Connect with us

Tech

Two H1 2026 attack chains

Published

on

Cybershield

Gen Threat Labs followed two H1 2026 campaigns where attackers used legitimate accounts, browser settings and blockchain data as part of the attack path.

The Gen Threat Report is a twice-yearly examination of the biggest cyber threats shaping the digital landscape, offering an in-depth look at the trends affecting consumers around the world. Gen’s H1 2026 Threat Report has its share of headline numbers.

Scams accounted for almost 46% of Gen threat detections in the first half of the year. Malvertising represented almost another 30%. Gen blocked 114.2 million e-shop scam attacks and 20.3 million tech support scam attacks during the same period.

Those figures are useful, but they compress very different attacks into a handful of categories. A detection count does not show how the first lure became script execution, how the script became a browser or proxy change, or how a wallet address was replaced before the victim signed a transaction.

Advertisement

Two H1 investigations are worth looking at in detail. In the first, a banking-malware campaign started with compromised corporate mailboxes and ended with proxy and browser manipulation.

In the second, a cryptocurrency campaign used a Rust-based clipper and retrieved command-and-control infrastructure pointers from Binance Smart Chain.

The payloads were different, but neither campaign depended on breaking the trusted system in front of the user. The banking campaign used a legitimate account to deliver the lure. The clipper let the blockchain record a valid transaction after changing the destination address locally.

Two attack chains

The business email really came from a business

The banking campaign targeted users in Czechia, Slovakia, Poland and Lithuania. The lures looked like normal business emails: shipment notices, invoice-related messages and scanned document notifications. One simply told the recipient that a scanned copy of a shipment was attached.

Advertisement

In several cases, the messages were sent from compromised corporate mailboxes. The email was not made to look like it came from a legitimate company. It came from a legitimate account that attackers had already taken over.

SPF and DKIM can still pass when a message is sent through authorized infrastructure, while reputation systems may see a sender with a legitimate history. 

The attachment launched a JavaScript dropper. From there, the chain moved through PowerShell stages before reaching shellcode and banking functionality. The available indicators pointed towards GepyS.

The malware modified proxy settings and installed a browser add-on, placing itself close to the victim’s banking session. 

Advertisement

At a simplified level, the chain looked like this: compromised mailbox -> JavaScript dropper -> PowerShell stages -> shellcode loader -> proxy and browser manipulation.

One stage-three payload used a 32-bit position-independent loader. Static analysis showed MMX and SSE junk instructions, jumps into the middle of instructions, and a decryption routine based on an LFSR-generated keystream followed by XOR.

None of those techniques was new, but together they added enough friction to make a quick static pass less productive.

Across the chain, the email only had to get the user to open the attachment. JavaScript and PowerShell handled the staging, the loader slowed analysis, and the proxy and browser changes moved the operation into the banking session.

Advertisement

Comparable H1 campaigns used similar regional and operational patterns with different payloads. In Italy, fake invoice PDFs, including Booking.com-themed lures, led to Vercel-hosted scripts with per-victim JavaScript obfuscation, Blogspot-hosted PowerShell stages and XWorm.

In Poland, invoice-themed phishing delivered a steganographic .NET loader that installed Remcos RAT.

Gen Threat Labs analyzed H1 2026 activity across scams, malware, identity exposure, privacy and AI-driven threats.

The full report includes telemetry, case studies and guidance on how attacks are moving through trusted workflows.

Advertisement

Read the report

The clipboard was the payment layer

The second campaign abused a much smaller user interaction: copying and pasting a cryptocurrency address.

The final payload was a Rust-compiled clipboard hijacker. It monitored copied content for wallet addresses across 21 blockchain types, including BTC, ETH and LTC. When the malware recognized a supported address, it replaced it with an attacker-controlled one.

From the victim’s point of view, the transaction could still look normal: copy an address, paste it into a wallet or exchange, and approve the payment.

The blockchain was not compromised and the wallet’s cryptography was not broken. The transaction itself was valid, but the destination had already been changed locally before signing.

Advertisement

Wallet addresses are long, visually noisy strings and difficult for humans to verify. Many users check only the first and last few characters, giving attackers room to use replacement addresses that survive a quick glance.

The command-and-control design added another layer. The malware used Binance Smart Chain as part of its C2 resolution through EtherHiding. It did not store the full backend on-chain. Instead, it read infrastructure pointers from data stored in a smart contract and used them to reach attacker-controlled infrastructure.

The resolved domain, URL or IP address could be blocked, taken down or replaced. The smart-contract data remained publicly readable, useful as an investigative pivot and harder to remove through normal takedown processes.

A simple network IoC list therefore aged quickly in this setup.

Advertisement

The contract address, the method used to read its data, the returned value and the infrastructure reached afterwards belonged in the same investigation.

Detection has to follow the sequence

For the banking chain, sender authentication needs to be paired with post-delivery telemetry. An attachment launching JavaScript, PowerShell retrieving additional stages, shellcode execution, proxy changes and a new browser extension should be correlated as one sequence rather than handled as unrelated events.

A sender’s legitimate history should not lower the priority of that activity when the mailbox itself may be compromised.

Where operationally possible, organizations can restrict script interpreters for users who do not need them, apply application-control policies to downloaded attachments and alert on unexpected proxy or browser-extension changes.

Advertisement

Monitoring for mailbox takeover remains part of the same detection problem because the compromised account is also the delivery infrastructure.

For the crypto campaign, defenders can monitor clipboard-modifying processes, wallet-address pattern matching and blockchain queries from applications that have no reason to make them. The smart-contract pointer and the infrastructure it resolves should be tracked together rather than treating the current C2 domain as the complete indicator set.

Users making cryptocurrency payments should verify the full destination shown by the signing device or wallet immediately before approval.

