Connect with us

Tech

Mcon controller review: Price, performance, specs

Published

on

The Mcon controller balances portability and performance in a compact, MagSafe-compatible design for iPhone gamers.

Gaming controllers usually come in two flavors. You’ll find ones that are extremely comfortable and capable, as well as those that are small and portable.

Finding a controller that is both portable and capable is a rarity, to say the least. The OhSnap Mcon is the first one I’ve tested that makes good choices on compromises and uses MagSafe for easy connection to iPhone.

Mcon mobile gaming controller review: Design

Mcon has a very cool design. It’s roughly the size of my iPhone 17 Pro, but a bit thicker.

Advertisement
Man in dark shirt holding a smartphone with detachable game controller, smiling and pointing at it in a room with brick wall background.

Mcon mobile gaming controller review: It’s fun to open the Mcon controller

It connects to your iPhone with MagSafe and has a solid hold. When you’re ready to game, you just press the silver button that sits right where your fingers rest.

When the button is pressed, the controller springs open. The Bluetooth is turned on, and the iPhone gets positioned just above the controller buttons.

Man holding a mobile gaming device with a controller attachment, pointing at it, standing in a room with a brick wall and shelves in the background.

Mcon mobile gaming controller review: The grips fold flat to the controller

Advertisement

It’s just fun to do and has a satisfying whoosh and click. I also appreciate that the phone doesn’t just slide forward; it angles upward slightly to make it more comfortable.

With the controller open, you can then rotate out two extra palm grips from around the back. This puts you in a natural gaming position with access to the joysticks, triggers, and all the other buttons.

Close-up of a white gaming controller's right side, featuring a joystick and four circular buttons labeled X, Y, A, B on a textured dark surface.

Mcon mobile gaming controller review: The buttons use XYAB labels

Speaking of the buttons, they’re in a bit of an interesting layout. It’s like a combination of a PlayStation controller and an Xbox controller.

Advertisement

It uses the XYAB buttons that Xbox uses, but it uses dual, center-justified joysticks as PlayStation does. The button labels are mostly irrelevant, and I vastly prefer this joystick setup to the Xbox’s.

Hand holding a white gaming controller in front of a smartphone displaying a video game on a wooden table.

Mcon mobile gaming controller review: The top comes off to use as a stand

Those joysticks use what OhSnap calls MagRes technology that promises to be ultra-accurate, lag-free, and drift-free. OhSnap even claims it is superior to the well-respected Hall-effect mechanics.

You can use the controller via Bluetooth, or you can use it wired via USB-C. If you go wireless, you can enter “kickback mode” by pressing the eject button and removing the MagSafe module.

Advertisement
Person holding a white gaming controller case in both hands, with a smartphone being placed inside. A candle and earbud case appear in the background.

Mcon mobile gaming controller review: It’s easy to reassemble and snaps into place

This gives you a magnetic stand for your phone that you can place anywhere you want and then relax with the wireless controller. It’s very clever how the metal arm that works as the stand also doubles as the central guide and stabilizer as it opens and closes.

Mcon mobile gaming controller review: Gaming performance

I wouldn’t consider myself a professional gamer by any means, but I’m certainly an avid one. I’ve long been a proponent of more console-level games making their way to iPhone, iPad, and Mac.

Quickly after launch, I eagerly downloaded Assassin’s Creed Mirage, Hitman World of Assassination, and Red Dead Redemption. Not to mention many more mobile-specific games like PowerWash Simulator, Thronefall, Call of Duty Mobile, or Alto’s Odyssey.

Advertisement
Hands holding a handheld gaming device displaying a game. Nearby are a candle, earbuds case, and a small device.

Mcon mobile gaming controller review: Playing Hit Man on iPhone with the Mcon controller

I tested the Mcon controller with most of these games over the course of the last several weeks. While it wasn’t perfect, it’s very reliable to use.

All of the buttons were incredibly tactile, providing a solid click each time they are pressed. The bumpers and triggers also felt reliable, though they were skinny, leaving my finger feeling a bit unsupported.

Hand holding a white gaming controller with a thumb on the directional pad, next to a phone screen displaying app icons.

Mcon mobile gaming controller review: The joysticks are very accurate and responsive

Advertisement

To me, the joysticks are the most important control, and OhSnap did a great job with these ones. They’re absolutely on the small side, but there was basically no dead zone in the middle, and they were very reactive when using them.

A person presses the R2 shoulder button on a handheld gaming console, showing a close-up of the controller's back.

Mcon mobile gaming controller review: The bumper and trigger buttons feel good, but are somewhat thin

I think all of these buttons are premium in design and performance, but are slightly smaller to accommodate the portable footprint.

Mcon mobile gaming controller review: Should you buy it?

With mobile gaming being as popular as it is, there is no shortage of controllers on the market. We’ve reviewed several here at AppleInsider.

