Authorities in the Netherlands said they dismantled a botnet that comprised more than 17 million devices and were managed by 200 servers in a joint operation by the police and the National Cyber Security Center.
The action, announced Thursday, came about after a security researcher reported the sprawling network to authorities. The host infrastructure was located in the Netherlands.
Used for criminal purposes
“The police then seized several botnet servers from a hosting provider for investigation,” the NCSC said. “The botnet was taken offline by the provider because it was used for criminal purposes.”
According to a report Thursday by the NL Times, the botnet was linked to ASOCKS, a Russia-based company that provides residential proxy services. These services cater to people and organizations who want to obscure their locations or identities by proxying their Internet traffic through third-party devices. Proxy services are often used for illicit or unethical purposes such as performing DDoS attacks, running botnet command-and-control servers, operating phishing operations, and scraping website content.
Advertisement
Ars was unable to independently confirm the NL Times report, but the claim checks out. Thursday’s NCSC post linked to a separate post that the nonprofit organization published a day earlier. That post, in turn, was updated to add a link to Thursday’s post. Wednesday’s post, headlined “Residential proxies and their major impact on digital security in the Netherlands,” warned: “Residential proxies are used to maintain anonymity and circumvent geographical restrictions. In this way, a Dutch organization can be attacked with Dutch proxies that have similarities with ‘regular’ traffic, making cybercrime mitigation more difficult.”
Kyndryl said the ‘politicisation’ of the deal has ‘overshadowed’ potential benefits it could have provided to Dutch citizens.
The government of the Netherlands has blocked Kyndryl’s proposed acquisition of Dutch cloud provider Solvinity, citing a risk to public interest.
Solvinity stores data used by the country’s citizen identification tool DigiD. The company’s tools are also used by public institutions including the tax office and universities. The acquisition would have reportedly set Kyndryl back €100m.
“The [Dutch] Investment Screening Bureau (ISB) advised me to proceed with a complete prohibition of this acquisition. I have made this advice my own and have adopted it,” said Willemijn Aerdts, the country’s minister for the digital economy and sovereignty, in a translated letter to parliament.
Advertisement
“The Netherlands attaches great value to the presence of foreign, including explicitly American, technology companies and their contribution to the Dutch economy and digital infrastructure,” the minister added, though she did not explain why the acquisition would risk public interest.
This is the first time the ISB has blocked a US acquisition since it was set up in 2020.
Several members of the Dutch parliament had openly criticised Solvinity’s acquisition by a US IT company over concerns that the US government could access private European citizen data.
“We are extremely disappointed by the Netherlands’ government decision to prohibit Kyndryl’s acquisition of Solvinity,” said Kyndryl in a statement.
Advertisement
“Since announcing the proposed transaction, Kyndryl has consistently engaged in good faith with relevant stakeholders across the Netherlands’ government.
“Despite this engagement and our long history of managing mission-critical operations in the Netherlands, the politicisation of this process has overshadowed the clear and important benefits this transaction would have brought to Solvinity’s customers and Dutch citizens”.
Kyndryl announced the proposed acquisition last November, stating that the deal would enable it to offer customers expanded services in “modernising, innovating and securing sensitive and complex workloads”.
The back-and-forth led to China temporarily halting Nexperia chip exports in early October. However, a Dutch court later upheld the seizure decision, as well as a decision to suspend the company’s Chinese CEO and hand control off to EU-based directors.
The dispute, triggered by the Dutch government, led to parent company Wingtech suing its subsidiary Nexperia earlier this month, arguing that the government’s actions resulted in billions in losses. The company is demanding €1bn in damages.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
Ivan Miranda has turned a long-running experiment with rolling balls into a clock that actually keeps pace with passing seconds. The latest version of his marble timepiece refreshes its display fast enough to show hours, minutes, and seconds without any visible lag between changes. Each digit takes shape inside a compact 3-by-5 grid. Fifteen marbles settle into the exact spots needed to outline a number. White marbles stand where a digit needs its bright segments, while black marbles fill the remaining positions to create clear contrast. The result looks like a physical version of familiar numeric shapes, built from actual objects rather than light or ink.
Hundreds of marbles, a stunning collection, live at the bottom of the machine, waiting to be sorted, and to be honest, they are getting a good exercise there. So, an elevator moves rows of marbles up in batches at a time, and infrared sensors examine each marble’s colour as it rises. Colors that do not match are softly shoved to one side by little actuators, and the entire cycle is repeated. They merely keep going until they have the perfect marble mix, at which point the mix required for the next exhibit is tossed down the tight tracks. Gravity takes over, transporting the picked marbles to their proper spots in the grids.
