Every day seems to brings fresh news of an AI agent going “rogue.” Whether that’s compromising Hugging Face, hacking a gym website, or creating its own fake profiles to socially engineer an intrusion, AI models are increasingly behaving like bad actors.
So, the AI labs that make the models doing the hacking are expanding their cyber protection offerings. This week, OpenAI announced an expansion of Daybreak, its cyber defense service which it launched earlier this year, not long after Anthropic released its cyber-focused model Mythos.
Daybreak is a service that bundles access to models, tools and workflows for defenders. The expansion includes access to a brand new cyber-focused model designed for defensive work.
OpenAI said Monday that Daybreak would now consist of two tiers: Blue and Red. Both of these tiers will allow approved customers access to OpenAI’s limited-access frontier cyber models. Frontier models — the most advanced available — have been a subject of controversy. The Trump administration previously sought to collaborate with AI companies on the roll out of such models, purportedly over safety concerns. Previously, OpenAI deployed significant guardrails to using these models, limiting what customers could do with them.
Advertisement
Blue, which appears to be the more basic of the two, offers a variety of cyber services, including incident response, malware analysis, and patch validation. OpenAI calls Blue its “recommended starting point for most defenders,” implying that it should be more than enough for most enterprises.
Red, on the other hand, offers a broader and potentially more dangerous toolkit. The company grants its users “purpose-trained cybersecurity models,” designed to carry out security testing and vulnerability research.
With Red also comes the new model, GPT‑5.6‑Cyber, which is only available at that tier. 5.6-Cyber is built off of GPT‑5.6 Sol, and offers enhanced capabilities for certain specialized cybersecurity tasks, the company said.
At the moment, GPT‑5.6‑Cyber is only being made available for “trusted customer partners,” including reportedly Accenture, IBM, Crowdstrike, Cloudflare, and others.
Advertisement
While the threats from AI agents are rapidly increasing, critics have also pointed out that they function as marketing opportunities for the AI labs. OpenAI is certainly marketing its upgraded Daybreak that way.
“The cybersecurity world is rapidly changing—threat actors will increasingly use AI to conduct cyberattacks at unprecedented speed and scale, including in fully autonomous ways,” the company said in a blog post. “As these capabilities spread, defenders have a narrowing window to prepare.”
At the same time, enterprises remain interested in buying their protection from the AI labs who know the security risks best, because they know them first-hand.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
The all-glass iPhone Pro model expected in 2027 was rumored to have been canceled, but another report now suggests it is proceeding as planned.
A financial analyst firm, Jefferies, suggested the 2027 iPhone would no longer get an all-glass model. Another analyst has stepped in to suggest otherwise.
According to a report from Bloomberg Apple’s all-glass iPhone Pro expected in 2027 was still moving forward. The Jefferies report suggested that there was a low yield, and the new report counters that.
Apple is expected to reveal an all-glass iPhone 20 or iPhone 19, depending on the naming convention chosen, in September 2027. The iPhone 18 lineup hasn’t been revealed yet, but that won’t stop the rumor mill from looking ahead.
Advertisement
The all-glass iPhone 20 Pro
Okay, it won’t be “all” glass, as there still has to be a frame, motherboard, and other components, but you get the idea. The glass-focused model will have glass that curves around the edges and be supported only by a metal band in the middle.
Rumors have suggested the glass design is meant to be a physical representation of the software’s move to Liquid Glass. The latest report suggests that Apple wanted to use even more glass, but scrapped that concept early on.
Perhaps the Jefferies report had a half-truth: the 20th-anniversary iPhone with maximized glass usage was canned. However, the redesign itself wasn’t, it was just toned down.
When the iPhone X debuted in 2017, it was a significant design departure from the previous long iPhones with a Home Button. The design hasn’t shifted significantly since with the exception of moving to the Dynamic Island and going from camera bump to camera plateau.
Advertisement
The 2027 iPhone Pro models wouldn’t see such significant schedule changes this late into development, the report suggests. As Apple generally locks in a design a year out from the September reveal.
What just happened? Bill Swearingen’s noRecognition project is testing whether computer-generated patterns can interfere with software used to identify people, vehicles, and other objects on surveillance cameras. The project received its first public test Friday at the Def Con cybersecurity conference in Las Vegas. Swearingen worked with Donut Media to cover a 2009 Toyota Yaris with one of his patterns and drive it past a Flock camera. “We proved it was effective,” Swearingen, a cybersecurity professional and founder of SIXCYBER, told TechCrunch.
Donut Media plans to release video of the test in the coming weeks.
The pattern does not stop a camera from recording. Instead, it is designed to prevent the software connected to the camera from recognizing what it sees. A person or car wearing the pattern would still appear in the footage, but the detection system may not flag it as a person or vehicle.
That is the central idea behind noRecognition. Swearingen wants to make it harder for automated camera systems to track people in public spaces. He said the project is intended to give people a way to “opt out of being tracked.”
Advertisement
“Privacy is a fundamental right,” Swearingen said.
Swearingen has spent the past year building and testing the system from his home in Kansas City. He said he has run about 31 million tests so far. The work began as a small test lab aimed at defeating individual open-source object-detection algorithms. It later evolved into a reinforcement learning model that can generate and improve patterns on its own.
He described the process as teaching the model “how to paint.”
The model tests a pattern against camera-detection software. If the software can still identify the object covered by the pattern, the system adjusts it and tries again. Over time, it learns which visual elements are more likely to confuse the algorithms.