Advertisement
Hands holding a smartphone gaming controller and circular device, with other controllers nearby on a gray surface.

Mcon mobile gaming controller review: There are lots of controllers out there, but none as compact and premium

For standalone controllers, I’m still the biggest fan of the DualSense controller that is MFi certified and even has a streamlined pairing process with iOS 26. The Razer Kishi Ultra is also an excellent option.

Both of them are inarguably more comfortable than the Mcon is. They fit your hand better, and the buttons are bigger.

Neither of those, nor the equally popular Backbone, will fit in your pocket, though. That portability is ultimately what matters most with the Mcon.

Advertisement
Person wearing a textured sweater holds a green phone with a white gaming attachment, seated beside a window with a potted plant visible.

Mcon mobile gaming controller review: You can play the Mcon controller anywhere

You can find more comfortable controllers, but you’d be hard-pressed to find a portable one that is as solid as this one is.

Mcon mobile gaming controller review: Pros

  • Premium construction with metal parts
  • Hall-effect triggers and mag-res joysticks
  • Simple MagSafe connection
  • Works wired or wireless

Mcon mobile gaming controller review: Cons

  • Not the most comfortable controller out there
  • Relatively expensive

Rating: 4.5 out of 5

Where to buy the OhSnap Mcon controller

Buy the Mcon controller for $129 from OhSnap in either black or white.

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Hackers breached a small Polish energy plant via private APN last year

Published

on

Hackers breached a small Polish energy plant via private APN last year

Hackers used a dedicated mobile gateway to compromise a second facility during the destructive cyberattacks that hit Poland’s energy sector last year.

The second target was a small combined heat-and-power (CHP) plant that supplies heat to around 50,000 residents, resulting in the steam turbine and the water treatment system being shut down.

The Polish Computer Emergency Response Team (CERT) disclosed this second incident in a follow-up report over the weekend, saying that the attacker used a private Access Point Name (APN) to access the operational technology network.

image

“The attack was made possible, among other factors, by a misconfiguration that allowed arbitrary devices within the private APN network to communicate with one another.”

On December 29, 2025, an attacker believed to be linked to the Russian Electrum threat group targeted 30 wind and solar power installations and a large CHP plant in Poland, destroying key equipment beyond repair.

Advertisement

The threat actor hit distributed energy resource (DER) sites across the country, disabled communications equipment, corrupted operational technology (OT) devices, and wiped Windows systems. Despite this effort to destabilize the grid, energy generation and distribution were not disrupted.

In the newly disclosed attack at a second, smaller CHP plant, the threat actor switched off the programmable logic controllers (PLC) and protected access with a password, thus deactivating a steam turbine and the plant’s process-water treatment system and interrupting cogeneration operations.

The staff at the plant managed to restore impacted systems quickly, so the outage was short-lived and had no impact on the population.

Novel attack path

Upon investigating the incident, the Polish CERT determined that the attacker initially compromised a FortiGate VPN/firewall at a wind farm and used a Teltonika cellular router on its network to tunnel into a private APN managed by the distribution system operator.

Advertisement

The APN lacked client isolation, allowing the attacker to scan for and communicate with devices at other facilities.

Beginning on December 18, the attacker found a WAGO PFC200 PLC at the CHP plant whose web interface was exposed on the APN and protected with default administrator credentials.

After compromising the controller, the attacker enabled SSH and used it as a bridge into the plant’s OT network.

Over the following week, they scanned the network for SCADA systems and industrial devices, and on December 25 they connected to three Siemens PLCs, likely in preparation for the attack.

Advertisement

At approximately 5:30 a.m. on December 29, the attacker accessed the SCADA interface and Siemens PLCs, switching them into STOP mode, activating password protection, and shutting down the steam turbine and process-water treatment system.

Complete attack path
Complete attack path
Source: CERT Polska

The attacker also reset and reconfigured several Moxa devices to impede recovery, destroyed logs, and hindered forensic analysis by corrupting or resetting the WAGO controller, Teltonika router, and FortiGate firewall used throughout the intrusion.

The Polish CERT believes this to be the first known real-world cyberattack in which an attacker entered an OT network by moving laterally through a private APN.

“To the best of our knowledge, the incident described in this report, which involved gaining access to an OT network through a private APN, was the first observed instance of this attack vector being used in a real-world cyberattack,” commented CERT Polska.

The surveys that followed the investigation determined that this configuration was common in Poland at the time, and the country’s CERT estimates that it’s likely similar arrangements are widely used internationally.

