The 2026 Data Engineering Bundle has 7 online courses designed to help learners build skills that align directly with industry expectations. The focus is on practical tools and languages used by data professionals: Python for programming, Pandas and NumPy for data manipulation, foundational certification prep and specialized work with Databricks, an industry-standard platform for data engineering and analytics workflows. The content is on-demand, self-paced and designed to be revisited as learners build proficiency over time. It’s on sale for $35.
Note: The Techdirt Deals Store is powered and curated by StackSocial. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.
A malware campaign is using fake Zoom updates and business files to install ScreenConnect, giving attackers remote control through software that can resemble legitimate IT activity. And now, it’s come to Mac.
Securonix researchers detailed the campaign, named Smoke#Screen, in an August 4 report. They traced Windows scripts, compiled loaders, an HTML phishing page and a macOS package named “ZoomUpdateInstaller.pkg” to shared infrastructure.
ScreenConnect is legitimate remote monitoring and management software published by ConnectWise and commonly used by IT departments. The campaign configures genuine ScreenConnect clients to contact attacker-controlled relay servers rather than an authorized company system.
Once connected, the software can give an attacker remote desktop and management capabilities. The resulting activity may resemble ordinary technical support, making the intrusion harder to identify without examining how the software arrived and where it connects.
Advertisement
The macOS package contacted the same primary relay server as several Windows payloads, tying it to the wider operation. However, Securonix did not identify how the Mac installer was distributed or report any confirmed Mac infections.
The report also didn’t say whether the macOS package was signed and notarized by Apple. The discovery therefore establishes that the campaign’s infrastructure included a Mac payload, but not that attackers successfully delivered it to Mac users.
The finding adds to a series of campaigns using fake installers and familiar software brands to persuade Mac users to run malware. In this case, the strongest evidence of completed infection chains comes from the Windows payloads analyzed by Securonix.
Fake updates lead to ScreenConnect
Securonix documented four social engineering themes involving Zoom updates, Adobe updates, business document reviews and system maintenance checks. Each observed attack path tried to persuade the victim to open a file that installed ScreenConnect.
Advertisement
A live WsgiDAV server running at 207.174.0.143:8080, a Python-based WebDAV implementation commonly used for local file sharing and development. Image credit: Securonix
The investigation began with a Windows VBScript file named “zoom-update.vbs” that appeared in Securonix telemetry. Researchers followed its network activity to an accessible staging server containing 15 payloads, including the macOS Zoom installer.
Other files included ScreenConnect installers named “SystemCheck.msi” and “Document-review.msi.” The server also hosted Windows executables posing as Adobe Reader updates and document viewers.
The files used different names and delivery methods, but they served the same purpose. Each installed an unauthorized ScreenConnect client configured to contact attacker infrastructure.
Researchers identified three ScreenConnect relay clusters, each using a separate RSA key pair. The primary server also hosted the campaign’s payloads, allowing it to distribute files and manage infected computers.
Other parts of the campaign used Dropbox and a Cloudflare Quick Tunnel to deliver payloads or conceal supporting infrastructure. Downloads involving familiar cloud services may attract less attention than traffic from an unknown domain, although security tools can still detect suspicious commands and installations.
Advertisement
Separate relay servers could also make the campaign more difficult to disrupt. Identifying or shutting down one cluster would not disable clients configured to contact the others.
Windows loaders attack security defenses
The Windows samples show that the campaign changed its methods during Securonix’s investigation. Initial loaders relied on obfuscated VBScript, encrypted commands and environmental checks intended to complicate automated analysis.
One script stopped running when it found less than 2 GB of physical memory, a condition associated with some lightweight virtual machines and malware sandboxes. It also searched for Wireshark, Process Monitor, VirtualBox services and VMware Tools before continuing.
Other loaders used batch files and compiled .NET programs to attack Windows security controls before installing ScreenConnect. The commands attempted to disable Microsoft Defender protections, change SmartScreen settings and add antivirus exclusions.
Advertisement
JqbMljCi.msi is one of the randomly named files hosted on the staging server and is one of three files confirmed to be identical. Image credit: Securonix
The loaders also tried to remove Mark of the Web data from downloaded files. Windows uses that marker to identify files obtained from the internet and apply additional security warnings.
One loader added the root of the C: drive to Microsoft Defender’s exclusion list. It also attempted to change the Windows Defender service’s startup configuration.
Securonix said the sequence could leave a computer with weakened protections even if the later ScreenConnect download failed. The broad exclusion could also make it easier for additional malware to avoid antivirus scanning.
