Tech
Larry Ellison has cancelled his plan to sell $7.5bn of Oracle stock, a day after it surfaced
Larry Ellison has cancelled a trading plan that would have let him sell up to 50 million Oracle shares by 24 October, a day after the plan was disclosed and with no stock sold under it. The instrument is a Rule 10b5-1 plan, an American safe harbour with no European counterpart, because EU market abuse rules bar managers from dealing in the 30 calendar days before results instead.
Larry Ellison has cancelled the plan that would have let him sell up to 50 million Oracle shares, a day after it was disclosed, Bloomberg reported.
“No Oracle stock was sold under that plan, and he has no other plans to sell any of his Oracle stock,” the company said.
The plan was adopted on 22 June and would have run to 24 October. The shares were worth about $8.75B then and about $7.5B now, after a 16% fall. Oracle described it as a 10b5-1 plan in its statement.
Ellison controls about 40% of the company and is its executive chair and chief technology officer.
The timing was the problem. Oracle reported shrinking gross margins on Thursday, its shares fell 1.7% on Friday, and the same week it raised the cost of its job cuts to $2.8B.
A Rule 10b5-1 plan is a piece of American market plumbing with no European equivalent.
An executive who adopts one while not holding inside information can let trades execute later on a fixed schedule, including in periods when selling at their own discretion would draw questions. The rule dates from 2000, and the SEC tightened what has to be disclosed about these plans in 2022.
Europe closes the window instead.
Under the Market Abuse Regulation, a person discharging managerial responsibilities may not deal in the company’s shares during the 30 calendar days before an interim or year-end report.
There is no adopt-in-advance exemption from that.
Europe also discloses different things. It publishes transactions rather than intentions, within three working days of each deal, once EUR 5,000 has been reached in a calendar year. A plan that never traded would have left no trace at all.
None of which suggests Ellison did anything improper. No shares were sold, and the plan was disclosed exactly as American rules require, which is the only reason anybody knew about it.
But the two regimes would have produced different weeks. Europe would never have published a plan for the market to read, and would not have let one run through the results of a company sitting one notch above junk.
Tech
Researchers warn that social media can reveal sensitive details about users
What you post online is only part of the story. A new review of research into social media privacy warns that platforms and third parties can potentially infer sensitive details about people from seemingly ordinary digital activity, including their political opinions, religious leanings and shopping habits.
The findings, as reported by Techxplore, published in the International Journal of Management Concepts and Philosophy, point to a widening gap between the amount of personal information generated online and the legal and ethical protections designed to safeguard it. The researchers examined privacy breaches, regulatory frameworks, and the responsibilities of both social media companies and their users.
Your digital trail says more than your posts
The central concern is not necessarily what users deliberately share. Instead, researchers highlight what can be inferred from their activity after it has been collected, indexed, and analysed.
Every interaction can contribute to a broader “digital trail” containing information about activities, locations and interactions. According to the research review, this trail can potentially be searched and analysed by third parties or, at the very least, by the platforms themselves. Even mundane online behaviour can provide clues about personality traits, purchasing patterns, political opinions and religious affiliations.

That creates a privacy problem that is easy to overlook. You might never explicitly state a political preference, religious belief or particular consumer habit, yet your online behaviour could still provide enough signals for someone else to make an educated inference.
The researchers argue that privacy is therefore not simply about keeping secrets. It is about maintaining control over who can access and interpret information about you. They connect that control to personal autonomy, civil liberties and democratic participation.
Why stronger privacy rules may be needed
The findings matter because social media has transformed privacy from something people could largely manage themselves into something increasingly shaped by algorithms, platforms and data analysis. Not just this; last year the city of New York decided to start treating social media with warning labels, like cigarettes.

The review calls for greater legal accountability and transparency from social media companies, alongside better digital literacy so users can understand and manage the risks associated with sharing information online.
The familiar argument that people who have “nothing to hide” have little reason to worry about privacy also comes under scrutiny. The researchers frame privacy as a right to decide who gets to see into the personal aspects of our lives – not as a tool for concealing wrongdoing.
For users, the takeaway is straightforward: your social media profile is potentially more revealing than the information you consciously put on it. Likes, interactions, locations and other seemingly harmless activity can form a larger picture when analysed together.
What happens next will depend on how regulators, platforms and users respond. The researchers’ call for stronger accountability and transparency suggests that privacy protections may need to evolve alongside the increasingly sophisticated ways online behaviour can be analysed.
Tech
Apple’s best use of AI isn’t happening on the iPhone
AI is constantly being shoved in our faces. From your laptop to your phone, every new gadget now ships with some features built around AI. Over the last couple of years, even Apple has tried to make Apple Intelligence sound like the next big thing on the iPhone.
With iOS 27, the argument finally became worth listening to. Siri AI is a great example of this. It can search through personal information and understand what is on your screen before answering specific or broader general questions. Visual Intelligence looks through your phone’s camera to understand what you’re seeing, and a lot more.
