Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
I mean, they’ve been around forever.
The humble USB flash drive has been among the most enduring pieces of consumer technology. After unseating the floppy disk as the portable storage medium du jour, flash drives began to hit the consumer market in the early 2000s, and they’ve been collecting dust at the bottom of backpacks and desk drawers ever since. Whereas floppy disks held very little data, flash drives came off the top rope with multiple whole megabytes of capacity and much faster data transfer rates. Those figures improved over time, scaling as flash storage increased in capability. But has the flash drive finally reached the end of the road?
The Museum of Obsolete Media still rates USB flash drives at a 1, indicating a low risk of obsolescence. As long as USB ports don’t go the way of the dodo, neither will these convenient little drives. The increasing cost of other storage mediums is likely to prolong their popularity, too. But while there’s no direct evidence of declining flash drive sales, they’ve fallen out of favor as people deal more regularly with large files and faster data transfer capabilities on newer hardware. Increasingly, more capable devices are needed, especially for people working in IT or creative professions.
So, what are thumb drives still good for, and should you be transitioning away from them? That depends.
If flash drives no longer feel flashy, that can be chalked up to their increasing impracticality. Their relatively small capacities — most brands top out at 128GB — make them useless when dealing with large files. Many people now deal with larger files than ever. New smartphones can produce libraries of 4K video which take up roughly 1GB for every minute of footage at high frame rates. ZIP archives, smartphone or PC backups and other such files can easily exceed the capacity of a thumb drive. Even if your files fit on a flash drive, they’ll transfer at relatively slow speeds.
SSDs pick up the slack. The best SSDs tend to have larger capacities of 1TB or more and much faster transfer speeds. They’re also more durable, with portable SSDs often clad in protective housings, and they tend to use higher quality memory controllers. The ease with which they can outlast an average flash drive, all else being equal, makes them better long-term investments. And whereas older SSDs could be somewhat bulky, newer models are eminently pocketable. While not as small as flash drives, they hardly take up space in most bags.
Lastly, there’s USB-C, which is the only type of data port on some newer laptops. USB-C flash drives do exist, but SSDs make things much simpler by using a cable. Most popular portable SSDs include both a USB Type-A and Type-C cable, allowing the user to choose the better option for their personal needs.
Whatever downward trajectory the humble flash drive may have been on, the AI boom has upended that gravity. Thanks to the surge in demand for data center storage and memory, the price of an SSD has skyrocketed since late 2025, and PC sales have fallen. After stabilizing at dirt-cheap prices that made data hoarding more economical than ever, the rush of new demand sent prices into the stratosphere. The 4TB Samsung 990 Pro SSD I used in my last PC build cost me $318 in November 2025, but Amazon lists it for $1,100 at the time of this writing. As if to rub salt in the wound, Samsung’s slower 990 costs even more than the original.
Meanwhile, a cursory look at the Amazon listings for USB flash drives reveals a landscape much less likely to induce heart palpitations. They’ve increased in price, but the rate of increase has lagged that of SSDs and HDDs. Additionally, they come in lower storage capacities, which further reduces the per-unit cost. A five-pack of PNY 64GB USB 3.0 flash drives will only run you $43 as of this writing, which is a far lower per-gigabyte cost than that of the Samsung 990. For most people who aren’t shooting reams of 4K video and just need to move a few documents or store some tax filings, flash drives are once again the more attractive option. It’s no wonder that Google Trends data shows a massive spike in search interest beginning in early 2026 for terms like “USB flash drive portable” and “USB flash drive 128GB.”
Moreover, flash drives still have their traditional silver bullet use cases. Want to create bootable media to install a Linux distro or Windows 11 instance on a machine? No use wasting a whole SSD for that. Ditto for running portable, zero-footprint OSes like Tail OS, carrying around a toolbox of diagnostics and repair tools or simply throwing on a keychain so you have access to portable storage in a pinch.
Apple obviously knows, and perhaps some of its retail staff have at least a clue, but for the rest of us, here’s the best estimate of when the iPhone 18 Pro will be announced.
No question, it’ll be in September. Apple has held its iPhone launches in October, but since 2011 the only time it has done that was during COVID.
The question is when in September we’ll find out the all-important updates and, more than ever this time, the all-important prices. Not to drag this out, the smart money says Wednesday, September 9, 2026.
That’s the most probable date that has been recently rumored. It’s in the first full week of September 2026, which is also when Labor Day is.
Since 2011 when Apple moved its iPhone launches away from their original announcements in June, the unveiling has been close to Labor day three times. In 2015, 2016, and 2022, and each time Apple has made its announcements on the following Wednesday.
In the 15 years since that move to the last quarter of the year, Apple has launched iPhones on Wednesdays five times. It’s launched them on Tuesdays nine times, and on Mondays just once, in 2024.
With the exception of the October launches in 2011 and 2020, every iPhone has been unveiled in the first two weeks of September. The latest date was September 14, in 2021 with the iPhone 13 range.
