Connect with us
DAPA Banner
DAPA Coin
DAPA
COIN PAYMENT ASSET
PRIVACY · BLOCKDAG · HOMOMORPHIC ENCRYPTION · RUST
ElGamal Encrypted MINE DAPA
🚫 GENESIS SOLD OUT
DAPAPAY COMING

Tech

AryStinger botnet infected thousands of D-Link routers worldwide

Published

on

Botnet

A previously undocumented malware botnet named AryStinger has compromised more than 4,000 outdated routers to turn them into proxies for malicious traffic.

Researchers at Qianxin’s XLab threat intelligence team say that the malware converts infected devices into remotely controlled “executors” that can perform scanning, proxying, tunneling, command execution, and other activities on behalf of the attacker.

“The attacker can split a massive scanning task into multiple small chunks and distribute them to different Executors for parallel execution,” XLab researchers note.

image

“With this distributed-like design, the attacker can efficiently complete the early “footprinting” activities, thereby providing strong assurance for the smoothness and success rate of subsequent intrusion operations.”

Apart from using compromised routers as a springboard for malicious operations, XLab warns that the malware can also tamper with DNS settings, hijacking the user’s browsing, and silently monitor and potentially steal all inbound and outbound network traffic.

Advertisement
Server distributing AryStinger scan jobs
Server distributing AryStinger scan jobs
Source: XLab

AryStinger exploits older flaws such as CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837, targeting primarily D-Link DIR-850L, D-Link DIR-818LW routers.

The two router models were previously targeted by the AVrecon malware botnet that Lumen communications services provider Lumen disrupted in 2023.

Qianxin’s telemetry data shows that almost half of all infections are located in South Korea (48.5%), followed by China (31.8%), Sweden (6.4%), Malaysia (3.5%), and Singapore (2.5%).

XLab researchers found two variants of the AryStinger malware: a C-based version targeting mostly outdated routers, and a Go-based one that focuses on NAS systems, but currently with a far more limited reach.

Infected router establishing C2 communication
Infected router establishing C2 communication
Source: XLab

The NAS version is the most advanced of the two, featuring additional capabilities such as IP and DNS scanning, command execution, payload execution, and internal network reconnaissance through the integration of open-source penetration testing tools.

The researchers noted that AryStinger’s distributed DNS-scanning infrastructure could potentially be repurposed to generate large volumes of DNS queries against resolvers, although they did not observe any such attacks.

Advertisement

Regarding the NAS version’s code execution capabilities, XLab says there’s support for Shell commands, as well as Go, Java, and Python source code.

However, there are some limitations to using source code instead of compiled binaries, as compilation requires language runtimes on the host, and the process as a whole introduces noise that can break stealth.

The researchers did not attribute AryStinger to any known activity cluster, stating that “many mysteries surrounding AryStinger remain to be solved.”

Owners of end-of-life (EoL) routers should replace them with new, actively supported models, apply the latest available firmware updates, change the default administrator account password, and disable remote management panels.

Advertisement

article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

This Tabletop Machine Turns Scrap Plastic Into Working Pens

Published

on

Desktop Plastic Recycler Machine DEGO Pens
Most people toss broken baskets, empty food tubs, and leftover packaging without a second thought. Brothers Make decided to keep a pile of that material and feed it into a compact new machine called the DEGO. In one afternoon they turned the scraps into a set of usable pens, complete with unintentional swirl patterns, even when the colors refuse to stay neat.



The DEGO plastic extruder is the creation of plasticpreneur, an Austrian business that has spent years refining large recycling equipment for workshops and schools, but this new version is small enough to fit on a workbench at home. Weighing around 20 kilograms and measuring approximately 21cm by 55cm by 39cm, all you have to do is plug it in, put on a mold, and you’re ready to begin. A built-in fume extraction mechanism directs any unpleasant vapors directly through a filter, keeping the entire arrangement more cleaner than prior open versions.

Sale


Bambu Lab A1 mini 3D Printer + LED Lamp Kit, Set Up in 20 Mins, High Speed & Precision, Full-Auto…
  • A1 mini + LED Lamp Kit for Creative Light Projects: Bring your ideas to life with the included LED Lamp Kit. Simply print compatible lamp models and…
  • The Perfect 3D Printer for Beginners: A1 mini 3D Printer is designed to make 3D printing easy from day one with automatic calibration, simple setup…
  • Experience the Bambu Lab Ecosystem: Access MakerWorld’s huge library of ready-to-print models, manage prints through the Bambu Handy app, and enjoy…

For those who like simplicity, the process is straightforward: shovel chopped-up plastic flakes in from the top and turn the hand crank. The crank cranks a screw inside a heated barrel, pulling the flakes forward, melting them down with friction and electric heat, and pushing the gooey plastic out the front nozzle. Put a mould on the nozzle, keep rotating the handle, and the cavity will fill; once finished, just open the mold, pull out your freshly created pen, and start again. The guys in the video built a bunch with a pen barrel mold and were churning them out one by one in only a few minutes.

Advertisement

Desktop Plastic Recycler Machine DEGO Pens
They were largely experimenting with high-density polyethylene, the hard plastic used in laundry baskets, chocolate tubs, fishing rope, marker cases, and cracker containers. Each type of plastic had its own distinct color; a pale yellow-green basket looked great paired with bright red tubs, teal rope contrasted nicely with black pen barrels, and orange cracker packaging was a beautiful addition to the mix. They also added some white flakes for a little more contrast here and there. Because of the way the screw mixes the plastic, it is uncommon to achieve pure color blocks. Instead, you’ll see nice streaks, marbling, and delicate color transitions as you walk from one piece to the next.

