Connect with us

Tech

3 limited series on Hulu you can binge-watch this weekend (August 7-9)

Published

on

Wondering what to watch this weekend but too lazy to dig around? No worries, I have rounded up three hidden gems you can binge-watch in a single weekend. There is a technothriller stuffed with cold-case flashbacks, a tense two-hander that unfolds almost entirely inside a basement, carried by sharp dialogue, and a divorce story that turns messier and more human with every episode. I recommend these three limited series on Hulu for their unexpected plot twists and stellar performances.

We also have guides to the best new movies to stream, the best movies on Netflix, the best movies on Hulu, the best free movies, and the best movies on Amazon Prime Video.

A Murder at the End of the World (2023)

Genre: Mystery, thriller, drama
IMDb: 7.0/10
Rotten Tomatoes: 89%

Advertisement

Darby Hart (Emma Corrin), an amateur sleuth and hacker, is invited to a secluded Arctic retreat hosted by a reclusive tech billionaire (Clive Owen). When one of the other guests turns up dead, Darby has to use her investigative skills to prove it was murder before the killer strikes again. The show splits its time between the present-day retreat and flashbacks to an earlier road trip Darby took with a fellow hacker, layering a cold-case mystery underneath the main one.

Beneath the whodunit setup, this underrated TV show is really about isolation, technology, and how much control we have handed over to people who never asked for our trust. Emma Corrin plays Darby with a sharp, guarded intelligence that makes her easy to root for even when she is the only person who suspects anything is wrong. Clive Owen plays the tech mogul with a quiet menace that keeps you questioning his real motives. It’s a slow burn that rewards patience, especially once the final twist comes into focus.

You can watch A Murder at the End of the World on Hulu.

The Patient (2022)

Genre: Psychological thriller, drama
IMDb: 7/10
Rotten Tomatoes: 89%

Advertisement

Therapist Alan Strauss (Steve Carell) gets kidnapped and held captive in a basement by his own patient, Sam (Domhnall Gleeson). Sam turns out to be a serial killer who wants Alan’s help to suppress his urge to kill again. Trapped on a chain, Alan must navigate his captor’s twisted mind while confronting his own family trauma. This underrated show on Hulu displays much of the tension through dialogue, since Alan spends most of the series chained up in a single room with almost no physical way to fight back.

Steve Carell delivers a phenomenal performance that relies on micro-expressions and quiet vulnerability. I really liked how he stripped away every trace of his usual comedic energy to create an uncomfortable atmosphere that grips you instantly. Meanwhile, Domhnall Gleeson matches him scene for scene, making his character feel disturbingly human rather than a typical movie villain. If you enjoy high-stakes, nerve-wracking stage play, this limited TV series is for you.

You can watch The Patient on Hulu.

Advertisement

Fleishman Is in Trouble (2022)

Genre: Drama, comedy
IMDb: 7.7/10
Rotten Tomatoes: 87%

Toby Fleishman (Jesse Eisenberg), a recently divorced doctor, is finally enjoying success on dating apps when his ex-wife Rachel (Claire Danes) vanishes without warning, leaving him to care for their two kids alone. As Toby scrambles to find her, the show slowly peels back both sides of their marriage, revealing a much messier and more sympathetic picture than either of them originally let on. What starts as a story about one man’s midlife reinvention also sheds light on ambition, resentment, and how differently two people can remember the same relationship.

I enjoyed how this show makes its characters unlikable before earning your sympathy for them. Jesse Eisenberg brings a jittery, self-absorbed energy to Toby, and Claire Danes delivers one of the show’s best performances in a late-series episode that changes everything you thought you understood about Rachel. I admit the show takes a bit of patience early on, but the payoff is worth it.

Advertisement

You can watch Fleishman Is in Trouble on Hulu.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

TP-Link Roam 7 travel router review

Published

on

Why you can trust TechRadar


We spend hours testing every product or service we review, so you can be sure you’re buying the best. Find out more about how we test.

TP-Link Roam 7: 30-second review

The TP-Link Roam 7 is a compact travel router that lets you connect to whatever internet you can find and turns that into your own private network. This helps reduce the need to reconnect all your devices in each new location; just connect the router and all other devices will connect automatically through it.