Then the earliest is a tie between 2016 and 2022, which were both on September 7.
Despite occasional leaks, we obviously won’t know for certain when the iPhone launch is until Apple announces the date. But the company has form on even those invitations, too.
It’s a form that seems to be lengthening, too. Back around 2013, it was common for Apple to issue invitations to the launches one week ahead of the event.
Expect another gorgeously-designed invitation like this one from 2025, which will then be studied intently for clues – image credit: Apple
That happened several times, such as in 2015, 2016, 2018, and again in 2021. Then for the iPhone 14 event on September 7, 2022, Apple revealed the date two weeks before with an AR invite.
There was again two weeks’ notice for the iPhone 15 in 2023, and the iPhone 16 in 2024.
In fact, from the iPhone 14 onwards, Apple has consistently issued invitations two weeks to the day before the event. That means it is now always during the last week of August that it reveals the date.
So expect the 2026 invitation and event date to be announced on Wednesday, August 26. Expect the event to be on Wednesday, September 9, 2026.
Which just leaves the question of when the new iPhones will be available to pre-order. Typically that happens on the Friday immediately following the event, and that won’t be changed because of the unveiling being on a Wednesday instead of a Tuesday.
It might be changed because the Friday is September 11. Apple has avoided doing anything on that date since the World Trade Centers were destroyed on September 11, 2001.
Then Apple isn’t likely to delay taking orders by very much, if at all, but it might have to push back shipping dates. Typically buyers start getting their iPhones by the Friday after pre-orders open, and that’s also when retail Apple Stores get their first stocks.
For the first time since COVID, though, there are likely to be delays in production. In this case it’s because of the global chip shortage, which could conceivably mean a longer than usual gap between launch and shipping.
Or it might be that Apple launches on its usual schedule, but will then take longer than normal to fulfil orders.
That’s specifically been rumored for the expected iPhone Fold, but it’s possible for the iPhone 18 Pro and iPhone 18 Pro Max too.
Then if the invitation date, event date, pre-order and shipping dates aren’t enough, Apple looks like it will have one more whole set of dates to look out for. Perhaps because of the chip shortage, Apple is strongly rumored to split its iPhone launch for the first time.
If this is correct, the presumption is that Apple will launch its biggest sellers, the Pro models, first. So the regular iPhone 18 may launch in the Spring instead.
It isn’t as likely to get an event, though, so at least there’s just the launch, pre-order and shipping dates to wonder about then.
Levi Strauss & Co. (Levi’s) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines.
The company has disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC), saying that its response was sufficiently quick to prevent the compromise of consumer data.
“Based on preliminary findings from the Company’s investigation, the Company believes that certain corporate information was accessed and exfiltrated as a result of the incident,” Levi’s says.
“As of the date of this filing, the Company believes that its rapid response efforts successfully contained and terminated the unauthorized access, and that no consumer data was impacted.”
The company added that it has not experienced any interruption in business operations as a result of the incident.
Levi’s clothing giant has 19,000 employees and an annual revenue of $6.3 billion, best known for its signature 501-line jeans.
The company operates at least 3,300 stores worldwide, and its products can also be found in numerous third-party retail shops, both “brick and mortar” and online.
The firm says it recently detected a cybersecurity incident in which an unknown attacker social-engineered three of its employees, resulting in the breach of company-issued computers.
The investigation launched in response to the incident remains ongoing, and additional notifications will be provided to affected parties as required.
Based on the findings of the investigation to date, Levi’s does not believe the incident will have a material impact on its business or financial position.
Levi’s also noted that it has not experienced any operational disruptions as a result of this breach.
BleepingComputer could not identify online any threat actors claiming the attack on Levi’s.
However, some media outlets have linked this incident to UNC6671, which Google’s Threat Intelligence Group (GTIG) associated with a recent wave of voice phishing attacks targeting hundreds of organizations.
Although Levi’s stated that no customer data was impacted, until more information becomes available, holders of Levi’s shop accounts should monitor for suspicious activity and promptly report it to the firm.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
One of Apple’s memory suppliers is making a massive investment to expand chip production amid global shortages, but it won’t make your next iPhone any cheaper.
On Friday, SK hynix announced that it has approved a 54 trillion won ($38.3 billion) investment to build two new semiconductor fabrication plants in South Korea.
The investment includes 35.2 trillion won ($24 billion) towards the Yongin Y2 facility, which will produce high-bandwidth memory (HBM) and next-generation DRAM products. Construction will begin in 2027 and wrap up by 2029.
A 19.1 trillion won ($13.6 billion) investment will go towards building the Cheongju M17 facility set to open in late 2028. The facility would serve as a NAND production base, geared toward enterprise SSD and AI inference storage.
SK hynix is one of the world’s largest memory chip manufacturers. It’s one of Apple’s key memory suppliers and provides components used across Apple’s lineup, including the iPhone, iPad, and Mac.
