Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw.
SMA1000 is an enterprise-grade secure remote access gateway used by large corporations, government agencies, and Managed Service Providers (MSSPs) to provide VPN access to internal applications and corporate networks.
SonicWall released patches for the two security flaws (tracked as CVE-2026-15409 and CVE-2026-15410) in mid July, when it also warned that threat actors had been exploiting them in zero-day attacks.
“SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory,” the company warned at the time. “Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate these vulnerabilities.”
Incident response firm Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 (weeks before SonicWall publicly disclosed the flaws) to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
Internet security watchdog Shadowserver currently tracks over 380 SMA1000 appliances exposed online, although some may already have been secured against attacks.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the two flaws to its Known Exploited Vulnerabilities (KEV) Catalog on July 14, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three days.
“This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” the cybersecurity agency said.
While SonicWall has yet to update its original advisory to confirm that CVE-2026-15409 and CVE-2026-15410 are targeted in ransomware attacks, CISA has now also flagged them as exploited by ransomware gangs in recent updates to the KEV Catalog.
In December, the company warned customers to patch another vulnerability (CVE-2025-40602) in the SonicWall SMA1000 Appliance Management Console (AMC) that was being chained by hackers in zero-day attacks to gain root privileges.
One month earlier, SonicWall linked state-sponsored hackers to a September security breach that exposed customers’ firewall configuration backup files after researchers warned of over 100 SonicWall SSLVPN accounts compromised using stolen credentials.
In September, it also pushed a firmware update to help remove OVERSTEP rootkit malware deployed in attacks targeting SMA 100 series devices.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Magnets: how do they work? Pretty much the same regardless of brand name.
MagSafe seemed like a potential gimmick when Apple introduced it on the iPhone 12, leveraging the same branding it had long used for magnetic MacBook chargers. But the simple idea to add a ring of magnets around the wireless charging coil already found in previous iPhones turned out to be more than a way to sell overpriced accessories (though it certainly accomplished that, too). Once you’ve experienced the ease of snapping your phone onto a charging stand or one of the best MagSafe power banks, you’ll never want to fiddle with USB-C cables ever again.
In fact, MagSafe proved so useful that the Android world decided to adopt it from Apple. On non-Apple devices, the magnetic charging ring is part of the Qi2 spec, so rather than calling it MagSafe you should look for a Qi2 label. They’re functionally identical though, so you can snap Qi2 phones and cases directly onto MagSafe-branded accessories.
So far, only a few Android phones have integrated Qi2 directly on-device, most notably in the form of the PixelSnap ecosystem on the Google Pixel 10. Other companies have integrated it into accessories, with Samsung going so far as to claim people don’t need on-device Qi2 because they can simply buy an extra phone case with Qi2 magnets onboard (a position the company reiterated during the launch of the Galaxy Z Fold 8).
With so many developments in the space, some users are bound to wonder whether Qi2 is the same thing as MagSafe, and if so, why it goes by a different name. The answer is, as you might expect, a matter of corporate branding, but also one of control.
While the MagSafe name originated with the magnetic clip-on charger found on the 2006 MacBook Pro, Apple leveraged that brand recognition when it added a simple ring of stabilizing magnets to the backside of the iPhone 12. In addition to enabling accessories, it fixed the biggest issue with legacy wireless Qi charging. Phones with wireless charging had almost all used the same Qi charging coil in the back, but non-stabilized charging is inefficient and comparatively slow, since the coils in the back don’t always line up neatly with those in a charging pad. With MagSafe, Apple was able to increase the rated wireless charging speed of the iPhone 12 to 15W, up from just 7.5W.
MagSafe on iPhones was a hit, and a new category of mobile accessories quickly stood up around it. Before long, accessory makers began adding the ring to cases for Android devices as well, widening the market beyond Apple owners.
Apple is a member of the Wireless Power Consortium (WPC), which sets the Qi charging standard. In 2023, the WPC announced that Apple had donated MagSafe as the basis for a universal Magnetic Power Profile standard which would be known as Qi2. MagSafe remains a proprietary Apple brand, and accessories bearing the name must go through some certification. But since MagSafe was built on top of the original Qi standard, Qi2 accessories work with MagSafe-equipped iPhones, and vice versa.
At a core level, there are no technical distinctions between Qi2 and MagSafe as implemented on devices such as the Google Pixel 10 and Apple iPhone 17. Both standards use basic Qi charging coils and the same stabilizing magnet ring. Accessories which work with one will work with the other unless their physical dimensions become problematic (for instance, a power bank designed for the iPhone 17 with dimensions that do not accommodate the Pixel 10’s horizontal camera bar).
