Connect with us

Tech

Microsoft Uses Plagiarized AI Slop Flowchart To Explain How Git Works

Published

on

It’s becoming somewhat of a theme that machine-generated content – whether it’s code, text or graphics – keeps pushing people to their limits, mostly by how such ‘AI slop’ is generally of outrageously poor quality, but as in the case of [Vincent Driessen] there’s also a clear copyright infringement angle involved. Recently he found that Microsoft had bastardized a Git explainer graphic which he had in 2010 painstakingly made by hand, with someone at Microsoft slapping it on a Microsoft Learn explainer article pertaining to GitHub.

As noted in a PC Gamer article on this clear faux pas, Microsoft has since quietly removed the graphic and replaced it with something possibly less AI slop, but with zero comment, and so far no response to a request for comment by PC Gamer. Of course, The Internet Archive always remembers.

What’s probably most vexing is that the ripped-off diagram isn’t even particularly good, as it has all the hallmarks of AI slop graphics: from the nonsensical arrows that got added or modified, to heavily mutilated text including changing ‘Time’ to ‘Tim’ and ‘continuously merged’ into ‘continvuocly morged’. This makes it obvious that whoever put the graphic on the Microsoft Learn page either didn’t bother to check, or that no human was involved in generating said page.

Spot the differences. (Credit: Vincent Driessen (left), Microsoft (right) )
Spot the differences. (Credit: Vincent Driessen (left), Microsoft (right) )

It definitely gives a dystopian ‘Dead Internet’ vibe where the fruits of past labor are being cynically regurgitated and spat out in the form of AI slop that bears little resemblance to the original, and should send real humans either running off in abject terror or fall over in uncontrollable laughter.

Even if this output was the result of [Vincent]’s original graphic getting scraped and shoved struggling and screaming into a diffusion model’s training dataset, there are so many dead giveaways that it was based on this original: from the text blurbs, to the use of the label ‘feature branches’ that’s retained in the reproduction even though the second feature branch has been trimmed.

Advertisement

All of this raises many uncomfortable questions about copyright in the context of both large language models and diffusion models, with cases like these making it clear that sometimes substantial elements of copyrighted works are being reproduced nearly verbatim. Depending on the associated copyright license, this can result in very expensive copyright infringement lawsuits, with some of these already working, or having worked their way through various courts pertaining to primarily stock images and books.

And to think that all that Microsoft would have had to do here was to check with [Vincent] for the license on the graphic if they had wanted to use it. As [Vincent] indicates, he would have been more than happy to do so if a backlink and credit was provided. This obviously is the human way to do things, where a human contacts a fellow human being to inquire about their thoughts on a topic, or peruses the works by fellow humans to find something to their liking prior to contacting said human with a usage question.

In this era of ‘just ask the machine’ by mashing in a query on a prompt, it would seem that this particular case will be far from the last one. The cynical take here is that the value of human output has been reduced to mere training data for the content machines, but maybe Microsoft will surprise us here with a tearful apology and real actions to prevent such events from ever happening again.

Advertisement

Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Tech

GameSir G8 Plus review: an iterative upgrade fit for iPad mini fans

Published

on

The first GameSir G8 was an affordable return to iPhone grip controllers, and while its successor doesn’t have any significant bells or whistles, it gains Apple certification and iPad mini support.

An iPad mini showing a pixelated farm game while in a white game controller grip with neon and wall art blurred in the background.
GameSir G8 Plus review

Not every product needs to blow us away with some revolutionary new feature or concept. Game controllers have found a fairly mature place, design-wise, so there’s no need to rock the boat.
The GameSir G8 Plus is an MFi-certified controller with a USB-C connector, rumble support, programmable buttons, and customization options. It closely resembles the GameSir G8 Galileo that it replaces, but it has some notable improvements.
Continue Reading on AppleInsider | Discuss on our Forums

Source link

Continue Reading

Tech

Samsung isn’t aping the AirPods, but doing a better job on the upcoming Galaxy Buds 4

Published

on

Ahead of their expected launch on February 25, 2026, the Samsung Galaxy Buds 4 have appeared in real-life photos shared by @Mr_TechTalkTV on X. Although they contain non-functional or dummy units used for displays in retail stores, they give us a good idea of how the earbuds will look.

