Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tech
Florida confirms DMV database breached via stolen police account
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach after the ShinyHunters extortion gang claimed to have compromised the system.
The disclosure comes after the ShinyHunters extortion group claimed it breached the DAVID database and stole more than 200,000 driver records.
“On September 4, 2026, FLHSMV learned of a data breach conducted by an international cybercriminal organization,” the agency said in a statement posted to X.
“The data breach was quickly mitigated and no further breach has occurred or is ongoing.”
FLHSMV says its investigation determined that the attacker used compromised credentials belonging to a single Plant City Police Department user that had been improperly stored on the employee’s personal electronic device.
The agency says it has notified the Florida Office of the Attorney General of the breach and is working with the Florida Digital Service and Florida Department of Law Enforcement as part of its response.
“As this is an ongoing criminal investigation, further information will be released at an appropriate time in the future,” FLHSMV said.
ShinyHunters claimed a different access method
FLHSMV’s findings are different from how ShinyHunters previously claimed to have gained access to the database.
The hackers claimed they exploited a password reset flaw to gain access to multiple DAVID accounts, including accounts belonging to DMV employees and an FBI agent.
ShinyHunters said it then began iterating through DAVID record IDs and downloading associated HTML pages and images beginning on September 3.
As proof of the breach, the threat actors shared a screenshot of a DAVID record belonging to Jeffrey Epstein that contained sensitive personal and vehicle information.
ShinyHunters later told BleepingComputer that it had lost access to the system and believed the flaw was being patched.
FLHSMV has not disclosed how many records were accessed or stolen during the breach and has not confirmed ShinyHunters’ claim that more than 200,000 records were taken.
Tech
Parents Are Bringing AI to the IEP Meeting. How Should Teachers Respond?
EDITOR’S NOTE: This article has been updated to clarify language about educator response.
The individualized education program (IEP) process generates a big stack of papers, full of terminology that parents may not understand. In response, some parents have begun using artificial intelligence to better understand IEPs and prepare for teacher meetings. Kimberly Morris, who taught pre-K through the 2025-26 school year, saw this firsthand.
Morris would set school goals in the IEP, “and some parents would then utilize AI as a way to create a home goal,” she says.
Morris, who is now a curriculum and instruction specialist supporting early childhood learning at Unlocking Children’s Potential of Central Florida, didn’t mind that parents were using AI to align home efforts with school goals. But as the conversation around AI use transparency grows in classrooms, some wonder whether parents should disclose if they used AI to prepare for an IEP meeting.
How Parents Use AI
Concerned parents might use AI in several ways during the IEP process, says Elizabeth Laird, director of equity and civic technology at the Center for Democracy and Technology. “A parent might turn to AI to learn more about the process and what their rights are, what their child’s rights are,” she notes.
Laird thinks that’s not necessarily a bad thing. “AI can play a role in democratizing access to information about the process itself, as well as being a starting point for thinking about what types of accommodations parents may want to ask about,” she reasons.
For many parents, “just because you’re a parent of a child with a disability doesn’t mean you automatically understand all of these things related to your child’s IEP,” says Olivia Coleman, an assistant professor in the School of Teacher Education at theUniversity of Central Florida. “They’re using it to translate the jargon, any acronyms. It’s helping them to draft questions.”
Parents are putting their child’s IEP into AI models “and then having it put it into plain language, like, ’What is this thing and what does it mean?’” says Coleman, who is also a co-principal investigator at the Center for Innovation, Design, and Digital Learning.
Morris, the curriculum and instruction specialist, sees an upside to parents using AI in IEP meetings. “They can become more of a team member alongside the teacher, occupational therapist, physical therapist and speech therapist,” she says.
But there are risks. For example, when a parent’s AI-generated contribution to the meeting sprawls to 20 or 30 pages, “it’s going to take a teacher the majority of their day just to read through a request,” says Phyllis Wolfram, executive director of the Council of Administrators of Special Education. “It will slow down the process.”
“AI is not an IEP expert,” Laird adds, noting that the AI’s outputs can be inaccurate. With that in mind, she counsels teachers and parents to reflect together on the AI’s findings. A key aspect of the IEP process, she notes, “is its emphasis on bringing different subject matters together to collaborate, to identify what is the best path forward for an individual child.”
Here’s where federal law enters the picture. The Family Educational Rights and Privacy Act (FERPA) provides privacy protections for parents regarding their children’s education while the Individuals with Disabilities Education Act (IDEA) offers additional privacy protections for students receiving special education.
With FERPA and IDEA as the legal backdrop, parents should not put identifiable personal data like medical diagnoses and legal documents into AI. The tool could potentially train on that data, which risks that information becoming publicly visible. The data also may be at risk of being exposed in a security breach, if the AI provider gets hacked.
Should Parents Disclose?
Some argue that parents need to be candid about their AI use for that collaboration to be effective. Some parents were upfront about AI when meeting with Morris. “When I would report on a goal, they also had input and would say, ‘Hey, I created something at home and I used AI for that.’ I thought that was really cool, that parents stepped out of their own mindset to think about how to incorporate those goals at home,” she says.
Even if parents don’t disclose, teachers and others could spot AI-generated text. “Right now, the information that parents are providing to school districts regarding their IEP meetings is much lengthier, and it carries some legal jargon that doesn’t typically come from parents,” Wolfram says. “Most educators will know when they’ve received something written by AI.”
If teachers do want parents to disclose AI usage, they can make a strong case for that, Laird believes. After all, in schools across the country, “parents are demanding from their school to know whether and how AI is being used,” she says.
The key is to avoid being defensive if AI is being used in the IEP meeting, says Coleman. “We don’t want to pit anyone in the IEP team against each other. We want to work together.” For the IEP process to meet its intent, she adds, participants need to trust each other, and “transparency builds trust.”
Parents might consider using AI for a number of reasons as they prep for an IEP meeting:
-
To summarize IEP documents
-
To verify their rights against local state guidelines
-
To translate unfamiliar jargon or bridge a language gap
-
To formulate proposed goals
-
To generate questions to help guide the process
In all these cases, educators say they’d prefer parents disclose their AI use, so that everyone can align in what is supposed to be a collaborative process. Parents should also double-check with local and state rules to make sure they are allowed to use AI with their IEPs.
Crafting a Response
Morris counsels teachers to assume that some parents will use AI. “I have created the IEP and I know my role and goals as well as those for the student and parents,” she says. How the family responds is up to them, “and I’ve always kept an open relationship with the parents that I have worked with,” she adds.
In the spirit of collaboration, teachers can model appropriate transparency and disclosure etiquette with parents. “We can’t make disclosure mandatory, but we can practice it and set an example,” Coleman argues. “Teachers can say up front, ‘We’re not against AI use, but we’d really appreciate you also being transparent, and this is why.’ We want to make sure we’re all on the same page,” she says.
With trust in place, Wolfram notes, the teacher can talk openly about the AI outputs a parent brings to a meeting. “The educator can say, ‘Let’s talk about those recommendations. Do you see those as different from what we’re already doing? And if so, let’s talk about why you think that’s needed,’” she says.
The AI discussion requires some finesse, but Morris thinks it’s worth the effort. “I want parents to be advocates, and to understand exactly what is being told to them on their child’s IEP,” she says.
Tech
Passkey-themed phishing attacks lead to Microsoft 365 data theft
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services.
The activity has been observed since May 2026 and begins with the attackers researching targeted organizations and employees before calling or messaging victims while impersonating corporate IT help desks.
The attackers tell employees that they must urgently update a passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration to avoid losing access to corporate systems.
