Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Microsoft said MDASH with MAI-Cyber-1-Flash received a 96 percent score on CyberGYM, a standard benchmark test. The rating is 12 points higher than Anthropic’s Mythos and also beats Google Gemini and OpenAI GPT. The new MDASH costs half as much to use as the previous MDASH offering.
The second tool Microsoft announced on Monday is named Project Perception. It too is a collection of specialized AI agents that perform red-, blue-, and green-team functions for finding vulnerabilities, investigating them to determine their risk, and taking corrective actions, respectively. Microsoft said the platform selects the models to use based on the assigned task. Considerations that go into the decision include the model’s effectiveness and the end cost to the customer. Microsoft said the decisions are shaped by “ongoing research, benchmarking and evaluation across frontier and specialized models.”
Microsoft said Project Perception is designed to perform 90 percent of tasks for lower costs than similar platforms from competitors. That means customers can turn to the more expensive alternatives only for the remaining 10 percent of tasks.
Microsoft said the new tools respond to a seismic shift in how organizations secure their networks against catastrophic hacks.
“As AI accelerates the speed and scale of cyberattacks, defenders are being asked to secure increasingly complex digital environments with approaches built for a different era,” the company said. “Security teams are often forced to piece together signals, context, and risk insights across vast amounts of data, making it harder to keep pace with emerging threats.”
With last week’s OpenAI incident evoking troubling scenes straight out of the most dystopian sci-fi novels, the tools, which are currently in preview mode, deserve a healthy dose of caution that Microsoft made no mention of. They should be closely scrutinized and evaluated before being used in production. On the other hand, there are clear risks for not adopting such tools. Balancing the risks of using AI agents versus the threat of avoiding them is a work in progress with no clear answers for now.
Today’s Strands puzzle is a little tricky. Once you recognize the theme, you realize many words can fit as clues. Plus, some of the answers are long and could be difficult to unscramble. If you need hints and answers, read on.
Today’s Strands theme is: Leave nothing out.
If that doesn’t help you, here’s a clue: Don’t do anything halfway
Your goal is to find hidden words that fit the puzzle’s theme. If you’re stuck, find any words you can. Every time you find three words of four letters or more, Strands will reveal one of the theme words. These are the words I used to get those hints, but any words of four or more letters that you find will work:
These are the answers that tie into the theme. The goal of the puzzle is to find them all, including the spangram, a theme word that reaches from one side of the puzzle to the other. When you have all of them (I originally thought there were always eight, but learned that the number can vary), every letter on the board will be used. Here are the nonspangram answers:

Today’s Strands spangram is ITSALLTHERE. To find it, start with the I that’s four letters down on the far-left vertical row, and wind over and back.
Today’s NYT Connections: Sports Edition puzzle is a pretty tough one. That purple group lives up to its reputation as being almost impossible to solve. If you’re struggling with the puzzle but still want to solve it, read on for hints and the answers.
Yellow group hint: NFL roles.
Green group hint: Get your racket.
Blue group hint: More than one point.
Purple group hint: Look at how they end.
Yellow group: Football positions.
Green group: Tennis shot descriptors.
Blue group: Worth two points/runs.
Purple group: Ends in a number.

The theme is football positions.
The four answers are guard, linebacker, running back and tight end.
The theme is tennis shot descriptors.
The four answers are backhand, drop, slice and smash.
The theme is worth two points/runs.
The four answers are 2-run HR, layup, safety and wrestling reversal.
The theme is ends in a number.
The four answers are Conine (nine), end zone (one), heavyweight (eight) and Witten (ten).
Rhino Entertainment has been busy digging down into its archives of the legendary Atlantic Records label, restoring many classic recordings to their audiophile best via its Rhino High Fidelity premium reissue series. Just out is a wonderful upgrade of Dusty Springfield’s iconic 1969 album, Dusty in Memphis.
Dusty in Memphis is widely regarded as one of the greatest recordings in pop music history. A stroke of production genius, the decision to bring the acclaimed British pop singer to Memphis for a recording session that blended her pop prowess with American Southern soul resulted in a timeless album that has since been inducted into both the GRAMMY Hall of Fame and the National Recording Registry.

