalating it to the Chief of Police to get it done. While the chief didn’t go so far as to apologize, he did at least let her know she did a “great job” proving her innocence, when that’s not how it’s supposed to work in the first place.
While I understand the presumption of innocence only really applies once criminal proceedings are underway, law enforcement’s reliance on unreliable tech is now forcing people to document their own movements and actions just as thoroughly as Flock tracks theirs, just in case the cops have it wrong. That’s fucked up. We shouldn’t be obligated to constantly generate a history of our movements just to get bogus criminal charges dropped, especially when we know that doing so just means providing the government with additional ways to track our movements.
When cops are boxing you in as you’re trying to leave the mall, they’re the ones who should be as absolutely sure as possible that their actions are justified. The imbalance of power between citizens and law enforcement demands better from law enforcement, but every new tech tool that cops embrace just makes it easier to make more mistakes faster. There’s nothing out there that even slightly suggests pervasive surveillance is reducing crime, but cops treat everything an algorithm spits out as gospel because it means they won’t have to think for themselves. This is unacceptable. And just because no one got arrested or killed doesn’t mean these errors are harmless.
Filed Under: alprs, colorado, false positives, license plate readers, minnesota, surveillance
Companies: flock safety
Since the early days of smartphones, storage space continues to be a persistent problem. More specifically, running out of it. For Android users, that often translates to your Google account storageand with Google now counting Android device backups toward your account storage limits, it’s worth reviewing your backup settings to check for any redundancies. After all, no one wants to pay for more cloud storage space if they don’t actually need it.
Android device backups themselves typically only need a small amount of storage, but there’s an overlooked setting that might be wasting gigabytes of extra space in your cloud: backing up WhatsApp media through Google Photos. Turns out, this giant messaging app is probably already saving those very same files to the cloud. So by opting in for separate WhatsApp backups to your Google account storage, you’re actually backing them up twice.
It’s like this: WhatsApp automatically downloads any photos and videos you open and places them into a specific folder on your device. And if you chose to back up every device folder to Google Photos (which you probably did during initial setup way back when), then those downloaded files might also be getting uploaded to Google Photos. The result is the same images and videos being stored twice to your Google account. Messaging apps eat up storage as it is, but this issue doubles the trouble.
If you send and receive a ton of photos and videos through WhatsApp, you could be wasting dozens of gigabytes of duplicated data over the course of a year. Backing up isn’t a bad idea, but backing up twice is just unnecessary. So, rather than turning off WhatsApp backups altogether, the smarter solution is to simply stop Google Photos from backing up WhatsApp folders. That way, you can keep allowing this Facebook-owned app to do its chat backups without creating duplicates in your Google account.
For most Android users, the easiest thing to do is to change your Google Photos settings to stop backing up the folders that contain WhatsApp images and videos. Open the Google Photos app, hit your profile picture in the top right corner, tap “Photos settings,” then hit “Backup.” From there, scroll down to “Back up device folders” and toggle off WhatsApp.
WhatsApp users can also adjust the specific app’s backup frequency to daily, weekly, monthly or never within WhatsApp’s chat backup settings. You can also reduce backup size by excluding videos, which are typically going to be the largest files included in backups. Past WhatsApp backups can also be removed separately through Google One’s WhatsApp backup management tools.
Security
A lesson for aspiring vandals: Take out all the cameras, not just the ones that flout your ideals
Note to privacy-conscious vandals: If you’re going to destroy Flock license plate readers, make sure you also take out the other CCTV cameras in the area that could catch you in your crime. Otherwise, you’ll end up like one unlucky Californian.
Marcus Bee, 40, was arrested by the Monterey County Sheriff’s Office on Tuesday, accused of joining the ever-growing band of US citizens damaging the controversial cameras popping up across the country.
A police report filed this week stated that Bee, of Pismo Beach, was arrested on suspicion of attacking at least three Flock cameras in Lockwood and Bradley.
According to the deflock.org website, which maps Flock camera deployments, there are only three of the automated license plate readers (ALPRs) running in the two communities – one in Lockwood and two in Bradley, roughly 25 miles away.
Police allege Bee caused thousands of dollars’ worth of damage to “public safety infrastructure.”
Monterey County Sheriff’s Office added that Bee was caught after “his actions were captured by other surveillance cameras located nearby,” along with other investigative leads.
“This arrest sends a clear message that anyone who intentionally damages public safety equipment will be identified, arrested, and held accountable,” said Monterey County Sheriff Tina Nieto.
