Connect with us

Tech

New U-Boot flaws could enable stealthy firmware attacks

Published

on

Motherboard

Six vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during device boot, potentially enabling stealthy firmware attacks that compromise security protections and install persistent malware.

U-Boot is one of the world’s most widely used open-source bootloaders and is found in many embedded Linux devices, including enterprise servers’ Baseboard Management Controllers (BMCs), networking equipment, industrial systems, IoT devices, and other appliances.

Because U-Boot is responsible for loading the operating system, vulnerabilities in the bootloader can allow attackers to compromise a device before the operating system and its security software have a chance to start.

image

One of its security features, known as Verified Boot, uses cryptographic signatures to ensure that only firmware and operating system images signed by a trusted key are loaded during startup.

In a report published this week, firmware security company Binarly disclosed six vulnerabilities in U-Boot’s FIT (Flattened Image Tree) signature verification code.

Advertisement

“Recognising the critical nature of this component, the Binarly Research team decided to examine the core functionality of the U-Boot project more closely,” explains Binarly.

“This research revealed six distinct vulnerabilities, ranging in impact from denial of service (DoS) to arbitrary code execution during the verification of an untrusted image.”

According to the researchers, two of the flaws can potentially lead to arbitrary code execution during firmware verification, while the remaining four can be exploited to crash vulnerable devices. 

As these flaw impact the code for validating firmware images before the operating system starts, if an attacker can exploit that process, they may be able to execute malicious code before the operating system loads.

Advertisement

The six disclosed vulnerabilities are:

  • BRLY-2026-037: A flaw that can cause U-Boot to crash when processing a malicious firmware image and, under certain conditions, can be used for arbitrary code execution.
  • BRLY-2026-038: A memory corruption vulnerability that could allow attackers to execute arbitrary code during firmware signature verification.
  • BRLY-2026-039: An out-of-bounds read vulnerability that can crash devices by forcing U-Boot to read beyond the firmware image.
  • BRLY-2026-040: A null pointer dereference that allows specially crafted firmware images to crash the bootloader.
  • BRLY-2026-041: Improper validation of externally stored firmware data that can cause U-Boot to crash when processing malicious firmware images.
  • BRLY-2026-042: An unbounded recursion flaw that can exhaust available stack memory and crash the bootloader.

According to Binarly, most of the vulnerable code has existed since U-Boot version 2013.07, causing the flaws to potentially affect more than 50 releases of the project as well as vendors who utilized the vulnerable code in their own firmware.

“This means that they potentially affect over 50 stable releases of the U-Boot project. Counting many downstream vendor forks, these vulnerabilities have a significant impact on the industry,” explains Binarly.

If successfully exploited, the arbitrary code execution vulnerabilities could allow attackers to execute code during the earliest stages of the boot process.

Because this occurs before the operating system loads, attackers could potentially disable firmware security features, modify the boot process, install persistent firmware malware, or carry out other malicious actions with high levels of access.

Advertisement

Binarly says that malicious would be difficult to detect because they execute before the operating system starts.

Binarly says exploiting these vulnerabilities does not always require physical access. On systems such as BMCs that support remote firmware updates, an attacker who has already compromised the management interface could upload a specially crafted firmware image to exploit the flaws.

Binarly reported the vulnerabilities to the U-Boot maintainers and submitted patches for all six issues, which have since been accepted into the project’s upstream codebase.

However, because U-Boot is integrated into firmware by individual hardware manufacturers, the fixes must first be incorporated into vendors’ firmware updates before they can be distributed to customers.

Advertisement

Older or unsupported devices that no longer receive firmware updates may never be patched.


article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Boroux vs. Rorra vs. Culligan: Water Filters, Tested Head to Head

Published

on

Perhaps more importantly, Rorra, Boroux, and Culligan have shed nearly all plastic from their devices, especially in areas that come in contact with filtered water. Boroux in particular has taken the extra step of attaining certification for microplastic filtration. If microplastics are a big concern for you, the new generation of gravity-fed filters does quite a bit to alleviate these worries.

Best Countertop Water Filter Overall: Boroux Legacy

  • Photograph: Matthew Korfhage

  • Photograph: Matthew Korfhage

Boroux

Legacy Water Filter System

Advertisement

WIRED

  • NSF-certified microplastic and particulate filtration
  • Independent testing shows yearlong filtration of PFAs, heavy metals, chlorine
  • Gosh, it’s handsome

TIRED

  • Big, bulky
  • Setup and filter priming is tedious

Of the three new-school gravity-fed systems I tested, the Boroux is my Goldilocks choice among usability, aesthetics, filter life, and extensive third-party testing. It’s also obtained international certifications to NSF criteria (in this case, through the WQA) for particulate and microplastic removal, in addition to lead-free manufacturing.

Independent third-party testing showed efficacy against chlorine, PFAS, and lead. And my own testing showed its efficacy in chloramine-treated water systems, reducing total chlorine by more than 95 percent. The water tasted good. And the Boroux is also the prettiest water filter system I know, which matters quite a bit if it’s going to live in your kitchen for years.

Boroux also sells supplemental fluoride filters, for those worried about fluoridated water. I wasn’t able to test the efficacy of this, because I live in Portland, Oregon, the largest metropolitan area in America without fluoride in its water. But independent, third-party testing backs up these claims.

One reason for Boroux’s performance is simple: Boroux’s filters are a trusted technology, functionally identical to the original Berkey black filters made with a mix of activated carbon and antimicrobial silver. In fact, they’re made by the Berkey filters’ original manufacturer, Clearbrook, which also separately sells its own filters.

Advertisement

Berkey is not currently selling those filters. The company is instead embroiled in a long fight with the Environmental Protection Agency, which issued a stop-sale notice in 2023 on Berkey’s classic black activated-carbon filters, saying the company’s antimicrobial claims meant the Berkey water systems were being sold as unregulated pesticides. Berkey’s maker, New Millennium Concepts, has since been fighting this order in court, but has also endorsed a filter called the Phoenix that I’m in the process of testing.