Address books or allowlists reduce repeated manual entry, while first-time or changed destinations deserve a full comparison rather than a check of only the opening and closing characters.

Advertisement

In both campaigns, the first trust decision could look legitimate while the surrounding workflow had already been changed. Detection and verification need to cover the steps between the authenticated email, the copied value and the final action.

Gen’s H1 2026 Threat Report covers the broader picture across scams, malware, identity exposure, privacy and AI-driven attacks.

Read the full report here: Gen H1 2026 Threat Report.

Sponsored and written by Gen Digital.

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

4 new 4K Blu-rays from July 2026 to add to your collection

Published

on

Welcome to the Blu-ray Bounty July 2026. This is where we test the latest 4K releases of each month that we think will be perfect for showing off your home theater. If you’re new to the Blu-ray Bounty, you can check out previous editions here, where we’ve reviewed over 100 discs since starting in November 2024.

4K Blu-ray is easily one of the best ways to enjoy a movie at home, especially when it’s on the best TVs and best soundbars. I personally use it as my main source for testing AV equipment, thanks to its uncompressed picture and audio quality.

Source link

Advertisement
Continue Reading

Tech

ClickFix attack pushes macOS infostealer for crypto theft attacks

Published

on

Go-based macOS infostealer hijacks cryptocurrency transactions

A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials.

​The malware can intercept and redirect transactions with various cryptocurrencies. Although it can empty wallets entirely, it can also calculate the total value of a transaction to determine how much to divert to the attacker.

Security researchers at Managed Detection and Response (MDR) services company Huntress discovered the payload after responding to a ClickFix incident.

image

The targeted user received an email with a link to a page instructing them to run a command in Terminal.

This downloaded a Bash script acting as a profiler and malware loader that collected system information (e.g., CPU, RAM) and retrieved a Mach-O payload that matched the victim system’s processor architecture.

Advertisement

The profiler also identified the account name for the currently logged-in user and created a directory named after trustd, the macOS process responsible for validating cryptographic certificates and code signatures.

It copied the infostealing and crypto-draining payload to the directory as com.apple.verified and removed the com.apple.quarantine extended attribute to prevent Gatekeeper from treating the file as quarantined and showing a security alert when executed.

According to Huntress’ analysis, the malware establishes persistence and increases privileges by collecting system credentials via a fake error created using the osascript utility.

Fake dialog box prompting for admin password
Fake dialog box prompting for admin password
source: Huntress

The stealer payload checks the storage for files containing credentials, identified both by name and their extension.

“Browser password databases, the Apple Keychain, and cached credentials in browser cookies are all targeted,” Huntress says.

Advertisement

However, the Go-based malware also includes code that modifies cryptocurrency transactions before they are signed, and can be configured to redirect to the attacker only a percentage of the funds.

Malware can be configured to drain a certain crypto amount
Malware can be configured to drain a certain crypto amount
source: Huntress

Huntress says that it is the first time they analyzed a crypto drainer that did not empty victims’ wallets but could remove less than the total amount.

Additionally, the researchers observed separate functions that determined the value of 1% of the wallet’s content, depending on the cryptocurrency type.

Among the targeted cryptocurrency assets are Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple’s XRP.

According to Huntress, the malware communicates to shared IP addresses in Autonomous System (AS) 210644, which is “operated by a Russian corporation known as the Aeza Group.”

Advertisement

The company and individuals affiliated with it have been sanctioned by the US and the UK for providing bulletproof hosting services to ransomware groups.


article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Advertisement
Continue Reading

Tech

Indyx review: Wardrobe apps say they’ll help you shop less. Do they overpromise?

Published

on

The influencers have started to promise me that they know how to get me to stop shopping: I just have to enter every garment of clothing I own into an app, one by one. “I digitally cataloged my ENTIRE wardrobe,” they swear on videos, routinely pulling in hundreds of thousands of views.

The selling point of these apps (Indyx, Whering, ACloset, OpenWardrobe, and many more) is seductive; they promise to help users understand exactly what they already own so that they shop less. In theory, that means saving money — and slowing the steady damage the fashion industry is wrecking on our planet.

“Collectively, we are buying and then throwing away more than ever before,” Indyx warned on its website, before reciting dire statistics about how many clothes are produced now and how many of them end up in landfills. Luckily, it said, “We’re here to break the cycle.”

That idea appealed to me. I am not a fashionista, but I enjoy clothes enough to buy more than I really need, despite what I know about fashion’s impact on the planet. My intellectual understanding of climate change can’t always stop me from clicking “add to cart” when I see a dashing pair of wide-legged trousers, even though there’s a hard limit on the number of times a person can wear wide-legged trousers in one week.

Advertisement

Still, to make these apps work, you have to individually enter photos of everything you own now and everything you buy in the future, which sounds like a tedious, laborious process. (You can take the photos yourself or hunt down product pictures from the brand.) And because so many influencers are pushing this, it’s hard to tell how life-changing it really is and how much is just marketing speak and hype. So, I decided to test one of these apps — Indyx — for you. I also talked to wardrobe cataloging enthusiasts and experts on sustainable consumption to see what I could learn from them. I wanted to know: Could cataloging our wardrobes actually make us shop less? And, if it can, would it be worth the effort?

  • Experts estimate the fashion industry accounts for between 2 to 10 percent of global greenhouse gas emissions.
  • Wardrobe cataloging apps are presented as a strategy for buying fewer clothes, helping to minimize fashion’s impact on the planet.
  • Some people find these apps to be a constructive way to redirect their shopping energy.
  • But the initial setup process for the apps is highly labor intensive, and they require constant tending over time.
  • Wardrobe apps may be right for you if you find yourself reflexively browsing clothes in your spare time, and you want to direct that impulse elsewhere.
  • They may be wrong for you if the idea of photographing everything you own individually fills you with a powerful dread.