“These cameras have become an invaluable investigative resource that helps us solve crimes, recover stolen vehicles and ag equipment, locate missing persons, and protect our communities. Any attempts to disable these systems will not prevent us from doing our job.
“In this case, the suspect’s own actions were captured on surveillance cameras, leading directly to his arrest. We will continue to aggressively investigate these crimes and seek prosecution against anyone who targets public safety infrastructure.”
Bee was jailed with bail set at $30,000.
The case follows a similar one in Georgia last week, although local police were unable to identify the suspect(s) behind the two attacks, which involved setting two ALPRs on fire.
The two attacks were timed fairly close together, although the phenomenon of inflicting criminal damage onto Flock cameras is something of a long-running trend.
Several US police forces have been tasked with arresting alleged Flock vandals, including Jeffrey Scott Sovern, 41, who authorities believe was behind a spate of attacks on ALPR cameras in North Suffolk, Virginia, between April and October 2025.
He said, at a hearing in June, that he believed the technology was unconstitutional.
Monterey County Sheriff’s Office said Flock’s cameras “are an important investigative tool” used to help solve various types of crimes, including missing persons cases, car thefts, and violent crimes such as shootings and homicides where suspect vehicles are involved.
Contrary to the opinions held by many, it went on to say that the cameras “are used exclusively to support legitimate criminal investigations,” and refuted the notion that they are used to support the US government’s anti-immigration efforts.
Likewise, Flock has repeatedly denied offering contracts to agencies such as Immigration and Customs Enforcement (ICE), although reports suggest police were instead carrying out searches on ICE’s behalf. Customs and Border Protection (CBP) has also allegedly used Flock data in its own immigration investigations.
Other critiques of the technology used by thousands of police departments across the US include problematic abuses, such as police officers using it to stalk romantic interests.
The Institute of Justice is aware of at least 26 cases of this behavior, it reported earlier this month, with the majority taking place since 2024.
Additionally, the American Civil Liberties Union (ACLU) takes issue with the scale of data gathering by ALPRs.
It claims that less than 1 percent of the cars scanned are connected to crime, yet they still have details added to a database, such as vehicle manufacturer, model, color, license plate number, bumper stickers, and scratches.
Flock CEO Garrett Langley claimed this week in an interview with The Drive that the company’s cameras were used to solve around 1 million crimes across the US last year.
Responding to claims such as Sovern’s – that the cameras are unconstitutional, specifically that they violate Americans’ Fourth Amendment rights – Langley said there are no legal issues, and he doesn’t foresee any arising in the future.
Flock’s spokespeople have repeatedly condemned the cases of camera vandalism, highlighting the risk of losing evidence that could be crucial to solving ongoing criminal cases. ®
This article is republished from The Conversation under a Creative Commons license. Read the original article.
A little-noticed presidential national security directive is now the legal engine behind a wave of terrorism prosecutions against left-wing protesters.
That domestic campaign now has an international dimension, one that American officials had been planning for months, culminating on July 16, 2026, when Secretary of State Marco Rubio’s Ministerial on the Resurgence of Political Terrorism drew representatives from more than 65 countries to Washington. The gathering was informally called the “Antifa summit.”
Rubio described antifa-aligned networks as sharing infrastructure across borders and accused Iran and Cuba of helping bankroll the movement, without offering evidence. The White House declared the summit the start of an “unprecedented global offensive” against what it calls “radical left terrorism.”
This offensive is built on the same domestic legal architecture that has now sent American activists to prison for decades.
That architecture is National Security Presidential Memorandum/NSPM-7, issued on Sept. 25, 2025, which for the first time appeared to authorize preemptive law enforcement measures against Americans based not on whether they are planning to commit violence but for their political or ideological beliefs.
Nearly a year later, that blueprint has moved from paper into practice.
The Justice Department has built task forces staffed by counterterrorism prosecutors. The FBI has set up its own NSPM-7 mission center to oversee investigations into left-wing movements, including a joint effort with the IRS to investigate nonprofit groups.
The Justice Department has used this machinery to convict activists and send some of them to prison for decades.
NSPM-7 was not passed by Congress. It’s a lesser-known tool of executive power: a presidential memorandum.
As an international relations scholar who has studied U.S. foreign policy decision-making and national security legislation, I recognize that presidents can take several types of executive actions without legislative involvement: executive orders, memoranda and proclamations.
