Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
AI and ML
Connect all the things and watch what happens
Avoiding the “lethal trifecta” – access to private data, exposure to untrusted content, and an external communication path – is difficult enough when working with AI agents.
But the use of connectors – integrations with third-party services like Gmail or Slack – expands the scope of concern in a way that makes it exceedingly difficult to reason about defensive due diligence.
PromptArmor, an AI security biz, recently looked at how OpenAI’s ChatGPT and Anthropic’s Claude work with connectors. The results are not reassuring.
Shankar Krishnan, co-founder of PromptArmor, told The Register in an email that enterprise adoption of connectors and the rate of change among connectors helped focus concern on the connector ecosystem.
Connectors share some of the risks of MCP servers, upon which connectors are based. “For connectors, the risks are mostly about the type of tools, what they can do, where the data is going, and what is being done with the data,” said Krishnan.
Introduced about a year ago, connectors (for Claude or ChatGPT) have been going through a lot of changes recently. According to PromptArmor, 931 of 2,517 connectors (37 percent) changed over the six-week period from mid-May to the end of June. So any security assumptions based on declared capabilities may no longer be valid.
PromptArmor found that 1,686 new tools were added to connectors that were already live, creating new ways for AI models to operate on user data and interact with third-party services.
It also found that 1,127 tool descriptions were rewritten, potentially changing how and when an AI model decides to invoke a tool.
And there are a variety of other changes, all of which potentially could raise data security concerns or invalidate governance assumptions.
PromptArmor cited the Dropbox connector as an example, noting that at the start of the study it exposed eight tools and by the end of the study that number had risen to 24. It went from having three write-capable tools to 10, and from zero potentially destructive tools to four. Permission scopes changed and injected instructions for the model were added.
If that weren’t enough to worry about, connectors can behave like intrusive websites that run dozens of tracking scripts: connectors commonly send data to additional AI services.
PromptArmor evaluated all 7,517 tools used by 487 Claude connectors and found that 189 of the connectors, or about 2 in 5, are likely to call additional AI services.
“As an example, if your Claude agent activates Zoom’s connector tool to search meetings with natural language, and passes in a query containing sensitive data, Zoom AI may send that data to any of its ten AI subprocessors in order to generate a response from one of eight different model families it uses,” the security company said.
“The issue is that most teams approving connectors are evaluating and considering the connector – unaware that the vendor is calling more AI services, adding new subprocessors and terms,” explained Krishnan. “So someone concerned about AI risks who has evaluated Claude may not be aware of AI services that the connector is calling externally.”
Anthropic’s connector documentation acknowledges that its security controls don’t necessarily cover third-party data processing.
“Connected services process data on their own infrastructure, under their own terms, which may be located outside the United States,” the AI biz explains. “Settings that control where Claude’s inference runs, like the US-only inference setting on Enterprise plans, don’t change where third-party services operate.”
Krishnan said that connectors vastly expand the risk surface for attacks.
“Bringing agents new sensitive data, new untrusted data, and new sensitive actions to take, the blast radius of an attack explodes,” he said. “We recently highlighted a risk in Codex where even with one connector – email – the combination of sensitive and untrusted data enables exfiltration of legal and financial communications.” ®
There is no shortage of examples of Major League Baseball attempting to wield overly broad trademarks its obtained to bully others, nor examples of MLB attempting to stretch its trademark rights much further than they go. MLB opposed a trademark for a Brooklyn burger joint on behalf of the Dodgers, a team that hadn’t played in Brooklyn for over five decades at that point. The league, at one point, tried to bully a local Little League for using the names of MLB teams, but not their logos, which is something that roughly every Little League team everywhere does. It attempted to trademark the names of three cities in which MLB teams play. And, my personal favorite and most appropriate for this post, the league opposed a finance company’s trademark application because it claimed two of its separate teams both owned the rights to the letter “W”.
The real lesson in all of this is that the League can’t be trusted with anything other than very narrow trademarks. Anything more broad than that causes them to act the fool. And perhaps this is a lesson the USPTO has actually learned, given that it recently denied MLB’s attempt to trademark the phrase “Play Ball”.
The United States Patent and Trademark Office denied MLB’s application to trademark “Play Ball” for clothing, the USPTO wrote in a final action filing on Friday.
“In this case, the applied-for mark is a commonplace term, message, or expression widely used by a variety of sources that merely conveys an ordinary, familiar, well-recognized concept or sentiment,” the USPTO wrote in its denial.
The USPTO also wrote phrases “that merely convey an informational message are not registerable.”
Those are things that MLB’s well-dressed lawyers absolutely know, of course. But they attempted to bank on a complacent trademark office to try to sneak one past the goalie anyway, to mix metaphors. And if the league had gotten the mark, you can be one hundred percent certain it would have gone on yet another bullying campaign targeting apparel makers, other sports leagues, and who knows who else.
