Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices.
The monthly report aggregates security advisories from major infrastructure vendors and highlights the vulnerabilities administrators should prioritize based on a flaw’s exploitability, exposure, and real-world risk rather than severity scores alone.
The inaugural July 2026 InfraTrust Pulse by Paul Asadoorian, Principal Security Researcher at Eclypsium, tracked 61 infrastructure advisories from 14 vendors, including six critical advisories and 26 remotely exploitable, unauthenticated vulnerabilities.
The report also highlights several advisories containing actively exploited vulnerabilities or flaws tracked in CISA’s Known Exploited Vulnerabilities (KEV) catalog.
Eclypsium also argues that organizations should prioritize vulnerabilities based on exploitability, reachability, and exposure rather than CVSS scores alone.
The focus on infrastructure security comes as Russian and Chinese state-sponsored threat actors have increasingly targeted vulnerable network edge devices.
In recent years, attackers have repeatedly exploited flaws in routers, VPNs, firewalls, and other internet-facing infrastructure to breach critical infrastructure and telecommunications providers, including in campaigns attributed to state-sponsored hacking groups such as Volt Typhoon and Salt Typhoon.
The report highlights several advisories that admins should prioritize because they affect internet-exposed infrastructure, are already exploited, or can be compromised remotely without authentication.
Below are the infrastructure advisories Eclypsium says administrators should prioritize based on active exploitation, exposure, and the potential impact of a compromise.
| Advisory | Why patch now? |
|---|---|
| SonicWall SMA1000 | Two actively exploited vulnerabilities affecting an internet-facing remote-access appliance. |
| Fortinet FortiSandbox | Two flaws later added to CISA KEV-listed that allow unauthenticated command injection. |
| Dell Networking (EMC Networking OS10 / SmartFabric Manager) | Critical remotely exploitable, unauthenticated vulnerabilities affecting switching and data-center fabric management. |
| F5 BIG-IP | Unauthenticated, network-reachable vulnerabilities affecting internet-facing application delivery controllers and load balancers. |
| Juniper | Remotely exploitable flaws that can be used to crash affected networking devices, potentially causing denial-of-service conditions. |
| NVIDIA BlueField / ConnectX | Vulnerabilities affecting BlueField DPUs and ConnectX SmartNICs used in AI and data-center infrastructure. |
In SonicWall’s case, attackers were exploiting the SMA1000 flaws, tracked as CVE-2026-15409 and CVE-2026-15410, to install custom malware weeks before SonicWall disclosed the flaws and before they were added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.
The Fortinet FortiSandbox advisories (FG-IR-26-100 / FG-IR-26-141) include two older critical command injection vulnerabilities tracked as CVE-2026-39808 and CVE-2026-25089. While these vulnerabilities were disclosed in April 2026 and June 2026, they were later added to CISA’s KEV catalog on July 16, after exploitation was detected.
While these advisories were not published in the 30-day reporting period, Eclypsium highlighted them because organizations may not have patched them or known they were exposed to attacks.
“These two Fortinet CVEs were in advisories released before our 30-day window opened. Still, we are including them because CISA added both to the Known Exploited Vulnerabilities catalog on July 16, 2026, with a federal remediation deadline of July 19 under BOD 26-04,” explains Eclypsium.
The Dell advisories (DSA-2026-240 and DSA-2026-317) address critical vulnerabilities in EMC Networking OS10 and SmartFabric Manager. Eclypsium notes that the OS10 advisory alone includes hundreds of upstream fixes, illustrating that network operating systems are full Linux distributions with large attack surfaces.
The F5 BIG-IP advisory (K000153397) addresses critical unauthenticated vulnerabilities affecting internet-exposed application delivery controllers (ADCs) and load balancers. Eclypsium highlights these devices because they frequently sit at the edge of enterprise networks, making them attractive targets for attackers.
The Juniper Networks advisory (JSA110083 and JSA110086) addresses remotely exploitable flaws in Junos OS that can crash affected routers and switches, potentially disrupting network availability.
The NVIDIA advisory (NVIDIA Security Bulletin 5865) addresses vulnerabilities in BlueField DPUs and ConnectX SmartNICs used in AI and data-center infrastructure.
Eclypsium also noted firmware and hardware vulnerabilities, warning that updates for these components commonly lag behind upstream security fixes because they depend on hardware vendors to integrate and distribute them.
As an example, HP’s Poly Video advisory shipped four months after an included Qualcomm GPU driver vulnerability (CVE-2026-21385) had already been exploited in attacks and added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.
Unlike many vulnerability roundups that count individual CVEs, InfraTrust tracks vendor advisories because a single infrastructure advisory can contain dozens or even hundreds of vulnerabilities.
While the July report contains six critical advisories, it also identifies 26 vulnerabilities that can be exploited remotely without authentication, noting that an internet-reachable flaw with a lower CVSS score may present a greater risk to organizations than a higher-scoring vulnerability that requires an attacker to have local administrator access.
Below is a complete list of the 61 infrastructure advisories tracked by Eclypsium in its inaugural July 2026 InfraTrust Pulse report.
