Connect with us
DAPA Banner

Tech

How Autonomous Drone Warfare Is Emerging in Ukraine

Published

on

WHEN KYIV-BORN ENGINEER Yaroslav Azhnyuk thinks about the future, his mind conjures up dystopian images. He talks about “swarms of autonomous drones carrying other autonomous drones to protect them against autonomous drones, which are trying to intercept them, controlled by AI agents overseen by a human general somewhere.” He also imagines flotillas of autonomous submarines, each carrying hundreds of drones, suddenly emerging off the coast of California or Great Britain and discharging their cargoes en masse to the sky.

“How do you protect from that?” he asks as we speak in late December 2025; me at my quiet home office in London, he in Kyiv, which is bracing for another wave of missile attacks.

Azhnyuk is not an alarmist. He cofounded and was formerly CEO of Petcube, a California-based company that uses smart cameras and an app to let pet owners keep an eye on their beloved creatures left alone at home. A self-described “liberal guy who didn’t even receive military training,” Azhnyuk changed his mind about developing military tech in the months following the Russian invasion of Ukraine in February 2022. By 2023, he had relinquished his CEO role at Petcube to do what many Ukrainian technologists have done—to help defend his country against a mightier aggressor.

It took a while for him to figure out what, exactly, he should be doing. He didn’t join the military, but through friends on the front line, he witnessed how, out of desperation, Ukrainian troops turned to off-the-shelf consumer drones to make up for their country’s lack of artillery.

Advertisement

Ukrainian troops first began using drones for battlefield surveillance, but within a few months they figured out how to strap explosives onto them and turn them into effective, low-cost killing machines. Little did they know they were fomenting a revolution in warfare.

Group observes a drone demonstration indoors, with a presenter explaining features.

Compact black camera module with textured surface and orange ribbon cable on white background.The Ukrainian robotics company The Fourth Law produces an autonomy module [above] that uses optics and AI to guide a drone to its target. Yaroslav Azhnyuk [top, in light shirt], founder and CEO of The Fourth Law, describes a developmental drone with autonomous capabilities to Ukrainian President Volodymyr Zelenskyy and German Chancellor Olaf Scholz.Top: THE PRESIDENTIAL OFFICE OF UKRAINE; Bottom: THE FOURTH LAW

That revolution was on display last month, as the U.S. and Israel went to war with Iran. It soon became clear that attack drones are being extensively used by both sides. Iran, for example, is relying heavily on the Shahed drones that the country invented and that are now also being manufactured in Russia and launched by the thousands every month against Ukraine.

A thorough analysis of the Middle East conflict will take some time to emerge. And so to understand the direction of this new way of war, look to Ukraine, where its next phase—autonomy—is already starting to come into view. Outnumbered by the Russians and facing increasingly sophisticated jamming and spoofing aimed at causing the drones to veer off course or fall out of the sky, Ukrainian technologists realized as early as 2023 that what could really win the war was autonomy. Autonomous operation means a drone isn’t being flown by a remote pilot, and therefore there’s no communications link to that pilot that can be severed or spoofed, rendering the drone useless.

By late 2023, Azhnyuk set out to help make that vision a reality. He founded two companies, The Fourth Law and Odd Systems, the first to develop AI algorithms to help drones overcome jamming during final approach, the second to build thermal cameras to help those drones better sense their surroundings.

Advertisement

“I moved from making devices that throw treats to dogs to making devices that throw explosives on Russian occupants,” Azhnyuk quips.

Since then, The Fourth Law has dispatched “more than thousands” of autonomy modules to troops in eastern Ukraine (it declines to give a more specific figure), which can be retrofitted on existing drones to take over navigation during the final approach to the target. Azhnyuk says the autonomy modules, worth around US $50, increase the drone-strike success rate by up to four times that of purely operator-controlled drones.

And that is just the beginning. Azhnyuk is one of thousands of developers, including some who relocated from Western countries, who are applying their skills and other resources to advancing the drone technology that is the defining characteristic of the war in Ukraine. This eclectic group of startups and founders includes Eric Schmidt, the former Google CEO, whose company Swift Beat is churning out autonomous drones and modules for Ukrainian forces. The frenetic pace of tech development is helping a scrappy, innovative underdog hold at bay a much larger and better-equipped foe.

All of this development is careening toward AI-based systems that enable drones to navigate by recognizing features in the terrain, lock on to and chase targets without an operator’s guidance, and eventually exchange information with each other through mesh networks, forming self-organizing robotic kamikaze swarms. Such an attack swarm would be commanded by a single operator from a safe distance.

Advertisement

According to some reports, autonomous swarming technology is also being developed for sea drones. Ukraine has had some notable successes with sea drones, which have reportedly destroyed or damaged around a dozen Russian vessels.

Hand holding a drone with six rotors, outdoors against a blue sky.The Skynode X system, from Auterion, provides a degree of autonomy to a drone.AUTERION

For Ukraine, swarming can solve a major problem that puts the nation at a disadvantage against Russia—the lack of personnel. Autonomy is “the single most impactful defense technology of this century,” says Azhnyuk. “The moment this happens, you shift from a manpower challenge to a production challenge, which is much more manageable,” he adds.

The autonomous warfare future envisioned by Azhnyuk and others is not yet a reality. But Marc Lange, a German defense analyst and business strategist, believes that “an inflection point” is already in view. Beyond it, “things will be so dramatically different,” he says.

“Ukraine pretty rapidly realized that if the operator-to-drone ratio can be shifted from one-to-one to one-to-many, that creates great economies of scale and an amazing cost exchange ratio,” Lange adds. “The moment one operator can launch 100, 50, or even just 20 drones at once, this completely changes the economics of the war.”

Advertisement

Drones With a View

For a while, jammers that sever the radio links between drones and operators or that spoof GPS receivers were able to provide fairly reliable defense against human-controlled first-person-view attack drones (FPVs). But as autonomous navigation progressed, those electronic shields have gradually become less effective. Defenders must now contend with unjammable drones—ones that are attached to hair-thin optical fibers or that are capable of finding their way to their targets without external guidance. In this emerging struggle, the defenders’ track records aren’t very encouraging: The typical countermeasure is to try to shoot down the attacking drone with a service weapon. It’s rarely successful.

Truck on rural road covered with camouflage netting, trees and fields in the background.A truck outfitted with signal-jamming gear drives under antidrone nets near Oleksandriya, in eastern Ukraine, on 2 October 2025.ED JONES/AFP/GETTY IMAGES

“The attackers gain an immense advantage from unmanned systems,” says Lange. “You can have a drone pop up from anywhere and it can wreak havoc. But from autonomy, they gain even more.”