Victims are then directed to phishing sites designed to resemble legitimate Microsoft login pages, with links sometimes sent through SMS messages to employees’ personal phones.
Microsoft says that while the lures frequently revolve around passkeys, the attackers are not attempting to enroll a passkey.
Instead, the passkey lures are used to trick targeted employees into signing in to adversary-in-the-middle (AiTM) phishing sites or using device-code authentication flows.
AiTM attacks allow the threat actors to capture credentials and session tokens. Device code phishing tricks victims into authorizing access to their account via an attacker-controlled client using Microsoft’s legitimate authentication pages.
Microsoft says the attackers conduct extensive research before targeting employees.
“The actor appears to invest heavily in pre-attack research, likely gathering information about employees and organizational structure from public sources such as social networking and professional profiling platforms,” explains Microsoft.
The threat actors also register phishing domains that combine company names with words related to passkeys, SSO, key synchronization, account setup, and identity verification.
Some examples seen by Microsoft include: passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, oktasession[.]com, keysyncos[.]com, and oskeysync[.]com.
The attackers commonly place the victim company’s name in a subdomain, such as company-name.secure-passkey[.]com, to make the phishing portal appear more convincing.
Microsoft attributes the initial-access activity to multiple threat actors operating in the same extortion ecosystem, including groups it tracks as Storm-3121 and Storm-3032.
Storm-3121 is associated with ShinyHunters and Falcon extortion, while Storm-3032 is believed to be tied to BlackFile extortion group members that now work under the Helix name.
This activity overlaps with attacks previously documented by Google Threat Intelligence under the UNC6671 threat cluster.
Google previously reported that UNC6671 uses phone-based social engineering and passkey-themed phishing infrastructure to compromise corporate identities before accessing enterprise cloud environments.
Google has also linked UNC6671 activity to the same extortion gangs, including BlackFile, Helix, Falcon, Pink, and Redact.
Mapping the Microsoft cloud after compromise
Microsoft’s new research gives a closer look at what happens inside Microsoft cloud environments after an account is compromised.
In one investigated attack, Microsoft observed a suspicious sign-in from an unmanaged device to a Microsoft 365 service identified in Entra logs as “OfficeHome.”
OfficeHome is associated with the Office 365 portal’s shared infrastructure, including Office applications accessed through a browser.
After completing MFA, Microsoft says the attacker established a valid session and began checking what resources the compromised account could access.
Within minutes, the session was used to access My Apps to see what applications are assigned to the account, My Profile for organizational information, Microsoft Approval Management, account-management interfaces, and My Sign-Ins.
The attacker then accessed SharePoint Online, Outlook Web, Microsoft 365 collaboration and search services, an internal business application, and authentication flows associated with virtual desktops.
Microsoft says the session remained active for approximately one hour while the attacker listed sensitive files and internal applications.
In another attack, the passkey social engineering attacks led to device-code phishing, where the victim was convinced to enter a supplied code into Microsoft’s legitimate authentication page.

This issues an authentication token to the attacker-controlled OAuth application, allowing the threat actor to access the victim’s account without completing another MFA challenge.
The attacker now has access to all of the user’s resources and connected SSO applications, whether they be Microsoft 365, Salesforce, Google Workspace, Dropbox, Adobe, SAP, Slack, Zendesk, Atlassian, and many others.
In a third attack, the threat actor used previously compromised credentials for an account where it is believed an authenticator application had been registered days earlier.
Microsoft says the threat actors then performed reconnaissance using an automated Node.js system and Microsoft Graph.
After gaining access, the attackers often gain persistence by adding an MFA method they control.
Microsoft says the attackers register new phone numbers, authenticator applications, and software-based one-time password tokens with compromised identities.
This allows the threat actor to satisfy future MFA challenges without the victim’s help, although Microsoft notes that the persistence does not survive a complete credential and session reset.
The attackers then use Microsoft Graph to enumerate the victim’s cloud environment.
Microsoft saw Graph requests that enumerate:
- Organizations, licenses, and enabled services
- Users, groups, and group membership
- Directory roles and privileged accounts
- Registered authentication methods
- Applications and service principals
- OAuth permissions and application role assignments
- SharePoint sites, document libraries, folders, and files
- OneDrive resources
- Mail folders, messages, and attachments
Microsoft says Graph requests such as /users, /groups, or /sites are common in enterprise environments, so they may not raise alarms.
However, the activity becomes more suspicious when the same account, application, or access token rapidly moves across different resources, checks privileges and authentication settings, and then begins accessing email, attachments, files, or documents.
After reconnaissance, the attackers move into cloud data collection from Microsoft 365.
“Microsoft observed high-volume access and download activity targeting Microsoft SharePoint Online and Microsoft OneDrive for Business, with some intrusions extending into Microsoft Exchange Online through REST API-based access to email content,” explained Microsoft.
“Across SharePoint and OneDrive, the activity generated significant volumes of FileAccessed and FileDownloaded events, indicating systematic retrieval of cloud-hosted documents and organizational data.”
Microsoft says the activity appears automated, with connections using the python-httpx user agent during SharePoint and OneDrive access exfiltration.
The attackers also appear to avoid rapid “smash-and-grab” exfiltration to avoid detection.
Microsoft says the data theft instead lasts from a few hours to multiple days, with threat actors accessing fewer than 1,000 files or emails in a single hour to blend in with legitimate traffic.
Microsoft recommends looking for unusual sign-ins followed by new MFA registrations, Microsoft Graph reconnaissance, and suspicious access to SharePoint, OneDrive, or Exchange.
If an account is compromised, administrators should revoke active sessions and tokens, reset credentials, remove any authentication methods or mailbox rules added by the attackers, and require the user to re-register their authentication methods.
Microsoft also recommends using phishing-resistant MFA, limiting sensitive cloud resources to managed devices, and disabling device-code authentication when it is not needed.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tech
Mars astronauts could live in houses made of yeast and jello, say scientists
offbeat
Low-energy 3D printing could turn Martian dirt into sturdy structures
If humans ever make it to Mars – and that’s still a big IF – they will need to build shelters there. And they could build those shelters out of yeast and gelatin, if a method described by Hong Kong-based researchers makes it out of the lab.
A paper published on Thursday by a group of researchers from The Hong Kong University of Science and Technology and The Hong Kong Polytechnic University describes a method for building structures on Mars that doesn’t rely on energy-intensive heating to turn regolith into building blocks. The team instead turned to bioengineered yeast and gelatin mixed with simulated Mars dirt to 3D print structures.
“My inspiration came from freeze-dried fruits that become harder,” senior author Jishen Qiu, an associate professor at The Hong Kong University of Science and Technology, told Cell Press, the publisher of the paper.
Qiu’s idea is a relatively simple one once you break it down: Take one part yeast bioengineered to produce adhesive proteins that bind the components. Combine with artificial gelatin hydrosol to serve as a growth medium for the yeast. Add plain old Martian dirt, and extrude the material through a 3D-printing nozzle.
If everything works as intended, the recipe should create a foamy substance that, when exposed to the dry, cold Martian atmosphere, essentially freeze-dries. As the ice sublimates into vapor, you should be left with a light, porous, but incredibly strong material. According to the researchers, that’s exactly what they got.
“The hardened material achieved mean compressive and flexural strengths of approximately 12 and 6 MPa, respectively,” the team said. For reference, that’s roughly the same strength as low-grade terrestrial concrete. As an added perk, the team noted, the energy demand is one to two orders of magnitude lower than that of heat-processing Martian (or lunar, for that matter) dirt into building material.
