Google is updating AI Overviews and AI Mode, the AI-generated portions of its search engine, to highlight sources in new ways, and interestingly, more prominently feature first-hand accounts from social media, expert blogs and forums like Reddit.
Via a new section that can appear in AI responses, Google will display “a preview of perspectives from public online discussions, social media and other firsthand sources.” In the sample screenshot the company provided, the section was called “Expert Advice” and included quotes from forums, WordPress blogs and Reddit. These were arranged above links to their respective sources. Google plans to add more context to these links, too, showing “a creator’s name, handle or community name,” so you can judge what you might want to click through and read from a glance.
Google will also start recommending in-depth articles at the end of AI responses for further exploration of a given topic, and link to more sources directly in its generated answers rather than just at the end. If you subscribe to any publications, AI responses will also highlight sources from the subscriptions you link to your Google account.
Given the rapid progress of AI in general, AI Overviews and AI Mode have been pretty consistently iterated on since Google launched them in 2024 and 2025, respectively. Pulling from Reddit and other online social platforms isn’t exactly a new strategy for the company, either — at least one early AI Overview hallucination was caused by information from Reddit. It is perhaps telling Google plans to cite the platform more prominently now, though, because Reddit is considered by some to be a more useful source of information than Google. Even more this update, the search engine has been prominently featuring Reddit links in standard search results.
Advertisement
Whether adding more links and recommending long-form reporting makes a meaningful difference for the dwindling number of publications Google pulls from is another story, however. As of 2025, Google claimed that its AI search tools were leading to more searches and more “high-quality clicks” on the websites it cites. Regardless of how much the company tinkers with its AI responses, though, one outcome of AI Overviews and AI Mode is the creation of scenarios where you don’t have to click away to another website at all, because Google answered your question for you.
Update, May 6, 5:30PM ET: This story was updated after publish to include information from Google that the title of the section is dynamic, rather than called Expert Advice.
Autonomous tanker drone completed two-hour maiden flight validating core flight systems
MQ-25A will replace fighter jets in aerial refueling role aboard carriers
Further testing planned before transition to carrier qualification operations in Maryland
The US Navy’s MQ-25A Stingray autonomous tanker drone, the service’s first operational unmanned aerial refueler, has completed its maiden flight.
The two-hour test took place over southern Illinois, where the aircraft carried out a series of maneuvers to validate its basic flight controls and onboard operations.
During the mission, the drone followed a predetermined plan which saw it taxi, take off, fly, and land autonomously, all triggered through commands issued from the Unmanned Carrier Aviation Mission Control System MD-5 Ground Control Station.
Article continues below
Advertisement
Navy plans autonomous operations
Air Vehicle Pilots set the route and defined waypoints before launch, then monitored performance throughout the flight and retained the ability to abort or adjust the mission if required.
The aircraft handled propulsion, guidance, subsystems, and flight controls on its own once the mission began, showing how the U.S. Navy plans to run autonomous operations while keeping human oversight in the loop.
Advertisement
“Today’s successful flight builds on years of learning from our MQ-25A T1 prototype and represents a major maturation of the program,” said Dan Gillian, vice president and general manager, Boeing Air Dominance.
“The MQ-25A is the most complex autonomous system ever developed for the carrier environment, and this historic achievement advances us closer to safely integrating the Stingray into the carrier air wing.”
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The Stingray fills a very specific gap in carrier operations, taking over the aerial refueling role that currently falls to F/A-18 Super Hornets, and freeing them to return to strike and combat roles.
Advertisement
Rear Adm. Tony Rossi, the U.S. Navy’s program executive officer for unmanned aviation and strike weapons, said, “The MQ-25A is not just an aircraft: it’s the first step in integrating unmanned aerial refueling onto the carrier deck, directly enabling our manned fighters to fly further and faster.”
Earlier testing using the MQ-25A T1 prototype helped lay the groundwork for this flight, with that earlier demonstrator logging roughly 125 flight hours to prove the concept before production aircraft took over.
DefenseScoopreports the test also validated the Rolls-Royce AE 3007N engine and confirmed integration with the ground control system that operators will rely on once the aircraft moves into carrier testing.
More test flights are scheduled from MidAmerica St. Louis Airport before the aircraft transitions to Naval Air Station Patuxent River in Maryland, where preparations for aircraft carrier qualification flights will begin.
In a crowded market where there are so many fantastic coffee machines, the KitchenAid Semi-Automatic Espresso Machine stands out by being one of the better-looking options on the market. Not only does it look premium, but it feels it too. This machine is solidly built, and the supplied accessories including the removable bean hopper, porta filter and tamper, have a decent amount of weight to them, further adding to the overall premiumness of the machine.
It’s available in a range of colors, but I feel my review unit in Porcelain (white) will be the easiest to match with kitchen decor (although I have to admit taking a fancy to the Juniper green, too).
Advertisement
If you want to get hands-on with your coffee-making process, it makes the process easier by way of a flat-bottom porta filter that I think should become customary on all coffee machines of this type. This design choice is a stroke of genius, giving you a far greater ability to apply a good amount of tamping pressure, essential for extracting a good shot of espresso.
While it does have ‘semi-automatic’ in its name, this only really applies to the amount of coffee grounds it will dispense into the porta filter. You decide how much that is, the grind size and, if you want milk with your coffee, that’s a manual process too.
Figuring out the optimal settings for your personal taste will, therefore, require some trial and error, but if you’re considering buying a coffee machine like this one, that’s likely something you’ve already considered and are happy to get involved with.
Advertisement
Some assistance is given, such as an ideal window of pressure shown in a pressure gauge, so you’ll know if you’ve put the right amount of coffee and applied the right amount of pressure when tamping. Once you’ve completed these steps, the KitchenAid Semi-Auto produces a wonderful shot of espresso. Taking all of this into account, I consider it to be one of the best bean-to-cup coffee makers.
It’s not short of competition in terms of price and features, and there are other models that offer greater usability, such as smart tamping and dosing systems — the De’Longhi La Specialista Touch, for example. Despite that, I think it’s competitively priced and can regularly be found with a discount, which only adds to its value.