In fact, the most surprising part of all of this is that it appears to have taken 4 years for the USPTO to reach this decision. Josh Gerben breaks it all down like this.
Gerben said the rejection and public domain nature of phrases could depend on the class. Other companies have trademarked “Play Ball,” including a food company for bubble gum, a minerals company for surfacing playgrounds and “The Play Ball” for the gala fundraiser for the Strong National Museum of Play in Rochester, New York.
“In this case they are saying that the phrase has become so ubiquitous and it has this underlying meaning,” Gerben said. “For a clothing brand, the government doesn’t think it’s unique enough to be registered.”
Somehow, some way, we have to get past this practice of looking at trademarks as some kind of retroactive profit center, where a business gobbles them up and then corners a market that was already in existence. That’s all that this sort of attempt to lock up language is. The term “play ball” can be associated with Major League Baseball, certainly. It can also be associated with other sporting activities, or business negotiations, or any other number of things. That’s because it has become a generic phrase, no longer an identifier of the source of a good or service.
Again, MLB’s lawyers knew all of this before applying for the mark. They just didn’t care.
Filed Under: baseball, play ball, play ball play ball play ball, trademark, uspto
Companies: mlb

A palm-sized drone flies through thick fog, artificial snow, and near-total darkness, dodging poles, transparent plastic sheets, and tree trunks without a single camera or laser. Its only guide is sound. Researchers at Worcester Polytechnic Institute built the system, called Saranga, by copying the way bats find their way in caves. The result is a lightweight, low-power approach that keeps working when vision-based sensors simply stop.
Cameras and LiDAR begin to fail as light becomes dispersed or just disappears. Radar, on the other hand, drains the batteries right when the machines need them. By contrast, ultrasound travels through smoke, dust, and snow in the same way as it does in clean air. Bats have been doing it forever, simply emitting short, high-frequency chirps and listening for faint return echoes that bounce off obstacles. The WPI team, led by Nitin Sanket of the Perception and Autonomous Robotics division, decided to give a flying robot the same superpower.
Sale
They began with a quadcopter that they custom manufactured, measuring 16 cm across and weighing 460 kilos. It has two very tiny TDK InvenSense ICU30201 ultrasound sensors at the front, each with a broad sonic horn. Another one points downward to help with altitude. All of this ultrasound sensing requires only 1.2 milliwatts, and it all operates on a Google Coral Mini computer with no additional beacons or GPS, so there is no extra power expenditure.

Propeller noise was the first major issue, as the spinning blades are basically spewing out some serious ultrasound noise that drowns out the weak echoes coming back from distant objects (we’re talking minus 4.9 decibels here, which is weak signal territory for the team), so they fixed it by physically taping a simple foam and plastic shield between the propellers and the sensors. This barrier shuts out the majority of the prop noise while allowing outward sound and returning echoes to pass through. With this piece of hardware fixed, the usable range increased from one meter to two meters.

Even after they sorted the prop noise with their shield, the returning echoes were still getting lost in the random noise, so they attempted utilizing classical filters to sort it all out, but it wouldn’t comply. They required something more sophisticated, so they trained a tiny neural network to sort through all the filth. They termed it Saranga (also a neural network), and it basically looks at a brief string of echo readings as if it were a little picture. It uses this to learn the forms of true reflection patterns, after which it can suppress random prop noise. Training employed a lot of synthetic data mixed in with some real propeller noise, so once they had it functioning, the model flowed over to the real world very easily, with no additional fine tuning required. Saranga is then “compiled” to function on the Edge TPU, and it only takes up approximately 0.5 gigabytes of memory and does an inference in around 15 milliseconds while using only a few millijoules of energy.

The cleaned-up echoes are then sent to a basic localization stage, and because the left and right sensors are at slightly different angles, they can determine the horizontal angle to an obstacle in the same way that bats do. The down-pointing sensor then provides the height. It’s all really easy; simply a quick list of surrounding obstacles, and then it’s up to the flight controller to say, “Hey, steer clear of all this while still traveling in that direction.”
[Source]
A new American Heart Association scientific statement concludes that up to about 400 milligrams a day, or roughly three to five cups of plain coffee, is safe for most adults and may be linked to lower risks of cardiovascular disease. The benefits appear to depend heavily on the source and preparation, with coffee and tea looking more favorable than energy drinks, and added sugar, cream, syrups, or sweeteners potentially canceling out the upside. ScienceAlert reports: “Caffeine consumed in coffee is a key part of daily life for millions of people,” says Gregory Marcus, cardiologist at the University of California, San Francisco, and Chair of the AHA volunteer writing group behind the statement. “In our review of the most recent research, for most adults, intake of up to 400 milligrams of caffeine per day, the equivalent of up to five cups of caffeinated coffee per day without added sugars or fillers, is safe and does not increase cardiovascular risk.”