Unfortunately, neither of these investments directly helps the average Apple consumer. Instead, the new facilities are being built to serve high-growth AI and enterprise markets, not traditional consumer electronics.
Of course, one could argue that by creating dedicated facilities for increasing enterprise products, SK hynix could give itself breathing room to manufacture consumer-grade products.
And, maybe that’s true.
Even still, SK hynix’s investment isn’t going to solve issues anytime soon. After all, the plants aren’t even slated to open until late 2028 at the earliest.
We’ve said it before, and we’ll say it again: this is going to get worse before it gets better.
Currently, DRAM prices are edging up to an untenable level for even large corporate customer bases, with nothing to say of the average consumer.
DDR-5 DRAM prices have very nearly sextupled on average on the consumer side. In February 2025, two 16GB sticks of DDR5-6000 RAM sold for about $100.
Present pricing is around $600.
We’ve most recently seen the effects as Apple increased prices on most of its product lineup.
The increase wasn’t surprising. Inflation and supply chain issues often drive prices “up like a rocket,” especially on consumer-level products.
The market, bolstered by consumers at all levels rushing to buy products “before they get any more expensive,” stands to make a good profit. That is, at least, until people genuinely can’t afford the costs.
And while we’ll likely see a drop in pricing due to increased manufacturing and market correction, I wouldn’t expect it to be fast or dramatic.
Instead, prices will float “down like a feather.” Slowly, and likely in a sine-wave pattern.
The point, as it often is, is that asymmetric price transmission is a real pain in the ass for the end consumer.
Global supply chain shortages are a real thing. The boom of AI has put a lot of stress on manufacturers to keep up with demand.
But let’s not point the accusatory finger purely at data centers and general market scarcity. There’s plenty of blame to go around.
It’s important to remember that SK hynix is also one of the companies targeted in a recent price fixing suit.
The complaint centers on DRAM, the working memory used in computers, smartphones, tablets, servers and many other electronic devices. Samsung, SK hynix and Micron dominate the global DRAM market, giving them enormous influence over memory supply.
Allegedly, Samsung, SK hynix and Micron shifted manufacturing capacity toward HBM, which commands much higher prices from AI companies. This shift has left DRAM supplies dwindling across the tech industry.
And yes, companies are allowed to pursue more profitable products. But the real question is whether these companies coordinated the production decisions or reached them independently.
Ultimately, whatever investments SK hynix makes right now doesn’t solve the immediate problem. Suppliers have already sold their entire production capacity of memory at high prices through 2027.
Get ready to unleash your inner demon when Overwatch Season 4 begins on Aug. 11. The game’s next chapter brings new tank hero D.Mon, who comes from the same robot suit-piloting Meka Squad as launch hero D.Va but brings a different style of gameplay to the hero shooter’s tank roster.
Yuna “D.Mon” Lee enters the roster as the first new tank hero since Domina back in February. The mech pilot has been in the lore since 2018, when she appeared in D.Va’s Shooting Star cinematic, and the community has been begging for more mech heroes ever since.
And here she is: the new leader of South Korea’s Meka Squad. D.Mon is an “untouchable, cool ice queen,” according to Eleni Rivera, a narrative designer for Overwatch. That’s an interesting contrast to the Meka team’s former leader as mentioned in the lore, who was much louder and more in your face. D.Va was a bit more of an individualistic leader, doing her own thing, Rivera said, whereas D.Mon is much more about being a cool, collected team player.
In a group media interview, Lead Hero Producer Kenny Hudson said, “The story of this hero has been great attention to detail, and pride in the craft.” Much like the rest of the community, the Overwatch team has had high expectations for this hero for years.

In contrast to D.Va’s design, which fulfilled a more ballistics-based mech fantasy, D.Mon brings agile, sci-fi sword and shield gameplay to Overwatch. Referencing the popularity of the game’s iconic, hammer-swinging tank, Reinhardt, Hudson said the team wanted to expand the melee tank roster, aiming to “give those players who like to play up-close and personal with their tanks more to choose from.”
D.Mon’s primary fire swings a plasma sword in an arc in front of her, while her secondary fire pulls up a shield. While the shield is up, you can activate primary fire to lunge forward with the sword, dealing damage and knocking back enemies. She also has a Fusion Repeater ability that gives her a few seconds of ranged damage and a resource-based horizontal dash ability that boosts her quickly along the ground.

Hudson said D.Mon’s design was partly inspired by the team wanting to see what happens when you have a melee tank with more mobility. As a result, she’s able to dash around while holding up her shield, giving her a distinct feel from other melee tanks, who generally lack movement abilities.
Her ultimate ability, called Limit Break, charges up the plasma sword before swinging through a wide arc. The maneuver grants D.Mon overhealth, and any enemies hit take damage from the swipe while also receiving increased damage from other attacks for a brief duration.
Like D.Va, D.Mon switches to pilot form if her mech is destroyed and can build up ultimate charge to call down a new mech. When she does, nearby enemies take damage and are knocked back.