The campaign later changed direction. Researchers found a newer loader that removed the aggressive Defender-tampering sequence and instead waited three minutes between installing ScreenConnect and starting its service.
The delay appeared designed to separate related events inside endpoint detection logs. Securonix also found a source-code comment that referred specifically to breaking Elastic event correlation.
Advertisement
The finding supports the researchers’ conclusion that the operators adjusted their tools in response to commercial security products. However, the report does not establish when each loader entered circulation or whether all versions were used sequentially.
The analyzed Windows attack paths ultimately installed legitimate ScreenConnect MSI packages signed by ConnectWise through a valid DigiCert certificate chain. Signed remote-management software may receive less scrutiny than an unknown executable, although a valid signature does not make an unauthorized installation safe.
Attackers have used similar remote access capabilities in previous Mac malware campaigns because they provide continuing control without requiring a custom backdoor. Smoke#Screen instead deploys a genuine enterprise management client that may already be familiar to corporate security teams.
The report does not identify the people operating Smoke#Screen or connect the campaign to a known hacking group. Shared servers, encryption keys and payload development link the analyzed files, but they do not reveal the operators’ identity, location or motive.
Advertisement
How Mac users can stay safe from Smoke#Screen
The attack paths documented by Securonix required a victim to open a file presented as an update, document or maintenance utility. Software such as Zoom and Adobe Reader should be updated through built-in tools or installers downloaded directly from the developer.
Mac users should treat unexpected installer packages as suspicious, even when the filename refers to familiar software. Previous campaigns have shown that signed or even notarized apps can still begin a malicious installation.
Organizations should inventory approved remote management tools and identify ScreenConnect agents that contact unknown servers or raw IP addresses. Defenders should also examine how the software arrived, which process launched it and whether the installation was authorized.
The ScreenConnect name and its valid digital signature are not enough to establish that an installation is safe. The relay destination and surrounding activity provide the context needed to separate approved support software from an attacker’s remote-access tool.
Something to look forward to: Microsoft is expanding how older Xbox games are played, with new plans that would bring Xbox 360 titles to PC and a wider range of devices. The effort, outlined in a document sent to developers, points to a broader push to make Xbox games work across consoles, PCs, and handheld systems.
According to the document seen by The Verge, Xbox 360 games will be able to run not only on Microsoft’s upcoming Project Helix console, but also on “Xbox PCs” and handheld devices. That follows earlier signals that Helix will support PC games, suggesting Microsoft is building a system where the same titles can move more easily between different types of hardware.
The goal appears to be a more unified Xbox ecosystem. By extending older games to PC, Microsoft can grow its overall library and make it accessible beyond traditional consoles. It’s also part of a longer-term shift toward digital distribution, where games are tied to accounts rather than physical formats or specific devices.
Developers will decide whether to make their Xbox 360 titles available through the backward compatibility program. They will also control pricing and whether those games are included in Game Pass. That flexibility could help Microsoft bring more titles into the program without forcing publishers into a single model.
Advertisement
The rollout for Xbox 360 compatibility is expected to happen gradually between 2027 and 2028 across next-generation devices. Ahead of that, Microsoft is planning a full launch of its original Xbox games on PC in October 2026. That program was introduced earlier this year with just four titles, suggesting a phased approach.
The same document also sheds light on Microsoft’s efforts to connect physical and digital ownership. The company is working on a system that would let players convert certain disc-based games into digital licenses. If a user inserts an Xbox One or Series game disc into a compatible console, they would receive a digital license tied to both the disc and their account.
That license would carry across devices, allowing players to access the game without needing the disc each time. However, ownership would still be linked to the physical copy. If the disc is sold or transferred, the digital license would move with it, and the original owner would lose access. This setup is designed to keep resale and trade-ins possible while limiting duplicate use.
Microsoft had planned to test this feature with Xbox Insiders in July, with a wider rollout expected in August. The beta has been delayed, and it is unclear whether the original timeline still applies.
Apple has set new annual sales in India, with its second main iPhone manufacturing base generating a record $10 billion in sales despite currency and tax challenges.
India serves as Apple’s second base of iPhone production alongside China, as part of the wider supply chain. While Apple has been building up its production capacity in India, it’s also been increasing sales there, too.
According to a Tuesday Bloombergreport, Apple has exceeded $10 billion in annual sales in India over the last fiscal year. It eclipses the $9 billion annual revenue that was reported in September 2025.
Advised by an unnamed source familiar with the matter, the $10 billion was for the 12-month period running to March. It represents a double-digit year-on-year percentage increase over the previous fiscal year.
