Connect with us

Tech

Oura is facing a lawsuit over whether its $300 ring can actually track sleep

Published

on

Crystal ball: Oura is facing a proposed class action lawsuit over the accuracy of its sleep-tracking claims. Filed this week in San Francisco by Clarkson Law Firm, the complaint argues that Oura’s smart rings can’t directly detect the physiological signals needed to assess sleep quality or identify sleep stages, and instead lean on AI-generated estimates the suit says amount to “a coin flip’s chance of being correct.”

The lawsuit takes aim at a core feature of the product: its ability to turn data collected from a wearer’s finger into scores for sleep, readiness, and activity. Oura rings track measures like heart activity and skin temperature, then run that data through software to generate sleep reports.

But the complaint argues this approach can’t deliver the same information as a clinical sleep study. Sleep stages, it says, are determined through brain and eye measurements that require electrodes on the scalp and sensors near the eyes.

“Sleep happens in the brain, not on one’s finger,” the complaint states.

Advertisement

Oura has marketed its ring as “built for accuracy” and offering “unparalleled accuracy,” according to the filing. The complaint says the company has claimed 79% accuracy in its measurements and, more recently, 95% sleep-staging accuracy compared with clinical sleep labs.

The complaint alleges Oura marketed rings costing $300 or more as tools capable of tracking sleep and identifying its four stages. It argues those claims overstate what a finger-worn device can do, since determining sleep stages requires the scalp electrodes and eye sensors used in clinical sleep studies.

The plaintiffs argue that Oura’s marketing leaves consumers with the impression that the ring can measure sleep the same way a lab can. They say consumers may use the device’s reports to shape health-related decisions, even though its estimates may not reflect their actual sleep.

The lawsuit follows years of online complaints from Oura users questioning the accuracy of the ring’s sleep reports. Some have said the device logged a strong night of sleep when they felt exhausted. Others have questioned its ability to identify REM and deep sleep.

Advertisement

The complaint asks the court to stop Oura from making what it calls misleading claims about the ring’s capabilities, and seeks restitution for consumers who bought Oura products based on those claims. Oura did not immediately respond to a request for comment.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

555 Makes A Useful Beat Frequency Oscillator

Published

on

If you’ve got a cheap ham rig, it might not be very practical for you to receive certain transmissions out of the box. However, if you were to hack in a convenient little beat frequency oscillator (BFO) to your rig, then you’d be up and running. Here’s a simple way to do just that with a venerable old part everybody knows and loves.

The build in question concerns the use of a 555 timer IC. It’s seasoned with the right smattering of resistors and capacitors to taste, producing a 455 kHz beat frequency oscillator. This can be injected into the intermediate frequency chain of a receiver, making up for the lack of a steady carrier wave when receiving continuous-wave and single side-band suppressed carrier transmissions. Thanks to a potentiometer in the circuit, it’s tunable, too, from 455 kHz, plus or minus twenty percent or so. Thanks to the versatility of the 555, it’s possible to run the chip on a wide voltage range, anywhere from 4.5 volts to 16 volts, which makes it easy to install in just about any old radio set without requiring adding a specialized power supply. There’s also an alternative design that EDN covered in greater detail some time ago.

If you’re eager to dive into a wider range of transmissions than your radio can currently receive, this old-school ham hack could be just what the shack ordered. We feature plenty of good ham hacks around these parts, and don’t forget—we always want to hear about the freshest ones on the tipsline.

Advertisement

Source link

Advertisement
Continue Reading

Tech

Apollo finds AI is hitting paychecks rather than payrolls

Published

on

An Apollo analysis of 321 occupations found that wages in jobs highly exposed to AI grew 6.7% more slowly after 2023, with no statistically significant employment effect. The gap was 10.7% in the lowest-paid quartile and absent in the highest.

The first measurable mark AI has left on the labour market is not unemployment. Apollo’s chief economist Torsten Slok says the employment effect so far is insignificant, and that the visible damage is to pay.

His analysis with Sania Edlich found that wages in occupations highly exposed to AI grew 6.7% more slowly after 2023 than in low-exposure work. Employment in those occupations showed no statistically significant change.

The distribution is the part worth sitting with. The gap was 10.7% in the bottom wage quartile, 5.4% in the second and 4.0% in the third, and there was no significant effect at all in the top quartile.

Advertisement

The method is unusual and worth stating. The authors matched 321 occupations to labour statistics data from 2015 to 2025, using the Anthropic Economic Index, which measures observed AI usage from actual model interactions rather than theoretical exposure.

They are candid about the limits. Exposure is measured from one company’s usage data, only 321 of roughly 800 occupations were matched, and their most dramatic figure, a 24.3% gap for service workers, is flagged as a small subsample to be treated with caution.

Other evidence points the other way. US statisticians found a 0.2% fall in jobs across 18 exposed occupations while payrolls overall grew 0.8%, and Goldman Sachs reported faster declines in openings in fields exposed to AI substitution, in a market where new entrants are already being squeezed.

Diane Gherson, formerly IBM’s chief human resources officer, offers a reason the job losses may be hard to see. Companies are quietly hiring fewer people into high-attrition, lower-wage roles rather than announcing layoffs.

Advertisement

She also names an accounting distortion that pushes the same way. Severance can be booked as a one-off restructuring charge that investors discount, while retraining lands in operating expenses every quarter, which makes cutting look better on paper than reskilling.

