Last night, the increasingly enterprise-focused AI startup Sakana launched Fugu, a multi-agent orchestration system that delivers frontier-level AI performance through a single, OpenAI-compatible API.
Designed for developers, enterprises, and nations seeking resilience against vendor lock-in and geopolitical export controls, Fugu (Japanese for “pufferfish”), bypasses the traditional monolithic model structure by dynamically routing queries to a swappable pool of specialized AI agents.
Sakana CEO and co-founder David Ha, formerly of Google Brain, positioned Fugu as a more reliable option for enterprise workflows than any single AI model provider in the wake of Anthropic’s move on June 12 to revoke public access to its most powerful models, Claude Mythos 5 and Claude Fable 5, in the wake of a U.S. government export control order. As Ha wrote in a post today on X:
“Fugu dynamically orchestrates the world’s best models to tackle complex tasks. We are proving that a well-orchestrated pool of swappable agents can match restricted frontier models like Fable and Mythos.
But Fugu is about more than just performance. I believe that Orchestration Models are the next frontier, beyond bigger models.
Advertisement
Relying on a single company’s model for national infrastructure is a massive risk. As recent export controls have shown, access to top models can disappear overnight.
Collective intelligence is the practical hedge against this concentration of power. Fugu simply routes around vendor restrictions by relying on an entirely swappable agent pool.”
Sakana AI explicitly states that the specific models Fugu selects and how it coordinates them are proprietary, meaning this routing information is hidden from the user by design. The documentation only refers generally to a “diverse pool of powerful models,” “multiple LLMs,” or “specialized models” without providing a specific count.
By acting as a sophisticated coordinator rather than a standalone foundation model, Fugu matches the output quality of top-tier models like Fable and Mythos on third-party benchmarks of agentic tasks, while fundamentally altering how developers deploy critical AI infrastructure.
Advertisement
How Sakana Fugu works and where it beats Anthropic’s Claude Fable 5
At its core, Sakana Fugu operates like a master general contractor. When presented with a complex request, Fugu does not attempt to execute every step itself.
Instead, it breaks the problem down, delegates sub-tasks to a pool of expert foundation models, verifies their work, and synthesizes the final output.
Sakana Fugu functional diagram. Credit: Sakana AI
“Fugu is itself an LLM, trained to call various LLMs in an agent pool, including instances of itself recursively,” the Sakana AI team noted in their technical release.
Advertisement
Grounded in two of Sakana’s 2026 research papers, TRINITY and the Conductor, the system autonomously manages the entire lifecycle of model selection and verification using learned coordination strategies rather than hand-designed workflows. To the end user, this multi-agent swarm is entirely abstracted behind a standard API endpoint.
Sakana AI is offering two variants of the system to cater to different operational workloads:
Fugu: A high-speed, low-latency model optimized for everyday tasks. It is designed to act as the default engine for interactive chatbots and integrates directly into coding environments like Codex.
Fugu Ultra: The flagship tier engineered for complex, high-stakes tasks such as AI research, cybersecurity analysis, and multi-step patent investigations. According to Sakana, Fugu Ultra coordinates a deeper pool of experts and matches industry-leading monolithic models across rigorous scientific and reasoning benchmarks.
Additionally, on the pay-as-you-go plan, standard Fugu charges a dynamic rate based on the specific underlying models activated, whereas Fugu Ultra utilizes a fixed pricing structure starting at $5 per million input tokens and $30 per million output tokens.
As indicated by benchmark charts shared by Sakana, Fugu actually exceeds the performance of Anthropic’s Claude Fable 5 on LiveCodeBench, an open source benchmark testing coding performance on regularly refreshed, software problem-solving tasks (Fugu Ultra: 93.2, Fugu: 92.9, Fable: 89.8), and beats the prior Claude Mythos Preview model on GPQA-D (Diamond) , a test of 198 graduate-level multiple-choice questions in biology, physics, and chemistry (Fugu Ultra: 95.5, Fugu: 95.5, Mythos Preview: 94.6).
Advertisement
Sakana Fugu performance benchmark comparison chart vs. other leading frontier models. Credit: Sakana AI
By orchestrating multiple models from different providers, Fugu essentially builds native redundancy into the AI stack. If one provider suffers an outage or faces sudden regulatory restrictions, Fugu routes around the disruption to maintain uptime.
Licensing and availability
Fugu is offered as a commercial, proprietary API service, not an open-source framework.
Because Sakana’s core intellectual property lies in its non-obvious collaboration patterns, the specific routing information—meaning exactly which underlying models Fugu selects for a given query—remains proprietary and is intentionally hidden from the user.
Advertisement
However, Sakana offers critical controls for enterprise data compliance. Developers can explicitly opt specific models or providers out of their Fugu routing pool to maintain strict corporate privacy standards.
Additionally, users can opt out of having their prompts used for future training data. Geographically, Fugu is restricted from operating within the European Union (EU) and European Economic Area (EEA) while Sakana works to align its black-box data routing architecture with GDPR regulations.
Pricing is fairly steep
Fugu is available immediately in most regions—with the temporary exception of the EU and EEA—at subscription tiers and pay-as-you-go pricing.
Teams can opt for monthly subscription allowances designed for individual or hands-on use: a Standard tier at $20/month for lightweight workflows, a Pro tier at $100/month providing 10x standard usage, and a Max tier at $200/month offering 20x usage for continuous, long-running tasks. I wasn’t able to find the actual amount of tokens covered under these plans, but I’ve reached out to Ha on X for more information.