All of this is impressive, till you see what Apple has in store with the Apple Watch Series 12 and Watch Ultra 4. The way it approaches AI in the wearables is different. It isn’t just a smaller secondary screen with a language model, and that’s why it works.

The Apple Watch doesn’t waste time
An iPhone gives Apple plenty of space to demonstrate AI, which is not the case for the Watches. Its tiny screen actively discourages long interactions, and I think that limitation is forcing Apple toward more interesting ideas. Take the new Audio Intelligence suite, for example. Each of the new features under it serves to make the users’ lives easier.
Sound Recognition can identify important noises such as alarms, sirens, doorbells, or a crying baby and alert you. Automatic Shazam identifies music around you and surfaces the result in Smart Stack. Live Rewind can recover the previous 15 seconds of speech when you missed something someone said. Siri Recap can turn conversations into short summaries you can revisit later.

Live Rewind can be really useful… if you ignore the privacy concerns
Live Rewind is probably the best example. I can just double-press the Digital Crown and get the previous 15 seconds as text if I missed something important in the conversation. Adding to its functionality, you can even ask Siri about it or have it saved for later. On the iPhone side, there isn’t any such interaction. By the time I’ve taken my phone out, unlocked it, and started recording, it’s already too late.
A lot of the new AI gadgets are all about seamless, display-free interactions. And just like those devices, the new Apple Watch changes how we interact with AI thanks to its physical proximity. A wearable has access to situations an iPhone sitting in my pocket can’t interact with quite as naturally, and Apple is beginning to build intelligence around that advantage.

We made a similar argument about Siri Recap recently. The privacy implications of a smartwatch listening to conversations deserve scrutiny. Though Apple’s implementation avoids retaining raw recordings and processes audio inside a hardware-isolated Secure Exclave on the S11 chip. Live Rewind also gives people nearby an audible and visual indication when it has been activated.
Why an iPhone can’t match the Apple Watch
Fitness and health features are what make the Apple Watch so popular. It knows much more about what my body is doing at any particular moment. Workout Buddy uses Apple Intelligence to provide spoken motivation based on personal workout data, and watchOS 27 expands the information it can incorporate. It can now operate while you exercise without carrying your iPhone, even if Apple still requires a paired Apple Intelligence-enabled iPhone and compatible Bluetooth audio hardware.
Series 12 and Ultra 4 also gather heart-rate measurements every five seconds and HRV as frequently as every five minutes through the new Health Sensing System. This data feeds Apple’s new Readiness experience, which combines activity, sleep, vitals, and training information into a score that updates as your condition changes throughout the day.

Apple’s redesigned Health app uses Apple Intelligence to interpret longer-term health information, while new vision-based AI assessments can combine the iPhone camera with Watch data to evaluate flexibility, strength, balance, movement mechanics, and VO2 max.
Siri AI on your wrist just works
Ironically, even Apple’s more conventional chatbot-style AI arguably gains something by being on the Watch. Siri AI brings the same personal-context understanding, conversational abilities, and broad knowledge available on the iPhone to watchOS 27. But on a phone, Siri is competing with other AI services like ChatGPT and Gemini.

With the Apple Watch, however, I can change an activity goal halfway through a run. Maybe even find something from my personal info or ask about my training without ever having to reach for my phone. Even watchOS 27’s smaller intelligence features play into this whole thing. The app grid can surface Siri-suggested apps based on usage, and something like Smart Stack recommendations can appear around context such as where you parked or someone’s birthday.
To be fair, the Apple Watch is more powerful than the iPhone. Features like Visual Intelligence bring some serious image-generation and editing tools. I just think the Watch is providing a better example of how AI can fit into an existing product without becoming the product.
I like the version of AI that’s all about making interactions feel more natural. It hears the thing you missed and recognizes the song playing nearby without needing any input. Nothing too intrusive, but still present enough to be handy in day-to-day use.
Tech
Anthropic CEO Dario Amodei Calls For AI Slowdown
An anonymous reader quotes a report from The New York Times: The chief executive of Anthropic called for a global slowdown of artificial intelligence development in a 3,800-word essay on Saturday, just days after one of the company’s employees quit over concerns about the safety of the technology. Dario Amodei, who co-founded Anthropic to focus on securely and carefully building A.I., wrote that while he believed the technology could bring many benefits, it was advancing at too quick a pace for researchers to continue safely.
“Over the last few months, I have become convinced that fully addressing the risks requires even more prudence — not just investing in risk prevention, but pacing the rate of capabilities advancement so that risk prevention has time to keep up,” Mr. Amodei said. “We must slow the pace at which we improve the capabilities of A.I. models. Progress will still seem fast, and we must make wise use of the time we gain.” […] “Left unchecked, it could outrun our ability to understand and control these systems, and so must be pursued very carefully, if at all,” Mr. Amodei said.
