The Zenbook S 16 (2026) has a brighter and sharper OLED than its predecessor that's one of the best large-screen choices I've tested.
New AMD Gorgon Point chip inside
Advertisement
This new model also utilises one of AMD's new Gorgon Point APU processors with a small bump in overall power.
Redesigned chassis
Asus has also redesigned the chassis a tad from the older model, while retaining its use of innovative materials.
Introduction
The Asus Zenbook S 16 (2026) feels more of an iterative upgrade against its hugely impressive predecessor.
I loved the Zenbook S 16 (2024) so much that I nearly considered purchasing one as my main work machine, although I couldn’t give up macOS that easily. Nonetheless, it seems like Asus has rolled its sleeves up a little with this refreshed model, with it packing in one of AMD’s revised Gorgon Point APUs (the Ryzen AI 9 465 in this instance), plus it’s got a slightly different look to it, and there’s a new 16-inch OLED panel to get excited about.
This new model is going straight up against the likes of the Samsung Galaxy Book6 Pro as a large-screened, premium ultraportable laptop for those who want or need the luxury of a bigger panel without sacrificing on style. It also carries a beefier price tag of £1699.99, meaning it’s a little behind Samsung’s choice there, too.
Advertisement
Advertisement
I’ve been putting the Zenbook S 16 (2026) through its paces to see if it can keep its crown as one of the best laptops we’ve tested.
Design and Keyboard
More generic and minimalistic look
Slender, with a capable port selection
Snappy keyboard and huge trackpad
The stylish ceraluminum chassis was one of the main reasons I fell for the older Zenbook S 16 model as much as it did, with its blend of ceramic and aluminium to create a very durable and surprisingly lightweight laptop for its size. That material is back for this new 2026 iteration, and it helps this laptop look and feel fantastic in hand, with a reassuring weight and slender chassis that oozes class.
One area of this 2026 model I’m not as keen on is the redesigned lid, though. Asus has opted for a more minimalistic approach to the Zenbook S 16 (2026)’s design, choosing to ditch the etched lines on the lid and replace them simply with ‘Asus Zenbook’ lettering in the middle.
Image Credit (Trusted Reviews)
Advertisement
It tips the scales at just 1.5kg, making its mass identical to the previous model. For a large 16-inch ultrabook, it’s especially portable, and very competitive with Samsung’s offering in this regard.
Asus also hasn’t changed the solid port selection the Zenbook S 16 (2026) comes with, which is a good thing. In spite of being just 11mm thin, it comes with a pair of Thunderbolt 4-capable USB-C ports, a USB-A, HDMI, full-size SD card reader and a headphone jack.
Opening the lid reveals a centred small form factor keyboard that’s similar in layout to the current crop of MacBook Pro models. It’s a snappy and tactile offering, with just the right amount of key travel, plus it has some sharp white backlighting for after-dark working.
Advertisement
Image Credit (Trusted Reviews)
The Zenbook S 16 (2026) is also bestowed with a huge trackpad, the same as the old model was, which feels slick and smooth under finger, and gives your hands a fair amount of real estate to play with.
Display and Sound
Sharp, detailed OLED screen
Even brighter with more contrast than its predecessor
Similar downwards-firing speaker arrangement
Advertisement
Asus has upgraded the Zenbook S 16 (2026)’s OLED panel to make it an even more dazzling prospect than the 2024 model. It remains a capable 16-inch 2880×1800 resolution panel with 120Hz refresh rate for sharp visuals with oodles of detail and rather smooth motion and responsiveness.
The virtually perfect colour accuracy that this screen comes with is no surprise. To be specific, we’re getting 100% coverage of both the mainstream sRGB and creative DCI-P3 gamuts, while Adobe RGB coverage at 93% is also excellent, making this screen an ideal pairing for both mainstream and more colour-sensitive workloads.
Image Credit (Trusted Reviews)
There are deep blacks and gorgeous contrast, too, with a measured 0.01 and 31610:1, respectively, to provide some serious dynamic range and keep this as one of the best screens you’ll find on a 16-inch laptop. The 6800K colour temperature is pretty good as well.
Asus’ main upgrade for the Zenbook S 16 (2026)’s screen is that it has boosted the peak brightness. There is now a peak HDR brightness of 1000 nits against the older one’s 500 nits, plus uprated support for DisplayHDR True Black 1000. There is also a bump up in SDR brightness, as I noted with my colorimeter, with a peak of 434.3 nits, which is some 25% brighter than the peak of the old panel, for even punchier images.
Image Credit (Trusted Reviews)
Advertisement
The speakers on the Zenbook S 16 (2026) remain downwards-firing, meaning placing the laptop on a softer surface, such as a bed or sofa, can impact performance. They are nonetheless decent, offering solid clarity and body with an okay amount of low-end.
Performance
New AMD Gorgon Point APU inside
Reasonable performance
Fast SSD and sensible RAM capacity
The main reason for Asus refreshing the Zenbook S 16 model for 2026 is the presence of some new mobile APUs from AMD, which are all the more important due to the successes we’ve already seen from Intel’s Panther Lake chips on the samples I’ve used.
