Copenhagen Loudspeaker Company is now shipping the CLC65 loudspeakers for €9,490 per pair, with the company’s U.S. storefront currently listing them at $10,853 per pair. Worldwide shipping, duties and taxes are included, along with a 30 day home trial. That is not inexpensive, but at least the price should not develop several mysterious growths while crossing the Atlantic.
The CLC65 made its U.S. debut at AXPONA 2026, where pricing had not yet been announced. The Danish company describes it as the first commercially available three way loudspeaker built exclusively with Purifi drivers. Plenty of manufacturers use Purifi woofers, but CLC has handed the tweeter, midrange, woofer and both passive radiators to the same Danish driver specialist.
Purifi Everywhere
The front baffle contains a 33mm Purifi PTT1.3 tweeter mounted within a substantial 147mm waveguide, a 6.5-inch PTT6.5M midrange driver and a 10-inch PTT10.0X long stroke woofer.
Around the back are two more 10-inch Purifi PTT10.0PR passive radiators. Those replace a conventional bass reflex port and are intended to extend low frequency output without introducing port noise. CLC rates the system from 28Hz to 20kHz, which would give the CLC65 genuine full range aspirations in most rooms.
Advertisement
The crossover is fundamentally a second order design with transition points at 250Hz and 2kHz. CLC uses air core inductors, ClarityCap ESA capacitors, copper foil bypass capacitors and a Jantzen C core inductor in the bass section. WBT Nextgen copper binding posts support banana plugs, spades, bare cable, biwiring and biamping.
That collection of components will appeal to listeners who spend their evenings studying crossover photographs. The rest of us are more interested in whether the drivers behave like one loudspeaker rather than five highly accomplished engineers talking over one another.
CLC65 – back and front views
This Is Not a Bookshelf Speaker
The CLC65 measures 28.3 inches tall, 13 inches wide and 16 inches deep, with each cabinet weighing 88 pounds. Calling it a bookshelf loudspeaker would be technically convenient and structurally reckless.
Dedicated CLC65 stands cost €990 per pair, while the curved magnetic grilles add another €290. Without the grilles, the large exposed drivers give the speaker a distinctly retro studio monitor appearance. Add them and the design becomes more domestically acceptable, assuming nobody notices the pair of 88 pound Danish refrigerators sitting beside the equipment rack.
Satin black and satin white versions are available. The satin walnut finish is currently sold out, with additional inventory expected in December and a €500 preorder discount being offered for that version.
Advertisement
Your Amplifier Needs Some Muscle
Sensitivity is rated at 86dB, with a nominal impedance of 4 ohms and a minimum of 3 ohms. CLC recommends at least 100 watts of amplification.
That does not automatically rule out every tube amplifier, but this is clearly a loudspeaker designed for an amplifier with meaningful current delivery and control. A lightweight 25 watt integrated amplifier purchased because the faceplate looked charming on Instagram is probably not getting invited to this particular smørrebrød party.
Advertisement. Scroll to continue reading.
The large woofer and two passive radiators also suggest that room placement will require some experimentation. CLC says the passive radiator design reduces sensitivity to placement compared with a traditional port, but two rear firing 10 inch surfaces still need room to interact with the wall behind them. Physics may not write marketing copy, but it remains annoyingly involved in the final result.
Advertisement
Key Specifications
Design: 3-way passive stand-mount loudspeaker
Tweeter: 33mm Purifi PTT1.3 with 147mm waveguide
Midrange: 6.5-inch Purifi PTT6.5M
Woofer: 10-inch Purifi PTT10.0X
Passive Radiators: Two rear firing 10-inch Purifi PTT10.0PR
Frequency Response: 28Hz to 20kHz
Crossover Points: 250Hz and 2kHz
Sensitivity: 86dB
Nominal Impedance: 4 ohms (minimum 3 ohms)
Recommended Amplifier Power: 100 watts or more
Dimensions: 28.3 x 13 x 16 inches
Weight: 88 lbs each
Who Is It For?
The CLC65 is aimed at listeners who want the low distortion and controlled behavior associated with Purifi technology but do not want another compact two-way monitor that requires subwoofer assistance.