Source link

Continue Reading

Tech

Airport sign fails to boot, officers already on the scene

Published

on

OFFBEAT

Bork! Bork! That’s the sound of the police

BORK!BORK!BORK! The sight of the police can make even the clearest conscience twitch. Perhaps the authorities have finally come to ask about that music track you copied 30 years ago. We’re not saying the presence of the law sent this digital signage into a tizz, but you never know.

Spotted by an eagle-eyed Register reader at a Phoenix airport car rental building, today’s borked signage looks like the result of a PC in the background choking when trying to find a boot device.

Advertisement
Police vehicle parked under a covered airport walkway beneath a digital sign with an EFI Shell error.

The EFI Shell looks much like a terminal prompt and usually appears because the system has failed to boot normally. An experienced user can use it to load drivers or boot loaders manually, but for the vast majority, it doesn’t rear its head unless something is amiss.

The system appears to have dropped into the EFI Shell instead of starting the signage software. Perhaps the expected drive or filesystem mapping has disappeared, or a startup script is looking for something that is no longer there. An experienced techie might be able to fix it, but the audience here is more likely to consist of harried passengers wondering whether EFI Shell is a new budget airline.

And then there is the presence of the police. We know that some users find the approach to quality adopted by certain software vendors bordering on the criminal, but calling the cops on some borked signage seems a bit excessive. There doesn’t appear to be anyone inside the vehicle, so perhaps the officers have gone in search of the IT operative responsible for the shoddy work that has left the digital sign in such a distressed state.

Hopefully it won’t give users ideas about how to escalate the ticket that IT appears to be studiously ignoring. Tech support, after all, is not the fourth emergency service, despite what that user with a dodgy mouse might think. ®

Advertisement

Source link

Continue Reading

Tech

What’s his angle? Teen frustrated by plastic protractor reimagines the classic classroom tool

Published

on

Wenxin Fang of Redmond, Wash., holds the ZeroPivot Protractor that he designed and is selling through a new Kickstarter campaign. (Photo courtesy of Wenxin Fang)

Wenxin Fang was 14 years old when he realized he was fed up with fighting with a flimsy piece of plastic in math class.

As an eighth grader at Evergreen Middle School in Redmond, Wash., Fang kept bumping into the limits of standard classroom protractors — the cheap, clear tools generations of students have used to measure and plot angles. Frustrated by how often he had to realign the plastic arc just to mark a single line, he started sketching an alternative in his notebook.

Two and a half years and seven design iterations later, the incoming Tesla STEM High School junior is launching the ZeroPivot Protractor, a sleek, precision-machined aluminum hardware project aiming to drag an overlooked classroom staple into the modern era.

“I shouldn’t be fighting with a piece of plastic to draw an angle,” said Fang, now 17, during a call from China this week where he was meeting with suppliers ahead of production of his tool.

Fang launched a Kickstarter campaign on July 26 to fund the initial production run of the ZeroPivot. The campaign hit its initial target within 48 hours and has raised more than $2,200 from dozens of early backers.

Advertisement

Priced at $19, the ZeroPivot is positioned as a durable, high-precision upgrade over standard $3 plastic models. The funding will cover tooling costs and help manufacture the custom-machined aluminum components through HKAA Industrial, a supplier Fang vetted and partnered with during a visit to Shenzhen.

To make the tool work, Fang abandoned the traditional semi-circular design in favor of a guide-rail system made from anodized aluminum — a material choice he insisted on despite the higher production costs.

Unlike a standard protractor, which requires users to mark an angle’s vertex and rays in separate steps, the ZeroPivot features an adjustable sliding mechanism that allows users to plot and draw precise angles in a single fluid sweep.

“I went down this path of product design, trying to come up with something that’s small, that’s almost simplistic … that is able to improve the lives of people in tiny ways through good design,” Fang said.

Advertisement

Fang didn’t just keep his ideas trapped in his notebook. After coming up with the initial sketches, he brought them to his middle school engineering teacher, who encouraged him to build an actual prototype rather than treat it as a fleeting thought.

The ZeroPivot Protractor. (Photo courtesy of Wenxin Fang)

When he transitioned to high school, that mentorship expanded into a full support structure. A trio of teachers helped him turn his hobby into a legitimate consumer hardware launch:

  • Steven Bonomo, an engineering and product design teacher with a background working on Microsoft’s Surface Laptop line, guided Fang through user testing, ergonomics, and physical product design.
  • Andrew Christensen, who has a background in law, walked him through the corporate, operational, and legal logistics of starting his company, Bonae Artis LLC.
  • Karen Schaeffer, a graphic design teacher, helped him refine the brand identity and the final visual aesthetics of the product and its packaging.

That guidance proved essential as Fang spent the past year user-testing prototypes in class on himself and his classmates, refining the tool’s feel and mechanics in real classroom conditions.

Balancing the demands of a hardware startup with high school homework requires an intense level of discipline — and plenty of late nights.

“It’s a ton of work, that’s just the reality of it,” Fang said. “If you’re pushing a project by yourself, there’s not an external deadline there. What you have to do is set deadlines for yourself and say, ‘Hey, this iteration needs to get out by Sunday.’ I do late nights pretty often just to get something in on time.”

Diary of a protractor reinvention, from left: Wenxin Fang’s notebook sketches, touring a manufacturing facility in China, and various prototypes throughout the process. (Photos courtesy of Wenxin Fang)

For Fang, the ZeroPivot is just the starting point for a career he has been prepping for since childhood. His earliest memory of designing anything was at age 9 during Chinese Lunar New Year, when he used Lego bricks and superglue to create a custom ceiling hook to help his grandparents hang decorative lanterns.

Now aiming for a college degree and future career in product design and mechanical engineering, Fang sees the protractor project as proof of what simple, physical problem-solving can accomplish.

Advertisement

“That was kind of when I first realized, hey, I could make something so simple, and I could have somebody else use it, and it could be really nice for them,” Fang said.

With the Kickstarter campaign already funded, Fang is focused on executing the manufacturing run smoothly in China and delivering the finished ZeroPivot protractors to backers by his estimated February fulfillment target.

While he isn’t yet ready to reinvent the ruler or big pink eraser, Fang does envision creating more consumer hardware tools down the road. But his immediate motivation remains remarkably simple.

