Phishers find a new use for invisible Unicode tag characters
Fraudsters have found a new use for ASCII smuggling, typically used to hide malicious prompts intended for AI models, in an old-school attack method: email phishing.
Advertisement
Microsoft uncovered a massive phishing campaign using invisible Unicode tag characters that peaked at more than 2.37 million messages in late February, remained elevated during weekdays over the next three months, and gradually declined by mid-June.
“As AI-era attack methods become better understood, threat actors may adapt them for use in more traditional threats such as phishing and spam,” Redmond’s researchers Noam Kochavi and Sarah Wolstencroft said in a Thursday blog. “This case illustrates how techniques that emerge in AI security research can quickly cross over into established attack ecosystems, reinforcing the need for defenders to view emerging threats through a cross-domain lens.”
ASCII smuggling involves using invisible or non-rendering Unicode characters to hide content inside text that appears normal to humans, and this makes it a popular technique for indirect prompt injection attacks. In these, an attacker hides instructions for an AI assistant in invisible Unicode characters, and embeds those malicious prompts inside a webpage or document. A human can’t see them, but a model can, and it decodes them as text – and may then follow the attacker’s instructions to leak data or take unauthorized actions.
Instead of using ASCII smuggling for prompt injection, however, Microsoft’s security team spotted someone using invisible characters – inserting Unicode tag spaces between letters – to split financial-lure words in phishing emails in an apparent attempt to evade keyword matching and other content filters. So, for example, instead of writing “funding” in the email, the attackers wrote “fun⟨U+E0020⟩ding.”
Advertisement
“When we looked at a sampling of the flagged messages, the surprise was there were no smuggled instructions to an AI assistant,” Kochavi and Wolstencroft wrote. “Instead, the invisible tag characters were inserted inside common financial keywords, splitting them apart so that a literal signature or keyword match would fail.”
Redmond first detected the ASCII-smuggling signature in early February, flagging about 21,000 messages on February 8 before the number skyrocketed to more than 1.3 million the next day. Most of these emails came from about 150 finance-themed sender domains, and they continued for the next three months, dropping sharply after May 15 but continuing with occasional smaller spikes through at least mid-June.
The security researchers pointed out two notable characteristics, including sending massive numbers of emails on weekdays and then going silent over the weekend.
The campaign also had a long, gradual decline. “After an intense first phase, with weekday volumes of 1 to 2.37 million messages, peaking on February 26, the numbers stepped down slowly to roughly 80 percent less per weekday by late March.” It then dropped significantly after May 15, continuing with lower activity through mid-June.
Advertisement
According to Redmond, the most important thing defenders can do to protect against Unicode tag blocks in phishing emails is to verify that normalization and tokenization pipelines handle tag characters consistently.
“Any content that will be evaluated by keyword, signature, or regex logic should first have invisible and non-rendering Unicode code points stripped or folded, so that splicing them into a word no longer defeats the match,” the threat hunters wrote.
This same control can also help reduce the threat of ASCII-smuggling against AI assistants that ingest email content.
Microsoft also suggests scanning for behavioral indicators. “The observed activity had a distinctive shape: bulk volume from churning, finance-themed disposable domains, on a strict weekday-on / weekend-off schedule,” Kochavi and Wolstencroft warned. “A sudden spike of tag-block characters concentrated on finance-themed senders, switching on and off weekly, is a high-confidence campaign indicator.” ®
Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution.
Tracked as CVE-2026-73749, the security issue is a buffer overflow that allows unauthenticated remote attackers to send specially crafted packets to an affected daemon process, achieving code execution with elevated privileges.
“Multiple vulnerabilities exist in a daemon of ArubaOS-CX that may allow for improper processing of malformed input,” reads HPE’s bulletin.
“An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service.”
Advertisement
Affected release branches and fixes listed in the bulletin are:
10.18.0001 → upgrade to 10.18.1002+
10.17.1021 and earlier → 10.17.1030+
10.16.1051 and earlier → 10.16.1060+
10.13.1180 and earlier → 10.13.1190+
10.10.1180 and earlier → 10.10.1181+
HPE noted that the AOS-CX 10.10.1181 version has reached End of Maintenance (EOM) and only receives fixes for internally discovered, critical issues, a condition that also applies to CVE-2026-73749.
ArubaOS-CX is HPE Aruba Networking’s operating system for its enterprise-grade network switches, typically used by large businesses, government agencies, universities, healthcare organizations, data centers, and service providers.