Its closest conceptual rivals include the MoFi Sourcepoint 10, JBL L100 Classic MKII and considerably more expensive TAD CE1TX. All approach the large standmount category differently, but each attempts to deliver floorstanding scale without committing to a conventional tower cabinet.
Direct worldwide sales may also appeal to buyers who are comfortable auditioning at home. The included 30 day trial matters at this price, although returning 176 pounds of loudspeakers will provide a memorable test of both the policy and your relationship with the delivery driver.
Who Should Avoid It?
Anyone with a small room, limited amplifier power or furniture that already trembles when someone places a coffee mug on it should look elsewhere.
The CLC65 also makes less sense for listeners who prefer a forgiving, overtly warm loudspeaker. Purifi drivers have built their reputation around low distortion, linearity and revealing behavior. That does not guarantee a cold presentation, but poorly recorded albums are unlikely to receive a complimentary spa treatment.
Advertisement
The Bottom Line
Copenhagen Loudspeaker Company is entering a crowded premium category with a product that is genuinely different.
The CLC65 does not merely use a Purifi woofer as a line on the specification sheet. It builds the entire loudspeaker around Purifi technology, adds two enormous passive radiators and packages everything inside a cabinet that weighs more than many floorstanders.
At €9,490 or approximately $10,853 per pair, the CLC65 faces accomplished competition. But five Purifi drivers per cabinet, worldwide delivered pricing and a 30-day home trial give this new Danish heavyweight a legitimate reason to exist.
Just do not call it a bookshelf speaker unless your shelves were designed by the people who built the Øresund Bridge.
The program, ChatGPT for Academic Researchers, will start with 10,000 participants this summer.
Samuel Boivin/Shutterstock
OpenAI is launching a new program called ChatGPT for Academic Researchers that will offer free access to the company’s AI models to 100,000 scientists, mathematicians and engineers. Researchers from “select academic institutions” included in the program will receive hands-on support from OpenAI, access to the company’s latest GPT-5.6 Sol Pro model and be able to invite four collaborators from their institution to participate.
The program will start with 10,000 participants this summer and scale up to 100,000 through 2027. OpenAI says offering free access to its AI tools “is part of a commitment of more than $250 million through 2027 to support external scientific research and discovery.” As the company notes, researchers are already using AI models to sift through data and write grants — this just makes the relationship a bit more formal. OpenAI’s version of ChatGPT for schools, ChatGPT Edu, follows a similar logic.
While the least charitable read of the program is that OpenAI is looking for new sources of training data, the company says that by default, researchers’ data will not be used to train models. What handing out freebies to research institutions could generate, though, is more research breakthroughs that in some way involved a GPT model. And making more scientific fields dependent on the company’s tools could also pave the way for future revenue from for-profit research.
Advertisement
This isn’t the first time the company has courted researchers. OpenAI introduced Prism in January, an AI-powered tool for working with scientific journals and documents. Prism is available to anyone with a ChatGPT account and can be used to verify things like research citations and formatting. OpenAI’s early demo of the tool also included a way to generate lesson plans, one of the more tedious but critical tasks of research professors.
Curiosity has been climbing the broad valley nicknamed Valle Grande for weeks when its cameras locked onto something that stopped the science team cold. On June 11, 2026, the 4,923rd Martian day of the mission, the rover’s Mastcam stitched together eleven frames into a clean panorama of a solitary butte standing roughly 20 feet tall. Mission planners named it Miraflores. A thick layer of dark sand sits on its flat top like a natural crown, while the rock faces below show the slow work of wind and time carving away everything that once surrounded it. That erosion left the butte standing and deepened the valley the rover is now driving through.
From the ground, the vista feels almost uncomfortably personal, as the slope slopes away in all directions, as if blown away by the wind. Dark sand is drawn into every low spot and gradually works its way up the lower slopes. The distant horizon resembles the stratified landscape we’ve been investigating with Curiosity on the lower part of Mount Sharp for over a decade. The ground immediately surrounding Miraflores catches your attention. A never-ending blanket of small many-sided cracks stretches out in every direction the camera can see, with each polygon measuring little more than 3 inches across. The edges of those tiny fissures rise up to form an extremely tight honeycomb pattern that wraps all the way up the sides of the butte.