Of course, there is still some preparation to be done before you can begin. You’ll need to remove any stickers and cut up any large pieces of plastic with scissors, shears, or a guillotine, and having a dedicated shredder to speed up the process is a major help, but the DEGO itself can run on plain old plastic flakes with no extra processing. Once the material is clean and dry, the machine does the rest, as the temperature is high enough to melt the plastic smoothly while remaining low enough not to burn most common varieties. It’s still a manual process, which keeps the learning curve low and safety concerns at a minimum.

Desktop Plastic Recycler Machine DEGO Pens
The base model will cost roughly 3500 euros, with additional molds for pens or carabiners costing slightly more. When compared to a full industrial extruder, the DEGO is a bargain. It takes up almost no space, requires no compressed air or fussy hydraulics, and can be up and operating in a matter of minutes. Cleanup is a breeze; simply pass any residual material through till the barrel is empty.

Source link

Advertisement
Continue Reading

Tech

Keychron Q6 HE 8K Review: Specs, Features, Price

Published

on

The Keychron Q6 HE 8K is a solid mechanical keyboard with magnetic switches. While it’s not cheap, it’s got more than enough to give a great typing experience on Mac.

When it comes to mechanical keyboards, Keychron stands out as one of the industry leaders. All thanks to its vast array of styles, colors, and features aimed at both Windows and macOS users.

The Keychron Q6 HE 8K is a beefy new release, and I put it through an extended test drive in my ongoing series of reviews of Keychron products. It’s an ever-continuing search for the mechanical keyboard that will earn a permanent position on my workspace.

The Q6 HE 8K is a full-size magnetic switch mechanical keyboard with an 8K polling rate that supports a direct wired connection. It has a staggering variety of customizations.

Advertisement

Keychron Q6 HE 8K Review: Specifications

  • Size: 137 x 446mm
  • Front Height: 20.6 mm (without keycaps)
  • Back Height: 31.37 mm (without keycaps)
  • Feet Height: 1.24mm
  • Angle: 5.26 degrees
  • Weight: 2,268g +/- 10g
  • Body Material: Aluminum
  • Keycap: OSA double-shot PBT keycaps
  • Plate Material: Aluminum
  • Switch: Keychron Ultra-fast Lime Magnetic Switch
  • Stabilizer: Screw-in PCB stabilizer
  • Backlight: South-facing RGB LED
  • Compatible System: macOS/Windows/Linux
  • Operating Environment: -10 to 50C
  • Connectivity: Type-C Wired
  • Polling Rate: 8000 Hz / 4000 Hz / 1000 Hz
  • N-Key Rollover (NKRO): Yes
  • Rapid Trigger: Yes
  • Sensitivity: 0.01 mm
  • Adjustable Actuation Points: 0.1 – 3.35mm
  • Dynamic Keystrokes: 4-in-1 action keys
  • Hot-Swappable: Yes, compatible with Keychron Ultra-fast Lime Magnetic Switch only.
  • MCU: 1MB

Keychron Q6 HE 8K Review: Unboxing

The Q6 HE 8K arrives in a standard black box with a metallic Keychron logo. The keyboard and accessories are packaged in heavy foam cutouts for maximum travel safety.

  • 1x Fully Assembled Keyboard
  • 16x Gaskets (12 Installed and 4 in the Box)
  • 8 sets x Stabilizers
  • 1 set x Keycaps (PBT Double-shot)
  • 1 set x Magnetic Switches
  • 1x Type-C Cable
  • 1x Type-A to Type-C Adapter
  • 1x Keycap & Switch Puller
  • 1x Screwdriver
  • 1x Hex Key
  • User Guide

Keychron Q6 HE 8K Review: Build Quality

The Q6 HE 8K is a full-size mechanical keyboard with a metal case. Even by the industry standards for a keyboard of this size, I was surprised by the sheer weight and feel of it.

This is a very beefy keyboard that will easily withstand the rigors of daily use, at stationary or mobile workspaces alike.

Keychron offers the Q6 HE 8K in two colors: Black or white. That’s it.

Compact mechanical keyboard with light gray and white keys, dark gray modifier keys, and a single dark blue Escape key in the top left corner on a white surface

Keychron Q6 HE 8K Review: Left side with Mac keyset

Advertisement

This is a recurring theme with Keychron and their keyboards, and I have written about it in the past. But with the amazing quality of its keyboards, I would love to see it expand its range of colors.

I’ll be the first to admit I do not know its manufacturing limitations with such meticulously engineered products. But even so, the occasional red, blue, green, or pink would be welcome in this age of colorful workspaces and peripherals.

The Q6 HE 8K arrives with the proprietary Keychron Ultra-fast Lime Magnetic Switches as standard. Keychron sells Banana and Silent Red switches on the Keychron website for an added cost of $29.99, depending on the type of sound level or tactile feel you prefer.

Keychron products never feel cheap or like an afterthought. Every keyboard it makes uses premium materials and engineering built to last for years.

Advertisement

The Q6 HE 8K is certainly no exception. From the heavy aluminum case and double-gasket design to the double-shot keycaps, PCB stabilizers, adapters, and tools, everything in the box feels like bespoke, white-glove service.

