Connect with us

Tech

A free AI model is winning over developers. And nobody knows whose servers it runs on

Published

on

An anonymous model called Ox Alpha appeared on OpenRouter last week, free to use with a million-token context window, and developers have been impressed. OpenRouter’s own listing says prompts and completions are retained by the unidentified provider.

A model that nobody will take credit for is being tested across the industry. Ox Alpha appeared on OpenRouter last Thursday as a stealth release from an anonymous third-party provider, free to use, with a context window of just over a million tokens.

The scale on offer is not modest. The open-source agent OpenCode said the model would be free for a week with near unlimited usage, and that its provider had capacity for 100 trillion tokens a day.

Developers rate it. Stripe’s chief executive Patrick Collison tried it and called it “very impressive,” and it is positioned for coding, long-horizon agent work and production use.

Advertisement

The guessing game has been inconclusive. The leading theory points to Z.ai, which previously tested GLM-5 anonymously under another name, while a competing analysis of its tokenizer suggests Microsoft’s MAI family instead, in a market already reshaped by free Chinese models.

By the weekend the confidence had drained out of every theory. The AI analyst Andrew Curran wrote that people seemed “less sure of anything” than they had been the night before.

The more useful detail is not the identity but the terms. OpenRouter’s own listing states that prompts and completions “are retained by the provider and are not used for training.

Read that again with a work project in mind. Whatever you send goes to a company that has not said who it is, and it keeps it.

Advertisement

For European businesses that is not an intrigue, it is a blocker. Data protection law requires a contract with a named processor and an assessment of where data goes, neither of which is possible when the counterparty is anonymous.

The timing sharpens it. The AI Act’s transparency obligations took effect on 2 August, with penalties reaching €15mn or 3% of global turnover, in a regime built on knowing which provider is responsible for what.

None of this makes the model bad. Open-weight releases have closed the capability gap faster than the safety one, and a stealth launch is a legitimate way to benchmark a model before announcing it.

But free has a price here, and it is information. Somebody is paying for 100 trillion tokens a day of inference, and until they say who they are, the sensible European position is to test Ox Alpha with nothing that matters.

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

AWS Security makes an inscrutable choice

Published

on

security

Quarantining leaked credentials is not good enough

One of the best ways to lower your AWS bill by 99 percent or more is by not checking your keys into public GitHub repositories. Many of us have done this inadvertently over the years, and the defenses against it have improved dramatically (my personal favorite being “using non-ephemeral credentials derived from OIDC or SSO is an anti-pattern”), but it still happens.

On Friday, BleepingComputer reported on a Truffle Security finding that hundreds of leaked AWS keys are root keys and are somehow still active and valid.

Advertisement

AWS Security is full of very smart people who care deeply about a number of things, including “not abetting crime.” If they detect (usually via automated means) that a credential has been leaked, they’re quick to apply a Quarantine Policy to it. Trouble is, that policy enumerates a bunch of bad behaviors in an ever-expanding graph of principals and associated behaviors.

AWS’ considered position on this is that they don’t want to break customer environments: “The policy aims to limit the potential damage that may be caused by fraud-related activity leading to unauthorized charges, while not impacting the existing resources.”

AWS’ considered position on this is wrong.

If I get access to your credentials (much less a root credential, good god), deactivating them may very well break your workload because anything that relies on those credentials will start failing. Until you rotate them, those workloads will continue to fail. That’s not good!

Advertisement

But I promise you, as a bad actor, I can do far worse to you.

Hold my tea

Go ahead and apply a quarantine policy to a credential set and toss it my way. I won’t be able to buy savings plans, read your S3 data, modify Lambda functions, and do a host of other things.

But here’s what I can do.

  • Anything I damn well feel like on RDS. You don’t have anything important in databases, right?

  • ssm:SendCommand / ssm:StartSession are permitted, which means I can run commands as root on EC2 instances, which will in turn invoke with that instance role’s permissions.

  • sts:AssumeRole means that I can assume any other role in the account and get its permissions, rendering the entire restriction list potentially moot.