HPE’s security bulletin also covers a set of 23 other security vulnerabilities, some with high severity ratings, between 8.1 and 8.8:
CVE-2026-73750: A low-privileged authenticated remote attacker can send malformed or truncated input to an AOS-CX management module, potentially causing denial of service or executing code with elevated privileges.
CVE-2026-73751: A low-privileged authenticated user can submit crafted input through the AOS-CX web-based management interface to execute arbitrary commands on the underlying operating system.
CVE-2026-73752: An unauthenticated attacker with adjacent-network access can exploit an AOS-CX API endpoint to write arbitrary files to the underlying operating system, potentially leading to remote code execution.
CVE-2026-73753: A low-privileged authenticated user can exploit affected AOS-CX command-line operations to execute arbitrary commands as a privileged user on the underlying operating system.
CVE-2026-73782: An unauthenticated attacker with adjacent-network access can exploit a format-string vulnerability in the AOS-CX command-line interface to execute arbitrary code as a privileged user on the underlying operating system.
CVE-2026-73781: An authenticated remote attacker can exploit a stored cross-site scripting vulnerability in the AOS-CX web-based management interface to execute arbitrary scripts in an administrator’s browser if the administrator interacts with the affected content.
CVE-2026-73780: An unauthenticated remote attacker can exploit missing CSRF protections in some certificate-authenticated AOS-CX sessions to submit arbitrary input to the web-based management interface by convincing an authenticated user to open a crafted URL.
CVE-2026-73779: An unauthenticated attacker with adjacent-network access can bypass authentication controls on AOS-CX switches, potentially exposing sensitive information, enabling unauthorized modifications, and disrupting services.
CVE-2026-73778: An unauthenticated remote attacker can use a predictable factory-default password to obtain full administrative control of an AOS-CX device that remains in its factory-default or post-ZTP state before an administrator configures credentials.
CVE-2026-73777: An unauthenticated remote attacker can exploit vulnerabilities in an AOS-CX API endpoint to bypass access controls and escalate privileges.
The vendor “strongly encourages” customers to upgrade to one of the fixed releases listed in the bulletin.
HPE mentions that, at the time of the bulletin’s publication, it was not aware of active exploitation or publicly available proof-of-concept exploits targeting the listed flaws.
Advertisement
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Apple TV just confirmed that Silo is returning for a fourth season on July 9, 2027, and the teaser that dropped with the announcement gives us glimpses of what happens next. The final chapter will pick up after the dramatic events of Season 3, with Juliette Nichols preparing for a direct confrontation that could determine the fate of every silo.
Juliette taking the fight to Silo 1 in season 4 trailer
Season 3 expanded the story by revealing the truth about Silo 1, where survivors from the past oversee the remaining silos. The teaser shows Juliette returning with a new purpose after uncovering those secrets. Instead of simply trying to survive, she is now determined to challenge the people controlling the underground world.
Apple says the new season follows Juliette as she uncovers even more hidden truths while fighting to protect the future of the silos. The teaser also hints that the conflict between Silo 18 and Silo 1 will become the central focus.
Advertisement
According to showrunner Graham Yost, the season can be summed up in two words: “It’s war.” The story will also spend more time inside Silo 1, giving viewers a closer look at how it operates and the people pulling the strings.
Apple TV
The final season is set to answer long-running questions
Season 4 will expand its focus inside Silo 1, bringing side characters like Senator Rosalind Thurman, her daughter Anna, and aide Henry further into the spotlight. But the bigger payoff might be closure on characters who’ve been missing since the explosion that first sent everyone underground.
Apple TV
Journalist Helen Drew disappeared from the story after that moment, and Yost has confirmed her fate is exactly what season 4 plans to reveal, along with flashbacks connecting her time inside Silo 18 to the present. Whatever happened to trillionaire Per Stensen remains a separate open question the show hasn’t addressed yet, but we see a glimpse in the teaser.
The final season brings back Rebecca Ferguson, Common, Harriet Walter, Chinaza Uche, Avi Nash, Ashley Zukerman, Jessica Brown Findlay, and Steve Zahn. With a release date now locked in, Silo is heading toward its ending with a lot riding on it, and a full cast ready to bring its sprawling mystery to a close next year.
Less than three months after emerging from stealth, XDOF, a startup that collects real-world teleoperation data for training general-purpose robots, is in late-stage talks to raise a Series B at a valuation of about $1.2 billion valuation led by 8VC, several people with knowledge of the deal said.