The Roam 7 differs from a mobile router insofar as there’s no internal SIM or battery; power is supplied through a USB source such as a power bank, and the internet connection comes from a range of available options, including Ethernet at a hotel or business, public Wi-Fi, your phone tethered or a USB modem.

Advertisement

Source link

Continue Reading

Tech

Cloudflare says humans could become a “rounding error” as bots generate 1,000 times more internet traffic

Published

on

Crystal ball: Just a couple of months after Cloudflare revealed that bots have officially surpassed human traffic online, the company has given its view on what things will look like in five years. It’s not good news for us fleshy meatsacks: non-human traffic could be up to 1,000 times higher than human traffic.

CDN and cybersecurity giant Cloudflare held its Q2 earnings call on Thursday, during which chief financial officer Thomas Seifert gave a concerning prediction about what the web will look like in the future.

“If the current trends continue, we think in five years, non-human traffic will be as much as 1,000 times as much as human traffic,” he said.

“In other words, humans will be a rounding error on the internet, not because human traffic goes down, but that’s just how fast we’re seeing non-human traffic grow.”

Advertisement

Seifert did add the important caveat that his predictions have been wrong in the past. Cloudflare CEO and co-founder Matthew Prince will likely be able to relate to this. He had predicted that bot traffic would surpass humans at the end of 2027, but it happened earlier this year.

Also read: The Zero Click Internet

It goes without saying that the sudden acceleration in non-human traffic is being driven by AI – agentic AI, specifically. Agentic systems behave very differently from traditional web crawlers and fraud bots. Their activity can closely resemble ordinary browsing, but it happens at machine speed and can be repeated on an enormous scale.

Advertisement

Even a straightforward prompt may trigger thousands of requests. Prince illustrated the difference using online shopping: someone searching for a camera might check five retailers, while an AI agent could examine 5,000 sites on their behalf. Multiply that behavior across millions of users asking assistants to compare products and airfares, research topics, collect information, or condense articles, and you can see why Seifert believes humanity’s online presence will become a rounding error.

Seifert said that if traffic does grow the way he expects, “we’ve got to get a lot more efficient,” which is where Cloudflare’s services come in, of course. He also mentioned the security implications of a web made up pretty much entirely of bots.

The idea that Dead Internet Theory – the concept that the internet is mostly run by bots and AI – will be demonstrably true in a few years (or now, arguably) is a concerning one. For a start, it could see the end of independent sites that have relied on the web’s business model since the 1990s.

There’s also the fact that an internet full of bots, AI slop, and privacy risks is making more people pull away from the online world. In our poll, 97% of people said the internet today was a hellscape compared to its early days, and it looks like things are only going to get worse.

Advertisement

Source link

Continue Reading

Tech

Google Should Still Be Forced To Shed Chrome, Advocacy Group Argues

Published

on

“Google should be required to divest the Chrome browser, and prohibited from paying Apple to distribute Google’s search engine, the nonprofit advocacy group Public Knowledge argues in a new court filing,” MediaPost reports, citing a friend-of-the-court brief filed Tuesday in the D.C. Circuit Court of Appeals:

The group adds that “independent ownership” of Chrome “would open the distribution channel Google controls and allow Chrome to serve browser users when it makes privacy decisions and determines how to integrate search and (artificial intelligence)…”

In September 2025, [U.S. District Court Judge] Mehta issued a remedies order that requires Google to share some data about users’ searches with “qualified” competitors and to provide syndicated search results and ads to those competitors. The order also prohibits Google from entering into exclusive distribution contracts for Google Search, Chrome, Google Assistant and the Gemini app for six years, but allows the company to continue to make payments for search-ad revenue or distribution to Apple, Mozilla and others…
Google recently appealed Mehta’s order. The company argued in its written brief that it “prevailed in the marketplace fair and square,” adding that Apple and Mozilla “sensibly chose” Google as the default search engine “because it gave their users the best experience,” and because Apple and Mozilla would earn the most ad revenue through the deals. The [U.S.] Justice Department and states countered to the appellate court last week that the liability finding should stand, and also argued that Google should have been banned from paying Apple and Mozilla for placement as the default search engine on their browsers.