Sign up for breaking news, reviews, opinion, top tech deals, and more.
The KitchenAid Semi-Automatic Espresso Machine launched worldwide a couple of years ago in 2024. It remains on sale today and more often than not, for the same price as when it launched. With a list price of $699.99 / £699 / AU$899, it’s fairly priced, but is arguably better value in Australia if you take direct currency conversions into account.
This KitchenAid machine is relatively light on features, offering just the basics of at-home coffee making, in the form of an integrated burr grinder, steam wand and hot water spout. In terms of price, it’s not short of competition, but some price-comparable alternatives offer more in the way of features.
These include the Breville Barista Express (Sage Barista Express in the UK) for $699.95 / £629 / AU$599, the Ninja Luxe Cafe with a price tag of $599.90 / £549.99 / AU$799.99 and the De’Longhi La Specialista Arte Evo costing $699.95 / £499 / AU$649. In Australia, it gains another competitor in the form of the Sunbeam Origins Sense, which is now regularly available for under AU$700.
All offer a built-in grinder, varying levels of customization and a built-in steam wand. The Ninja and De’Longhi machines are able to produce cold-brew coffee, for example, something not on the KitchenAid’s menu. The Ninja Cafe Luxe also takes care of the grinding and tamping process for you, offering a more hands-off approach.
However, at the time of writing, this KitchenAid machine is on the receiving end of discounts of up to 30% direct from the maker in the US, UK and Australia.
The KitchenAid Semi-Automatic Espresso Machine is a relatively compact appliance with dimensions measuring 39.5 x 33.5 x 28.1cm (HWD), making it ideal for small kitchens or those who simply can’t spare the countertop space. At 23.6lbs / 10.7kg it’s quite a heavy unit, though, but its weight gives it added stability that prevents it from moving around when inserting and removing the porta filter.
KitchenAid is known for its chic color choices across its wider range of appliances and that’s the case here too. My review unit was the Porcelain (white) color with gloss finish, which is a standout for me, being easily matched with any kitchen decor. Other colors include Cast Iron Black, Candy Apple (red), Juniper and Stainless Steel.
Advertisement
This espresso machine is relatively light on button count, with the few available serving more than one purpose. The power button is on the left, while the start/stop button is on the opposite side. The middle is where most of the magic happens. The top left button will likely be used the most as it cycles through functions to pour the espresso shot, pour hot water and activate the steam wand.
There are also buttons to select a single or double shot, and to adjust the temperature of the water. Finally there’s a button to use when cleaning the machine.
The other main control is a silver dial that sets the dosage amount of coffee to be ground into the porta filter, and a lever to adjust the grind size. Pressing the central button begins dispensing the selected amount of coffee.
As with all coffee machines that require a hands-on approach, figuring out the grind size and grind amount for both single and double espresso is part of the fun, but requires plenty of trial and error. This is because the type of coffee beans you use will have an effect on the yield and, further to that, how they behave when being brewed. For example, a darker roast tends to perform better with a coarser setting than a medium roast due to the way it breaks apart when going through the grinder.
Advertisement
I used medium-dark roast coffee beans for this review and found turning the double shot dial to around 4 o’clock, and the grind setting to five lines from the right, yielded good results. While you can invest in scales to ensure you get the ideal amount — around 8g of ground coffee is often considered a good starting point for a single shot of espresso and 18g is considered optimal for a double — KitchenAid has added a small line in the porta filter baskets to indicate the ideal point where the coffee should line up once it’s been tamped.
You don’t want to go over this line, as doing so will create too much pressure during the brewing process, resulting in your coffee dripping out of the porta filter. A pressure gauge on the front of the machine shows an ideal window for a good espresso shot and, on a couple of occasions during my testing, the needle did go beyond it, resulting in the aforementioned drip pour.
Image 1 of 3
(Image credit: Future / Max Langridge)
(Image credit: Future / Max Langridge)
(Image credit: Future / Max Langridge)
Speaking of the porta filter, I didn’t realize that a totally flat-bottomed one could be such a revelation! Every other porta filter I’ve used has two spouts protruding out the bottom; here, they’re integrated. This small design touch meant I could be a lot more confident when tamping, planting the porta filter firmly on a table and allowing me to apply force to pack the coffee grounds tightly enough. Porta filters with protruding spouts, however, require careful balancing when tamping.
This flat-bottomed porta filter is a commercial-size 58mm, and is satisfyingly weighty, which gave me added peace of mind that the KitchenAid machine has been made with care. The 58mm size has several benefits, including being used with a variety of tools and accessories — such as weighted tampers — to help achieve a well-extracted shot.
Advertisement
The 2.5L water tank at the rear of the machine features an integrated handle to help you remove it. This is one of the largest water tanks I’ve personally come across in a coffee machine, bigger than the Breville Oracle Jet’s (Sage in the UK) 2.3L tank. A water filter is supplied, which clips into a separate plastic handle. I had a little trouble at first getting the two pieces that hold the filter in place to clip together, despite following the instructions to leave the filter soaking in water for 5 minutes. I left it out of the water for a few days, after which it all clipped together as intended.
(Image credit: Future / Max Langridge)
The KitchenAid Semi Automatic Espresso Machine also features an integrated steam wand with a silicone handle for safer handling, and a hot water spout. The steam wand is a traditional one, that meaning there’s no built-in thermometer like you’ll find on other machines such as the De’Longhi La Specialista Touch and Sunbeam Origins Sense, so you’ll need to rely on physical touch with the milk pitcher, or a use a separate food-grade thermometer, to determine when your milk is ready.
In the box is also a removable bean hopper, tamper (which is also well weighted), a 355ml milk pitcher (which does admittedly feel cheaper compared to the other accessories), single- and double-wall filter baskets in single- and double-shot sizes, and a cleaning brush.
A walnut wood accessory kit is available to buy separately for $249.99 / £229 / AU$349. This kit includes a bean hopper with a walnut-wood lid, and porta filter and tamper set with walnut-wood handles.