XDOF was co-founded by UC Berkeley researchers Philipp Wu (CEO) and Fred Shentu (CTO) in 2024. TechCrunch reported on the startup’s $70 million Series A in June, with participation from Thrive Capital, Andreessen Horowitz, Lux, and Spark Capital. XDOF wasn’t planning to raise again so soon after that round. But the company’s rapid growth — with annualized revenue approaching $50 million — prompted VCs to approach it about a new round, the people said.
TechCrunch was unable to learn the total capital being raised or whether the valuation includes the new funding. The terms of the deal are not final and could still change.
XDOF and 8VC didn’t respond to our request for comment.
Advertisement
The startup aims to build the data pipelines, collection tools, and annotation systems that frontier AI labs and robotics companies can’t easily build themselves, essentially acting as an outsourced data-supply chain for the robotics industry.
As a PhD student, Wu was studying how robots learn from large datasets. One big impediment to his research was the lack of “large-scale data to work with,” he told TechCrunch in June.
So he teamed up with Shentu on a project called GELLO, a low-cost teleoperation system that allows a human operator to control a robotic arm remotely in order to generate training data. Their work led to an influential paper in robotics.
That research formed the foundation for XDOF, which investors now describe as the Scale AI or Mercor for physical robotics, a reference to the data-labeling giants that helped fuel the AI boom. Unlike LLMs, which initially trained on the entirety of the internet, physical robots don’t have an equivalent real-world dataset to draw from, making data collection a critical bottleneck to building general-purpose machines.
Advertisement
XDOF is partnering with UC Berkeley’s AI Research lab to release what it believes is the largest collection of high-quality robot training data ever assembled, dubbed ABC.
To capture this data, XDOF combines remote robot teleoperation with human collectors who wear sensors to record everyday tasks like folding clothes and flattening boxes.
The startup plans to hire and train teams of data collectors worldwide, including teleoperators who steer robots remotely and egocentric operators who wear body sensors to capture movement data.
XDOF previously told TechCrunch that it is already working with 20 customers, including several frontier AI labs.
Advertisement
Other startups attempting to collect real-world data for robot training include Mecka AI, as well as human-data platforms expanding beyond LLMs, such as Scale AI and Micro1.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
AMD just built a desktop that really has no business sitting on an actual desk. At IFA 2026, the company unveiled the Threadripper Halo Station.
As the name probably already suggests, it is a liquid-cooled machine that can run AI models with more than a trillion parameters without touching the cloud even once. If you don’t already know, those numbers are reserved for server shelves, not someone’s personal desk.
AMD / X
So what exactly is inside the Threadripper Halo Station?
The CPU alone is quite absurd on paper. It uses AMD’s Threadripper Pro 9995WX, built on Zen 5 architecture, with 96 processing cores and 192 threads. The maximum clock speed (with boost) can reach 5.4GHz, helping it tackle demanding tasks faster, and it also has a massive 384MB M3 cache for faster data processing.
Besides, 128 PCIe 5.0 lanes provide plenty of bandwidth for the rest of the hardware. To sustain all that performance, the machine needs a 350W TDP, which is significantly higher than a regular gaming PC.
Alongside it are two liquid-cooled Instinct MI350P accelerators, each with 128 CDNA 4 compute units built on TSMC’s N3 process. Each can draw up to 600 watts and comes with 144GB of HBM3E memory and up to 4TB/s of bandwidth, and the GPU memory is frankly ridiculous: 288GB across the two accelerators.
Advertisement
For context, 288GB is several times more GPU memory than you’ll typically find in higher-end gaming PCs or laptops. AMD says the platform will eventually support up to four accelerators, pushing that figure up to 576GB.
AMD / X
How does this compare to rival systems, and can you actually buy one?
All of that sits on top of 2TB of DDR5 system memory, which, yet again, shows how far beyond a typical PC this machine is. The combination of the CPU cores, GPU horsepower, and sheer memory capacity lets AMD claim this machine can load and run AI models north of a trillion parameters entirely on-device.
This is clearly built for a server room with proper power and cooling infrastructure, not a home office. AMD hasn’t announced pricing or a release date for the Halo Station yet, though. However, estimates about the component costs alone put the machine well past $100,000
I’d still consider this a showcase of sheer computing power in a cabin that looks like a high-end gaming PC, at least at IFA 2026.