[Antitrust enforcers had originally asked the judge to order Google to divest Chrome, but he’s already rejected that request.] The government did not argue in its appellate papers that Google should be forced to sell Chrome. But Public Knowledge independently contends in its friend-of-the-court brief that divestiture would benefit consumers… “Divestiture would place those decisions with an institution whose success depends on serving browser users primarily….” The group is calling the appellate court’s attention to Google’s April 2025 decision to preserve tracking cookies — a reversal from its earlier plans to block third-party cookies by default. “Google is in the position of both deciding Chrome’s tracking rules while running the advertising business affected by them,” Public Knowledge writes. “An independent Chrome could make those decisions on behalf of users alone.”

Advertisement

But Firefox developer Mozilla filed its own friend-of-the-court brief Thursday warning Firefox could be forced to “exit the browser and browser engine markets” if it can’t receive payment from Google for distributing its search engine, according to a later report from MediaPost:

Federal and state antitrust enforcers recently asked the appellate court to reverse the portion of Mehta’s order that allows those payments to continue. But Mozilla counters in its new friend-of-the-court brief that Mehta’s decision regarding those payments was supported by the evidence –including a study it conducted concluding that its revenue would “decline dramatically” if forced to replace Google with Bing as Firefox’s default search engine…

Google is expected to file new arguments with the appellate court next month.

Read more of this story at Slashdot.

Advertisement

Source link

Continue Reading

Tech

Qwen 3.8-Max and Claude Opus 5 show why raw benchmark scores don’t predict the bill

Published

on

Alibaba released Qwen 3.8-Max this week and marketed the preview as second only to Claude Fable 5 (their launch-day table was more equivocal: the model leads on one of 12 coding-agent rows). But an independent harness came close to the opposite conclusion: a benchmark run, apparently using the Preview version, put Qwen 3.8-Max’s best effort setting mid-pack, and its default setting last.

Both results are real and defensible. The gap between them is about token and time budgets, and that matters because those figures aren’t usually headline numbers. Alibaba’s footnotes give its coding numbers a five-hour timeout, and up to 12 hours per run on PaperBench. The independent harness, VulcanBench, allowed between 45 and 60 minutes of wall clock time. A time budget between five and 16 times larger on Alibaba’s side explains the huge difference in results.

It’s time to do two things to start accounting for these differences when choosing models. First, the metric to use is cost per successful task: total spend, including everything you spent on attempts that failed, divided by the tasks that actually passed your acceptance check. Second, you need to make time or token budgets an explicit part of your acceptance criteria, not a hidden detail.

Price per token has stopped predicting the bill

The comparison everyone published in Qwen 3.8-Max’s first week was a price comparison, because that was the only data available. It is not a cheap model. DeepSeek-V4-Flash-0731, which entered public API beta on July 31, lists at 14 cents per million input tokens and 28 cents output. Qwen 3.8-Max lists at $2 and $6. Kimi K3 sits at $3 and $15.

Advertisement

Those prices tell you less than they used to, for a reason specific to reasoning models like Qwen: getting to a result costs thinking tokens. A model that spends most of its token allowance on reasoning can reach a token cap before it writes the answer, giving you an empty result indistinguishable from a total failure at the cost of a full run.

Artificial Analysis has the cleanest published measurement of how this can affect real agent spend: running its Intelligence Index on DeepSeek-V4-Flash at maximum effort took 210 million output tokens against a class median of 100 million. Absolute cost stayed low anyway, because the tokens were so cheap. But verbosity costs time, not just money, and depending on your use case that can sink you.

What you need is a number that counts everything you spent, including the attempts that came back empty, against the tasks that actually got done in the time and token budget you specified. This is what a cost-per-success metric helps you see.

Your failure rate is partly a configuration setting

A run that produces a wrong answer and a run that runs out of budget are different events with different fixes. Almost no harness distinguishes them, and almost no leaderboard reports the split. I hit this building an agent benchmark of my own: the harness logged a failure and nothing about why, and I had to add the distinction myself. When you do separate them, budget exhaustion turns out to dominate.

Advertisement

Long-Horizon-Terminal-Bench, published in July, ran 17 frontier models across 46 tasks through a shared harness with one 90-minute attempt each. Timeouts accounted for 79% of unresolved runs, against 19% for agents that stopped on their own and 3% for harness errors. The authors are careful about what that does and does not mean: the timed-out runs were not close to finishing, with mean reward between 0.10 and 0.35, so you cannot assume more time would have resulted in success. But the lesson is: benchmarks are implicitly measuring time efficiency, whether or not they shout about that.