Previously, we’ve seen the regular Buds 4 (with an open-ear design) in black and the Buds 4 Pro in white (with silicon eartips). However, the new pictures flip this order, showcasing the regular earbuds in white and the Pro ones in black.

Exclusive: First real-life look at the Galaxy Buds 4 and Galaxy Buds 4 Pro. These are non-functional dummy units that Samsung sends to retail stores for display. pic.twitter.com/Wz74oJqaGB

— TechTalkTV (@Mr_TechTalkTV) February 19, 2026

Fresh leaks, familiar rivalry

From what it looks like, both earbuds will be available in white and black finishes, appealing to buyers who aren’t into the simple white color the AirPods are available in.

Advertisement

Everything from the AirPods’ charging case, top lid, and earbuds is made of the same glossy white plastic material, which is surely iconic, but it doesn’t leave buyers with any other option.

While the choice of colors shouldn’t be an issue with the Galaxy Buds 4 series, the design should be what distinguishes it from the AirPods (and for good). As seen in the pictures, both Buds 4 models have a metallic paint finish on their stems, elevating their look.

More choice, more personality

Samsung has opted for a flat charging case, where the earbuds lie horizontally, making them easier to access and easier to remove in a hurry. The wider layout also allows for a slimmer profile in your pocket or backpack and a case that feels more stable on a tabletop.

With two colors, an elevated design, a flat charging case, optimized touch/gesture controls, and potential upgrades in sound quality and noise cancellation, the Galaxy Buds 4 should be a compelling choice for Galaxy S26 buyers, or other Android users, for that matter.

Advertisement

Source link

Continue Reading

Tech

‘In the Irish market there is a supply and demand for niche senior roles’

Published

on

IAS’s Claire Griffin explores how she began her career in recruitment and the opportunities open to professionals in this space.

A technical recruiter at Integral Ad Science, Claire Griffin tells SiliconRepublic.com that a career in the recruitment sector was initially unexpected. 

“I came from a performing arts and teaching background. I have always worked in very people-focused roles, where building relationships and really understanding individuals was at the heart of what I did,” she says. 

“Making the leap into something completely new is what brought me into recruitment, but it’s the people side of the role that’s kept me here for more than 10 years. Every day is different, and I still genuinely enjoy meeting new people, hearing their stories and helping connect them with opportunities where they can really thrive.”

Advertisement
What are some of the challenges in this industry and how are they overcome?

There are plenty of challenges in tech recruitment right now. In terms of the Irish market, there is a supply and demand for filling certain niche senior roles that require specific skillsets. AI, while driving us forward in many ways, has inhibited certain aspects of recruitment processes, including the creation of CVs to match job specs as opposed to candidates’ experience and the use of undeclared tools within technical interviews. Also, the shortage of housing and skyrocketing rents in Ireland have deterred skilled workers from relocating to Ireland, making the competition for talent tighter.

What career opportunities are there for professionals in this space?

Ireland is a really strong place to build a career in deep tech right now. There’s a healthy mix of world-class research, multinational R&D and a growing number of ambitious start-ups, which gives candidates a lot of choice in how they go about shaping their careers.

Candidates with deep-tech skills can work across research and innovation through Ireland’s universities and research centres, where there’s a strong focus on turning breakthrough ideas into real-world solutions. At the same time, many global giants in tech and life-sciences companies base their engineering and R&D teams here, offering opportunities to work on cutting-edge projects with global impact.

