Connect with us
DAPA Banner

Tech

How to test OpenClaw without giving an autonomous agent shell access to your corporate laptop

Published

on

Your developers are already running OpenClaw at home. Censys tracked the open-source AI agent from roughly 1,000 instances to over 21,000 publicly exposed deployments in under a week. Bitdefender’s GravityZone telemetry, drawn specifically from business environments, confirmed the pattern security leaders feared: employees deploying OpenClaw on corporate machines with single-line install commands, granting autonomous agents shell access, file system privileges, and OAuth tokens to Slack, Gmail, and SharePoint.

CVE-2026-25253, a one-click remote code execution flaw rated CVSS 8.8, lets attackers steal authentication tokens through a single malicious link and achieve full gateway compromise in milliseconds. A separate command injection vulnerability, CVE-2026-25157, allowed arbitrary command execution through the macOS SSH handler. A security analysis of 3,984 skills on the ClawHub marketplace found that 283, about 7.1% of the entire registry, contain critical security flaws that expose sensitive credentials in plaintext. And a separate Bitdefender audit found roughly 17% of skills it analyzed exhibited malicious behavior outright.

The credential exposure extends beyond OpenClaw itself. Wiz researchers discovered that Moltbook, the AI agent social network built on OpenClaw infrastructure, left its entire Supabase database publicly accessible with no Row Level Security enabled. The breach exposed 1.5 million API authentication tokens, 35,000 email addresses, and private messages between agents that contained plaintext OpenAI API keys. A single misconfiguration gave anyone with a browser full read and write access to every agent credential on the platform.

Setup guides say buy a Mac Mini. Security coverage says don’t touch it. Neither gives a security leader a controlled path to evaluation.

Advertisement

And they’re coming fast. OpenAI’s Codex app hit 1 million downloads in its first week. Meta has been spotted testing OpenClaw integration in its AI platform codebase. A startup called ai.com spent $8 million on a Super Bowl ad to promote what turned out to be an OpenClaw wrapper, weeks after the project went viral.

Security leaders need a middle path between ignoring OpenClaw and deploying it on production hardware. Cloudflare’s Moltworker framework provides one: ephemeral containers that isolate the agent, encrypted R2 storage for persistent state, and Zero Trust authentication on the admin interface.

Why testing locally creates the risk it’s supposed to assess

OpenClaw operates with the full privileges of its host user. Shell access. File system read/write. OAuth credentials for every connected service. A compromised agent inherits all of it instantly.

Security researcher Simon Willison, who coined the term “prompt injection,” describes what he calls the “lethal trifecta” for AI agents: private data access, untrusted content exposure, and external communication capabilities combined in a single process. OpenClaw has all three — and by design. Organizational firewalls see HTTP 200. EDR systems are monitoring process behavior, not semantic content.

Advertisement

A prompt injection embedded in a summarized web page or forwarded email can trigger data exfiltration that looks identical to normal user activity. Giskard researchers demonstrated exactly this attack path in January, exploiting shared session context to harvest API keys, environment variables, and credentials across messaging channels.

Making matters worse, the OpenClaw gateway binds to 0.0.0.0:18789 by default, exposing its full API to any network interface. Localhost connections authenticate automatically without credentials. Deploy behind a reverse proxy on the same server, and the proxy collapses the authentication boundary entirely, forwarding external traffic as if it originated locally.

Ephemeral containers change the math

Cloudflare released Moltworker as an open-source reference implementation that decouples the agent’s brain from the execution environment. Instead of running on a machine you’re responsible for, OpenClaw’s logic runs inside a Cloudflare Sandbox, an isolated, ephemeral micro-VM that dies when the task ends.

Four layers make up the architecture. A Cloudflare Worker at the edge handles routing and proxying. The OpenClaw runtime executes inside a sandboxed container running Ubuntu 24.04 with Node.js. R2 object storage handles encrypted persistence across container restarts. Cloudflare Access enforces Zero Trust authentication on every route to the admin interface.

Advertisement

Containment is the security property that matters most. An agent hijacked through prompt injection gets trapped in a temporary container with zero access to your local network or files. The container dies, and the attack surface dies with it. There is nothing persistent to pivot from. No credentials sitting in a ~/.openclaw/ directory on your corporate laptop.

Four steps to a running sandbox

Getting a secure evaluation instance running takes an afternoon. Prior Cloudflare experience is not required.