“There’s only one solution to the mess that we find ourselves in: buying less”

Wardrobe cataloging apps did not always advertise themselves as being good for the planet.

In 2023, the journalist Avery Trufelman investigated the nascent wardrobe cataloging app industry for her podcast series Articles of Interest. She found that a lot of the apps flopped. The issue was the business model, which was based on revenue generated from affiliate links. The idea was that people would click to purchase items they saw within the apps, and the company would take a cut of each sale. But when the apps were well designed, Trufelman reported, users felt less of a need to buy more clothes.

The current generation of wardrobe cataloging app developers has turned this from a bug into a feature. They now market their wares as the solution to overshopping, and they make their money by charging for either the app itself or for its extra content. (Indyx itself is free, but you have to pay a $75 yearly subscription for its enhanced features.)

Advertisement

What the marketing gets right is that the fast fashion problem is real. “Anywhere from two to 10 percent of our global greenhouse gas emissions are associated with fashion,” said Brie Berry, assistant professor of environment and sustainability at Ursinus College in Pennsylvania.

Fashion’s emissions are generated by the factories that manufacture clothing (the water and the fertilizers for growing cotton, the oil for developing synthetics) and the consumers who wear these garments (the slow shed of microplastics from yoga pants, the water and the energy consumed by washing and drying). When we get rid of old clothes, much of it ends up in landfills or incinerated. By some estimates, the fashion industry contributes more to climate change than the aviation industry.

“There’s only one solution to the mess that we find ourselves in: buying less,” said Katia Dayan Vladimirova, a researcher whose consulting firm Post Growth Fashion focuses on alternatives to growth in the fashion system.

To buy less, it helps most people to know what they already own, said Alyssa Beltempo, a slow-fashion content creator and educator. Beltempo makes videos guiding viewers through the process of “shopping their own closets” to help them buy less stuff, but she’s found in her work that a lot of people aren’t clear on the contents of those closets. Because of that confusion, they end up buying stuff they don’t need.

Advertisement

That’s where cataloging can be helpful, Beltempo said. “These apps reduce that hurdle of not seeing the clothes you have,” she said.

Personally, what I was looking for wasn’t enhanced clarity so much as a barrier. I wanted to erect a wall between my desire to own a new piece of clothing and the click of the buy button. A searchable, scannable lookbook of everything I owned, I thought, might well do the trick.

How to catalog every piece of clothing you own

A photo of a black t-shirt with the phrase BOURGEOISIE SAUVAGE written in yellow print.

The Indyx AI’s first attempt at rendering my sweatshirt. Note the yellow text.
Constance Grady/Vox
A black sweatshirt with text saying BOMIRGEOISIE SAUMA8E.

One more try.
Constance Grady/Vox
A black sweatshirt saying BOURGEOISIE SAUVAGE in white text.

There we go.
Constance Grady/Vox

Indyx has been hyping up its new AI feature, which transforms a picture of a garment hanging limply off a hanger into a neat flat lay photo. It sped the process up, but it was also buggy; it garbled text on the front of T-shirts, misread colors, and had a tendency to interpret loose threads as ornamental bows while leaving wrinkles (I am not an ironer) untouched.

Advertisement

I was also concerned that the process inserted AI, with its insatiable need for water and energy, into a project sold as a way of reducing my environmental impact. But the sustainability experts I spoke to were both skeptical that this sort of light AI use was such a big deal.

“Taking photos and then asking an app to think about how to arrange your clothing into outfits is probably one of the lighter uses of AI that I could imagine,” Berry said. Vladimirova agreed that using AI for this task is unlikely to be as bad for the planet as buying even one new garment. “But then, there is also no proven causality between using this app and reducing overconsumption,” she added as a caveat.

It’s possible to input your clothes into Indyx without using the AI feature, but the truth is: I don’t know that I could have made myself go through with the whole rigamarole without it. I ran out of free AI processing about 80 percent of the way through and, overwhelmed at the thought of having to do my own flat lays, paid $75 to buy more without hesitating.

All told, it took me about five hours and many old episodes of Top Chef to photograph my summer clothes, not including shoes, jewelry, or accessories. My time spent cataloging did not include the process of entering additional data about each garment (including its initial cost, its fiber composition, where I bought it), a herculean task that I have been tackling much more slowly than the initial entry process.

Advertisement

Doing the shoot properly would have taken longer. Angela Goodman, a 51-year-old marketer from Seattle with a background in product photography, says she ran her own cataloging session like a pro shoot, using art lights and folding and refolding each garment to lie perfectly. It took her 10 hours spread out over multiple weeks.

As an exercise, photographing every piece of clothing I owned was clarifying, although not significantly more clarifying than going through it Marie Kondo-style. It left me with a small donation pile of items I no longer wanted and a fretful awareness that I own too many white T-shirts. In theory, that’s the kind of insight a wardrobe cataloging app produces by the spade.

“I’m not shopping. I’m building.”

Vladimirova, the sustainability consultant, said that, even though she has a better idea than most of how destructive the fashion industry is, she struggles with over-shopping. She thinks a lot about why people buy so many clothes; her best guess is that it’s a way to self-soothe.

Advertisement

“A lot of consumption happens in the evening when we feel vulnerable and tired, and we’re trying to reward ourselves with this shot of dopamine,” she said. For some people, these apps can replace the dopamine hit that comes from scrolling through other people’s outfit photos with the dopamine hit of scrolling through your own clothes, neatly folded and filtered until they look like aspirational fashion inspo.

Two charts appear above each other. The first shows a wardrobe broken down by type of garment. The second shows a wardrobe broken down by color of garment.