Official materials from Rhino confirm that the new reissue was “cut from the original master tapes by Kevin Gray and pressed on 180-gram black vinyl at Optimal in Germany. These releases feature glossy gatefold packaging with ‘tip-on’ jackets and newly written liner notes. They are limited to 5,000 individually numbered copies and available today exclusively at Rhino.com and select Warner Music Group stores internationally.”
Dusty in Memphis is available from Rhino’s website for $39.98.

Surprisingly, Dusty in Memphis did not sell particularly well upon its initial release, stalling at No. 99 on the Billboard 200, despite containing Dusty’s spectacular version of “Son of a Preacher Man,” which was a Top 10 hit single in both the U.S. and U.K. at the time.
Those who did buy the Dusty in Memphis LP back in the day tended to love it, so it can be hard to find original editions in good condition. I know this because it has taken me ages to find one out in the “wilds” of collecting—garage sales, thrift shops, and flea markets!

For those who are not the crate-digging type, obtaining a nice copy on the collectors’ marketplace can be a challenge, at least for the wallet. For example, the five “Near Mint” copies listed on the online music marketplace Discogs at the time of this writing range in price from $45 to $175. So there is some real appeal to a high-quality reissue.
That said, after a reference listen to my 1969-era “Monarch” pressing—considered by many collectors and audiophiles to be among the best-made vinyl records of its day—I found the listening experience offered by the new Rhino High Fidelity edition to be far superior. It sounds more open and far less compressed, offering a wider soundstage, crisp highs, and fuller, more distinct lows.
Most importantly, it sounds the way Dusty in Memphis should sound, which is the bottom line for many fans. At times, it feels as though we are hearing more of that master recording for the first time.

Again, you can order Dusty in Memphis directly from Rhino for $39.98. It’s a limited run, so get one while you can.
★★★★★★★★★★ Music
★★★★★★★★★★ Sound Quality
★★★★★★★★★★ Pressing Quality
Mark Smotroff is a deep music enthusiast / collector who has also worked in entertainment oriented marketing communications for decades supporting the likes of DTS, Sega and many others. He reviews vinyl for Analog Planet and has written for Audiophile Review, Sound+Vision, Mix, EQ, etc. You can learn more about him a LinkedIn.
With today’s emerging threats, traditional radar and electronic warfare (EW) systems that rely on static threat libraries face a critical vulnerability: mode-agile emitters operating in non-traditional modes that cannot be matched against predefined databases. A cognitive RF system addresses this challenge through artificial intelligence and machine learning techniques, enabling autonomous perception, reasoning, and response to unknown threats in the RF spectrum. This white paper reviews the architecture of cognitive AI/ML radar and EW systems, including key functional blocks such as RF acquisition, AI-driven analysis and inferencing, waveform synthesis, and RF generation. It also examines the challenges of training these systems — from acquiring real-world and simulated signal datasets to performing hardware-in-the-loop (HIL) and system-in-the-loop (SIL) testing — and describes how closed-loop testbeds can iteratively develop, validate, and improve the AI/ML algorithms needed to counter unknown threats.
Apple released new updates for macOS Sequoia and macOS Sonoma, extending security and maintenance support to Macs that haven’t moved to macOS Tahoe.
The updates are available through Software Update on supported Macs. Apple hasn’t identified any major new consumer features, which points to releases focused on security, stability, performance, and compatibility.
Users can install the updates by opening System Settings, selecting General, and choosing Software Update. A Mac will only offer the update that applies to its currently installed operating system.
The new releases give Mac owners another reason to stay current even when they aren’t ready or able to install macOS Tahoe. Some Macs can’t run Tahoe, while businesses and other users may remain on an older version because of software, hardware, or management requirements.
Apple has historically maintained the current version of macOS alongside two earlier releases. The company doesn’t promise a fixed support period, however, and older versions generally receive security and compatibility fixes rather than new features.
Updates for macOS Sequoia and macOS Sonoma keep older Macs secure and compatible while Apple puts most new features into macOS Tahoe and macOS 27 Golden Gate.
Apple introduced macOS 27 at WWDC on June 8 and released the first developer beta later that day. The company followed with the first public beta on July 13.
Apple hasn’t posted complete security documents for the new Sequoia and Sonoma updates. The company often publishes or expands those documents after an operating system update becomes available.
The previous updates, macOS Sequoia 15.7.7 and macOS Sonoma 14.8.7, arrived on May 11 with security fixes for both operating systems. Apple also released Safari 26.5.2 on June 29 for Sequoia and Sonoma.