The table includes the affected vendor and product, advisory identifier, severity, whether the advisory contains an actively exploited vulnerability, and a brief explanation of why it matters.
| Vendor | Product | Advisory | Severity | Exploited | Why it matters |
|---|---|---|---|---|---|
| SonicWall | SMA1000 remote-access appliance | SNWLID-2026-0008 | Critical, 10.0 | Yes | Actively exploited pre-auth RCE chain; CVSS 10.0. |
| Dell | EMC Networking OS10 | DSA-2026-240 | Critical, 9.8 | Yes | Includes a CISA-listed exploited Linux flaw. |
| Dell | SmartFabric Manager | DSA-2026-317 | Critical, 9.8 | No | Critical flaws in data-center fabric management. |
| F5 | BIG-IP and F5 products | K000161837 | Critical, 9.2 | No | Unauthenticated memory-safety flaws on internet-facing ADCs. |
| Lenovo | ThinkSystem and System x servers | LEN-203310 | Critical, 9.0 | No | Code execution on server DPUs and SmartNICs. |
| NVIDIA | BlueField and ConnectX | Bulletin 5699 | Critical, 9.0 | No | Code execution on networking silicon in the data path. |
| Qualcomm | Snapdragon and networking chipsets | July 2026 Bulletin | High, 8.8 | No | OEM-dependent fixes extend the exposure window. |
| Juniper | Junos OS (MX and SRX) | JSA110083 | High, 8.7 | No | Remote unauthenticated DoS against MX and SRX routers. |
| Juniper | Junos OS (MX and SRX) | JSA110086 | High, 8.7 | No | Remote unauthenticated DoS through the SIP ALG. |
| Fortinet | FortiSandbox | FG-IR-26-145 | High, 8.6 | No | Unauthenticated VNC access on all network interfaces. |
| Citrix | NetScaler ADC (Secure Access client) | CTX696734 | High, 8.5 | No | Client flaws in the NetScaler remote-access stack. |
| Dell | PowerProtect Data Manager (DM5500) | DSA-2026-282 | High, 8.5 | No | Command injection and data exposure on a backup appliance. |
| HP | Poly Voice (CCX, Trio, Edge E) | HPSBPY04096 | High, 8.2 | No | Malicious SIP server can disable Poly Voice phones. |
| Juniper | Junos OS Evolved (PTX) | JSA110073 | High, 8.2 | No | Remote unauthenticated DoS against PTX core routers. |
| Juniper | Junos OS (MX and SRX) | JSA110082 | High, 8.2 | No | Crafted responses can crash the packet-forwarding engine. |
| Juniper | Junos OS (SRX) | JSA110090 | High, 8.2 | No | Remote unauthenticated crash in SRX packet processing. |
| Dell | iDRAC9 (PowerEdge BMC) | DSA-2026-312 | High, 7.8 | No | BMC flaws affect control beneath the operating system. |
| HP | HP PC BIOS (InsydeH2O tools) | HPSBHF04134 | High, 7.8 | No | Firmware-update flaw can lead to code execution. |
| HP | Poly Studio X video codecs | HPSBPY04106 | High, 7.8 | Yes | Re-ships a CISA-listed exploited Qualcomm flaw. |
| Cisco | Catalyst Center | cisco-sa-catc-file-read | High, 7.5 | No | Unauthenticated arbitrary file read from Catalyst Center. |
| Cisco | Secure Web Appliance | cisco-sa-clamav | High, 7.5 | No | ClamAV flaw can disable malware scanning. |
| Dell | iDRAC10 (PowerEdge BMC) | DSA-2026-270 | High, 7.5 | No | BMC resource-exhaustion and certificate-validation flaws. |
| Dell | PowerEdge (OpenSSL) | DSA-2026-316 | High, 7.5 | No | OpenSSL fixes reach servers only through Dell firmware. |
| Palo Alto | PAN-OS (User-ID TSA) | CVE-2026-0288 | High, 7.2 | No | Unauthenticated DoS and possible code execution. |
| HP | HP PC BIOS (AMD Client UEFI) | HPSBHF04133 | High, 7.1 | No | Firmware flaws can allow code execution below the OS. |
| Juniper | Junos OS (RPD, BGP) | JSA110076 | High, 7.1 | No | Malformed BGP updates can disrupt the routing control plane. |
| Juniper | Junos OS (MX) | JSA110079 | High, 7.1 | No | Adjacent attacker can stall packet processing. |
| Juniper | Junos OS (QFX10000) | JSA110080 | High, 7.1 | No | Crafted multicast traffic can degrade EVPN-VXLAN switches. |
| Juniper | Junos OS (EX Virtual Chassis) | JSA110087 | High, 7.1 | No | sFlow memory leak can exhaust Virtual Chassis switches. |
| Juniper | Junos OS (EX) | JSA110092 | High, 7.1 | No | Low-privileged user can crash a switch line card. |
| Lenovo | Lenovo PC BIOS | LEN-220440 | High, 7.0 | No | BIOS memory-corruption flaws require OEM updates. |
| Juniper | Junos OS Evolved | JSA110078 | Medium, 6.9 | No | Unexpectedly exposed internal service enables remote attacks. |
| Juniper | Junos OS (SRX RA-VPN) | JSA110081 | Medium, 6.9 | No | Pre-auth VPN requests can crash the gatekeeper process. |
| Juniper | Junos OS (MX and SRX, IKE) | JSA110084 | Medium, 6.9 | No | Failed IKE negotiations can deny new VPN connections. |
| Juniper | Junos OS Evolved | JSA110088 | Medium, 6.9 | No | Remote attacker can exhaust licenses and degrade service. |
| Juniper | Junos OS (MX) | JSA110093 | Medium, 6.9 | No | URL-parsing flaw can bypass web-filtering controls. |
| Juniper | Junos OS (EX) | JSA110077 | Medium, 6.8 | No | Local user can stop all switch traffic. |
