Connect with us
DAPA Banner
DAPA Coin
DAPA
COIN PAYMENT ASSET
PRIVACY · BLOCKDAG · HOMOMORPHIC ENCRYPTION · RUST
ElGamal Encrypted MINE DAPA
🚫 GENESIS SOLD OUT
DAPAPAY COMING

Tech

5,000 vibe-coded apps just proved shadow AI is the new S3 bucket crisis

Published

on

Most enterprise security programs were built to protect servers, endpoints, and cloud accounts. None of them was built to find a customer intake form that a product manager vibe coded on Lovable over a weekend, connected to a live Supabase database, and deployed on a public URL indexed by Google. That gap now has a price tag.

New research from Israeli cybersecurity firm RedAccess quantifies the scale. The firm discovered 380,000 publicly accessible assets, including applications, databases, and related infrastructure, built with vibe coding tools from Lovable, Base44, and Replit, as well as deployment platform Netlify. Roughly 5,000 of those assets, about 1.3%, contained sensitive corporate information. CEO Dor Zvi said his team found the exposure while researching shadow AI for customers. Axios independently verified multiple exposed apps, and Wired confirmed the findings separately.

Among the verified exposures: a shipping company app detailed which vessels were expected at which ports. An internal health company application listed active clinical trials across the U.K. Full, unredacted customer service conversations for a British cabinet supplier sat on the open web. Internal financial information for a Brazilian bank was accessible to anyone who found the URL.

The exposed data also included patient conversations at a children’s long-term care facility, hospital doctor-patient summaries, incident response records at a security company, and ad purchasing strategies. Depending on jurisdiction and the data involved, the healthcare and financial exposures may trigger regulatory obligations under HIPAA, UK GDPR, or Brazil’s LGPD.

Advertisement

RedAccess found phishing sites built on Lovable that impersonated Bank of America, FedEx, Trader Joe’s, and McDonald’s. Lovable said it had begun investigating and removing the phishing sites.

The defaults are the problem

Privacy settings on several vibe coding platforms make apps publicly accessible unless users manually switch them to private. Many of these applications get indexed by Google and other search engines. Anyone can stumble across them. Zvi put it plainly: “I don’t think it’s feasible to educate the whole world around security. My mother is [vibe coding] with Lovable, and no offense, but I don’t think she will think about role-based access.”

This is not an isolated finding

In October 2025, Escape.tech scanned 5,600 publicly available vibe-coded applications and found more than 2,000 high-impact vulnerabilities, over 400 exposed secrets including API keys and access tokens, and 175 instances of personal data exposure containing medical records and bank account numbers. Every vulnerability Escape found was in a live production system, discoverable within hours. The full report documents the methodology. Escape separately raised an $18 million Series A led by Balderton in March 2026, citing the security gap opened by AI-generated code as a core market thesis.

Gartner’s “Predicts 2026” report forecasts that by 2028, prompt-to-app approaches adopted by citizen developers will increase software defects by 2,500%. Gartner identifies a new class of defect where AI generates code that is syntactically correct but lacks awareness of broader system architecture and nuanced business rules. The remediation costs for these deep contextual bugs will consume budgets previously allocated to innovation.

Advertisement

Shadow AI is the multiplier

IBM’s 2025 Cost of a Data Breach Report found that 20% of organizations experienced breaches linked to shadow AI. Those incidents added $670,000 to the average breach cost, pushing the shadow AI breach average to $4.63 million. Among organizations that reported AI-related breaches, 97% lacked proper access controls. And 63% of breached organizations had no AI governance policy in place.

Shadow AI breaches disproportionately exposed customer personally identifiable information at 65%, compared to 53% across all breaches, and affected data distributed across multiple environments 62% of the time. Only 34% of organizations with AI governance policies performed regular audits for unsanctioned AI tools. VentureBeat’s shadow AI research estimated that actively used shadow apps could more than double by mid-2026. Cyberhaven data found 73.8% of ChatGPT workplace accounts in enterprise environments were unauthorized.

What to do first

The audit framework below gives CISOs a starting point for triaging vibe-coded app risk across five domains.