Advertisement
As part of the initial rollout, Sakana is offering a free second month for users who subscribe to any tier by July 31, 2026.
For enterprise scaling and production deployments, Sakana offers an elastic pay-as-you-go plan. Crucially for high-stakes environments, requests made under this consumption-based model are served at a higher priority than those from monthly subscription plans.
Under this framework, the standard Fugu engine charges the single rate of the highest-tier underlying model involved in a query, without ever stacking multi-agent fees. The flagship Fugu Ultra tier (fugu-ultra-20260615) utilizes a fixed pricing structure per one million tokens: $5 for input, $30 for output, and $0.50 for cached input. These rates increase to $10, $45, and $1.00 respectively for extreme workloads utilizing context windows above 272K tokens. That puts it among the more expensive options compared to single AI models via provider APIs:
Model
Advertisement
Input
Output
Total Cost
Source
Advertisement
MiMo-V2.5 Flash
$0.10
$0.30
$0.40
Advertisement
Xiaomi MiMo
deepseek-v4-flash
$0.14
$0.28
Advertisement
$0.42
DeepSeek
deepseek-v4-pro
$0.435
Advertisement
$0.87
$1.305
DeepSeek
MiniMax-M3
Advertisement
$0.30
$1.20
$1.50
MiniMax
Advertisement
Gemini 3.1 Flash-Lite
$0.25
$1.50
$1.75
Advertisement
Google
Qwen3.7-Plus
$0.40
$1.60
Advertisement
$2.00
Alibaba Cloud
MiMo-V2.5
$0.40
Advertisement
$2.00
$2.40
Xiaomi MiMo
Grok 4.3 (low context)
Advertisement
$1.25
$2.50
$3.75
xAI
Advertisement
MiMo-V2.5 Pro (≤256K)
$1.00
$3.00
$4.00
Advertisement
Xiaomi MiMo
Kimi-K2.6
$0.95
$4.00
Advertisement
$4.95
Moonshot
GLM-5.2
$1.40
Advertisement
$4.40
$5.80
Z.ai
Grok 4.3 (high context)
Advertisement
$2.50
$5.00
$7.50
xAI
Advertisement
MiMo-V2.5 Pro (>256K)
$2.00
$6.00
$8.00
Advertisement
Xiaomi MiMo
Qwen3.7-Max
$2.50
$7.50
Advertisement
$10.00
Alibaba Cloud
Gemini 3.5 Flash
$1.50
Advertisement
$9.00
$10.50
Google
Gemini 3.1 Pro Preview (≤200K)
Advertisement
$2.00
$12.00
$14.00
Google
Advertisement
GPT-5.4
$2.50
$15.00
$17.50
Advertisement
OpenAI
Gemini 3.1 Pro Preview (>200K)
$4.00
$18.00
Advertisement
$22.00
Google
Claude Opus 4.8
$5.00
Advertisement
$25.00
$30.00
Anthropic
GPT-5.5
Advertisement
$5.00
$30.00
$35.00
OpenAI
Advertisement
Sakana Fugu Ultra
$5.00
$30.00
$35.00
Advertisement
Sakana AI
Claude Fable 5 / Claude Mythos 5
$10.00
$50.00
Advertisement
$60.00
Anthropic
Developers modeling operational costs should also note a significant architectural caveat in how Fugu bills for its multi-agent capabilities. According to the developer documentation, Fugu Ultra’s API responses include detailed usage fields that separate user-visible token generation from internal orchestration work. The background tokens consumed and generated when Fugu delegates sub-tasks, verifies code, or routes between underlying agents are not absorbed by the provider; they represent real token usage and are counted toward the final price of the request at standard rates.
The Orchestration landscape: Fugu vs. The Field and notable benchmark performance
To understand Fugu’s position in the mid-2026 AI ecosystem, it is critical to distinguish between model routing and multi-agent orchestration.
Advertisement
Over the past year, enterprise adoption of standard routing platforms—such as Not Diamond, Martian, and the open-source RouteLLM framework—has skyrocketed. These systems act as intelligent air traffic controllers; using semantic classifiers or meta-models, they analyze an incoming prompt and predict which single foundation model will yield the highest quality or most cost-effective response, dispatching the query accordingly.
Fugu operates on a fundamentally different paradigm. Rather than making a one-shot routing decision, Fugu aligns more closely with complex multi-round systems like Router-R1 (a framework introduced at NeurIPS 2025). It breaks a query down, interleaves reasoning with delegation, and dynamically assigns sub-tasks to multiple models in parallel or sequence before synthesizing a final output.
While frameworks like LangGraph, CrewAI, and Microsoft AutoGen offer developers the tools to build similar multi-agent systems, they require immense manual configuration—defining roles, setting up conditional edges, and managing state across long-running loops.
Fugu abstracts this operational overhead entirely. It is essentially a LangGraph-style workflow packaged as a single, black-box API endpoint.
Advertisement
An orchestration system is ultimately bounded by the raw capabilities of the underlying models in its pool, a reality reflected in Sakana’s own benchmark testing against standalone frontier models.
On rigorous coding and agentic tasks, collective intelligence shows a distinct advantage over standard models. Fugu Ultra posted a 73.7 on SWE-Bench Pro, significantly outperforming Anthropic’s Claude Opus 4.8 (69.2) and OpenAI’s GPT-5.5 (58.6).