My sample of the Zenbook S 16 (2026) came with AMD’s new Ryzen AI 9 465 chip, which is one of the higher-end models in the new ‘Gorgon Point’ generation of AMD’s mobile processors. It’s more of a mid-generation refresh of last year’s impressive Strix Point APUs with improvements such as higher boost clocks and faster supported memory, rather than an outright upgrade.
Image Credit (Trusted Reviews)
To this end, this Ryzen AI 9 465 chip has ten cores and 20 threads, with the cores being split between four full-fat Zen 5 cores and six more efficient Zen 5c cores. It’s a small deficit against the beefier Ryzen AI 9 HX 370 from last year’s model, which had 12 cores and 24 threads.
Advertisement
As such, the needle isn’t moved too much in synthetic benchmarks over the old model, with comparable scores in the likes of Geekbench 6 and Cinebench R23 in terms of single-core oomph. Multi-threaded numbers are within the margin of error against the older chip, and there’s less raw power than the Panther Lake Core Ultra X7 358H inside the Samsung Galaxy Book6 Pro. Has AMD gotten too complacent for 2026?
Advertisement
Image Credit (Trusted Reviews)
AMD also hasn’t done anything to improve the integrated graphics on these new APUs, with this chip coming with the same Radeon 880M iGPU as its predecessor. It’s a respectable score in 3DMark Time Spy to provide a helping hand for more graphically-intensive creative tasks, although the 1080p gaming numbers with 20fps in Returnal, 19.82fps in Cyberpunk 2077 and 42fps in Rainbow Six Extraction aren’t too great.
My sample came shipped with 32GB of fast DDR5 RAM, providing a fair amount of headroom for multitasking and more intensive workloads, while there’s also a capacious 2TB SSD to get excited about for storin’ all kinds of stuff on. With measured read and write speeds of 7111.32 MB/s and 6727.37 MB/s, it’s a decently brisk one, too.
Software
Reasonably clean Windows 11 install
Some pre-installed Asus apps
Also comes with Copilot AI features
The Zenbook S 16 (2026)comes with Windows 11 and a reasonably clean install, too. There isn’t much in the way of bloatware with regard to an unwanted anti-virus or similar, although there are some pieces of software courtesy of Asus that come pre-installed.
Advertisement
There is MyAsus, which comes as part of the taskbar when you first open the Zenbook S 16. This is where you can check on everything from battery level and enabling battery care modes to choosing which type of workload the Zenbook S 16’s network connection prioritises.
Image Credit (Trusted Reviews)
In addition, there is also GlideX, which is where you can manage tasks such as casting or mirroring the Zenbook S 16’s screen to other devices wirelessly, or transfer files across the same network. You can also enable remote access to a mobile device, too. The Storybook app is designed as another means of organising photos and videos, using AI to recognise faces and file your photos for you, which is handy.
There is also enough AI horsepower from the Ryzen AI 9 465 chip inside to mark this laptop as a Copilot+ PC, providing access to Microsoft’s AI functionality for generative powers and filters in the Photos and Paint app, as well as the clever Windows Studio webcam effects for background blurring, auto framing and maintaining eye contact. With the latest version of Windows 11, there is also the controversial Microsoft Recall feature.
Battery Life
Lasted for 10 hours 10 minutes in the battery test
Capable of lasting for one working day
Asus has upped the battery capacity of the Zenbook S 16 (2026) with an 83Whr cell, which is a slight increase on the 2024 model. The last model had reasonable endurance, lasting for over 13 hours in our testing, so it makes sense to expect some form of improvement with this new model.
Advertisement
In putting it through the PCMark 10 Modern Office test with the brightness set to the requisite 150 nits, I was quite disappointed to find that this Asus laptop lasted for just ten hours and ten minutes. That’s three hours less than its predecessor, which means this laptop only just meets our general target for battery life.
Advertisement
For reference, the Samsung Galaxy Book6 Pro managed nearly double the runtime, while the Acer Swift Edge 14 AI hit nearly 16 hours on a charge. The result here is very comparable to the large-screen Acer Aspire 16 AI, with just five minutes separating the two laptops.
Squirrel Widget
Should you buy it?
You want a dazzling and large OLED screen
Advertisement
This new Zenbook S 16 (2026) benefits from much stronger brightness and contrast, which make it one of the best OLED screens I’ve seen on a 16-inch laptop.
Advertisement
You want strong battery life
Weirdly, the Zenbook S 16 (2026) has worse endurance than its predecessor, and a lot of its rivals, meaning if battery life is key, then you may want to look elsewhere.
Advertisement
Final Thoughts
The Asus Zenbook S 16 (2026) is a lovely Windows ultrabook with a fantastic OLED screen, a stylish chassis and decent performance from the new AMD processor inside. It’s more of a refinement over its predecessor, though, which means some tradeoffs in design and endurance, but the older model still has the lead in some respects. Against the Zenbook S 16 (2024), this new model has a brighter and even sharper OLED panel, and a more refined look than some prefer, although the performance isn’t too much improved, and the battery life of the 2026 model is actually worse. In some respects, the Panther Lake-powered Samsung Galaxy Book6 Pro is a better buy with much stronger endurance, a fair bit more raw power and a MacBook Pro-inspired finish. It is a bit more expensive, though. For more options, check out our list of the best laptops we’ve tested.