Domain

Advertisement

Current State (Most Orgs)

Target State

First Action

Discovery

Advertisement

No visibility into vibe-coded apps

Automated scanning of vibe coding platform domains

Run DNS + certificate transparency scan for Lovable, Replit, Base44, and Netlify subdomains tied to corporate assets

Authentication

Advertisement

Platform defaults (public by default)

SSO/SAML integration required before deployment

Block unauthenticated apps from accessing internal data sources

Code scanning

Advertisement

Zero coverage for citizen-built apps

Mandatory SAST/DAST before production

Extend the existing AppSec pipeline to cover vibe-coded deployments

Data loss prevention

Advertisement

No DLP coverage for vibe coding domains

DLP policies covering Lovable, Replit, Base44, Netlify

Add vibe coding platform domains to existing DLP rules

Governance

Advertisement

No AI usage policy or shadow AI detection

AI governance policy with regular audits for unsanctioned tools

Publish an acceptable-use policy for AI coding tools with a pre-deployment review gate

The CISO who treats this as a policy problem will write a memo. The CISO who treats this as an architecture problem will deploy discovery scanning across the four largest vibe coding domains, require pre-deployment security review, extend the existing AppSec pipeline to citizen-built apps, and add those domains to DLP rules before the next board meeting. One of those CISOs avoids the next headline.

Advertisement

The vibe coding exposure RedAccess documented is not a separate problem from shadow AI. It is shadow AI’s production layer. Employees build internal tools on platforms that default to public, skip authentication, and never appear on any asset inventory, which means the applications stay invisible to security teams until a breach surfaces or a reporter finds them first. Traditional asset discovery tools were designed to find servers, containers, and cloud instances. They have no way to find a marketing configurator that a product manager built on Lovable over a weekend, connected to a Supabase database holding live customer records, and shared with three external contractors through a public URL that Google indexed within hours.

The detection challenge runs deeper than most security teams realize. Vibe-coded apps deploy on platform subdomains that rotate frequently and often sit behind CDN layers that mask origin infrastructure. Organizations running mature, secure web gateways, CASB, or DNS logging can detect employee access to these domains. But detecting access is not the same as inventorying what was deployed, what data it holds, or whether it requires authentication. Without explicit monitoring of the major vibe coding platforms, the apps themselves generate a limited signal in conventional SIEM or endpoint telemetry. They exist in a gap between network visibility and application inventory that most security stacks were never architected to cover.

The platform responses tell the story

Replit CEO Amjad Masad said RedAccess gave his company only 24 hours before going to the press. Base44 (via Wix) and Lovable both said RedAccess did not include the URLs or technical specifics needed to verify the findings. None of the platforms denied that the exposed applications existed.

Wiz Research separately discovered in July 2025 that Base44 contained a platform-wide authentication bypass. Exposed API endpoints allowed anyone to create a verified account on private apps using nothing more than a publicly visible app_id. The flaw meant that showing up to a locked building and shouting a room number was enough to get the doors open. Wix fixed the vulnerability within 24 hours after Wiz reported it, but the incident exposed how thin the authentication layer is on platforms where millions of apps are being built by users who assume the platform handles security for them.

Advertisement

The pattern is consistent across the vibe coding ecosystem. CVE-2025-48757 documented insufficient or missing Row-Level Security policies in Lovable-generated Supabase projects. Certain queries skipped access checks entirely, exposing data across more than 170 production applications. The AI generated the database layer. It did not generate the security policies that should have restricted who could read the data. Lovable disputes the CVE classification, stating that individual customers accept responsibility for protecting their application data. That dispute itself illustrates the core tension: platforms that market to nontechnical builders are shifting security responsibility to users who do not know it exists.

What this means for security teams

The RedAccess findings complete the picture. Professional agents face credential theft on one layer. Citizen platforms face data exposure on the other. The structural failure is the same. Security review happens after deployment or not at all. Identity and access management systems track human users and service accounts. They do not track the Lovable app a sales operations analyst deployed last Tuesday, connected to a live CRM database, and shared with three external contractors via a public URL.

Nobody asks whether the database policies restrict who can read the data or whether the API endpoints require authentication. When those questions go unasked at AI-generation speed, the exposure scales faster than any human review process can match. The question for security leaders is not whether vibe-coded apps are inside their perimeter. The question is how many, holding what data, visible to whom. The RedAccess findings suggest the answer, for most organizations, is worse than anyone in the C-suite currently knows. The organizations that start scanning this week will find them. The ones that wait will read about themselves next.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Premier League Soccer: Stream Man City vs. Brentford From Anywhere Live

Published

on

When to watch Man City vs. Brentford

  • Saturday, May 9, at 12:30 p.m. ET (9:30 a.m. PT).

