Connect with us
DAPA Banner

Tech

Best Merino Wool Clothing (2026): Base Layers, Hoodies, Jackets & More

Published

on

Merino wool is a super fiber. The best merino wool clothing somehow manages to be comfortable in 95-degree heat, and merino base layers keep you warm well below freezing. Unlike synthetic fibers derived from petroleum, merino wool is natural and renewable.

Merino wool’s versatility means there’s a bewildering array of blends and options to choose from. Here are our favorite merino wool products that we’ve tested by wearing and washing (usually in cold water, and hung to dry, although we do machine dry them just to see what happens) over the course of months and even years in some cases. Once you’re done here, don’t forget to check out the rest of our apparel guides, like the Best Merino Wool T-Shirts, Best Base Layers, Best Puffer Jackets, Best Hoodies, and Best Hiking Boots.

Updated April 2026: We’ve changed out top pick boxers to Wool & Prince, added more hoodies, and the Ibex women’s Goat short sleeve. We also updated prices and links throughout.

Table of Contents

Advertisement

Why Is Merino Wool So Great?

Merino wool is great because you’re stealing a sheep’s ability to keep itself warm or cool based on the temperatures it’s in, a process often referred to as thermoregulation. If you’ve only ever worn the sort of itchy wool sweaters your proverbial grandmother supposedly made, you might wonder what all the fuss is. The answer is that Merino sheep have thinner, softer wool, which has evolved to keep them comfortable across a wide range of temperatures and is comfortable to wear next to your skin. Wool is sustainable, too.

One sheep can produce 4 to 5 pounds of wool per year. That’s because the sheep that make merino wool drink only the purest alpine waters and study the art of comfort under the tutelage of those stuck-up Pashmina goats, who, let’s face it, might know a thing or two about wonderfully pillowy softness. Just kidding. Merino sheep do have that softer wool though, and merino wool is a remarkable fabric that’s become the cornerstone of my wardrobe.

Merino wool comes in different weights, which you will frequently see listed as “200 gsm” or something similar. (The “gsm” refers to grams per square meter, sometimes listed as g/m.) What’s important is the scale and where your garment falls on it. At the low end, you have T-shirts and underwear, which are typically 150 gsm, though we have seen some as low as 120 gsm. Generally, anything below 200 gsm will be a good base layer or T-shirt. From 200 to 300 gsm are your mid-layers, and anything above 300 is a heavier garment.

Advertisement

If you’re more familiar with synthetic ratings like those often used on fleece, know that, in my experience, about 120–160 gsm wool corresponds to 100-weight fleece, 160–200 gsm wool roughly matches 200-weight fleece and 200+ wool is like 300-weight fleece. In every instance, the wool is warmer because it’s better at trapping heat, especially in the wind. (That said, there are reasons to go with fleece at times, like how incredibly lightweight it can be.)

Nuyarn is a merino wool/synthetic hybrid weave, wherein merino wool is wrapped around a nylon core for warmth, lightness, and extra durability. The idea is to get the temperature regulation benefits of merino, but to add some of the longevity of nylon. In my experience, Nuyarn mostly works. It’s our top pick for base layers, though I find it less necessary in more casual garments, where I prefer 100 percent wool.

How to Care for Merino Wool

Most merino products will have care instructions. Most likely it will be to wash cold and lay flat to dry. The latter is important, as hanging wool to dry will stretch it out (because of the water weight). While most merino labels say the garment can be machine washed, my experience has been that hand-washing merino will extend its life. This is particularly true of very lightweight (150 gsm) merino base layers and T-shirts. The exception is Minus33’s Microweight Raglan short sleeve T-shirt, which is machine-washable and dryer-friendly. Having done both to mine for over a year, I can vouch that it does indeed hold up.

Advertisement

I’ve never had a problem storing merino in my closet between wears, but for long-term storage, I recommend you take precautions against moths, which are notorious for eating holes in wool. I have lost merino garments to moths.

If you don’t want to smell like mothballs, there are better solutions. I make sure to wash and thoroughly dry whatever I am storing, then I seal it in a compression bag, like this. Another option is to put your merino garment in a cotton bag or otherwise wrap it in cotton and then put it in a plastic bin. It’s very important to make sure that the garment is completely dry before using any of these storage methods, otherwise your wool will smell musty and moldy. Other options include storing your garment in a cedar chest, which is a good natural deterrent for moths, or use moth traps or lavender sachets, which will repel the moths.

100 Percent Merino vs. Blends

Should you buy 100 percent merino or should you go for a blend? The answer is … it depends. On the garment in question, the use case, and your preferences. Probably the best way to find out is to try several and see what you like. One advantage to blends is that they’re stretchy, which makes them better for active pursuits like hiking, rock climbing, and the like. I like 100 percent merino for heavier mid-layers like hoodies or jackets, but I prefer blends for lighter layers. My experience has been that the closer I get to my skin, the more blend I want, with Nuyarn being my top pick for base layers.

Advertisement

There are also some alpaca blends out there that are also wonderfully soft (I love everything I’ve tried from Paka and Arms of Andes). If you’re one of the rare people who do find merino itchy, you might be allergic to lanolin, which is the skin oil produced by sheep. Alpacas don’t make lanolin, and the fibers are thinner and finer than merino. That makes alpaca warmer and softer, but it’s also more expensive.

Merino vs. Synthetic Fibers

Which is better? The answer again is … it depends (sorry). But usually merino. By synthetics, I generally mean polyester, nylon, polypropylene, rayon, or blends of these and other fabrics—everything but cotton, wool, and linen.

Synthetics generally win for wicking away sweat, which means they tend to feel drier. They also tend to dry faster, so when it comes to things like socks and underwear, even most “merino” options are often more than 50 percent synthetic. Synthetics are just better at handling moisture. How much this matters depends on a host of personal factors. For example, I feel weird and almost clammy in anything synthetic, so I don’t really care how much moisture it wicks away.

