Connect with us
DAPA Banner

Tech

New tool blocks imposter attacks disguised as safe commands

Published

on

New tool blocks imposter attacks disguised as safe commands

A new open-source and cross-platform tool called Tirith can detect homoglyph attacks over command-line environments by analyzing URLs in typed commands and stopping their execution. 

Available on GitHub and also as an npm package, the tool works by hooking into the user’s shell (zsh, bash, fish, PowerShell) and inspecting every command the user pastes for execution.

URLs in commands look identical but are different
URLs in commands look identical but are different
Source: GitHub

The idea is to block deceptive attacks that rely on URLs containing symbols from different alphabets that appear identical or nearly identical to the user but are treated as different characters by the computer (homoglyph attacks).

Wiz

This lets attackers create a domain names that looks the same as that of a legitimate brand but have one or more characters from a different alphabet. On the computer screen, the domain looks legitimate for the human eye, but machines interpret the anomalous character correctly and resolve the domain to the server controlled by the attacker.

While browsers have addressed the issue, terminals continue to be susceptible as they can still render Unicode, ANSI escapes, and invisible characters, says Tirith’s author, Sheeki, in the description of the tool.  

According to Sheeki, the Tirith can detect and block the following types of attack:

Advertisement
  • Homograph attacks (Unicode lookalike characters in domains, punycode, and mixed scripts)
  • Terminal injection (ANSI escapes, bidi overrides, zero-width chars)
  • Pipe-to-shell patterns (curl | bash, wget | sh, eval $(…))
  • Dotfile hijacking (~/.bashrc, ~/.ssh/authorized_keys, etc.)
  • Insecure transport (HTTP to shell, TLS disabled)
  • Supply-chain risks (typosquatted git repos, untrusted Docker registries)
  • Credential exposure (userinfo URLs, shorteners hiding destinations)

Unicode homoglyph characters have been used in the past in URLs delivered over email that led to a malicious website. One example is a phishing campaign last year impersonating Booking.com.

 and hidden characters in commands are very common in ClickFix attacks used by a broad range of cybercriminals, so Tirith could provide some level of defense against them on supported PowerShell sessions.

It should be noted that Tirith does not hook onto Windows Command Prompt (cmd.exe), which is used in many ClickFix attacks that instruct users to execute malicious commands.

Sheeki says the overhead of using Tirith is sub-millisecond level, so the checks are performed instantaneously, and the tool terminates immediately when done.

The tool can also analyze commands without running them, break down a URL’s trust signals, perform byte-level Unicode inspection, and audit receipts with SHA-256 for executed scripts.

Advertisement

Tweet

The creator assures that Tirith performs all analysis actions locally, without making any network calls, does not modify the user’s pasted commands, and does not run in the background. Also, it does not require cloud access or network, accounts, or API keys, and does not send any telemetry data to the creator.

Tirith works on Windows, Linux, and macOS, and can be installed through Homebrew, apt/dnf, npm, Cargo, Nix, Scoop, Chocolatey, and Docker.

BleepingComputer has not tested Tirith against the listed attack scenarios, but the project has 46 forks and almost 1,600 stars on GitHub, less than a week from being published.

Modern IT infrastructure moves faster than manual workflows can handle.

In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Tesla admits that remote humans can sometimes take control of its robotaxis

Published

on


The revelation comes from a March 26 response to Markey’s investigation into how autonomous vehicle companies use remote assistance operators.
Read Entire Article
Source link

Continue Reading

Tech

Bang & Olufsen Unveils Beolab 90 Zenith and Monarch Editions: Ultra-Luxury Anniversary Speakers Push Design and Price Into the Stratosphere

Published

on

To close out its 100th anniversary in appropriately over-the-top fashion, Bang & Olufsen has introduced the final two models in its five-part Beolab 90 Special Edition series: the Zenith and Monarch. They join the previously released Phantom, Mirage, and Titan variants, all built around the company’s flagship Beolab 90 loudspeaker, which remains in regular production. These aren’t incremental updates or lightly tweaked finishes.