Advertisement
The bulk of the sales are for the iPhone, the source claimed. However, the demand for other products, such as iPad and Mac sales, also rose in the year.
A significant increase, despite financial disadvantages
Earning $10 billion in revenue in India is certainly a lot. Compared to other markets, India is still relatively small.
By comparison, China has a comparative population of 1.41 billion people, but accounted for $18.8 billion in revenue in Apple’s most recent quarter. Japan managed $6.6 billion in the last quarter, with its population of 122 million people.
The $10 billion figure isn’t significant when put against other major regions Apple monitors. But, it is when you consider that India is a challenging country for sales.
Advertisement
While there’s a backdrop of Apple expanding its presence with more retail stores over time, it has to combat exchange rates. India’s rupee has declined 10% versus the US dollar.
There are also local taxes to contend with, which also push the price up. The entry-level iPhone 17 is 82,900 rupees in India, making it approximately $870 versus the same $799 product in the United States.
The higher prices have been countered by Apple working with banks to provide credit card rebates, as well as increasing student discounts and handling trade-ins.
More than just production
India is a tougher trading environment for Apple, and it is succeeding, but it is only part of the reason for its work there.
Advertisement
Apple has been working to diversify its supply chain from its China-centric arrangement for years, and India has proven itself to be highly useful in accomplishing that.
It also helps that Apple gets considerable financial benefits for setting up shop in India. Various production incentives and tax exemptions have made it viable for Apple to continue expansion in the country.
On Monday, it was revealed that more benefits are on the way. That includes import tax exemptions for components that are used for manufacturing in India bit are used in products that are exported and not sold in the country.
The Ford Mustang that is currently sold in Europe has a number of similarities to the U.S. model, but it also differs in numerous ways, incorporating a number of changes that make it viable to sell in Europe from a marketing perspective, while also enabling the Mustang to meet the necessary standards that every vehicle sold in the EU must conform with. Just like with other American and European cars, there are differences between the EU market Mustang and the American versions.
The current Mustang sold in both Europe and the U.S. is the seventh-generation S650 model, which has been on sale since the 2024 model year. On the outside, it displays its new “tri-bar” LED headlights, set into a more aggressive front end, with wider rear fenders. Inside, there have been major changes, with a new interior featuring two digital displays that can be configured to each owner’s preferences.
Advertisement
The digital instrument cluster measures 12.4 inches, while the adjoining central touchscreen is larger at 13.2 inches. This significant change to the Mustang’s interior is clearly an attempt on Ford’s part to attract a younger, more tech-savvy customer to its long-running ponycar, in Europe as well as in the U.S. The seventh-gen ‘Stang is definitely one of the best-looking Mustangs Ford has ever made.
Advertisement
European Mustangs are all made with V8 engines
After offering the previous, sixth-generation Mustang in both four-cylinder EcoBoost and V8 GT versions and seeing most buyers opting for the full-fat V8, Ford made the decision to offer only the V8 in Europe when the seventh-generation model went on sale. The current Mustang lineup consists of the Mustang GT, in either coupe or convertible form, and the Mustang Dark Horse coupe, which showed us why Ford’s Mustang is a survivor.
Just as with the U.S. versions, the Euro Mustang GT and Dark Horse are powered by a 5.0-liter V8 engine, but due to stricter emissions controls, the GT model loses 40 horsepower, dropping its output to 440 horsepower, compared to 480 for the U.S. version. The Mustang Dark Horse model is also restricted, generating only 448 horses, sacrificing 52 to the European emissions gods. Transmission options consist of either a six-speed manual or a 10-speed automatic, both or which drive the rear wheels. The GT features a limited-slip differential, while the Dark Horse runs a Torsen limited-slip diff. An added bonus for European Mustang customers will be a standard Performance Pack, which comes with an active valve exhaust, 19-inch alloy wheels, and the previously mentioned limited-slip differential.
Performance figures provided by Ford show that the 10-speed automatic provides better acceleration figures. The 0-100 km/h run (equal to 0-62 mph) goes by in 4.9 seconds for the GT coupe and in 4.4 seconds for the Dark Horse, which is still pretty good, considering the power loss.
Advertisement
European Mustangs are much more expensive
By the time that the Mustang conforms to European emission regulations and is shipped thousands of miles to its destination, it ends up costing quite a bit more than the U.S. version. The U.S. base Mustang GT Fastback coupe with the Performance Pack added, which comes closest to the Euro spec GT, lands here for $54,455 including destination charges but without taxes. The European price for the same car, on Ford’s German website, comes out to 62,400 Euros, which at the current exchange rates comes out to about $71,000, which does include Europe’s value-added tax, 19% in Germany’s case.
