Tech
Canon’s R8 II Camera Borrowed Its Styling From A Classic SLR Film Camera
Though preoccupied with vlogging lately, Canon hasn’t forgotten its photography market. The company just unveiled the 24-megapixel EOS R8 II, an entry-level full-frame camera with all new styling that’s strikingly different from the previous R8 model. In fact, the new camera reaches back much further, borrowing design cues from its classic EOS 650 SLR film camera, adding a touch of retro chic to a previously dull design.
A few things you may notice about it are the much more squared-off design compared to the rounded, swoopy R8. With the optional battery grip installed, it has an angled right corner like the 650 and more horizontal shutter button area. That said, it’s significantly larger and more modern-looking than its muse. As for controls, it has a joystick to move the autofocus point that the R8 sadly lacks.
Canon told Engadget that it addressed issues that myself and other reviewers found wanting in the R8. First off, it’s faster. The R8 II can now shoot at 40 fps in electronic shutter mode with continuous autofocus and auto-exposure, and capture more shots in a burst (58 percent more JPEG and 30 percent more RAW images). And unlike the previous model, it’s equipped with 5-axis in-body stabilization that reduces shake up to 7.5 stops with supported lenses. It’s also the lightest full-frame camera on the market with this feature at 1.2 pounds (546 grams).
The autofocus has been overhauled as well. Equipped with Canon’s Dual Pixel CMOS AF II, it offers 100 percent coverage and subject tracking of people, animals and vehicles, while delivering more tenacious tracking than the EOS R8, Canon said. It also comes with a feature we’ve only seen on higher-end models like the EOS R6 III: the ability to register specific people for tracking. You also get pre-continuous shooting that allows the capture of up to 20 frames (a half second’s worth) before fully pressing the shutter button.
Video hasn’t changed much, but was already pretty powerful with the R8. You can capture 4K 60p video that’s oversampled from the full 6K sensor width, as before, along with uncropped 1080p video at 180 fps. It supports 10-bit 4:2:2 capture with Canon Log3 in HEVC or AVC codecs at bit rates up to 250 Mbps. Video autofocus is much improved, with all the same tracking and subject detection AF features as for photos.
Other features include new Positive Filmtone, Negative Filmtone and Night Scene film looks, an A+ Automatic Exposure feature with a blurred background setting for movies, a separate Slow & Fast mode, a single UHS II card slot and enhanced stabilization modes for video. The 3-inch 1.62-million-dot vari-angle rear display and 2.36-million-dot EVF are basic, as is the LP-E17 battery that allows for just 340 shots in power saving mode.
The Canon EOS R8 II is now on pre-order for $1,899, with shipping set to start in late October. You may find that price a bit shocking for an “entry level” model, but it appears to be the new normal for cameras in a world of inflation and tariffs. You can also get it in a kit with Canon’s RF24-50mm F/4.5-6.3 IS STM lens for $2,099. The optional EG-E2 Extension Grip is $100, and Canon’s new Speedlite EL-5 Ver.2 flash will set you back $379.
Tech
The TicWatch Pro 5 Enduro is an unbelievable 73% off
A 73% discount is rare for any wearable, but that’s exactly what’s landed on the TicWatch Pro 5 Enduro today.
Amazon has taken £240 off the TicWatch Pro 5 Enduro Smartwatch this week, dropping it from £329.99 to just £89.99, which means you’re basically paying close to a quarter of its original price right now.
Ticwatch Pro 5 Enduro smartwatch drops to £89.99, save 73%
The robust TicWatch 5 Pro Enduro is down to just £89.99, a massive 73% saving on one of the most durable smartwatches you can buy.

At £89.99, you’re getting a lot of smartwatch for the money. The Enduro sports premium features like sapphire crystal glass, MIL-STD-810H certification and full 110-plus sports-tracking suite that you wouldn’t find south of £100.
The TicWatch Pro 5 Enduro, as its name suggests, has plenty of stamina, running for up to 90 hours in Smart Mode or stretching to 45 days in Essential Mode on a single charge.
Even topping it back up is quick, with just 30 minutes on the charger enough to squeeze out roughly two more days of typical use according to Ticwatch.
Underneath, the Snapdragon W5+ Gen 1 platform pairs a 4nm chip with a low-power co-processor, which is what lets the watch stay responsive for navigation and notifications without draining that long-lasting battery in the process.
Resilience carries through to the case itself, since the sapphire crystal glass and reinforced bezel are certified to US Military Standard 810H for knocks, sand, ice and vibration that would trouble lesser watches on the market.
Fitness tracking runs just as deep, covering 110-plus sports modes, 5ATM open-water swim resistance, and continuous heart rate and blood oxygen monitoring, alongside a new sleep tracker that can now detect snoring automatically each night.


A redesigned rotating crown lets you flick through tiles, adjust volume and zoom into maps with one gloved finger.
If you’re comparing wearables generally, our guide to the 11 best smartwatches you can buy in 2026 is worth a browse first, but at £89.99, the TicWatch Pro 5 Enduro is an absolute steal for Android owners who want a rugged smartwatch that can go the distance.
SQUIRREL_PLAYLIST_10148964
Tech
PS Plus Gets a Diverse Lineup for September With WWE 2K26, RuneScape: Dragonwilds and More
It’s September 2026, and the avalanche of quality games is already underway with Onimusha: Way of the Sword, Star Wars Zero Company and Marvel’s Wolverine. The big game releases will continue to happen weekly until Nov. 19, when Grand Theft Auto 6 releases, but this month, PS Plus subscribers are getting a mix of action, fantasy and a sprinkle of quirky games added to the service.