Where to watch

  • Man City vs. Brentford will air in the US on NBC Sports Network and Peacock Premium.
73% off with 2yr plan (+4 free months). Now only $3.49/month


See more details

See at Fubo
Advertisement
Fubo

Watch the Premier League in Canada

Fubo Canada

Advertisement

Nothing less than a win looks likely to do for title-chasing Man City on Saturday as it hosts a Brentford side looking to build on its London derby win last weekend. 

Second-placed City has a game in hand over title rival Arsenal. However, the team comes into this weekend’s action five points behind the Gunners, having played out a tremendously entertaining 3-3 draw at Everton on Monday.  

Brentford enters this game in seventh place and with renewed hope of qualifying for Europe for the first time in its history following last weekend’s 3-0 win over London rival West Ham. 

Manchester City takes on Brentford on Saturday, May 9, at the Etihad Stadium, with kickoff set for 5:30 p.m. BST. That makes it a 12:30 p.m. ET or 9:30 a.m. PT start in the US and Canada, and a 2:30 a.m. AEST kickoff in Australia in the early hours of Sunday morning. 

Advertisement
Jeremy Doku of Manchester City running with the ball.

Jeremy Doku scored a last-second equalizer against Everton to rescue a point on Monday night. 

Shaun Brooks/CameraSport/Getty Images

How to watch Man City vs. Brentford in the US without cable

Saturday’s clash at the Etihad Stadium will be broadcast on NBC and streaming service Peacock. To catch the game live on Peacock, you’ll need a Peacock Premium or Premium Plus subscription. NBC Sports Network is available on platforms like YouTube TV.

Advertisement

Peacock offers two Premium plans, and after recent price increases, the ad-supported Premium plan costs $11 a month and the ad-free Premium Plus plan costs $17 a month.

How to watch the Premier League 2025-26 with a VPN

If you’re traveling abroad and want to keep up with Premier League action while away from home, a VPN can help enhance your privacy and security when streaming.

Advertisement

It encrypts your traffic and prevents your internet service provider from throttling your speeds, and can also be helpful when connecting to public Wi-Fi networks while traveling, adding an extra layer of protection for your devices and logins. VPNs are legal in many countries, including the US and Canada, and can be used for legitimate purposes such as improving online privacy and security. 

However, some streaming services may have policies that restrict VPN use to access region-specific content. If you’re considering a VPN for streaming, check the platform’s terms of service to ensure compliance.

If you choose to use a VPN, follow the provider’s installation instructions to ensure you’re connected securely and in compliance with applicable laws and service agreements. Some streaming platforms may block access when a VPN is detected, so verify whether your streaming subscription allows VPN use.

Advertisement

James Martin/CNET

Price $78 for two yearsLatest Tests No DNS leaks detected, 18% speed loss in 2025 testsJurisdiction British Virgin IslandsNetwork 3,000 plus servers in 105 countries

ExpressVPN is our current best VPN pick for people who want a reliable and safe VPN, and it works on a variety of devices. It’s normally $120 a year for its most popular plan (Advanced), but if you sign up for an annual subscription for $90, you’ll get three months free. That’s the equivalent of $6 a month.

Advertisement

Note that ExpressVPN offers a 30-day money-back guarantee.

73% off with 2yr plan (+4 free months). Now only $3.49/month

Livestream Man City vs. Brentford in the UK 

This Saturday afternoon clash is exclusive to Sky Sports and will be shown on its Sky Sports Main Event channel. If you already have Sky Sports as part of your TV package, you can stream the game via its Sky Go app. Cord-cutters will want to set up a Now account and a Now Sports membership to stream the game. 

Advertisement

Now TV

Sky’s standalone streaming service Now offers access to Sky Sports channels with a Now Sports membership. You can get a day of access for £15 or sign up to a monthly plan from £35 a month right now.

Livestream Man City vs. Brentford in Canada 

If you want to livestream EPL games in Canada this season, you’ll need to subscribe to Fubo. The service has secured exclusive rights to the Premier League and is broadcasting all 380 matches live. 