This amounts to a $16,601 premium that European buyers pay for the least expensive Mustang, with even higher prices for optioned-up GTs. Then there’s the Dark Horse, which starts at 75,000 Euros, which converts to $85,398 including the VAT. That becomes an upcharge of $19,863 when compared to the least expensive U.S.-purchased Dark Horse, which is $66,075 with destination but before taxes. Even after you add local sales tax, that’s still quite a difference.
Advertisement
Then there are the individual option prices, some of which benefit European buyers. Ford allows European buyers to specify any color at no additional charge, while the U.S. website charges $495 to $995 for six out of nine colors offered. The front Recaro sports seats cost 1,800 Euros, or almost $2,100 additional in Europe, but must be ordered with the GT Performance package in the U.S., which is already standard on the Euro model, boosting the price up by around $8,000. Simply put, there are some tradeoffs.
Advertisement
Right-hand drive manufacturing
In addition to the normal left-hand drive versions of the European Mustang that are made for the majority of European countries that drive on the right side of the road, there are also European Mustangs produced for those countries that drive on the left side of the road, which includes the United Kingdom, Ireland, the Isle of Man, Cyprus, and Malta.
While Ford did a decent job of moving the steering wheel and the pedals to the right side of the Mustang, it came up short as far as the center console goes. Just as it had done with the previous generation of Mustang, Ford continues to use the console designed for the left-hand drive version. While this is most likely a cost-saving move on Ford’s part, it leaves the Mustang’s parking brake on the passenger’s side of the console with the right-hand drive setup. This makes things complicated when the driver wants to use the parking brake’s added functionality as a drift brake.
The Mustang’s drift brake, intended for track use only, can be activated with a few simple steps. After first pressing either the Mustang Pony button on the dash or choosing Features on the car’s touchscreen, the driver can then select My Mustang, followed by Track Apps and then Drift Brake. This enables the drift brake feature, which can either brake or fully lock up the rear wheels only, letting the driver drift the car sideways.
Advertisement
Methodology
For this analysis of the major differences between the Ford Mustang made for the European market and the Mustang made for the U.S. market, we reviewed a variety of materials put out by Ford itself on this topic. The manufacturer materials were supplemented by other publications, with data including performance differences as a result of the different markets’ emission regulations, and the compromises made during the car’s conversion to a right-hand drive version.
Pricing information was converted from Euros into dollars, based on the exchange rate at the time this article was written. The prices in the article also include the value-added tax for the German market, while the U.S. prices include destination charges, but do not include any local sales taxes that may apply.
[Les] likes lasing lasers, and who doesn’t? [Les] likes larger lasers than lots of folks, with his current project being an Nd:YAG (that’s Neodymium:Yttrium Aluminum Garnet) flash pumped laser intended for tattoo removal. Like most of its ilk, the YAG crystal at the heart of that device is a rosy purple color, so when [Les] spotted a Yellow YAG with different doping promising powerful pulses, he purchased it promptly.
Specifically, the retailer was claiming a 30-50% efficiency increase for this yellow rod, thanks to cerium doping. It’s still considered an Nd:YAG, though you can label it as an Nd:Ce:YAG for clarity. The efficiency gain comes from the cerium atom taking unused energy from the flashbulb pulse — which is much broader-wavelength than the thin absorption line of the Nd ions in the rod — and giving that energy to the Nd atoms that do the lasing via fluorescence. He doesn’t try it, but reports on a paper showing these crystals can actually lase with reasonable efficiency from sunlight alone, which we’d love to see. Send us a tip if you try.
His original Nd:YAG rod produced 72.8 mJ pulses, while in the same setup with the yellow laser is peaking at 153 mJ, more than double the original output. That’s even better than the 30-50% [Les] expected, but he reckons it is because the old YAG is, well, old. The coatings break down over time, and UV light from the flashbulbs degrades the crystals too. That’s another benefit of tossing cerium in there, as apparently it acts as sunscreen for your laser rod. It lasts longer and works better, making it a no-brainer of an upgrade.
Advertisement
We’ve seen [Les]’s laser-based hacking before, like this diode-laser PSU and we’re always glad to take a look with our remaining eye. We also featured his tattoo removal laser back when he started working on it, along with less-lasery projects like his crystal-growing rig.
Unless you have been living under a rock, you already know that artificial intelligence is everywhere. What is less obvious is that the infrastructure feeding the AI boom is now competing with the televisions, AV receivers, streamers, gaming consoles, wireless headphones, smartphones, and other electronics inside your home.