However, Fugu is not a silver bullet, and its performance is not a clean sweep across the board. When compared to highly specialized or restricted-access monolithic models, Fugu occasionally trails:
SWE-Bench Pro: While Fugu Ultra (73.7) beat most accessible models, it was comfortably eclipsed by Anthropic’s limited-access Fable 5 (80.0), which is currently absent from Fugu’s swappable pool due to the U.S. government’s export control order and Anthropic’s subsequent response to remove the model entirely from global usage.
Humanity’s Last Exam: Fugu Ultra (50.0) narrowly edged out Opus 4.8 (49.8), but again fell short of Fable 5 (53.3).
Long-Context and Security: On the MRCRv2 long-context-recall test, OpenAI’s GPT-5.5 maintained the lead (94.8 vs Fugu Ultra’s 93.6), and Opus 4.8 remained the top performer on the CTI-REALM cybersecurity benchmark (69.6 vs Fugu Ultra’s 69.4).
The quantitative data points to a clear conclusion: Fugu is highly effective at boosting performance on messy, multi-step tasks (like writing a complex HTML5 game from scratch) by leaning on the combined strengths of multiple mid-tier and high-tier models.
Advertisement
However, for sheer brute-force reasoning within a single, highly constrained domain, the industry’s largest standalone models still hold the edge—provided an enterprise can maintain uninterrupted access to them.
Background on Sakana’s formation and noteworthy achievements to date
Sakana AI was formed in Tokyo in 2023 by Llion Jones, a co-author of Google’s foundational 2017 “Attention Is All You Need” paper, and David Ha, the former head of research at Stability AI.
Disillusioned by large tech company bureaucracy and the industry’s hyper-fixation on scaling single, massive foundational models, the founders built Sakana around principles of biomimicry and evolutionary computing.
The company’s name, derived from the Japanese word for fish, reflects its core technical thesis: utilizing collective “swarm” intelligence rather than brute-force compute. Following a $2.6 billion Series B valuation in late 2025 and the recent June 2026 launch of Marlin—an autonomous, eight-hour research agent for the B2B sector—Fugu represents the commercialization of Sakana’s multi-agent routing technology for everyday developers.
Advertisement
A mixed reception among the broader AI community online
The developer community has responded to Fugu by rigorously testing its practical tradeoffs, weighing its routing efficiencies against the sheer power of monolithic foundation models.
AI observer, developer and influencer Chris (@ChrissGPT on X) highlighted the specific utility of Fugu over raw foundational AI.
“For a single clean prompt, you probably would [use Fable 5, Mythos, or GPT-5.5 directly],” he noted, but argued that Fugu’s true value emerges in messy, multi-step environments. “…whether it involves delegation, verification, synthesis, code review, research loops, security analysis… the more it would make sense to use this,” he wrote.
Chris also pointed out the strategic geopolitical advantage of Fugu’s architecture, noting that if frontier AI access is abruptly revoked due to regulation or export controls, an orchestrator can dynamically swap models to prevent a total system failure.
Advertisement
Creative agency owner Mark Santos (@markksantos) of Mark Studios provided a direct, real-world comparison by tasking both Fugu Ultra and Claude Opus 4.8 with building a “Crossy Road” game clone using Three.js. The results underscored the operational differences between an orchestrator and a monolithic giant:
Sakana Fugu Ultra: Completed the task in 22 minutes using ~89,000 tokens for roughly $7.32. However, the final game suffered from minor logic errors, such as inverted directional turns and wonky camera angles.
Claude Opus 4.8: Took 79 minutes, burned ~940,000 tokens for nearly $37.85, and got stuck in a retry loop requiring human intervention. Despite the inefficiency, it ultimately produced superior application design and functionality.
Santos concluded the experiment by stating, “In terms of application functionality, quality, and design, Opus won. In terms of model speed and performance, Fugu… won”.
Elie Bakouch, a research engineer at cloud-based, open AI infrastructure and systems provider Prime Intellect, pointed out on X that “to be clear, this is a closed source orchestrator on top of closed source models. if before you didn’t control the models, now you don’t even control which ones are used or how much. this is not ‘AI sovereignty’…”
These early tests and reactions mirror the sentiment summarized by Reddit user GreedyWorking1499 in initial platform discussions: “Until proven otherwise, this is just a highly advanced router/wrapper, not a fundamental not a fundamental leap in intelligence like Mythos/Fable was.“
Advertisement
Yet, as enterprises increasingly demand fail-safes against single-vendor reliance, Sakana is proving that packaging collective intelligence into a single API endpoint is a highly viable commercial path.
Ultrahuman is rolling out Emerald today, its biggest platform update in four years. If you own an Ultrahuman Ring Air, Ring Pro, or any of its other health devices, your app is about to look and feel very different.
What is UltraSphere, and why does it matter?
The big update is the UltraSphere, a decision engine Ultrahuman claims is a first for a smart ring. Instead of throwing another chart at you, it sits front and center on the home screen and hands out more than 60 Next Best Actions based on your sleep, recovery, HRV, stress, movement, and even glucose data if you use the M1 or M2 CGM.
Ultrahuman
These suggestions change depending on where you are, the weather, and your circadian rhythm, so a jet-lagged traveler and a new parent will not get the same advice. Examples Ultrahuman shared include a nudge to step outside soon after waking to reset your body clock, or a heads-up that caffeine past a certain point will mess with your sleep later.
Ultrahuman
Mohit Kumar, CEO of Ultrahuman, explained the thinking behind the shift. “All wearable trackers generate data. Data is empowering, but people need something more than a number, they want to know what to do. The Emerald Update is focused on making data actionable, adding layers of biointelligence that finally answer the question of so what with context and insight at every layer.”
