Connect with us

Tech

Northrop’s robot space mechanic is a new way to keep satellites at work longer

Published

on

High above the Earth, a new generation of robots designed to keep satellites working longer is replacing its predecessor — quite literally.

This week, a spacecraft built and operated by Northrop Grumman called a Mission Extension Vehicle (MEV) unplugged from a communications satellite operated by the Australian firm Optus. For more than a year, the MEV spacecraft has been stuck to the back of the Optus satellite, keeping it in the right place in space so it can continue its mission.

Now, the satellite life-extension spacecraft is leaving to make room for its replacement. In July, four new Northrop spacecraft launched into orbit on a SpaceX Falcon 9 rocket. One is called the Mission Robotic Vehicle (MRV), a powerful satellite equipped with two advanced robotic arms that was developed by DARPA, the U.S. military research organization. The other three are called Mission Extension Pods, or MEPs, smaller, simpler satellites that are essentially modular propulsion systems.

Those four spacecraft are currently headed for targets around 27,000 miles above the Earth. In 2027, the MRV will use its robotic arms to attach one of the MEP pods to the Optus satellite, which should keep it in orbit for years to come.

Advertisement

The satellites that provide communications or scan the planet with various sensors only last for so long. They typically fail when they run out of fuel to stay in the right place, not because their computers and transceivers stop working. The Optus satellite was launched in 2009, and designed for a 15-year lifespan. If all goes well, the satellite could fly — and generate revenue — for another six years.

Now, cheaper launch costs and lower-cost space components are making spacecraft repair missions a reality.

The goal is “a paradigm shift where we can see space as sustainable, with a more resilient architecture and infrastructure base where we can do things like spacecraft repairs, life extension, or even upgrades and maintenance of satellites,” according to Northrop’s director of logistics and servicing, Cassie Wong.

There are two MEVs in orbit right now, launched in 2019 and 2020, which have provided 10 years of life extension to three customers, including two different Intelsat spacecraft and the Optus satellite. MEV-1 will wait in a parking orbit for another customer, while MEV-2 is currently attached to its Intelsat customer until 2030.

Advertisement

The Mission Robotic Vehicle, or MRV, represents an evolution of the business model. Satellite operators buy and own the MEPs, which are permanently attached to their spacecraft. That frees up the MRV to service more vehicles, creating a cheaper offering.

The offering requires some serious technology chops. The vehicles need to autonomously approach one another and dock safely, not a simple task when both are moving at velocities of thousands of miles an hour. The MEVs use a docking probe to plug in and hang onto satellite thruster nozzles. Meanwhile, the MRVs will need to carefully attach the MEPs using their robotic arms.

Unlike most satellites, the MRV is designed to be refueled in orbit — in part, a proof of concept for the kind of capabilities other satellites will need if this kind of in-orbit servicing becomes a norm. Right now, the extra cost and weight of such adaptations keeps spacecraft operators from investing in them.

Indeed, the current trend in satellites is flying lots of cheap, effectively replaceable spacecraft in low orbits, as Starlink and Amazon LEO do. On the other hand, spacecraft keep getting bigger, and there are plenty of expensive, large satellites in orbit that could benefit from life extension. Wong hopes that the MRV will take on other missions in the future, adding new components to satellites as well as adjusting their orbits.

Advertisement

That’s likely to include defense customers, given the number of expensive satellites it owns in high orbits, and DARPA’s involvement in developing the MRV’s arms. Indeed, the U.S. Space Force has previously characterized a Chinese servicing spacecraft with robotic arms as a weapon, since it could theoretically grapple and degrade a rival satellite. Northrop says that its vehicles are focused on servicing missions.

The vehicle could also be used in LEO, Wong says, to extend the life with valuable assets there. The startup Katalyst Space is attempting a similar mission to extend the life of a NASA space telescope after malfunctions left its vehicle tumbling last month. The company has a fix in place and hopes to complete the mission.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Hundreds of fake Chrome VPN extensions route traffic through a proxy

Published

on

Hundreds of fake Chrome VPN extensions route traffic through a proxy

More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users’ traffic through SOCKS5 proxies operated by a single provider.

Some of the extensions impersonated dozens of established brands, including Proton VPN, NordVPN, Surfshark, ExpressVPN, and Cloudflare’s 1.1.1.1 public domain name system (DNS) resolver.

Researchers at application security company Socket found that the campaign relied on 40 publisher accounts and used a shared analytics account.

image

While on the Chrome Web Store, the extensions were downloaded nearly 75,000 times, mainly by Russian users looking for tools to bypass blocked services in the country.

“With all browser traffic forced through it [the relay], the threat actor’s server is positioned to read every destination, every TLS SNI value, the victim’s source IP, and any request body sent over plain HTTP,” Socket explains.