The Luna Band is now shipping worldwide, giving users access to a wearable that promises to personalise its health tracking around their individual goals. The company announced the global availability at IFA 2026, alongside LifeOS, the health intelligence platform that powers the Band.
Unlike conventional wearables that use the same tracking approach for everyone, Luna says its Band adapts to what each user wants to achieve. When a new goal is added, the device changes what it measures and how frequently it takes readings, while LifeOS retrains its models around that individual’s body.
That means two Luna Bands can effectively become different products depending on who is wearing them. The hardware itself uses the same set of sensors, but the user’s goals shape how those sensors, the firmware and LifeOS are used. Luna says the system learns each wearer’s personal baselines rather than comparing them with an average user.
The Band also uses what Luna calls Micro Apps and Peak Score to tailor the experience further. Rather than simply presenting biometric data and leaving users to work out what it means, Luna says LifeOS turns those signals into actionable guidance and builds a daily calendar around the user’s goals.
Advertisement
The company says more than 100,000 people joined the Luna Band waitlist ahead of its launch, while the first drop sold out. Early reviews have also described it as a different approach to health tracking, with personalisation and goal-based progress built into the same system.
Advertisement
There is no subscription required, either. Luna says all of the guidance is included with the Band, which could make its €149 price more appealing for users who don’t want another monthly health subscription.
The Luna Band is now available worldwide through Luna’s website for €149. The company is also showcasing the wearable at IFA Berlin.
The Creative Soundblaster AE-X is a compact, well-built PCIe sound card that delivers a genuinely audible step up from on-board audio with a beefed-up DAC to allow for detailed audio and a clean overall presentation. It handles games and music equally well, while the on-board software provides extensive customisation. Against other soundcards, it drops multi-channel surround support entirely, so anyone running a discrete speaker setup rather than headphones won’t find much reason to make the switch.
Hi-fi grade DAC brings real detail retrieval
Drives even 600-ohm headphones with ease
Feature-rich Nexus software with AutoEQ support
Stereo only, no multi-channel surround
Overkill if you’re on more affordable hardware
Key Features
Advertisement
Review Price:
£169.99
ESS ES9039Q2M Sabre DAC inside:
Advertisement
The DAC inside this Creative sound card is a real step-up from previous options, providing more space, clarity and detail.
Single-slot design:
Advertisement
It’s also fully metal, and takes up only a single slot in a PC case so is nice and compact.
Nexus software:
Advertisement
The Soundblaster AE-X has some neat Windows software with lots of customisation potential.
Introduction
Creative has been a name synonymous with PC audio for a very long time, especially its venerable line of Soundblaster sound cards.
The new Soundblaster AE-X is the brand’s first in some time and is a mid-range add-in card for folks wanting to level up their PC audio game from standard on-board audio on your motherboard.
Advertisement
Specs-wise, we’ve got an ESS ES9039Q2M DAC chip inside, a Discrete Xamp Bi-Amplifier for headphones with up to 600 ohms of impedance, plus some far-reaching software and file format support to make this one of the more feature-rich PC sound cards you can buy.
At £169.99 / $179.99, it’s in the mid-range for what PC gamers might consider a viable option if you want to beef up your on-board audio without breaking the bank.
Advertisement
Design
Two-tone white and grey colour scheme
Solid metal finish
Compact and easy to place in a PC
The Soundblaster AE-X works as a PCIe add-in card that you can slot into a vacant PCIe slot in your PC underneath your graphics card. These kinds of devices specifically for audio aren’t as common as they used to be, but it’s pleasant to know they still exist.
The card itself is compact and sits at a single slot wide, so it won’t take up much space in your PC internally. Connectivity is handled by a small PCIe x1 slot, meaning this card will fit in virtually any vacant slot you have on your motherboard.
Advertisement
Image Credit (Trusted Reviews)
The chassis of the Soundblaster AE-X is entirely metal, lending itself to a quality finish. I’m a fan of the two-tone white and black colour scheme, which gives this sound card a more professional aesthetic than something traditionally designed for the gaming crowd.
Advertisement
As well as the card itself, the brand also includes a 3.5mm splitter cable and a convenient quick start guide.
Features
Beefed-up DAC against previous models
Solid port selection for stereo listening
Extensive PC software features
Inside, the Soundblaster AE-X features an ESS ES9039Q2M Sabre DAC, which is one of ESS’s newest DACs, and a big upgrade over the ESS E9016K2M Creative had employed on previous Soundblaster products.
