Connect with us
DAPA Banner
DAPA Coin
DAPA
COIN PAYMENT ASSET
PRIVACY · BLOCKDAG · HOMOMORPHIC ENCRYPTION · RUST
ElGamal Encrypted MINE DAPA
🚫 GENESIS SOLD OUT
DAPAPAY COMING

Tech

Could active speakers spark a resurgence in hi-fi?

Published

on

Every year in the hi-fi and home cinema world there are trends – some you see from the start of the year, others start to develop over the course of a few months.

This type of convergence can almost be an act of serendipity – all these products launching around the same time – what could have kick-started this or any trend?

Let’s take a look at active, also known as powered speakers. They are starting to pop up with unerring regularity.

We’ve had Ruark Audio’s five-star powered speakers. We’ve also had the launch of Cambridge Audio’s L/R S (with more to come), KEF has launched a few active/powered speakers in the last few years, there are new models from Tangent, Triangle, Elipson, Kanto, Klipsch, Edifier – and this is just the beginning.

Advertisement

Hi-Fi for the masses?

Hi-Fi has struggled to attract the attention of a younger generation glued to smartphones, tablets and other mobile devices. Hi-Fi can seem hoary and stuffy compared to the worlds that mobile devices can offer.

Advertisement

Some hi-fi brands have taken the route of headphones to entice people not au fait with hi-fi. Speaker brands such as Bowers & Wilkins, Dali, Focal and others have invested big-time in headphones (or head-fi) as a gateway to hi-fi, but is it actually a gateway? Do people jump from headphones to hi-fi? Let’s say I’m not too sure.

Dali IO-12 lying flatDali IO-12 lying flat
Image Credit (Trusted Reviews)

But we’ve seen a renaissance of vinyl. There’s been a resurgence in CD, and even cassette tapes have enjoyed a few days in the sun, while wired headphones continue to drum up positive publicity.

But proper – or trad hi-fi – still struggles for some traction and momentum. The appeal it has is men of a certain age who like to decamp to their den to listen to music in peace.

Advertisement

But active and powered speakers could change that outlook.

For one, hi-fi takes up space. Who has space these days? Everyone wants to move to a bigger house for more space, and everyone wants to move to a smaller house because it’s less expensive. What’s something that’s the best of both worlds – saving space, still offering a good experience but ultimately provides convenience?

Advertisement

Well that could be active/powered speakers.

Advertisement
Ruark MR1 Mk3 speakersRuark MR1 Mk3 speakers
Image Credit (Trusted Reviews)

The amplification, in some cases the streaming and processing, can be done with just two boxes rather than many. But more than that, they’re multi-purpose in use.

I’m currently testing a pair of KEF and Edifier speakers, both of which come with HDMI eARC to connect to a TV, making them potential soundbar replacements. Other models have a built-in phono stage to connect directly to a turntable. USB means you can plug your music in that way.

And then there’s the wireless support. Some cheaper options will make do with just Bluetooth, but active speakers with Wi-Fi open the world to the likes of Spotify Connect, Tidal, Qobuz etc – high quality music streaming services that you just need to tap a few buttons to get started.

Hi-Fi sound, but without the faff. You can see the appeal, and why brands seem to have set their stall up in this area of the market.

Advertisement

Advertisement

But can they have an impact?

The great thing about active and powered speakers is that they can fit within your current set-up rather than having to buy certain products to create a system.

While traditional hi-fi offers outright performance, especially if you know what you’re doing, knowledge can also be a bit of a bugbear. Not everyone knows what they’re doing or can be bothered to find out either.

This is why the convenience of powered speakers is useful. The plug-and-play mentality, of reducing the number of steps and therefore complexity, is one I’d reckon has wide appeal.

Everyone likes to listen to good music – if you don’t, I fear you might be a miserable so–and–so–and a pair of speakers that can do that without sacrificing much in the way of performance has got to be worth pursuing.

Advertisement
PSB Alpha IQ on tablePSB Alpha IQ on table
Image Credit (Trusted Reviews)

Advertisement

But convenience is only great if you can afford it. At the low end you might consider £400 rather expensive – especially if you’re the type of person for whom a £70 Bluetooth speaker is you pushing the boat out. £400 (sorry, £399) has become the first boundary marker. You’ll find a decent experience for less, but you won’t find better for less.