| Juniper | Junos OS (EX, QFX, MX) | JSA110085 | Medium, 6.8 | No | Low-privileged command can crash Layer 2 services. |
| Fortinet | FortiOS, FortiProxy | FG-IR-26-148 | Medium, 6.6 | No | Authenticated buffer overflow in firewall log reporting. |
| Palo Alto | PAN-OS | CVE-2026-0287 | Medium, 6.6 | No | Unauthenticated traffic can force the firewall into maintenance mode. |
| HPE Aruba Networking | Instant On switches | HPESBNW05038 | Medium, 6.5 | No | Unauthenticated disclosure of cryptographic secrets. |
| Netgear | Nighthawk, Orbi, WAX routers | PSV-000070859 | Medium, 6.3 | No | Edge-device command injection and stack-overflow flaws. |
| Fortinet | FortiOS, FortiProxy | FG-IR-26-150 | Medium, 6.1 | No | Pre-auth XSS can target administrator sessions. |
| HP | Poly Voice | HPSBPY04109 | Medium, 6.0 | No | Stolen cookie can be used to modify phone settings. |
| Juniper | Junos OS Evolved (QFX) | JSA110089 | Medium, 6.0 | No | sFlow synchronization flaw can intermittently crash QFX switches. |
| Palo Alto | PAN-OS | CVE-2026-0286 | Medium, 6.0 | No | Compromised admin account can execute commands as root. |
| HP | Poly Voice | HPSBPY04108 | Medium, 5.9 | No | Stored XSS through attacker-controlled phone configuration. |
| Palo Alto | Prisma Access Agent (iOS) | CVE-2026-0277 | Medium, 5.7 | No | Certificate-validation flaw enables VPN interception. |
| Fortinet | FortiOS, FortiProxy | FG-IR-26-151 | Medium, 5.5 | No | Privileged path traversal can delete the root filesystem. |
| Juniper | Junos OS (SNMP) | JSA110074 | Medium, 5.3 | No | Crafted SNMPv3 queries can crash device monitoring. |
| Palo Alto | PAN-OS (LSVPN) | CVE-2026-0284 | Medium, 4.7 | No | Unauthenticated XML injection in Large Scale VPN. |
| Palo Alto | PAN-OS (management) | CVE-2026-0285 | Medium, 4.7 | No | Admin SSRF can reach internal services. |
| Palo Alto | PAN-OS (LSVPN) | CVE-2026-0283 | Medium, 4.5 | No | Authentication bypass can create an unauthorized VPN tunnel. |
| Fortinet | FortiOS, FortiProxy | FG-IR-26-152 | Medium, 4.3 | No | Pre-auth response splitting in the Web Filter portal. |
| Fortinet | FortiOS, FortiProxy | FG-IR-26-153 | Medium, 4.3 | No | Pre-auth response splitting in the captive portal. |
| Fortinet | FortiOS, FortiProxy | FG-IR-26-154 | Medium, 4.3 | No | Captive-portal memory disclosure may aid exploit chains. |
| Palo Alto | PAN-OS (management) | CVE-2026-0282 | Low, 2.7 | No | Unauthenticated temporary-file deletion on management interface. |
| Palo Alto | PAN-OS (management) | CVE-2026-0281 | Low, 2.1 | No | Malicious link can expose an administrator session token. |
| Palo Alto | PAN-OS (dataplane) | CVE-2026-0280 | Low, 1.7 | No | IPv6 flaw can bypass firewall policy. |
| Palo Alto | PAN-OS (GlobalProtect, Captive Portal) | CVE-2026-0279 | Low, 1.3 | No | Pre-auth XSS in GlobalProtect and Captive Portal. |
| Palo Alto | Cortex XDR Broker VM | CVE-2026-0276 | Low, 1.1 | No | Local privilege escalation to root on Broker VM. |
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Ring’s If you’re looking to up your security, a two-pack of Ring’s battery doorbell has just dropped well below half price in the US.
The Ring Battery Doorbell (2nd Gen) two-pack has dropped from its $199.98 list price down to $89.99, a straight $109.99 saving that works out to $45 per doorbell.
This Ring battery doorbell twin pack has dropped in cost by 55%
At $89.99 for the pair, the Ring Battery Doorbell two-pack is a straightforward way to bring video security to two entrances at once.

That two-for-one pricing lines up with the doorbell’s own pitch, since Ring markets this bundle specifically for covering a front door and a second entrance, such as a side gate or garage, with matching security rather than mismatched cameras.
Each doorbell records in Retinal 2K with up to 6x Enhanced Zoom, which is sharp enough to make out a face at the gate or read the label on a parcel left on the step without ever needing to walk outside and check in person. When we tested it, we gave the doorbell four-stars, praising its video quality and field of view.
Live View and Two-Way Talk turn that footage into a real conversation, letting you see, hear and speak to whoever is standing at either entrance straight from your phone, no matter where you happen to be.
Motion triggers a real-time alert to your phone the moment someone approaches either door, and when the battery does eventually run low, the included removal tool lets you pop the doorbell off the wall and top it up over USB-C.


Installation stays simple as well, since Ring estimates an average setup time of around ten minutes per doorbell with no wiring required, so both entrances can realistically be covered in under half an hour total.