PS Plus, which is Sony’s version of Xbox Game Pass, offers a large, constantly expanding library of games. Subscribers can choose from the Essential, Extra and Premium tiers, each with unique perks and benefits. Starting at $11 per month, the plans give subscribers access to games and rewards, and each month, subscribers can play a handful of new games at no additional charge.
If you’re a PlayStation Plus Extra or Premium subscriber, you can grab these games now.
RuneScape: Dragonwilds
Set on the forgotten continent of Ashenfall, RuneScape: Dragonwilds is a cooperative survival RPG where players must gather resources, craft gear, build shelters and develop their skills to survive a land filled with dangerous creatures. The adventure combines classic RuneScape lore with survival mechanics and a new fantasy setting. Players can unlock abilities and spells as they progress, while quests lead them through a hand-crafted world filled with familiar enemies and new threats. At the center of the adventure is a confrontation with the fearsome Dragon Queen.
RuneScape: Dragonwilds is available for PS Plus Extra and Premium subscribers on Tuesday.
WWE 2K26
WWE 2K26 puts hundreds of WWE Superstars and legends at your fingertips, combining wrestling simulation with a variety of ways to play out your own version of WWE history. The massive roster includes modern stars alongside icons from the Attitude Era, while Showcase mode focuses on CM Punk and explores alternate versions of his career. Players can also rewrite wrestling history through fantasy scenarios, allowing them to revisit famous rivalries and imagine how things might have unfolded differently. It’s a wrestling game built around both authenticity and fan-driven fantasy.
WWE 2K26 is available for PS Plus Extra and Premium subscribers on Tuesday.
Ball x Pit
A ruined city, a bottomless pit and an army of monsters set the stage for Ball x Pit, a fast-paced fantasy roguelite built around frantic combat and progression. Players descend through increasingly difficult levels while using magic-infused projectiles to battle enemies and overcome obstacles. Between runs, they can develop new ammunition and resources, recruit additional heroes and work toward rebuilding the destroyed city of New Ballbylon. Its combination of arcade-style action, randomized challenges and character progression gives each attempt a different feel as players push deeper into the pit.
Ball x Pit will be available for PS Plus Extra and Premium subscribers starting Sept. 22.
Date Everything!
When a woman loses her customer service job to AI, a mysterious gift gives her a bizarre new career path: dating the objects in her own house. Date Everything! turns the traditional dating simulator into a comedic adventure where magical Dateviator glasses bring everyday items to life. Each object has its own personality, story and relationship path, and your choices can lead to friendship, romance or conflict. The game blends visual novel storytelling, relationship management and comedy, with a huge cast of voiced characters hidden among the furniture and appliances around your home.
Date Everything! is already available for PS Plus Extra and Premium subscribers.
Slitterhead
Set in the neon-soaked streets of Kowloon, Slitterhead is a horror action-adventure that follows Hyoki, a mysterious entity without a physical body or memories. His goal is to hunt Slitterheads, monstrous creatures that disguise themselves as humans. Combat revolves around manipulating blood and working alongside special humans known as Rarities, who can help Hyoki infiltrate dangerous groups and take down enemies. As the investigation unfolds, players uncover the mystery surrounding Hyoki and the creatures haunting the city. The result is a dark blend of supernatural horror, action and investigative storytelling.
Slitterhead will be available for PS Plus Extra and Premium subscribers starting Sept. 22.
Ninja Gaiden: Ragebound
Ninja Gaiden: Ragebound brings the classic series into a modern 2D action-platformer, combining the fast combat and lore of the original games with ideas inspired by the newer 3D entries. When the barrier between the human and demon worlds breaks, Hayabusa Village is overrun while Ryu Hayabusa is away. Young ninja Kenji Mozu must step up and defend his home from the invading forces. Developed by the team behind Blasphemous, Ragebound emphasizes precise movement, aggressive combat and challenging enemies in a stylish side-scrolling adventure.
Ninja Gaiden: Ragebound will be available for PS Plus Extra and Premium subscribers starting Sept. 29.
Dungeons of Hinterberg
Corporate burnout takes Luisa to the Austrian Alps, where a quiet vacation town hides a network of mysterious dungeons. Dungeons of Hinterberg mixes action-adventure gameplay with puzzle solving, exploration and social simulation. Players can snowboard across snowy landscapes, climb mountains, explore the countryside, and tackle dungeons filled with magical abilities and unusual challenges. Time spent in town is just as important, allowing Luisa to build friendships with locals and fellow adventurers. The result is a colorful fantasy adventure that balances combat and exploration with brain-teasing puzzles and character-driven downtime.
Dungeons of Hinterberg will be available for PS Plus Extra and Premium subscribers starting Sept. 29.
Sniper Elite: Resistance
Set behind enemy lines in occupied France, Sniper Elite: Resistance follows SOE agent Harry Hawker as he works with the French Resistance to stop a devastating Nazi superweapon. The third-person shooter emphasizes stealth, tactical combat and the series’ signature long-range sniping, giving players considerable freedom in how they approach missions. Multiple targets and different infiltration and extraction points encourage experimentation rather than a single path through each level. The campaign can also be played cooperatively, adding another layer to its mix of methodical shooting, reconnaissance and tactical action.
Sniper Elite: Resistance will be available for PS Plus Extra and Premium subscribers starting Sept. 29.
Mega Man X Command Mission
Mega Man X Command Mission puts the robot hero and his allies in the middle of a dangerous conflict over Giga City. Unlike the series’ traditional run-and-gun platformers, this adventure is a turn-based RPG, allowing players to assemble a team and combine their abilities during battles. X is joined by familiar characters, including Zero and Axl, along with new allies, as they tackle more than 50 missions. Side quests, powerful bosses and team-based combat add depth to the futuristic story, making it a notable genre shift for the Mega Man X series.