“I’m definitely focused on getting this through to fulfillment and getting this in people’s hands,” Fang said. “I think that is the most satisfying part of doing products — getting to see people using them.”

Advertisement

Source link

Continue Reading

Tech

Meta, TikTok, Snap And Google Face Wrongful Death Lawsuit From Four US Families

Published

on

The Social Media Victims Law Center accused the companies of creating addictive and dangerous platforms.

Another lawsuit is aiming to hold social media platforms accountable for their claimed impact on younger users. The Social Media Victims Law Center (SMVLC) filed a personal injury and wrongful death lawsuit against Meta, TikTok, Snap and Google. The legal action accused these companies and their platforms of creating addictive and dangerous products that contributed to the death of four kids.

The lawsuit accused the social media platforms of having “ignored repeated warnings from their own researchers, concealed evidence of harm, and built systems that profiled minors during moments of psychological vulnerability.” The SMVLC also alleged that these companies tracked user behaviors to push certain content, including “diet and beauty advertisements, appearance-changing filters, social comparison features” and more, which led to “depression, self-harm and suicidal ideation” in the name of increasing user engagement. The deaths related to the lawsuit happened between July 2024 and September 2025 in Texas, North Carolina, Minnesota and Tennessee, but SMVLC filed the lawsuit in Delaware after internal documents from these social media companies were unsealed in recent state and federal court proceedings. 

We reached out to the companies named in the lawsuit and will update the story when we hear back. In a statement to Engadget, a Google spokesperson said, “Providing young people with a safer, healthier experience has always been core to our work. In collaboration with mental health and parenting experts, we’ve built services and policies to provide young people with age-appropriate experiences, and parents with robust controls. We send our deepest sympathies to the families and are reviewing the claims in this lawsuit.”

Advertisement

Besides this latest legal action, the same platforms are facing other similar lawsuits. Earlier this summer, four US states sued Meta, claiming that both Facebook and Instagram had addictive designs and misled the public about how safe these apps were. A month prior, Meta, Snap and TikTok each individually settled a social media addiction lawsuit that was filed by a Kentucky school district.

Source link

Advertisement
Continue Reading

Tech

Stewart Platform Walker Gains Feeling In Legs From Resistors

Published

on

Stewy is a very interesting robot, with some slightly odd kinematics. Its head is a Stewart platform, which is a common-enough 6-DOF actuated plate normally used with a fixed base. By connecting legs to the same servos running the Stewart platform, [JD] turned it into an adorable hexapod walker. The walker had a problem, though: it can’t feel its feet, and [JD] thinks that would make it much more mobile on uneven surfaces. So he got some resistors to turn the cheap servos in its legs into force-sensing actuators.

Well, almost. He’s not actually putting strain gauges or anything like that into the legs; he’s just measuring the voltage drop across a resistor in series with the servos. Since the motors draw more current the more torque they’re putting out, he has a very quick and easy way to sense the current and thus the torque using good old Ohm’s law and an analog input on the microcontroller driving the robot. It’s a simple hack, but the data he’s getting is surprisingly good for how much work it is to add to a robot, as you can see in the video — at least once he slowed down the servos a touch.

Perhaps this isn’t a ground-breaking innovation, but [JD] does a very good idea explaining it. Of course if you want to use resistors to sense force directly, force-sensitive resistors are a thing that we’ve seen in everything from Twister-mat MIDI controllers to self-leveling 3D printers.

Advertisement

Source link

Advertisement
Continue Reading

Tech

UK wants datacenters to pay a fee for grid connection requests

Published

on

SYSTEMS

Refundable charge intended to discourage time wasters from filing applications that will never be realized

Ofgem is seeking feedback on proposals to levy a fee on datacenter development projects at the time they apply for a grid connection.

The move aims to discourage companies from seeking approval for speculative applications that clog up the pipeline and cause connection delays, without ever resulting in finished datacenters.

Advertisement

The UK regulator for electricity and gas says connection applications for electrical supply have surged from 41 gigawatts (GW) to 125 GW in under a year, with datacenters accounting for at least 80 GW of the new demand.

Even before that happened, one of the UK’s big developers complained that its build teams faced a wait of “a number of years” for work such as local substation upgrades to increase grid capacity.

Ofgem is proposing a Datacenter Commitment Fee paid by the developers of large server farm projects when accepting a grid connection offer. The fee would be refunded once the facility is drawing power, or forfeited if the project exits the queue early instead.

Alan Howard, Omdia principal analyst for Colocation and DC Building, told us previously that the power connection queue issue is a big problem, not just for the UK, but also in the US and other markets around the globe.

Advertisement

“The strategy for many datacenter operators is to secure multiple land parcel rights, request a grid load connection for each (often requiring a costly load study), and see what gets approved so they can build. The capital investment to take all these projects seriously is clearly untenable and a huge financial risk for the energy sector if the demand doesn’t fully materialize,” he said.

The issue is therefore that developers apply in multiple locations to secure power for a single campus, fill up the national application pipeline with speculative requests and hold up the works for viable projects.

“Britain’s electricity demand connections queue has more than tripled in size in less than a year, and consumers should not bear the risks created by speculative projects taking up space in the system,” said Eleanor Warburton, the regulator’s director for Energy System Design and Development.

Ofgem’s suggestion is that the fee should be set within a proposed range of £237,500 ($319k) to £712,500 ($957k) per megawatt, which it believes is equivalent to about 2.5 percent to 7.5 percent of average project costs.

Advertisement

It is suggests developers demonstrate progress with their project if they wish to retain their place in the queue, meeting criteria such as financial capability, commercial maturity and procurement activity milestones.

Global colocation biz Telehouse, which operates five datacenters in the London area, told The Register it supports measures to ensure grid capacity is prioritized for credible project, though it has some reservations.

“Ofgem’s proposal is an important initiative, but it must be implemented in a way that maintains the UK’s attractiveness as a destination for AI and digital infrastructure investment,” said Telehouse Europe, managing director, Mark Pestridge.

“A refundable fee-based approach should not deter serious investors, but create a more transparent connections process that gives viable projects greater certainty.”