Advertisement

It is recommended to treat private APNs as untrusted external networks, enable isolation between connected clients, use allowlists for essential traffic between APN gateways and OT systems, and disable exposed SSH and Telnet administration services.


article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Advertisement
Continue Reading

Tech

Developer ports Word for Windows 1.1a to modern x64 systems using original source code

Published

on

Sounding off: Microsoft’s push to bake AI into every product and service it sells is understandably facing some backlash. Even Office is turning into a vessel for Redmond’s chatbots, which may be why one developer decided to go back in time instead, releasing a wild modern port of an early Word release.

Developer Justin Marshall recently ported Word for Windows 1.1a to modern Windows systems. The open-source conversion draws on the source code of the original program, which Microsoft shared with the community in 2014.

Marshall’s port brings the original WfW experience to Windows x64, replacing non-working 16-bit code with modern programming conventions. The coder explains there’s no emulation, virtualization, or reimplementation trick involved: the original Word application runs with its original resources and UI elements intact.

Porting WfW to Windows x64 wasn’t exactly a “plug-and-play” affair. Marshall said that while the original C code and resource files are still part of the port, he had to make the 16-bit code behave properly in a modern 64-bit Windows environment. Specific behaviors tied to the Win16 API had to be adapted to modern Win32 APIs, while dialogs, cursors, and bitmap elements had to be rebuilt with native host tools through the CMake build process.

Advertisement

“CMake inventories the legacy assembly tree but does not compile those modules into native targets. This keeps the historical implementation available as a reference while ensuring all shipped code is valid for AMD64,” Marshall explained on the project’s GitHub page.

Word, and Word for Windows 1.1a specifically, hold a special place in Microsoft’s software history. The original Word for Windows debuted in 1989, bringing the DOS-based productivity tool to a new GUI paradigm; version 1.1a followed a year later as the release that added dedicated support for Windows 3.0. Over time, Word became the de facto standard for word processing in lieu of WordPerfect.

Compared to the barebones GUI of Word for Windows 1.1a, today’s Word is a completely different beast. Microsoft now treats its productivity software largely as a means of promoting its AI services. Thanks to chatbots and LLMs, the latest Microsoft 365 version of Word can even write documents and expand drafts on its own. No pesky human intelligence required.

While Microsoft keeps cramming more AI into Office, some developers are trying to fight back by returning to the roots of its software tools. Before the WfW port, Marshall built other projects blending old software with modern tech, including a ray-tracing port of Quake 1 and a merge of the Quake 4 SDK with the Doom 3 graphics engine, among others.

Advertisement

Source link

Continue Reading

Tech

5 Car Brands Bringing Back Boxy SUVs

Published

on





Anyone who grew up or was already driving in the 1990s remembers the era of the jellybean car — all smooth lines and soft curves. Today, many modern vehicles, even bulky SUVs, are still mostly comprised of sleek lines. It’s a dramatic shift from the 1970s and 1980s, when most automakers used flat panels and straight lines, producing vehicles that more closely resembled a cardboard box than the aerodynamic designs we see on the road today. You may have noticed another shift in recent years, however, as some automakers are bringing back those boxy blueprints.

SUVs trace their lineage back to the Willys Jeep that was used during World War II. The earliest SUVs mimicked this design, which was easy to manufacture, and offered lots of interior space for families to spread out and carry luggage or cargo. By the 1960s, other manufacturers had joined Jeep with their own boxy SUVs, and the style remained popular until the late 1990s. SUVs soared in popularity, and designs trended to more car-like lines. Stricter rules regarding fuel efficiency also helped soften lines for more aerodynamic designs.

Car design, like almost everything else, however, is cyclical, and boxy SUVs are making a comeback. Modern engineering and advances in engine design mean that those straight lines don’t have as much effect on fuel efficiency as they did in the past, and many Americans are hungering for retro designs in everything from cameras to cars. Here are five car brands that make boxy SUVs engineered for the modern buyer.

Advertisement

Ford

Ford is one the most iconic automakers in American history, so it stands to reason that it has produced vehicles of every shape and size over its more than 100-year history, and one of its most legendary models is the Bronco. First introduced in 1966, the Bronco was designed as an all-purpose vehicle that could easily take you off the road and go head-to-head with vehicles like the Jeep CJ. Ford ended production on the Bronco in 1996, but reintroduced the model with a retro vibe, including the boxy exterior that so many loved, in 2021.

Advertisement

Now a competitor to the Jeep Wrangler, the Bronco’s shape isn’t just an homage to a well-loved vehicle. Those straight lines and the flat hood make it easier for drivers to see where they are on a rocky path or muddy trail. The 2026 model starts at $40,795, and offers a four-cylinder engine and standard four-wheel drive. Buyers can opt for either a two-door or a four-door model.

Ford also sells the Bronco Sport, a more refined option that still offers that retro-inspired, rugged design. It has a lower starting price of $31,845 but comes with standard four-wheel drive. Unlike both the two-door and four-door models of the Bronco, the doors on the Bronco Sport are not removable.