Indyx generates statistics about your wardrobe. Here, mine is broken down by type of garment and color.
Constance Grady/Vox

Part of the satisfaction here is the infographics. After you’ve given Indyx all your fashion data, the app crunches your numbers and tells users how much you’ve bought new versus secondhand, as well as the share of natural fibers as opposed to synthetics in your closet, so that you can track the environmental impact of your shopping habits. (Synthetics tend to have a higher carbon footprint than natural fibers.) It tells you what their cost per wear is on each item to help you track which expensive garment was worth the splurge and which was a waste of money. Users can also plan outfits. You can share your wardrobe with stylists who will plan the outfits for you (on Indyx, the service ranges from $25 a month to “the low hundreds”). It’s like playing paper dolls with your own wardrobe.

For Goodman, the former product photographer, all this data takes the place of recreational shopping. She describes getting a marketing email from one of her favorite brands about a sale. After a quick scroll through their offerings, she found that she felt no urge to buy.

“I was like, ‘I do not need more clothes. I’m going to go update my Indyx, because I’m a couple of weeks behind,’” she said. She started inputting the last few outfits she’d worn into one of the Indyx services that is supposed to allow users to track their patterns and see which clothes they actually wear and what they like in an outfit. “I’m playing with clothes,” she said. “But, like, I’m not shopping. I’m, you know, building.”

Advertisement

Over time, all this data is supposed to inform future shopping choices. “There is something very clear about seeing two pieces that you’ve owned for the same amount of time — one that you’ve worn 57 times and one that you’ve worn twice,” said Alexandra, a 29-year-old consultant in Northern Virginia who requested her last name be withheld. She thinks tracking her clothes has given her “a little bit less buyer’s remorse.”

Cataloging your wardrobe can’t prevent a compulsive need to buy, though.

“I don’t think it cured me of my undiagnosed shopping addiction,” Alexandra said. “You can very quickly go from ‘I’m cataloging what I have’ to ‘I’m seeing a bunch of gaps in my wardrobe that I should fill immediately.’”

“There just wasn’t incentive anymore”

Advertisement

The main question I had about these apps was whether, with such a labor-intensive process, there comes a time when the juice is no longer worth the squeeze.

Alexandra says that she gradually stopped using her wardrobe app last year, after she moved out of her own apartment and back into her family’s suburban house in the midst of a career transition.

“I was separated from a lot of my belongings for a very long time, and then, as I started to get things back, it didn’t feel worth the effort anymore,” she said. Who was she going to see in one of her curated outfits? “My job’s on a computer. When I leave the house, I go to the grocery store and the pharmacy and the bookstore,” she said. “There just wasn’t incentive anymore, compared to when I was closer to the city and doing things more regularly.”

Beltempo, the slow fashion content creator, said she doesn’t bother to add every new purchase to her own catalog.

Advertisement

“I really use it more for my packing,” she said. Before she travels, she makes a list of likely candidates for her suitcase and enters them into the app. “And then, I’ll play, and I’ll make outfits,” she says.

Vladimirova, the sustainable consumption researcher struggling with overshopping, gave the apps a spin. She tried three of them and found that she was only able to stick with each one for a matter of months. “In the beginning, when the novelty of the app is there, it’s very satisfying,” she said. “It records your outfits in vivid colors. It can crop out the ugly background and keep it very neat, create fancy capsules. They look so lovely.”

But over time, they all began to bore her. “And now, I forget to update when I buy something new — usually from secondhand sources — and it kind of lost its meaning for me,” she said. “But the premise is good!”

My own experience seems to be closest to Vladimirova’s. I keep having to remind myself to enter my outfits into Indyx. Every time I put on a piece of clothing, I think with dread, “Oh god, if I don’t look up how much I paid for this, I’ll never know my cost per wear and, then, what’s the point?” I keep giving my shoes guilty looks and thinking about how I should really photograph and catalog them — if I’m doing this right.

Advertisement

“It’s a project,” said Lauren Ludwig, a 41-year-old who has been using her wardrobe apps for the past three years. “But it’s a fun one for someone who enjoys clothing.”

Indyx and its brethren are slick, and their infographics are beautiful. For dedicated wardrobe hobbyists, they’re probably a great option. But for most people who just want to cut down on their clothes shopping, it’s hard to say that the $75 annual subscription is worth it. The free version will give you the same paper doll effect if you are willing to do your own flat lays, or you can recreate it by dragging phone camera pictures of your clothes onto a Google Slides deck.

If you find, as Vladimirova theorized, that you shop when you don’t feel good, you can try replacing that habit with a “dopamine menu” of small acts that bring you joy, like hugging a pet, doing a puzzle, or going for a walk. And if your closet is filled with brand new clothes you never wear, you’re racking up debt buying clothes, or you just have the nagging sense that your shopping has spiraled completely out of control, therapy is not a bad idea.

Personally, I found that Indyx could not give me what I really crave when I want to play with clothes: the understanding of the way fabric drapes against my body, the knowledge of its texture against my skin. There is no substitution for the slow analog process of walking into my closet, touching my clothes with my human hands, and learning with my five senses that what I have is already enough.

Advertisement

Source link

Continue Reading

Tech

Suno Says It Will Start Watermarking Songs

Published

on

Suno says it will begin watermarking and fingerprinting AI-generated songs, tighten download policies to curb mass distribution, and explicitly prohibit deceptive audio and unauthorized voice or likeness cloning. The changes come as the company faces mounting copyright lawsuits, a recent adverse ruling in Germany, and scrutiny over a past data breach that revealed training-data sources. TechCrunch reports: In a blog post, co-founder and CEO Mikey Shulman shared core principles and said that the platform wants to promote original creation while enabling more people to make music with its AI tools. One of the key points of contention involved users uploading AI-generated songs on other streaming platforms and gaming the system to earn revenue. Suno said that now it will use audio watermarking and fingerprinting to prevent misuse on other streaming platforms. It’s not clear if Suno will use an existing system like Google’s Synth ID or adopt a new one, and the company did not say when contacted by TechCrunch about this.