Advertisement

However, reforming the queue will not resolve the underlying capacity challenge, Telehouse points out – the need to expand the grid and make more energy available.

“A long-term solution will require sustained investment in the grid, alongside much closer collaboration between datacenter operators, local councils, National Grid and network operators at the earliest stages of planning,” Pestridge said.

“Better coordination and forecasting will help ensure infrastructure is developed in the right places, at the right time, and that viable projects do not continue to face delays even after speculative demand has been removed.”

The finger of blame for all this bother can be pointed at the government, which unveiled its AI Opportunities Action Plan at the start of last year. This included plans for “AI Growth Zones” with streamlined planning processes to speed along the building of more datacenters, apparently without bothering to check if the electricity infrastructure was ready.

Advertisement

To try to tackle the bottleneck, the government set up an AI Energy Council, bringing together energy industry representatives and major technology firms to thrash out a strategy, co-chaired by the former Technology Secretary and Energy Secretary. The Register reported on the challenges faced last year.

Ofgem’s consultation is open to anyone with an interest, and closes on September 16, 2026.  The agency has response templates available on its website here. ®

Source link

Advertisement
Continue Reading

Tech

Best of eCoustics July 2026: Audio, TV and Music Stories Worth Reading

Published

on

July is supposed to be one of the quieter months of the year.

Apparently nobody told the audio industry, TV manufacturers, streaming services, record labels or the lawyers attempting to untangle the latest media merger without setting the furniture on fire.

eCoustics published more than 120 reviews, product stories, features, news reports and buying guides during July 2026. Nobody has time to read them all, so we have done the heavy lifting and selected the stories that mat

From affordable streamers and British loudspeakers to RGB MiniLED televisions, CanJam London, all-analog vinyl and the increasingly awkward arrival of AI-generated music, these were the eCoustics stories worth revisiting.

Advertisement

Hi-Fi Gear That Earned a Second Look


Wharfedale Super Denton Review: The British Bulldog of Standmount Speakers

Wharfedale Super Denton Loudspeakers in walnut

The Wharfedale Super Denton is not the smallest, most technically radical or least expensive standmount loudspeaker in its class. It is, however, one of the most enjoyable.

Its three-way design delivers a warm midrange, surprisingly deep bass and the kind of tonal balance that encourages long listening sessions rather than an emergency search for the treble control. It also happens to be one of our favorite loudspeakers currently available below $1,500.

The Super Denton needs proper stands and enough room to breathe, but listeners who value natural timbre, scale and musical engagement should put it near the top of their audition list.

Continue reading full story →

Bluesound NODE Review: Is This $750 Streamer Finally Ready for WiiM and Cambridge?

Bluesound NODE N132

The Bluesound NODE has spent years occupying the middle ground between affordable WiiM streamers and more expensive network players from Cambridge Audio, Eversolo and others.

The latest version offers improved sound quality, a stable BluOS platform, broad streaming support and the potential addition of Dirac Live room correction. It is not the cheapest option, but it makes a stronger case for itself as the digital hub of a serious two-channel system.

Advertisement

Whether that is enough to hold off increasingly capable and considerably less expensive competitors is another matter. The streaming category has become rather impolite.

Advertisement. Scroll to continue reading.

Continue reading full story →

Klipsch The Sevens II Review: Wireless Speakers for Music, Movies and TV

Klipsch The Sevens II Wireless Speakers in black lifestyle next to TV

Klipsch’s second-generation Sevens combine powered stereo loudspeakers, HDMI eARC, music streaming, substantial bass output and Dirac Live room correction in one system.

They can replace a soundbar, amplifier, streamer and pair of passive loudspeakers without making music sound like an afterthought. Their size and energetic presentation will not suit every room, but few wireless speaker systems offer the same combination of scale, flexibility and outright entertainment.

Advertisement

Continue reading full story →

Q Acoustics Q SUB100 Review: Affordable Bass Without the Usual Drama

Q Acoustics Q SUB100 powered subwoofer white lifestyle

Subwoofers are often sold through increasingly absurd claims about output, infrasonic extension and their ability to rearrange the foundations of your home.

The Q Acoustics Q SUB100 takes a more useful approach. It delivers controlled bass for music and home theater, works with a wide range of loudspeakers and does not require a room the size of an aircraft hangar.

For listeners building a two-channel or compact home-theater system, that may prove considerably more valuable than another specification designed primarily to frighten the neighbors.

Continue reading full story →

Advertisement

Home Theater Had an RGB Summer


Hisense UR9 RGB MiniLED TV Review: Cutting-Edge Tech Minus the Inflated Price

2026 Hisense UR9 65-inch RGB MiniLED 4K TV

RGB MiniLED televisions are shaping up to be one of the most important TV developments of 2026, promising greater color volume and improved brightness without relying on OLED panels.

The Hisense UR9 brings that technology to a lower price tier than several flagship competitors. Its aggressive value proposition does not make it perfect, but it demonstrates that advanced RGB backlighting will not remain confined to televisions priced like lightly used German automobiles.

Continue reading full story →

Samsung R95H vs. Sony BRAVIA 7 II: Which RGB TV Should You Buy?

2026 Sony Bravia 7 II vs. Samsung R95H 4K TVs

Specifications only tell part of the story, especially when manufacturers create competing names for variations of similar technology.

Advertisement. Scroll to continue reading.

After reviewing both televisions, we compared Samsung’s flagship R95H Micro RGB with Sony’s BRAVIA 7 II True RGB to determine where each model excels, what buyers give up and whether Samsung’s higher price is justified.

Advertisement

This is the kind of comparison consumers need before standing inside a brightly lit warehouse store while a salesperson explains that every television on the wall is “basically the best one.”

Continue reading full story →

Samsung HW-Q990H Soundbar System Review: Praising the Bar

2026 Samsung HW-S990H Soundbar Lifestyle

Samsung’s latest flagship soundbar system attempts to deliver immersive Dolby Atmos sound without filling the room with an AVR, speaker cables and enough loudspeakers to alarm the family.

