Derek Lam has more than 31,000 followers on TikTok and nearly 40,000 on X as of this writing. He is shirtless a lot, he dances a lot, and he is shirtless dancing a lot, which may explain how he got so many fans. His comments are filled with compliments (“beautiful”) in different languages (“hombre bello y sensual”) and superlatives (“this might be the finest man on the internet”) accompanied by different emoji (red hearts, crying laughing, lips). Their responses make it seem like Derek Lam is the first and only beautiful man they’ve ever seen, which may explain why he is also selling “exclusive,” seemingly adult, content.
Tech
Is that thirst trap influencer AI? Inside the world of very convincing deepfakes
He is also, possibly unbeknownst to his many admirers, AI-generated.
To be fair, there were some signs that this man was not real: Despite the multiple videos, Derek never speaks. His videos are also rather brief, just seconds long. A real hot person probably would have parlayed a following of this size into brand deals or “get ready with me” videos. And the selfies on his X account show a completely different man just three years ago.
Still, the followers of Derek I talked to didn’t even notice he was AI because he seemed to blend in so seamlessly with the other hot men on the internet.
Derek isn’t the only AI thirst trap showing off defined abs for likes and money. He’s one of an increasing number of completely fake, AI-generated figures sinking their fangs into the real models, influencers, and porn stars who populate our feeds, sucking up their beautiful faces and bodies, and using them to profit, without a penny going to the real humans they fed from.
When it comes to the damage AI could wreak on society, an army of Dereks tricking horny people into giving him likes — or, worst case, money and Amazon gift cards — doesn’t exactly sound like the singularity doomsday scenario that we’ve been warned about. It’s clearly unfortunate for the adult entertainers competing with deepfakes and a fraud risk for their fans, but one might believe if they don’t fall into one of these two groups, they’re relatively safe and unaffected.
But there’s something more going on here. History shows that porn and sex drive innovation in the tech industry. The way tech platforms treat sex workers is typically a glimpse into the future, and a warning about how tech platforms will eventually treat all of us. If human desire demands the capability to steal, loot, and turn anyone and everyone into something for sale — possibly into hot Dereks — is anyone safe?
The Dereks of the internet are a bleak look at what’s happening in the real world: nothing belongs to us anymore — not our looks, our beauty, our sex, and our art. Our most human desires are slowly being synthesized, with or without our consent. And AI is making it all possible.
Deepfake technology has gotten alarmingly good in recent years
Artificial hots like Derek are considered “deepfakes,” an umbrella term for AI-generated media (audio, video, or both) that resembles a real-life person.
When deepfakes first started appearing in late 2017, they were fairly low-quality, making it easy to tell when someone had used a rudimentary app to paste a celebrity or politician’s head onto a different body. Still, it wasn’t very long until people started wielding this technology to be nasty.
“The first set of deepfakes were actually used to create pornographic videos. They replaced the subjects in those videos with the faces of celebrities,” Siwei Lyu, a professor at the University at Buffalo who studies digital forensics, told me.
Because the quality of those videos was bad and the content was often absurd or unrealistic, it was easy to tell they weren’t real. Those clunky apps needed a lot of data — videos, images, etc. — of real people to produce crappy videos; Lyu explained that this is why you mostly only saw deepfakes of politicians and celebrities at the time.
As the technology got better, it became less reliant on having a huge amount of data. Instead of needing a whole archive, the new versions of these apps can pretty much run on nothing. “They do not need that much data to train a model anymore. Some of the most recent algorithms just need a single picture — just a single picture of someone,” Lyu said. And the quality is better too. Lyu said that there are AI programs that can now change a person’s appearance and voice in real time, like in Facetimes and Zooms or on live broadcasts.
Given how many of us are constantly posting photos and videos online, it is now extremely easy to create a convincing social media presence for a person who is not real, and to use it to catfish unwitting people on the internet.
“This is the problem. It’s becoming more and more challenging to visually tell deepfakes apart,” Lyu said. “Seven years ago, when I started working in this area, checking them was not this difficult,” he added.
Lyu is an expert in digital media forensics and machine learning, and he went through one of Derek’s videos frame by frame and pointed out some obvious AI tells. There was a distorted watchface with weird swirls instead of numbers and a moment in the video where all of Derek’s fingers on one hand were the same length. Lyu also pointed out that Derek’s chest hair fluctuates, appearing dense in one frame and then dissipating in another.
Through social media, I attempted to contact the owner of Derek Lam’s account with evidence from Lyu that these videos are artificial; I did not hear back.
During my deep dive into Derek Lam’s social media presence, I looked at the accounts he was following. I noticed that of those accounts, someone who goes by the name Vance Ford also had tens of thousands of followers and had nearly identical videos to Derek. The flexing, dances, movements, and music they were set to were all the same, but with what appeared to be a different man performing them.
I attempted to contact Vance through DMs on social media and did not get a response. I also e-mailed two models who appear to be the actual people that the Derek and Vance AI personas were trained on, but they didn’t respond.
I sent two of Vance’s videos to Lyu, who analyzed them manually and with AI-detection software. He confirmed that “their movements are nearly identical — consistent with generation from a shared motion source,” and noted that the Vance videos had moments of distortion, unintelligible text, and facial warping.
“Young Magnum PI…Tom Selleck,” commented one admirer.
What happens when real people follow fake hots
“Wow I’m a boomer,” said Patrick, one of Derek’s followers on X, after I told him that he might be following an AI-generated thirst account. (Vox agreed to let Patrick, and Derek’s other followers, use a pseudonym so they could speak frankly about being thirsty for a fake guy.) Prior to our chat, Patrick had no idea Derek was likely a deepfake, and maintains that he didn’t even know he was following the account. Patrick is 33 years old, roughly 30 years younger than the youngest boomer, but being fooled by a hot AI man has made him feel old and vulnerable, susceptible to scams and perhaps light financial crime.
“This was probably some smut account I followed before I moved all that over to an alt,” Patrick said, noting that in daily life, he’s only ever used AI to help organize and write emails. Wielding AI to create fake videos and photos does not thrill him, nor does the potential of seeing more of Derek.
How to spot a deepfake, especially when they’re hot
If you’re following someone extremely attractive online and found yourself wondering if they’re perfectly hot or simply an AI generated to be perfectly hot, deepfake experts and adult entertainers say there are a few things to check to see if your crush is an actual human:
- Look at logos or objects with text, like clocks and posters. As good as AI is getting, some apps still struggle with rendering text, numbers, and patterns. Instead of distinct text or numerals (e.g., the 12 digits on a watch face), it’ll look like a distorted jumble.
- Is the background consistent? If the background of a video or photo has an unusual blur to it, that could be a sign that a program was having difficulty creating the video.
- Is this person on OnlyFans? OnlyFans, as adult entertainers told me, has a set of rules regarding AI, along with an ID verification process — essentially, OnlyFans is where real creators are (at least for now). Smaller, less mainstream creator sites may not have the same kind of rules and guardrails.