Mega Man X Command Mission is currently available for PS Plus Premium subscribers.
Metro Redux
Metro Redux combines two atmospheric first-person shooters set in a post-apocalyptic Russia where survivors live in underground stations after a devastating nuclear war. Players take control of Artyom, who ventures through the Metro tunnels and eventually into the poisoned world above while confronting mutants, hostile survivors and a growing threat to humanity. The games emphasize tense exploration, resource management, stealth and gunplay, with limited supplies making every encounter dangerous. Blending survival horror with immersive storytelling and first-person action, Metro Redux creates a bleak underground world where survival is never guaranteed.
PlayStation Plus subscriptions start at $11 a month
For more on PlayStation Plus, here’s what to know about the service. You can also check out other games on PlayStation Plus and games on Xbox Game Pass.
Tech
Revolut gets its Colombian banking licence, its sixth worldwide
Revolut has received its licence to operate from Colombia’s financial regulator, the Superintendencia Financiera de Colombia (SFC). The company said the licence is the last regulatory step it needs before it launches in the country.
Revolut announced the approval on 15 September. The licence allows it to operate as a regulated bank in Colombia.
Around 200,000 people in Colombia have already joined the waiting list, according to the company. It has not given a launch date.
Six banking licences
Colombia is Revolut’s sixth full banking licence. The company already holds banking licences in the UK, France, Australia, Lithuania, and Mexico.
This year Revolut has obtained bank licences in France, Australia, and the UK. It has also received conditional approval from the US Office of the Comptroller of the Currency for a national bank charter.
In the same period, Revolut won a payments licence in the UAE. It also received an organisation licence from Peru’s banking, insurance and pension regulator, the SBS.
Chief executive and founder Nik Storonsky said in the announcement:
“Securing this licence allows us to bring our cutting-edge technology and financial stability to a dynamic market, offering Colombians a transparent platform that puts power back in their hands. With over 80 million people already trusting Revolut and a balance sheet that reflects our strong and sustained profitability, we are proving that financial control can, and should be, borderless.”
What Revolut plans in Colombia
Revolut says it will launch a full range of financial products in Colombia. It plans to focus on everyday banking and on managing money across borders, including remittances.
The company said it has met the SFC’s capital requirements. Fogafín, Colombia’s deposit insurance scheme, will protect customers’ deposits.
Diego Caicedo, chief executive of Revolut Colombia, said:
“Today we are one step closer to operating in Colombia. We are not going to just launch as a bank; we are connecting Colombia to the global economy, simplifying remittances and access to world-class products in one single place, supported by the infrastructure of one of the world’s most innovative financial platforms. This licence is an important regulatory milestone, and we are excited to demonstrate the value of our proposition in the Colombian market.”
The numbers behind the expansion
Revolut says it has more than 80 million customers worldwide. It aims to reach 100 million by mid-2027.
According to its 2025 annual report, Revolut made $6bn in revenue last year, up 46% on the year before. Pre-tax profit was $2.3bn, its fifth year in a row of net profit. Customer balances reached $67.5bn.
A share sale earlier this year valued the company at $115bn. A new share deal for Storonsky targets a $500bn valuation.
Revolut’s expansion has also drawn regulatory attention. In June, the European Central Bank moved to restrict some of its products. On 13 September, TNW reported that Revolut handed customer passports to scammers who used a real government email domain.
Tech
The vulnpocalypse rains iBugs down on Apple with record-setting number of patches
Apple has addressed more than 260 CVEs across all of its operating systems, browsers, and other software products, marking the largest single patch cycle in Cupertino’s history.
While this CVE count is hardly notable compared to some vendors – hello, Microsoft’s record-breaking 974 bugs disclosed earlier this month – it does set a company record for Apple. It also reflects the new reality of AI-driven bug hunting, as models become exponentially better and faster at finding security vulnerabilities.
However, the flip side of the AI coin we were promised – that models would also excel at writing patches and automatically fixing software and systems – yeah, that hasn’t happened yet.
The silver lining for everyone updating their Apple products right now (including this humble vulture): none of the vulnerabilities are listed as being under active exploitation. Of course, that may change very quickly as attackers are, at this very moment, looking to exploit the newly disclosed bugs, too. And we promise you that they are using AI.
Apple’s latest mobile and operating system versions, iOS 27 and macOS 27 Golden Gate, released on Monday, also address a record 122 and 204 security vulnerabilities, respectively, across phone, iPad, and computer operating systems.
Of these hundreds of CVEs, however, there are only ten (by our count) that AI is directly credited with finding.
iOS 27 fixes 122 flaws
Just two of the iPhone and iPad CVEs fixed with iOS 27 credit a coding agent or AI assistant with finding them. These include CVE-2026-65410, a vuln that exists in iPhone and iPad AVE video encoders, that can cause unexpected system termination. Apple credited AI-bug-finding firm Calif, along with Claude and Anthropic Research, with finding and reporting this security flaw.
Then there’s CVE-2026-65409, a type-confusion issue in iOS’ Foundation framework that can be abused to cause a denial of service, also found by Calif – specifically human researcher Bruce Dang – in collaboration with Claude and Anthropic Research.
Some of the more interesting and serious iOS bugs fixed with the newest update aren’t listed as found by AI.
These include CVE-2026-43689, a privilege-escalation flaw that could allow an app to gain root access. Apple credited Nosebeard Labs’ Andreas Jaegersberger and Ro Achterberg with reporting this bug.