It’s when we start to go up through the price bands that I can see things start to stall. Yes, Wi-Fi is a ‘good thing’ to have, but eyebrows start to raise when you see those models pushing £1000 if not more. And then we have your ‘posh’ active speakers, models that stretch the asking price to £2000+, despite not offering a feature set that’s markedly different from a pair of actives half the price. And in some cases, a performance that doesn’t quite live up to the premium billing.

So while this emergence of active and powered speakers is very much ‘good’, it’s also susceptible to money. It is also something of a lifestyle choice. People like listening to music, but how they do so is different. Not everyone wants to be tied to a desktop or their living room. They like to take their music with them.

Profile - Elipson Prestige Facet II 6 Active BTProfile - Elipson Prestige Facet II 6 Active BT
Image Credit (Trusted Reviews)

So while this emergence/growth of the active/powered is a good thing and may lower the barrier and make hi-fi more accessible, the biggest obstacle active speakers face is not in terms of perception. The biggest obstacle that active speakers, and hi-fi in general faces, is that it has, in a way, been superseded by something in plain view.

Like a riddle; what can you use at home and outside of it? What comes in different forms that allows you to listen to audio however you like? What’s the device tied to you in a very personal way?

Advertisement

Advertisement

What hi-fi has to overcome is the unassailable might of headphones, which has pretty much replaced traditional hi-fi. And I for one can’t see that happening anytime soon. Is the active/powered speaker doomed? Of course not, but maybe this sudden gold rush won’t necessarily result in the riches hi-fi brands hope it will.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Apple is considering increasing the screen size for the iPhone 20 Pro Max

Published

on

A new rumor claims that Apple is considering using what it will call a 7-inch screen for one of the 20th anniversary iPhones, although that isn’t as great an increase as it sounds.

One recent rumor claimed that Apple had begun production evaluation for a 2027 iPhone with a display that is curved on all four sides. Then another claimed that the iPhone 20 range would feature a significant redesign.

For the first time, though, a leaker is claiming that Apple is testing what would be its largest iPhone screen. According to Digital Chat Station on Chinese social media site Weibo, if it goes ahead with this screen, Apple will market it as being a 7-inch one.

The claim says, though, that it would actually be 6.96 inches. That’s close enough for Apple’s marketing, but it seems less significant since the current iPhone 17 Pro Max screen is 6.86 inches.

Advertisement

Still, screen sizes are measured diagonally so such a difference could amount to the iPhone 20 Pro Max screen being up to 2% larger than the current model. That’s enough to be noticeable in the hand, although there’s no indication yet whether the pixel density will remain the same.

The last time Apple increased the screen size of its iPhones was in 2024. Then the iPhone 16 Pro Max went up from 6.7 inches to 6.9 inches, while the iPhone 16 Pro screen was 6.3 inches where its predecessor had a 6.1 inch display.

Digital Chat Station says that the new, larger screen size has not been decided on. This leaker has a reasonable track record with Apple leaks, and has recently reported rumors about the screen size of the iPhone Fold 2.

Advertisement

Source link

Continue Reading

Tech

AI confidence just dropped 17 points in six months. That’s actually great news.

Published

on

Presented by JumpCloud


The organizations losing confidence in AI are the ones most likely to get it right.

Six months ago, 40% of IT leaders described their organizations as mature in AI deployment. Today that number is 23%. Before you read that as a setback, consider what it actually reflects.

We recently surveyed 800 IT leaders across the U.S. and U.K. for our Q3 2026 trends report, and the data tells a consistent story: the organizations revising their self-assessment downward are overwhelmingly the ones that have moved AI agents from pilots into production. They’re not losing faith in AI. They’re running into the problems that only show up when agents are doing real work in real systems, and they’re being honest about what they found.

Advertisement

That kind of honesty is harder to come by than it sounds, and it matters more than the confidence number itself.

Deployment was the easy part

84% of organizations plan to expand AI use in IT operations over the next 6 to 24 months, so the drop in confidence isn’t a retreat. What it reflects is a more accurate picture of what production actually requires.

In a pilot, an AI agent does one thing in a controlled setting. In production, it accesses real systems, makes decisions that affect real workflows, and operates continuously, often without a human in the loop. The governance infrastructure that entails is materially different from what it took to get the pilot working. Most organizations built enough to ship. Fewer built enough to scale.

The IT leaders revising their self-assessment are confronting questions they didn’t have to ask at the pilot stage: Can we see every agent running in our environment? Do we know what each one can access? If an agent behaved unexpectedly last week, how long would it take to find out? For most organizations, at least one of those answers is uncomfortable.