- Is this person asking you for gift cards? “I don’t need an Amazon gift card,” one exasperated adult entertainer told me, pointing out that anyone asking for one-off, off-platform payments should raise suspicion. Other red flags also include asking for private information (like your bank account information or passwords).
- Are they too good to be true? Sometimes a fake hot can be “too perfect,” a digital forensic scientist told me. It’s worth asking yourself why that very handsome person is essentially shirtless on a plane in economy class, asking if you want to be his airplane crush, and thinking about how little sense taking this photo makes in the real world.
“A person being real, someone you could run into at a bar, is half the fun,” Patrick told me, explaining some of the accounts he follows. “AI porn is not of interest, to me, anyway.”
Not being able to tell the difference between the real beautiful men on the internet and the AI-generated beautiful men on the internet not only makes Patrick feel old, but also a bit “hollow.” The fact that the people we are attracted to are so unrealistically hot, so perfect, that machines can step in for them and go relatively undetected is a reflection of the current state of unattainable desire, which is just as scary as how good these programs have gotten at mimicry.
“Black mirror shit,” Patrick said.
The guys I DMed about Derek felt ashamed once they found out the truth.
“It’s embarrassing and he’s not my type,” said Chris, 33. “I’ve come across several AI accounts, and this one is really good, I have to say. But you can see there’s like no life in his eyes.”
Chris made clear to me that the humiliating thing isn’t that he follows attractive men on the internet. That isn’t a big deal.
What irks him that he got duped. Chris works in digital marketing and has seen AI used professionally to tabulate calculations for campaigns, and has used it privately for silly things like memes. “AI can do a lot of things, things we probably should not want it to do,” he told me. “I think what’s also scary…is that everybody has access to it. And yes I already unfollowed this person.”
Chris believes there’s something more nefarious afoot. He thinks that whoever is running Derek may have hijacked the username (i.e., the original person Chris was following) and then populated it with AI to drive up follower counts — a scam he’s seen online before.
“This is super concerning and super scary because you eventually could be texting with this person,” he said, describing a hypothetical situation where unknowing users could be lured into subscribing to fake content and, ultimately, giving the account their personal information, whether that’s photos or perhaps even passwords.
“This person could be selling your nudes,” he said, explaining one extreme end point of a possible scam. “But you were like jacking off to AI content and that’s embarrassing.”
AI deepfakes are bad for real thirst traps too
While flirting with or masturbating to a fake person is awkward but ultimately manageable and private, Cherie DeVille has an even more complicated problem with AI manipulation. If DeVille is scrolling social media, there’s usually a chance that she’s running into an AI version of herself saying things she’s never said and doing things she’s never done.
DeVille, an adult star who calls herself “The Internet’s Stepmom,” has roughly 4.5 million followers on Instagram. But her account is often down, which she says is the work of fraudsters that are determined to send traffic to DeVille’s AI imposters and get her actual account removed.
“It’s almost always the fake accounts of me reporting me,” DeVille said. “They want to be the biggest me. They want to be the biggest scammer. They want to use my altered AI images to scam fans without my real account getting in the way.”
DeVille and others I spoke to explained to me that deepfakes have been an annoying reality in the adult entertainment industry for years. The way the scam goes is that someone would fake photos or videos of DeVille (or any star), create an impostor profile, and then trick DeVille’s fans (e.g., through social media DMs) into following that copycat. Later they’d squeeze them for money, payments through Paypal, or Amazon gift cards, perhaps by offering unique content.
“If you made a fake me and I don’t do double anal, but my AI can, they could have all kinds of ‘exclusive’ stuff,” DeVille said, explaining that double anal is grueling work.
The lack of protections becomes even clearer when you consider that not every deepfake is a carbon copy. Some personas may borrow a face from one actress, a torso from another, or a pair of legs from a different star. This can make fakes tougher to track down and prove, and more difficult to fight from a legal aspect.
“Who owns your face once it’s scraped into AI systems? Who profits from your digital clone? How do performers protect themselves from unauthorized replicas or manipulated content?” Rachel Steele, an adult star and the CEO of Red MILF Productions, said to me in an email. “Those questions are still very unanswered.”
Like DeVille, Steele worries about how many of the people using AI to create and consume content don’t seem to consider the artists, models, writers, performers, etc. that these engines have been trained on. It’s bad enough to watch AI slurp up and regurgitate your written work or your digital art. Some people also have to contend with LLMs that have been trained on their own faces and bodies.
“Real creators are competing against characters that can be flawless in every image, never age, never have bad lighting, never get tired, and can appear available 24/7,” Raissa Bellini, an OnlyFans creator who touts gymnastics and firebreathing among her unique skills, told me of the impossibility of keeping up with a machine. She explained to me that she’s seen people create AI-generated personas with the looks of popular models or influencers, only tweaking small details like hair color or eye color.
A spokesperson for OnlyFans told Vox via email that the company’s terms of service prohibit deceptive or inappropriate content, and said that all content posted on OnlyFans must belong to a verified 18+ OnlyFans content creator: “This means that you can only share content which has been generated, altered or enhanced by AI if it clearly features the verified OnlyFans creator and the user can tell that the content has been generated, altered or enhanced by AI.”
Bellini explained to me that while OnlyFans has measures to protect its creators, some smaller subscription and adult-content platforms do not have the same kind of guardrails. She also noted that most social media sites do not have strict rules or enforcement when it comes to AI, and that she’s seen the algorithm appear to favor AI over human creators.
“AI raises questions not only about competition, but also about likeness rights, authenticity, audience expectations, and what happens when fans can no longer easily tell the difference between a real person and a generated character,” Bellini added.
What’s stopping a stranger from creating an AI thirst trap of you? Nothing, really.
For Deville, Steele, Bellini, their cohort, and even you and I, there are minimal protections stopping someone creating an AI us and making money off of these fake variants.
According to Jason Schultz, a law professor and director of NYU’s Technology Law & Policy Clinic, humans have, for the last couple of centuries, generally been protected by copyright and right of publicity laws.
AI obviously didn’t exist when these laws were written, and courts now have to interpret the laws in the context of all of this new technology, in combination with other existing rights (like free speech). Schultz told me that there are more than 100 current cases pending about training AI with copyrighted material.
He also explained the difficulty of determining whether or not an AI-generated persona constitutes a violation of someone’s right of publicity. It’s more clear-cut when the human involved is a celebrity, because their public persona and appearance is so distinct. It gets murkier when the humans aren’t well known, and the AI creates a persona that’s more of an amalgam than a one-to-one copy.
“It would raise this question of whether these avatars are based on a particular entertainer, or are they more of an aggregate?” Schultz explained to me. But even if courts side with the humans whose likenesses are being used to create fake personas, Schultz cautions that the technology will always accelerate faster than court decisions are handed down. “I think that the thing that worries me a little is we’re going to get these sets of decisions in two years, but we’ll be dealing with the next three generations of technologies,” he said.
DeVille, who has been working in the industry for nearly two decades, told me that without better legal protection, she isn’t hopeful for the future of porn or, more broadly, any type of art.
“If my income started tanking and their theft was at the point where I couldn’t compete with literally myself, there might be no choice but to retire,” DeVille said.