For years, the machine simply chugged away, updating once per minute. It was just the right pace to allow the marbles to organize themselves, travel to their destination, and settle in. However, adding only a few seconds to the mix nearly threw everything off course. Marbles were jamming up against the walls or each other, black and white marbles would take slightly different routes, causing them to be out of sync with one another, the plastic parts would flex and bend under the loads, and the drive system was nearing failure due to the large spikes in power demand.
Miranda needed to think of a new way to do things, so he developed a series of modifications that all worked together. He expanded the main housing so that marbles could move around without becoming too crowded. Then he built a safety net, which is a type of buffer zone that collects all marbles for a digit in one location before the last move. Release is now accomplished using gates carved from robust aluminum and equipped with a thin metal plate that serves as both a hinge and a spring. The flywheel, which weighs just shy of two kilograms, simply spins silently away on the drive shaft, keeping the motion flowing smoothly even as the mechanism begins to pull strongly. They took sure to include a great smooth-riding joint in the axle so that power is properly distributed even though the layout results in an unusual angle.
All of these modifications resulted in the 15 marbles for each digit dropping into their final positions in around 150 milliseconds. Which is just fast enough for the display to change once per second while still producing clean, crisp numerals. The time is handled by an Arduino controller, which is connected to a constant clock source and is in charge of communicating with the sensors and actuators. The motors and gears handle all of the heavy lifting, with the flywheel smoothing out any peaks and troughs that would otherwise cause the entire system to stall.
Recycling is still the slowest part, as the marbles tumble back down to the collection area after each cycle and must be hoisted again for the next cycle. The existing elevator just cannot match the one-second pace for lengthy run times, therefore the equipment continues to hesitate or slow down during long tests. Even with such limitation, the core display is able to process updates at a rate comparable to real-life seconds.
The entire design is a bit of a hybrid, as he used 3D printed tracks and frames where they made sense, and only a few proper machined metal parts where they were truly needed. Miranda has also been documenting every step of the route on camera, highlighting the worst of the clogs that slowed progress and the best of the solutions that restarted the flow. What began as a ridiculous idea about moving actual pixels has evolved into a workable proof of concept for how gravity, sensors, and properly formed pieces can accomplish tasks such as spitting out correct seconds without the traditional bits, hands, or glowing bits. [Source]
The Global Tech Ecosystem Index for 2026 tracks start-up ecosystems in 325 cities across 77 countries through three categories.
European cities account for 10 of the top 20 densest tech ecosystems in the world, according to a new report by innovation tracking platform Dealroom.
The ‘Global Tech Ecosystem Index’ for 2026 tracks start-up ecosystems in 325 cities across 77 countries through three categories: scale, per capita performance – or density – and growth, aiming to provide a “multidimensional view of the global innovation landscape”.
In density ratings, 45 European cities feature in the global top 100, ahead of North America’s 40. The rankings measure innovation output per capita, including start-up activity, enterprise value creation, ‘unicorns’ and university affiliations.
Advertisement
Cambridge, London, Stockholm, Ghent, Lausanne, Oxford, Tallinn, Copenhagen, Munich and Amsterdam are among the 20 global density leaders. The UK’s Cambridge is third in this metric, behind only the Bay Area and Boston, both in the US.
US ecosystems account for nine entries overall for density leaders.
Europe is one of six global macro regions monitored by the index – alongside North America; Latin America; Asia-Pacific; Middle East and North Africa; and Sub-Saharan Africa – for economic ties, investment flows and tech ecosystem integration.
The index suggests this approach reflects how innovation ecosystems operate in practice, connected by trade, talent and capital rather than by strict geography alone.
Advertisement
In the index’s scale rankings, tracking the “world’s largest and most successful tech ecosystems”, London (fourth), Paris (eighth) and Stockholm (19th) feature in the top 20, with 11 places occupied by North American cities.
Istanbul, Zagreb and Kyiv are European entries in the top 20 growth locations globally.
“As Europe struggles with entrenched low growth, political leaders see tech and innovation as a fundamental building block of economic competitiveness,” said Yoram Wijngaard, Dealroom’s founder and CEO.