This DAC allows the unit to support PCM playback up to 32-bit/384KHz. It also has native DSD playback, supporting up to DSD256 files, helping to reflect Creative’s positioning of this sound card as closer to dedicated hi-fi DACs rather than a conventional PC sound card.
Image Credit (Trusted Reviews)
It becomes clear Creative is positioning this sound card more towards headphone and stereo listening rather than any form of surround sound, as it has in the past. This is reflected in its selection of ports on the rear side, which totals a Toslink SPDIF input, a Coaxial SPDIF output, RCA line-out for left and right, a headphone out and a mic/line-in port.
Advertisement
Advertisement
The Soundblaster AE-X also has its own dedicated headphone amp inside, delivering up to 350mW at 32 ohms, while this unit is happy to drive headphones with up to 600 ohms of impedance. I know impedance isn’t the only thing that affects how easy a set of headphones is to drive, but it means this Creative unit can drive some seriously beefy cans without breaking a sweat.
Image Credit (Trusted Reviews)
The front of the card is home to something that resembles a USB 2.0 or HD Audio connector, but is instead a front panel audio hookup, so you can run your case’s front panel connector directly to the Creative’s DAC rather than the on-board audio. However, that only gives you access to the 3.5mm jack likely on the front of your PC, so you’re best using the rear ports.
Once installed in your PC, the Soundblaster AE-X works with the brand’s Nexus software that provides the opportunity for a wide array of tinkering. This includes a comprehensive multi-band EQ along with a good selection of presets, plus you can save your own, too. It also includes an AutoEQ that can be set with a range of specific headphone models to apply calibration curves to compensate for any anomalies in a set of cans’ frequency response.
Image Credit (Trusted Reviews)
In the software, you can also choose different sound modes – Direct Mode bypasses most DSP processing to provide the cleanest sound, while Acoustic Engine mode unlocks Creative’s DSP toolkit for this sound card, and Scout Mode is specifically designed for competitive games where you want the most precise audio possible.
Advertisement
Performance
Lower noise floor than on-board audio
Confident drive of hard-to-power headphones
Detailed presentation with good bass extension and solid mids
The real benefit of upgrading to the Soundblaster AE-X over on-board motherboard audio becomes apparent almost immediately. By moving to a proper card with a strong DAC with real hi-fi credentials, the big change is that you move to a lower noise floor.
This essentially means that it lessens any background hiss, plus you get improved dynamic range and audio becomes more detailed. In testing with a set of affordable FiiO SP3 BT speakers, the Soundblaster AE-X provided audio that felt even more spacious and detailed, while the DAC itself didn’t tend to colour the audio too much. It provides a neutral and well-balanced presentation.
Advertisement
Image Credit (Trusted Reviews)
Moving over to a set of hard-to-drive Drop + Sennheiser HD6XX headphones (deliberately chosen for their more neutral, reference-like profile), this Creative sound card afforded audio that provides a tight and controlled low-end when delving into my usual suite of rock testing tracks from Rush and Marillion. Plus, it played completely nicely with an SACD rip of Genesis’ Abacab in DSD64.
As for the mid-range, moving to James Taylor’s September Grass, the Soundblaster AE-X offers some wonderfully detailed results, accentuating elements such as the distant drum shuffle and the intimate combo of Taylor’s voice and lovely fingerpicked guitar.
Advertisement
Image Credit (Trusted Reviews)
The top-end presented by this card isn’t so much particularly harsh, but rather provides more meat on the bone and detail. The competing percussion intro on Steely Dan’s Do It Again provides a formidable test, which this Creative card handles with panache, offering a rich and wide soundscape with plenty of detail retrieval, and without verging on harsh.
This also lends well to the Soundblaster AE-X’s Scout Mode, which is ideal for FPS gaming. When paired with the right set of headphones or a gaming headset, details such as footsteps and enemy movement are much wider and clearer than with on-board audio, with greater precision. While it isn’t going to be a substitute for using a lower-grade headset, it can certainly help you position enemies in a more optimal manner.
Image Credit (Trusted Reviews)
That said, the Scout Mode can tend to accentuate those details a little too much, skewing the overall sound signature somewhat. The default tuning of this Creative soundcard still helps for excellent directional accuracy.
Advertisement
Advertisement
Should you buy it?
You want more from your headphones
The AE-X’s discrete amp and 600-ohm drive capability get genuinely better results out of demanding headphones than on-board audio can manage, with a noticeably lower noise floor and more detailed audio to match.