  • I can use autoscaling:CreateAutoScalingGroup / UpdateAutoScalingGroup to launch instances via the Auto Scaling service-linked role, so the ec2:RunInstances deny never applies.

  • cloudtrail:LookupEvents gets denied (that’ll stop you from… reading the audit log), but I can call both cloudtrail:StopLogging and DeleteTrail which do exactly what you expect; you don’t have an audit log anymore.

  • SES denies ses:GetSendQuota / ListIdentities actions, but y’know what’s missing? SendEmail, so I can blast my spam out to your entire list.

  • sns:GetSMSAttributes means I can’t get your SMS configuration, but I can absolutely sns:Publish to send fraudulent text messages wherever I’d like.

  • s3:DeleteObject gets denied, but s3:PutObject is allowed. I can’t delete your data, but I can fill a bucket to petabytes.

  • Next, they fail to block s3:PutBucketVersioning, s3:PutObjectLockConfiguration, s3:PutObjectRetention, and s3:PutObjectLegalHold. So on any existing bucket, like that one I just stuffed petabytes into, I can enable versioning, turn on Object Lock, and set a bucket-default COMPLIANCE-mode retention out to 2126, or alternatively slap it on per object. COMPLIANCE retention can’t be shortened or removed by anyone, including the account root and AWS Support. The only way to remove it is to delete the entire AWS account.

  • secretsmanager:GetSecretValue, ssm:GetParameter* (WithDecryption), and kms:Decrypt are all unencumbered, so your secrets are now my secrets. Sharing is good! 

  • Backups are important, so it’s a shame you don’t have any. Well, not after I kick off backup:DeleteRecoveryPoint / DeleteBackupVault, and rds:DeleteDBSnapshot. 

  • If you’re using CloudFormation, and for some things you almost certainly are, cloudformation:DeleteStack going unmentioned means you’re not using it anymore and all of your stacks are gone.

I would make different choices

This isn’t a comprehensive list – just a few things that occurred to me over the course of about an hour. I’m not a bad actor; I’m almost positive that I’m missing a whole bunch.

Advertisement

AWS is almost certainly going to change this. My question for them is simply, “how big of a customer incident needs to happen before you do?” ®

Source link

Continue Reading

Tech

Casio decides it’s about time the simple digital watch got a little smarter

Published

on

PERSONAL TECH

F-B100W adds Bluetooth and step tracking while keeping a two-year battery

Casio has added Bluetooth and step tracking to a £55 digital watch without turning it into a smartwatch or sacrificing replaceable-battery convenience.

The snappily named F-B100W pairs with Casio’s smartphone app to record activity, adjust settings, and keep its clock accurate. Despite the additional electronics, Casio claims approximately two years of operation from a replaceable CR2016 battery.

Advertisement

It is very much not a smartwatch. There is no touchscreen, app store, or stream of notifications – just a conventional digital watch with a step counter and a little Bluetooth connectivity. That combination has nevertheless attracted attention on Hacker News and Reddit.

We admit it: this ape-descended life form is so astoundingly primitive that he still thinks digital watches are a pretty neat idea.

Douglas Adams first mocked humans’ fondness for digital watches when the original Hitchhiker’s Guide to the Galaxy was broadcast in 1978 – nearly half a century ago. The Casio F-91W is only a decade younger. This strangely ubiquitous watch, once labeled a supposed “sign of al-Qaida,” is widely regarded as the classic quartz digital watch and has been described as the bestselling watch of all time. One reason is that it’s only £20 ($30) new. Another is that if you bought one of the first batch, it’s probably only on its third or fourth battery by now: they are rated for seven years, but often last longer.

The F-91W is very simple and very cheap. Its main rival for all-time bestselling watch is the reverse: the Apple Watch has also shifted about 300 million units.

Advertisement

This is not a radical innovation for Casio. The existing ABL-100 does much the same, but costs over 25 percent more and weighs more than twice as much. What is interesting is that Casio has brought the functionality to a smaller, cheaper, and lighter watch – and possibly a more robust one. It’s also retained an impressive battery life. These Bluetooth-enabled models should still run for two years or more on a single, replaceable, CR2016 lithium button cell. Since those only cost a buck or so, that sounds good to us.