Advertisement

The downside to that moisture wicking is that synthetics retain odor. There are some chemical treatments that can help, but I’ve never tried anything synthetic that was as odor-resistant as merino wool.

Another difference is breathability. Synthetics are passable in this department, but it’s where merino really excels. If you’re hot and are hiking up an exposed slope toward an open pass and then dropping down into the cool of a forest, merino is your friend, because the breathability means less sweat to cool you when you get out of the sun. Again, how much this matters depends on your body.

The final factor worth thinking about is durability. In some cases, synthetics will last longer than pure merino, particularly in scenarios where abrasion is a major source of wear. To my mind, this is just another reason to choose a merino blend rather than going all the way to synthetics, but it’s something to think about if you do a lot of off-trail hiking or rock climbing—any activity where your clothes are going to take a beating.

Base Layers

Advertisement

To really see how remarkable merino wool is, start at the bottom, with the clothes next to your skin. Merino really shines as a base layer. It’s warmer for the weight, wicks moisture well, and unlike synthetic fabrics, merino stays stink-free for days of wear. Be sure to read our layering guide for more on how to put it all together and stay comfortable in any weather. We also have a separate guide to the best base layers if you want know all your options, but here are our top merino picks from that guide.

Best Lightweight Base Layer

Ibex Woolies Pro Tech Crew in teal

Ibex

Woolies Pro Tech Crew

The Ibex Woolies Pro Tech base layer crew is the best lightweight merino base layer we’ve tested. If you want a hard-wearing shirt, this it it. Woolies are Nuyarn (see above), which is 85 percent merino wool and 15 percent nylon—the merino wool is wrapped around a nylon core, which increases the warmth while being lighter (5 oz for the men’s large) and more durable. This is my top pick for all things technical. It’s what I bring hiking, backpacking, and it’s reviews editor Adrienne So’s pick for running, climbing and other high-aerobic activities when it’s cold. I also love the Woolies Pro Tech Bottoms ($115), which are what I bring backpacking in all but the warmest of weather. There’s also a quarter zip version of the shirt if you prefer.

Advertisement

Aside from comfort and warmth, a bit part of the reason we recommend Woolies is that they last. Ibex is what passes for a heritage company in this space; the company was founded in 1997 and has been cranking out merino garment for a long time. Adrienne’s parents bought her two sets of Ibex base layers in 2001 that she still wears today, in the year of our Lord 2025. Properly cared for, Woolies will keep you comfortable warm for years to come.

Best Heavyweight Base Layer

Smartwool all season merino long sleeve t-shirt in green

SmartWool

Merino Classic Long-Sleeve

When I want something a bit warmer than the lightweight Woolies above, I reach for Smartwool’s Classic long sleeve base layer. These may be the most popular merino shirts around, and for good reason: They’re very comfortable, tending to the looser side, feature heavy duty seams that don’t rub, and sit off the shoulder for more comfort when wearing a pack. At 87 percent merino wool (blended with nylon), these are also very durable while remaining lightweight (10.3 oz for a men’s large). This Smartwool shirt, along with the matching pants ($125), are great for chilly winter days.

Advertisement
Unbound Long-Sleeve Merino Crew shirt in green

Courtesy of Unbound Merino

Unbound Merino

Long-Sleeve Merino Crew

The picks above all have what my wife calls “that sporty look,” which the industry refers to as “technical.” This 100 percent merino shirt from Unbound is the opposite: it just looks like a long sleeve shirt. It’s incredibly soft and while it does pill a bit if you run it through the dryer (don’t), it’s proved itself plenty durable—I’ve been wearing it constantly for over a year now and it still looks like it did when I got it. It’s the long-sleeve, base layer twin to our favorite T-shirt (see below). It’s on the thin side for a base layer, which makes it perfect for those cool weather mornings in the shoulder seasons. It’s versatile too; it can be used as a base layer, but it also works as a T-shirt when it’s not too chilly. Fit runs true to size, and if the one you want is sold out, be patient; Unbound frequently updates its stock.

There are so many! Here’s a few more to consider, but really, go read the base layer guide.

Advertisement

Ridge Merino

Aspect High Rise Base Layer Bottoms

These are another great option fro women looking for something that can be worn around town as well as on the trail. My daughter has even worn them under shorts for no-gi juijitsu and they’ve held up great, which is a testament to their durability.

Minus33

Advertisement

Heavyweight Yukon Thermal Long Sleeve

If you’re going to be in extreme cold, New Hampshire-based Minus33 is the company to shop. Where I live winter temps regularly dip below 0F and the Yukon comes into its own. The 400 gsm weave of 100 percent merino is more like a sweatshirt than a base layer, but if you live in the north, you need it.


2 pieces of rectangular fabric overlapping, one in green and one in red, to show the Turtle Fur Merino Pipe Dream Neck Gaiters

Turtle Fur

Merino Pipe Dream Neck Gaiter

Don’t forget your neck. I live in this Turtle Fur gaiter during the winter and I also use the lighter, superfine version for hiking at elevation in the summer to keep the sun off my neck without resorting to sunscreen. It’s wonderfully soft, not overly tight, and never smells.

Advertisement

Merino Mid Layers

Fleece has its place, but I rarely wear it these days. I prefer merino for my mid layers. It’s better at helping your body regulate its temperature. The one place fleece still wins for me is backpacking. It’s almost always lighter for comparable warmth, at least in mid layers.