Step 1: Configure storage and billing.

A Cloudflare account with a Workers Paid plan ($5/month) and an R2 subscription (free tier) covers it. The Workers plan includes access to Sandbox Containers. R2 provides encrypted persistence so conversation history and device pairings survive container restarts. For a pure security evaluation, you can skip R2 and run fully ephemeral. Data disappears on every restart, which may be exactly what you want.

Step 2: Generate tokens and deploy.

Clone the Moltworker repository, install dependencies, and set three secrets: your Anthropic API key, a randomly generated gateway token (openssl rand -hex 32), and optionally a Cloudflare AI Gateway configuration for provider-agnostic model routing. Run npm run deploy. The first request triggers container initialization with a one-to-two-minute cold start.

Advertisement

Step 3: Enable Zero Trust authentication.

This is where the sandbox diverges from every other OpenClaw deployment guide. Configure Cloudflare Access to protect the admin UI and all internal routes. Set your Access team domain and application audience tag as Wrangler secrets. Redeploy. Accessing the agent’s control interface now requires authentication through your identity provider. That single step eliminates the exposed admin panels and token-in-URL leakage that Censys and Shodan scans keep finding across the internet.

Step 4: Connect a test messaging channel.

Start with a burner Telegram account. Set the bot token as a Wrangler secret and redeploy. The agent is reachable through a messaging channel you control, running in an isolated container, with encrypted persistence and authenticated admin access.

Total cost for a 24/7 evaluation instance runs roughly $7 to $10 per month. Compare that to a $599 Mac Mini sitting on your desk with full network access and plaintext credentials in its home directory.

A 30-day stress test before expanding access

Resist the impulse to connect anything real. The first 30 days should run exclusively on throwaway identities.

Advertisement

Create a dedicated Telegram bot, and stand up a test calendar with synthetic data. If email integration matters, spin up a fresh account with no forwarding rules, no contacts, and no ties to corporate infrastructure. The point is watching how the agent handles scheduling, summarization, and web research without exposing data that would matter in a breach.

Pay close attention to credential handling. OpenClaw stores configurations in plaintext Markdown and JSON files by default, the same formats commodity infostealers like RedLine, Lumma, and Vidar have been actively targeting on OpenClaw installations. In the sandbox, that risk stays contained. On a corporate laptop, those plaintext files are sitting ducks for any malware already present on the endpoint.

The sandbox gives you a safe environment to run adversarial tests that are reckless and risky on production hardware, but there are exercises you could try:

Send the agent links to pages containing embedded prompt injection instructions and observe whether it follows them. Giskard’s research showed that agents would silently append attacker-controlled instructions to their own workspace HEARTBEAT.md file and wait for further commands from an external server. That behavior should be reproducible in a sandbox where the consequences are zero.

Advertisement

Grant limited tool access, and watch whether the agent requests or attempts broader permissions. Monitor the container’s outbound connections for traffic to endpoints you didn’t authorize.

Test ClawHub skills before and after installation. OpenClaw recently integrated VirusTotal scanning on the marketplace, and every published skill gets scanned automatically now. Separately, Prompt Security’s ClawSec open-source suite adds drift detection for critical agent files like SOUL.md and checksum verification for skill artifacts, providing a second layer of validation.

Feed the agent contradictory instructions from different channels. Try a calendar invite with hidden directives. Send a Telegram message that attempts to override the system prompt. Document everything. The sandbox exists so these experiments carry no production risk.

Finally, confirm the sandbox boundary holds. Attempt to access resources outside the container. Verify that container termination kills all active connections. Check whether R2 persistence exposes state that should have been ephemeral.

Advertisement

The playbook that outlasts OpenClaw

This exercise produces something more durable than an opinion on one tool. The pattern of isolated execution, tiered integrations, and structured validation before expanding trust becomes your evaluation framework for every agentic AI deployment that follows.

Building evaluation infrastructure now, before the next viral agent ships, means getting ahead of the shadow AI curve instead of documenting the breach it caused. The agentic AI security model you stand up in the next 30 days determines whether your organization captures the productivity gains or becomes the next disclosure.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Erykah Badu’s Mama’s Gun Gets 25th Anniversary Vinyl Reissue with RTI 180g Pressing and Analog Restoration: Review

Published

on

The new  25th Anniversary Vinylphyle restoration of Erykah Badu’s chart-toping 2000 album Mama’s Gun is an excellent reissue which should be of interest to fans of vocal jazz and modern soul sounds as well as analog loving audiophiles.