Side view of a compact mechanical keyboard showing USB-C port, Win/Mac switch, three-position toggle switch, and white keycaps with one highlighted purple key in the top right corner

Keychron Q6 HE 8K Review: Rear has USB-C and two control switches

The back of the Q6 HE 8K includes a USB-C port for connection and use. There are two switches next to the USB port.

One switch is a three-position switch to toggle between up to three potential keyboard configuration profiles. The second switch moves between default macOS and Windows configurations.

Advertisement

Keychron Q6 HE 8K Review: Customization

The Q6 HE 8K has a wide variety of customization options, including third-party keycaps and remapping variations available from Keychron’s proprietary Keychron Launcher tool. The pool of possibilities is very deep.

Keychron touts that the Q6 HE 8K is truly customizable from top to bottom, and it is. By default, Keychron includes keycaps for both macOS and Windows configurations.

The switches on the Q6 HE 8K are hot-swappable, with Keychron noting that hot-swapping works with Keychron Lime and Gateron Jade magnetic switches.

The new Keychron screw-in PCB stabilizers deliver incredible stability on the big keys, namely the space bar, shift, enter, and delete. The installation is quick and easy for experienced users and mechanical keyboard newbies alike.

Advertisement
Keychron keyboard configuration software interface showing top view of keyboard layout and bottom panels for setting actuation distance, rapid trigger sensitivity, trigger debounce, and user macros on a dark theme

Keychron Q6 HE 8K Review: Managing the actuation distance in the Keychron Launcher

The south-facing RGB lights on the Q6 HE 8K are vibrant and fully customizable to each individual key, using Keychron’s Per-Key RGB feature. The contrast of the bright lights against the white metal body and keycaps makes everything pop.

Keychron’s Launcher tool is web-based, and it allows you to adjust almost everything. Adjustments span keymapping, the internal RGB light configuration, and adding custom macros for use with the Q6 HE 8K.

Previous versions of the Keychron Launcher did not play well with macOS and several browsers. The process is incredibly smooth now. It’s nice to see a manufacturer like Keychron listen to the concerns of their customers and address them.

Advertisement

Keychron Q6 HE 8K Review: In use

I used the Q6 HE 8K for several weeks prior to writing this review, and it was the best Keychron experience I have had to date. That is, in a line of good Keychron experiences.

On my standard workspace layout, I use a digital pen display and stylus with my right hand. A wireless, low-profile keyboard is used by my left hand for key commands.

I need to move the tablet and the keyboard around often throughout my workday. I find most full-size keyboards to be cumbersome in this space, but despite its size, weight, and wired connection, the Q6 HE 8K handled the job incredibly well.

Close-up of a light gray mechanical keyboard showing number pad, navigation keys, and a few dark blue keys, on a white background

Keychron Q6 HE 8K Review: Right side with numpad and knob

Advertisement

I’ll admit, I tested this as my work keyboard only to be thorough and see how the Q6 HE 8K behaves at work and at play. I expected to dislike the work experience based on my personal preferences, but I was surprised by how well the keyboard worked for me.

I had a few initial hours where my muscle memory for low-profile keyboards worked against me, with a series of missed clicks or a bit of fatigue with the larger keycaps. That passed in time, and I found the size and weight of the Q6 HE 8K to be a welcome change.

Where I expected the Q6 HE 8K to excel was in my gaming space on my Windows machine. It lived up to everything I anticipated and more.

The weighty keyboard provides stability, and the ability to customize every key actuation point and utilize the LKP (last key priority) and DKS (dynamic keystrokes) opened up an entire world for me. Think pressure sensitivity adjustments and absolute control with games like Marvel Rivals, where quick, responsive actions are vital.

Advertisement

I am an older gamer, so experiencing these features for the first time truly made me feel a bit like a caveman cracking rocks together with my previous basic keyboard and mouse. Meanwhile, other gamers are building rockets.

Full-size mechanical keyboard with white and light gray keys, accented by a few dark blue keys, including Enter and spacebar, on a clean white background

Keychron Q6 HE 8K Review: Full top-down view

The Q6 HE 8K is not the quietest mechanical keyboard I have ever used. If I decide to get one for my gaming desk, I will absolutely purchase and use the Silent Red switches from Keychron.

The bumpy-clack of the standard switches is nice, but it is not my preference.

Advertisement

The volume adjustment push knob on the Q6 HE 8K is amazing, and it is a simple quality-of-life feature that I love. It isn’t something I expected, and the clickable knob made quick muting feel satisfying.

Keychron Q6 HE 8K Review: An excellent mechanical keyboard

The Q6 HE 8K is an amazing mechanical keyboard, and I recommend it for gamers.

The retail price of the Q6 HE 8K is $239, and that is not anywhere close to inexpensive or budget-friendly for most. But the price is worth it if you are looking for a rock-solid mechanical keyboard.

Keychron Q6 HE 8K Pros

  • High build quality
  • Great for daily typing
  • Excels at gaming
  • Excellent customization options in Keychron software

Keychron Q6 HE 8K Cons

  • High entry price for keyboards
  • Case color options are limited

Rating 4.5 out of 5

Where to buy the Keychron Q6 HE 8K

The Keychron Q3 HE is available on the Keychron website for $239. It’s also available from Amazon,

Advertisement

Source link

Continue Reading

Tech

Geekbench Download Free – 7.0

Published

on

Geekbench includes updated CPU workloads and new Compute workloads that model real-world tasks and applications. Geekbench is a benchmark that reflects what actual users face on their mobile devices and personal computers.