What else changes with this update?
Ultrahuman is also adding an essential feature for frequent flyers and anyone stuck without signal. It can now process everything on the device, so your recovery score, stress rhythm, and Next Best Actions keep working with zero connectivity.
Ultrahuman
Workout tracking also gets an upgrade, with better automatic detection and heart rate accuracy validated against gold standard devices. If you prefer an Apple Watch, Garmin, WHOOP, or even AirPods Pro Gen 3 for workouts, you can now pair that data directly into the app instead of relying on the ring alone.
VO2 Max, one of the best predictors of long-term health, also got smarter. Ultrahuman says its updated algorithm lands within 5 mL per kg per min of real lab results, tested across more than 100 athletes.
Advertisement
Ultrahuman
There is plenty more packed in too, including a new Longevity tab for markers like UltraAge and Brain Age, a Sleep Screener that bundles your nightly signals into one report, and the option to finally share cycle and ovulation data with a partner.
Should you update?
The Emerald update is rolling out globally starting today, so there is really no reason to skip it. What I like most is that none of this costs extra. It’s a free update, and it genuinely makes the whole experience feel better.
Alphabet went into its second-quarter results on Wednesday carrying one question louder than the rest: whether the tens of billions it is funnelling into AI infrastructure has started to earn its keep. Judged by the after-hours share price, the answer was not yet.
The company reported revenue of $119.8bn for the three months to June, up 24% from $96.4bn a year earlier and comfortably ahead of forecasts.
Google Cloud did the heavy lifting, with revenue climbing 82% to $24.8bn, operating income more than tripling to $8.8bn, and its margin widening to about 36%. Group operating margin edged up to 34% from 32%.
That extends a streak that had Alphabet closing in on Nvidia as the world’s most valuable company, and it slots into a Big Tech capex cycle now running past $650bn a year. Cloud backlog, the contracted work Google has yet to book, rose to $514bn from $490bn.
Advertisement
Going in, the pressure was explicit. Bloomberg framed the quarter as a test of whether the spending pays off, and Alphabet was hardly alone in facing it, with investors weighing the same question at Tesla and across the rest of the Magnificent Seven the same week.
The 💜 of EU tech
The latest rumblings from the EU tech scene, a story from our wise ol’ founder Boris, and some questionable AI art. It’s free, every week, in your inbox. Sign up now!
The spending, not the growth, is what rattled them. Alphabet lifted its full-year capital-expenditure guidance to as much as $205bn, up from a prior range of $180bn to $190bn, and said quarterly capex had roughly doubled from a year earlier to $44.9bn.
Advertisement
Even $205bn does not cover it. Alphabet said it would keep expanding rented, third-party capacity as a bridge while its own data centres come online, a measure of how quickly demand is outrunning what it can build.
The bill pushed free cash flow to negative $5.9bn, the first quarterly outflow in nearly two decades.
Shares fell about 5% in extended trading despite the revenue beat, part of a now-familiar rhythm this earnings season of clean beats undone by capex lines that land heavier than expected.
The scale is the story. Alphabet is on course to spend more on capital investment in a single year than it books in net income over a comparable stretch, funding the build largely from a search and advertising business growing far more slowly. Analysts have started asking when, exactly, that gap closes.
Advertisement
The backlog is the counterargument the bulls reach for. A book of $514bn in contracted, not-yet-recognised revenue suggests the capacity being built already has buyers waiting; the bearish read is that it is a promise Alphabet still has to fund and deliver while the meter runs.
What both sides agree on is that the answer hinges on cloud becoming self-sustaining before the capex wave crests.
The headline profit figure did not settle the argument. Net income came in at $112.1bn, close to quadruple a year earlier, but roughly $98bn of that was an unrealised paper gain on Alphabet’s stake in SpaceX. Strip it out and the underlying number looks a good deal more ordinary.
The core ad engine held. Search revenue rose 17% to $63.3bn and YouTube advertising 13% to $11.1bn, while the Gemini app reached 950 million monthly active users and Alphabet’s first-party model APIs processed some 22 billion tokens a minute.
Advertisement
Sundar Pichai said AI features in Search were driving incremental queries while still sending billions of clicks to websites each week, and that AI Mode had passed 1 billion monthly users.
To pay for the build, Alphabet has already leaned on a record $85bn equity raise and a debut yen bond. CFO Anat Ashkenazi told investors no further equity offerings were planned beyond a $40bn at-the-market programme starting this quarter.
For all the noise, the results left open the one question they were meant to answer. The AI spending is clearly producing growth.
When it begins paying for itself, and how much more Alphabet is willing to spend while it waits to find out, is still unresolved.
Samsung now sells two book-style foldables side by side. The regular Galaxy Z Fold8 starts at $1,899.99. The Z Fold8 Ultra opens at $2,099.99 for the 256GB model and climbs to $2,699.99 for 1TB. That $200 jump lands the Ultra in rare air for a phone that still has to fold in half. The question is simple: does the extra money buy enough to matter?
Unfolded, the Ultra is only 4.1 millimetres thick and weighs roughly 215 grams, making it one of the thinnest and lightest foldables Samsung has ever created for a pocket. Underneath the large display is a dual-layer titanium structure, and the hinge is also made of titanium alloy, as it’s surprisingly difficult to spot the crease nowadays. The whole thing has an IP48 rating, which should be good for being submerged in 1.5 meters of fresh water for half an hour. When folded, it’s somewhat taller and thinner than the standard Fold8, so it’s not as pocket-friendly, but it’s still a good fit.