This structure allows the president to direct law enforcement and national security agencies, with little opportunity for congressional oversight.
Executive memorandums direct agencies to prepare reports, implement policies or align programs with the administration’s priorities. Unlike executive orders, they aren’t required to be published. When they relate to national security, like NSPM-7, they’re called national security directives – many of which stay classified and may not be declassified for years or decades.
The stated purpose of NSPM-7 is to counter domestic terrorism and organized political violence, focusing mainly on perceived threats from the political left. The memorandum identifies “anti-Christian,” “anti-capitalism” or “anti-American” views as potential indicators that a group or person will commit domestic terrorism.
The memorandum claims that political violence originates with “anti-fascist” groups that hold the following views: “support for the overthrow of the United States Government; extremism on migration, race, and gender; and hostility towards those who hold traditional American views on family, religion, and morality.”
The strategy includes preemptive measures to disrupt groups before they engage in violent political acts, empowering multiagency task forces to investigate potential federal crimes related to radicalization and the groups’ funders. Former Attorney General Pam Bondi’s December 2025 implementation memo went further, ordering a five-year review of agency files on antifa. A task force staffed with counterterrorism and organized-crime prosecutors is carrying out these investigations.
The memorandum directs the Department of Justice to focus FBI resources from approximately 200 Joint Terrorism Task Forces on investigating “acts of recruiting or radicalizing persons” for the purpose of “political violence, terrorism, or conspiracy against rights; and the violent deprivation of any citizen’s rights.”
NSPM-7 also allows the attorney general to propose groups for designation as “domestic terrorist organizations.” That includes groups that engage in “organized doxxing campaigns, swatting, rioting, looting, trespass, assault, destruction of property, threats of violence, and civil disorder.”
Existing laws allow the secretary of state to designate groups as “foreign terrorist organizations” that are then subject to financial sanctions.
But these laws do not permit the president to label domestic groups this way.
That gap hasn’t stopped prosecutions. In Texas, eight defendants tied to a “North Texas Antifa Cell” were sentenced in June 2026 for a 2025 armed confrontation at the Prairieland immigration detention center. One man received 100 years, and others who never fired a weapon still drew decades in prison under terrorism sentencing guidelines.
In Minnesota, 15 members and associates of a group called Direct Action Minnesota were indicted in June 2026 on conspiracy and assault charges. A 94-page indictment cited behavior such as wearing an “I’m Antifa!” sweatshirt, possessing a bullhorn or including a devil emoji in a Signal message.
NSPM-7 marks a major conceptual shift in U.S. counterterrorism policy, departing from approaches that primarily targeted foreign threats.
Earlier directives, dating to Ronald Reagan’s presidency, treated terrorism as a global menace countered through military power and diplomacy. In the 1990s, the Clinton administration reframed it as a domestic challenge after the 1993 World Trade Center bombing and 1995 Oklahoma City bombing.
After 9/11, the Bush administration fused counterterrorism with national defense through the global war on terrorism. The Obama administration later tried to narrow those powers, asking whether targeted individuals “pose a continuing, imminent threat to U.S. persons” — a standard focused on tactics and capture feasibility, not ideology.
The first Trump administration used a “travel ban” against several “terror-prone” countries, while President Joe Biden redirected focus toward weapons of mass destruction.
Notably, the “domestic terrorist” label itself has rarely produced actual charges. The State Department designated four antifa-aligned groups as foreign terrorist organizations. But antifa is a decentralized movement, not a formal group with a roster.
This designation lacks any real legal weight because U.S. law has no formal domestic terrorist organization category. Creating one risks infringing on First Amendment protected speech. Domestic terrorism itself is not a chargeable offense.
Prosecutors have instead leaned on older statutes such as material support for terrorism and conspiracy laws, tools originally built for cases like the ones above, not protest movements.
There is no single official definition of terrorism in U.S. law; definitions vary by purpose – criminal law, intelligence collection, civil liability.
Definitions in all those areas typically focus on identifying violent or dangerous acts done with the intent to intimidate or coerce civilians or influence government policy.
But more than redefining terrorism, NSPM-7 reorients the machinery of national security toward the policing of belief.
The First Amendment generally prevents the government from punishing people for unpopular opinions. It also protects the ability for people to associate to advance public and private ideas in pursuit of political, economic, religious or cultural goals.
