Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
OpenAI and Anthropic have both had a rough few weeks on the AI safety front. OpenAI recently disclosed that its models broke out of a test environment and hacked into Hugging Face and four other organizations. The news prompted Anthropic to review its own testing, which revealed that Claude had also gained unauthorized access to three companies.
Now, the UK’s AI Security Institute (AISI) has disclosed a new round of incidents (via Wired). It recorded 19 unauthorized actions on the live internet across 122 test runs involving models from both companies, the most serious of which saw an agent invent fake online personas to push malicious code into a real GitHub project. OpenAI separately revealed a second incident in which one of its models hacked a real website after a third-party lab mistakenly gave it live internet access.
AISI traced 17 of the 19 unauthorized actions to Anthropic’s Mythos 5 model, with the remaining two tied to OpenAI’s GPT 5.6 Sol. The GitHub incident was one of the 17, and it didn’t end when a human reviewer rejected the submission. The agent posted a summary of its progress publicly, inviting other automated systems to pick up where it left off, an attempt at what AISI calls prompt injection. A separate agent later found that message, used it, and continued the work.
AISI says it deliberately gave the models internet access and relaxed some safety protections to test their capabilities, but never instructed the agents to target real people or organizations. The institute says it’s still unclear whether the agents understood they’d gone beyond the scope of the simulation.
A second incident, disclosed by OpenAI the same day, started with a mistake at Irregular, a third-party lab OpenAI hired to run its cybersecurity tests. Irregular meant to keep its evaluation model confined to an isolated sandbox, but a configuration error gave the model direct access to the live internet. Once out, it exploited a vulnerability to break into a real website, then found and used credentials to operate the site it had just hacked. OpenAI hasn’t named the website or detailed what the model did with its access.
Both companies say the new incidents happened under deliberately loosened conditions that don’t reflect how their public models behave. Be that as it may, that doesn’t change the fact that AI agents from two of the industry’s most closely watched companies have now slipped past their intended limits in three separate incidents within a matter of weeks. And that doesn’t bode well for an industry racing to hand AI agents more real-world tasks before proving it can keep them in check.
I snore. Not politely, either. More like a diesel generator trying to restart in January, which means my wife occasionally wakes up at 3:00 a.m. weighing two options: hold a pillow over my head and see whether Trenton State Prison has decent Wi-Fi, or find an actual solution.
The $279 Ozlo Sleepbuds 2 are designed for the second option. Developed by former Bose engineers, these tiny sleep-focused earbuds mask snoring, traffic, hotel noise, barking dogs, and other overnight disturbances without relying on active noise cancellation.

These are not conventional true wireless earbuds that have been made slightly smaller and given a rain-sounds playlist.
Ozlo says the Sleepbuds 2 are the smallest earbuds designed specifically for sleep. Their low-profile silicone housings sit flush inside the ear, while secure-fit wings are intended to keep them in place throughout the night. That matters most for side sleepers, who already know that pressing a normal wireless earbud into a pillow can become uncomfortable rather quickly. Each earbud weighs a reported 1.6 grams.
The Sleepbuds 2 also avoid active noise cancellation. Instead, they combine passive isolation with continuous noise-masking sounds intended to cover unpredictable interruptions such as snoring, barking dogs, traffic, roommates, and whatever the people upstairs are apparently building at 2:00 a.m.
Users can select from more than 30 built-in soundscapes and masking sounds, or stream music, podcasts, and audiobooks over Bluetooth. The earbuds can automatically switch from streamed content to a stored masking sound when the user falls asleep, after a timer expires, or when the streamed program ends.
Five customizable Sleep Modes determine how audio behaves during the night, while the new Sleep Shield feature blocks incoming calls, alerts, notifications, and unexpected Bluetooth audio. A private in-ear alarm can wake the wearer without disturbing anyone sleeping beside them.

Battery life increases from roughly 10 hours on the original model to up to 14 hours, based on Ozlo’s testing at 50 percent volume. The Smart Charging Case holds enough power for another two or three nights, although actual performance will depend on volume, Bluetooth streaming, enabled features, and battery condition.