Additionally, CVE-2026-65406, a logic-issue flaw due to improper validation in Background Assets, could be abused to access sensitive user data. Background Assets is an Apple framework that lets you download large files and content in the background before a user opens the app for the first time. Baidu Security researcher Ye Zhang spotted this one.
macOS 27 patches 204 vulns
Meanwhile, the new macOS 27 update that addresses 204 vulns also fixes both the AI hunted bugs: CVE-2026-65410 and CVE-2026-65409. Plus, it credits AI helpers with discovering eight others, including one especially nasty flaw that could lead to remote code execution through the CUPS printer interface. Let’s start with that one.
CVE-2026-43692 is a validation issue in CUPS that can be exploited by a remote user to either terminate the app or execute malicious code. Aaron Grattafiori and the Nvidia AI Red Team receive credit for disclosing this flaw.
CVE-2026-64790 in CUPS can be exploited to gain elevated privileges. Grattafiori and the Nvidia AI Red Team again get credit for the win.
CVE-2026-43791, a validation issue in StorageKit, can be abused to read files. Grattafiori, the Nvidia AI Red Team, Meridian Miftari, and Amy from amys.website disclosed this flaw to Apple.
CVE-2026-43690 is a race-condition bug in the Server Message Block (SMB) network communication protocol. A local user can exploit the flaw to read kernel memory. Calif’s Bruce Dang, with Claude and Anthropic Research, found this one.
CVE-2026-43719 is another SMB use-after-free bug, discovered by Calif’s Dang and Jakob Pammer, Claude, and Anthropic. “Mounting a maliciously crafted SMB network share may lead to system termination,” Apple warned.
CVE-2026-65376 is yet another SMB issue – this one an out-of-bounds-read flaw reported by Dang, Claude, Anthropic, and 재영 정.
CVE-2026-65374 is a memory-corruption issue in the WebDAV protocol that can lead to code execution. Dang, Claude, Anthropic, and He Wei (ギカク) receive credit for finding this bug.
CVE-2026-65375, also in WebDAV, can cause unexpected system termination. Apple credited Dang, Claude, Anthropic, and Devcore Research Team’s YingMuo.
CVE-2026-43677 is an out-of-bounds write issue in WebDAV with a slew of researchers receiving credit for finding it. In addition to the usual trio (Dang, Claude, and Anthropic), bubu, Omar Cerrito, HE WEI(ギカク), Roman Zabicki, Richard Zana, Chris Bailey – Short Circuit, Aswin Kumar Gokulakannan, and Surya Narayan Kushwaha are on the list.®
Tech
Interlune raises $5M for initiatives that go beyond mining the moon

Seattle-based Interlune has raised $5 million in fresh funding to support a business plan that involves building space infrastructure as well as mining the moon for helium-3 and other valuable resources.
The funds were raised through a Simple Agreement for Future Equity, or SAFE, in which investors provide upfront cash to a startup in exchange for shares to be issued during a future priced round. Interlune used the same approach to raise $5 million earlier this year.
Interlune said existing and new investors participated in its latest SAFE offering, which came to light today in a regulatory filing with the Securities and Exchange Commission.
“The company’s continued traction with government contracts, along with major milestones across the space ecosystem over the past year, makes this a beneficial approach ahead of our next priced round,” Interlune CEO Rob Meyerson said in an emailed statement.
When Interlune was founded in 2020, the company focused primarily on developing technologies for extracting resources from lunar rocks and soil, also known as regolith. Helium-3 leads its target list because that material is more abundant on the moon than on Earth and is highly valued for applications ranging from medical imaging and quantum computing to fusion power. The price for helium-3 can exceed $9 million a pound.
Meyerson noted that Interlune’s business plan is no longer limited to space mining. “In response to growing market demand, we’ve expanded our product offering to include space infrastructure and survival services, leveraging the same technologies we’ve been developing to harvest natural resources from space,” he said.
In July, Interlune announced it was expanding its partnership with Vermeer, an Iowa-based industrial equipment manufacturer, to develop construction tools for use on the moon. Such tools could support NASA’s 10-year, $30 billion initiative to build the infrastructure for a moon base. Interlune is also adapting its helium-3 extraction process for terrestrial applications.
The company is planning to send its first payload — a mineralogical mapping instrument — to the moon later this year aboard Voyager Technologies’ Griffin-1 lander. Follow-up missions will characterize the moon’s helium-3 reserves and test technologies for excavation and extraction. Interlune plans to start harvesting lunar helium-3 and bringing it back to Earth in the 2030s.
Tech
What Zero-Day Response Should Be in the Post-Mythos Era
By Sila Ozeren Hacioglu, Security Research Engineer at Picus Security.
If you run PaperCut NG or MF, the last week of August showed what vulnerability response looks like when AI speeds up vulnerability discovery.
On August 27, PaperCut’s urgent advisory said attackers were already exploiting servers. No CVE, no exploit, no patch. The first emergency patch came a day later and was bypassed the same day. The third one landed on September 1. Six days without a patch that held or an exploit to test with, while attackers were already exploiting in the wild.
And the window is closing. Disclosure-to-exploitation averaged 21.5 days last year. It is measured in hours now. PaperCut isn’t the outlier. It’s the template.
Below is one day in the life of a security team, told through a hypothetical CVE.
The CVE is made up. The day is not: it is what PaperCut’s customers lived through in August. Let’s walk through it hour by hour.
08:00 – A CVE drops. No patch.
You wake up and CVE-2026-1001 is in your feed: unauthenticated RCE, no patch. You run a version check. Twenty assets match. Before you can finish reading the list, your phone rings. It’s management. They’ve already seen it, they’ve already been asked about it, and they want an answer in the next fifteen minutes: are we exposed, and what are we doing about it?
Strip the panic away and there are exactly two questions to answer:
1. Are these 20 assets actually exploitable, in my environment?
2. Would my security controls stop it, right now?
Version data says “affected.” Version data is not an answer. Both questions start the day at Unknown.