The directive’s emphasis on ideological orientations – “anti-Christianity,” “anti-capitalism” and “anti-American” views – as indicators of domestic terrorism potentially jeopardizes First Amendment rights.
Thirty-one members of Congress sent a letter to Trump in October 2025 expressing “serious concerns” about NSPM-7, warning that it poses “serious constitutional, statutory and civil liberties risks, especially if used to target political dissent, protest or ideological speech.”
As the ACLU warns, any definition of terrorism that includes ideological components risks criminalizing people or groups based on belief rather than based on violence or other criminal conduct.
Congress has declined to create a domestic complement to the foreign terrorist designation in large part because of the potential for impinging on First Amendment–protected association and speech.
But I fear that chilling speech may be the point.
NSPM-7 does not criminalize previously legal conduct.
Rather, it states that the Trump administration will focus investigations around the identity and ideology of supposed perpetrators. Prioritizing investigations into this broad swath of ideologies serves to instill fear, silencing anti-fascist and other messages in opposition to the Trump administration.
Law professor Steve Vladeck frames this chill as “obeying in advance,” in which organizations self-censor rather than risk investigation, prosecution or defending against the “domestic terrorist” label. Federal judges in the Prairieland case have shown little sympathy for that distinction: One judge described the protest itself as “an assault on democracy,” even for defendants who never touched a weapon.
Although left-wing violence has risen in the past decade, empirical evidence shows it remains far below historical levels of right-wing or jihadist violence.
Most domestic terrorists in the U.S. are politically on the right, accounting for the vast majority of domestic terrorism fatalities.
Yet NSPM-7 focuses disproportionately on left-wing ideologies. NSPM-7 departs from prior U.S. counterterrorism frameworks by prioritizing the suppression of ideologically motivated dissent, even where, as in Minnesota, judges have already dismissed roughly half of similar federal cases for lack of evidence.
Melinda Haas is Assistant Professor of International Affairs at the University of Pittsburgh
Filed Under: 1st amendment, censorship, domestic terrorism, fbi, free speech, marco rubio, nspm-7, presidential memorandum, radical extremism
Okta on Thursday agreed to acquire AI identity security startup Permiso Security, betting that demand for protecting AI agents and other machine identities will grow as enterprises deploy autonomous software across their operations.
The identity management company did not disclose the terms of the transaction. But TechCrunch has learned that the acquisition is valued at just under $200 million and is structured as an almost all-cash deal, according to a source with knowledge of the deal. A spokesperson for Okta did not dispute the figure when asked by TechCrunch, but would not comment on specifics of the deal terms.
The deal is expected to close in the third quarter of its fiscal 2027, Okta said, subject to customary closing conditions.
Okta’s move to buy Permiso comes as identity management companies seek to expand beyond verifying users at login to continuously monitoring what users, applications, and AI agents do once gaining authorized access to a network environment. That shift has intensified competition to secure machine identities as enterprises embed AI deeper into everyday operations.
Permiso, which emerged from stealth in 2022, develops software that helps security teams spot suspicious activity in cloud environments after users or applications have been granted access. More recently, the startup has expanded its platform to monitor AI agents and other machine identities.
Co-founded by former FireEye executives Paul Nguyen and Jason Martin, Permiso specializes in detecting attacks that use stolen or compromised identities to move through cloud infrastructure. In April, the startup also introduced SandyClaw, a platform designed to analyze AI agent skills in a sandboxed environment to identify malicious behavior before they are deployed.
The deal strengthens Okta’s push into securing AI agents and other non-human identities alongside its core identity management business.
“Permiso will extend Okta’s identity security fabric with proven identity threat detection and response capabilities, and an incredible threat research and security team that will advance Okta’s threat detection and prevention capabilities,” Okta’s chief product officer Ely Kahn said in a prepared statement.
Permiso has raised about $29 million to date, including an $18.5 million Series A round in April 2024 led by Altimeter Capital. People familiar with the financing said the Series A valued the Palo Alto-based startup at about $80 million on a post-money basis.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Rumor mill: Google’s Pixel 11 is coming into focus thanks to two separate leaks. One is an official teaser video released by Google itself, while the other is a Bluesky post from WinFuture’s Roland Quandt detailing the phone’s storage options, battery capacity, and pricing.
The Google video is the more visual of the two. It offers a close look at the Pixel 11 Pro’s rear camera bar, where the phone retains its three-lens setup while adding a circular light effect beside the cameras. The clip does not name the feature or explain what it does, but the spinning colors suggest Google is building something new around the camera area rather than adding a feature elsewhere on the phone.