Ozlo has also redesigned the Bluetooth system to improve connection reliability and range. That is an important upgrade because bedtime is a particularly bad moment for pairing problems, firmware drama, or an earbud deciding that it needs some personal space.
A physical button on the Smart Case provides phone-free access to basic functions, including starting a stored sleep sound and snoozing the alarm. Initial setup and streaming still require the Ozlo app and a compatible phone, but stored sounds can be configured to begin without an active Bluetooth connection.
The earbuds monitor movement and breathing, while sensors in the Smart Case measure bedroom sound, light, and temperature. The Ozlo app combines that information into sleep-pattern and environmental insights designed to help users identify what may be disturbing them during the night.

The strongest candidates are light sleepers, side sleepers, shift workers, frequent travelers, apartment dwellers, and anyone sharing a bedroom with a partner whose snoring resembles a diesel generator trying to start in January.
They also make sense for people who already fall asleep to podcasts, audiobooks, meditation programs, or ambient sound but find ordinary earbuds too bulky or uncomfortable for overnight use.
They make less sense for someone who needs versatile everyday earbuds for calls, workouts, commuting, and serious music listening. There is no ANC, and the sound system has been optimized for masking noise and reproducing spoken content at low volume rather than delivering subterranean bass or an audiophile listening experience.
And at $279, they are not an impulse purchase. But for someone whose sleep is regularly interrupted by environmental noise, the real comparison may not be against another pair of earbuds. It may be against another exhausted morning, an increasingly annoyed partner, or a hotel-room air conditioner that sounds like it survived the Korean War.
Disney+ has found a way to restore 4K UHD on selected TVs and streaming devices following a European patent injunction, but HDR10, Dolby Vision, 3D, Apple TV 4K, Samsung TVs, and game consoles remain on the outside looking in.
Disney+ has found a way to put some of the missing pixels back, but affected Premium subscribers in Europe should probably hold the fireworks.
Only days after Disney confirmed that a court ruling had forced it to remove 4K UHD and HDR streaming in parts of Europe, the company has begun restoring 4K through an alternative video technology. The good news is that selected subscribers can once again watch Disney+ content at 4K resolution. The bad news is that device support remains limited, and HDR has not returned.
Premium, apparently, is still a work in progress.
According to German publication Heise, Disney+ is using the VP9 video codec for its temporary 4K workaround rather than HEVC, the technology at the center of its ongoing patent dispute with InterDigital.
Disney has not publicly confirmed VP9 by name, but it has acknowledged adopting an alternative technology and beginning the restoration of 4K UHD. Denmark has been specifically confirmed as part of the rollout, although Disney says availability may vary by market and device.
The switch matters because VP9 support and its implementation within the Disney+ app are not universal. A television or streaming device may be technically capable of decoding VP9 video without currently receiving a compatible Disney+ 4K stream.
In other words, do not assume that a 4K logo on the box means everything will work.

Disney says its alternative 4K delivery system currently supports:
Compatibility can vary between individual models, regions, and versions of the Disney+ app.
Several major platforms remain unsupported, including:
That is not a minor omission. Samsung remains one of the world’s largest television manufacturers, while Apple TV 4K and game consoles are widely used as primary streaming devices in home theater systems.
Disney says it is working to expand device support, but it has not provided a timetable.

The current workaround restores resolution, not the complete Premium viewing experience.
HDR10 remains unavailable in affected markets, while Dolby Vision and Disney+ 3D content have not returned. That means compatible devices may once again receive a sharper 4K image, but without the expanded brightness, contrast, and color range provided by HDR.
Disney says it is working to restore HDR as quickly as possible but cannot confirm when it will become available.
That distinction is important. Four times the pixel count of 1080p can improve fine detail, particularly on larger displays, but HDR often contributes more to the visible impact of modern movies and television programs. A 4K SDR stream is an improvement over the recent 1080p SDR downgrade, but it is not what Premium subscribers originally paid to receive.
The latest disruption followed a July 23, 2026, ruling from the Düsseldorf Local Division of the Unified Patent Court. The court found that Disney infringed an InterDigital patent covering certain HEVC video-encoding techniques and granted an injunction spanning 11 European Union countries, including France, Germany, and Italy. Disney can appeal the decision.