But she also wants to make it extremely clear that she isn’t against AI; she would just like to be in control of it. That means being able to own her likeness, her voice, her image, and the ability to choose whatever she wanted to do with it — or at least get some compensation or have some legal protection if someone’s using Cherie DeVille without her permission.
“It would be a beautiful way to extend my career beyond what my knees can take,” DeVille told me. But, she added, “if someone’s making an AI of me doing double anal, I should be making the money.”
Tech
BYD will unveil its first humanoid robot in August
BYD sells more electric cars than anyone. Next month, it wants to sell you one using a robot.
China’s biggest EV maker will unveil its first humanoid robot in August, at its Di Space experience centres in Zhengzhou, the company told the South China Morning Post. It will be a working prototype, not a concept, and it will mingle with visitors.
The robot reportedly has a name and a job. According to Chinese outlet KrASIA, citing a since-deleted BYD post, it is called “Xiao Di,” a service humanoid that stands 1.61 metres, weighs 58.5kg and can translate between six Chinese dialects and six foreign languages in real time. BYD has not officially confirmed the specs.
Cars first, then everything else
The plan starts in the showroom. Executive vice-president Stella Li wants two or three robots in every BYD store, greeting customers and explaining cars. She insists they will assist human staff, not replace them.
From there, the ambition widens: supermarkets, malls and warehouses in the medium term, and eventually homes, doing the cleaning, cooking and companionship. BYD says it will build an open platform that makes both its own robots and models co-developed with others.
Its pitch is manufacturing. BYD already builds its own batteries, motors and electronics at huge scale, and Li argues cars and robots share the same roots. That, in theory, lets it build robots more cheaply than a standalone startup can.
Everyone with a car factory wants one
BYD is not early. It is late. Tesla’s Optimus is the headline rival, but China’s carmakers are swarming in. Xpeng is trialling its Iron robot, Li Auto is exploring designs, and Chery’s Aimoga is already selling to consumers.
The backdrop is a humanoid boom. China made about 20,000 humanoids in 2025 and more than 40,000 in the first half of 2026 alone, with the government pushing for far more. Some forecasts stretch to tens of millions of robot workers within a decade.
The catch, and the timing
There is a reason for the robot rush, and it is not entirely rosy. BYD’s car business is under strain, with first-half sales down about 16% amid China’s brutal price war. A new growth story is welcome.
But a slick demo is not a business. Investors still have no price, no production timeline and no paid deployments to judge. BYD has also denied separate reports of a factory robot line, so much remains unconfirmed.
And the overseas door is closing. The move lands just as the US moves to bar imports of Chinese robots, which could keep Xiao Di out of one of its biggest potential markets. For now, BYD’s robot has one job: sell cars, in China, from a showroom floor.
Tech
Viaim RecDot Review: These AI earbuds sounds great and also take notes for you
Quick Take
The Viaim RecDot grabbed my attention because they offer a truly unique feature to wireless earbuds. Rather than chase the best possible sound or the best noise cancellation, they’re built to capture, transcribe, and summarize everything you hear. Simply hit the record button (located on the case) and choose a record mode to turn calls, lectures, and in-person meetings into searchable transcripts. The Viaim app’s AI then gives you summaries and to-do lists within seconds. If you spend your day in back-to-back conversations and are ok giving up your AirPods, then the RecDot can be a very helpful companion.
The Viaim RecDot is a decent set of earbuds in their own right. The 11mm titanium-coated drivers produce fairly good, detailed, balanced sound that produces great vocals and acoustic tracks, and battery life runs up to nine hours per charge, or 36 with the case. Calls came through clearly for me in most calls, and the recording and transcription features are fast and dependable. Translation covers more than a dozen languages, and the whole system is easy to live with once you accept that the app is doing most of the work.
On the other hand, they’re not perfect. Noise cancellation is good, not great, and bass gets muddy on some deep house or hip-hop tracks. The build feels plasticky, and at full price they sit uncomfortably close to more polished all-rounders from Apple, Soundcore and Samsung. But if your main goal is capturing and organizing what’s said around you, the RecDot does it very well. For the right buyer, these are a great choice that I would recommend.
Viaim RecDot specifications
| Product | Viaim RecDot AI Recording True Wireless Earbuds |
| Drivers | 11mm titanium-coated dynamic drivers |
| Bluetooth | Bluetooth 5.2, multipoint (dual pairing) |
| Codecs | AAC (manufacturer does not detail full codec list) |
| Noise cancellation | Smart ANC, rated up to 48dB reduction; auto/low/mid/high modes |
| Battery life | Up to 9 hours (buds); up to 36 hours with charging case |
| Charging | USB-C and wireless charging |
| Water resistance | IPX5 |
| Weight | ~4.9 g per earbud |
| Eartips | 5 sizes included, with in-app fit test |
| AI features | Real-time transcription, summaries, to-do lists, mind-map, translation (14+ languages); 600 free minutes/month, 1800 minutes for $9.99/month and unlimited minutes for $19.99/month |
| Price | $249.99 MSRP (frequently $179–$219 at retail as of July 2026) |
Viaim RecDot design, build & comfort

The RecDot follows the long-stem template Apple made famous, but these sit a touch chunkier in the hand than the AirPods 4 that I use on a regular basis and the AirPods Pros that I borrowed to compare these against – and you notice it. That extra bulk makes room for the recording hardware, so it’s easy to understand why it’s there. The build leans more plastic than premium, and the sliding lid on the charging case feels flimsier than the rest of the package at times. Everything else about the case is genuinely good. The buds snap into their magnetic cradles with a satisfying click and stay put no matter how hard you shake the thing.
Best of all is a physical record button on the outside of the case, which starts a meeting recording with a single press. It’s a smart, tactile touch, though the tiny blinking light that tells you recording is live could be far more obvious in direct sunlight. Viaim throws in five sizes of eartips, which is more generous than most, and an in-app fit test runs frequencies through the earbuds to check your seal. Swapping tips is a little fiddly, but once you land on your size, the fit holds up for long sessions. These aren’t gym buds, though.
The fit isn’t tight enough for running or hard training, but for sitting at a desk, commuting, or grinding through a day of meetings. Controls live on the stem as a touch sensor that handles play, pause, volume slides, and track skips. Overall, it works. There’s no haptic confirmation, though, so you sometimes can’t tell whether your tap registered, and the triple-press to jump back a track takes practice. If you plan on switching earbuds for different occasions (like running, flying, etc), then you might have a tough time remembering the tap sequences.
Viaim RecDot app, transcribing & features





This is where the RecDot earn their name and why you would buy them. There are three ways to record: call recording that transcribes system or VoIP calls in real time, audio or video recording that transcribes a clip, and live recording for face-to-face conversations and small meetings. Starting a recording was fairly straightforward for me, whether you press the button on the case or hold the stem until you hear “recording start.” Pressing the button on the case was simpler for me.