PRE-ORDER NOW: Get an Amazon gift card when you pre-order Samsung Galaxy Z Fold8 Ultra. You will receive an email once your gift card is available…
SPLIT THE VIEW. MULTITASK¹ TO THE MAX: Productivity never felt this powerful. Use up to three apps¹ at once on the expansive inner screen of Galaxy…
MULTITASKING MADE SMARTER WITH AI: Stay one step ahead with AI² that suggests which apps you might need next. Then view those multiple windows side…
The outside and inner screens have both expanded in size, with the cover display now measuring 6.5 inches of FHD+ Dynamic AMOLED 2X goodness, and the main panel expanding to a full 8 inches of QXGA+ when the phone is opened. Peak brightness is increased to 3,000 nits, and there’s an anti-reflection coating to keep things from becoming too shiny on the larger surface. There’s also an Adaptive 120Hz refresh rate, which helps keep things smooth whether you’re using the phone one-handed or treating it like a tiny tablet. The difference between viewing a video and running things side by side is rather noticeable.
The Ultra has also received a significant camera upgrade. The main sensor is a 200-megapixel beast with an f/1.7 lens, and there’s Quad Pixel autofocus for extra sharpness. You can also achieve a nice 2x optical-quality cut that retains sharpness. But that’s not all; in addition to the primary sensor, there’s a 50-megapixel ultrawide with an enhanced f/1.9 aperture for capturing more light, as well as a separate 10-megapixel telephoto picture that finally provides genuine 3x optical zoom. To make things even more intriguing, the main and ultrawide cameras can also shoot 8K video. When you add Nightography and the ProVisual Engine to help with low-light shots, as well as Super Steady to keep your handheld videos from being too shaky, it’s evident that the Ultra is in a class by itself when it comes to camera performance. You can’t help but make comparisons to the S26 Ultra, and to be honest, the difference is now less than it has ever been on a foldable. The normal Fold8, on the other hand, only has two 50-megapixel cameras and no optical telephoto. Zoom and detail are obviously going to be more of an issue with that one.
Advertisement
Inside the Ultra, you’ll find the same dependable Snapdragon 8 Elite Gen 5 chip, which has been optimized to maximize Galaxy phone performance. You can get it with 256GB or 512GB of storage and 12GB of RAM, or if you want to go all out, 1TB of storage and 16GB of RAM. The battery has finally expanded to 5,000 mAh, making it the largest Samsung has ever put in a Fold, and it claims up to 27 hours of video playback. There’s also charging, 45W wired charging should charge your battery to two-thirds capacity in under an hour.
Software includes the whole new One UI 9, which puts a comprehensive set of Galaxy AI tools at your fingertips. The Nudge tool just observes what you’re doing and makes excellent ideas for using split screen in a way that suits you. My FanCam can lock onto a subject and reframe the video on the fly, all without you having to move a finger. With Photo Assist, you can simply type a text prompt and move, remove, or expand items; it’s that simple. Many of these capabilities are also available on the standard Fold8, but having more screen real estate on the larger version helps them feel more natural, especially when you have numerous windows open. [Source]
Guardio Labs found CVE‑2026‑48294 in Adobe Acrobat Chrome extension, enabling cross‑site data disclosure
Attackers could steal WhatsApp Web chats if victims opened malicious landing pages with extension active
Adobe patched the flaw in version 26.7.2.0; update recommended for 314M extension users
If you have Adobe Acrobat’s extension for Chrome, and you like chatting through WhatsApp Web, there is a potential security vulnerability you might want to address.
Security researchers from Guardio Labs discovered a “universal cross-site scripting (UXSS)-class cross-origin data disclosure vulnerability”, which is another way of saying that a website could use the flaw to read the contents of a different website, loaded in a separate tab.
The vulnerability was found in the Adobe Acrobat Chrome extension and is now tracked as CVE-2026-48294. It was given a severity score of 7.4/10 (high), and affects versions 26.5.2.2 and earlier. Guardio Labs dubbed it “HermeticReader” because of what it exploits.
Latest Videos From
“Insultingly ordinary” setup
The extension comes with different integrations, such as Google Drive or, in this case – WhatsApp Web. The WhatsApp integration component, internally known as “Hermes” is where the bug was found.
Advertisement
In theory, an attacker could create a new landing page and share it with the victim via email, instant messaging, SEO poisoning, or other methods. If the victim 1) has the vulnerable version of the Adobe Acrobat Chrome extension installed; 2) has WhatsApp loaded in a separate tab; and 3) opens the malicious landing page, it could trigger the extension’s vulnerable code path and allow the attackers to access everything the victim has on their WhatsApp.
Some sources argue that threat actors could use this vulnerability to pull one-time passcodes delivered via WhatsApp.
“The setup is almost insultingly ordinary: an attacker-controlled page, dressed to look like the kind of page you land on via search results, marketing emails, etc.,” Guardio Labs wrote in its analysis.
Advertisement
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
“The visitor, who already has the Adobe Acrobat extension installed, opens that page. The page wakes up a dormant engine inside the extension, reaches directly into WhatsApp Web. Seconds later, the rendered WhatsApp Web view – the chat list, contact names, messages, the profile name, the text of whatever conversation is open – the whole WhatsApp in the attacker’s hands.”
Adobe has since publicly acknowledged the issue and thanked Guardio Labs’ researchers for their help. It has also fixed the problem in version 26.7.2.0 that’s currently available for download. The extension has more than 314 million users.