They are ultra-limited, design-forward statements aimed at buyers who treat six-figure audio purchases the way most people treat a weekend Costco run. If you’re weighing one of these against a Bentley SUV and Porsche 911 Turbo on a random Monday and still have enough left over to feed an entire girls soccer team Chick-fil- A and imported herring, Bang & Olufsen knows exactly who you are and would like to have a word.  

Peter Bang and Svend Olufsen Founders
Peter Bang and Svend Olufsen, Founders

Founded in 1925 by Peter Bang and Svend Olufsen, the company didn’t just shape the look of modern audio gear—it built its reputation on turning serious engineering into functional art. A century later, Bang & Olufsen is marking the milestone the only way it knows how: by leaning harder into statement products that remind everyone why the brand still commands attention 100 years on.

The Original Beolab 90 

Bang & Olufsen Beolab 90
Bang & Olufsen Beolab 90 (original)

The original Beolab 90 landed in 2015 as Bang & Olufsen’s 90th anniversary statement, and it wasn’t subtle. It hit like a controlled detonation. I was there for the debut, and the reaction hasn’t changed since: this thing is a brute, but a smart one. The engineering is serious, the power is borderline absurd, and the design doesn’t ask for your attention—it takes it. You don’t forget hearing a Beolab 90. Not the first time, not the tenth.

Each speaker packs 8,200 watts of built-in amplification driving 18 Scan-Speak drivers, powered by 14 ICEpower amps and four additional Class D units. It’s a ridiculous amount of hardware, housed inside an angular, multi-faceted enclosure that sits on a curved wooden base. The whole thing looks less like a loudspeaker and more like something pulled from a modern architecture exhibit.

Advertisement

And it’s not just brute force. The Beolab 90 backs it up with real flexibility: extensive wired and wireless connectivity, including WiSA, plus a deep toolkit of calibration and room optimization technologies to shape how it performs in your space. This isn’t a flagship that leans on looks alone. It earns it.

Active Room Compensation: Adjusts for room acoustics, furniture placement, and speaker positioning to deliver a more precise soundstage with clearer spatial cues.

Beam Width Control: Lets you dial in how focused or wide the sound dispersion is, shifting from a tight sweet spot to broader room coverage for more relaxed listening.

Beam Direction Control: Enables selection of one of five acoustic “front” positions, allowing the system to redirect the primary listening focus based on your room layout.

Advertisement

Active Bass Linearization (ABL): Dynamically manages bass output relative to volume and available power, enhancing low-end presence at lower levels while protecting the drivers from overload.

Now that the fundamentals of the Beolab 90 are clear, Bang & Olufsen is marking both its 100th anniversary and the speaker’s 10-year milestone with five limited releases: the Beolab 90 Titan Edition, Phantom (Shadow), Mirage, and the new Monarch and Zenith editions, all developed through B&O’s Atelier program.

Advertisement. Scroll to continue reading.

Beolab 90 Monarch Edition

beolab-90-monarch

The Beolab 90 Monarch Edition leans into textural sophistication and Danish furniture design heritage, but compared to its sibling, this is the “restrained” one—if anything in this price range can be called that. It’s still sculptural, still a little intimidating, but at least it doesn’t look like it’s about to wake up in the middle of the night and make a decision about your family or dog.

Wood in Motion: Angled and curved rosewood lamellas follow the contours of the aluminium cabinet, creating a 360-degree visual rhythm that nods to classic fabric covers while adding real texture and tactility.

Advertisement

Dynamic Knots: Six wooden knots connect the lamellas, with the front knot incorporating a subtle light-through-wood stripe that adds depth without screaming for attention.

Architectural Flow: A rosewood top ring frames the speaker, while the lower base panels continue the lamella pattern, tying the entire structure together in a cohesive, sculptural form.

Material Dialogue: The interplay between rosewood and ochre-coloured aluminium feels deliberate and balanced, blending natural warmth with precision engineering.

Textured Acoustics: Semi-transparent fabric sections reveal glimpses of the drivers beneath, reinforcing that this is still a serious piece of audio equipment—just dressed like high-end furniture instead of a sci-fi prop.