Advertisement

Hyundai Santa Fe

When Hyundai debuted the fully redesigned 2024 Santa Fe, some enthusiasts were shocked at its transformation. The smooth, flowing lines of its predecessor were nowhere to be seen, replaced by a new boxy design that is reminiscent of days long past. The change wasn’t for simple aesthetics, however. Automakers try to stay ahead of emerging trends when it comes to design, hoping to satisfy buyers when these vehicles hit the sales lot. 

The Santa Fe’s boxy look is geared toward outdoor enthusiasts, offering more interior space along with a wide tailgate opening that allows for easy loading and access to cargo. Tail lights are positioned low on the vehicle to enhance that wide space for even better accessibility.

Despite the boxy look, Hyundai carefully designed the Santa Fe to maximize aerodynamics, and it has excellent fuel economy. This three-row SUV also has a lower starting price than many competitors, with the base SE trim available for $36,650 including destination.

Advertisement

Other Hyundai models retain the flowing lines many modern consumers expect, but the Santa Fe isn’t the automaker’s only angular SUV. Its much smaller cousin, the Venue, also has a compact, boxy design to maximize interior space, while the fully electric IONIQ 9 offers a structured look. The Venue starts at $20,550, while the IONIQ 9 has an MSRP of $58,955, showcasing Hyundai’s commitment to providing thoughtfully-designed vehicles at different price points.

Advertisement

Jeep

Jeep has a long history of boxy SUVs, all the way back to the pioneering Willys, but it’s also produced many rounded, sleek models as well. Today, the Wrangler and the brand new Recon are Jeep’s most angular vehicles. The Recon is fully electric and trail-rated, with 650 horsepower and enough torque to easily get you up a rocky path. It’s more than a typical electric SUV, however. 

The Recon has removable doors, removable rear-quarter glass, removable swing gate glass, and an available power-folding roof that opens with the touch of a button. The Recon’s retro look isn’t just rugged and cool, it also gives buyers a ton of interior cargo space. This new model has a starting price of $66,995.

Jeep’s iconic Wrangler has always had a boxy shape, even as both consumer preference and technology changed over the years. The 2026 Wrangler is no different. Starting at $36,035, the Wrangler’s shape is intrinsically tied with its history and utility. This much beloved vehicle is made for off-roading fun, and the outcry would likely be enormous if Jeep ever changed its basic design.

The large Grand Wagoneer, priced at $63,995, also has an angular silhouette. The design is a nod to the original Jeep Wagoneer, which was launched in the 1960s. The straight sides and flat roof offer plenty of room for your family to stretch out over three rows of seats.

Advertisement

Mercedes-Benz

Many words come to mind when you think of Mercedes-Benz. Luxurious, timeless, and high-performing, most Mercedes models have smooth, aerodynamic bodies with flowing rooflines. The G-Class is the exception to the rule. Nicknamed the G-Wagon, this SUV has been produced continuously since it first debuted in 1979, and Mercedes never smoothed out those iconic sharp corners. 

The automaker originally partnered with an Austrian military vehicle manufacturer called Steyr-Daimler-Puch to design the Geländewagen for both military and civilian use. These roots are still evident in the vehicle’s ladder-frame chassis, tailgated-mounted spare tire, and rugged design. With a starting price of almost $200,000, however, the latest G63 AMG goes beyond your typical off-roading vehicle. It’s highly-capable on the trail, but it can also go from 0 to 60 mph in about four seconds, thanks to a 577 hp twin-turbo V8.

Advertisement

Inside, buyers will find leather seats available in a wide array of patterns and colors, a premium sound system, two 12.3-inch screens under a single pane of glass, and other truly cool features. There’s more than 37 cubic feet of cargo space and a side-hinged tailgate that looks great, but it might be cumbersome at times. Most of Mercedes-Benz’s other vehicles have a more streamlined design, even its wagons, but some of the more affordable SUVs like the GLB and the EQB offer harder edges that lend themselves to more cargo space.

Advertisement

Toyota

The Land Cruiser has been one of Toyota’s boxier SUVs since its launch in the 1950s, but there’s no denying that the automaker softened its lines in the late 1990s and into the 2000s. After discontinuing the model in 2021, the Land Cruiser made a triumphant return in 2024 with a look that harkens back to its original, boxy appearance.

The current model offers only two rows instead of three like its predecessor, and it offers ample cargo space. The retro touches are everywhere, from the TOYOTA heritage grille to the round headlights found on the base “1958” trim. Of course, it’s a different story when it comes to tech and safety features, and there’s also a modern hybrid powertrain with 326 hp and better-than-average fuel economy. It also boasts full-time four-wheel drive and three drive modes. Prices start at $59,675 including destination.