The statement focused on caffeine’s relationship with cardiovascular risk factors, such as blood pressure and diabetes, as well as types of cardiovascular disease, including arrhythmias, coronary artery disease, stroke, and heart failure. The picture that emerges is complicated, but generally positive. […] All up, the new AHA statement concludes that there’s a growing body of evidence that caffeine isn’t harmful when taken in moderation, and that coffee specifically may be beneficial. The statement was published in the journal Circulation.
Hugging Face’s incident response team first turned to frontier AI models to analyze a breach of the company’s production infrastructure, and the models refused to help. Commercial safety guardrails built to stop attackers blocked every forensic query because they treated the IR team’s real exploit data the same way they would treat a live attack.
The attacker, an autonomous AI agent running the campaign end to end, moved laterally across the Hugging Face infrastructure for a weekend, undetected and unstopped.
Security leaders are quick to recognize the pattern and diagnose what went wrong. “I’ve seen versions of this during red-team exercises and internal security testing, but this is one of the first high-profile examples where it materially affected real incident response,” said Merritt Baer, senior adviser to Andesite, G2I, and AppOmni and former Deputy CISO at AWS.
None of this is unique to Hugging Face, Baer said. “Commercial frontier models optimize for preventing misuse. They generally have no cryptographic or organizational way to determine whether the person asking ‘analyze this malware’ is an incident responder or the malware author.”
On July 16, Hugging Face disclosed that an autonomous AI agent system had compromised its production infrastructure, gaining unauthorized access to a limited set of internal datasets and several service credentials. The company verified that its software supply chain was clean and found no evidence of tampering with public models, datasets, or Spaces.
Hugging Face is still assessing whether the intrusion touched any partner or customer data and says it will contact affected parties directly as required. But few enterprise threat models had accounted for the attacker Hugging Face faced. An autonomous agent ran the entire campaign from initial access through credential harvesting. No human guided it.
The entry point was a malicious dataset. When the data-processing pipeline ingested it, the dataset triggered code execution in two ways, through a remote-code loader and through a template-injection flaw in dataset configuration files. No admission gate screened the file before it reached a processing worker, the compute job assigned to each dataset. Initial access came through the data pipeline itself, a route that worked because most enterprise security teams treat the data feeding their pipelines as trusted input rather than an attack surface.
Worker isolation did not hold. From that first foothold, the agent broke out onto the node running the workload, then harvested cloud and cluster credentials scoped broadly enough to reach multiple internal clusters, all of it inside a single weekend. Hugging Face described the agent framework as executing thousands of individual actions through a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services. The disclosure adds that the framework appeared to be built on an agentic security-research harness, which would put tooling designed for red-team work behind a live intrusion.
Investigators reconstructed more than 17,000 recorded events using AI-driven analysis agents of their own.
First attempts at the log analysis ran on frontier models behind commercial APIs. Defenders’ steps included submitting real attack commands, exploit payloads, and command-and-control artifacts for classification, but safety guardrails blocked the requests outright.
Baer traced the block to the prompts themselves. “The same prompts that are most valuable during an active intrusion, shell commands, exploit chains, credential dumps, persistence mechanisms, lateral movement, are exactly the prompts most likely to trigger safety systems,” she told VentureBeat. “As AI becomes embedded in security operations, this becomes an operational resilience issue rather than merely a model policy issue.”
GLM 5.2, an open-weight model deployed on Hugging Face’s own infrastructure, took the job the commercial APIs refused. No attacker data left the company’s environment. “This experience points to a gap worth planning for,” the company wrote in its disclosure. Hugging Face does not know which model powered the agents. It could have been a jailbroken hosted model or an open-weight model running without restrictions. Either way, the disclosure continued, “the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried.” Hugging Face drew that line itself, writing that the experience is not an argument against safety measures on hosted models and that it is sharing the feedback with the providers concerned.
The industry, Baer argued, needs to move past treating AI safety as a content moderation problem. “Security operations require something different. Authenticated trust.” Instead of asking whether anyone should receive an answer, the question becomes whether an authenticated security team, operating under enterprise controls, should receive it. “The model shouldn’t only understand what is being asked. It should understand who is asking, why, and under what governance.”
“Organizations already build contingency plans for cloud outages, identity provider failures, or EDR failures,” Baer wrote. “AI assistants are becoming another dependency.”
Her advice on IR playbooks was blunt. “A mature incident response plan should assume that during a severe incident, commercial AI APIs may refuse requests, API rate limits may become unavailable, internet connectivity may be impaired, and data governance rules may prohibit uploading forensic evidence externally.” The lesson, she wrote in her emailed answers, “isn’t ‘don’t use commercial models.’ It’s ‘don’t make them a single point of failure.’”