[…] In his essay on Saturday, Mr. Amodei suggested actions that the industry might take to slow down the pace of development.
Mr. Amodei said all A.I. labs could agree to third-party technology assessments from “embedded evaluators,” or outside specialists who can verify best safety practices across companies. He also suggested that countries with democratic governance systems coordinate to create safety standards, which could take the form of regulatory action. He added that it would probably require a global effort working with other nations, including authoritarian ones, to properly coordinate a slowdown.
Mr. Amodei stressed in his essay that he still finds A.I. capable of bringing “incredible benefits” to humanity, including potentially curing diseases and accelerating economic growth. But even so, Mr. Amodei said the risks of A.I. were too great to not proceed with extreme caution. “The measures I propose to advance the frontier at a safe pace will not be easy,” Mr. Amodei wrote. “But I believe we owe it to humanity to try.” Amodei’s essay comes just hours after Bloomberg reported that Sam Altman told OpenAI employees the company is open to slowing the pace of AI development amid similar concerns.
Read more of this story at Slashdot.
Tech
How and When to Use Them
A virtual card number is a substitute payment number linked to an eligible underlying card account. You can use it for supported online or in-app purchases without giving the merchant the number printed on your physical card, which can reduce the usefulness of exposed payment credentials if a merchant is later compromised.
It does not usually create a separate account or credit line, make an unsafe merchant trustworthy, or add new dispute rights by itself. Its main benefit is isolating the credential used at checkout from the number on the physical card.
How Virtual Card Numbers Work
A virtual card number replaces the card number you would normally type at checkout with a different number generated for an eligible account. Capital One describes its virtual card numbers as unique numbers linked to the underlying credit-card account, allowing eligible users to make online purchases without sharing the physical card number.
The number associated with the actual card account is commonly called the Primary Account Number, or PAN. A virtual-card system leaves the underlying account in place while presenting a substitute credential to the merchant.
In practical terms, the process usually works like this:
- An issuer or supported payment service generates a virtual card number for an eligible account.
- You use the substitute number at an online or in-app checkout instead of the number printed on the physical card.
- The merchant submits the virtual credential for authorization through the normal card-payment process.
- The virtual credential remains associated with the underlying account so the issuer can authorize and post the purchase there.
- The transaction appears on the underlying account rather than creating a separate balance or credit line.
Implementations differ. Capital One currently offers both general-use virtual numbers and eligible merchant-specific numbers. Its general-use number can work with multiple online merchants, while a merchant-specific number is restricted to one merchant. Capital One also notes that not every customer or card is eligible.
Google describes its virtual cards as digital versions of eligible cards that use randomly generated numbers instead of the actual card number. Google also says availability depends on participating banks or networks, supported countries or regions, and merchant acceptance.
A simple example is a physical card whose account number ends in 1234. A supported virtual-card service can provide a different number for checkout while the resulting purchase still belongs to the original account.
Virtual card numbers and tokenized digital wallets can both reduce exposure of the underlying card number, but they are not necessarily the same technical implementation or checkout experience.
A virtual card number may look like an ordinary card number that you or a browser autofill tool enters into an online checkout. A digital wallet can instead use a payment token associated with a device, merchant, or payment context.
EMVCo describes payment tokenization as replacing a Primary Account Number with an alternative value that can be constrained to a particular merchant, device, or payment scenario. That explains the broader security principle, but not every product marketed as a virtual card should automatically be described as an EMV payment token.
The distinction matters because different products support different controls. Some virtual numbers stay the same across many purchases, others are tied to one merchant, and wallet tokens can be restricted to a device or payment environment.
A virtual card vs digital wallet comparison matters when choosing between a manually entered substitute card number and a wallet-based payment token.
Our Recommendations
1
When Buying From a New but Legitimate Online Store
Best for: reducing exposure of your physical card number when trying a retailer you have independently checked but have not used before.
A virtual number can be useful when you trust a merchant enough to make a purchase but would rather not give it the reusable number printed on your card.
Where the issuer supports merchant-specific numbers, the containment can be stronger. Capital One states that its merchant-specific virtual numbers are valid only with the assigned merchant, so that credential cannot simply be reused at another store through the same feature.
The benefit is credential containment, not merchant verification. A virtual number can still successfully authorize a payment to a dishonest seller if you approve the transaction.
The Federal Trade Commission recommends checking unfamiliar online sellers independently and warns that an encrypted website alone does not prove that the seller is legitimate.
Important limitation: a virtual card number can reduce exposure of your physical card number, but it cannot establish whether a merchant is legitimate or whether an order will be fulfilled.
2
When a Merchant Stores Your Card for Future Purchases
Best for: isolating one merchant from the number on your physical card when the issuer supports merchant-specific virtual credentials.
Saved-card checkout is convenient, but it means a merchant or its payment provider retains a payment credential associated with your account. A merchant-specific virtual number can give that merchant a dedicated substitute credential rather than the number printed on your physical card.