It was the second UPC injunction InterDigital secured against Disney in 2026. An earlier ruling from the court’s Mannheim division involved another HEVC-related patent and led to the removal of Dolby Vision and 3D support in affected markets.
As we previously reported, some Disney+ Premium subscribers were subsequently limited to 1080p SDR while continuing to pay the full price for a tier advertised around 4K UHD and HDR playback.
Affected customers who subscribe directly through Disney+ can request a partial refund for the current billing period. Subscribers billed through Apple, Google, Amazon, or another third party will need to contact that billing provider instead.
Disney has also suggested that customers who no longer want the Premium tier can switch to a less expensive plan. Downloads are reportedly unaffected by the streaming restrictions.
Restoring 4K this quickly is a meaningful step, but Disney+ has not fully solved the problem. The current VP9 workaround provides 4K playback on a limited selection of televisions and streaming devices, while some of the most widely used platforms remain unsupported. HDR10, Dolby Vision, and 3D are also still missing.
Affected subscribers are therefore receiving something closer to Disney+ Premium Lite: more pixels, fewer devices, no HDR, and the same monthly bill.
Disney says broader device support and HDR restoration are coming. Until that actually happens, the service has only repaired part of the damage.
Walt Disney built the Magic Kingdom on imagination. Disney’s new leadership appears to be testing how many Premium features can disappear before subscribers do.
For much of Techdirt’s nearly three decades in existence we’ve covered attacks on the media by the rich and powerful. And sometimes we’ve been on the receiving end of such attacks ourselves. But I have never seen or heard of anything quite as extreme as what happened to Ina and David Steiner, proprietors of the website eCommerceBytes. As we and many others chronicled, the story that came out sounded impossible.
But now it’s finally concluded, with eBay and three of its former top execs agreeing to pay the Steiners nearly $49 million, plus another $7 million in charitable commitments — about $56 million total, for the horrors they put them through in response to (barely) critical reporting.
The Steiners ran a small online trade publication covering eBay, mostly focused on helping sellers on the site. For years they had a good relationship with the company itself, but in the late 2010s, the company was struggling and under new management, and its execs started to get annoyed at what they saw as critical coverage of the company by the Steiners (for example, questioning why a company that was struggling financially had decided to build a replica of an east coast bar in its headquarters).
What followed still reads like fiction. If you haven’t seen it yet, I highly recommend watching the documentary, Whatever It Takes, which tells the whole story in amazing detail, including security camera footage and getting one of the (low level) eBay employees who took part in the campaign of harassment to talk about what happened on camera.
The title of the film comes directly from a text then-CEO Devin Wenig sent to eBay’s communications boss at the time, Steve Wymer, saying that Ina Steiner needed to be taken down, “whatever it takes.” Wymer replied “we’re going to crush this lady.” According to the Steiners’ lawsuit, this was then communicated to others at the company and an operations exec, Wendy Jones, then told the company’s security boss, Jim Baugh, to take care of things “off the record,” apparently telling him she didn’t want to know any details.
This allowed Baugh to concoct an escalating campaign that started with angry DMs to Ina Steiner and moved on to shipping increasingly awful things to their home: a stack of pizzas, a preserved fetal pig, a bloody pig mask, a book about surviving the loss of a spouse followed by a funeral wreath, an envelope full of “barely legal pornography” that was (deliberately) sent to a next door neighbor. And on and on.
Multiple eBay employees also traveled to the town of Natick, Massachusetts, where the Steiners lived, repeatedly driving by their house and following the Steiners when they drove around town. They also planned to break into the garage and put a tracking device on the Steiners’ car.
As the documentary makes clear, much of this was driven by the somewhat wild imagination of Baugh, who had done private security for other tech CEOs before coming to eBay, where he moved improbably fast from the CEO’s bodyguard to running eBay’s entire global security operation. The documentary details how he pushed out most of the long-time security staff and brought in a crew of young and inexperienced female hires — at least one of whom he began a relationship with — making them watch movies about top secret operations, plying them with alcohol, and demanding total loyalty.
