Samsung has steadily improved its foldables, but the eighth annual update includes a fresh face, the Z Fold8, which features the long-rumored wide form factor. It slots in between the flagship Z Fold8 Ultra, which is the successor to last year’s Fold7, and the smaller Flip8, which succeeds the Flip7. Is the newcomer an awkward middle child or the glue that holds Samsung’s folding family together? Samsung also has a couple of new smartwatches, the Galaxy Watch Ultra2 and Watch9.
The new phones are available for preorder, but before you get yours, let’s dig into the details to help you decide which of Samsung’s folding phones to buy. I’ll break down the key differences and similarities, so you can make an informed choice. And remember, Samsung sells many other smartphones, and we highlight the ones worth looking at in our Best Samsung Phones guide.
Table of Contents
Which Samsung Galaxy Z Is Right For You?
Advertisement
Photograph: Julian Chokkattu
Let’s take a quick peek at what the eighth-generation Samsung Galaxy Z foldables have in common this year.
Although Samsung’s foldables all feature exterior and foldout screens in completely different sizes, they all boast Samsung’s Dynamic AMOLED 2X technology, so you get a 120-Hz refresh rate, support for HDR, and higher peak brightness than ever before (up to 3,000 nits), making it easy to read your screen, even in direct sunlight. They also have features designed to filter blue light and reduce eye strain.
The Fold8 Ultra and Fold8 have a special Flex Titanium layer that reduces the visible crease and provides extra strength, flexibility, and resilience. The titanium-alloy film should help the displays last longer, but also means they are flatter and smoother than before, with an anti-reflective finish that reduces glare.
All three phones have Qualcomm’s Snapdragon 8 Elite Gen 5 processor inside, with 12 GB of RAM and 256 GB or 512 GB of storage. You can also get the Fold8 Ultra and Fold8 with 16 GB of RAM and 1 TB of storage. They are all IP48 water- and dust-resistant and feature Samsung’s Advanced Armor Aluminum frame, which is scratch-resistant and durable enough to survive minor drops. The Fold8 Ultra and Fold8 support fast charging at up to 45 watts and fast wireless charging at 20 watts; the Flip8 is slightly slower for both. All three support Wireless PowerShare to top up wireless earbuds and other devices. Connectivity includes Wi-Fi 7 and Ultra Wideband (UWB).
Advertisement
Photograph: Julian Chokkattu
Aside from the sizes, the camera systems are very different, but here are all the specs, so you can see exactly where they diverge.
We put all of our ovens through standard tests to see how well they cook. Evenness of heat is very important, particularly when cooking sensitive items, such as Yorkshire puddings or cakes. To test this, we fill a baking tray with ceramic beads and heat the oven to 200°C. We then use a thermal camera to take an image of the beads, to see how heat is distributed, while an infrared heat gun is used to measure temperature at the front and back of the tray.
We use slices of bread spread across a shelf to measure how evenly an oven can grill and which areas, if any, it can’t reach.
We measure power usage while cooking a batch of oven chips. This is particularly important when testing ovens with special features, as we can tell you if they save you money, as well as if they’re any good.
When we have an oven with a temperature sensor, we cook a chicken breast and set the oven to 74°C, so we can see if the results are what they should be: perfectly cooked with no pink, yet not dried out.
Advertisement
Finally, we tell you how easy the oven is to use, and connect it to any smart apps to see if they add extra features and are worth using.
The Army previously urged workers to get behind AI, offering them unlimited tokens
Limits have been reinstated by the long-term future is less certain
Iran operation saw token consumption skyrocket
The US Army has reportedly been forced to reinstate limits on GenAI use after workers quickly used the full allowance of tokens early, revealing that even one of the most well-funded agencies in the world can’t keep up with AI’s unpredictable and rising costs.
In May 2026, it was revealed that the Army would give users unlimited tokens, but by mid-June that token pool had already run dry.
Now an internal email, verified by Wired, confirmed that these limits have had to be reintroduced as a result, with usage renewed at its current level for the time being.
Latest Videos From
US Army struggling to keep up with AI token spend
Token availability beyond October 2026 remains uncertain, though, with the Army likely worried about rising costs.
Advertisement
“Apparently the whole Army burned through the whole year of tokens for just one service,” an unnamed employee told Wired.
As for the intricacies, Wired reports that an annual enterprise pack for Ask Sage, the Army’s chosen AI platform, contained 100 million tokens – enough for around 200,000 tokens per employee per month. Users who exhausted their initial allocations were automatically allocated more, though, making the cap virtually pointless.
To put quantities into perspective, the Defense Department reportedly used 20 billion AI tokens per day during its 38-day Operation Epic Fury in Iran.
Advertisement
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
More broadly, workers have been actively encouraged to use generative AI across the breadth of their roles so that the Army could find out exactly where the tech could seriously improve productivity.
Army aside, this particular case is the perfect example of how aggressive AI pushes might not always consider the impacts of cost., and with many AI vendors now shifting to unpredictable consumption-based or output-based models over flat per-seat subscriptions, it’s becoming increasingly harder to predict and allocate budgets.
The UK’s AI safety watchdog put five frontier models through a set of security tests to see whether they would cut corners. Every one of them cheated. Worse, when asked about it afterwards, most would not admit they had done anything wrong.