Safari 26.5.2 fixed WebKit and web extension vulnerabilities that could expose sensitive information, move data across website boundaries, escape web-content restrictions, or crash Safari and related processes.
The separate Safari update showed why older macOS versions still need active maintenance. A Mac doesn’t have to run Apple’s newest operating system to face the same browser and WebKit threats.
Most users running macOS Sequoia or macOS Sonoma should install the applicable update. People who depend on specialized software, drivers, security tools, or managed enterprise systems may want to confirm compatibility before updating.
YouTube Premium will include Peacock Premium at no extra charge beginning in early 2027. “The deal brings a slew of premium content to the [$15.99 per month] YouTube Premium subscription, including live sports like the NFL, NBA and MLB and entertainment like Law & Order, Saturday Night Live and Love Island,” reports The Hollywood Reporter. “It also has the potential to dramatically scale Peacock, which remains smaller than many of its streaming competitors.” From the report: Peacock has 48 million subscribers, while YouTube Premium and YouTube Music have a combined 125 million subscribers, though they don’t break out how many each of those offerings have. The agreement, which expands on the deal the company inked with YouTube parent company Google last year, will also extend the entertainment company’s programming deal with YouTube TV, while bringing some of YouTube’s offerings to Comcast Xfinity and Xumo platforms.
There’s also a notable sports and production element to the deal, with NBC Sports agreeing to stream some live sporting events on its YouTube channels, and with NBC agreeing to serve as the production partner for select live events on YouTube. YouTube will also bundle some of the company’s International streaming offerings like Universal+ and Hayu in select markets.
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges.
The security issue affects FastJson versions 1.2.68 through 1.2.83 and is leveraged in attacks targeting various organizations in the U.S.
The malicious activity was observed last week by the agentic security company ThreatBook, and researchers at the business protection company Imperva confirmed that it was “targeting a wide range of organizations, across Financial Services, Healthcare, Computing, Retail, Business, and other industries.”
“Attacks are currently almost entirely targeting US-based organizations, with a few attacks in Singapore and Canada, although this will likely continue to expand globally,” Imperva says.

FastJson is an open-source Java library developed by Alibaba, used for serializing Java objects to JSON, and vice versa.
The project has 25,600 stars and 6,400 forks on GitHub, and is especially prevalent in Chinese enterprise software and projects built on Alibaba’s platform.
CVE-2026-16723 was discovered by FearsOff, an offensive security company, which published a technical write-up earlier this month.
The researchers explain that the flaw stems from the library’s type-resolution logic, which performs attacker-controlled resource lookups before enforcing AutoType restrictions. This creates a path for executing code remotely in Spring Boot fat-JAR deployments.
By abusing @type processing, the researchers were able to load and execute malicious classes without AutoType enabled or requiring third-party gadget chains.
In its security bulletin, Alibaba confirmed the critical severity of the vulnerability and warned that it is exploitable on “the most common Spring Boot deployment model.”
“The only deployment prerequisite is that the target runs as a Spring Boot executable fat-jar (i.e., launched via java -jar xxx.jar),” reads Alibaba’s security advisory.
The vendor notes that specifying a target class during deserialization does not mitigate CVE-2026-16723, as attackers can embed malicious payloads within ‘Object’ or ‘Map’ fields.
The vulnerable type-resolution logic is not present in fastjson2, which uses an allowlist-first model for polymorphic deserialization and doesn’t rely on the @JSONType annotation as a trust signal.
Also, FastJson versions 1.2.60 and earlier, and any non-fat-JAR deployments, aren’t affected either.
Developers using a version within the affected spectrum are urged to immediately enable SafeMode or switch to a non-impacted build.
Currently, there’s no fix issued for CVE-2026-16723. Imperva has also noted that FastJson 1.x is no longer actively maintained, so it’s unlikely it will receive a security update.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Firefighters in France are confronting a phenomenon never seen in the region before: fire clouds. It’s a sign of the intensity of the blazes burning—and how climate change is upping the odds that they appear.
A wave of fires has swept over France and Spain, sending hundreds of thousands fleeing. Firefighters on the frontlines are facing what a spokesperson for the French firefighter association told AFP called an “operational impossibility”—in other words, a “natural force beyond our control.”