Hudson said that, based on internal playtests, D.Mon is very effective at taking space and works well in rush comps that feature speed boosts from supports like Lúcio or Juno. Her ultimate ability also pairs well with other damage hero ultimates, thanks to the damage amplification element, Hudson said, while noting that D.Mon had to play heavily around cooldowns — especially the fuel for her dash.

I’m interested to see where D.Mon fits into the overall roster. While her design has echoes of Reinhardt, D.Mon appears to be significantly more maneuverable, though she lacks Reinhardt’s raw melee damage and larger team-friendly shield. And unlike her Meka Squad teammate, D.Mon can’t boost into the air to quickly claim high ground or circumvent shields. Instead, she’ll have to rely on the quick bursts of horizontal movement to circle around (or maybe plow straight through) enemy teams.
Her dash ability and melee weapon should be a tough matchup for tanks like Domina and Sigma, who rely on barriers and distance to stay safe. I also imagine her being effective against low-mobility heroes like Cassidy, Ana and Illari, who might not be able to escape a D.Mon dashing in with shields up.

A team of D.Mon along with flankers, like Shion, Tracer or Genji, and a backline of healers, with Juno, Ana or Kiriko, sounds good to me on paper. The flankers can match D.Mon’s engagement, especially with the help of a speed-boosting Hyper Ring, and can help the tank burst down key targets. A similar team with one flanker subbed out in favor of someone like Cassidy or Sojourn may also work, with D.Mon and the flanker causing havoc and creating space for the ranged damage player to do their thing.
At the same time, I imagine D.Mon having trouble against an enemy team full of ranged damage heroes that can maintain their distance, especially on maps with high ground, or against highly mobile teams that are hard to pin down. D.Mon seems like she would struggle against a Winston or Wrecking Ball with Tracer, Echo or Pharah dealing damage from afar and extremely mobile supports like Kiriko, Lúcio and Jetpack Cat, all of whom would be hard to pin down with a plasma sword.
Exciting new tank heroes are the best thing Overwatch can add to the game. The tank role is the least popular because it’s the one that most challenges your map knowledge, macro strategy and — based on personal experience — overall mental fortitude. Most players, me included, generally find it more fun to just run around shooting things or healing teammates.
With a good team, though, playing tank can feel electrifying. The glory of being the team leader, drawing enemy attention and clearing space for your teammates is a unique type of thrill in Overwatch. Sadly, it’s too often undermined by any combination of uncoordinated teammates, enemy counter-swapping or just generally having every single resource and crowd-control ability thrown in your direction.

Junker Queen has become my go-to tank because she’s a little more self-sufficient, thanks to her damage abilities’ bonus self-healing — and because she depends on smart use of those abilities. A Junker Queen who lands every knife and axe swing will dominate a lobby; one who misses most of them will immediately crumple.
I’m hoping that D.Mon offers a similar experience. Her Fusion Repeater can get bonus damage on a head shot, rewarding precise aim, and I’m hoping that her dash ability supports enough skill expression to reward practiced and creative uses. I can already envision the thrill of turning a losing fight with a well-timed Limit Break, keeping D.Mon alive with sudden overhealth while helping your team cut through the remaining enemies.
I’ve been playing more tank for the past week just in anticipation of D.Mon’s release, and seeing her kit in detail has only made me more excited about yeeting myself into the frontlines. That may or may not last over the course of the season, but it’s the first time since Junker Queen launched in 2022 that I’ve been excited about playing tank, and that itself is an achievement.
See you on the battlefield in season 4.
A go-kart track is an odd location to launch a tech initiative in the nation’s biggest city. Yet last month there was New York City mayor Zohran Mamdani, zipping around the 900-foot oval at Coney Island’s Luna Park before stepping up to a podium to unveil a program called Public Interest Technology (PIT) Crews. Thus the go-kart theme.
PIT will consist of five “game-changing” teams that, Mamdani promised, will “raise the bar for what New Yorkers can expect from City Hall.” Working closely with city agencies, these small groups of engineers and designers will strive to change the hidebound and confusing tenor of current city services by using state-of-art skills to rapidly whip up specialized apps that solve real problems. “We want to transform how New Yorkers interact with the government,” said the mayor. “We want to raise expectations on what government can deliver, because we really can deliver.”
Do those words sound familiar? If you follow government tech, they might. Because Mamdani’s message could have fit quite comfortably in the pitch that Barack Obama’s chief technology officer, Todd Park, delivered in 2014 while recruiting tech talent for what would become the United States Digital Service. The USDS was an idealistic effort to bring top Silicon Valley talent into the executive branch to bypass the logjams caused by outdated and inefficient IT, by building great, user-centric software.
The agency somehow survived the first Trump administration and kept going through the Biden term. But in 2025, Elon Musk and his DOGE wrecking crew infiltrated the agency and pulled the plug on much of the useful stuff. (Now, with the National Design Service, the Trump administration is ostensibly trying to revive some of what it destroyed.)