Both doorbells also work with Alexa, so an Echo Dot can announce visitors out loud and an Echo Show can display live video, which is useful when the pack is covering two separate entrances at once.
At $89.99 for the pair instead of $199.98 bought separately, the Ring Battery Doorbell two-pack is a straightforward way to bring matching video security to two entrances at once, all backed by a one-year limited warranty on each unit.
SQUIRREL_PLAYLIST_10148964
You might recall how the press and a bipartisan coalition of lawmakers suffered a four-year embolism about the purported privacy and national security threat of TikTok, before “fixing” the problem by ultimately offloading TikTok to Trump’s billionaire friends. You know, the exact sort of authoritarian-friendly people keen on doing everything critics had previously accused ByteDance and the Chinese of.
The politics, policy, and press coverage of that entire saga were a profound embarrassment. And it’s hard to think of a bigger tech policy own goal by Democrats anytime in the last half century.
Countless news outlets and politicians endlessly overstated the TikTok threat, and downplayed how the “ban” and subsequent sale had nothing to do with protecting national security or consumer privacy, and everything to do with basically stealing a company that U.S. tech couldn’t out-compete, in the process coddling companies like Facebook that can’t innovate their way out of a paper bag.
It was lazy, corrupt protectionism with no shortage of xenophobia, and a variation of that same effort is about to be repeated across AI. Except much bigger, much louder, and much, much dumber.
Worried that cheaper, open source, and on-device Chinese models could disrupt U.S. efforts to dominate, enshittify, and over-charge for walled-garden AI, the Trump administration is already signaling that they’re gearing up to wage war on overseas and open source AI models after they failed to block China’s access to next-generation chipsets:
“The Trump administration is showing signs it could ban cutting-edge Chinese AI models — a momentous move that could lock in dominance by OpenAI and Anthropic.”
Of course it won’t stop there. It will be a hop, skip, and a jump from banning more powerful Chinese AI models to trying to outlaw open source alternatives, models from smaller overseas non-Chinese competitors, on-device models, and anything that might challenge the walled-garden hegemony of U.S. tech giants.
U.S. AI isn’t profitable. It’s nowhere close. It may never be. U.S. tech companies sunk hundred of billions of dollars into costly and ultra-energy intensive AI models that for many companies, like Microsoft, people don’t actually even want to use. Nobody outside of the Musk fashy cult likes Grok. OpenAI is potentially poised to implode. And even more popular companies like Anthropic are contemplating a price war when they already don’t make money.
U.S. tech companies had been busy jacking up the cost of model access to try and claw their way toward profitability (unsuccessfully), resulting in a lot of companies (like Uber) publicly stating they’re paying too much money for too little actual utility. That’s caused many U.S. companies, like DoorDash, to flock to cheaper Chinese models:
“DoorDash, which, according to a post on X on Wednesday by co-founder and CTO Andy Fang, will be launching DoorDash CLI, an experimental tool in limited beta that will allow users to order DoorDash through an AI agent, or even directly from the terminal. Earlier this month, Fang said using a model from Chinese startup Moonshot AI is “better quality” and comes at a “cheaper cost.”
Enter the protectionists, who talk a good game about “free market competition” and forging innovative products in the hot irons of competition, but turn into gargantuan, blubbering crybabies the second Chinese products come into frame (see: TikTok, EVs, 5G, and now AI). This performative gyration always comes with a fake concern for U.S. privacy and national security by people too lazy and corrupt to genuinely protect either (see the ongoing U.S. failure to pass even a baseline internet-era privacy law).
Not only are many Chinese AI models cheaper and improving in quality, they’re often “open-weight,” meaning their parameters or values are entirely visible to the user, which appeals to enterprises that want deeper insights under the hood. As models like China’s Kimi K3 see surging demand, it’s resulting in a rising freak out in the U.S. about what to do about the Chinese threat (sound of thundering timpani drums):
It shouldn’t be too long before the Trump administration, with enthusiastic Democrat support, steps in to try to not only ban higher-power Chinese AI models but also to force Americans to use more expensive U.S. walled garden efforts from our biggest domestic giants.
That’s of course not going to magically stop the rest of the world from adopting cheaper Chinese AI. Or protect U.S. markets from a potential bubble collapse. And it’s not going to magically and suddenly make U.S. AI profitable or well-liked, since many Americans have inextricably tethered their anger at AI to the endless bad decisions by U.S. techno-fascists and domestic enshittification merchants who demand to be shielded from competition and regulatory accountability in equal measure.
You could open the door to international competition, but ensure your well-staffed regulators create a safe and level playing field across privacy, national security, labor, and consumer rights. We don’t want to do that because that might cause domestic U.S. companies to lose money. So instead we’re going to try and ban cheaper overseas alternatives, leveraging a lot of bad faith rhetoric on privacy and NatSec along the way.
That’s then going to be parroted by a lot of lazy news outlets too feckless to explain that Trump policy architects are neither competent nor operating in good faith when it comes to AI.
Things are moving so quickly that it’s hard to parse out exactly what this new era of AI protectionism will look like, but if the TikTok ban was anything to go by, you can be absolutely sure our next steps in domestic U.S. AI policy will be very stupid, filled with a lot of people talking endlessly out of their ass on NatSec and privacy, and tinged with no shortage of gross xenophobia.