The self-navigating drones rely on image-recognition algorithms that have been around for over a decade, says Lange. And the mass deployments of drones on Ukrainian battlefields are enabling both Russian and Ukrainian technologists to create huge datasets that improve the training and precision of those AI algorithms.

Six-wheeled robotic vehicle with mounted equipment in a grassy field.A Ukrainian land robot, the Ravlyk, can be outfitted with a machine gun.

While uncrewed aerial vehicles (UAVs) have received the most attention, the Ukrainian military is also deploying dozens of different kinds of drones on land and sea. Ukraine, struggling with the shortage of infantry personnel, began working on replacing a portion of human soldiers with wheeled ground robots in 2024. As of early 2026, thousands of ground robots are crawling across the gray zone along the front line in Eastern Ukraine. Most are used to deliver supplies to the front line or to help evacuate the wounded, but some “killer” ground robots fitted with turrets and remotely controlled machine guns have also been tested.

Advertisement

In mid-February, Ukrainian authorities released a video of a Ukrainian ground robot using its thermal camera to detect a Russian soldier in the dark of the night and then kill the invader with a round from a heavy machine gun. So far these robots are mostly controlled by a human operator, but the makers of these uncrewed ground vehicles say their systems are capable of basic autonomous operations, such as returning to base when radio connection is lost. The goal is to enable them to swarm so that one operator controls not one, but a whole herd of mesh-connected killer robots.

But Bryan Clark, senior fellow and director of the Center for Defense Concepts and Technology at the Hudson Institute, questions how quickly ground robots’ abilities can progress. “Ground environments are very difficult to navigate in because of the terrain you have to address,” he says. “The line of sight for the sensors on the ground vehicles is really constrained because of terrain, whereas an air vehicle can see everything around it.”

To achieve autonomy, maritime drones, too, will require navigational approaches beyond AI-based image recognition, possibly based on star positions or electronic signals from radios and cell towers that are within reach, says Clark. Such technologies are still being developed or are in a relatively early operational stage.

How the Shaheds Got Better

Russia is not lagging behind. In fact, some analysts believe its autonomous systems may be slightly ahead of Ukraine’s. For a good example of the Russian military’s rapid evolution, they say, consider the long-range Iranian-designed Shahed drones. Since 2022, Russia has been using them to attack Ukrainian cities and other targets hundreds of kilometers from the front line. “At the beginning, Shaheds just had a frame, a motor, and an inertial navigation system,” Oleksii Solntsev, CEO of Ukrainian defense tech startup MaXon Systems, tells me. “They used to be imprecise and pretty stupid. But they are becoming more and more autonomous.” Solntsev founded MaXon Systems in late 2024 to help protect Ukrainian civilians from the growing threat of Shahed raids.

Advertisement

Silhouette of a triangular drone flying in the sky.A Russian Geran-2 drone, based on the Iranian Shahed-136, flies over Kyiv during an attack on 27 December 2025.SERGEI SUPINSKY/AFP/GETTY IMAGES

First produced in Iran in the 2010s, Shaheds can carry 90-kilogram warheads up to 650 km (50-kg warheads can go twice as far). They cost around $35,000 per unit, compared to a couple of million dollars, at least, for a ballistic missile. The low cost allows Russia to manufacture Shaheds in high quantities, unleashing entire fleets onto Ukrainian cities and infrastructure almost every night.

The early Shaheds were able to reach a preprogrammed location based on satellite-navigation coordinates. Even one of these early models could frequently overcome the jamming of satellite-navigation signals with the help of an onboard inertial navigation unit. This was essentially a dead-reckoning system of accelerators and gyroscopes that estimate the drone’s position from continual measurements of its motions.

Silhouette of person with large equipment under a starry night sky.In the Donetsk Region, on 15 August 2025, a Ukrainian soldier hunts for Shaheds and other drones with a thermalimaging system attached to a ZU23 23-millimeter antiaircraft gun.KOSTYANTYN LIBEROV/LIBKOS/GETTY IMAGES

Ukrainian defense forces learned to down Shaheds with heavy machine guns, but as Russia continued to innovate, the daily onslaughts started to become increasingly effective.

Today’s Shaheds fly faster and higher, and therefore are more difficult to detect and take down. Between January 2024 and August 2025, the number of Shaheds and Shahed-type attack drones launched by Russia into Ukraine per month increased more than tenfold, from 334 to more than 4,000. In 2025, Ukraine found AI-enabling Nvidia chipsets in wreckages of Shaheds, as well as thermal-vision modules capable of locking onto targets at night.

Advertisement

“Now, they are interconnected, which allows them to exchange information with each other,” Solntsev says. “They also have cameras that allow them to autonomously navigate to objects. Soon they will be able to tell each other to avoid a jammed region or an area where one of them got intercepted.”

These Russian-manufactured Shaheds, which Russian forces call Geran-2s, are thought to be more capable than the garden variety Shahed-136s that Iran has lately been launching against targets throughout the Middle East. Even the relatively primitive Shahed-136s have done considerable damage, according to press accounts.

Those Shahed successes may accrue, at least in part, from the fact that the United States and Israel lack Ukraine’s long experience with fending them off. In just two days in early March, upward of a thousand drones, mostly Shaheds, were launched against U.S. and Israeli targets, with hundreds of them reportedly finding their marks.

One attack, caught on videotape, shows a Shahed destroying a radar dome at the U.S. navy base in Manama, Bahrain. U.S. forces were understood to be attempting to fend off the drones by striking launch platforms, dispatching fighter aircraft to shoot them down, and by using some extremely costly air-defense interceptors, including ones meant to down ballistic missiles. On 4 March, CNN reported that in a congressional briefing the day before, top U.S. defense officials, including Secretary of Defense Pete Hegseth, acknowledged that U.S. air defenses weren’t keeping up with the onslaught of Shahed drones.

Advertisement

Broken drone on soil, cylindrical container nearby.Russian V2U attack drones are outfitted with Nvidia processors and run computer-vision software and AI algorithms to enable the drones to navigate autonomously.GUR OF THE MINISTRY OF DEFENSE OF UKRAINE

Russia is also starting to field a newer generation of attack drones. One of these, the V2U, has been used to strike targets in the Sumy region of northeastern Ukraine. The V2U drones are outfitted with Nvidia Jetson Orin processors and run computervision software and AI algorithms that allow the drones to navigate even where satellite navigation is jammed.