The clearest published example of the mechanism comes from VulcanBench, the same open-source harness behind the Qwen chart. In a report dated July 26, Claude Opus 5’s lowest-effort setting was its best, solving 20 of 23 tasks against 18 at high effort. The extra reasoning wasn’t useless: high effort returned the fewest wrong answers of any setting, one against three. It ran out of clock instead, and a timeout scores zero. Two of its three regressions were cutoffs on tasks that low effort solves, and given unlimited time on both it only ties its cheapest setting, at 3.1 times the cost.

That has a direct consequence for anyone building a routing ladder. The standard design escalates to more reasoning when a cheap attempt fails, on the assumption that the next rung is better and merely costs more. For a meaningful share of model and task combinations that assumption is wrong, and you pay the higher rung’s price to escalate into a timeout or hitting a cap.

Who is already measuring this

Several groups have landed on cost per successful task independently in the last few months, which is the strongest signal it’s becoming standard.

Advertisement

VulcanBench reports dollars per solved task as a headline column and has since its earliest reports. Long-Horizon-Terminal-Bench publishes per-task cost next to accuracy, and its most instructive row is GPT-5.4 at roughly $26 per task with a much lower pass rate than Grok 4.5 at about $11. TestEvo-Bench runs agents under a cost cap, and Claude Code’s test-generation score falls from 71% to 44% at the tighter cap.

Vendors are already on board with the idea of measuring per successful task. HubSpot moved its Breeze Customer Agent in April to 50 cents per resolved conversation, down from $1 per handled conversation. Zendesk bills per automated resolution. Fin charges 99 cents per outcome and bills only on end-to-end resolution.

What to change this week

  • Emit a failure reason on every agent run as a required field, with budget exhaustion, verifier failure and harness error as distinct values rather than one failure flag. Until you can separate a timeout from a wrong answer, your pass rate is measuring two things at once and you cannot tell which one to fix.

  • Compute cost per successful task per effort level, not just per model. Total spend including failed attempts, divided by tasks that passed your acceptance check. The ranking will not match the rate card, and the cheapest setting may well win.

  • Cap on tokens rather than wall clock unless latency is genuinely in your service level objective. A wall-clock cap scores your provider’s serving speed as model quality.

  • Check the default effort setting on everything you have deployed. Qwen 3.8-Max runs at its highest reasoning setting when the effort field is unset, and its highest setting was its worst performer in independent testing. A team that never touches that parameter is running the configuration that costs the most per solved task.

Source link

Advertisement
Continue Reading

Tech

How To Get The Best Battery Life From Your Retro Handheld Game Console

Published

on

If your vintage gaming system eats through batteries in a hurry, this is for you.

Old-school gaming handhelds can be battery hogs. Whether it’s the original Game Boy’s four AA batteries or the Game Gear’s six, they tear through cells at a rate that makes modern consoles feel like luxuries. Here’s the easiest way to boost your battery setup on your old Nintendo, Sega or Atari portable.

For this guide, we’re focusing on the most popular battery-powered handhelds from the late ’80s through the early 2000s. Those would be Nintendo’s original Game Boy, Game Boy Color, Game Boy Pocket and Game Boy Advance, plus Sega’s Game Gear and the Atari Lynx.

Advertisement

The bottom line? Modern rechargeable batteries smooth much of the friction out of these retro handhelds. They save money, cut environmental waste and let you avoid the headaches that go along with disposable alkalines.

The right rechargeable batteries

For most people, a set of nickel-metal hydride (NiMH) rechargeable batteries is the way to go. They’re reliable, reusable and much cheaper over time than disposable alkalines.

Panasonic Eneloop is an Engadget staff favorite. It’s consistent and tends to hold up over time better than cheaper options. If you want to save a few bucks, IKEA LADDA is a good budget alternative. (Some have speculated that they’re rebranded Eneloops, but that isn’t confirmed.) Both are sold in the AA and AAA sizes you need for these systems.

Advertisement
  • Game Boy – 4 × AA
  • Game Boy Color – 2 × AA
  • Game Boy Pocket – 2 × AAA
  • Game Boy Advance – 2 × AA
  • Game Gear – 6 × AA
  • Atari Lynx – 6 × AA

Just keep in mind that the system’s battery indicators don’t always behave the same way with rechargeables. If the low-battery warning comes on, you may want to get in the habit of quickly saving your game to be safe.