Advertisement

The researchers identified three threat behaviors associated with the campaign:

  • 520 extensions configured Chrome to route all browser traffic through the operator’s SOCKS5 proxies on port 1082.
  • 104 extensions resolved their proxy hostnames through Cloudflare or Google DNS-over-HTTPS to protect the operator’s domain from scrutiny.
  • Extensions that advertised non-existent premium servers in Japan, Singapore, Canada, Australia, and Turkey for subscription fraud

Socket could not analyze the code in all of the extensions because 212 of them had already been removed when the researchers collected them.

Based on the strings found, the campaign appears to be an attempt to funnel customers to a subscription-based VPN service in Russia.

The researchers noted that the mechanism used by the extensions appears no different from that of a legitimate service, but they identified several indicators of intentional deception:

  • impersonating well-known brands
  • advertising nonexistent premium server locations
  • nonfunctional payment or connection mechanisms
  • misleading disclosures to store reviewers
  • adding remote configuration after the extension was approved
  • the use of techniques to hide proxy destinations from analysis

Socket says that while Google removed more than 200 of the extensions related to the identified campaign, over 500 of them are still available in Chrome’s Web Store.

Socket has published the IDs of all extensions linked to the campaign and recommends that users check their browsers for any of them and remove them if found. They should also confirm that Chrome’s proxy configuration is back to normal.

Advertisement

article image

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

Source link

Continue Reading

Tech

Revolut bets on airport lounges as some premium WeWork perks cut

Published

on

Revolut is scaling back some WeWork perks for premium members just as it unveils its first airport lounge, part of a wider push to build out its own physical footprint.

As Revolut continues to increase its physical presence, its latest bet is premium airport lounges. The announcement of its first airport lounge in Copenhagen comes as reports have been circulating of Revolut premium members losing access to some WeWork locations  – a significant perk offered by the fintech.

A spokesperson for Revolut told SiliconRepublic.com that its ‘Metal’ and ‘Ultra’ users continue to retain access to WeWork in Dublin, but conceded there is “a slight change to the available locations”. They added that more than 265 locations “remain active and accessible to Revolut’s premium members”.

“We always strive to ensure that our premium (Ultra and Metal) customers receive maximum value across our global partner network,” Revolut said in response to the reports. “While benefit availability can change due to various requirements, we remain committed to offering our members access to premium workspace solutions and other global lifestyle benefits.”

Advertisement

SiliconRepublic.com understands that around 6pc of the Revolut x WeWork network will no longer be accessible to premium members, after WeWork raised some of its pricing and Revolut was unwilling to absorb the cost or pass it on to members.

Therefore, Revolut’s current strategy of creating its own physical spaces would make a lot of sense. The company said this new strategy will launch a network of premium lounges across some of its priority markets over the coming years, with the aim of  becoming one of the largest premium lounge networks globally.

It has signed an inaugural partnership agreement with Copenhagen Airport to establish “a premium design blueprint” that Revolut can then roll out across key international hubs in 2027 and beyond.

Back in April, Revolut confirmed it was piloting a physical store in Barcelona in its latest attempt to compete with traditional banks. The fintech stressed that this will not be a traditional bank branch, but rather a “new format built for how modern customers engage with brands today”.

Advertisement

“This is a new physical concept space where people can experience Revolut products and services in-person, receive support, discover features and engage with the brand more tangibly. At our scale, physical presence builds trust and visibility,” a company spokesperson told SiliconRepublic.com at the time.

Revolut’s strategy to become a truly global bank got a major boost this week, as it was awarded its first full French banking licence, giving the fintech giant a second European Union hub after Lithuania.

The French approval is the latest in a run of regulatory wins for Revolut this year. It finally secured its full UK banking licence in March after a five-year wait, applied for a US banking licence around the same time, and in July launched its first Asia-Pacific banking entity in Australia after receiving regulatory approval there.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Advertisement

Source link

Continue Reading

Tech

This S’pore restaurant has let customers decide the bill for 25 years. Here’s how it’s still surviving.

Published

on

⁠In Singapore’s brutal F&B industry, Annalakshmi still lets you pay whatever you want

For 25 years, Annalakshmi has operated on a premise that seems almost antithetical to conventional F&B economics: let diners decide how much they want to pay.

In Singapore, where restaurants contend with rising rent, manpower costs and increasingly cautious consumers, giving customers control over the bill might sound like a recipe for financial trouble.

Yet somehow, the vegetarian restaurant has made it work all these years.

Founded in 1986, the restaurant moved from a fixed-price concept to its current pay-as-you-wish model in 2001. The idea behind it was simple: anyone should be able to enjoy a wholesome meal, regardless of what they can afford. Those who are able to give more help make that possible for someone else.

Advertisement

But the model is not simply a matter of trusting diners to be generous.