In recent years, Ireland has also experienced huge growth in the start-up ecosystem. Deep-tech founders and early hires are increasingly finding support, funding and international reach. This can open pathways into leadership, product development and commercial roles. Overall, deep tech in Ireland isn’t just about technical roles anymore. It’s about long-term careers that combine innovation, impact and global relevance.

Advertisement
What makes an applicant stand out from the crowd?

In a world full of AI-generated CVs, it can sometimes feel hard for candidates to stand out. We see a lot of these CVs listing technologies which candidates may have worked for five years or five minutes on, but are listing it in hopes of bypassing an applicant tracking system. What really sets candidates apart is their ability to show impact, not just skills. A strong CV will clearly explain what they’ve built, why it mattered and what problem it solved.

Strong candidates also demonstrate curiosity and adaptability. Technology moves quickly, so hiring managers look for people who are actively learning. This is shown through side projects, open-source contributions or keeping up with emerging trends, and then applying that learning in practical ways.

Communication is another key differentiator. The ability to explain complex ideas clearly, work across teams and understand the business context behind the technology is often what separates good engineers from great ones. Finally, a small bit of research into a company goes a long way. Candidates who understand the company’s mission, who can articulate why they want that specific role and who can show how their experience aligns with it tend to stand out far more than those sending generic applications.

What skills should deep-tech professionals prioritise?

In Ireland’s tech sector, deep-tech professionals should prioritise strong core technical skills, particularly in areas like software engineering, AI, data, and systems design. They should also have the ability to apply that expertise in real-world settings. Employers value people who can move quickly from concept to deployment.

Advertisement

Adaptability is a key differentiator for individuals to move forward. Ireland’s tech ecosystem spans multinationals, start-ups and research centres, so professionals who can work across environments, learn continuously and collaborate with diverse teams tend to stand out. Clear communication and commercial awareness matter. Being able to explain complex technology simply and understand how it supports business outcomes is increasingly important in Ireland’s growing tech industry.

What advice do you have for other technical recruiters working in this space?

My main advice is to go beyond keywords and really understand the technology you are hiring for. A lot of tech roles are nuanced and strong candidates don’t always fit a standard profile. Taking the time to understand the problem a team is trying to solve makes a huge difference. We are recruitment partners, so strong relationships built on trust and transparency – both with hiring managers and candidates – are key to moving forward.

Ireland’s deep-tech talent pool is small, so taking the time to establish and nurture relationships for long-term engagement are far more valuable both to your company and you as an individual than making quick wins.

Lastly, engaging with research centres, start-ups and industry networks and meetups is a great way to keep your finger on the pulse of what is happening from both a client and candidate perspective.

Advertisement

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Source link

Advertisement
Continue Reading

Tech

The Joy Of Making Handheld Tetris From Scratch

Published

on

As anyone who’s made a thing knows, a lot of work goes into bringing something from idea to completion. But there’s also considerable satisfaction in the process. [Willian] recently did exactly that, and shares the joyful experience of creating a homebrew handheld game gadget from scratch. It runs a homebrewed Tetris clone (as well as Snake), and we love the results.

The game gadget uses an ATmega328P programmed via the Arduino IDE, and a 1.8″ TFT color LCD screen. It’s self-contained in a box with a few buttons as controls and runs off three AAA cells. [Willian] made the smart design choice to run the microcontroller at 8 MHz instead of the more common 16 MHz, because doing so meant the board can run at 3.3 V instead of 5 V. Why does this matter? The LCD display runs off 3.3 V as well, and if all components can run off the same supply and logic levels, it simplifies things considerably.

Also, creating a 3.3 V supply is a simple matter of three alkaline cells in series with an LDO (low drop-out) regulator, which is great for a handheld device. We do note that AA cells have a considerably higher energy density and capacity than AAA cells and are usually the better choice, but one works with what one has, and sometimes the space and weight saved by AAA is just too good to pass up.

