We’ve got an AppleInsider staffer inside Amazon’s new drone delivery range. After trying it out on Thursday, we can tell you that it’s effective, and we’re going to use it again.
Earlier this week, Amazon greatly expanded the service area of its drone delivery service. A little napkin math suggests that the airborne delivery service now covers about 3500 square miles more than it did a few days ago.
And, as part of this expansion, one of our staffers is now inside the footprint of that service.
Partly out of curiosity, and partly out of need, he ordered something to be delivered by drone. It wasn’t an iPhone or AirPods, as Amazon suggested, no, but that didn’t seem prudent to try first.
Advertisement
The box the package shipped in
An initial delivery time was given, and Amazon was close enough to that estimate. Delivery was only about 10 minutes later than expected. The drone approached from the north of his location, and buzzed into place.
It hovered for a moment. With a light click, and continued mad hornet buzzing, it dropped the package about four feet, accurately, onto the selected front yard landing zone.
We did see, though, that the package rolled a bit before it settled into place. Your mileage may vary on this, of course, depending on the slope of your yard, the surface it lands on, and the angle of impact of the box.
Advertisement
The drone, leaving, after having dropped its payload.
You get to fine-tune the drop zone on your property when you order, some, but don’t expect it to be precise enough to drop it on a second-floor balcony. It’s probably not wise to bombard your driveway or your roof with your Amazon box.
Time and costs for Amazon Drone delivery
All told, from order to delivery took about an hour and a quarter, with it launching about a half an hour after the order was placed. The box was better packed than most of Amazon’s packages these days, which you’d probably expect since they know they’re dropping it from a bit of a height.
Amazon drone delivery packaging for a very small and light item
Advertisement
Amazon deliveries by vehicle within an hour cost $9.99 in some metro areas. If you can accept delivery within three hours, it’s generally $3.99. This incurred no additional cost, for now, at least.
Limits on shipped items are about five pounds, and the package has to fit in a box about the size of a shoebox, as seen above. Our package contents weigh about the same as an AirPods 4 box.
So far, we’re pretty impressed with this service. We’re also sure there’s going to be incidents of packages rolling under cars and the like.
Plus, you probably want to be home, since the box will be in your yard somewhere.
Advertisement
For now, though, so far, so good. We’ll do it again. Just maybe not with a $1000 iPhone.
In recent months, several Japan Home stores were found to either be closing or turned into Valu$ shops
Is the Japan Home you’ve always walked past seemingly getting less crowded? Or worse, has it shuttered or turned into what looks suspiciously like a Valu$ store?
You’re not imagining it. Stores that were once packed with shoppers hunting for S$2 deals have been thinning out for months.
But now the cat is out of the bag: Japan Home isn’t quietly fading away. Its remaining Singapore stores are being handed over to Radha Exports, the company behind Valu$.
Here’s what’s going on.
Advertisement
What’s really going on right nowis moving fast
Japan Home at Hougang Mall has since closed./ Image Credit: Harold Ng via Google Reviews
Between Jun and Jul 2026, Japan Home announced closing-down sales for five outlets—at Hougang Mall, Century Square, Northpoint City, HarbourFront Centre and Buangkok Square—on its Facebook page.
And when the Business Times visited another nine Japan Home stores on Aug 18, it found three had already shuttered, while several others were closed for “stocktaking.” Significant quantities of Valu$ merchandise were also visible inside some of the outlets.
Japan Home is a retail chain store offering affordable homeware, while Valu$ is a chain of stores that operates via a dollar-store concept.
At Japan Home’s Bedok Mall outlet, which remained open, shelves had already been stocked with Valu$ products alongside its own. At the brand’s Waterway Point outlet, staff were spotted wearing Valu$ T-shirts.
Some other outlets are also reported to have 50% clearance sale signs up or to have Japan Home’s products cleared out.
A Valu$ store manager told the Business Times that Valu$ is not replacing Japan Home, though the evidence on the ground appears to tell a more complicated story. The outlets in Bedok and Woodlands are confirmed as joint operations, and more are expected to follow, said some Japan Home workers.