Behind the buffet is a network of volunteers, donors, loyal customers and other business activities that have helped Annalakshmi weather the realities of running an F&B business in Singapore.

A stranger’s kindness

Annalakshmi first opened in 1986 at the Excelsior Hotel, Singapore./ Image Credit: Annalakshmi Singapore

The origins of Annalakshmi’s business model can be traced back to its founder, Swami Shantanand Saraswathi.

At 16, he had chosen a monastic life and found himself at the Kashi Annapurna Temple in Varanasi, India. With little more than the clothes on his back, he was hungry and uncertain about where his next meal would come from.

A woman eventually stepped forward and served him a meal.

Advertisement

She did not ask whether he could afford it—and she did not ask for anything in return.

For Swami Shantanand, that simple act of kindness planted the idea of sharing food with compassion and generosity, and of creating a place where no one would be turned away simply because they could not afford a meal.

That idea eventually found its way to Singapore, and in 1986, Annalakshmi opened its doors. At the restaurant, diners contribute what they are able to, with those who give more helping make a meal possible for someone else.

But turning generosity into an F&B model is one thing in theory, and another in practice. How do you keep a restaurant running when you don’t decide what your customers pay?

Advertisement

The customers who pay it forward

For Annalakshmi, part of the answer lies with the people who walk through its doors.

Image Credit: Maria Christine Asuncion, Pete Jankus via Google Reviews

Some of its diners first came as students or young professionals, when they could only contribute what they could afford. Years later, many return with their families, friends or colleagues—this time with the means to give more.

Some even tell the restaurant that Annalakshmi had reminded them of home during a time when money was tight.

These customers illustrate how the pay-as-you-wish model can create a kind of long-term relationship between diners and the restaurant.

But the restaurant can’t rely on goodwill from diners alone. Keeping an F&B business running requires a much bigger support system.

Advertisement

A “long chain of helping hands”

One of the biggest parts of that support system is Annalakshmi’s volunteers.

They are involved in almost every part of the operation, from preparing vegetables and packing meals to serving guests, replenishing food during busy periods and assisting at the cash register.

Annalakshmi’s volunteers, from the restaurant’s early days in Singapore (left) to the present day (right), have remained central to keeping its pay-as-you-wish model going./ Image Credit: Annalakshmi Singapore

But for Annalakshmi, their role goes beyond simply providing an extra pair of hands.

Many volunteer because they believe in what the restaurant is trying to do, giving their time in the same spirit of service that the organisation was built around.

Some also contribute in other ways—through in-kind donations, professional expertise, or simply by spreading the word about the restaurant. The organisation affectionately calls these volunteers “annalakshmis,” a name inspired by the Hindu concept of abundance.

Advertisement

As Annalakshmi puts it, the model is sustained by a “long chain of helping hands,” from patrons and donors to volunteers and staff. And it has spent decades building a community willing to contribute in different ways to keep the whole thing going.

What happens when the model is tested?

Annalakshmi is rooted in the Hindu principle of Atithi Devo Bhava—”Guest is God.” It’s a philosophy that could easily be read as bad business sense, especially in a city where rent and manpower costs only move in one direction.

The restaurant sees it differently. To the team, “Guest is God” was never about ignoring financial reality. It simply means that every decision starts from an intention of service, not profit.

That still leaves the practical questions to answer. Costs have to be managed. Suppliers, donors and the community have to be kept close.

Advertisement
The Annalakshmi Café./ Image Credit: Xiao Long Bao, Rajavel Mathivanan via Google Reviews

For Annalakshmi, that’s meant building various revenue streams, including a steady catering and events business.

Over the years, it has also reviewed its catering menus and pricing, and eventually opened Annalakshmi Café—a conventionally priced, à la carte concept that now runs alongside the original buffet for diners who’d rather not think about what to give.

None of these moves, the team says, are a departure from the restaurant’s values. They’re what allow Annalakshmi to keep living those values as Singapore’s F&B landscape keeps shifting under it.

Even so, the pressures are real. Rising costs of living and rising operating expenses weigh on the people running Annalakshmi the same way they weigh on any other business owner in Singapore.

What the team points to instead is a kind of collective resilience—when one person loses sight of the bigger picture, someone else in the community is there to remind them why the restaurant exists in the first place.

Advertisement

Beyond the buffet line

Annalakshmi celebrated its 40th anniversary in Mar 2026—four decades since it first opened its doors, and a quarter-century since it adopted the pay-as-you-wish model.

Over the years, the restaurant has moved through locations including Chinatown Point and Central Square, and now operates out of OUE Downtown Gallery.

But its philosophy has never stopped at the buffet line.