The Reg FOSS desk has a fondness for inexpensive technology that performs a modest set of tasks well. Our first budget smartwatch was an Amazfit Bip, bought new for about £60 ($80). It had an always-on, daylight-readable color display, lasted a month and a half on a charge, and did everything we asked of it.

After five years of daily use, its battery stopped holding a charge. We replaced it with the then-latest Bip 5, only to find that the newer model lacked its ancestor’s always-on display and offered less than a quarter of its battery life.

Our next move was therefore backward to a secondhand Amazfit Neo. It is the most basic smartwatch we have encountered. A conventional segmented LCD displays the time, while a smaller strip cycles through the world clock, step count, pulse, estimated calories burned, battery level, and waiting notifications. It cost £15 ($20) and still lasts a week and a half on a charge.

Advertisement

This “beyond retro” design is, we need hardly say, no longer made. That is why Casio’s move in the opposite direction – adding a few connected features to a basic digital watch – interests us.

We found the existing threads about these devices highly educational. There’s a whole world of digital watch geekery that we barely even knew existed.

Some posters raised concerns we found very relevant. For instance, the vexed issue of date formats: it seems many low-end Casios can only display dates in US MM/DD format. Apparently, to get European-format dates, you need to go to more high-end models such as the GW-M5610U-1ER at a princely £135 ($185).

These lower-end Bluetooth-equipped Casio devices send only one Bluetooth Low Energy update to the phone at the end of each day, which is why they can boast such impressive battery life. In its pricier G-Shock range, the company does offer devices with bidirectional Bluetooth support, so that the watch can display on-screen notifications, such as the £129 ($165) G-Squad GBD-200 and GBD-300. Better still, it seems these can deliver silent vibrating alerts.

Advertisement

Another concern is that officially syncing these watches requires Casio’s proprietary smartphone app, but there are FOSS alternatives such as Casio G-Shock Smart Sync.

The Register asked Casio for more information and a review unit but had not received a response at the time of publication. ®

Source link

Advertisement
Continue Reading

Tech

Harvard’s $699 startup bootcamp offers AI avatars of its instructors

Published

on

As Harvard Business School seeks to expand its reach, it’s leaning on AI avatars to provide individual feedback.

These avatars were created by a startup called HeyGen and are included in the eight-week, $699 HBS Foundry bootcamp for entrepreneurs. The program offers live sessions with instructors every week, but the AI avatars are the ones providing feedback during practice pitches and board meetings.

New York Times reporter Sarah Kessler actually tried this out herself by pitching an AI-generated copy of Flybridge Capital co-founder Jeff Bussgang. Apparently, both the real Bussgang and his simulacra were unimpressed by her plan to build “Uber for bananas,” but Kessler said the virtual version offered a noticeably frozen smile during her pitch.

Project director Katharina Rings said she initially envisioned the AI component as something closer to a chatbot. However, after HBS released a trial version, students said they wanted a more guided experience.

Advertisement

And while some college students haven’t been shy about expressing their negative feelings towards AI, Foundry participants told Kessler they like the avatars. As for Bussgang, he acknowledged his digital copy is a little “creepy,” but he said, “My students love it.”

Source link

Continue Reading

Tech

Anduril exits Seattle shipyard following canceled Navy program and omission from new warship list

Published

on

Anduril recently vacated the the old Foss Shipyard on Seattle’s Lake Washington Ship Canal. (GeekWire Photo / Kevin Lisota)

Defense technology giant Anduril Industries has quietly vacated its maritime operations along Seattle’s Lake Washington Ship Canal.

The exit, confirmed by the company to GeekWire this week, comes after the U.S. Navy canceled the specific autonomous vessel acquisition program Anduril was pursuing at the historic former Foss Maritime shipyard site.

“Anduril has moved out of its shipyard space in Seattle,” a spokesperson said in a statement. “The space supported a Navy program pursuit; the Navy canceled that program, and the shipyard footprint was no longer needed. The Seattle shipyard presence was always small — a handful of employees worked from the space. Anduril’s broader Seattle footprint continues to grow across its other offices in the city.”