Advertisement
July-VentureBeat-Article-Graphic (1)

The gap between perception and reality is where risk accumulates

The graphic above captures the structural problem. Across confidence, governance, and autonomy, the same pattern holds: deployment is moving faster than the controls built around it.

The organizations that have closed this gap share specific characteristics. They’ve consolidated their IT environments rather than adding tools to solve each new problem, because every additional platform creates another place where agent identity, access, and accountability can go unmanaged. They treat AI agents as governed identities rather than tolerated shadow processes. And they measure what AI actually produces, not just what it deploys.

The payoff is tangible. Organizations in the top tier of our maturity model are five times more likely to report no barriers to expanding their AI agents than the average organization. They are not more cautious about AI. They are more confident in it, because they built the foundation that makes confidence earned rather than assumed.

The governance gap has a specific shape

The hardest problem in enterprise AI right now is not capability. It is accountability, and the data makes the specific failure point clear: non-human identity governance is the least adopted AI security practice we measured, in place at just 21% of organizations.

Non-human identities now outnumber human users in 83% of organizations, and that population is growing fast. Yet most of those identities exist without the governance structures that every human employee has as a matter of course: no formal record, no named owner, no defined scope of access, no offboarding process when their purpose expires. They keep running. They keep accessing systems. They keep accumulating permissions. We call these Zombie Agents, and they are the service account problem of the AI era, operating at machine speed and in every department.

Advertisement

The accountability gap is where real risk lives. When a human employee takes an action, there is an implicit accountability chain. When an autonomous agent takes an action, that chain breaks unless it has been deliberately engineered. Most organizations have not yet engineered it, and the gap between the autonomy agents are being granted and the oversight structures in place to manage them is widening every month.

What the confidence drop is actually telling us

When AI maturity confidence was uniformly high across the market, that was worth worrying about. It meant most organizations hadn’t yet run into the hard parts. A selective drop, concentrated among organizations actively running agents in production, means the market is developing a more accurate picture of what AI operations genuinely require.

The organizations recalibrating are doing the work that makes long-term AI adoption possible: building identity infrastructure that covers agents alongside humans and devices, unifying the environments where governance needs to apply, and measuring outcomes rather than just counting deployments. They haven’t lowered their ambitions for AI. They have raised their standards for what it means to run it responsibly.

84% of organizations plan to expand AI use over the next two years. The ones that will do it well are honest enough, right now, to admit what they haven’t yet built.

Advertisement

JumpCloud’s Q3 2026 AI Readiness Research report (n=800 IT leaders, U.S. + U.K.) is available here. The report covers AI agent deployment stages, identity governance gaps, IT unification benchmarks, and budget realism across mid-market and enterprise organizations.

Rajat Bhargava is CEO and Co-founder at JumpCloud.


Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact sales@venturebeat.com.

Source link

Advertisement
Continue Reading

Tech

Veteran Microsoft security executive joins AWS amid broader reshuffle in Redmond

Published

on

Rudra Mitra will lead Amazon security services in his new role. (LinkedIn Photo)

Rudra “Rudy” Mitra, who spent more than 27 years at Microsoft and most recently led its Purview data-security business, is joining Amazon Web Services as vice president of security services.

Mitra will oversee an AWS portfolio that includes tools such as GuardDuty and Security Hub, which companies use to track security risks across their cloud accounts. AWS recently added AI-specific threat detection to GuardDuty and, perhaps notably given today’s news, extended Security Hub to monitor AI workloads and security inside Microsoft Azure. 

He will report to Chet Kapoor, the former DataStax CEO whom AWS hired last year as vice president of search, security and observability, a role that reports to AWS CEO Matt Garman.

“Rudy brings decades of security experience, a passion for building, and a deep understanding of what customers need as the security landscape continues to evolve,” Kapoor wrote on LinkedIn

Mitra joined Microsoft in 1999 straight out of college, working on early efforts to deliver Office as an online service before launching Purview, the company’s data-security and governance product, in 2014. He announced his exit from Microsoft last week, addressing what was next at the time by saying only that there was “more on that soon.”

Advertisement

His departure comes amid a broader reshuffling of Microsoft’s security leadership this year under Hayete Gallot, who returned from Google in February to run the group and has been reshaping its executive ranks in recent weeks and months.