Autonomous AI-driven attacks are not limited to AI platforms. CrowdStrike’s 2026 Global Threat Report documented AI-enabled adversary operations increasing by 89% year over year, with average breakout times falling to 29 minutes. Enterprises running AI workloads in production with agentic access to their pipelines face similar exposure.
Six control domains determined the blast radius and recovery speed at Hugging Face. Each one maps to a concrete action security leaders can take before the next autonomous-agent breach arrives.
|
Control Domain |
What Broke |
Monday Action |
|
Dataset admission controls |
Two code-execution paths were exploited. No admission gate validated the dataset before it reached a processing worker. The data pipeline became the initial access infrastructure. |
Require sandbox execution and static analysis of all datasets before they reach workers. Block remote-code loaders and template-injection paths by default. Audit for any path granting code execution to untrusted content. Report to the board as a supply-chain risk. |
|
Worker-to-node privilege boundaries |
Worker isolation failed to prevent escalation to the node. The agent gained cluster credentials because the workload-infrastructure boundary was never enforced at container runtime. |
Enforce hard privilege boundaries between workers and nodes. Deploy container runtime security to prevent workload escape. Audit whether workers can reach node-level APIs or credential stores. Include in the next penetration test scope. |
|
Credential exposure |
Cloud and cluster credentials harvested after node access. The scope was broad enough for lateral movement across multiple clusters over a weekend. |
Rotate credentials on a scheduled cadence and after any anomaly alert. Scope to the minimum cluster and service. Deploy monitoring that flags access from unexpected nodes at machine speed. Map blast radius for board reporting. |
|
Machine-speed detection |
Thousands of actions through short-lived sandboxes with self-migrating C2. AI-assisted anomaly detection surfaced the campaign after a weekend of lateral movement, per the disclosure. |
Calibrate detection for machine-speed patterns. Ensure high-severity alerts page responders in minutes, regardless of time. Audit SIEM rules for detecting thousands of short-lived executions within a single hour. |
|
Private AI forensic capacity |
Commercial APIs blocked forensic analysis. Guardrails screened query content, never analyst identity. Investigation ran on GLM 5.2 privately. |
Deploy a capable open-weight model on private infrastructure before an incident. Test against real forensic workflows. Ensure IR playbook includes fallback for when commercial APIs refuse. Document gap for cyber insurance. |
|
Autonomous-agent threat modeling |
The campaign matched the forecast agentic-attacker scenario, but no threat model had operationalized it. LLM powering the agent is still unknown. |
Add autonomous AI agents as a distinct adversary class with machine-speed decision cycles. Run tabletop at agent speed. Present results to the board as evidence that timelines need recalibration. Include in the cyber insurance application. |
“The question for directors is simple. What happens if one of our critical security tools becomes unavailable during the exact moment we need it most?” Baer framed that as operational resilience, not AI policy.
She would have boards take that framing straight to management and press for specifics. “Have we actually exercised that fallback during tabletop exercises? How quickly can we switch during an incident?” Procurement needs to change alongside governance, starting with the questions buyers ask. Security teams evaluating AI vendors should ask about their process for authenticated incident responders, whether enterprise customers receive different handling during verified incidents, and whether models can be deployed privately. “Those questions belong alongside uptime, privacy, and compliance,” Baer said.
“The biggest takeaway isn’t that safety guardrails are ‘bad.’ They’re doing what they were designed to do,” she argued.
Her larger point is that the threat model itself has changed. “For decades, defenders had better tools than attackers because they operated inside trusted enterprise environments. With foundation models, both sides increasingly use the same capabilities, but one side is constrained by enterprise governance, policy, compliance, and safety controls, while the adversary simply downloads an uncensored open-weight model and keeps going. That’s a new kind of asymmetry,” she added. “The organizations that handle it best won’t necessarily be the ones with the most powerful AI. They’ll be the ones that architect AI as a resilient security capability rather than a single cloud service.”
Hugging Face has contained the intrusion, rebuilt compromised nodes, rotated credentials, and reported the incident to law enforcement. The company recommends that all users rotate access tokens and review recent account activity. Mid-incident, Hugging Face found out whether its own AI tooling would be available, and the first answer was no. Security leaders running AI in production should find out in incident response planning instead, before an autonomous agent forces the test.
Fatal road accidents are tragically common on U.S. roadways. According to the National Vital Statistics System’s Mortality Data for 2024, 41,241 people were killed on U.S. roads that year alone. There’s one particular time of year that’s especially notorious for such traffic accidents among teenage drivers: The period between Memorial Day in late May and Labor Day in early September, the so-called 100 Deadliest Days of Summer.