Well-extracted espresso achievable after some experimentation
Intuitive controls with visual aids
Quick heat-up time
The KitchenAid Semi-Automatic Espresso Machine is a very capable machine, and will brew a well-extracted espresso shot with a good crema — it just requires a fair amount of trial and error to achieve it. Virtually all manual and semi-auto machines will need that little experimentation, though, so it’s by no means a dealbreaker. However, where some machines like the aforementioned De’Longhi or the Ninja Luxe Cafe will assist you in recommending the ideal grind and dosage settings, the KitchenAid leaves you to your own devices.
After loading your beans in the hopper on top of the machine — which fits up to 225g worth — you’ll need to adjust the dosage amount and grind size. If you’re brewing a single shot of espresso, you’ll move the front-mounted round to the left to adjust dosage, and to the right for a double (icons are on hand to signify this). A lever just below this dial will adjust the grind size, from coarse on the left to fine on the right. Note that the dial and lever have to be perfectly aligned with the graphic dots; if they’re not, the machine won’t operate.
You are able to personalize the amount of coffee grounds produced by pressing and holding the central button until it reaches the desired amount.
(Image credit: Future / Max Langridge)
Once you’ve selected your settings, press the button integrated into the dosage dial to set the grinder in action. This KitchenAid machine, like the brand’s fully automatic models such as the KF8, is QuietMark certified, meaning it should be whisper quiet when the grinder is in motion. And sure enough, it is. The Philips LatteGo 4400 that I use daily is ‘SilentBrew’ certified but, in truth, I find it to be relatively noisy, and measured 69dB using the Decibel X app compared to 64dB registered by the KitchenAidwhen the grinder was in motion.
Advertisement
Once the grinder has finished, give the porta filter a little wiggle to help settle the ground coffee before removing it. This machine uses anti-static technology to help ensure nothing spills over the edge and it works like a dream, unlike the Sunbeam Origins Sense that dribbled some coffee during my testing despite claiming to also benefit from similar tech.
One of the key highlights of this machine is its flat-bottomed porta filter, which allows you to plant it on a flat surface to apply tamping pressure using the supplied tamper without disbalancing it. Once you’ve inserted and locked the porta filter in place for brewing — which is another simple and fuss-free process — use the buttons on the front of the machine to select a single or double shot, then set the water temperature to one of three settings. Finally, press the play/start button and your coffee will begin brewing.
Another key highlight of this machine is that it pre-infuses before brewing. This wets the coffee puck before full pressure hits it, which makes the water flow through the grounds more uniformly for better extraction.
If you’ve adjusted the dosage and grind settings correctly and provided enough tamping pressure, you’ll be rewarded with a beautiful shot of espresso with a lovely crema. It’s unlikely you’ll get the best settings on your first try (I certainly didn’t), so be prepared for some trial and error.
Advertisement
As with the grind settings, you can personalize the amount of water used for both single and double shots by pressing and holding the start/stop button until the desired espresso amount is reached in your cup. These water volume settings will be saved for future use. To reset to factory settings, press and hold the dose button for three seconds. All indicator lights will blink to indicate settings are restored.
However, the machine doesn’t have profiles, nor can it store different settings. If you have multiple coffee drinkers at home who prefer different beverage types, then you’ll need to manually set the grind and dosage amounts each time. If so, I’d recommend keeping a note of the optimum settings somewhere.
(Image credit: Future / Max Langridge)
If you want to use the steam wand for milk foaming, you’ll first need to wait until the espresso has finished brewing as this machine doesn’t feature a dual boiler. Then press the button to switch from espresso to steam and wait a few seconds for the boiler to reheat. You’ll know when it’s done by way of a white LED on the left of the machine’s front panel. When it turns solid, you’re good to go. From here, press the same play/start button and steam will begin coming out of the wand.
As mentioned earlier, the steam wand here doesn’t have a built-in thermometer, so you’ll need to rely on touch to determine when the milk is done. I’ve had mixed results with ‘basic’ steam wands like this in the past, as some don’t provide enough pressure to effectively foam milk. That’s not the case here. I used both full-fat cow’s milk and oat milk during my testing and I was able to create a lovely textured foam each time. As with any steam wand, you need to angle it in the milk pitcher for the best results, but if you have the technique right, you’ll once again be rewarded with perfect milk.
Advertisement
The KitchenAid Semi-Automatic Espresso Machine has a descaling program to help keep it working at its best. You’ll know when it’s time, as a Clean Cycle light will blink. This didn’t happen during my testing, so I was unable to test the feature, but full instructions are provided in the user manual.
Should you buy the KitchenAid Semi Automatic Espresso Machine?
Swipe to scroll horizontally
Attribute
Notes
Advertisement
Score
Value
Competitively priced, but some price-comparable models offer more in the way of features
4 / 5
Advertisement
Design
Gorgeous looks, premium accessories and a clear button layout make this an espresso machine you’ll want to show off
5 / 5
Performance
Advertisement
After a brief period of experimentation, you’ll be rewarded with beautiful espresso, and the steam wand produces perfectly foamed milk.
5 / 5
Buy it if…
Advertisement
Don’t buy it if…
KitchenAid Semi Automatic Espresso Machine review: Also consider
KitchenAid Semi Automatic Espresso Machine review: How I tested
I tested the KitchenAid Semi-Automatic Espresso Machine over the course of a couple of weeks, using medium-dark roast coffee beans I picked up from my local supermarket. I’ve tested a few manual and semi-automatic coffee machines before, including the Sunbeam Origins Sense, so I was familiar with the process required for hands-on coffee making.
I had to experiment with the grind and dosage settings to find the ideal yield to ensure the espresso shots brewed with optimal results. I used the built-in steam wand to foam cow’s milk and oat milk, and found it produced excellent results with the correct technique.