Bizarrely, what got them caught was the whole “going to Natick and following the Steiners around” bit, which allowed the Steiners to get a license plate which the police and FBI then used to track it back to the eBay employees. A bunch of eBay employees were arrested, all of whom eventually entered guilty pleas, and many ended up being sentenced to prison sentences, with Baugh receiving the longest at 57 months.
But the Steiners were (understandably) angry that Wenig, Wymer, and Jones were never charged. While the former execs insisted that they didn’t know this was happening, that they never would have condoned it, and that they were horrified by the news when it came out, that’s difficult to believe when so much of the evidence shows that all three were on board in a “wink, wink, nudge, nudge” way given the messages they sent between themselves and Baugh.
A few years back the Steiners filed a civil suit against eBay and those former top executives. The case was set to go to trial soon, but last week they reached a settlement, with the Steiners securing $55.7 million total — $48.7 million of it going directly to them, the rest in charitable commitments:
- The plaintiffs will receive $48.7 million in compensation, including $46.15 million from eBay, $2 million from former eBay executive CEO Devin Wenig, $500,000 from former eBay executive Wendy Jones, and $50,000 from former eBay executive Steve Wymer.
- eBay will fund $6 million in charitable contributions to various nonprofit organizations. Former eBay executive CEO Devin Wenig will contribute an additional $1 million to a charity dedicated to protecting First Amendment rights in the name of Ina Steiner.
In the end, this means that the lower level employees who did much of the dirty work ended up in jail. The top execs who set this in motion end up with small dents in their large bank accounts.
eBay’s statement on the matter is at least somewhat direct in calling what happened to the Steiners “reprehensible and should never have happened.” It also “acknowledges” what it says was “the unprofessional tone in internal communications demonstrated, to different degrees and number, by Mr. Wenig, Mr. Wymer, and Ms. Jones.” I’m not exactly sure that meets the requirements of the agreement which, according to the Steiners would include “a strongly-worded public statement regarding the conduct” of those execs from eBay.
Importantly (and kudos to the Steiners for demanding and getting this) the agreement is totally public and “contains no confidentiality provision.” This is rare in cases like this (and it’s also something we insisted on in the case we dealt with). It’s important to be able to talk about this stuff, and tragically the rich and powerful who try to take down news sites are often able to negotiate confidentiality clauses into the agreements.
For what it’s worth, Wenig and Wymer are still working in Silicon Valley, with both of them co-founding AI startups, naturally. Incredibly, Wenig’s startup supposedly provides AI tools to journalists, which is quite a pivot from directing a security goon to “take down” a journalist with “whatever it takes.” That also makes the part of the agreement of Wenig providing an additional $1 million to a charity in Steiner’s name to help protect First Amendment rights even more striking.
The fact that the defendants in this case were willing to pay so much and allow the terms of the deal to be public suggests they knew exactly how badly a public trial would make all of them look.
Kudos and congrats to the Steiners. These days especially, for most media players who are attacked by the rich and powerful for their reporting, the best you can usually hope for is to get a case dismissed. Maybe, if you’re lucky, to win an anti-SLAPP motion to get your legal fees paid. To actually win a settlement this size is almost unheard of. But the Steiners deserved it. They didn’t just face bogus SLAPP lawsuits designed to shut them down. They were legitimately terrorized in ways that have had long-lasting effects.
While the Steiners situation was extreme, it’s important to recognize that this kind of thing is the inevitable end result of the constant escalation in the past few decades of the rich and the powerful attacking the free press for daring to do accurate and critical reporting on them. The craziest bit in this story isn’t even everything that eBay employees did to the Steiners, but the fact that they were so brazen about it and so careless that they got caught doing so in a way that resulted in this kind of payout. Most attacks on the press never see the light of day, let alone allowing the media entities targeted to be able to claim restitution.