The counterexample she reaches for is European. Ikea retrained call centre staff as remote interior design advisers after automating much of their previous work, and the resulting service has been widely reported as a business worth around €1.3bn.

Slok’s wider claim is that the economy is getting more dynamic rather than smaller, with business formation at the highest rate on record. He also concedes the productivity payoff is unproven, since margins outside the largest technology companies have not yet risen.

Europe has no equivalent study, which is the gap worth noticing. The wage channel Apollo describes would be invisible in most European labour data, and TNW has already reported what AI is actually doing to jobs here without anyone measuring pay this way.

Advertisement

Source link

Continue Reading

Tech

Custom Hammond Organ Boasts Hand-Cranked Tonewheels and Twelve Keys That Sing Through Steel

Published

on

Hammond Organ Project Build
Uri Tuchman decided a musician friend needed a present that could actually make noise. He chose the Hammond organ, that old electromechanical machine whose spinning iron disks and magnetic coils once filled churches and stages with pure tones. Instead of a full console, he built a single octave version he could turn by hand. The result sits somewhere between a careful reconstruction and a living demonstration of how sound can come from metal moving past a coil.



He began with these keys, the white ones made of strong maple wood and the black ones from a denser hardwood that didn’t have a fancy name. Each key boils down to a simple on/off switch; press it, and the circuit closes. Twelve keys, twelve switches; that portion seemed almost routine until you looked closer at the woodwork, how clean the cuts were, and how perfectly the entire mechanism fit inside the brass frame.

Sale


Elgato Stream Deck MK.2 Studio Controller, 15 Macro Keys
  • 15 Customizable LCD Keys: instantly control your apps, tools and platforms.
  • One-Touch Operation: trigger single or multiple actions, launch social posts, adjust audio, mute mic, turn on lights, and much more.
  • Visual Feedback: know that your command has been executed.

Hammond Organ Project Build
Next came the pickups. Each is a coil of copper wire wrapped around a steel rod, similar to how a guitar pickup works. The coil is up against a revolving tonewheel. When the edge of the iron disk moves past the rod, the changing magnetic field creates a little current. The little current is the note. Uri coiled the coils carefully to ensure that the signal was powerful enough to drive a standard guitar amp with no further electronics in between the pickups and the amp. One key, one tonewheel, and twelve notes.

Hammond Organ Project Build
The tonewheels themselves had to be built of iron or steel because it was the only metal that had enough of an effect on the magnetic field to produce a useful signal. Uri had them laser cut to ensure precise results. The edges are not sharp gear teeth, but rather smooth rounded profiles designed to produce something similar to a sine wave when they spin past the pickup. The tough part is finding the perfect spacing between those profiles. Equal temperament necessitates ratios based on the twelfth root of two, which is a tall order considering you’re working with metal; gears and cut disks can only scrape the surface of those ratios. Hammond’s first machines never quite achieved perfect equal temperament, but they came close enough that the ear was content to accept the result, and that minor imperfection became part of the instrument’s character. Uri’s smaller set operates on the same principle: the disks rotate on a common shaft powered by a hand crank and a few gears.

Hammond Organ Project Build
Because everything can spin at any pace you like, tuning is entirely up to you. If you spin it too slowly or too fast, every note begins to tremble. That constraint becomes a feature in the finished instrument. Changing the speed of the crank while a key is still held down causes all of these sliding warbling effects that a fixed speed motor could never achieve. The device simply plugs into a guitar amplifier. No fancy Leslie speakers, no drawbars, and no frequency doubling. You get the raw output of twelve mechanical oscillators.

Hammond Organ Project Build
The finished organ is pretty compact, made largely of brass and wood, with dark iron disks poking out from the inside. It appears more like a well-made tool than a polished musical instrument. Which is suitable for the project. Uri has a long history of creating things that clearly demonstrate how they work. This organ does the same. The wheels spin, the keys close the circuit, and the pure tones appear as soon as the crank reaches the proper speed. The sound is a little thin compared to a full-on Hammond, and it’s intentionally faulty, but the mechanism is obvious.
[Source]

Advertisement

Source link

Continue Reading

Tech

What Speed Do Fighter Jets Land At?

Published

on





Fighter jets are some of the fastest air-breathing machines mankind has ever made, so it’s well-established that they move quickly through the air. The F-35 Lightning II, for example, has a top speed of Mach 1.6 (1,200 mph), so it’s not slow. Given how fast it and other fighter jets typically operate, it begs the question, “How fast do they land?” 

Comparatively, when you’re in a fast-moving commercial passenger plane that’s coming in for a landing, you probably don’t think too much about speed. Still, you’re moving pretty fast, and the same is true of fighter jets, though it depends on where it’s landing. Touching down on a nice, paved runway is ideal in most situations, but for fighter jets, the most challenging landing happens on an aircraft carrier, which forces the plane to a nearly immediate stop almost as soon as its wheels hit the deck. That’s due to the limited space and the need to arrest the aircraft’s movement so it doesn’t fall off the edge of the ship.

Advertisement

Looking back at commercial jets, they typically land at between 130 and 160 mph. The same is mostly true of fighter jets, as the physics of landing don’t change all that much whether you’re talking about a 344-ton Boeing 747 or a 9.85-ton F-16 Fighting Falcon. The typical range that a fighter jet lands is between 170 and 210 mph, so they come in at greater speeds than commercial aircraft, but not by too much. There are several reasons for this, including a fighter’s design for supersonic speeds, which actually makes it safer to land faster than a commercial aircraft would.