You can choose to have every call auto-record as well. When you have this turned on, you will hear a voice telling you and the person on the other end that the call is being recorded. Everything winds up in the Viaim app, and this is the one thing I had to learn. Viaim markets recording on the buds themselves, but the transcription and AI features live in the app. Simply put, the app isn’t optional. You have to use it.
Once your audio is in, the AI does the work. Transcription was pretty reliable and thorough for me in my testing, picking up speech with few errors. The meeting assistant extracts concise summaries and pulls out actionable to-do items, and it does so quickly and with surprising accuracy about who owns what. There’s even a mind-map view, and the app taps large language models such as ChatGPT, Gemini, and Claude for its AI tools. Transcripts can be translated into more than a dozen languages, though translation is laggy, the way it is on rival systems.
Note: I only used Spanish in my translation testing.
Two quirks jumped out for me. A long pause makes the software insert a full stop or start a new sentence, so you’ll do some light cleanup afterward, and speaker separation is inconsistent, nailing it in some sessions and merging voices in others. My hope is that future firmware updates will fix this. You get 600 free transcription minutes a month, which most people won’t use up. If you want more minutes, you’ll need to spend extra per month for those (I listed them above in the specs, and below in the FAQs). One practical note the marketing skips: recording conversations carries legal and etiquette obligations that vary by location, so know the consent rules where you are before you hit record.
The rules depend on where you and the other person are. Federal law and most states use one-party consent, meaning if you’re part of the conversation, you can record it without telling anyone else. That covers states like New York, Texas, and Virginia. A minority of states like California require all-party consent, where everyone must be informed and agree before you record. In those states, quietly recording a meeting or call can be a crime even if you’re a participant.
Viaim RecDot sound quality
For a product built around AI, the RecDot sounds better than I expected it to. The 11mm titanium-coated drivers put out a vibrant, detailed, crisp presentation that leans balanced rather than bass-heavy, great for vocals. Ed Sheeran’s Azizam (a recent favorite of mine, make fun all you want) serves up a dance beat that punches through without trampling the vocal, and the soundstage runs surprisingly wide for earbuds. Orchestral material holds up too, with clear separation between flutes, piano, and the rest of the sections.
Where the RecDot’s struggled for me is during dense, heavy music. Rock tracks can turn muddy and cluttered at times, the loudest sections sounding squashed rather than powerful. Bass occasionally feels stuck and short on depth, and percussion can lean tinny. Sparser genres like acoustic, singer-songwriter, soul, and ambient electronic are where these buds shined for me. There’s an EQ in the app with pop, bass boost, and electronic presets, and while a few nail specific tracks, none held up reliably across a broad library, so the default balanced profile is the one that I thought worked best for me. Audiophiles looking for next-level detail will want a dedicated pair of earbuds, or straight-up over-the-ear headphones. Everyone else will find the sound more than pleasant.
Viaim RecDot active noise cancellation
Viaim’s Smart ANC claims up to 48dB of reduction, and in daily use it does a decent job of quieting an office or a commute on a plane or bus. It isn’t class-leading, and I felt like it was on par with my AirPods 4 in most instances. To be fair though, I think the AirPods 4 do an OK job. I have been on plenty of calls where the person on the other end had ANC turned on, and they were difficult to hear during that call. Put the RecDots side-by-side with the best buds at this price, and the RecDot let more low-frequency rumble through, and jet-engine noise on a long-haul flight would test its limits. There are low, middle, and high manual modes, but none of them stayed reliable as environments changed, so the auto setting is the one I would recommend. Auto occasionally colors the sound in the process, but that beats fiddling with presets every time you move rooms. For everyday commuting and open-plan offices, the ANC is more than good enough.
Viaim RecDot call quality

The RecDot’s call quality is clear and dependable. In my tests, callers said my voice came through cleanly, with only a slight fuzziness on sharp sibilant sounds, and the mics keep background noise off the line. In a busy environment, you can still make out a caller’s words without straining. As I mentioned before, it’s not the best on the market, but it’s perfectly reliable for the meetings and 99 percent of the calls you will make.
Viaim RecDot battery & charging
Battery life really surprised me. Coming from my AirPods 4, I was expecting to get about 4 hours of continuous use, but was able to push beyond that in the 7-9 hour range with the RecDots. You get up to nine hours from the buds themselves and an extra 36 hours with the case as a charger, which comfortably outlasts AirPods Pro and Samsung’s Galaxy Buds. In my testing, eight hours of listening drained the buds to 80 percent, which is a lot given all the recording and processing happening in the background. The case charges over USB-C or wirelessly, which is a nice convenience at this price. Cheaper rivals push past 40 hours, but for a pair doing this much processing, the RecDot’s battery life is more than competitive.
Viaim RecDot comparison & alternatives

Apple AirPods Pro remain the pick for anyone in the Apple ecosystem who cares most about noise cancellation, fit, and easy device switching, and they now do basic live translation, though they can’t come close to matching the RecDot’s structured summaries and to-do lists. Samsung Galaxy Buds are the equivalent choice for Galaxy owners, with strong ANC and longer battery than Apple, and they only cost a little more than the RecDot. For pure recording on the cheap, dedicated AI note-takers like the Plaud NotePin capture and summarize conversations for less, but you lose the everyday earbud. The RecDot’s whole argument is that it does both jobs in one device, and for the right person that combination justifies the premium. And I’d say for the average person, the premium is worth it.
Verdict: Should you buy them?
The Viaim RecDot are a forward-looking pair of earbuds that do the one thing they set out to do, and they do it extremely well. Recording and transcription are fast, accurate, and super useful. The sound and battery life are much better than I expected. Holding them back from being a perfect 10 for me is the ANC that trails the best in class, bass that struggles with heavier music, a plasticky build, and a premium price. If your days are full of meetings, lectures, or interviews, nothing else at this price captures and organizes them as neatly. I found the RecDot to be the perfect companion for my work and play schedule. Score: 4 out of 5.
How I tested the Viaim RecDot earbuds
I tested the Viaim RecDot over three weeks of daily use, wearing them for meetings, calls, drive-time and plane commutes, and focused desk work, with listening sessions running well past two hours at a stretch. I streamed music from Spotify, Pandora, and Apple Music across an iPhone and a laptop, listening to EDM/House, Rock, classical, acoustic, and podcast material, and leaned on the recording and transcription features across real calls and in-person conversations. I compared them directly against Apple AirPods 4 and AirPods Pro for sound, ANC, and call quality.
FAQs (Frequently Asked Questions)
Do the Viaim RecDot record phone calls?
Yes. Call recording transcribes system and VoIP calls in real time. You either hold the stem or press the button on the case to start. I found the button on the case to be the simplest. The transcript, summary, and any to-do items appear in the Viaim app afterward.
Do I need a subscription to use the AI features?
You get 600 free transcription minutes a month, which covers most people. Heavy, all-day recorders may hit that cap; the AI tools themselves run through the Viaim app. Viaim offers a Pro plan, which is $9.99/month or $79.99/Year and comes with 1800 minutes, and an Ultra plan, which is $19.99/month and $159.99/year and has unlimited minutes.
How many languages does translation support?