According to the paper, the material can be broken down and reused too – provided at least a single yeast cell survives the process, and the cold, barren wasteland of Mars, that is. The team isn’t sure that would necessarily be the case, but nothing is stopping Martian yeast masters from keeping a supply on hand for future projects just in case.
The structures they built and tested in their simulated Martian conditions were tiny little beehive-shaped things, measuring just 45 mm tall (a little under 2 inches).
“Is there any physical law or fundamental mechanism that prevents us from doing this?” Qiu asks of his work. “I can’t see any at this point in time.”
Qiu said his team is confident that it can scale the tech, but that’s not the only thing that needs to be tested more fully. Per the paper, testing the ability of the yeast-gelatin building foam to retain the pressure necessary to keep humans from succumbing to the Martian elements was outside the scope of the research.
“A practical lunar or Martian habitat must integrate pressure retention, gas tightness, mechanical support, thermal regulation, radiation shielding, dust protection, repairability, and resource recycling,” the paper notes. “These requirements will likely require hybrid architectures” that include both the yeast foam and more traditional structures.
Either way, avoiding the need to heat Martian dirt could reduce the energy and heavy equipment required to build structures there. That’ll be important if we ever actually want to get to Mars. But if we get there, at least we’ll have yeast. ®
Tech
Samsung S90H OLED TV Review: A Mid-range OLED for the Everyman
The Samsung S90H is the mid-range series in Samsung’s 2026 OLED TV lineup, slotting in between the budget Samsung S85H series and flagship Samsung S95H series. Samsung opted to pack every possible feature into the S95H, including the company’s latest-generation QD-OLED display panel with a Glare Free screen and a distinctive “FloatLayer” metal frame. Between the fancy frame and support for the Samsung Art Store (the S95H is the first OLED TV from the company to offer that feature), Samsung has positioned the S95H as a high-performance Art TV, a category the company pioneered with its The Frame series models.
The Samsung S90H, in contrast, is a more affordable TV option for viewers who simply want to tap OLED’s impressive picture quality for movie-watching and gaming and don’t mind having their TV display a blank, black screen instead of a Kandinsky painting when not in use. To that end, the Samsung Art Store isn’t supported by S90H series TVs, which also have a more conventional, bezel-less “Laser Slim” design.

Related Reviews:
What is it?
The Samsung S90H is an OLED TV sold in screen sizes ranging from 42 to 83 inches. Unlike the S95H series, S90H TVs use a conventional W-OLED panel sourced from LG Display. Launch prices for the S90H series start at $1,399.99 and top out at $5,299.99 for the 83-inch model. Prices for S90H TVs have dropped significantly since launch, with the 55-inch model that Samsung sent me to review now selling for $1,399.99 (original price: $1,999.99).
It may lack the S95H’s QD-OLED panel and Art Store support, but the S90H series features the same Glare Free matte screen found on Samsung’s flagship OLED and Mini-LED TVs, including the Samsung R95H Micro RGB TV. This effectively diffuses reflections when watching in bright-room lighting conditions and, unlike earlier versions of the Glare Free screen, does so without overly elevating black levels in darker images.
The S90H uses the same NQ4 AI Gen3 Processor found in the flagship S95H series. This delivers a range of AI enhancements for picture and sound, such as AI Motion Enhancer Pro, which eliminates the “flickering ball” effect in sports, and 4K AI Upscaling Pro. There’s also an Auto HDR Remastering feature that upscales standard dynamic range programs to HDR, along with AI Customization Mode, which detects the type of content being watched and automatically adjusts picture settings. Pantone Validated color is another feature that, combined with the TV’s Filmmaker Mode, ensures colors look natural and true-to-life.

Audio on the S90H is delivered by a 2.1-channel, 40W speaker system with support for Dolby Atmos and Eclipsa Audio for YouTube. Sound quality is surprisingly good for such a slim TV, with features like Active Voice Amplifier Pro, which uses the TV’s AI processor to identify voices in movie and TV soundtracks and elevate the dialogue level, adding clarity and definition to the sound. Other audio-related features include Object Tracking Sound Lite, which uses virtual processing to link dialogue and effects to the onscreen action, and Q-Symphony for use with Samsung-branded soundbars like the Samsung HW-Q990H.
The S90H series features Samsung’s “Ultimate Gaming Pack.” This means the TV accepts a 4K 165Hz input across all four HDMI 2.1 ports, and there’s also support for ALLM, AMD FreeSync Premium Pro, and Nvidia G-Sync. Samsung’s Gaming Hub, which gets its own dedicated section in the TV’s smart interface, offers a wide range of apps such as Xbox, Nvidia GeForce Now, and Amazon Luna, and it supports a range of third-party wireless gaming controllers.

One UI Tizen
Samsung’s One UI Tizen serves as the S90H’s smart TV platform, and it’s supported with seven years of future OS updates. Samsung’s new layout for Tizen moves tabs from the side to the top of the TV’s screen for a cleaner arrangement. Along with the wide array of streaming apps accessible from the home page, a Live TV tab presents a grid guide of Samsung TV Plus free ad-supported channels. This guide can also show local channels pulled in by an attached antenna, though the TV’s built-in tuner only supports the ATSC 1.0 digital TV broadcast format and not ATSC 3.0 (aka NextGen TV).

The S90H’s Tizen interface also features a Samsung Vision AI portal with the Copilot and Perplexity AI assistants. You can communicate with these bots using the TV’s built-in far-field mic or by pressing the AI button on the TV’s Solar Cell remote control, which draws power from ambient light in your viewing room. I’m generally a fan of Samsung’s Solar Cell remote, as it eliminates the need for disposable batteries. But the compact remote’s limited button array — there’s no input select button, for instance — means most controls need to be activated from onscreen menus, which can become annoying over time.

Tizen also features the Samsung SmartThings Hub, which lets you view a map of all connected smart home devices (Matter is supported) and control them using voice commands or the Solar Cell remote. Other new Tizen updates include Storage Share, which lets you access files across Samsung devices, and Karaoke for singing songs using your phone as a mic.

The S90H has a more typical, subdued look compared to the aluminum-framed flagship S95H OLED. Samsung’s Simple Plus Blade stand is made of plastic but gets the job done, and it can be snapped together and attached without having to use tools. The display panel itself is extremely slim, but a bottom section containing the power supply and connections extends the TV’s depth to 1.6 inches. Four HDMI 2.1 ports (one with eARC) are split between side- and bottom-facing panels, and there are also optical digital and mini-jack audio outputs.

Setup & Viewing Impressions
Measurements of the Samsung S90H were made using Portrait Display’s Calman Color Calibration software. All adjustments were left at the default settings in the Filmmaker Mode and Standard picture presets for measurement, with the exception of Brightness Optimization, a setting located in the Power & Energy Saving menu that automatically sets picture brightness based on room lighting. We turned that off for the tests.
HDR brightness measured on a white 10% window pattern was 1,553 nits in Filmmaker Mode and 1,414 nits in Standard mode. For a full-screen white pattern, HDR brightness was 292 and 274 nits, respectively, for the same modes. In standard dynamic range tests, the S90H measured 165 nits on a 10% white window in Filmmaker Mode and 481 nits in Standard.
If you’re wondering how those results compare to the flagship Samsung S95H OLED, that model hit a peak HDR brightness of 2,526 nits in Filmmaker Mode and 2,471 nits in Standard when we measured it. As for standard dynamic range results, the S95H measured 215 nits in Filmmaker Mode and 527 nits in Standard.