In addition to the Land Cruiser, several of Toyota’s other SUVs have boxy, rugged designs. The massive Sequoia has strong, muscular lines that maximize cabin space for both passengers and cargo. Nothing is small about the Sequoia, which starts at a much higher $67,920 including destination. The rugged, midsize 4Runner is designed to be as capable off-road as it is on the highway, and its square shape gives drivers a clearer line of sight, especially on the trail. The 2026 model starts at $43,865 including destination. Even the popular RAV4 is relatively boxy, with a squared-off roofline and fender arches that give it a distinctly Toyota off-roader shape.

Advertisement



Source link

Advertisement
Continue Reading

Tech

DEF CON hackers add new muscle to water utility protection

Published

on

Security

Franklin project adds new security providers, employs digital twins and AI

DEF CON hackers expanded their efforts to provide free cyber-defenses to rural water systems in the US to include managed detection and response providers, digital twins, and AI agents.

On Friday, at the annual hacker’s conference, DEF CON Franklin and the National Rural Water Association (NRWA) announced a new program called the Water Watch Center. It will initially fund five providers – Defendify, Legato Security, L1 Secure, Rapid7, and Sentinel Technologies – to help small water utilities serving fewer than 10,000 people detect and mitigate breaches. 

Advertisement

The security providers will exchange threat info and share that with the NRWA, which provides technical assistance and operational support to small water and wastewater utilities across all 50 states.

“We’ve had our volunteer experts out for two years in these water utilities, in the trenches with these folks, and the thing that we’ve realized is that there’s just not a scalable delivery mechanism for cyber for these utilities when there’s 150,000 of them, and 98 percent of them are small businesses,”  Jake Braun told The Register during an interview at DEF CON.

Braun co-founded the Franklin project at DEF CON in 2024, and 350 people signed up that year to donate their time and talent to securing water facilities.

We’ve had our volunteer experts out for two years in these water utilities, in the trenches with these folks, and the thing that we’ve realized is that there’s just not a scalable delivery mechanism for cyber for these utilities when there’s 150,000 of them

Advertisement

“We groped around in the dark for what to do, and eventually realized we already know how to do security for small businesses – it’s MSSPs,” Braun said. “So why don’t we just do that?”

He described the new Water Watch Center as a pyramid, with the NRWA at the top, the managed detection and response providers’ sensors hunting for security vulnerabilities across the utilities’ networks, and then Franklin volunteers fixing issues or responding to instructions as needed.

“We have five initial MSSPs, which will expand to 10 eventually, based on the 10 CISA regions,” Braun said. “And then below that, we have volunteers who can help, and connect water utilities to MSSPs, so we’re not just sending alerts. We can take the alerts that CISA and the ISAC put out, and deliver cybersecurity. That’s been the missing piece: there has been no delivery mechanism for cybersecurity that’s scalable nationally – that’s what this is.”

Suspected Iranian hackers have hit numerous water systems in recent weeks, and most were small, community systems that left programmable logic controllers directly exposed to the internet using default or weak passwords. There’s no indication that the attackers used AI to help plan or carry out these digital disruptions. However, as both cyber and national security experts told The Register during conversations on the sidelines of Black Hat and DEF CON, it’s only a matter of time until that happens.

Advertisement

DEF CON Franklin has a plan for that scenario, too.

The Water Watch Center also partnered with Vanderbilt University to apply research from the DARPA Cyber Agents for Security Testing and Learning Environment (CASTLE) program. This partnership will create digital twins for a few WWC water and wastewater system environments, and then researchers will deploy both red- and blue-team agents across these digital dupes.

The red-team attack agents try to hack the water systems, testing the blue-team defenders’ automated detection and response capabilities, with the eventual goal of deploying AI-based defense to water and wastewater facilities across the US.

“They let it fight each other a gazillion times, and then they figure out when does the blue team win, so we can train agents to then later drop into these 150,000 water utilities,” Braun said.

Advertisement

“There’s already a 500,000-person shortage of cyber professionals. The idea that we’re magically going to find 150,000 new people is a fantasy. There is no other way to really be able to combat the AI attacks that are going to be coming at these things.” ®

Source link

Continue Reading

Tech

Microsoft’s Weather app can eat up to 1.2GB of RAM just sitting open

Published

on

Facepalm: Microsoft’s default Weather app in Windows 11 can use nearly 1.2 GB of RAM while sitting open on a forecast screen, according to testing by Windows Latest. The app doesn’t need to be actively used to reach that level of memory consumption. The report found that MSN Weather launches as many as nine Chromium-based subprocesses, suggesting the app is built around a web wrapper rather than as a fully native application. That design helps explain why a basic system utility can use so much memory.

MSN Weather is the standard weather app included with Windows 11. It provides a detailed set of tools, including live radar, hourly forecasts, wind and precipitation data, air-quality readings and moon phases. The data comes from several weather providers, with Foreca serving as a primary source.