Two versions of the Ibex Mammoth Hoodie, one in white and one in black

Like the Northern Lights or the McRib, the thickest Ibex wool hoodie appears irregularly and with some fanfare. The Mammoth Hoodie is indeed a big, furry beast of a garment—it’s basically the weight of the classic American Giant hoodie but made of 85 percent wool cut with 15 percent nylon for added warmth and stretch. Ibex says it’s the warmest hoodie they’ve ever made, and in my week of testing, I’ve used it in place of a jacket in mid-30s temps. It has an athletic cut with zippered pockets and thumb holes. I do wear a stocking hat with it in the cold because the scuba hood is meant to fit under a helmet which means it’s too small to provide enough warmth for my large shaved head on its own. —Martin Cizmar

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

How Russia’s SU-34 Flies So Far Without Refueling

Published

on





Back during World War II, Adolph Hitler dreamed of bombing the United States, but technology at the time literally couldn’t deliver. Nowadays, intercontinental flights are easy, thanks to aerial refueling. That’s how most aircraft in the United States Air Force operate, but the Russian Federation’s Su-34 is a completely different type of jet. The Su-34 Fullback can fly from Moscow to Washington, D.C. without refueling, which is impressive, seeing as that’s a distance of 4,867 miles.

There are several reasons why the Su-34, which Russia has used in the Russo-Ukrainian War, can fly so far. For one, it’s a massive aircraft, measuring 76.5 feet in length with a 48-foot wingspan. Under normal operations, it doesn’t need to go that far. In cases where it might be needed, it can add three PTB-3000 external fuel tanks to its hard points, which normally accommodate weapons, significantly increasing its range. Each of those tanks holds 793 gallons of fuel, which is added to the bomber’s internal fuel capacity.

Advertisement

That fuel capacity gives the Su-34 a ferry range of 2,485 miles. Once you add the external fuel and push the Su-34 to its limits, its range can exceed 4,971 miles. That puts it in range to strike Washington, D.C., though it wouldn’t be able to make a return trip home without refueling. Granted, it’s unlikely that Russia would ever use its Su-34 fleet in such a manner, but it could, making the Su-34 one of the most powerful non-American fighter jets in service.

Advertisement

The Su-34 is the world’s longest-range fighter (currently)

With its added drop tanks, the Su-34 is the world’s longest-range fighter, and it’s not even close. The United States’ longest-range fighter is the F-35C Lightning II, which has an internal fuel capacity of 3,002 gallons. That gives it a range of 1,381 miles. The F-35 doesn’t have drop tanks, but they are being designed for the Block 4 upgrade that’s expected to be complete no sooner than 2031. Of course, aerial refueling can indefinitely extend the F-35’s range.

Still, it pales in comparison to the Su-34. Additionally, the Su-34 will likely receive an upgrade in the form of the AL-51F engine, which was developed for the Su-57 5th-generation fighter. The Su-34 is a 4.5-generation fighter (sometimes referred to as a 4++ generation), thanks to various upgrades that keep it flying. With the introduction of a more fuel-efficient engine, it’s likely that the aircraft’s range will increase significantly, making it a truly intercontinental strategic aircraft.

The Su-34 first entered the Russian inventory in 1990, and it has a proven track record. While it’s unclear how many Russia has, estimates put the Russian Air Force’s inventory at around 123 Su-34s. Production continues, and several have been lost in Ukraine, so the total number in the inventory fluctuates over time. Regardless, Russia probably sees a future where the Su-34 remains an important part of its strategic focus, so it’s likely that the country will continue producing its intercontinental fighter for the foreseeable future.

Advertisement



Source link

Advertisement
Continue Reading

Tech

Your Push Notifications Aren’t Safe From the FBI

Published

on

Amid horrific threats from United States president Donald Trump as the US and Iran negotiated a ceasefire, the US government warned this week that Iran-linked hackers were carrying out attacks against US energy and water infrastructure targets. With nearly one in five people in Lebanon displaced by Israeli attacks, the government is attempting to manage the crisis without modern digital infrastructure and an emergency system that is barely hanging on. Plus, a WIRED analysis looked at Syrian government account hijacks in March and the inadequacies they expose in Syria’s baseline cybersecurity defenses.

Amid rising fears of political violence, a WIRED investigation found that US political candidates are spending more on security, including purchasing equipment like home alarms and bulletproof vests. And recent research looking at Telegram groups found that men are sharing thousands of nonconsensual images of women and girls, purchasing spyware to use against their wives and friends, and engaging in doxing and sexual abuse. Meanwhile, as governments scramble to address growing industrial scamming originating from Southeast Asia, China has emerged as the biggest enforcer, but also a selective one, resulting in crime syndicates shifting their focus abroad to avoid Chinese targets.

Anthropic formally announced its new Claude Mythos Preview model this week and said that for now it will only make the model available to a select group of a few dozen leading tech and financial organizations, including Apple, Microsoft, Google, and the Linux Foundation. The consortium, dubbed Project Glasswing, will explore Mythos Preview’s advanced hacking and other cybersecurity capabilities and assess the best ways to improve software and hardware defenses before capabilities like the ones in Mythos Preview proliferate more broadly across other models and inevitably end up in the hands of attackers. The announcements sparked controversy about whether Mythos Preview and similar capabilities will truly be as consequential for cybersecurity as Anthropic says. Experts told WIRED that while it may not be a dramatic catastrophe, it is important for defenders to come together and use their early access to make changes in how software is developed and how organizations around the world invest in patching.

Finally, a WIRED investigation found that nonprofit groups linked to Customs and Border Protection facilities were selling challenge coins that celebrated the Trump administration’s immigration raids, including one coin that depicted Charlotte’s Web characters in riot gear.

Advertisement

And there’s more. Each week, we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.

The FBI recently got its hands on copies of encrypted Signal messages being sent to a defendant’s iPhone because the contents of those messages were included in push notifications, 404 Media reports. Even though Signal had been removed from the phone prior to it being seized by the FBI, the notifications still lived on in the phone’s internal memory.