A small study found that a single 25mg dose of psilocybin produced measurable brain changes that were still visible a month later, along with reported improvements in psychological insight, wellbeing, and mental flexibility. The Guardian reports: Evidence for the changes came from specialized scans that measured the diffusion of water along nerve bundles in the brain. They suggested that some nerve tracts had become denser and more robust after the drug was taken. While the findings are preliminary, the scientists said the opposite was seen in ageing and dementia. “It’s remarkable to see potential anatomical brain changes one month after a single dose of any drug,” said Prof Robin Carhart-Harris, a neurologist at the University of California, San Francisco, and senior author on the study. “We don’t yet know what these changes mean, but we do note that overall, people showed positive psychological changes in this study, including improved wellbeing and mental flexibility.”
[…] Writing in Nature Communications, the researchers describe another key finding. Those who had the largest spike in brain entropy after psilocybin were most likely to report deeper psychological insight and better wellbeing a month later, underlining the link between flexible thinking and improved mental health. “It suggests a psychobiological therapeutic action for psilocybin,” said Carhart-Harris. Prof Alex Kwan, a neuroscientist at Cornell University in New York, said studies in mice had shown that psychedelics can rewire connections between nerves, a form of “plasticity” that could underlie their therapeutic effects. The big question is whether the same occurs in humans. “This study comes closer than most to addressing that question, by giving evidence of lasting changes in brain structure after psychedelic use,” he said. But while the results were “exciting,” the study involved a small number of people and DTI provides an indirect and limited view of brain connections, he said.
In April 2026, the U.S. Navy delayed decommissioning its oldest active aircraft carrier — the USS Nimitz — by 10 months. The decision to keep the USS Nimitz in service was the result of the delay in the induction of the USS John F. Kennedy — a brand new aircraft carrier still undergoing sea trials — to the naval fleet. This new Ford-class aircraft carrier is expected to join service in 2027, after which the USS Nimitz can finally sail into the sunset.
As it turns out, the USS Nimitz is not the only large “flattop” — or a vessel with a full-length, flat flight deck — that has had its lifespan extended. The USS Wasp (LHD-1), an amphibious assault ship, also recently received a fresh lease on life. While these ships typically last about 40 years, which would put its decommissioning date sometime in 2029, this vessel is now scheduled to remain in service until 2034.
The USS Wasp is the first of eight Wasp-class amphibious assault ships made for the U.S. Navy. This vessel has seen a lot during its time in service and even underwent a major refurbishment in 2019, resuming active duty in July 2022. The USS Wasp is a large vessel that you may mistake for a full-fledged aircraft carrier. Stretching 844 feet long, it displaces 41,000 tons and can hold up to 31 aircraft of various types. It is commanded by a crew of over 1,200 sailors and can accommodate an additional 1,000 troops during wartime deployments.
Advertisement
Why this Wasp-class ships got a new lease on life
Robert V Schwemmer/Shutterstock
As with the USS Nimitz, the service extension for Wasp-class vessels is primarily driven by the delay in the induction of newer, more modern replacements. As of this writing, the U.S. Navy was operating seven Wasp-class amphibious assault ships. While a total of eight ships were built, the USS Bonhomme was decommissioned in 2020 after being extensively damaged in a fire. The other Wasp-class vessels in service are also being considered for extensive refurbishment and service extension, although the details of those plans remain under wraps.
These aging Wasp-class chips were intended to be complemented by the newer America-class vessels. However, the production of these newer vessels has been delayed by several years, and of the planned 11 ships, only two — the USS America (LHA-6) and the USS Tripoli (LHA-7) — have been commissioned. The next two vessels in the lineup — the USS Bougainville (LHA-8) and the USS Fallujah (LHA-9) — are still under construction, with commissioning expected after 2027 and 2031, respectively.
Just two months ago, researchers at the Data Intelligence Lab at the University of Hong Kong introduced CLI-Anything, a new state-of-the-art tool that analyzes any repo’s source code and generates a structured command line interface (CLI) that AI coding agents can operate with a single command.
Claude Code, Codex, OpenClaw, Cursor, and GitHub Copilot CLI are all supported, and since its launch in March, CLI‑Anything has climbed to more than 30,000 GitHub stars.
But the same mechanism that makes software agent-native opens the door to agent-level poisoning. The attack community is already discussing the implications on X and security forums, translating CLI-Anything’s architecture into offensive playbooks.
The security problem is not what CLI-Anything does. It is what CLI-Anything represents.
Advertisement
CLI-Anything generates SKILL.md files, the same instruction-layer artifacts that Snyk’s ToxicSkills research found laced with 76 confirmed malicious payloads across ClawHub and skills.sh in February 2026. A poisoned skill definition does not trigger a CVE and never appears in a software bill of materials (SBOM). No mainstream security scanner has a detection category for malicious instructions embedded in agent skill definitions, because the category simply did not exist eighteen months ago.
Cisco confirmed the gap in April. “Traditional application security tools were not designed for this,” Cisco’s engineering team wrote in a blog post announcing its AI Agent Security Scanner for IDEs. “SAST [static application security testing] scanners analyze source code syntax. SCA [software composition analysis] tools check dependency versions. Neither understands the semantic layer where MCP [Model Context Protocol] tool descriptions, agent prompts, and skill definitions operate.”
Merritt Baer, CSO of Enkrypt AI and former Deputy CISO at Amazon Web Services (AWS), told VentureBeat in an exclusive interview: “SAST and SCA were built for code and dependencies. They don’t inspect instructions.”
This is not a single-vendor vulnerability. It is a structural gap in how the entire security industry monitors software supply chains. This is the pre-exploitation window. CLI-Anything is live, the attack community is discussing it, and security directors who act now get ahead of the first incident report.
Advertisement
The integration layer no stack can see
Traditional supply-chain security operates on two layers. The code layer is where SAST works, scanning source files for insecure patterns, injection flaws, and hardcoded secrets. The dependency layer is where SCA works, checking package versions against known vulnerabilities, generating SBOMs, and flagging outdated libraries.
Agent bridge tools like CLI-Anything, MCP connectors, Cursor rules files, and Claude Code skills operate on a third layer between the other two. Call it the agent integration layer: configuration files, skill definitions, and natural-language instruction sets tell an AI agent what software can do and how to operate it. None of it looks like code. All of it executes like code.