Advertisement

Beolab 90 Zenith Edition

beolab-90-zenith

The Beolab 90 Zenith Edition takes a very different path with less restraint, and more spectacle. It’s a study in textural precision and sculptural excess, the kind of design that makes you stop and wonder if it’s genius, madness, or both. We’re honestly torn. Is this Rick James with metal cornrows, or something a high priest would wear in Dune? Either way, subtlety didn’t get an invite.

Pearl Architecture: Six panels feature 289 anodized aluminium spheres each, arranged in seven pearl-inspired finishes that shimmer and shift with the light. It’s mesmerizing—and just a little confrontational.

Facemask Precision: The machined aluminium facemask is pearl blasted and anodized in dark grey, giving it an oyster shell vibe that feels both organic and slightly armored.

Top Lid Inlay: A circular mother-of-pearl inlay crowns the speaker, matching the sphere dimensions and adding a luminous focal point that draws your eye whether you want it to or not.

Sculptural Flow: Curved panels follow the cabinet’s contours, integrating the layered textures into the overall architectural form without completely taming the visual chaos.

Advertisement

Material Harmony: Polished aluminium elements and semi-transparent fabric attempt to balance the design, blending acoustic function with a tactile, almost ceremonial aesthetic that you’re either going to admire—or quietly question.

Advertisement. Scroll to continue reading.

Specifications

Pro Tip: As of now, all Beolab 90 variants; including the Monarch, Zenith, Titan, Phantom (Shadow), and Mirage Editions, share the same internal architecture and specifications. If Bang & Olufsen indicates otherwise, we’ll update the chart accordingly.

beolab-90-anniversary-edition-loudspeakers
Bang & Olufsen Model Beolab 90
Product Type Wireless Powered Speaker
Price (pair) From $211,800 (base model) Special Editions priced higher – refer to Availability and Price section
Designer Noto GmbH
Construction Materials Aluminium Fabric Wood
Recommended Room Size 30-200 m²
300-2000 ft²
Driver Configuration (per speaker) 7 x 1″ Scan-Speak Illuminator tweeter
7 x 4 ½” Scan-Speak Illuminator mid-range
3 x 10″ Scan-Speak Discovery woofer
1 x 13″ Scan-Speak Revelator front woofer
Amplification (per speaker) 7 x Bang & Olufsen ICEpower AM300-X for tweeter
7 x Bang & Olufsen ICEpower AM300-X for mid-range
3 x Heliox AM1000-1 for woofer
1 x Heliox AM1000-1 for front woofer
Frequency Range <12 – >43,000 Hz
Maximum Sound Pressure Level (SPL) @1m 126 dB SPL
Bass Capability (per pair) 118 dB SPL
Advanced Sound Features Adaptive Bass Linearization
Advanced Active Room Compensation
Beam Direction Control (5 sides)
Beam Width Control
Thermal Protection Yes
Wireless Connections Wireless Power Link (24-bit/48kHz)
WiSA (24-bit/96kHz)
Physical Connections (Primary Speaker) 1 x RCA (L/R)
1 x MIC / IR
1 x Power Link (RJ45)
1 x S/P DIF (24 bit / 192 kHz) 
1 x XLR (L/R) (fully balanced)
1 x Optical (24 bit / 96 kHz) 
1 x USB-B (Audio) (24 bit / 192 kHz)
1 x USB-A
2 x Digital Power Link
1 x Digital Power Link / Ethernet
1 x Power
Physical Connections (Secondary Speaker) 1 x USB-B (Audio)
1 x USB-A
3 x Digital Power Link
1 x Power
Dimensions per speaker
(WxHxD)
73.5  x 125.3 x 74.7 cm
(28.94 x 49.33 x 29.41 inches)
Weight (per speaker) 137 kg / 302 lbs

The Bottom Line

Bang & Olufsen is not chasing volume here. The Monarch and Zenith editions exist to reinforce a point. The Beolab 90 remains one of the most technically ambitious loudspeakers ever built, and B&O can still wrap that engineering in designs that feel closer to gallery pieces than traditional hi-fi.

What is unique? The performance has not changed, and that is intentional. You still get the full Beolab 90 platform with 8,200 watts of amplification, beamforming, room compensation, and one of the most adaptable active speaker systems available. The premium is in the materials, finish, and exclusivity.