The startup also signed an agreement with lyrics provider Musixmatch to use its Sentinel system for copyright detection, the blog post said. […] The company added that it plans to add a new download policy to bar mass distribution on streaming platforms, but declined to provide details on the record. Suno has also changed its community guidelines to explicitly prohibit “deceptive audio presented as real” and “using a real person’s voice or likeness without permission” to prevent copycats.

Read more of this story at Slashdot.

Advertisement

Source link

Continue Reading

Tech

Cloudflare launches Kitesurf, a browser built for AI agents

Published

on

Cloudflare is the latest company to join the race to build a new web browser. But instead of pitching a Chrome alternative to consumers, the internet infrastructure provider launched Kitesurf, a cloud-hosted browser designed specifically for AI agents.

AI software is evolving from chatbots that answer questions to agents that can complete tasks on users’ behalf. Browsers are a critical part of this transition, as they’ll need to navigate the web and use websites, as humans do.

Unlike traditional web browsers built for humans, a browser built for AI agents doesn’t care about visual elements, like themes, tabs, or browser extensions, Cloudflare explained in its announcement. A browser designed for AI agents needs to manage context windows, performance, token costs, and scalability. It also faces a different threat model because an AI browser could be subject to vulnerabilities like prompt injection attacks and more, the company noted.

With Kitesurf, AI developers will be able to build software that can navigate websites, fill out forms, and complete other browser-based tasks, without having to build their own browser software.

Advertisement

Cloudflare says it decided to build Kitesurf just 12 weeks ago, and it runs entirely on top of the company’s serverless platform, called Workers. Kitesurf is available for free while in beta in Browser Run, which lets developers programmatically control and interact with headless browser instances on Cloudflare’s network.

For developers, Cloudflare’s pitch is that this enables AI agents to use the web more efficiently while using less computing power than Chromium, which keeps costs down.

“Kitesurf is significantly more efficient in CPU and memory consumption than Chromium for common agentic tasks like screenshots and HTML extraction,” according to the company.

Image Credits:Cloudflare

The browser itself was built from other technologies, including a modular rendering engine from Blitz; Firefox’s CSS parser, Stylo; and Boa JS, a Rust ECMAScript engine. Everything else runs inside Cloudflare Workers. Although still new, Cloudflare says Kitesurf already passes around 215,000+ web platform tests, and it’s adding hundreds more, passing tests every week.

Cloudflare also credited the open source Rust headless engine, Obscura, for inspiring it to develop Kitesurf, noting that the first proof of concept was a port of Obscura to Workers.

Advertisement

The company said the browser correctly renders pages like TodoMVC, a popular benchmark application for comparing JavaScript frameworks, along with Wikipedia, Hacker News, the Cloudflare Blog, and much of the Cloudflare dashboard.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Source link

Advertisement
Continue Reading

Tech

Cops Across The US Are Being Fired For Misusing Flock Camera Data

Published

on





Over 120,000 Flock cameras are found along roads throughout the United States, surveilling 6,000 communities. While these artificial intelligence cameras are meant to be used to record license plates for related crimes, residents have remained skeptical, accusing Flock cameras of putting personal information beyond just plates in nationwide databases that don’t have proper oversight. It certainly hasn’t helped that there have been over 50 cases of police officers misusing the information gathered from Flock cameras, most often to spy on women. 

Georgia is one of the most Flock-heavy states, with Atlanta boasting the most cameras in the country at 5,000. Ten officers from the state have been arrested for misusing the license plate information collected from the Flock cameras, with additional officers still under investigation. Former Police Chief Michael Steffman had used the cameras to monitor his ex-girlfriend’s location around Atlanta over 600 times, reported The Washington Post, resulting in stalking, harassment, and license plate reader misuse charges. He was found dead before he went to trial. 

Advertisement

Police officers have easy access to Flock data, and are misusing it

The Institute For Justice has been reviewing the privacy and security concerns associated with Flock cameras, noting that the most common reason for surveillance abuse has been stalking partners, exes, and even attractive strangers. 

There are currently around 30 cases of police officers using Flock cameras to stalk their romantic interest. In Georgia, Deputy Christian Brewer was fired and arrested after using Flock cameras to track his partner. Sergeant Michael Palitz resigned after stalking a female officer in Texas. Florida Detective Brandy Almany was fired and charged for using data to track her husband’s ex-wife. Deputy Lamar Roman in Florida was able to eventually pull over a woman he’d been stalking with Flock cameras.  

Flock Safety (Flock’s official blog) has stated that there are internal safeguards to prevent misuse, including logging every search and providing audit tools to identify unusual usage. However, the Institute For Justice reported that most stalking incidents were not internally investigated and were only found out once the victim realized they were being followed and contacted police. With no required warrant, every police officer has the ability to look at all private information captured by Flock cameras — and it seems to go unnoticed. To fight against Flock cameras’ invasiveness, drivers have started mapping out where the cameras are located and checking if they have been stalked on HaveIBeenFlocked.

Advertisement



Source link

Advertisement
Continue Reading

Tech

The Pixel 11 is almost here, but I’m more excited about what could come with it

Published

on

It’s August, which means one thing if you follow smartphones even remotely closely: new Pixels are almost here. Google is holding its next Made by Google event on August 12, and this year, we’re expecting another packed lineup of phones. The Pixel 11, Pixel 11 Pro, Pixel 11 Pro XL, and Pixel 11 Pro Fold are all expected to take the stage. Yes, that’s the same four-phone lineup Google gave us last year, but the interesting part will obviously be what’s changing underneath. Between the usual camera improvements, new hardware, and whatever AI tricks Google has been cooking up, there should be plenty to talk about.