According to the AAA, between the years of 2012 and 2021, traffic fatalities during this period reached “nearly half of the total number of those killed in teen-driver crashes for the entire rest of the year.” Armed with these sobering statistics, though, authorities can anticipate when such accidents tend to spike in frequency, and tailor campaigns and anti-speeding measures to try to help mitigate them. One major effort to do just that during this period is Operation Southern Slowdown, which returned for its ninth year and ran from July 13-18, 2026. It saw a group of five southern states (Alabama, Florida, Georgia, South Carolina, and Tennessee) embark on efforts to, as the Florida Department of Transportation put it, “reduc[e] speed-related crashes through a combination of increased enforcement and public education.” Speed limits vary a lot between U.S. states, but all must be obeyed.
The additional patrols during this campaign in 2025, Atlanta News First reported, resulted in “more than 13,000 speeding contacts in just one week” across Georgia. It was also just one part of a range of nationwide efforts to curb speeding during this deadly time of the year. Here are some more measures that different states are employing, as well as a closer look at why these 100 summer days are statistically so deadly in the first place.
A national campaign from the Federal Motor Carrier Safety Administration aims to increase public understanding of the dangers and encourage safer driving practices throughout the 100-day period. It’s called the 100 Days of Roadway Safety and focuses on providing digital resources, primarily blog posts, that underscore essential safe driving principles. Among them are reminders to be wary of unpredictable movements by children in school zones and that larger vehicles like trucks need to be given essential space at all times.
New York State’s Department of Health developed a Teen Driving Safety Toolkit to educate young drivers and their parents and guardians during this turbulent time of year. It highlights some particular risk factors, some resources that can be used by both the former and the latter for safety’s sake (such as the Parent/Teen Contract), and other ways these vital messages can be spread (morning high school announcements about driving safety being another).
Increased patrols, as we’ve seen, can have a big impact too. Tragically, though, it’s also vital to address the increased need for emergency responses during this time. In a Facebook post, Tennessee’s Fall Creek Falls State Park acknowledged that these 100 days can call for life-saving blood transfusions, sharing how they work and explaining the $25 eGift card incentives for doing so. Washington State, meanwhile, sees around one-third of its fatal traffic accidents during the three-month stretch beginning in June, which it calls the 90 Dangerous Days. In response, the Washington State Patrol shares the most common causes of accidents (speeding being key among them), some vital driving tips, including “always buckle up, adhere to posted speed limits, drive sober, and stay distraction-free.”
Road safety is paramount for drivers to bear in mind every journey they make. Nonetheless, as the National Road Safety Foundation points out, the summer is marked by an uptick in fatalities among teenage drivers. There are more vehicles on the road generally, for one thing, and during this period, younger drivers will typically have more free time to hit the road. Combine that with their lack of experience with safe driving habits and possibly with their vehicle itself, and it makes sense that this is a particularly dangerous time for them. After all, there are some common mistakes that even experienced drivers make on the road, and the risks are heightened with newer motorists.
During this time of year, there’s often more road maintenance and repair work taking place. All of these factors add up to busier roads that are more difficult and frustrating to navigate, which is also a very dangerous mix for those maintaining the roads and larger, less maneuverable vehicles like buses in particular.
A specific focus on safety measures during the 100 days of summer doesn’t mean that states across the country don’t prioritize these matters during the rest of the year, of course. Also in July 2026, Caltrans announced an enormous investment of approximately $2.5 billion, intended to “Strengthen transportation infrastructure and improve mobility across the state.” Including steps such as establishing more crossings and a sidewalk-widening program, it’s a strong signal that broader matters of road safety are vital across America year-round. Even so, the more attention that can be brought to the 100 days of summer, the safer motorists, pedestrians, and passengers may be.
Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out.
This known WSUS sync issue affects both client (Windows 10, version 1607 and later) and server (Windows Server 2012 and later) platforms.
On impacted WSUS servers, admins are not able to deploy the latest Windows updates via WSUS or Configuration Manager due to increased synchronization times or sync operation timeouts caused by a buildup of publishing metadata.
Microsoft rolled out a service-side mitigation on Saturday to address the issue for newly installed or rebuilt WSUS servers following heightened impact observed starting one week ago, on July 13.
“Synchronization times and sync operations on WSUS servers have been restored and are operating normally for new WSUS installations and rebuilds,” Microsoft said.
On Monday, Microsoft also shared a manual fix for customers who are still experiencing sync operation issues and timeouts to help admins return their WSUS servers to normal functionality.
“Organizations with existing WSUS server installations that are experiencing long sync times can benefit from manual steps in order to clean up unneeded metadata,” it noted in a Windows release health dashboard update. “This metadata is present in existing WSUS installations but can be safely removed.”