Mamdani’s PIT crew initiative adopts much of the original USDS ethos, with a timely twist: It embraces Silicon Valley expertise while taking a skeptical, almost adversarial, stance toward Big Tech itself. The combination of mayoral charisma and a chance to make software that doesn’t serve advertisers, the military, or the pocketbooks of centibillionaires makes the Mamdani team an attractive, high-status, mid-career change of pace for some techies. Suddenly, one of the sexiest places in geekdom is the Brooklyn headquarters of New York City’s Office of Technology and Innovation.
Mamdani’s transition team set the stage for an urban, democratic-socialist-adjacent, USDS-style tech squad when it tapped Lisa Gelobter for the city’s chief technology officer job. Gelobter’s résumé includes stints at big companies and startups, but the standout item was her post at the United States Digital Service, where she was embedded in the Department of Education. She led the effort to create a College Scorecard that focused on nuts-and-bolts criteria like costs and graduation rates. To this day, she gets misty when recalling her Washington experience; she even remembers what she was wearing when the USDS team took a group picture with Obama just before he left office.
“I’m really excited about trying to recapture that essence, that energy here,” she says. Her budget for the program is $5.24 million, with an additional $2 million grant from the Rockefeller Foundation, which will fund one of the crews.
Gelobter says she brings an engineering mindset to New York City government. “I know how to build software,” she says. “I know how to run a technology organization from a technology perspective.” It’s also a cultural thing for her. “I’m wearing jeans to work—not because I don’t look great in a suit, but it’s a statement, right?” she says. (The same norm-breaking happened in the USDS, which had to overcome objections from bureaucrats who didn’t want to meet with anyone wearing a hoodie.) Naturally, the two people Gelobter hired to run the PIT crew program are also USDS veterans, Luke Farrell and Maya Israni.

Zillow Group’s layoffs will eliminate 91 jobs in Washington state, landing heavily on senior staff, according to a notice the company filed with the state Employment Security Department.
The filing under the federal Worker Adjustment and Retraining Notification (WARN) Act is the first detailed accounting of who was affected by the more than 500 layoffs the company announced Tuesday. The cuts hit about 7% of its global workforce, which stood at 7,058 as of March 31.
Zillow Group is officially headquartered in Seattle, but the relatively small share of the layoffs in its home state (18%) reflects how distributed it has become. The company adopted a remote-first model it calls “Cloud HQ” in 2020, at the height of the pandemic, and it has continued to bet on remote work as other tech companies pulled employees back to the office.
The list of affected job titles in Washington state is dominated by senior positions. It includes five directors and three senior directors, 14 principal-level roles, and a long list of senior managers and senior individual contributors. Relatively few junior positions appear on the list.
Product and engineering absorbed the most. Senior Product Manager is the single largest line at seven positions, followed by Senior Software Development Engineer, Software Development Engineer and Senior UX Researcher at four each. Together, product and engineering roles account for more than a third of the Washington cuts.
The list also includes AI and machine learning positions: a Senior Machine Learning Engineer, a Senior Manager of Machine Learning Engineering, a Senior Applied Scientist, a Senior Manager of Research Science, and an Annotation Lead, associated with labeling data to train AI models.
@media (max-width: 600px) {
aside.callout { float:none !important; max-width:100% !important; margin-left:0 !important; margin-right:0 !important; }
aside.callout .callout-img { display:none !important; }
}
Zillow told GeekWire on Tuesday that AI did not drive the layoffs. “Today’s changes are about better positioning Zillow for the path ahead, which includes having the right people in the right roles and being able to move faster,” a company spokesperson said.
The WARN notice adds a detail Zillow did not mention publicly: “Some of these terminations are the result of, or are expected to result in, the relocation or contracting out of operations and/or employee positions.”
Affected employees were notified Aug. 4 and will be terminated effective Oct. 5, more than 60 days later as required under state and federal law. They will continue to receive pay and benefits until then, according to the filing. Employees who are offered and accept another role at the company before that date will not be terminated.
The cuts affect workers at Zillow Group’s headquarters at 1301 Second Ave. in downtown Seattle and employees working from home elsewhere in Washington. The company said in the filing that its headquarters will remain open. None of the affected employees are represented by a union.
Zillow Group reports second-quarter earnings Wednesday afternoon.
networks
Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again
N-able has confirmed attackers exploiting an N-central zero-day made it into customer networks, as the vendor pushes out a second mandatory hotfix just days after the first.
The security shop published an update on Thursday detailing what happened after attackers exploited CVE-2026-18577, the critical N-central flaw that can hand an unauthenticated attacker administrative access to the remote monitoring and management platform.
According to N-able, attackers exploited vulnerable N-central servers remotely, then used the platform’s Take Control feature to connect to systems inside the environments being managed through them.