The HW-Q990H cannot completely replace a carefully assembled component system, but its combination of surround immersion, bass response, ease of use and competitive pricing makes it one of the most complete soundbar packages available.

Continue reading full story →

Advertisement

The Best 4K Blu-ray Discs of 2026 So Far

Best 4K UHD Blu-ray Movies of 2026 So Far

Streaming may have won the convenience war, but physical media continues to offer the most consistent route to superior picture and sound quality.

Our midyear selection includes Fight ClubBen-HurPerfect BlueStranger ThingsThe Patriot, Jackie Chan and Steven Spielberg collections, and several other discs worthy of shelf space.

Ownership remains a remarkably attractive feature when streaming services keep removing films, changing formats and behaving as though customers should be grateful for the privilege.

Continue reading full story →

Personal Audio Went to London


The Best Headphones from CanJam London 2026

Best in Show Headphones at CanJam London 2026

CanJam London returned with more new headphones, wireless models, electrostatic designs and boutique manufacturers than one person could reasonably evaluate over a single weekend.

James Fiorucci listened to nearly 30 models and selected the designs that stood out across a broad range of prices. The results include established manufacturers, unexpected newcomers and several products we intend to review more thoroughly.

Advertisement
Advertisement. Scroll to continue reading.

No, they were not all inexpensive. This is CanJam, not a church rummage sale.

Continue reading full story →

The Best DACs, Headphone Amps and DAPs from CanJam London 2026

Best in Show DAPs, DACs, and Headphone Amplifiers at CanJam London 2026

The electronics surrounding headphones have become almost as varied as the headphones themselves.

CanJam London showcased compact Class A amplifiers, R2R digital audio players, portable DACs, desktop systems and several products designed to serve both sensitive IEMs and considerably more demanding full-size headphones.

Advertisement

The best products did more than add power or specifications. They offered useful features, thoughtful ergonomics and a clear reason to exist in a category already crowded enough to require traffic control.

Continue reading full story →

XENNS Mangird Tea Pro SE Review: A New Reference for Meta Tuned IEMs

2026 XENNS Margird Tea Pro SE IEMs

The Tea Pro SE is not merely a cosmetic variation of the original Tea Pro.

Its warmer, reference-inspired balance, articulate treble and sturdy metal shells make it a strong alternative to the increasingly standardized tuning found across the modern IEM market. Listeners seeking heavy bass or a strict upgrade over the original should look elsewhere, but those who value texture and long-term comfort will find plenty to like.

Continue reading full story →

Advertisement

Questyle QCC Dongle Pro 2 Brings Better Bluetooth to Almost Everything

2026 Questyle QCC Dongle Pro2 connected to smartphone

Bluetooth audio has improved significantly, but codec compatibility, latency and inconsistent device support continue to complicate what should be a simple process.

Questyle’s compact transmitter adds Bluetooth 6.1, broad codec support, low-latency operation and Auracast compatibility to phones, computers and gaming consoles. It is designed for listeners who want the best wireless performance available without first consulting three compatibility charts and an electrical engineer.

Continue reading full story →

Advertisement. Scroll to continue reading.

Music, Vinyl and AI’s Uninvited Arrival


Joni Mitchell’s Court and Spark Rhino High Fidelity Vinyl Review

Joni Mitchell Court and Spark Rhino High Fidelity Edition LP 2026

Joni Mitchell’s Court and Spark has been an audiophile demonstration record for more than five decades, but affordable premium single-disc editions have been surprisingly limited.

Rhino’s new High Fidelity pressing uses all-analog mastering, lacquers cut by Kevin Gray and 180-gram vinyl pressed at Optimal Media. More importantly, it sounds warmer, wider and more natural than typical original copies and easily surpasses the thin, bright Nautilus SuperDisc pressing.

Advertisement

The glossy replacement artwork cannot match the textured original jacket, but the record itself is the reason to buy this edition. The old cover can stay. The Nautilus pressing can start packing.

Continue reading full story →

Dusty Springfield’s Dusty in Memphis Gets the Rhino High Fidelity Treatment

2026 Dusty in Memphis Rhino High Fidelity Vinyl LP Reissue

Rhino applied a similar formula to Dusty in Memphis, pairing Kevin Gray’s mastering with an Optimal pressing and a price that remains far below many premium audiophile releases.

The result brings greater openness, dynamics and presence to one of the defining soul albums of the late 1960s without turning it into another oversized box containing certificates, gloves and enough packaging to survive re-entry.

Continue reading full story →

Advertisement

Why Should AI-Created Music Be Allowed on the Charts at All?

Deezer Ai Generated Music Detection

Major record labels have proposed rules determining when music involving generative AI should qualify for official chart recognition.

Those rules include licensing, disclosure, legitimate streaming activity and a requirement that the final work remain substantially human-made. All of that sounds reasonable until one remembers that several of the same companies are already negotiating licensing agreements with AI platforms.

More human than human, apparently—provided the royalty statement clears.

Continue reading full story →

Can Winamp and Deezer Put Streaming and Your Music Library in One Place?

2026 Deezer and Winamp Partnership

Winamp and Deezer want to combine subscription streaming with the music files listeners already own.

Advertisement. Scroll to continue reading.
Advertisement

That sounds almost revolutionary in an era when most streaming platforms behave as though local music libraries were discovered in an archaeological dig. The idea has genuine potential, but execution, availability and platform support will determine whether it becomes a useful listening tool or another promising service that disappears after everyone has created an account.

Continue reading full story →

Also Worth Reading

July also delivered our coverage of the 2026 TV Shootout25 Essential American Films That Explain America at 250, the best summer horror films, the Revox World Foundation’s preservation of 800 Studer and Revox components, AudioBro V2, the Q Acoustics 3040c and KEF’s sculptural LS LUXE wireless loudspeakers.

There was also the small matter of Paramount and Warner Bros. Discovery, whose proposed merger remains trapped in an antitrust fight that will now drag well into 2027. Hollywood has once again demonstrated that no amount of expensive content can compete with lawyers billing by the hour.

Advertisement

What Comes Next

August begins with Audio Advice Live in Raleigh, where eCoustics will be covering new home-theater systems, loudspeakers, electronics and one particularly ambitious 9.7.4-channel demonstration from ASCENDO, Trinnov and Christie.