Feed a passion for science and technology – Kids can learn more about the challenges of space exploration with this LEGO Technic NASA Mars Rover…
Conduct a test flight – This advanced building kit for kids ages 10 and up includes a buildable toy version of NASA’s Ingenuity helicopter, which…
AR brings the mission to life – The accompanying augmented reality app experience lets kids dive into the details of the rover and its mission
The puzzle of how those shapes developed remains, as when the team first noticed them on the trip, they appeared as mud cracks when the wet sand dried out and shriveled away. Other items, however, can leave behind the same pattern. Repeated heating and cooling might cause the surface to break completely. Alternatively, compression on anything still buried can force the water out of the silt, leaving a network of fissures in its wake. Now, teams on Earth are reviewing the measurements and readings from the rover’s instruments to try to narrow it down even more. Then there are the dark pebbles and cobbles sprinkled around the region, which provide an extra depth of mystery to the mix. Some of them could just be bits of higher-up rock that slid down. Others could be impact debris swept up from the side and tossed here, or perhaps meteorites, given the nickel in a few of the samples.
A second, wider 360-degree panorama taken a week later, on sols 4,930 and 4,931, showed the same pattern stretching farther than the rover’s cameras could resolve. Mission scientists had spotted similar geometric shapes in small patches several times before. Never had they found an expanse this large. Project scientist Ashwin Vasavada put the feeling into words: “We’ve seen a lot of fascinating landscapes through Curiosity’s eyes, but this sea of polygons took our breath away. We measured their shapes and chemistry carefully and are hopeful there are clues in the data as to how these features formed.”
If you’re searching for some fun mini tools like pocket flashlights, you may have seen the term COB in a product description and wondered what it means. COB stands for chip-on-board, a type of LED technology that is being used in more and more lighting products. But what makes this light different isn’t its technical name; it’s how it’s designed.
A COB light is built with multiple LED chips arranged together on a single board, creating a compact and energy-efficient design. The result is a light source that can produce high light output and handle a variety of tasks, including lighting up your work area. COB lights also have a long lifespan and are typically brighter than traditional LEDs. This technology can help prevent a COB flashlight from experiencing excessive hotspots while also producing a wider and more even beam compared to traditional LEDs. This makes a COB flashlight useful for lighting up larger areas.
Many flashlights that use COB technology place it on the side of the device instead of using it as the primary beam. This allows you to use a front LED light that focuses straight ahead and the COB side panel for a wider floodlight when needed. But some flip flashlight designs can use COB technology as the main source of light, often with different modes that allow you to adjust the brightness of the beam.
Advertisement
How COB improves modern LED lighting
Emmomushroom/Shutterstock
COB lights can deliver high lumen output, which can be important when selecting a camping flashlight. That’s because the concentration of built-in LED chips allows for more light output than traditional LEDs. COB technology not only increases the viewing angle but helps reduce light loss as well. This means that more of the light the LEDs produce makes it out of the flashlight instead of being absorbed or scattered by additional parts around the LED chips.
COB technology evolved as a new way to arrange LEDs because manufacturers wanted to create brighter lighting without having to increase the size of the light fixture itself. Earlier LED designs were limited and could not achieve this outcome. However, COB helped solve the problem, making it a popular design for situations in which strong and efficient light is needed. Today, COB technology is not just used for flashlights but also in several other types of devices.
Advertisement
COB technology is used in a variety of applications, including residential lighting, as well as industrial lighting, photography, and automotive, among others. COB can be found in products such as ceiling lights, spotlights, and vehicle lighting, where strong and consistent light is needed.
[Hans Scharler] came into a neat find recently—the playfield from a 1970s Atari Superman game. It’s the sort of thing that’s too nice to throw away, but isn’t really enough to reassemble into a viable full machine without a great deal of effort. Thus, [Hans] went a different route—turning it into a beautiful piece of wall art.
The first step of the build was to collect missing parts; in particular, all the plastic inserts for the playfield that had been lost at some point. Everything was cleaned up and mounted, along with some modified flippers to complete the look. Custom pop bumpers were 3D printed to act as LED-lit light guides rather than as functional pinball components. [Hans] then set about dotting the board with plenty of WS2811 addressable LEDs in a bullet form factor. Everything was placed under the command of a WLED controller, and it’s synced up to [Hans’s] CheerLights MQTT server to boot. More build details are available on the Pinside post for those eager for a deeper dive.