Advertisement

What is great is that B&O left the core alone. The Beolab 90 remains a reference level system that can adapt to real rooms in ways most speakers at this level cannot. What is not so great is the price and the design risk. These sit in the middle of the six figure range, and the Zenith in particular will divide opinion and raise some questions from your therapist.

Who are these for? Not anyone chasing value. These are for buyers who want top tier performance and a visual statement that makes everything else in the room feel ordinary. In the context of ultra high-end Danish audio, that price almost feels reasonable when you look at what Børresen is asking for its top models.

beolab-90-zenith-monarch-loudspeakers
Beolab 90 Zenith Edition (left) | Monarch Edition (right)

Pricing & Availability

Following the debut of the Phantom (Shadow) and Mirage Editions at Bang & Olufsen’s San Francisco Culture Store in December 2025, the Beolab 90 Monarch and Zenith Editions are set to make their first public appearance at the same location before heading out on a global tour. Prospective buyers will have a chance to see them up close and hear them in a more controlled setting than the usual trade show chaos. Only 10 pairs of each edition will be produced, which tells you everything you need to know about who these are really for.

Each pair includes a certificate of authenticity, and buyers will also receive a miniature aluminum Beolab 90 sculpture in the matching finish, packaged in a custom aluminum case. It’s equal parts accessory and reminder that you didn’t just buy speakers, you bought into the mythology.

Advertisement

U.S. pricing has not been officially confirmed, but estimates put both the Monarch and Zenith at around $520,000 per pair. In the UK, pricing is reported at £410,000, with EU pricing at €480,000 per pair. For context, the original Beolab 90 launched in 2015 at roughly $78,000, climbed to $135,000 in 2023, and now sits at $211,800 per pair in 2025. Inflation is one thing. This is something else entirely.

The Monarch and Zenith can be ordered from bang-olufsen.com.

Source link

Advertisement
Continue Reading

Tech

KitchenAid just added 3 smart new features to its iconic stand mixer

Published

on

KitchenAid is giving its classic stand mixer a thoughtful refresh, as the new Artisan Plus adds three practical upgrades aimed at making everyday baking a little smoother.

At the top of the list is a built-in LED bowl light, which automatically switches on when the tilt-head is lowered. It’s a small but useful addition, as it allows you to keep an eye on texture or consistency without stopping mid-mix.

In addition, KitchenAid has introduced precision speed control and a soft-start function. The latter gradually ramps up mixing speed to avoid the all-too-familiar flour explosion. At the same time, the refined controls give you a bit more accuracy when working with delicate ingredients.

Those changes build on what’s already a well-established formula. The Artisan Plus keeps the familiar tilt-head design but adds a double-flex edge beater that scrapes the bowl as it mixes. It also comes with a secure-fit pouring shield and stainless steel accessories, although existing attachments still work here too. As a result, long-time KitchenAid users won’t need to start from scratch.

Advertisement
KitchenAid Artisan PlusKitchenAid Artisan Plus

Advertisement

There’s also a bit more flexibility in how you use it day to day. The mixer offers 11 speeds, including a new half-fold setting designed for gently combining lighter mixtures, preventing you from knocking the air out of them.

Design-wise, KitchenAid hasn’t strayed far from what made the mixer iconic in the first place. You’ll still get that classic silhouette, now paired with 15 colour options including exclusive finishes like a fetching Sun Dried Tomato, Wild Blueberry and Feather Pink.

It’s a relatively modest update on paper, but that’s arguably the point. Rather than reinventing the mixer, KitchenAid is refining it, adding small, genuinely useful features while keeping the core experience intact.

The Artisan Plus Stand Mixer is available now for $600. This positions it as the brand’s most premium take on a design that’s already stood the test of time.