Trusted Score
How We Test
This Asus laptop has been put through a series of uniform checks designed to gauge key factors, including build quality, performance, screen quality and battery life. These include formal synthetic benchmarks and scripted tests, plus a series of real-world checks, such as how well it runs popular apps and extensive gaming testing.
Advertisement
Advertisement
FAQs
What’s the difference between the Asus Zenbook S 16 (2026) and the Asus Zenbook S 16 (2024)?
Against the older model, the Asus Zenbook S 16 (2026) has a new AMD processor, a brighter OLED screen, a larger battery and a slightly redesigned chassis.
Test Data
Asus Zenbook S 16 (2026)
Full Specs
Asus Zenbook S 16 (2026) Review
UK RRP
£1699.99
CPU
AMD Ryzen AI 9 465
Manufacturer
Asus
Screen Size
16 inches
Storage Capacity
2TB
Front Camera
1080p webcam
Battery
83 Whr
Battery Hours
10 10
Size (Dimensions)
353.6 x 243 x 11 MM
Weight
1.5 KG
Operating System
Windows 11
Release Date
2026
First Reviewed Date
08/02/2026
Resolution
2880 x 1800
HDR
Yes
Refresh Rate
120 Hz
Ports
1x USB 3.2 Gen 2 Type-A (data speed up to 10Gbps) 2x USB 4.0 Gen 3 Type-C with support for display / power delivery (data speed up to 40Gbps) 1x HDMI 2.1 TMDS 1x 3.5mm Combo Audio Jack SD 4.0 card reader
Microsoft is investigating a known issue that prevents some Classic Outlook users from sending emails via Outlook.com.
Affected users are being warned that their message hasn’t reached some intended recipients, and they will encounter this problem more often when the Outlook.com account they use to send email is an Outlook profile linked to another Exchange account.
“This message could not be sent. Try sending the message again later or contact your network administrator,” the non-delivery report (NDR) error displayed when sending or replying to emails reads.
“You do not have the permission to send the message on behalf of the specified user. Error is [0x80070005-0x0004dc-0x000524].”
Advertisement
Microsoft added that another condition that may trigger these errors is that the sender’s account has an Exchange Online mail contact with the same SMTP address.
Classic Outlook non-delivery report (NDR) error (Microsoft)
While investigating this issue and still looking for a fix, the Outlook team shared several workarounds that may help affected customers temporarily mitigate the issue.
Microsoft recommends removing the M365 account Address Book so that the Outlook client does not check it when sending emails, hiding the Outlook.com contact from the Microsoft 365 account Global Address List (GAL).
Other alternatives include creating a new classic Outlook profile that includes only the account receiving NDR errors, and using the New Outlook client or Outlook.com on the web to send email from the affected account.
Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.
This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.
Scientists say extreme March heat caused an unusually rapid collapse of snowpack across the American West that’s leaving major basins at record or near-record lows. “This year is on a whole other level,” said Dr Russ Schumacher, a Colorado State University climatologist. “Seeing this year so far below any of the other years we have data for is very concerning.” The Guardian reports: […] The issue is extremely widespread. Data from a branch of the US Department of Agriculture (USDA), which logs averages based on levels between 1991 and 2020, shows states across the south-west and intermountain west with eye-popping lows. The Great Basin had only 16% of average on Monday and the lower Colorado region, which includes most of Arizona and parts of Nevada, was at 10%. The Rio Grande, which covers parts of New Mexico, Texas and Colorado, was at 8%. “This year has the potential of being way worse than any of the years we have analogues for in the past,” Schumacher said.
Even with near-normal precipitation across most of the west, every major river basin across the region was grappling with snow drought when March began, according to federal analysts. Roughly 91% of stations reported below-median snow water equivalent, according to the last federal snow drought update compiled on March 8. Water managers and climate experts had been hopeful for a March miracle — a strong cold storm that could set the region on the right track. Instead, a blistering heatwave unlike any recorded for this time of year baked the region and spurred a rapid melt-off. “March is often a big month for snowstorms,” Schumacher said. “Instead of getting snow we would normally expect we got this unprecedented, way-off-the-scale warmth.”
More than 1,500 monthly high temperature records were broken in March and hundreds more tied. The event was “likely among the most statistically anomalous extreme heat events ever observed in the American south-west,” climate scientist Daniel Swain said in an analysis posted this week. “Beyond the conspicuous ‘weirdness’ of it all,” Swain added, “the most consequential impact of our record-shattering March heat will likely be the decimation of the water year 2025-26 snowpack across nearly all of the American west.” Calling the toll left by the heat “nothing short of shocking,” Swain noted that California was tied for its worst mountain snowpack value on record. While the highest elevations are still coated in white, “lower slopes are now completely bare nearly statewide.”
Studio 64 Bits worked tirelessly for four months to hand-draw every single frame, allowing them to introduce Elden Ring to the wild world of Saturday morning television in the 90s. The end effect feels like a bizarre parallel universe in which the game appears alongside Thundercats and He-Man.