The sale of Nvidia chips to Russia is banned under U.S. sanctions against the country. However, press reports suggest that the chips are getting to Russia via intermediaries in India.

Antidrone Systems Step Up

MaXon Systems is one of several companies working to fend off the nightly drone onslaught. Within one year, the company developed and battle-tested a Shahed interception system that hints at the sci-fi future envisioned by Azhnyuk. For a system to be capable of reliably defending against autonomous weaponry, it, too, needs to be autonomous.

MaXon’s solution consists of ground turrets scanning the sky with infrared sensors, with additional input from a network of radars that detects approaching Shahed drones at distances of, typically, 12 to 16 km. The turrets fire autonomous fixed-winged interceptor drones, fitted with explosive warheads, toward the approaching Shaheds at speeds of nearly 300 km/h. To boost the chances of successful interception, MaXon is also fielding an airborne anti-Shahed fortification system consisting of helium-filled aerostats hovering above the city that dispatch the interceptors from a higher altitude.

Advertisement

“We are trying to increase the level of automation of the system compared to existing solutions,” says Solntsev. “We need automatic detection, automatic takeoff, and automatic mid-track guidance so that we can guide the interceptor before it can itself flock the target.”

Gray drone on display stand, surrounded by military personnel in camouflage uniforms.An interceptor drone, part of the U.S. MEROPS defensive system, is tested in Poland on 18 November 2025.WOJTEK RADWANSKI/AFP/GETTY IMAGES

In November 2025, the Ukrainian military announced it had been conducting successful trials of the Merops Shahed drone interceptor system developed by the U.S. startup Project Eagle, another of former Google CEO Eric Schmidt’s Ukraine defense ventures. Like the MaXon gear, the system can operate largely autonomously and has so far downed over 1,000 Shaheds.

What Works in the Lab Doesn’t Necessarily Fly on the Battlefield

Despite the progress on both sides, analysts say that the kind of robotic warfare imagined by Azhnyuk won’t be a reality for years.

“The software for drone collaboration is there,” says Kate Bondar, a former policy advisor for the Ukrainian government and currently a research fellow at the U.S. Center for Strategic and International Studies. “Drones can fly in labs, but in real life, [the forces] are afraid to deploy them because the risk of a mistake is too high,” she adds.

Advertisement

Two people launching a drone in an open field using a catapult system.Ukrainian soldiers watch a GOR reconnaissance drone take to the sky near Pokrovsk in the Donetsk region, on 10 March 2025.ANDRIY DUBCHAK/FRONTLINER/GETTY IMAGES

In Bondar’s view, powerful AI-equipped drones won’t be deployed in large numbers given the current prices for high-end processors and other advanced components. And, she adds, the more autonomous the system needs to be, the more expensive are the processors and sensors it must have. “For these cheap attack drones that fly only once, you don’t install a high-resolution camera that [has] the resolution for AI to see properly,” she says. “[You install] the cheapest camera. You don’t want expensive chips that can run AI algorithms either. Until we can achieve this balance of technological sophistication, when a system can conduct a mission but at the lowest price possible, it won’t be deployed en masse.”

While existing AI systems are doing a good job recognizing and following large objects like Shaheds or tanks, experts question their ability to reliably distinguish and pursue smaller and more nimble or inconspicuous targets. “When we’re getting into more specific questions, like can it distinguish a Russian soldier from a Ukrainian soldier or at least a soldier from a civilian? The answer is no,” says Bondar. “Also, it’s one thing to track a tank, and it’s another to track infantrymen riding buggies and motorcycles that are moving very fast. That’s really challenging for AI to track and strike precisely.”

Clark, at the Hudson Institute, says that although the AI algorithms used to guide the Russian and Ukrainian drones are “pretty good,” they rely on information provided bysensors that “aren’t good enough.” “You need multiphenomenology sensors that are able to look at infrared and visual and, in some cases, different parts of the infrared spectrum to be able to figure out if something is a decoy or real target,” he says.

German defense analyst Lange agrees that right now, battlefield AI image-recognition systems are too easily fooled. “If you compress reality into a 2D image, a lot of things can be easily camouflaged—like what Russia did recently, when they started drawing birds on the back of their drones,” he says.

Advertisement

Autonomy Remains Elusive on the Ground and at Sea, Too

To make Ukraine’s emerging uncrewed ground vehicles (UGVs) equally self-sufficient will be an even greater task, in Clark’s view. Still, Bondar expects major advances to materialize within the next several years, even if humans are still going to be part of the decision-making loop.

Military radar equipment in a grassy field.A mobile electronic-warfare system built by PiranhaTech is demonstrated near Kyiv on 21 October 2025.DANYLO ANTONIUK/ANADOLU/GETTY IMAGES

“I think in two or three years, we will have pretty good full autonomy, at least in good weather conditions,” she says, referring to aerial drones in particular. “Humans will still be in the loop for some years, simply because there are so many unpredictable situations when you need an intervention. We won’t be able to fully rely on the machine for at least another 10 or 15 years.”

Ukrainian defenders are apprehensive about that autonomous future. The boom of drone innovation has come hand in hand with the development of sophisticated jamming and radio-frequency detection systems. But a lot of that innovation will become obsolete once the pendulum swings away from human control. Ukrainians got their first taste of dealing with unjammable drones in mid-2024, when Russia began rolling out fiber-optic tethered drones. Now they have to brace for a threat on a much larger scale.

Quadcopter drone flying with a fire extinguisher attached in a cloudy sky.An experimental drone is demonstrated at the Brave1 defense-tech incubator in Kyiv.DANYLO DUBCHAK/FRONTLINER/GETTY IMAGES

“Today, we have a situation where we have lots of signals on the battlefield, but in the near future, in maybe two to five years, UAVs are not going to be sending any signals,” says Oleksandr Barabash, CTO of Falcons, a Ukrainian startup that has developed a smart radio-frequency detection system capable of revealing precise locations of enemy radio sources such as drones, control stations, and jammers.

Advertisement

Last September, Falcons secured funding from the U.S.-based dual-use tech fund Green Flag Ventures to scale production of its technology and work toward NATO certification. But Barabash admits that its system, like all technologies fielded in Ukrainian war zones, has an expiration date. Instead of radio-frequency detectors, Barabash thinks, the next R&D push needs to focus on passive radar systems capable of identifying small and fast-moving targets based on the signal from sources like TV towers or radio transmitters that propagate through the environment and are reflected by those moving targets. Passive radars have a significant advantage in the war zone, according to Barabash. Since they don’t emit their own signal, they can’t be that easily discovered by the enemy.