Advertisement

Fubo

Fubo is the go-to destination for Canadians looking to watch the EPL, with exclusive streaming rights to every match. It currently costs CA$27 for the first month, then CA$31.50 per month thereafter.

Livestream Man City vs. Brentford in Australia 

Livestreaming rights for the EPL are now with Stan Sport, which is showing all 380 matches live, including this game.

Advertisement

Stan

Stan Sport will set you back AU$20 a month (on top of a Stan subscription, which starts at AU$12). It’s also worth noting that the streaming service is currently offering a seven-day free trial.

A subscription will also give you access to Premier League, Champions League and Europa League action, as well as international rugby and Formula E.

Advertisement

Source link

Continue Reading

Tech

The Switch 2 still doesn’t have a proper YouTube app, so users made their own solution

Published

on

As the Nintendo Switch 2 still doesn’t have access to the YouTube app, owners have managed to find a workaround on the console.

This workaround is via the free-to-play title Super Animal Royale and takes advantage of the news section embedded within the app. As shared by Reddit user JampyL, the news section surfaces YouTube videos that open inside the console’s browser and enables gamers to search for and watch any YouTube content freely.

Nintendo Switch 2 owners have found a workaround to access YouTube on the console through the free-to-play title Super Animal Royale, filling a gap that Google has yet to address with an official application.

Undoubtedly it’s a clever workaround, however it’s not without its compromises. Firstly, the browser-based playback caps resolution at just 360p which makes longer or detail-heavy content much harder to watch on a TV. In addition, users won’t be able to sign into their YouTube accounts which means there’s no access to personal playlists or recommendations.

Advertisement

The absence of a native YouTube application on the Switch 2 is a notable gap given that the original Nintendo Switch shipped with a dedicated YouTube app that remained available to users throughout the console’s life cycle, with that same legacy app remaining downloadable on Switch 2 hardware for owners who want a stopgap while waiting for a purpose-built successor.

Advertisement

Nintendo Switch 2 - top down - controllers disconnectedNintendo Switch 2 - top down - controllers disconnected
Image Credit (Trusted Reviews)

Google confirmed during an earlier period that a YouTube application for the Switch 2 is in active development, though more than a year has passed since that acknowledgement without any further update on timing or availability, leaving the console without streaming video support that competing platforms have offered as standard for well over a decade.

The Switch 2 launched earlier this year to strong demand, with Nintendo reporting significant early sales figures, making the continued absence of a fully functional YouTube experience on the platform increasingly conspicuous among the broader library of missing media applications at this stage of the hardware cycle.

Google has not confirmed when a dedicated YouTube application will arrive on the Nintendo eShop, leaving Switch 2 owners reliant on workarounds for a feature the platform’s predecessor supported from relatively early in its own life cycle.

Advertisement

Source link

Continue Reading

Tech

Photos: Inside the 2026 GeekWire Awards

Published

on

The scene at the 2026 GeekWire Awards at Showbox SoDo in Seattle on Thursday night. (GeekWire Photo / Kevin Lisota)

Hundreds of Pacific Northwest tech community members turned out to honor each other, network and party at the 2026 GeekWire Awards in Seattle on Thursday.

The shimmering scene inside Showbox SoDo — highlighted by crystal accents to mark the event’s 15th anniversary — included an especially geeky and futuristic acrobatic dance performance by members of Maison de V’s circus and dance community.

Seattle Sounders FC captain Cristian Roldan made a special appearance. There was also a silver-clad juggler tossing lighted batons; a fortune teller’s booth; the usual antics in the photo booth; dinner, drinks and much more as Seattle turned out for the annual event — sponsored by Astound Business Solutions — to celebrate the leading entrepreneurs and innovators across the region’s tech landscape.

Read about all the winners in our main awards story, and keep scrolling for a photographic recap of the event. And thanks again to everyone for attending!