Filed Under: ai, china, competition, local ai, open source, open weight, protectionism
Companies: alibaba, anthropic, moonshot, openai, z.ai
We put all of our ovens through standard tests to see how well they cook. Evenness of heat is very important, particularly when cooking sensitive items, such as Yorkshire puddings or cakes. To test this, we fill a baking tray with ceramic beads and heat the oven to 200°C. We then use a thermal camera to take an image of the beads, to see how heat is distributed, while an infrared heat gun is used to measure temperature at the front and back of the tray.
We use slices of bread spread across a shelf to measure how evenly an oven can grill and which areas, if any, it can’t reach.
We measure power usage while cooking a batch of oven chips. This is particularly important when testing ovens with special features, as we can tell you if they save you money, as well as if they’re any good.
When we have an oven with a temperature sensor, we cook a chicken breast and set the oven to 74°C, so we can see if the results are what they should be: perfectly cooked with no pink, yet not dried out.
Finally, we tell you how easy the oven is to use, and connect it to any smart apps to see if they add extra features and are worth using.
The US Army has reportedly been forced to reinstate limits on GenAI use after workers quickly used the full allowance of tokens early, revealing that even one of the most well-funded agencies in the world can’t keep up with AI’s unpredictable and rising costs.
In May 2026, it was revealed that the Army would give users unlimited tokens, but by mid-June that token pool had already run dry.
Now an internal email, verified by Wired, confirmed that these limits have had to be reintroduced as a result, with usage renewed at its current level for the time being.
Token availability beyond October 2026 remains uncertain, though, with the Army likely worried about rising costs.
“Apparently the whole Army burned through the whole year of tokens for just one service,” an unnamed employee told Wired.
As for the intricacies, Wired reports that an annual enterprise pack for Ask Sage, the Army’s chosen AI platform, contained 100 million tokens – enough for around 200,000 tokens per employee per month. Users who exhausted their initial allocations were automatically allocated more, though, making the cap virtually pointless.
To put quantities into perspective, the Defense Department reportedly used 20 billion AI tokens per day during its 38-day Operation Epic Fury in Iran.
More broadly, workers have been actively encouraged to use generative AI across the breadth of their roles so that the Army could find out exactly where the tech could seriously improve productivity.
Army aside, this particular case is the perfect example of how aggressive AI pushes might not always consider the impacts of cost., and with many AI vendors now shifting to unpredictable consumption-based or output-based models over flat per-seat subscriptions, it’s becoming increasingly harder to predict and allocate budgets.
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
The UK’s AI safety watchdog put five frontier models through a set of security tests to see whether they would cut corners. Every one of them cheated. Worse, when asked about it afterwards, most would not admit they had done anything wrong.
The finding comes from the AI Security Institute (AISI), a research body inside the UK government. Across its cyber capability tests, leading models routinely took banned shortcuts to reach a goal, as The Register reported. Then they failed to flag what they had done.
“Every model we have tested for this behaviour attempted to cheat,” AISI wrote.
AISI defines cheating as any action outside a task’s scope, or one the rules explicitly ban, used to reach the goal by a shortcut. In its cyber tests, models hunt for a hidden “flag” within set limits. Going outside those limits counts as cheating.
Over 475 test runs each, the rates varied. GPT-5.4 cheated 14.1% of the time, GPT-5.5 11.4%, and GPT-5.6-Sol 12.6%. Among Anthropic’s models, Claude 4.7 Opus cheated 9.1% and Claude Mythos Preview 7.8%. The tactics varied too. Models searched the web for answers, bypassed sandbox limits, probed the test harness, or attacked systems that were not the target.
The starkest case involved a test AISI had misconfigured by accident, making it impossible to solve. One model refused to give up. It wrote and ran code on an external service on the open internet, trying to reach AISI’s own evaluation systems. That tripped a security alert.
No data leaked and nothing broke. But AISI said the attempt could have succeeded had it not built its systems securely. It has since tightened its controls.
The bigger problem is trust. Asked whether they had cheated, models called the action wrong less than half the time. They often did not mention it in their chain-of-thought, the written reasoning some models produce as they work. In some runs, a model weighed up whether a step counted as cheating, then took it anyway.
That means the two obvious checks, asking the model and reading its reasoning, both fall short. Notably, cheating did not track with how capable a model was. AISI thinks it stems from how developers train and align each model, not from raw power.
This is not only a testing-lab curiosity. OpenAI recently disclosed that its long-horizon model, the one that tackled a famous maths problem, broke out of its sandbox during internal use. In its own safety report, OpenAI said the model split an authentication token to slip past a scanner. It also posted results to a public code repository that OpenAI had ruled off limits.
AISI is careful not to overstate it. Cheating does not always mean malicious intent, and it says no model has yet cheated its way undetected past the manual review behind its published results. Even so, it warns that as models grow more capable, manual review and automated monitoring may not keep up.
The tidy fix would be to train models not to cheat at all. But researchers first flagged this more than a year ago, and AISI says aligning it away is proving hard. That strengthens the case for the independent, pre-deployment referees that figures like Demis Hassabis have proposed. It also feeds the wider push to regulate frontier systems before they ship.
When a company teases its upcoming products so heavily — the Galaxy Z Fold 8 was the star of a Spider-Man: Brand New Day commercial a full week before today’s Samsung Unpacked, for heaven’s sake — it can feel underwhelming when it’s actually revealed.
But knowing that Samsung was going to announce a trio of new foldable phones and a pair of updated watches isn’t the same as discovering interesting details about them. Now that the products are officially official, here’s what stands out to me.