Advertisement
You run a surround speaker setup
The card is strictly stereo with no 5.1/7.1 or Dolby/DTS support, so anyone relying on multi-channel speakers won’t see any benefit from making the switch to the Soundblaster AE-X.
Advertisement
Final Thoughts
The Creative Soundblaster AE-X is a compact, well-built PCIe sound card that delivers a genuinely audible step up from on-board audio with a beefed-up DAC to allow for detailed audio and a clean overall presentation.
It handles games and music equally well, while the on-board software provides extensive customisation. Against other soundcards, it drops multi-channel surround support entirely, so anyone running a discrete speaker setup rather than headphones won’t find much reason to make the switch.
Advertisement
How We Test
We test every DAC we review thoroughly over an extended period of time. We use industry standard tests to compare features properly. We’ll always tell you what we find.
We never, ever, accept money to review a product.
Find out more about how we test in our ethics policy.
Tested for several days
Tested with real world use
FAQs
What DAC does the Creative Soundblaster AE-X use?
The Creative Soundblaster AE-X uses the ESS ES9039Q2M Sabre DAC, which is a real step-up from previous Soundblaster cards.
Advertisement
Test Data
Full Specs
Creative Soundblaster AE-X Review
Manufacturer
Creative
Size (Dimensions)
126 x 179 x 18 INCHES
Weight
263 G
DAC
ESS ES9039Q2M Sabre DAC
Release Date
2026
First Reviewed Date
21/08/2026
Resolution
x
Audio Formats
Up to 32-bit / 384 kHz, with up to DSD256 support
Outputs
Toslink SPDIF input, a Coaxial SPDIF output, RCA line-out for left and right, a headphone out and a mic/line-in port.
At TechRadar this weekend we’ve got one eye on the best Labor Day sales that you can pick up — with big discounts on offer on tech and so much more — and another eye on the week that just finished, which was as hectic as most weeks in technology tend to be.
We had a host of new products on show at the IFA 2026 tech event in Berlin, OpenAI dropping its best ChatGPT model yet and declaring the age of AGI (Artificial General Intelligence), and Dyson bringing out its first toothbrush. Oh, and we also made time to review the Pixel 11 Pro and have an exclusive chat with Sonos CEO Tom Conrad.
You’ll find all that and more in our ICYMI (In Case You Missed It) round-up below — our pick of the best tech headlines on our pages over the past week. Enjoy catching up!
Advertisement
Latest Videos FromTechRadar
7. The ‘Lake America’ saga hit Google and Apple
There’s more Google Maps drama (Image credit: Google)
The Trump administration has decided that Lake Ontario on the US-Canada border should be called Lake America, after some 400 years or so (and a few trade spats with Canada). Google Maps and eventually Apple Maps went along with the change, stressing that it was just their policy to use government data — but MapQuest has been standing firm so far.
While Canadians still see ‘Lake Ontario’ on their maps, and international maps users see both names together, the acquiescence of the mapping companies hasn’t gone down well with commenters online. “Beyond ridiculous” and “braindead” are just a couple of the comments left in a Reddit thread on the name change rolled out in Google Maps.
Advertisement
6. IKEA revealed its first smart radiator thermostat
IKEA has introduced the Liljebagge (Image credit: IKEA)
IKEA has made a concerted effort to push out simple, affordable, reliable smart home gear in recent months, and the Liljebagge is the latest in the series to appear. It fastens to your radiator and can be used to control its temperature independently, either through a connected phone app or via the buttons placed on the actual thermostat itself.
With Matter and Thread support, this looks like another appealing gadget from IKEA, though we don’t yet know about international availability and pricing. Hopefully this device goes on sale worldwide before too long — and we’d like to see IKEA continue to compete with the big names in tech when it comes to sensibly priced smart home kit.
Advertisement
Sign up for breaking news, reviews, opinion, top tech deals, and more.
5. We reviewed the Google Pixel 11 Pro
(Image credit: Future/Jason Cipriani)
TechRadar’s Jason Cipriani has spent a week testing out the new Pixel 11 Pro from Google, and he’s ready to share his thoughts: his in-depth review covers the core specs and pricing of the phone, and its design, display quality, performance, software, cameras, and battery life. You’ll be hard pushed to find a more thorough review anywhere else on the web.