Features

CPU Benchmark

Geekbench 7 measures your processor’s single-core and multi-core power, for everything from checking your email to taking a picture to playing music, or all of it at once. Geekbench 7’s CPU benchmark measures performance in new application areas including video conferencing, streaming, and game physics, so you’ll know how your system handles the tasks you rely on every day.

GPU Benchmark

Advertisement

Test your system’s potential for GPU compute tasks including machine learning, image processing, and video editing with the GPU Benchmark. Test your GPU’s power with support for the OpenCL, Metal, Vulkan, and CUDA APIs. New to Geekbench 7 is an increased focus on Machine Learning, and support for NVIDIA’S CUDA API.

Real-World Tests

Geekbench uses practical, everyday scenarios and datasets to measure performance. Each test is based on tasks found in popular real-world apps and uses realistic data sets, ensuring that your results are relevant and applicable. Geekbench 7’s multi-core tests only run multi-threaded when real applications do, so your scores reflect how software actually behaves.

Cross-Platform

Advertisement

Compare apples and oranges. Or Apples and Samsungs. Designed from the ground-up for cross-platform comparisons, Geekbench 7 allows you to compare system performance across devices, operating systems, and processor architectures. Geekbench 7 supports Android, iOS, macOS, Windows, and Linux.

Geekbench Browser

Upload your results to the Geekbench Browser to share them with others, or to let the world know how fast (or slow) your devices can go! You can track all your results in one place by creating an account, and find them easily from any of your devices.

Benchmark Charts

Advertisement

Verify device performance using the Geekbench Benchmark Charts. Available on the Geekbench Browser, these charts are based on data aggregated from real users in real-world environments. Whether you’re considering a new purchase or are curious about a device’s capabilities, use these charts to make informed decisions.

Stress Tests

Geekbench includes stress tests, which are tests that help determine the stability of your system. Stress tests help you find small problems with your system before they become big problems.

Multicore Aware

Advertisement

Every test in Geekbench is multi-core aware. This allows Geekbench to show you the true potential of your system. Whether you’re running Geekbench on a dual-core phone or a 32-core server, Geekbench is able to measure the performance of all the cores in your system.

Here’s what the different numbers mean:

Battery Runtime is the battery test runtime. If the test started with the battery completely charged and ended with the battery completely discharged then the test runtime is also the battery lifetime.

Battery Score is a combination of the runtime and the work completed during the battery test. If two phones have the same runtime but different scores, then the phone with the higher score completed more work. As with Geekbench scores, higher battery scores are better.

Advertisement

Battery Level is the battery level at the start and the end of the test.

What’s New

Geekbench 7, the latest version of Primate Labs’ cross-platform benchmark, has arrived and features both new and improved workloads to measure the performance of your CPUs and GPUs.

New Media Workloads

Geekbench 7 includes new media workloads that measure how well your CPU handles audio and video encoding, decoding, and processing. The workloads model the tasks behind video conferencing, screen sharing, and everyday content consumption. These new workloads:

Advertisement
  • Encode screen-sharing video with the AV1 codec, modeling the screen-sharing features in video conferencing apps.
  • Compress music and spoken-word audio with the Opus codec, modeling voice memo and podcast apps.
  • Decode video and audio while generating live captions with the Whisper speech recognition model, modeling video playback with automatic subtitles enabled.

Alongside the new media workloads, Geekbench 7 adds a Game Physics workload built on the Jolt Physics engine used in popular video games, expands the Photo Editor workload with a richer set of real-world edits, and updates the Photo Library workload to support importing and processing modern image formats such as JPEG XL and DNG.

A Smarter Multi-Core Benchmark

The multi-core benchmark in Geekbench 7 has been redesigned to better reflect how real applications behave. Not every task in the real world is multi-threaded, and pretending otherwise distorts scores without telling you anything useful about your device.

In Geekbench 7, a workload only runs in multi-threaded mode if the task it models actually runs multi-threaded in real applications. For example, the HTML5 Browser test isn’t included in the multi-threaded suite because web browsers are single-threaded (or lightly threaded).

The result is a multi-core score that’s a more accurate, more useful, and more relevant measure of how your device performs the work you actually do.

Advertisement

A Refreshed GPU Benchmark

The GPU benchmark has a new focus on the machine learning and content creation applications that increasingly define GPU performance. For machine learning, the GPU benchmark includes workloads that:

  • Track faces and apply real-time filter effects to video, modeling the face filters in social media apps.
  • Upscale images with machine learning, modeling super resolution features in content creation apps.
  • Blur backgrounds in video conferencing streams, modeling virtual background features in video conferencing apps.

Geekbench 7 also introduces new GPU image editing and synthesis workloads, including RAW image processing, LUT-based video color grading, path tracing, and fluid simulation.

And by popular demand, CUDA joins OpenCL, Vulkan, and Metal as a supported API in the GPU Benchmark. You can now measure your NVIDIA GPU using the API that powers its most demanding applications.

Larger Data Sets

Advertisement

Since the release of Geekbench 6, the tasks people perform have become more strenuous, and the data sets they use have grown larger and more demanding. To reflect this, we’ve updated the data sets the workloads process so they’re more challenging for your device and better reflect the files people work with today. This includes:

  • More (and more varied) archives in the File Compression workload, spanning source code, object code, and text documents.
  • More (and more varied) documents in the PDF Viewer workload, from park maps to technical documents to academic papers.
  • More assets and different image formats throughout the developer and image processing workloads.