“Active radar is emitting signals, so if you are using active radars, you are target No. 1 on the front line,” Barabash says.

Bondar, on the other hand, thinks that the increased onboard compute power needed for AI-controlled drones will, by itself, generate enough electromagnetic radiation to prevent autonomous drones from ever operating completely undetectably.

“You can have full autonomy, but you will still have systems onboard that emit electromagnetic radiation or heat that can be detected,” says Bondar. “Batteries emit electromagnetic radiation, motors emit heat, and [that heat can be] visible in infrared from far away. You just need to have the right sensors to be able to identify it in advance.” She adds that that takeaway is “how capable contemporary detection systems have become and how technically challenging it is to design drones that can reliably operate in the Ukrainian battlefield environment.”

Advertisement

There Will Be Nowhere to Hide from Autonomous Drones

When autonomous drones become a standard weapon of war, their threat will extend far beyond the battlefields of Ukraine. Autonomous turrets and drone-interceptor fortification might soon dot the perimeter of European cities, particularly in the eastern part of the continent.

Person holding gray drone against a blue sky, preparing to launch it.A fixed-wing drone is tested in Ukraine in April 2025.ANDREWKRAVCHENKO/BLOOMBERG/GETTY IMAGES

Nefarious actors from all over the world have closely watched Ukraine and taken notes, warns Lange. Today, FPV drones are being used by Islamic terrorists in Africa and Mexican drug cartels to fight against local authorities.

When autonomous killing machines become widely available, it’s likely that no city will be safe. “We might see nets above city centers, protecting civilian streets,” Lange says. “In every case, the West needs to start performing similar kinetic-defense development that we see in Ukraine. Very rapid iteration and testing cycles to find solutions.”

Azhnyuk is concerned that the historic defenders of Europe—the United States and the European countries themselves—are falling behind. “We are in danger,” he says. While Russia and Ukraine made major strides in their drones and countermeasures over the past year, “Europe and the United States have progressed, in the best-case scenario, from the winter-of-2022 technology to the summer-of-2022 technology.

Advertisement

“The gap is getting wider,” he warns. “I think the next few years are very dangerous for the security of Europe.”

This article appears in the April 2026 print issue as “Rise of the AUTONOMOUS Attack Drones.”

From Your Site Articles

Related Articles Around the Web

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

DIY UPS Keeps Home Assistant Running

Published

on

If you put a bunch of computers in charge of your house, it’s generally desirable to ensure their up-time is as close to 100% as possible. An uninterruptible power supply can help in this regard. To that end, that’s why [Bill Collis] whipped one up for his Home Assistant setup.

[Bill]’s UPS is charged with one job—keeping the Home Assistant Green hub and an Xfinity XB7 cable modem online when the grid goes dark. The construction is relatively straightforward. When the grid is up, everything is powered via a Mean Well AC-DC 12 V power supply, while the power is also used to charge a 12.8 V 10 Ah lithium iron phosphate battery pack. When the grid goes out, the system switches over to running the attached hardware on pure battery power. A Victron BatteryProtect is used to automatically disconnect the load if the battery voltage drops too low. Meanwhile, a Shelly Plus Uni module is used to monitor battery voltage and system status, integrated right into Home Assistant itself.

If you want to keep the basics of your smart home going at all times, something like this is a pretty simple way to go.  We’ve featured some other great UPS builds in the past, too. If you’re whipping up your own hardware to keep your home or lab alive in the dark of night, don’t hesitate to notify the tipsline.

Advertisement

Source link

Advertisement
Continue Reading

Tech

NIST to stop rating non-priority flaws due to volume increase

Published

on

NIST to stop rating non-priority flaws due to volume increase

The National Institute of Standards and Technology will stop assigning severity scores to lower-priority vulnerabilities due to the growing workload from rising submission volumes.

Starting April 15, the service will only analyze and provide additional details (e.g., severity rating, product lists) for security issues that meet specific criteria related to the risk they pose.

The National Vulnerability Database (NVD) will still list all submitted vulnerabilities, but those considered low priority will have a severity rating only from the CVE Numbering Authority (CNA) that evaluated and submitted it.

Wiz

In an announcement this week, the non-regulatory federal agency said it will only provide additional details for vulnerabilities that meet one of the following criteria:

  • are in CISA’s Known Exploited Vulnerabilities (KEV) catalog
  • affect the U.S. federal government software
  • involve critical software as per Executive Order 14028

NIST explained that the decision was driven by the large number of submissions, which grew by 263% recently and continued to accelerate in 2026. The organization enriched 42,000 CVEs in 2025, but it can no longer keep up with the increasing volume.

NIST NVD is a public, centralized database of known software and hardware vulnerabilities, which also provides additional descriptions and analyses on top of the unique identifiers (CVE IDs) assigned by CNAs, such as vendors and the not-for-profit The MITRE Corporation.

Advertisement

The point of enriching vulnerability details is to make CVE entries usable for risk management, including assigning severity scores, identifying affected product versions, classifying weaknesses, and providing links to advisories, patches, or related research.

NIST NVD is used universally by security researchers, software vendors, government agencies, IT professionals, journalists, and regular users seeking more information about a specific security issue.

“All submitted CVEs will still be added to the NVD. However, those that do not meet the criteria above will be categorized as “Not Scheduled,” explains NIST.

“This will allow us to focus on CVEs with the greatest potential for widespread impact. While CVEs that do not meet these criteria may have a significant impact on affected systems, they generally do not present the same level of systemic risk as those in the prioritized categories.”

Advertisement

NIST admits that the new rules allow some potentially high-impact CVE slip through. For this reason, the agency accepts enrichment requests for “any lowest priority CVEs” via email messages at ‘nvd@nist.gov.’

The lack of enrichment or notable delays was noticeable since 2024, but the organization has now formally declared that it will focus on the most important entries.

AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

Source link

Advertisement
Continue Reading

Tech

Building A Rim-Driven Jet Engine

Published

on

Rim-driven thrusters turn the normal propeller-motor arrangement inside out; rather than mounting the motor at the center of the propeller, they use a large hollow motor, with the blades attached to the inside of the rotor. They’re mostly used in ship propellers, though there have been some suggestions to use them in electric aircraft. [Integza], always looking for new and unusual ways to create propulsion, took this idea and made it into a jet engine.

Rather than using an electric motor, the fan in this design is propelled by miniature rocket nozzles along the edge. The fan levitates on a layer of high-pressure gas between the fan rim and the housing. To prevent too much pressurized gas from escaping, the fan and housing needed to fit together closely, but with minimal friction. A prototype made out of acrylic and resin and powered by compressed air proved that the idea worked, but [Integza] wanted to make to this a combustion-powered engine.