Once there, they registered a new Cloudflare Tunnel service to keep their foothold even after being booted from the N-central server – behavior that Huntress had already observed in the wild.
N-able has now confirmed that its own investigation found the same activity, and says a “limited number” of customers were affected. It hasn’t said how many customers that means, how many downstream systems attackers reached, or what they did once they had established persistent access.
N-Able didn’t answer these questions when asked by The Register, instead providing a statement saying it is “proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques.”
The firm’s limited disclosure comes alongside Hotfix 2, version 2026.3.1.10, which N-able says customers running N-central on-premises must install immediately – including those that already installed the first emergency fix released on August 2.
“This is not a duplicate of our previous communication,” N-able warned. “Hotfix 2 is required, even if you already applied the earlier hotfix.”
The company says the new update supersedes Hotfix 1 and adds further hardening measures as it monitors threat actors and watches them “evolve their attack techniques.”
Exactly what prompted the second round of defenses isn’t clear. N-able hasn’t said whether attackers found a way around Hotfix 1, and its latest description says the exploited vulnerability affected N-central servers running versions prior to 2026.3.1.7, the first hotfix. Hosted N-central environments have already received the latest mitigations, according to the vendor.
N-able first became aware of the attacks on July 31, after its Adlumin managed detection and response service picked up suspicious activity at a customer. Further digging uncovered a zero-day being actively exploited against an N-central server.
CVE-2026-18577 was subsequently disclosed, and the first hotfix was released on August 2. CISA added the bug to its Known Exploited Vulnerabilities catalog and gave US federal agencies until August 6 to fix it – an unusually short three-day deadline reserved for vulnerabilities the agency considers an urgent risk.
N-central is particularly attractive territory for attackers because managed service providers use the software to administer large numbers of customer systems from one place. Compromising the management platform can therefore provide a route into machines belonging to the MSP’s customers rather than leaving attackers stuck on the original server.
Huntress previously described successful exploitation as giving an attacker the same level of N-central access normally reserved for trusted network operations and engineering staff. Its investigation found attackers using that access to launch remote-control sessions against managed endpoints.
N-able has now published 10 IP addresses it says were used in the attacks and released a service template that customers can use to hunt for known indicators of compromise on Windows endpoints.
The company is warning customers not to take a clean scan as an all-clear, however, saying the tool only checks for indicators identified so far and that more may emerge as its investigation continues.
For anyone running N-central on-premises, the immediate instruction is pretty straightforward: install Hotfix 2, even if Hotfix 1 is already in place. ®
For a while now we’ve been mocking the Trump White House’s plans for an “AI framework” that would have the frontier AI labs hand over their top models for an initial review. After all, this was more or less the exact same plan that the Biden admin worked out in 2023, but it was done in a thoughtful and careful manner. And it caused a bunch of the VC bros in Silicon Valley to come out in support of fascism, while claiming it was a necessary defense against Biden’s attack on supposedly open innovation. Of course, all of that was bullshit, and that’s made even more clear by every step the Trump White House has taken to reinvent a similar “voluntary” AI review plan, but dumber.
Indeed, Trump’s AI framework is so dumb… that they’re keeping it a secret.
The White House does not plan to publicly release its new framework for evaluating advanced AI models, three sources familiar with the discussions told Axios.
Ah, transparency at work. It’s also wreaking havoc on the rest of the AI ecosystem that wasn’t invited to the White House to get the details.
The Trump administration invited staffers from OpenAI, Anthropic, Google, Meta, Nvidia, and other leading AI companies to the White House on Tuesday to share an overview of its new AI oversight framework, the people said. AI developers will have the ability to voluntarily submit new models to the federal government up to 30 days ahead of their public release. The White House will then vet their cyber capabilities according to a classified benchmarking system and share the AI models with federal agencies and trusted corporate partners.
The White House isn’t sharing more information about its testing criteria or which AI models will be covered by the framework, though open models will reportedly be excluded, according to Axios. That has left smaller AI startups, safety advocates, and third-party researchers in the dark about crucial aspects of how the federal government is addressing the cyber risks posed by advanced AI systems. Some argue that the secretive process will give an advantage to larger companies.
Considering that the likes of Andreessen Horowitz (investors in OpenAI) claimed they had to support Donald Trump over Joe Biden because they would support anyone who agreed with their “little tech agenda,” I’m curious how they can possibly square that with the fact that this new framework is significantly worse than the Biden framework, specifically for the “little tech” companies that a16z has used as a shield to defend their support for authoritarian politics?
Of course, the other reason why the White House is probably keeping the framework a secret is because it would show how incompetent they are. All the reporting so far suggests the entire process has been a clusterfuck, which is much more about which companies get to set up which regulatory moats to protect their own business models, rather than what’s best for either innovation or the American public.