Ranni is right there at the start, cradling a double-necked electric guitar slung lazily across her shoulders, and as she begins noodling on the opening chords, the camera sweeps across these blasted landscapes, full of familiar faces from both the base game and the Shadow of the Erdtree expansion. We see Malenia charging ahead with blades flashing, Blaidd standing tall and loyal by her side, and Messmer looming large as the true new threat. Meanwhile, Miquella and Radahn share a dramatic moment, and Melina, Rykard, Mohg, Varre, Midra, Placidusax, Astel, Maliketh, and the Elden Beast all flash across the screen in quick, splashy bursts. Each character receives the usual cartoon makeover, complete with bold outlines, vivid colors, and exaggerated posturing that transforms their conflicts into heroic showdowns rather than gloomy, terrible struggles.
The animation sticks to the technical limits of 90’s TV production, which means that the colors don’t deviate much from a fairly limited palette, the lines have just a hint of that creaky hand-drawn cel look to them, and the transitions snap along with the same crisp timing you’d see on shows from that era. The music builds to a precise pitch, culminating in a driving rock song that sounds like it might have come directly from the opening titles of Jayce and the Wheeled Warriors or Captain Planet. Every second creates the impression that an entire series could follow, with the Tarnished rushing across the continent to repair the Elden Ring and face off against these legendary monsters in one thrilling episode after the next.
After the main intro concludes, the film transitions to a brief commercial in which Elden Ring appears to have recently been released for the old SNES. A happy narration promises additional dungeons, secrets, and a fate that is entirely in the player’s control. The tagline reverses a humorous old Nintendo slogan into ‘Now you’re playing with power, rune power’, and the spot concludes with a quick little bumper that parodies the DIC logo from coutnless old 90’s cartoons. It connects neatly to their last full-length SNES remake, making the entire package feel like one continuous block of faux Saturday morning programming.
Smart glasses have always had a basic problem for people like me. They looked cool in demos, sounded futuristic in press releases, and usually came with the same quiet catch. If you already wear glasses every day, you are expected to work around them. This meant adding prescription lenses later, settling for a fit that is not quite right, or treating the whole thing as a novelty instead of something you would actually wear throughout the day.
This is what makes Meta’s latest announcement more exciting. The company just unveiled its first prescription-optimized AI glasses, the Ray-Ban Meta Blayzer Optics (Gen 2) and Ray-Ban Meta Scriber Optics (Gen 2), and they are explicitly designed around people who rely on prescription eyewear all day.
Meta says they support nearly all prescriptions, start at $499 in the US, and will be available at optical retailers beginning April 14.
For me, that is the first time Meta’s glasses story has felt less like wearable hype and more like something I could actually live with.
Advertisement
Meta
Prescription wearers don’t have to do extra work
Billions of people around the world use glasses or contacts for vision correction, and Meta itself notes that many Ray-Ban Meta and Oakley owners already add prescription lenses to existing models. But “can be added later” is not the same thing as “built for you from the start.”
The new prescription-first push feels more thoughtful. Meta says that these new models were designed for all-day comfort and include features like overextension hinges, interchangeable nose pads, and optician-adjustable temple tips. These may sound like dry-product language stuff, but if you actually wear glasses every day, it is the kind of detail that decides whether something stays on your face for the next eight hours or if it gets thrown into a case after 20 minutes.
Balancing act between ‘gadget’ and ‘eyewear’
Meta
Meta is not just launching two new frame styles and calling it a day. It is trying to make AI glasses feel like a normal category of eyewear rather than a niche device for early adopters. These new prescription-optimized frames aren’t alone, as Meta also announced more frame and lens options across Ray-Ban Meta and Oakley Meta glasses.
There’s also a new software feature, like hands-free nutrition tracking, WhatsApp summaries and recall through Meta AI, and Neural Handwriting support expanding to iMessage. All of this makes these new glasses feel more natural for daily use. The tech itself is only half the story. The real breakthrough is when you don’t need to accommodate the hardware.
And if you already wear prescription glasses, that threshold is even higher. A smartwatch can be optional. Glasses are not.
Meta
This is the first Meta glasses move that feels genuinely practical
This is basically why I think these new Meta glasses matter more than they might look on paper. The usual wearable pitch is about features, AI tricks, cameras, and convenience. But for prescription wearers, such as myself, the first question is whether I would actually want to wear this all day instead of normal glasses?
And for a change, Meta seems to be answering that question directly.
Advertisement
Yes, the concerns don’t disappear, and smart glasses still have the privacy baggage and hefty price tag. They also haven’t proved that their AI features are useful often enough to justify becoming part of your daily routine. But this launch clears a much more fundamental barrier than people give it credit for.
And for someone who already owns prescription Wayfarers and knows how much difference proper eyewear fit makes, Meta’s new AI glasses suddenly feel a lot more attractive.
For those of us who hack old cameras, the 3D printer has undoubtedly been a boon. High precision, or at least consistent precision, lightproof enclosures can be easily made and reproduced for others. As a result there are quite a few printable cameras out there, and we’ve featured our share here. We didn’t realize just how many there are without the work of [Sebastian] though, as he’s gathered together every one he can find in a glorious catalog of homemade photographic construction.