Valu$ Shop at Paya Lebar Square./ Image Credit: Mokkie Mok
The ownership connection makes the transition less surprising than it initially appears.
Meanwhile, Valu$ is operated by DD Pte Ltd, which was founded by FMCG company Radha Exports in 2005. In other words, Japan Home Singapore and Valu$ are not entirely separate businesses—they are connected through the wider Radha group.
Advertisement
Just yesterday, on Aug 20, Japan Home’s website confirmed that it has licensed the operation of its remaining Singapore stores to Radha Exports, the fast-moving consumer goods company behind Valu$.
The three-year deal takes effect from Aug 19, and is renewable for a further three years—described by the company as part of Japan Home’s “ongoing business development.”
Three consecutive years of declining profits—and now, losses
Japan Home at Heartland Mall, Kovan./ Image Credit: Bryan “Ultimix97” Neo Yang, Eugene via Google Reviews
Before 2024, Japan Home Singapore’s profits had already been declining for three consecutive years. By the financial year ended Apr 30, 2024, revenue had dipped to S$51.7 million from S$53.7 million the previous year.
Then, it tipped from declining profits into actual losses. For the financial year ended Apr 30, 2025, losses after tax from continuing operations almost tripled to S$2.3 million, from S$858,596 the year before.
Existing members were given until Aug 18 to redeem their J-Fun points, J Cash Rebates, and loyalty rewards, after which unused points and rebates expired.
The various states of Japan Home’s outlets all over the island have not been update on its website.
Boasting over 380 branches globally
Japan Home at Lot One Shopping Mall./ Image Credit: Lot One Mall
Founded in Hong Kong in 1991 under parent company International Housewares Retail Company, household retail chain Japan Home was brought to Singapore in 1999 by co-founders Ngai Lai Ha and Peter Lau Pak Fai.
It opened its first three stores in Toa Payoh, Ang Mo Kio, and Bugis Village, and eventually grew to a peak of 34 outlets in Jun 2026. Globally, it boasted over 380 branches, including locations in Macau, Cambodia, Eastern Malaysia, and Australia.
Advertisement
Inspired by Japan’s 100-yen shop concept, Japan Home aimed to source affordable housewares, sell them at accessible prices, and make shopping for daily necessities.
For weeks, the Singapore situation played out almost similarly to the way Hong Kong’s did a year earlier: closures without a clear explanation, staff giving conflicting accounts, and a company staying quiet.
Back in Jul 2025, concerns about a possible shutdown of Japan Home in Hong Kong circulated on social media, after several customers reported seeing 50% discounts advertised across branches as part of renovation clearance sales. Adding to the speculation, shoppers at multiple locations also spotted “lease expired” notices posted in stores, according to reports covered by on.cc and HK01.
Despite denying closure rumours, the financial performance of Japan Home’s parent company told a more difficult story. International Housewares Retail Company issued a profit warning in Jul 2025, forecasting a 51% to 57% decline in annual profits compared to the prior year’s HK$100 million (S$16.21 million).
The group mainly attributed the decline to weak consumer sentiment, changing purchasing behaviours, and, more pointedly, competition from mainland Chinese e-commerce platforms, which have collectively led to a 5.6% year-on-year decrease in revenue. That said, it still remains profitable, making HK$47.727 million (S$7.73 million) for FY 2024/25.
Feeling the pressure of Chinese rivals
Kitchen racks can be found for under S$10 across Taobao, Pinduoduo and Shein, which likely cost more at Japan Home due to operational, rental and manpower costs./ Image Credit: Vulcan Post
Japan Home’s value proposition was always about price and convenience: affordable, decent-quality housewares that one could pick up at a mall near where you live. And that model had no real challenger for most of the 2000s and 2010s.
A physical housewares store like Japan Home minimally charges you for the rent, the staff, and the logistics of getting products from a factory in China to a shelf in Tampines.
But ordering from an online platform charges you for a fraction of that since they don’t have to deal with the high rental, operational, and manpower costs prevalent in Singapore’s retail scene. When the price gap becomes too obvious to the customer and the ordering process becomes frictionless, the heartland housewares store would naturally lose its market share.