Advertisement

Fighters are designed to land at high speeds

Landing for commercial aircraft is purposefully designed to be as quiet and easy as possible. If not, fewer people would board a plane knowing that it would be an uncomfortable bump at the end of their flight. Military aviators aren’t afforded such luxury, but fast landings aren’t always about combat readiness. The problem concerns a fighter’s design, which prefers maneuverability and speed to comfort. As a result, landing slowly risks stalling; while hitting the ground at speeds of 210 mph may be rough, but it’s the safest way to get a fighter jet on the ground.

When you’re talking about landing a plane onto an aircraft carrier, however, it’s a completely different level of complexity. A fighter approaches the carrier for landing at around 150 mph, but don’t forget that the carrier itself is in constant motion; even if the ship isn’t moving forward, it’s sitting atop an ever-changing ocean landscape. Once the aircraft hits the flat top’s runway, it has to stop within 350 feet, which is where the arresting cables come into play.

In the above image, an F/A-18 Super Hornet is coming in for a landing on the USS Theodore Roosevelt (CVN-71). You can see its hook, jutting out behind the landing gear. This is meant to “grab” the cable, which stops the aircraft before it runs off the edge. So, while a Navy Aviator lands at 150 mph, they also stop almost suddenly, going from 150-0 mph in a matter of seconds. That’s quite different from landing on a runway, but many brave men and women do it numerous times throughout their careers.

Advertisement



Source link

Advertisement
Continue Reading

Tech

MRO Data Cleansing Before ERP Modernization: What to Fix First

Published

on

“In a perfect world, field and maintenance workers would go right to the system, search for a part, find it, and be on their way. However, many have a hard time locating what they need.”

 — Robbie Thompson, EY Americas Energy Supply Chain and Operations Leader

ERP modernization programs rank among the most capital-intensive initiatives in asset-intensive operations. The business case rests on automation, predictive maintenance, integrated procurement, and real-time inventory visibility. However, each of these capabilities depends on something a new platform cannot improve on its own : the quality of MRO data in the material master.

A new ERP changes how data is processed, connected, and used.. The content of that data stays exactly as it was on migration day. Duplicate records, unstructured descriptions, missing classifications, obsolete part numbers, and broken bills of material travel into a modern system intact, and the platform then acts on all of them.

Advertisement

The question that follows concerns sequence. Enterprise material masters can contain hundreds of thousands of records, and every modernization program works against a fixed go-live date. Teams that establish which defects to correct first arrive at go-live with a catalog the platform can trust.

The MRO Data Quality Gap: What Modernization Leaves Untouched

The material master in most legacy MRO systems reflects years of decentralized data entry, system migrations, and inconsistent conventions. Maintenance and procurement teams absorb the resulting gaps through undocumented operator knowledge and informal workarounds, which keeps those gaps invisible during routine operations.

The problems become harder to ignore when the data must support automated processes, cross-system reporting, or platform migration. At that point, the underlying issues appear in five recurring forms.

Duplicate Item Records

Advertisement

The same physical part appears under multiple descriptions, and each record carries its own stock balance, purchasing history, and reorder parameters. Demand and spend data fragments across those records, carrying costs rise, and part availability stays flat.

Unstructured Descriptions

Critical attributes such as dimensions and material specifications remain buried in free-text fields or go missing altogether. Naming conventions and data fields also drift across time and departments. A term such as “start date” or “criticality,” or a given part code, often carries a different definition today than it carried in 2015. Records that lack structured attributes fall out of search results, resist classification, and block automated processing.

Missing Classification

Advertisement

Records without UNSPSC codes, ECLASS identifiers, or standardized units of measure sit outside catalog-level governance. Spend analysis, demand aggregation, and supplier rationalization all need classification data, and each one stalls when that data goes missing.

Obsolete Records

Parts associated with decommissioned equipment stay active in the item master, hold safety stock, generate false demand signals, and overstate inventory values.

Orphaned Bills of Material

Advertisement

Spare parts that lack a link to the assets they support push maintenance planners back onto institutional knowledge. When the planner holding that knowledge stays unavailable, parts identification during a repair event slows to a halt.

The Operational and Financial Consequences of Poor MRO Data

Migration carries the downstream impacts of poor MRO data forward rather than clearing them. The new system inherits them all, and automation hides the data layer from direct view, making the same problems harder to trace.

This pattern extends well past ERP modernization. Product information management shows the same behavior, where a better system delivers better outcomes only when the underlying data supports it.

“In B2B and MRO contexts, incorrect product data creates duplicate ordering, wrong-part procurement, and downstream operational disruption.”

 — SunTec India

Advertisement

In ERP modernization programs, those consequences take five recurring operational and financial forms.

Inflated Working Capital: Duplicate SKUs hold the same physical parts under separate records, which raises carrying costs while availability stays where it was.

Procurement Leakage: The organization sources the same item from multiple suppliers at variable price points, because spend sits fragmented across duplicate records and resists consolidation.

Extended Mean Time to Repair (MTTR): Incomplete bills of material and broken spare-to-asset linkages delay parts identification during repair events, and asset availability falls as a result.