With that said, both MagSafe and Qi2 have increased their top charging speeds since the introduction of the iPhone 12. That phone launched with 15W wireless charging over MagSafe. By contrast, the iPhone 17 and 17 Pro support 25W charging over the latest MagSafe revision. Meanwhile, the latest Qi standard (Qi2.2) allows for 25W wireless charging and is supported on devices including the Pixel 10 Pro XL and the Samsung Galaxy S26 Ultra (albeit with a magnetic case).
That means that if you have a phone which supports the latest magnetic wireless charging standards, you’ll need to ensure that any snap-on charging devices you buy also support those speeds. Don’t look for promises of MagSafe or Qi2 compatibility. Make sure that the charger is rated for 25W. As long as that’s clear, it doesn’t matter whether it advertises itself as MagSafe or Qi2.2… at least to anyone outside of Apple.
The original Minimal Phone built its entire identity around an E Ink screen that made scrolling annoying on purpose. The black-and-white E Ink screen intentionally made watching videos or scrolling through social media posts look less colorful or appealing to the human eye.
So, when The Minimal Company announced its successor with an AMOLED display that supports a higher refresh rate, I was a bit surprised. I wasn’t expecting the company to walk back the hardware choice that made it quite interesting. But that doesn’t mean that the Minimal Phone 2 isn’t worth a look.
The Minimal Phone 2 trades its e-reader-style E Ink panel for a 3.92-inch 90Hz AMOLED screen. While E Ink displays are slow, sluggish with animations, and genuinely painful for anything beyond text, the AMOLED display gives the phone a modern look and appeal.
Isn’t it ironic: Minimal Phone with an AMOLED panel? Anyway, the rest of the redesign feels quite necessary, at least to me. The blocky, sharp-edged shell is gone, and in its place, the company has used a curved aluminum body.
It ships in Black or Silver colors. The physical QWERTY keyboard sticks around as well, with a tactile QWERTY layout that uses metal dome switches, remappable keys, and long-press shortcuts. For use in darker environments, the keys are backlit as well.
Buyers also get a physical silent switch at the top, alongside a 3.5mm headphone jack, which goes with the overall old-school vibe and feel of the phone, which, to be honest, reminds me of classic BlackBerry.
Unlike the original Minimal Phone, the latest iteration gets 5G support, which also implies that the company has used a new chipset inside. Although it’s not confirmed yet, a tipster claims that it could be the Dimensity 8300, paired with 8GB of RAM and either 256GB or 512GB of storage space.

Although the company mentioned that more details about the phone will be revealed on August 10, 2026, the Kickstarter landing page suggests the crowdfunding will remain active for another 29 days. The project has already reached its goal, though, which means that it’s almost certain that the brand will move forward with a commercial launch.
Lacking sane leadership, generative AI companies have proven to be irresponsible, all in service of the almighty dollar. The nuclear power industry is the best example of a model to follow.
Generative AI is the largest automated plagiarism engine that ever existed. That’s on top of AI consuming resources and driving up electric costs for neighborhoods that didn’t ask for these data centers. Still, there are larger problems.
Generative AI companies suffer from leadership failures and decisions being made for the wrong reasons.
All of these companies need sane, moral leadership. Decisions need to be made by the leaders that will safeguard the development of generative AI, but also be protective of the future, and the resources that are being consumed along the way, human and otherwise.
Making it worse, these AI companies are not learning from experience the way that they should be right now, because that costs money. They are not instituting safeguards the way that they have to, because that costs money.
They do not care about who they’ve stolen from, and are happy charging users to use those thefts. Yes, because that costs money.
And at the same time, they’re all talking a big game. They talk about modernizing business, saving companies money and time, and so forth.
All they’re effectively doing right now is moving money around from one billionaire or another, consuming resources, and committing or aiding and abetting felonies.
Hacking into other companies is a felony that the AI is perpetrating itself. Generating nudes without the consent of other people is a felony in most US states, and some international laws are far harsher than that.
We’ve got a long way to go to get to ethical and sane advancement of the technology. Generative AI needs to be treated like nuclear power’s inception, with regulation and control.
Nuclear power is an immense force. Splitting the atom should be regarded as a wonder of the world, where it is mostly a victim of bad press and poor education.
And it can be used for good or evil. There’s more of the latter these days, with generative AI committing those felonies that I mentioned earlier than the good parts.