Surviving Singapore’s increasingly brutal retail scene
Isetan and Daiso were formerly at Tampines Mall and Tampines 1./ Image Credit: Matthew Chia via Google Reviews, Daiso Singapore
Japan Home’s difficulties aren’t happening in isolation. Singapore has seen a broader retreat of Japanese-style affordable retail over the past year:
It’s pretty evident that these Japanese brands built on affordable, middle-market physical retail are squeezed from below by e-commerce and from above by mall rental costs that haven’t adjusted to lower footfall.
For Singapore shoppers who grew up with Japan Home as the default stop for a cheap chopping board or a new set of dish towels, the transition marks the end of a special kind of heartland retail.
Whether Valu$ can fill that space under the Japan Home name for the next three years or whether this 100-yen concept will join other precedents of Japanese retail in Singapore and downsize or bite the dust is a question only time can answer.
Read other articles we’ve written on Singaporean businesses here.
YouTube Premium appears to be getting more expensive again, with subscribers in several countries reporting fresh price increases. Singapore has the clearest confirmed change so far, while Android Authority reports higher prices showing up in parts of Europe. The latest reports follow another recent YouTube Premium price hike in the US.
In Singapore, The Straits Times reports that an individual subscription is rising from S$13.98 to S$15.98 per month, while the family plan jumps from S$27.98 to S$31.98. New subscribers are already paying the higher rates, while existing members will see them take effect after at least 30 days.
Elsewhere, the picture is less certain. Subscribers in several European markets are reportedly receiving emails showing higher prices, but YouTube hasn’t published a wider list of affected countries or new rates.
Where prices are going up
The Singapore increase shows this isn’t purely speculative, but the wider pattern is still being pieced together from regional reports and subscriber notices.
Advertisement
That makes the scope hard to pin down. A hike reported in one country doesn’t necessarily tell you what another market will pay, and the changes can vary depending on the plan. YouTube has also recently raised the price of YouTube Music Premium, adding to the sense that its subscription pricing is moving upward more broadly.
If you already subscribe to Premium, your billing email may be the first reliable sign that your price is changing.
Why this rollout is messy
Without a broader announcement from YouTube, there’s no single place to check which markets are affected. Users are instead relying on local reports and individual notices.
The reported increases also don’t appear to follow one universal jump. That makes it difficult to compare countries or predict what a subscriber elsewhere might end up paying.
Advertisement
Unsplash
The evidence, however, points to another round of increases rather than one clearly defined global change.
What subscribers should watch next
The safest move is to keep an eye on your next YouTube Premium billing notice or email. Until YouTube publishes something broader, that will likely be more useful than assuming every country is changing at once.
A higher monthly bill can also change how easy Premium is to justify, especially if you’ve been letting the subscription renew automatically. If the increase reaches your market, it may be worth comparing the full plan against YouTube Premium Lite before the next renewal.
For now, the clearest signal will be what YouTube tells subscribers directly in each affected market.
Authorities gave them permission to deploy thousands of robotaxis in Clark County.
Waymo
You’ll start seeing a lot more taxis in Las Vegas with no human driver behind the wheel over the coming year. The Nevada Transportation Authority has approved Tesla’s, Waymo’s and Uber’s applications for an Autonomous Vehicle Network Company permit, which gives them the authority to offer paid rides in Clark County, including Las Vegas. Tesla investor Sawyer Merritt has reported that Nevada officials gave Tesla permission to deploy up to 5,000 robotaxis over the next 12 months after their August 20th meeting.
The company’s permit reportedly allows it to operate across the entire state, provided it notifies the agency that it’s expanding its coverage. According to the Q&A with Tesla during the session, the company is working with law enforcement to shoot a five-minute step-by-step video first responders can follow for emergencies involving its autonomous vehicles. The company also said that 5,000 is just the max number of robotaxis it’s allowed to deploy, and that it would be “extremely happy” if it could get 2,500 robotaxis on the streets of Nevada by 2027.