A juggler performs at the GeekWire Awards VIP Reception.
The Yoodli team in the photo booth at the GeekWire Awards.
Peter Tomozawa, CEO of Seattle World Cup 2026 and president of business operations for the Seattle Sounders.
From left: Sonu Aggarwal of TiE Seattle, GeekWire co-founder John Cook, and First Tech’s Keion Mauldin.
GeekWire co-founder Todd Bishop, right, interview’s Augmodo founder and CEO Ross Finman.
The calm before the storm at the GeekWire Awards.
Inside the Baird Fortune Suite at the GeekWire Awards.
From left: Magdalena Balazinska of the UW’s Allen School, Brett Goodwin of Carbon Robotics, Kevan Krysler of Carbon Robotics and Dan Renouard of Baird.
Members of Maison de V’s circus and dance community perform at the GeekWire Awards. (GeekWire Photo / Kevin Lisota)
The Fuel Talent table at the GeekWire Awards.
Karen Dhillon of GeekWire Awards presenting sponsor Astound Business Solutions delivers a toast to open the 2026 GeekWire Awards.
GeekWire co-founders Todd Bishop, left, and John Cook on stage at the GeekWire Awards.
Sounders FC majority owner Adrian Hanauer, center, and Peter Tomozawa, CEO of Seattle World Cup 2026, left, are recognized during the GeekWire Awards.
From left: Wilson Sonsini’s Craig Sherman, Deal of the Year winner Greg Demopulos of Omeros, and Remitly Chairman Matt Oppenheimer.
Seattle Sounders FC captain Cristian Roldan on stage at the GeekWire Awards.
Ambika Singh, left, founder and CEO of Armoire, alongside GeekWire co-founder John Cook while presenting Workplace of the Year.
2025 CEO of the Year David Shim of Read AI, right, congratulates 2026 winner Luis Poggi of HouseWhisper AI.

More photos!

Check out the images from the photo booth here.

Many thanks to Astound Business Solutions, the presenting sponsor of the 2026 GeekWire Awards.

Advertisement

Thanks also to gold sponsors Amazon SustainabilityBairdBECUDeloitte, JLLPwC, F5, First Tech, Microsoft, and Wilson Sonsini, and silver sponsors Prime Team Partners.

Source link

Continue Reading

Tech

Expedia Group sees reward and risk in the rise of AI-powered travel

Published

on

Expedia Group CEO Ariane Gorin. (Expedia Group Photo)

More than 30% of Expedia Group’s self-serve customer support interactions are now handled by AI. Its fastest-growing marketing channel is getting its brands to show up in AI responses. And the company now has travel booking integrations across both ChatGPT and Claude.

Expedia Group CEO Ariane Gorin offered new details about the Seattle-based online travel giant’s AI push on the company’s first-quarter earnings call Thursday, describing a strategy that includes both internal cost-cutting and a bet on chatbots as a new source of customers.

The company reported revenue of $3.43 billion, up 15% year over year, and adjusted earnings of $542 million, up 83%. Its first-quarter profit margin was 15.8%, the highest in 15 years.

Expedia’s stock was down about 6.5% Friday, however, as investors reacted to the company holding its full-year guidance unchanged despite the strong first-quarter results. 

In addition to its flagship Expedia portal, Expedia Group includes Hotels.com, Vrbo, and a B2B business that powers hotel bookings for partners including airlines and corporate travel companies. Last week, it became the exclusive hotel partner for Uber, which will integrate Expedia’s lodging inventory into its app.

Advertisement

AI impact: The AI push is both an opportunity and a defensive necessity for Expedia. The company lists “emerging AI-powered platforms” among its competitive threats, reflecting concerns that chatbots could cut online travel agencies out of the booking process altogether.

OpenAI recently scaled back plans to enable direct checkout inside ChatGPT, a decision that sent OTA stocks higher in March. Gorin said she wasn’t surprised by the pullback, arguing that travel booking and servicing are too complex for AI platforms to handle on their own.

If the market evolves further toward a paid model, she said, “that’s a space we know well.” Expedia was among the first travel brands to launch as an app inside OpenAI’s ChatGPT last October. The company went live with ads on ChatGPT in February.

In addition to travel booking integrations in ChatGPT and Claude, Gorin said Expedia is working to show up on Google’s Gemini as well. 

Advertisement

She noted that traffic and bookings from AI-driven channels are small but the company is encouraged by the mix of new users, conversion rates, and average purchase size. 

New efficiencies: Gorin said Expedia handles roughly 250 million customer service interactions per year, with more than half resolved through self-service and a growing share powered by AI. 

The company has cut new customer service agent onboarding time by about 60%. When customers do need a human agent, AI generates summaries of previous conversations so agents don’t have to start from scratch. The system now works in more than 30 languages. 

At the same time, Expedia has cut hundreds of engineering, product, and technology jobs over the past two years, including 162 roles at its Seattle headquarters earlier this year. 