Advertisement

Inaccurate Financial Reporting: Duplicate and obsolete records overstate inventory and asset values, which creates exposure during an external audit.

Constrained Planning Accuracy: Inconsistent attribute and classification data undermine demand forecasting, criticality scoring, and inventory optimization at the catalog level.

How Modern ERP Platforms Compound Poor Data Quality

Modern ERP platforms remove the manual intermediary that legacy systems relied on. Automated reordering, predictive maintenance algorithms, spend analytics, and inventory optimization operate directly on master data and skip per-transaction human review. The platform acts on the inputs it receives, and that behaviour represents the core value proposition of modernization in MRO master data management.

The same behavior turns existing data gaps into larger operational liabilities.

Advertisement

In a legacy environment, humans filter data quality issues at the point of transaction. Modernization hands that filtering job back to the data itself.

Human-Mediated
Corrections Under Legacy MRO Systems

Outcomes
Under Modern ERP Platforms

A buyer recognizes that two records refer to
the same part and overrides the system before issuing a PO

Advertisement

Automated reordering generates separate
replenishment orders for the same physical part under multiple SKUs

A planner ignores a phantom BOM entry based
on field knowledge

Work order automation schedules an emergency
callout against a part that the system fails to locate

A category manager flags misclassified spend
before reporting it upward

Advertisement

Spend analytics produces a report that
misallocates spend by category and supplier

“When humans step too far back, a small system error can quickly turn into a wider operational problem. AI systems don’t fail only because of bad data; they can also fail by pushing a correct process in the wrong direction.”

 — Forbes

The Real Question: What Does an ERP Modernization Need in Order to Deliver Its Business Case?

The answer is MRO data cleansing, completed before migration and governed after go-live. Clean, deduplicated, and classified MRO data determines whether automated workflows deliver the business case or compound the failure. The platform inherits the data problem and passes it straight through to every process that runs on it. That work belongs upstream, in the data itself, before it ever reaches the new system.

Advertisement

Modernize MRO Operations: Cleanse, Govern, and Migrate

Phase 1: Cleanse MRO Data in Dependency Order Against a Stable Baseline

The team cleanses the current material master before it finalizes the migration design. The order of activities carries as much weight as the activities themselves, because each one consumes the output of the one before it:

1. Description normalization to ISO 8000-compliant noun-modifier-attribute format. Structured descriptions come first, because deduplication, taxonomy mapping, and catalog search all read these fields.

2. Deduplication across item masters, vendor masters, and cross-site records. Structured attributes turn duplicate detection from string matching into attribute comparison, which surfaces the pairs that free text hides.

Advertisement

3. Taxonomy mapping to UNSPSC, ECLASS, or another industry classification standard. Mapping runs once per surviving record, which spares the team a second round of adjudication after merges complete.

4. Attribute enrichment from OEM catalogs and verified supplier databases, applied to the records that survive consolidation.

5. Obsolete record identification and deletion flagging, carried out after consolidation so that the accurate record survives and its weaker twin retires.

6. BOM-to-asset linkage for critical spares, built last so that every link points at a stable, classified, enriched record.

Advertisement

Subject-matter experts review records after automated processing. Their review covers ambiguous duplicates, criticality classifications, regulated items, and BOM linkage decisions that call for field-level expertise of specific assets and operating environments.

Phase 2: Establish Governance Before Migration

Governance established before migration embeds itself in the new platform’s configuration. Teams that retrofit it after go-live find it harder to enforce and easier to bypass. The work includes:

  • Mandatory attribute sets enforced at the point of record creation
  • Restricted creation rights held by assigned data stewards by item category
  • Duplicate-check workflows embedded in the material requisition process
  • Change-control procedures governing the addition, modification, and deletion of records

Phase 3: Migrate Clean MRO Data

Clean, governed data turns validation into confirmation rather than discovery. Predictive maintenance, automated reordering, and spend analytics receive the structured, complete, and deduplicated inputs they need to deliver the operational returns the modernization promised: reduced downtime, optimized inventory, and consolidated spend.

Advertisement

MRO Data Cleansing: Automation with Human Oversight

MRO data cleansing has historically faced four constraints: timeline, cost, expert availability, and consistency at scale. Manual review at enterprise catalog depth ran slowly, cost heavily, and produced inconsistent results across thousands of records handled by multiple analysts.

AI-assisted approaches changed each of these constraints. Capabilities now standard in MRO cleansing programs include:

  • NLP-driven deduplication that identifies semantic duplicates across records whose descriptions and abbreviations differ
  • Machine learning classification engines that map items to target taxonomies at enterprise volume
  • Automated attribute enrichment against OEM catalogs and supplier databases

Human oversight remains essential throughout the cleansing process. Subject-matter experts review confidence scores on automated decisions, audit samples drawn from high-volume operations, and apply full adjudication to records that carry operational, safety, or compliance stakes.

The Business Case: Four Constraints Shape the Build-or-Buy Decision

Material masters at enterprise scale demand a time commitment that internal teams manage only by keeping attention away from their primary operations.

Domain expertise spans equipment, parts, suppliers, regulatory standards, and industry taxonomies, and few internal teams hold that combination end to end.

Advertisement

The supporting tooling stack covers NLP deduplication, ML classification, agentic enrichment, and validation databases, and building it for a single program ties up substantial capital.

Consistency across thousands of records depends on standardized workflows that mature over repeated engagements, not a single one.