Transcripts can be translated into more than a dozen languages, including English, Chinese, French, and German. Translation works but lags in real time, much like it does on Apple and Samsung buds (from what I have researched).
Are the RecDot good for working out?
Not really. The IPX5 rating shrugs off sweat and light rain, but the fit isn’t tight enough for running or hard training. They’re built for desks, commutes, and meetings. You’ll want dedicated earbuds for that.
Should I buy the RecDot over AirPods Pro?
Buy the RecDot if automatic transcripts, summaries, and to-do lists genuinely save you time. Choose AirPods Pro if you mainly want stronger noise cancellation, a snugger fit, and tight integration with Apple devices.
Tech
A Fundamental Flaw Leaves LLMs Strikingly Vulnerable To Attack
joshuark quotes a report from MIT Technology Review: It is impossible to make large language models fully secure against hacks because of a fundamental flaw in how they work, a team of researchers argue in a paper presented at the International Conference on Machine Learning, a top AI conference, this month. The claim has huge implications for the safety of this technology. By taking advantage of this flaw, which concerns how LLMs identify who or what is giving them instructions, the researchers were able to make popular LLMs spit out information they had been trained not to provide, such as how to synthesize cocaine and how to sabotage a commercial aircraft’s navigation system. “There’s a real probability that this is going to be a problem that’s fundamentally unsolvable,” says Charles Ye, an independent researcher and coauthor of the ICML paper. […]
The ICML paper describes attacks against several of OpenAI’s models, but Cui and Ye say that they have since seen similar results with models made by Anthropic, Alibaba, and DeepSeek. Cui and her colleagues wanted to find out why an attack like chain-of-thought forgery was so effective. They suspected it had something to do with the mechanism that LLMs use to keep track of where their instructions are coming from. But what Cui and her colleagues discovered is that LLMs are in fact very bad at keeping track of different roles.
In a series of experiments that looked at what was going on inside a handful of different models, the researchers found that LLMs seem to identify the role of a specific chunk of text not by the tags around it but by the style of that text and the words it contains. The upshot, the researchers claim, is that all an attacker needs to do to hack an LLM is write text that spoofs a certain role. And because roles are a fundamental part of how LLMs work, no amount of training will fully solve the problem. “There’s going to be a huge economic incentive for people to do jailbreaks and prompt injections,” says Cui. The best defense could be to expect the worst. Organizations shouldn’t trust LLMs, and they should expect that anything done by agents could be unsafe, he says: “That’s not a great solution, but it just might be what we have to do.”
“It’s really incredible that these things are being deployed everywhere to control super-critical systems. There’s been no study of the fundamental science here. We’re all doing it ad hoc.”
Tech
Can Winamp and Deezer Put Streaming and Your Music Library in One Place?
Winamp will use Deezer technology to launch a premium streaming service in 2027, combining subscription music with local files, radio, podcasts and cloud libraries. It sounds useful, but the important details remain missing.
Before Spotify, Apple Music and recommendation algorithms decided what everyone should hear next, millions of listeners stored their music on a computer. Those collections were assembled from ripped CDs, purchased downloads and MP3 files acquired through methods best left between the listener and their internet service provider.
Winamp was the software that made those libraries manageable.
The Windows music player let users organize playlists, adjust an equalizer, install plug-ins, run visualizations and completely change the interface through downloadable skins. It was fast, flexible and considerably more personal than most of the streaming apps that eventually replaced it.
Now Winamp wants another opportunity to shape digital music playback.
The company announced on July 29, 2026, that it has formed a strategic partnership with Deezer to develop a new Winamp Player. Scheduled for the first half of 2027, the software will combine a Winamp-branded premium streaming service with locally stored music, internet radio, podcasts, personal cloud collections and other audio sources.
That is considerably more interesting than launching yet another streaming service. The world already has enough of those, along with enough annual price increases to make renting the same albums indefinitely feel like a retirement strategy.
What Was Winamp?
Winamp first appeared in 1997 and was developed by Justin Frankel through his company Nullsoft. It arrived as the MP3 format was beginning to change how music could be stored, shared and played on personal computers.
Winamp did not invent digital music, but it helped make large computer-based libraries practical for ordinary users. AOL acquired Nullsoft in 1999 after the software had attracted millions of listeners.
Its popularity was about more than playback. Winamp gave users control over how their music was organized and how the software looked. Thousands of skins and plug-ins turned it into something that felt personal rather than another corporate storefront.
The player later drifted through ownership changes and uncertain development. AOL announced plans to discontinue it in 2013, although the shutdown did not happen as expected. Belgian internet radio company Radionomy acquired Winamp and Shoutcast in 2014.
Winamp never completely disappeared. A legacy Windows version remains available, while newer mobile applications have been released for iOS and Android.
Calling the 2027 product a full comeback is therefore not entirely accurate. Winamp has been trying to rebuild itself for several years. The significant change is the addition of a complete subscription streaming service powered by Deezer.

What Are Winamp and Deezer Building?
Deezer will supply its catalog and white-label streaming technology, but the service will be presented as a native Winamp subscription rather than Deezer wearing someone else’s jacket.
Winamp says the new player will bring together streaming music, local files, internet radio, podcasts and personal cloud libraries within one customizable interface. The company is also promising social features and new tools for music discovery and organization.
The existing desktop player will eventually gain access to the premium subscription.
Winamp and Deezer also claim that more than 40 million people still actively use the desktop software worldwide. That is an extraordinary figure for an application many listeners assumed had disappeared alongside dial-up modems, although neither company has provided independent verification.
Deezer is a logical infrastructure partner. It already operates a global streaming service and supplies music technology to telecommunications companies, hardware manufacturers and other third-party businesses.
For Deezer, Winamp creates another way to distribute its catalog without having to persuade Spotify and Apple Music subscribers to switch directly to the Deezer brand.

Why Deezer?
Deezer enters the Winamp partnership from a stronger financial position than its smaller market share might suggest.
The French streaming company reported revenue of €268.2 million for the first half of 2026, adjusted EBITDA of €8.5 million and net income of €6.7 million, reversing a €7.6 million loss from the same period one year earlier. Direct subscribers increased 8.7% to 5.8 million, although Deezer’s total subscriber base declined 3.5% to 8.9 million as subscriptions supplied through outside partnerships continued to fall.
Deezer is not remotely close to challenging Spotify or Apple Music on scale, but it has a licensed global catalog, lossless streaming technology and an expanding business supplying music infrastructure to other companies. Winamp does not need Deezer to become the world’s largest streaming platform. It needs Deezer to make the plumbing work.
What Are the Alternatives to Winamp?
Winamp will not be the first platform to combine locally stored music with subscription streaming.
Roon is the most obvious alternative for audiophiles. It merges local files with services including TIDAL and Qobuz, adds extensive metadata and discovery tools, supports bit-perfect playback and works with more than 1,000 compatible audio devices. It is also priced at $14.99 monthly, $149.88 annually or $829.99 for a lifetime subscription, before anyone buys a dedicated Roon server.