A platinum seller with three hit singles including her first top 10, this is a super chill, fluid grooving and melodic song cycle often categorized as “neo-soul” and bridging pop, soul, funk, jazz, hip hop and even singer-songwriter pop. While I’ve read numerous references to Billie Holiday in discussing Ms. Badu’s vocal style, I also hear strong Dinah Washington flavors by way of Minnie Ripperton and Chaka Kahn (which are some pretty great touchstones as well).  

As with other Vinylphyle releases in this top-notch new series from Universal Music, Mama’s Gun was pressed at RTI — renown as one of the best vinyl manufacturing facilities in the world. The 180-gram vinyl is dark and well centered. The production quality elements throughout are also outstanding, the album cover is made of heavy cardboard stock akin to a vintage jazz album from 1960s on Verve or Blue Note. Each disc comes housed in an audiophile-grade plastic lined inner-sleeve.  

erykah-badu-liner-notes

From Universal’s udiscovermusic website we’ve also gleaned some additional information which reveals that this release is more than “just” a reissue but a genuine restoration of note for fans seeking the best quality version of a favorite album.

There we learn: 

Advertisement

“There are no sequenced analog masters for Mama’s Gun. The original 44.1kHz/16-bit files, with the original CD mastering and limiting, have been the only source for all digital and vinyl reissues—until now. The record was reassembled and rebuilt digitally from 14 individual track tapes, newly transferred in 96kHz/24-bit, in order to create the first true remaster of this record since it came out 25 years ago.”

In the new liner notes for the album Ms. Badu adds insights into her passion for analog at the crossroads of digital: “With this remastering, we’ve carefully blended analog warmth with digital precision. It’s breathtaking to hear the subtleties of each layer come alive in a new way, making the project resonate even more powerfully.”

Erykah Badu Back Cover 660×600

Indeed, what a lush round sound Mama’s Gun delivers! Largely played by live musicians in top studios including New York’s iconic Electric Lady (which was created by Jimi Hendrix), no less than The Roots’ Questlove is featured on drums on many of the tracks.  

It is haunting hearing “In Love with You” which features vocal contributions from Stephen Marley — Bob Marley’s second son — supported mostly by lovely softly strummed nylon string acoustic guitar. Ms. Badu’s  hit “Bag Lady” (#6 Billboard Top 100) was co-written with soul legend Issac Hayes and received two Grammy nominations that year. “Cleva” — which features Roy Ayers on Vibraphone, feels almost like a lost Stevie Wonder tune. 

erykah-badu-mamas-gun-vinylphile

if you ever liked early Meshell Ndegeocello albums like her 1999 masterwork Bitter or even newer artists like New Orleans’ Tank & The Bangas, you might well enjoy Mama’s Gun. Highly recommended. 

Universal’s Vinylphyle series 2LP release of Erykah Badu’s Mama’s Gun is currently exclusively available via udiscovermusic for $54.98.

Advertisement

Mark Smotroff is a deep music enthusiast / collector who has also worked in entertainment oriented marketing communications for decades supporting the likes of DTS, Sega and many others. He reviews vinyl for Analog Planet and has written for Audiophile Review, Sound+Vision, Mix, EQ, etc.  You can learn more about him at LinkedIn.

Advertisement. Scroll to continue reading.

Source link

Advertisement
Continue Reading

Tech

The Real Difference Between Pickup Truck And Car Engines

Published

on





Are pickup truck engines the same as those used in normal passenger or sports cars? The answer is both yes and no. Physically, at least, there’s usually little that separates an engine in a truck’s engine bay from one in a car’s. After all, there have been plenty of times in the industry’s history when automakers have sold cars and trucks with nearly identical engines. Case in point, the legendary Chrysler slant-six engine, which came in everything from compact cars to pickup trucks and vans.

But in the modern era, especially, there can be notable differences between car and truck engines, even if their displacement and general engine architecture are the same. The modern HEMI V8 used in Dodge muscle cars and Ram pickups is a good example of this, with different versions of the same engines used in performance cars and pickups. Most of the differences between truck and car engines involve how and when the engines deliver their horsepower and torque. 