Specialized MRO data cleansing services close these gaps. They provide domain expertise, technical infrastructure, and standardized workflows for assessment, cleansing, enrichment, and governance, leaving internal teams free to focus on core business operations and enterprise growth.

Conclusion: Clean MRO Data Is Critical to ERP Modernization 

The bigger question for modernization leaders is the data, not the platform. Every modern ERP processes MRO data at scale. The decision that matters is whether the data arrives clean, complete, and governed well enough for the organization to trust the maintenance, procurement, inventory, and reporting processes the platform will run on it.

Advertisement

MRO data cleansing therefore needs to be completed before migration, when defects can still be resolved without disrupting live workflows. Prioritize records with the greatest operational impact, establish clear ownership, and embed validation rules in the new environment before go-live.

It reduces the need for manual workarounds, gives automated processes more dependable inputs, and makes future data issues easier to identify and correct. In this way, data quality becomes part of how the organization sustains the value of ERP modernization after implementation. 

Source link

Advertisement
Continue Reading

Tech

Ratfield After Dark, Heatwarped Brings Back the Neon Nights of Early 2000s Need for Speed Street Racing

Published

on

Heatwarped Game Indie Racer Need for Speed
Somewhere between the wet asphalt reflections and the glow of undercarriage lights, a small indie team has built something a lot of players have wanted for years. Heatwarped, from Sealime, is an open-world arcade racer set squarely in the 2000s. It leans hard into the feeling of those late-night underground meets that defined Need for Speed Underground and its closest contemporaries. A free demo is already available on Steam, and the full game remains unscheduled.



Ratfield is smack in the midst of it all, a city that combines the excitement of busy downtown regions illuminated by neon lights with the wide-open spaces of the outskirts where you can stretch your legs and go for a run. As a player, you can freely switch between the two, hunting for rare components, fine-tuning your car’s setup, and earning your reputation one race at a time. Races often feature four cars on the road at the same time, and getting them all to the finish line is as simple as checking the board on your beloved PDA, which serves as a portable racing forum. You simply check the board, accept certain challenges, and off you go.


PlayStation®5 Digital Edition – 825GB
  • Slim Design, players get powerful gaming technology packed inside a sleek and compact console design.
  • 825GB of storage, keep your favorite games raeady and waiting for you to jump in and play
  • Ultra-High Speed SSD, maximize yoru play sessions with near instant load times for installed PS5 games

Heatwarped Game Screenshot
The primary focus of the game, however, is on the automobiles, namely the level of customization available. Deep, deep customization options allow you to go all out for that exact Y2K look, complete with body kits, spoilers, exposed carbon fiber hoods, and neon kits – or build up from an everyday ride into a real head-turner with some rare parts, and the goal remains the same as it has always been: make that car your own, then show it off on the street.

Heatwarped Game Screenshot
Driving-wise, the game remains firmly arcade, with extended drifts, nitrous blasts that leave a trail of light behind them, and the occasional jump to keep the adrenaline going. The city roads use a neat glowing chevron system so you can see those racing lines clearly while still feeling like you have plenty of room to move around in, and night driving gets a special treatment, as the way the light reflects off the wet road, the way the headlights cut through the darkness, and a soundtrack that matches the mood all work together to really pull you into the scene.

Heatwarped Game Screenshot
One of the most interesting things the developers have done is with the graphical settings. In addition to a very clean ‘Enhanced’ option, there’s a ‘Authentic’ setting that purposely reduces the graphics and interface to create a deliberate retro vibe, like the old sixth-generation consoles, and you can even drop the resolution way back to low if you want to get that true period feel.

Heatwarped Game Screenshot
The demo is brief, but it provides a decent overview of the main loop; simply stroll around, tweak your car, race a few times, and experiment with both visual styles. The good news is that full controller support is already in place, so if you have a controller, you can get right into it. When the entire game is out, you’ll be able to compete against other players online, racing in the same city.
[Source]

Source link

Advertisement
Continue Reading

Tech

Apple says third parties won’t run safe App Stores, but isn’t either

Published

on

Apple doesn’t even seem to be trying with App Store Review. Users should not be the ones who find problem apps, but over and over, that is what is happening. And, it’s happened again with a renovation app hiding Russian bank functionality.

No question, Apple has the resources to protect us from bad apps, and, no question, it keeps telling regulators that it has. As regulators around the world press for third-party firms to run iPhone App Stores, Apple consistently protests that only it can do a good job of keeping bad apps at bay.

It is absolutely true that if, or when, the door is open to rival App Stores, there will be a flood of apps that set out to defraud users. But if you’re going to hold up the App Store Review process as the last thin line of defense, you have to make it work and Apple is repeatedly failing.

Staggering and repeated mistakes

In August 2026, after countries such as the UK outlawed “nudifying” apps, for instance, The Independent has found several still on the App Store. One unnamed example lets users upload images into scenes called “bedroom rape.”

Advertisement

As keeps happening, Apple has now removed that app. But it passed App Store review and was only taken down when Apple was asked about it by that newspaper.

There are ways that developers can try skirting around the App Store Review process. They can, at least in theory, present an app that retrieves images and other assets from a website.

And then once the app is in the store, they can change those assets, or redirect the website. Apple would need to keep checking apps after they’ve passed the review process.