As a snapshot of the world of home made cameras it’s refreshing to see such a wide range of designs. There are pinholes aplenty as well as cameras using lenses from scavanged point and shoots through 35mm SLR, medium format, and even one using a Micro Four Thirds compact digital camera lens. For film there’s 35mm and 120 as well as large format, but we’re pleased to see a few instant cameras in there. Some of the models in the list are paid-for designs but most of them are free, so you probably won’t need any encouragement to make yourself a camera!
Unless we missed something, we didn’t see any movie cameras in the list. With 35mm and 16mm models to be found, we hope some of them make it.
ChatGPT arrives on Apple CarPlay update for iOS 26.4
Update adds support for “voice-based conversational apps”
Interaction is limited to voice prompts only
We reported on a big Apple update in February of this year with the release of the new iOS 26.4 public beta.
The headline news was the inclusion of third-party, voice-controlled AI chatbots on CarPlay for the first time, allowing drivers to make the most of AI assistants outside of those that come part and parcel of many modern cars.
Where Mercedes-Benz has its “Hey Mercedes!” prompts, and Renault’s more recent offerings have Reno, these are not only limited to only the newest models, but are also relatively limited in what they can deliver.
Article continues below
Advertisement
On the other hand, the likes of ChatGPT, Google’s Gemini, and Claude open up the opportunity for more powerful AI assistants, even in older vehicles.
Last week, Apple released iOS 26.4 to the public, and a few days later, OpenAI responded with an update for ChatGPT that made it compatible with the iPhone mirroring software.
(Image credit: Mac Rumors)
Those running the latest version of iOS will see a dedicated ChatGPT app pop up on screen (so long as it exists on the device itself), and, when opened, it allows for “voice-based” conversations with the AI-powered app.
Advertisement
Users will be able to see a list of previous chats, but due to safety legislation put in place by Apple, they will only be able to converse with the chatbot, rather than type or read the resulting reams of text that it produces.
Sign up for breaking news, reviews, opinion, top tech deals, and more.
Essentially, it’s the same as interacting with the smartphone app in voice mode, and the CarPlay app is about as simple as they come. There’s merely an ask icon to show that the app is listening and a button to mute and end the conversation.
Advertisement
Analysis: simple but effective
(Image credit: Getty Images/NurPhoto)
ChatGPT’s voice mode is pretty good, and for most drivers, the ability to ask questions and receive detailed answers will be a boon. It’s a great tool for settling in-car arguments.
That said, there’s no wake word, so you have to open the app manually to use it (a distraction in itself), nor can the app be used to interact with the iPhone or make adjustments to the car’s settings like Siri and manufacturer-designed chatbots can.
It’s a cautious first step into the world of AI apps and Apple CarPlay or Android Auto integration, but it’s likely to be just the beginning.
And of course, you can also follow TechRadar on YouTube and TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.
“Your AI? It’s my AI now.” The line came from Etay Maor, VP of Threat Intelligence at Cato Networks, in an exclusive interview with VentureBeat at RSAC 2026 — and it describes exactly what happened to a U.K. CEO whose OpenClaw instance ended up for sale on BreachForums. Maor’s argument is that the industry handed AI agents the kind of autonomy it would never extend to a human employee, discarding zero trust, least privilege, and assume-breach in the process.
The proof arrived on BreachForums three weeks before Maor’s interview. On February 22, a threat actor using the handle “fluffyduck” posted a listing advertising root shell access to the CEO’s computer for $25,000 in Monero or Litecoin. The shell was not the selling point. The CEO’s OpenClaw AI personal assistant was. The buyer would get every conversation the CEO had with the AI, the company’s full production database, Telegram bot tokens, Trading 212 API keys, and personal details the CEO disclosed to the assistant about family and finances. The threat actor noted the CEO was actively interacting with OpenClaw in real time, making the listing a live intelligence feed rather than a static data dump.
Cato CTRL senior security researcher Vitaly Simonovich documented the listing on February 25. The CEO’s OpenClaw instance stored everything in plain-text Markdown files under ~/.openclaw/workspace/ with no encryption at rest. The threat actor didn’t need to exfiltrate anything; the CEO had already assembled it. When the security team discovered the breach, there was no native enterprise kill switch, no management console, and no way to inventory how many other instances were running across the organization.
OpenClaw runs locally with direct access to the host machine’s file system, network connections, browser sessions, and installed applications. The coverage to date has tracked its velocity, but what it hasn’t mapped is the threat surface. The four vendors who used RSAC 2026 to ship responses still haven’t produced the one control enterprises need most: a native kill switch.
Maor ran a live Censys check during an exclusive VentureBeat interview at RSAC 2026. “The first week it came out, there were about 6,300 instances. Last week, I checked: 230,000 instances. Let’s check now… almost half a million. Almost doubled in one week,” Maor said. Three high-severity CVEs define the attack surface: CVE-2026-24763 (CVSS 8.8, command injection via Docker PATH handling), CVE-2026-25157 (CVSS 7.7, OS command injection), and CVE-2026-25253 (CVSS 8.8, token exfiltration to full gateway compromise). All three CVEs have been patched, but OpenClaw has no enterprise management plane, no centralized patching mechanism, and no fleet-wide kill switch. Individual administrators must update each instance manually, and most have not.