Audirvāna Studio also combines local files stored on computers, USB drives and NAS devices with TIDAL, Qobuz, Presto Music, HIGHRESAUDIO and internet radio. Its emphasis is more firmly placed on high-resolution playback and computer-based audio than mainstream discovery or social features.
Plexamp is another strong option for people who primarily want to organize and stream their own music collection. It offers gapless playback, loudness leveling, smart playlists, CarPlay, Android Auto, AirPlay and Chromecast, but it does not merge that library with a full subscription music catalog in the same way Winamp is proposing.
Winamp’s opportunity is therefore not proving that local and streamed music can coexist. Roon and Audirvāna already do that rather well. Its challenge is making the experience simpler, cheaper and more accessible to people who do not own a dedicated server or use “bit-perfect signal path” in casual conversation.

Why Does This Matter?
Streaming services have made access to music remarkably convenient, but they have also separated many listeners from the music they already own.
Someone with 2,000 ripped CDs, purchased FLAC downloads, independent releases, live recordings and carefully organized playlists often needs one application for local files and another for streaming. Internet radio, podcasts and cloud storage may require additional software.
Winamp wants to put those sources inside one player.
That could be genuinely useful because streaming and locally owned music serve different purposes. Streaming is excellent for discovery and immediate access. Local files offer permanence, specific masterings and control over recordings that may disappear when licensing agreements change.
Winamp is not the first company to attempt this. Roon combines local libraries with several streaming platforms, while music servers from companies such as Innuos merge stored files with subscription catalogs. Apple Music also allows listeners to manage local music alongside its streaming library.
The difference is that those solutions are either tied to specific ecosystems, require another subscription or work best with dedicated audio hardware.
A properly designed Winamp application could offer a broader software-based alternative for listeners who want one library without purchasing a dedicated music server.
The word “could” is carrying a rather large loudspeaker up the stairs.
Who Would Use It?
The most obvious audience consists of listeners who built substantial digital music libraries during the CD-ripping and download eras and never deleted them simply because Spotify arrived.
That includes people with MP3, AAC, ALAC, WAV and FLAC collections stored on computers, external drives or cloud accounts. It also includes listeners who buy music directly from artists, collect alternate masterings or own recordings unavailable through mainstream services.
Existing Winamp users are another natural audience, assuming that 40 million figure is remotely close to reality.
The player could also appeal to people who dislike the increasingly uniform design of major streaming applications. Customization was central to Winamp’s original appeal, and the company says users will again be able to modify layouts and create skins.
Audiophiles should remain cautious.
Deezer currently offers lossless streaming, but neither company has confirmed that the Winamp subscription will include lossless audio. There is also no information about bit-perfect playback, exclusive audio modes, automatic sample-rate switching, USB DAC support or compatibility with network streamers.
Until those details emerge, this is a promising library-management concept rather than an audiophile playback platform.

What We Don’t Know
Winamp has not announced the price, launch countries or which operating systems will be supported at launch. There are no confirmed details about streaming quality, offline downloads, family plans, playlist transfers or whether existing Deezer subscribers will have any upgrade path.
The company has not identified which cloud-storage platforms will work or whether the player will index NAS drives and shared network folders.
Hardware support is another large blank space. Winamp has not confirmed AirPlay, Google Cast, UPnP, DLNA, smart-speaker integration, automotive support or direct playback through connected audio components.
It has also not demonstrated the finished software.
At this stage, Winamp and Deezer have announced a partnership, a concept and a 2027 release window. That is not the same thing as delivering a stable player capable of merging a complicated local library with millions of streamed tracks.
The Bottom Line
Winamp and Deezer are pursuing an idea that deserves attention.
Major streaming services have spent years improving discovery and recommendation systems while often treating locally owned music as something listeners abandoned with CD binders and beige computers.
Millions of people still own large digital collections and should not require a separate archaeological expedition every time they want to play them.
Deezer gives Winamp a catalog, licensing relationships and streaming infrastructure. Winamp brings a recognizable brand and decades of experience with local music playback and customization.
That combination could produce a genuinely useful alternative to conventional streaming apps. It could also become another Deezer-powered service with a different logo, several customizable buttons and a marketing department leaning very heavily on the past.
The difference will come down to pricing, audio quality, hardware support and whether Winamp can combine local and streamed music without turning library management into unpaid technical support.
The llama may still whip the llama’s ass.
It also needs to support your DAC.
For more information: winamp.com
Related Reading:
Tech
Building a Secure and Scalable DevOps Environment Using Open-Source Tools
We can all see how the newest digital products require flexibility and the ability to scale quickly together with the business. At the same time, they must cope with growing workloads. That’s why teams choose is*hosting for their Linux VPS hosting to get the job done. Flexible server solutions make it possible to configure resources, select a suitable location, and deploy the environment automatically.
The list of users who will find this helpful is extensive: DevOps engineers, web application developers, SaaS platforms, and many others. Using open-source tools helps them create a reliable, transparent, and scalable environment for development and operations.
DevOps is today one of the key approaches to creating and managing software products. It connects development, testing, and operations, helping teams work faster. Open-source tools make workflows easier and flexible. Open source is basically built to bend. You can customize your tools, stitch them together, and automate the boring stuff. Honestly, it’s a perfect fit for pretty much anything — web, mobile, cloud, data, or AI.
It is fair to say that several specific DevOps components help automate processes, improve system stability, and shorten the time between product development and launch. These include:
- application build automation;
- containerization of production services;
- server configuration management;
- infrastructure health monitoring;
- secure storage of credentials.
Less manual grunt work means fewer mistakes. Auto-deploys let you ship updates in a flash, while smart monitoring catches performance bottlenecks before they become fires.
Scalable Infrastructure for DevOps Teams
In practice, any DevOps model requires a reliable and powerful infrastructure. Every project, even the smallest one, must have the ability to quickly scale resources as more and more users join or as technical requirements change. The server environment must support flexible power settings, rapid creation of new environments, and stable service operation.
International IaaS providers offer VPS/VDS, dedicated servers, VPN services, and additional infrastructure solutions. Users can configure key server parameters, including:
- processing power;
- amount of RAM;
- drive type;
- data center location.
A broad infrastructure geography makes it possible to select suitable locations for different projects and reduce access latency. Such opportunities are in demand in various fields. Online stores use scalable servers to handle large numbers of requests.
When choosing DevOps infrastructure, it is important to consider not only current challenges but also growth prospects. A flexible server platform should allow configuration changes without complex migrations. Among the most popular features are:
- setting up CPU and RAM;
- use of fast NVMe drives;
- support for different operating systems;
- connecting additional IP addresses;
- automatic deployment of environments;
- integration via API tools.
This model makes it easier for technicians and helps launch new projects faster. DevOps teams can create test environments, run experiments, and migrate applications between environments with minimal time investment.
Fundamentals of System Security and Resilience
As soon as digital products begin to evolve, securing the system as a whole becomes just as important as maintaining performance. Good companies must secure the users data, provide uninterrupted service, and minimize the risk of breakdowns.