Filed Under: 1st amendment, cyberstalking, david steiner, devin wenig, free speech, harassment, ina steiner, jim baugh, journalism, steve wymer, wendy jones
Companies: ebay, ecommercebytes
This post is going to come with something of a warning label. RFK Jr. went on CNN this past weekend for an interview with Dana Bash. I’m going to post the entirety of that interview immediately below. Before you watch it, get yourself a bib, or some paper towels, or wrap yourself in one of those plastic ponchos they hand out to keep the rain off of you. You’re quite likely to spit out whatever is in your mouth, vomit, or perhaps even have your brains leak out of your ears. You’ve been warned.
Whether you’ve watched that entire thing or chosen not to, potentially for your own health, the interview is completely bonkers. It’s honestly pretty tough to pull out the lowlights to comment upon, it’s so bad. The themes of the 20-plus minute interview, however, are easy to outline: RFK Jr. takes no responsibility for what he’s done past or present, he spends the entire time attacking Dana Bash as though she personally is responsible for everything he hated about the COVID response, he pretends that Donald Trump had no agency over that response despite being president at that time, and he insists that only he is listening to the science and doctors when it comes to health outcomes.
Let’s get into some of those. When talking about the COVID response and specifically what we need to do better for the next pandemic, Kennedy predictably went into a minutes long diatribe about how the most important thing is our constitutional rights and how the entire constitution was thrown out by Anthony Fauci (and not Donald Trump, somehow). When Bash pointed out that wasn’t really what she was asking about, Kennedy snarled and attacked her.
“Forgive me, but you’re just talking about rights and I’m asking about a potential public health crisis that is coming,” Bash said after Kennedy launched into a lengthy defense of constitutional rights that he claimed were “dismantled” during COVID-19 lockdowns.
“I really want to move on,” Bash added as Kennedy repeatedly interrupted to continue his argument. That appeared to set him off.
“Of course you do, because you were part of the problem!” Kennedy shot back, pointing at the host.
“No, I wasn’t part of the problem,” Bash replied.
“Yes! There was absolute press malpractice,” Kennedy continued. “You weren’t allowing—”
As Bash tried to interject, he kept going: “Your job is fierce skepticism toward authority. And you weren’t doing that. You were beating up the people who were dissenting.”
Somehow both predictably and unbelievably, this exchange ended with Kennedy stating that he wasn’t attacking Bash at all and instead insisted that she attacked him. She really didn’t. Go ahead and watch the interview if you haven’t. To that point, she hadn’t done anything that could even be misconstrued reasonably as “attacking” Kennedy.
Bash then pivoted to the measles outbreaks of the last 20 months, pointing out that the messaging from Kennedy on getting vaccinated hasn’t been clear and asking for his stance on it. Kennedy then did what he always does. First, he affirmed that everyone should be getting vaccinated for measles… and then launched into his conspiracy-laden and well-worn diatribe explaining all the reasons parents shouldn’t necessarily get their children or themselves vaccinated, and that vaccines haven’t been proven to be safe.
“Do you want people to get the MMR vaccine?” Bash later asked.
“Yeah, I said that already,” Kennedy replied with a smirk before pointing at the host. “I know you’re flustered now, and it’s frustrating.”
Bash quickly pushed back.
“I’m not flustered at all. I am frustrated,” she said. “The reason I’m frustrated is because you are the HHS secretary and you are talking about things that lead to vaccine hesitancy in this country. And it is something that causes problems for people when there is not anything—”
Kennedy cut her off again.
“Let me ask you something,” he said. “Do you see your job as ending vaccine hesitancy, or do you see your job as telling the truth to the American people?”
Bash replied, “I see my job as telling the truth, and the truth is that there is study after study after study. It‘s one of the most studied things out there in science—”
“You’re repeating it like a parrot,” Kennedy snarled as he lunged forward over the table. “You‘re repeating it like a parrot. I’ve actually read the science.”
The conversation again devolved into raised, overlapping voices, before Bash proclaimed: “I’m not debating nonsense.”
“All you know how to do is repeat what people told you and say ‘trust in the experts,’” a red-faced, wildly gesticulating Kennedy replied, blaming trust in Fauci for poor public health.