Nuclear power had that early Manhattan Project effort, then it was more fully regulated just a few years later. And a sane leader stepped in to govern how things should be done.
In 1934, Enrico Fermi irradiated uranium with neutrons. At first, he thought he just made transuranic elements. He didn’t initially measure the radiation thrown off from the reaction from fission.
Otto Hahn and Fritz Strassman found fission products in 1938. A year later, Lise Meitner and Otto Frisch detailed the process and explained what was happening.
It didn’t take long for the governments of the world to figure out that this could be used for power, or weaponry. Regulation, and sane management are crucial to any world-altering invention, but that can take some time to roll out.
The US started the Manhattan Project, whose main goal, first and foremost, was the creation of an atomic bomb. What they learned sparked the idea that a power-generating nuclear reactor could be made.
Here comes more “learning from experience” and “institute safeguards” part that comes from sane, rational management.
There was a “demon core” that was intended for the third atomic bomb. In the course of early lack of supervision, and insufficient regulation, in two incidents, it went supercritical, killing two scientists and sickening more.
Sane leadership finally stepped in at Los Alamos. They stepped in late, but they stepped in.
After the second death, Los Alamos changed the rules. They mandated that remote-controlled equipment be used for experiments, which would have prevented the deaths of the two scientists.
In 1946, they melted down the infamous demon core, reusing its fissionable material in other cores.
These were the early days. This is when the US government figured out that there had to be safeguards, or there would be more deaths and more problems.
The US Navy had one of these sane leaders too. Hyman G. Rickover is known as the “Father of the Nuclear Navy” for a reason.
Under his leadership and strong hand, he drove the US Navy into the nuclear age, with a project that started in 1946. The US Navy has yet to experience a reactor accident well past his death, and his safety policies kept two AppleInsider staffers alive many years later.
On the other hand, the Russians have had at least 11 Naval reactor accidents in the same time period. Beyond seagoing reactors, one incident in 1957 associated with military radioactive waste contaminated 23,000 square kilometers.
And then there’s Chernobyl, which by far is the worst reactor accident that has ever happened.
Most of the US nuclear power industry’s hires are from the US Navy, as you’d expect. The US nuclear industry did have Three Mile Island in 1979. There were no deaths from that accident, and a one-day dose of about 1/300 of annual exposure from all sources to the citizenry near the plant.
And, it inspired more changes in training, regulation, engineering, procedures, and in the industries that built reactors in the US at the time.
Rickover retired in 1982, after 63 years of service. He died in 1986, and a few years later, a submarine was named after him. That culture of safety persists in the US Navy to this day.
Nobody is taking Rickover’s role in generative AI. Given the pursuit of profitability, that seems unlikely.
It is sorely needed, though.
AI leadership is not sane, nor do they seem to learn from failures. When presented with AI breakouts and the felonies of breaking into other companies, leadership shrugs and promises changes that never seem to materialize.
These things seem to keep happening. These incidents don’t seem to be forcing any changes inside all of these generative AI companies.
A Rickoverian culture of safety is hard to implement and is expensive. It’s still needed here.
Instead, the same mistakes keep being made. All we’re hearing is how much money is being spent, how much RAM is being used, how much utility prices are climbing because of data centers, how much water is being consumed by open-air cooling systems, and more.
I’m not certain we’re going to find 10 Rickovers for generative AI. That man was more than a force of will; he was a force of nature and a menace simultaneously, unpolluted by profit margin concerns or the demand for shareholder gains.
So instead, regulation will have to do. There’s a meeting on August 11 at the White House with the existing CEOs to present a draft, again, and talk to the President, again, so we’ll see what pops out the other side.
I’d like to think that the generative AI industry can self-regulate in the interest of the users. It’s clear from behavior that they can’t, and public comments strongly hint that they won’t accept any real control being ceded to the feds.
Given how generative AI companies plagiarize and don’t generally compensate publishers of any size or media as a general rule, the rocky road that we’re on should have been apparent from the start.
It’s not too late to change. It’s not too late for one of these companies to realize that there’s a foundational problem or five here that all of them need to be fixed.
The feds have started to figure out that there need to be changes and controls. But when they tell you that it’s time to make some changes, the exit you should have taken to make those changes is probably behind you.
Maybe the company CEOs are thinking about a course correction. You can’t tell if they are, over the tumult that they’re making that it’s too hard to identify sources, cite properly, or pay the folks they’re stealing from.