You’ll have to click through to get the final verdict, but phrases like “enticing to potential iPhone converts” and “truly magical” (in regard to one specific AI feature) give you an idea of the way the review leans. It’s now been a decade since Google switched the Nexus branding for the Pixel branding, and all of that experience is starting to really show.
Advertisement
4. Sonos exclusively talked to us about its new Ultra products
Sonos CEO Tom Conrad and a pair of Sonos headphones (Image credit: Sonos / Future)
Sonos CEO Tom Conrad is the man in charge of trying to turn the company’s fortunes around after the software debacles of the last couple of years, and he was kind enough to give his time to TechRadar for an exclusive chat about new hardware and a new AI-infused ‘operating system‘ that runs seamlessly across all the products in the Sonos portfolio.
There are new Ace Ultra headphones and a new Beam Ultra soundbar to talk about, and based on early impressions, it seems as though Sonos is getting back to what it does best — making high-end audio equipment that’s as good as anything else you’ll find on the premium market. Find out what Conrad has to say about his first year in charge below.
Advertisement
3. We reviewed Dyson’s ‘game-changing’ toothbrush
Meet the Dyson CameraJet (Image credit: Future / Emily Peck)
Dyson just entered the smart toothbrush category, and it’s not messing about: the Dyson CameraJet offers deep teeth cleaning, liquid flossing, and oral hygiene guidance in a complete package. There’s even a camera on board this toothbrush, so you can get feedback on how well (or otherwise) you’re managing to clear the grime from your mouth.
We’ve already given the Dyson CameraJet toothbrush the in-depth TechRadar review treatment, so we can tell you honestly whether it’s worth your while picking up this (rather expensive) gadget and sticking it in your mouth — read on to find out why we described it as a “a unique and effective solution” for keeping your precious teeth in top shape.
Advertisement
2. We went to IFA 2026 and picked our favorite gadgets
(Image credit: DJI / Agibot / Anker)
There’s always so much great tech to see at the IFA 2026 tech show that takes place every year in Berlin. To help cut through the thousands of brands and products being exhibited to the very best gadgets, we’ve put together a list of our favorite reveals. You’ll find projectors, exoskeletons, e-readers, AI recorders, laptops, tablets, and more listed here.
While a lot of these listed products won’t be available to buy for a month or three, they give us plenty to look forward to for the rest of the year, and act as indicators of where the technology industry is going next. In summary, everything is getting smarter, thinner, and lighter, and there’s never been a better time to be a fan of cutting-edge technology.
1. OpenAI launched GPT-6 Astra and said ‘welcome to the AGI era’
OpenAI CEO Sam Altman (Image credit: Shutterstock/photosince)
OpenAI has announced the new GPT-6 Astra model for ChatGPT, and it comes with a lot of hype attached. According to the company, this is a “significant step forward” for AI, which is now reaching an “extremely capable” stage that apparently can’t be fully understood. At the same time, OpenAI’s president Greg Brockman is saying “welcome to the AGI era”.
Advertisement
AGI is a reference to Artificial General Intelligence, a point at which AI gets smarter than humans and can do just about everything better than we can — although there’s plenty of debate around the definition. Our take? We perhaps need to be more cautious about developing these AI models if it means a high risk of them escaping our control.
Google’s AirDrop-compatible Quick Share feature may finally be reaching some older Pixel devices that were left out of the initial rollout.
As spotted by Android Authority, Pixel 7 and Pixel 8 users have started receiving notifications saying they can now share files with Apple devices through AirDrop. Similar support has also been spotted on the Pixel Tablet, which has so far been absent from Google’s official compatibility list.
The development is especially interesting for the regular Pixel 8. Google previously extended direct AirDrop compatibility down to the Pixel 8a, leaving the older Pixel 7 series and the more expensive Pixel 8 waiting.
Shikhar Mehrotra / Digital Trends
How it works on older Pixel devices
If support is fully enabled, the process should work the same way it does on newer Android phones. Pixel users can open Quick Share, select a file, and send it directly to a nearby iPhone, iPad, or Mac as long as AirDrop is set to “Everyone for 10 Minutes.”
There is no confirmation from Google yet that the Pixel 7, Pixel 8, and Pixel Tablet have officially joined the compatibility list. Some users who received the notification also report that file sharing still does not work, suggesting the feature may be rolling out gradually or depend on another software update to become functional.
Older Android devices already have another way to exchange files with iPhones through Google’s Quick Share QR code system. Direct AirDrop compatibility is still the cleaner option, and these sightings suggest Google may finally be extending it further down the Pixel lineup.