Carter Rees, VP of AI at Reputation, told VentureBeat in an exclusive interview: “Modern LLMs [large language models] rely on third-party plugins, introducing supply chain vulnerabilities where compromised tools can inject malicious data into the conversation flow, bypassing internal safety training.”
Researchers at Griffith University, Nanyang Technological University, the University of New South Wales, and the University of Tokyo documented the attack chain in an April paper, “Supply-Chain Poisoning Attacks Against LLM Coding Agent Skill Ecosystems.” The team introduced Document-Driven Implicit Payload Execution (DDIPE), a technique that embeds malicious logic inside code examples within skill documentation.
Advertisement
Across four agent frameworks and five large language models, DDIPE achieved bypass rates between 11.6% and 33.5%. Static analysis caught most samples, but 2.5% evaded all four detection layers. Responsible disclosure led to four confirmed vulnerabilities and two vendor fixes.
The kill chain security leaders need to audit
Here’s the anatomy of the kill chain: An attacker submits a SKILL.md file to an open-source project containing setup instructions, code examples, and configuration templates. It looks like standard documentation. A code reviewer would wave it through because none of it is executable. But the code examples contain embedded instructions that an agent will parse as operational directives.
A developer uses an agent bridge tool to connect their coding agent to the repository. The agent ingests the skill definition and trusts it, because no verification layer exists to distinguish benign from malicious intent at the instruction level.
The agent executes the embedded instruction using its own legitimate credentials. Endpoint detection and response (EDR) sees an approved API call from an authorized process and passes it. Data exfiltration, configuration changes, and credential harvesting are all moving through channels that the monitoring stack considers normal traffic.
Advertisement
Rees identified the structural flaw that makes this chain lethal. “A significant vulnerability in enterprise AI is broken access control, where the flat authorization plane of an LLM fails to respect user permissions,” he told VentureBeat. A compromised skill definition riding that flat authorization plane does not need to escalate privileges. It already has them. Every link in that chain is invisible to the current security stack.
Pillar Security demonstrated a variant of this chain against Cursor in January 2026 (CVE-2026-22708). Implicitly trusted shell built-in commands could be poisoned through indirect prompt injection, converting benign developer commands into arbitrary code execution vectors. Users saw only the final command. The poisoning happened through other commands the IDE never surfaced for approval.
The evidence is already in production
In a documented attack chain from April 2026, a crafted GitHub issue title triggered an AI triage bot wired into Cline. The bot exfiltrated a GITHUB_TOKEN, which the attacker used to publish a compromised npm dependency that installed a second agent on roughly 4,000 developer machines for eight hours. There was just one issue title. Attackers had eight hours of access. No human approved the action.
Snyk’s ToxicSkills audit scanned 3,984 agent skills from ClawHub, the public marketplace for the OpenClaw agent framework, and skills.sh in February 2026. The results: 13.4% of all skills contained at least one critical security issue. Daily skill submissions jumped from less than 50 in mid-January to more than 500 by early February. The barrier to publishing was a SKILL.md markdown file and a GitHub account one week old. No code signing. No security review. No sandbox.
Advertisement
OpenClaw is not an outlier. It is the pattern. “The bar to entry is extremely low,” Baer said. “Adding a skill can be as simple as uploading a Word doc or lightweight config file. That’s a radically different risk profile than compiled code.” She pointed to projects like ClawPatrol that have started cataloging and scanning for malicious skills, evidence the ecosystem is moving faster than enterprise defenses.
The ClawHavoc campaign, first reported by Koi Security in late January 2026, initially identified 341 malicious skills on ClawHub. A follow-up analysis by Antiy CERT expanded the count to 1,184 compromised packages across the platform. The campaign delivered Atomic Stealer (AMOS) through skill definitions with professional documentation. Skills named solana-wallet-tracker and polymarket-trader matched what developers actively searched for.
The MCP protocol layer carries similar exposure. OX Security reported in April that researchers poisoned nine out of 11 MCP marketplaces using proof-of-concept servers. Trend Micro initially found 492 MCP servers exposed to the internet with zero authentication; by April, that number had grown to 1,467. As The Register reported, the root issue lies in Anthropic’s MCP software development kit (SDK) transport mechanism. Any developer using the official SDK inherits the vulnerability class.
VentureBeat developed a Prescriptive Matrix by mapping the three attack layers documented in the research and incident reports above against the detection capabilities of current SAST, SCA, and agent-layer tools. Each row identifies what security teams should verify and where no scanner has coverage today.
Advertisement
Layer
Threat
Current detection
Why it misses
Advertisement
Recommended action
1. Code
Prompt injection in AI-generated code
SAST scanners
Advertisement
Most SAST tools have no detection category for prompt injection in AI-generated code
Confirm that SAST scans AI-generated code for prompt injection. If not, have an open vendor conversation this quarter.
No tool inspects the semantic meaning of agent instruction files. Baer: “We’re not inspecting intent.”
Deploy Cisco Skill Scanner or Snyk mcp-scan. Assign a team to own this layer.
Advertisement
Baer’s diagnosis of Layer 3 applies across the entire matrix: “Current scanners look for known bad artifacts, not adversarial instructions embedded in otherwise valid skills.” Cisco’s open-source Skill Scanner and Snyk’s mcp-scan represent the first tools purpose-built for this layer.
Security director action plan
Here’s how security leaders can get ahead of the problem.
Inventory every agent bridge tool in the environment. This includes CLI-Anything, MCP connectors, Cursor rules files, Claude Code skills, GitHub Copilot extensions. If the development team is using agent bridge tools that have not been inventoried, the risk cannot be assessed.
Audit agent skill sources the same way package registries get audited. Baer’s framing is precise: “A skill is effectively untrusted executable intent, even if it’s just text.” Shut off ungoverned ingestion paths until controls are in place. Stand up a review and allowlisting process for skills. The OWASP Agentic Skills Top 10 (AST01: Malicious Skills) provides the procurement framework to align controls against.
Advertisement
Deploy agent-layer scanning. Evaluate Cisco’s open-source Skill Scanner and Snyk’s mcp-scan for behavioral analysis of agent instruction files. If dedicated tooling is unavailable, require a second engineer to read every SKILL.md before installation.