As with most things, we’ll see where we end up with time. And, we’ll see what they actually do, or are forced to do.
Data suggests that employees are working to improve their abilities around artificial intelligence in a workplace environment being transformed by the technology.
IrishJobs has published the results of a report exploring Ireland’s evolving hiring landscape and shifting attitudes across the jobs market. What was discovered is that there has been a significant push among professionals to upskill in AI.
According to the report, which gathered data from more than 500 employers and nearly 1,000 professionals across Ireland, this urge to upskill in AI is being driven by a growing adoption of AI tools and technology in the workplace.
More than one-third (35pc) of participants have taken steps to enhance their AI skills this year amid the accelerating AI workplace transformation.
With 86pc of contributing professionals confident that their skills will stay relevant over the next three years, the report indicates that the potential impact of AI on the jobs market is expected to take place over the long-term, rather than the short-term.
Commenting on the findings, Christopher Paye, country director of The Stepstone Group Ireland with responsibility for IrishJobs, said, “Across Ireland, the hiring landscape is evolving at pace, shaped by a combination of economic and geopolitical volatility, accelerating technological change and shifting workforce expectations.”
He added, “There is a growing sense of uncertainty around the impact of AI and how this could affect future careers. Professionals in Ireland are responding to these changes by enhancing AI skills and putting an increased emphasis on the value of adaptability in the workplace.
“Employers, too, have a vital role to play in investing and skilling up their workforce to ensure their people can successfully adapt to these shifts.”
IrishJobs’ report also found that increased automation in the recruitment process is potentially affecting how candidates experience and engage with recruitment. Almost three-quarters of jobseekers who contributed to the research said it is more difficult to reach the interview stage of the hiring process, while 65pc report that they do not hear back from recruiters beyond an autoreply.
Skills, for both applicants and employers, remain a divisive subject, as 78pc of candidates find that job adverts require more skills than ever before, while skills-matching remains the top hiring challenge for employers. The report suggests this is reflective of a growing disconnect between employers and candidates on the expectations around roles.
Perhaps unsurprisingly, salary was found to be the top factor for candidates when considering new opportunities, followed by work-life balance, flexible working and job security. This is in line with rising inflation and cost-of-living pressures.
With the increased economic uncertainty in mind, 77pc of contributing candidates said that job security is more important than career progression when considering potential opportunities. Meanwhile, 23pc of employers are struggling to meet jobseekers’ rising salary expectations, leading to one of the biggest hiring challenges for recruiters.
“The findings also spotlight a growing disconnect between employers and candidates across several key areas. Challenges around rising salary expectations, skills-matching and increasingly complex job requirements are contributing to friction in the hiring process,” said Paye.
“To stay competitive, employers need to sharpen their approach, setting clear and realistic expectations from the outset of the recruitment process and leading with transparency on pay, flexibility and career development. Those who actively invest in skills and support employees through the significant change ahead will be best placed to attract and retain high-calibre talent.”
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
Marta M Elvira of the University of Navarra, Nils Neumann of the University of Michigan and Olivier Godechot of Sciences Po discuss the impact of a city’s financial market on the wider landscape.
Try to imagine the history of New York without Wall Street, or London without the City. It’s not easy.
Hosting a country’s main financial markets shapes a city’s identity, raises its profile and creates jobs. But there are trade-offs. By acting as a magnet for high-paying finance jobs and related professions, many financial cities suffer from particularly high levels of income inequality.
In fact, alongside globalisation and the clustering of highly skilled workers, our research has found that the presence of a financial market is a major driver of the growing concentration of top earners and earnings inequality in select cities.
In a study conducted by two-dozen researchers, we examined top earnings in cities in 10 countries across Europe, North America and Asia, analysing two decades of linked employer-employee data.
For every country studied, we compare two cities: the financial hub housing the main national markets and related industries, and a second, comparison city that is closest in terms of population, employment and share of GDP.
In the US, for instance, we compared New York to Los Angeles. In Spain, we compared Madrid to Barcelona; in Japan it was Tokyo and Osaka; in France, Paris and Lyon; the Netherlands, Amsterdam and Rotterdam – and so on.
We wanted to understand whether the earnings of the top 1pc were increasing, whether higher earners were clustered in certain cities, and what role the finance sector plays in determining income inequality.
Across all 10 countries, the earnings share of the top 1pc (ie how much of the total income went to those one percenters) increased over time, growing by an average of 0.17pc per year. Countries such as Denmark and Sweden experienced the smallest rises, while the US posted the largest.