Source link

Continue Reading

Tech

Nvidia’s latest trick for cooling its data center hardware is… hot water? ‘Hot liquid cooling’ is warmer than a hot tub, but apparently does the job pretty well

Published

on


  • Nvidia’s Rubin-generation AI servers run coolant that is often hotter than a hot tub as it enters a closed loop at up to 45°C and leaves at around 55°C, with no performance penalty in tow
  • The principle leveraged here is that of a temperature gradient with server chips still running hotter than the coolant, allowing heat transfer to occur seamlessly
  • The approach allows Nvidia to roughly conserve 2.6 million gallons per megawatt annually to near zero and could save a 50MW site over $4 million a year in cost

Nvidia‘s Rubin generation is the first of its kind in multiple ways, but the one that sticks out possibly is the fact that it is 100% liquid cooled, implementing it as a core design feature at a platform level with every single chip and networking component covered by a closed loop.

The reference design by Nvidia aims to allow for AI factories that effectively consume zero water by implementing a closed loop circuit that does not leverage evaporative water cooling 99% of the time.

Source link

Continue Reading

Tech

Tech Moves: Agility Robotics gets CFO; Microsoft security departure; Zap’s legal officer; new KEXP CPTO

Published

on

Michael Beer. (Agility Robotics Photo)

Agility Robotics named Michael Beer as its chief financial officer. Current CFO and chief operating officer Jennifer Hunter will transition to serving exclusively as COO.

“Michael brings outstanding public company finance and capital markets experience, while Jennifer, with her prior experience as a publicly traded COO, will focus exclusively on scaling our operational excellence and manufacturing capabilities,” said CEO Peggy Johnson, in a statement.

The Salem, Ore.-based startup, whose two-legged Digit robots have been tested inside Amazon warehouses, is set to become the first publicly traded U.S. company dedicated solely to humanoid robots, the company announced last month.

Beer joins Agility Robotics from the California energy storage company Energy Vault, where he was CFO for two years. Past roles include venture partner at Vest Coast Capital and CFO at FreeWire Technologies.

Matt Fisher. (Efekta Education Photo)

— Seattle-area tech veteran Matt Fisher has taken the role of CTO for London-based Efekta Education. The company is developing an agentic teaching and learning platform.

“I’ve spent my career building technologies that help people learn, connect and achieve more. What attracted me to Efekta is its clear vision for using AI to enhance learning, support teachers and
make high-quality education accessible to more people around the world,” Fisher said.

Advertisement

Last August, Fisher joined immersive media startup Adventr as a late-stage co-founder. Prior to that, he was co-founder and CTO at Daydream, a startup that raised a $50 million seed round last year to shake up the way people find and buy clothing online. Other past roles include leadership at Amazon, Microsoft, Nordstrom and Auth0.

— There is another name to add to the raft of departures from Microsoft‘s security leadership.

Rahul Prakash. (LinkedIn Photo)

Rahul Prakash, head of product for Microsoft Security Copilot, shared that he’s leaving his role after nearly a decade with the company.

“As any Identity professional will tell you, the world of [Identity Access Management] is far more intricate than people realize, and it’s being rewritten for the world of AI agents. At Microsoft, I’ve had the privilege of going deep into this space…” Prakash said on LinkedIn.

On Monday, GeekWire reported that Rudra “Rudy” Mitra, who spent more than 27 years at Microsoft, was joining Amazon Web Services as vice president of security services. Other recent departures include Krishna Kumar Parthasarathy, who resigned at after nearly three decades.

Advertisement
Nancy Lipson. (LinkedIn Photo)

Nancy Lipson has joined Zap Energy as chief legal officer. The Everett, Wash.-based company is in pursuit of fusion energy, and recently expanded its scope to include next generation nuclear fission.

Lipson was previously executive vice president and CLO for the gold mining giant Newmont Corporation, departing after 18 years in 2023.

“Nancy’s deep expertise in areas of corporate strategy, governance, compliance, and sustainability will be key assets as Zap pursues its integrated approach to advanced nuclear,” Zap posted on LinkedIn.

Jyoti Shukla. (LinkedIn Photo)

Jyoti Shukla was named chief product and technology officer at KEXP, a nonprofit radio station serving Seattle and the Bay Area. The station includes community and performance spaces, and features wide-ranging music genres.

“There is a lot of meaningful work ahead, and I’m excited to keep learning, building, and partnering with an amazing team as we shape what’s next,” Shukla said on LinkedIn.

Prior to taking the role, Shukla served on KEXP’s board of directors and was senior vice president of product design at SiriusXM. She has also worked in tech leadership roles at Nordstrom and Starbucks, and started her career at Microsoft.

Advertisement

ZEV Co-op, a Washington-based nonprofit EV carshare cooperative, announced Ry Armstrong as its new executive director. Armstrong was previously at Sustainable Seattle, where they served as co-director. 

Tirzah VanDamme has joined Gagen MacDonald as senior director of AI and digital transformation. She brings more than 20 years of experience and was most recently at Microsoft.

— The Washington State Academy of Sciences (WSAS) announced the election four new board members. They are:

  • Amanda Boyd, executive director of Native American Programs and Professor in the Elson S. Floyd College of Medicine at Washington State Universit
  • Mary Czerwinski, former research manager at Microsoft Research
  • John Stein, former science and research director of NOAA Fisheries’ Northwest Fisheries Science Center
  • Judith Wasserheit, professor emerita of Global Health, Medicine, and Epidemiology at the University of Washington

WSAS also elected 30 new members, who will assist the organization in providing scientific and technical information to state policymakers.