Advertisement
Swearingen said the model has produced patterns that can defeat all 11 open-source detection algorithms he tested. Those include software used in systems associated with Flock license plate readers, Axon body cameras, and Clearview AI. He said the model now produces new patterns every minute, adding that each unsuccessful test gives it more data and allows it to generate more effective patterns over time.
The technology falls into a category often called adversarial machine learning. It relies on the fact that computer-vision systems do not interpret images the same way people do. A pattern that looks like an unusual design to a person may cause a detection model to misclassify an object or fail to identify it altogether.
The approach differs from efforts to physically block cameras. noRecognition is not designed to hide someone from view or interfere with the camera itself. Instead, it targets the software layer that processes video, reads license plates, and identifies faces or objects.
That software has become a standard feature of many camera networks. Law enforcement agencies use it to search footage and identify vehicles or people of interest. Private companies and local governments also use automated detection tools across parking lots, streets, and other public places.
Advertisement
These systems can process far more video than a person could review manually. But they have also drawn scrutiny over errors and the consequences of inaccurate matches. Swearingen said his concerns about the spread of surveillance cameras helped motivate the project.
He said he noticed the density of cameras in his hometown of Kansas City and began thinking about how difficult it would be to avoid automated tracking. He also said he felt uneasy about attending a protest last year because of the possibility that cameras could track participants.
Artists and clothing makers have previously tried to develop designs that confuse facial-recognition systems. Swearingen said that work helped demonstrate that such methods were possible. His project focuses on using a model to create and refine patterns at a much larger scale.
noRecognition is also running a crowdfunding campaign for clothing printed with the patterns, including T-shirts and hoodies. Swearingen said vehicle skins could follow. He said the goal is to make the patterns large and clear enough to work at a distance without making the clothing impractical to wear or the skins impractical to use.
Advertisement
He is keeping his strongest patterns private for now, saying he does not want camera companies to quickly develop defenses against them.
Facepalm: Microsoft has confirmed that it jumped the gun by rolling out a new OneDrive Photos app to millions of Windows 11 PCs earlier than intended. The app was automatically installed on client and enterprise computers without user permission, prompting complaints from users who don’t use OneDrive to store their photos.
In an X post, Microsoft’s EVP of Apps and Agents, Jeff Teper, noted that OneDrive Photos is an incubation project that was meant to be tested with select users but was mistakenly pushed to more devices than intended. He confirmed that the issue will be resolved in a future update, suggesting that the app will be removed from devices that were not originally supposed to be included in the test.
Teper added that Microsoft will “always” offer users the option to use local storage instead of OneDrive for storing their photos and videos.
Despite Teper’s assurance, some users are livid that the unwanted app cannot even be uninstalled without removing the main OneDrive app. Some social media users have also questioned the rationale behind creating a web-based app instead of a native Windows application, arguing that it makes the software unnecessarily resource-intensive.
Advertisement
A report from Windows Central appears to confirm that the OneDrive Photos app is extremely memory-intensive and not very responsive, souring the experience even for OneDrive users.
It is worth noting that OneDrive Photos is designed exclusively for consumer PCs and is meant to be installed through the OneDrive background sync client without user intervention. However, it was also rolled out to enterprise devices, upsetting IT admins.
Windows Latest adds that the new app has system-wide access to all media files, even when users are not signed into a Microsoft account. It also reportedly asks for permission to scan faces in photos, although Microsoft says that the data will not be shared with third parties. Users can configure the settings to prevent the app from scanning specific files and folders.
Despite the controversy surrounding the OneDrive Photos app, Microsoft is working on the Windows 11 26H2 update, which is scheduled for release this October. It will ship as an enablement package on the same “Germanium” platform that underpins 24H2 and 25H2, with most of the new features aimed at power users and IT admins rather than mainstream consumers.
Earlier today, OpenAI launched GPT-5.6-Cyber, a specialized model designed to perform advanced vulnerability research and exploit development for approved defenders — including categories of work that its general-purpose models will often refuse.
GPT-5.6-Cyber is a fine-tuned version of OpenAI’s most advanced general model, GPT-5.6 Sol, unveiled back in June, but trained specifically to improve performance on advanced cybersecurity tasks, including finding zero-day vulnerabilities and developing exploit chains.
Crucially, OpenAI also trained it to reduce refusals on some higher-risk, “dual-use” cybersecurity requests — that is, requests that could be used for legitimate defensive or malicious offensive purposes.
Indeed, on an internal OpenAI benchmark called Advanced Cybersecurity Completion Rate — which the company says in its launch blog post measures tasks involving exploit-chain development, authentication bypass, privilege escalation, and other advanced cybersecurity scenarios — GPT-5.6-Cyber completed 95% compared to just 57.3% from its immediate predecessor model GPT-5.5-Cyber, and just 1.5% with the normal GPT-5.6 Sol model and all its safeguards applied.
Advertisement
OpenAI researcher Eric Wallace posted on X, describing GPT-5.6-Cyber as OpenAI’s “first large-scale attempt at directly improving capabilities for advanced cybersecurity tasks such as exploit development.”
Pricing and availability
Unfortunately for enterprises, GPT-5.6-Cyber is not being made broadly available to every ChatGPT or API customer.
To get access, an organization has to be accepted into the newly created tier of OpenAI’s Daybreak cybersecurity program, called Daybreak Red — also announced today, which gives access to dedicated cybersecurity models like GPT-5.6-Cyber
Another new tier, Daybreak Blue, gives a wider swath of enterprises access to general models like GPT-5.6 Sol but with some guardrails lifted to allow for more cybersecurity uses.