Capital One currently lets eligible users create multiple merchant-specific virtual numbers, each intended for one merchant, and manage those credentials separately.
This can be useful if you shop repeatedly at one website and want the stored credential for that retailer separated from the card number you use elsewhere.
Important limitation: merchant-specific numbers are implementation-dependent. Other virtual-card services may provide one substitute number that works across multiple merchants.
3
For Subscriptions You Want to Isolate
Best for: recurring payments when the issuer supports a persistent virtual number that can be managed separately.
A persistent virtual number can be useful for subscriptions because the merchant can keep charging the substitute credential without receiving the physical card number.
Capital One states that eligible virtual cards can be used for recurring payments and subscriptions. Its current management tools also let eligible users lock, replace, or delete virtual numbers separately from ordinary purchases made with the physical card number.
That can isolate one recurring merchant from unrelated card activity. For example, a merchant-specific credential used only for one subscription is easier to identify and manage than one physical card number shared across many merchants.
There is an operational consequence. Capital One explicitly states that recurring payments associated with a deleted virtual number will be declined, so legitimate payment details may need to be updated afterward.
Deleting a payment credential is not the same as canceling a contract or subscription. If the service has a cancellation process, follow it rather than relying on failed future charges.
Important limitation: deleting or replacing a virtual number can interrupt legitimate recurring payments, and issuer behavior varies.
4
When You Want Online Purchases Separated From Your Physical Card Number
Best for: routine e-commerce when you want merchants to receive a substitute credential instead of the number printed on your card.
This is the broadest everyday use case. Instead of entering the physical card number at each supported checkout, a virtual-card system can provide a different credential while keeping the same underlying account.
American Express says its eligible virtual-card implementation does not share the physical card details with the merchant and dynamically supplies the security code used at checkout. Purchases still appear as regular transactions on the underlying Amex account.
This illustrates the central trade-off: the credential shown to the merchant changes, but the underlying account remains. Spending still posts to that account and remains subject to its credit limit, balance, issuer rules, and other account terms.
Capital One likewise states that its virtual cards are tied to the associated physical-card account. If the physical card is locked, transactions on its virtual cards will not go through.
Important limitation: a virtual number does not separate you from the underlying account’s balance, credit limit, fees, interest, or repayment obligations.
5
For Controlled Business or Vendor Payments
Best for: organizations that need payment credentials with transaction or policy controls.
Commercial virtual cards can do more than conceal a broader funding-account number. Business systems can generate credentials for specific transactions, suppliers, or workflows and apply controls to their use.
Mastercard’s current commercial virtual-card material describes unique virtual numbers, workflow approvals, and controls defining how, where, and when a virtual number may be used. Its commercial platform also supports spending limits and restrictions.
This can let a business provide a constrained payment credential for a supplier or purchase without exposing the broader funding-account number.
These are commercial virtual-card capabilities. They should not be assumed to exist on an ordinary consumer virtual card merely because both products use the same general terminology.
Important limitation: amount restrictions, approval workflows, merchant controls, and similar features are commercial product capabilities, not universal consumer virtual-card features.
When a Virtual Card Number Is a Poor Fit
A substitute credential is useful only when the merchant and the later transaction lifecycle can support it. In some cases, the physical card number or another payment method is more practical.
- The merchant does not accept virtual cards. Google says certain merchant sites and apps opt out of virtual-card acceptance, while Capital One also notes that some merchants may reject virtual numbers.
- You may need to show the original card later. Capital One warns that a virtual number may be unsuitable when a travel reservation, hotel, event, or similar transaction requires the customer to present or swipe the card used for booking because the virtual and physical numbers do not match.
- Your account is not eligible. Availability can depend on the issuer, card, account status, network, country or region, browser, device, and payment platform.
- A changing credential would interfere with repeat billing. Persistent virtual numbers can support subscriptions, but short-lived or replaced credentials can cause later charges to fail.
- You are treating it as protection from a fraudulent seller. A virtual number can still authorize a transaction that you willingly approve.
If an eligible virtual card unexpectedly fails, a virtual card decline can result from merchant acceptance, an expired credential, a billing-address mismatch, insufficient available credit, or issuer restrictions.
How to Get a Virtual Card Number
There is no universal setup process because availability is controlled by the issuer, network, or supported payment platform. Common access methods include an issuer’s website or mobile app and supported browser or Android autofill features.
For example, Capital One currently lets eligible cardholders access virtual numbers through its website and mobile app. Google supports virtual-card enrollment for eligible cards from participating banks or networks in supported regions. American Express lets eligible U.S. cardholders enroll supported cards for its Google-based virtual-card feature.
Before relying on a virtual number, check:
- whether your exact card or account is eligible;
- whether identity verification or enrollment is required;
- whether the credential works only online or in supported apps;
- whether it is general-use, merchant-specific, persistent, or temporary;
- whether recurring payments are supported;
- how the issuer lets you lock, replace, or delete it; and
- what happens when the underlying card is locked, replaced, or closed.