The full engine would be similar to a rocket engine, with the fan being the nozzle. The combustion chamber was built out of a brass fitting, and it burned propane in compressed air. The fan and housing were CNC-milled out of aluminium and brass, respectively. They worked well when powered with compressed air, but seized up when connected to the combustion chamber — the fan was thermally expanding and jamming in the housing. Progressively rounding down the edges of the fan failed to solve this, and a hole melted in the fan during one test. [Integza] machined a new fan, which he anodized to increase its heat resistance.

To keep it from overheating, he sprayed water into the combustion chamber, creating steam and cooling the exhaust stream to a manageable temperature. The engine did work, though we do wonder whether the fan actually increases its thrust over that of the base rocket engine.

Advertisement

This isn’t the first unconventional jet engine [Integza]’s built, nor the first which tries to amplify the thrust produced by a rocket engine.

Thanks to [Keith Olson] for the tip!

Advertisement

Source link

Continue Reading

Tech

Panic says the Playdate Catalog won’t accept games made with generative AI

Published

on

Panic, the company behind the tiny and excellent Playdate console, is taking a stand on generative AI. The company has published an AI disclosure that says as of this month, the Playdate Catalog “will no longer accept titles that use ‘Generative AI’ for art, audio, music, text, or dialog.” Panic does allow for developers to use AI assistance for coding, but also says that “we will flag any title as such and specify the extent that it was used (for example, “Lua debugging”) so the customer can decide whether to support it or not.”

This comes a day after Panic announced that Playdate season three was happening and would arrive later this year. For those who don’t recall, the Playdate includes a “season” worth of games when you buy it, 24 titles in total with two revealed every week. Season two came out last year with 12 games — but, as Game Developer notes, one of those games used generative AI for writing and coding. On Bluesky, someone asked Panic if it would disclose what games in season three used AI, and the company confirmed that it was a requirement for season three that developers not use AI for art, music, writing or coding.

Specifically, Panic says you can’t use large language models like ChatGPT or Google Gemini, AI image generators like Stable Diffusion or audio generators like MuseNet and Suno. Previously-approved games with generative AI will be allowed to stay on the catalog with a disclosure that indicates what exactly AI was used for. The company says these guidelines are “under constant discussion and is subject to change at any time.”

I recall seeing AI disclosures on games in the Playdate Catalog in the past, but it makes sense to be up-front and clear on exactly what Panic allows and what it will reject. That said, it’s fairly easy to sideload games onto a Playdate, so anyone who wants to use generative AI to make a game isn’t entirely out of luck — though distribution and discovery for Playdate owners will obviously be harder.

Advertisement

Source link

Continue Reading

Tech

Cyberpunk platformers, gallivanting geckos and other new indie games worth checking out

Published

on

Welcome to our latest roundup of what’s going on in the indie game space. Once again, there are some neat new games for you to check out this weekend. We’ve got a bunch of updates and announcements for upcoming titles to tell you about too.

There have been a bunch of solid indie showcases lately (and highlights from another one to tell you about below). If you want to learn about a ton of other games ASAP, you might want to set your alarm pretty early on April 25.

Starting at 5AM ET that day, the latest edition of Indie Life Expo takes place on YouTube, Twitch, TikTok, Bilibili and elsewhere. This one will feature more than 200 games! A rapid-fire Indie Waves segment will power through 160 of them. Organizers received 1,100 submissions for this installment, so hats off to them for featuring a sizable percentage of those.

Before that, you can check out another showcase on April 21. Top Hat Studios Presents: Spring Showcase 2026 will start at noon ET on the publisher’s YouTube and Twitch channels.

Advertisement

The stream will feature Motorslice, Well Dweller and survival horror game Becrowned, as well premieres and other Top Hat games. I’ve been looking forward to Motorslice, which has a May release window. I wager we’ll get a precise release date for that during this stream.

Meanwhile, there’s an interesting Steam event taking place soon. InterfaceX26 will run from April 27 until May 4. This one is focused on games that deal with made-up operating systems and other custom interfaces. Organizers have brought together more than 150 developers and publishers, who are asking Valve to introduce an official “Fake OS” tag for games on Steam.

Some neat games will be included in a sale and a showcase on May 2, including Blippo+, TR-49 and The Roottrees are Dead. Expect demos and relevant new releases too. Speaking of which…

New releases

We’ve been waiting a very long time for Replaced. This cyberpunk adventure from Sad Cat Studios and publisher Thunderful finally landed this week on Steam, GOG, Xbox on PC and Xbox Series X/S. It’s on Game Pass Ultimate and PC Game Pass. Otherwise, the base game costs $20. A supporter edition that includes the soundtrack is $25. It’ll hit the Epic Games Store at a later date.

Advertisement

The game was initially supposed to arrive in 2022. It certainly didn’t help that Sad Cat Studios was forced to relocate from Belarus to Cyprus after Russia’s invasion of Ukraine. But the game is finally here and it debuted to generally positive reviews.

Replaced is a 2.5D action platformer set in an alternate version of 1980s America, in which you play as an AI trapped in a human body that may or may not dream of electric sheep. I haven’t yet had a chance to properly jump into this gorgeous-looking game, but I’m hoping to do so this weekend.

Speaking of games I’ve long had on my wishlist, Gecko Gods arrived this week. I think I first clapped eyes on this around 2022. Various trailers charmed me with the idea of a puzzle exploration platformer that casts you in the role of a gecko that’s able to run along walls and ceilings.

I’ve played around 90 minutes of this one so far. I dig the look and the gecko is very cute (being able to customize its appearance is a nice touch). I love that you “collect” different types of bugs by eating them. It’s a fairly relaxing game, which is broadly what I need at the minute.

Advertisement

I think there are some issues here, though. I’ve explored two of the main five islands in the open world and it feels a bit sparse so far. The joy of being able to clamber up and around any object complicates things when it comes to more precise platforming sections. While the sailing sections are pretty, the boat is clunky to control on the choppy water. I ran into some mild technical issues as well on PS5 with occasional framerate dips and objects popping in. Hopefully, that’s something the developers at Inresin are able to address.

Gecko Gods — from publishers Super Rare Originals and Gamersky Games — is available now on Steam, PS5 and Nintendo Switch. It’s normally $20, but there’s a 10 percent launch discount until April 30 (on PS5, this only applies to PlayStation Plus members)

Another highly anticipated game landed this week in the form of Mouse: PI for Hire. We’ve had our eyes on this first-person shooter/detective game with sumptuous rubberhose-style animation for quite some time. Reviews have been generally positive so far, and it seems that there’s enough substance here to live up to those stellar visuals.