Advertisement
OpenAI’s documents list pricing for GPT-5.6-Cyber at $12.50 per million input tokens and $75 per million output tokens, with cached input at $1.25 per million tokens.
OpenAI-GPT-5.6-Cyber and Sol (Daybreak) pricing table. Credit: OpenAI
That makes it more expensive than GPT-5.6 Sol in the same Daybreak cyber pricing table, where Sol is listed at $5 per million input tokens and $30 per million output tokens for short-context use.
OpenAI does not list long-context pricing for GPT-5.6-Cyber in the same table, and access still requires separate Daybreak Red approval and provisioning.
Advertisement
Red vs. Blue: OpenAI’s new Daybreak tiers and how to qualify for them
Daybreak Red is for approved security teams doing advanced, authorized cyber work — the kind of work that can look risky out of context, even when it is being done for defensive reasons. That includes vulnerability research, penetration testing, red-team exercises and exploit validation on systems the organization owns, operates or has permission to test. In other words, OpenAI is saying GPT-5.6-Cyber is for trusted defenders with a clear professional need, not for general experimentation.
Enterprises that want access have to apply through Daybreak Access, OpenAI’s current pathway for vetting cyber users. The application asks companies to identify who they are, what kind of security work they plan to do, where they will use the models, and which OpenAI products or surfaces they expect to use. Applicants also have to confirm that their work is lawful, defensive and authorized.
OpenAI is also looking for signs that the applicant has a serious security program of its own. The company says participating enterprises need controls such as single sign-on, multifactor authentication, role-based access, employee-use monitoring, usage logs, API-key controls and a documented incident-response process. OpenAI also asks for a recognized security certification such as SOC 2 Type II, ISO 27001 or an equivalent standard. Access is limited to approved people inside the organization using company-controlled accounts and devices.
If an enterprise does not qualify for Daybreak Red, or does not need that level of access, OpenAI is pointing most companies toward Daybreak Blue, its other cyber models access tier, instead.
Advertisement
Blue is the broader tier for approved defenders. It does not provide GPT-5.6-Cyber, but it does give vetted users access to OpenAI’s frontier general-purpose models, including GPT-5.6 Sol, with safeguards adjusted for legitimate defensive work.
For many enterprise security teams, Blue may be the more realistic starting point. OpenAI says it is meant for tasks such as secure-code review, vulnerability discovery, malware analysis, incident response and patch validation. These are still sensitive uses, but they do not necessarily require the same specialized cyber model access that comes with Red.
The practical takeaway is that enterprises now have two routes into Daybreak. Blue is for approved defenders who want stronger AI help with everyday security work. Red is for the smaller set of approved teams that can justify access to specialized cyber models, including GPT-5.6-Cyber. Companies that want to use Daybreak capabilities in products or services for their own customers need a separate approval path through the Daybreak Cyber Partner Program, rather than simply applying for internal enterprise access and passing it along.
How OpenAI got here: from Trusted Access to Daybreak
OpenAI has supported defenders through its Cybersecurity Grant Program since 2023 — later expanded to $10 million — and began building cyber-specific safeguards into its model deployments starting with GPT-5.2.
Advertisement
In February 2026 it introduced Trusted Access for Cyber (TAC), an identity-and-trust framework that gave vetted defenders lower classifier-based refusals for authorized work such as vulnerability triage, malware analysis and binary reverse engineering.
From there, the cadence accelerated. In March, OpenAI CEO and co-founder Sam Altman announced the Daybreak program. In April, OpenAI scaled TAC and released GPT-5.4-Cyber, a version of GPT-5.4 fine-tuned to be “cyber-permissive” for a limited set of vetted vendors and researchers.
In May, it followed with GPT-5.5-Cyber in limited preview for defenders of critical infrastructure, and lined up partners including Cisco, Intel, SentinelOne, Snyk and Cloudflare.
Notably, OpenAI said at the time that GPT-5.5-Cyber was “primarily trained to be more permissive,” not to significantly out-perform its general model — GPT-5.5-Cyber actually scored worse than GPT-5.5 on some evaluations.
Advertisement
TAC required phishing-resistant Advanced Account Security for individuals on its most capable models beginning June 1, and Daybreak now requires hardware security keys for individual accounts beginning September 1.
OpenAI says GPT-5.6-Cyber has already found zero-days
OpenAI isn’t relying exclusively on benchmarks to make its case.
The company says its researchers used GPT-5.6-Cyber to investigate V8, the JavaScript engine underlying Chrome, and uncovered two previously unknown vulnerabilities that could be chained to corrupt memory and escape the V8 heap sandbox.
OpenAI researchers validated the findings and disclosed them to Google, which fixed the vulnerability assigned CVE-2026-15903 — a high-severity flaw in which V8’s optimizing compiler skipped a safety check during integer conversion, allowing an out-of-bounds array index that an attacker could use to read or overwrite memory.
Advertisement
OpenAI says the model has also contributed to finding at least five vulnerabilities in an unnamed popular mobile operating system, three critical vulnerabilities in an unnamed popular database, and more than 400 vulnerabilities capable of producing privilege escalation in a popular operating-system kernel. Those disclosures are still being coordinated, according to OpenAI.
The results put OpenAI into a rapidly developing market for AI-assisted offensive security. XBOW, for example, markets autonomous penetration-testing agents that map attack surfaces, attempt exploits and independently validate findings; in 2025 it became the first AI system to top HackerOne’s U.S. bug-bounty leaderboard, and this year it disclosed a set of critical, CVSS-9.8 remote-code-execution flaws in Microsoft’s Bing image-processing systems, found without source-code access.