They include 26 scientists and engineers elected by their WSAS peers and four members recently elected to the National Academies of Science, Engineering, or Medicine or awarded the Nobel Prize and who reside or work in Washington state.

Advertisement

The members include 11 UW professors and eight from WSU, five researchers from Pacific Northwest National Laboratory, three from Fred Hutch Cancer Center, and three at private companies, with some participants holding roles at multiple institutions.

Source link

Continue Reading

Tech

Apple’s lawsuit against OpenAI gets new judge

Published

on

A federal district judge will oversee Apple’s lawsuit accusing OpenAI of using stolen intellectual property to advance its hardware efforts.

In early July, Apple sued OpenAI after alleging that two ex-employees successfully stole intellectual property to enrich OpenAI’s development efforts. Now, on Thursday, a judge has been assigned to the case.

Initially, when the suit was first filed, it was randomly assigned to Magistrate Judge Virginia K. DeMarchi. Now, it seems as though U.S. District Judge Edward Davila will oversee the case.

As 9to5Mac notes, each party was given the choice whether to allow the magistrate judge to sit the case. Apple appears to be the party that declined, instead opting to reassign the case to a district judge.

Advertisement

The case’s previous initial case management conference had been scheduled for October 13. However, it will now need to be rescheduled before Judge Davila.

Maintained intellectual property theft

Apple’s argument against OpenAI hinges on its argument that two previous employees had been stealing intellectual property for quite some time. The two employees are Chang Liu and Tang Yew Tan, the former Vice President of Product Design for iPhone and Apple Watch.

Reportedly, Liu failed to return Apple-issued hardware that was still authenticated to access Apple’s networks. He allegedly told a colleague, Yu-Ting “Alyssa” Peng, still at Apple, that he was planning to access Apple information.

Tan, however, allegedly began emailing himself information about Apple suppliers months before he left to serve as OpenAI’s Chief Hardware Officer. He also allegedly directed candidates to bring unreleased hardware components from Apple to their interviews with OpenAI.

Advertisement

Apple believes this was part of a concerted effort to take and use confidential information. Apple is seeking judgment, an injunction against use and possession of Apple’s intellectual property, a return of Apple’s property, damages, and royalties for use of Apple’s intellectual property.

Source link

Advertisement
Continue Reading

Tech

Fake Claude app promoted by Bing ads pushes SectopRAT malware

Published

on

Fake Claude app promoted by Bing ads pushes SectopRAT malware

A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware.

At least 29 organizations were compromised between July 21-22 during the malicious operation, which researchers call FakeAgent.

The attacker uses a malicious Claude Artifact hosted on Claude’s legitimate domain, which is a common tactic that has been used 

image

The attackers used a malicious Claude Artifact hosted on Claude’s legitimate domain, a tactic that has been used at the beginning of the year to push macOS malware via ClickFix lures.

Researchers at managed security company Huntress found that the malicious Claude Artifact, downloaded 7,100 times before Anthropic removed it, directed visitors to websites that hosted a fake installer named ClaudeDesktop.exe.

Advertisement
The malicious artifact resembling a download portal
Phishing page hosted as a Claude artifact
Source: Huntress

However, the file is a legitimate JetBrains Chromium component that sideloads a malicious DLL (libcef.dll) to deliver the SectopRAT remote access trojan with info-stealing capabilities.

Persistence on the system is achieved through another executable named DockerDesktop.exe, which installs a scheduled task.

Huntress says that the various loaders and staging components used in the infection chain feature anti-analysis mechanisms, including VMProtect packing, shader timing checks, GPU and VRAM checks, and virtual machine (VM) detection.

The SectopRAT malware was recently observed being distributed via CastleLoader campaigns and ClickFix attacks.

The malware uses the EtherHiding technique to retrieve a working command-and-control (C2) address via Ethereum BNB Smart Chain transactions.

Advertisement

SectopRAT, also known as ArechClient2, has been active since 2019 and is an information-stealer with HVNC (Hidden Virtual Network Computing) functionality. It allows remote hands-on operations and real-time interaction with the compromised system.

The malware targets user passwords, credit card data, files, browser logins and cookies, FTP credentials, data from various messaging clients, including Discord and Telegram, Steam, and VPN products.

The malicious Bing search results
Malicious Bing search results
Source: Huntress

In an interesting twist, Huntress reports it used Claude Opus 4.8 to assist with shader emulation, cryptographic reconstruction, and .NET code analysis.

Analysis of the decrypted .NET payload (SectopRAT) helped attribute the attacks to SectopRAT operations, or a closely related fork, and opened the path to infrastructure analysis.

At that stage, the researchers found 10 domains registered to the same email address since December 2025, with one of them previously linked to the StealC distribution and seized during Operation Endgame.

Advertisement

Huntress does not have enough evidence to attribute the FakeAgent campaign to a specific, known threat cluster.

Users looking for software should trust official websites and download portals, instead of search results, especially sponsored ones.


article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Advertisement
Continue Reading

Tech

How AI guardrails are impeding the work of offensive cybersecurity researchers

Published

on

For months, AI giants have devised special vetted programs and strict guardrails to limit the use of their models by malicious hackers. But these limits are now hindering the work of legitimate network defenders, as well as that of offensive cybersecurity researchers. 

In June, the U.S. government slapped export control restrictions on Anthropic’s much-hyped AI models Mythos and Fable. The move was prompted at least in part by a report that claimed it was possible to bypass the models’ guardrails designed to prevent users from using them to build and execute malicious cyberattacks.