Clearly, the S95H offers a substantial brightness boost over the S90H, giving it an edge when it comes to displaying specular highlights in HDR content and overall screen brightness when viewing in well-illuminated rooms. In everyday use, however, I found the S90H’s picture to be amply bright even with my room’s overhead lights on, and with the lights dimmed, its brightness was more than good enough for movie viewing.
The S90H’s color measurements were also impressive, although here again, its performance fell short of the Samsung S95H. Color gamut coverage was 75.8% for BT.2020 and 99.4% for DCI-P3. The S90H’s color accuracy was exceptional out of the box, with grayscale Delta E (the margin of error between the test pattern source and what’s displayed on-screen) averaging 1.7 in Filmmaker Mode’s default settings and 1.1 in color point testing.
As usual when I test a TV, the first thing I watch during subjective evaluation is the Spears & Munsil Ultra HD Benchmark disc. The S90H really smashed it here, displaying rich yet accurate color and excellent detail. Blacks were deep and solid in the demonstration reel’s darker shots, and highlights in these sequences looked exceptionally clean. For example, an image of a carousel at night showed clear transitions between the individual LED lights on its surface. On some Mini-LED TVs I’ve tested, those same transitions can appear blurred out as a result of backlight blooming, but on the S90H OLED, they looked perfectly clean and clear.

The S90H’s motion handling appeared to need a bit of adjustment help when I watched a reference scene from the James Bond movie No Time to Die, where Bond walks across a hillside cemetery to visit the grave of Vesper Lynd. At the default settings, there was visible judder and blur, but setting the control for each to +3 in the Expert Settings’ Picture Clarity submenu cleared things up without adding a soap opera effect.
When watching both No Time to Die and Spider-Man: Into the Spider-Verse, colors looked rich and detailed, and in the case of the Bond movie at least, skin tones were natural. With Dolby Vision content like this (Samsung TVs don’t support Dolby Vision HDR, instead displaying it in the base HDR10 format), I found that selecting the Active Tone Mapping option in the Advanced Picture settings menu helped to flesh out shadow detail in dark scenes, which otherwise was being buried with the default Static Tone Mapping option active.
We should note that, while Dolby Vision dynamic HDR is not supported, Samsung does support HDR10+ dynamic HDR, which seems to be making in-roads on some streaming services, including Amazon Prime Video, AppleTV+, Netflix and Disney+. However, Dolby Vision is much more common on physical media (UHD Blu-ray) and is currently the only dynamic HDR format available on Kaleidescape.
The sci-fi series Pluribus is one of the best shows I’ve seen on Apple TV, and I’m eagerly awaiting season 2, which is supposed to arrive sometime in late 2027 or 2028. That’s a long time to wait, so I’ve lately been rewatching some of the best episodes from the first season, like episode six, where Carol drives to Las Vegas to confront the debauched Mr. Diabaté. Watching the party scene in the casino, the glittering surface of a server’s green dress was powerfully illuminated by the S90H, and the colors of poker chips and multiple sports cars in the casino parking area looked vivid. Shadows in darker scenes from this episode also looked deep, with the S90H delivering the consistently strong contrast I expect to see on an OLED TV.
Samsung’s 4K AI Upscaling Pro did a good job overall of upscaling HD and lower-resolution content to 4K. When I watched regular HD Blu-ray movies with the TV’s Auto HDR Remastering feature turned on, it gave a slight brightness boost to highlights and also pumped up color saturation a bit. The effect of Auto HDR Remastering was milder than on the Samsung R95H Micro RGB, which revealed a significant loss of highlight detail when I enabled the same feature.

The Bottom Line
At Samsung’s current discounted price of $1,399.99, the 55-inch S90H I tested is an excellent OLED TV value. You’d need to spend substantially more to step up to the flagship Samsung S95H in the same screen size, and the benefits of that upgrade — primarily higher brightness and wider color space coverage — are likely to be lost on many viewers. As it stands, the S90H is sufficiently bright for most viewing environments, and its Glare Free screen helps its picture stand out even in rooms with bright overhead lighting.
The Samsung S90H is also priced at the same level as its main competition, the LG C6 OLED TV. That model offers roughly the same brightness as the S90H, but lacks the anti-reflective screen tech used on the flagship LG G6 OLED (and on the Samsung S90H with its Glare Free screen). With its solid combination of picture quality and features, the Samsung S90H is recommended for anyone wanting the benefits of OLED at a real-world price.
Pros:
- Good brightness for an OLED TV
- Glare Free screen
- Accurate out-of-box color
- Clean upconversion of HD and lower-res sources
- Solid combination of picture quality and features for price
- Wide range of screen size options
- Extensive gaming features
- Supports HDR10+ dynamic HDR
- Supports Eclipsa Audio
Cons:
- No Dolby Vision HDR support
- No DTS audio support
- No input select control on remote
- No ATSC 3.0 tuner
Our Ratings:
★★★★★★★★★★ Picture Quality
★★★★★★★★★★ Design
★★★★★★★★★★ Usability
★★★★★★★★★★ Sound Quality
★★★★★★★★★★ Features
★★★★★★★★★★ Value
Where to buy:
Related Reading:
Tech
Microsoft comms chief Frank Shaw to exit after nearly three decades shaping the company’s message

It’s the end of an era at Microsoft: Frank X. Shaw, the executive who oversaw the tech giant’s communications for nearly three decades, first at an external agency and for the last 17 years as one of its senior leaders, is leaving at the end of the year.
Shaw, 64, said he’s not retiring, although he doesn’t have another job lined up. He plans to stop working for a while, do some of the things he hasn’t had time for, and then decide what’s next.
“I have had a ringside seat at some of the biggest leadership, technology, and business transformations that have ever taken place,” Shaw said, sharing the news of his departure (under embargo) in a phone call Thursday afternoon. “I just feel incredibly fortunate.”
He said he had been discussing his potential departure for some time with Takeshi Numoto, Microsoft’s chief marketing officer, looking for the right moment.
Microsoft has not announced a successor for his role as chief communications officer. In a LinkedIn post, Shaw said the company will consider internal and external candidates.
A statement from Shaw’s colleagues in corporate communications credited him for his many years shaping Microsoft’s “voice and reputation with intelligence, candor and wit. His leadership and contributions to the company are too extensive to list, as is the number of journalists who have, at one point or another, used his name in vain.”
A former Marine Corps public affairs officer, Shaw has worked with all three of Microsoft’s CEOs. He started on the agency side, at Waggener Edstrom — now known as We. Communications — when Bill Gates was still running the company.
He built his reputation defending and advocating for Microsoft through some of its hardest stretches: the antitrust years, the Windows Vista backlash, the scramble to replace Steve Ballmer as CEO, and the weekend in 2023 when OpenAI’s board fired Sam Altman.
As the company’s top communications executive, he has also told the story of Microsoft’s reinvention under CEO Satya Nadella, from the LinkedIn and Activision Blizzard deals to an AI push that has carried Azure past $100 billion in annual revenue.
Evolving with technology: Shaw has spent much of his career closely watching the tech landscape and moving Microsoft’s voice into new channels as they emerged.
“We’re always thinking about what is the art and science of communications,” Shaw told PRWeek. “How do we reach our audiences most effectively in a changing environment?” He called the arc from print to radio and TV to social media and newsletters a “constant evolution of influence.”
He turned the corporate blog into a place where the company argued its own case, writing “Microsoft by the numbers” himself in 2010 — a stat-by-stat comparison against Apple and Google that TechCrunch dubbed “fantastic passive-aggressive.”