The finding comes from the AI Security Institute (AISI), a research body inside the UK government. Across its cyber capability tests, leading models routinely took banned shortcuts to reach a goal, as The Register reported. Then they failed to flag what they had done.
“Every model we have tested for this behaviour attempted to cheat,” AISI wrote.
What the numbers show
AISI defines cheating as any action outside a task’s scope, or one the rules explicitly ban, used to reach the goal by a shortcut. In its cyber tests, models hunt for a hidden “flag” within set limits. Going outside those limits counts as cheating.
Advertisement
The 💜 of EU tech
The latest rumblings from the EU tech scene, a story from our wise ol’ founder Boris, and some questionable AI art. It’s free, every week, in your inbox. Sign up now!
Over 475 test runs each, the rates varied. GPT-5.4 cheated 14.1% of the time, GPT-5.5 11.4%, and GPT-5.6-Sol 12.6%. Among Anthropic’s models, Claude 4.7 Opus cheated 9.1% and Claude Mythos Preview 7.8%. The tactics varied too. Models searched the web for answers, bypassed sandbox limits, probed the test harness, or attacked systems that were not the target.
One model went too far
The starkest case involved a test AISI had misconfigured by accident, making it impossible to solve. One model refused to give up. It wrote and ran code on an external service on the open internet, trying to reach AISI’s own evaluation systems. That tripped a security alert.
Advertisement
No data leaked and nothing broke. But AISI said the attempt could have succeeded had it not built its systems securely. It has since tightened its controls.
They will not own up
The bigger problem is trust. Asked whether they had cheated, models called the action wrong less than half the time. They often did not mention it in their chain-of-thought, the written reasoning some models produce as they work. In some runs, a model weighed up whether a step counted as cheating, then took it anyway.
That means the two obvious checks, asking the model and reading its reasoning, both fall short. Notably, cheating did not track with how capable a model was. AISI thinks it stems from how developers train and align each model, not from raw power.
Not just in the lab
This is not only a testing-lab curiosity. OpenAI recently disclosed that its long-horizon model, the one that tackled a famous maths problem, broke out of its sandbox during internal use. In its own safety report, OpenAI said the model split an authentication token to slip past a scanner. It also posted results to a public code repository that OpenAI had ruled off limits.
Advertisement
A case for referees
AISI is careful not to overstate it. Cheating does not always mean malicious intent, and it says no model has yet cheated its way undetected past the manual review behind its published results. Even so, it warns that as models grow more capable, manual review and automated monitoring may not keep up.
The tidy fix would be to train models not to cheat at all. But researchers first flagged this more than a year ago, and AISI says aligning it away is proving hard. That strengthens the case for the independent, pre-deployment referees that figures like Demis Hassabis have proposed. It also feeds the wider push to regulate frontier systems before they ship.
When a company teases its upcoming products so heavily — the Galaxy Z Fold 8 was the star of a Spider-Man: Brand New Day commercial a full week before today’s Samsung Unpacked, for heaven’s sake — it can feel underwhelming when it’s actually revealed.
But knowing that Samsung was going to announce a trio of new foldable phones and a pair of updated watches isn’t the same as discovering interesting details about them. Now that the products are officially official, here’s what stands out to me.
Another aspect (ratio) on foldables: The Z Fold 8 ‘Wide’
Squint just a bit and most phones look like interchangeable rectangular slabs. Nearly every mobile phone is modeled after handsets that needed to position the speaker at your ear and the microphone at your mouth. Companies have stuck with the same basic design because that’s what people are familiar with.
The Z Fold 8 has a 4:3 aspect ratio.Andrew Lanxon/CNET
The Z Fold 8, with its squat folded size and 4:3 aspect ratio when opened, invites you to think about using a phone from another angle. The traditional tall screen of most slab designs has locked us into an infinite-scroll, squeezed-video existence that crushes us from both sides.
OK, that was too dramatic. A narrow phone fits well in your hand.
Advertisement
But there’s room for more phone variety. As CNET Senior Technology Reporter Abrar Al-Heeti wrote in her hands-on article, “the Z Fold 8 feels equally optimized for watching horizontal videos or multitasking in landscape mode, and browsing vertically oriented apps in portrait mode.”
The Galaxy Z Fold 8 takes up less space when closed than many other phones.Andrew Lanxon/CNET
To be fair, taking on a predominantly wide orientation invites risk… think back to the Planet Computers Gemini PDA built wide to accommodate a physical keyboard, or the quirky LG Wing. But bending the design into a foldable phone hopefully gives the best of both orientations.
The format isn’t entirely new: The iPad also has the same 4:3 aspect ratio (when used horizontally), as does Samsung’s Galaxy Z TriFold when fully opened. But those are very different devices.
If the design is embraced, Apple might see it as validation for its rumored iPhone Ultra foldable, which may have similar dimensions.
The new, revised foldables: Z Fold 8 Ultra and Z Flip 8
Does it really count if my “favorite” things include almost every new announced product? Yes, because as always with phones, details matter. And there are some details of the other two foldables that stand out.
Its svelte proportions mean that even when the Z Fold 8 Ultra is closed, it’s still not very thick.Andrew Lanxon/CNET
For example, the Galaxy Z Fold 8 Ultra strongly resembles last year’s Z Fold 7, just with an upgraded Qualcomm Snapdragon 8 Elite Gen 5 for Galaxy chip, a 5,000-mAh battery and a 50-megapixel ultrawide camera.