The software has some notable approaches to keep things responsive and optimal. Instead of defining each of the Tetris pieces as a 2D shape, [Willian] instead pre-defines each piece (and their rotations) so that rotating a piece is just an index change in an array, instead of a transform implementing a rotation. Also, full-screen redraws are comparatively slow over SPI and caused flickering, so only cells that have changed are redrawn to the screen to keep things responsive. The code is all on GitHub, and it’s a great peek at how things get implemented under the hood.

Advertisement

The enclosure is just cardboard, and it does the job in [Willian]’s case. But we’ll point out that cardboard is actually a highly adaptable material from which to prototype. With just a few tips and a little care, paper products can be your new best friend when it comes to one-offs and prototypes.

Source link

Advertisement
Continue Reading

Tech

Barnes & Noble’s NOOK Reading Tablet 8.7 Shows That Dedicated Reading Hardware Refuses to Fade Away

Published

on

Barnes & Noble Nook Reading Tablet 8.7 Lenovo
Barnes & Noble has just released the NOOK Reading Tablet 8.7, a subtle reminder that e-readers are still very much a thing. This latest device, available in Seafoam Green and priced at $150, provides a clean Android experience geared to the activities you want to do on it, such as read books, periodicals, comics, or listen to audiobooks. With its cooperation with Lenovo, the new NOOK feels more like a companion for readers than a general-purpose tablet.


Barnes & Noble NOOK Reading Tablet 8.7
The 8.7-inch display is a properly sized IPS LCD with a resolution of 1340 x 800 pixels. The screen is bright enough for even the brightest rooms at up to 480 nits, and it has an oleophobic coating to keep fingerprints to a minimum. TÜV Rheinland certification assures that it emits low enough blue light to not cause eye strain. You may switch to grayscale for text-heavy content, which feels more like actual e-ink, and you can even view comics or periodicals in full color.

Sale


Lenovo Idea Tab – College Tablet – 11″ 2.5K IPS Touchscreen Display – 90Hz – MediaTek Dimensity…
  • POWER YOUR STUDY, FUEL YOUR PLAY – Discover smarter learning with the Lenovo Idea Tab. Stay campus-ready with all-day battery life, AI-powered apps…
  • SMOOTH, POWERFUL, IMMERSIVE – The MediaTek Dimensity 6300 processor is more powerful than ever, with the AI-enhanced multitasking you need to stay…
  • CIRCLE IT, SEARCH IT – Use your Lenovo Tab Pen or fingertip to circle items for instant search results or to translate other languages without…

Barnes & Noble NOOK Reading Tablet 8.7
Performance is provided by a MediaTek Helio G85 eight-core processor paired with 4GB of RAM; common chores such as flicking across pages, browsing the NOOK store, and streaming audiobooks all go smoothly. Storage starts at 64GB but can be expanded up to 1TB via a microSD card slot, providing ample space for a huge library or downloaded content. The tablet is powered by Android 15 and features a bespoke NOOK interface that places all of the books and reading apps right where you need them while still allowing you to access everything the Google Play Store has to offer.

Barnes & Noble NOOK Reading Tablet 8.7
The battery capacity is a reasonable 5,100mAh, and Barnes & Noble claims it can last up to 16.5 hours. It also supports 15W quick charging over USB-C. Stereo speakers calibrated for Dolby Atmos are positioned on either side, allowing for clear audiobook playback, while a 3.5mm headphone port remains for wired listening. Bluetooth 5.1 supports wireless earbuds and speakers. The cameras are quite standard, with an 8MP rear device with autofocus and a 2MP front-facing unit for video calls.

Source link

Advertisement
Continue Reading

Tech

Flaw in Grandstream VoIP phones allows stealthy eavesdropping

Published

on

Grandstream

A critical vulnerability in Grandstream GXP1600 series VoIP phones allows a remote, unauthenticated attacker to gain root privileges and silently eavesdrop on communications.