“Innovation is seen as a route not only to securing growth but also national resilience and strategic autonomy. What stands out is not just the strength of leading hubs like London and Paris, but the rise of high-performing smaller ecosystems often built around leading research and academic institutions.”
Advertisement
In the AI sector, European ecosystems account for 10 of the index’s global top 20 by density, with Cambridge ranking second for the category. Tel Aviv, Israel and nine US cities complete the category.
In the index’s defence sector top 20 by density, European cities account for six entries, with Munich ranking second for the category.
Dealroom said: “The rankings reflect Europe’s distinctive innovation model – globally competitive ecosystems built around research institutions, technical talent and specialised industries rather than scale alone. Across the continent, smaller cities are increasingly producing outsized impact in areas such as AI, biotech, climate-tech and advanced manufacturing.”
According to Dealroom, its database draws from four sources: aggregated public information such as news, filings, registries, job boards; community-submitted data from start-ups, investors and accelerators validated by Dealroom; direct government API connections; and third-party data partnerships.
Advertisement
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
Looking for a portable Bluetooth speaker that will not disappoint in terms of performance? The Ultimate Ears WONDERBOOM 4, priced at $51.44 (was $100), is an ideal fit. It fits neatly into daypacks or backpacks without adding weight, yet produces music that penetrates through even small spaces and outdoor gatherings with startling power.
This speaker is 4 inches tall and weighs 15 ounces, making it easy to pick up and move with one hand, whether you’re setting it up or simply repositioning it. On top, there is an elastic loop that can be clipped into your backpack or bike handle without bulking up. The device is coated in a fabric finish and has some excellent rubberized portions at the ends to keep it gripping even when your hands are damp and soggy. Plus, it’s made to withstand some punishment: the IP67 rating means you can put it in a muddy puddle and still know it’ll work, and the fact that it floats means that if you drop it in a pool or lake, it’s less of a nightmare and more of a ‘oh well, I’ll just fish it out’.
Balanced 360-Degree Sound: The WONDERBOOM 4 portable waterproof Bluetooth speaker features 360-degree sound in a petite package; boosted sound for up…
Outdoor Boost and Podcast Mode: Engineered for full stereo sound; tap the Outdoor Boost button for outdoor environments; use the new Podcast Mode to…
14 Hours of Boom: With a rechargeable battery that lasts throughout the day, this waterproof portable speaker booms on with up to 14 hours of…
The sound is, frankly, pretty impressive all things considered. See, the configuration of the two active drivers and some passive radiators is set up such that it’s nice and open, which is wonderful news for anyone who wants to use it from a table or on the ground, and it works nicely no matter how you hold it, so you don’t have to worry about setting it perfectly. The bass, while not ridiculously deep, has a great weight to it, and the vocals are audible whether you’re listening to a podcast or just chilling out to some music.
Advertisement
There are also some extremely cool features to look out for. For example, tapping the button at the bottom activates the Outdoor Boost feature, which helps cut through background noise and get the sound through loud and clear. You can even pair a second WONDERBOOM 4 to get proper stereo separation, which is a game changer for larger rooms or sharing with a friend because it provides a considerably wider soundscape without requiring any additional cords or downloading anything. It also has multipoint Bluetooth connections, which allow you to couple with two devices at the same time and effortlessly switch between them.
The controls are simple to use, with volume buttons right up front for quick adjustments on the go. Everything else, including power, pairing, and playback controls, is conveniently located up top. The good news is that you don’t have to be a tech whiz to get started; simply plug it in, flip the switch, and you’re ready to go. You’ll have up to 14 hours of gameplay, which should provide for a road trip, a few shorter sessions, or a full day of work, plus some evening listening before you need to recharge. When you’re done, simply grab a standard USB-C cable to get back up and running.
Dutch authorities have taken offline a massive botnet of 17 million devices and seized more than 200 servers at a local provider that supported the operation.
The action was carried out following an investigation from the Police in collaboration with the country’s cybersecurity agency, the National Cyber Security Centre (NCSC).
According to the authorities, the seized servers controlled “computers, tablets, and smartphones to carry out cyberattacks.”
Botnets are networks of compromised devices used for illegal activities such as distributed denial-of-service (DDoS) attacks, malicious traffic proxying, or cryptocurrency mining.
Advertisement
“The investigation revealed that the botnet consisted of at least 17 million infected devices and that the 200 servers used to host the infrastructure were located in the Netherlands,” the NCSC said.