And the phones may only be part of the story. Google is expected to have a few more announcements up its sleeve, making this one of its biggest hardware events of the year. So, if you’re planning to tune in, here’s when the Made by Google event starts, how you can watch it, and everything we expect Google to announce.

Google’s Pixels are getting their glow on

First up, and probably the reason most people will be tuning in, is the Pixel 11 series. At this point, though, Google may not have many surprises left to pull out of its pocket. The phones have leaked extensively over the past few months, and if those leaks are accurate, anyone hoping for a dramatic redesign might want to temper their expectations. From everything we’ve seen so far, Google appears to be sticking with the design language it established with the Pixel 10 family. That isn’t necessarily a bad thing — I quite like the current Pixel look. Still, the Pixel 11 series probably won’t be one of those upgrades you can immediately identify from across the room. There is one addition that could make it stand out, though. Google has already teased a new light built into the camera bar, reportedly called HiLight or Pixel Glow. It appears to borrow its look from Gemini’s rainbow-like visual language, potentially lighting up while you’re interacting with Gemini or waiting for the AI to finish thinking. But I’m much more curious about what Google does with it beyond AI. Imagine different colors appearing for notifications, charging status, timers, or even incoming calls. If Google gives developers access to it, that little light could end up being far more useful for users.

The bigger changes should be happening inside. Google’s new Tensor G6 chip is expected to power the Pixel 11 lineup, replacing the Tensor G5 from last year. A faster processor is always welcome, but raw performance isn’t really what I’m interested in here. After using recent Pixels extensively, I want to see how the G6 behaves when you’re actually pushing the phone — shooting photos and videos, navigating on mobile data, jumping between apps, or simply using it outside on a hot afternoon. Better thermal management would mean much more to me than another impressive-looking benchmark score. Battery life and charging are equally high on my list. Samsung has finally started embracing silicon-carbon battery technology and faster charging with its Galaxy Z Fold 8 series, so I’d love to see Google make similar progress rather than playing things safe for another generation. A phone can have all the AI features in the world, but none of them are particularly exciting when you’re hunting for a charger halfway through the day. Then there’s the price. Android Headlines has reported that the Pixel 11 Pro could start at $1,099 in the US and €1,199 in Europe. If accurate, that would make the US model $100 more expensive than the Pixel 10 Pro, which launched at $999. The reported colors are Dune, Light Fog, Midnight Haze, and Pine, although those names apparently aren’t finalized yet. Still, with Google’s event only days away, I wouldn’t treat any leaked pricing or naming as gospel. We won’t have to wait much longer to find out what the Pixel 11 series actually costs — and, more importantly, whether Google has done enough this year to justify paying more for one.

Finally, a Pixel for your keys

Next up is easily the announcement I’m most excited about: the Pixel Tag. Google has somehow gone this long without making its own Bluetooth tracker, but if the recent leak spotted by 9to5Google is accurate, that could finally change at this year’s event. And honestly, it’s about time. Apple has had AirTags for years, Samsung has its SmartTag lineup with a third-generation model reportedly on the way, while Pixel owners have largely had to rely on third-party trackers. A proper Pixel Tag could finally fill that rather obvious hole in Google’s hardware ecosystem.

Advertisement

The leaked tracker has an oblong design and is expected to work with Google’s Find Hub network, which would allow nearby Android devices to help locate something you’ve lost anonymously. The feature I’m really hoping makes the cut, though, is Ultra-Wideband. That could give the Pixel Tag much more precise directional finding when you’re close to a lost item — the kind of experience that makes hunting for keys buried somewhere around the house considerably less annoying. There is one slightly amusing design choice, however. The Pixel Tag reportedly won’t have a built-in lanyard hole, meaning Google could follow Apple’s approach of making you use a separate accessory if you want to attach one to your keys or bag. Samsung’s rumored Galaxy SmartTag 3 is apparently heading in the same direction, too. So it’s quite clear that Bluetooth trackers have collectively decided that holes are no longer fashionable. Still, if Google gets the fundamentals right — particularly UWB tracking and tight integration with Find Hub — the Pixel Tag could be one of the smallest announcements at the event, but potentially one of the most useful.

Google’s little circle gets a bigger brain

Of course, it wouldn’t really feel like a Made by Google hardware event without a new Pixel Watch showing up, and this year, that should be the Pixel Watch 5. Visually, Google doesn’t appear to be tearing up the rulebook, but the upgrades happening underneath could be much more interesting. Battery life is the first thing I’ll be watching. The Pixel Watch 5 is expected to squeeze slightly larger batteries into both sizes, which is always welcome on something you’re supposed to wear all day, track workouts with, sleep in, and somehow still have enough juice left for the next morning. It’s also rumored to use a faster version of Qualcomm’s Snapdragon W5 Gen 2 chip, which should hopefully make everyday interactions feel quicker and smoother.

Storage could get a surprisingly big bump, too. Rumors point to the Pixel Watch 5 offering twice as much storage as its predecessor. That might sound excessive for a watch, but it starts making more sense when you consider how heavily Google is leaning into Gemini Intelligence. With Wear OS 7 pushing smartwatches toward becoming more contextually aware and capable of handling tasks on your behalf, that extra room could eventually become quite useful. As for the hardware itself, the familiar 41mm and 45mm sizes are expected to stick around, along with the same IP68 dust and water resistance and 5ATM rating. So, if you already like the circular Pixel Watch design, Google apparently sees very little reason to mess with it. Pricing could remain familiar as well. According to GSMArena, the 41mm Pixel Watch 5 is expected to start at $399, with LTE adding another $100, while the larger 45mm model could begin at $429.