AI data centers require enormous quantities of processors, high-bandwidth memory, DRAM, NAND storage, networking hardware, and power-management components. Chipmakers are directing more production capacity toward these lucrative commercial customers, tightening supplies of conventional memory and other components used throughout the consumer-electronics industry. The problem is no longer confined to expensive AI GPUs or hyperscale server farms.
The impact is already being felt. Memory prices have risen sharply throughout 2026, manufacturers are warning about higher component costs, and Qualcomm has indicated that price increases will be necessary as AI infrastructure demand strains supplies of memory, wafers, packaging, and testing capacity. TrendForce says the DRAM market will remain extremely tight during the third quarter of 2026, with contract prices expected to rise another 13 to 18 percent.
For consumers, that could mean fewer discounts, delayed product launches, longer delivery times, reduced specifications, and higher prices for everything from smart TVs and projectors to network streamers, soundbars, and AV receivers. Some manufacturers may absorb the added expense temporarily, but nobody should expect them to keep doing that indefinitely.
Advertisement
AI may live in the cloud, but consumers are increasingly being asked to pick up the tab at the checkout counter.
Related Reading:
The AI Shortage Rundown
Chip Making Priorities: Microsoft, Google, and Amazon are redirecting wafer allocations and RAM supply toward enterprise AI hardware, especially for AI data center applications. Samsung, SK Hynix, and Micron are prioritizing high-margin AI-related memory and High Bandwidth Memory (HBM) over conventional DRAM and other chips used in many mainstream consumer products. The result could be a “RAMageddon” for mainstream memory chips.
The Cloud: Cloud providers are panic-buying and locking in long-term supply agreements with makers, further widening the global supply gap. With a large portion of content, program access, and storage utilizing the cloud, any chip shortage needed to support cloud services would stifle access speed and limit storage capacity.
Higher Prices Are Already Here
Apple has already raised prices on several MacBook and iPad models after conceding that it could no longer absorb soaring memory and storage costs. The 512GB MacBook Air increased from $1,099 to $1,299, the 1TB MacBook Pro jumped from $1,699 to $1,999, and the 128GB iPad Air rose from $599 to $749. More relevant to the home entertainment market, Apple also increased prices on both HomePod models and the Apple TV streaming player.
The warning signs are already visible in the audio industry. FiiO raised U.S. prices on four products beginning April 1, including the JM21 digital audio player at $259.99, the M21 at $369.99, and the M33 at $699.99. FiiO specifically blamed sharply rising memory chip costs that had exceeded its ability to absorb them and warned that additional pricing adjustments could follow if upstream component costs continue to increase.
Advertisement
Shanling says the AI-driven component squeeze now extends beyond CPUs and RAM to memory, circuit boards, copper, aluminum, and other materials. Prices on new and existing products will rise beginning in August, while some lower-margin models may be discontinued entirely.
That matters because modern audio and video components are computers wearing more attractive clothes. Smart TVs, network streamers, AV receivers, wireless speakers, soundbars, and multiroom audio systems rely on processors, RAM, flash storage, networking chipsets, and power management components to run their operating systems, streaming apps, room correction, video processing, voice control, wireless connectivity, and increasingly, locally processed AI features.
Advertisement. Scroll to continue reading.
Roku has increased prices across its streaming hardware lineup, reportedly blaming the global shortage of RAM and other components. The Roku Streaming Stick increased from $29.99 to $39.99, the Streaming Stick Plus rose from $39.99 to $59.99, and the Streaming Stick 4K jumped from $49.99 to $79.99. The Roku Ultra climbed from $99.99 to $149.99—a 50 percent increase on a product that directly competes with Apple TV, Google TV, and other network streaming platforms.
The gaming industry is being hit even harder. Effective August 1, 2026, Microsoft raised Xbox console prices worldwide by $100 for models with 512GB of storage and $150 for 1TB versions. The company is also discontinuing its 2TB model. Microsoft said console storage and memory costs had increased by more than 2.5 times and warned that they could double again by the fall of 2027.
Advertisement
That pushes the 512GB Xbox Series S to $499 and the 1TB version to $599, while the Xbox Series X Digital Edition rises to $749 and the standard 1TB Series X reaches $799. These are six-year-old consoles moving farther away from their original launch prices rather than becoming cheaper with age—the opposite of how the console business traditionally works.
Sony raised PlayStation 5 prices on April 2 after surging memory costs placed additional pressure on its hardware business. The standard PS5 increased from $549.99 to $649.99, the Digital Edition rose to $599.99, and the PS5 Pro jumped from $749.99 to $899.99. Even the PlayStation Portal increased from $199.99 to $249.99.