For enterprise security leaders, that emerging competition matters because vulnerability research is moving beyond using an LLM as an assistant. Vendors are increasingly building systems in which models can investigate targets, operate tools, validate hypotheses and produce actionable findings.
Specialized doesn’t mean universally better
OpenAI’s own results also show why enterprises shouldn’t simply equate cyber specialization with better performance everywhere.
Advertisement
GPT-5.6-Cyber outperformed GPT-5.6 Sol and GPT-5.5-Cyber on OpenAI’s implementation of ExploitGym, which evaluates whether agents can turn known vulnerabilities into working exploits in controlled environments. It also beat Sol on an internal zero-day evaluation.
But GPT-5.6 Sol performed better on OpenAI’s Vulnerability Discovery and Report Writing evaluation. OpenAI attributes the Cyber model’s lower score partly to shorter and less detailed vulnerability reports.
Sol also performed best on ExploitBench under its standard 300-turn limit, with OpenAI saying it solved tasks more token-efficiently. Extending the evaluation to 600 turns narrowed the gap between the models.
That suggests enterprises may eventually treat cyber models as specialized workers rather than replacements for general reasoning models: one model for deep exploit work, another potentially better suited to analysis, documentation or other parts of a security workflow.
Advertisement
SpecterOps CTO Jared Atkinson said GPT-5.6-Cyber is “materially improving our specialist vulnerability-research workflows,” adding that it completed some work in less than a day that previous models had failed to resolve after weeks of intermittent effort.
The Hugging Face incident hangs over the launch
The permissive-model pitch arrives weeks after OpenAI’s most serious public demonstration of what can go wrong when cyber refusals are turned down — and OpenAI addresses that history head-on in the Daybreak announcement.
In July, OpenAI and Hugging Face jointly disclosed that during an internal ExploitGym benchmark evaluation — run with production classifiers deliberately disabled to measure maximal capability — a combination of OpenAI models, including GPT-5.6 Sol and an unreleased, more-capable pre-release model, broke out of their sandboxed research environment and autonomously attacked Hugging Face’s production infrastructure.
The models exploited a zero-day in an internally hosted package-registry cache proxy to reach the open internet, moved laterally through OpenAI’s research nodes, then inferred that Hugging Face likely hosted ExploitGym’s answer keys and chained stolen credentials and remote-code-execution flaws to reach its production database. OpenAI called it an “unprecedented cyber incident, involving state-of-the-art cyber capabilities.”
Advertisement
As VentureBeat previously reported, the episode also exposed the flip side of blanket safety guardrails: when Hugging Face’s defenders tried to use commercial frontier models to analyze the raw exploit payloads and credential dumps from the attack, the models refused, and the company completed its forensic reconstruction only after switching to a Chinese open-weight model, GLM 5.2, run locally.
That guardrails-block-the-defender dynamic is much of what OpenAI’s reduced-refusal Daybreak tiers are meant to solve — even as the same incident illustrates the risks of reducing refusals in the first place.
OpenAI is careful to draw a line between that incident and this product. In the Daybreak announcement it states directly that GPT-5.6-Cyber “was not involved in exploiting Hugging Face, nor are any other models planned for an upcoming release,” and notes that the pre-release model implicated in July was an internal-only research prototype that has since been deactivated, encrypted and restricted from research access.
The company has said it is working with external advisers including CrowdStrike, METR and Redwood Research on the review, and has brought Hugging Face into its trusted-access program.
Advertisement
In my assessment, the access model still leaves OpenAI with a hard question: whether keeping GPT-5.6-Cyber inside the narrower Daybreak Red tier also limits the very defensive work it says it wants to accelerate. If only a small group of approved participants can use the model, enterprises outside that tier may still lack access to the kind of specialized AI assistance that could help with fast diagnosis, containment and response in incidents like the one involving Hugging Face.
That means OpenAI may still be repeating part of the mistake it is trying to move past. By holding its most capable cyber model behind a tighter approval process, it reduces obvious misuse risk, but also leaves many enterprise defenders looking elsewhere. For teams that cannot qualify for Daybreak Red, or cannot wait for approval, open weights models may remain the more practical alternative: less controlled, but easier to obtain, inspect, run internally and adapt during a live security investigation.
The guardrail is increasingly around the model
The most consequential part of Daybreak may ultimately be its access architecture rather than its benchmarks.
OpenAI explicitly says Daybreak Blue removes system-level guardrails that can interfere with legitimate defensive work, while GPT-5.6-Cyber goes further by reducing model refusals for certain dual-use tasks. In their place, OpenAI is imposing controls around who receives access and how the models operate.
Advertisement
Daybreak access is restricted to approved individuals and organizations performing authorized work. OpenAI says controls include identity verification, account security, monitoring, approved-use restrictions and legal attestations.
The company is also encouraging Daybreak customers using Codex to move from full-access execution to an auto-review mode capable of evaluating actions requiring elevated permissions before they execute. Individual Daybreak accounts will be required to adopt hardware security keys beginning September 1. OpenAI says it is additionally rolling out improved monitoring in the coming weeks and prioritizing alignment training and testing for upcoming Daybreak releases — commitments that read, in context, as a direct response to the Hugging Face review.