VoIP communication equipment from Grandstream Networks is being used by small and medium businesses. The maker’s GXP product line is part of the company’s high-end offering for businesses, schools, hotels, and Internet Telephony Service Providers (ITSP) around the world.

The vulnerability is tracked as CVE-2026-2329 and received a critical severity score of 9.3. It impacts the following six models of the GXP1600 series of devices that run firmware versions prior to 1.0.7.81:

Wiz
  • GXP1610
  • GXP1615
  • GXP1620
  • GXP1625
  • GXP1628
  • GXP1630

Even if a vulnerable device is not directly reachable over the public internet, an attacker can pivot to it from another host on the network. Exploitation is silent, and everything works as expected.

In a technical report, Rapid7 researchers explain that the problem is in the device’s web-based API service (/cgi-bin/api.values.get), which is accessible without authentication in the default configuration.

Advertisement

The API accepts a ‘request’ parameter containing colon-delimited identifiers, which is parsed into a 64-byte stack buffer without performing a length check when copying characters into the buffer.

Because of this, an attacker supplying overly long input can cause a stack overflow, overwriting adjacent memory to gain control over multiple CPU registers, such as the Program Counter.

Rapid7 researchers developed a working Metasploit module to demonstrate unauthenticated remote code execution as root by exploiting CVE-2026-2329.

Metasploit module
Metasploit module
Source: Rapid7

Exploitation enables arbitrary OS command execution, extracting stored credentials of local users and SIP accounts, and reconfiguring the device to use a malicious SIP proxy that allows eavesdropping on calls.

Stealing credentials
Stealing credentials
Source: Rapid7

Rapid7 researchers say that successful exploitation requires writing multiple null bytes to construct a return-oriented programming (ROP) chain. However, CVE-2026-2329 permits writing of only one null terminator byte during the overflow.

To bypass the restriction, the researchers used multiple colon-separated identifiers to trigger the overflow repeatedly and write null bytes multiple times.

Advertisement

“Every time a colon is encountered, the overflow can be triggered a subsequent time via the next identifier,” explain the researchers in the technical writeup.

“We can leverage this, and the ability to write a single null byte as the last character in the current identifier being processed, to write multiple null bytes during exploitation.”

The researchers contacted Grandstream on January 6 and again on January 20 after receiving no response.

Eventually, Grandstream fixed the issue on February 3, with the release of firmware version 1.0.7.81.

Advertisement

Technical details and a module for the Metasploit penetration testing and exploitation framework. Users of vulnerable Grandstream products are strongly advised to apply available security updates as soon as possible.

Modern IT infrastructure moves faster than manual workflows can handle.

In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.

Source link

Advertisement
Continue Reading

Tech

Giga Texas Sees First Tesla Cybercab Roll Off the Line

Published

on

Giga Texas First Tesla Cybercab Production
Tesla has made considerable progress toward fully autonomous vehicles, and its staff at Gigafactory Texas are clearly excited. Just the other day, they gathered around the first Cybercab to roll off the assembly line, a streamlined two-seater with no visible steering wheel or pedals, and Tesla even shared the moment on social media, complete with a congratulatory message from Elon Musk himself on the team’s excellent work.



The fact that this vehicle arrived weeks ahead of schedule is undoubtedly impressive, and while full production isn’t expected until April, this early prototype is a major thumbs up for the entire production line. Musk has advised us not to anticipate too much too soon in the early days, but this feat demonstrates how far we’ve come in moving this hardware from the planning board to the actual world.