Do not assume two issuers implement virtual cards the same way. Capital One, American Express, Google-supported issuers, and commercial Mastercard systems expose different eligibility rules, controls, and checkout behavior.
What a Virtual Card Does Not Protect You From
A virtual card number addresses one main problem: exposing the number associated with the underlying physical card. It does not eliminate the other ways online payments can fail.
- Fraudulent merchants: a substitute number can still authorize a purchase from a scam seller.
- Account takeover: an attacker who gains access to your issuer account or authentication method may present a different problem from stolen merchant-side card data.
- Underlying debt: a virtual credit-card number is still connected to the underlying credit account, so balances, interest, fees, and repayment obligations remain.
- Merchant disputes: using a virtual number does not automatically create stronger refund, chargeback, or statutory rights than the underlying account already provides.
- Compatibility problems: the feature may not be available for the card, platform, region, or merchant involved in the transaction.
If the goal is broader than concealing a physical card number, compare alternatives to credit cards for online payments by credential exposure, reachable funds, dispute options, and debt risk.
A virtual card number is most useful when you already intend to make a legitimate online purchase and want the merchant to receive a substitute credential instead of your physical card number. Used in that role, it can reduce credential-reuse risk without changing the account that ultimately pays for the transaction.
Tech
Sam Altman backs Dario Amodei’s call to slow down, and says OpenAI will do the same
Sam Altman says OpenAI will match Anthropic’s commitment to give independent evaluators employee-like access, a day after Dario Amodei asked the industry to slow down and asked Washington for a narrow antitrust waiver so competitors could coordinate. Europe has no waiver to grant, because Brussels abolished individual exemptions in 2004, and the only soft safe harbour it has since written for competitor standards covers sustainability.
OpenAI has said it will match Anthropic’s safety commitment, a day after Dario Amodei asked the industry to slow down. “I agree with Dario that we need to pace the frontier,” Sam Altman wrote, as Axios reported.
He called independent evaluators with employee-like access a great idea, said OpenAI would do the same, and promised more to share soon. Pacing had been a primary topic of discussion inside OpenAI in recent weeks, he added.
Elon Musk, who runs xAI, was briefer. “Dario is right,” he posted.
Amodei’s essay on Saturday asked frontier labs to let outside teams verify their safety work from inside their offices. Anthropic’s own version gives them desks, badges, company laptops and the right to publish what they find. It also asked Washington for something harder.
He wants a narrow waiver, so that competitors can hold safety conversations without the conversations themselves becoming the legal problem. Governments need not take part, he wrote, only permit the discussions.
Two of the largest labs have now agreed a common commitment in public, inside a day. That is the first rung of the three-step plan Amodei set out.
In Europe there would be nobody to ask.
The Commission stopped granting individual exemptions when Regulation 1/2003 took effect in 2004. Before that, companies notified their agreements to Brussels and waited. Competitors now assess their own against Article 101 and live with the answer.
What Europe has instead is a precedent. It rewrote its horizontal cooperation guidelines in 2023, expanding them from 72 pages to 167.
The new text carries a 21-page chapter on sustainability agreements, including a soft safe harbour for standards that meet six conditions. It also reworked the chapters on standardisation and on information exchange between rivals.
That is close to the machinery Amodei is asking America to build. Europe has already built it once, for a different public good.
There is no equivalent chapter for safety standards, and nobody has asked for one.
His essay does not mention Europe, and neither did Altman’s reply. The Commission’s own tech chief said last week that global rules are needed.
Tech
AT&T store worker gets 16 months inside for SIM-swap side hustle
cyber-crime
Phone shop staffer claimed he was paid less than $4k for in his part attacks leading to combined intended losses of $600,000
A former AT&T retail worker who used his system access to hijack customers’ phone numbers for cybercriminals has been sentenced to 16 months in federal prison.
Kenneth Carter, 44, carried out the SIM swaps at a store in Portland, Oregon, , allowing the criminals to intercept authentication codes and raid victims’ bank accounts.
Court documents show that Carter worked with at least three other people in the scheme, which ran between May 2018 and November 2019, and caused nearly $600,000 in intended losses.
Co-conspirator One, described in court documents as the operation’s main “hacker,” identified victims with online bank accounts, gathered their personal data, and sent it to Carter, who could reassign their phone numbers.
Carter abused his access to AT&T’s systems to transfer victims’ phone numbers to devices controlled by the other criminals. His role was described as “instrumental to the scheme.”
Co-conspirator Two and Co-conspirator Three would walk into the store and impersonate the victim whose number they planned to SIM-swap, and Carter would reassign the number to a phone they controlled – usually a “cheap flip phone.”
Once the swap was complete, the criminals could use the flip phone to intercept SMS-based 2FA codes and password reset messages, take over the victim’s bank account, and steal funds.
The intercepted codes were relayed to Co-conspirator One, who used them to access the victims’ bank accounts.