Meanwhile, Waymo has received permission to deploy 1,000 robotaxis in the region over the next year. Authorities allowed it to ditch human riders and go fully autonomous in Las Vegas back in July, but with this new permit, the company can now charge for its rides.
Advertisement
Sarfraz Maredia, the global head of Autonomous Mobility & Delivery at Uber, has announced that the ride-hailing company’s application to offer paid robotaxi rides in Nevada has been approved as well. Uber will also be able to deploy 1,000 robotaxis in Clark County, which it will operate with Amazon’s Zoox and Hyundai’s Motional.
A 15-year-old from New Jersey has dropped her case against Meta, Google, and Snap seven weeks before it was due to be heard in Los Angeles. Her lawyer said she wanted to get on with her life.
The case was one of three bellwethers set for trial in October in California state court, chosen to test claims that the companies designed their products to be addictive to minors. TikTok had already settled its part before the dismissal, which is how TikTok has handled every one of these so far.
All three remaining defendants confirmed that the plaintiff, identified in filings as P.M-Y., received no payment in connection with dropping her claims.
Her attorney said she had brought the case to hold the companies to account and then chose to dismiss the remainder of it out of a desire to resume her life. That is the entire stated reason, and none of the parties has offered another.
Advertisement
The defendants read it differently, as defendants do. Meta said the plaintiff had a significant mental health condition that predated her use of social media; YouTube said the outcome affirms its longstanding position that it provides safe and age-appropriate experiences, and Snap pointed to its work on safeguards, tools, and educational resources.
This is the second time a bellwether plaintiff has walked away shortly before trial. In July, a 15-year-old from Panama City withdrew his claims days before a Los Angeles jury was due to hear them, also without payment from Meta.
Two teenagers with similar claims against the same companies are still scheduled for October. Losing one of three test cases does not collapse the wider litigation, which involves thousands of individual claims consolidated in California and in federal court.
It does remove a data point the plaintiffs’ side wanted. Bellwethers exist to give both sides a price, and each one that ends without a verdict leaves the eventual settlement value less certain than it was.
Advertisement
What the plaintiffs already have is a win. In March, a California jury found Meta and Google liable in the first of these trials, awarding $4.2m against Meta and $1.8m against Google, figures small in themselves but significant as a finding of liability.
The companies have appealed the legal foundations of the litigation without success. The Ninth Circuit allowed roughly 2,400 addiction lawsuits to proceed without disturbing Section 230, which left the design-defect theory intact and the cases heading for juries.
Design defect is the pivot the whole thing turns on. The plaintiffs are not arguing about what users posted, which Section 230 protects, but about infinite scroll, autoplay, and notification systems, which they say are product features and therefore subject to ordinary product liability law.
Meta is simultaneously defending itself in Oakland against four state attorneys general on overlapping claims, in a trial that opened this week and is expected to run for about six weeks.
Advertisement
Nobody has explained why two bellwether plaintiffs in a row have chosen to stop. Litigation of this kind requires teenagers to give depositions about their own mental health and then be cross-examined on it, which is a considerable amount to ask of anyone, let alone at 15.
The consolidated litigation is unusually large. Thousands of individual claims sit in a California state court proceeding and a parallel federal multidistrict case, alongside suits brought by school districts and by more than 30 state attorneys general.
Settlement is where most of it will end, as it did for TikTok, which has never let one of these reach a jury. The price of that settlement is what the bellwethers were meant to establish, and two of them have now produced nothing to price against.
The October trial date holds for the remaining two, but the companies have not indicated whether they intend to settle those as well.
Of all the things I thought the Trump administration would cause to enter the public lexicon, I certainly did not have screwworms on my list. If you somehow haven’t heard of this, screwworms are actually a fly that lays its eggs by burrowing into the flesh of other animals. Those animals are mostly cattle, sometimes household pets, and even occasionally humans. It’s a horrific experience and can lead to death in a few weeks. We used to have an international monitoring program in Mexico through USAID designed to stop the problem at the source before it ever gets to America, but Elon Musk’s DOGE did away with that program, citing it as unnecessary. Well, now screwworms are back in Texas and surrounding states, and they put at risk $2 billion in potential damage to the Texas economy alone. It’s bad enough that this particular administration has decided to pull drones from patrolling the southern border for scary illegal brown people to instead hunt for evidence of screwworm infection in domestic cattle.