The issue affects all apps that send push notifications, not just Signal, but users of that app can adjust their settings to not show the content of a message or the name of the sender in push notifications. To adjust your settings for notifications going forward, open Signal and go to Settings, then Notifications, and change the option to Name Only or No Name or Content.

Despite the tenuous and contested ceasefire enacted in the US-Israel war with Iran, tens of millions of ordinary Iranians are still without regular and reliable internet connectivity. The regime-imposed internet blackout, which started during the first hours of the war on February 28, is now reaching the 1,000 hour point, according to internet monitoring group NetBlocks. In recent weeks, the internet shutdown has become the longest in Iranian history and one of the longest worldwide—depriving Iranians of accurate news about the war, stopping them contacting family and loved ones, and causing further economic harm to the nation. US-based Iranian digital rights project Filter Watch has detailed how the Iranian regime, while being bombarded during the conflict, has labeled anti-censorship tools as “malicious” and claimed to have arrested individuals using Starlink internet connections to get around the block.

Advertisement

The FBI’s annual internet crime report typically paints a bleak picture: year-on-year, the number of cybercrime reports increases and the amount of money lost by Americans shoots up. Unfortunately, 2025 was no different. Last year, according to the FBI’s annual report, losses reported to the Internet Crime Complaint Center topped $20 billion—an increase of 26 percent compared to 2024. More than half of these reported losses ($11.3 billion) were linked to cryptocurrency scams, often through fraudulent investment schemes, according to the FBI. Business email compromise, tech and customer support scams, personal data breaches, and confidence or romance scams, make up the other most common crime reports. Crimes mentioning AI led to $893 million in losses.

Google this week expanded Gmail’s end-to-end encryption to its Android and iOS apps, allowing enterprise users to compose and read E2EE messages natively on mobile for the first time without separate apps or mail portals required. Encrypted emails appear as standard threads in the Gmail app for recipients using Gmail, while those on other providers can access them via a secure browser view. This rollout builds on the client-side encryption model introduced to Google Workspace web users in April 2025, where messages are encrypted with customer-controlled keys, preventing Google from accessing their contents. The approach is particularly appealing for organizations with strict compliance requirements, including HIPAA, export controls, and data sovereignty regulations.

Access, however, remains limited: The feature is available only to Google Workspace Enterprise Plus customers with the Assured Controls or Assured Controls Plus add-on, and is not supported for personal Gmail accounts. Administrators must also explicitly enable the Android and iOS clients in the admin interface before eligible users can access the feature, which is off by default. End users then toggle encryption per-message by tapping the lock icon and selecting “Additional encryption,” mirroring the web workflow. The rollout is available immediately to both Rapid Release and Scheduled Release domains.

Source link

Advertisement
Continue Reading

Tech

A Suction-Driven Seven-Segment Display | Hackaday

Published

on

There’s a long history of devices originally used for communication being made into computers, with relay switching circuits, vacuum tubes, and transistors being some well-known examples. In a smaller way, pneumatic tubes likewise deserve a place on the list; [soiboi soft], for example, has used pneumatic systems to build actuators, logic systems, and displays, including this latching seven-segment display.

Each segment in the display is made of a cavity behind a silicone sheet; when a vacuum is applied, the front sheet is pulled into the cavity. A vacuum-controlled switch (much like a transistor, as we’ve covered before) connects to the cavity, so that each segment can be latched open or closed. Each segment has two control lines: one to pressurize or depressurize the cavity, and one to control the switch. The overall display has four seven-segment digits, with seven common data lines and four control lines, one for each digit.

The display is built in five layers: the front display membrane, a frame to clamp this in place, the chamber bodies, the membrane which forms the switches, and the control channels. The membranes were cast in silicone using 3D-printed molds, and the other parts were 3D-printed on a glass build plate to get a sufficiently smooth, leak-free surface. As it was, the display used a truly intimidating number of fasteners to ensure airtight connections between the different layers. [soiboi soft] used the display for a clock, so it sits at the front of a 3D-printed enclosure containing an Arduino, a small vacuum pump, and solenoid valves.

This capacity for latching and switching, combined with pneumatic actuators, raises the interesting possibility of purely air-powered robots. It’s even possible to 3D-print pneumatic channels by using a custom nozzle.

Advertisement

Thanks to [Norbert Mezei] for the tip!

Source link

Advertisement
Continue Reading

Tech

Oxygen Made From Moon Dust For First Time

Published

on

“Breathable oxygen has been created from Moon dust,” reports the Telegraph, “in a world first that paves the way for a lunar base.”

Jeff Bezos’s Blue Origin “”announced this week that it had developed a reactor that could successfully release oxygen from lunar soil by using an electric current.”

Almost half of Moon dust — the thin layer of rock that blankets the lunar surface — is oxygen, but it is bound to metals such as iron and titanium… Previous work to isolate oxygen has been lab-based, and the unwieldy equipment needed has been too difficult to send to the Moon. In contrast, Blue Origin said its small-scale reactor, named Air Pioneer, could be made flight-ready to “provide the first breath of life for a sustainable Moon base”… As well as breathable air, Blue Origin said the reactor produces other critical elements for planetary infrastructure, such as iron, aluminium and silicon for construction and electronics, as well as glass for windows and solar panel covers. The company has previously said it wants to turn the Moon, and eventually Mars, into “self-sustaining worlds where robots and humans can go beyond visiting and truly explore, grow, live, and thrive”….

Blue Origin said it would need to generate around one megawatt of power to drive the reactors — about the energy it would require to power around 400 to 1,000 homes simultaneously. It envisages that each lunar settlement would have an array of nearby solar panels, generating the power needed for one reactor.
Besides breathable air for astronauts, the oxygen could also be used in propellant for refuelling landers and fuel cells, Blue Origin points out — and “produced right where they’re needed, and at much lower cost than being brought from Earth.”

Advertisement

Thanks to Slashdot reader fjo3 for sharing the article.