Court documents also refer to “an unnamed family member” who held a minor role in the scheme. They were described as someone “who occasionally passed along the two-step authentication codes” to Co-conspirator One.
According to the Justice Department, three victims incurred combined intended losses of $593,963.77, and Carter admitted carrying out additional unauthorized SIM swaps.
Carter’s plea agreement [PDF] included details of three SIM swap attacks he helped execute. Only one victim suffered an actual loss: $99,528.33 transferred to a Portuguese bank account.
The conspirators attempted to transfer $247,652.74 and $246,782.70 from the other two victims, but the banks’ fraud controls blocked both transactions.
Prosecutors said Carter was paid between $1,000 and $2,000 per swap, although he maintained that he earned less than $4,000 in total.
Law enforcement raided Carter’s residence in November 2019, finding copies of the personal data provided to him to carry out the SIM swaps, including the Social Security number of the one victim whose money was successfully stolen.
AT&T terminated Carter’s employment at an unspecified date in 2019. He pleaded guilty on March 24, 2026, to conspiracy to commit wire fraud and bank fraud.
In a letter to United States District Judge Stanley Blumenfeld, Jr., Carter described his offending as “a one-off situation that truly was a mistake.”
He explained that he takes care of his mother-in-law, who spends much of her time in a hospital bed located in the family living room, and two daughters, one of whom has schizophrenia.
Carter claimed that he was “propositioned by my in-law cousin with an opportunity for me to make a little extra money for my family.”
“I was told I wouldn’t have to do anything but do my job,” he added. “So, I was under the impression that this was a harmless act. As far as I knew at the time, I was never a part of a ring, nor was this an out-of-state matter.
“My incident was isolated to just Portland, OR, and the incident occurred while I was employed by AT&T. I later learned that what I found myself a part of was criminal, and I also learned after the fact the severity of what my co-conspirators were doing with the flip phones I sold under customer accounts.”
Federal prosecutors were unmoved by Carter’s letter. In their response [PDF], US attorneys argued that Carter had not provided enough evidence to show he was unaware of the criminal activity’s scope or nature, or that he was less culpable than the “hacker” who coordinated the operation.
In addition to the 16-month sentence, Judge Blumenfeld, Jr. ordered Carter to pay $99,528 in restitution. ®
Tech
More JFrog Artifactory bugs under attack, and all 3 have patches
security
If you’re waiting for a sign to upgrade to a fixed version: this is it
JFrog Artifactory instances continue to get hit hard. Multiple attackers are exploiting three JFrog Artifactory bugs to gain administrative control over vulnerable instances – in some cases, just days after the vendor published a patch – and then using this illicit access to install malicious plugins and backdoors.
The three vulnerabilities are:
CVE-2026-42018 is a high-severity, improper authentication flaw that can return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled. An attacker can use this token to authenticate to the repository manager and then access sensitive resources. JFrog patched this vulnerability on August 12.
CVE-2026-42016 is a high-severity privilege-escalation bug. Artifactory doesn’t properly validate the token’s scope, and this can allow an attacker with low-privileged access to elevate privileges and perform actions that they should not be allowed to do. JFrog fixed this one on July 27.
CVE-2026-82329 is a critical authentication-bypass vulnerability that allows unauthenticated attackers with network access to obtain administrative privileges. JFrog published a patch for it on August 28.
Earlier this month, security researchers told The Register that miscreants began battering internet-exposed systems vulnerable to CVE-2026-82329 just four days after JFrog disclosed the bug. In addition to creating new administrative credentials, watchTowr’s honeypot network caught miscreants “enumerating users, groups, credential sets and federated access topologies,” said Yordan Ganchev, principal threat intelligence specialist at watchTowr.
The one thing everyone agrees upon is that attackers didn’t start exploiting any of these CVEs until after JFrog issued fixes.
In a Thursday report, Wiz security researchers “confirmed in-the-wild exploitation of all three vulnerabilities across multiple environments,” and noted that “patching velocity has been slow.”
JFrog has not responded to any of The Register’s inquiries about attacks against any of the three CVEs.
‘Patching velocity has been slow’
Six weeks after JFrog disclosed CVE-2026-42016, 59 percent of organizations remain vulnerable, and 62 percent remain vulnerable to CVE-2026-42018 after four weeks. Organizations have been quicker to remediate the critical bug, CVE-2026-82329, although 49 percent remain vulnerable two weeks after its publication, according to Wiz.
Beginning August 15 and running through September 8, Wiz spotted “multiple” attackers chaining CVE-2026-42018 and CVE-2026-42016 against self-hosted Artifactory instances to gain admin access. Many of these intruders then dropped a custom Rust backdoor to establish command-and-control (C2) capabilities.
While the post-exploitation activity varies, Wiz reports observing attackers doing all types of mischief with their administrative access to compromised Artifactory instances, including establishing persistent admin accounts, installing Groovy plugins to achieve remote code execution on the server, executing shell commands run through the plugin to perform reconnaissance and scan for sensitive files, deliver second-stage payloads, and upload web shells.