But if you don’t think all of that is bad enough of a look for what DOGE and the administration did to cause this, what if we had thousands of dead puppies and kittens in the news instead?
Adoptions are on hold for thousands of dogs and cats in Texas, potentially putting the animals at risk of being euthanized, because of efforts to stop the spread of the New World screwworm, an insect that has crossed the border from Mexico into the United States for the first time in 60 years.
“It’s thrown a wrench into things, for small rescues as well as the bigger shelters,” said Mia Bendixsen, executive director of the Texas Humane Legislation Network, which promotes animal welfare laws.
The screwworm can lay eggs that hatch into flesh-eating larvae in wounds or mucous on any mammal, and of the dozens of infections in southern Texas and southeastern New Mexico, several have been in dogs. Forty-four states have restricted the movements of pets from infested areas, creating a hardship for shelters from Texas that typically send thousands of animals to other states each year.
Advertisement
There are several factors at work here, combining to risk the live of thousands of good boys and girls at these shelters. The screwworm issue is one of them. Another is that Texas is notorious for having low spay and neuter rates for pets and, specifically, working animals. Dogs in particular tend to be left in their natural state because ranchers somehow think that spaying or neutering them will decrease their drive to work.
Whether that’s actually true or not I can’t really say, but the fact is that sentiment was around long before this year and it’s the screwworms that are causing a major uptick in unadopted animals in Texas. And the euthanizing of thousands of animals would be just one of many consequences of us choosing actively to let screwworms become an American problem again.
Restrictions on animal transports followed efforts by the U.S. Department of Agriculture to keep the New World screwworm fly from crossing the border with Mexico.
Those efforts include construction of a $750 million fly factory in southern Texas for breeding billions of sterile males set to open in April 2027. The U.S. had largely eradicated the fly by the early 1970s by breeding sterile males and releasing them from planes to mate with females, who laid eggs that wouldn’t hatch.
Smaller facilities in Texas and southern Mexico have been dispersing sterile flies bred in Panama, and another is planned for Arizona.
Advertisement
When it comes to this particular issue, it’s obvious that there were no taxpayer cost savings due to DOGE’s fuckery. If anything, it seems like we’ll be spending more money to remediate the problem than we did keeping it from becoming one.
And when you layer on the dead bodies of thousands of cats and dogs on top of it all, well, it’s quite a legacy for Musk and his DOGE bros to leave behind.
China’s Chang’e 7 mission is set to launch for the moon’s south pole, where it will attempt the first-ever landing directly at the pole and search the region’s dark craters for water ice. “It’s an amazing mission,” says Norbert Schorghofer, a Hawaii-based senior scientist at the Planetary Science Institute. “There has never been a landed mission to find water [on the moon].” If successful, China “will be the leader in lunar science,” Schorghofer adds. Scientific American reports: Chang’e 7, China’s seventh moon mission, is scheduled to launch on a Long March 5 rocket from the coastal Wenchang Space Launch Site on the island of Hainan, with the launch window opening on the morning of August 24 local time (the evening of August 23 EDT). The mission includes an orbiter, as well as a lander, which totes a rover and a novel “hopping” robot. The spacecraft will take up to six days to reach lunar orbit, where it will then spend two months preparing for a November landing meant to be a near bull’s-eye on the lunar south pole. The mission also includes equipment from several international partners, highlighting China’s growing global influence — both on and off Earth.
The mission’s lunar target is Shackleton Crater, a 21-kilometer-wide (13-mile-wide) pit with a rim that grazes the moon’s south pole. No other spacecraft has ever landed so close. That proximity should allow Chang’e 7 to prospect for water ice trapped in smaller depressions near Shackleton that, because of the moon’s tilt, never see sunlight and have temperatures just a few dozen degrees above absolute zero. “There are big reservoirs of ice water at the poles,” says Simone Dell’Agnello, a physicist at Italy’s National Institute for Nuclear Physics.