A car engine may produce more peak horsepower than an equivalent truck engine, but the truck engine will often provide more torque or deliver the same amount of torque at lower revs. Just how much difference there is between the two will vary by automaker, and some brands, like Ford, offer V8 engines designed from the ground up for trucks that share nothing with their car counterparts.

Advertisement

The different flavors of V8s

Ultimately, the main difference between car and truck engines is rooted in the difference between horsepower and torque. While horsepower matters in a truck, when it comes to pulling a trailer or carrying a heavy load, it’s the torque that’s important — and the lower in an engine’s powerband that torque comes, the better it is. Thus, the popularity of ultra-torquey, but relatively low-horsepower turbodiesel engines for large pickups. Peak horsepower, meanwhile, takes prominence in a sports car where engine speeds are higher. 

Even within the same V8 family, there can be notable differences in car and truck engines. In GM’s V8 lineup, the 401-hp 6.6-liter L8T truck engine is designed for low-speed torque, with 464 lb-ft of torque at 4,000 RPM. The Chevrolet Corvette’s smaller, 495-hp 6.2-liter LT2 V8 is part of the same family and easily bests the L8T in peak horsepower, yet it barely edges the L8T in torque. It also needs to rev much higher to generate its torque, with its 470 lb-ft coming at 5,150 rpm. 

Advertisement

Ford’s Super Duty 7.3-liter Godzilla V8 takes this concept even further. Not only is the Godzilla much larger than the 5.0 Coyote V8 in the Mustang GT, but it also uses an entirely different design with an overhead-valve, single-camshaft design compared to the 5.0’s dual overhead cams and 32 valves. At 480 hp, the 5.0 beats out the 430-horsepower Godzilla, but the 7.3 takes the torque crown, with 475 pound-feet to the Mustang’s 415 lb-ft.

Advertisement

The curious case of the Nissan 240SX

So what happens, then, if you put a pickup truck engine into a sports car? Look no further than the North American-market Nissan 240SX from the 1990s. When the S13 Nissan Silvia and 180SX debuted in the Japanese home market, the cars were available with high-horsepower turbocharged four-cylinder engines — first the 1.8-liter CA18DET and later the legendary SR20DET. This, combined with a great chassis and tons of aftermarket support, helped the S13 become a smash hit among enthusiasts.

However, when it came time to export the car to America, Nissan decided to forgo the turbo engines in favor of the naturally aspirated 2.4-liter KA24 engine used in Nissan pickup trucks. Though the USDM engine was larger than its JDM counterpart and produced a decent amount of torque for its size, the KA24 only made 140 hp and, more importantly, lacked the high-revving sports car feel many expected from the 240SX. 

Fortunately, the SR20DET was an easy swap, and Nissan’s decision to go with a truck engine didn’t entirely detract from the many features that helped the 240SX become a legendary drift car in the years and decades that followed. Even then, though, one can’t help but wonder what would’ve happened had Nissan given the U.S. market 240SX the turbocharged performance engine it deserved.  

Advertisement



Source link

Continue Reading

Tech

AI Can Clone Open-Source Software In Minutes

Published

on

ZipNada writes: Two software researchers recently demonstrated how modern AI tools can reproduce entire open-source projects, creating proprietary versions that appear both functional and legally distinct. The partly-satirical demonstration shows how quickly artificial intelligence can blur long-standing boundaries between coding innovation, copyright law, and the open-source principles that underpin much of the modern internet.

In their presentation, Dylan Ayrey, founder of Truffle Security, and Mike Nolan, a software architect with the UN Development Program, introduced a tool they call malus.sh. For a small fee, the service can “recreate any open-source project,” generating what its website describes as “legally distinct code with corporate-friendly licensing. No attribution. No copyleft. No problems.” It’s a test case in how intellectual property law — still rooted in 19th-century precedent — collides with 21st-century automation. Since the US Supreme Court’s Baker v. Selden ruling, copyright has been understood to guard expression, not ideas.

That boundary gave rise to clean-room design, a method by which engineers reverse-engineer systems without accessing the original source code. Phoenix Technologies famously used the technique to build its version of the PC BIOS during the 1980s. Ayrey and Nolan’s experiment shows how AI can perform a clean-room process in minutes rather than months. But faster doesn’t necessarily mean fair. Traditional clean-room efforts required human teams to document and replicate functionality — a process that demanded both legal oversight and significant labor. By contrast, an AI-mediated “clean room” can be invoked through a few prompts, raising questions about whether such replication still counts as fair use or independent creation.