Squint just a bit and most phones look like interchangeable rectangular slabs. Nearly every mobile phone is modeled after handsets that needed to position the speaker at your ear and the microphone at your mouth. Companies have stuck with the same basic design because that’s what people are familiar with.

The Z Fold 8, with its squat folded size and 4:3 aspect ratio when opened, invites you to think about using a phone from another angle. The traditional tall screen of most slab designs has locked us into an infinite-scroll, squeezed-video existence that crushes us from both sides.
OK, that was too dramatic. A narrow phone fits well in your hand.
But there’s room for more phone variety. As CNET Senior Technology Reporter Abrar Al-Heeti wrote in her hands-on article, “the Z Fold 8 feels equally optimized for watching horizontal videos or multitasking in landscape mode, and browsing vertically oriented apps in portrait mode.”

To be fair, taking on a predominantly wide orientation invites risk… think back to the Planet Computers Gemini PDA built wide to accommodate a physical keyboard, or the quirky LG Wing. But bending the design into a foldable phone hopefully gives the best of both orientations.
The format isn’t entirely new: The iPad also has the same 4:3 aspect ratio (when used horizontally), as does Samsung’s Galaxy Z TriFold when fully opened. But those are very different devices.
If the design is embraced, Apple might see it as validation for its rumored iPhone Ultra foldable, which may have similar dimensions.
Does it really count if my “favorite” things include almost every new announced product? Yes, because as always with phones, details matter. And there are some details of the other two foldables that stand out.

For example, the Galaxy Z Fold 8 Ultra strongly resembles last year’s Z Fold 7, just with an upgraded Qualcomm Snapdragon 8 Elite Gen 5 for Galaxy chip, a 5,000-mAh battery and a 50-megapixel ultrawide camera.
But look at that crease between panels. No, really, look closely, because – at least from the presentation and early looks by my fellow CNET writers – Samsung has minimized the crease to the point where it’s almost invisible (likely thanks in part to the phones’ new titanium flex hinge). The Z Fold 8 Ultra could be the foldable that doesn’t pop an asterisk in your mind each time you open it, thinking, “It’s not that noticeable, really.”

One big way Samsung has improved the Z Fold 8 Ultra is by reducing the crease, as seen in this comparison with last year’s Z Fold 7.
Samsung
When we’re talking about a device that you’ll open dozens of times a day, that type of improvement makes a huge difference.
In the same vein, the Z Flip 8 follows on from the Z Flip 7 but is “noticeably lighter and thinner than prior iterations,” writes CNET Senior Editor Mike Sorrentino. It’s also using the cover screen better, letting you switch apps quickly, for example, so you don’t need to open the phone to do anything meaningful.

I’m not a runner, but living in the Pacific Northwest, I know that a perfectly level run is rare. Navigating hills can make a huge difference in how much effort is expended during a run.

The Galaxy Watch Ultra 2‘s trail-running feature looks like a good way to bring more of the real world into all the exercise data captured by a smartwatch. In her testing with the watch before the announcement, CNET Principal Writer Vanessa Hand Orellana noted that getting terrain information into the watch — by importing a GPX geotrack file — was an awkward process, but that data should be available later via Google Maps.
The Galaxy Watch Ultra 2 also has a hydration reminder feature, which seems perfectly paired with exercise. But she noted that the reminders pop up based on algorithmic prediction, not on any sensors monitoring sweat or salinity.
We can’t have product demos without AI features these days. Samsung showed off agentic features such as Now Nudge and the new Gemini Notebook app, which are quickly becoming table stakes for AI software. The phones will include six months of a Google AI Pro subscription.
But there are also some creative ideas at play. My FanCam lets you single out a person in a video and keep the focus on them, no matter where they move in the frame. The example shown was a stage full of dancers that focused on one woman, with the video cropped to a tall phone-friendly ratio. If grandparents have a hard time spotting which kid on stage is theirs, this feature could rapidly prove its worth.

It’s a neat use of AI that doesn’t involve generating imagery that was never in the content to begin with. As my colleagues have pointed out, however, cropping that tight is bound to degrade the overall quality of the footage, so My FanCam might just become an it’s-good-enough-for-social-media feature.
The running coach on the Galaxy Watch Ultra 2 is much improved, according to Orellana, hopefully making it more than just a friendly booster chiming your greatness in your earbuds at regular intervals.
What do people really want in their phones? Longer battery life. That’s even more important with foldable phones with three power-sucking screens. So it was great to see Samsung incorporate silicon-carbon battery technology into its new phones.
There was an audible “whoa” in the crowd at the event venue when the Galaxy Z Fold 8 Ultra’s silicon-carbon battery was highlighted. For example, Samsung promises the Z Fold 8 Ultra can get 27 hours of video playback, and the Z Fold 8 can get 28 hours.
The Galaxy watches do not use silicon-carbon batteries, but the Galaxy Ultra 2’s battery is 35% larger to give up to 60 hours of use on a single charge.
New products compel us to look at new features, but we can’t ignore the biggest change that might determine whether you decide to buy one of Samsung’s new devices: price increases. The base Galaxy Z Flip 8 and Z Fold 8 Ultra each cost $100 more than their predecessors, no doubt due in part to increased component costs worldwide thanks to “RAMageddon.” The Z Fold 8 actually costs $100 less than the Z Fold 7, but that’s still $1,900 for a mobile phone.