Regardless of whether the incident was really motivated by fears of a jailbreak, the fact is that Anthropic has repeatedly marketed Mythos as some kind of doomsday cybermachine that can only be given to carefully vetted users, and even then with strict guardrails in place. (The export controls on Fable 5 and Mythos 5 have since been lifted. Fable 5 returned to general access on July 1; Mythos 5 has been reintroduced only to vetted U.S. organizations as part of the government’s review process.)

That kind of gatekeeping isn’t unique to Mythos. Both Anthropic, with its other models, and OpenAI offer cybersecurity researchers programs they can apply to get vetted and — if approved — access models with fewer cybersecurity restrictions: OpenAI’s Trusted Access for Cyber and Anthropic’s Cyber Verification Program

Advertisement

These guardrails have been widely criticized, particularly by researchers whose job is to find unknown vulnerabilities in systems and devise ways to exploit them before criminals do.

During a recent appearance on a cybersecurity podcast, Mark Dowd, a well-known security researcher, said that, “it’s not really comfortable to me that these random large companies are making arbitrary decisions about what is safe in security and what’s not.”

Dowd has spent decades finding and selling “zero days” — previously unknown software flaws and the exploits that take advantage of them — to Western governments, rather than report them to the software makers so they get patched. Governments pay a premium for vulnerabilities precisely because they stay open, which is useful for intelligence operations.

Dowd admitted his work may make him biased, but he isn’t alone. Several people who work in offensive cybersecurity — they proactively probe systems for weaknesses — described to TechCrunch how they use AI tools and deal with their guardrails. 

Advertisement

Chris Anley, the chief scientist at security consulting giant NCC Group, said that asking an AI model to try to exploit a bug is a key step in confirming it’s a real vulnerability worth fixing. But if a guardrail prompts the model to refuse to answer the question outright, the guardrail hurts defenders, he said.

“This is where the whole offensive versus defensive and guardrails part comes in, because ‘fix this code’ as a prompt is both an essential mechanism for defense but also a roadmap for finding critical vulnerabilities in the code base,” said Anley. “So at the same time, the same tool is both an offensive tool and a defensive tool, and the two can’t really be unpicked.”

It’s “like a hammer,” he continued. “You can’t build a house without a hammer. It’s definitely a tool but it’s also irreducibly a weapon as well.”

When he and his colleagues run into such a roadblock, they sometimes fall back on open-source AI models that come with no guardrails at all.

Advertisement

Paolo Stagno, the chief technology officer at CrowdFense, a well-known company that develops, acquires, and sells unknown vulnerabilities to government agencies, agreed with Dowd, saying AI companies “essentially treat customers like children who need babysitting” with their vetted programs and guardrails. 

Stagno said he and his colleagues do use frontier models — but only for reverse engineering. They avoid using AI to help find vulnerabilities or build exploits, he said, because feeding that work into a cloud-based model risks leaking sensitive vulnerability data or having it absorbed into future training runs. For that step, he said, they use open source models run locally, as they do not rely on sharing data outside of the model. 

Giuseppe Cali, a security researcher who finds zero-days and develops exploits, said guardrails are not impeding his work. That’s because he doesn’t use AI for offensive work; instead, he uses it for initial reverse engineering, to understand the code he’s analyzing, and to build supporting tools. For that, he said, AI tools can speed up the process and allow him to focus on discovering vulnerabilities. 

“I still want to own the actual bug discovery and weaponization myself and that wouldn’t change if all guardrails were lifted tomorrow,” said Cali. “I am jealous of my bugs, and I like this game too much to let models play it for me.”

Advertisement

One researcher at a smartphone-component manufacturer, who spoke on condition of anonymity because he isn’t authorized to talk to the press, said his employer isn’t part of Anthropic’s CVP program and as a result, its tools are barely useful for finding vulnerabilities because the guardrails are too strict.

“If it catches wind we’re doing anything security related, it just stops and isn’t usable,” the person said. 

Chris Thompson — chief executive of cybersecurity firm RemoteThreat and founder of Offensive AI Con, an offensive security and AI-focused event — said that in his experience using the frontier AI models, the guardrails can be inconsistent and work differently every day. That’s true even inside the looser boundaries of Anthropic and OpenAI’s vetted programs. 

“I think the practical impact is you spend a lot of time negotiating with the model instead of working on the core security program,” said Thompson. “Instead of analyzing a vulnerability and reasoning through the exploitability, you’re trying to find why you’re getting inconsistent results or why are models over-sanitizing the output.” 

Advertisement

As a consequence, researchers rely on or get pushed toward Chinese open-source models like GLM — freely downloadable models that can be run locally with no vetting or usage restrictions — said Thompson.

“You have these responsible researchers that are being pushed away from U.S.-governed systems to foreign-owned systems,” he said. “I think it’s more harmful than good to have these guardrails in place.”

Rather than tightening restrictions further, Thompson called for the AI frontier labs to open up their programs, provide responsible access, and also hold those who abuse their tools accountable. Otherwise, he argued, defenders will lose the AI race.

“There’s this big storm coming. There’s this big wave of attacks that are going to happen at speed and scale like never before,” said Thompson. “But the same security consulting firms and legit researchers that are trying to make a difference are being stifled right now.”

Advertisement

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Source link

Continue Reading

Tech

Tesla shares fall after company misses Q2 analyst expectations

Published

on

Elon Musk has reignited speculation of a potential Tesla-SpaceX merger.