Source link

Advertisement
Continue Reading

Tech

Intel repurchasing 49pc stake in Leixlip chip factory for $14.2bn

Published

on

Intel said the agreement is reflective of a strong partnership with Apollo, as well as the organisation’s role in the age of AI.

US technology company Intel has plans to repurchase a 49pc stake of the Leixlip, Kildare Fab 34 manufacturing facility, via a partnership with asset manager Apollo Global Management. The deal which will be valued at $14.2bn is expected to be funded through cash on hand and proceeds from the issuance of new debt of approximately $6.5 bn. 

With work beginning in 2019, Fab 34 was designed to be an advanced semiconductor manufacturing facility. 

There has been significant investment in the plant over the years with the organisation hitting several important milestones and currently it is a fabrication facility for products utilising the Intel 4 and Intel 3 process technologies, for example Intel Core Ultra and Intel Xeon 6 processors.

Advertisement

In 2024, it was decided that Intel would sell a 49pc stake in Fab 34 to Apollo Global Management.

At the time, David Zinsner, the chief financial officer at Intel, said that the $11bn deal would give the chip maker the “additional flexibility to execute our strategy as we invest to create the world’s most resilient and sustainable semiconductor supply chain”. Intel also said it would be retaining full ownership and control of Fab 34 and its assets. 

Commenting on the recent announcement Zinsner said, “Our 2024 agreement was the right structure at the right time and provided Intel with meaningful flexibility, enabling us to accelerate critical initiatives. Today, we have a stronger balance sheet, improved financial discipline and an evolved business strategy.”

Apollo Partner Jamshid Ehsani added, “Our partnership with Intel began at an important stage in the execution of its advanced manufacturing roadmap, where our long-term strategic capital played a meaningful role in accelerating the production of next-generation chip technology.

Advertisement

“Flexibility and alignment are core to how we approach relationships as a long-term, solutions-oriented capital partner, and we are pleased to facilitate this transaction in support of Intel’s evolving strategic and operational priorities.”

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Source link

Advertisement
Continue Reading

Tech

Thinborne Samsung Galaxy S26 Ultra Case Review: Is It Better Than Samsung’s Slim Magnet Case?

Published

on

Samsung already has its own slim magnetic case for the Galaxy S26 Ultra, so most people won’t think twice about alternatives.

But choosing the right Samsung Galaxy S26 Ultra case isn’t always as straightforward as it seems. Some cases look great on day one but end up feeling too smooth, slightly bulky, or just awkward to use after a few days. Thinborne is still a thin magnetic case, but it takes a slightly different approach.

This review focuses on how it feels in real use, and how it compares to Samsung’s own option.

Thinborne Overview of Features

It helps to look at what Thinborne actually offers and how those features translate in real use.

Advertisement

Material and Build

Thinborne uses 600D aramid fiber, which you’ll usually see in lightweight, high-strength materials. You’ll notice how it feels:

  • It’s very light
  • It feels firm rather than flexible
  • The surface has a subtle texture

At 0.90 mm thin, it doesn’t add much bulk. The phone still feels close to how it does without a case.

What makes it different from typical cases is the structure. It doesn’t have that soft, slightly rubbery feel you get from silicone. It’s more rigid, almost like a thin shell that snaps into place. Over time, silicone can start to feel sticky or collect dust – this doesn’t.

Black Thinborne case for the regular S26

MagSafe Compatibility

Like most Galaxy S26 Ultra cases, Thinborne includes built-in magnets since the phone itself doesn’t have them. In everyday use, that means:

  • Chargers snap into place quickly
  • Car mounts hold steady
  • Wallets and stands attach cleanly

The experience is straightforward, and everything lines up as expected (and it stays in place).

One thing that helps with the setup is the case’s rigidity. Since it doesn’t flex much, the alignment stays consistent. You don’t get that slight shift you sometimes notice with softer cases.

S26 Ultra case connected to a MagSafe case

Available Colors

Thinborne keeps the color options simple:

  • Black
  • Royal Crimson
  • Wild Navy

All three use the same woven finish, so the feel doesn’t change – only the color does. The tones are muted and don’t draw too much attention.

Thinborne Thin Phone Case vs Samsung Galaxy S26 Ultra Slim Magnet Case

Samsung’s Slim Magnet Case is the most direct comparison. Both cases fall into the same general category: thin, lightweight, and magnetic.