Gallot replaced Charlie Bell, who had joined from AWS in 2021 and continues at Microsoft as an individual contributor focused on engineering quality. She’s been overhauling the group’s product lineup, according to The Information, which reported last week that at least nine corporate vice presidents who reported to Bell have left the company this year.

Rohan Kumar left for Salesforce in June, Vasu Jakkal stepped down after six years. Krishna Kumar Parthasarathy departed this month after 28 years. Joy Chik, president of identity and network access, announced her retirement in April.

On the inbound side at Microsoft, Naseem Tuffaha returned in June to fill the corporate VP role Kumar had left, after nearly two decades at the company and a stint away.

Advertisement

When Gallot arrived, Microsoft named Ales Holecek, a longtime engineering leader, as the security group’s chief architect, reporting to her. David Weston, another veteran Microsoft executive, also reportedly shifted into the security unit earlier this year.

Source link

Continue Reading

Tech

US Police Now Armed With Israeli Spy Vans Simulating Mobile Phone Towers

Published

on

Longtime Slashdot reader schwit1 quotes an X post by Josh Walkos, author of the Substack We the Free: If you thought Flock was bad check out Falconet. Falconet from Israeli company Cognyte serves as a cell tower simulator that intercepts cell phone data from all devices within range. Police mount these systems in Tahoes so the vehicles can collect information while driving through areas without any direct interaction with targets. This mobile approach generates ongoing records of phone locations and communications for everyone nearby rather than only suspects, which creates comprehensive movement profiles and bypasses traditional warrant requirements under the Fourth Amendment.

Cognyte sells the technology directly to U.S. agencies, as shown by the Texas Department of Public Safety purchase of four Tahoes where over three point eight million dollars went to the interception equipment. Adoption spreads through routine vehicle procurement with little external review of how the collected data is stored or shared. Once active the systems permit warrantless collection of private cell phone data across entire communities during normal patrols, which enables potential misuse and leaves individuals with no effective way to discover or contest the surveillance.

Source link

Continue Reading

Tech

Head of US Safety Agency Resigns

Published

on

Chris Fall has resigned as director of the U.S. Center for AI Standards and Innovation just three months after being appointed to lead the Commerce Department’s federal AI testing institute. Arvind Raman, who oversees the Commerce office responsible for the institute, will serve temporarily in the role. “The Commerce Department did not provide a reason for Fall’s departure,” reports Reuters. From the report: Fall’s exit marks the latest change in direction for Trump’s approach to AI. The president upon returning to office in 2025 said the federal government should take a hands-off approach to the tech sector. He has since taken a more active role in monitoring the technology, though his public statements and policies appear to change week by week.

The institute is responsible for working with leading AI labs such as Anthropic, Google’s DeepMind and OpenAI to test their unreleased models for vulnerabilities. The group is staffed by scientists and engineers, who are focused on calculating the “demonstrable risks” posed by advanced AI models, according to the institute’s website. They want to limit opportunities for U.S. adversaries to use AI to develop chemical or biological weapons, or corrupt the data used to train American AI models.

Source link

Continue Reading

Tech

Assassin’s Creed Shadows for the Switch 2 is almost half price, but you’ll need to be quick

Published

on

Assassin’s Creed Shadows only launched last year, and Switch 2 owners can already pick it up at almost half its original price.

That reduction comes from a limited time deal that cuts Assassin’s Creed Shadows on Switch 2 from its usual £49.99 down to £25.99, a 48% saving that brings one of the franchise’s best reviewed games within easy reach.

Assasins creed shadows on a foamy backgroundAssasins creed shadows on a foamy background

Assassin’s Creed Shadows for the Switch 2 is almost half price today, in a time limited deal

This critically acclaimed Assassin’s Creed Shadows on Switch 2 drops from £49.99 to £25.99, a 48% saving on one of this year’s best games.

Advertisement

View Deal

Playing as Naoe puts the focus on stealth, using noise, light and shadow to slip past enemy patrols, while a new grappling hook opens up parkour routes across castle rooftops that were not available in earlier games in the series.

Advertisement

Naoe’s kit also includes a hidden blade for instant assassinations along with shuriken and smoke bombs to create useful distractions, giving stealth focused players several ways to clear a room without ever triggering an alarm.

Switching over to Yasuke flips that approach entirely, trading stealth for silent bow takedowns and heavy melee combos with a katana or naginata, so a single stronghold can be cleared through patience or brute force depending on your mood.