CanJam SoCal and CEDIA are also approaching, while our review queue includes more loudspeakers, headphones, digital sources, music releases and home-theater products.

July was not quiet. August does not appear interested in behaving any better.

Source link

Advertisement
Continue Reading

Tech

How is your enterprise tracking AI agent telemetry? Groundcover thinks it should never leave your cloud

Published

on

The AI agent observability space is taking off — but how can enterprises be sure what observability products and solutions they need?

Observability startup groudcover (lower case “g” intentional) announced this week that it raised $100 million in a round led by One Peak, bringing its total funding to $160 million.

The company says it has more than 250 paying customers, tripled annual recurring revenue over the past year and is increasingly replacing established observability platforms inside enterprise environments. Those are company-reported figures, but together they point to growing momentum in one of enterprise software’s most competitive markets.

That market has long been dominated by companies including Datadog, Dynatrace, New Relic, Splunk and Grafana. Between them, they represent billions of dollars in annual revenue and years of product maturity. Breaking into that group has never been easy.

Advertisement

groundcover’s argument is that artificial intelligence has fundamentally changed the assumptions those platforms were built on.

Rather than competing feature for feature, the four-year-old company is trying to convince enterprises that the architecture underpinning observability itself needs to change as AI systems become more autonomous, produce vastly more telemetry and increasingly participate in software operations. Whether that thesis proves correct remains an open question, but it offers a compelling lens through which to examine how observability is evolving alongside enterprise AI.

AI is turning telemetry into an infrastructure problem

Observability has traditionally been viewed as a post-production discipline. Engineers deploy applications, monitor logs, metrics and traces, investigate incidents, and improve reliability over time.

That workflow is changing.

Advertisement

AI-assisted software development has dramatically accelerated deployment cycles. Coding assistants generate more code, infrastructure evolves more rapidly, and organizations are deploying increasingly complex distributed systems that combine microservices, Kubernetes clusters, APIs and large language models. At the same time, enterprises are beginning to operate AI agents that execute multi-step workflows, call external tools and interact with production systems.

Each of those activities generates telemetry.

The result is an explosion of operational data that organizations increasingly want to retain rather than discard. AI applications introduce additional layers of observability beyond traditional infrastructure monitoring, including prompt execution, model latency, token consumption, retrieval pipelines, tool invocations and agent behavior. As enterprises experiment with autonomous systems, that telemetry becomes increasingly valuable because it provides the context needed to understand what an AI system actually did and why.

For many organizations, this creates tension with pricing models that charge according to the amount of data ingested.

Advertisement

Historically, engineers have often responded by sampling traces, shortening retention periods or limiting which data is collected. Those approaches reduce costs, but they also reduce visibility precisely when AI-driven systems demand more complete operational context.

“We’ve seen telemetry exploding,” groundcover co-founder and CEO Shahar Azulay said during a recent media briefing. “Users are frustrated by not getting all the value from Datadog and similar platforms. They’re limiting the data, siloing it, sampling it.”

Whether that frustration is widespread enough to reshape the market remains to be seen, but the underlying trend is difficult to ignore. AI is making observability less about collecting enough data and more about collecting everything organizations may eventually need.

Rather than adding AI, groundcover argues the architecture itself has to change

Many observability vendors have introduced AI assistants, AI-powered root cause analysis and AI observability features over the past two years. Datadog, Dynatrace, New Relic and Grafana have all announced products aimed at helping enterprises monitor AI applications or automate operational tasks.

Advertisement

groundcover acknowledges those developments but argues they do not address what it sees as the more fundamental issue: where telemetry lives and how customers pay for it.

Instead of operating a conventional SaaS platform that stores customer telemetry in vendor-managed infrastructure, groundcover uses what it calls a bring-your-own-cloud (BYOC) architecture.

Customers keep the data plane—including telemetry storage and processing—inside their own AWS, Microsoft Azure or Google Cloud environments, while groundcover provides a managed control plane and user experience. A fully self-hosted deployment option is also available.

While some competitors, including Datadog and a few other observability vendors, do offer limited hybrid or customer-controlled data residency options, these are generally not equivalent to a full BYOC model. In most cases, telemetry is still processed and stored within the vendor’s managed infrastructure, with only partial controls (such as regional data residency, private links, or selective log forwarding) available.

Advertisement

That architectural decision influences nearly every aspect of the company’s strategy.

Because customers already pay for their own cloud infrastructure, groundcover argues it can avoid charging based on telemetry ingestion. Instead, pricing is based primarily on monitored hosts, regardless of telemetry volume.

The company believes this changes customer behavior.

Rather than deciding which logs or traces are too expensive to keep, organizations can theoretically retain complete telemetry and use it for operational analysis, compliance and AI-assisted troubleshooting.

Advertisement

“We don’t price by data volume,” Azulay said. “We price by the size of the infrastructure.”

The distinction matters because AI workloads tend to increase telemetry far faster than infrastructure itself.

That does not necessarily make host-based pricing universally cheaper. Organizations with relatively light workloads spread across many hosts may find different economics than dense Kubernetes environments generating enormous amounts of telemetry. The company’s own briefing notes that per-host pricing is most advantageous for organizations with high telemetry density and may be less compelling for lightly utilized fleets.

Still, the broader argument is less about cost alone than predictability. Enterprise infrastructure teams often struggle with observability bills that fluctuate alongside application growth. groundcover’s model attempts to align pricing more closely with infrastructure planning rather than data generation.

Advertisement

eBPF sits at the center of the company’s technical differentiation

The second pillar of groundcover’s strategy is eBPF, a Linux kernel technology that has rapidly become one of the most important building blocks for modern cloud observability.

Instead of requiring developers to manually instrument applications, eBPF allows software running inside the operating system kernel to observe network traffic, system calls and application behavior with minimal code changes.

That enables faster deployment and broader visibility across infrastructure.

For organizations operating Kubernetes clusters and cloud-native applications, reducing instrumentation complexity can significantly shorten deployment times while increasing telemetry coverage.