Mouse: PI for Hire — from Fumi Games and publisher PlaySide — is out now for $30. It’s available on PC, Nintendo Switch 2, PS5 and Xbox Series X/S.

Advertisement

Thirsty Suitors developer Outerloop Games and co-publisher Outersloth served up the cooking-themed Dosa Divas this week. It tells the story of two sisters who set out on a journey with their mech to take down a fast food empire and reconnect communities through cooking.

It caught my eye when I saw it during a showcase a while back and it has a great concept, though I don’t exactly love turn-based combat. I’ve read a few lukewarm reviews of the game, and the consensus seems to be that the cooking mechanics and combat perhaps needed some more time to simmer.

If you’d like to try Dosa Divas yourself, you can pick it up on Steam, Xbox Series X/S, PS5, Nintendo Switch and Switch 2. It’ll usually run you $20, but there’s a 10 percent launch discount until April 28.

If you’re looking for a puzzle game that can be relaxing or rather dark, depending on your mood, it might be worth checking out A Storied Life: Tabitha. As you pack up the home of a late loved one, you’ll need to decide which items to keep in the limited storage space you have and discard the rest. You’ll need to wrap fragile items in bubble wrap and vacuum pack soft items to save room in the boxes.

Advertisement

As you save items, you’ll unlock words that you can use to fill in the blanks of your loved one’s life and tell their story, Mad Libs-style. Given that you’ll find items like a blackmail letter and a shirt with lipstick on the collar, it seems like there’s a lot of variety to the kinds of stories you can tell.

A Storied Life: Tabitha is available on Steam now. It’ll normally run you $15, but you can save 10 percent if you buy it before April 28.

To round out this section, I’ll quickly note that Hades 2 is out now on PS5 and Xbox Series X/S for  $30, with a 20 percent launch discount. It’s on Game Pass Ultimate, Game Pass Premium and PC Game Pass too.

I bought Hades 2 when Supergiant Games brought it to Steam early access two years ago, telling myself I’d wait until the full game was out. But I still haven’t gotten around to it yet. There are always too many games tugging at my fragile attention span and Hades 2 faded into the background for me. I really ought to play it, I know!

Advertisement

Upcoming

I’m keeping an eye out for Agefield High: Rock the School from Refugium Games. This spiritual successor to Rockstar’s Bully is set to arrive this summer on Steam. It emerged this week that it will hit PS5 and Xbox Series X/S later in the year.

It’s a coming-of-age adventure in which you play as Sam, a young lad who has moved to a new school in the early 2000s. He wants to make his last few months of high school a time to remember.

There’s a branching narrative with multiple endings here — you can opt to go to classes and be a good student, or skip school and cause trouble. As a mostly rule-abiding student way back when, I’d be tempted to go for the latter. This seems like a bit of a life sim with a broad array of activities and ways to get into bother. I’m looking forward to it.

The latest edition of the Galaxies Showcase — yet another indie spotlight event — took place this week and The Backworld caught my attention. This is a Mother-inspired RPG from Numor Games and publisher Top Hat with charming art direction (yes, I did see that one character doing a Naruto run), an intriguing mix of characters and…

Advertisement

Oh no, why did the music stop? Why did it get so dark all of a sudden? What are these horrifying beasts that are chasing my character? Yup, there’s a heavy horror element here. Numor took inspiration from The Backrooms as well.

The Backworld will be released later this year. A demo just hit Steam.

A Study in Blue, from Relate Games, was another highlight of the Galaxies Showcase, thanks in large part to that impressive animation. This is a point-and-click adventure in which you play as two characters with complex pasts: private detective Kenneth and runaway Blue.

You’ll explore a semi-open world and solve crimes by collecting clues and calling out characters’ lies. There are three intertwined story acts and multiple endings. A Steam demo featuring a side quest from the main game that’ll take around two hours to complete is available now.

Advertisement

I’m always going to be interested in any game that riffs on The Legend of Zelda: A Link to the Past. On the face of this trailer, Elementallis developer AnKae Games seems to borrow quite a bit of the design language and other ideas from the SNES classic. Still, if you’re going to crib from anything, it may as well be the best game of all time.

This 2D action RPG, which is also published by Top Hat and has a heavier focus on elemental powers than A Link to the Past, looks very much like my kind of jam. It’s coming to Steam, GOG, Switch, PS4, PS5, Xbox Series X/S and Xbox One on April 28. Per the eShop listing, it’ll cost $18.

Source link

Advertisement
Continue Reading

Tech

How to Tell if Someone Else’s Apple AirTag Is Tracking You

Published

on

The biggest benefit of Apple’s AirTags is that they help you find your belongings, whether you’re looking for lost keys or keeping track of your luggage while traveling. But AirTags can also be used to track you without your knowledge. 

AirTags work by combining built-in sensors, wireless signals and Apple’s wide Find My network to let you keep tabs on your valuables. If you ever lose your wallet with an AirTag inside, for example, you can use the Find My app to locate it on a map, have it play a sound to help you find it nearby, or mark it as “lost,” which allows other Find My users to help you find it. 

One of the biggest complaints about AirTags, however, is that someone with malicious intent could easily slip one of the tiny tags into your bag and then track your movements without your consent. Multiple people have reported AirTag-related stalking incidents where the victims didn’t know the trackers were placed on them until much later.  

Advertisement

Apple and Google (Android users have their own choice of Bluetooth trackers, such as the Moto Tag, which works with Google’s Find Hub) have since collaborated on an industry standard that alerts the user if a device is being used to track them without their knowledge. Thanks to this collaboration, Android users will be able to know if an AirTag is being used to track them, too. 

Apple, for its part, has also made some changes in the past few years that improve the ability to detect an unwanted AirTag. In the initial rollout, an AirTag would make a sound three days after it’s separated from its paired device. Now, that duration is 8 to 24 hours. If you have unwanted tracking notifications enabled (which we’ll get to below), you’ll receive an audible alert.

We should note here that the new AirTag is 50% louder than the first-generation model, and would therefore be theoretically better at alerting you to the unwanted AirTag. Apple has also said that the speaker on the second-gen AirTag is harder to remove than on the first-gen model, in case bad actors try to remove it. 

Advertisement
an iPhone with Find My on the screen next to an AirTag 2

Apple’s Find My helps you set up and track an AirTag. It can also help notify you if an unwanted tracker is detected.