That is the aggregate for top earners: already high incomes increasing year after year. Our findings are consistent with data documenting the global increase in income inequality. But where do these high-flyers live and work?
In all of the countries we studied, the highest earners nationwide were more concentrated in financial cities than in the second cities. In 1990, earnings in financial cities were on average 1.7 times more likely to be in the national top 1pc than those in comparison cities. Nearly two decades later, they are 2.4 times more likely.
Financial hubs were consistently responsible for an outsized percentage of the income growth among very top earners. On average, financial cities accounted for 65pc of the increase in their countries’ top 1pc earnings shares. In France, Spain and Sweden, financial cities accounted for more than 100pc of the increase, meaning that earnings in other cities actually declined.
The growing gap between financial and comparison cities is mainly driven by the surge in earnings in the financial sector. We estimate that this sector accounts for 30pc of the divergence between the two types of cities.
The research’s two-decade-long timeframe helps interpret the trend. In the 1990s, many finance firms distributed ballooning profits among their employees, pushing salaries skyward.
As another of our studies has shown, even when banking profits took a hit – during the 2008 crisis and its aftermath, for instance – salaries remained high. This was even the case when countries enacted specific regulations like capping bonuses to curb salaries in the sector and discourage risk-taking.
Broader national contexts – including overall income inequality levels and how centralised and diversified economies are – also make a difference.
In countries such as Spain, Sweden and Denmark, financial cities contributed substantially to relatively modest increases in overall top 1pc earnings shares. In contrast, in Germany, the US and Canada, financial cities played a smaller role in much larger aggregate increases in national top earnings.
Sweden, Norway and Spain are generally more centralised economies than Germany, Canada or the US, so their financial hubs naturally play a larger role.
Additionally, in North America, finance’s wage-setting practices have spread to other sectors such as tech. Meanwhile, in Scandinavian countries, finance has remained a niche sector, with exceptionally high wages but limited spillover into other sectors.
Some 75pc of European Union citizens live in cities and urban areas, a figure set to rise to 78pc by 2050. Around the world, cities are expanding.
This makes it vital to understand what makes them the way they are. Globalisation is often blamed for income inequality in cities because cities provide the high-paying professional infrastructure – the consultants and lawyers as well as the bankers – for global business. Our research shows that some of the cities with the largest surge in earnings concentration are places like Stockholm and Madrid – important European capitals but not centres of global commerce.
Another suggested cause for income inequality is that highly educated workers and productive firms cluster in amenities-rich cities. But our research carefully paired cities with similar amenities and skill levels. In every case, the financial city contributed disproportionately to top earnings, and the other did not.
It is therefore safe to say that the presence of a financial sector is the determining factor in income inequality. This finding has profound implications for the sorts of cities, and societies, we want to create.
By Marta M Elvira, Nils Neumann and Olivier Godechot
Marta M Elvira is a full professor of strategic and people management, for the IESE Business School at the University of Navarra. There, she has served as vice-dean of research and is a member of the management committee in Madrid, as well as holding the chair of family business. She has a PhD in organisational behaviour and labour relations from the Haas School of Business at the University of California, Berkeley and a degree in economics from the University of Oviedo.
Nils Neumann is a graduate student of sociology at the University of Michigan. His main interests lie in how market and organisational dynamics can shape economic inequality.
Olivier Godechot is a professor in sociology at Sciences Po. He is also a director at AxPo Observatory of Market Society Polarisation.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
An anonymous reader quotes a report from ABC News & Headlines: Andrew asked his personal assistant to book him a spot in one of his gym’s coveted morning classes. It was a task he thought was well suited to this particular assistant because the booking form was online and because his assistant was not a person — it was artificial intelligence (AI). But Andrew was shocked by what happened next. His AI assistant found a way to book the gym class months further in advance than the gym allowed, thanks to a vulnerability it discovered in the booking software. Then it went further, kicking someone out of the waiting list who was ahead of Andrew — something it was not asked to do. The accidental hack is the first known Australian case of an emerging risk from a new generation of AI capable of behaving in unexpected ways.
Read more of this story at Slashdot.
Identity security is under growing strain. The passwords, multi-factor authentication (MFA) responses, IP reputation, geolocation and browser characteristics organizations have traditionally used to judge whether a login is legitimate are becoming easier for attackers to steal, imitate or work around.