Now, one thing that was cut off from my transcription of the COVID response portion of the interview was this. Pay close attention to who Kennedy indicates we should listen to in crafting public policy, because on this I believe he’s right:
Got it? In that clip he says we should listen to “frontline doctors.” Now, while there’s no official poll of national physicians to rely on, we can certainly look to the groups that those same frontline doctors choose to represent them. Many of those groups have directly called on RFK Jr. to resign.
So, Kennedy can do something principled and brave after this absolute meltdown of an interview. He can listen to frontline doctors. And he can resign.
But he won’t. Because it’s not actually frontline doctors he wants to listen to at all. He’s carefully choosing his language. When he says “frontline doctors” he doesn’t mean any of the actual frontline doctors represented by any of those trusted groups mentioned above. Instead, he means the propaganda/conspiracy organization known as “America’s Frontline Doctors,” the same group that focused most of its attention on selling bogus COVID treatments, and whose founder went to prison for her role in the January 6th insurrection. Not surprisingly, that group (which these days appears to consist of just a random Substack) repeatedly supports all of RFK Jr.’s totally unsubstantiated claims. How surprising.
Filed Under: dana bash, health & human services, measles, responsibility, rfk jr., science, vaccines
Companies: america’s frontline doctors
Most drivers in the U.S. likely have a good idea what “radar enforced” means on some speed limit signs. But this isn’t the only method law enforcement uses to help ensure that vehicles are moving at safe speeds, whether on a rural road or on a major highway. For example, “photo enforced” means that a speed camera is indeed being used to identify drivers going beyond the speed limit.
This use of cameras is part of an Automated Speed Enforcement (ASE) system. ASE systems are often seen in work zones and school zones, but can be placed in high-speed locations as well. The speed limit signs themselves may be posted before the actual speed camera. This is done in order to notify drivers of the speed limit and also that automated enforcement is being used ahead. If one of these cameras catches a driver speeding, they may receive a speeding ticket that is issued automatically based on the violation recorded by the system.
ASE systems are designed to improve safety by encouraging drivers to slow down. This is especially important in work zones, though workers may not have to be present for you to receive a speeding ticket. According to the Federal Highway Administration (FHWA), these systems have been shown to reduce the number of speeding drivers, as well as crashes, injuries, and fatalities in work zones.
ASE systems can come in several different forms, depending on where they are used. These include fixed pole-mounted cameras, semi-fixed cameras that can be moved between locations, speed-on-green cameras that detect vehicle speeds at intersections, and mobile ASE units. The type of ASE system used depends on the location, as well as the needs of the affected community. But are these systems actually legal?
The answer depends on where you are, because state laws and local regulations governing photo-enforcement cameras can differ. Some jurisdictions allow automated speed enforcement programs only in certain areas, as long as specific controls are in place. This can include posted warning signs notifying drivers of speed enforcement zones, as well as equipment calibration and certification. There may even be a required review process before citations are issued. The way violations are handled can also differ, with some jurisdictions holding the driver responsible, while others hold the registered vehicle owner accountable.
It’s important to know that while posted warning signs may seem like a logical component in ASE systems, their use can vary by state. The FHWA does not establish a nationwide set of rules for speed safety camera programs, including whether or not warning signs must be put in place. Those decisions are determined by state and local laws, which also govern where the cameras will be installed.
Just unboxed a new computer? Here’s our curated list of essential Windows and macOS apps for productivity, security, entertainment, and everything you need to get up and running.
SpaceX has ramped up purchases of Tesla Megapack, spending $295 million on the battery storage devices in the second quarter and $329 million so far this year, according to the company’s earnings report released on Tuesday.
The purchase illustrates just how interconnected Elon Musk’s universe of companies are. Musk, who is the CEO and largest shareholder of SpaceX, also runs Tesla. Musk’s artificial intelligence business xAI acquired his social media platform, X, in 2025. Earlier this year, SpaceX gobbled up xAI.
The industrial-scale batteries are likely being deployed at the company’s xAI data centers. Before xAI merged with SpaceX, the AI company bought $430 million worth of Megapacks for its data centers. In the first quarter of this year, xAI had purchased only $34 million worth of the equipment. SpaceX also reported that as of December 2025, it had acquired $131 million worth of Tesla Cybertrucks at manufacturer’s suggested retail price, according to its regulatory filing.