But wait, Google might not be done

Those are the announcements I’d put firmly at the top of the list, but Google could still have a couple of surprises waiting in the wings. And this is where things get a little more interesting. Earlier this year, Google confirmed that it was working on a new generation of laptops that would bring Android and ChromeOS much closer together. We haven’t heard much about the project since, but Google previously pointed to a fall launch, which puts us awfully close to that window. I’m not necessarily expecting Google to roll out a laptop on stage on August 12, but a teaser, a name, or even a proper look at what it has been building certainly wouldn’t feel out of place. The interesting bit is that these so-called Googlebooks aren’t expected to replace Chromebooks. Instead, they could sit above them as a more premium option, built around a unified operating system and much tighter integration with Android phones.

Then there are smart glasses, because apparently every tech company has looked at Meta’s Ray-Bans and decided our faces are the next great computing platform. Samsung has already given us a glimpse of its own plans, and Google has been steadily building toward Android XR glasses as well. That makes the Made by Google stage a pretty tempting place to show them off again. I wouldn’t necessarily count on being able to buy a pair immediately, but a fresh demo or even a launch window would be enough to get my attention. And that’s what makes this event particularly interesting. We already have a pretty good idea of what’s coming from the Pixel 11 family, but it’s the things Google hasn’t spent the past few months leaking all over the internet that could end up providing the biggest surprises.

How to watch Google’s August 12 showcase?

All of that sounds exciting, but there’s one rather important detail left: how do you actually watch Google announce everything? Google is doing things a little differently this year — Google will share its announcements earlier in the day before holding the Made by Google show later that evening.

Advertisement

The event takes place on August 12 at 3 PM PT, and you’ll be able to watch the entire thing live on YouTube. So, whether you’re here for the Pixel 11 series, desperately waiting for the Pixel Tag like I am, or simply curious to see whether Google has a surprise tucked away for the end, you can tune in and watch everything unfold in real time. And considering how much hardware could be on the table this year, it might be worth sticking around until the very last announcement.

Source link

Advertisement
Continue Reading

Tech

When you can expect to buy an iPhone 18 Pro

Published

on

Apple obviously knows, and perhaps some of its retail staff have at least a clue, but for the rest of us, here’s the best estimate of when the iPhone 18 Pro will be announced.

No question, it’ll be in September. Apple has held its iPhone launches in October, but since 2011 the only time it has done that was during COVID.

The question is when in September we’ll find out the all-important updates and, more than ever this time, the all-important prices. Not to drag this out, the smart money says Wednesday, September 9, 2026.

We’ve been here before

That’s the most probable date that has been recently rumored. It’s in the first full week of September 2026, which is also when Labor Day is.

Advertisement

Since 2011 when Apple moved its iPhone launches away from their original announcements in June, the unveiling has been close to Labor day three times. In 2015, 2016, and 2022, and each time Apple has made its announcements on the following Wednesday.

In the 15 years since that move to the last quarter of the year, Apple has launched iPhones on Wednesdays five times. It’s launched them on Tuesdays nine times, and on Mondays just once, in 2024.

With the exception of the October launches in 2011 and 2020, every iPhone has been unveiled in the first two weeks of September. The latest date was September 14, in 2021 with the iPhone 13 range.

Then the earliest is a tie between 2016 and 2022, which were both on September 7.

Advertisement

Enough guessing

Despite occasional leaks, we obviously won’t know for certain when the iPhone launch is until Apple announces the date. But the company has form on even those invitations, too.

It’s a form that seems to be lengthening, too. Back around 2013, it was common for Apple to issue invitations to the launches one week ahead of the event.

Glowing Apple logo with vibrant blue, yellow, and red gradient against a black background.

Expect another gorgeously-designed invitation like this one from 2025, which will then be studied intently for clues – image credit: Apple

That happened several times, such as in 2015, 2016, 2018, and again in 2021. Then for the iPhone 14 event on September 7, 2022, Apple revealed the date two weeks before with an AR invite.

Advertisement

There was again two weeks’ notice for the iPhone 15 in 2023, and the iPhone 16 in 2024.

In fact, from the iPhone 14 onwards, Apple has consistently issued invitations two weeks to the day before the event. That means it is now always during the last week of August that it reveals the date.

Two more dates to watch

So expect the 2026 invitation and event date to be announced on Wednesday, August 26. Expect the event to be on Wednesday, September 9, 2026.

Which just leaves the question of when the new iPhones will be available to pre-order. Typically that happens on the Friday immediately following the event, and that won’t be changed because of the unveiling being on a Wednesday instead of a Tuesday.

Advertisement

It might be changed because the Friday is September 11. Apple has avoided doing anything on that date since the World Trade Centers were destroyed on September 11, 2001.

Then Apple isn’t likely to delay taking orders by very much, if at all, but it might have to push back shipping dates. Typically buyers start getting their iPhones by the Friday after pre-orders open, and that’s also when retail Apple Stores get their first stocks.

For the first time since COVID, though, there are likely to be delays in production. In this case it’s because of the global chip shortage, which could conceivably mean a longer than usual gap between launch and shipping.

Or it might be that Apple launches on its usual schedule, but will then take longer than normal to fulfil orders.

Advertisement

That’s specifically been rumored for the expected iPhone Fold, but it’s possible for the iPhone 18 Pro and iPhone 18 Pro Max too.

Then if the invitation date, event date, pre-order and shipping dates aren’t enough, Apple looks like it will have one more whole set of dates to look out for. Perhaps because of the chip shortage, Apple is strongly rumored to split its iPhone launch for the first time.

If this is correct, the presumption is that Apple will launch its biggest sellers, the Pro models, first. So the regular iPhone 18 may launch in the Spring instead.