“ The police subsequently seized several botnet servers from a hosting provider for investigation purposes. The hosting provider took the botnet offline because it was being used for criminal activities.”
Although the authorities did not name the botnet, local media reported that it was linked to a service called Asocks, which advertises itself as a “universal proxy service” with 7 million IP addresses, 150 locations, and 100,000 clients.
The platform offers corporate, residential, and mobile proxies for monthly subscriptions between $5 and $15, with discounts for bulk purchases.
Advertisement
Although such services often comprise IPs that voluntarily donate bandwidth by using a specialized client in exchange for a fee, NCSC’s action indicates that the owners of the devices that were part of the botnet did not knowingly participate in supporting cybercrime operations.
BleepingComputer has contacted Asocks with a request for a comment on the allegations, but we have not received a response by publication time.
To protect networking devices from botnet infections, ensure the default credentials have been changed to something unique and strong, the latest firmware update has been applied, and remote administration panels are disabled when not needed.
Automated pentesting tools deliver real value, but they were built to answer one question: can an attacker move through the network? They were not built to test whether your controls block threats, your detection rules fire, or your cloud configs hold.
This guide covers the 6 surfaces you actually need to validate.
The cable news channel has accused the AI company of “massive copyright infringement.”
Hapabapa/Getty Images
CNN has joined the growing ranks of media companies suing Perplexity for copyright infringement. The cable news network has accused the AI search company of “massive copyright infringement” that includes wrongfully scraping its website and copying more than 17,000 pieces of its content.
The lawsuit, which was filed Thursday, claims that the AI company “unlawfully crawls, scrapes, copies, and distributes CNN’s content from CNN Digital Platforms and third-party platforms.” It also accuses the AI tools of reproducing “verbatim copies” of its articles, including paywalled stories, in query responses to users. Perplexity’s AI tools allegedly have incorrectly attributed “hallucinated” content to CNN, which the company says in the suit violates its trademark.
“CNN’s lawsuit stands for the proposition that Perplexity, a company valued at tens of billions of dollars, should not be able to steal from entities that create the original content Perplexity exploits,” a CNN spokesperson said in a statement to the outlet. “The public rely on high quality news journalism reported by human beings to understand their world, which is frequently dangerous and expensive to produce. Commercial operators can and must pay to make use of it.”
Advertisement
CNN is far from the first media company to sue Perplexity for scraping content without permission. The New York Times, Chicago Tribune, Reddit, Merriam-Webster, Encyclopedia Britannica and Nikkei have also filed lawsuits against the company. “You can’t copyright facts,” Perplexity’s Chief Communications Officer Jesse Dwyer said in a statement to CNN.
Interestingly, it seems that Perplexity was at one point trying to strike a deal with CNN that would have allowed it to use some of the network’s content. According to the lawsuit, the two companies were in negotiations last year that would have made paywalled CNN content available to Perplexity’s paid subscribers. The deal ultimately fell through, but Perplexity continued to use CNN’s name and content in its products despite warnings from the TV network’s legal team. Perplexity never responded, the lawsuit says.
The reboot of the classic Xbox series is now coming out in February 2027.
Fable, a reboot of the Xbox fantasy RPG series developed by Playground Games, has been delayed. The game’s release date is shifting from fall 2026 to February 2027 “so it can have the dedicated moment it deserves,” according to a post from Xbox on X. The new release date will give developers more time to polish the game before it comes out, while also moving it out of the blast radius of Grand Theft Auto VI, which is scheduled for release on November 19.
This isn’t the first time the reboot has been delayed, and as Microsoft notes in its announcement post, the back half of the year is particularly stacked with big releases like Call of Duty: Modern Warfare 4, Control Resonant and the aforementioned Grand Theft Auto VI. Moving to 2027 rather than duking it out with those more hotly anticipated titles could give Fable more time to shine. It does make a long development cycle even longer than it was before, though. The Fable reboot was originally announced in 2020, and Microsoft didn’t share proper gameplay footage of the game until January of this year. That means from announcement to release, Fable will have taken seven years to make, and that’s likely not taking into account work that went into the project ahead of its original announcement.