This requires them to back up each SUSDB database, run a cleanup query from SQL Management Studio against all SUSDB databases (including WSUS replicas), and update the MaxXMLPerRequest value to its default setting.
After the cleanup process, the first Windows Update scan may take longer than usual, but subsequent scans will return to normal timing.
“After the cleanup, reindex SUSDB, run the WSUS Server Cleanup Wizard, and then run IISReset or recycle the WsusPool application pool to clear cached catalog state,” Microsoft added. “The client-side DataStore.edb does not shrink automatically after the detectoids are removed. This is expected and does not affect scan performance.”
Microsoft has addressed similar WSUS issues that prevented admins from deploying the latest Windows updates in May 2025, July 2025, and August 2025.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
It’s official: We’re getting a pickle emoji next year. On Tuesday, July 14, the Unicode Consortium announced the nine new emoji you’ll see on your device in 2027. One new emoji is the pickle, and that means the eggplant’s reign as the go-to emoji for male anatomy could be coming to an end.
Here are the nine new emoji you will see on your device next year.
The Unicode Consortium originally proposed a squinty face emoji in 2025. However, the Unicode Emoji Standard & Research Working Group recommended changing that emoji to a cracking face in January.
Honestly, the cracking face emoji feels more relevant to today than the squinty face emoji. The squinty face read as suspicious while the cracking face emoji screams, “I’m putting on a brave face in these trying times.” If that’s not the most relatable sentiment these days, I don’t know what is.
While the Unicode Consortium approved these emoji, companies like Apple and Samsung still need to design and then implement their versions of the emoji. Those companies usually add the emoji to devices as part of a software update in the spring, so you likely won’t see these emoji on your phone until 2027.
Before these emoji land on your device, the Unicode Consortium will begin fielding proposals for the next round of new emoji. Anyone can submit an idea for a new emoji, and the Unicode Consortium usually uploads proposed new emoji to a public document late in the year. For example, the upcoming emoji were originally accepted in October, 2025.
For more on emoji, here’s how to decipher every emoji and the newest emoji on your iPhone and Android.
It’s officially the second half of 2026, which is going to be all about Grand Theft Auto 6. Until then, Sony has a new selection of games coming to PS Plus in July that includes Avatar: Frontier of Pandora, Dying Light and a couple of classic PlayStation 2 games.
PS Plus, which is Sony’s version of Xbox Game Pass, offers a large, constantly expanding library of games. Subscribers can choose from the Essential, Extra and Premium tiers, each with unique perks and benefits. Starting at $11 a month, the plans give subscribers access to games and rewards, and each month, all subscribers can play a handful of new games at no additional charge.
If you’re a PlayStation Plus Extra or Premium subscriber, you can grab these games starting July 21.
Avatar: Frontiers of Pandora came out in 2023, a year after Avatar: The Way of Water released in theaters. Developed by Massive Entertainment – a division of Ubisoft – the open-world action-adventure puts players in the role of a Na’vi raised by the Resources Development Administration, or RDA, before returning to defend Pandora. Set in the previously unseen Western Frontier, the game emphasizes exploration, aerial traversal on an ikran and combat using both traditional Na’vi weapons and human firearms. While its gameplay shares many similarities with the Far Cry series, its lush environments and faithful recreation of Pandora earned praise from critics.
Avatar: Frontiers of Pandora will be available for PS Plus Extra and Premium subscribers starting July 21.
Team Ninja went a different direction than its usual Ninja Gaiden style with 2024’s Rise of the Ronin. Set during Japan’s turbulent Bakumatsu period in the late 19th century, the open-world action RPG lets players shape the story by siding with competing political factions. Combat combines fast-paced swordplay with firearms and other period weapons with the challenging gameplay the studio is known for. Its blend of historical events, exploration and player-driven choices helped distinguish it from Team Ninja’s previous action games.
Rise of the Ronin is now available for PS Plus Extra and Premium subscribers.
Firefighting Simulator: Ignite puts players in the role of a firefighter responding to emergencies across a large fictional city in the American Midwest. Whether playing solo with AI teammates or cooperatively with up to three friends, players battle dynamic fires, rescue civilians and use authentic firefighting equipment to contain increasingly dangerous blazes. Powered by Unreal Engine 5, the game features real-time fire, smoke and heat simulation designed to create a more realistic firefighting experience.
Firefighting Simulator: Ignite will be available for PS Plus Extra and Premium subscribers starting July 21.
Mighty Morphin Power Rangers: Rita’s Rewind is a true nostalgia bomb of a game. The side-scrolling beat-’em-up reimagines the classic 1990s TV series with pixel art visuals, cooperative multiplayer and familiar villains, including a robotic version of Rita Repulsa. Players battle through stages inspired by the show before piloting Dinozords and the Megazord in 3D action sequences that break up the traditional brawler gameplay.