But look at that crease between panels. No, really, look closely, because – at least from the presentation and early looks by my fellow CNET writers – Samsung has minimized the crease to the point where it’s almost invisible (likely thanks in part to the phones’ new titanium flex hinge). The Z Fold 8 Ultra could be the foldable that doesn’t pop an asterisk in your mind each time you open it, thinking, “It’s not that noticeable, really.”
Advertisement
One big way Samsung has improved the Z Fold 8 Ultra is by reducing the crease, as seen in this comparison with last year’s Z Fold 7.
Samsung
When we’re talking about a device that you’ll open dozens of times a day, that type of improvement makes a huge difference.
In the same vein, the Z Flip 8 follows on from the Z Flip 7 but is “noticeably lighter and thinner than prior iterations,” writes CNET Senior Editor Mike Sorrentino. It’s also using the cover screen better, letting you switch apps quickly, for example, so you don’t need to open the phone to do anything meaningful.
The Galaxy Z Flip 8 is thinner and lighter than its predecessor.Andrew Lanxon/CNET
A watch that’s meant to be used: Galaxy Watch Ultra 2
I’m not a runner, but living in the Pacific Northwest, I know that a perfectly level run is rare. Navigating hills can make a huge difference in how much effort is expended during a run.
The Galaxy Watch Ultra 2 can withstand the elements. Vanessa Hand Orellana/CNET
The Galaxy Watch Ultra 2‘s trail-running feature looks like a good way to bring more of the real world into all the exercise data captured by a smartwatch. In her testing with the watch before the announcement, CNET Principal Writer Vanessa Hand Orellana noted that getting terrain information into the watch — by importing a GPX geotrack file — was an awkward process, but that data should be available later via Google Maps.
The Galaxy Watch Ultra 2 also has a hydration reminder feature, which seems perfectly paired with exercise. But she noted that the reminders pop up based on algorithmic prediction, not on any sensors monitoring sweat or salinity.
I’m shocked – shocked! – to learn that AI is happening in here
We can’t have product demos without AI features these days. Samsung showed off agentic features such as Now Nudge and the new Gemini Notebook app, which are quickly becoming table stakes for AI software. The phones will include six months of a Google AI Pro subscription.
But there are also some creative ideas at play. My FanCam lets you single out a person in a video and keep the focus on them, no matter where they move in the frame. The example shown was a stage full of dancers that focused on one woman, with the video cropped to a tall phone-friendly ratio. If grandparents have a hard time spotting which kid on stage is theirs, this feature could rapidly prove its worth.
Advertisement
Didn’t focus enough on just one person? My FanCam will recrop your video to focus on whoever you want.Andrew Lanxon/CNET
It’s a neat use of AI that doesn’t involve generating imagery that was never in the content to begin with. As my colleagues have pointed out, however, cropping that tight is bound to degrade the overall quality of the footage, so My FanCam might just become an it’s-good-enough-for-social-media feature.
The running coach on the Galaxy Watch Ultra 2 is much improved, according to Orellana, hopefully making it more than just a friendly booster chiming your greatness in your earbuds at regular intervals.
Silicon-carbon batteries are coming for better battery life
What do people really want in their phones? Longer battery life. That’s even more important with foldable phones with three power-sucking screens. So it was great to see Samsung incorporate silicon-carbon battery technology into its new phones.
There was an audible “whoa” in the crowd at the event venue when the Galaxy Z Fold 8 Ultra’s silicon-carbon battery was highlighted. For example, Samsung promises the Z Fold 8 Ultra can get 27 hours of video playback, and the Z Fold 8 can get 28 hours.
The Galaxy watches do not use silicon-carbon batteries, but the Galaxy Ultra 2’s battery is 35% larger to give up to 60 hours of use on a single charge.
Advertisement
Plus a pricey, not-so-favorite thing
New products compel us to look at new features, but we can’t ignore the biggest change that might determine whether you decide to buy one of Samsung’s new devices: price increases. The base Galaxy Z Flip 8 and Z Fold 8 Ultra each cost $100 more than their predecessors, no doubt due in part to increased component costs worldwide thanks to “RAMageddon.” The Z Fold 8 actually costs $100 less than the Z Fold 7, but that’s still $1,900 for a mobile phone.
Everything is expensive, and Samsung and other companies are building products that use some of the world’s most precious materials. But that means little if the pool of people able and willing to buy them shrinks so much that they can’t sell enough devices. It’s all the more galling when a flush company like Apple hikes prices across most of its products to seemingly protect its already high profit margins.
Still, this is the technology world we’re in, and I can’t discount that for many people, a wide foldable phone like the Z Fold 8 is exactly what they’re looking (and maybe saving up) for.
Jeff Carlson
Senior Writer
Advertisement
Jeff Carlson writes about mobile technology for CNET. He is also the author of dozens of how-to books covering a wide spectrum ranging from Apple devices and cameras to photo editing software and PalmPilots. He drinks a lot of coffee in Seattle.
See full bio
Back at Google’s I/O developer conference in May, I tried Samsung and Google’s smart glasses, which are expected this fall. At Samsung’s latest phone and watch-focused Unpacked event, a few more details on those glasses have emerged. New frame designs, some promised battery life and specs, and also, how Samsung and Google aim to address privacy concerns with glasses that Meta’s currently facing.