@media (max-width: 600px) {
aside.callout { float:none !important; max-width:100% !important; margin-left:0 !important; margin-right:0 !important; }
aside.callout .callout-img { display:none !important; }
}

The disclosure provides a sudden plot twist in a maritime push that GeekWire first reported on in April, after Anduril established a presence at the Foss shipyard. At the time, the company offered a muted response when pressed for specifics about its local shipyard activities.

Advertisement

The plans went back to late 2025, when Anduril announced a major partnership with South Korea’s HD Hyundai Heavy Industries.

The companies set out to build a new class of dual-use Autonomous Surface Vessels designed to compete for the Navy’s Modular Attack Surface Craft (MASC) program, which sought unmanned vessels capable of carrying large payloads over long distances.

At the time, Anduril pitched the Pacific Northwest as the ideal industrial launchpad, pointing to the region’s historic shipbuilding roots.

“Anduril has invested tens of millions of dollars to revamp a previously retired shipyard in the Pacific Northwest region at the historic former Foss Shipyard in Seattle, Washington,” the company said during the partnership rollout. “This facility will serve as Anduril’s initial U.S. hub for low-rate vessel assembly, integration, and testing of ASVs for the MASC program.”

Advertisement

That vision, however, was quickly upended. The U.S. Navy canceled the MASC initiative in March, replacing it with a new acquisition strategy for Medium Unmanned Surface Vessels, or MUSVs.

Rather than relying on a traditional program competition, the new marketplace allows the Navy to evaluate autonomous vessels through at-sea demonstrations, with successful systems eligible for follow-on production.

Defense giant Anduril recently abandoned its plans at the old Foss Shipyard in Seattle. (GeekWire Photo / John Cook)

When the Department of the Navy announced the seven defense vendors selected to move forward in the new program, the lineup included defense contractors like Leidos, Huntington Ingalls Industries, Saronic Technologies and Sea Machines — leaving Anduril off the roster for initial testing.

Companies that successfully deploy vessels at sea will receive $15 million, and be eligible for follow-on production. At-sea testing was set to start in June, and is expected to conclude in October.

Anduril did not respond to additional questions about the Foss facility, its maritime operations in the Seattle area or its plans for the Navy’s new MUSV program.

Advertisement

Despite vacating its shipyard presence, Anduril’s broader push into Western Washington remains on a steep upward trajectory. The Costa Mesa, Calif.-based company employs 560 people across its Bellevue and downtown Seattle offices — up from roughly 30 four years ago — and operates a multi-acre military testing facility in rural Carnation, Wash.

The high-flying defense giant, which closed a $5 billion funding round at a $61 billion valuation earlier this year and is reportedly targeting a $100 billion valuation in a new funding round, is rapidly building a massive engineering footprint in the greater Seattle region.

Senior Vice President Tom Keane told GeekWire the company could eventually grow its regional workforce to 1,000 people, including engineers working on augmented reality displays, edge computing hardware and other military technologies.

Anduril’s rapid expansion in the region is the subject of a separate profile story today on GeekWire.

Advertisement

Source link

Continue Reading

Tech

Samsung’s Quiet Heavy Hitter, the Galaxy S25+, Still Wins in 2026 and Here’s Why

Published

on

Samsung Galaxy S25+ in 2026
Most people who want the newest phone look at the Ultra or the latest foldable. Meanwhile, Samsung’s Galaxy S25+, priced at $679.99 (was $1,000), delivers the same daily performance without the increased weight or cost. A year and a half after its release, it is still in that unusual position where the hardware feels modern while the software continues to improve.



The phone’s round aluminum edges and glass sandwich provide a really substantial feel in the hand, which you’ll quickly get used to. At 190 grams and just more than 7mm thick, it’s pleasant to hold for as long as you need. The camera is placed low enough so that when you set the phone on a table, it does not rock or tilt to one side. The IP68 rating means you won’t have to worry about rain or the rare accidental splash of water spoiling anything.