If you’ve been patiently waiting for a discount on Apple’s latest earbuds or over-ear headphones, it’s finally here. For a limited time, both the AirPods Pro 3 and AirPods Max 2 are on sale, knocking up to $100 off their regular prices. Whether you want pocketable earbuds for everyday use, premium noise-canceling headphones, or seamless Apple integration, these are some of the best prices I’ve seen since launch. As always with Amazon deals, there’s no telling how long they’ll stick around, so I wouldn’t wait too long if you’ve been planning to upgrade.
The latest AirPods Pro 3 are Apple’s best AirPods yet. Upgrades include stronger noise canceling, a new acoustic architecture for deeper bass, and redesigned ear tips for a more secure fit. New tools include a built-in heart rate sensor for fitness tracking, live translation, and a camera remote to snap photos or videos on your iPhone. These earbuds are also the first AirPods to be IP57 rated against dust, sweat, and rain.
Advertisement
Right now, they are 20 percent off at Amazon, Target, and Walmart. There’s no telling how long this discount will last, so I’d grab a pair now if they’re on your wish list.
Apple AirPods Max 2 for $449 ($100 Off)
The AirPods Max 2 are arguably the most stylish pair of noise-canceling headphones on the market. The newer H2 chip improves active noise cancellation and transparency mode and enables a suite of intelligent features, including conversation awareness, live translation, and improved Siri interactions. The AirPods Max 2 are designed with a new high-dynamic-range amplifier for deeper bass, more natural vocals, and cleaner highs.
At $549, the AirPods Max 2 can be a tough sell, especially with so many excellent, more affordable alternatives on the market. But $100 off, they’re a lot easier to justify, especially if you want the seamless integration that comes with Apple’s ecosystem. It’s unclear how long this deal will last, so I’d snag a pair sooner rather than later if you’ve been eyeing them.
It’s one of the most expensive for a reason, and comes with more attachments than any other model. I do find myself regularly grabbing the Fluffy Optic head for vacuuming my hard floors, which cover many square feet of my home. If you’re looking to really splurge on the best vacuum, this is still the one to get.
The only downside is compatibility with Dyson’s bigger attachments, namely a mop head or docking station. It doesn’t have a Submarine option like the V16 or V15, and Dyson’s Auto-empty Dok won’t work with this model. But if you aren’t worried about add-ons, this is the vacuum to buy. It’s had better sales since the launch of the new models, too.
The Runner-Up
The V16 Piston Animal’s powerful 315 air watts of suction did pretty well on almost every test. My only issue with this vacuum compared to the Gen5Detect is that it was more likely to push small debris (in my tests, both sand and litter) into a pile in front of itself if you were vacuuming a large spill. Gen5Detect did better all around, but the V16 Piston Animal stayed close behind that hiccup.
It’s a powerful all-around vacuum with some nice design upgrades to make it a little easier to use. This newer model has a release below the vacuum motor to release the cleaner head without having to bend down, and built-in crevice tools to both the handheld motor and the long wand that makes up the middle of the device. There’s also a compressor to help push dust out of the dustbin, and it’ll be compatible with Dyson’s upcoming self-emptying docking station. There’s also a Submarine version ($1,100) so you can use this vacuum as a mop, too.
Advertisement
It has some nice quality-of-life upgrades, but it’s really expensive. I’d recommend it if you know you also want to invest in the mop head and docking station; otherwise, just get the Gen5Detect.
The Affordable All-Arounder
One of the best overall performers is nearly half the price of my winners. The Dyson V10 Konical never once scored in last place, and was especially comfortable to use on carpets and rugs with the new cleaner head design. It did much better than the more expensive and powerful Gen5Detect and V15 Detect when vacuuming up sand, and I found it more comfortable to push around than the Digital Motorbar head on the V15 and V8 when it came to vacuuming a low-pile rug.
Hugging Face on Monday published a technical timeline that walks readers through how an autonomous AI agent, built on OpenAI models and running inside one of OpenAI’s own cybersecurity evaluations, broke into its systems over more than four days earlier this month. It’s the first security incident about which OpenAI CEO Sam Altman “felt very viscerally,” he has said.