At Nvidia, Microsoft, Google and Meta, executives grew increasingly concerned that Anthropic and OpenAI would win over the White House with their arguments for tighter restrictions, according to two of the people. That would potentially cement the A.I. start-ups’ positions as market leaders,
Other A.I. labs were at risk of falling permanently behind, the people added. And because several of the companies make their own open-source models or supply hardware to businesses that use open-source technology, they worried the restrictions could harm them.
Over private texts, phone calls and video conferences, executives quietly built an argument that open-source models were good for the world and for American innovation, according to three of the people familiar with the talks.
But, of course, that’s just the way things work when you have a White House that makes decisions entirely based on transactional motives, rather than anything involving principles.
As we discussed last week, so much of this is all about whose vision of the AI world wins out — whether a handful of giant companies get to lock in the regulatory moat they’ve built for themselves, or an actually competitive market lets people make their own decisions and keep control over their own experiences. Maybe that’s the real reason nobody’s allowed to see the rulebook: because it would reveal who the administration agreed to let write the rules.
Filed Under: ai, ai framework, competition, donald trump, joe biden, open weights, voluntary testing
Companies: a16z, anthropic, google, nvidia, openai

Between July 21 and August 6, OpenAI, Anthropic, and Meta each disclosed that AI under evaluation had broken into other companies, and the UK’s AI Security Institute disclosed that models it was testing had tried. Each AI was told to win a game, and it found an unexpected way to do so.
Some people feel blindsided by these attacks, but they shouldn’t be. We are simply living what I’ve long called the “Murphy’s Law of AI,” now in the age of cyber-capable AI agents. To put it as plainly as possible: Anything AI can do wrong, it will do wrong.
My 2018 version ran longer. As I wrote at the time, when you give AI a goal, it will do it, whether or not you like the implications. Goethe got there in 1797 with the sorcerer’s apprentice, a broom that would not stop carrying water.
Each of these systems was running an evaluation: capture a flag and win the game. The intrusions were the shortest path to a high score. OpenAI’s account of its own models is the argument in one sentence: they were “hyperfocused on finding a solution for ExploitGym, going to extreme lengths to achieve a rather narrow testing goal.” This is not a surprise; this is what AI does. It’s Murphy’s Law of AI in a nutshell.
Press coverage landed on “AI can now hack.” That’s missing the broader threat: the more capable AI gets, the more can go wrong.
Loitering munitions given a target list may find that the fastest way to finish the list is to lengthen it. A warehouse robot told to clear an obstruction may count the person in front of it as an obstruction. Agents that open accounts and buy compute are a short step from spawning copies of themselves, and that first step is not hypothetical. To win its exercise, Claude needed a package-registry account, which needed an email address, which needed a phone number. Phone numbers cost money, so it tried several ways to get some. None of this requires superintelligence. It requires an imperfect boundary and a scoreboard.
The industry has a name for the underlying failure. Dario Amodei and five co-authors called it reward hacking in “Concrete Problems in AI Safety” in 2016. Their proposed cure is better alignment, and Amodei’s January essay, The Adolescence of Technology, makes the case in the language of upbringing. He likens the shaping of Claude’s character to “a child forming their identity by imitating the virtues of fictional role models they read about in books,” and sets a goal for 2026 of a Claude that “almost never goes against the spirit of its constitution.”
@import url(‘https://fonts.googleapis.com/css2?family=Roboto+Slab:wght@500&display=swap’);@media (max-width:768px){.gw-pt{display:none!important}}
Indeed, Anthropic’s newest model recognized on its own that its target was real and stopped, though Anthropic notes it went further before stopping than the company wanted.
But alignment isn’t a trustworthy solution to AI’s problem. Perfect alignment is not achievable, and the target is incoherent: aligned to what, and to whom? The same essay concedes that Claude blackmailed fictional employees when told it faced shutdown. “Almost never” is not a safety property.
Put a number on it. At 99.9 percent, across millions of agentic tasks a day, that’s thousands of violations a day. Alignment also does nothing about people who strip the safety training out or run open weights that never had a constitution.
The alternative is not a new idea, and enterprise security has been building versions of it for years. It’s called bounded autonomy. We never tried to “align” electricity; we simply put a breaker on every branch of the house, and the breaker doesn’t need to know what caused the surge.
Bound what an agent can touch rather than what it wants. The limits are set in advance, live outside the model, and are enforced by software the model doesn’t control. The agent still chooses its own route. The perimeter decides which routes exist.
Nothing depends on what the model believes, which matters, because belief is what failed. Anthropic’s prompt told Claude it had no internet access. Claude believed it. The network said otherwise. A bounded system doesn’t tell an agent it has no internet. It gives it none.
If you want to get into the weeds: bounds cost something. The AI Security Institute opened the internet to its agents on purpose, because that’s the only way to measure what a model can really do, and it now says such access must be justified rather than assumed.