He and his team experimented with different and risky methods of telling the company’s story, holding mass briefings under embargo and publishing documents known as the “Book of News” in advance of its major keynotes and conferences. The prospect of a reporter having to answer to “fxs” was no doubt a factor in ensuring the news (mostly) didn’t leak.
Shaw hired Steve Clayton out of a technical role at Microsoft in London, where he had been blogging about the company unofficially out of frustration with how it was perceived, and made him chief storyteller. In the middle of the AI boom, Clayton and Shaw embraced the analog undercurrents in popular culture and launched Signal, a quarterly Microsoft print magazine for business leaders.
Clayton was VP of communications strategy by the time he left in January to become chief communications officer at Cisco, making Shaw’s planned departure the second high-profile exit from Microsoft’s comms team in a year.
Adapting to AI: In recent years, Shaw made his own team a testing ground for AI, publishing what worked and what didn’t. In a 2023 post he described using Copilot in Teams to pull story ideas out of conversations with spokespeople and anticipate coverage after interviews, and asking the AI to “poke holes in a statement we’re making on a tricky topic.”
He called it his corporal, a reference to Napoleon, who was said to bring one to meetings and ask whether his generals’ war plans made sense to him. A survey of 80 people in Microsoft’s communications and marketing organization found 84% did not want to go back to working without it.
Shaw was also known to use AI as a sounding board when a story frustrated him, offering him an objective take before he called and let a particular reporter have it.
He announced his departure Friday morning in a message to Microsoft’s communications team (reminding them he’s still there for a few months yet) and his public post on LinkedIn.
“Thank you as well to all the reporters, editors, writers, influencers and analysts who have put up with me over this time, enduring my early and late night calls, my off the record ‘no comments,’ my bad story ideas and my extended commentary on headlines and positioning,” he wrote.
“You all have incredibly hard and valuable jobs,” he added, “and while I’ve not agreed with everything said about us 😊 I appreciate you anyway.”
Tech
UK Government Rejects 'Kill Switch' Idea For Dangerous AI
The UK government has rejected proposals for an emergency AI “kill switch,” arguing that blocking access to dangerous models inside Britain would do little if the same systems remained available or were developed elsewhere. The BBC reports: The proposal to create a legal mechanism for the UK to switch off an AI model in an emergency has been brought to Parliament by lords and MPs in recent weeks as fears grow about the threat the tech poses. But the Cabinet Office – the part of government which leads on AI safety – said the UK “cannot simply turn AI off”.
“Blocking access to models in the UK would not prevent them being developed or misused elsewhere,” a spokesperson told BBC News. The government’s opposition to the legislation does not prevent it from progressing through parliament, but makes it unlikely it will become law. “Switching off access to an AI model in an emergency will do little to protect you,” said former OpenAI researcher Daniel Kokotajilo. “You’re still going to be steamrolled by the super intelligences created in the US.”
Read more of this story at Slashdot.
Tech
Since 9/11, Fear Has Driven Our Politics. Don’t Let It Drive The Next 25 Years.
from the fear-sucks dept
Twenty-five years ago today I was woken up by a phone call from a close friend, who, like me, grew up in New York and, like me, was now living in California. She told me that something horrible had happened in New York and to turn on the TV. She said something about a plane flying into the World Trade Center, and I assumed it was a small Cessna or something that went horribly off-course. It was only once I turned on the TV news (and started searching the internet) that I began to comprehend what was happening.
I’m guessing there aren’t many Techdirt readers from back then still reading today, but after a few hours of staring blankly at the TV — scared by what had happened and already uneasy about what the world would do in response — I put up a post saying that I had nothing else to say and wouldn’t be posting (other than to link to some resources). The next day, I was already expressing concern about how the world would respond, and calling out the people rushing to play the blame game. I pointed to a quote from a New Yorker saying “we aren’t in a state of war, we’re in a state of mourning.” But it wasn’t difficult to see where things were heading. Late that night I warned (in a poorly written, rambling post) about how people blindly reacting via ignorance was going to lead to bad outcomes, and how mass surveillance of the internet was likely coming.
A few days later, I pointed to a satirical piece on a now defunct website, entitled: “Why the Bombings Mean That We Must Support My Politics,” which can be found here in the Internet Archive. It does a great job of showing how basically everyone saw the attack as a chance to push forward their own existing political views:
Many people will use this terrible tragedy as an excuse to put through a political agenda other than my own. This tawdry abuse of human suffering for political gain sickens me to the core of my being. Those people who have different political views from me ought to be ashamed of themselves for thinking of cheap partisan point-scoring at a time like this. In any case, what this tragedy really shows us is that, so far from putting into practice political views other than my own, it is precisely my political agenda which ought to be advanced.
Not only are my political views vindicated by this terrible tragedy, but also the status of my profession. Furthermore, it is only in the context of a national and international tragedy like this that we are reminded of the very special status of my hobby, and its particular claim to legislative protection. My religious and spiritual views also have much to teach us about the appropriate reaction to these truly terrible events.
That satirical take turned out to have been pretty prescient, right? The politics that won out almost immediately was the pure politics of fear from power-hungry politicians, many of whom squeezed 9/11 for every political desire they had already wished for regarding surveillance, control, and expanded governmental powers. They had plans ready to go in a drawer, and pointed to 9/11 as the reason they had to be enacted. And quick. And much of that is still with us, leading to a much greater cynicism and distrust in government.
That alone helped the grievance politics of MAGA succeed — though, as I’ll get to below, the Mamdani administration in NYC is demonstrating something that’s been sorely lacking for years: a politics that doesn’t need you to be afraid of anything and is built on real love for the place and its inhabitants.
Still, it was obvious from the day it happened that the attacks were going to set in motion a bunch of horrible ideas from the political class. The always thoughtful Radley Balko has a piece in the NY Times looking back at the past 25 years, and noting that almost every prediction made by those warning about how the political reaction would erode our civil liberties turned out to be true.
Civil libertarians questioned these new powers’ connection to the 2001 attacks. Some provisions had long been on the wish lists of federal law enforcement agencies, and it was not clear that the new powers would have prevented the attacks. They also cautioned that if history was any indication, the government would use the new powers primarily for routine law enforcement. They urged Americans to imagine those powers in the hands not of an altruistic and conscientious president, but one with little respect for norms, institutions or democratic principles.
The civil libertarians were mostly ignored, and as one new threat followed another — Iraq, ISIS, “lone wolves” — the president’s reach continued to grow. Across the Bush and Obama administrations, the commander in chief was given, or simply took, new powers to prosecute, shut down and seize the assets of alleged terrorist groups and their supporters. With the arrival of armed drones, the president assumed the right to remotely assassinate anyone, anywhere outside U.S. borders, at any time, including American citizens.
And, as he notes, we’ve arrived at the worst-case scenario: a president handed every one of those powers by a frightened nation, abusing them at every opportunity. Many of us who warned about the PATRIOT Act and the surveillance apparatus it made possible were dismissed and ignored. When we pushed back on centralized monitor and control points of the internet, the “adults in charge” mocked us as “internet shut-ins.” But, as Balko points out, the internet shut-ins had a point. As he says, “welcome to the worst-case scenario” that lots of us were, in fact, worried about.
The piece is long and thorough, and we’re only scratching the surface here. But Balko draws a straight line from the entirely predictable overreaction of September 2001 to today: the media and the political class sold a narrative of fear, Congress handed over a sweeping set of powers without even the slightest concern for potential risks, and those powers have since curdled into one abuse after another.