Samsung and Google’s first wave of smart glasses are display-free, but have a camera, microphones and speakers, much like many of Meta’s glasses. Display-enabled versions are also on the way, like Meta’s Ray-Ban Displays, but afterwards. They run Qualcomm chipsets inside, much like Meta’s glasses also do.
The big difference for these glasses is how they support Gemini AI and deep connections to Android phones, along with working with Google Wear OS watches. Samsung’s watches will control the glasses, something I got to try a bit of during a glasses demo in May.
The glasses, as we already knew, are designed with Warby Parker and Gentle Monster. But Samsung showed off two new frame designs at Unpacked, to go with the two already revealed at Google I/O. The four frames revealed so far look good, but from a distance won’t seem much different from Meta’s existing glasses designs. Won-Joon Choi, Samsung’s COO of mobile experiences, confirmed that more designs are yet to be revealed when he spoke to reporters in London before Samsung Unpacked.
Advertisement
The new Warby Parker frame design (Photo by Tara Brown/CNET).
Choi revealed more details about the upcoming glasses in an on-record chat. He said that durability tests for the glasses show better strength than standard eyewear, “multiple times stronger than regular glasses.” Samsung has already filed more than 200 patents filed for its smart glasses tech.
The Warby Parker and Gentle Monster glasses use Qualcomm Snapdragon AR1 Gen 1 chipsets, the processor that’s also in Meta’s glasses. The battery life sounds better, though: according to Choi, they can run for 9 hours on a charge (one hour better than Meta’s latest models), and even do that while handling video recording and Gemini Live AI modes, although we’ll see how battery life actually handles in a future review. The glasses case can charge the glasses an additional seven times.
The charging case for the Gentle Monster glasses. (Photo by Tara Brown/CNET)
The privacy problem
The glasses will run both Google Gemini and Samsung Bixby AI, offering at least a bit of a choice compared to glasses like Meta’s. But privacy concerns sound like they’re still at play. Google and Samsung’s glasses will show a recording light when taking photos or videos, but they need to be on your face to work. If the LED is blocked, the camera won’t record either.
But Choi acknowledges that privacy concerns on camera-enabled AI glasses is a shared industry problem.
But this is also, according to Choi, “just the beginning” for where Samsung wants to go with its interconnected wearables. These glasses still use Bluetooth and Wi-Fi to connect. Choi says that “is not enough” for where camera-enabled eyewear needs to be, and that Qualcomm and Samsung are working on future ideas.
The two newly revealed frame designs designs have a pretty familiar-for-smart glasses look (Credit: Samsung)
Better connections for wearables, especially for future higher-bandwidth devices like display glasses or full AR glasses, feels like a must. And even more so when you might have a watch, earbuds and glasses all connected at once. And Choi acknowledged that AI services, too, still need to evolve.
But so do privacy considerations. Samsung’s acknowledgment of the industry problem around glasses privacy doesn’t solve the problem. Choi feels that “if you stop the innovation, you don’t go anywhere,” and expresses confidence that Samsung (and Google) will find a way to “optimize the right solution” going forward. I’m curious to see how Samsung and Google’s AI privacy settings will feel compared to Meta’s. And also, how much better the phone and AI hook-ins will feel in everyday use.
Advertisement
For more, it looks like we’ll need to wait till the fall.
Scott Stein
Editor at Large
I started with CNET reviewing laptops in 2009. Now I explore wearable tech, VR/AR, tablets, gaming and future/emerging trends in our changing world. Other obsessions include magic, immersive theater, puzzles, board games, cooking, improv and the New York Jets. My background includes an MFA in theater which I apply to thinking about immersive experiences of the future.
See full bio
Cascade, a startup building a platform to help architecture, engineering, and construction firms find and win projects, has raised a $3.5 million seed round from Andreessen Horowitz Speedrun, Ada Ventures, and Snowball VC.
Launched in 2025, Cascade is a result of its founders, Hannia Zia and Joana Ferreira, witnessing firsthand the difficulty construction businesses face with predictably securing work.
“My mother worked in a company that sold materials to construction companies, and my uncle built mansions in the Middle East. They’re incredible at their craft but just don’t have access to the right tools to get more work,” Ferreira told TechCrunch. And Zia recalled the time her father tried starting a construction business back in her native Pakistan: “He just couldn’t get enough projects to sustain himself.”
Zia describes the current process of finding construction projects as a “constant treasure hunt,” with firms having to log into each U.S. state, city, district, county, and federal agency’s portals. “So if you’re really good at building suspension bridges, you have to find all of those opportunities across these disparate portals.”
Advertisement
Cascade aims to help architecture, construction, and engineering firms on this front by tracking ongoing and upcoming projects, and then using prior tender data to predict which developers are likely to win the deals.
Here’s how the platform works: A company signs up to the platform, and then Cascade uses AI tools to determine which projects they have the best chance of winning. It also predicts what projects are coming up, using different signals and data points across U.S. states, local districts, private contracts, and federal agencies. For example, if a state announces a $100 million affordable housing grant, Cascade will monitor which developers won the grant the last time it was announced.