No one knows, however, just how big those reservoirs are or what their actual distribution is across the lunar south pole’s crater-pocked desolation. And because that ice might be used as for manufacturing rocket fuel or to make potable water for thirsty astronauts, answering those questions is key for the U.S.’s and China’s competing plans to construct crewed lunar outposts.
The UK government has six months to decide whether to terminate a deal worth more than $400 million between the country’s National Health Service and American software company Palantir. If one part of the NHS is already doing without Palantir, politicians are asking, why can’t the rest of the country?
In 2023, the UK commissioned Palantir to develop a “federated data platform” (FDP) that could ingest and organize the tangle of health data produced across the country. According to Palantir and the NHS, the new system is already cutting wait times and the length of hospital stays, and maximizing the use of operating theatres.
The health care board for one part of England, Greater Manchester, has repeatedly declined to adopt Palantir’s FDP, choosing to stick with a home-spun platform developed over the best part of a decade. The board claims it doesn’t need Palantir, that its own platform is functionally superior and more trusted by the public. “[Even] a technically strong platform will struggle to realize value if clinicians, data controllers, patients or the public do not trust it,” Matt Hennessey, chief data and analytics officer at NHS Greater Manchester, tells WIRED. “If we were to fully adopt the FDP … it would be a retrograde step.”
Advertisement
That claim—disputed by Palantir and other FDP advocates—has fed into a national debate over whether the government should seize an opportunity next February to terminate the NHS contract early, instead of allowing it to run until 2031.
For decades, NHS workers have used a combination of digital systems, spreadsheets, paper, and whiteboards to keep track of patients. Sometimes, when a patient moves from one care setting to another, their treatment records are left behind with occasionally deadlyconsequences. Without a way for different types of care providers to share information effectively, NHS administrators have had to base funding and resource allocation decisions on an incomplete patchwork of data. Palantir’s FDP is meant to change all that.
The NHS began to roll out the FDP in early 2024. The platform consists of a national pool of health data meant to help identify care deficiencies, and a bunch of local databases that individual regions can use to perform analyses and develop tools specific to their needs—say, waitlist management or discharge planning. The various components all share the same underlying technology scaffolding, in theory making it possible for tools developed in one corner of the country to be readily adopted in another.
“You can lift and shift. That’s the real power of the FDP,” says Tom Bartlett, an independent IT consultant who previously oversaw the national-level FDP rollout as deputy director of data engineering at NHS England. “The other advantage is that you’ve got a surface for artificial intelligence to work across.”
Advertisement
Within the sprawling NHS, two types of organizations can access the FDP: trusts that run hospitals and local care, and integrated care boards (ICBs), responsible for planning and commissioning health care services at a regional level. Both use data for different purposes, but share the ultimate goal of improving patient care.
One remains a pillar of Linux, while the other keeps the BeOS dream alive
This is a quiet time of year in tech circles – perhaps explaining why, 25 and 33 years ago, the people behind two ambitious operating system projects kicked them off.
Debian
Last weekend, the Debian project turned 33 years old. The Linux kernel first appeared in September 1991, so it was not quite two years old when Ian Murdock announced the new distribution. (Indeed, the term “distribution” itself hadn’t really caught on yet – his announcement only uses the word as an adjective.) Sadly, Murdock died in 2015, before his project became one of the world’s most widely used forms of Linux in the world.
Advertisement
We examined the project’s history and success when it turned 30, and it continues to thrive.
It’s not the oldest maintained distro: that distinction goes to Slackware, which is about a month older – it turned 30 that July. Slackware remains actively maintained, although it has not produced a new release in a while. The Register’s own Slackware enthusiast Richard Speed looked at version 15.0 back in 2022. Since then, we have had Debian 12 in June 2023 and Debian 13 a year ago.
And in case you’re curious, as far as this vulture can see, the first release The Reg covered was Debian 2.1 in 1999.