It is exactly these advanced open-source tools that help not only manage the entire system but also monitor it clearly. Teams will be able to track changes, audit settings, and implement additional security measures. When building a secure DevOps environment, special attention is paid to the following aspects:
- isolation of virtual servers;
- data backup;
- protecting network connections;
- use of IPv4 and IPv6;
- user access control.
KVM technology ensures effective isolation of virtual machines and stable operation of VPS servers. SSDs and NVMe drives enable faster processing, and the latest generation of Intel Xeon and AMD EPYC processors allows you to run resource-intensive applications.
How to Choose Infrastructure for Long-Term Development
Choose a server that actually grows with you. You want to scale smoothly without hitting hidden fees. Look for clear, pay-as-you-go pricing — it’s the smartest way for startups to get top-tier tech without breaking the bank.
Flexible servers work for almost any project. Building an edtech app? Marketing tools? Analytics? AI? To summarize, good infrastructure is the secret sauce to keep your product growing smoothly.
When you need a comprehensive strategy, keep in mind that it can only be based on a successful combination of elements. This includes automation, open-source tools, and high-quality server infrastructure. Together, they create a secure and scalable DevOps environment. These technologies help developers build products faster, monitor all critical processes, and manage resources as efficiently as possible.
Tech
Crissa Graves Built a Handheld Game Boy Pocket Camera That Actually Shoots

Photo credit: Crissa Graves
Crissa Graves has spent years making the old Game Boy Camera feel less like a novelty and more like something you might actually carry. Her latest prototype, the GBD-M2, takes that work further. It starts with a fully working Game Boy Pocket and turns the whole thing into a dedicated handheld camera with a removable camera module and interchangeable CS-mount lenses.
Video of Camera GBD-M2 in action
Once I’ve reached a comfortable place with the project, I plan on sharing the files to build yourself
— Game Boy Camera (@gameboycamera.com) July 28, 2026 at 4:20 PM
You still get the same 128 by 112 pixel grayscale photographs that the first Game Boy Camera produced in 1998. The small little sensor from that era remains at the heart of every photo, but Graves has simply given it a body that makes you feel like you’re holding a proper camera while still being able to play all of the original Game Boy titles.
There is a dedicated shutter button that sits exactly where your finger would normally go, and the screen is a nice illuminated IPS LCD that you can see outside, which is a great benefit. An 1800mAh battery will keep you snapping away for hours, and you can even charge it via USB-C. The connection connector remains, allowing you to transfer your images to a Game Boy Printer. Surprisingly, Graves claims that you can even play some casual games like Tetris or Pokémon one-handed, despite the fact that the speaker has been removed from this version.

Graves had already completed various iterations of this Camera M project, demonstrating that the whole concept was feasible, although those older versions required hacking into a Game Boy Pocket and had some rather improvised power boards that you’d have to cobble together. The GBD-M2 is a completely new design that takes the Game Boy’s original CPU and RAM and transplants them onto a fresh new circuit board without interfering with a functional handheld. The layout is more camera-like, with bespoke buttons and a shell that has been reduced to a more manageable size after several rounds of design improvement. You also get two battery options: a LiPo battery that can be charged by USB-C, or a set of simple AA cells that you can replace out when they run out.

The camera module detaches, allowing you to replace the custom CS-mount version with alternative lenses, insert the original Game Boy Camera, or simply load a typical old game cartridge. Graves has already created a separate camera module the size of a regular game cartridge, using an iPhone lens and a custom board, which still works in any Game Boy. The GBD-M2 employs the same technique, but in a body designed to be portable and usable.



There are no mass production plans for this device yet, but Graves has mentioned releasing both DIY kits and a limited run of the finished model. You can access all of the files and updates on her GitHub page for the Camera M2 project. For the time being, the GBD-M2 is only a functional prototype, the latest stage in a long journey to find new methods to revitalize an old relic from 1998. You may monitor her progress at gameboycamera.com and on her Bluesky account.
[Source]
Tech
Apple services hits 1.5 billion subs but misses Wall Street
Apple has reached 1.5 billion paid subscriptions across its platform, adding another milestone to an Apple Services business that generated record June-quarter revenue of more than $30 billion.
CEO Tim Cook disclosed the milestone during Apple’s fiscal third-quarter earnings report. Apple didn’t provide a breakdown showing how many subscriptions belong to its own services or third-party apps sold through the App Store.
The figure represents paid subscriptions rather than 1.5 billion individual customers. A single customer can hold multiple subscriptions, and multiple devices in use, across services such as iCloud, Apple Music, Apple TV, and third-party apps.
Apple’s Services division generated $30.74 billion during the June quarter, up 12% from a year earlier and setting a new June-quarter record. Revenue increased across advertising, the App Store, AppleCare, music, video, iCloud, and payment services.
The result still came in below the $31.22 billion analysts expected. Apple cited foreign exchange headwinds, but the shortfall against Wall Street’s estimate doesn’t change the division’s year-over-year growth or its new June-quarter record.
Services generated $30.9 billion in the previous quarter, continuing the division’s steady growth beyond hardware sales. The latest result rose from $27.4 billion in the same quarter a year earlier.
Apple also has more than 2.5 billion active devices in use, giving the company a large installed base for subscriptions and other digital services. Paid and transacting accounts reached records during the previous quarter, although Apple didn’t disclose a comparable subscription count at the time.
The 1.5 billion total is more than 50% higher than the nearly one billion paid subscriptions Apple reported in 2023. The increase shows continued expansion across Apple’s subscription ecosystem even as quarterly Services revenue missed analysts’ forecast.
Services have become a major source of repeat business beyond Apple’s hardware sales. The latest milestone reinforces that growth, while the Wall Street miss shows investors are still judging the division by the revenue those subscriptions produce.
Tech
How ThinkPad designers gaslit IBM to save the iconic TrackPoint
“It’s not red,” IBM’s design center manager patiently explained. “It’s magenta.”
The safety function officer wasn’t buying it. Between his fingers, he held up a small, rubbery disc that looked like a pencil eraser. “You know it’s red and I know it’s red,” he said.
The design manager didn’t back down. He insisted that what the man held was indeed magenta. The safety officer called his boss. The boss called Tom Hardy, Design Program Director at IBM. Hardy didn’t flinch.
Latest Videos FromTechRadar
“It’s not red. It’s magenta.”
It was one of the boldest lies ever told in tech. And it made the ThinkPad iconic.
Years later, Hardy relayed the incident in an interview with Laptop Retrospective, detailing the design origins of the TrackPoint, the input stick resting in a central position of the ThinkPad keyboard since 1992.
Instantly recognizable today, the little red nub remains core to the ThinkPad’s identity. For anyone working in design, its history serves as a lesson on creative control and innovation.
Every designer knows red on black is a classic combination. So, for Hardy’s team, it was a no-brainer choice when first tasked with adding the TrackPoint to the system.
However, at the time, IBM instituted a strict color-code. For control systems like the TrackPoint, the standard was blue. Playing by the rules, the team toyed with that. According to Hardy, “it just didn’t sing like red did.”
They switched back to red. But there was a major problem with that.