Annalakshmi’s outreach efforts during COVID-19./ Image Credit: Annalakshmi

Beyond the restaurant, Annalakshmi has extended that spirit of giving through community outreach, preparing and delivering meals to groups including migrant workers and the elderly—people who may never walk through its doors, but who still fit within its founding belief that no one should go without a meal.

That commitment was tested most during COVID-19, when the restaurant could no longer operate as normal and instead turned its kitchen almost entirely toward preparing meals for communities in need.

Advertisement

In 2020 alone, it served more than 50,000 meals to migrant workers, subsidised 500 meals every fortnight for needy families, and delivered 1,000 meals every fortnight to elderly beneficiaries and aged homes, among other relief efforts.

There’s no right number

If you’re heading to Annalakshmi for the first time, you might wonder how much you’re supposed to contribute—or worry about being judged for paying too little.

The restaurant says that’s one of the most common questions it gets from first-time diners.

Rather than suggesting an amount, the team explains the philosophy behind the model and reassures guests that there are no expectations. The only encouragement is to give whatever genuinely feels right.

Advertisement

For Annalakshmi, the real measure of success isn’t what ends up in the cash register, but what people carry with them after they leave.

If Annalakshmi has inspired even a few people to carry that spirit of generosity beyond our dining room into their homes, workplaces and communities, then we think we’ve achieved something.

  • Find out more about Annalakshmi here.
  • Read other articles we’ve written on Singaporean businesses here.

Featured Image Credit: Wan2eats, Pete Jankus via Google Reviews

Source link

Advertisement
Continue Reading

Tech

Everything is better with pickles… except Windows

Published

on

offbeat

Operating system indigestion pops up over chicken sandwich ad

BORK!BORK!BORK! “Everything is better with pickles,” trumpets a Wendy’s sign. Everything is also better with a helping of bork, if the screen is to be believed.

Wendy’s menu board showing pickle-themed sandwiches and fries with a Windows error dialog overlay.

Do you want bork with that?

Spotted by an eagle-eyed Register reader in Vancouver, the display shows something amiss with Windows Phone Link – although why a PC encouraging customers to drop dollars on a Dill Pickle Chicken Sandwich needs the app is anyone’s guess.

Advertisement

The error itself usually comes up when something running Windows has been a bit careless with stack memory. Perhaps there’s been a stack overflow, a software conflict, or a memory shortage. The usual fix is to reach for the power button or perform a restart. The more technically minded might try to diagnose the whoopsie and fix it without a boot cycle, although had a more technically minded person set up the system in the first place, it’s unlikely that the PhoneExperienceHost.exe application would have reared its ugly head in this way.

Phone Link connects a Windows PC to an Android phone or iPhone. The theory goes that users can keep track of mobile notifications, send and receive messages, or deal with calls from their Windows desktop. It arrived with Windows 10 as Your Phone before Microsoft renamed it Phone Link and continued adding features.

Ordinarily, the service doesn’t use much in the way of memory or CPU. However, something has clearly upset the instance here, much as an excess of dill pickles might disagree with the customer.

While we’re sure the foodstuffs on offer are excellent (although our reader told us they were only popping in for a Frosty Dairy Dessert rather than anything slapped with a dill pickle), we might give the chicken sandwich a miss this time. Even Windows appears less than keen. ®

Advertisement

Source link

Continue Reading

Tech

Amazon will train on Twitch streamers’ content by default, unless they opt out

Published

on

The streaming platform Twitch will now use creators’ content to help train generative AI models for its parent company, Amazon. This move has inspired swift and concentrated backlash from the Twitch community, especially because creators are opted in to having their content used for this AI training by default.

For Amazon, these stream recordings are incredibly valuable, offering thousands of hours of audio and video content to help train AI models. But Twitch users worry that since creators have to manually opt out, they might be surrendering their content to train Amazon’s AI content models without even knowing it. This is especially concerning on a platform like Twitch, where creators are often recording livestreams of themselves and their voices for many hours per week.

Image Credits:Twitch /

In a stream on the official Twitch channel, Twitch Head of Community Mary Kish and Chief Product Officer Mike Minton addressed a live audience of nearly 3,000 aggrieved users, many of whom were posting anti-AI sentiments in the chat.

“Why is it not opt-in? That’s what everybody is spamming in chat. I get it. ‘Let me opt in versus making me opt out,’” Minton said. “Well, there’s an honest answer… If this was opt-in, nobody would opt in. That’s honestly the answer.”

Twitch knows that its community of streamers is largely opposed to the use of generative AI, since the most prevalent generative AI products are trained on books, images, videos, and other materials scraped from the internet without consent.

Advertisement

Even Twitch’s approach to breaking this news shows that the company is braced for backlash. Instead of telling the community that Amazon would begin training on Twitch users’ content, Twitch framed this change as “[adding] a setting that lets you opt out of having your channel content used to train generative AI content models across Amazon.”