Patching is off the table, because there is no patch.
Shutting the services down would settle the question, but the business runs on them. Nobody is going to negotiate that. You need a verdict, not a shutdown.
08:05 – Your first instinct cannot act
The natural move is to reach for your automated pentesting tool. Take the exploit, fire it at the 20 assets, see what falls. So you go looking for the exploit.
There isn’t one. No public PoC, nothing to run. The tool that would give you the answer is waiting for ammunition, and so are you.
The attacker is not. Weaponization used to take weeks; now it takes hours, and the clock started at 08:00. If you wait for a public exploit, the first working one you see may be the one that hits you.
08:15 – The exploit is a chain, not a payload
Here is the shift. An exploit is not just a payload. It is a chain: the payload has to be delivered, it has to execute, and then the attacker has to escalate privileges, inject into a process and pull credentials to make the foothold worth anything. Each step is a known technique, and techniques can be simulated safely against your controls before anyone has written the payload itself.
You cannot test the exploit, because there is none. But you can test the chain the exploit would need. Map the CVE to the techniques it has to run, delivery, execution, privilege escalation, injection, credential access, and run those against your live stack: NGFW, WAF, endpoint hardening, EDR, SIEM. Per asset. The output is a verdict: would this chain succeed in your environment?
The question “is it exploitable here?” becomes testable ten minutes after disclosure.
We explained how this works in detail in our post on validating CVEs without a working exploit.
08:30 – Simulated, tested, ticketed
By 08:30 the chain has run. The results are not comfortable, and that is the point. The NGFW missed the delivery step. The WAF detected it but did not block. Endpoint hardening flagged execution. The EDR raised no alert. The SIEM raised no alert.
Now the two Unknowns have answers. The 20 assets are exposed to this chain, and nothing in the stack would stop it. But the gaps have names and owners. An action plan is created: a detection rule for the NGFW, a prevention rule for the WAF, GPO hardening for the endpoints, an IOA rule for the EDR, a detection rule for the SIEM. The EDR and SIEM rules deploy automatically. The rest go out as tickets and get worked through the morning, alongside a patch ticket for every affected asset, parked until a patch exists.
By 08:45 the chain is re-run. This time: detected, blocked, blocked, alerted, alerted.
You have not patched anything. You have broken the chain on every affected asset before a working exploit exists.
At The Validation Summit ’26, a vulnerability drops with no patch and no working exploit.
See it validated on day one, then tested with the real exploit against live controls when it arrives, then re-validated after the fix. Live in the product.
12:00 – The threat gets a name
Threat intel arrives. An Iranian threat group is running a campaign weaponizing CVE-2026-1001. There is still no public exploit, but the attacks have started. At 08:00 you had a vulnerability. At 12:00 you have an adversary.
That changes the question. The CVE is now one link in a full kill chain: initial access, lateral movement, persistence, exfiltration. You validated the vulnerability this morning. Would you survive the campaign?
12:30 – The whole campaign, rehearsed
You take the new report, pull the group’s past behavior from earlier reporting, and assemble the full campaign as an attack simulation. Run it end to end against your controls.
-
Initial access: blocked. The 08:30 fixes hold, and the morning pays off twice.
-
Lateral movement: detected, alert fired.
-
Persistence: missed. This is a technique the CVE-focused work could never have surfaced, because it has nothing to do with the CVE.
-
Exfiltration: blocked, egress controls holding.
The persistence gap runs the same loop as the morning: rule delivered, deployed, re-proven. Closed before lunch is over. Remember this rehearsal.
16:00 – The exploit goes public
A working exploit is published. Now, and only now, live testing has ammunition. Automated pentesting can fire the real thing.
But two constraints show up immediately.
First, you may not be allowed to. Policy often forbids firing live exploits at production or critical assets, and print servers, domain controllers, and OT systems are exactly where that policy bites.
Second, reach: with a real exploit, a pentest can safely touch maybe 5 of the 20 assets. The other 15 were only ever answerable the way you answered them at 08:15.
16:30 – Ground truth, two ways
The five reachable assets get tested with the real exploit. Three are not exploitable: the controls hardened this morning meet the real attack and hold. That is live confirmation the simulated verdicts were correct.
Two are exploitable. They need the patch, and there still isn’t one, so the patch tickets opened at 08:30 get upgraded to critical, with the working PoC and the exploitation evidence attached. No severity debate. The proof is in the ticket. Until the patch lands, the two go behind the WAF prevention rule with web access restricted to trusted IPs.
18:00 – The attacker arrives. Nothing happens.
The campaign hits your organization. Blocked. Alerted. Gaps already closed. The attack fails against controls validated at 08:15, fixed by 08:30, and proven at 08:45.
Ten hours before the attacker had a working exploit, your environment already did not have this exposure. That is what machine-speed validation buys: you finish before they start.
What this day required
Look at what actually got used. Not one capability, three, and none of them is a silver bullet on its own:
And they had to work together, on signal, in hours. The 12:30 campaign reused the 08:30 fixes. The 16:30 pentest confirmed the 08:15 verdicts. Findings from one fed the next. Run them as three siloed tools on three schedules and this day takes six weeks, not ten hours.
That is what the Picus Platform is built to do: exploitability validation, security control validation, and autonomous pentesting on one platform, sharing one data fabric, triggered by change rather than by calendar.
See the whole day, live
We are going to run this exact scenario, live in the product, at The Validation Summit ’26 on October 14 at 1 PM ET and October 15 at 11 AM BST.
Mikko Hyppönen opens with what changed after Mythos. Our CTO Volkan Erturk shows how machine-speed validation closes the patch gap and the speed gap. Security leaders from Chanel, Atlassian, and Kraft Heinz talk about how they are actually preparing. Ron Eddings of Hacker Valley hosts.