The TV industry is unlikely to escape the fallout. Premium models may have enough margin to absorb some of the added cost temporarily, but mainstream and entry-level televisions are sold on much thinner margins. If component prices keep rising, manufacturers will have limited options: raise retail prices, reduce discounts, trim specifications, delay launches, or cut production.
China to the Rescue or Taking Control?
China-based semiconductor manufacturers are rapidly expanding production as the AI boom strains global supplies of processors, memory, storage, and other critical components. That additional capacity could eventually reduce shortages and help consumer-electronics manufacturers contain rising costs, but describing China as merely coming to the rescue misses the much larger story.
Advertisement
China is no longer simply chasing the United States in artificial intelligence. According to Stanford’s 2026 AI Index, the performance gap between leading American and Chinese AI models has effectively closed, with models from the two countries trading the lead since early 2025. China also leads in AI research publications, citations, total patent output, and industrial robot installations.
Chinese companies including DeepSeek, Moonshot AI, Alibaba, and Z.ai are also producing increasingly capable models that are often cheaper and more openly available than their American competitors. That combination of competitive performance, lower operating costs, and open access is helping Chinese AI platforms gain users well beyond China, including inside the United States.
The United States still holds an advantage in the most powerful AI accelerators. Nvidia’s H200 remains more capable than Huawei’s Ascend 950PR, and China continues to face constraints involving advanced fabrication equipment and high-end chip production capacity. But those restrictions have not stopped China’s progress. They have accelerated Beijing’s drive to replace American processors, software, and manufacturing equipment with domestic alternatives.
Chinese-made processors are projected to account for roughly half of China’s AI-chip market during 2026, while American semiconductor companies have effectively lost their once-dominant position inside the country. China is not merely adding production capacity; it is constructing a competing AI ecosystem that could challenge American control over models, hardware, standards, and global technology infrastructure.
Advertisement
That creates a difficult political and economic dilemma. Greater Chinese production could ease shortages, reduce component costs, and improve product availability. At the same time, becoming dependent on Chinese memory, processors, and manufacturing capacity would give Beijing greater leverage over supply chains used by television, audio, automotive, smartphone, and computer manufacturers.
The real question is therefore not whether China can rescue the semiconductor market. It is whether the United States and its allies are comfortable allowing their largest technological rival to become the supplier that the rest of the world cannot afford to live without.
Advertisement. Scroll to continue reading.
Note: The following video is from China Central Television.
Advertisement
The Bottom Line
Back in 2021, the global chip shortage was driven primarily by pandemic-related factory shutdowns, supply-chain disruptions, and a sudden surge in demand for computers, gaming consoles, automobiles, and other electronics. AI was not yet a significant factor.
Just as those pressures began to ease, the rapid expansion of artificial intelligence created a new and potentially longer-lasting problem. AI now touches everything from automobiles and consumer electronics to massive data centers that consume enormous amounts of electricity and water. To meet that demand, chipmakers are prioritizing high-margin AI processors, advanced memory, and data-center components while devoting less capacity to conventional DRAM and other chips used in mainstream consumer products.
Until AI-chip demand begins to level off and production of memory and other essential components stabilizes, shortages and higher costs are likely to continue. Some industry forecasts suggest that the pressure may persist through at least 2028.
Advertisement
The companies building AI infrastructure will continue spending because they can afford to. Consumer electronics manufacturers will pass along at least some of their rising costs because they have little choice. The consumer, stuck paying more for TVs, computers, game consoles, streamers, audio components, and smartphones that may offer fewer upgrades for the money, is the one who ultimately loses.
N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers.
The company on Sunday released hotfix 2026.3.1.7 to address the security issue, which affects all versions of N-central before 2026.3.
On August 1st, the vendor disclosed that it detected active exploitation and launched an investigation that uncovered additional security concerns affecting all versions of N-central, its flagship Remote Monitoring and Management (RMM) platform.
In an update the next day, the company announced the hotfix and strongly recommended all customers to upgrade immediately to the new release.
Hosted deployments already received the update, while customers of on-premises instances need to install it manually.
Advertisement
N-central is a remote monitoring and management (RMM) platform used by managed service providers (MSPs) and corporate IT departments to manage large clusters of multi-OS systems and network devices.
Because of this, compromising these servers allows threat actors to extend the attack beyond N-able’s direct customers.
The product was also targeted last year, in zero-day attacks that prompted CISA to issue an urgent alert.