In some cases, this created confusion among streamers about whether their content had already been fed to Amazon without their knowledge. When one user asked if their videos had already been used for training, Minton responded, “I don’t actually know the answer to that question because I don’t know what Amazon […] has done in terms of model training and what they’ve used and not used.”

Kish noted that Twitch is not unique in its use of user content for AI training. Meta, for example, uses public content from its platforms to train its own AI models, meaning that if your Facebook and Instagram accounts are public, then your data has probably already been used for Meta’s AI training. (If you live in the U.K., you can opt out of Meta’s training — if not, the only way to “opt out” is to use private settings, which isn’t feasible for creators who monetize their accounts.)

Kish said that even including an opt-out option on Twitch is “a reflection of reacting to this community’s voice that you are not wanting to train Gen AI models, and we want to give you that option.”

Advertisement

To opt out of AI training on Twitch, users can navigate to their channel settings (not the creator dashboard), select the security and privacy tab, scroll down to the option “training for generative AI,” and toggle it off.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Source link

Advertisement
Continue Reading

Tech

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Published

on

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe’s Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts.

The flaw is described as an incorrect authorization vulnerability that could be leveraged to “gain elevated access to sensitive resources” without authentication and is one of the seven issues that Adobe addressed in a security update yesterday.

Although the software vendor states in the advisory that it is not aware of exploits in the wild for any of the fixed flaws, eCommerce security company Sansec says that its Shield web application firewall (WAF) is already blocking CVE-2026-71362 exploitation attempts.

image

According to Sansec, exploiting the vulnerability requires “no existing account, administrator privileges or user interaction.”

After analyzing Adobe’s patch, the researchers pinned the problem to Magento improperly handling customer identity in an account session.

Advertisement

“Sansec reviewed the patch and confirmed that the vulnerability lets attackers switch a customer session to another customer account. This gives them access to the victim’s account and private customer data,” the security company explains.

Four of the other flaws Adobe fixed with yesterday’s updates received a high-severity score, and the other two are medium and low severity:

  • CVE-2026-48414 (7.7, high severity): Stored cross-site scripting vulnerability that could result in arbitrary code execution. Exploitation requires authentication and administrator privileges.
  • CVE-2026-48413 (8.7, high severity): Stored cross-site scripting vulnerability that could result in arbitrary code execution. It requires authentication but not administrator privileges.
  • CVE-2026-48415 (7.6, high severity): Incorrect-authorization vulnerability affecting Adobe Commerce B2B that could enable a security-feature bypass. It requires authentication but not administrator privileges.
  • CVE-2026-48416 (7.5, high severity): Incorrect-authorization vulnerability that could enable a security-feature bypass. It requires neither authentication nor administrator privileges.
  • CVE-2026-48411 (6.5, medium severity): Incorrect-authorization vulnerability that could enable a security-feature bypass. Exploitation requires authentication and administrator privileges.
  • CVE-2026-48412 (2.7, low severity): Incorrect-authorization vulnerability that could result in privilege escalation. Exploitation requires authentication and administrator privileges.

Website administrators are advised to apply the August 2026 security update for currently supported Commerce, Commerce B2B, and Magento release lines as soon as possible.

According to Sansec, these monthly fixes are distributed as isolated patch files rather than a new security release or updated Composer packages.

Website admins must first ensure they’re running the latest -p release available for their supported release branch before applying the corresponding isolated patch.

Advertisement

article image

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

Source link

Continue Reading

Tech

Nvidia-backed CodeRabbit valued at $1.5bn after $143m funding round

Published

on

CodeRabbit intends to put part of the funds towards expanding its European workforce and moving into the Asian market.

AI code review start-up CodeRabbit, which is backed by Nvidia, has announced a Series C funding round in which the organisation raised $143m, bringing the company to a valuation of $1.5bn. The round was co-led by Atomico and ​Smash Capital, with participation from new investors including BMW i Ventures, ​Datadog and Hirtle Callaghan.

Established in 2023, CodeRabbit is headquartered in California and has an additional office in London. The company offers an AI-powered coding tool that enables users to automatically review code as it is being written. 

The organisation intends to use the new capital to accelerate its international expansion, as well as advance its research and product development. Reportedly, CodeRabbit plans to expand the Europe-based workforce and extend into Asia, with a particular focus on Japan and Singapore. 

Advertisement

Commenting on the announcement, Luca Eisenstecken, a partner at Atomico, who will soon join CodeRabbit’s board of directors, said, “As AI becomes critical infrastructure for the global economy, organisations will increasingly need independent governance layers that can validate software regardless of which model produced it. 

“That kind of trusted, model-agnostic infrastructure strengthens the resilience of the software that businesses depend on. CodeRabbit’s independent review system and deep contextual understanding position it as the control layer for agentic software development.”