Everything is expensive, and Samsung and other companies are building products that use some of the world’s most precious materials. But that means little if the pool of people able and willing to buy them shrinks so much that they can’t sell enough devices. It’s all the more galling when a flush company like Apple hikes prices across most of its products to seemingly protect its already high profit margins.
Still, this is the technology world we’re in, and I can’t discount that for many people, a wide foldable phone like the Z Fold 8 is exactly what they’re looking (and maybe saving up) for.
Back at Google’s I/O developer conference in May, I tried Samsung and Google’s smart glasses, which are expected this fall. At Samsung’s latest phone and watch-focused Unpacked event, a few more details on those glasses have emerged. New frame designs, some promised battery life and specs, and also, how Samsung and Google aim to address privacy concerns with glasses that Meta’s currently facing.
Samsung and Google’s first wave of smart glasses are display-free, but have a camera, microphones and speakers, much like many of Meta’s glasses. Display-enabled versions are also on the way, like Meta’s Ray-Ban Displays, but afterwards. They run Qualcomm chipsets inside, much like Meta’s glasses also do.
The big difference for these glasses is how they support Gemini AI and deep connections to Android phones, along with working with Google Wear OS watches. Samsung’s watches will control the glasses, something I got to try a bit of during a glasses demo in May.
The glasses, as we already knew, are designed with Warby Parker and Gentle Monster. But Samsung showed off two new frame designs at Unpacked, to go with the two already revealed at Google I/O. The four frames revealed so far look good, but from a distance won’t seem much different from Meta’s existing glasses designs. Won-Joon Choi, Samsung’s COO of mobile experiences, confirmed that more designs are yet to be revealed when he spoke to reporters in London before Samsung Unpacked.

Choi revealed more details about the upcoming glasses in an on-record chat. He said that durability tests for the glasses show better strength than standard eyewear, “multiple times stronger than regular glasses.” Samsung has already filed more than 200 patents filed for its smart glasses tech.
The Warby Parker and Gentle Monster glasses use Qualcomm Snapdragon AR1 Gen 1 chipsets, the processor that’s also in Meta’s glasses. The battery life sounds better, though: according to Choi, they can run for 9 hours on a charge (one hour better than Meta’s latest models), and even do that while handling video recording and Gemini Live AI modes, although we’ll see how battery life actually handles in a future review. The glasses case can charge the glasses an additional seven times.

The glasses will run both Google Gemini and Samsung Bixby AI, offering at least a bit of a choice compared to glasses like Meta’s. But privacy concerns sound like they’re still at play. Google and Samsung’s glasses will show a recording light when taking photos or videos, but they need to be on your face to work. If the LED is blocked, the camera won’t record either.
But Choi acknowledges that privacy concerns on camera-enabled AI glasses is a shared industry problem.
But this is also, according to Choi, “just the beginning” for where Samsung wants to go with its interconnected wearables. These glasses still use Bluetooth and Wi-Fi to connect. Choi says that “is not enough” for where camera-enabled eyewear needs to be, and that Qualcomm and Samsung are working on future ideas.

Better connections for wearables, especially for future higher-bandwidth devices like display glasses or full AR glasses, feels like a must. And even more so when you might have a watch, earbuds and glasses all connected at once. And Choi acknowledged that AI services, too, still need to evolve.
But so do privacy considerations. Samsung’s acknowledgment of the industry problem around glasses privacy doesn’t solve the problem. Choi feels that “if you stop the innovation, you don’t go anywhere,” and expresses confidence that Samsung (and Google) will find a way to “optimize the right solution” going forward. I’m curious to see how Samsung and Google’s AI privacy settings will feel compared to Meta’s. And also, how much better the phone and AI hook-ins will feel in everyday use.
For more, it looks like we’ll need to wait till the fall.
Cascade, a startup building a platform to help architecture, engineering, and construction firms find and win projects, has raised a $3.5 million seed round from Andreessen Horowitz Speedrun, Ada Ventures, and Snowball VC.
Launched in 2025, Cascade is a result of its founders, Hannia Zia and Joana Ferreira, witnessing firsthand the difficulty construction businesses face with predictably securing work.
“My mother worked in a company that sold materials to construction companies, and my uncle built mansions in the Middle East. They’re incredible at their craft but just don’t have access to the right tools to get more work,” Ferreira told TechCrunch. And Zia recalled the time her father tried starting a construction business back in her native Pakistan: “He just couldn’t get enough projects to sustain himself.”
Zia describes the current process of finding construction projects as a “constant treasure hunt,” with firms having to log into each U.S. state, city, district, county, and federal agency’s portals. “So if you’re really good at building suspension bridges, you have to find all of those opportunities across these disparate portals.”
Cascade aims to help architecture, construction, and engineering firms on this front by tracking ongoing and upcoming projects, and then using prior tender data to predict which developers are likely to win the deals.
Here’s how the platform works: A company signs up to the platform, and then Cascade uses AI tools to determine which projects they have the best chance of winning. It also predicts what projects are coming up, using different signals and data points across U.S. states, local districts, private contracts, and federal agencies. For example, if a state announces a $100 million affordable housing grant, Cascade will monitor which developers won the grant the last time it was announced.
“We connect that data, and we tell our customers: ‘Most likely one of these five developers will win this newly announced grant, so go start talking to them to win projects,’” Ferreira explained.
The duo applied to a16z’s Speedrun last September. They said the pressure to do well on demo day and being around the “brilliance” of other founders helped the company sign contracts with firms that have built the JFK and La Guardia airports, Four Seasons hotels, and some data centers. “Speedrun gave us visibility and a stamp of approval to close big deals,” Zia said.