Tesla has missed recent analyst expectations by a large margin, reporting roughly $1.1bn in adjusted net income in the quarter past. Wall Street had expected the company to rake in around $1.9bn.

The loss is despite the Elon Musk-owned company recording a 26pc growth in revenue to a better-than-expected $28.2bn, with car sales alone bringing in more than $20bn – marking a 23pc year-over-year growth.

Electric vehicle (EV) sales jumped 25pc since last year to a little more than 480,000 units in Q2 2026. The company produced around 451,000 vehicles during the period.

Advertisement

Tesla stocks dropped around 1.3pc at market close on Wednesday (22 July) following the announcement and fell a further 4.2pc in after-hours trading. Company shares have been down nearly 8pc since last month and nearly 17pc in the last six months.

The loss coincides with a drop in share value for Musk’s other company SpaceX, which Tesla has close financial ties with. SpaceX’s filings from earlier in the year showed that the company purchased nearly $700m worth of Tesla’s battery storage products across 2024 and 2025, as well as more than $130m of its Cybertrucks in 2025.

Meanwhile, xAI – now owned under SpaceX – purchased $292m in Tesla battery solutions by April this year, and more than $400m last year. The two companies are also collaborating to develop semiconductors as part of Terafab.

Tesla sales bounced back the strongest in Europe, partially led by higher fuel prices, which drove consumers towards EVs.

Advertisement

New registrations for Tesla vehicles soared across the region, according to June figures – more than doubling in France, and seeing a 39pc rise in Denmark and a 56pc jump in Sweden.

Meanwhile, the company suffered on its home turf in the US after the government cut federal tax credits for EVs and dismantled rules that encouraged their production.

Additionally, Chinese competitors such as BYD, Nio and Xiaomi are also encroaching on Tesla’s EV market share with their more affordable yet high-tech options.

Tesla is attempting to diversify its revenue streams away from EVs (which makes up a majority of its earnings) to autonomous taxis and AI-powered humanoid robots.

Advertisement

“The company reports that paying customers have travelled 2.5m miles in Tesla’s robotaxis and that 380,000 of those miles have been unsupervised, with no safety monitor in the vehicle,” said Forrester VP and principal analyst Paul Miller.

“Those unsupervised miles are rising, but they’re currently a fraction of the 220m miles reported by competitor Waymo back in March.”

Tesla more than doubled its capital spending compared to Q2 last year to fund the diversification push, marking a $1.1bn negative cash flow caused by a capex increase of about $3.3bn.

Musk, meanwhile, told investors that the company aims to spend more than $25bn this year – nearly triple the $8.5bn it spent in 2025. Big Tech heavyweights are expected to commit several hundred billion dollars in capex this year alone to build out their AI ambitions.

Advertisement

Musk also reignited speculation of a possible Tesla-SpaceX merger at the earnings call yesterday.

“As you can tell from the many collaborations on so many fronts with SpaceX, there’s more and more overlap,” Musk said.

“We can’t ​talk about, you know, combining companies and that kind of thing on an earnings call. It’s ​got to be done with the appropriate process.”

A merger could ease matters for the otherwise struggling Tesla, which is already making a pivot closer to SpaceX with its push into AI.

Advertisement

SpaceX president and chief operating officer Gwynne Shotwell told CNBC in June that a combined business “might ⁠make Elon’s life a little easier” by potentially simplifying Musk’s trillion-dollar corporate empire.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Source link

Advertisement
Continue Reading

Tech

This $299 flip phone is the anti-smartphone, promises to save you from doomscrolling hell

Published

on

First look: Brooklyn-based consumer electronics company Light has launched a minimalist flip phone designed to cut down on screen time without compromising on essential communication. The $299 Light Flip features a clamshell design reminiscent of the Motorola Razr devices from the turn of the century, and offers a barebones software experience without social media, web browsing, media streaming, and shopping apps.

The Light Flip features a 2.8-inch non-touch OLED display, 6GB of RAM, 128GB of storage, a 50MP rear camera, and a replaceable 1,800mAh battery. It sports an old-school T9 keypad, which used to be standard on candybar feature phones from Nokia, Motorola, and Sony Ericsson in the early 2000s.

Connectivity options include 5G, Wi-Fi, Bluetooth, GPS, and a 3.5mm headphone socket. It is available in six colors and comes with a lanyard notch, adding to its nostalgic appeal.

The Light Flip runs on LightOS, a minimalist Android skin that offers only essential apps and services, such as calls, texts, camera, calendar, music player, and an alarm clock.

Advertisement

As part of its core philosophy of “going light,” the device deliberately skips social media apps and web browsers, encouraging people to use their phone as little as possible. It also supports Light’s digital detox program ‘Flip Your Life,’ which aims to help users adapt to a less connected lifestyle.

Talking to ZDNet, Light co-founders Joe Hollier and Kaiwei Tang said that contrary to popular perception, the target demographic for the Flip are 18- to 30-year-olds who are tired of the 24×7 connected lifestyle. The company believes that dumb phones could make a comeback, as its internal research suggests that 52% of millennial and Gen Z consumers would consider using basic feature phones to cut back on social media consumption and escape the endless cycle of doomscrolling.

The Light Flip is now up for preorder with a $39 deposit but it’s not expected to ship until April 2027.

It will be sold unlocked for $299 from the company’s official website, and customers can also get it on a two-year, $39-a-month service plan directly through Light. Whether it will land on major carriers like Verizon, AT&T, or T-Mobile and become available with a contract remains to be seen.

Advertisement

Source link

Continue Reading

Trending

Copyright © 2025