Harjot Gill, CodeRabbit’s CEO and co-founder added, “Code changes now originate across the software organization, including from developers, non-technical personnel, as well as from coding agents to issue trackers, support systems, and production alerts. 

“Every change creates a decision for the team. We pioneered AI code review to give teams an independent system that validates the work before it ships. Agentic change management expands that layer to determine what deserves attention, explain each change’s impact, and continue monitoring the codebase after it ships.”

Advertisement

There has been a recent surge of interest in tools and programmes designed to enable coders and other tech employees to churn out code quickly and efficiently. In March, Replit, a ‘vibe-coding’ start-up, announced a funding milestone after raising $400m in a Series D round to stand at a $9bn valuation. 

Following Anthropic’s launch of Code Review, an AI-powered feature designed to catch and eliminate bugs before they make it into a software’s codebase, SiliconRepublic.com spoke with Globant’s senior vice-president of digital innovation, Agustin Huerta about the pros and cons of creating an environment in which coding is far simpler. 

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Advertisement

Source link

Continue Reading

Tech

SpaceX’s Starlink starts taking orders in Vietnam, on Hanoi’s terms

Published

on

SpaceX’s Starlink has begun taking orders for its satellite-internet service in Vietnam, opening one of Southeast Asia’s fastest-growing markets to Elon Musk’s orbital broadband.

It is a notable win for a business that has become SpaceX’s cash machine, though this time the company is arriving very much on Hanoi’s terms.

The sums involved are not trivial. A monthly subscription costs VND1.71m, or roughly $65, while the Standard 4X equipment kit runs to VND10.27m, about $390.

Add shipping of around $22 and an upfront deposit of some $70 that is later applied to the kit, and a first-year outlay lands near VND31.4m, or approximately $1,190. This is a premium proposition rather than a mass-market one.

Advertisement

For that money, Starlink promises download speeds of 135 to 305 Mbps and uploads of 20 to 40 Mbps, while hedging, as it always does, that the figures vary by location, network density and weather.

In practice, that still puts it comfortably ahead of the patchy or non-existent connections it is meant to replace. The performance is beside the point for most likely buyers, who care less about peak throughput than about having any reliable signal at all.

The service operates under a five-year pilot programme, approved by Vietnam and running until 1 January 2031. The framework is unusually accommodating in one respect and pointedly restrictive in another.

It lets SpaceX keep 100% local ownership, a rare concession in a tightly controlled telecoms sector, but caps the number of subscribers at 600,000, ensuring the venture never grows large enough to unsettle the domestic order.

Advertisement

Hanoi is policing the hardware, too. Authorities require that only officially distributed equipment be used, and have warned against imported devices, which carry the risk of fines or confiscation.

Grey-market Starlink dishes have quietly proliferated across parts of Asia, and Vietnam is signalling that it wants the service on the books, taxed and traceable, rather than smuggled in through the back door. The message is clear enough: Starlink is welcome, provided the state can see exactly who is using it and how.

On price, Vietnam sits towards the pricier end of the neighbourhood. At around $1,190 a year, it is roughly 12% above the global average of about $1,061, and dearer than Malaysia at some $909 or the Philippines at $1,045.

It remains cheaper than Indonesia, where a year costs about $1,491, so the premium, while real, is hardly extortionate by regional standards.

Advertisement

Crucially, Starlink is not chasing the city dwellers already served by fibre. Its pitch is aimed at the underserved: rural areas, remote islands, fishing vessels, construction sites and farms, the sort of places where a dish pointed at the sky beats waiting for cables that may never come.

It is the same gap the company fills from Africa to the American Midwest, and the same one rivals such as Amazon are only now scrambling to reach.

Vietnam formally licensed Starlink earlier in 2026, after clearing the foreign-ownership rules that had long kept it out, a move made easier by the broader climate of US trade considerations.

The timing is not incidental. Satellite broadband has quietly become another bargaining chip in the choreography between Washington and its trading partners, and Hanoi, keen to keep its export relationship with the US on an even keel, has read the room.

Advertisement

Letting an American firm operate freely, but on a tight leash, is the sort of compromise that keeps everyone at the table.

For SpaceX, Vietnam is another dot on a map that keeps expanding, from its recent round of price rises to markets where state-backed challengers are still finding their feet.

For Vietnam, it is a calculated bet that it can import American connectivity without importing American dependence. Both sides, for the moment at least, appear content to call that a fair trade.

Advertisement

Source link

Continue Reading

Tech

Could a Shirt Fool Facial Recognition? The Answer Is Complicated

Published

on

A camera and its software labeled Bill Swearingen as a person. Then it suddenly wasn’t sure — all because of some weird pattern that he held up to disguise himself.