Advertisement

AI costs: Outgoing CFO Scott Schenkel said the company expects AI compute costs to rise in the second half of the year but is funding the investment through cuts elsewhere. The company didn’t disclose specific AI costs as a line item in its earnings report or conference call. 

Gorin said the company is not holding back on AI adoption but is also being strategic about its usage, scrutinizing where the technology is deployed to make sure it delivers returns.

Source link

Advertisement
Continue Reading

Tech

Europe can’t afford to sit on the agentic commerce sidelines

Published

on

The basic assumptions behind online commerce are starting to fracture, says Paul Conroy, CTO at Square1, as he looks back at last week’s Stripe Sessions in San Francisco.

Stripe bills Sessions as its “internet economy conference”. Across a few days in San Francisco, thousands of people from around the world gathered last week to talk about the future of online commerce.

But for all the product launches and big-name keynotes, one fundamental shift kept surfacing – the basic assumptions behind online commerce are starting to fracture.

For more than 20 years, payment systems have been built on the assumption that bots are the problem. A good customer browses, hesitates, clicks around and eventually buys something. A suspicious customer lands directly on a payment page, provides almost zero behavioural signal and comes from a server farm rather than a smartphone.

Advertisement

Stripe Sessions 2026 made it very clear: that assumption is dead. In the next phase of commerce, it’s likely that the bot is actually the customer.

Agents need merchants they can understand

One of the clearest examples of this shift is the soon-to-be-everyday idea of asking an AI agent to buy you something. Not just “find me this jacket”, but something more concierge-like: “Get me a full outfit for hiking in France in July, within this budget.”

That request asks vastly more of a merchant than a traditional product search. A human can squint at a product page, read around missing information, infer whether two items might work together and gauge if a return policy feels fair. An agent needs that same information in a structured, reliable format. It needs to understand sizes, materials, compatibility and, crucially, whether a merchant can be trusted.

For merchants, agentic commerce raises a practical question – can your products, prices and policies actually be understood by machines?

Advertisement

This is why new commerce protocols are suddenly so vital. The Universal Commerce Protocol (supported by companies like Stripe, Shopify and Google) is an attempt to standardise how this should work. If agents are going to shop, merchants need a common way to tell those agents what they sell and how it can be bought. Businesses with messy product data will soon find themselves effectively invisible to machine customers.

The new unit economics of AI

This evolution also shows up when we look at agents paying for digital work in tiny increments.

One demo at Sessions involved a code review tool which charges based on tokens consumed. That sounds niche until you consider the economics of AI more broadly. As more companies rely on AI, the cost of inference becomes a massive operational risk. We have all seen the funny screenshots where someone persuades a fast-food chatbot to ignore the menu and write a React app instead. That unintended use is amusing until it is applied to a service with real inference costs behind it. If usage spikes, costs spike.

In the demo, the tool’s price was thousandths of a cent per token used. That is far too small to make sense through traditional credit card processing, so delayed billing in aggregate is common, though risky, for this type of merchant today. However, if an agent can call an API, use an authorised wallet, and make thousands of tiny payments as and when it consumes a service – while keeping processing fees low – viable microtransactions suddenly look very real.

Advertisement

How do you charge for AI-native services when the unit economics are too small, too fast-moving or too risky for traditional payment models? This is where stablecoins graduate from crypto buzzword to practical infrastructure.

The view from Europe

Spending a few days in San Francisco makes the difference in pace hard to ignore. Coming from Dublin, where the bus shelters are more likely to be selling phone plans or supermarket offers, it is striking to arrive somewhere where every billboard seems to be advertising some novel AI startup, or a company with a new way to move money.

Some of that is inevitably hype. But what is entirely real is that the US is actively wiring up the infrastructure to support these shifts. Stablecoin adoption and agent wallets are rapidly moving from theoretical concepts to live commercial deployments.

From a European perspective, that should make us slightly uncomfortable. We have a tendency to approach new financial infrastructure by regulating first. The rollout of the MiCA (Markets in Crypto-Assets) framework is a perfect example. While it gives Europe necessary regulatory clarity, our heavy focus on compliance often means commercial deployment lags behind.