The defender-side telemetry is just as alarming. CrowdStrike’s Falcon sensors already detect more than 1,800 distinct AI applications across its customer fleet — from ChatGPT to Copilot to OpenClaw — generating around 160 million unique instances on enterprise endpoints. ClawHavoc, a malicious skill distributed through the ClawHub marketplace, became the primary case study in the OWASP Agentic Skills Top 10. CrowdStrike CEO George Kurtz flagged it in his RSAC 2026 keynote as the first major supply chain attack on an AI agent ecosystem.
AI agents got root access. Security got nothing.
Maor framed the visibility failure through the OODA loop (observe, orient, decide, act) during the RSAC 2026 interview. Most organizations are failing at the first step: security teams can’t see which AI tools are running on their networks, which means the productivity tools employees bring in quietly become shadow AI that attackers exploit. The BreachForums listing proved the end state. The CEO’s OpenClaw instance became a centralized intelligence hub with SSO sessions, credential stores, and communication history aggregated into one location. “The CEO’s assistant can be your assistant if you buy access to this computer,” Maor told VentureBeat. “It’s an assistant for the attacker.”
Ghost agents amplify the exposure. Organizations adopt AI tools, run a pilot, lose interest, and move on — leaving agents running with credentials intact. “We need an HR view of agents. Onboarding, monitoring, offboarding. If there’s no business justification? Removal,” Maor told VentureBeat. “We’re not left with any ghost agents on our network, because that’s already happening.”
Advertisement
Cisco moved toward an OpenClaw kill switch
Cisco President and Chief Product Officer Jeetu Patel framed the stakes during an exclusive VentureBeat interview at RSAC 2026. “I think of them more like teenagers. They’re supremely intelligent, but they have no fear of consequence,” Patel said of AI agents. “The difference between delegating and trusted delegating of tasks to an agent … one of them leads to bankruptcy. The other one leads to market dominance.”
Cisco launched three free, open-source security tools for OpenClaw at RSAC 2026. DefenseClaw packages Skills Scanner, MCP Scanner, AI BoM, and CodeGuard into a single open-source framework running inside NVIDIA’s OpenShell runtime, which NVIDIA launched at GTC the week before RSAC. “Every single time you actually activate an agent in an Open Shell container, you can now automatically instantiate all the security services that we have built through Defense Claw,” Patel told VentureBeat. AI Defense Explorer Edition is a free, self-serve version of Cisco’s algorithmic red-teaming engine, testing any AI model or agent for prompt injection and jailbreaks across more than 200 risk subcategories. The LLM Security Leaderboard ranks foundation models by adversarial resilience rather than performance benchmarks. Cisco also shipped Duo Agentic Identity to register agents as identity objects with time-bound permissions, Identity Intelligence to discover shadow agents through network monitoring, and the Agent Runtime SDK to embed policy enforcement at build time.
Palo Alto made agentic endpoints a security category of their own
Palo Alto Networks CEO Nikesh Arora characterized OpenClaw-class tools as creating a new supply chain running through unregulated, unsecured marketplaces during an exclusive March 18 pre-RSA briefing with VentureBeat. Koi found 341 malicious skills on ClawHub in its initial audit, with the total growing to 824 as the registry expanded. Snyk found 13.4% of analyzed skills contained critical security flaws. Palo Alto Networks built Prisma AIRS 3.0 around a new agentic registry that requires every agent to be logged before operating, with credential validation, MCP gateway traffic control, agent red-teaming, and runtime monitoring for memory poisoning. The pending Koi acquisition adds supply chain visibility specifically for agentic endpoints.
Cato CTRL delivered the adversarial proof
Cato Networks’ threat intelligence arm Cato CTRL presented two sessions at RSAC 2026. The 2026 Cato CTRL Threat Report, published separately, includes a proof-of-concept “Living Off AI” attack targeting Atlassian’s MCP and Jira Service Management. Maor’s research provides the independent adversarial validation that vendor product announcements cannot deliver on their own. The platform vendors are building governance for sanctioned agents. Cato CTRL documented what happens when the unsanctioned agent on the CEO’s laptop gets sold on the dark web.
Advertisement
Monday morning action list
Regardless of vendor stack, four controls apply immediately: bind OpenClaw to localhost only and block external port exposure, enforce application allowlisting through MDM to prevent unauthorized installations, rotate every credential on machines where OpenClaw has been running, and apply least-privilege access to any account an AI agent has touched.
Discover the install base. CrowdStrike’s Falcon sensor, Cato’s SASE platform, and Cisco Identity Intelligence all detect shadow AI. For teams without premium tooling, query endpoints for the ~/.openclaw/ directory using native EDR or MDM file-search policies. If the enterprise has no endpoint visibility at all, run Shodan and Censys queries against corporate IP ranges.