I watched it happen from my seat at annual hacker convention Defcon. Swearingen, a longtime cybersecurity professional and founder of the Kansas City security community SecKC, stood onstage in front of a live camera feed as a person-detection system analyzed him. On the giant screen behind him, the software’s confidence score cleared 0.75, the threshold it needed to declare that, yes, there was a human being in the frame.

Then Swearingen raised a flat panel covered in a bizarre black-and-white pattern. The score started falling. It slipped below the threshold, eventually landing at 0.21.

“No person detected,” the screen announced in bright green letters.

Advertisement

It felt like a low-budget magic trick. Swearingen was still standing there, plainly visible to everyone in the room. The software was still receiving the camera image, but it no longer detected a person above the configured confidence threshold.

Swearingen has spent the past year searching for patterns that can confuse the computer-vision systems used to identify people. His project is called noRecognition, and its end goal is to create clothing that makes the wearer harder for AI surveillance systems to detect. It’s a fascinating project, but it’s still a work in progress.

The camera wasn’t trying to identify him

We tend to call this kind of technology “facial recognition,” but surveillance systems can involve several separate layers of AI-based detection.

A person detector asks whether a human body is in the frame. A face detector finds and isolates a face. Facial recognition then compares that face with a database and asks whether it knows who the person is.

Advertisement
A slide shows three different models of AI detection.
Person detection, face detection and facial recognition perform different jobs, though each step can depend on the one before it.

The demonstration I saw targeted the first step. The system didn’t mistake Swearingen for somebody else or decide the room was empty. It simply stopped reporting a person detection above the threshold set for the demonstration.

If you break the first link, the rest of the surveillance chain may never get started. If a camera fails to detect a person, it may never crop out that person’s face, send it to an identity database, then track them across a series of images.

An AI detector doesn’t “see” a person in the way we do. It generates thousands of guesses about what might be in an image, assigns a score to them and discards anything that fails to clear a chosen confidence threshold.

Swearingen was still there. The detector’s math just wasn’t sure he was a person.

How the patterns are made

Swearingen didn’t sit down and draw the patterns himself. He built a program to create them.

Advertisement

Security researchers normally use programs called fuzzers to bombard software with strange inputs in an attempt to break it. Swearingen’s fuzzer does something similar with computer vision. It creates a pattern, digitally places it on an image of a computer-generated person and then shows the altered image to several AI models.

If a pattern causes a major change, like making the person’s detection box disappear or sharply lowering the model’s confidence score, then the fuzzer flags it for more testing.

The most successful designs are altered and combined to produce new patterns, much like selectively breeding specific traits in animals. Swearingen’s software repeats that process automatically, allowing it to work through far more possibilities than a person could design and test by hand.

He currently tests each pattern against 11 models: five that detect people, four that find faces and two that try to recognize whose face it is. In many cases, he tested a public model that works similarly to proprietary systems, not the actual software being used by companies in the wild. Most are publicly available models that researchers can run themselves.

Advertisement

Swearingen said the project had run 31.7 million tests as of June. About 534,600 triggered one of his system’s anomaly rules. That could mean a detector found fewer people or faces than it did in the original image, invented extra ones, produced a much lower confidence score or returned the wrong identity. It doesn’t mean he found 534,600 patterns that could hide someone from a camera.

On a slide at the presentation is Swearingen’s custom fuzzer at work.
Swearingen’s custom fuzzer automatically generates patterns, tests them against computer-vision models and flags designs that produce unusual results.

Of those results, 85 met the project’s definition of “extreme,” which means the pattern defeated at least one person detector and at least one face detector in the same test. 

The tests also showed that covering more of the body isn’t always more effective. Torso patterns had the greatest effect on person detectors, while patterns closer to the head mattered more to systems looking for faces. In one comparison, Swearingen said a small collar pattern worked better than a much larger print across the torso.

Even the winning patterns can lose

Some of Swearingen’s results looked promising until he tested the designs on different people.

One pattern lowered the detector’s confidence for all four people whose images were used while it was being developed. But when Swearingen applied that same design to images of eight new people, it didn’t work once.

Advertisement
Models the company used to text their product.
Swearingen used computer-generated people wearing different garments and accessories to test where adversarial patterns might work best.

Counted together, the pattern had worked on four of 12 people. Swearingen withdrew the resulting 33% performance claim because every success involved people whose images had been used to develop the pattern. It hadn’t worked on anyone new.

Another pattern, designed to fool a different detector, worked on all eight new people. That contrast shows how much the results can change between detectors — what works with one person or detection model may fail with another.

Even a successful pattern may have a short shelf life. A camera company could retrain its software to recognize it. Swearingen compared the patterns to software “zero-days” vulnerabilities — they take advantage of a weakness that may disappear once the system is updated.