Advertisement

The Whatsapp LogoThe Whatsapp Logo

Get Updates Straight to Your WhatsApp

Advertisement

Join Now

Switching between the two protagonists mid mission is encouraged rather than locked to separate story chapters, letting you scout a stronghold as Naoe before switching to Yasuke for a more direct assault once guards are alerted.

Advertisement

Both characters explore the same dynamic version of feudal Japan, where castle towns, ports and shrines shift with the weather and the seasons, giving the world a sense of change that keeps returning to the same location interesting.

And now with a glowing discount, you have the chance to explore feudal Japan in all its glory.

SQUIRREL_PLAYLIST_10148964

Advertisement

Advertisement

Source link

Continue Reading

Tech

USPTO Denies MLB’s Insane Attempt To Trademark ‘Play Ball’

Published

on

from the play-trademark-ball dept

There is no shortage of examples of Major League Baseball attempting to wield overly broad trademarks its obtained to bully others, nor examples of MLB attempting to stretch its trademark rights much further than they go. MLB opposed a trademark for a Brooklyn burger joint on behalf of the Dodgers, a team that hadn’t played in Brooklyn for over five decades at that point. The league, at one point, tried to bully a local Little League for using the names of MLB teams, but not their logos, which is something that roughly every Little League team everywhere does. It attempted to trademark the names of three cities in which MLB teams play. And, my personal favorite and most appropriate for this post, the league opposed a finance company’s trademark application because it claimed two of its separate teams both owned the rights to the letter “W”.

The real lesson in all of this is that the League can’t be trusted with anything other than very narrow trademarks. Anything more broad than that causes them to act the fool. And perhaps this is a lesson the USPTO has actually learned, given that it recently denied MLB’s attempt to trademark the phrase “Play Ball”.

The United States Patent and Trademark Office denied MLB’s application to trademark “Play Ball” for clothing, the USPTO wrote in a final action filing on Friday.

“In this case, the applied-for mark is a commonplace term, message, or expression widely used by a variety of sources that merely conveys an ordinary, familiar, well-recognized concept or sentiment,” the USPTO wrote in its denial.

The USPTO also wrote phrases “that merely convey an informational message are not registerable.”

Advertisement

Those are things that MLB’s well-dressed lawyers absolutely know, of course. But they attempted to bank on a complacent trademark office to try to sneak one past the goalie anyway, to mix metaphors. And if the league had gotten the mark, you can be one hundred percent certain it would have gone on yet another bullying campaign targeting apparel makers, other sports leagues, and who knows who else.

In fact, the most surprising part of all of this is that it appears to have taken 4 years for the USPTO to reach this decision. Josh Gerben breaks it all down like this.

Gerben said the rejection and public domain nature of phrases could depend on the class. Other companies have trademarked “Play Ball,” including a food company for bubble gum, a minerals company for surfacing playgrounds and “The Play Ball” for the gala fundraiser for the Strong National Museum of Play in Rochester, New York.

“In this case they are saying that the phrase has become so ubiquitous and it has this underlying meaning,” Gerben said. “For a clothing brand, the government doesn’t think it’s unique enough to be registered.”

Somehow, some way, we have to get past this practice of looking at trademarks as some kind of retroactive profit center, where a business gobbles them up and then corners a market that was already in existence. That’s all that this sort of attempt to lock up language is. The term “play ball” can be associated with Major League Baseball, certainly. It can also be associated with other sporting activities, or business negotiations, or any other number of things. That’s because it has become a generic phrase, no longer an identifier of the source of a good or service.

Advertisement

Again, MLB’s lawyers knew all of this before applying for the mark. They just didn’t care.

Filed Under: baseball, play ball, play ball play ball play ball, trademark, uspto

Companies: mlb

Source link

Advertisement
Continue Reading

Tech

Drones with Echolocation Technology Lets Them Hear Through the Haze

Published

on

Drones Echolocation Technology
A palm-sized drone flies through thick fog, artificial snow, and near-total darkness, dodging poles, transparent plastic sheets, and tree trunks without a single camera or laser. Its only guide is sound. Researchers at Worcester Polytechnic Institute built the system, called Saranga, by copying the way bats find their way in caves. The result is a lightweight, low-power approach that keeps working when vision-based sensors simply stop.



Cameras and LiDAR begin to fail as light becomes dispersed or just disappears. Radar, on the other hand, drains the batteries right when the machines need them. By contrast, ultrasound travels through smoke, dust, and snow in the same way as it does in clean air. Bats have been doing it forever, simply emitting short, high-frequency chirps and listening for faint return echoes that bounce off obstacles. The WPI team, led by Nitin Sanket of the Perception and Autonomous Robotics division, decided to give a flying robot the same superpower.