Patch or isolate. Check every discovered instance against CVE-2026-24763, CVE-2026-25157, and CVE-2026-25253. Instances that cannot be patched should be network-isolated. There is no fleet-wide patching mechanism.
Audit skill installations. Review installed skills against Cisco’s Skills Scanner or the Snyk and Koi research. Any skill from an unverified source should be removed immediately.
Enforce DLP and ZTNA controls. Cato’s ZTNA controls restrict unapproved AI applications. Cisco Secure Access SSE enforces policy on MCP tool calls. Palo Alto’s Prisma Access Browser controls data flow at the browser layer.
Kill ghost agents. Build a registry of every AI agent running. Document business justification, human owner, credentials held, and systems accessed. Revoke credentials for agents with no justification. Repeat weekly.
Deploy DefenseClaw for sanctioned use. Run OpenClaw inside NVIDIA’s OpenShell runtime with Cisco’s DefenseClaw to scan skills, verify MCP servers, and instrument runtime behavior automatically.
Red-team before deploying. Use Cisco AI Defense Explorer Edition (free) or Palo Alto Networks’ agent red-teaming in Prisma AIRS 3.0. Test the workflow, not just the model.
The OWASP Agentic Skills Top 10, published using ClawHavoc as its primary case study, provides a standards-grade framework for evaluating these risks. Four vendors shipped responses at RSAC 2026. None of them is a native enterprise kill switch for unsanctioned OpenClaw deployments. Until one exists, the Monday morning action list above is the closest thing to one.
Kia’s combustion-powered Seltos has grown up and glowed up with more space and bigger tech inside.
Antuan Goodwin
Antuan started out in the automotive industry the old-fashioned way, by turning wrenches in a driveway and picking up speeding tickets. He now has nearly 20 years of expertise and experience behind the wheel of hundreds of cars, including electric, hybrid, plug-in hybrid, hydrogen, and traditional combustion vehicles.
For each car he tests, Antuan covers more than 200 miles behind the wheel and evaluates driving dynamics; acceleration and braking performance; range; and efficiency.
Antuan’s goal is to use his extensive car knowledge to educate CNET readers and help with their next car-related buying decision. Whether you’re EV-curious, an EV-enthusiast or a combustion-car loyalist, Antuan will bring you the unbiased advice, reviews, best lists and news you need.
Eighteen months ago, Legora was a Stockholm startup with a handful of law-firm clients and roughly $1 million in annual recurring revenue. On Tuesday, the company told Business Insider that it has crossed $100 million in ARR, a milestone that in enterprise software typically takes the better part of a decade. Max Junestrand, Legora’s 26-year-old cofounder and chief executive, framed the number as a reflection of demand rather than salesmanship. “This is a reflection of how quickly our customers are pushing the industry forward,” he said in a statement. “They’re redefining how legal work gets done, and AI is becoming the core infrastructure for the profession.”
The claim, if verified independently, would place Legora among the fastest-growing software companies in European history and firmly establish it as the most serious challenger to Harvey, the San Francisco-based legal AI company that currently leads the market. Harvey, which was last valued at $11 billion after raising $200 million in late March, said it had crossed $200 million in ARR and now serves more than 100,000 lawyers across 1,300 organisations. Legora’s customer base has grown to more than 1,000 firms and legal teams, according to the company, up from around 800 at the time of its Series D financing in early March.
The revenue figure helps explain a valuation that, until now, looked difficult to justify on the numbers alone. Legora raised $550 million in a Series D round led by Accel on 10 March, with the round pricing the company at $5.55 billion. At the time, its publicly disclosed ARR was approximately $23 million, putting the valuation at a staggering 240 times revenue. If the company was already running closer to $100 million, the multiple drops to roughly 55 times, still aggressive but within the range investors have accepted for high-growth vertical AI businesses. Among the backers in that round were Benchmark, Bessemer Venture Partners, General Catalyst, ICONIQ, Redpoint Ventures, Menlo Ventures, Salesforce Ventures, Bain Capital, and Y Combinator, which backed Legora in its Winter 2024 batch. Total funding now stands at $816 million.
Junestrand’s biography reads like a case study in the argument thatEurope should bet bigger on young founders. He was 23 when he started Legora with Sigge Labor, the company’s chief technology officer, and August Erséus, having previously competed in professional gaming, studied machine learning and business at KTH and the Stockholm School of Economics simultaneously, and worked at McKinsey. None of the three founders had practised law. They met Labor’s early prototype of software that could automate simpler legal tasks during the pandemic, but the state of large language models at the time limited what it could do. When the models improved, Legora launched.
Advertisement
The 💜 of EU tech
The latest rumblings from the EU tech scene, a story from our wise ol’ founder Boris, and some questionable AI art. It’s free, every week, in your inbox. Sign up now!
The product now covers the full arc of legal work that firms have historically staffed with junior associates: tearing through data rooms during due diligence, comparing contracts clause by clause, drafting briefs, and running multi-document reviews. In November 2025, the company launched Portal, a platform designed to let law firms productise their expertise and deliver it to in-house legal teams through custom AI workflows and intelligent document sharing. Design partners on Portal include Linklaters, Cleary Gottlieb, Goodwin, Deloitte, and Bird & Bird, with general availability scheduled for the first quarter of 2026. On 12 March, days after closing the Series D, Legora acquired Walter AI, a Canadian startup building agentic legal workflows, integrating its nine-person team into Stockholm and establishing a Toronto office under Walter’s former chief customer officer.