Despite being a GoPro product, the Wireless Mic System isn’t limited to action cameras. The main selling point here, though, is its direct connectivity to GoPros. Since the Hero 12, you could connect a Bluetooth microphone directly. Ironically, that meant, up until now, DJI’s Mic Mini and Mic 3 were likely the best options for connecting directly to a GoPro as those both offer Bluetooth alongside a physical receiver.
Pairing the Wireless Mic System with the camera is simple: Turn on one of the microphones and tap the power button three times to switch to Bluetooth mode. Turn the mic off, then back on while keeping the power button held down to pair. The GoPro recognizes the mic and you’re all set. You can pair either microphone to the camera, but only one at a time. A single press of the mic button turns on noise reduction and a white LED confirms it’s activated.
Using either of the receivers is as simple as connecting to the camera or PC via USB or 3.5mm (depending which one you’re using) and then turning on the mic. Unless you last used it with a Bluetooth connection, in which case, three taps of the power button will put you back in receiver mode.
While it’s a major benefit to connect a mic to a GoPro without a receiver, the hardware receiver offers superior audio quality. What’s more, it means you can use both mics at the same time. The USB receiver is designed to fit neatly into a GoPro’s recessed USB port. You don’t need to fully remove the protective door from the camera, but you can if you want things to look a little neater. If you plan on using the kit with a phone, the dongle slightly extends from the base of your handset, but it’s snug and practical, and feels secure.
Advertisement
James Trew for Engadget
I noticed while using both microphones and the USB receiver, the GoPro only shows one VU meter on its display. At first, it looks like only one mic is connected, but watching back through the video, both are in fact recorded.
In this setup, the mics record in “split” mode, one mic on the left channel and the other on the right. This is jarring when listening back on headphones or a TV with connected speakers. The TRS receiver lets you change between mono or stereo, but right now there’s no apparent way to do this with the USB dongle. This means you need to convert the track to mono in editing software, which adds friction if you just want to share a clip directly from your phone or PC.
With your phone, you can side-step this issue with apps like Blackmagic camera that have the option to merge both channels, but most native camera apps don’t offer this. Combined with the UI issue mentioned above, it feels a little clumsy. The good news is, it should be easy to fix in a firmware update. GoPro itself has two apps — Quick and the Fluid camera — that could offer a way to update settings on the USB dongle, but right now you’re stuck with workarounds.
While we’re talking feature requests, there’s no way to start and stop recording on a GoPro with GoPro’s own mics, something DJI offers and a feature I use all the time with its Osmo cameras. It’s a small detail, but I feel it’s a missed opportunity.
South Korean government discloses ten‑month cyberattack on the National Diplomatic Academy’s online education system
Data stolen included user IDs, names, emails, and encrypted passwords of at least 6,000 individuals
MFA shut down IT systems, deployed enhanced security, and delayed disclosure due to diplomatic sensitivity
Current and former employees of the South Korean Ministry of Foreign Affairs (MFA), as well as other government personnel, may have had their data siphoned out by cybercriminals in an attack that lasted for ten months.
The South Korean government has disclosed an attack against the online education system of its National Diplomatic Academy. The system, set up in 2022 by the country’s premier institution for educating and training diplomats, apparently contained a security vulnerability that unnamed threat actors managed to exploit.
In an announcement published on the official website of the South Korean government, both the details about the flaw, as well as about the attackers, were not disclosed.
Latest Videos From
Thousands are affected
However, it did note that the attack took place between April 2025 and February 2026. During these ten months, cybercriminals were able to steal user IDs, names, emails, as well as encrypted passwords of trainees in the National Diplomatic Academy Online Education System.
Advertisement
Unique identification information, sensitive information, mobile phone numbers, home addresses, and photos were not compromised, it said.
In response to the attack, MFA shut down its entire IT infrastructure and deployed “enhanced security measures”, without elaborating what these measures were. It urged all employees to remain vigilant of incoming emails, and to reach out if they receive anything “suspicious”.
While the official announcement lacks details, BleepingComputer reported that the attack impacted “at least 6,000 individuals, 350 of them being current government attachés dispatched abroad.” Citing an MFA spokesperson, the publication said the Ministry decided to disclose the incident with a five-month delay due to the “sensitive nature” of the attack, and the need to thoroughly analyze it before going public.
Advertisement
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
“We recognized this issue in February, but we announced it five months later because of the sensitivity of the matter regarding our diplomatic and security affairs, and the need for careful review and analysis,” said South Korea Foreign Ministry’s spokesperson Park Il.
Samsung’s latest Galaxy Unpacked event wasn’t just about new hardware. Alongside the Galaxy Z Fold8, Galaxy Z Flip8 and new Galaxy Watch lineup, Google used the occasion to announce a series of updates aimed at Android developers, encouraging them to optimize apps for a growing range of foldable devices and wearable form factors.
The guidance focuses on one challenge that has become increasingly relevant as foldables evolve: building apps that work seamlessly across different screen sizes, aspect ratios and device postures. With the Galaxy Z Fold 8 adopting a wider, landscape-first display, Google says developers can no longer assume every Android phone follows the traditional portrait-first design philosophy.
The company has also introduced new tools for camera apps, adaptive layouts, AI-powered features and Wear OS 7 widgets, making this one of its broader developer updates around Android’s expanding device ecosystem.