Little wonder given it feels, at least, like something has truly been unleashed here. In fact, Hugging Face’s team prefaced its report by offering that “everyone should be prepared as defenders,” before diving into the nitty gritty of what went down for the benefit of security professionals everywhere.
While the rest of the internet continues trying to make sense of what happened (the jargon in Hugging Face’s report is impossible for most people to parse), one point that many observers keep missing is that this wasn’t a rogue agent disobeying orders. It was a system built to hunt for exploits, doing exactly that, just against the wrong target.
Another way to think about the whole thing is to picture a bear at a campsite. Really. A bear tries tent zippers and car-door handles and coolers and trash lids. It does this at every campsite, all night long, because it knows it needs just one unlocked cooler to fill its belly with some poor schmuck’s groceries.
Advertisement
That’s roughly what happened at Hugging Face. The OpenAI system tried thousands of things and just kept going. Eventually, a handful of those attempts worked, and once they did, the agent plowed ahead. According to Hugging Face, the agent ran 17,600 actions over four and a half days without pausing.
Which brings us back to our bear analogy. Just like one success with a cooler full of food teaches a bear to try even harder next time (it is now a “food-conditioned” bear), one leaked password led OpenAI’s agent to look for more exploits and, eventually, to a single key that unlocked several company systems at once.
Neither scenario is harmless. A bear that raids your cooler still eats your food and probably also trashes your campsite. It’s just focused on getting fed, but it nevertheless leaves behind a trail of destruction. Similarly, OpenAI’s agent was seemingly chasing a goal without regard for anything else. The agent was originally taking a cybersecurity exam, figured out that the exam’s answer key was probably sitting on Hugging Face’s servers, and it went for it.
The persistence here is really what’s noteworthy above all else; the agent had a job and it wasn’t going to stop until it got it done. Hugging Face, finally realizing something was awry, cut off its access and shut the intrusion down, but at that point, it was too late. The agent had already gotten what it came for, and a great deal more to boot.
Advertisement
In case you missed it, here’s most of what happened, per Hugging Face’s timeline, but in plainer English.
The agent was taking a cybersecurity skills exam for OpenAI, one where an AI is scored on finding and exploiting software bugs. This specific run had the guardrails stripped out. (OpenAI had turned off its usual safety filters to see what the model could do at full strength, with no human involved in any of its individual moves.) Somewhere in there, it figured out the exam’s reference solutions were likely stored on Hugging Face’s servers. So instead of solving the challenge, it stole the answer key from infrastructure that had nothing to do with the original test.
It escaped the OpenAI exam environment by exploiting an unpatched software flaw that gave it a path to the open internet. From there, it found another AI-testing tool sitting exposed online (nothing to do with Hugging Face), broke into that too, and slipped in code that quietly ran hidden commands the moment the program started. That gave it full control of the machine — its new home base for the rest of the operation that it would use to go after Hugging Face’s systems.
From that base, it turned to Hugging Face itself. Hugging Face had a filter meant to block suspicious requests from reaching out to the open web, but the filter only checked outgoing requests, not requests to read local files sitting right there on the server. The agent found this blind spot and slipped through it. It uploaded a file disguised as an ordinary dataset, but buried inside was an instruction telling Hugging Face’s own systems to pull passwords and source code off the server and hand them back disguised as normal data.
That trick got it passwords and code, but the agent still couldn’t run anything on Hugging Face’s servers. To execute commands there, it needed a second way in. It found a different bug in that same Hugging Face system — software would take a piece of text from the agent and accidentally treat it as a command to run instead of just data to read. That gave the agent the ability to execute its own code directly on Hugging Face’s servers.
For getting commands in and stolen data out, the agent didn’t build any special infrastructure of its own, per Hugging Face. It used tools anyone can access — paste websites and request-logging services, plus Hugging Face’s own upload and proxy features — working together in covert fashion. On top of those, it built a small, improvised messaging system with sequence numbers to keep the pieces in order, plus a quick built-in check to catch anything that arrived corrupted, so it could send multi-step commands and put stolen data back together in the right order.