Google’s narration only mentions familiar services such as Gmail, Maps, Search, Calendar, and Gemini. The video title teases “the next obvious move,” but Google leaves the meaning deliberately vague. That has fueled speculation that the light could serve as a status indicator, a Gemini-related processing light, or a notification system, but none of those theories have been confirmed.
The second leak comes from Bluesky, where Quandt posted what appears to be retailer-sourced information about the Pixel 11 lineup. According to the post, 256GB will be the minimum storage option across the entire range, marking a long-awaited shift for Google’s standard models. The leak also claims that the Pixel 11 will cost £879 in the UK, while the Pixel 11 Pro and Pixel 11 Pro XL will be priced at £1,079 and £1,279, respectively.
Those pricing figures are not as straightforward as they initially appear. The Pixel 11 and Pixel 11 Pro are technically cheaper than their 256GB Pixel 10 counterparts, while the Pixel 11 Pro XL costs more than last year’s model. However, the difference stems from Google’s decision to eliminate lower-capacity storage tiers rather than from a broad price cut across the lineup.
Pixel 11 256GB = 879 GBP, 4985mAh Pixel 11 Pro 256 GB = 1079 GBP, 4850mAh Pixel 11 Pro XL 257 GB = 1279 GBP, 5115mAh
– Roland Quandt (@rquandt.bsky.social) July 28, 2026 at 3:06 AM
Quandt’s Bluesky post also includes battery capacity details. The base Pixel 11 is said to feature a 4,985mAh battery, while the Pixel 11 Pro and Pixel 11 Pro XL are listed with 4,850mAh and 5,115mAh batteries, respectively. If accurate, the base model and the larger Pro XL would receive modest battery upgrades, while the regular Pro would see a slight reduction compared with the previous generation.
Google is set to unveil the Pixel 11 lineup on August 12. Until then, the picture remains incomplete.
Imagine you’re a company. You’ve got sensitive data you need kept safe, and you’ve got a cloud service provider that’s protecting it. But do you know how far that protection goes, and at what point it’s your turn to take over?
The sheer number of data breaches due to human error, specifically database misconfiguration, suggests that many don’t know that they, not the provider, are responsible for securing all the data properly (or are unsure how to do it).
In this article, we’ll look into the shared responsibility model: what it is, why it’s relevant, its benefits, its limits, and what happens when companies disregard it.
The Shared Responsibility Model is a security and compliance framework that defines the divided responsibilities of cloud service providers (CSPs) and their customers. This means that each has their own tasks in maintaining security.
In short, the provider is responsible for securing the underlying cloud infrastructure, but the customer needs to secure their own data, configurations, and any applications they may have.
In more detail, the provider takes care of:
On the other hand, the customer secures everything they own:
It would make things a lot easier if these rules and divisions were standardized, so when you understand them for one provider, you understand them for all. Alas, that’s not the case.
The above guidelines are general because the model somewhat differs between providers, and this lack of uniformity contributes to security gaps between the provider and the customer.
That said, make sure you understand your full responsibilities with each provider you use. For example, AWS says “customers should carefully consider the services they choose as their responsibilities vary depending on the services used, the integration of those services into their IT environment, and applicable laws and regulations.”
AWS makes a clear distinction between these responsibilities, saying that the customer is in full charge of managing the guest operating system, including updates and security patches. They must also configure the AWS-provided security group firewall and manage any other application software they own.
Microsoft further explains that responsibilities vary depending on where the workload is hosted: on software as a service (SaaS), platform as a service (PaaS), infrastructure as a service (IaaS), or in an on-premises datacenter.
However, “for all cloud deployment types, you own your data and identities,” it says. “You’re responsible for protecting the security of your data and identities, on-premises resources, and the cloud components you control.”
Google Cloud went with yet a third approach, differentiating between the shared model of other providers and its own “shared faith”:
Given that understanding the shared responsibility model properly in order to secure one’s data can be challenging, “Google believes that the shared responsibility model stops short of helping cloud customers achieve better security outcomes,” it writes. “Instead of shared responsibility, we believe in shared fate.”
The explanation of this approach focuses on “partnership” between the provider and the customer for increased security, as well as offering support and resources to help organizations secure data on their end.