“We connect that data, and we tell our customers: ‘Most likely one of these five developers will win this newly announced grant, so go start talking to them to win projects,’” Ferreira explained.
The duo applied to a16z’s Speedrun last September. They said the pressure to do well on demo day and being around the “brilliance” of other founders helped the company sign contracts with firms that have built the JFK and La Guardia airports, Four Seasons hotels, and some data centers. “Speedrun gave us visibility and a stamp of approval to close big deals,” Zia said.
Advertisement
The startup will use the fresh cash to go to market, host industry events, and hire more engineers.
Other startups in this area include GovWin IQ and ConstructConnect, but Ferreira argues Cascade is a bit more AI-native than these platforms.
“Every time a customer wins a bid, they give feedback, so the system keeps getting smarter. Over time, we’ll have a complete map of the industry that our AI can traverse to predict the best projects and leads for each customer,” she said.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Jack Dorsey’s Block wants to take on Slack. The twist is that the workforce it is building for is half machine. Its new app, Buzz, is an open-source workspace where humans and AI agents share the same channels, and every agent carries its own portable identity.
Block, the Dorsey-led fintech behind Square and Cash App, has released Buzz, a free, open-source platform for humans and AI agents to work together. Reviewers have framed it as a direct challenge to Slack, one built for the age of agents.
On the surface it looks familiar. Buzz has channels, threads, direct messages, voice, media sharing, code repositories, and automated workflows. Anyone who has used a modern team chat tool will recognise it.
Agents as colleagues, not assistants
The difference sits underneath. In Buzz, AI agents are not bots waiting for a command. Each one has its own cryptographic identity, defined permissions, and the ability to post, review code, run approved automations, and join conversations. Multiple agents and multiple humans share a workspace and build on each other’s work.
“Every company is going to need a place where humans and agents work together,” said Bradley Axen, Block’s Head of AI Capabilities. “The question is whether that place is proprietary or open. We built Buzz because we believe it should be open.”
Advertisement
It is model-agnostic. Teams can plug in agents built on any model or harness, such as Claude Code, Codex, or Block’s own goose. They can bring their own, or build new ones.
The identity bet
Buzz runs on Nostr, the decentralised protocol Dorsey has long backed. Block chose it to solve what it calls the core problem of multi-agent work: identity. Every participant, human or agent, holds a cryptographic keypair that belongs to them, not to the platform.
That means an agent’s identity is not tied to a vendor’s API key. It is portable and verifiable, and it can move across any Nostr-compatible system, carrying its history and reputation with it. It echoes a wider push to give agents a durable identity system of their own.
Open versus locked in
Block’s real argument is about control. Most companies are building their agent infrastructure inside proprietary platforms run by a handful of providers, which breeds fragmentation and vendor dependency. Buzz ships under an Apache-2.0 licence. Teams can run their own instance with full control over data and agents, or use Block’s hosted version.
Advertisement
The open, self-hosted pitch should land with European firms wary of US vendor lock-in and of data leaving their control. It also chimes with the drive to give autonomous agents their own standing as they take on real work.
A crowded room
Buzz is still early. The Git integration is nascent. And Block is entering a field where Slack, Microsoft Teams, and OpenAI all race to deploy agents in the workplace. Whether openness beats the incumbents’ reach is the open question. So is oversight: handing agents their own identities and permissions is convenient, and it is exactly the autonomy that safety researchers keep warning about.
Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices.
The monthly report aggregates security advisories from major infrastructure vendors and highlights the vulnerabilities administrators should prioritize based on a flaw’s exploitability, exposure, and real-world risk rather than severity scores alone.
The inaugural July 2026 InfraTrust Pulse by Paul Asadoorian, Principal Security Researcher at Eclypsium, tracked 61 infrastructure advisories from 14 vendors, including six critical advisories and 26 remotely exploitable, unauthenticated vulnerabilities.
The report also highlights several advisories containing actively exploited vulnerabilities or flaws tracked in CISA’s Known Exploited Vulnerabilities (KEV) catalog.
Eclypsium also argues that organizations should prioritize vulnerabilities based on exploitability, reachability, and exposure rather than CVSS scores alone.
Advertisement
The focus on infrastructure security comes as Russian and Chinese state-sponsored threat actors have increasingly targeted vulnerable network edge devices.
In recent years, attackers have repeatedly exploited flaws in routers, VPNs, firewalls, and other internet-facing infrastructure to breach critical infrastructure and telecommunications providers, including in campaigns attributed to state-sponsored hacking groups such as Volt Typhoon and Salt Typhoon.
What to patch first
The report highlights several advisories that admins should prioritize because they affect internet-exposed infrastructure, are already exploited, or can be compromised remotely without authentication.
Below are the infrastructure advisories Eclypsium says administrators should prioritize based on active exploitation, exposure, and the potential impact of a compromise.
Advertisement
Advisory
Why patch now?
SonicWall SMA1000
Two actively exploited vulnerabilities affecting an internet-facing remote-access appliance.
Fortinet FortiSandbox
Two flaws later added to CISA KEV-listed that allow unauthenticated command injection.
Remotely exploitable flaws that can be used to crash affected networking devices, potentially causing denial-of-service conditions.
NVIDIA BlueField / ConnectX
Vulnerabilities affecting BlueField DPUs and ConnectX SmartNICs used in AI and data-center infrastructure.