Source link

Continue Reading

Tech

X readies dedicated messaging app as XChat goes live on App Store

Published

on

Early in March, X (formerly Twitter) started testing a dedicated app called XChat among thousands of beta testers. It appears that the test phase is over and the app is ready for its public rollout. The Elon Musk-owned company has announced that XChat is now listed on the App Store, with a wide launch lined up in the coming days. 

What’s the big play? 

The chat app’s listing page on the App Store mentions a release date of April 17, and it will be available simultaneously for iPhone and iPad. As far as features go, the XChat app is advertising end-to-end encryption as one of its highlight features. For the unaware, E2E is currently deemed the safest security protocol to ensure that your messages are private, and no middleman or third-party (including the company that built the platform) can read your conversations. 

WhatsApp and Signal, for example, implement it by default. On Instagram and Telegram, there’s a dedicated private chats feature that relies on end-to-end encryption to protect your messages.

Circling back to XChat, it will also enable screenshot blocking, which means no participant in the conversation can take a screengrab of the chats. The app will let users edit or delete sent messages, and will also let them send disappearing messages. Calling and group chats will also be a part of the package.

Ever since Musk took over X (which eventually merged with xAI, followed by a broad merger with SpaceX), plans for creating a super-app took center stage. Back in December, Musk quipped that he wants to transform X into something like WeChat, the Chinese app that allows everything from messaging and payments to reservations, among a whole bunch of other quirky services. In June last year, it was reported that the X super app would also offer investment and trading services once the super app plans materialize. 

Advertisement

Why is this an interesting shift? 

There’s more to the plans than a straightforward messaging pivot to XChat. Or at least that’s what Musk’s past claims, and the recent turn of events, suggest. On the surface, it would seem that Musk simply wants to serve a messaging app that fills the functional gaps that you can’t quite access on the social media app.

Just a day ago, Musk shared on X that WhatsApp can’t be trusted, referring to a lawsuit claiming that Meta allowed third parties access to the encrypted messages on WhatsApp. Even though WhatsApp has denied these claims, Musk’s statement added more fuel to the privacy fire. Separately, Telegram founder, Pavel Durov, claimed that WhatsApp’s encryption claims amount to the “biggest consumer fraud in history.” But that was not all.

Signal — one of the most widely trusted messaging apps out there, owing to its robust security protocols — also found itself in the line of fire. As per reports, the FBI was able to obtain the contents of Signal messages after accessing the notifications history on a suspect’s iPhone, even though the app allows a lock facility. Pavel also took a potshot at Signal, highlighting how Telegram never shows a message’s contents in the notification banner. 

It seems XChat is making a splashy public debut at a time when trust in the popular privacy-first platforms such as WhatsApp and Signal is coming under scrutiny. Moreover, it would be interesting to see if X offers all the features for free, or whether some of them will be locked behind a premium subscription, just like the sibling social media service. 

Advertisement

Source link

Continue Reading

Tech

Anthropic’s Glasswing project employs Mythos to prevent AI cyberattacks

Published

on

AI models now surpass most humans at finding and exploiting software vulnerabilities, said Anthropic.

A new Anthropic project will see global companies use Claude as part of their defence security systems.

‘Project Glasswing’ gives partnering companies access to Anthropic’s unreleased Claude Mythos, which, according to the AI giant, has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser. Mythos was launched in preview yesterday (7 April).

Anthropic’s Mythos preview is significantly more capable at generating exploits. In its research, the company noted that Mythos developed working exploits 181 times out of the several hundred attempts, while Opus 4.6 had a near 0pc success rate.

Advertisement

“We did not explicitly train Mythos preview to have these capabilities. Rather, they emerged as a downstream consequence of general improvements in code, reasoning and autonomy,” the company noted. Publications, including the New York Times and the Register have warned against the negative consequences of models such as Mythos falling into the hands of bad actors.

Fortunately, Anthropic has chosen not to release the model. Instead, the company is bringing together leading businesses, including Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JP Morgan Chase, the Linux Foundation, Microsoft, Nvidia and Palo Alto Networks, allowing them to access Mythos preview to boost their cyber defences.

The company has extended Mythos access to a group of more than 40 organisations that build or maintain critical software infrastructure.

“AI models have reached a level of coding capability where they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities,” said Anthropic.

Advertisement

Anthropic has promised to share learnings from Project Glasswing to benefit the wider industry. The company has also made a commitment of up to $100m in usage credits for Mythos preview across the project, as well as $4m in direct donations to open-source security organisations.

The Claude-maker has also hired Eric Boyd, the long-term president of AI platforms at Microsoft, to lead as the company’s head of infrastructure.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Advertisement

Source link

Continue Reading

Tech

Best Electric Cargo Bikes (2026): Urban Arrow, Lectric, Tern, and More

Published

on

Specialized’s proprietary, 700-watt motor feels natural—sometimes to an annoying extent, as the bike is designed for you to pedal and you won’t get faster than 10 mph just by using the throttle. Also, there’s no option for a dual battery. Still, the battery well exceeded Specialized’s estimated 60-mile range. Granted, I am a small person, but I was usually hauling at least one other person on the bike with me at all times, so I still found this remarkable.

It’s easily adjustable—both my 5’10” husband and my 5’2″ self were able to switch off riding, which is important if this is your family’s all-purpose hauler. The display is intuitive, and the buttons are well-spaced apart so you don’t get confused or end up button-mashing. Also, Specialized’s accessories go a long way toward making this bike so much more useful. Yes, you could jerry-rig some Home Depot buckets to the front of your bike and drill holes in the bottoms for them to drain, but the Coolcave panniers ($90) are so much more attractive, easy to use, and helpful for carting everything from kid dioramas to a dozen tiny soccer balls.