As for how many batteries you need, a good rule of thumb is to buy two full sets. That way, you always have one in the handheld with another charged and ready to go.

One possible exception is modded retro handhelds, since things like brighter screens can run through batteries faster than the stock hardware. In that case, a third set could be in order. Some power-hungry or voltage-sensitive mods might work better with 1.5V rechargeable lithium batteries, although they tend to cost more than standard NiMH cells.

Advertisement

USB-C battery mods

Some models, including the original Game Boy, can be modded with USB-C rechargeable battery pack kits. These make the handheld feel more like a modern system, removing the annoyance of battery swaps. Some work with USB-C power banks, although not all support charge-and-play.

There are a few risks and downsides. For example, some USB-C battery mods don’t fully isolate the battery while charging. This can generate extra heat and make it less safe to play while charging. So, it’s worth checking user feedback and sticking with well-regarded mods if you go that route.

Source link

Advertisement
Continue Reading

Tech

RingConn Gen 3 review | TechRadar

Published

on

Why you can trust TechRadar


We spend hours testing every product or service we review, so you can be sure you’re buying the best. Find out more about how we test.

RingConn Gen 3: One minute review

RingConn has always been a solid challenger to Oura in the smart ring space, and after spending two weeks testing it, I can safely say the new RingConn Gen 3 continues that trend. You’ll get most of the same health, sleep and recovery tracking features as rivals in our best smart rings guide here, but without the monthly subscription that puts some people off buying a smart ring altogether.

The Gen 3 tracks heart rate, heart rate variability (HRV), blood oxygen levels, skin temperature, respiratory rate, stress, activity and sleep. New additions include a haptic motor for some alerts and reminders, improved battery life and new vascular health trend insights, which are designed to give you a picture of your cardiovascular wellbeing over time.

Advertisement

Source link

Continue Reading

Tech

Apple continues to dominate premium smartphone market share

Published

on

For smartphones selling at over $600, Apple owns 65% of that market and grew 9% year over year in the first half of 2026. However, Chinese brands are making a dent in local market share.

Apple ships 23% of all smartphones sold globally and captures 49% of all profit. It’s a behemoth on its own, but when accounting for smartphones in the $600 plus range, it’s the clear leader in market share.

According to a report from Counterpoint Research, Apple captured 65% of the global premium smartphone market. It grew 9% year over year during the first half of 2026, though its market share is still down when compared to the 74% held in 2022.

The decline since 2022 can be attributed to the premium Chinese smartphone market growing in popularity. When a Chinese consumer is presented with an option between an iPhone and a smartphone from Huawei, Xiaomi, or Oppo, they choose the local brand.

Advertisement

That said, Apple still holds most of the market globally at 65% and Samsung at 19%. The other OEMs make up the remaining 16%.

Bar chart comparing premium smartphone market share: Apple dominates around two-thirds, Samsung about one-fifth, others under one-fifth across H1 2022, H1 2025, H1 2026, with overall premium share gradually increasing.

Apple holds onto 65% of premium market share even as the rest of the market increases prices. Image source: Counterpoint

The premium smartphone market grew 5% overall year over year for the first half of 2026 and makes up a record 29% of the global market. The global RAM shortage driving up prices has pushed more smartphones into the premium $600 plus segment and price hikes on lower-end models are driving customers to more premium models.

The report suggests these trends are why smartphone manufacturers are leaning further into financing options. Samsung recently launched its Galaxy Card while Apple has introduced Apple Upgrade.

Advertisement

Trade-in prices have also gone up, as was seen with Apple earlier Thursday. Everything is meant to entice customers holding onto their more expensive devices for longer to upgrade sooner in spite of price increases.

It’s going to be an interesting fall as everything seems to be creating quite the hurdle for Apple to overcome. iPhone 18 Pro sales could be limited by the RAM shortage and Apple reports that it’s already selling as many iPhone 17 models as it can make.

Demand won’t be the issue, but supply held back by global supply chain instability. Consumers may be feeling the impact of economic uncertainty, but that may not matter if financing options continue to be plentiful.

Advertisement

Source link

Continue Reading

Tech

What Are The 5 Ps For Pilots And Why Are They So Important?