Advertisement

Samsung doesn’t list an exact thickness, but it’s positioned as a slim case. What we do know is that it weighs 24 grams, making it a bit heavier than Thinborne, which weighs around 20 grams.

Here’s how they compare:

Feature Thinborne Galaxy S26 Ultra Case Samsung Slim Magnet Case
Weight 20 g 24 g
Thickness 0.90 mm slim profile (not officially listed)
Material 600D aramid fiber Synthetic/plastic
Grip Textured (woven) Smooth
Magnets Built-in magnetic array Built-in magnets

As you can see, Thinborne and Samsung look similar. In use, however, the differences can be noticed:

  • Grip – Thinborne has a bit more texture, so it feels more secure in your hand. Samsung’s case is smoother, which can feel slightly slippery.
  • Weight – The difference isn’t huge, but the lighter feel can be noticeable over time – especially on a large phone like the S26 Ultra.
  • Material feel – Thinborne feels more solid and structured. Samsung’s case feels more like a standard slim case.

Pricing and Availability

Thinborne and Samsung are priced almost the same, so cost isn’t really the deciding factor here.

Thinborne comes in at $69.69, while Samsung’s Slim Magnet Case is slightly higher at $69.99. The difference is minimal, and in practice, both sit in the same premium range for thin magnetic cases.

Advertisement

Where they differ is availability. Thinborne is sold through its official website and is also available on Amazon, which gives you a bit more flexibility when buying. It typically includes extras like a tempered glass screen protector as well.

Samsung’s case is easier to find overall. It’s available through Samsung’s store and most major retailers, making it a more convenient option if you prefer to buy locally or through familiar channels.

At this price point, it really comes down to which case fits your preferences better, not which one is cheaper.

Wrap Up

Thinborne keeps things simple, and that’s really the point. It’s built as a thin phone case that doesn’t change how the Galaxy S26 Ultra feels in your hand. The lighter weight, subtle texture, and rigid build all come together in a way that feels easy to live with day to day.

Advertisement

Samsung’s Slim Magnet Case still does what it’s supposed to. It’s reliable, widely available, and works well with magnetic accessories. But if you care about how your phone actually feels in use, Thinborne has a clear edge. The lighter weight and textured finish make it easier to hold, especially during one-handed use – something you start to notice after a few days of use.

Source link

Continue Reading

Tech

Microsoft links Classic Outlook issue to email delivery problems

Published

on

Outlook

Microsoft is investigating a known issue that prevents some Classic Outlook users from sending emails via Outlook.com.

Affected users are being warned that their message hasn’t reached some intended recipients, and they will encounter this problem more often when the Outlook.com account they use to send email is an Outlook profile linked to another Exchange account.

“This message could not be sent. Try sending the message again later or contact your network administrator,” the non-delivery report (NDR) error displayed when sending or replying to emails reads.

“You do not have the permission to send the message on behalf of the specified user. Error is [0x80070005-0x0004dc-0x000524].”

Advertisement

Microsoft added that another condition that may trigger these errors is that the sender’s account has an Exchange Online mail contact with the same SMTP address.

Classic Outlook non-delivery report (NDR) error
Classic Outlook non-delivery report (NDR) error (Microsoft)

​While investigating this issue and still looking for a fix, the Outlook team shared several workarounds that may help affected customers temporarily mitigate the issue.

Microsoft recommends removing the M365 account Address Book so that the Outlook client does not check it when sending emails, hiding the Outlook.com contact from the Microsoft 365 account Global Address List (GAL).

Other alternatives include creating a new classic Outlook profile that includes only the account receiving NDR errors, and using the New Outlook client or Outlook.com on the web to send email from the affected account.

Over the last two weeks, Microsoft fixed two other known issues, including one that caused Classic Outlook to crash when enabling the Microsoft Teams Meeting Add-in and another that triggered 0x800CCC0F and 0x80070057 errors when synchronizing Gmail and Yahoo accounts.

Advertisement

Microsoft is also investigating known bugs that cause “Can’t connect to the server” errors when creating groups if Exchange Web Services (EWS) is enabled for the tenant, and that make the mouse pointer disappear for some users in Classic Outlook, OneNote, and other Microsoft 365 apps.

Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.

This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.