Advertisement

Source link

Continue Reading

Tech

Gmail finally lets you change your cringey old usernames

Published

on


Google is finally doing the thing Gmail users have been begging for years, which is letting them change the actual username in their Gmail address. This is no longer just an early rollout, as Google says the feature is now available for all Google Account users in the US. So it’s still a limited release, […]

Source link

Continue Reading

Tech

Volvo’s parent just revealed a $15,000 extended-range EV, and it shows how wide the US value gap has become

Published

on

Geely, the Chinese automotive giant that owns Volvo, has just unveiled the Boyue EREV in China with a limited-time price of 107,900 Yuan, or roughly about $14,900. This price is worth noting, considering it’s not a stripped-down city car, but an extended-range SUV. It further highlights the value gulf between China and the US looks even wider.

This isn’t some tiny -range compromise either. Geely says the Boyue EREV offers up to 375 km of CLTC electric range and as much as 1,525 km of combined range, depending on the variant. It uses a 1.5 liter range extender, a 160kW electric motor, and either a 28.3 kWh or 50.4 kWh LFP battery pack. The larger battery also supports 3C fast charging, which claims to hit 80% charge from 30% in just about 15 minutes.

What else does it offer?

The Boyue EREV also doesn’t cut corners for the price, offering a 14.6-inch central display, an 8.8-inch instrument cluster, Flyme Auto, and support for both Carlink and Huawei HiCar. Keeping up with other high-tech Chinese EVs, you also get 50W wireless charging, an optional 16-speaker audio, an optional HUD, and L2-level driver assistance. It is also a real family SUV too, measuring 4,680mm long with a 2,778mm wheelbase.

Why this is such a big deal

The bigger story here is not just Geely’s new SUV. It is what this kind of product says about the market split. Reuters reported earlier this week on Geely’s broader importance to Volvo as the Swedish brand navigates a tough car market. It also underlines just how central the Chinese parent has become. And despite US buyers wanting to buy Chinese EVs, they remain largely shut out of this kind of value.

Source link

Advertisement
Continue Reading

Tech

European Union wants to ban AI-created images and video in official messaging

Published

on


  • EU reckons it could assert trust and authenticity by removing AI-generated content
  • The bloc is also drafting a code of practice to protect citizens
  • Blocking AI altogether might not be the best move, though

The European Union is reportedly considering a ban on AI-generated images and videos – otherwise known as deepfakes – in official communications.

According to new Politico reporting, with ongoing geopolitical tensions rising, elections running their courses and further public announcements, it’s believed the focus would be to protect trust in government messaging.

Advertisement

Source link

Continue Reading

Tech

Samsung Galaxy Book6 Pro review: a super thin slab with a glorious display

Published

on

Why you can trust TechRadar


We spend hours testing every product or service we review, so you can be sure you’re buying the best. Find out more about how we test.

Samsung Galaxy Book6 Pro: Two-minute review

The Samsung Galaxy Book6 Pro is a laptop in the ultrabook class, featuring a sublime design that keeps bulk to a minimum.

Advertisement

Source link

Advertisement
Continue Reading

Tech

Google fixes fourth Chrome zero-day exploited in attacks in 2026

Published

on

Google Chrome

Google released emergency updates to fix another Chrome zero-day vulnerability exploited in attacks, marking the fourth such security flaw patched since the start of the year.

“Google is aware that an exploit for CVE-2026-5281 exists in the wild,” Google said in a security advisory issued on Tuesday.

As detailed in the Chromium commit history, this vulnerability stems from a use-after-free weakness in Dawn, the underlying cross-platform implementation of the WebGPU standard used by the Chromium project.

Attackers can exploit this Dawn security flaw to trigger web browser crashes, data corruption, rendering issues, or other abnormal behavior.

Advertisement

While Google has found evidence that threat actors were exploiting this zero-day flaw in the wild, it did not share details about these incidents.

“Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed,” the company noted.

Google Chrome 146.0.7680.178

​Google has now fixed the zero-day for users in the Stable Desktop channel, with new versions rolling out to Windows, macOS (146.0.7680.177/178), and Linux users (146.0.7680.177). While Google says that this out-of-band update could take days or weeks to reach all users, it was immediately available when BleepingComputer checked for updates today.

If you don’t want to update the browser manually, you can also have it check for updates at the next launch and install them automatically.