Red was reserved for emergency power shutdowns. It’s the kill-switch color. Hardy knew, even then, the safety team had to approve the color scheme. There was no way they’d let it ship with a red cursor control. That simply wasn’t the way it was done.
Rather than fight and inevitably lose that battle, the designers got creative.
They scrapped every trace of ‘red’ in the documentation. They replaced it with ‘magenta’.
“The safety guys,” Hardy explained, “They may not know what magenta is, but they’ll know it’s not red.”
They may not know what magenta is, but they’ll know it’s not red.
Soon, the parts came in, labeled as magenta. No-one looked twice at them until the safety official snooped on a box of TrackPoints and demanded to know who approved the color for non-power related functions. He didn’t get an answer he liked. He threatened to shut down the whole production line.
Hardy got involved shortly after. Corporate on corporate combat ensued, arguing over the subjective difference between magenta and red. “The next stop in the line,” Hardy reminded them, “It goes to the CEO.”
Fighting his corner, he tells them, will be famed industrial designer Richard Sapper who created the classic ThinkPad design, as well as corporate graphic design consultant Paul Rand, the man behind the IBM logo. Both are color experts.
Even as the back and forth continued, Hardy’s team had linked up with the advertising team. The ad agency had poured millions of dollars into a campaign that was ready to launch. “So hot,” the adverts said with a close-up on the new TrackPoint, “We had to make it red.”
It was enough to make the safety team think twice. Later that day, an email was sent. It said: ‘Make them red.’
They’ve been the same iconic color ever since.
It’s no secret I’m a massive ThinkPad fan ever since I got my paws on a T431s, but check out the best business laptops my team and I have tested.
Tech
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers.
The cloud computing giant linked the compromises of the typo-crypto, debug, chalk, and axios libraries to the Sapphire Sleet threat actor, also known as BlueNoroff and Stardust Chollima.
Initial activity started with trojanizing the typo-crypto package in March 2025, which Amazon believes served as a testing ground. It then escalated in September of the same year with the compromise of the widely used debug and chalk packages, affecting an estimated 10% of cloud environments within two hours.
In March 2026, the hacker targeted axios, one of npm’s most popular packages with over 100 million weekly downloads.
It should be noted that the axios incident has already been publicly attributed to DPRK-linked actors, but Amazon connected it to the earlier package compromises.
Amazon says the attacker gained access by socially engineering package maintainers, and then published malicious updates that were automatically distributed to unsuspecting users.
The attribution to Sapphire Sleet has medium confidence and is based on the shared tactics, techniques, and procedures (TTPs) observed in the campaign, the command-and-control (C2) infrastructure, and various operational similarities.
Also, the researchers believe the attacker had a financial motivation, targeting popular packages to gain indirect access to a large pool of potential downstream victims at once.
Amazon also highlights several trends that have emerged from the recent supply-chain attacks:
- Attackers are splitting malicious functionality across multiple seemingly benign packages, making detection more difficult.
- Threat actors are spending months building trust by maintaining legitimate projects or becoming contributors before introducing malicious code.
- Malicious behavior is increasingly decoupled from package contents, relying on external scripts, configuration files, or servers that can be weaponized later.
- Malware is using stronger encryption and multi-stage payloads, with runtime or remotely fetched keys that hinder static analysis.
- Payloads are becoming environment-aware, delaying execution unless they detect real developer or production environments to evade analysis sandboxes.
- Attackers are increasingly exploiting “slopsquatting” by registering package names hallucinated by AI coding assistants, hoping developers or autonomous coding agents will install them.
Many of these tactics are enhanced and simplified by AI, Amazon explains, as they help attackers generate code, documentation, and maintainer identities.
Amazon highlighted a multi-faceted response to these dangers, including reporting its findings and intelligence to the community, collaborating with OpenSSF and other industry partners, and investing $12.5M in the Akrites initiative, which helps protect critical open-source software from AI-enabled attacks.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Tech
Fixing A JMicron-Based M.2 USB Enclosure That Stopped Working
As useful as USB-to-M.2 SSD adapters are, sometimes you come across a bit of a dud. A case in point is the Orico-branded TCM2-C3 that features both an attractive clear case and in its earlier revisions a JMicron controller-based circuit that apparently degrades over time, causing erratic boot behavior. After implementing a fix a few years ago, [Mark Furneaux] can happily report that the thus fixed enclosures are still working.
These faulty board revisions feature the JMicron JMS583 controller IC, which has a 1.0V core voltage input pin. Apparently to save power, Orico designed the board to target the minimum ~-0.95V core voltage per the datasheet. Apparently due to component drift or degradation, this lower core voltage is after a while often not enough any more to start the controller, which thus translates into an unresponsive USB device and presumably some panic about lost data.
Although [Mark] doesn’t describe the fix in detail, it entails bumping up this core voltage to something closer to the nominal 1.0V, which restores functionality at the cost of presumably a measurable amount of extra heat production by said controller.
Later versions of the Orico TCM2-C3 enclosure switched from this JMicron controller to a Realtek one, which so far appears to be noticeably more reliable. Although Orico kept the same model name, the transparent enclosure makes it at least a snap to see which revision you are dealing with.
-
Fashion6 days agoWeekend Open Thread: Brooks Brothers
-
Sports4 days agoCommonwealth Games boxing: Jadumani Singh seals dominant 5-0 win over Pakistan’s Sumama Rehman to enter quarter-finals | Commonwealth Games News
-
Business1 day agoWhy Trees Belong on the Risk Register
-
Tech4 days agoIntel is reversing course and bringing hyper-threading back to its server chips
-
Crypto World5 days agoRipple bought a bank in pieces. The $4 billion audit
-
Politics4 days agoLuke Littler dismantles Gerwyn Price to retain title in Blackpool
-
Entertainment6 days agoA New Post-Apocalyptic Gundam Anime Series Blasts Into SDCC
-
Politics3 days agoThe Part of the Electric Transition Nobody Wants to Discuss
-
News Videos4 days agoBITCOIN JUST ENTERED THIS CRITICAL ZONE…
-
Fashion7 days ago16 Dresses for the High Summer Event
-
Sports7 days ago2026 3M Open leaderboard: Scottie Scheffler finds putter in Round 1, sits three back
-
Business2 days agoMajor shareholder moves on Canyon
-
Crypto World5 days agoXRP Ledger adds $2.6B as RWA inflows rank second
-
Politics4 days agoSpain sweeps the board at 2026 World Cup with individual awards
-
News Videos11 hours agoBitcoin Enters the 3rd Stage of the Bear Market
-
Entertainment2 days ago‘Stargate’ Creator’s New Sci-Fi Series Returns for Season 3 Tomorrow
-
Tech6 days agoAnthropic launches Claude Opus 5, a cheaper AI model for coding, agents and enterprise workflows
-
Crypto World2 days agoKraken Enables Retail Access to Jersey Mike’s IPO via Tokenized Shares
-
Entertainment5 days agoSara Gilson Killed By Husband After Viral “Pedophile” TikTok Video
-
News Videos2 days agoClaude: Build Financial Dashboards in Minutes (2026)








You must be logged in to post a comment Login