Mighty Morphin Power Rangers: Rita’s Rewind will be available for PS Plus Extra and Premium subscribers starting July 28.
It’s been more than a decade since Dying Light was released, but it’s still a title that gamers fawn over. Players explore the zombie-infested city of Harran using a fast-paced parkour system that makes traversing rooftops as important as combat. Scavenging for supplies, crafting weapons and surviving a dynamic day-night cycle keep the tension high as more dangerous infected emerge after dark. Its fluid movement and intense survival mechanics helped make it one of the most acclaimed zombie games of its generation.
Dying Light will be available for PS Plus Extra and Premium subscribers starting July 21.
Citizen Sleeper 2: Starward Vector builds on its predecessor by sending players across a lawless star system as an escaped android searching for freedom. Rather than focusing on traditional combat, the game emphasizes dialogue, dice-based skill checks and resource management as players assemble a crew and take on dangerous contracts. Its choice-driven storytelling and tabletop-inspired mechanics make every decision feel meaningful, with multiple paths that shape how the story unfolds.
Citizen Sleeper 2: Starward Vector will be available for PS Plus Extra and Premium subscribers starting July 28.
Snow Bros. Wonderland revives the long-running arcade franchise with a fresh 3D isometric look while staying true to its classic action-platforming roots. Players freeze enemies into snowballs before kicking them across each stage to defeat other foes and rack up combos. Cooperative play, colorful environments and larger-than-life boss battles help modernize the series without losing the charm that made the original games fan favorites.
Snow Bros. Wonderland will be available for PS Plus Extra and Premium subscribers starting July 28.
Psi-Ops: The Mindgate Conspiracy was first released for the PS2 in 2004 and had a mix of interesting physics gameplay that was a big trend in gaming at the time. Players control Nick Scryer, a secret agent who combines traditional gunplay with psychic abilities like telekinesis, mind control and pyrokinesis to take down enemies. The game’s physics-based powers encouraged creative problem-solving and helped it stand out from other action shooters of its era, earning it a cult following years after its release.
Psi-Ops: The Mindgate Conspiracy will be available for PS Plus Premium subscribers starting July 21.
Before it made a name for itself with the games Heavy Rain and Detroit: Become Human, developer Quantic Dream first experimented with making the point-and-click adventure gameplay style a bit more action-oriented with Indigo Prophecy. The supernatural thriller follows several interconnected characters as they investigate a string of mysterious murders while uncovering a conspiracy that threatens humanity. Its cinematic presentation, branching narrative and quick-time events helped lay the foundation for the studio’s later interactive dramas.
Indigo Prophecy will be available for PS Plus Premium subscribers starting July 21.
For more on PlayStation Plus, here’s what to know about the service. You can also check out other games on PlayStation Plus and games on Xbox Game Pass.

Microsoft Chief Sustainability Officer Melanie Nakagawa faced a barrage of pointed questions from the audience Friday during a session at the annual Pacific Northwest Climate Week in Seattle.
Protesters challenged Nakagawa through most of the 30-minute session held in a conference room at Seattle’s City Hall, calling out the company’s use of fossil fuel energy sources to power its AI data centers and challenging Microsoft’s commitment to climate goals set years ago.
As a reporter covering sustainability issues for GeekWire, I moderated the session. Many of the issues raised by the crowd were on my list of questions for Nakagawa. The disruptions also included chants from protesters seated among attendees, at times going beyond climate issues to condemn Microsoft’s technology deals with Israel.
Security guards ultimately ushered some protesters out of the space, while others remained. Interruptions from the audience continued for all but the final 10 minutes of the session.
The event capped off Pacific Northwest Climate Week, which included conversations around the city and region about climate change solutions, policies and innovations.
Microsoft has for many years been viewed as an environmental corporate leader, setting an ambitious goal in 2020 to become carbon negative within a decade. It created an internal carbon tax — one of the corporate world’s largest — that charges individual Microsoft divisions for emissions from sources like air travel to fund climate-friendly initiatives. The company is credited with helping create and sustain the carbon dioxide removal sector, among other roles.
But the rapid expansion of AI data centers and their huge energy demands are undercutting Microsoft’s standing. The company recently released its annual sustainability report, disclosing that its carbon footprint grew 25% last year, moving it further from its 2030 target.

One protester’s question was about a deal announced earlier this year in which Microsoft is partnering with Chevron to build a 2.7 gigawatt natural gas facility to power a data center campus in Texas. I asked Nakagawa how the company defends the agreement, and she pointed to the 4.7 gigawatts of renewable energy that Microsoft has supported in the state. I followed up by asking about the Redmond, Wash.-based company’s commitment to carbon dioxide removal (CDR) projects given recent reports about a pause on new deals.