Best Value

The vast majority of people I know who buy a cargo ebike with their own money choose the Lectric XPedition2. There is just no better value for a dual-battery long-tail cargo ebike. Out of the box, Lectric has also gone above and beyond to make its bikes and accessories easy to assemble and use. You even pop the pedals in, instead of using regular screw-on pedals.

Advertisement

This bike’s specs are also wild for the price. It has a 1,310-watt rear hub motor, twice as powerful as the already-powerful Globe Haul. (It has a throttle and is a Class 2 ebike out of the box, though you can use the display to unlock its Class 3 capabilities and assist up to 28 mph.) It has hydraulic disc brakes, front suspension, an incredibly large and bright LCD color display, integrated lights, and fenders.

Source link

Continue Reading

Tech

When attackers already have the keys, MFA is just another door to open

Published

on

Login prompt

The Figure breach exposed 967,200 email records without a single exploit. Understanding what that enables — and why your MFA cannot contain it — is an architectural problem, not a user education problem.

In February 2026, TechRepublic reported that Figure, a financial services company, exposed nearly 967,200 email records in a newly disclosed data breach. No vulnerability was chained. No zero-day was burned. The records were accessible, and now they are in adversary hands.

Coverage of breaches like this tends to stop at the count. That is the wrong place to stop. The number of exposed records is not the event — it is the starting inventory for the event that follows.

To understand the actual risk, you have to follow the attack chain that a credential exposure like this enables, step by step, and ask honestly whether the authentication controls in your environment can interrupt it at any point.

Advertisement

Most cannot. Here is why.

What Adversaries Do With 967,000 Email Records

Exposed email addresses are not static data. They are operational inputs. Within hours of a record set like this becoming available, adversaries are running it through several parallel workflows simultaneously.

The first is credential stuffing. Figure customers and employees almost certainly reused passwords across services. Adversaries combine the exposed addresses with breach databases from prior incidents — LinkedIn, Dropbox, RockYou2024 — and test the resulting pairs against enterprise portals, VPN gateways, Microsoft 365, Okta, and identity providers at scale. Automation handles the volume.

Success rates on credential stuffing campaigns against fresh email lists routinely run at two to three percent. On 967,000 records, that is 19,000 to 29,000 valid credential pairs.

Advertisement

The second workflow is targeted phishing. AI-assisted tooling can now generate personalized phishing campaigns from an email list in minutes. The messages reference the organization by name, impersonate internal communications, and are visually indistinguishable from legitimate correspondence.

Recipient-specific targeting — using job title, department, or public LinkedIn data to tailor the lure — is standard practice, not a capability reserved for nation-state actors.

The third is help desk social engineering. Armed with a valid email address and basic OSINT, adversaries impersonate employees in calls to IT support teams, requesting password resets, MFA device resets, or account unlocks.

This attack vector bypasses authentication technology entirely — it targets the human process that exists to handle authentication failures.

Advertisement

In each of these workflows, no technical vulnerability is required. The adversary’s goal is not to break in. It is to log in as a valid user. The breach does not create access. It creates the conditions under which access becomes achievable through the authentication system itself.

Token’s Biometric Assured Identity platform is built for organizations where authentication failure is not an acceptable outcome.

See how Token can strengthen identity assurance across your existing IAM, SSO & PAM stack.

Learn More

Why Legacy MFA Cannot Interrupt This Chain

This is the part of the analysis that most incident post-mortems underweight. Organizations read about a credential exposure and conclude that their MFA deployment protects them. For the attack chain described above, that conclusion is structurally incorrect.

Advertisement

Modern adversary tooling executes what security researchers call a real-time phishing relay, sometimes referred to as an adversary-in-the-middle (AiTM) attack. The mechanics are precise.

An adversary builds a reverse proxy that sits between the victim and the legitimate service. When the victim enters credentials on the spoofed page, the proxy forwards those credentials to the real site in real time.

The real site responds with an MFA challenge. The proxy forwards that challenge to the victim. The victim responds — because the page looks legitimate and the MFA prompt is real. The proxy forwards the response. The adversary receives an authenticated session.

Push notification MFA, SMS one-time codes, and TOTP authenticator apps are all vulnerable to this relay. They authenticate the exchange of a code. They do not verify that the individual completing the exchange is the authorized account holder. They cannot distinguish a direct session from a proxied one.

Advertisement

Toolkits that automate this attack — Evilginx, Modlishka, Muraena, and their derivatives — are publicly available, actively maintained, and require no advanced tradecraft to operate. The capability is not exotic. It is the baseline.

MFA fatigue compounds this. Adversaries who obtain valid credentials but cannot relay the session in real time will instead trigger repeated push notifications until a user approves one out of frustration or confusion. This attack has been used successfully against organizations with mature security programs, including in incidents that received significant public coverage.

The common thread across all of these techniques: legacy MFA places a human being at the final decision point of the authentication chain, then relies on that human to make the correct call under conditions specifically engineered to defeat it.

The Structural Problem Legacy MFA Cannot Solve

The security industry’s standard response to authentication failures is user education. Train people to recognize phishing. Teach them to verify unexpected MFA prompts. Remind them not to approve requests they did not initiate.

Advertisement

This response is not wrong. It is insufficient, and the insufficiency is architectural, not motivational.

A relay attack does not require a user to recognize a phishing page. The MFA prompt they receive is real, issued by the legitimate service, delivered through the same app they use every day. There is nothing anomalous for the user to detect. The attack is designed to be invisible to the human in the loop — and it is.

The deeper problem is that the authentication architecture most organizations have deployed was not designed to answer the question that actually matters in a post-breach environment: was the authorized individual physically present and biometrically verified at the moment of authentication?

Push notifications do not answer this question. SMS codes do not answer this question. TOTP does not answer this question. USB hardware tokens answer a related but different question — they prove the registered device was present, not the authorized person.