In SonicWall’s case, attackers were exploiting the SMA1000 flaws, tracked as CVE-2026-15409 and CVE-2026-15410, to install custom malware weeks before SonicWall disclosed the flaws and before they were added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.
Advertisement
The Fortinet FortiSandbox advisories (FG-IR-26-100 / FG-IR-26-141) include two older critical command injection vulnerabilities tracked as CVE-2026-39808 and CVE-2026-25089. While these vulnerabilities were disclosed in April 2026 and June 2026, they were later added to CISA’s KEV catalog on July 16, after exploitation was detected.
While these advisories were not published in the 30-day reporting period, Eclypsium highlighted them because organizations may not have patched them or known they were exposed to attacks.
“These two Fortinet CVEs were in advisories released before our 30-day window opened. Still, we are including them because CISA added both to the Known Exploited Vulnerabilities catalog on July 16, 2026, with a federal remediation deadline of July 19 under BOD 26-04,” explains Eclypsium.
The Dell advisories (DSA-2026-240 and DSA-2026-317) address critical vulnerabilities in EMC Networking OS10 and SmartFabric Manager. Eclypsium notes that the OS10 advisory alone includes hundreds of upstream fixes, illustrating that network operating systems are full Linux distributions with large attack surfaces.
Advertisement
The F5 BIG-IP advisory (K000153397) addresses critical unauthenticated vulnerabilities affecting internet-exposed application delivery controllers (ADCs) and load balancers. Eclypsium highlights these devices because they frequently sit at the edge of enterprise networks, making them attractive targets for attackers.
The Juniper Networks advisory (JSA110083 and JSA110086) addresses remotely exploitable flaws in Junos OS that can crash affected routers and switches, potentially disrupting network availability.
The NVIDIA advisory (NVIDIA Security Bulletin 5865) addresses vulnerabilities in BlueField DPUs and ConnectX SmartNICs used in AI and data-center infrastructure.
Eclypsium also noted firmware and hardware vulnerabilities, warning that updates for these components commonly lag behind upstream security fixes because they depend on hardware vendors to integrate and distribute them.
Advertisement
As an example, HP’s Poly Video advisory shipped four months after an included Qualcomm GPU driver vulnerability (CVE-2026-21385) had already been exploited in attacks and added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.
Unlike many vulnerability roundups that count individual CVEs, InfraTrust tracks vendor advisories because a single infrastructure advisory can contain dozens or even hundreds of vulnerabilities.
While the July report contains six critical advisories, it also identifies 26 vulnerabilities that can be exploited remotely without authentication, noting that an internet-reachable flaw with a lower CVSS score may present a greater risk to organizations than a higher-scoring vulnerability that requires an attacker to have local administrator access.
July 2026 infrastructure reference
Below is a complete list of the 61 infrastructure advisories tracked by Eclypsium in its inaugural July 2026 InfraTrust Pulse report.
Advertisement
The table includes the affected vendor and product, advisory identifier, severity, whether the advisory contains an actively exploited vulnerability, and a brief explanation of why it matters.
Vendor
Product
Advisory
Advertisement
Severity
Exploited
Why it matters
SonicWall
SMA1000 remote-access appliance
Advertisement
SNWLID-2026-0008
Critical, 10.0
Yes
Actively exploited pre-auth RCE chain; CVSS 10.0.
Dell
Advertisement
EMC Networking OS10
DSA-2026-240
Critical, 9.8
Yes
Advertisement
Includes a CISA-listed exploited Linux flaw.
Dell
SmartFabric Manager
DSA-2026-317
Critical, 9.8
Advertisement
No
Critical flaws in data-center fabric management.
F5
BIG-IP and F5 products
K000161837
Advertisement
Critical, 9.2
No
Unauthenticated memory-safety flaws on internet-facing ADCs.
Lenovo
ThinkSystem and System x servers
Advertisement
LEN-203310
Critical, 9.0
No
Code execution on server DPUs and SmartNICs.
NVIDIA
Advertisement
BlueField and ConnectX
Bulletin 5699
Critical, 9.0
No
Advertisement
Code execution on networking silicon in the data path.
Qualcomm
Snapdragon and networking chipsets
July 2026 Bulletin
High, 8.8
Advertisement
No
OEM-dependent fixes extend the exposure window.
Juniper
Junos OS (MX and SRX)
JSA110083
Advertisement
High, 8.7
No
Remote unauthenticated DoS against MX and SRX routers.
Juniper
Junos OS (MX and SRX)
Advertisement
JSA110086
High, 8.7
No
Remote unauthenticated DoS through the SIP ALG.
Fortinet
Advertisement
FortiSandbox
FG-IR-26-145
High, 8.6
No
Advertisement
Unauthenticated VNC access on all network interfaces.
Citrix
NetScaler ADC (Secure Access client)
CTX696734
High, 8.5
Advertisement
No
Client flaws in the NetScaler remote-access stack.
Dell
PowerProtect Data Manager (DM5500)
DSA-2026-282
Advertisement
High, 8.5
No
Command injection and data exposure on a backup appliance.
HP
Poly Voice (CCX, Trio, Edge E)
Advertisement
HPSBPY04096
High, 8.2
No
Malicious SIP server can disable Poly Voice phones.