Haiku beta beckons
Meanwhile, the Haiku OS project keeps on going. The Desktop on Fire blog celebrated with an article on 25 Years of Haiku.
Advertisement
Its development was prompted by Palm buying Be in August 2001, as The Registercovered at the time. A couple of days later, an email modestly titled “OK, let’s start” set the OpenBeOS project in motion, as this history of project milestones describes.
Doubters might note that after a quarter of a century of work, there’s still been no Haiku OS 1.0 release. Fair, but this is not a Linux distro – it is an entirely new OS built from the ground up. Although it now boasts impressive Unix compatibility, it remains quite different: for a start, it is written in C++ rather than C, and its 32-bit x86 version is also BeOS binary compatible. That matters less today, however, because Haiku has developed a substantial software catalog of its own.
The latest activity report from Haiku’s dedicated paid developer “Waddlesplash” discusses the possibility of a new version any time now: “Are we beta6 yet? We have a definite release timeline now: a branch should be made by the end of this week, with a target release date of mid-August. Keep an eye on the forums for details to come about how you can help test!”
Never mind the version number: the project continues to make impressive technical progress. A PowerPC port has been in the works for more than five years, and in July YouTuber ActionRetro demonstrated an AI-assisted build running on the architecture. This joins a preliminary Arm64 port that was demonstrated back in May.
Advertisement
Not Haiku, but adjacent
Several Haiku-adjacent projects are also making progress. The cross-platform BeOS-derived programming toolkit Cosmoe, which we covered in June 2025, is still in active development. Its source code is available on GitLab, and it now builds and runs on Linux, Windows, and macOS.
Another project with overlapping goals, although no apparent direct relationship to Cosmoe, is VitruvianOS. V, as the team calls it for short, is a port of the Haiku display server and desktop to run on a Linux kernel.
Porting the BeOS desktop onto a Linux kernel has been tried before – the first such effort we saw was called BlueEyed OS, back in 2003. V seems to be unconnected with either BlueEyedOS or Cosmoe, but it’s making impressive progress all the same.
However, V is making headway. Since its public debut, the project has produced another half-dozen releases: it is now up to version 0.6.0, which gets considerably further in our testing – it boots to a very Be-like startup screen, with a language selection dialog and the choice to run a live environment or start installation. Sadly, that’s as far as we can go.
The idea certainly has potential. Linux has enviable hardware support now, and given the rivalry between X11 and Wayland, we admire how V sidesteps the dispute: it does not attempt to be either. Instead, it replaces both with a new system based on BeOS’s clean design from 1995 – when the original XFree86 Linux X11 server was only about three years old. ®
Office printers usually sit there doing their quiet job of putting toner on paper. One Samsung C410W now spends part of its time generating infinite blocky terrain and letting players dig, build, and chat across a local network. The project belongs to a maker known as vimpo, the same person who previously convinced a Wi-Fi light bulb to host a Minecraft world.
After a poll of regular visitors revealed that printers were the most popular choice, the quest began for a networked machine that was ancient but still had valuable debugging tools and was modern enough to communicate with an Ethernet network. The C410W printer met the requirements. It’s a tiny color laser printer from the mid-2010s that still includes wifi and has a firmware revision from December 15th, 2015 (V3.00.02.20).
Portable Wireless Printer – The ETIKEZ D90E is an inkless printer and portable printer that uses advanced thermal technology, requiring no ink, toner…
Bluetooth & USB Connectivity – Connect this D90E portable printer to iPhones or Android via Bluetooth. This wireless printer also works with PC over…
Multiple Printing and Format – The wireless portable printer supports 8.5″ x 11″ US Letter thermal paper (B0GD61HPDC, B0GD5JFC2Q). It meets all your…
Opening the case revealed a leftover debug serial port, which the manufacturers must have kept in there. The first step was to plug in a USB to serial converter and launch a terminal program to see what was going on behind the scenes. Soon, some standard commands appeared that weren’t really helping much, but pushing the escape key prompted a memory dump instead. Reboot messages described the heap and stack layouts, and the entire 23 megabytes of RAM spilled out into a disassembler for us to work with.