Citing researchers published Friday, Ars Technica writes that AI agents “posted 18,000 messages to a public wiki that discussed ways for other agents to bypass security sandbox restrictions.”
Reuters attributes the discussion to “a swarm of rogue OpenAI agents” that “hijacked a German website this spring and transformed it into a bulletin board for other AI agents, according to new research published Friday and two people familiar with the matter.”
OpenAI officials learned of the incident weeks ago but kept it under wraps as executives grappled with the fallout from the July breach of the open source repository Hugging Face, the people said.
The episode, which began in May and has not previously been reported, underscores growing tension within the AI industry. Companies are racing to build increasingly autonomous agents capable of carrying out complex, valuable tasks, yet evidence is mounting that those systems may also learn to bend rules, exploit loopholes and coordinate with one another in ways developers neither anticipated nor intended. During the Hugging Face breach, OpenAI agents autonomously plotted a digital heist that went undetected for more than a week, intensifying concerns OpenAI is sacrificing safety to push the AI frontier. Its failure to disclose the May incident may revive questions about its oversight…
Advertisement
The German incident reflects a broader pattern of AI activity that some OpenAI investigators wanted to scrutinize more closely. But efforts to widen the probe met resistance from others inside OpenAI, including legal advisers, according to four people familiar with the matter. “Claims that our legal team discouraged investigation of the incident are false,” the OpenAI spokesperson said…
The researchers said public server logs indicated much of the activity originated from Microsoft Azure infrastructure, which OpenAI sometimes uses. They also observed repeated visits to the site by OpenAI employees after the episode, a pattern they said strongly suggested the agents and the company were linked. Messages reviewed by the researchers showed agents plotting ways to evade detection, use tools such as Tor and preserve communications even after they had been shut down. When the site’s moderator began deleting pages in June, the agents responded by creating backup pages to dodge the cleanup.
Reuters got this reaction from Maurice Chiodo, an academic at Cambridge University’s Centre for the Study of Existential Risk. “The episode, he said, should reinforce growing concerns that the greatest threat from advanced AI may not be a single superintelligent system, but ‘vast colluding swarms of semi-intelligent AI.’”
Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities.
The exploited security issue, identified as CVE-2026-85046, is described as a type confusion. It was reported to Google by researcher Salvatore Gulizia, known online as “Serotav.”
The update brings Chrome to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, as part of a gradual rollout..
“Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the advisory reads.
Advertisement
The company did not disclose any technical or specific exploitation details about the flaw to give users and dependent projects time to apply the fix.
Type confusion flaws cause software to misinterpret one type of object as another, allowing attackers to corrupt memory.
V8 is Chrome’s open-source JavaScript and WebAssembly engine, which compiles and executes code used by websites.
Hence, CVE-2026-85046 could potentially be triggered by a specially crafted HTML page containing malicious JavaScript, potentially allowing remote code execution within Chrome’s sandboxed renderer process.
Advertisement
The update also addresses nine other high-severity vulnerabilities, including use-after-free and out-of-bounds memory flaws in Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools, Skia, and a race condition in V8.
CVE-2026-85046 is the sixth actively exploited bug Google has fixed in Chrome since the start of the year. Previous fixes include:
An out-of-bounds read and write vulnerability in Chrome’s V8 JavaScript engine (CVE-2026-11645), exploited in the wild and patched in June.
An iterator invalidation vulnerability (CVE-2026-2441) in CSSFontFeatureValuesMap, Chrome’s implementation of CSS font feature values, fixed in mid-February.
Two additional Chrome zero-days exploited in March attacks: an out-of-bounds write flaw in the Skia 2D graphics library (CVE-2026-3909) and an inappropriate implementation issue in the V8 JavaScript and WebAssembly engine (CVE-2026-3910).
A use-after-free vulnerability in Dawn (CVE-2026-5281), the cross-platform implementation of the WebGPU standard used by Chromium, was patched in April.
Chrome users are recommended to apply the available update as soon as the rollout reaches them by going to Settings > About Chrome and waiting for the update to download and install.
After the update process is done, a browser restart is required for the fixes to apply.
A similar action is recommended for users of Chrome-based browsers, including Microsoft Edge, Brave, Opera, and Vivaldi, though it may take a couple of extra days for fixes to arrive on those apps.
Advertisement
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
You must be logged in to post a comment Login