Then, between September 1 and 8, Wiz saw “several” attackers exploiting CVE-2026-82329. These intrusions were not a “unified attack chain by a single threat actor,” but spanned multiple illicit behaviors including exfiltration of configuration details, establishing persistent admin accounts, token minting for long-lived credentials, stealing keys, attaching their own SSH keys to created users in some cases, and enumerating users, repositories, and tokens.
If you haven’t already, patch vulnerable instances
Wiz advises – and we strongly concur – upgrading to a fixed Artifactory version as soon as possible.
“Given that exploitation may be possible remotely without authentication under the default configuration, organizations should prioritize internet-accessible Artifactory instances and restrict network access to trusted users and systems where possible,” the researchers added. “Organizations should also review Artifactory authentication and administrative activity for unexpected privileged access.”
These latest exploits follow a rough few months for JFrog’s package management system, which has been under fire from both human and AI attackers.
OpenAI and JFrog revealed that OpenAI’s models broke out of their cages to hack Hugging Face by exploiting an Artifactory zero-day in July, and at Black Hat, the model provider said agents used Artifactory to build message boards and help each other access the open internet. ®
Tech
Google may have a fitness tracker in the works with a display and Wear OS
Google may be preparing a successor to the Fitbit Charge 6, and it could bring a major software change to the fitness band. A mystery device identified as G8BL6 has appeared at the FCC with Bluetooth LE, built-in GNSS, and what appears to be a display. 9to5Google believes the device could run Wear OS and says it would make sense as a successor to the Charge line.
The Charge 6 has not been refreshed since 2023. Google also showed an unidentified fitness band in Pixel 11 ads in August. The device had a tall display and looked closer to a Fitbit Charge than a Pixel Watch. Google never identified it, but the FCC device could be the same product.



Wear OS would be a major change for the Charge line
The Charge 6 already supports Google Maps, Google Wallet, YouTube Music controls, notifications, and dozens of exercise modes without running Wear OS. Moving a future Charge to Wear OS could give it access to a broader app ecosystem and deeper Google integration. It would also be unusual for a fitness band. Devices in this category generally use lighter software that requires less processing power and consumes less energy.
A full Wear OS experience would also require more capable hardware than a conventional fitness tracker. Google would likely need a modern wearable processor, more memory, and substantially more storage.

Battery life could be the difficult part
The Charge 6 is rated for up to seven days of battery life, although Google notes that features such as the always-on display can reduce that figure.
Matching that endurance with Wear OS could prove difficult in a slim fitness-band design. Google could instead develop a stripped-down version of Wear OS for this form factor and remove some of the apps, background services, and other smartwatch features that demand more hardware and power.
For now, though, that is all speculation. Both ideas depend on clues from the FCC filing and the assumption that this is the same mystery tracker Google previously showed in its advertising.
Tech
Automattic confirms Mullenweg has returned as CEO after attempted ouster by board
After a tumultuous week, which saw WordPress founder Matt Mullenweg ousted from his position as CEO of Automattic, WordPress.com’s parent company, by way of a board vote, the company has now issued a statement confirming that Mullenweg has returned to his position.
“Matt Mullenweg is the chairman and CEO of Automattic, with full support of the board and if you search online you can see many top executives and Automatticians supporting him as well,” a company spokesperson shared with TechCrunch via email just after 5 PM ET on Saturday evening. (The mention of online support appears to refer to supportive posts on X that Mullenweg has been reposting from his X account.)
Automattic’s board had voted earlier this week to put Mullenweg on a paid leave of absence for unknown reasons. The move seemingly came as a surprise to Mullenweg, who posted on Automattic’s Slack, accusing the board members of “conspiring” against him.
Automattic confirmed Mullenweg’s removal to TechCrunch on Wednesday, saying that Mullenweg was “currently on leave” and that Automattic’s Chief Financial Officer, Mark Davies, would lead as interim CEO with “full confidence” of the board.
However, the board’s plan did not go smoothly. Seemingly declining to depart, Mullenweg booted other admins out of the company Slack and told employees everything had been worked out and that he was back in control of Automattic, multiple sources told TechCrunch. At one point, he also posted to Slack, “I’m a pirate now” and cursed, which is something Mullenweg famously did not do. “If this is an HR problem, please wrangle me in since my normal wranglers are with Mark Davies,” he wrote.
When TechCrunch asked Mullenweg if his comments about being back as CEO were legitimate, he promised a blog post was coming. When it arrived, however, it was about him buying a houseboat. When we asked if his comments about being back were also him trolling, he replied, “I’m not a troll I’m a pirate, obviously.” Mullenweg never provided any official comment about his return, but noted on X that this was likely the fifth time he’s faced a “coup.”