Published

on





Safely piloting an aircraft requires training, skills, and experience. Take the 1500-hour rule for pilots for example, which requires those seeking to be licensed in airline transport to achieve a certain number of hours performing flights in different scenarios, totaling 1,500 hours. Even then, there’s still a number of factors to keep in mind, especially when you’re the sole aviator behind the controls. It’s for this reason, practices like the 5 P checklist are recommended as part of a successful single-pilot crew resource management (SRM) system.

The 5 P checklist is comprised of plan, plane, pilot, passengers and programming. Each one of these categories exist in order to help manage the level of risk for each flight. While on its face, the 5 P checklist seems fairly self-explanatory, going through each one helps to provide a thorough means of preparation and readiness. This isn’t something reserved for new pilots either, as repetitious checklists help even seasoned aviators ensure they’ve covered everything. 

Advertisement

Each part of the 5 P checklist explained

There should always be a plan in place, which takes into account specific aspects of the trip. Some things to consider include whether the destination airport has any of the runways shut down, alternate airports should a problem arise, current weather conditions, and contingencies in the event of an emergency.

Of course, the plane itself should also be subject to evaluation. Pilot’s must go through pre-flight checklists and consider the aircraft’s limitations versus the flight requirements. Double check that the plane is configured properly, such as the distribution of weight, which affects the aircraft’s center of gravity.

Pilots should be evaluating themselves as well, to ensure they aren’t contributing to risks. For example, a pilot’s health, mental state, and experience are crucial components of a safe journey. If a pilot has the flu, is highly fatigued or lacks specific knowledge relating to the flight, they can actively reduce the level of safety.

Advertisement

A pilot also can’t neglect their passengers, as this can lead to problems in the air. Explaining things like emergency procedures beforehand and what to anticipate during the flight can help limit risk and reduce stress in the passengers.

The last entry of the 5 P checklist is programming, which reminds a pilot to verify things like their route and navigation points in their GPS system. GPS is just one aspect of how pilots see at night, so it’s critical to verify the system is functioning properly.

Advertisement

The 5 P checklist is used throughout the flight

The 5 P checklist is something that’s employed not only before the flight, but throughout it as well. There are several different phases of a flight, and each one presents its own set of potential risks. Therefore, a pilot must reevaluate during each one of these phases, making choices to help reduce hazards and enhance safety.

These phases of a flight consist of pre-take off, navigating to the runway (taxiing), the plane lifting off the runway, gaining altitude, reaching cruising height for level flight, descending, and finally landing. During these phases some aviators employ procedures based off of FAA guidelines, like the 30/70 rule, which can make takeoffs safer.

Pilots don’t only rely on the 5 P checklist but also combines it with others like the PAVE checklist, which stands for the pilot in command, the aircraft, the environment, and any external pressures. So, if as a passenger you’ve ever wondered what the pilot is up to before and during a flight, it’s likely they’re running through some of these checklists among other responsibilities.

Advertisement



Source link

Advertisement
Continue Reading

Tech

ShinyHunters called cancer diagnostics biz and tricked staffers into giving them access. Now they’ve dumped 10.9M email addresses

Published

on

CYBER-CRIME

Cancer diagnostics breach spills personal and health info as extortion crew says healthcare giant ‘should’ve paid the ransom’

Hackers have dumped data stolen from Abbott’s cancer diagnostics business after the healthcare giant apparently declined to pay up, with the leak containing 10.9 million unique email addresses alongside personal and health information.

Have I Been Pwned added the Exact Sciences breach to its database on Friday after data stolen by the ShinyHunters extortion crew was published online. The leak includes names, email and physical addresses, phone numbers, dates of birth, genders, and personal health information belonging to customers, patients, and healthcare providers.

Advertisement

Abbott, which acquired cancer diagnostics outfit Exact Sciences earlier this year, first disclosed the break-in on July 16. In an update on August 5, it acknowledged that some of the files accessed contained personal information and/or personal health information, but said it was still analyzing the data and had yet to determine who needed to be notified.

The company also revealed that the intrusion began with a vishing attack, and stressed that this was “not an encryption malware event.” It said only a limited number of internal systems within its cancer diagnostics business were affected, with no disruption to products, manufacturing, laboratory operations, or patient services.

ShinyHunters has a rather different way of describing what happened. On its dark web leak site, seen by The Register, the extortion crew told Abbott it “should’ve paid the ransom” and claimed the company had failed to reach an agreement despite being given multiple chances to do so.