If the ratcheting diminishment of our liberties came slowly and sometimes without much outcry under Presidents Bush, Obama and Joe Biden, the consequences of all those years of expanded presidential power are plainly visible now. Mr. Trump is using every authority we have given the president since Sept. 11, 2001, and some we haven’t, in ways the civil libertarians had tried to warn us about at the start.
Mr. Trump has used the president’s post-9/11 “national emergency” loopholes more than any other president. He claimed the country faced an emergency caused by crime to justify sending National Guard troops to Washington, and he used a 1903 law concerning “a rebellion or danger of a rebellion” to deploy them to Chicago, Portland, Ore., and Los Angeles. (He also sent active-duty Marines to Los Angeles.) It was the first time since the civil rights era that a president had sent troops over the objections of a state governor. When Mr. Trump tried to invoke the 1798 Alien Enemies Act to deport immigrants to a notoriously inhumane prison in El Salvador, a federal judge asked for information about deportation flights and Mr. Trump invoked the State Secrets Privilege.
Mr. Trump has tried to categorize leftist activists, as well as advocacy and funding groups, as terrorism supporters in an effort to use antiterror tools to shut them down, despite no evidence that those groups have any ties to terrorism. The administration has called Americans protesting against the deployment of militarized ICE officers “domestic terrorists.” It has claimed that activities protected by the First Amendment, including criticizing, naming and recording ICE officers, are acts of terrorism.
Mr. Trump and his team are taking full advantage of the immunity granted by the courts. The administration’s summary executions of suspected drug smugglers in the Caribbean have been denounced by legal scholars as illegal under both domestic and international law, and as likely crimes against humanity. The strikes have not only continued; the administration celebrates them. Mr. Trump’s deputy chief of staff, Stephen Miller, according to multiple reports, has openly encouraged immigration officers to use more violence and force more confrontation with protesters while regularly reminding them of their “immunity,” even after the killing of Renee Good in Minneapolis. After Ms. Good’s death the “border czar,” Tom Homan, went on Fox News to warn that “there’s still gonna be more bloodshed” unless ICE critics “shut their mouth,” a threat that’s likely a First Amendment violation in and of itself.
These are the abuses of post-9/11 powers we know about; there are almost certainly more that we don’t. The expanded surveillance authorities have such restrictive rules for disclosure that only a handful of people will know if they are being deployed against Americans. Mr. Trump’s handpicked prosecutors are going after the kinds of leaks that helped reveal abuses in prior administrations, which means more disclosure today is even less likely. And under Mr. Trump, the intelligence agencies have at times abandoned the post-Watergate practice of telling Congress what secret powers they are using.
The whole thing is worth reading, and it’s a good reminder of why we’ve spent so much of the last two and a half decades calling out these issues, and warning about further government control and intrusion into platforms and attacks on our privacy. It’s why we were concerned about draconian command-and-control copyright laws fifteen years ago just as much as we’re concerned about age verification laws today.
They’re all tools for control and surveillance, built to shrink what the public can do and expand what the government can get away with. And every single one of them was sold to the American public based on fear.
But there’s an important thing to understand about a ratchet built entirely out of fear: it only turns as long as people stay afraid. Which brings me back around to New York City. This past week there has been an entirely ridiculous and fabricated culture war-driven dispute regarding whether or not NYC mayor Zohran Mamdani should attend NYC’s commemorations of 9/11. There is no fathomable reason for him not to attend other than rank ignorance and bigotry against him for being Muslim.
For all the fuss and fear — much of it driven by a former NYC mayor who spent many years (including while mayor) leading by spreading fear across the city — the whole spectacle is the post-9/11 playbook running one more time, just scaled down: declare an out-group, never quite say that they did wrong, and insist that “they” are inherently opposed to “us.”
But also, Mamdani is running a fundamentally different kind of politics than the one 9/11 left us with. He has quite high approval ratings, in part because he is governing from a position of love for New York City and all its residents and visitors, rather than one of fear. This is what we saw during his campaign, when he did things like run a massive, fun, and educational scavenger hunt across NYC. But campaigning like that is one thing; carrying it into an actual administration is quite another — and somehow he’s done it.
Over and over again Mamdani has focused on what’s amazing about NYC and the ways he can and is improving it on a daily basis, from the little things to the big things. After years and years of expecting politicians to try to scare you into supporting them with “only I can protect you” rhetoric, it’s astounding to be reminded of what politics of love and community can actually be like. Sometimes it looks like this:
Or this:
You can argue Mamdani is a once-in-a-generation political talent, and that what works for him won’t work for everyone. Fine. But plenty of what he’s doing is entirely replicable, and the rest of the political class should be taking notes. He clearly loves New York City and the people there, and still believes in ways to make it better, not through fearmongering and hate, but through putting in the hard work of actually listening to people and helping them with real problems. It’s also a reminder of what good government can look like.
Twenty-five years ago this morning, I had two fears: what had just happened in NY and DC, and what the world was going to do about it. The second one was the one that stuck. Over the past twenty-five years, that fear has helped write dangerous laws, many of which are still on the books, and drive more and more division in our society. And where we’re at now is that a uniquely dangerous president has all those tools at his disposal, and is using them to anger and divide us further.
NYC’s mayor can’t repeal those laws. He can’t stop a president hell-bent on rancid politics of hate and fear. But that ratchet only ever turned because enough Americans were scared enough to let it, and because no one was offering them anything else as an alternative. This week, in the very city that was the primary target that morning, the guy running the city isn’t telling anyone to be afraid of anything. He’s showing up, doing the work, and reminding us of what’s good.
Twenty-five years is a long time to be told that’s naive.
May the next twenty-five years be more the politics of community building and hope, over the politics of fear and division.
Filed Under: 9/11, donald trump, nyc, politics, surveillance, tragedy, zohran mamdani
Tech
Upgraded In All The Right Places
Ultra-level features and a few design tweaks highlight the updates.
RATING : 8.4 / 10
- Extremely comfortable
- Improved audio and ANC performance
- Battery life is unchanged
- Design is still all business
We may receive a commission on purchases made from links.
When I think about Bose headphones, the iconic QuietComfort line immediately comes to mind. No, not the more recent Ultra version with all of today’s bells and whistles. I’m talking about the business-traveler-chic models that popularized active noise cancellation (ANC). They were never going to win any design contests, but you could rely on them to give you some relief on a flight while also offering decent audio quality.
The company rebranded these to the QuietComfort Headphones a few years back, and now Bose returns with the second-generation version. This time, there are some modest design changes, although the understated look is still intact. What’s more, the second-gen QC Headphones borrow features from the pricier QuietComfort Ultra Headphones which enhance both audio and ANC overall.
What’s new on the second-generation QuietComfort Headphones?
While this new version undoubtedly fits the aesthetic of the regular QuietComfort line, Bose made two notable design changes. First, there’s an updated headband that slides smoothly to adjust. Next, the company refined the shape of the earcups while installing improved ear pads for better cushioning. In a third change, a decidedly less exciting one, Bose relocated the power/Bluetooth pairing switch from the outside of the right ear cup to the bottom edge of the left ear cup. This doesn’t really impact the experience, but it does give the headphones a cleaner look on both sides.
In terms of features, Bose brought Immersive Audio to the regular QuietComfort Headphones for the first time. This is the company’s take on spatial audio that doesn’t rely on specially created content. Instead, the tool upscales any movies, shows or music as needed for enhanced listening. Before now, Immersive Audio was exclusive to the Ultra line of QuietComfort Headphones. Plus, Bose’s Cinema Mode, which enhances dialogue without constraining the wide soundstage of Immersive Audio, is on the second-gen QC Headphones too.