Advertisement
This is year is packed with incredible games for XBOX players to enjoy, from Halo: Campaign Evolved, Gears of War: E-Day and Call of Duty Modern Warfare 4 to Control Resonant, Star Wars: Galactic Racer and Grand Theft Auto VI. In order to plan our game launches through the… pic.twitter.com/eNXiA9ebn4
During its earlier 2026 showcase, Microsoft demoed Fable‘s detailed character creator and ambitious approach to simulating NPCs. The company also shared that the game would be available on PlayStation 5, alongside Xbox Series X/S, PC via Steam and Xbox and Game Pass Ultimate. While Fable won’t be available this year, Microsoft says it will show off “a major new look“ at the game during its Xbox Games Showcase on June 7.
You have probably experienced the following scenario yourself. A website suddenly stops loading, a login page times out, or an online service becomes unreachable at the worst possible moment. Sometimes the cause is not an internal outage, but a Distributed Denial-of-Service (DDoS) attack designed to overwhelm the service from the outside.
DDoS attacks have long been one of the simplest ways to disrupt an online service:flooding it with enough traffic, exhausting its infrastructure, and making it unreachable without breaking into the target’s systems. Now more than ever DDoS is being packaged, branded, and sold with the language of a mature online service, and the impact is well recorded in the real world.
Cloudflare reported blocking a 7.3 Tbps attack in 2025 and later said it mitigated a 31.4 Tbps attack in its Q4 2025 DDoS report. Microsoft also said Azure mitigated a 15.72 Tbps attack in October 2025, attributing the activity to the Aisuru botnet.
Behind those incidents, underground sellers are competing over the same buyers with an increasingly polished pitch. Recent underground activity analyzed by Flare researchers describe attack panels, API access, monthly plans, reseller options, customer support, botnet-backed capacity, game-server methods, and Cloudflare bypass claims.
Advertisement
A comparison of two datasets of DDoS-related underground activity from the first five months of 2023 and the first five months of 2026, shows how quickly that offer has changed. What once appeared more frequently as scripts, tutorials, leaked tools, and scattered forum posts is now more often presented as a repeatable product that is easier to buy and operate.
A DDoS attack attempts to overwhelm a website, application, network, or server with traffic from many sources at once. Some attacks target network capacity, while others focus on application layer resources such as login pages and APIs. The objective is usually simple: make the service unavailable, unstable, or expensive to operate.
DDoS-as-a-service lowers the barrier further. Instead of building infrastructure, an attacker can pay for access to a web panel, choose a target, select a duration, and rely on someone else’s botnet, proxy network, or third-party attack infrastructure.
A flow chart that illustrates how DDoS attacks work
Flare Researchers Analysis
Flare researchers searched for DDoS-related underground activity from two periods in time. The first was the fivefirst months of 2023 and the second was the first five months of 2026. The team cleaned the data, curated it and found some important insights.
Topic
Advertisement
2023
2026
Change
Volume of records
4,403
Advertisement
4,964
Slight increase
High-signal DDoS service ads
38
364
Advertisement
~10x increase
Unique ad clusters
31
123
~4x increase
Unique actors
Advertisement
15
41
~3x increase
Sources observed
22
Advertisement
43
~2x increase
An important disclaimer, in this research we focused on distributed DoS. There’s another category, which is denial of service.
Technically it is a bit different in the way a server is targeted, but the goal is the same. In this research we only focused on DDoS offerings and did our best to exclude the DoS offerings.
DDoS-as-a-service platforms are openly advertised across dark web forums and cybercrime communities — the same sources Flare monitors continuously.
Advertisement
Flare tracks underground marketplaces, botnet infrastructure chatter, and threat actor activity across thousands of dark web sources, so your security team sees emerging threats before they impact your operations.
The topics in the posts from 2023 are more diverse. Many offerings revolved around scripts, leaked tools, tutorials, or generic “botnet service” advertisements.
One repeated type of post from 2023 (as seen in the screenshot below) promoted a “Botnet Service L7 – L4” and claimed Layer 3, Layer 4, and Layer 7 capability, optional API access, automatic payments, high attack slots, game-server targeting, and bypasses for Cloudflare-related protections. The same advertising text appeared across multiple sources and actors, suggesting copying, reselling, or recycling marketing.
A post from 2023 offering Botnet services
While the post from 2023 was focused about the services, more recent posts from 2026 are focused around the price and the offering they give.
An advertisement of “SatelliteStress” described the service as an IP stresser with a user-friendly panel, API access, game-server support, and monthly plans starting at €20. The same post claimed the service was “100% botnet-powered” and did not rely on downstream APIs, a positioning meant to distinguish it from resellers that depend on another provider’s infrastructure.