The app’s interface is modern and works smoothly, but still, the level of resource use stands out when compared with Apple’s Weather app on macOS, which uses about 250 MB of RAM while providing similar forecast details. That is about five times the RAM usage for the built-in Windows alternative.

The Windows app also carries advertising. Windows Latest’s testing cited ads for Adobe Acrobat while others saw ads for LendingTree and Spotify. Microsoft may need to offset the cost of delivering weather data, but ads in a Microsoft-owned app remain a point of frustration for users who have already paid for a Windows license.

Advertisement

The report arrives as Microsoft has been talking more openly about Windows 11 performance. The company recently removed material recommending 32 GB of RAM for gaming PCs, and has said Windows 11 is optimized to run smoothly on systems with 8 GB of memory.

On an 8 GB machine, an app using close to 1.2 GB of RAM would take up roughly 15% of the system’s available memory. That is a significant share for an application users may open only to check the temperature or see whether rain is expected.

But it seems Microsoft has been building simple apps like this one using WebView2, the company’s framework for embedding web content inside Windows apps. It runs on the same Chromium engine that powers Microsoft Edge, splitting rendering, networking and GPU work into separate processes. That’s why Task Manager shows Weather behaving less like a single lightweight app and more like a small browser session running in the background.

Advertisement

Microsoft has said it plans to improve performance, reliability and memory use across Windows 11. It has also discussed updating the apps included with the operating system as it shifts from older Win32 and UWP approaches toward WinUI-based development.

It’s not clear whether that work will include MSN-branded services such as Weather and News. Those services are built into the Windows experience, but Microsoft hasn’t specifically said they’ll be part of the planned overhaul.

For now, the Weather app shows the gap between Microsoft’s broader optimization goals and the experience of using some Windows utilities today. The app is visually polished and offers plenty of forecast data, but its browser-based structure, high memory use and ads make it an awkward fit for a default desktop app.

Advertisement

Source link

Continue Reading

Tech

NYT Connections hints and answers for Tuesday, August 11 (game #1157)

Published

on

Looking for a different day?

A new NYT Connections puzzle appears at midnight each day for your time zone – which means that some people are always playing ‘today’s game’ while others are playing ‘yesterday’s’. If you’re looking for Monday’s puzzle instead then click here: NYT Connections hints and answers for Monday, August 10 (game #1156).

Good morning! Let’s play Connections, the NYT’s clever word game that challenges you to group answers in various categories. It can be tough, so read on if you need Connections hints.

What should you do once you’ve finished? Why, play some more word games of course. I’ve also got daily Strands hints and answers and Quordle hints and answers articles if you need help for those too, while Marc’s Wordle today page covers the original viral word game.

Advertisement

Source link

Advertisement
Continue Reading

Tech

Now Rippling is counter suing tiny startup Runlayer

Published

on

HR startup Rippling filed a lawsuit Monday accusing MCP gateway startup Runlayer of infringing on three of its patents, according to the lawsuit seen by TechCrunch.

The filing comes after Runlayer sued the HR startup last month, accusing it of breach of contract and stealing its product ideas.

It’s the latest saga between the two companies after Rippling spent nearly a year testing the startup’s MCP product. The two companies never agreed on a price, and the trial never turned into a paid contract. Instead, Rippling built its own MCP server, and will soon offer it as a product that competes with Runlayer. (Rippling often turns its internally used tech into products, like its recently released AI Spend Console.)

Their battle serves as a warning of how the relationship between customers and startups can devolve in this AI-powered age of fast product building.

Advertisement

Runlayer, which launched its product about a year ago, bundles an MCP gateway with cybersecurity features like threat detection. MCP is an open standard that allows AI agents to connect with data and software systems needed to work independently.

Runlayer has raised a total of $42 million and was founded by third-time founder Andrew Berman. (His previous companies were baby-monitor maker Nanit and an AI video conferencing tool, Vowel, that sold to Zapier in 2024). Rippling became one of Runlayer’s earliest potential customers trialing its software.

The most dramatic detail in the lawsuit is Runlayer’s claim that a Rippling employee reached out to Berman to warn him that his employer was building a “copy” of Runlayer’s product. A Rippling spokesperson tells TechCrunch that its employee has since revised that view.

On Rippling’s side, perhaps the most dramatic claim is that it informed Runlayer of the patents it believed Runlayer had infringed soon after the startup filed its lawsuit.

Advertisement

One might infer that the suit is intended as leverage to bring Runlayer to the settlement table. Indeed, that’s how Runlayer views it.

“This is a desperate, retaliatory ploy to distract from the fact Rippling misappropriated our proprietary technology. We clearly have a standout AI product that has nothing to do with these patents. No attempt to bully or distract will prevent us from protecting our IP and continuing to innovate and create the best product for our fast-growing customer base,” Berman said in a written statement.