The company’s CustomTune feature is also a new addition, a tool that calibrates audio and noise cancellation to the acoustic properties of your ears. It’s like room calibration for a soundbar, but for your headphones. And if you’re into lossless audio, you can listen with a cable over USB-C at up to 24-bit/48kHz. What’s more, the headphones can be charged while you’re using them with a cable. If you’ll recall, the previous QuietComfort Headphones still had a 3.5mm port for wired use. Bose ditched that on this new version as the only wired connectivity is over USB-C — for both charging and listening. For in-flight entertainment systems, there’s a USB-C to 3.5mm cable in the box, or you could opt for a $30 accessory like the AirFly for wireless use.
The company also improved ANC performance on this new model with the addition of ActiveSense. This feature automatically applies noise cancellation when the headphones detect sudden spikes of noise if you’re using Aware (transparency) mode. Bose says ActiveSense now responds more naturally to those brief periods of disruption before returning to ambient sound mode. The company also explains that the ANC system on the second-gen QC Headphones can better compensate for changes in the ear cup seal due to glasses. And last but not least, you can disable ANC entirely in the Bose app this time around.
What’s good about these headphones?
I’ll get to audio and ANC performance in a minute, but I must first applaud Bose for refining the QC Headphones without raising the price. This second-gen version costs $359, same as the previous installment did when it debuted. At a time where almost everything is more expensive, I’d expect any headphone company to raise prices on new models by at least $50, but that didn’t happen here. Plus, this price tag gives Bose fans a compelling alternative to the $449 second-gen QuietComfort Ultra headphones that costs significantly less.
ANC has long been the trademark feature of the QuietComfort lineup, and that doesn’t change here. These headphones continue Bose’s strong track record for effective noise cancellation with this model does well against constant noise sources (like fans) in addition to respectably lowering the volume on human voices (on TV and IRL). The second-gen QC Headphones don’t completely silence a chatty neighbor, but they consistently reduce the distraction.
While I concede the second-gen QuietComfort Ultra Headphones are Bose’s best option in terms of pure sound quality, this regular model is no slouch. The tuning is balanced, providing adequate low-end thump when a song demands it — like Nine Inch Noize’s “Vessel.” Even without Immersive Audio active, these QuietComfort Headphones provide plenty of fine detail in the texture and grit of the synthesizers on that track. Switch over to Basement’s WIRED and you get the same level of clarity and nuance in the band’s alt-grunge songs, particularly in the guitars. And it’s no surprise that more mellow genres sound great here. Billy Strings’ “Bluewater Breakdown” is embedded with all of the string-instrument subtleties that a lot of headphones don’t offer.
When I first took the new QC Headphones out of the case, I was immediately struck by how lightweight they are. Compared to the current Ultra headphones, this model is about 34 grams lighter, which makes a huge difference in comfort. I could tell the difference as soon as I put them on, and the disparity only increased the longer I wore both sets. Plus, the soft ear pads are both pillowy and sturdy enough that you can’t feel the edges of the ear cups. Lastly, the clamping pressure of the headband is adequate for respectable ANC performance without becoming a burden on my large head.
What’s not so good about the new QuietComfort Headphones?
If you didn’t like the design of the regular QuietComfort Headphones line before now, I highly doubt Bose did enough to change your mind. These are still the less-polished option compared to the pricier, shinier QC Ultra Headphones. I can appreciate fans of this model prefer it that way, and the company offers a dark pink and two green color variants if you need a splash of personality.
My only real complaint with the new QC Headphones is that battery life remains the same as the previous model. You get 24 hours of ANC use on a charge, which should be enough for multiple days, but the QC Ultra Headphones last 30 hours. I would’ve liked to see at least a modest bump in longevity here to go along with the feature additions and other improvements.
Wrap-up
After all these years, the QuietComfort line still lives up to its name. The second-generation QuietComfort Headphones are an all-around upgrade over the 2023 version, a compelling option that costs less than the QuietComfort Ultra Headphones (second-gen). I would’ve loved to see the upgrades extend to longer battery life, but if that’s my only gripe, the company did well. And if a few more hours of use would’ve come with a higher price, I can be happy with what’s here.
The regular QuietComfort Headphones remain a perfectly suitable, highly comfortable option that’s adept at noise cancellation and provides above average sound quality. That all combines to bolster Bose’s decades-long run of consistent performance, a source of reliability that isn’t likely to disappoint customers anytime soon.
Tech
AI agents are learning to spend money. Who will handle the payments?
AI is already changing how people find and buy things online, comparing prices, narrowing down options, doing in seconds what used to take an afternoon of tabs open.
An AI agent could find a flight that fits your schedule, for example. Giving it permission to actually buy the ticket is a more complicated problem.
That is because most payment systems were built around people. Someone enters their card details, signs into an account, clicks approve. If software is going to complete more tasks on their own, they will also need a way to pay without stopping to ask permission every time.
There are signs this could become a much bigger part of how software works. Gartner expects agentic AI to be built into 33% of enterprise software applications by 2028, up from less than 1% in 2024. McKinsey estimates that AI agents could mediate between $3 trillion and $5 trillion in global consumer commerce by 2030.
How those agents actually pay is now becoming its own technology problem. Mastercard, Coinbase, and blockchain networks, including XDC, are among those trying to solve it.
When software needs to buy something
Mastercard is preparing for the same possibility. When it launched Agent Pay for Machines in June, the company described a future in which agents could continuously buy services from each other, including payments worth fractions of a cent.
That is where XDC AI also comes in: by providing AI agents with the capability to find and pay for digital services on demand, rather relying on traditional human checkout flows, the platform allows software to programmatically handle micro-transactions in real time.
“Every internet transaction so far has assumed a person is on the other end of it,” said Atul Khekade, co-founder of XDC Network. “AI Agents are breaking that assumption completely. If software is going to act on our behalf, it needs a way to pay for what it needs without waiting for someone to approve it every time.”

A user can give an agent access to a wallet and set a limit on how much it is allowed to spend. When the agent needs data from a paid API to finish the task, it can make the request and pay for it in USDC, with XDC covering the gas fee, so the agent does not also need to hold XDC to make the payment.
XDC Tech, the US institutional arm of XDC Network, has also integrated with Bridge, a Stripe company, helping to connect those onchain payments with more traditional financial infrastructure by giving developers access to infrastructure for moving between fiat currencies and stablecoins.
An agent researching a market could need information from several paid data sources. Another might need access to a particular API or a small amount of computing power to finish a task. Instead of someone setting up a new account or subscription every time, the agent could find the service and pay only for what it needs.
An old part of the web finds a new use
XDC is building this on x402, an open protocol developed by Coinbase. That resurrects HTTP 402, an old web status code meaning “Payment Required” that has existed for years without becoming widely used. An agent requests a paid API, the server responds with a price instead of the data, and the agent’s wallet pays automatically, no login, no card number, no human in the loop. XDC has built that flow into its own marketplace, where an agent can find an API, pay per use in USDC, and stay within whatever limit its owner set.
Adoption is still early, but x402 is beginning to attract some large names. The Linux Foundation now oversees the x402 Foundation, which has 40 members including Mastercard, Visa, Stripe, American Express, Google, AWS and Circle. That does not mean x402 has become a mainstream payment rail, but it gives the protocol considerably more institutional backing than it had when Coinbase first introduced it.
That is a major reason why the infrastructure work matters more than the headlines right now. Fully autonomous shopping is still limited, and AI is much further along at helping people compare options than at completing purchases on its own. But the direction is clear, and XDC is betting that when agents do start paying their own way, they will need rails built for machine speed rather than human checkout, cents instead of dollars, and thousands of transactions instead of one.