Advertisement
As illustrated in the screenshot below, Areshun, which is another post that offers a “Premium DDoS Service” with Layer 4 and Layer 7 attacks, monitoring, API integration, custom plans, 24/7 support, and promotional discount codes is also pinpointed on specific service and its price.
Screenshot taken from Flare’s platform. Sign up for the free trial to access if you aren’t already a customer.
Another similar example is of “RebirthStress”, which is similarly marketed as a botnet-powered IP and web stressing device, a free Layer 7 hub, more than 400 slots, reselling suitability, and plans starting at $15 per month.
If you go over these posts, one-by-one and make the comparison, you see a distinct trend. The post in 2026 is more focused on a product, the sellers are competing one against another on customers. They package everything nicely, offer shiny features: ease of use, fully automated, full support, privacy promised, reselling capacity, and reliability.
The technical details have not disappeared, they became part of the sale pitch. In 2026 ads more commonly bundle Layer 4 and Layer 7 claims (means the service support both network-level attacks and application-layer attacks) words such as “panel,” “API,” “slots,” “bypass,” “monitoring,” “uptime,” and “support.”
One THORCC-related advertisement claimed more than 7,000 active Layer 4 bots and promoted bandwidth analytics and attack-vector statistics. Another Russian and English post presented “professional stress testing” while claiming Cloudflare and DDoS-Guard bypasses, high concurrency, and long attack durations.
Advertisement
Sellers are possibly exaggerating about their capabilities. However, the consistency of their marketing language remains important intelligence.
It shows what buyers are being encouraged to value beyond raw traffic volume, including web panels, automation, bypass claims, and the ability to launch or resell attacks with minimal effort.
The pricing of a DDoS attack in 2026 is very cheap. We’ve seen the following offers:
There are some more expensive offerings. An actor named “SamuraiDD” advertised attacks starting at $100 per day (see in the screenshot below).
Advertisement
Screenshot taken from Flare’s Platform. Sign up for the free trial to access if you aren’t already a customer.
Another actor named “POWERDDOS” used a tiered model of $5 tests, $100 per day for “weak” target, $200 per day for “medium” target, and $500 per day for “strong” or protected targets.
Lastly, we’ve also seen some “premium” offerings which included infrastructure-style targeting, including a DDoS botnet attack network advertised for $2,000.
The pattern shows a market segmented by buyer type. Cheap tests and short attacks for low-skill users, daily pricing for one-off disruption, private negotiation for longer campaigns, and higher-value infrastructure or reseller-style offers for more serious customers.
Public reporting on the booter economy (a paid DDoS-for-hire service that lets users launch attacks through someone else’s infrastructure) also aligns with this low-cost access model, with Akamai noting that some DDoS booter services can cost less than $25 per month and may offer limited trials.
Conclusions
DDoS-as-a-service is no longer only about traffic volume. The market is dropping down the entry bar, enabling easier purchase, easier operation, and easier to resell. What matters is not only how powerful an attack is, but how easy it is to launch an attack through a panel, various plans, full support, API access, and rented infrastructure.
Advertisement
This lowers the barrier for several types of actors. Low-skill users can buy short, cheap attacks. More serious customers can negotiate longer or higher-volume campaigns. Resellers can help expand the reach of the original service. As a result, defenders should not assume that disruptive DDoS activity requires a sophisticated attacker behind the keyboard.
In the near future, this market will likely continue moving toward more polished service models. As clearer pricing tiers, more automation, stronger reseller programs, and heavier branding around “bypass” capabilities and attack reliability.
Steeper discounts have resulted in the lowest prices ever on numerous M5 Pro and M5 Max 14-inch MacBook Pro configurations, with every model on sale.
Whether you’re looking for the standard M5 Pro 14-inch MacBook Pro that’s marked down to $1,999 at Amazon and B&H, or if you’d like to maximize your savings with Expercom’s record-breaking $1,300 markdown on a loaded M5 Max spec, there are a variety of deals to choose from this weekend.
Astell&Kern is bringing the A&ultima SP4000T Vacuum Tube DAP and Clarus In-Ear Monitor to High End Vienna 2026, and the timing feels right. The Vienna show opens June 4 at the Austria Center, just as wired IEMs are enjoying one of their strongest runs in years. CanJam NYC 2026 made that hard to miss, with in-ear monitors and portable audio electronics pulling heavy traffic from listeners who have not surrendered the 4.4mm balanced cable to the Bluetooth empire just yet.