Advertisement

Azulay argues this becomes especially important as AI systems generate increasingly complex interactions across services.

“Our sensor allows us to observe systems very deeply from infrastructure to application to AI workloads without developers needing to instrument code,” he said during the briefing.

eBPF itself is hardly unique. Many observability vendors now incorporate it into their platforms.

What groundcover argues differentiates its approach is combining automatic eBPF collection with customer-controlled storage, OpenTelemetry compatibility and unified pricing inside a single platform.

Advertisement

The company’s own research briefing acknowledges that none of these technologies individually represents a competitive moat. The claimed differentiation lies in the combination of eBPF-first collection, managed BYOC architecture, host-based economics and full-stack observability delivered together.

AI agents are becoming both customers—and users—of observability

Perhaps the most interesting aspect of groundcover’s strategy extends beyond traditional monitoring.

The company increasingly describes observability as infrastructure for autonomous software development.

Historically, observability platforms have served human operators investigating production incidents.

Advertisement

groundcover believes future observability platforms will increasingly serve AI agents as well.

Its Agent Mode product allows engineers to investigate incidents using natural language across logs, metrics, traces and Kubernetes events. More importantly, Azulay envisions observability becoming the feedback mechanism that informs coding agents about what actually happened in production.

Rather than simply detecting failures after deployment, observability becomes continuous operational context that autonomous systems can use to evaluate changes, identify regressions and eventually recommend or implement fixes.

“We’re seeing observability moving from being a post-production tool… to people taking context from production and feeding it back to their coding agents so they can write code better,” Azulay said.

Advertisement

Today, the company emphasizes that humans remain in the loop.

Agent Mode investigates incidents and surfaces recommendations, but production changes still require human approval. Azulay expects autonomy to increase gradually as organizations become more comfortable allowing AI systems to participate in operational workflows.

That vision reflects a broader trend emerging across enterprise software, where AI agents increasingly span development, testing, deployment and operations rather than functioning as isolated assistants.

Why some enterprises are considering alternatives

groundcover is entering an intensely competitive market populated by vendors with decades of enterprise experience.

Advertisement

Datadog alone generated more than $3 billion in annual revenue in 2025. Dynatrace, Cisco’s Splunk business, Grafana Labs and New Relic all maintain extensive partner ecosystems, mature integrations and enterprise support organizations that newer entrants cannot easily replicate.

groundcover is not attempting to outscale those incumbents overnight.

Instead, it argues that AI creates an architectural inflection point similar to previous transitions from on-premises infrastructure to cloud-native computing.

According to Azulay, many customers initially adopt groundcover to reduce observability costs but increasingly remain because they want unrestricted access to richer telemetry and AI-native workflows.

Advertisement

He says deployments typically replace incumbent platforms rather than operate alongside them, although the company has not publicly disclosed customer migration data or independent studies validating that claim.

The company’s journalist briefing also urges caution around some performance claims.

Revenue growth, customer counts and enterprise adoption figures originate from groundcover itself. Published customer case studies reporting significant cost savings are vendor-authored and should not be treated as independent validation without additional evidence. The briefing also recommends scrutinizing exactly what metadata leaves customer environments in standard BYOC deployments, rather than assuming that no operational data ever reaches vendor infrastructure.

Those caveats are important because the observability market has become crowded. Gartner currently tracks more than one hundred observability products, and nearly every major vendor now markets AI-powered operational capabilities.

Advertisement

Success will likely depend less on whether AI matters—which increasingly appears inevitable—and more on whether enterprises conclude that existing architectures remain sufficient.

The larger question investors are betting on

Viewed narrowly, groundcover’s Series C is another large infrastructure funding round.

Viewed more broadly, it reflects a growing debate about what observability becomes in an era where software increasingly writes, tests and operates itself.

If AI continues generating exponentially larger volumes of operational data, traditional assumptions about telemetry collection, pricing and storage may come under increasing pressure. Vendors that built businesses around charging for data ingestion may need to evolve their economics alongside customer expectations. New entrants, meanwhile, have an opportunity to design around those changing assumptions from the outset.

Advertisement

groundcover believes that opportunity lies in combining customer-controlled infrastructure, automatic telemetry collection and AI-assisted operations into a platform designed for autonomous software rather than simply adding AI features to existing observability products.

Whether that architectural bet proves durable will depend on enterprise adoption over the next several years.

But the company’s latest funding round suggests at least some investors believe the next battle in observability will not be fought over dashboards or alerts. It will be fought over who builds the operational data layer that increasingly intelligent software relies upon to understand—and eventually manage—the systems it runs.

Source link

Advertisement
Continue Reading

Tech

Hacker uses DeepSeek AI to autonomously attack vulnerable servers

Published

on

Malicious AI agent

A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement.

The activity was discovered by Palo Alto Networks’ Unit 42 researchers after Hermes accidentally created a web server from its home directory, exposing the attacker’s environment, including API keys, exploit scripts, target lists, shell history, and AI attack logs.

Unit 42 attributed the activity to a China-based threat actor operating under the aliases “knaithe” and “KnYuan,” who calls themself a “binary security researcher.”

image

While the autonomous attacks observed by Unit 42 did not successfully compromise the targeted servers, the researchers say the campaign illustrates an offensive AI workflow capable of discovering, evaluating, and attacking vulnerable systems.

“While the observed campaign had limited impacts, the workflow confirms a functional, end-to-end autonomous offensive capability,” Unit 42 said.

Advertisement

DeepSeek used for autonomous attacks

The threat actor used DeepSeek as the reasoning engine behind Hermes Agent, an open-source AI framework capable of interacting with operating system terminals, running commands, and connecting to the internet.

The agent supports a “Yolo” mode that allows it to operate and execute commands, even risky ones, without first requesting permission from its operator.

Hermes was configured to accept instructions from a Telegram channel, use custom offensive-security skills, and integrate with the FOFA internet asset search engine.

Unit 42 recovered a May 2026 session in which the operator appears to have provided only an initial task, after which the agent conducted the remaining activity autonomously without human feedback.