Sale


DJI Neo, Mini Drone with 4K UHD Camera for Adults, 135g Self Flying Drone that Follows You, Palm Takeoff…
  • Due to platform compatibility issue, the DJI Fly app has been removed from Google Play. DJI Neo must be activated in the DJI Fly App, to ensure a…
  • Lightweight and Regulation Friendly – At just 135g, this drone with camera for adults 4K may be even lighter than your phone and does not require FAA…
  • Palm Takeoff & Landing, Go Controller-Free [1] – Neo takes off from your hand with just a push of a button. The safe and easy operation of this drone…

They began with a quadcopter that they custom manufactured, measuring 16 cm across and weighing 460 kilos. It has two very tiny TDK InvenSense ICU30201 ultrasound sensors at the front, each with a broad sonic horn. Another one points downward to help with altitude. All of this ultrasound sensing requires only 1.2 milliwatts, and it all operates on a Google Coral Mini computer with no additional beacons or GPS, so there is no extra power expenditure.

Advertisement

Drones Echolocation Technology
Propeller noise was the first major issue, as the spinning blades are basically spewing out some serious ultrasound noise that drowns out the weak echoes coming back from distant objects (we’re talking minus 4.9 decibels here, which is weak signal territory for the team), so they fixed it by physically taping a simple foam and plastic shield between the propellers and the sensors. This barrier shuts out the majority of the prop noise while allowing outward sound and returning echoes to pass through. With this piece of hardware fixed, the usable range increased from one meter to two meters.

Drones Echolocation Technology
Even after they sorted the prop noise with their shield, the returning echoes were still getting lost in the random noise, so they attempted utilizing classical filters to sort it all out, but it wouldn’t comply. They required something more sophisticated, so they trained a tiny neural network to sort through all the filth. They termed it Saranga (also a neural network), and it basically looks at a brief string of echo readings as if it were a little picture. It uses this to learn the forms of true reflection patterns, after which it can suppress random prop noise. Training employed a lot of synthetic data mixed in with some real propeller noise, so once they had it functioning, the model flowed over to the real world very easily, with no additional fine tuning required. Saranga is then “compiled” to function on the Edge TPU, and it only takes up approximately 0.5 gigabytes of memory and does an inference in around 15 milliseconds while using only a few millijoules of energy.

Drones Echolocation Technology
The cleaned-up echoes are then sent to a basic localization stage, and because the left and right sensors are at slightly different angles, they can determine the horizontal angle to an obstacle in the same way that bats do. The down-pointing sensor then provides the height. It’s all really easy; simply a quick list of surrounding obstacles, and then it’s up to the flight controller to say, “Hey, steer clear of all this while still traveling in that direction.”
[Source]

Source link

Continue Reading

Tech

Drinking 5 Cups of Coffee a Day Could Reduce Heart Risk

Published

on

A new American Heart Association scientific statement concludes that up to about 400 milligrams a day, or roughly three to five cups of plain coffee, is safe for most adults and may be linked to lower risks of cardiovascular disease. The benefits appear to depend heavily on the source and preparation, with coffee and tea looking more favorable than energy drinks, and added sugar, cream, syrups, or sweeteners potentially canceling out the upside. ScienceAlert reports: “Caffeine consumed in coffee is a key part of daily life for millions of people,” says Gregory Marcus, cardiologist at the University of California, San Francisco, and Chair of the AHA volunteer writing group behind the statement. “In our review of the most recent research, for most adults, intake of up to 400 milligrams of caffeine per day, the equivalent of up to five cups of caffeinated coffee per day without added sugars or fillers, is safe and does not increase cardiovascular risk.”

The statement focused on caffeine’s relationship with cardiovascular risk factors, such as blood pressure and diabetes, as well as types of cardiovascular disease, including arrhythmias, coronary artery disease, stroke, and heart failure. The picture that emerges is complicated, but generally positive. […] All up, the new AHA statement concludes that there’s a growing body of evidence that caffeine isn’t harmful when taken in moderation, and that coffee specifically may be beneficial. The statement was published in the journal Circulation.