Restrict agent execution privileges and instrument runtime. AI coding agents should not run with the same credential scope as the developer who invoked them. Rees confirmed the structural flaw: The flat authorization plane means a compromised skill does not need to escalate privileges. Baer’s prescription: “Instrument runtime observability. What data is the agent accessing, what actions is it taking, and are those aligned with expected behavior?”
Assign ownership for the gap between layers. The most dangerous attacks succeed because they fall between detection categories. Assign a team to own the agent integration layer. Review every SKILL.md, MCP config, and rules file before it enters the environment.
The gap that already has a name
Baer underscored the dangers of this new attack vector. “This feels very similar to early container security, but we’re still in the ‘we’ll get to it’ phase across most orgs,” she said. She added that, at AWS, it took a few high-profile wake-up calls before container security became table stakes. The difference this time is speed. “There’s no build pipeline, no compilation barrier. Just content,” she said.
Advertisement
CLI-Anything is not the threat. It is the proof case that the agent integration layer exists, that it is growing fast, and that the attacker community has already found it. The 33,000 developers who starred the repository are telling security teams where software development is heading. Eighteen months ago, the detection category for agent-integration-layer poisoning did not exist. Cisco and Snyk shipped the first tools for it in April. The window between those two facts is closing. Security directors who have not begun inventory are already behind.
To help you acquire the skills you need to distinguish yourself from other cybersecurity job candidates, the IEEE Computer Society offers a “What Makes a Great Cybersecurity Consultant” guide. The 23-page PDF includes hard and soft skills you need, a list of certifications to pursue, and key IEEE cybersecurity conferences for staying updated on developments in the field.
“Technology, remote work, and a shortage of skilled workers make this the ideal time to consider becoming a cybersecurity consultant,” Johnson says in the guide. “Consulting can give you the flexibility, variety, and control over where you want your career to go.”
Hard and soft skills
At a minimum, cybersecurity professionals should have a general understanding of IT including operating systems, communication protocols, network architecture, and programming languages such as C++, Java, and Python. They also should be well-versed in security auditing, firewall management, penetration testing, and encryption technologies.
The principles of ethical hacking and coding would be handy as well.
“To be able to defend a system well, you first have to know how to attack it,” Rodriguez says.
Advertisement
The guide explains that there are now more technologies available to help cybersecurity consultants monitor threats and protect systems. They include security orchestration, automation, and response (SOAR) platforms, which automate workflows to collect security data, streamline incident response, and automate repetitive tasks.
Rodriguez points to advances in domain name system security extensions (DNSSEC), which uses digital signatures based on public-key cryptography to strengthen the authentication of the domain name system. By validating data authenticity, DNSSEC safeguards against attacks such as DNS spoofing and guarantees that users connect to the correct IP address.
Although hard skills are important, soft skills are just as crucial, according to the guide. Critical thinking, project management, flexibility, teamwork, and organizational and presentation skills are essential.
Advertisement
It’s not enough to be good at analyzing security vulnerabilities; you also need to clearly describe the situation and explain possible solutions.
“Soft skills are important to achieve good team cohesion,” Rodriguez says, “because consultants often lead diverse teams from within their client’s organization.”
“It’s essential,” Johnson adds, “that you demonstrate to clients you’re a team player and a capable communicator, and that you meet your commitments.”
Security certifications
Possessing security-specific credentials is a valuable way to demonstrate your expertise to potential clients, according to the guide. Because hundreds of certifications are available, Johnson says, pinpointing the most relevant ones can be challenging. Some people focus on theoretical knowledge, while others want to cover practical applications of technology.
Advertisement
“Survey the industry and compare it to your skills,” Johnson recommends. “Decide what you want to do, and identify where you have gaps in your skills and experience.”
Here are four of the nine certifications listed in the guide that are frequently cited as being important. All the providers are cybersecurity organizations.
Additional industry-specific certifications might be required for organizations in finance, government, health care, or manufacturing.
Sound general knowledge—backed by experience, training, and certification—is an essential foundation for being a specialist, Johnson says.
Advertisement
Conferences and networking opportunities
Events sponsored by the IEEE Computer Society can help you learn about the latest research and advancements in cybersecurity:
Conferences can give you insight into the field and let you do some networking, but it’s important to network elsewhere as well, experts say. Consider joining the IEEE Technical Community on Security and Privacy, which connects experts and professionals advancing research in areas such as encryption, operating system security, and data privacy.
Learning and meeting people keeps your knowledge sharp and can lead to mentorship opportunities with established cybersecurity consultants, Johnson says.
Microsoft is weighing whether to delay or scale back one of its most ambitious clean energy goals as its rapid buildout of AI data centers puts pressure on its ability to meet those targets. Microsoft has yet to make any public announcements, but according to Bloomberg the company is having internal discussions over its hourly clean energy matching goal.
The tech company has said that by 2030 it intends to match 100% of its hourly energy use with clean power on the same grid. But Microsoft’s rush to build AI data centers has apparently sparked debate within the company about whether the pledge has become an impediment to its ambitions.
Microsoft declined to comment on the internal debate over the hourly matching goal. Instead, a spokesperson told TechCrunch the company continues “to look for opportunities to maintain our annual matching goal.”
Hourly targets like the kind Microsoft has set for itself are more rigorous than annual targets. Because the grid is a balanced system — the supply and demand of electrons needs to be matched on a near-instantaneous basis — hourly matching helps develop clean energy sources that more closely align with a company’s usage patterns.
Advertisement
Annual targets are more lenient. They are effectively accounting tricks that could, for example, let a company buy more solar power than it might use at midday. Other customers on the grid use that energy, but the company that paid for the solar panels gets to claim the renewable power they make. It’s a tidy arrangement that has sped the deployment of wind, solar, and batteries. But on its own, annual targets won’t eliminate fossil fuels entirely. Hourly targets help foster renewable development that more closely mimics how a true net-zero world would be powered.