Advertisement

This is the fourth actively exploited Chrome zero-day patched since the start of the year. The first (CVE-2026-2441) was an iterator invalidation bug in CSSFontFeatureValuesMap (Chrome’s implementation of CSS font feature values), which Google addressed in mid-February.

Google patched two other Chrome zero-day bugs exploited in attacks earlier this month: the first is an out-of-bounds write weakness in the Skia 2D graphics library (CVE-2026-3909), and the second is an inappropriate implementation vulnerability in the V8 JavaScript and WebAssembly engine (CVE-2026-3910).

In 2025, Google fixed a total of eight zero-days exploited in the wild, many of which were discovered and reported by Google’s Threat Analysis Group (TAG), which is known for tracking and identifying zero-day exploits used in spyware attacks.

Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.

This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.

Advertisement

Source link

Continue Reading

Tech

Startup Pitches ‘Brainless Clones’ To Serve the Role of Backup Human Bodies

Published

on

MIT Technology Review discovered that startup R3 Bio has pitched an ethically and scientifically explosive long-term vision beyond its public work on non-sentient monkey “organ sacks”: creating human “brainless clones” or replacement bodies for organs as part of an extreme life-extension agenda. From the report: Imagine it like this: a baby version of yourself with only enough of a brain structure to be alive in case you ever need a new kidney or liver. Or, alternatively, he has speculated, you might one day get your brain placed into a younger clone. That could be a way to gain a second lifespan through a still hypothetical procedure known as a body transplant.

The fuller context of R3’s proposals, as well as activities of another stealth startup with related goals, have not previously been reported. They’ve been kept secret by a circle of extreme life-extension proponents who fear that their plans for immortality could be derailed by clickbait headlines and public backlash. And that’s because the idea can sound like something straight from a creepy science fiction film. One person who heard R3’s clone presentation, and spoke on the condition of anonymity, was left reeling by its implications and shaken by [R3 founder John Schloendorn’s] enthusiastic delivery. The briefing, this person said, was like a “close encounter of the third kind” with “Dr. Strangelove.” […]

MIT Technology Review found no evidence that R3 has cloned anyone, or even any animal bigger than a rodent. What we did find were documents, additional meeting agendas, and other sources outlining a technical road map for what R3 called “body replacement cloning” in a 2023 letter to supporters. That road map involved improvements to the cloning process and genetic wiring diagrams for how to create animals without complete brains. A main purpose of the fundraising, investors say, was to support efforts to try these techniques in monkeys from a base in the Caribbean. That offered a path to a nearer-term business plan for more ethical medical experiments and toxicology testing — if the company could develop what it now calls monkey “organ sacks.” However, this work would clearly inform any possible human version.

Source link

Advertisement
Continue Reading

Tech

If TikTok doomscrolling wasn’t bad enough, it now serves an emoji game in DMs

Published

on

As if endless scrolling wasn’t bad enough already, TikTok has now quietly added a hidden emoji game inside DMs. The mini-game is live right now and works in both one-on-one messages and group chats. It means the app now has one more little trick to keep users hanging around even when they are technically done watching videos.

And honestly, it is exactly the kind of feature you would expect from a platform that has mastered years of mastering the art of making “just five more minutes” turn into an hour.

What’s the game, and why you should be wary

The game kicks off when you send a single emoji in a chat. If you tap on this emoji, your chosen emoji becomes part of the game itself, floating across the screen to give you a speed boost as you try to bounce upward across a stack of alligators.

The goal is to climb as high as possible while avoiding skeleton alligators, with some of these disappearing after one landing. So it’s all about quick reactions and enough chaos to make you give it another try. TikTok also shows both your score and your opponent’s high score in the top-right corner. So this basically turns it into a lightweight little competition instead of just a throwaway gimmick.

It is very on-brand

TikTok told TechCrunch that it launched the Easter egg to make messaging more fun and add a playful competitive element to DMs. This isn’t the first time we’re seeing something like this. Instagram added its own hidden emoji DM game two years ago, and Meta has also been experimenting with games inside Threads chats.

On paper, this is just a harmless little DM mini-game. But in practice, it is one more engagement hook dropped into a platform that was already very good at monopolizing attention.

Advertisement

Source link

Continue Reading

Trending

Copyright © 2025