One question answered: what does Mythos-ready actually look like?
Two hours. Free. See the workflow run live.
Sponsored and written by Picus Security.
Tech
New Meta One Subscriptions Puts Extra Stories, Muse Videos, and WhatsApp Themes on a Monthly Tab

Meta One went live today as a paid layer across Instagram, Facebook, WhatsApp, and Meta AI, grouping more than 50 extras that sit on top of the free apps. Plans already collected 15 million subscriptions and trials during earlier tests, and Meta says later waves will reach Edits and AI glasses. Everyday feeds, chats, and basic Meta AI stay free.
WhatsApp Plus costs $2.99 per month, while Instagram and Facebook Plus cost $3.99 each. Core packages those three Plus subscriptions with additional AI capabilities for $7.99. Premium grants you access to the most AI allowance for $19.99. On top of that, you have your Creator and business tiers, which begin at $14.99 for Essential, $49.99 for Advanced, $149 for Expert, and a staggering $499 for Max. Keep in mind that these charges vary by location and account, and if you run a business on Instagram or Facebook, you may receive separate bills for each unique profile.
Meta Glasses, Fury AI Glasses
- Answers, tips and inspiration are a question away. Forgot an ingredient for dinner? Ask Meta AI for a substitute to save a trip back to the store…
- Meta Glasses are meticulously designed to deliver a fit that feels custom to you. Choose from a variety of bold colors and experience a comfortable…
- Travel like a local whether you’re navigating a bustling market in Spain or having a conversation in Japanese. Just say “Hey Meta” to start a live…
Instagram Plus offers a really great deal: you can stretch your Stories to 48 hours (before they disappear), use custom fonts in your DMs and Stories, receive notifications everytime someone views your Story, and even look at someone else’s Story without being added to their viewer list. Facebook Plus, on the other hand, provides personalized app icons, super hearts, additional Reels stats, and larger reactions in both the Feed and Reels. WhatsApp Plus offers exclusive themes and icons, some fancy effect stickers, and the ability to pin up to 20 chats. Backup storage and scheduled Focus Schedules are also on the way.

Core and Premium upgrade the Meta AI with additional functionality and greater limits. You can generate more photographs and videos with the Muse models, experiment with Restyle on more Instagram Stories, and utilize in-app creative tools like voice effects more frequently. People that joined up for testing used both the AI tools and the style extras rather regularly, and it turns out that Restyle and voice effects were the two most common causes.

Advanced is where all of the scheduling and operations magic occurs. You can queue up Stories up to 30 days in advance, schedule posts and Reels even further ahead of time, include clickable links in your organic posts and Reels, access exportable analytics, deeper audience insights, team seats without revealing your password, additional linked WhatsApp devices, and a slew of broadcast credits. Expert and Max push those boundaries even farther for larger teams and more corporate traffic. One thing to look out for is edits. Plus, it will include cloud project storage and an assistant that will read your Instagram analytics and make suggestions.

It’s worth noting that subscription does not remove ads completely, as Meta continues to run the same ad-supported core for its 3.6 billion daily visitors. Instead, they’re positioning these subscription tiers as a method to assist big hitters that use a lot of AI, while also providing power users and organizations with a single location to manage everything rather than having to fragment among a variety of third-party schedulers, link pages, and analytics tabs. To keep track of the rollout, the feature list will vary depending on your location, app, and account, so you’ll need to look inside the applications to see what’s available to you.

Helen Ma, Meta’s VP of subscriptions, told reporters that people who want specialized work out of apps built for billions now have a paid lane, and that free creator tools will not be cut to force a sale. Essential adds an enhanced profile with website and location slots, a bolder follow button on Reels, automatic follow invites to people who already engage, more Meta Business Agent replies on WhatsApp around the clock, a verified badge and WhatsApp Business channel after checks pass, plus impersonation monitoring.
Tech
Today’s NYT Strands Hints, Answers and Help for Sept. 16, #927
Looking for the most recent NYT Strands puzzle answers? CNET publishes daily answers and hints for The New York Times Mini Crossword, Connections, Connections: Sports Edition and Strands puzzles.
Strands is like a word find game, but without the list of words to find. Sometimes I see the theme and begin recognizing the answers right away. But for those times when I can’t seem to manage this, there’s a loophole: Strands lets you make as many words of four or more letters as you want. For every three of those words you find, the puzzle will highlight one of the answers. You’re still going to have to unscramble that answer, though, which can be very tough.
I go into depth about the rules for Strands in this story.
Today’s puzzle has a fun category, with some lively words. They’re pretty easy to unscramble once you pick up on the theme. Read on for hints and all the answers.
Hint for today’s Strands puzzle
Today’s Strands theme is: Hard not to notice.
If that doesn’t help you, here’s a clue: Showy or glitzy.
Clue words to unlock in-game hints
Your goal is to find hidden words that fit the puzzle’s theme. If you’re stuck, find any words you can. Every time you find three words of four letters or more, Strands will reveal one of the theme words. These are the words I used to get those hints, but any words of four or more letters that you find will work:
- CASE, CHIN, STIR, SHACK, HACK, LACK, LACE, LACY, TRICK, RICE
Answers for today’s Strands puzzle
These are the answers that tie into the theme. The goal of the puzzle is to find them all, including the “spangram,” a theme word that reaches from one side of the puzzle to the other. When you have all of them (I originally thought there were always eight, but learned that the number can vary), every letter on the board will be used. Here are the nonspangram answers:
- JAZZY, VIVID, BRIGHT, FLASHY, VIBRANT, STRIKING
Today’s Strands spangram

Today’s Strands spangram is EYECATCHING. To find it, start with the E that’s the first letter on the top row, and wind down, over, and then down again.