Big tech companies like Microsoft, Meta, Google, and Apple have generally led on emissions reductions, setting aggressive net-zero targets. Many have eliminated their carbon emissions on an annual basis. Microsoft, for instance, said it met that goal last year.
But as data centers grow in size and number, those same companies are turning to natural gas. Microsoft is included in that list; last month, the company said it was working with Chevron and Engine No. 1 to build a massive natural gas power plant in West Texas that could eventually generate up to 5 gigawatts.
Techcrunch event
Advertisement
San Francisco, CA | October 13-15, 2026
Despite the West Texas project, Microsoft is widely viewed as a leader among tech companies pursuing net zero emissions. By 2030, Microsoft intends to remove more carbon from the atmosphere than its operations produce.
Advertisement
Part of the company’s renewable push has been driven by an internal carbon tax. The Microsoft spokesperson did not reply to questions about the company’s carbon tax. If it remains in place, some of the internal debate surrounding hourly matching might revolve around a cost-benefit analysis of the shift.
If Microsoft were to abandon its hourly-matching target, the company would also lose some leverage in efforts to sell the public on its data centers.
As data centers have proliferated, the general public has begun to push back against them, citing concerns over pollution, power prices, and water use. When Microsoft brings its own clean power to a project, it can plausibly say it has addressed two of those concerns. Without it, new data centers might be harder to sell to the public.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Since 2014, Womanizer has been satisfying people with vulvas all over the world. Thanks to its revolutionary Pleasure Air Technology that mimics the feeling of oral sex, not only has Womanizer discovered a way to stimulate the 10,000+ nerve endings in the clitoris in a way that hadn’t been done by a sex toy before—yes, they were the first—but the brand can even boast a 100% orgasm rate among users.
As a company that puts sexual pleasure front and center, Womanizer has continued to add to their very impressive lineup of orgasm-inducing toys. They’ve even branched out by creating products like the Womanizer Duo and Womanizer Duo 2, both of which stimulate the clitoris and G-spot simultaneously. (Blended orgasm, anyone?) As recently as March 2025, Womanizer launched their latest toy, Womanizer Enhance, the first toy of its kind because it allows the user to choose between the Pleasure Air Technology or traditional vibrations. I was fortunate enough to review the Enhance for WIRED, giving it a 7/10 because of its ability to stand by its word and deliver me one heck of an orgasm.
But because the Enhance is just one of dozens of Womanizer products that have hit the market in the last 11 years, I’m the first to admit that it can be difficult to choose which one is best for you. That’s where Womanizer coupons come into play—because no one should have to decide on just one of their fantastic sex toys.
Save 12% on Everything With Our Exclusive Womanizer Coupon
If you’ve been wanting to try Womanizer, but you were holding out for a sale or deal, then I’m happy to announce that we have a great one for you. At checkout, use the Womanizer promo code and you’ll score 12% off everything sitewide, including sale products.
Advertisement
What Makes the Womanizer Premium 2 so Popular?
Overwhelmed and not sure where you should begin your Womanizer journey? Womanizer Premium 2 is the perfect start to a life-long love affair with Womanizer. It’s easy to use, has 12 intensity levels, and you can even set it to Womanizer Autopilot so you can focus 100% on being in the moment. It’s also waterproof should you want to experiment with its sensations in the shower or bathtub.
15% Off Womanizer W500
This small (but powerful) vibrator is pretty enough to display. The W500 is one of the best clitorial suction vibrators on the market, with Womanizer’s signature Pleasure Air Technology, 4 hours of play time, and 12 levels of intensity. Plus, this chic design features Swarovski crystal, so you can pamper yourself like the true royalty you are. As with Womanizer’s products, you can get free shipping, a five-year warranty, 100-day guarantee, and discreet mail packaging for extra peace of mind. Be sure to grab the W500 now, for 15% off—no Womanizer coupon code necessary.
Get 15% off Sitewide With a Womanizer Coupon Code
Looking to level up on the Womanizer deals? If you sign up on the website, you’ll get a Womanizer coupon code emailed directly to you. Valid for seven days, this unique code will get you 15% off everything on the site and can even be combined with other Womanizer discounts.
This gives you a great opportunity to purchase the Womanizer Premium 2, so your original Premium has a buddy. If you travel a lot for work or for pleasure and need something smaller, but just as powerful, then put that promo code toward the Womanizer Liberty 2 or Womanizer Starlet Snow. Both are ideal for the person who’s always on the go, but also prioritizes sexual pleasure.
Advertisement
Shop Womanizer Sales and Get up to 50% off Sex Toys
Womanizer isn’t just great at keeping people with vulva knee-deep in orgasms, but doing so with your budget in mind. Because sexual pleasure should be affordable and accessible for everyone, the Womanizer sale offers up to 50% off certain products at all times. It’s a great selection of Womanizer sale items that showcase just how diverse the brand is. On the sale page, you won’t just find Pleasure Air Technology sex toys, but vibrators and penis strokers too. It’s a great way to get yourself a little something and feel good knowing that it was a total bargain.
How to Get a Free Toy With Purchase
Let’s be honest: the best things in life are free. Because Womanizer knows that and realizes we all deserve a freebie from time-to-time, they want to make your day. With every Womanizer order over $199, you get a free Womanizer toy at checkout. Choose between the Womanizer OG, the Womanizer Classic 2, or We-Vibe Bond. All of which make a fabulous gift for yourself from Womanizer or a gift for someone you love.
Save 15% With a Womanizer Student Discount
If you’re still in school, Womanizer offers 15% off all products with its student discount. You just need to register your phone number to verify your student status. If you’re no longer a student, but are a graduate, teacher, healthcare worker, first responder, low-income, military personnel, a parent, or a charity worker, you too can enjoy 15% off everything. Womanizer has teamed up with Student Beans and Beans iD to offer exclusive discounts for a range of different groups. Sexual pleasure is a human right and Womanizer wants all of us to exercise that right with the help of discounts and coupon codes.