Google expands adaptive app toolkit for foldables
The biggest change is Google’s renewed focus on adaptive app design. Instead of designing apps around fixed screen dimensions, Google is encouraging developers to build interfaces that automatically adjust based on the available window size. The company recommends using Window Size Classes through the Jetpack WindowManager library to detect how much screen space an app actually has, particularly when devices enter split-screen or multi-window modes.
Advertisement
Google is also highlighting the latest Jetpack Compose April 2026 release (Compose BOM version 2026.04.01), which introduces a new Grid API, FlexBox layout API, and MediaQuery API. Together, these tools allow developers to build layouts that can adapt to changing screen sizes, fold states, keyboard configurations, and device posture without relying on hardcoded interface rules.
You will only notice the crease when light falls on it from an angle.Nadeem Sarwar / Digital Trends
The company is also asking developers to make apps “fold aware” by detecting hinges and fold lines through Jetpack WindowManager. That allows applications to avoid placing important controls across the fold while maintaining app state when users switch between folded and unfolded modes.
Camera apps are receiving attention as well. Google recommends migrating to CameraX, whose PreviewView automatically manages camera orientation, scaling, and display changes during folding transitions. Developers maintaining Camera2-based apps can instead use the CameraViewfinder library to simplify preview handling without rewriting their camera stack.
Wear OS 7 and Gemini Nano 4 open new opportunities
The updates extend beyond foldable phones. With Wear OS 7, Google is introducing Wear Widgets, allowing developers to build glanceable widgets using Jetpack Glance and RemoteCompose. These widgets can now appear inside multi-widget tiles, giving third-party developers access to functionality that was previously limited to Google’s own apps.
Nadeem Sarwar / Digital Trends
Google is also encouraging developers to build on-device AI experiences for Samsung’s latest devices. The new Galaxy foldables ship with Gemini Nano 4, which supports more than 140 languages and improved multimodal capabilities. Through ML Kit’s Prompt API, developers can integrate structured outputs and reasoning features into apps without relying entirely on cloud-based AI processing.
While these announcements don’t introduce new Android features for end users, they provide an early look at where Google’s software priorities are heading. As foldables become more diverse and wearables continue to evolve, Android developers are being encouraged to build apps that adapt to changing hardware rather than assuming every device looks and behaves like a conventional smartphone.
A nine-year-old race condition vulnerability in the Linux kernel’s XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges.
Dubbed RefluXFS by the Qualys Threat Research Unit (TRU), which found and reported it, the security flaw affects systems with an XFS filesystem with reflink enabled (a default configuration on major enterprise Linux distributions), running Linux kernel v4.11 or later, with a directory writable by an unprivileged local user, and a high-value target (a root-owned configuration file or SUID-root binary).
Also, standard defenses (including the Security-Enhanced Linux SELinux kernel security module, kernel lockdown, container isolation mechanisms, and memory-protection features like KASLR, SMEP, and SMAP) don’t block RefluXFS attacks because the flaw operates at the filesystem allocation layer, below where those protections apply.
According to Qualys, exploitation is highly reliable, leaves no kernel log output, and the on-disk modification survives a system reboot.
“The attacker reflink-clones a target file (for example /etc/passwd, or a SUID-root binary such as /usr/bin/su) into a scratch file they own, then races concurrent O_DIRECT writes on that scratch file,” the Qualys TRU team explains in a detailed technical write-up published on Wednesday.
Advertisement
“A lock-drop window in the kernel’s copy-on-write allocation path lets one of those writes land, not in the attacker’s own storage, but in the physical block that still backs the original file. The change is made directly on disk, persists across reboot, produces no kernel log output, and does not touch the target file’s inode — so a modified SUID-root binary keeps its SUID bit.”
RefluXFS has existed since kernel version 4.11, after being introduced in February 2017 by commit 3c68d44a2b49. It has been present in every mainline and stable kernel since and was patched on July 16 after commit 2f4acd0was merged into the Linux kernel source tree.
The list of impacted Linux distros includes Red Hat Enterprise Linux (RHEL), Oracle Linux, Amazon Linux and Fedora, as well as CentOS Stream, Rocky Linux, AlmaLinux and CloudLinux.
Advertisement
Qualys estimates that it potentially affects more than 16.4 million systems based on analysis using its Cybersecurity Asset Management software.
Saeed Abbasi, the head of Qualys’ Threat Research Unit, says the discovery emerged from a research initiative between Qualys and Anthropic, in which researchers integrated the AI model Claude Mythos Preview into their manual audit workflow.
The Claude Mythos Preview was tasked with hunting for a race condition resembling the “Dirty COW” vulnerability class, and after iterative refinement identified the flaw in XFS and generated a functional proof-of-concept. Abbasi added that the Qualys security researchers then reviewed the model’s reasoning, reproduced the exploit, and independently verified all technical claims before coordinating disclosure with kernel maintainers.
“Immediate kernel patching is recommended to neutralize this vulnerability. Exploitation succeeds consistently under standard hardening settings, and the on-disk modification survives a system reboot,” said Abbasi.
Advertisement
“Vendor-fixed kernels are now available and being backported to enterprise distributions. Organizations should prioritize patching exposed and multi-tenant systems and ensure a reboot to verify the update. As of now, there are no reliable or practical mitigations or temporary configuration changes available.”
Mozilla walls off your online identities as MZLA unleashes a bumper repair job
Mozilla released Firefox 153 on Tuesday, closely followed by MZLA with Thunderbird 153 – codenamed “Meadow” for reasons that remain obscure for now.