Sale


Samsung Galaxy S25+ Cell Phone, 256GB Smartphone, Unlocked Android, AI Night Mode Camera, Snapdragon…
  • MULTIPLE TASKS WITH ONE ASK: Streamline your day with an assistant that gets you. Ask it to Google search for a pet-friendly vegan restaurant nearby…
  • START THE DAY SMARTER: Stay one step ahead with a phone that gives you the info you need before you even know you need it with Now Brief.²
  • REDUCE THE NOISE. REVEAL THE MAGIC: AI Camera with Audio Eraser lets you capture vibrant videos in low light and minimize unwanted noises so you can…

A 6.7-inch Dynamic AMOLED screen occupies nearly the whole front of the phone. The resolution is a whopping 3120 by 1440 pixels, so text is sharp and images are clear and detailed. Even if you’re out in the hot midday sun, the peak brightness of 2600 nits will ensure you can see what you’re doing on the screen. Scrolling and animations feel silky smooth because to the 120Hz variable refresh rate, which also saves battery life. Gorilla Glass Victus 2 protects the phone’s front and rear.

Advertisement


Under the hood is the Snapdragon 8 Elite for Galaxy, a chip developed by Qualcomm and Samsung specifically for this line of phones. As a consequence, you’ll get quick app launches, consistent frame rates in games, and plenty of buffer to do whatever you require. It has 12GB of RAM and 256GB of storage, and UFS 4.0 keeps things operating smoothly. Wireless connectivity choices include Wi-Fi 7 and Bluetooth 5.4.

Samsung Galaxy S25+ in 2026
The cameras are functional and not overly complicated. The 50-megapixel primary sensor performs well in daytime conditions, providing strong dynamic range. Optical image stabilization helps to keep photos and videos steady. A 10-megapixel 3x telephoto lens is adequate for most everyday zooming demands without sacrificing quality too soon. The 12-megapixel ultrawide is ideal for group photographs and confined spaces. When necessary, video can be captured in 8K and remains crisp at 4K. The 12-megapixel front camera captures natural-looking selfies and excellent video calls.

Samsung Galaxy S25+ in 2026
The 4900mAh battery will power you through a full day of messaging, navigation, streaming, and light photography without trouble. If you’re running low, 45W wired charging will recharge your phone in just an hour with a compatible charger, while 15W wireless charging works on any Qi pad. Reverse wireless charging allows you to charge your earbuds if needed.

Samsung Galaxy S25+ in 2026
One UI 7, which is developed on top of Android 15, arrived polished and has only continued to improve. With 7 years of significant reliability updates already paid for, you can be confident that this phone will be up to date until at least the early 2030s. Galaxy AI tools can handle on-device operations such as search, editing, and summarization without the need to constantly sync with the cloud. The ultrasonic fingerprint scanner continues to lock and unlock with the same speed and reliability as before. Stereo speakers provide excellent sound quality for casual listening or video.

Source link

Advertisement
Continue Reading

Tech

Uber launches its first European robotaxi service in Croatia

Published

on

Pony and Uber are also expanding their partnership across four additional European cities.

Uber is launching its first robotaxi service in Europe in partnership with autonomous vehicle (AV) builder Pony AI and Croatian mobility company Verne.

Robotaxi services are now available via Uber in select areas in Croatia’s capital city Zagreb, including the city centre.

The phased launch will see a licensed operator on board behind the wheel, before vehicles are slowly scaled to being fully autonomous, the companies said. The service’s geographic coverage is also expected to expand over time.

Advertisement

Pony and Uber are expanding their partnership elsewhere in Europe too, with plans for a fleet of 2,000 additional robotaxis spread across four cities. Details of the expansion plans have not yet been disclosed.

The two companies first began collaborating in 2025 by bringing Pony robotaxis onto Uber’s platform in international markets outside the US.

In March, they joined forces with Verne to test out Pony’s ‘Gen-7’ autonomous driving system in Zagreb, which has already seen “meaningful” commercial scale in China – including unit economics breakeven in China’s Guangzhou and Shenzhen regions – according to Pony.

Verne had already launched AV booking services in Zagreb this April via its own app, in partnership with Pony. Since then, the company said, it has completed “thousands” of AV trips.

Advertisement

This new service in Croatia brings together Pony’s autonomous driving solution, Verne as the fleet owner and service operator, and Uber integration of the service into its ride-hailing network.