Advertisement

Auditors, regulators, and cyber insurers are increasingly drawing this distinction explicitly. The question “can you prove the authorized individual was there?” is appearing in CMMC assessments, NYDFS examinations, and underwriter questionnaires. Device presence is no longer accepted as a proxy for human presence in high-stakes access contexts.

What Phishing-Resistant Authentication Actually Requires

FIDO2/WebAuthn gets cited frequently in this conversation, and it is a meaningful step forward — but it is not sufficient on its own. Standard passkey implementations bind the credential to a device or cloud account.

Cloud-synced passkeys inherit the vulnerabilities of the cloud account: SIM swap attacks against the recovery phone number, account takeover via credential phishing, recovery flow exploitation. Device-bound passkeys prove device possession. They do not prove human presence.

Phishing-resistant authentication that closes the relay attack vector requires three properties simultaneously:

Advertisement
  • Cryptographic origin binding: the authentication credential is mathematically tied to the exact origin domain. A spoofed site cannot produce a valid signature because the domain does not match. The attack fails before any credential is transmitted.
  • Hardware-bound private keys that never leave secure hardware: the signing key cannot be exported, copied, or exfiltrated. Compromise of the endpoint does not compromise the credential.
  • Live biometric verification of the authorized individual: not a stored biometric template that can be replayed, but a real-time match that confirms the authorized person is physically present at the moment of authentication.

When all three properties are present, a relay attack has no viable path. The adversary cannot produce a valid cryptographic signature from a spoofed site. They cannot relay a session because the cryptographic binding fails the moment the origin changes.

They cannot use a stolen device because the biometric verification fails without the authorized individual. They cannot social-engineer an approval because there is no approval prompt — the authentication either completes with a live biometric match at the registered hardware, or it does not complete.

Token: Cryptographic Identity That Verifies the Human, Not the Device

TokenCore was built on a single, uncompromising principle: verify the human, not the device, credential, or session.

Most authentication products add factors to a weak foundation. Token replaces the foundation. The platform combines enforced biometrics, hardware-bound cryptographic authentication, and physical proximity verification — three properties that must all be satisfied simultaneously for access to be granted.

There is no fallback. There is no bypass code a user can enter in the field. The authorized individual is either present and verified, or access does not occur.

Advertisement

This matters precisely because of the attack chain described above. Token’s Biometric Assured Identity platform eliminates each link:

  • No Phishing. Every authentication is cryptographically bound to the exact origin domain. A spoofed login page produces no valid signature — Token simply refuses to authenticate.
  • No Replay. The private signing key never leaves the hardware. A relayed session cannot be reconstructed because the cryptographic material it would need to replicate is physically inaccessible.
  • No Delegation. A live fingerprint match is required for every authentication event. A colleague, an adversary with a stolen device, or a social engineering target cannot complete authentication on behalf of the authorized individual.
  • No Exceptions. There is no code, no recovery flow, and no help-desk override that can substitute for biometric presence. The control is absolute because the risk is absolute.

The form factor matters too. Token is wireless — Bluetooth proximity, no USB port required. Authentication takes one to three seconds: the user initiates a session, taps their fingerprint on the Token device, Bluetooth proximity confirms physical presence within three feet, and access is granted.

For on-call administrators, trading floor operators, and defense contractors working across multiple workstations, this eliminates the friction that drives the shadow IT and workaround behavior legacy hardware tokens create.

Unlike USB-based alternatives, Token is field-upgradeable over the air. As adversaries evolve their tooling, Token’s cryptographic controls can be updated remotely and immediately — without replacing hardware or reissuing devices. The investment does not expire when the threat landscape changes.

Token verifies the human. Not the session. Not the device. Not the code. The human.

Advertisement
Mitigate Risk and Secure Vulnerabilities with TokenCore
Mitigate Risk and Secure Vulnerabilities with TokenCore

The Honest Assessment

The Figure breach will produce downstream authentication attacks. So will the next breach, and the one after that. The adversary infrastructure that runs credential stuffing, AI-generated phishing, and real-time relay attacks operates continuously against exposed email records.

The question is not whether these attacks will be attempted against your environment. They will be.

The relevant question is whether your authentication architecture requires human judgment to succeed — or whether it is designed so that human judgment is not the failure point.

Legacy MFA, in all of its common forms, requires human judgment. A user must recognize the anomaly, question the prompt, and make the correct decision under adversarial pressure. That is a brittle dependency at a critical control point, and adversaries have built an entire toolchain to exploit it.

Token removes that dependency. The device signs for the legitimate domain with a confirmed biometric match — or it does nothing. There is no prompt to manipulate. There is no decision to engineer. There are no exceptions.

Advertisement

That is not a feature. It is the architectural requirement for authentication that holds under the conditions this breach, and every breach like it, creates.

See How Token Closes the Gap

Token’s Biometric Assured Identity platform is built for organizations where authentication failure is not an acceptable outcome — defense contractors, financial institutions, critical infrastructure, and enterprise environments with high-privilege access requirements.

Cryptographic. Biometric. Wireless. No phishing. No replay. No delegation. No exceptions.

Learn more. Visit tokencore.com.

Advertisement

Sponsored and written by Token.

Source link

Advertisement
Continue Reading

Tech

No Surprise Here: Inspection Reveals Dozens Of Violations In El Paso ICE Detention Center

Published

on

from the fuck-em-for-being-human-beings,-I-guess dept

I’m not here to cut the Trump administration any slack or engage in both-sides bullshit, but this is something that has always been true: we treat anyone imprisoned or detained as less than human. The dehumanization begins with something we call “processing” — a word that separates a human from their humanity by making them sound like nothing more than paperwork.

The horrors seen in jails and prisons are often compounded at immigrant detention facilities. While some duty of less-than-minimal care might be extended to imprisoned US citizens, it’s far more often ignored when federal officers believe (mistakenly) that migrants aren’t protected by the Constitution.