JCC 1/24 Diecast Taxi Alloy Model Car,Pull Back Toy, with Light and Sound, 4 Opening Parts…
  • 【PULL-BACK MOTOR & NO BATTERIES NEEDED】 Simply pull the car back and watch it zoom across the floor! This classic pull-back friction mechanism…
  • 【INTERACTIVE SOUND & LIGHT EFFECTS】 Press the designated buttons or wheels to trigger realistic engine revving sounds and exciting flashing LED…
  • 【MULTIPLE OPENABLE PARTS & DETAILS】 Features fully functional doors, hood, and trunk that can be opened and closed. This highly interactive…

From the ground up, the engineers intended the Cybercab to function flawlessly as an autonomous vehicle. Its compact cabin with scissor doors that allow passengers to enter inside and enjoy a smooth, driverless trip. Cameras and Tesla’s cutting-edge Full Self-Driving (FSD) software handle the navigation, eliminating the need for all of the controls we normally take for granted, such as a steering wheel and pedals.


Tesla is now manufacturing the Cybercab using a unique, Unboxed approach that divides the entire thing into separate sections that are all built at the same time and then joined together at the end. The numerous small components and heavy castings of the past have been replaced by simpler, lighter single-piece castings that accelerate the process while saving space. Of course, if the problems are worked out, that change in approach will allow the Giga Texas plant to scale up to produce millions of devices every year, which is just around the corner given the expected growth over the next several years.

Advertisement

Of course, there are still a number of regulatory barriers to overcome before the Cybercab can be used on public roads, especially because present federal safety requirements are focused toward having a human driver behind the wheel. That means the federal government will have to make an exemption for an automobile manufactured without all of the regular restrictions, and that will be true at the state level as well. Even while Tesla is running a limited number of driverless Model Y vehicles in Austin and San Francisco, those vehicles have fallback alternatives that the Cybercab lacks.

Giga Texas First Tesla Cybercab Production
Then there’s the subject of price, and there are some big shocks in store. Elon Musk recently revealed that a consumer version of the Cybercab might be available for $30,000 or less by 2027, at the latest. That would make it very affordable for both individuals and fleet operators, and the economics of personal transportation would begin to move toward shared, on-demand use.
[Source]

Source link

Advertisement
Continue Reading

Tech

H&R Block Coupons and Deals: $50 Off Tax Prep in 2026

Published

on

As they say, the only things you can’t escape in life are death and taxes. Doing your own taxes has only gotten easier over the years but it’s still plenty confusing, especially with both federal and state rules and rates always in flux. To help you figure out this confusing process, I’ve written a guide on How to Pay Your Taxes Online, and included H&R Block and other competitors to give you more information as you navigate between the seemingly endless options available for your specific tax needs. Tax day may not be until April 15 but as we all know too well, that date comes around quickly each year. With that in mind, now’s a great time to start getting your affairs in order.

For 70 years, H&R Block has stepped in to help with tax preparation services that aim to make things as painless as possible. H&R Block has its classic in-person help from a tax expert along with easy-to-use online tax services that you can complete online while in your pajamas. We here at WIRED love to help you save money too, and that’s why we have rotating deals and H&R Block coupons to help ease the pain of tax season a little more.

Save With Our $50 H&R Block In-Store Coupon (And More)

To help make tax season a bit more bearable, you can get $50 off in-person tax prep when you file with an H&R Block tax pro (until February 23). To redeem this offer, you’ll need to make an appointment online, and present the coupon either digitally or in-print. This coupon features single-use codes, so you’ll need to click on the module at the top of the page to get the H&R Block discount code (and you can’t use the same one twice). Also through February 23, you can also get 25% off H&R Block’s DIY online offering, with no promo code needed!

Can I File My Taxes for Free at H&R Block?

H&R Block knows taxes are confusing, and the process is one that no filer looks forward to. That’s why H&R Block eases some of the tax filing woes by offering H&R Block Online Free Edition. Over half (around 55% of filers) qualify; this service is for simple taxes only, meaning Form 1040s and no schedules except Earned Income Tax Credit, Child Tax Credit, Student Loan Interest, and Retirement Plan Distributions. File your simple state return for free on H&R Block today.