@media (max-width: 600px) {
aside.callout { float:none !important; max-width:100% !important; margin-left:0 !important; margin-right:0 !important; }
aside.callout .callout-img { display:none !important; }
}
The category is real and funded. For example, Certiv, a Seattle startup, launched in March with $4.2 million to put software on the employee’s machine that checks each action an AI agent attempts against company policy and blocks violations. “You cannot control these new workers if you don’t live on the compute where agents actually run,” CEO Jason Needham said at launch. CodeIntegrity is building an adjacent layer, and Mandiant founder Kevin Mandia raised $190 million for Armadin, which points autonomous agents at the offensive side of the same problem.
In 2017, I argued in the New York Times that “any A.I. must have an impregnable ‘off switch.’” That was a call to arms then. It’s a product category now.
Two objections to off switches invariably come up. The first is that AI will talk the human out of using it. Mythos 5 tried something close, inventing GitHub identities to pressure a maintainer into approving malicious code, and the maintainer refused. The institute says the margin was narrow and rested on human vigilance rather than a technical barrier, which argues for better barriers.
The second objection is that AI will move faster than any human can react. So do equity markets, which is why their circuit breakers trip automatically. Bounded autonomy doesn’t require a person in the loop at machine speed. It requires a boundary that holds at machine speed.
Both objections, in their extreme form, assume AI is omnipotent, and you cannot stop omnipotence. AI is not God. It is powerful technology, and powerful technology is what safety engineering has always been for.
The problem is Murphy’s Law of AI. The solution is bounded autonomy.
A New Mexico court has ordered Meta to pay $567 million for failing to warn the public about the dangers its social media platforms posed to children. The judgment is in addition to the $375 million the Instagram and Facebook parent company was ordered to pay in March as part of the trial’s first phase.
In a ruling late Thursday, Judge Bryan Biedcheid wrote that New Mexico teens are in the midst of a mental health crisis and found that “Meta’s platforms are a significant contributing cause to the crisis.” The $567 million will fund awareness and prevention, screening and assessment, and referral programs, with the bulk — $420 million — going to treatment.
Biedscheid’s ruling called Facebook’s platforms a “public nuisance” and compared Meta to a factory, with advertising and other content displayed on the platforms as its product and “the psychological harm and sexual exploitation of children to be the pollution that must be abated.”
The court ordered Meta to implement private-by-default settings for its users under 18 and to limit their Friends to users who are also under 18. Accounts belonging to under-18s shall not show up in search or appear in recommendations, according to the order.
New Mexico Attorney General Raúl Torrez said Thursday’s verdict is a victory for parents worried about the effects social media is having on their children.
“This case has always been about protecting children, standing up for families, and making sure that one of the world’s largest technology companies cannot profit from practices that endanger young people without consequence,” Torrez said in a statement.
Meta said in a statement that it disagreed with the ruling and would appeal it.
“We work hard to keep people safe on our platforms and have been transparent about the challenges of identifying and removing bad actors and harmful content,” a Meta spokesperson said in a statement. “We remain confident in our record of protecting teens online and will continue to defend ourselves against claims that misrepresent the facts.”
This isn’t the only legal scrutiny Meta has faced over how it handles underage users on its platform. In March, a California jury found both Instagram owner Meta and Google’s parent company Alphabet liable in a lawsuit brought by a 20-year-old woman who alleged that YouTube and Instagram were designed to be addictive to children.
Social media platforms have introduced specific settings and tools for their youngest users, such as Instagram’s teen accounts, but many of these were launched relatively recently, in just the past few years.
Weekend Open Thread: Wit & Wisdom
Meta enters AI-training agreement with far-right ‘propaganda rag’ Newsmax
Zack Polanski: an incitement to murder Nigel Farage?
MicroStrategy Post-Earnings CLARITY Act Push Could Add New Catalyst for Its Stock
XRP Ledger v3.3.0 brings five institutional features
New York sues Kalshi over prediction market gambling
Crypto PAC spending tops $2M in Michigan House race
DTCR: Deleveraging And A Hedge Fund Collapse Point To A Possible AI Bottom
ESET tracks rise in malicious AI skills and adaptable malware
3 Fed Officials Just Explained Their Rate Hike Vote: Is Inflation Winning?
France Cricket implodes: letters hidden in a drawer and a board at war
XRP Ledger urges node upgrade after manifest flood
Moneyflip CEO charged in $40K murder-for-hire plot
Bruno Fernandes decision made as Man United ‘discuss’ striker transfer option
FIFA has scrapped $20 billion World Cup sell-off plan, New York Post reports
Financial Crash Expert: The 90-Day Collapse Timeline They Are Desperately Hiding.
Jordan Coyle & Cordiamo take Laya Arena Stakes at RDS
Commonwealth Games 2026 Live Updates | Day 9 CWG 2026: Lovlina Borgohain, Sachin Siwach Enter Final After Indian Judokas Script History
US Tech Stocks See Largest 5-Week Inflow in History: Can Nasdaq Break Its Downtrend?
Tourist plane on sightseeing flight in Peru crashes into a field, killing all 13 people on board
You must be logged in to post a comment Login