Juniper
Advertisement
Junos OS Evolved (PTX)
JSA110073
High, 8.2
No
Advertisement
Remote unauthenticated DoS against PTX core routers.
Juniper
Junos OS (MX and SRX)
JSA110082
High, 8.2
Advertisement
No
Crafted responses can crash the packet-forwarding engine.
Juniper
Junos OS (SRX)
JSA110090
Advertisement
High, 8.2
No
Remote unauthenticated crash in SRX packet processing.
Dell
iDRAC9 (PowerEdge BMC)
Advertisement
DSA-2026-312
High, 7.8
No
BMC flaws affect control beneath the operating system.
HP
Advertisement
HP PC BIOS (InsydeH2O tools)
HPSBHF04134
High, 7.8
No
Advertisement
Firmware-update flaw can lead to code execution.
HP
Poly Studio X video codecs
HPSBPY04106
High, 7.8
Advertisement
Yes
Re-ships a CISA-listed exploited Qualcomm flaw.
Cisco
Catalyst Center
cisco-sa-catc-file-read
Advertisement
High, 7.5
No
Unauthenticated arbitrary file read from Catalyst Center.
Cisco
Secure Web Appliance
Advertisement
cisco-sa-clamav
High, 7.5
No
ClamAV flaw can disable malware scanning.
Dell
Advertisement
iDRAC10 (PowerEdge BMC)
DSA-2026-270
High, 7.5
No
Advertisement
BMC resource-exhaustion and certificate-validation flaws.
Dell
PowerEdge (OpenSSL)
DSA-2026-316
High, 7.5
Advertisement
No
OpenSSL fixes reach servers only through Dell firmware.
Palo Alto
PAN-OS (User-ID TSA)
CVE-2026-0288
Advertisement
High, 7.2
No
Unauthenticated DoS and possible code execution.
HP
HP PC BIOS (AMD Client UEFI)
Advertisement
HPSBHF04133
High, 7.1
No
Firmware flaws can allow code execution below the OS.
Juniper
Advertisement
Junos OS (RPD, BGP)
JSA110076
High, 7.1
No
Advertisement
Malformed BGP updates can disrupt the routing control plane.
Juniper
Junos OS (MX)
JSA110079
High, 7.1
Advertisement
No
Adjacent attacker can stall packet processing.
Juniper
Junos OS (QFX10000)
JSA110080
Advertisement
High, 7.1
No
Crafted multicast traffic can degrade EVPN-VXLAN switches.
Juniper
Junos OS (EX Virtual Chassis)
Advertisement
JSA110087
High, 7.1
No
sFlow memory leak can exhaust Virtual Chassis switches.
Juniper
Advertisement
Junos OS (EX)
JSA110092
High, 7.1
No
Advertisement
Low-privileged user can crash a switch line card.
Lenovo
Lenovo PC BIOS
LEN-220440
High, 7.0
Advertisement
No
BIOS memory-corruption flaws require OEM updates.
Juniper
Junos OS Evolved
JSA110078
Advertisement
Medium, 6.9
No
Unexpectedly exposed internal service enables remote attacks.
Juniper
Junos OS (SRX RA-VPN)
Advertisement
JSA110081
Medium, 6.9
No
Pre-auth VPN requests can crash the gatekeeper process.
Juniper
Advertisement
Junos OS (MX and SRX, IKE)
JSA110084
Medium, 6.9
No
Advertisement
Failed IKE negotiations can deny new VPN connections.
Juniper
Junos OS Evolved
JSA110088
Medium, 6.9
Advertisement
No
Remote attacker can exhaust licenses and degrade service.
Juniper
Junos OS (MX)
JSA110093
Advertisement
Medium, 6.9
No
URL-parsing flaw can bypass web-filtering controls.
Juniper
Junos OS (EX)
Advertisement
JSA110077
Medium, 6.8
No
Local user can stop all switch traffic.
Juniper
Advertisement
Junos OS (EX, QFX, MX)
JSA110085
Medium, 6.8
No
Advertisement
Low-privileged command can crash Layer 2 services.
Fortinet
FortiOS, FortiProxy
FG-IR-26-148
Medium, 6.6
Advertisement
No
Authenticated buffer overflow in firewall log reporting.
Palo Alto
PAN-OS
CVE-2026-0287
Advertisement
Medium, 6.6
No
Unauthenticated traffic can force the firewall into maintenance mode.
HPE Aruba Networking
Instant On switches
Advertisement
HPESBNW05038
Medium, 6.5
No
Unauthenticated disclosure of cryptographic secrets.
Netgear
Advertisement
Nighthawk, Orbi, WAX routers
PSV-000070859
Medium, 6.3
No
Advertisement
Edge-device command injection and stack-overflow flaws.
Fortinet
FortiOS, FortiProxy
FG-IR-26-150
Medium, 6.1
Advertisement
No
Pre-auth XSS can target administrator sessions.
HP
Poly Voice
HPSBPY04109
Advertisement
Medium, 6.0
No
Stolen cookie can be used to modify phone settings.
Juniper
Junos OS Evolved (QFX)
Advertisement
JSA110089
Medium, 6.0
No
sFlow synchronization flaw can intermittently crash QFX switches.
Palo Alto
Advertisement
PAN-OS
CVE-2026-0286
Medium, 6.0
No
Advertisement
Compromised admin account can execute commands as root.