Advertisement

Don’t Go at it Alone With H&R Block Assistance Options

Tax assist options are available, whatever your need. Not a CPA or DIY-er? No problem. H&R Block’s tax experts are trained and ready to help with big and small tax questions. There are tons of choices, no matter your need, like a one-on-one meeting in an office where you can make an appointment ahead of time, or just walk in; from home where you can work with your Tax Pro online; and you can even drop off files at an H&R Block office. Plus, you can even get a free Second Look Review of past returns to see if there was money left on the table.

Get Up to $4,000 With a Refund Advance Loan at H&R Block

If you can’t wait on your refund (no judgement; I get it), you can get up to $4,000 in refunds immediately after filing, without waiting for the slow-moving federal and state processes. If eligible, you can get a Refund Advance loan within minutes of filing when you complete the process with an H&R Block Tax Pro. With this loan advance, there’s no loan fees or interest. Act sooner rather than later, as this deal is only available through March 15.

How Much Does H&R Block Charge?

H&R Block has different tiers depending on tax filing needs, so you can pick the online filing option that works best for you. The free online is best for simple returns, with $0 per state filed; deluxe starts at $28 for federal and $37 per state filed, which includes itemized deductions and free tax Pro review. Premium is now only $56 and $37 per state filed, and also includes investments and free tax Pro review. Plus, they have an option for self-employed folks and business owners, whose taxes can be complicated and costly. That service includes 1099 forms with expenses and includes free tax Pro reviews, and costs $68 right now with $37 per state filed.

How Do I Get an H&R Block Key Code?

An H&R Block Activation Code is a unique ten-character code that’s attached to your personal H&R Block Tax Software. It’ll be a long string of uppercase letters and numbers. This activation code registers your software and is used to unlock your five free federal e-files. Once opened, you’ll need to enter it to activate the software. More in-depth directions and troubleshooting can be found here.

Advertisement

Other Deals for New and Existing H&R Block Customers

To find which service best fits your needs, select all that apply to you—like if you have kids, own a home, or are a freelancer—to find your best personal filing experience. H&R Block has four different packages, including federal and state. Best of all, you can save 20% on H&R Block tax software products without an H&R Block promo code (until April 15).

H&R Block has tons of incentives and perks, including a free 3-year Second Look. That means H&R Block will review your last three tax returns to find errors, mistakes, or money others may have missed. Get your taxes done and spend the rest of the spring chilling; DIY online file, or get an in-store assisted file for less—no H&R Block coupon needed.

Source link

Advertisement
Continue Reading

Tech

PromptSpy is the first known Android malware to use generative AI at runtime

Published

on

Android malware

Researchers have discovered the first known Android malware to use generative AI in its execution flow, using Google’s Gemini model to adapt its persistence across different devices.

In a report today, ESET researcher Lukas Stefanko explains how a new Android malware family named “PromptSpy” is abusing the Google Gemini AI model to help it achieve persistence on infected devices.

“In February 2026, we uncovered two versions of a previously unknown Android malware family,” explains ESET.

Wiz

“The first version, which we named VNCSpy, appeared on VirusTotal on January 13th, 2026 and was represented by three samples uploaded from Hong Kong. On February 10th, 2026, four samples of more advanced malware based on VNCSpy were uploaded to VirusTotal from Argentina.”

First known Android malware to use generative AI

While machine learning models have previously been used by Android malware to analyze screenshots for ad fraud, ESET says that PromptSpy is the first known case of Android malware integrating generative AI directly into its execution.

Advertisement

On some Android devices, users can “lock” or “pin” an app in the Recent Apps list by long-pressing it and selecting a lock option. When an app is locked this way, Android is less likely to terminate it during memory cleanup or when the user taps “Clear all.”

For legitimate apps, this prevents background processes from being killed. For malware like PromptSpy, it can serve as a persistence mechanism.

However, the method used to lock or pin an app varies between manufacturers, making it hard for malware to script the right way to do so on every device. That is where AI comes into play.