“From today, Verne rides are also available through Uber, giving customers another way to access the service,” said Marko Pejkovic, the CEO of Verne. “This marks another European first – the first time autonomous rides are available through Uber in Europe.

“This is an important milestone not only for Verne, but also for Croatia. A service pioneered here in Zagreb is now available through the world’s largest mobility platform. The experience we are gaining every day in Zagreb will help us bring Verne to other European cities.”

Uber said it expects AV and human drivers to “coexist and grow together for the foreseeable future”. Many journeys will continue to require human drivers while AVs are trained, it added. Riders can access the service through the UberX or Comfort options on the Uber app.

Advertisement

“Today marks a major milestone for autonomous mobility in Europe,” said Annie Duvnjak, the global head of autonomous mobility operations at Uber.

“By bringing together Pony AI’s proven autonomous-driving technology, Verne’s operational expertise and Uber’s global platform, we’re making it simple for riders to access autonomous rides through the Uber app.

“Zagreb is an important first step as we work to bring AVs to millions of riders and build the world’s largest platform for AV deployment.”

The US ride-hailing platform has plans in place to expand robotaxis to London, Madrid, Munich, Hong Kong and a number of US cities. It already operates robotaxis in Abu Dhabi, Dubai and Riyadh, alongside US cities Atlanta, Austin and Dallas.

Advertisement

Uber also has existing partnerships with May Mobility, Lucid and Nuro, China’s Baidu and WeRide, and the UK’s Wayve to test and deploy AVs across metropolitan areas worldwide.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Source link

Advertisement
Continue Reading

Tech

SickKids data breach exposes employee and job applicant info

Published

on

SickKids

The Hospital for Sick Children (SickKids) has disclosed that the personal information of some current and former employees, as well as job applicants, was exposed in a “cybersecurity incident.” The hospital says the breach stemmed from a flaw in third-party software.

Clinical systems and patient records were untouched, according to the Toronto pediatric hospital, but its public-facing Careers website was temporarily pulled offline.

Careers site restored, incident scope under review

SickKids disclosed the incident this week, saying it resulted in unauthorized access to employee data.

image

The hospital attributes the breach to a vulnerability in a third-party software application that it says is used by SickKids and other organizations, according to a media statement.

The framing appears to suggest that there’s a wider campaign against users of the same product, although the hospital has not named the vendor, the application, or the CVE involved.

Advertisement

The external Careers website was temporarily affected and has “since been safely restored,” per the statement.

Clinical systems and patient information were not affected, and patient care continued as usual, SickKids says.

After learning of the incident, the hospital launched an investigation with the help of outside cybersecurity experts.

The findings indicate that personal information belonging to current and former SickKids, Boomerang (a SickKids-owned pediatric clinic), and SickKids Foundation employees, as well as SickKids job applicants, may have been exposed.

Advertisement

The hospital has not said what categories of data were involved, how many people are affected, or when the intrusion took place.

Its review of the impacted information is ongoing, with individuals confirmed as affected to be notified directly.

In the meantime, SickKids says it has alerted everyone potentially caught up in the incident out of an abundance of caution, and is offering 24 months of complimentary credit monitoring and identity protection.

Job application portals are an unusually rich target for data thieves. Applicants routinely hand over full names, home addresses, phone numbers, employment histories, and in some jurisdictions government identifiers. That information is useful both for identity fraud and for building convincing social engineering pretexts against hospital staff.

Advertisement

A repeat target

This is not the first publicly known security incident to have hit the hospital in recent years.

In December 2022, SickKids was hit by a ransomware attack that disrupted internal systems, hospital phone lines, and its website, and caused delays in lab and imaging results.

The LockBit ransomware gang subsequently issued a rare public apology, saying the affiliate responsible had broken its rules against encrypting medical institutions, and handed over a free decryptor, though only after the hospital had spent nearly two weeks restoring systems on its own.

In September 2023, SickKids was among the Ontario healthcare providers caught up in a breach at a third-party organization it shares perinatal and child health data with. That incident, which stemmed from mass exploitation of the MOVEit Transfer zero-day (CVE-2023-34362), exposed information on 3.4 million people, including names, home addresses, dates of birth, and health card numbers.