Firefox 153 is Mozilla’s new Extended Support Release (ESR), so it will receive security updates until some time after the next ESR in mid-2027. We covered the highlights of what’s new in this version last week.
Advertisement
Firefox 153 will be good news if you used the Multi-Account Containers extension: a preview version of the functionality is now built in. Firefox already has user profiles, which let you keep sets of settings and credentials separate. With some extra effort, you can even launch multiple separate instances of Firefox with different profiles. Containers make similar functionality much easier: each container has its own set of stored credentials. So, for instance, a “home” container could hold a set of tabs logged into various sites with your personal accounts, while a “work” container could log into the same sites with your day-job credentials.
There are also new features for users on mobile. Firefox 153 for Android gets tab groups, while Firefox for iOS users in the US get the new Quick Answers feature. Speech recognition happens on the device, although the transcribed question is sent online to generate an answer.
Thunderbird ‘Meadow’
MZLA’s Thunderbird messaging client also has a new version, itself an ESR: Thunderbird 153.
This version is codenamed “Meadow,” replacing the previous “Eclipse” release, but at the time of writing, info about what “Meadow” signifies is scant. The New in Thunderbird Desktop page hasn’t been updated since Thunderbird 150, which came out back in April. At least there’s some info there, even if it’s outdated. At the time of writing, following the What’s New in Thunderbird 153 link in the release notes gives this helpful info:
Advertisement
Thunderbird 153 is here, with hundreds of fixes and tweaks – not that MZLA wants to tell us about itLiam Proven
Since that final link is the only helpful thing there, we’ve done so. It might even be fixed by the time you read this.
Firefox 115.38
Some ESRs get updates for much longer. Although Firefox 115 came out three years ago, the same day as Firefox on our Sequoia iMac updated itself to version 153, The Reg FOSS desk’s last remaining macOS 10.13 machine got Firefox 115.38. Good news for the determined users of Windows 7 to 8.1, and macOS 10.12 to 10.14.
Perhaps the team has been too busy fixing things instead, which seems like respectable prioritization to us. Under What’s New are 32 refinements, 15 entries under What’s Changed, and a whopping 181 bug fixes under What’s Fixed.
This many changes is good news for an ESR release, and it looks like the team has been busy fixing things. It does make us wonder if MZLA is struggling to keep up with Firefox’s monthly release schedule, as it’s been doing since Thunderbird 138 in April 2025. Since Mozilla decided to accelerate Firefox to fortnightly releases from September, perhaps MZLA should drop Thunderbird back down to annual releases.
Advertisement
Still, this ESR brings improvements to folder handling, notifications, OpenPGP encryption, OAuth login, address book export, PDF handling, and much more. There won’t be any more 32-bit Linux binaries – joining Firefox, which did that in September after Firefox 144. “Junk” mail is now called “Spam,” and the dedicated setup option for the Russian Odnoklassniki service has been dropped, with users directed to configure it through XMPP instead.
Thunderbird offers so many different views that we’ve seen some user confusion about this, but they are handy, and a few of the non-default ones are improved in this release. We sometimes use the “Unread Folders” view, and it’s now better at hiding folders with no unread messages. The other non-obvious view is “Unified Folders.” This categorizes and combines multiple inboxes into one tree: all your inboxes, followed by separate per-account trees of all subfolders. It sounds confusing, but we find it very helpful. This view now lets you color-code different accounts.
Several of Thunderbird’s new options around account handling concern Thundermail accounts. These are part of MZLA’s paid email service, Thunderbird Pro. This hasn’t been launched yet, but the new account type suggests it’s getting close. One of the most visible signs is in the Account Hub wizard for adding messaging accounts: it now has a “Sign in with Thundermail” button at the top.
This vulture is on the waiting list, and we will report back when we get to the front of the line. ®
Apple reportedly plans to launch a Klarna-backed financing program next week that will let you pay off an iPhone, iPad, Mac, or Apple Watch in monthly installments over two to three years. While Apple hasn’t shared any details about the rumored “Apple Upgrade” program yet, code spotted in an iOS 27 beta release suggests the company has already built a system to deal with customers who fall behind on payments.
A built-in switch lenders can flip to lock most apps
According to 9to5Mac, iOS 27 includes a new framework called App Managed Features, which hands an approved lending app the ability to monitor whether a customer has been keeping up with payments. If they miss enough installments, the lender can put their iPhone in Restricted Mode, which blocks access to all but nine apps.
Shikhar Mehrotra / Digital Trends
Phone, Settings, Wallet, Clock, Health, Passwords, Magnifier, Accessibility Reader, and the App Store will reportedly continue to work. Subscriptions tied to any blocked apps will also keep running, since Restricted Mode doesn’t appear to touch App Store billing. That means someone locked out of an app will be charged even if they can’t use the subscriptions.
A second layer called Partner Finance Lock will close off the obvious workarounds, preventing users from disabling Restricted Mode with a factory reset, selling a restricted device, or stripping it for parts.
The lender sets the rules, not Apple
Messages, Home, and other apps that send critical alerts may stay available during a lockout. That call reportedly sits with the lender, so the exceptions a user gets could depend on who financed the phone.
Advertisement
The code also sets no threshold for how many missed payments trigger a lockout, suggesting that financing partners will decide those terms as well. If that’s the case, the agreement a customer signs will be the only place to learn how much wiggle room they get.
None of this is confirmed, and Apple could make further changes before the system rolls out with iOS 27 later this year. It’s also unclear whether the same system will reach financed iPads, Macs, or Apple Watches.
You must be logged in to post a comment Login