As evidence of how out of control the wildfires in France are, look no further than the skies where the blazes have, in some cases, created their own weather. To form a fire cloud—what meteorologists call a pyrocumulonimbus or the even more metal-sounding cumulonimbus flammagenitus—you first need heat, which fires have in spades.
But just as important are dry conditions near the ground and cool, relatively moist conditions aloft in the atmosphere. As superheated smoke rises miles above the flames and into the cool atmosphere, water vapor condenses around the particles of ash to form water droplets. (Yes water vapor and water droplets are two different things.) As the air keeps rising, those water droplets eventually become ice crystals.
At this point, the smoke and water droplets have created a cloud, but unfortunately one that’s unlikely to provide much relief in the form of rain. Instead, these towering fire clouds can unleash lightning strikes that can start more fires and generate powerful downdrafts that reach the ground to fan flames further. At their worst, pyrocumulonimbus clouds can even spawn tornadoes.
Pyrocumulonimbus clouds have been documented in the US, Canada, and Australia, among a handful of other locations. But until now, there were no documented fire clouds in France. While the country is no stranger to wildfires, the size and ferocity of this summer’s blazes is well outside the normal.
Last week was France’s single most destructive week for wildfires over the past 20 years, according to data from the European Forest Fire Information System. It more than doubled the previous record during that period, which coincides with accurate satellite data. This isn’t an isolated bad week either. More than 220,000 acres have burned across the country so far, six times the annual average. That’s 61,000 acres higher than the previous yearly record.
If that sounds like a familiar trend, well, it unfortunately is. Burning fossil fuels has heated the planet up, making explosive wildfires more common and destructive around the world. A 2024 study found the incidence of extreme fires globally more than doubled from 2003 to 2023. Six of the seven most extreme years have happened since 2016.
After a slight weekend reprieve as temperatures dipped, they’re expected to rocket back up above 104 degrees Fahrenheit (40 degrees Celsius) in France and 108 degrees Fahrenheit in Spain later this week. That means firefighters will have to contend with more extreme fire weather—including the possibility of clouds created by the blazes themselves.
After getting his hands on a rope driver module from the Apollo project era that had a big ‘Scrapped Module’ stamped on it, [Mike Stewart] was naturally left curious as to what exactly had failed in this module. Originally destined for the Apollo Guidance Computer, these Raytheon-manufactured modules were the pinnacle of space-grade high-tech of the 1960s, with requisite acceptance testing so as to not endanger a very expensive space mission.
The cool part here is that the acceptance documents for the module in question (B16-B17) have been scanned in and can be found on the Internet Archive. With the part itself being potted and very much inaccessible, this document helpfully lays out the expected measurements on the module’s pins, as well as schematics and mechanical drawings. Unfortunately the reasons for the rejection were not recorded, so replicating the failing test results is required to understand the reason.

A slight complication here is that the testing procedure doesn’t just involve hooking up a multimeter for some voltage and capacitance measurements. There are also temperature and voltage extremes, and vibration tolerance involved, which would be somewhat complex to test, but most of all risk damaging a historical artefact. Thus a somewhat conservative testing procedure was chosen, even if this may not reveal the actual fault.
As noted in the video, sometimes modules were also rejected because someone simply dropped it on the floor along the way. However, generally if a module was found to be faulty they would open it to diagnose said fault, with a closer look at this module indeed revealing suspicious marks in the potting compound where it was apparently opened and conceivably repaired. This also might explain why they also put the ‘For engineering use only’ on it.
With multiple of such locations visible in the potting compound, these locations were mapped to the schematics for the module, to get some idea of what may have been accessed. After this, basic testing was performed on the module, as per the acceptance testing document.
Along the way an error was detected in said document, in the form of the wrong pin number. In table 4-2 the input pin 269 was mistakenly listed as having output pin number 169 when it should have been pin 168. Pin 169 is chassis ground, so this was presumably fixed in a later version of the document.
After all the testing with just stationary, room-temperature conditions, everything appeared to check out. This means that likely this was indeed a repaired module that got subsequently used for engineering purposes rather than installed in flight-ready hardware. The only issue found was that channels were out of calibration, but whether this was an original flaw or due to the module being half a century old is hard to tell in the absence of repair logs.
Overall it’s an exciting opportunity to document another part of history, since so many of the details pertaining to these original modules and related technologies got lost or muddled over the decades.