Advertisement

The agent first targeted internet-exposed Langflow servers vulnerable to CVE-2026-33017, downloading a public proof-of-concept exploit, identifying 84 exposed instances through FOFA, and scanning them for vulnerable configurations.

After determining that the available targets could not be exploited, the agent searched for other potential vulnerabilities to scan for vulnerable devices.

DeepSeek then analyzed multiple public exploit repositories before selecting the n8n workflow automation platform to target, which had more than 647,000 exposed instances identified through FOFA.

The agent downloaded an exploit that chained CVE-2026-21858 and CVE-2025-68613, identified servers running vulnerable versions, and checked them for unauthenticated file-upload forms required to complete the attack.

Advertisement

However, the discovered forms required authentication, and Unit 42 says the autonomous attempts failed to compromise any targets.

Unit 42 says the campaign is significant because the agent independently researched vulnerabilities, determined which targets were the best option, downloaded exploit code, and then attempted to exploit found targets in minutes what would normally take many hours.

“This autonomous process of target identification, sampling and narrowing of scope is notable because the system executed hundreds of hours of manual targeting analysis in mere minutes, while also managing its own compute resources,” explained Palo Alto.

While the AI agent was used extensively, the threat actor also conducted manual attacks against more than 460 systems using vulnerabilities affecting Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE VPN, and other products.

Advertisement

Unit 42 confirmed three successful compromises targeting the Citrix NetScaler vulnerability CVE-2026-3055, which the actor used to extract memory and search for authentication cookies that could be used to hijack sessions.

The actor had also configured other AI coding platforms, including Qwen, GLM, Kimi, MiniMax, Claude Code, and OpenAI’s Codex, but Unit 42 found that they were not used often.

Autonomous AI attack flow
Autonomous AI attack flow
Source: Palo Alto Unit 42

Hermes used in previous cyberattack

The exposed AI campaign comes after another recently disclosed incident in which poorly secured Hermes infrastructure exposed details about an alleged cyberattack against Thailand’s Ministry of Finance.

Last week, BleepingComputer reported that Hunt.io and security researcher Bob Diachenko discovered open web directories containing exploit tools, web shells, credentials, compiled payloads, and Hermes activity logs.

Those logs showed Hermes running in unattended “YOLO” mode to automate post-exploitation activity, including searching for privilege-escalation opportunities, enumerating services, inspecting containers, traversing filesystems, and cataloging documents stored on Ministry of Finance systems.

Advertisement

However, the earlier incident did not show Hermes independently choosing the target or determining how to compromise it.

A human operator supplied the target, objectives, and attack tools, while Hermes automated routine activity after access had apparently already been obtained.


article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Advertisement
Continue Reading

Tech

The EU clears the $55bn Saudi-led buyout of EA under its subsidy rules

Published

on

The European Commission approved the PIF-led take-private of Electronic Arts under its Foreign Subsidies Regulation, removing one of the last hurdles to the biggest leveraged buyout ever.


The European Union has cleared the $55bn takeover of Electronic Arts by a Saudi-led consortium, removing one of the last regulatory hurdles to the largest leveraged buyout in history.

The European Commission signed off under its foreign-subsidies rules on 31 July, days after approving the deal on competition grounds, running the kind of regulatory gauntlet that Microsoft’s Activision Blizzard deal faced a few years earlier.

The buyers are a powerful trio. Saudi Arabia’s Public Investment Fund, the private-equity firm Silver Lake, and Affinity Partners, the fund led by Jared Kushner, agreed to take EA private in September 2025.

Advertisement

The structure is historic in scale. At $55bn it is the biggest take-private deal ever struck, funded by a mix of consortium equity and a vast pile of debt, with PIF set to hold about 93% of the company once it closes.

The subsidy review was the sensitive part. The EU’s Foreign Subsidies Regulation exists to stop state money from outside the bloc from distorting competition when a foreign-backed buyer acquires a business in Europe.

PIF is exactly the kind of buyer it targets. As a sovereign wealth fund worth around $1 trillion, its backing raised the question of whether state cash was tilting the field, which is why the clearance mattered.

The Commission decided it did not. It concluded the deal would not raise competition concerns and cleared it under both merger and subsidy rules, letting the transaction proceed across the bloc.

Advertisement

For EA, this is a profound change of ownership. The company behind The Sims, Battlefield, Apex Legends, and its long-running football franchise would pass from public markets into the hands of a sovereign fund and its partners.

It is also a bet on how EA makes money. The publisher has been aggressively expanding monetisation, recently building a full advertising platform inside its games aimed at more than 100 million players.

The strategic logic sits in Riyadh. The purchase is a centrepiece of Saudi Arabia’s push to turn itself into a global gaming hub, part of a wider effort to diversify its economy away from oil.

PIF has been buying its way in for years. Through its Savvy Games arm it has taken stakes in studios and esports firms around the world, and EA would be its most valuable prize by far.

Advertisement

The politics are unavoidable. Kushner’s involvement, Saudi state money, and control of games played by hundreds of millions have drawn scrutiny from human-rights groups and lawmakers wary of the kingdom’s soft-power ambitions.

Europe is not the only gatekeeper. The deal still faces review elsewhere, most notably in the United States, where the Committee on Foreign Investment scrutinises foreign control of American companies.

That US review is the bigger unknown. Foreign ownership of a major American publisher, backed by a Gulf state and a president’s son-in-law, sits squarely in the territory CFIUS was built to examine.

Regulators everywhere are warier of big technology deals. Transatlantic friction over how Europe polices tech has grown, with US lawmakers pressing to open a trade probe into EU tech rules even as Brussels waves this one through.

Advertisement

The gaming industry has seen this before. Consolidation has swept the sector, from speculation over Microsoft’s next target to its Activision purchase, and EA’s sale is the latest sign that scale and deep pockets now set the terms.

Shareholders have already said yes. EA investors voted overwhelmingly in favour of the takeover, leaving regulators as the main obstacle, and Europe has now stepped aside.

What remains is the finish line. With the EU cleared, the consortium’s focus shifts to the outstanding approvals, and to the question of what a sovereign-owned EA will mean for the players who never got a vote.

Advertisement

Source link

Continue Reading

Trending

Copyright © 2025