Automattic also did not respond to repeated requests for comment on Friday, nor to reports we heard about board member Toni Schneider stepping down. Schneider, a founding CEO of Automattic, now leads Bluesky. He did not return requests for comment at his personal email or via requests sent to Bluesky.
We have since asked Automattic again about this and other changes to the board’s composition, which we’re hearing still may be in flux.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Tech
Is There Any Benefit To Restarting Your Gaming Handheld Regularly?
It helps on a number of levels, it turns out.
If there’s one piece of advice that’s been echoed all over tech forums and support pages the moment someone brings up an issue, it’s probably, “Restart your device.” Even though gaming handhelds like the Steam Deck and the ROG Ally don’t look like laptops, under that portable hood they’re running full PC operating systems, regardless of whether that’s Valve’s SteamOS or Windows. So, at their core, they still run on the same principles as your regular PC. That means the age-old advice of “turn it off and on again” still holds true here and with an impressive success rate.
On the surface, restarting your gaming handheld seems like basic advice, but there’s more to it than meets the eye. That simple restart can fix a surprising number of issues, from a game that keeps crashing to sudden frame drops and lag. It can even clear up lingering audio issues. So there are a lot of benefits to restarting your gaming handheld regularly; it’s even one of the first troubleshooting steps on Valve’s Steam Deck support page. It won’t solve everything, but it’ll at least clear out whatever’s built up in your background and give the system a clean slate to work with.
Benefits of restarting your gaming handheld regularly
The first benefit of making regular restarts a habit is that it keeps your device’s memory clear. The more you use your console, the more your RAM (random-access memory) gets filled up, and over time some games and applications can fail to release memory back to your system or leak memory even after you’ve closed them. These leaks and memory hogging eventually slow down your gaming handheld, and worse, it’s not something you can prevent. But by simply restarting your gaming handheld regularly, you can keep those effects from building up over time.
Another unsung benefit of restarting your gaming handheld is that it allows your system to apply updates effectively. A good ol’ restart allows your device to properly integrate all the important stuff packaged into an update (like bug fixes, security patches and performance improvements) into your system. So, by regularly restarting your gaming handheld, you ensure that your device is always up to date. Regular restarts can also help you resolve software glitches before they cause your gaming handheld to freeze or crash.
Yes, hibernating and powering off helps too
Powering off your handheld gives the same benefits as restarting simply because it’s basically the same thing. Meanwhile, hibernating your gaming handheld doesn’t give the benefits of a restart or power-off; instead, it allows you to save your exact session to storage when you’re not using the device and then pick up where you left off, all with little to no battery drain. Powering off or hibernating your gaming handheld when it’s not in use is widely recommended, especially when you’re carrying it around inside a carry case or a bag with poor ventilation where it risks overheating.
In case you’re wondering, regularly restarting your gaming handheld doesn’t mean you need to do it every few hours. There’s no fixed or universally accepted number on how often you should restart your gaming handheld, but a good place to start is once every few days or at least once a week.
-
Tech5 days agoMemory prices are slowing because buyers ran out of money
-
Business3 days agoMicron Stock Climbs Above $1,031 as AI Memory Crunch and a $50 Billion Outlook Fuel the Rally
-
Business3 days agoAMD Stock Climbs After Management Lifts 2027 Data Center Outlook Toward $70 Billion in AI Sales
-
Crypto World4 days agoBitcoin price risks $76K drop as $78K support weakens
-
Crypto World4 days agoRobinhood Stock: How To Take Advantage With Reduced Risk
-
Crypto World4 days agoEthereum price stalls below $2,500 as ADX drops to 11
-
Fashion1 day agoWeekend Open Thread – Corporette.com
-
NewsBeat5 days agoEngland up in reading, maths and science rankings as Scotland and Wales dip
-
Crypto World2 days agoXAG/USD: Silver’s Short-Term Rally Meets Its Moment of Truth
-
Crypto World3 days ago2 Chip Stocks Broke Out This Week. Neither Was Nvidia
-
Crypto World2 days agoOKX launches 10x OpenAI, Anthropic X-Perps in Europe
-
Crypto World2 days agoDiesel Tops $6 a Gallon for the First Time as 28 States Set Records
-
Crypto World4 days agoIntel Stock Jumps 9% on Chip Price Hike Report, US Stake Gains $36 Billion
-
NewsBeat4 days agoWhat went right this week: an ‘historic’ fall in violent crime, plus more
-
Crypto World3 days agoBitcoin price risks $70K if $78K neckline breaks
-
Business4 days agoMeta debuts long-awaited personal AI agent, Muse
-
Crypto World2 days ago
Ethereum Price Analysis: Consolidation at $2.5K Tests Momentum as On-Chain Activity Surges
-
Crypto World5 days agoPump Fun and Kraken delete Hunter Biden $LAPTOP promotion
-
Crypto World4 days agoBitcoin price holds near $79K as cycle drawdowns narrow
-
Entertainment3 days agoCase Sees Major Update As Jury Deliberations Begin

You must be logged in to post a comment Login