The crooks claim that they made off with more than 30 million rows of customer information, including more than one million Social Security numbers and 7.5 million dates of birth. More concerning are claims that the haul includes 22 million-plus rows of client notes containing confidential doctor-patient conversations and health information, as well as more than 20 million medical-order records containing patient IDs, prescription types, order dates, and refill information.

Advertisement

ShinyHunters also claims to have siphoned more than 425 million rows of assorted data from Databricks, 130,000 files from SharePoint, and 89,000 contracts from Coupa, though those figures have not been independently verified.

Abbott has not said how the vishing attack led to the theft of the data, how long the intruders had access to its systems, or whether it received an extortion demand. Its latest update says the investigation remains ongoing and that affected individuals will be notified where required.

For those caught up in the breach, however, that review may come a little late. Whatever number Abbott eventually puts on the incident, a sizeable chunk of the stolen data is already in the wild. ®

Source link

Advertisement
Continue Reading

Tech

Google’s top hacker hunter explains why hacking groups get codenames

Published

on

For more than a decade, the cybersecurity industry has been assigning names to different hacking groups. Some of them, like Fancy Bear, have crossed over into the mainstream because of their prominent hacks and memorable names. Others are only known within the cybersecurity industry. 

Oftentimes, even industry insiders can’t keep track. In part, that’s because every company names hacking groups differently. That’s why there are resources like this one, which attempt to be a one-stop shop where cybersecurity professionals, government officials, policymakers, journalists, and the wider public can make sense of who is who. 

Last month, Google became the latest company to revamp its naming system for hacking groups.

Gone are the days APT1, APT41 or APT whatever number, which was the system adopted by Mandiant, once an independent security firm that’s now part of Google. Mandiant was the first to adopt a naming scheme.

Advertisement

From now on, Google’s system is relatively simple: A hacking group will have a first name that is memorable and random, and a second word whose initial indicates the country of origin: Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia.

According to Shane Huntley, the chief technology officer of Google Threat Intelligence Group, the company’s in-house hacker hunting team, the revamp was necessary to bring clarity to security researchers both inside the company and externally. 

In the early 2010s, when companies started publishing reports on cyberattacks and naming the hackers behind them, Huntley told TechCrunch that, “we were not expecting to have as many threat groups as we do today.”

It had become hard to keep track of everyone. Google now tracks more than 5,000 “activity clusters” in several countries, according to John Hultquist, chief analyst at Google Threat Intelligence Group. Huntley said that there are very few developed nations that don’t have their own cyber capabilities and hacking groups. 

Advertisement

But what is the point of naming hacking groups? It’s not just an academic exercise, Huntley explained. The goal is to have a baseline understanding of who is attacking who, and how they are attacking them. That way organizations can recognize threats more quickly, prepare against them, ideally stop them, or at least investigate incidents more promptly. 

All that, he said, it’s possible only if you name the hackers and track them consistently. 

“If you actually get hacked by them or you’re dealing with some incident, knowing how that actor behaves, what they do, what they’ve done in the past, all of these details become critically important to help the response and also work out your coverage against these threats as well,” said Huntley.

Knowing how the North Korean government hackers known as the Lazarus Group behaves, what their goals usually are, and who they work for, gives defenders a starting point in dealing with these hackers. 

Advertisement

Tracking state-sponsored hackers, while challenging, is easier than tracking cybercriminal groups and hackers-for-hire, Huntley explained. The government hackers tend to have more consistent targets and activities, while cybercriminal groups have members that come and go, sometimes splinter, and otherwise are more amorphous. Hacker-for-hire groups and spyware makers tend to have a lot of customers in different parts of the world, making them slightly harder to track. 

A common criticism whenever a new naming system gets announced is: Why don’t all companies and organizations just use the same codenames? While that seems like an easy question to answer, the reality is that every company has a slightly different view of every group, based on their own sets of data and telemetry. Huntely said this is an inescapable reality that can’t be avoided just by sharing more information among companies and groups of researchers. 

“No one has perfect visibility,” he said. “We are building our model and our best understanding, but we will never know everything about what’s going on.”

By unifying the naming scheme of Google’s old Threat Analysis Group, which Huntely headed, and Mandiant, at least now there’s one fewer scheme to remember. For everything else, refer to this gargantuan list.

Advertisement

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Source link

Continue Reading

Trending

Copyright © 2025