Patrick Holland/CNET

Detecting unwanted trackers

To be able to detect unwanted trackers, first enable unwanted-tracking notifications. For AirTags or other Find My accessories, these pop-up notifications (e.g., “AirTag found moving with you”) are available on devices with iOS 14.5 or later. For other Bluetooth tracking devices, these notifications are enabled on iOS 17.5 or later. 

You should enable Location Services, Find My iPhone, Bluetooth and Allow Notifications. Here’s how:

  • Head to Settings, then Privacy & Security, then Location Services and toggle it on. 
  • After that, head to Settings, then Apple Account, select Find My and turn Find My iPhone on. 
  • To enable Bluetooth, go to Settings, then Bluetooth and turn that on. 
  • Then go to Settings, then Notifications, scroll down to Tracking Notifications and toggle on Allow Notifications. Make sure airplane mode is off, or you won’t receive tracking notifications. 

Watch this: Testing the New AirTag, While Tim Cook’s White House Visit Sparks Apple Boycott Calls

What to do when you get the tracking notification

If you do get a notification like “Unknown tracker alert” or “Item detected near you,” you can try to find the unwanted AirTag by tapping it. Tap continue and then tap Play Sound or tap Find Nearby to locate the AirTag in question. 

Advertisement

If it doesn’t play a sound or you’re unable to find it, the item may no longer be on your person. Apple suggests checking your other belongings or the area around you, just in case. If you want to review the notification at a later time, you can open the Find My app, tap Items and then tap Items Detected With You.

Be aware that there are often “false positives,” when notifications are triggered when someone nearby has a tracker on them. If you’re traveling on a train, plane or bus, waiting in line or seated in a public space, a mistaken tracking alert could stem from glitches or high-density Bluetooth environments. 

If you get an alert, though, it’s always a good idea to take it seriously and investigate what might be causing it.

If you do find an AirTag that doesn’t belong to you, hold the top of your iPhone near the tracker until you see a notification. Tap it, and this will launch a website that provides information like its serial number, the last four digits of the phone number or a blurred-out email address of its owner. If the AirTag is marked as “lost,” you may see a message with instructions on how to contact them. 

Advertisement

If you’re concerned that the tracker is being used to monitor your movements and location, Apple advises taking a screenshot of the information above for your records. You can then disable the AirTag by pressing down on the back of the AirTag, turning it counterclockwise to remove the cover and removing the battery.  

Of course, before making any of these changes, it’s important to come up with a safety plan, especially if you’re afraid you’re being tracked by a current or former abusive partner. Contact your local law enforcement if you feel like your safety is at risk, or the National Domestic Violence Hotline 800-799-SAFE (7233).

Source link

Advertisement
Continue Reading

Tech

Premier League Soccer: Stream Man City vs. Arsenal From Anywhere Live

Published

on

When to watch Man City vs. Arsenal

  • Sunday, April 19, at 11:30 a.m. ET (8:30 a.m. PT).

Where to watch

  • Man City vs. Arsenal will air in the US  on NBC and Peacock Premium.
73% off with 2yr plan (+4 free months). Now only $3.49/month


See more details

See at Fubo
Advertisement
Fubo logo

Watch the Premier League in Canada

Fubo Canada

Advertisement

Can English Premier League leader Arsenal hold its nerve, or will second-place Man City take the chance to close the gap on the Gunners in this crucial title race showdown at the Etihad? 

A home victory for the hosts on Sunday looks essential if Man City is to claim a sixth EPL title under manager Pep Guardiola. A win here would move City to within three points of Arsenal. The hosts can draw plenty of encouragement from the comfortable 2-0 win in last month’s League Cup final as they look to heap further pressure on the Gunners. That pressure may be starting to get to the league leaders.

While Arsenal’s 2-1 home defeat last Sunday against Bournemouth has given City renewed optimism that it can catch its title opponents, Mikel Arteta’s team nevertheless claimed a positive result in midweek. Arsenal’s goalless draw at the Emirates against Sporting Lisbon ensured its passage into the UEFA Champions League semifinals for the second season in a row. 

Man City takes on Arsenal on Sunday, April 19, at the Etihad Stadium, with kickoff set for 4:30 p.m. BST. That makes it an 11:30 a.m. ET or 8:30 a.m. PT start in the US and Canada, and a 1:30 a.m. AEST kickoff in Australia in the early hours of Monday morning. 

Advertisement
Declan Rice of Arsenal celebrating, shouting.

Midfield star Declan Rice is set to start for Arsenal on Sunday. He recovered from an illness to star in the Gunners’ midweek 0-0 draw with Sporting Lisbon in the Champions League.

Catherine Ivill/AMA/Getty Images

How to watch Man City vs. Arsenal in the US without cable 

Sunday’s crucial clash will be broadcast on NBC and streaming service Peacock. To catch the game live on Peacock, you’ll need a Peacock Premium or Premium Plus subscription. 

Advertisement

Peacock offers two Premium plans, and after recent price increases, the ad-supported Premium plan costs $11 a month and the ad-free Premium Plus plan costs $17 a month.

How to watch the Premier League 2025-26 with a VPN

If you’re traveling abroad and want to keep up with Premier League action while away from home, a VPN can help enhance your privacy and security when streaming.

Advertisement

It encrypts your traffic and prevents your internet service provider from throttling your speeds, and can also be helpful when connecting to public Wi-Fi networks while traveling, adding an extra layer of protection for your devices and logins. VPNs are legal in many countries, including the US and Canada, and can be used for legitimate purposes such as improving online privacy and security. 

However, some streaming services may have policies that restrict VPN use to access region-specific content. If you’re considering a VPN for streaming, check the platform’s terms of service to ensure compliance.  

If you choose to use a VPN, follow the provider’s installation instructions to ensure you’re connected securely and in compliance with applicable laws and service agreements. Some streaming platforms may block access when a VPN is detected, so verify whether your streaming subscription allows VPN use.

Advertisement

James Martin/CNET

Price $78 for two yearsLatest Tests No DNS leaks detected, 18% speed loss in 2025 testsJurisdiction British Virgin IslandsNetwork 3,000 plus servers in 105 countries

ExpressVPN is our current best VPN pick for people who want a reliable and safe VPN, and it works on a variety of devices. It’s normally $120 a year for its most popular plan (Advanced), but if you sign up for an annual subscription for $90, you’ll get three months free. That’s the equivalent of $6 a month.

Advertisement

Note that ExpressVPN offers a 30-day money-back guarantee.