PromptSpy sends Google’s Gemini model a chat prompt along with an XML dump of the current screen, including the visible UI elements, text labels, class types, and screen coordinates.

Advertisement
PromptSpy sending an LLM prompt to Google Gemini
PromptSpy sending an LLM prompt to Google Gemini
Source: ESET

Gemini then responds with JSON-formatted instructions describing the action to take on the device to pin the app.

The malware executes the action through Android’s Accessibility Service, retrieves the updated screen state, and sends it back to Gemini in a loop until the AI confirms that the app has been successfully locked in the recent apps list.

“Even though PromptSpy uses Gemini in just one of its features, it still demonstrates how incorporating these AI tools can make malware more dynamic, giving threat actors ways to automate actions that would normally be more difficult with traditional scripting,” explains ESET.

While the use of an AI LLM for run-time changes to behavior is novel, PromptSpy’s primary functionality is to act as spyware.

The malware includes a built-in VNC module that allows the threat actors to gain full remote access to devices with Accessibility permissions are granted.

Advertisement

Using this access, the threat actors can view and control the Android screen in real time.

According to ESET, the malware can:

  • Upload a list of installed apps
  • Intercept lockscreen PINs or passwords
  • Record the pattern unlock screen as a video
  • Capture screenshots on demand
  • Record screen activity and user gestures
  • Report the current foreground application and screen status

To make removal harder, when users attempt to uninstall the app or turn off Accessibility permissions, the malware overlays transparent, invisible rectangles over UI buttons that display strings like “stop,” “end,” “clear,” and “Uninstall.”

When a user taps the button to stop or uninstall the app, they will instead tap the invisible button, which blocks removal.

Unclear if its a proof-of-concept malware

Stefanko says that victims must reboot into Android Safe Mode so that third-party apps are disabled and cannot block the malware’s uninstall.

Advertisement

ESET told BleepingComputer that it has not yet observed PromptSpy or its dropper in its telemetry, so it is unclear whether the malware is a proof-of-concept.

“We haven’t seen any signs of the PromptSpy dropper or its payload in our telemetry so far, which could mean they’re only proofs of concept,” Stefanko told BleepingComputer.

However, as VirusTotal indicates that several samples were previously distributed via the dedicated domain mgardownload[.]com and used a web page on m-mgarg[.]com to impersonate JPMorgan Chase Bank, it may have been used in actual attacks.

“Still, because there appears to be a dedicated domain that was used to distribute them, and fake bank website, we can’t rule out the possibility that both the dropper and PromptSpy are or were in the wild,” Štefanko added.

Advertisement

While the distribution of this malware appears very limited, it demonstrates how threat actors are using generative AI to not only create attacks and phishing sites, but also to modify malware behavior in real time.

Earlier this month, Google Threat Intelligence reported that state-sponsored hackers are also using Google’s Gemini AI model to support all stages of their attacks, from reconnaissance to post-compromise actions.

Modern IT infrastructure moves faster than manual workflows can handle.

In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.

Source link

Advertisement
Continue Reading

Tech

Brazil banks want 'free ride' access to iPhone NFC payments, says Apple

Published

on

Regulatory bodies around the globe are asking if Apple has a right to charge for access to the popular platforms built around iPhone. Apple keeps telling them yes — this time in Brazil.

iPhone showing Apple Wallet and a series of cards available for use
Apple charges for access to iPhone NFC for payments

The Administrative Council for Economic Defense (CADE) in Brazil has been pursuing Apple on antitrust claims surrounding the App Store. The result was alternative app stores and external payment methods coming to Brazil, but now Apple’s NFC rules are under fire.
According to a report from O Globo, first shared by 9to5Mac, Apple says third parties like banks and payment service providers want “free ride” access to Apple’s proprietary technologies. In this case, Apple is referring to the NFC payment platform offered by iPhone.
Continue Reading on AppleInsider | Discuss on our Forums

Source link

Continue Reading

Trending

Copyright © 2025