Advertisement

Consumer protection and stability are critical, of course. But there is a difference between moving carefully and moving so slowly that the next generation of infrastructure is built somewhere else, with someone else’s interests at heart. If AI-native commerce, agent wallets and real-time stablecoin microtransactions become the foundation of how online commerce is conducted, Europe cannot afford to watch from the sidelines. The challenge is to regulate well without regulating late.

The fraud arms race gets harder

The fraud angle is where this agentic ecosystem gets significantly more complicated.

Historically, fraud tooling has treated bot-like behaviour as suspicious by default. No normal browsing pattern, a single fast request to transact and a data-centre IP were strong signals that something bad was happening. In an agentic commerce world, a perfectly legitimate transaction will look exactly like that.

This creates a catch-22 for merchants. Block good agents, you lose revenue. Allow bad agents, you lose money. The old signals are failing in both directions.

Advertisement

This came up repeatedly during Sessions. There is a new arms race developing: fraudsters using AI to scale attacks and probe weaknesses, and Stripe using its own AI models in Radar to detect and respond. What I found most interesting was the frankness in many of the talks. There was no triumphalism, just a lot of, “we do not have this fully figured out just yet”. How do we authenticate intent? Who owns the transaction when a user has delegated the decision to an agent?

These are existential questions for businesses operating on low margins. The same automation that makes new buying experiences possible makes abuse much cheaper to attempt.

Clean APIs and the human element

Between talks in the main hall, instead of piped-in background music, a live string quartet played pop covers. It sounds like a tiny thing, and it won’t appear in anyone’s ROI model, but it was a conscious decision somebody somewhere in Stripe made, to make the room a nicer place to be.

That theme of the hidden utility of beauty came up during Patrick Collison’s interview with Sam Altman. Altman noted that Stripe has cared to an almost irrational degree about design and beauty in its APIs for years. That aesthetic consistency was designed to appeal to human developers, but ironically, it may become their biggest advantage in a world of agents. Agents, it turns out, benefit from the exact same things human developers do – clear APIs, coherent abstractions and predictable behaviour. Stripe spent years making itself easier for developers to choose, putting it in a remarkably strong position now that software starts choosing tools too.

Advertisement

During that same interview, there was an interruption as a protester with a guitar walked down the aisle, singing that music and art should be made by humans, not machines. It was a strange and funny moment. The Moscone Center acoustics are so good, many thought he was part of the show initially, before he was hurriedly escorted away. There were numerous callbacks to this during subsequent talks – John Collison noted that an AI demo that was taking too long to run could have used a guy with a guitar to keep people entertained – but it served as another reminder that AI is changing more than commerce. It is colliding directly with culture more broadly, for better and worse.

The future is unevenly distributed

For visitors to San Francisco, Waymo’s autonomous cars navigating the hills still feel like a futuristic tourist attraction. For locals, they are just more traffic.

Agentic commerce feels a lot like those driverless cars. It brings to mind William Gibson’s famous line about the future being already here, just not evenly distributed.

While agentic commerce is unevenly distributed, it is very much here. The businesses that prepare now by cleaning up their data, rethinking their pricing for microtransactions and strengthening their fraud controls will be ready for a fundamentally new kind of customer.

Advertisement

The ones that wait may find the agents have already learned to shop somewhere else.

Paul Conroy is CTO at Square1, an award-winning digital transformation agency specialising in payments and online publishing. He was also among the first cohort of Stripe Partner Advocates – a group of technical leaders with deep payments experience, chosen to collaborate directly with Stripe product teams. Disclosure: Square1 is a longtime collaborator of Silicon Republic.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Advertisement

Source link

Continue Reading

Tech

Top Megelin Deals for Laser and LED Therapy Devices (2026)

Published

on

The red-light therapy market shows no signs of slowing down. According to Fortune Business Insights, the industry is projected to grow from $1.21 billion in 2026 to $1.76 billion by 2034. Riding that wave is Hong Kong-based Megelin, which is currently running its largest Mother’s Day sale yet, offering major discounts on most of its LED devices and select electrical muscle stimulation (EMS) tools.

I’ve been testing the Duo Lux Laser & LED Light Therapy Mask for the past two weeks as part of a six-week trial. While I’m still forming my final verdict, I already have some early thoughts (more on that below). In the meantime, check out the standout deals because some of these discounts might be too good to pass up while they’re live.