An AI agent spent over 12 hours churning away at labeling functions and trying to figure out where a program was crashing, but in the end it just helped map out the code since it couldn’t find a way to operate the printer. Manual investigation of an obscure other residual protocol proved effective. The printer still had an old port 7000 open, which was reserved for something called the LAN Test Protocol, a manufacturing tool that received XML messages regardless of their size. So he put the payload into one that was just a little too big, which overwrote the buffer, overwrote the program counter, and redirected execution to a known function that flashed the status lights. Once that basic step was completed, the same procedure could be followed to get custom code running on the printer.
He was running UCraft, a Minecraft server created specifically for devices with limited memory and computing capability. It’s a tiny binary file, at about 46 kilobytes without requiring the user to sign in, and it consumes about 50 kilobytes of memory for a single player. It just about manages to get enough of the protocol sorted so that clients can join in, walk about a procedurally created terrain, punch blocks, and send text messages. By design, it excludes many of the complete vanilla features. The server is compatible with more modern Java Edition clients, and it previously ran on a light bulb microcontroller.
Once you’ve gotten beyond the overflow, the printer’s lights begin to flicker, and a Minecraft world appears at the device’s local IP address. One person can go in and look around, but it’s a sluggish process because chunks take a long time to load and the printer’s small processor is under strain. When you add extra players, the game lags and print jobs crash because the CPU is overloaded.
It is also worth noting that anyone with the same C410W printer and firmware can reproduce the entire thing because the exploit and server code are all available in public repositories. So all you have to do is obtain the necessary equipment and software to get it up and running, and then be willing to put in the time to set it up in the first place. When all is said and done, you end up with a working, if rather problematic, multiplayer universe running inside a device that was initially designed to simply print out words and images on paper. [Source]
Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances.
The most severe of the two, tracked as CVE-2026-19490, can allow remote attackers without privileges to bypass authentication when the appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the NetScaler firmware version and whether SAML Action is configured.
Admins can check if an appliance is vulnerable to attacks targeting CVE-2026-19490 by inspecting their NetScaler configuration for SAML action configuration (add authentication samlAction .*) string and Auth or VPN vserver (‘add authentication vserver .*’ and ‘add vpn vserver .*’) strings.
The second, a high-severity memory overflow security flaw tracked as CVE-2026-19489, can be abused by remote unauthenticated threat actors in denial-of-service (DoS) attacks when SIP ALG (Session Initiation Protocol Application Layer Gateway) is enabled on a large-scale NAT group configuration.
Security teams can determine whether Citrix NetScaler appliances on their network meet the preconditions for CVE-2026-19489 exploitation by inspecting their configuration for the “add lsn group.*sipalg.*” string.
Advertisement
Citrix advised customers to upgrade vulnerable NetScaler ADC and NetScaler Gateway appliances to:
NetScaler ADC and NetScaler Gateway 14.1-73.32 or later,
NetScaler ADC and NetScaler Gateway 13.1-63.21 or later,
NetScaler ADC FIPS 14.1-73.32 FIPS or later,
or NetScaler ADC FIPS and NDcPP 13.1-37.277 or later, as applicable
“The bulletin applies to supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds. SecurAccess ZTNA Hybrid (formerly Secure Private Access Hybrid) deployments that use customer-managed NetScaler instances are also affected and should be upgraded to the recommended builds.”
CISA added the CVE-2026-3055 vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on March 30 and ordered federal agencies to secure vulnerable Citrix appliances within three days.
Advertisement
Over the last five years, the U.S. cybersecurity agency has flagged 22 Citrix vulnerabilities as exploited in the wild, six of them also abused in ransomware attacks.
The ShadowServer Foundation now tracks over 22,000 NetScaler ADC and nearly 1,800 NetScaler Gateway instances exposed online. However, it does not provide information on the number of honeypots or how many may be vulnerable to attacks targeting CVE-2026-19489 and CVE-2026-19490.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
You must be logged in to post a comment Login