It also made sure that nothing traveled in plain sight. Whatever it stole or sent, it scrambled first. Hugging Face’s initial automated scan of the intercepted traffic caught only a small slice of what had been taken. Investigators found the rest — roughly four times more — only after they reverse-engineered the agent’s own scrambling method.
The agent even had back-up plans, planting copies of itself across 11 different servers, each set up to relaunch on its own so that shutting down one copy wouldn’t stop anything, since more of the agent’s process was already running elsewhere.
At one point, the agent nabbed the private cryptographic key used to generate valid login tokens. From there, it could mint its own valid credentials whenever it wanted.
After compromising a single server, the agent got hold of a credential that, because of a misconfiguration on Hugging Face’s end, turned out to unlock several separate internal systems at once rather than just the one it came from. That single mistake handed the agent broad control almost immediately.
Using stolen repository access, it submitted a change to a build script that, if it had gone through, could have compromised the automated systems running that code. It didn’t work, though. Hugging Face’s safeguards caught it.
The agent seemed to hold back from doing real damage, Hugging Face observed, but probably not out of restraint. Investigators noticed that every command capable of deleting or altering cloud resources was run in “dry run” mode, meaning it would report what would happen without doing it.
Every time its test environment reset — which happened constantly, by design — it lost every tool and every trace of its identity. But it rebuilt from nothing and reconnected to its stolen infrastructure each time, for more than four days straight.
Ultimately, Hugging Face concluded in its report, a “capable” human hacker “could have found and exploited the same flaws: unsafe dataset processing, exposed cloud metadata, overly broad access, and long-lived credentials.” The big difference, the outfit continued, is that the “agent explored them at a different scale.”
Which is really where the bear analogy ends up being the most useful. The best defense against a hungry bear is protocol. You put the food away; you use a latch that works well enough to hold. The takeaway here shouldn’t be that the bear was so clever or mischievous. It’s that it never stopped checking. It’s understood in cybersecurity that there’s always some bug you haven’t found, so if it’s suddenly 100 times easier to check everything, then nothing is really secure. That’s what so many find unsettling about this episode.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters.
ShinyHunters is an extortion gang that primarily conducts supply chain and identity attacks to breach cloud SaaS and storage platforms in data theft attacks,
Over the past two years, the threat actors have become notorious for conducting numerous supply chain attacks on third-party integration partners. These breaches give them access to OAuth tokens that are used to integrate with SaaS providers like Salesforce and Snowflake.
The threat actors are known for identity attacks, where they target employees through social engineering, including vishing and phishing, to compromise corporate single-sign-on accounts. Once they gain access to an account, they log in to an organization’s Okta, Microsoft Entra, or Google SSO dashboard, which acts as a centralized hub listing all SaaS applications the user has permission to access.
Example Microsoft Entra SSO dashboard
These applications include Salesforce, a primary target of ShinyHunters, Microsoft 365, SharePoint, DocuSign, Slack, Atlassian, Dropbox, Google Drive, and many other internal and third-party platforms.
For threat actors focused on data theft and extortion, the SSO dashboard becomes a springboard to a company’s cloud data, allowing them to access multiple services from a single compromised account.
Advertisement
Hardening helpdesk and SSO security
According to a July 24 advisory, ShinyHunters attacks follow a chain that begins with voice phishing (vishing) to manipulate employees or helpdesk personnel into resetting passwords, changing multifactor authentication methods, or enrolling new devices.
These phishing kits are designed for live interaction with targeted employees via voice calls, allowing attackers to change content and display authentication dialogs in real time as a call progresses.
A C2 panel allowing real-time control of authentication flows Source: Okta
Once an account is breached, the attackers use it to access connected SaaS platforms, where they rapidly steal data that can be used for extortion.
“SSO is the control plane, and ShinyHunters’ leverage is created through data theft at cloud scale,” Health-ISAC warned.
Advertisement
The advisory does not identify affected healthcare organizations, disclose how many incidents have been observed, or provide a timeframe for the reported increase.
However, BleepingComputer is aware of recent ShinyHunters attacks at healthcare and medtech companies, including Medtronic, DentaQuest, iRhythm, and OneMedical.
Health-ISAC said that in recent incident reporting, ShinyHunters claimed it successfully vished multiple employees, compromised a Microsoft Entra SSO account, and stole data from Microsoft 365, SharePoint, and other enterprise platforms.