CVE-2026-18577 is the result of an incomplete patch for CVE-2026-18576, a vulnerability described as an “authentication bypass using an alternate path or channel, which affected all N-central versions through 2026.1. Both vulnerabilities could be exploited for administrative account takeover.
N-able has not shared any technical details about the security issue or provided information about the number of customers targeted or compromised through CVE-2026-18577.
The vendor provided indicators of compromise on the hotfix download page, including four specific IP addresses, a registered service named ‘Cloudflared,’ and ‘svchost.exe’ in the users’ documents folder.
If any of these are found, customers are advised to contact N-able support immediately and engage their own security team.
Advertisement
It should be noted that attackers frequently abuse Cloudflared, the legitimate tunneling utility from Cloudflare, to create outbound tunnels that expose compromised machines or provide remote access without opening inbound firewall ports.
The vendor also says that agents do not need immediate updates to mitigate CVE-2026-18577, but the action is recommended to get the latest fixes and features.
N-able’s status update “strongly recommends” that customers remain vigilant and monitor their environments closely, while the company also promised to share more updates as quickly as possible.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Apple says its lower-cost MacBook Neo is beginning to displace Windows laptops and Chromebooks in K-12 schools, with several districts purchasing thousands of units. According to the company’s latest earnings call, nearly half of the large MacBook Neo purchases made by U.S. educational institutions last quarter reportedly replaced competing platforms. 9to5Mac reports: Apple’s commentary highlighted some large district deployments moving to Neo Pinellas County Schools, one of the largest districts in Florida, which is moving its 25k students off Windows and onto MacBook Neo across its 18 high schools. In Washington, Peninsula School District 401 moved over its 8,000 students from Chromebooks to MacBook Neo. Midwest City-Del City School District in Oklahoma purchased more than 6,000 MacBook Neos to become an all-Apple district for students.
A Russia-linked group tracked as Midnight Blizzard has compromised hotel and conference Wi-Fi portals worldwide, redirecting guests to phishing pages and fake software updates that steal credentials, session tokens, and other sensitive data. Microsoft says the campaign, dubbed CaptiveCrunch, “targets traveling employees generally rather than a particular sector,” reports iTNews. From the report: Midnight Blizzard, tracked internally by Microsoft under its earlier codename NOBELIUM, is attributed by the US and UK governments to Russia’s SVR (Sluzhba Vneshney Razvedki) foreign intelligence service. Microsoft’s technical analysis said compromises occurred in “several countries” without naming them, and it did not give a total number of affected venues, organisations or individuals.
A related investigation published earlier in July by security firm ReliaQuest, and which Microsoft cited in its report, found compromised captive portal gateways across multiple United States cities as well as in India and Saudi Arabia, mostly at hotels. ReliaQuest said the traffic it observed came from organizations across financial services, professional services, legal, health care, energy and retail, suggesting the campaign targets traveling employees generally rather than a particular sector.
[…] Where attackers gained a foothold, Microsoft said they deployed two main tools: CornFlake, a Windows remote access trojan (RAT) written in Go capable of keylogging, screenshot and webcam capture, audio surveillance and credential and session token theft. They would also drop ChocoShell, an in-memory PowerShell infostealer targeting browser cookies, saved passwords, Microsoft 365 single sign-on (SSO) tokens and wi-fi credentials. Microsoft also said it has seen indications the attackers might be targeting Android devices with similar prompts urging victims to download and install an APK file.
Chetan Jaiswal of Quinnipiac University explains what a side-channel attack is and how it impacts modern cybersecurity.
When people hear the word cyberattack, they usually imagine someone guessing a password, planting malware, stealing a computer, hacking an organisation’s network or exploiting a flaw in software. A side-channel attack works differently. It looks for clues a computer gives away while doing ordinary work.
A simple analogy is a locked safe. A thief may not know the combination and may not be able to break the lock. But if the thief can listen closely as the dial turns, small clicks or churns or pauses might reveal something about what is happening inside. The safe is not meant to share that information, but its physical behaviour still leaks clues.
Modern computers have their own versions of such clues. For example, each computer might take different amounts of time to complete different tasks or may use different amounts of electricity. The hardware – processors, memory, graphics cards and storage drives – may leave tiny patterns as they work.
Advertisement
I’m a computer scientist who studies security and privacy. I define a side-channel attack as an attempt to observe these indirect clues and use them to infer something private.
This is what makes these side-channel attacks unusual. The weakness comes from the way a machine performs its work. The attacker does not steal a password directly or break into the computer, but instead studies the traces left behind by the machine while it is operating.