A&K has earned some goodwill from us recently. The A&ultima SP3000T showed that a tube-equipped DAP could be more than a glowing party trick, while the SP3000 impressed with its resolution, timbre, and natural presentation. The SP4000T and Clarus now give Astell&Kern an opportunity to show whether its next portable flagship pairing can deliver the kind of wired listening experience that has personal audio buzzing again.
The A&ultima SP4000T
The A&ultima SP4000T gives Astell&Kern a new flagship tube DAP by combining modern digital audio processing with a more traditional analog output stage. The headline feature is its use of four RAYTHEON JAN6418 MIL-Spec vintage vacuum tubes in a quad configuration, making it the first portable digital audio player to use that tube arrangement. It is the kind of spec that will get the portable audio crowd leaning forward, assuming they have not already spent the rent money on cables and IEMs.
Raytheon Tubes Inside the SP4000T
The SP4000T uses an independent dual tube structure with four tubes in total, divided between the left and right channels. That type of channel separated tube design is more commonly associated with home audio tube amplifiers than portable digital audio players.
Each tube is measured for noise and gain characteristics before matching. Astell&Kern says the tube section is isolated through independent modular flexible PCBs and a multi layered internal architecture, which is important in a portable design where noise, heat, vibration, and consistency are all factors.
Advertisement
The SP4000T also introduces Triple Tube Mode, which Astell&Kern describes as a first for the DAP category. Combined with the company’s T Series Signature Triple AMP Mode and adjustable Tube Current settings, the player offers up to 54 possible sound combinations.
Astell&Kern offers three tube modes on the SP4000T. Triode Mode is intended to emphasize harmonic richness, warmth, and a more rounded presentation. Pentode Mode is designed for higher output and stronger dynamic impact while retaining tube character. Ultra Linear Mode sits between the two, balancing the tonal weight of Triode Mode with the control and drive of Pentode Mode.
The larger goal is to combine Astell&Kern’s TERATON ALPHA platform, quad vacuum tube architecture, and OP AMP design in a portable player that can deliver high resolution digital playback with adjustable analog tube character.
Amplifier Mode Support
The SP4000T gives listeners three amplifier options. OP AMP Mode uses the player’s solid state output stage and is intended to deliver lower noise, stronger control, and a more direct presentation. TUBE AMP Mode routes playback through the vacuum tube section for listeners who prefer a warmer tonal balance and a more spacious presentation.
Advertisement
HYBRID AMP Mode blends the OP AMP and tube stages across five selectable levels, allowing users to adjust how much tube character is added to the signal. The goal is to give listeners more control over the SP4000T’s output character without requiring external hardware or EQ.
Noise Suppression
The SP4000T introduces an upgraded 5-stage second-generation Anti-Microphonic Architecture (up from the previous 4-stage design) to suppress microphonic noise (noise generated in vacuum tubes from even the most minor external vibrations).
Advertisement. Scroll to continue reading.
Streaming and Wi-Fi
The SP4000T runs Android 15 and includes Google Play Store support, giving users broader access to streaming apps than earlier closed-platform DAPs. To preserve playback quality, Astell&Kern uses its ADP, or Astell&Kern Direct Path, technology to bypass Android’s standard sample rate conversion. That allows compatible streaming services to deliver lossless, bit-perfect playback through the player rather than being forced through Android’s normal audio path.
Advertisement
The SP4000T also introduces Astell&Kern’s first dual Wi-Fi antenna design. The goal is faster and more stable wireless streaming and downloads, especially on 5GHz networks. According to Astell&Kern’s internal testing, the new design can deliver up to twice the 5GHz download speed of previous models, although real-world performance will still depend on network conditions, router quality, and distance from the access point.
DACs and Processing
The SP4000T uses a discrete circuit architecture that separates digital and analog signal processing. Its DAC section is built around dual AKM AK4499EX DACs and dedicated AK4191EQ processors for each channel, a layout intended to reduce noise and preserve signal integrity across the playback chain.
Based on Astell&Kern’s SP4000 platform, the SP4000T also includes High Driving Mode, which uses a parallel OP AMP configuration to increase output capability and improve control with more demanding IEMs and headphones.