Though xAI has leaned heavily on natural gas to power its data centers — including dozens of unpermitted turbines at a site in Mississippi not far from the Colossus data center project — large batteries like the Megapack are still a critical part of data centers.
In addition to providing substantial backup power that can be tapped in a second or less, batteries can provide extra power to GPUs when they demand it. AI data centers don’t draw power consistently. Rather, their power demand ramps up and down depending on the demands of training AI models and running inference.
Such peaks can incur significant charges from a local utility or overwhelm on-site generators. Batteries help smooth out those peaks, lowering costs while ensuring that the data center can operate consistently.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Electronic Arts is once again a privately held company, but it’s saddled with $20 billion in new debt.
Electronic Arts is now privately owned after a $55 billion buyout of the game publisher closed on Tuesday. EA said last week the deal had cleared all of the required regulatory hurdles, paving the way for the company and its new owners to wrap things up, several months later than they originally anticipated. The proposed acquisition was announced last September and EA shareholders voted in favor of the deal a few months later.
Saudi Arabia’s Public Investment Fund now owns over 93 percent of the company. Private equity firms Silver Lake and Affinity Partners are also among the new owners. Current CEO Andrew Wilson remains at the helm of EA, which is still based in Redwood City, California.
The takeover is the largest leveraged buyout in history. The buyers used $20 billion in debt financing to secure the deal. EA will have to pay that back over time. For the company’s most recent fiscal quarter, which ended June 30, it posted a profit of $387 million after operating expenses and taxes. In a letter to EA employees announcing the deal’s closure, Wilson reiterated the company’s commitment to “building the world’s greatest games, communities, and creative culture.”
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE).
The flaws were uncovered by Forescout’s Vedere Labs researchers, who published the full details at the Black Hat USA security conference earlier today.
Omada is TP-Link’s business networking product line that includes Wi-Fi access points, Ethernet and PoE switches, internet gateways, and VPN routers.
They are typically used by small to medium-sized businesses, although TP-Link also markets pro-grade deployments for enterprises.
ZTP is a way to deploy network devices without manually configuring each one on-site, allowing an IT team or managed service provider (MSP) to prepare everything remotely based on a predetermined configuration.

Some of the 15 flaws Forescout discovered also impact various TP-Link products and services, such as IP cameras, smart home IoT devices, mobile applications, and cloud accounts.
The issues include hard-coded cryptographic keys, information disclosure, remote code execution, device hijacking and spoofing, client-side code execution, and interception or compromise of encrypted communications.
Forescout says attackers could combine the new flaws with two previously disclosed command-injection vulnerabilities to compromise Omada’s chain of trust and infiltrate networks.
“The vulnerabilities fall into four impact categories: client-side code execution, information disclosure, device hijacking and spoofing, and compromise of encrypted communications,” Forescout explains.
“Combined with two previously disclosed CVEs (CVE-2025-7850 and CVE-2025-7851), these flaws enable concrete attacks that let attackers infiltrate networks through controllers and client devices.”
TP-Link’s advisory lists 15 newly disclosed flaws, of which 11 received the following identifiers:
The remaining four findings did not receive a tracking number. They concern device adoption based only on knowing the serial number, default credentials used during initial adoption, predictable serial numbers, and files made available via unauthenticated temporary download links.
In one attack scenario Forescout described, a remote attacker could enumerate predictable device serial numbers to obtain MAC addresses and identify devices awaiting adoption.
The attacker could then impersonate one of those devices, exploit a race condition during cloud adoption, and authenticate using default credentials.
This would cause the controller to disclose the device configuration, including a cleartext username, an unsalted MD5 password hash, and potentially VPN keys.
The attacker could also inject JavaScript into the controller’s administrative interface to phish an administrator and steal their cloud-controller credentials.
Having stolen the credentials, the attacker can then reconfigure managed devices, create VPN tunnels into the internal network, and exploit previously disclosed command-injection flaws to compromise network equipment.