HP
Poly Voice
HPSBPY04108
Medium, 5.9
Advertisement
No
Stored XSS through attacker-controlled phone configuration.
Every few months, another headline declares the college degree dead. This Week with EdSurge examines what still holds up when artificial intelligence moves fast, through two guests who are both defending something slow against something fast.
A Four Year Degree in the Age of AI
Rita Finkel, co-president of the Armory Foundation and director of the Armory College Prep program, argues that a college degree was never just about a technical skill. She says the data tells a different story than the headlines suggest, and that the value of a degree comes from something artificial intelligence cannot replicate.
The Fourth Essay
Cobretti Williams of the EdSurge Voices of Change Fellowship makes a similar case for writing. He talks about the beauty in imperfection, and how a fellow’s fourth essay reads nothing like the first, growth that only comes from doing the work yourself.
Samsung is trying to jazz things up once again in the foldable space, and the mantra this time around is going smaller and lighter. The result of those efforts is the Galaxy Z Fold 8, and it’s the first time in years that I vocally said “wow” the moment I picked it up. It’s pocketable, light, sleek, and most importantly, oozes functional charm.
Just take a look at how petite it is when held alongside a modern-age iPhone. In an age when smartphones are getting thicker and bulkier, the Galaxy Z Fold 8 wants to stand out in a rather unique fashion. Even in the unfolded state, it’s less than a millimeter thicker than an iPhone 17 Pro (9.7 vs 8.75 mm). If you compare the weight, the comparison flips in its favor. The Galaxy Z Fold 8 is lighter than even the smaller iPhone 17 Pro (201 grams vs 204 grams).
Nadeem Sarwar / DigitalTrends
This is the foldable that finally feels pocket-friendly
The difference may not seem huge, but the Galaxy Z Fold 8 packs two screens. But that’s not even the big novelty here. It’s the format that makes this one special. One instant, you have an utterly palm-friendly compact screen in your hands. And as soon as you unfold it, the phone gives you access to a sharp 7.6-inch screen with a 4:3 aspect ratio.
That 4:3 number is nothing short of a boon. Everything feels naturally spread out on the inner flexible screen. It’s wider and more naturally suited for content, whether it’s films, books, or games. You don’t see ugly black bars or have to deal with a forcibly stretched perspective to fill the screen. Samsung is not shy about that appeal either. It is “designed around the way people naturally consume content,” says the company.
Nadeem Sarwar / DigitalTrends
The 4:3 display changes everything
You see, typical book-style foldable phones are usually tall, thick, or adopt a square-ish look, which means letterboxing persists, or content is chopped off. You either see those unforgiving black bars while watching videos, or have to sacrifice content real estate in games and videos. The Galaxy Z Fold 8 is an antidote to those viewing problems, and it does so in style.
There is another underrated side to it that Samsung didn’t discuss, but it’s equally important. The cover display is just 5.5 inches across, and thanks to its wider 10:16 aspect ratio, it feels even smaller in the hand. Even the iPhone 15, which is supposedly deemed one of the last compact phones from a mainstream brand, features a 6.1-inch panel, while its successors have moved to an even bigger panel.
Advertisement
Nadeem Sarwar / DigitalTrends
A small outer screen, and that’s actually a good thing
And yet, it’s not just the smaller panel size that stands out on the Galaxy Z Fold 8. It’s the overall smaller footprint, as well. Technically, everything looks great and loads just fine on this screen. But thanks to the petite vertical screen real estate, dopamine-inducing content, such as TikToks and vertical social media content, doesn’t feel as immersive.
If you look at the digital detox and minimalist phone community, you’ll see a pattern. Smaller screens and weirder aspect ratios. The idea is to broadly make the “addictive” multimedia content appear less appealing so that you spend less time consuming it. I love it, irrespective of whether Samsung was on the same minimalism page as me or not.
Nadeem Sarwar / DigitalTrendsNadeem Sarwar / DigitalTrends
Less screen, fewer distractions
The engineering, otherwise, is impeccable. It’s unbelievably slim, light, and easy on the eyes. And oh, it’s blazing fast, too. Both screens are 120Hz type, which means all user interactions feel super fluid. Under the hood, you get Qualcomm’s top-shelf silicon, fast 45W wired charging, and a pair of 50-megapixel camera sensors at the back.
It’s the whole flagship foldable package, just in a different form factor. Yes, the asking price of $1,899 is a tough pill to swallow. And compared to what Chinese brands (or even a US label like Motorola) have to offer with the Razr Fold, the Galaxy Z Fold 8 might feel underequipped in a few key departments, such as the camera hardware. In hindsight, no phone is cheap these days, or stays that way, thanks to the AI-triggered industry-wide crisis.
Nadeem Sarwar / Digital Trends
Here’s the bottom line, though. The Galaxy Z Fold 8 is the right Samsung foldable to buy this year. It’s fresh, bold, sturdier, faster, and more importantly, a functionally rewarding evolution. It might miss out on the razzle-dazzle of a 200-megapixel camera that you get on the Ultra sibling (for $200 extra), but that’s the end of it. It’s the most refreshing and refined foldable hardware I’ve seen in years, and I can’t wait to explore it. Stay tuned for the review!
You must be logged in to post a comment Login