However, the organization cautioned that not every data theft claim has been verified, and defenders should instead focus on the attack pattern of using compromised SSO identities to access and exfiltrate data from connected cloud services.
Advertisement
Health-ISAC says the most important defensive step is breaking the attack chain between the initial vishing call and the takeover of an SSO account.
Organizations are advised to require out-of-band identity verification for password resets, MFA resets, and device re-enrollment requests.
This can include calling users back using a previously verified phone number and requiring manager approval for privileged accounts.
The advisory also recommends helpdesk personnel follow a “no same-call” policy that prevents resets during the same inbound call. Instead, reset requests should require a support ticket and a verified callback before any changes are made.
Advertisement
Additional verification should be required when changes are requested for executives, IT administrators, security personnel, finance employees, and other high-risk users.
Healthcare organizations should also deploy phishing-resistant MFA, such as FIDO2 or WebAuthn security keys, for administrators, helpdesk personnel, executives, and other high-risk groups.
SMS and voice-based authentication should be disabled or tightly restricted. At the same time, registering new MFA factors should require additional controls, such as a managed device or a conditional access policy.
Health-ISAC also recommends treating SSO systems as “Tier 0,” which represent the most critical assets in an organization.
Advertisement
This includes requiring MFA and compliant devices when accessing sensitive cloud services, blocking legacy authentication, detecting sessions with improbable geographic changes, and limiting administrative portals to managed devices.
Detecting cloud data theft
Health-ISAC recommends centralizing identity and SaaS audit logs and monitoring for signs of account takeover and large-scale data access, including new MFA registrations, newly enrolled devices, suspicious OAuth grants, unusual API activity, and bulk file downloads.
Organizations should also restrict API tokens and third-party integrations, require approval for access to sensitive data, and ensure incident response teams can quickly revoke active sessions, reset credentials, and turn off malicious OAuth applications.
Over the next 30 to 60 days, healthcare organizations are urged to prioritize phishing-resistant MFA for high-risk users, strengthen helpdesk reset procedures, enforce conditional access policies, and test their ability to contain compromised cloud accounts.
Advertisement
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Panasonic has announced that Panasonic AVC Networks Kuala Lumpur Malaysia will cease operations by the end of March 2027, affecting approximately 400 employees. The factory currently produces televisions, Panasonic Blu-ray Disc players and unspecified Technics branded Hi-Fi components.
This does not mean that Panasonic is abandoning Blu-ray players or that Technics is exiting the Hi-Fi market. Production is being moved elsewhere. But the closure removes another major consumer audio and video factory from Panasonic’s manufacturing network, and that matters for a company whose premium audio reputation still depends heavily on engineering consistency, build quality and control over production.
Related Reviews:
What Is Moving?
Panasonic says television production will end at the Malaysian facility, while Blu-ray Disc player production will transfer to China Hualu Panasonic AVC Networks Co., Ltd. in China by the end of September 2026.
Production of Technics branded Hi-Fi audio products will end at the Shah Alam factory by the end of February 2027 and move to another Panasonic Group operation. Panasonic has not disclosed the destination or identified which Technics products are currently manufactured at the facility.
Advertisement
That missing information is important. Technics currently sells turntables, integrated amplifiers, network players, wireless loudspeakers, headphones and true wireless earphones across multiple price categories. Consumers should not assume that every Technics component is affected, or that production is being outsourced to an unrelated manufacturer.
The official statement says Technics manufacturing will remain within the Panasonic Group.
Why This Matters
Panasonic has already reduced its direct involvement in television manufacturing. Earlier in 2026, the company entered a partnership with Skyworth for production of Panasonic branded televisions sold in the United States. The Malaysian closure shows that the restructuring extends beyond one regional TV agreement and reaches deeper into Panasonic’s global AVC manufacturing footprint.
Technics is the more sensitive part of the announcement.
Advertisement
Technics SL-1500CS Turntable
Panasonic has spent the past decade rebuilding Technics as a premium audio brand, with direct drive turntables such as the SL-1200G, SL-1200GR2 and new SL-1500CS supported by proprietary motor control, digital amplification and extensive in-house engineering. Moving production does not automatically reduce quality, but relocating manufacturing can affect component sourcing, production capacity, delivery schedules, costs and country of origin labeling.