Rippling loves a good fighting-words statement too. Its spokesperson told TechCrunch: “It takes a certain boldness to accuse a competitor of violating intellectual property laws while infringing on that competitor’s inventions. But that’s exactly what Runlayer has done here. Rippling’s lawsuit calls out Runlayer’s hypocrisy. Having manufactured claims against Rippling to distract from its business failures, it now has to face a lawsuit for repeatedly copying Rippling’s inventions in building its own products.”

Now it’s up to the courts to unwind who did what to whom, unless the parties settle. But these dueling cases still serve as a buyer- and seller-beware warning. With AI advances, enterprises have never before been more empowered to build tech in-house. Yet they still may put a startup through its paces before choosing that option.

Advertisement

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Source link

Continue Reading

Tech

BdThemes plugins supply-chain hack creates rogue WordPress admins

Published

on

BdThemes plugins supply-chain hack creates rogue WordPress admins

A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators’ browsers to create rogue admin accounts.

Starting Saturday, the affected BdThemes products were no longer available for download after the WordPress Plugins team closed all of them pending a full review.

BdThemes provides premium WordPress plugins, including Element Pack, Prime Slider, Ultimate Post Kit, Pixel Gallery, and Ultimate Store Kit.

image

Its flagship free Element Pack plugin alone currently shows more than 100,000 active installations on WordPress.org, while the developer advertises a portfolio with over 350,000 active installs.

WordPress security firm Defiant started seeing attacks through its Wordfence web application firewall (WAF) on August 7.

Advertisement

The researchers say that the attacker “poisoned a static remote JSON data stream fetched by an administrative promotional banner component” after obtaining write access to the vendor’s storage bucket.

According to the researchers, the plugin developer had introduced a cross-site scripting (XSS) vulnerability in the JSON response parsing code, allowing the attacker to replace the legitimate promotional JSON with malicious code that exploited the security issue.

The researchers report that the attack was enabled by a coding flaw introduced in March 2026 in the JSON response-parsing code, which created a cross-site scripting (XSS) vulnerability in the BdThemes infrastructure.

The flaw is in the Biggop Library used by the Biggopti component responsible for getting promotional banners from the vendor’s API server and showing them in the customers’ WordPress admin dashboard.

Advertisement

A report from Defiant explains that the malicious JavaScript injection uses the legitimate administrator’s authenticated session to create rogue admin accounts on impacted sites, while an additional payload (w2.js) establishes persistence via a webshell (emer-run.php) by installing a fake plugin.

“The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insufficient output escaping,” Wordfence researchers say.

“This makes it possible for attackers who can compromise the Sigmative API server to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.”

The malicious API response
The malicious API response
Source: Wordfence

The issue was assigned a “medium” severity score, and Defiant’s report lists it as unpatched as of publishing.

Because the attack is entirely API-driven, requires no interaction, file modification, or plugin update, it is entirely stealthy, and the payload executes every time a logged-in administrator opens a wp-admin page.

Advertisement

The injected code manipulates WordPress database queries to hide rogue administrator accounts from the user list, making the compromise more difficult to spot.

Defiant’s Wordfence researchers say that reports that the command-and-control (C2) infrastructure used in the observed attacks points to the same attacker behind the recent Advanced Responsive Video Embedder and OptinMonster supply-chain compromises.

After discovering the attacks, the researchers analyzed available records and determined that the earliest possible start of the campaign was June 23.

The affected plugins were pulled from the WordPress.org directory on August 8, pending investigation, while two poisoned API endpoints now return clean JSON data.

Advertisement

At the time of writing, the vendor has not published an official statement about the incident on its website.

BleepingComputer has contacted BdThemes for a statement, but we have not received a response.


article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Advertisement
Continue Reading

Tech

The Galaxy S26 FE specs are out, and Samsung is playing the same old game

Published

on

Samsung’s upcoming “budget” flagship has leaked so many times over the past few months that there is not much left for the company to reveal. We have already seen its colors, redesigned camera housing, older processor, and familiar cameras. Now, a new leak appears to have filled in nearly the entire spec sheet.

WinFuture has obtained detailed specifications for the Galaxy S26 FE, pointing to a 6.7-inch Dynamic AMOLED 2X display with a 2340 x 1080 resolution, 120Hz refresh rate, and brightness reaching 1,900 nits in high-brightness mode. The phone is expected to come in Graphite, Pistachio, and Blueberry.

The older chip is no longer much of a surprise

The leak once again points toward Samsung’s Exynos 2500 paired with 8GB of RAM and either 128GB or 256GB of storage. We already covered an alleged Geekbench result for the phone in April, where the older chip trailed the Exynos 2600 inside the regular Galaxy S26 series by a sizeable margin.