The flaws affect Omada Controllers, Gateways, Switches, Access Points, OLT platforms, Cloud services, and TP-Link mobile applications.
Forescout reports identifying over 1,800 internet-accessible Omada controllers, despite such deployments generally not being intended for direct internet exposure.
As for the Android applications, Omada and Omada Guard have 1.1 downloads on Google Play, while TP-Link apps collectively have 3 to 7 million active accounts.
Users are advised to visit TP-Link’s Omada download portal to source the latest firmware images for their device model.
Additionally, it is recommended to use strong, unique administrator credentials, enable multi-factor authentication (MFA), rotate all secrets when compromise is suspected, update mobile apps, and monitor network traffic for suspicious activity.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
The official unveiling of the Google Pixel 11 series is just over a week away, and the leaks and rumors keep spilling out. The latest leaks show a new, multicolored notification light on the back of the phone next to the camera setup. Google has teased the new feature in short YouTube videos released previewing the official event, which is on Aug. 12.
This isn’t the first time we’ve heard of this feature, dubbed Pixel Glow in previous rumors, but the latest leak replaces that name in favor of the less interesting HiLight. The feature itself hearkens back to the old days when many Android phones and BlackBerry devices shipped with notification LEDs. This time around, Google’s putting a bit of a spin on the feature.
On Monday, Roland Quandt of tech site WinFuture shared a post on BlueSky with an image that appears to be official French-language marketing material, showing the Pixel 11 Pro Fold and detailing the new feature.
The text translates as, “When your smartphone is face down, HiLight lights up discreetly when your favorite contacts call or when you chat with Gemini.”
HiLight replaces the temperature sensor introduced in previous Pixel devices. While the earlier sensor saw limited real-world use, HiLight is better positioned as a feature users can benefit from more consistently in everyday use. Still, there’s a reason some people choose to keep their phone face down in public. It helps avoid distractions and prevents notifications from constantly demanding their attention. By making this feature a default part of the experience, Google effectively removes that option unless users can disable it entirely.
What is interesting about HiLight is that it appears to be a very small display rather than a static, multicolored LED. Many of the phones from Nothing Technology have LEDs that light up for notifications and timers, and perhaps HiLight will have its own customizations.
It remains to be seen whether HiLight will be able to work with other apps beyond favorite contact notifications and interactions with Gemini. Developers may have to provide support within their own apps for the feature to work, which could take time and adding support for a single feature on a single family of phones isn’t necessarily the most compelling reason for them to do so.
We’ll learn more about the Pixel 11 family and all of its new bells and whistles next week at Made by Google 2026. We can also expect the debut of the Pixel Watch 5, which has already been spotted in, of all places, the Caribbean Sea.
Why Trees Belong on the Risk Register
Weekend Open Thread: Wit & Wisdom
Meta enters AI-training agreement with far-right ‘propaganda rag’ Newsmax
Reform UK betrays West Mids residents by running from party pledges
MicroStrategy Post-Earnings CLARITY Act Push Could Add New Catalyst for Its Stock
Zack Polanski: an incitement to murder Nigel Farage?
XRP Ledger v3.3.0 brings five institutional features
Bitcoin Enters the 3rd Stage of the Bear Market
Luke Littler’s dominance sparks GOAT debate
Seema Kaliramna Wins Discus Throw Bronze, Takes India’s CWG Medals Tally To 17
New York sues Kalshi over prediction market gambling
Crypto PAC spending tops $2M in Michigan House race
Gemini can now summarize the messiest comment threads in Google Docs
Trump Announces Hamas Disarmament Agreement as Iran Strikes Kuwait Air Base and US Attacks Pause Overnight
ESET tracks rise in malicious AI skills and adaptable malware
DTCR: Deleveraging And A Hedge Fund Collapse Point To A Possible AI Bottom
Gemini Spark can now use Chrome logins and saved passwords to run errands on your behalf
Building A Reproduction PlayStation Motherboard
Four people die trying to cross Channel in small boats
Sakshi, Arundhati Enter Boxing Semi-Finals. India Assured Of 18 Medals At CWG 2026
You must be logged in to post a comment Login