Advertisement

Healthcare remains one of the most heavily targeted sectors for both ransomware crews and data extortion groups.

Pediatric hospitals in particular sit on decades’ worth of sensitive records, which continues to make them attractive to attackers regardless of the ethical lines criminal operations claim to observe.


article image

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

Source link

Advertisement
Continue Reading

Tech

How to watch Sri Lanka vs India 2nd Test: Free Streams & TV Channels

Published

on

After a dominant win at Galle in the first Sri Lanka vs India Test, Shubman Gill’s men will now be looking to grab another 30 crucial World Test Championship (WTC) points in the second Test at SSC Colombo.

India now need 7 wins out of their remaining 8 matches to make it to the WTC final. Sri Lanka’s loss, however, puts them nearly out of the WTC final race, as they now need 6 out of 6 wins to keep their hopes alive, while also depending on other results.

Source link

Continue Reading

Tech

If Waymo Cars Are Level 4 Automation, What Does It Take To Be A Level 5?

Published

on

It’s less about an autonomous vehicle’s capabilities and more about what conditions it can operate in.

Seeing a car move through city traffic with no one in the driver’s seat can make it feel like Waymo has already reached the highest possible level of automation. From a passenger’s perspective, there’s no steering, no monitoring and no need for a human to intervene. The vehicle handles the entire trip on its own.

But under SAE’s (Society of Automotive Engineers) driving automation framework, that capability is still Level 4 rather than the highest: Level 5. The key distinction isn’t how “independent” the driving looks in practice, but where that independence is allowed to exist. At Level 4, the system can fully handle the driving task without human input — within a defined set of conditions and locations. Level 5 removes those boundaries entirely.

Advertisement

Why Waymo is considered Level 4 automation

Strictly speaking, it’s the Waymo Driver, the company’s automated driving system, that’s classified as Level 4. Waymo’s published safety research describes it as an SAE Level 4 automated driving system, and that classification explains why an empty driver’s seat doesn’t automatically make a Waymo Level 5.

There are a total of six SAE automation levels, numbered 0 through 5. The National Highway Traffic Safety Administration (NHTSA) starts its breakdown at Level 0, where the human does all the driving even if safety systems can briefly intervene. Level 1 can continuously assist with steering or acceleration and braking, while Level 2 can handle both at the same time. In each case, the driver remains responsible for the car.

Level 3 changes who’s doing the driving. The system can handle the entire driving task under certain conditions, but the human must be available to take over when requested. At Level 4, that requirement disappears. Once the automated system is operating within its intended conditions, the occupants are passengers rather than backup drivers.

This is also why Waymo can describe its service as fully autonomous without claiming SAE Level 5. Its cars can complete rides without anyone sitting behind the wheel, but that ability still has defined operating limits.

Advertisement

What separates Level 4 from Level 5 automation

Those limits are usually described as an operational design domain, or ODD. In simple terms, the ODD defines where and under what conditions a self-driving system is designed to operate. That can include geography, the types of roads it’s designed for and the weather conditions it can handle. SAE defines it as the set of conditions an automated driving system is designed for, and Level 4 systems are expected to handle driving on their own within those boundaries.

At Level 4, the system handles the entire driving task within its ODD. Level 5 removes that limitation: NHTSA describes it as operating universally rather than within limited service areas. So Level 5 isn’t about a car being “more autonomous” during a particular maneuver. A Level 4 Waymo already handles steering, braking and decision-making on its own when operating within its domain. The difference is scope, not who is responsible for driving.

That’s why Waymo can keep improving its system and still remain Level 4. For example, Waymo says its sixth-generation Driver has expanded capabilities for more diverse environments, including extreme winter weather. Expanding into new cities or weather types makes the system more capable, but as long as it still operates within defined boundaries, it remains Level 4 rather than Level 5.

Advertisement

Why getting to Level 5 is much harder than expanding Level 4

Expanding a Level 4 system gives developers boundaries around the problem. They can define where the system should operate, identify the conditions it needs to handle and test its behavior against scenarios relevant to that domain. Removing those boundaries dramatically increases what has to be accounted for.