The shirt doesn’t exist yet, and the tech isn’t field-tested

On one of Swearingen’s slides, in large type, were the words “Still unproven: The worn garment.”

During the demo, Swearingen held the pattern in front of his body on a rigid panel. It wasn’t printed on clothing, which would be a much harder test. Ink on a flat board stays exactly where the software expects it to be. Fabric drapes, folds and stretches. Sunlight, shadows, wrinkles, viewing angles and distance all change what reaches the camera.

Advertisement

Swearingen said most of his 31.7 million tests were digital, with patterns pasted onto images and scored by computer-vision models. The panel demonstration was a limited physical test using a model he said came from a fielded Flock Safety unit. Until a pattern works while printed on fabric, worn by a moving person and viewed through deployed hardware, he isn’t claiming that the clothing itself works.

On the left is a person wearing a plain black shirt. On the right the person is wearing a shirt with a pattern designed to confuse AI detectors.
In a noRecognition digital test, the detector reported the plain-shirt image as a person with 86% confidence but produced no person detection after the pattern was added.

The noRecognition website is promoting a Kickstarter-backed run of T-shirts, hoodies and neckwear, with each pattern scored against 11 models before it ships. Swearingen said the money would help pay for test fabrics, a dye-sublimation printer and additional cameras so he can see whether the patterns still work once they’re printed and worn.

So could a pattern on your clothing fool facial recognition?

Maybe. But the real test begins when he prints it on clothing and steps back in front of the camera.

Source link

Continue Reading

Tech

Android malware combo takes out loans and relays victims’ credit cards

Published

on

Android malware combo takes out loans and relays victims' credit cards

A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal card data and send it to attackers in real time.

In an incident investigated by the cybersecurity company Group-IB, a fraudster impersonated a bank employee and called the victim under the pretense of a problem with their payment card.

During the call, the threat actor instructed the victim to sideload the SpyNote RAT disguised as a legitimate app and grant it Accessibility Service permissions, giving the attacker remote access to the Android device.

image

To add credibility, the attacker personalized the malicious app label with the victim’s name.

Builder creates victim-specific SpyNote APKs
Builder creates victim-specific SpyNote APKs
Source: Group-IB

After gaining remote access to the device through SpyNote, the attacker installed WindRelay without further interaction with the victim and used the banking app to take out a loan in the victim’s name.


Advertisement

Additionally, the victim was instructed to tap their payment card on the phone and enter their PIN. WindRelay turned the phone into a fraudulent contactless reader and relayed the live NFC (near-field communication) exchange, including the card’s transaction-specific authentication data, to the attacker’s device.


This allowed the attacker to use the card data for purchases at a genuine payment terminal.


Advertisement

Group-IB says that the entire activity occurred in a 13-minute phone call, and transactions were approved using the PIN provided by the victim.


Attack chain overview
Attack chain overview
Source: Group-IB

The researchers highlight that the combination of SpyNote and WindRelay may indicate a toolkit that provides both access to the victim’s device for banking transactions and a direct cash-out channel.

Also, in contrast to most modern Android malware with live screen sharing and VNC features, this malware mix enabled the attackers to commit fraud solely through social engineering over the phone.

Android NFC malware is a growing problem, as shown by malware families such as NFCShare, NGate, SuperCard X, and RelayNFC.

In a typical attack, the victim installs a malicious app and grants it access to NFC. The attacker then uses social engineering to trick the victim into tapping their payment card against the compromised phone.

Advertisement

The phone uses its NFC interface to communicate with a contactless payment card and capture available data, which it then transmits over the internet to an attacker-controlled device.

Depending on the data obtained and the technique used, the attacker may be able to use it for fraudulent transactions or other financial theft, including ATM cash withdrawals.

The SpyNote RAT and variants such as SpyMax and CypherRAT have been circulating since at least 2021 and recorded an increase in detections in late 2022 and early 2023, following the leak of the malware’s source code.

The malware can steal bank data, Facebook and Google account credentials, Google Authenticator codes, GPS tracking, and SMS texts. It can also activate the device microphone and camera, and generic intercept keystrokes.

Advertisement

Group-IB has identified almost two dozen WindRelay samples submitted to VirusTotal between November 2025 and July 2026 that communicated with four command-and-control IP addresses.

According to the researchers, targeting appears focused on Czechia, Slovakia, and Slovenia, based on the organizations impersonated and the languages used.

Unless they know and trust the publisher, Android users are advised to avoid APK packages outside Google Play, and to be very careful with apps that request NFC access or other dangerous permissions.

When receiving a call from your bank and asked to take urgent action, it is advisable to terminate the call, dial the number listed on the organization’s official website, and ask to connect with the same support agent.

Advertisement

article image

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

Source link

Continue Reading

Trending

Copyright © 2025