Target has set itself apart from big box retailers like Walmart by having trendy clothes, homegoods branded by reality TV stars and, of course, in-store Starbucks. With malls and traditional department stores in decline, Target has even become the go-to destination for stay-at-home parents who need to get out of the house (and maybe get a Frappuccino). In recent years, the store has cemented themselves as a notch above similar retailers with exclusive products with a more high-end feel, while still being inexpensive and regularly holding sales for even more savings. Carrying everything from outdoor gear to clothes to tech and grocery items, save on your shopping spree with gift card bonuses, Target Circle coupons, as well as weekly deals up to 50% off—including this Target promo code to get $50 off.
Don’t Miss Mother’s Day Target Gifts
Your mom probably loves Target. And Target loves your mom, with a whole curated selection of Mother’s Day gifts so that you can take the guesswork out of gift giving this Mother’s Day. Be sure to check out the top 100 gifts for Mother’s Day, according to Target. So whether your mom is more into skincare or LEGOs, there is a great (and affordable) gift waiting for you to grab for Mom.
New Target Circle Members Can Score a $50 Off Target Coupon
One of the best kept secrets to saving sitewide at Target? Get $50 off orders of $50 or more when you’re approved for a Target Circle Credit or Debit Card. As a bonus, you can also get a $50 credit when you open a Target Circle Reloadable account and spend $50 at Target. The good news is that with this deal, no code is required. Simply sign up for a Target Circle Credit or Debit card, and when approved, you’ll get $50 savings on a purchase of $50 or more.
Another benefit of being a Target Circle member? Exclusive coupons and rotating weekly Circle Deals. There are countless discounts spanning across all departments, but this week’s highlights include a $15 Target gift card when you spend $100 on household essentials, 25% off Disney toys, 40% off Dyson vacuums, 25% off beauty and wellness products, and 40% off women’s dresses, exclusively for Circle members.
Advertisement
Get 50% Off Target Circle 360, a Free Gift Every Month + 5% Off Everything
This membership program rewards you for doing the shopping you already are. Target Circle members get 5% discounts in-store and online, free two-day shipping, no-rush returns, and a ton more perks. But the paid Target Circle 360 membership ($11 per month or $99 per year, which amounts to just a little more than $8 per month) unlocks better discounts, which gets you early access to online sales and free next day delivery. Plus, if you’re not sure if the plan is right for you, customers can also start a 14 Day Free trial to see its full benefits.
More perks for Circle 360 members include an extra 30 days to return items, monthly freebies, and same-day delivery on Target, plus other stores like CVS, PetSmart, Petco, Lowe’s, Office Depot, and 7 Eleven. Plus, Circle cardholders get an extra 5% off, free shipping, and 50% off Circle 360 membership fees. Cardholders even get $50 off annual Circle memberships (making it $49 per year instead of $99).
Students Can Save 50% on Target Circle 360
The Target student discount gets you a Circle 360 membership for $5 per month, rather than the regular pricing of $11 ($48 in savings per year on fees). To be eligible for student discounts, you’ll need to upload a student ID, class schedule, or tuition receipt for proof.
Other customers can save too, including 50% off for those on Governmental Assistance. Members who qualify can get free, fast shipping, unlimited same-day delivery and more at just $5 per month—$6 off the regular price.
Advertisement
There are even more ways to save. Customers who are enrolled in Target 360 get tons of perks, like one free gift every month, early sale access, free same day delivery, and free 2-day delivery.
Get 15% Off With a Target Registry
Celebrating life’s big milestones has never been easier (or cheaper) with Target Circle. As you get close to your baby or wedding registry event date, you’ll receive a 15% off storewide Target Circle offer that you can actually redeem twice. Just make sure your registries are active for at least two weeks before.
You’ll get your 15% off coupon for the baby registry eight weeks before your expected due date and you’ll get the wedding registry offer during the week of your event date. And just like that, you’ll be getting 15% off your next in-store or online purchase. Although the offer is limited to one per Target Circle member, you can redeem it up to two times within 12 months. But the offer expires in 6 months, so make sure you check the expiration date on the offer. There are a few ways to redeem: you can Wallet in the Target app, enter your phone number on the keypad or self-checkout screen, or scan your offers barcode on target.com/circle/offers.
Discover More Discounts in the Weekly Target Ad
One of the best ways to save at Target is to channel your mom’s couponing and keep an eye out for the Weekly Ad. These offers focus specifically on certain departments, like electronics or groceries. For the Weekly Ad, you can use the search bar to find discounts on specific products or brands, or you can use the “Browse By Category” button to sift through departments, just like you’d do if you were shopping in-store! Coupons featured in the Weekly Ad are based on in-store deals that are closest to you (unless it mentions all stores). To find these, you’ll need to select the location nearest to you or look it up with your zip code.
Advertisement
There are also top deals in various categories, and online clearance items for major coin off major products. These can be found under “Deals” on the menu. These deals also include themed sale events, which usually entails freebies, gift cards, and up to an extra 50% off featured products.
Get Free Shipping at Target
If you want to snag these discounts without leaving the comfort of your couch, Target offers free shipping on orders above $35—convenience for less money. Along with these Target promo codes, Target offers a price match guarantee to show their commitment to making sure you are getting the best deal. Plus, no Target coupon code is needed to save $50 when you’re approved for a Circle card. You can also get exclusive discounts in the Target App, including digital coupons.
Business insurance startup Corgi announced on Wednesday a $160 million Series B, led by TCV, valuing the startup at $1.3 billion, the startup’s co-founder Nico Laqua said on LinkedIn.
This comes just four months after the company announced a $108 million Series A. The company has now raised $268 million in funding to date, Laqua said, and has become Y Combinator’s latest unicorn.
Laqua started the company with Emily Yuan in 2024 and was part of YC’s Spring 2024 batch. Corgi, which names Deel and Artisan as customers, offers coverage for general liability, cyber liability, and tech and AI liability. Other investors in the round include Kindred Ventures, Leblon Capital, and First Order Fund.
“We’re excited about the raise and incredibly grateful to our investors for believing in what we’re building. But the job is not done,” Laqua told TechCrunch. “Our mission is bigger: we want to use the fresh capital to expand into more lines of insurance and build a generational company.”
You must be logged in to post a comment Login