The cameras are looking equally familiar. WinFuture lists a 50MP main camera with optical image stabilization, an ultrawide camera, and an 8MP telephoto offering 3x optical zoom. A 12MP camera sits on the front. An earlier leak already suggested Samsung would recycle much of the Galaxy S25 FE’s camera hardware, so there are few surprises here.

At least the battery gets some attention

The Galaxy S26 FE is said to pack a 4,900mAh battery and support 45W charging, which is exactly what Samsung already offers on the Galaxy S25 FE. The more interesting part is the battery chemistry. WinFuture believes Samsung may have switched to silicon-carbon technology.

Advertisement

If accurate, Samsung could be taking a similar approach to the Galaxy Z Flip 8. The foldable retained the same battery capacity as its predecessor, but the newer battery technology helped Samsung make the device slimmer. The Galaxy S26 FE could follow the same playbook, using silicon-carbon to reduce thickness rather than squeeze in a larger battery. Other specifications include IP68 protection, Wi-Fi 6, Bluetooth 5.4, NFC, Android 17, and One UI.

The phone is expected to cost €799 in the European market, which is €50 more than the launch price of the Galaxy S25 FE. Considering the current market conditions around RAM and storage, that price increase doesn’t look too bad, and Samsung has already warned that its future devices could get pricier due to rising component costs. Still, an older processor, familiar cameras, and no increase in the battery department could make the price harder to justify.

Source link

Advertisement
Continue Reading

Tech

A California Program Is Bringing Down the Cost of Heat Pumps by Buying Bulk

Published

on

When heat waves descended on California this summer, Shreyas Sudhakar, founder and chief executive officer of heat pump installation firm Vayu, took his chance.

Just 54 percent of homes in the state have central air-conditioning, but rising temperatures are making cooling a must-have. Sudhakar saw the hot weather as an opportunity to sign up multiple households to a heat pump “group-buy” scheme, offering them a chance to purchase technology that provides carbon-free heating and cooling at a discount. After advertising the venture online, he was flooded with queries.

Heat pumps often cost more than cooling-only air conditioners, which is why adoption hasn’t been more widespread in the US. But the group-buy approach offers would-be purchasers a bulk discount that can defray part of the cost. Group-buys also mean installers can line up a tidy string of jobs—a win-win potentially enabling whole neighborhoods to switch to heat pumps.

Along with heat pump marketplace VoltHub, Vayu launched the first California Heat Pump Group Buy last year. “Nobody, to our knowledge, had done it in California,” recalls Sudhakar. “We thought, ‘Let’s try it out.’” The program is available around Los Angeles and the Bay Area.

Advertisement

Air-source heat pumps run on electricity. They work by harvesting heat from outside air and distributing it indoors, or gathering excess internal heat and dumping it outside.

This isn’t exactly rocket science. Except, perhaps, to a former rocket propulsion engineer.

“I tell people this all the time,” laughs Sudhakar, who previously designed rocket engines at Blue Origin. “At the end of the day, it’s a bunch of pipes and a heat exchanger moving energy from one place to another.”

Among the first group of roughly 10 customers in the initial group-buy scheme was Naoya Kanai, a data scientist who lives with his wife and toddler in the Bay Area city of San Mateo. Kanai stumbled on the group-buy online and jumped at the chance, knowing that federal rebates for carbon-free appliances would soon disappear under the Trump administration.

Advertisement

“It was one of the most affordable ways to get a quality system,” he says of the program. Kanai recalls thinking, “I can really sell it to my spouse.”

Once households are signed up to the group-buy, Sudhakar and his colleagues work out what equipment they’ll need for each installation. Then, they shop around for deals from distributors so they can make offers to participants. “We’re looking for what is the best value across the entire group,” he adds. “Typically, we’re getting 15 to 30 percent discounts on the equipment.”

Kanai’s house is a two-story 1980s suburban home that has about 2,500 square feet of space. The new heat pump system cost roughly $14,500 and provides heating and cooling via ductwork that was already in place. Kanai says the flow of temperature-controlled air is much more comfortable and steady compared to his old gas furnace and air conditioner. He’s barely noticed this summer’s heat waves until going outside. “A lot of times we’ll step out the front door [and realize] ‘Oh, wow, it was actually really hot today.’”

Other group-buy programs are available across North America, with one of the oldest operational programs on Gabriola Island, British Columbia, a 58-square-kilometer land mass home to about 4,500 people. In 2010, a group called Energy Gabriola set itself up as a heat pump dealer via a distributor, so it could buy heat pumps in bulk and sell them at cost. This was possible because, until that point, there was no heat pump market or installation service on the island whatsoever.

Advertisement

Relying partly on volunteers, the group has installed more than 1,000 heat pumps to date, electrifying nearly half of the island’s households. “We think we’re the heat pump capital of Canada,” says Steven Earle, of Vancouver Island University, who is involved in Energy Gabriola.

Source link

Continue Reading

Trending

Copyright © 2025