73% off with 2yr plan (+4 free months). Now only $3.49/month

Livestream Man City vs. Arsenal in the UK 

This Sunday afternoon clash is exclusive to Sky Sports and will be shown on its Sky Sports Main Event channel. If you already have Sky Sports as part of your TV package, you can stream the game via its Sky Go app. Cord-cutters will want to set up a Now account and a Now Sports membership to stream the game. 

Advertisement

Now TV

Sky’s standalone streaming service Now offers access to Sky Sports channels with a Now Sports membership. You can get a day of access for £15 or sign up to a monthly plan from £35 a month right now.

Livestream Man City vs. Arsenal in Canada 

If you want to livestream EPL games in Canada this season, you’ll need to subscribe to Fubo. The service has secured exclusive rights to the Premier League and is broadcasting all 380 matches live. 

Advertisement

Fubo

Fubo is the go-to destination for Canadians looking to watch the EPL, with exclusive streaming rights to every match. It currently costs CA$27 for the first month, then CA$31.50 per month from then on.

Livestream Man City vs. Arsenal in Australia 

Livestreaming rights for the EPL are now with Stan Sport, which is showing all 380 matches live, including this game.

Advertisement

Stan

Stan Sport will set you back AU$20 a month (on top of a Stan subscription, which starts at AU$12). It’s also worth noting that the streaming service is currently offering a seven-day free trial.

A subscription will also give you access to Premier League, Champions League and Europa League action, as well as international rugby and Formula E.

Advertisement

Source link

Continue Reading

Tech

Dublin’s Audrey AI closes $1.8m pre-seed funding round

Published

on

The investment will fund growth across auditing and engineering, with expansion expected across Ireland and the UK.

Dublin-based start-up Audrey AI has announced the closure of a $1.8m pre-seed funding round, which was led by Sure Valley Ventures and Delta Partners. There was additional participation from Enterprise Ireland, former CEO of Calypso Donnchadh Casey, former CBO of Wayflyer Conor Jones, alongside former Big 4 auditors.

Established in 2025 by Ryan Loughran and David Burke, who met on the Founders programme at Dogpatch Labs, Audrey AI develops AI solutions for financial auditors. The AI-powered platform aims to automate the most time-consuming parts of financial audit engagements.

The organisation has stated that the newly secured funds will be put towards the expansion of Audrey AI’s specialist audit and engineering teams, as the company expands its reach across Ireland, the UK and “beyond”.

Advertisement

Commenting on the announcement, Loughran, who is also the company’s CEO, said: “Developers have Copilot, lawyers have Harvey, but auditors still primarily work in Excel. We’re building AI that understands auditing deeply enough to raise the bar on quality, not just speed, freeing auditors to focus on the judgement and oversight that matters most.” 

A number of Irish organisations operating within the artificial intelligence space have already announced major investments in April. Start-up Otel AI, which is building an AI platform for hotel managers, recently announced a raise of €2m, bringing the company’s total funding to date to €2.8m. 

E-commerce technology company Zellor raised €850,000 in its very first external funding round. The start-up, which is led by CEO Niall O’Sullivan, received backing from Enterprise Ireland and a number of strategic Irish investors.

Galway-based AI security software start-up Octostar, which also has offices in Italy and the UK, raised €6.1m in an extended seed funding round. 

Advertisement

Updated, 1.05pm, 16 April 2026: This article was amended to clarify Audrey AI’s expansion plans.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Source link

Advertisement
Continue Reading

Tech

ZionSiphon malware designed to sabotage water treatment systems

Published

on

ZionSiphon malware designed to sabotage water treatment systems

A new malware called ZionSiphon, specifically designed for operational technology, is targeting water treatment and desalination environments to sabotage their operations.

The threat can adjust hydraulic pressures and raise chlorine levels to dangerous levels, researchers found during their analysis.

Based on its IP targeting and political messages embedded in its strings, ZionSiphon appears to focus on targets based in Israel.

Wiz

Researchers at AI-powered cybersecurity company Darktrace found a flawed encryption logic error in the malware’s validation mechanism that makes it non-functional but warn that future ZionSiphon releases could fix the flaw to unleash its power in attacks.

Upon deployment, the malware checks whether the host IP falls within Israeli ranges and whether the system contains water/OT-related software or files, to ensure it is running in water treatment or desalination systems.

Advertisement
Strings from the targets list
Strings from the targets list
Source: Darktrace

Darktrace notes that the logic for country verification is broken due to an XOR mismatch, causing the targeting to fail and triggering the self-destruct mechanism instead of executing the payload.

If ZionSiphon were to activate, it could cause significant damage by increasing chlorine levels and maximizing the flaw and pressure.

It does this via a function named “IncreaseChlorineLevel(),” which appends a text block on existing configuration files to maximize the chlorine dose and flow as much as it is physically supported by the plant’s mechanical systems.

“IncreaseChlorineLevel()” checks a hardcoded list of configuration files associated with desalination, reverse osmosis, chlorine control, and water treatment OT/Industrial Control Systems (ICS),” Darktrace says.

“As soon as it finds any one of these files present, it appends a fixed block of text to it and returns immediately.”

Advertisement

“The appended block of text contains the following entries: “Chlorine_Dose=10”, “Chlorine_Pump=ON”, “Chlorine_Flow=MAX”, “Chlorine_Valve=OPEN”, and “RO_Pressure=80”.”

The intention to interact with industrial control systems (ICS) is obvious from scanning the local subnet for the Modbus, DNP3, and S7comm communication protocols.

However, Darktrace has found only partially functional code for Modbus, and merely placeholders for the other two, indicating that the malware is still in an early development phase.

ZionSiphon also has a USB propagation mechanism that copies itself to removable drives as a hidden ‘svchost.exe’ process and creates malicious shortcut files that execute the malware when clicked.

Advertisement
Creating shortcuts on removable drives
Creating shortcuts on removable drives
Source: Darktrace

USB propagation is key in critical infrastructure systems, where computers that manage security-critical functions are often “air-gapped,” meaning they are not directly connected to the internet.

While ZionSiphon isn’t operational in its current version, its intent and potential for damage are concerning, and all that’s needed to unlock both is to fix a minor verification error.

AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

Source link

Advertisement
Continue Reading

Tech

Leakers claim PlayStation 6 could offer at least 3x the performance of the PS5

Published

on


YouTube channel Moore’s Law Is Dead recently made new claims about the performance of upcoming next-generation consoles based on supposedly leaked internal documents from AMD. Although most analysts expect the PlayStation 6 to improve ray tracing performance over the PlayStation 5 significantly, its overall impact on game performance remains a…
Read Entire Article
Source link

Continue Reading

Trending

Copyright © 2025