There are an incredible number of apps being submitted to the App Store every day, so periodic rechecking is time-consuming and expensive. But Apple cannot claim to be this protector of us all and then say except where it costs too much.

Advertisement

It appears, too, that in the case of that abhorrent “bedroom rape” app, Apple may have been able to catch it during the regular review process. That’s because the listing for the app reportedly featured descriptions and even graphic videos.

If the developer originally listed the app with something innocuous, then surely it uploading anything else should have triggered a new review. Developers have legitimate reasons to update their listings, but those listings are hosted on Apple’s servers so any change should be spotted and at least flagged for attention.

Gaming the system

There are too many apps being submitted and it’s at least conceivably possible for developers to make certain changes after being accepted. But it really does not appear as if Apple’s App Review team is doing its job.

For instance, long-time developer Jeff Johnson has detailed how he spotted and investigated a suspicious app. He dug into developer’s company and checked the validity of cited reviews. There were obvious clues from the start.

Advertisement
Grid of six customer review cards with five-star ratings, short testimonial titles, and brief text describing positive experiences using a software tool, including improved memory usage, research workflows, and tab management

Five-star reviews purportedly from the App Store, but including dates months before the app was released. Image credit: Jeff Johnson.

Johnson has two Safari extensions in the Mac App Store, and noticed that the same section includes one with a 4.9 out of 5 star rating. However, TabControl, which is still available in the App Store, unquestionably was not showing a genuine App Store rating.

Instead, the whole “4.9” part was a banner in the poster image, it has nothing to do with the App Store. At time of writing, there is no genuine App Store rating.

“This app hasn’t received enough ratings or reviews to display an overview,” says the App Store listing.

Advertisement

That’s a little odd when the app’s official website says that the extension is currently being used by “5,000+ Safari users.”

Johnson also found a number of purported App Store reviews listed on that site. These now appear to have been removed, but Johnson shows screengrabs including reviews that are dated from before the app was on the App Store.

“Do I expect Apple App Store review to do the research that I’ve done in this blog post?” writes Johnson. “Well, yes. Yes I do!”

We do too. It just isn’t happening with enough regularity.

Advertisement

“Practically speaking, App Store review didn’t even need to go as far down the rabbit hole as I did,” he continues. “The ‘4.9 out of 5’ stars in the App Store screenshot should have been a red flag.”

As he points out, Apple has all the details of all the ratings and reviews of every app from every country, so the App Store Review team should know it’s false advertising.

Even among more legitimate-seeming apps, though, Apple is ignoring clear problems. In AppleInsider research, for instance, we found that many price tiers listed for the “Simply Piano” app bore no relation to what the developer actually charges.

In that case, the developer first nonsensically claimed that it was a currency conversion issue. Then when that didn’t wash, they said that Apple keeps listing old prices because some users remain on those subscription rates.

Advertisement
Sidebyside screenshots showing a Simply Piano subscription: App Store list highlighting Individual Plan 1 Year at ?83.99, and a marketing screen advertising Individual Plan 12 months at ?164.99 billed annually

Left: Simply Piano’s listing for a one year individual plan in the UK App Store. Right: the same plan as charged inside the app downloaded from the App Store. Note the difference, it equates to $109. Screenshots taken 13 August 2026.

We reported this to Apple in June 2026, but the issue has not been addressed. Right now on the UK version of the App Store, Simply Piano’s listed price for an individual annual subscription is about $109 less than the app then charges.

It can’t go on

Apple is actually right about third-party App Stores, it is a dangerous and even frightening prospect that apps will not be tested and reviewed. It is true that we can’t automatically trust an app and just download it to see if we like it.

We’re already there in the official App Store. Trust in the App Store is already eroded, and it’s entirely Apple’s own fault.

Advertisement

The positive side is that for now it is under Apple’s control and so Apple can do something about all of this. There was the recent moment, for instance, when it pulled Telegram practically the moment that a user posted porn on it.

Apple also quickly restored it after the issue was resolved, so that’s another positive thing. But the Telegram issue was one user reportedly doing this deliberately to take down the app.

Grok flooded X with AI-generated porn in January 2026, some of it featuring minors. Reportedly Apple did threaten to remove Grok, and it did reject an update.

But the app remained on the App Store throughout. Apple rattled the sabers, and threatened removal. It didn’t actually do anything to prevent a horrific situation.

Advertisement

Maybe you can make a case that the App Store Review team gets tricked by developers replacing their listings or assets. And Apple surely isn’t lying when it proclaims that its App Review process prevented more than $2.2 billion in potentially fraudulent transactions in 2025.

What we cannot know, though, is how much fraud actually got through. We cannot know how much of that $2.2 billion was only prevented because of users like Johnson.

The Grok incidents were in your face headline news that caused global outrage, and the world’s richest man was publicly laughing about it. If that isn’t enough to get an app blocked, it’s no longer that the review process is about safety, it’s apparently about which developers have the most clout.

You shouldn’t have to be the one to investigate apps you want to try. That is the future of third-party App Stores, and that is a future to be fought.

Advertisement

But that future is here with the first-party App Store we already have. And this inability to trust an App Store is here, right now, because Apple will not do what it keeps saying it is doing and what it is charging developers to do.

Updated August 21 1:00 PM ET: The Russian T-Bank client “K8chen Pro” has made it to the top of the app store, masquerading as a 3D-rendering kitchen renovation assistant.