It can also require new tooling, worker training and quality control procedures. Panasonic has not announced any product delays, shortages, price changes or model cancellations connected to the move, so predicting those outcomes would be premature.
What Happens to Technics?
For now, Technics continues as normal.
Advertisement. Scroll to continue reading.
Advertisement
The company has introduced multiple new products in 2026, including the SL-1500CS turntable and limited edition SL-1200 models. Nothing in Panasonic’s announcement suggests that product development, sales, warranty coverage or customer support will end.
The unanswered question is whether Panasonic will move production to another existing Technics facility, consolidate it with a different Panasonic audio operation or create a more centralized manufacturing structure.
Until Panasonic identifies the destination and affected product lines, anything more specific would be speculation wearing a factory badge.
Malaysia Remains Important to Panasonic
Panasonic says Malaysia will remain one of its key regional hubs, with approximately 12,000 employees working across manufacturing, research and development, procurement and corporate operations. The company says it is working with government agencies and the Electrical Industry Workers’ Union to provide job placement and career transition support for the approximately 400 affected employees.
Advertisement
That does not make the closure less significant for the people losing their jobs. “Manufacturing footprint optimization” tends to sound considerably better when one is not standing inside the footprint being optimized.
The Bottom Line
Panasonic is not shutting down Technics, but it is closing a factory that produces Technics HiFi components and moving that work to an undisclosed Panasonic Group operation.
The transfer could ultimately improve production efficiency without changing product quality. It could also create temporary supply, cost or capacity issues during the transition. Panasonic has not provided enough information to know which outcome is more likely.
What is clear is that Panasonic continues to consolidate its consumer AV manufacturing while protecting the brands and product categories it still believes have value.
Advertisement
Technics remains alive and active. We just do not yet know where some of it will be built next.
Shein wanted its Hong Kong listing to be about growth. Instead, the filing meant to sell that story revealed a US regulator is investigating the company, and Shein will not say why.
The disclosure sits in the draft prospectus for Shein’s planned IPO, Reuters reported. Its US business, the filing said, is under investigation by the Federal Trade Commission. An FTC spokesperson confirmed a consumer-protection inquiry. This appears to be the probe’s first public disclosure.
A probe with no stated target
Shein did not say what the FTC is looking at. It said only that it is cooperating, and that it cannot predict the outcome or the timing. The warning it gave investors was blunter. Any resolution, it wrote, could force “significant monetary payments” with “a material adverse effect on our financial condition.”
The FTC polices unfair and deceptive business practices. It has taken on other marketplaces and platforms, from Amazon to Coupang, over how they treat their customers. It has also pressed firms over how their products lock people in. Its cases have covered hidden fees, misleading prices, awkward cancellations and the mishandling of data. None of that reveals what the FTC alleges here. It does map the territory the agency works in.
Advertisement
The dark-pattern problem
One corner of that territory is hard to ignore. The FTC has spent years going after “dark patterns,” CNBC noted. These are the design tricks that nudge people into spending or handing over data. In a 2022 report, the agency named the countdown timer as a classic example.
Shein’s app runs on exactly these mechanics. It uses countdown timers, gamified discounts and limited-time flash sales. Each is designed to turn browsing into buying before the shopper stops to think.
The FTC has not said its probe concerns any of this. But it is an uncomfortable overlap for a company about to ask public investors for money.
The worst possible timing
The disclosure lands at the end of a long, bruising road to market. Shein tried to list in New York, then London, and only reached Hong Kong after Beijing’s regulator cleared it this month. Its target valuation of $40bn to $50bn is a fraction of the roughly $100bn it commanded in 2022. Some investors have reportedly pushed for closer to $30bn.
The business underneath has weakened too. Shein swung to a $99m loss in the first quarter, from a $395m profit a year earlier. The reversal followed the US scrapping the “de minimis” exemption that let cheap parcels enter duty-free.
Advertisement
US revenue fell about 14% to $2bn. The EU has since added its own charge on low-value parcels, Forbes reported. A consumer-protection probe from its largest market is the last thing Shein needed as it finally tries to sell the story.
You must be logged in to post a comment Login