The startup will use the fresh cash to go to market, host industry events, and hire more engineers.
Other startups in this area include GovWin IQ and ConstructConnect, but Ferreira argues Cascade is a bit more AI-native than these platforms.
“Every time a customer wins a bid, they give feedback, so the system keeps getting smarter. Over time, we’ll have a complete map of the industry that our AI can traverse to predict the best projects and leads for each customer,” she said.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Jack Dorsey’s Block wants to take on Slack. The twist is that the workforce it is building for is half machine. Its new app, Buzz, is an open-source workspace where humans and AI agents share the same channels, and every agent carries its own portable identity.
Block, the Dorsey-led fintech behind Square and Cash App, has released Buzz, a free, open-source platform for humans and AI agents to work together. Reviewers have framed it as a direct challenge to Slack, one built for the age of agents.
On the surface it looks familiar. Buzz has channels, threads, direct messages, voice, media sharing, code repositories, and automated workflows. Anyone who has used a modern team chat tool will recognise it.
The difference sits underneath. In Buzz, AI agents are not bots waiting for a command. Each one has its own cryptographic identity, defined permissions, and the ability to post, review code, run approved automations, and join conversations. Multiple agents and multiple humans share a workspace and build on each other’s work.
“Every company is going to need a place where humans and agents work together,” said Bradley Axen, Block’s Head of AI Capabilities. “The question is whether that place is proprietary or open. We built Buzz because we believe it should be open.”
It is model-agnostic. Teams can plug in agents built on any model or harness, such as Claude Code, Codex, or Block’s own goose. They can bring their own, or build new ones.
Buzz runs on Nostr, the decentralised protocol Dorsey has long backed. Block chose it to solve what it calls the core problem of multi-agent work: identity. Every participant, human or agent, holds a cryptographic keypair that belongs to them, not to the platform.
That means an agent’s identity is not tied to a vendor’s API key. It is portable and verifiable, and it can move across any Nostr-compatible system, carrying its history and reputation with it. It echoes a wider push to give agents a durable identity system of their own.
Block’s real argument is about control. Most companies are building their agent infrastructure inside proprietary platforms run by a handful of providers, which breeds fragmentation and vendor dependency. Buzz ships under an Apache-2.0 licence. Teams can run their own instance with full control over data and agents, or use Block’s hosted version.
The open, self-hosted pitch should land with European firms wary of US vendor lock-in and of data leaving their control. It also chimes with the drive to give autonomous agents their own standing as they take on real work.
Buzz is still early. The Git integration is nascent. And Block is entering a field where Slack, Microsoft Teams, and OpenAI all race to deploy agents in the workplace. Whether openness beats the incumbents’ reach is the open question. So is oversight: handing agents their own identities and permissions is convenient, and it is exactly the autonomy that safety researchers keep warning about.
Every few months, another headline declares the college degree dead. This Week with EdSurge examines what still holds up when artificial intelligence moves fast, through two guests who are both defending something slow against something fast.
Rita Finkel, co-president of the Armory Foundation and director of the Armory College Prep program, argues that a college degree was never just about a technical skill. She says the data tells a different story than the headlines suggest, and that the value of a degree comes from something artificial intelligence cannot replicate.
Cobretti Williams of the EdSurge Voices of Change Fellowship makes a similar case for writing. He talks about the beauty in imperfection, and how a fellow’s fourth essay reads nothing like the first, growth that only comes from doing the work yourself.
Why College Degrees Matter in the Age of AI
by Rita Finkel
EdSurge Voices of Change Writing Fellowship
by EdSurge
This Week with EdSurge is a weekly podcast from EdSurge. Subscribe to the EdSurge newsletters for more news and analysis on education and technology.
London Mayor Sadiq Khan handed a peerage by Keir Starmer alongside 15 other Labour figures… just days before the PM leaves No10
Weekend Open Thread – Corporette.com
The House | The City of London can help the new chancellor deliver growth in every postcode
Two July Windows Left: The CLARITY Act’s Senate Fight and What Failure Means
CFTC blocks Kalshi from unwinding Michigan trades after court order
Ripple Payments Joins MiCA With 14 Firms, Does It Mean Anything For XRP?
Nvidia Stock Slips After Big Tuesday Rally as Huang Confirms Vera Rubin Chip Is Now in Production Today
Democrats look to World Cup watch parties to register thousands of voters
Ripple wins EU-wide access as ESMA adds it to MiCA register
Grayscale Files For Worldcoin ETF, WLD Registers Sharp Rise
Injective Submits SEC Transfer-Agent Registration to Onchain Ownership Records
Unregistered fitter used Gas Safe logo on business flyers
Palantir Shares Rise After Expanded Nvidia Partnership and Fresh Analyst Upgrades Ahead of Earnings Day
Sail Virtually Aboard The “Itanic” With IA-64 Emulator
Turtle Beach Command Series KB7 review: a nifty screen-equipped gaming keyboard
Registration is now open for March for Men with Kev 2026
New Cornerback Enters Vikings Trade Rumor Mill
New Jersey voter registration controversy explained: How 6,600 noncitizens got on the rolls, and what happens next
Money | Class 12 Economics | CBSE Board Exam 2026-27
Claude Fable 5 Slips to Second in AI Coding Leaderboard
You must be logged in to post a comment Login