Astell&Kern’s ESA, or Enhanced Signal Alignment, technology is included to improve timing accuracy across the frequency range. The goal is cleaner imaging, better clarity, and a more stable soundstage. The SP4000T also includes DAR, or Digital Audio Remaster, which applies upsampling to PCM and DSD files with the aim of improving perceived detail and harmonic texture.
Advertisement
Additional internal refinements include Any Layer HDI PCB technology and a 99.9% pure copper shield, both used to reduce signal loss, noise, and electromagnetic interference inside the player.
Connectivity and Display
The SP4000T includes 256GB of internal storage, with microSD expansion up to 1.5TB. It supports native playback up to 32-bit/768kHz PCM and DSD512, giving it the file compatibility expected from Astell&Kern’s flagship DAP lineup.
The player uses a 6-inch Full HD touchscreen and supports dual-band Wi-Fi, DLNA networking, USB audio output, and USB DAC operation with Mac and Windows computers.
Bluetooth support includes aptX Adaptive and LDAC, giving users higher-quality wireless options when a cable is not practical. BT Sink mode also allows the SP4000T to receive Bluetooth audio from an external device, such as a smartphone, and function as a portable Bluetooth DAC.
Advertisement
Other usability features include ReplayGain, AK File Drop for wireless file transfers, USB PD 3.0 fast charging, and customizable battery protection settings.
Crossfeed
For extended listening comfort, the SP4000T includes advanced Crossfeed controls that recreate a more speaker-like listening experience through headphones, allowing users to fine-tune spatial presentation and reduce listening fatigue over long sessions.
Packaging
The SP4000T is packaged with a premium leather “Cognac’ colored case crafted using ‘MINERVA’ leather from ‘BADALASSI CARLO‘, a renowned leather workshop located in the San Miniato district of Florence, Italy.
Advertisement. Scroll to continue reading.
Advertisement
Two additional premium leather cases will be available for the SP4000T. A black case, crafted from soft cowhide by GRUPPO MASTROTTO, delivers an exceptionally soft touch, with a uniform surface quality and a distinctively vibrant Italian colouration. An olive-coloured case, crafted from premium vegetable-tanned leather by BADALASSI CARLO, is crafted through a proprietary tanning and dyeing process. Both cases feature a standing mechanism on the back to provide greater convenience in use.
Astell&Kern Clarus IEM
In addition to the SP4000T, Astell&Kern will show its Clarus IEMs for the first time at High End Vienna 2026.
Clarus is the fourth model in Astell&Kern’s IEM series, developed around the company’s goal of delivering a transparent, low distortion presentation for high resolution portable listening.
The Clarus uses a new 9-driver Tribrid architecture. Each side combines dynamic, balanced armature, and MEMS drivers, with each driver assigned to its own frequency range rather than being asked to cover too much of the spectrum. The shells are crafted from premium grade 6061-T6 aluminum, a material chosen for its rigidity, durability, and ability to support a more stable acoustic structure.
The technical goal is a more controlled full range presentation, with bass handled by the dynamic driver, midrange and treble detail managed by the BA drivers, and the most delicate high frequency information reproduced by the MEMS drivers. In theory, that division of labor should help Clarus deliver stronger separation, cleaner imaging, and a more open sense of space without forcing one driver type to do all of the heavy lifting.
Advertisement
The Bottom Line
The SP4000T is not the first DAP to use vacuum tubes, and Cayin’s N8iii is an important reminder that Astell&Kern is not operating in an empty lane. What makes the SP4000T different is the combination of four Raytheon JAN6418 MIL-Spec tubes in a quad configuration, three selectable tube modes, hybrid amp control, Android 15 with Google Play Store support, and A&K’s flagship DAC and processing platform in one portable player.
It is too early to judge the sound, but Astell&Kern did not build its reputation in the DAP category by making timid moves. The SP4000T looks like a deliberate attempt to bridge high resolution digital playback with adjustable analog tube character. The real question is whether analog focused listeners will hear this as meaningful engineering or another very expensive pocket-sized argument for staying up too late with IEMs.
Price & Availability
The Astell&Kern SP4000T and Clarus will make their global debut at the High End Show, 4–7 June at booth HX4, M04, Austria Center Vienna.
Pricing and availability for the SP4000T in Stainless Steel and Copper editions will be announced shortly.
Advertisement
Clarus will be available for demo in the Astell&Kern booth at High End Vienna 2026. Pricing, availability, and further details will be confirmed in due course.
You must be logged in to post a comment Login