AI is adding to that pressure, not by creating a completely new class of attack, but by making familiar identity attacks faster and more efficient. Meanwhile, rotating IP addresses and disposable browser profiles make malicious logins harder to distinguish from legitimate ones.
Against this rapidly evolving threat landscape, organizations need effective Zero Trust measures that protect against ‘legitimate’ logins from attacker-controlled infrastructure. It’s here that device trust helps, ensuring that valid credentials are insufficient without the device context they were meant to be used from.
AI has not created a fundamentally new form of account takeover. Attackers still rely on familiar techniques: phishing, credential theft, MFA abuse, session hijacking and social engineering. What has changed is the amount of manual work needed to run those attacks effectively.
Threat actors can create and send thousands of convincing phishing emails with little effort. If a more personalized message is needed, AI can pull public information from across the internet to build a detailed profile of the target.
Attackers can then adapt their message to match the target’s language and business context. A finance employee might receive a supplier-related request, while an administrator is approached with a cloud access issue.
None of this means AI is autonomously running the entire intrusion. In most cases, people still choose the targets, control the infrastructure and decide what to do with successful access.
The more accurate way to describe the change is that AI compresses the human work between acquiring information and acting on it. It lowers the cost of personalization and triage, allowing teams to run more campaigns and focus their effort on accounts with the highest expected value.
Verizon’s Data Breach Investigation Report found stolen credentials are involved in 44.7% of breaches.
Effortlessly secure Active Directory with compliant password policies, blocking 6+ billion compromised passwords, boosting security, and slashing support hassles!
Identity platforms often combine several signals to decide whether a login should be trusted. Each still has value, but attackers increasingly know how to steal, imitate or bypass the evidence these controls rely on.
While passwordless options are becoming more popular, credentials are still required in most authentication flows. As such, phishing and credential-harvesting malware like infostealers form the first step in many account takeover attacks.
Attackers can also simply reuse credentials from previous breaches. In an incident earlier this year, IGN’s Twitch stream was hijacked by an unknown attacker, using Restream.io credentials that had sat in infostealers dumps for roughly a month before being exploited.
The attack highlights the importance of scanning for leaked credentials. Solutions such as Specops Password Auditor carry out a read-only scan of your Active Directory to identify leaked passwords and related vulnerabilities.
You’ll then receive an easy-to-understand report to help you prioritize fixes. Download Specops Password Auditor for free here.
MFA significantly improves security, but its strength depends on the method and the surrounding authentication flow.
One-time codes can be captured through phishing. Push notifications can be abused through repeated prompts or social engineering. Adversary-in-the-middle phishing can relay credentials and MFA responses to the legitimate service in real time.
Attackers may also steal session cookies after authentication and avoid the MFA challenge entirely.
IP reputation can identify connections from known malicious infrastructure, while geolocation can flag activity from an unexpected region.
However, attackers can route traffic through residential proxies, mobile networks or compromised systems. They may choose an exit node close to the victim, making the login appear geographically plausible.
Legitimate activity is equally difficult to interpret. Remote work and corporate VPNs can produce unfamiliar locations. Stricter policies may block more attacks, but they also increase false positives and support work.
NIST’s Zero Trust Architecture guidance reflects this limitation. SP 800-207 states that organizations should not grant implicit trust based solely on physical or network location.
It treats user and device authentication as separate functions that should take place before access to an enterprise resource is established.
Most identity controls still depend on credentials that can be presented from almost anywhere. This is why organizations need to extend trust decisions beyond traditional identity signals.
Solutions like Specops Device Trust limit an attacker’s ability to spoof legitimate login attempts and reduce the risk of account takeover by:
Organizations should be able to register and limit trusted devices, different policies to corporate, personal and third-party hardware.
If the login comes from an unknown device, the identity platform should treat that as a meaningful change in risk. Access shouldn’t be granted simply because the credentials and MFA succeeded.
A successful login should not create permanent trust for the rest of the session. Access should continue to depend on both the user’s identity and the health of their device.
If posture changes, such as through disabling endpoint protection or the device falling out of compliance, the level of access should change.
Security teams are right to be cautious about adding friction, so device posture policies do not have to make every issue a blocking event.
Depending on the application and the severity of the problem, organizations can reduce privileges or give the user a short grace period to fix the device.
That approach keeps the control proportionate. A missing update should not always be treated in the same way as disabled endpoint protection or a rooted device.
When access depends on device health, users need a clear way to resolve problems. Self-guided remediation allows employees to fix issues quickly, which reduces disruption while keeping the required security standard in place.