Source link

Advertisement
Continue Reading

Tech

Amazon drones go national, inside Anduril’s Seattle buildup, and AirTag leads to secret book-scanning site

Published

on

This week on the GeekWire Podcast: Amazon’s delivery drones are going national, nearly 13 years after Jeff Bezos unveiled them on 60 Minutes. We listen back and discuss what’s next.

Plus: We go inside Anduril’s unmarked Bellevue office as the defense company builds toward 1,000 Seattle-area engineers; a reporter hides an AirTag in a rare book and tracks it to a secret Amazon book-scanning facility in Las Vegas; and an Anduril-themed trivia challenge.

Audio editing and production by Curt Milton.

Related stories and links

Mentioned at the top

Amazon drone delivery

The AirTag and the book-scanning facility

Anduril in the Seattle region

Subscribe to GeekWire in Apple Podcasts, Spotify, or wherever you listen.

Source link

Advertisement
Continue Reading

Tech

OpenAI says California should strengthen its AI safety bill

Published

on

OpenAI is calling for California to add more safeguards to a landmark AI safety bill that was passed last year.

In a LinkedIn post from the company’s global affairs team, OpenAI said California’s SB 53 “should be amended to expand safeguards,” for example by “requiring monitoring of frontier models under training or evaluation for potential serious incidents,” and by “strengthening cybersecurity protections throughout the model-development lifecycle.”

“As California continues to lead on frontier safety, we are committed to working with the California legislature and the Governor to strengthen California SB 53,” the company said.

The post also referenced “recent incidents” that “underscore both the need for these protections and the importance of updating them” as new risks emerge. Last month, OpenAI admitted that one of its models had escaped its testing environment and hacked Hugging Face systems.

Advertisement

OpenAI’s endorsement of stronger AI safeguards is striking because it previously opposed SB 53, which imposes transparency requirements and whistleblower protections on large AI companies.

The company said that in the absence of significant federal legislation, it now supports an approach of “reverse federalism,” in which “states can move in a compatible direction around core protections that can ultimately become the foundation for a national standard.”

Source link

Advertisement
Continue Reading

Tech

If you’re not using AI to attack your own systems, your adversaries will

Published

on

AI agents excel at hacking organizations, as they’ve demonstrated in real-life attacks multiple times over the past few weeks. They also expose a whole new attack surface for organizations trying to protect against both human and AI intrusions.

As if defenders needed more worries to keep them up at night, agents introduce new data-integration channels that attackers can abuse. They also introduce a new type – and ever growing number – of non-human identities that are difficult to manage and can bypass traditional, static security policies.

“There is tremendous risk associated with agentic AI and machine identities,” Matt Hartman, former acting head of cyber of the US Cybersecurity and Infrastructure Security Agency (CISA), told The Register.

“As AI moves from generating content – yesterday’s use case – to taking actions, it is inevitable that agents are going to receive access to sensitive systems and sensitive data,” Hartman said. “One area where organizations are struggling today is that they’re going to need to treat every agent as a privileged identity.”

Advertisement

Enterprises also face agentic threats from outside their organization, he added.

“AI-enabled or AI-amplified identity and social engineering attacks are increasing significantly by the minute,” Hartman said. “We’re seeing very highly personalized phishing, very good impersonation, automated reconnaissance. That really makes traditional indicators of trust increasingly unreliable.”

For defenders, this means a “continued focus on strong identity, on phishing-resistant authentication, on behavioral signals, and on zero-trust principles therein,” he added. “Nothing deeply new here – but it is a whole new attack surface.”

Meanwhile, on the attackers’ side, agents don’t take time off, and they remain singularly focused on completing a task, whether that’s finding vulnerabilities and exploit chains or mapping networks and identifying sensitive files. All of this makes these near-autonomous attack bots a gift from the heavens for financially motivated criminals and government-backed cyber operatives

Advertisement

It also presents a security use case for defenders: agentic red teaming.

As former NSA cyber boss Rob Joyce said during a talk at RSAC: if you aren’t using AI agents to attack your own organizations, you can bet that someone else is. “You are going to be red-teamed whether you pay for it or not,” Joyce said. “The only difference is, you know who gets the results delivered to them.”

Hartman echoed Joyce’s words. “What we are seeing as the leading capabilities to help defenders – there is a burgeoning market for continuous, AI-native, AI-enabled, automated red teaming and pen-testing,” he told us.

After spending nearly two decades in the federal government at CISA, Hartman joined Merlin Group in October as its chief strategy officer. In his new private-sector role, he helps determine which early- to growth-stage cybersecurity and emerging technology companies the group invests in, and then works with these firms to navigate government, critical infrastructure, and other highly regulated markets. 

Advertisement

The goal is to integrate and scale “promising technologies” into critical environments, Hartman said. Right now, most of these technologies use AI agents to fight AI agents.

“Organizations are just inundated with vulnerabilities, and adversaries are able to leverage AI to find vulnerabilities and exploit them in seconds when it used to take days,” he said. Agentic red teaming “is a category of products that every organization, including federal agencies, absolutely needs in the near term just to keep pace.” 

‘Largest controlled live AI cyberattack on record’

Mandiant founder and former CEO Kevin Mandia has a new company, Armadin, which launched in March with a startling $190 million in seed and Series A funding. The firm builds and trains autonomous attacker swarms – thousands of AI agents that run 24/7 in organizations’ infrastructure to simulate real-life attackers.