Tech
When software starts shaping family memory
There is a particular kind of question that families postpone for years. It is difficult not because the answer is secret, but because the question is too large: Tell me about your life.
Faced with it, even a willing storyteller may retreat into generalities. A childhood becomes “happy”. A marriage was “good”. A migration, a war, a career, a grief, all reduced to a few durable adjectives. The trouble is not necessarily memory. Often, it is form.
From weekly prompts to voice
Storyworth began as a family project. Nick Baum recorded his 82-year-old father’s answers; in 2013, he and Krista Baum founded the family-owned company. Its established format is deliberately incremental: a storyteller receives regular questions, responds over time, and eventually turns those responses and photographs into a hardcover book. Rather than demanding an autobiography all at once, the service divides a life into scenes small enough to enter.
The original Storyworth model centered on written responses. A storyteller could answer a weekly prompt by replying to an email or using a Storyworth account. That route remains available.
With its newer voice features, however, Storyworth is adding a technological layer between memory and the finished memoir: software can now record, transcribe, prompt and help structure the recollection before it reaches the page.
Story Calls, Magic Interviews and Family Calls
The first step in that shift came in 2024 with Story Calls. Storyworth first enabled phone recording in 2013, initially relying on human transcription. In 2024, the company added automated transcription. Today, Story Calls lets a storyteller answer by phone, including on a landline, with the call transcribed word for word.
The distinction matters. A verbatim transcript preserves the loops, digressions and idiosyncratic phrasing of speech, even when the result is less orderly than conventional prose. The storyteller can later revise the text or add photographs, but the initial record begins with the spoken answer rather than a rewritten version of it.
In early 2026, Storyworth added two more conversational formats. Magic Interviews guides a storyteller through a phone conversation and asks follow-up questions. When the call ends, the exchange is shaped into a written narrative and added to the memoir.
Family Calls brings another person (a relative or friend) into the conversation, allowing that person to ask questions, contribute memories and help direct the story. The recording preserves both voices, while Storyworth adds a cleaned-up transcript of the conversation to the memoir.
These are small product distinctions, but they produce different kinds of documents. Story Calls privileges fidelity to speech. Magic Interviews privileges structure. Family Calls introduces relationship itself as a source.
A daughter may remember the name of a neighbour her father has omitted. A grandchild may ask why a detail mattered, rather than merely what happened. One person’s recollection can become more specific when another person is present to recognise the gaps.
Every question is a frame
That does not mean guided conversation produces a deeper or truer memory. Interviews are never neutral containers. Every question places a frame around the past, and every follow-up makes one path more visible while leaving others unexplored.
A polished narrative is also not the same object as a verbatim transcript. The first may be clearer and more readable; the second may preserve more of the speaker’s manner.
Storyworth’s expanded system is interesting partly because it makes those choices visible. Families are not simply deciding what to preserve. They are deciding how much shaping should occur between speech and page.
The more consequential shift is that Storyworth is no longer only giving families a place to store finished recollections. In Story Calls, software transcribes; in Magic Interviews, it asks follow-up questions and helps shape the conversation into a polished narrative; in Family Calls, it preserves a two-person conversation as a cleaned-up transcript. The product is beginning to mediate the act of remembering, not merely preserve its result.
Remembering is uneven. People contradict themselves, circle back, pause, misplace dates and discover the meaning of an event halfway through describing it. A useful family archive cannot eliminate that instability; it can only decide what to do with it.
A book with a second record behind it
Storyworth’s answer is layered preservation. Stories can be edited and supplemented with photographs after a call. Friends and family with access to the project can listen through a private podcast feed.
In the finished hardcover, a QR code takes authorised readers to the Memoir project page, with stories and available recordings; a downloadable audiobook is included. The result is neither simply a book nor simply an audio archive. It is a printed narrative with a second record behind it: the actual sound of the person speaking.
That hybrid model also creates a distinctly digital dependency: the book is physical, but access to the linked recordings is mediated through Storyworth’s platform.
Voice carries information that transcription cannot fully absorb. It contains pace, accent, hesitation and emphasis. It reveals where someone laughs before reaching the end of a sentence, where certainty weakens, where a familiar story still catches in the throat.
None of this guarantees intimacy. A recording can be formal, guarded or repetitive. Yet it preserves the physical event of telling: breath passing through a particular body at a particular moment.
Why the telephone works
That quality makes the telephone an unexpectedly apt instrument for family history. It is ordinary enough not to feel ceremonial. It does not require a studio, specialised equipment or, in Storyworth’s system, even a smartphone.
The same device used for routine check-ins can become the site where a memory is prompted, questioned, recorded and transferred into a more durable form.
The limits of a designed archive
There is a tension here that Storyworth cannot entirely resolve. The service turns private recollection into a designed process, and design always influences outcome.
Weekly prompts encourage continuity, but they also divide a life according to the questions selected. Guided interviews can draw out detail, but they may also smooth the disorder from which a person’s way of remembering becomes visible.
A family memoir is not the whole life. It is a sequence of chosen entrances.
Still, that limitation belongs to every archive. Photographs exclude what stood outside the frame. Letters preserve what someone was willing to write. Home videos favour occasions when a camera was present. Storyworth’s voice tools add another kind of partial evidence: not merely what a person remembered, but how the memory emerged in conversation.
The phrase “family legacy” is often used as though inheritance were a finished object passed intact from one generation to the next. In practice, it is usually assembled from fragments: a name written on the back of a photograph, an anecdote repeated at dinner, a voicemail no one meant to save.