Source link

Continue Reading

Tech

Safety guardrails blocked Hugging Face’s defenders, not the attacker, when an AI agent breached its systems

Published

on

Hugging Face’s incident response team first turned to frontier AI models to analyze a breach of the company’s production infrastructure, and the models refused to help. Commercial safety guardrails built to stop attackers blocked every forensic query because they treated the IR team’s real exploit data the same way they would treat a live attack.

The attacker, an autonomous AI agent running the campaign end to end, moved laterally across the Hugging Face infrastructure for a weekend, undetected and unstopped.

Security leaders are quick to recognize the pattern and diagnose what went wrong. “I’ve seen versions of this during red-team exercises and internal security testing, but this is one of the first high-profile examples where it materially affected real incident response,” said Merritt Baer, senior adviser to Andesite, G2I, and AppOmni and former Deputy CISO at AWS.

None of this is unique to Hugging Face, Baer said. “Commercial frontier models optimize for preventing misuse. They generally have no cryptographic or organizational way to determine whether the person asking ‘analyze this malware’ is an incident responder or the malware author.”

Advertisement

A malicious dataset opened two code-execution paths

On July 16, Hugging Face disclosed that an autonomous AI agent system had compromised its production infrastructure, gaining unauthorized access to a limited set of internal datasets and several service credentials. The company verified that its software supply chain was clean and found no evidence of tampering with public models, datasets, or Spaces.

Hugging Face is still assessing whether the intrusion touched any partner or customer data and says it will contact affected parties directly as required. But few enterprise threat models had accounted for the attacker Hugging Face faced. An autonomous agent ran the entire campaign from initial access through credential harvesting. No human guided it.

The entry point was a malicious dataset. When the data-processing pipeline ingested it, the dataset triggered code execution in two ways, through a remote-code loader and through a template-injection flaw in dataset configuration files. No admission gate screened the file before it reached a processing worker, the compute job assigned to each dataset. Initial access came through the data pipeline itself, a route that worked because most enterprise security teams treat the data feeding their pipelines as trusted input rather than an attack surface.

Worker isolation did not hold. From that first foothold, the agent broke out onto the node running the workload, then harvested cloud and cluster credentials scoped broadly enough to reach multiple internal clusters, all of it inside a single weekend. Hugging Face described the agent framework as executing thousands of individual actions through a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services. The disclosure adds that the framework appeared to be built on an agentic security-research harness, which would put tooling designed for red-team work behind a live intrusion.

Advertisement

Why the defenders’ queries looked like attacks

Investigators reconstructed more than 17,000 recorded events using AI-driven analysis agents of their own.

First attempts at the log analysis ran on frontier models behind commercial APIs. Defenders’ steps included submitting real attack commands, exploit payloads, and command-and-control artifacts for classification, but safety guardrails blocked the requests outright.

Baer traced the block to the prompts themselves. “The same prompts that are most valuable during an active intrusion, shell commands, exploit chains, credential dumps, persistence mechanisms, lateral movement, are exactly the prompts most likely to trigger safety systems,” she told VentureBeat. “As AI becomes embedded in security operations, this becomes an operational resilience issue rather than merely a model policy issue.”

The forensic analysis finished on GLM 5.2

GLM 5.2, an open-weight model deployed on Hugging Face’s own infrastructure, took the job the commercial APIs refused. No attacker data left the company’s environment. “This experience points to a gap worth planning for,” the company wrote in its disclosure. Hugging Face does not know which model powered the agents. It could have been a jailbroken hosted model or an open-weight model running without restrictions. Either way, the disclosure continued, “the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried.” Hugging Face drew that line itself, writing that the experience is not an argument against safety measures on hosted models and that it is sharing the feedback with the providers concerned.

Advertisement

What authenticated trust changes

The industry, Baer argued, needs to move past treating AI safety as a content moderation problem. “Security operations require something different. Authenticated trust.” Instead of asking whether anyone should receive an answer, the question becomes whether an authenticated security team, operating under enterprise controls, should receive it. “The model shouldn’t only understand what is being asked. It should understand who is asking, why, and under what governance.”

“Organizations already build contingency plans for cloud outages, identity provider failures, or EDR failures,” Baer wrote. “AI assistants are becoming another dependency.”

Her advice on IR playbooks was blunt. “A mature incident response plan should assume that during a severe incident, commercial AI APIs may refuse requests, API rate limits may become unavailable, internet connectivity may be impaired, and data governance rules may prohibit uploading forensic evidence externally.” The lesson, she wrote in her emailed answers, “isn’t ‘don’t use commercial models.’ It’s ‘don’t make them a single point of failure.’”