History of leaking
The idea is not new. In 1985, Dutch researcher Wim van Eck showed that electromagnetic signals from video display units could be captured and decoded, raising the possibility of eavesdropping on what a screen displayed. The screen was not intentionally broadcasting its contents. It was leaking signals as a side effect of operating.
In the 1990s, side-channel attacks became especially important in cryptography, the science of protecting information. In 1996, cryptography researcher Paul Kocher showed that carefully measuring how long certain operations took could reveal private information from systems using common cryptographic methods. A few years later, Kocher and fellow cryptographers Joshua Jaffe and Benjamin Jun showed that measuring power consumption could help recover secret keys from tamper-resistant devices such as smart cards.
Advertisement
These discoveries changed how engineers thought about security. It was not enough to ask whether an encryption algorithm was mathematically secure. It was even more important to ask whether the device running the algorithm leaked hints through timing, power, sounds or other physical behaviour.
There are several common types of side channels:
A timing attack looks for small differences in how long operations take.
In one striking example, researchers showed that the faint noise produced by a laptop during certain cryptographic operations could be used, under experimental conditions, to extract a 4,096-bit secret cryptographic key.
The examples that brought side-channel attacks into wider public discussion were processor attacks. Modern computer processors such as CPUs are extremely fast because they predict what a program is likely to do next. This technique, known as speculative execution, helps computers run more efficiently. But in 2018, cybersecurity researchers discovered two vulnerabilities, dubbed Meltdown and Spectre, in the technique. They showed that these predictions could leave behind measurable traces. A malicious program could use those traces to learn information that should have been protected from it.
Meltdown and Spectre mattered because they challenged one of the basic premises of modern computing: that different programs running on the same machine should be kept separate. They also showed that performance features built deep into computer chips could have security consequences.
Advertisement
New tech, new side channels
Since then, researchers have continued to find new side-channel attacks in modern hardware. One such side-channel attack revealed in 2022, called Hertzbleed, showed that changes in processor frequency – normally used to save power and manage performance – could become a timing signal that could, in some cases, expose remote servers’ cryptographic secrets.
Another side-channel attack, dubbed Downfall and revealed in 2023, affected certain Intel processors. It showed how a feature called Gather could leak older pieces of data left inside the processor after earlier work. Zenbleed, also revealed in 2023, affected AMD Zen 2 processors and could allow sensitive information from another process to appear where it should not.
Side-channel research has also moved beyond CPUs. GPU.zip showed that graphics processors, or GPUs, can sometimes leak visual clues through the way they handle image data behind the scenes, including the pixels from another webpage in the Google Chrome browser. GoFetch, published in 2024, showed that a hardware feature in many Apple processors designed to predict future memory needs could undermine protections in cryptographic software and help extract secret keys.
The latest attack, called FROST, short for “fingerprinting remotely using OPFS based SSD timing,” involves solid-state drives, or SSDs. These drives are an extremely common form of fast storage on almost all modern computers. FROST shows that a malicious website can use a browser storage feature called the origin private file system to create and access files inside a protected area, called sandbox, that the browser sets aside for that website, then measure tiny delays in SSD activity.
Advertisement
The intuition is simple. If several programs are using the same storage device, they can slow one another down slightly, like cars sharing the same road. By measuring those delays in a browser, the FROST researchers showed that a website could, under specific conditions, infer information about other activity on the same computer, such as websites visited or applications used.
Lessons more than losses
So, how often are side-channel attacks used? The honest answer is that while they can be damaging, they are not the everyday cyberattack most people encounter. Most real-world cybercrime still relies on easier and cheaper methods, such as exploiting software vulnerabilities, stealing credentials, phishing, malware and ransomware. Verizon’s 2026 Data Breach Investigations Report, for example, highlights software vulnerabilities and ransomware as major sources of breaches, not side-channel attacks as a routine entry point.
This does not make side-channel attacks unimportant. Many are discovered by researchers before they are seen in widespread criminal use. But they matter because they expose weaknesses in the assumptions behind modern computing. They influence chip design, browser security, cloud computing, cryptographic libraries and the way engineers think about privacy.
Side-channel attacks are a reminder that computers do not have to intentionally reveal secrets to leak them. Sometimes the smallest clues left behind while they work can say more than anyone expected.
Chetan Jaiswal is an associate prof of Computer Science at Quinnipiac University, Connecticut. His research interest lies in databases, security and privacy, cloud computing, computer vision, artificial intelligence and machine learning. He has prepared and taught several undergraduate and graduate courses on cybersecurity, database, operating systems, cryptography, information security, computer networks and languages such as Python, Scala, C, C++ and Java.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
You must be logged in to post a comment Login