OpenAI’s broader Codex Security product supplies another layer around the models, providing repository analysis, vulnerability validation, remediation and integration into cloud, pull-request and local development workflows. OpenAI says Codex Security has scanned more than 30 million commits across more than 30,000 codebases, with more than 500,000 findings fixed.
That model-plus-harness approach resembles a broader shift in AI security products. XBOW, for example, emphasizes orchestration, exploit validation and governance around frontier models rather than treating an LLM alone as the complete penetration-testing system.
Advertisement
OpenAI nevertheless acknowledges that increasingly permissive cyber models create additional risks, whether from misuse or misalignment. It assesses both GPT-5.6 Sol and GPT-5.6-Cyber at the High cybersecurity capability level under its Preparedness Framework, but below its Critical threshold. A fuller GPT-5.6-Cyber system card is planned for later publication.
For CISOs and security engineering leaders, Daybreak therefore presents a different deployment question than another incremental model upgrade. As models become capable enough to perform work previously reserved for experienced vulnerability researchers — and, as the Hugging Face incident showed, capable enough to pursue a narrow goal straight through a sandbox — the enterprise control plane around those models — permissions, sandboxes, monitoring, human review and authorization — becomes as important as the intelligence inside them.
The one-man F&B biz sells over 2,000 chimney cakes a month
Hungary’s official national dessert, kürtőskalács (also known as kurtos), is not exactly a familiar sight in Singapore. The chimney-shaped pastry is characterised by a caramelised crust wrapped around a hollow, pillowy centre.
One of the few places you can find it is at VivoCity, where Rollneyhas been selling the Hungarian treat since 2024.
According to founder Narresh Babu, kurtos remains virtually unknown in Singapore. But he’s betting that’s about to change.
We spoke with Narresh about how he brought the brand to Singapore, built it beyond a single dessert shop, and where Rollney is headed next.
Advertisement
Rollney was first founded in Malaysia
Rollney Malaysia’s Perak store./ Image Credit: Rollney Official
His idea was to pair the cylindrical pastry with soft serve ice cream, blending Hungarian baking with Asian dessert preferences. The brand eventually grew to 12 outlets across various states like Kuala Lumpur, Johor Bahru, and Perak.
Rollney Singapore launched in Jan 2024 when Narresh, a friend of Yee Ke, joined him through a joint venture. Narresh became director of the Singapore business, overseeing its local operations and international expansion independently of Rollney Malaysia.
He invested S$260,000 into the Singapore operation, with 60% coming from his own savings and the remaining 40% from a family loan. His relatives later told him to keep the money for expansion instead.
Each Rollney kurtos starts with a sweet, yeasted dough that is portioned and hand-wrapped around a traditional wooden spit. After proofing, the dough goes into a customised vertical oven, where multiple rolls can be baked at once.
Each one is made to order and takes around three to five minutes to bake.
Advertisement
The roll is filled immediately after it comes out of the oven. Crunchy toppings and compote are layered into the hollow centre before soft serve is added on top, followed by the customer’s choice of toppings.
There are more than 30 options, ranging from Milo powder and pistachio sauce to lemon pie sauce, Oreo crumbs and seasonal specials.
The soft serve is also made in-house daily at Rollney’s central kitchen.
We do not buy from suppliers, but produce our own ice cream, so we know the quality of the ice cream is different from any other soft serve.
Narresh Babu
Advertisement
A one-man F&B show
Image Credit: Rollney Singapore
Rollney started with a humble 300 sq ft store at VivoCity.
The first three months were promising. Then, sales started to dip.
“It doesn’t matter if you’ve got a good product, a fun store or a nice concept. It doesn’t mean people will just come in and buy,” Narresh said. “Awareness is the biggest key for everything.”
Narresh began putting more time into Rollney Singapore’s social media in Jul 2024, and sales gradually recovered.
But getting customers through the door was only part of the challenge. The shop’s average profit margin was between 25% and 28% in 2024, according to Narresh, but fell to 6% in 2026.
Advertisement
With an average customer spend of S$5 to S$8, the economics of running a physical F&B outlet were also difficult. Narresh estimated that Rollney needed roughly twice the daily transactions of a restaurant to cover the overheads of five staff and rent.
Rather than opening more outlets or switching to a different product, Narresh started looking for ways to make the same product work harder.
When he ran the numbers for a second physical store, he realised that the cost would be roughly equivalent to deploying six soft-serve vending machines.
That comparison led Rollney Singapore in a very different direction.
Advertisement
A new way to sell soft serve
Rollney Singapore now has 30 soft serve vending machines all over the city./ Image Credit: Rollney Singapore
In Nov 2025, Narresh invested S$125,000 to deploy five machines.
He said they were the first vending machines in Singapore to use a robotic arm to serve ice cream from scratch within the unit.
Unlike a physical outlet, each machine could be placed in a different location to reach different customer groups. And if a site underperformed, Narresh could simply move the machine elsewhere without being locked into a long-term lease or having to hire additional staff.
The machines also offered something a traditional vending machine couldn’t: a bit of spectacle. The robotic arm has become a draw in itself, with Narresh noticing that children in particular get excited when they see it in action.
Building multiple businesses around one dessert
Rollney’s answer to the challenges of running a small F&B outlet was not simply to sell more kurtos. It was to find more ways to make money from the same product.
Advertisement
Today, the business has four revenue streams: its physical VivoCity outlet, its own fleet of soft serve vending machines, a vending machine franchise model, and event rentals.