As AI improves the speed and personalization of account takeover, IT teams need solutions that blunt the effectiveness of those attacks.
While it may be a challenge to identify every malicious login from network signals alone, organizations can make valid credentials insufficient without the device context they were meant to be used from.
If you’re interested in seeing how Specops can help evolve your identity security strategy by bringing device trust into access decisions, contact us today.
Sponsored and written by Specops Software.
One element of the 80s F1 rubber straps that has not carried over to the new collection, though, is the V-shaped grooves on the bottom portion of the original straps. TAG made the 80s rubber straps extra long so surfers and divers could wear the F1s over wetsuits. The V-shaped grooves meant these could easily be cut down to a desired length—particularly useful if you were just going to wear it on the wrist and not in the waves. Clearly, TAG doesn’t want anybody cutting up its new rubber straps.
I’ve wanted a classic original orange TAG F1 for years, and finally managed to pick one up earlier this year, although it is the later WA1213 model. Eddy Burgener, who designed the TAG F1 in the 80s, has stated that bright, popping colors were key to the original collection, and that the models were not, initially at least, thought of as being linked to driving but watersports instead.
Speaking to watch site Hodinkee last year, Burgener said TAG was “trying to create a new style of watches for American surfers, divers, and other young folks heading for the beach,” so the brief was to create a new watch that was fun, colorful, and young, emulating the bright surfboards and the clothes surfers were wearing at the time.
To nail the bright colors, Burgener stated that the case had to be synthetic, which then added the complication of trying to make a diver’s watch using synthetic materials, something that was incredibly difficult at the time. In the end, they settled on a mixture of fiberglass and plastic as the base material for increased hardness and stability.
TAG’s solar F1s now sport a form of bioplastic—a more eco-friendly castor-based polyamide which the brand has named TH-Polylight—replacing the old “Arnite” thermoplastic. As before, this is molded over a steel inner core, making for a sports watch that’s more robust than most plastic-cased equivalents.
If you lost your remote and just got your new one, this is for you.
Picking up a streaming device like an Amazon Fire TV Stick or the Google TV Streamer is a cost-effective way to breathe new life into an older television. Roku’s fleet of streaming sticks and boxes enjoys a reputation for being affordable, easy to set up and offering a less bloated experience than Android TV. Like other streaming devices, every Roku model ships with a remote control that lets you control media playback and other actions.
Unlike your TV’s infrared remote, though, most modern Roku devices communicate with their remotes over newer technologies like Wi-Fi Direct or Bluetooth. This lets you enjoy more features like voice control and the ability to control your Roku device without requiring a clear line of sight between it and the remote. However, remotes using these technologies need to be paired before you can use them. This is done when you first set up your streaming device, but if you’ve replaced your remote or performed a factory reset, you’ll need to pair it with your Roku again.
To do this, you will need to put both the Roku device and its remote in pairing mode. Assuming you don’t have an extra remote to control your Roku device, unplug it from the power source, wait around five seconds, plug it back in and turn it on. Flip your remote over and look for a pairing button. It’s usually under the battery cover. Press and hold the button for five seconds until you see the status light flashing. If your Roku remote doesn’t have a pairing button, press and hold the Back and Home buttons simultaneously for 5 seconds. Your Roku remote control should now be paired with your device.
The Roku remote is a convenient way to control what’s on screen, but if you’ve misplaced it or if it refuses to pair, there is still one handy alternative: the Roku mobile app. You can install it on your Android or iOS device and use your phone to control your Roku device instead. Make sure your phone and Roku are both connected to the same Wi-Fi network. Launch the app on your phone, navigate to the Remote tab and tap on Connect device when it recognizes your Roku device.
The interface looks very similar to the layout of the physical remote. You get giant D-pad controls in the middle with your usual playback controls right below. The Home and Back buttons are situated at the top, where you will also find a microphone icon that lets you perform searches with your voice. Another advantage of using the Roku mobile app to control your TV is that you can type things out much faster on your phone’s keyboard whenever you trigger a search field.
The app also doubles as a hub for discovering new content and launching recently used apps faster. Plus, if you have headphones connected to your phone, your TV’s audio can be routed through them, making late-night movie watching more convenient.

Photo credit: Righto
In late 1972 Butler Lampson sat down at Xerox PARC and wrote a short internal memo titled “Why Alto?” He wanted a machine each researcher could claim as their own. Alan Kay had been dreaming of a portable Dynabook for years. Lampson and Chuck Thacker offered him an interim version that would fit under a desk instead. Bob Taylor gave the project its name, and work began that November. By April 1973 the first unit was running, with a Sesame Street Cookie Monster test pattern appearing on its tall portrait screen.