Legora’s trajectory has been shaped by a legal industry that appears to have moved past the question of whether AI belongs in the practice of law. A Thomson Reuters survey published in January found that law-firm spending on technology and knowledge-management tools grew 9.7 and 10.5 per cent respectively in 2025, the fastest real growth the sector has recorded. Separate research suggests that 55 per cent of lawyers are already using AI in some form. The global legal AI market, estimated at between $2.7 billion and $5.6 billion depending on whose definition of “legal AI” you accept, is projected to grow at compound annual rates of 17 to 22 per cent through the end of the decade.
Advertisement
The competitive landscape is narrowing. Harvey and Legora have emerged as the two dominant platforms for large law firms, with most other entrants either acquired, consolidated, or relegated to niche applications. Harvey’s advantage is depth of penetration: its tools are embedded in the daily workflows of some of the world’s largest firms, including those in the Am Law 100 and Magic Circle. Legora’s advantage is breadth and speed. The company expanded from 250 firms in May 2025 to more than 1,000 in less than a year, growing its headcount from 40 to more than 400 and opening offices in London, New York, and Sydney alongside its Stockholm headquarters. It becamethe fastest Y Combinator company to reach unicorn status, hitting $1.8 billion in its Series C in October 2025, just 13 months after its YC batch.
That speed carries risks. Legora’s valuation has roughly tripled every five months since its Series B, a pace that leaves almost no margin for a revenue deceleration. The $5.55 billion price assumes the company will continue scaling at rates that would place it in the top fraction of enterprise software businesses globally. If the $100 million ARR figure is accurate and growth sustains through 2026, Legora’s investors will look prescient. If the legal market’s appetite for AI tools plateaus, or if firms begin consolidating around a single platform rather than running both Harvey and Legora in parallel, the arithmetic gets considerably harder.
The broader question is what the legal AI boom tells us about theacceleration of AI adoption across professional services. Law was supposed to be resistant to automation: high-stakes, relationship-driven, riddled with jurisdictional complexity, and governed by professional regulators who move slowly. Instead, it has become one of the fastest-adopting verticals in enterprise AI, driven partly by the economics of the billable hour, which makes the value of time savings immediately and precisely quantifiable. A tool that lets a junior associate complete a document review in two hours instead of ten does not merely improve productivity. It changes the unit economics of the firm.
TheEuropean deep-tech paradox, in which the continent produces world-class research but struggles to build world-scale companies, finds an unusual counter-example in Legora. A Swedish company, built by founders in their mid-twenties with no legal background, has raised more than $800 million, grown to $100 million in ARR in a year and a half, and is now competing head-to-head with a Silicon Valley rival that has the backing of Sequoia, GIC, and the OpenAI ecosystem. Whether Legora can sustain that trajectory, or whether the extraordinary growth rates of 2025 and early 2026 represent a peak rather than a baseline, will depend on something no language model can yet predict: whether the lawyers who adopted these tools in a rush of enthusiasm will still be paying for them in three years’ time.
Advertisement
For now, the numbers suggest they will. The legal profession, it turns out, has been waiting for someone to automate the parts of the job that nobody enjoyed doing in the first place. Legora and Harvey are both betting that the parts nobody enjoyed doing also happen to be the parts that generated most of the revenue. That tension, between efficiency and economics, betweenthe promise of AI and the structures it disrupts, is the real story behind the $100 million milestone. The software works. The question is what the profession looks like once everyone is using it.
NASA’s Artemis II mission has launched four astronauts around the moon and back, marking humanity’s first crewed lunar voyage in 53 years and the first test flight of NASA’s Orion capsule and Space Launch System (SLS) with people on board. Five minutes into the flight, Commander Reid Wiseman saw the team’s target: “We have a beautiful moonrise, we’re headed right at it,” he said from the capsule. The Associated Press reports: Artemis II set sail from the same Florida launch site that sent Apollo’s explorers to the moon so long ago. The handful still alive cheered this next generation’s grand adventure as the Space Launch System rocket thundered into the early evening sky, a nearly full moon beckoning some 248,000 miles (400,000 kilometers) away.
Artemis II commander Reid Wiseman led the charge into space with “Let’s go to the moon!” accompanied by pilot Victor Glover, Christina Koch and Canada’s Jeremy Hansen. It was the most diverse lunar crew ever with the first woman, person of color and non-U.S. citizen riding in NASA’s new Orion capsule.
Carrying three Americans and one Canadian, the 32-story rocket rose from NASA’s Kennedy Space Center where tens of thousands gathered to witness the dawn of this new era. Crowds also jammed the surrounding roads and beaches, reminiscent of the Apollo moonshots in the 1960s and ’70s. It is NASA’s biggest step yet toward establishing a permanent lunar presence. Visit NASA’s Artemis II Launch Day blog for the latest updates.
You must be logged in to post a comment Login