Source link

Advertisement
Continue Reading

Tech

Rapid Snow Melt-Off In American West Stuns Scientists

Published

on

Scientists say extreme March heat caused an unusually rapid collapse of snowpack across the American West that’s leaving major basins at record or near-record lows. “This year is on a whole other level,” said Dr Russ Schumacher, a Colorado State University climatologist. “Seeing this year so far below any of the other years we have data for is very concerning.” The Guardian reports: […] The issue is extremely widespread. Data from a branch of the US Department of Agriculture (USDA), which logs averages based on levels between 1991 and 2020, shows states across the south-west and intermountain west with eye-popping lows. The Great Basin had only 16% of average on Monday and the lower Colorado region, which includes most of Arizona and parts of Nevada, was at 10%. The Rio Grande, which covers parts of New Mexico, Texas and Colorado, was at 8%. “This year has the potential of being way worse than any of the years we have analogues for in the past,” Schumacher said.

Even with near-normal precipitation across most of the west, every major river basin across the region was grappling with snow drought when March began, according to federal analysts. Roughly 91% of stations reported below-median snow water equivalent, according to the last federal snow drought update compiled on March 8. Water managers and climate experts had been hopeful for a March miracle — a strong cold storm that could set the region on the right track. Instead, a blistering heatwave unlike any recorded for this time of year baked the region and spurred a rapid melt-off. “March is often a big month for snowstorms,” Schumacher said. “Instead of getting snow we would normally expect we got this unprecedented, way-off-the-scale warmth.”

More than 1,500 monthly high temperature records were broken in March and hundreds more tied. The event was “likely among the most statistically anomalous extreme heat events ever observed in the American south-west,” climate scientist Daniel Swain said in an analysis posted this week. “Beyond the conspicuous ‘weirdness’ of it all,” Swain added, “the most consequential impact of our record-shattering March heat will likely be the decimation of the water year 2025-26 snowpack across nearly all of the American west.” Calling the toll left by the heat “nothing short of shocking,” Swain noted that California was tied for its worst mountain snowpack value on record. While the highest elevations are still coated in white, “lower slopes are now completely bare nearly statewide.”

Source link

Advertisement
Continue Reading

Tech

If Elden Ring was Turned Into a 90s-Inspired Saturday Morning Cartoon, This is What it would Look Like

Published

on

64 Bits Elden Ring 90s Cartoon
Studio 64 Bits worked tirelessly for four months to hand-draw every single frame, allowing them to introduce Elden Ring to the wild world of Saturday morning television in the 90s. The end effect feels like a bizarre parallel universe in which the game appears alongside Thundercats and He-Man.



Ranni is right there at the start, cradling a double-necked electric guitar slung lazily across her shoulders, and as she begins noodling on the opening chords, the camera sweeps across these blasted landscapes, full of familiar faces from both the base game and the Shadow of the Erdtree expansion. We see Malenia charging ahead with blades flashing, Blaidd standing tall and loyal by her side, and Messmer looming large as the true new threat. Meanwhile, Miquella and Radahn share a dramatic moment, and Melina, Rykard, Mohg, Varre, Midra, Placidusax, Astel, Maliketh, and the Elden Beast all flash across the screen in quick, splashy bursts. Each character receives the usual cartoon makeover, complete with bold outlines, vivid colors, and exaggerated posturing that transforms their conflicts into heroic showdowns rather than gloomy, terrible struggles.

64 Bits Elden Ring 90s Cartoon
The animation sticks to the technical limits of 90’s TV production, which means that the colors don’t deviate much from a fairly limited palette, the lines have just a hint of that creaky hand-drawn cel look to them, and the transitions snap along with the same crisp timing you’d see on shows from that era. The music builds to a precise pitch, culminating in a driving rock song that sounds like it might have come directly from the opening titles of Jayce and the Wheeled Warriors or Captain Planet. Every second creates the impression that an entire series could follow, with the Tarnished rushing across the continent to repair the Elden Ring and face off against these legendary monsters in one thrilling episode after the next.

64 Bits Elden Ring 90s Cartoon
After the main intro concludes, the film transitions to a brief commercial in which Elden Ring appears to have recently been released for the old SNES. A happy narration promises additional dungeons, secrets, and a fate that is entirely in the player’s control. The tagline reverses a humorous old Nintendo slogan into ‘Now you’re playing with power, rune power’, and the spot concludes with a quick little bumper that parodies the DIC logo from coutnless old 90’s cartoons. It connects neatly to their last full-length SNES remake, making the entire package feel like one continuous block of faux Saturday morning programming.