It isn’t as likely to get an event, though, so at least there’s just the launch, pre-order and shipping dates to wonder about then.

Advertisement

Source link

Continue Reading

Tech

Levi Strauss & Co. says hackers stole corporate data in cyberattack

Published

on

Levi's

Levi Strauss & Co. (Levi’s) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines.

The company has disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC), saying that its response was sufficiently quick to prevent the compromise of consumer data.

“Based on preliminary findings from the Company’s investigation, the Company believes that certain corporate information was accessed and exfiltrated as a result of the incident,” Levi’s says.

image

“As of the date of this filing, the Company believes that its rapid response efforts successfully contained and terminated the unauthorized access, and that no consumer data was impacted.”

The company added that it has not experienced any interruption in business operations as a result of the incident.

Advertisement

Levi’s clothing giant has 19,000 employees and an annual revenue of $6.3 billion, best known for its signature 501-line jeans.

The company operates at least 3,300 stores worldwide, and its products can also be found in numerous third-party retail shops, both “brick and mortar” and online.

The firm says it recently detected a cybersecurity incident in which an unknown attacker social-engineered three of its employees, resulting in the breach of company-issued computers.

The investigation launched in response to the incident remains ongoing, and additional notifications will be provided to affected parties as required.

Advertisement

Based on the findings of the investigation to date, Levi’s does not believe the incident will have a material impact on its business or financial position.

Levi’s also noted that it has not experienced any operational disruptions as a result of this breach.

BleepingComputer could not identify online any threat actors claiming the attack on Levi’s.

However, some media outlets have linked this incident to UNC6671, which Google’s Threat Intelligence Group (GTIG) associated with a recent wave of voice phishing attacks targeting hundreds of organizations.

Advertisement

Although Levi’s stated that no customer data was impacted, until more information becomes available, holders of Levi’s shop accounts should monitor for suspicious activity and promptly report it to the firm.


article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Advertisement
Continue Reading

Tech

Apple supplier SK hynix invests $38B in AI memory

Published

on

One of Apple’s memory suppliers is making a massive investment to expand chip production amid global shortages, but it won’t make your next iPhone any cheaper.

On Friday, SK hynix announced that it has approved a 54 trillion won ($38.3 billion) investment to build two new semiconductor fabrication plants in South Korea.

The investment includes 35.2 trillion won ($24 billion) towards the Yongin Y2 facility, which will produce high-bandwidth memory (HBM) and next-generation DRAM products. Construction will begin in 2027 and wrap up by 2029.

A 19.1 trillion won ($13.6 billion) investment will go towards building the Cheongju M17 facility set to open in late 2028. The facility would serve as a NAND production base, geared toward enterprise SSD and AI inference storage.

Advertisement

SK hynix is one of the world’s largest memory chip manufacturers. It’s one of Apple’s key memory suppliers and provides components used across Apple’s lineup, including the iPhone, iPad, and Mac.

Unfortunately, neither of these investments directly helps the average Apple consumer. Instead, the new facilities are being built to serve high-growth AI and enterprise markets, not traditional consumer electronics.

Rockets and feathers

Of course, one could argue that by creating dedicated facilities for increasing enterprise products, SK hynix could give itself breathing room to manufacture consumer-grade products.

And, maybe that’s true.

Advertisement

Even still, SK hynix’s investment isn’t going to solve issues anytime soon. After all, the plants aren’t even slated to open until late 2028 at the earliest.

We’ve said it before, and we’ll say it again: this is going to get worse before it gets better.

Currently, DRAM prices are edging up to an untenable level for even large corporate customer bases, with nothing to say of the average consumer.

DDR-5 DRAM prices have very nearly sextupled on average on the consumer side. In February 2025, two 16GB sticks of DDR5-6000 RAM sold for about $100.

Advertisement

Present pricing is around $600.

We’ve most recently seen the effects as Apple increased prices on most of its product lineup.

The increase wasn’t surprising. Inflation and supply chain issues often drive prices “up like a rocket,” especially on consumer-level products.

The market, bolstered by consumers at all levels rushing to buy products “before they get any more expensive,” stands to make a good profit. That is, at least, until people genuinely can’t afford the costs.

Advertisement

And while we’ll likely see a drop in pricing due to increased manufacturing and market correction, I wouldn’t expect it to be fast or dramatic.

Instead, prices will float “down like a feather.” Slowly, and likely in a sine-wave pattern.

The point, as it often is, is that asymmetric price transmission is a real pain in the ass for the end consumer.

There’s more than supply and demand

Global supply chain shortages are a real thing. The boom of AI has put a lot of stress on manufacturers to keep up with demand.

Advertisement
Black smartphone lying face down on a metallic surface, camera module with multiple lenses catching light, soft reflections emphasizing sleek, modern design

iPhone 17 Pro Max has been limited by supply chain constraints

But let’s not point the accusatory finger purely at data centers and general market scarcity. There’s plenty of blame to go around.

It’s important to remember that SK hynix is also one of the companies targeted in a recent price fixing suit.

The complaint centers on DRAM, the working memory used in computers, smartphones, tablets, servers and many other electronic devices. Samsung, SK hynix and Micron dominate the global DRAM market, giving them enormous influence over memory supply.

Advertisement

Allegedly, Samsung, SK hynix and Micron shifted manufacturing capacity toward HBM, which commands much higher prices from AI companies. This shift has left DRAM supplies dwindling across the tech industry.

And yes, companies are allowed to pursue more profitable products. But the real question is whether these companies coordinated the production decisions or reached them independently.

Ultimately, whatever investments SK hynix makes right now doesn’t solve the immediate problem. Suppliers have already sold their entire production capacity of memory at high prices through 2027.

Advertisement

Source link

Continue Reading

Trending

Copyright © 2025