The screen was an unusual 606 by 808 pixels, with each of them entirely independent and controlled by the Alto. No one else came close to creating a display that functioned like a blank piece of paper on its end (right on the edge of your desk). A three-button mouse lay on the edge, beside a detachable keyboard. The main box, about the size of a compact filing cabinet, housed a microcoded CPU running at around 5.8 Mhz, 128 kilobytes of memory, and a 2.5 megabyte detachable disk cartridge. Each Alto cost Xerox a hefty $12,000 in 1973 ($90,257 today).
Sale
PARC researchers immediately filled their offices with Alto machines by the dozens. By 1975, there were dozens buzzing away under desks across the facility. Users began pointing and clicking rather than entering obscure commands. They changed the documents and saw the final layout on screen before printing them. Charles Simonyi and his colleagues created Bravo, the first word processor that delivered on its promise of what you see is what you get. You could use Laurel to send emails, interact with vector graphics and paint tools, and even construct software with Smalltalk by treating everything as an object capable of communicating with other objects.
Bob Metcalfe and David Boggs used Alto to create a network called Ethernet, which flowed at roughly three megabits per second. Laser printers, pioneered at PARC by Gary Starkweather, sat immediately on the same network, allowing anyone to print a clean page without leaving their desk.
Over the next decade, around 2,000 Altos were manufactured. The majority of them ended up in Xerox offices. A few hundred made their way to universities and research facilities. One even ended up at the White House. However, none of these ever made it into a store catalog. Xerox’s headquarters were a long way to the east, and their definition of success was essentially steady sales of copiers, toner, and drums. A machine that could reduce paper usage appeared to be a threat to their ongoing revenue rather than a beneficial concept. Earlier efforts into large computers had cost the corporation a lot of money. The government’s inspection of Xerox’s dominance in the photocopying business gave them still another reason to be wary about selling a whole new type of computer. Selling a new type of computer also put them at risk of being accused of abusing their position in one market to get access to another.
In December 1979, a young Steve Jobs walked thru PARC as part of a stock deal. He observed the cursor travel under the mouse, jumping between overlapping windows, and subsequently stated that this type of demonstration made all of the other tech feel very evident. Apple’s Lisa and then Macintosh brought the same principles into people’s homes and offices. Charles Simonyi later contributed to the development of Microsoft Word. Ethernet became the standard as local networks began to be wired with it. The visual language of icons, menus, and pointing devices spread like wildfire, making it feel like it was meant to be.
It wasn’t until 1981 that Xerox introduced a commercial version known as the Star, which cost a whopping $16,000 ($58,781 today) and arrived after cheaper machines had already appeared on the market. Sales were poor, but the people who built the Alto had moved on to start new companies.
[Source]
Weekend Open Thread: Mattifying Sunscreen
Frugal Friday’s Workwear Report: Cap-Sleeve Pointelle Crewneck Sweater
Jordan Coyle & Cordiamo take Laya Arena Stakes at RDS
Can Astrology Help Find Gold and Silver Trends? A Financial Astrology Guide
US stocks: Dow closes at record on Mideast optimism; SpaceX, AMD drag Nasdaq
US Tech Stocks See Largest 5-Week Inflow in History: Can Nasdaq Break Its Downtrend?
Reform UK And Greens Sink To Lowest Favourability Ratings To Date
Nvidia Stock Climbs 2.5% as Chip Sector Rally Builds Ahead of AMD Earnings, Nvidia’s Own Report Looms
Polymarket targets $20 billion valuation as competition heats up in prediction market sector
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
Supply chain issues impact Ingredion
CLARITY Act Senate Vote Locked In, But 60-Vote Hurdle Looms Large
Rinn Pharma & Biopharma to join NordicPharmaTrain network
The Senate has one week: CLARITY’s last August window
Dow and S&P 500 Hit Records on AI Earnings: When Will the Bubble Burst?
How to Start a Cleaning Business: A Step-by-Step Guide
California Wildfire Bets Expose Polymarket’s Dark Side
Datadog: Best Of Breed For Multiple Reasons
CNH Industrial Shares Jump Over 15% After Beating Estimates and Raising Full-Year Earnings Guidance
BDC Weekly Review: Private BDC Q2 Numbers Are Strong
You must be logged in to post a comment Login