That’s already difficult at Level 4. In its 2026 research on collision-avoidance testing, Waymo noted that evaluating a Level 4 system is complicated by the potentially enormous number of operational scenarios in which a hazardous situation might develop. Its methodology identifies potentially hazardous scenarios using human driving data, data from Waymo’s automated-driving tests and expert knowledge.

Weather offers a concrete example of those limits. In May 2026, Waymos encountered flooded roads in Atlanta and San Antonio, leading the company to suspend or restrict some operations while it worked on improvements.

Advertisement

There isn’t a reliable countdown to when Level 5 will arrive. NHTSA currently says Level 5 technology isn’t available in vehicles for consumer purchase, and the SAE levels describe capabilities rather than a development roadmap.

Source link

Advertisement
Continue Reading

Tech

Hackers abuse FTP server banners to deliver new Windows malware

Published

on

Hackers abuse FTP server banners to deliver new Windows malware

Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE.

MalwareHunterTeam observed this unusual technique in July in an attack that used shortcut files (.LNK) and FTP server banners as dead-drop resolvers (DDR) to retrieve commands.

FTP banners are text strings the server uses as a greeting message for connecting hosts before they log in.

image

By embedding commands in the initial response sent when a compromised system connects to an FTP server, a malware stager can receive instructions from a remote server.

After discovering FTP banners being used to deliver malicious commands during an investigation, researchers at threat intelligence platform SOCRadar expanded their hunt and found that the technique remains in use.

Advertisement

“By utilizing FOFA searches, we determined that this technique has been weaponized since early July 2026 and remains operational, with new infrastructure observed as recently as August 2026.”

In a report shared with BleepingComputer, SOCRadar says that the observed attacks start with a ZIP archive that triggers an LNK-based infection chain. The researchers note that the initial compromise likely occurs through phishing.

LNK file retrieving data from FTP server banners
LNK file retrieving data from FTP server banners
Source: SOCRadar

The infection chain delivers two remote access trojans (RATs) named E4del and PINHOLE via two distinct infection routes, both retrieving  a PowerShell script from FTP banners.

E4del is a Node.js-based RAT packaged inside a digitally signed Electron application that masquerades as Discord.

The RAT supports running commands through persistent or temporary shells, capturing screenshots, streaming the desktop over WebSockets, and downloading and executing additional payloads.

Advertisement

SOCRadar also mentions a Node.js module named crypto32.node that attempts privilege escalation, but the researchers could not retrieve it for analysis.

The E4del RAT delivery chain
The E4del RAT delivery chain
Source: SOCRadar

PINHOLE retrieves its C2 configuration from Pinterest pins and SurveyMonkey survey questions, a tactic that offers versatility and resilience to take-downs.

The malware leaves a minimal footprint on the host, using shellcode fluctuation to keep only one 4KB section of the payload in memory at a time, and injecting the final assembly into a suspended ApplicationFrameHost.exe process via Early Bird APC injection.

PINHOLE supports 14 commands, including file enumeration, uploading and downloading files, command execution, process management, capturing screenshots, and deploying a module for stealing credentials stored in browsers.

PINHOLE execution chain and supported commands
PINHOLE execution chain and supported commands
Source: SOCRadar

At the time of analysis, the PINHOLE script counted only 11 execution events, suggesting that the campaign was in an early stage.

While abusing FTP banners to deliver commands is a novel alternative, SOCRadar says that the approach is less stealthy than traditional web-based DDRs (e.g., X, GitHub, YouTube) because FTP connections to unknown servers are more likely to stand out.

Advertisement

“While threat actors typically utilize legitimate web services, such as X, GitHub, or YouTube, to provide cover through high-volume, expected network traffic, FTP banners represent a novel alternative.”

The researchers note that the technique is very versatile and could “easily” be adapted for ClickFix social engineering campaigns.

SOCRadar’s report provides indicators of compromise that could help defenders identify the malicious infrastructure as well as infected machines on the network.


article image

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Advertisement

Get the report

Source link

Continue Reading

Trending

Copyright © 2025