Nakagawa was unable to answer before the crowd drowned her out with a call-and-response chant: “Microsoft, you can’t hide. We can see your dirty side.”
Another protester criticized the escalating pursuit of AI. “You’re selling us a product that we don’t even need, and we never should ask for,” he said. “No one wants AI. You’re destroying the climate with AI.”
I brought up legislation proposed earlier this year in Washington to mandate clean energy use and bring transparency to data center impacts in the state. Microsoft opposed and helped defeat the bill, though the company says it wants to work with lawmakers to pass rules next year. I asked what needed to change in the legislation for Microsoft to support it.
Nakagawa didn’t provide specifics, but noted that this year, for the first time, the company shared facility-level information in its annual report on electricity and water use for data centers worldwide.
“People want to know more about the data, and we believe you can have an honest and candid conversation with transparency and access to that information and data,” she said.
Given the obvious public concerns, I asked Nakagawa, “Do you really honestly believe that by 2030, the company can hit that carbon-negative goal?”
Nakagawa pointed to wide-ranging initiatives that are starting to help curb specific emissions, including investments to make Xbox devices lower carbon and financial support for the recent opening of a production plant in Moses Lake, Wash., for sustainable aviation fuel company Twelve.
“There are a couple areas where we’re seeing a lot of promising progress,” she said. “Look, this is going to be a hard target. We’ve not been at all shying away from the fact that this is a difficult goal.”
Apple has quietly increased the price of Apple Music in the US, with individual subscriptions now costing $11.99 per month instead of $10.99.
The change also affects Family and Student plans. In addition, several Apple One bundles are impacted. The price rise comes almost four years after Apple last increased Apple Music subscription fees in October 2022.
The biggest jump is for the Apple Music Family plan, which now costs $19.99 per month, up from $16.99. The Student plan has also increased by $1, bringing the monthly fee to $6.99.
Apple has also adjusted pricing for two of its Apple One bundles. While the Individual plan remains unchanged, the Family tier now costs $27.95 per month, up by $2. Meanwhile, the Premier plan has increased to $39.95 per month. Apple has also confirmed similar price increases in Brazil.
In a statement to Music Business Worldwide, Apple said the latest changes are “the result of rising licensing costs,” suggesting that higher payments to rights holders and music labels are behind the increase.
The price hike means Apple Music now sits closer to many of its biggest streaming rivals. However, the service continues to distinguish itself with features such as Lossless Audio, Hi-Res Lossless, Spatial Audio with Dolby Atmos, live radio stations and a catalogue of more than 100 million songs.
For existing subscribers, the increase is relatively modest on the Individual plan, but families will notice a more significant jump. Moreover, an extra $3 each month adds up to $36 more per year. This makes it one of the largest increases Apple has introduced for the service.
Spotify, YouTube Music and other services have all introduced price increases in recent years. As a result, premium music subscriptions are becoming steadily more expensive across the board.
If you’re already subscribed, the updated pricing should appear on your next billing cycle. New customers signing up from today will pay the new rates immediately. Meanwhile, anyone considering Apple’s wider ecosystem may want to compare whether an Apple One bundle now offers better overall value than paying for Apple Music on its own.
London Mayor Sadiq Khan handed a peerage by Keir Starmer alongside 15 other Labour figures… just days before the PM leaves No10
Weekend Open Thread – Corporette.com
The House | The City of London can help the new chancellor deliver growth in every postcode
Young campaigners urge incoming PM to act on outdoor junk food ads
CFTC blocks Kalshi from unwinding Michigan trades after court order
Two July Windows Left: The CLARITY Act’s Senate Fight and What Failure Means
Ripple Payments Joins MiCA With 14 Firms, Does It Mean Anything For XRP?
Nvidia Stock Slips After Big Tuesday Rally as Huang Confirms Vera Rubin Chip Is Now in Production Today
Democrats look to World Cup watch parties to register thousands of voters
Disney’s Most Ambitious Failed Star Wars Attraction Is Coming to SDCC
Ripple wins EU-wide access as ESMA adds it to MiCA register
Injective Submits SEC Transfer-Agent Registration to Onchain Ownership Records
Palantir Shares Rise After Expanded Nvidia Partnership and Fresh Analyst Upgrades Ahead of Earnings Day
Sail Virtually Aboard The “Itanic” With IA-64 Emulator
Turtle Beach Command Series KB7 review: a nifty screen-equipped gaming keyboard
Dark Secrets Emerge When Jailbreaking LLMs
XRP BOMBSHELL… XRP OMBOARDED FOR TRANSACTIONS!!!
Registration is now open for March for Men with Kev 2026
Unregistered fitter used Gas Safe logo on business flyers
New Cornerback Enters Vikings Trade Rumor Mill
You must be logged in to post a comment Login