The gap between x402’s onchain activity and its ecosystem valuation is a reminder that infrastructure and adoption rarely move at the same pace. What is being built is real, the settlement rails, the wallet permissions, and integrations with players like Bridge, but the volume moving through them today is still a fraction of what the numbers around this space suggest.
For now, AI remains far better at helping people decide what to buy than at completing the purchase itself. That is where the real contest is playing out. Card networks are wagering that trust and identity, the problem they have spent decades solving for humans, will matter just as much for machines.
Networks built for stablecoin settlement, XDC among them, are wagering the opposite: that speed and near-zero fees will define this market once agents start transacting at scale. In the end, the better approach will probably come down to the use case. But what is certain is that the infrastructure decisions being made now, by companies like Mastercard and XDC, will shape how autonomous commerce actually works once it arrives.
Tech
Britain’s technology brief is now everyone’s job and nobody’s responsibility
PUBLIC SECTOR
Whitehall has scattered science, AI, and digital government across a thicket of competing ministerial portfolios
OPINION “Where do we put digital government? You know, all those billions we spend on consultants and legacy systems?”
“Oh, that! Put it with sports and tourism. And something we’re calling ‘place’.”
It might be a fictional conversation between a SpAd* and a mandarin**, but in reality, the outcome is more or less the same. With the arrival of Andy Burnham as UK prime minister came a shake-up of responsibilities in Whitehall, leaving responsibility for science, technology, and government tech scattered across several departments and eliminating the dedicated technology ministerial role.
Shortly after the changes were announced in July, Dame Chi Onwurah, chair of the House of Commons Science, Innovation and Technology Committee, wrote to the government asking for an explanation. The government had yet to confirm what the new roles and responsibilities meant in practice, and there was no news on ministerial portfolios, she said.
Now a joint letter from the ministers leading three departments attempts to answer Onwurah’s questions. It brings clarity only by laying bare the government’s confused thinking and lack of credibility.
Take space, for example. The letter says BIST aims to “support companies from breakthrough ideas and research excellence through to commercialization, scaling and exporting, and to fortify the UK’s global leadership in this space.” When it comes to literal space, however, responsibility falls to Baroness Lloyd of Effra.
A law and history graduate, Lloyd worked in Tony Blair’s policy unit before becoming his deputy chief of staff. She will fit responsibility for the UK’s public and private space sectors between her cyber, regulatory reform, corporate governance, and Insolvency Service duties. She will work across two departments: the Department for Business, Innovation, Science and Trade (BIST) and the Department for Digital, Culture, Media and Sport (DCMS).
We’re sure the role will afford plenty of time to help oversee the £7.8 billion of cross-government spending brought together under the new space strategy intended to cover orbital collision warnings, low Earth orbit communications, military intelligence, launch capabilities, and space science.
The question is, where did technology go? Isn’t space related to technology? Technology was in the Department for Science, Innovation and Technology. But that T is now Trade. The D that stood for Department in DSIT is gone; in DCMS, it stands for Digital. (The DWP and DHSC still keep their D for Department, for those wishing to understand that no rules apply here.)
But what is digital? It underpins everything. “The technologies shaping our economy are also transforming how people create, communicate, learn, participate and access public services. By expanding DCMS’s remit to include responsibility for tech sector oversight and digital, including: digital skills, digital infrastructure and connectivity, cyber security, and the delivery of a modern digital government, we are enabling DCMS to lead the transformation of public services while strengthening and growing the digital, cyber and information foundations on which our economy and society depend.”
OK, but why is the technology sector separated from science? If digital underpins everything, then it is also worryingly vague. Is it really closer to culture and media? A photographer might want to use Photoshop, but they don’t need to know how the software works.
The development of computer hardware and software has gone hand in hand with wider research. The World Wide Web and DeepMind both came out of university projects, not to mention one of the early modern computers, the Manchester Mark 1, developed at the University of Manchester with input from WWII code breaker Alan Turing.
To further muddy the waters, Kanishka Narayan was appointed Minister of State for AI, a joint Cabinet Office and BIST role that comes with Cabinet attendance.
Responsibility for science and technology is now spread across four departments. Chris McDonald, Minister of State for Science, Innovation and Investment, works jointly across BIST and the Department of Health and Social Care. Science sits with business and trade, but digital sits with “creative industries” and sport. Digital government – which has been in three departments over two years – gets a junior minister in the DCMS. Stephanie Peacock is expected to perform that role along with responsibility for sport, tourism, and place (which is not defined in the letter or elsewhere). It is questionable whether she will get the backing needed to confront big tech suppliers repeatedly feasting on government spending while other ministers court those same companies for investment. Her public announcements so far have focused more on Blackpool staycations and the Commonwealth Games than digital government.
In their letter, the three ministers said the changes were necessary because “the UK stands at a critical juncture where unprecedented global changes demand that we secure our position as a world leader in AI, science and technology. In this context, we cannot see science and technology as an isolated issue, limited to one department. Instead it is a major priority that cuts across the whole of government and is vital to the UK’s future economic prosperity.”
But the government’s answer has been to break up the former technology department and scatter its responsibilities among portfolios where they will struggle for attention. As for tech in the public sector, we might hope the government will stop getting beaten up by suppliers, but we will be waiting a long time. ®
* Special Advisor in the British civil service
** slang term for a senior UK civil servant
-
Tech3 days agoMemory prices are slowing because buyers ran out of money
-
Business2 days agoMicron Stock Climbs Above $1,031 as AI Memory Crunch and a $50 Billion Outlook Fuel the Rally
-
Business2 days agoAMD Stock Climbs After Management Lifts 2027 Data Center Outlook Toward $70 Billion in AI Sales
-
Crypto World3 days agoBitcoin price risks $76K drop as $78K support weakens
-
Crypto World3 days agoRobinhood Stock: How To Take Advantage With Reduced Risk
-
Crypto World3 days agoEthereum price stalls below $2,500 as ADX drops to 11
-
NewsBeat3 days agoWhat went right this week: an ‘historic’ fall in violent crime, plus more
-
NewsBeat3 days agoEngland up in reading, maths and science rankings as Scotland and Wales dip
-
Crypto World3 days agoIntel Stock Jumps 9% on Chip Price Hike Report, US Stake Gains $36 Billion
-
Crypto World2 days agoBitcoin price risks $70K if $78K neckline breaks
-
Crypto World2 days agoBitcoin price holds near $79K as cycle drawdowns narrow
-
Business3 days agoMeta debuts long-awaited personal AI agent, Muse
-
Sports3 days agoPhones confiscated, players sent home: Pakistan’s England tour turmoil revives memories of Mohammad Amir, Salman Butt and Mohammad Asif’s 2010 Lord’s spot-fixing scandal | Cricket News
-
Crypto World20 hours agoOKX launches 10x OpenAI, Anthropic X-Perps in Europe
-
Crypto World3 days agoPump Fun and Kraken delete Hunter Biden $LAPTOP promotion
-
Crypto World3 days agoBrent Crude Oil Moves Above $100 for the First Time in 3 Months
-
Crypto World2 days agoEthereum price breakout hinges on a close above $2,535
-
Crypto World20 hours ago
Ethereum Price Analysis: Consolidation at $2.5K Tests Momentum as On-Chain Activity Surges
-
Crypto World1 day ago2 Chip Stocks Broke Out This Week. Neither Was Nvidia
-
Crypto World3 days agoVisa expands stablecoin card network to 160 programs


You must be logged in to post a comment Login