The litany of violations stretches back forever. Techdirt doesn’t stretch back quite that far, but let’s take a stroll down memory lane.

From 2022, back when Biden was still in office and people like me were thinking no one would ever elect Trump to office again:

Advertisement

ICE’s ‘Fierce Commitment’ To Ensuring Detainees Are Cared For Properly Includes Inadequate Staffing, Unsanitary Facilities

That’s taken from a report demanding (“Management Alert”) the immediate removal of all detainees from this New Mexico detention center due to numerous violations, including a shortage of 112 employees and no less than 83 cells with “inoperable” sinks and toilets.

Going back further to Trump’s first administration:

Report Shows ICE Almost Never Punishes Contractors Housing Detainees No Matter How Many Violations They Rack Up

Advertisement

In this Inspector General’s report, we learned that only 28 of 106 contractors were provided with the tools needed to meet minimum “performance standards.” We also learned that the $3.9 billion being thrown to private contractors was shored up by absolutely no level of accountability. ICE approved 96% of waivers requested by contractors who failed to meet minimum housing standards for detainees.

While it’s been a persistent problem, things are significantly worse now. The Trump administration is detaining more migrants than ever before. It’s also far more willing to pawn these duties off on private prison contractors who prioritize making money over taking care of the people thrust into their care by Trump’s top bigots.

On top of that, the administration is fighting wars on several litigation fronts in hopes of preventing any form of oversight from slowing its roll towards total migrant annihilation. Everything that was bad before is getting so much worse.

Thanks to the White House Merchant of Death, RFK Jr., measles outbreaks are being reported at detention facilities. Thanks to absolutely every-fucking-body else in the administration, reports of inhumane conditions are somehow still on the rise, even after years of regularly reported inhuman conditions at ICE facilities.

Advertisement

Here’s even more. At a facility where guards were caught setting up suicide “death pools” for inmates, more evidence of deliberate cruelty and inhumane treatment has surfaced. The host of ongoing atrocities is none other than Camp East Montana, comfortably nestled in the heartland of the “who gives a fuck about immigrants” Fifth Circuit: El Paso, Texas.

Here’s the New York Times with the details of more man’s inhumanity to man, as personified by “immigration enforcement” forces of Trump’s second term.

An inspection in February of Camp East Montana in Texas, one of the country’s largest immigration detention centers, found dozens of violations of national standards, including instances that may have exposed detainees to illnesses and uses of force that were not documented, a new report found.

[…]

The inspection, which was carried out by the agency over three days in February and included interviews with 49 detainees, found that there were at least 49 overall “deficiencies” from national standards at the camp. Of all the deficiencies, 22 involved use of force and restraints, and five involved issues related to medical care. 

Advertisement

ICE actually released this inspection report. However, it did make sure names were changed redacted to protect the innocent guilty. While it’s uncharacteristically protective of the inspectors, it also makes sure we may never know which “Creative Corrections” employees helped make this detention center the hell hole it is.

Other censorship by the administration deliberately denies Americans access to the facts. What possible purpose is served here, other than allowing the government to pretend its rights violations were somehow excused by the [redacted] passage of time?

The government not only censored the number of detainee files reviewed, but also the ratio of files in noncompliance. What escapes ICE’s black-boxed attempts to redeem itself is this, which is plenty damning on its own:

[I]nitial classification process and initial housing assignments were not completed within 12 hours of detainees’ admission […]; rather they were completed 14 hours to 25 days after [admission]…

Everything that might show how often (or how frequently) violations occurred has been removed. It’s a deliberate muddying of the statistical waters. Who knows what’s behind the black box? It could mean rights were violated 10% of the time. Or it could mean rights were violated almost every time. But we the people — you know, the ones expected to foot the bill for this bullshit — aren’t allowed to know the actual details of what’s being done in our names.

If the government wants to play it that way, fine. We’ll just assume the worst and dare it to provide evidence to the contrary. And we know it never will. If or when the government decides to unredact this report, it will undoubtedly show us what we’ve always assumed: The administration and its contractors routinely abused detainees and violated their rights because the people in charge made it clear they don’t consider migrants to be humans.

And that makes this news as inevitable as it is deplorable:

Advertisement

So far this year, 14 people have died in U.S. Immigration and Customs Enforcement custody, including a Mexican man who was found unresponsive last week at a facility outside Los Angeles, according to data from the Department of Homeland Security.

If that seems like a low (or worse, an acceptable) number of deaths, think again:

In 2025, ICE reported 33 total in-custody deaths and in 2024 there were 11.

Deaths in ICE custody tripled under Trump during his first year back in office. If this pace continues, we’ll be looking at 56 in-custody deaths, which would nearly double the same number Trump managed to triple in 2025.

This will only get worse. The administration is still trying to buy up any warehouses it can to repurpose as detention centers. The workload is being stretched even thinner, leaving private citizens more poorly trained than current ICE officers in charge of the lives and well-being of thousands of detainees. The misery and death will continue. Unfortunately for us, this administration not only welcomes blood on its hands, but revels in it.

Filed Under: camp east montana, detention centers, dhs, el paso, ice, mass deportation, rights violations, trump administration

Advertisement

Source link

Continue Reading

Tech

NYT Connections hints and answers for Sunday, April 12 (game #1036)

Published

on

Looking for a different day?

A new NYT Connections puzzle appears at midnight each day for your time zone – which means that some people are always playing ‘today’s game’ while others are playing ‘yesterday’s’. If you’re looking for Saturday’s puzzle instead then click here: NYT Connections hints and answers for Saturday, April 11 (game #1035).

Good morning! Let’s play Connections, the NYT’s clever word game that challenges you to group answers in various categories. It can be tough, so read on if you need Connections hints.

Advertisement

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025