When software joins the act of remembering
Storyworth’s newer features show how consumer software can move from storing memory to participating in how it is elicited and organised. A question is asked, a voice is recorded, a transcript is generated, and a conversation can be reshaped into narrative. Each step adds convenience, but each also adds another layer of design between the remembered event and the archive that survives it.
That makes Storyworth interesting beyond the family-memoir market. It points to a larger question for consumer technology: what happens when software becomes an active intermediary in human acts that once seemed too personal to automate? In this case, the act is remembering.
The inheritance is still human. The system helping to produce it increasingly is not.
Tech
While Hollywood Fears an AI Future, China's Film Industry is Embracing It
The Los Angeles Times reports:
Chen Yilong has racked up plenty of film and TV credits in his two decades as an actor, but with work getting scarcer he signed a contract in August to license the image of his face to a Chinese production studio. Chen’s role will be to sit in front of a video camera and make facial expressions at the prompt of a director. A neutral stare. An angry glare. A look of surprise. Using artificial intelligence, the studio will use images of Chen’s face to generate an avatar, also known as a “digital human,” to star in an AI-generated movie. “If you can’t beat it, join it,” said Chen, 38, who works in Beijing.
The Chinese film and video industry is being transformed by AI-driven storytelling, fueled by rapid advances in video generation software, and at ground zero are the so-called micro dramas that play out on millions of smartphones. Typically just a minute or two in length, the videos are devoured by Chinese audiences… And the cost of producing them has been cut drastically through the use of AI software developed by Chinese technology juggernauts including Kuaishou Technology and TikTok’s global owner, ByteDance. The number of Chinese-made micro dramas surged in the first three months of this year to 128,000, according to the China Netcasting Services Assn. More than 95% of them were made with AI, the association said….
Sun Wei founded Feixiang Universe, the Shenzhen-based studio that cast Chen. The fear of accidentally “stealing someone’s face” was a big reason she said she decided to license real people’s likenesses for an AI production set during China’s Tang Dynasty more than 1,000 years ago. Thanks to AI’s training data bias, AI-generated performers tend to have similar features and share a homogenous look, Sun said. Many have flawless skin and extremely symmetrical faces, requiring her and other Chinese AI filmmakers to cast a wide net to “buy” new faces and digitize actor’s expressions.
Lu Beike, who directed the big-budget Chinese series “Three-Body,” felt theAI-generated scenes he’d tried came out sub-standard. “Lu added that if 90% of a film was generated by AI, a real human performance could appear jarring. A real actor’s expressions carried more nuance and emotion. The skin textures did not match. Sometimes the only solution was to process the live-action material until the person looked a little less real — until they fit back into the ‘AI world,’ Lu said.”
But at Sun Wei’s studio, they’re thrilled they can produce a 90-minute AI film for $500,000 where professional productions used to cost millions of dollars. According to the article, Sun’s team works with ChatGPT, Kimi or DeepSeek to flesh out entire screenplays from a short paragraph. The screenwriter takes over, but “to produce the finished product, Sun’s team uses Chinese video-generation models to input the type of scenes, backgrounds and performers they want, with the AI generating 15 seconds of footage each time.”
Still, the article points out that “Similar tools are being tested in the U.S., and the AI trends upending China’s entertainment industry may be a harbinger for what’s to come in Hollywood, said Michael Berry, a professor specializing in contemporary Chinese culture at UCLA. Already, Chinese companies that sell AI-powered video-generation software are seeking inroads in Hollywood…”
Read more of this story at Slashdot.
-
Fashion4 days agoWeekend Open Thread – Corporette.com
-
Business6 days agoMicron Stock Climbs Above $1,031 as AI Memory Crunch and a $50 Billion Outlook Fuel the Rally
-
Tech3 days agoThe Latest Weird Thing to Play Doom Is the Mapped-Out Brain of a Fruit Fly
-
Business6 days agoAMD Stock Climbs After Management Lifts 2027 Data Center Outlook Toward $70 Billion in AI Sales
-
Crypto World5 days agoXAG/USD: Silver’s Short-Term Rally Meets Its Moment of Truth
-
Crypto World6 days ago2 Chip Stocks Broke Out This Week. Neither Was Nvidia
-
Business5 days ago10 Most-Streamed Songs On Spotify In 2026 So Far, Led By Ella Langley’s Dominant Run On The Charts This Year
-
Crypto World6 days agoPi Network ships Protocol 27 on a network with 14 million users and zero DeFi
-
Tech5 days agoBattery life is the only iPhone 18 Pro and iPhone Duo upgrade I care about. Apple didn’t disappoint
-
Crypto World5 days agoDiesel Tops $6 a Gallon for the First Time as 28 States Set Records
-
Crypto World5 days agoOKX launches 10x OpenAI, Anthropic X-Perps in Europe
-
Tech6 days agoApple Watch Ultra 4 vs Watch Ultra 3: Should you really spend another $799?
-
News Videos5 days agoFacing Financial Fears
-
Tech7 days agoModders have already found two ways to make DLSS 5 playable, and neither one is Nvidia’s
-
Crypto World6 days agoBitcoin price risks $70K if $78K neckline breaks
-
Crypto World7 days agoBitcoin price holds near $79K as cycle drawdowns narrow
-
Entertainment6 days agoCase Sees Major Update As Jury Deliberations Begin
-
Crypto World2 days agoElon Musk Drops a Bombshell: Grok 5 Could Be the AGI Breakthrough
-
Business3 days agoRivals Sam Altman and Elon Musk Rally Behind Dario Amodei’s Call for a Slowdown in AI Development
-
Crypto World5 days ago
Ethereum Price Analysis: Consolidation at $2.5K Tests Momentum as On-Chain Activity Surges





You must be logged in to post a comment Login