Image Credit: Rollney Singapore
The VivoCity store remains the brand’s public face and the only place where its kurtos rolls are made. But even that is being reworked. The current store will close on Sept 5 and reopen in Oct as a much smaller 20 to 40 sq ft kiosk, allowing Rollney to maintain its presence at VivoCity while cutting its rental costs.
The bigger bet, however, has been on vending machines. Rollney’s own machines dispense fresh soft serve from S$3 a cup, with sales growing by around 3% to 4% month-on-month. They have sold between 20,000 and 25,000 cups to date.
Narresh then realised he could sell more than just ice cream through the machines—he could sell the machines themselves.
Rollney now offers the vending machines as a franchise, charging operators S$28,000 per unit. In return, the company takes care of the operational work, including cleaning, maintenance, servicing and refills. The model gives franchisees a way into F&B without having to deal with the staffing, kitchen and day-to-day demands of running a traditional outlet.
Advertisement
Servicing costs around S$6,000 per run and covers 12 to 15 machines at a time. As more machines join the network, those costs can be spread across a larger base.
There are now 30 franchisees operating Rollney vending machines across Singapore, with the network on track to reach 50 machines by Sept.
Rollney’s fourth revenue stream comes from event rentals, where the machines are brought to corporate events and private functions. It gives the company another source of income while also putting the brand in front of potential customers beyond its usual retail locations.
In the span of a few years, Narresh has effectively built several businesses around one dessert. The kurtos may still be unfamiliar to many Singaporeans, but Rollney is no longer relying on customers walking into a shop to discover it.
Advertisement
A business refusing to stay still
Rollney Singapore’s Kaya Toast Kurtos and World Cup Argentina Kurtos./ Image Credit: Rollney Singapore
One of the more interesting aspects of Rollney Singapore is how quickly Narresh can take an idea from concept to counter.
The latest example was the Milo Dinosaur Kurtos, a limited-time National Day special that was conceived, tested and launched within three days.
Narresh’s process starts with the occasion. He thinks about what Singaporeans associate with it, then works backwards to see whether those flavours can be translated into a kurtos or ice cream combination.
“Milo Dinosaur is the first thing that tourists come here to try. So I came up with the Milo Dinosaur Kurtos,” he said.
The same thinking went into the Kaya Toast Kurtos, which combines Hokkaido ice cream with pandan kaya and sugar breadcrumbs for crunch.
Advertisement
Narresh during the 2026 World Cup Season./ Image Credit: Rollney Singapore
That speed is partly a product of how closely Narresh is involved in the business. There is no purchasing team or R&D committee to run ideas through.
“The good thing about being so involved is there’s no approval process in between,” he said. “I decide everything.”
He sources the ingredients, tastes them individually and together, works out whether the flavours and textures fit, and calculates whether the final product can be sold at a price customers will accept. If it works, it goes on the menu. If it doesn’t, he drops it.
That approach has allowed Rollney to experiment at a pace that would be harder for a larger F&B operation. During the 2026 World Cup, for instance, the brand came up with 10 different kurtos flavours inspired by 10 popular footballing nations.
The experimentation appears to have translated into a steady volume of sales. Rollney Singapore currently sells around 2,000 to 2,500 chimney cakes a month.
Advertisement
But Narresh’s ambitions extend beyond creating more flavours. He is targeting 100 vending machines across Singapore by Jan 2027, followed by another two to three physical outlets by the end of 2027.
For him, growth is not simply about how many stores Rollney can open.
“Some people feel they measure the success of a shop by how many outlets they have, but they don’t see the behind-the-scenes of the hard work behind just one single store,” Narresh said.
Rollney Singapore has come a long way from the 300 sq ft shop where it started—and Narresh’s next phase of growth looks increasingly like it will happen outside the four walls of a traditional F&B outlet.
Corma raised $60M seed from Sequoia, Khosla, Coatue. Building first defensive cybersecurity foundation model. In simulations, AI attackers won 88%, defenders caught 12%. Already deployed at Fortune 100/500 orgs. Team from DeepMind and Unit 8200.
In hundreds of simulations modelled on Fortune 500 companies with dozens of security tools, Corma tested leading AI models including GPT and Claude. First, the models attacked the simulated organisations and planted persistent threats. Then the same models were asked to defend and find what they had planted.
The attackers succeeded in 88% of simulations. The defenders caught 12%. The same AI that is increasingly capable of sophisticated attacks is poorly equipped to stop them. Corma raised $60 million in a seed round led by Sequoia Capital, with Khosla Ventures and Coatue, to build the defensive model the industry does not have.
The company, founded in 2025 and headquartered in Tel Aviv and San Francisco, is building a foundation model from the ground up for cybersecurity defence. Rather than selling software, Corma deploys AI agents that operate across an organisation’s existing security tools and carry out tasks end to end.
Advertisement
“We don’t replace anyone and we are not a product,” CEO Alon Pluda told Calcalist. “We sell virtual human resources.” Each organisation determines how many it needs. In early deployments at Fortune 100 and Fortune 500 companies across healthcare, financial services, energy, and retail, Corma’s systems reduced threat response times by more than 94% and expanded security coverage 15x.
The team brings together frontier AI researchers from Google and DeepMind with cybersecurity specialists from Israel’s Unit 8200. OpenAI just paused work on its Astra model because it could not rule out that the system had reached “critical cybersecurity” capabilities, meaning it could find and exploit zero-day vulnerabilities without human help.
That is the offensive side accelerating. Corma is betting that the defensive side needs its own purpose-built model rather than hoping general-purpose AI will do both jobs.