The provider states that “a key component of shared fate is the resources that we provide to help you get started, in a secure configuration in Google Cloud. Starting with a secure configuration helps reduce the issue of misconfigurations, which is the root cause of most security breaches.”
The shared responsibility model is meant to provide a division of security, compliance, and ethical duties. The number one goal is to cover all bases to ensure all security controls are managed, thus preventing security gaps and potential breaches.
Should a breach happen, this shared control system is theoretically designed to help contain it faster and more efficiently. I say “theoretically” because security gaps do exist, as we’ll see later.
Additionally, the model is designed to ensure that neither the provider nor the client duplicates security steps unnecessarily, wasting their time and effort.
Finally, the security and infrastructure cost is much lower than managing one’s own cloud, and the deployment speed is much higher.
Overall, the model provides the benefits of the public cloud without having to maintain its infrastructure.
According to AWS, this shared model “can help relieve the customer’s operational burden as AWS operates, manages and controls the components from the host operating system and virtualization layer down to the physical security of the facilities in which the service operates.”
However, failing to follow it for any reason carries significant risks:
The first is the one you should be the most worried about: should it happen, all the others will follow.
Simple misconfiguration mistakes can lead to data breaches, and unfortunately, this happens all the time.
This is a good time to discuss the issues with this system, and the first one is certainly the problem of misunderstanding, which leads to overlooked responsibilities and, subsequently, to security gaps in the customer’s databases, hence between the provider and the customer as well.
This issue results in misconfiguration – the direct culprit for most cloud security breaches.
Understanding responsibilities in a constantly changing environment is difficult. Sometimes organizations try to follow it, but overlook something. Sometimes they’re not even aware that they have this responsibility, presuming it all falls on the provider. And often they fail to protect certain data that may seem less relevant, such as backup files.
Either way, the end result is the same: databases are left unprotected and exposed for all to see and download.
This is so far from being theoretical that it’s nearly the norm. Just recently, security researcher Jeremiah Fowler discovered yet another unprotected database, with 666,369 records, including names, email addresses, phone numbers, IP addresses, and hashed passwords of the Tribeca Festival employees and attendees.
Potential consequences are massive and far-reaching for both the organizations that failed to protect the data and the individuals whose data was exposed.
Other issues in the shared model system include getting full visibility into the cloud environment, a lack of effective integrations that sustain and improve collaboration, challenges integrating tools and platforms, etc.
And if you’re managing security in a multi-cloud environment, that’s a larger beast to deal with.
Protecting data is neither only the cloud service provider’s job nor that of the company. Rather, the job is divided between “mine” and “yours”. Generally speaking, providers protect what they’ve created, their house, so to speak. Customers are in charge of making sure all their own data and related services in the rented rooms are properly secured.
This is more easily said than done, given that, despite the many advantages of sharing this responsibility (including significant time and cost savings), mistakes happen a lot for many reasons, and the customers’ databases end up exposed. It’s a key issue to overcome if this model is to function successfully long-term.
Weekend Open Thread: Brooks Brothers
Commonwealth Games boxing: Jadumani Singh seals dominant 5-0 win over Pakistan’s Sumama Rehman to enter quarter-finals | Commonwealth Games News
Why Trees Belong on the Risk Register
Intel is reversing course and bringing hyper-threading back to its server chips
Ripple bought a bank in pieces. The $4 billion audit
Luke Littler dismantles Gerwyn Price to retain title in Blackpool
The Part of the Electric Transition Nobody Wants to Discuss
A New Post-Apocalyptic Gundam Anime Series Blasts Into SDCC
BITCOIN JUST ENTERED THIS CRITICAL ZONE…
16 Dresses for the High Summer Event
2026 3M Open leaderboard: Scottie Scheffler finds putter in Round 1, sits three back
Major shareholder moves on Canyon
The Peugeot Family: How 200 Years of an “Old Money” Dynasty Died in A Boardroom
XRP Ledger adds $2.6B as RWA inflows rank second
Spain sweeps the board at 2026 World Cup with individual awards
Bitcoin Enters the 3rd Stage of the Bear Market
‘Stargate’ Creator’s New Sci-Fi Series Returns for Season 3 Tomorrow
Kraken Enables Retail Access to Jersey Mike’s IPO via Tokenized Shares
Anthropic launches Claude Opus 5, a cheaper AI model for coding, agents and enterprise workflows
Sara Gilson Killed By Husband After Viral “Pedophile” TikTok Video
You must be logged in to post a comment Login