There’s a hybrid vehicle recently named as the one with the highest annual mileage, according to iSeeCars data. The study reflects that conventional hybrids, which don’t need to be plugged in to recharge, are driven 10.3% more miles than pure gas vehicles. Analysts at iSeeCars found that the average conventional hybrid travels a total of 14,696 miles per year, the highest average annual mileage recorded in any category. In contrast, the other primary hybrid category, plug-in electric vehicles (PHEVs), is driven 12.5% fewer average miles than full battery electric vehicles (BEVs).
The conventional hybrid that travels the highest annual mileage within the category is the Toyota Sienna hybrid minivan. This iSeeCars study stated that the average Toyota Sienna traveled 17,368 miles each year. JD Power named the Sienna the most reliable minivan you can buy in 2025. The other conventional hybrids that finished in the top three places included Toyota’s Highlander hybrid (16,795 miles) in second and Toyota’s Camry hybrid (16,605 miles) in third.
For the methodology of this study, iSeeCars analyzed odometer readings of more than 2.1 million three-year-old cars sold in 2025. These vehicles were broken down by the type of drivetrain and number of miles driven annually, with low-sales models eliminated.
The Toyota Sienna hybrid minivan is powered by a 2.5-liter four-cylinder engine boosted by two electric motors for a combined 245 horsepower, channeled through an electronically controlled continuously variable transmission eCVT. It should be noted that the Sienna has been hybrid-only since it received its last redesign in 2021. Front-wheel drive is standard, but all-wheel drive is optional, courtesy of a third electric motor on the rear axle that does not add anything to the 245-horsepower rating. We also discovered that the Sienna is one of the many Toyotas that are great for seniors in more ways than one.
A 2026 Sienna with all-wheel drive can go from 0-60 mph in 7.5 seconds, based on testing by Car and Driver. It has adequate cargo-hauling capability, with 34 cu. ft. of storage behind the third row and 75 cu. ft. with the third row folded. Unfortunately, the latest generation Sienna’s (2021-2026) second row cannot be removed, unlike other rivals such as the Chrysler Pacifica and Honda Odyssey. For those who need to haul lots of stuff, this could be a deal-breaker. Even so, evaluating five of the Sienna’s coolest features might sway you toward a purchase.
The Sienna’s best EPA-estimated fuel economy goes to the front-wheel drive version, which gets 36 combined mpg. The all-wheel drive version gives up one mpg in the city, but maintains 36 mpg on the highway. Sienna pricing starts at $42,415 (base LE trim), including delivery. Standard equipment includes remote keyless entry, three-zone climate control, wireless charging, eight-speaker audio, LED headlights, and dual power sliding side doors.
Weekend Open Thread: Brooks Brothers
Grayscale Files For Worldcoin ETF, WLD Registers Sharp Rise
How a former Blue Peter presenter stunned America’s Got Talent judges
Intel is reversing course and bringing hyper-threading back to its server chips
Turtle Beach Command Series KB7 review: a nifty screen-equipped gaming keyboard
New Jersey voter registration controversy explained: How 6,600 noncitizens got on the rolls, and what happens next
Johnny Depp’s R-Rated Gothic Cult Classic Gets New Release Ahead of Sydney Sweeney Remake
Ethics, other provisions in crypto Clarity Act to be further discussed
Luke Littler dismantles Gerwyn Price to retain title in Blackpool
Shanghai science forum photos show China’s AI and robotics advances in rivalry with US
2026 3M Open leaderboard: Scottie Scheffler finds putter in Round 1, sits three back
Commonwealth Games boxing: Jadumani Singh seals dominant 5-0 win over Pakistan’s Sumama Rehman to enter quarter-finals | Commonwealth Games News
16 Dresses for the High Summer Event
The Peugeot Family: How 200 Years of an “Old Money” Dynasty Died in A Boardroom
Spain sweeps the board at 2026 World Cup with individual awards
A New Post-Apocalyptic Gundam Anime Series Blasts Into SDCC
Andrew Cuomo joins OKX board as crypto exchange expands in U.S.
BITCOIN JUST ENTERED THIS CRITICAL ZONE…
XRP Ledger adds $2.6B as RWA inflows rank second
NADINE DORRIES: I have witnessed first-hand what happens to new Prime Ministers when they enter No 10… and this is why Andy Burnham will be out by May
You must be logged in to post a comment Login