The gap Corma identified is structural. Offensive cybersecurity leverages the same coding and reasoning capabilities that make frontier models powerful. Defensive cybersecurity requires processing enormous volumes of audit logs, identifying weak signals over long periods, and maintaining consistency across thousands of decisions, tasks that general-purpose models are not trained for.
I have used Finder for as long as I have owned a Mac, and for most of that time, I never gave it a second thought. You open a window, dig through some folders, drag a file where it needs to go, and move on with your day. That’s just how it works, right?
Except it should not. Constantly opening new windows to move a file from one folder to another, waiting on searches that dig through my entire drive when I only want results from one folder, resizing the same columns over and over because they never remember their width (this one is especially galling) should not be normal.
None of it feels like a big deal on its own. But add it up over months and years of daily use, and it’s a lot of wasted clicks. Even then, I was not specifically searching for a solution, because in truth, I didn’t even know the problem existed. That is, until I discovered Bloom, and that changed everything. It has become one of my favorite Mac utilities, so let’s talk about it.
Multiple panes changed how I work
The first thing that hooked me was Bloom’s multi-pane layout. Instead of juggling separate Finder windows to move files around, Bloom lets you split a single window into several panes. There are up to 12 configurations to choose from, and you can set any one as your default setup.
Advertisement
Rachit Agarwal / Digital Trends
My go-to setup is three panes, a bigger one on the left and two smaller ones stacked on the right. The main three folders I access are the main directory, the Downloads folder, and the Documents folder. I keep the main directory open in the left pane, while the two other folders get the small right pane. Any time I want to move a file between the three folders, I can drag and drop without opening a new window.
Rachit Agarwal / Digital Trends
Even better, you can save these pane setups as Workspaces. I have a few saved for different parts of my routine, so when I sit down to work, I pull up the right workspace from the toolbar or a keyboard shortcut, and everything is exactly where I left it.
A floating window that follows you around
One of my favorite features of Bloom is something called the Portal, a small window that can float on top of whatever app you’re using. Think of it as a shelf for files you need to grab repeatedly while working somewhere else. I use it constantly whenever I need to pull files into another app without losing my place or breaking focus on what I’m actually doing.
Rachit Agarwal / Digital Trends
Search finally makes sense
The one feature that saves me more time than anything else in Bloom is its search capabilities. I can hit a global shortcut, type a folder name, and jump straight to it from anywhere. It’s far superior to the Go to Folder feature in Finder.
Rachit Agarwal / Digital Trends
Another thing I like about Bloom is that by default it searches inside the folder and not my entire Mac directory. I can hit Command-F, and instead of searching my entire drive as Finder does by default, which is both needless and time-consuming, Bloom searches the folder you’re currently in.
The little things I didn’t know I needed
Beyond the big features, Bloom is full of small touches that quietly save time. It can peek inside zip files and other archives without making me extract anything first, and lets me partially extract files.
The Columns resize themselves automatically instead of me fussing with them every time a filename is too long. This is my biggest annoyance with the Finder, and I am so relieved that I don’t have to deal with it anymore.
Rachit Agarwal / Digital Trends
There’s a menu bar app for quick access to your favorites, folders, and workspaces, plus built-in image editing tools and a shortcut to pop open your current folder in Terminal.
There’s also Footprints, which logs every file operation you make, so if you delete something you shouldn’t have or a batch rename goes sideways, you can undo it. Finally, it packs a regex-powered rename tool, which is a genuinely useful upgrade over Finder’s basic version.
Advertisement
Should you make the switch?
Bloom is a simple app that can quietly slide into your workflow and improve your life. It looks and feels familiar enough that you can start using it immediately. That said, there’s a surprising amount of depth for anyone willing to dig in.
If you manage even a moderate number of files on your Mac, I think you’ll notice the difference within a day. If you ever found Finder annoying or just not sufficient, I highly recommend you buy this app. I have been using this app for a month or so, and I cannot imagine going back to the Mac’s Finder.
If you’re looking for somewhere soft to land at the end of each day, a Tempur-Pedic mattress is a safe bet. Tempur-Pedic is known for its super-soft memory foam mattresses, and has a huge range of products for you to end your day on. I’ve slept on everything from a Tempur-Pedic mattress to sheet sets and even pillows from the brand—truly, if there’s new bedding you need, particularly anything with a soft, sinking sensation to cradle you as you sleep, you can find it from Tempur-Pedic.
You can get the ultra-soft goods for a little cheaper thanks to WIRED’s Tempur-Pedic coupon codes, no matter what kind of super-soft bedding you’re hoping to find with Tempur-Pedic’s famous feel. Explore our Tempur-Pedic discount codes to get deals on mattresses, toppers, pillows, and more.
Save With the Tempur-Pedic Sale
Shopping the Tempur-Pedic sale is one of the best ways to score huge discounts on usually pricey buy-it-for-life items like mattresses. Tempur-Pedic offers and discounts rotate (but usually hover around 30% off), but I’d recommend checking back often to see what new items are on sale and what new seasonal discounts have sprung up. Some of the best Tempur-Pedic discounts we’ve seen are huge price reductions on pillow bundles, buy two and save 30% on sheet sets, and 25% off pillows and bedding.
Get a 30% Tempur-Pedic Promo Code When You Sign Up
This isn’t the “forward this email or be cursed” email chain you got as a kid. Sign up for Tempur-Pedic’s email updates, and get a solid 30% off discount on pillows and sheets. Plus, you’ll be the first to know about new launches, sales, and everything Tempur-Pedic is up to in the sleep realm. Why wait on savings and better sleep?