This Laser & LED Light Therapy Mask Is $270 Off

Image may contain: Appliance, Device, Electrical Device, and Mixer

Megelin

Duo Lux Laser & LED Light Therapy Mask

The Megelin Duo Lux Laser & LED Light Therapy Mask combines 660-nanometer (nm) and 1,064-nm lasers with a 660-nm LED light for a more intensive treatment. The brand claims it can help smooth wrinkles, soothe inflammation, reduce pigmentation, and minimize redness. After two weeks of testing, I haven’t noticed any visible changes in my skin just yet, though to its credit, I also haven’t experienced any irritation or adverse reactions.

Advertisement

My biggest issue was the initial unboxing experience: The mask had a strong chemical odor that reminded me of formaldehyde. For a device that sits against your face and doesn’t have a mouth opening, that’s not exactly reassuring. Wiping it down and letting it air out significantly reduced the smell, but it definitely made for a less-than-ideal first impression.

That said, the mask itself is extremely comfortable. The soft, flexible silicone contours well to the face, and the dual-strap design keeps it secure without feeling restrictive. Treatments are quick and easy to customize thanks to four different modes, all controlled through an attached remote. And because it’s cordless, you’re free to move around while using it.

At full price, it’s a steep investment compared to its competitors. But with the current $270 discount, it becomes a much more compelling option, especially given the added laser therapy component, which isn’t as common at this price point. I’ll continue testing through the full six-week period before sharing my final verdict, but if you’re tempted to take advantage of the sale now, Megelin does offer a 60-day money-back guarantee and a one-year warranty.

Source link

Advertisement
Continue Reading

Tech

NYT Connections hints and answers for Saturday, May 9 (game #1063)

Published

on

Looking for a different day?

A new NYT Connections puzzle appears at midnight each day for your time zone – which means that some people are always playing ‘today’s game’ while others are playing ‘yesterday’s’. If you’re looking for Friday’s puzzle instead then click here: NYT Connections hints and answers for Friday, May 8 (game #1062).

Good morning! Let’s play Connections, the NYT’s clever word game that challenges you to group answers in various categories. It can be tough, so read on if you need Connections hints.

Advertisement

Source link

Continue Reading

Tech

Discord Is Back After An Outage That Took Some Users Offline

Published

on





Discord is recovering following a brief outage that saw some users unable to use the popular chat app. At 3:08PM ET, the company said it had begun investigating an issue with its API systems. Shortly thereafter, at 3:24PM ET, Discord said it had identified the problem, but noted at the time it was still affecting users, making it difficult for them to access the service. 

“We are continuing to work to remediate the issues impacting availability for some Discord users,” the company said at3:56PM ET. “This is causing impact across our service, including logging in and sending messages.” Whatever was causing the disruption, Discord appeared to solve it quickly. At 4:16PM ET, the company said it was starting to see “seeing significant recovery” across its systems. As of 4:59PM ET, the service isn’t at “fully healthy state” yet, so if you’re having trouble launching the app, it may take a bit more time before everything is up and running again. By 6:38PM ET, Discord reported that “all critical functionalities have recovered for all users.”

Update 6:4PM ET: The headline and copy of this article have been updated to reflect that Discord is back online for all users.

Advertisement



Source link

Advertisement
Continue Reading

Tech

I tried the lossless audio test and couldn’t believe my ears. Can you really tell the difference between lossless audio and plain old MP3 versions of your favorite tunes?

Published

on


  • A simple test can see how well you can recognize lossy formats using your own music choices
  • Beyond a certain point most people can’t easily tell the difference
  • High-quality lossless is still the most future-proof format

With music, how good is good enough? When you’re listening to digital music, what you hear depends on the original master, the file format and most of all, whether it’s lossy — reducing the sound quality to reduce file sizes — or lossless, which is pristine and perfect. If you’re serious about sound, lossless is going to defeat lossless every time.

Right?

Source link

Continue Reading

Tech

Apple is reportedly working on a holographic iPhone, an AI pendent, and AirPods Pro with AI cameras

Published

on


Information about the rumored new iPhone comes from tipster Schrodinger, who shared screenshots of messages from an unnamed source said to be familiar with the project. The screenshots suggest that Apple is working on a “Spatial iPhone” – codenamed H1 or MH1 – featuring a holographic display that would create…
Read Entire Article
Source link

Continue Reading

Trending

Copyright © 2025