Ahead of Black Hat earlier this month, the startup said it and Tenex.ai, an agentic security operations provider, executed what they called the “largest controlled live AI cyberattack on record” for an unnamed “leading” global institution.

Advertisement

Over the three-day attack, Armadin’s swarm generated 17 million offensive actions, discovered 38 validated attack paths, and produced 238 security findings. Tenex.ai’s agentic platform separately triaged 100 percent of 101,169 alerts and reconstructed the entire attack across 231 billion raw events. 

This exercise, we’re told, would have taken a five-person analyst team about 2,400 hours – or four months – to pull off.

Co-founder and Chief Offensive Security Officer Evan Peña was the global red-team lead at Mandiant before co-founding Armadin. At Mandiant, he led a 210-person team whose members spanned the globe.

“The problem was it was 100 percent human-led security assessments, and that would generally limit the amount of time that we would have,” Peña told The Register.

Advertisement

His red team “would do a couple weeks or a one-month engagement, and then we would report on the engagement, give them a PDF file, walk away, and they would hire us again in a year. In today’s age of AI, it’s very archaic to think about that when we can scale so significantly with AI.”

Attack yourself before someone else does

At Armadin, Peña leads the human team that trains the AI agents. One of the lessons learned from OpenAI’s models autonomously attacking Hugging Face, according to Peña, is that organizations need to perform safe offensive AI attacks against their own systems. “Safe” is the keyword here: remember OpenAI’s rogue models intentionally didn’t have any guardrails in place.

Yes, his statement is self-serving as it’s core to Armadin’s business. But he’s not wrong.

“Organizations can cover so much more attack surface because we are able to leverage these agents at scale, and we have three things that we didn’t have before,” he said. “We have more time, because agents don’t sleep and they don’t take holidays. There’s no workforce requirements for them.”

Advertisement

Number two, he said, is expertise. Attack agents need pre-training before they are set loose on organizations’ infrastructure. They need to know how to code, and perform source-code review. They need to know how to do application security, how to spot network misconfigurations, and hack into different systems and networks. “And then you add post-training to that from human expertise,” Peña said.

“Number three is coverage,” he said. “We were only able to cover a finite amount of attack surface in the past. So if you had 10,000 external systems with a limited amount of time and humans, you could maybe cover 2,000 or 1,000 of those within that particular period of time. Now we can cover all 10,000 in probably hours.”

Armadin’s AI agents have broken into every single customer’s environment, according to Peña. 

“We have found over 50 zero-days, and by zero-days, I don’t just mean this zero-day allowed you to deface a web page. That’s cool, but I want to break into your network from the internet,” he said. “The zero-days I’m referring to allow an attacker to get remote code execution on an actual system. They’re very high-impact zero-days. We don’t care about noise, we care about impact.” 

Advertisement

Quarterly pen-testing doesn’t cut it anymore

The biggest challenge these days for defenders is the scale and speed AI brings to previously manual attackers’ dirty work – like scoping potential victims, performing reconnaissance, identifying vulnerable systems and exploits, and reading logs. Now all of these tasks can be automated.

Penetration testing needs to keep up, Jay Bavisi, founder and group president of EC-Council, told The Register. The largest and best organizations do pen-testing once a year to meet compliance requirements, and “the better ones” run these exercises quarterly, Bavisi said. This is largely because human-led pen-tests take about three months.

“So you have a serious problem with speed,” he said in an interview. “Then comes the second problem, which is scope. Nobody pen tests the entire organization.”

There’s also what Bavisi calls a “sophistication problem,” because different human pen-testers will produce varied results, and organizations can’t hire hundreds of thousands of humans to try to break into their networks on a continuous basis.

Advertisement

“The bad guys are already using AI to get rid of the speed problem. You pen-test once a year for compliance. They do it all the time because you’re a gold mine. They don’t have a scope problem because they’re not just looking at the crown jewels – they’re looking at your entire organization. And they don’t have a sophistication problem because they’re using algorithmic systems.”

In June, the global cybersecurity training organization began offering pen-testing professionals a sponsored attempt to take the CPENT AI examination, and upskill themselves for the AI era. 

For every participant who passes, the council donates $1,000 in cybersecurity training and certification credits to nonprofit partners. For every completed training program, regardless of an exam pass or fail, the nonprofits get $250, and all of this has a $1 million max.

“The traditional model of pen-testing once a year or once a quarter, that’s going away, and AI will take over with automated pen-testing,” Bavisi said. “But will the role of pen testers vanish? No, it will not. It will evolve into something much bigger and something far more important.”

Advertisement

AI systems and AI-integrated applications mean there’s a lot more for security professionals to try to break and break into, and humans need to determine: What is the result of this system breaking? What’s the business impact? What do I prioritize fixing?

“The present pen-testers have to be reskilled into understanding business impact and being able to make those important engineering decisions,” Bavisi said.

Meanwhile, “offensive AI security professionals are the ones that are going to have to test the robustness of AI systems, because AI systems will become the heartbeat of organizations,” he added. “Pen-testers have to become masters of testing LLMs, understanding agentic behavior, thinking about what is the harm taxonomy, figuring out what kind of guardrails did we put in place.”

The job of pen-testers has changed, in other words. “It now has a far wider scope.” ®

Advertisement

Source link

Continue Reading

Trending

Copyright © 2025