Source link

Advertisement
Continue Reading

Tech

I skipped Meta’s AI glasses, but they’ve finally fixed a fundamental problem for millions other like me

Published

on

Smart glasses have always had a basic problem for people like me. They looked cool in demos, sounded futuristic in press releases, and usually came with the same quiet catch. If you already wear glasses every day, you are expected to work around them. This meant adding prescription lenses later, settling for a fit that is not quite right, or treating the whole thing as a novelty instead of something you would actually wear throughout the day.

This is what makes Meta’s latest announcement more exciting. The company just unveiled its first prescription-optimized AI glasses, the Ray-Ban Meta Blayzer Optics (Gen 2) and Ray-Ban Meta Scriber Optics (Gen 2), and they are explicitly designed around people who rely on prescription eyewear all day.

Meta says they support nearly all prescriptions, start at $499 in the US, and will be available at optical retailers beginning April 14.

For me, that is the first time Meta’s glasses story has felt less like wearable hype and more like something I could actually live with.

Advertisement

Prescription wearers don’t have to do extra work

Billions of people around the world use glasses or contacts for vision correction, and Meta itself notes that many Ray-Ban Meta and Oakley owners already add prescription lenses to existing models. But “can be added later” is not the same thing as “built for you from the start.”

The new prescription-first push feels more thoughtful. Meta says that these new models were designed for all-day comfort and include features like overextension hinges, interchangeable nose pads, and optician-adjustable temple tips. These may sound like dry-product language stuff, but if you actually wear glasses every day, it is the kind of detail that decides whether something stays on your face for the next eight hours or if it gets thrown into a case after 20 minutes.

Balancing act between ‘gadget’ and ‘eyewear’

Meta is not just launching two new frame styles and calling it a day. It is trying to make AI glasses feel like a normal category of eyewear rather than a niche device for early adopters. These new prescription-optimized frames aren’t alone, as Meta also announced more frame and lens options across Ray-Ban Meta and Oakley Meta glasses.

There’s also a new software feature, like hands-free nutrition tracking, WhatsApp summaries and recall through Meta AI, and Neural Handwriting support expanding to iMessage. All of this makes these new glasses feel more natural for daily use. The tech itself is only half the story. The real breakthrough is when you don’t need to accommodate the hardware.

And if you already wear prescription glasses, that threshold is even higher. A smartwatch can be optional. Glasses are not.

This is the first Meta glasses move that feels genuinely practical

This is basically why I think these new Meta glasses matter more than they might look on paper. The usual wearable pitch is about features, AI tricks, cameras, and convenience. But for prescription wearers, such as myself, the first question is whether I would actually want to wear this all day instead of normal glasses?

And for a change, Meta seems to be answering that question directly.

Advertisement

Yes, the concerns don’t disappear, and smart glasses still have the privacy baggage and hefty price tag. They also haven’t proved that their AI features are useful often enough to justify becoming part of your daily routine. But this launch clears a much more fundamental barrier than people give it credit for.

And for someone who already owns prescription Wayfarers and knows how much difference proper eyewear fit makes, Meta’s new AI glasses suddenly feel a lot more attractive.

Source link

Advertisement
Continue Reading

Tech

Every 3D Printable Film Camera, In One Place

Published

on

For those of us who hack old cameras, the 3D printer has undoubtedly been a boon. High precision, or at least consistent precision, lightproof enclosures can be easily made and reproduced for others. As a result there are quite a few printable cameras out there, and we’ve featured our share here. We didn’t realize just how many there are without the work of [Sebastian] though, as he’s gathered together every one he can find in a glorious catalog of homemade photographic construction.

As a snapshot of the world of home made cameras it’s refreshing to see such a wide range of designs. There are pinholes aplenty as well as cameras using lenses from scavanged point and shoots through 35mm SLR, medium format, and even one using a Micro Four Thirds compact digital camera lens. For film there’s 35mm and 120 as well as large format, but we’re pleased to see a few instant cameras in there. Some of the models in the list are paid-for designs but most of them are free, so you probably won’t need any encouragement to make yourself a camera!

Unless we missed something, we didn’t see any movie cameras in the list. With 35mm and 16mm models to be found, we hope some of them make it.

Advertisement

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025