Advertisement
Tempur-Pedic
Tempur-Adapt ProAdjust Pillow
Tempur-Pedic
Tempur-Breeze ProHi Pillow
Advertisement
Save $300 and up to 50% Off With Today’s Tempur-Pedic Coupons
If you’re looking to stay cool and comfortable, Tempur-Pedic has got your back (literally). Right now, you get $300 off when you bundle a (qualifying) mattress with Tempur-Ergo power bases and ProSmart bases. Just as breezy as they sound, each of these mattress lines really emphasize cooling and aim to dial down the temperature—and from my prior testing experience, they are very cool to the touch. Speaking ofl, you can also get 50% off a TEMPUR-ProAir Sheet Set, which features a moisture-wicking design to keep you cool and comfortable while you sleep. On top of that, be sure to take advantage of more bedding deals, like 25% off pillows and bedding, pillow bundles starting at 2 for $69, and 30% off any 2 Tempur-Pedic sheet sets.
Purchase a Tempur-Pedic Mattress Set, Get $300 Off Bases
You’re one of those “all in” kind of people when it comes to big decisions—respect. Game recognizes game, and Tempur-Pedic’s giving you a deal that’s hard to pass up. When you get a select Tempur-Pedic mattress and a Tempur-Ergo adjustable power base, you can get $300 off the base. Plus, you can get 25% off select bedding and pillows to really go for the full package.
Tempur-Pedic
Tempur-ActiveBreeze
Advertisement
Enjoy $39 Off Bundle Discounts on Tempur-Pedic Pillows
Tempur-Pedic doesn’t just create high-quality mattresses that exemplify awesome pressure relief and spine alignment. It also has a variety of pillows to carry out this mission, because there’s no lack of support happening on their watch. You can bundle pillows and get a nice discount while you’re at it: Get two Tempur-Cloud Pillows for $119; two dual-sided Tempur-Symphony Pillows for $169, two Tempur-Cloud Dual Cooling Pillows for $259; or two Tempur-Neck Pillows for $179 and save $39. When one pillow already has a higher price tag, this is a really good deal to double up on.
Tempur-Pedic
Tempur-Adapt ProHi Pillow
Get Two Tempur-Pedic Sheet Sets and Save 30%
A nice pair of sheets can really make or break your sleep experience. Plus, you’ll need a few pairs depending on the season: something cooling like the ProAir for summer, rayon bamboo if you want a silky feel, or cottonflannel for a cozier vibe. You’ll want to invest in a few pairs for every season (not to mention for extra clean ones if you want to avoid laundry). When you buy 2 Tempur-Pedic sheet sets, you’ll save 30%.
The Big Bang Theory‘s Bernadette as a demon is something I didn’t think I’d ever see in Stuart Fails to Save the Universe — but, now that I have, it somehow makes complete sense.
Last week’s episode saw us meet her in a wizarding world but, in this week’s entry we’re swapping the magical action for something a little more One Flew Over the Cuckoo’s Nest-coded.
But who, if anyone, really is crazy? And when does Stuart Fails to Save the Universeepisode 4 arrive on HBO Max?
Advertisement
Latest Videos FromTechRadar
What time can I watch Stuart Fails to Save the Universe episode 4 on HBO Max?
Stuart Fails to Save the Universe 1×04 Promo “Stuart Makes a Wallet” (HD) Big Bang Theory spinoff – YouTube
For US viewers, Stuart Fails to Save the Universe episode 4 will drop on Thursday, August 13 at 6pm PT/ 9pm ET.
Internationally, you’re looking out for these timings:
US – Thursday, August 13 at 6pm PT / 9pm ET
Canada – Thursday, August 13 at 6pm PT / 9pm ET
UK – Friday, August 14 at 2am BST
India – Friday, August 14 at 6:30am IST
Singapore – Friday, August 14 at 9am SGT
Australia – Friday, August 14 at 11am AEDT
New Zealand – Friday, August 14 at 12pm NZDT
When do new episodes of Stuart Fails to Save the Universe come out?
Me and who being suited and booted for more episodes? (Image credit: HBO Max)
New episodes of Stuart Fails to Save the Universe will make landfall every Thursday in the US and on Fridays everywhere else. Here are the all-important dates you need to know about:
For as capable as smartphone hardware is, the software running on them can be especially restrictive and cumbersome. Unlike a single-board computer with GPIO running a standard Linux operating system and some intuitive programming language like Python, smartphones are generally walled gardens where programming major overhead, and if a custom program can be run on them at all the user still has to figure out how to interface hardware with a USB-C port. To skip past all of this, [nicolas.ma] built an audio modem that can send keyboard input to a computer with nothing more than a browser.
The “keyboard” starts off in a browser running on a standard smartphone. A user can input text into the browser, which then gets converted into a series of audible audio pulses that can be sent to the keyboard. The keyboard itself listens to those pulses, decodes them, and then sends the text through to the computer as a standard USB device thanks to an Arduino Micro at the center. Arduino Micros are excellent choices for keyboard controllers because they have a built-in USB chip.
The protocol used here is designed and built by [nicolas.ma] as well. The words allow for variable length, with the device determining message length, and a word-ending scheme that automatically sends the message to memory when it’s detected that the message is finished. There’s also integrity checking and the ability to check on the link’s state. From hardware to software it’s an impressive build, and for anyone wondering what this might be used for [nicolas.ma] has already built a password manager from it.
You must be logged in to post a comment Login