AI-enabled attacks rose 89% year-over-year

Autonomous AI-driven attacks are not limited to AI platforms. CrowdStrike’s 2026 Global Threat Report documented AI-enabled adversary operations increasing by 89% year over year, with average breakout times falling to 29 minutes. Enterprises running AI workloads in production with agentic access to their pipelines face similar exposure.

Advertisement

Six control domains determined the blast radius and recovery speed at Hugging Face. Each one maps to a concrete action security leaders can take before the next autonomous-agent breach arrives.

AI Pipeline Breach Response Playbook

Control Domain

What Broke

Monday Action

Advertisement

Dataset admission controls

Two code-execution paths were exploited. No admission gate validated the dataset before it reached a processing worker. The data pipeline became the initial access infrastructure.

Require sandbox execution and static analysis of all datasets before they reach workers. Block remote-code loaders and template-injection paths by default. Audit for any path granting code execution to untrusted content. Report to the board as a supply-chain risk.

Worker-to-node privilege boundaries

Advertisement

Worker isolation failed to prevent escalation to the node. The agent gained cluster credentials because the workload-infrastructure boundary was never enforced at container runtime.

Enforce hard privilege boundaries between workers and nodes. Deploy container runtime security to prevent workload escape. Audit whether workers can reach node-level APIs or credential stores. Include in the next penetration test scope.

Credential exposure

Cloud and cluster credentials harvested after node access. The scope was broad enough for lateral movement across multiple clusters over a weekend.

Advertisement

Rotate credentials on a scheduled cadence and after any anomaly alert. Scope to the minimum cluster and service. Deploy monitoring that flags access from unexpected nodes at machine speed. Map blast radius for board reporting.

Machine-speed detection

Thousands of actions through short-lived sandboxes with self-migrating C2. AI-assisted anomaly detection surfaced the campaign after a weekend of lateral movement, per the disclosure.

Calibrate detection for machine-speed patterns. Ensure high-severity alerts page responders in minutes, regardless of time. Audit SIEM rules for detecting thousands of short-lived executions within a single hour.

Advertisement

Private AI forensic capacity

Commercial APIs blocked forensic analysis. Guardrails screened query content, never analyst identity. Investigation ran on GLM 5.2 privately.

Deploy a capable open-weight model on private infrastructure before an incident. Test against real forensic workflows. Ensure IR playbook includes fallback for when commercial APIs refuse. Document gap for cyber insurance.

Autonomous-agent threat modeling

Advertisement

The campaign matched the forecast agentic-attacker scenario, but no threat model had operationalized it. LLM powering the agent is still unknown.

Add autonomous AI agents as a distinct adversary class with machine-speed decision cycles. Run tabletop at agent speed. Present results to the board as evidence that timelines need recalibration. Include in the cyber insurance application.

The board question is operational resilience

“The question for directors is simple. What happens if one of our critical security tools becomes unavailable during the exact moment we need it most?” Baer framed that as operational resilience, not AI policy.

She would have boards take that framing straight to management and press for specifics. “Have we actually exercised that fallback during tabletop exercises? How quickly can we switch during an incident?” Procurement needs to change alongside governance, starting with the questions buyers ask. Security teams evaluating AI vendors should ask about their process for authenticated incident responders, whether enterprise customers receive different handling during verified incidents, and whether models can be deployed privately. “Those questions belong alongside uptime, privacy, and compliance,” Baer said.

Advertisement

“The biggest takeaway isn’t that safety guardrails are ‘bad.’ They’re doing what they were designed to do,” she argued.

Her larger point is that the threat model itself has changed. “For decades, defenders had better tools than attackers because they operated inside trusted enterprise environments. With foundation models, both sides increasingly use the same capabilities, but one side is constrained by enterprise governance, policy, compliance, and safety controls, while the adversary simply downloads an uncensored open-weight model and keeps going. That’s a new kind of asymmetry,” she added. “The organizations that handle it best won’t necessarily be the ones with the most powerful AI. They’ll be the ones that architect AI as a resilient security capability rather than a single cloud service.”

Hugging Face has contained the intrusion, rebuilt compromised nodes, rotated credentials, and reported the incident to law enforcement. The company recommends that all users rotate access tokens and review recent account activity. Mid-incident, Hugging Face found out whether its own AI tooling would be available, and the first answer was no. Security leaders running AI in production should find out in incident response planning instead, before an autonomous agent forces the test.

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025