Norton VPN has added support for split tunneling on MacOS as part of a wider push for feature parity across platforms and operating systems.
The feature allows users to specify the websites and apps they’d like to use Norton VPN for, while leaving the rest of their traffic untouched.
This can be useful for, say, accessing a website based in another country while streaming video content from your home region. Furthermore, some mobile banking apps or streaming services may block access entirely if a VPN is detected.
Advertisement
To use the new feature, open the Norton VPN app, head to the Settings tab, head to Connection Settings, and then select Split Tunneling to exclude specific apps and websites from the VPN connection.
As Norton VPN Product Lead, Himmat Bains, explained: “With Split Tunneling now available on Norton VPN for Mac, our customers have full control over which apps and websites travel through the VPN and which stay on their everyday connection.”
“This brings Mac users the same flexibility we already offer on Windows and Android,” he added.
Advertisement
Split tunneling is a staple feature across the best VPNs, but, despite MacOS officially supporting split tunneling, Mac users have seen slower rollouts for the feature, with some VPNs even removing split tunnel capability for years at a time.
Norton also shared that more updates are on the way for NortonVPN across various platforms, such as post-quantum encryption for its WireGuard protocol and manual IP shuffling for its iOS app.
Split tunneling and MacOS: issues and integration
MacOS has a fraught history when it comes to support for split tunneling (Image credit: Future)
Split tunneling has long been a point of contention for VPN users on macOS. While Apple’s desktop operating system does technically support split tunneling, user reports suggest that Apple services like FaceTime won’t work when a split tunnel is active.
While split tunneling capability returned to MacOS in 2022, VPN providers have been cautious in rolling out the feature. ExpressVPN, for example, only introduced split tunneling at the end of 2025.
Where split tunneling is implemented, it may have limitations not present on Windows or Linux computers. Mullvad VPN introduced split tunneling in 2024, with the caveat that it could not exclude Safari or Apple’s WebKit API from VPN connections.
And some of the best VPNs on the market still don’t offer split tunneling for macOS at all, including our pick for the best VPN overall, NordVPN.
Spring arrived at Eastnor Castle lake in Herefordshire with a surprise waiting for two of the most skilled bike riders on the planet. Danny MacAskill and Kriss Kyle knew only the broad outline of the day. They arrived ready to ride, yet the full scale of Red Bull’s construction floating on the water remained hidden until they stood on the shore.
Red Bull had created a gigantic floating obstacle course that stretched across the lake for nearly 200 meters. The entire structure sat directly on the water’s surface, posing a major engineering challenge. The platforms and beams that made up the course were placed on floats, causing them to heave up and down under the weight of a bike and rider each time someone passed through. The seesaws would also rock significantly merely by having someone on them, and you’d have to maneuver the narrow areas on the log skinnies without swerving off course even slightly.
【Excellent Motor Performance】This electric bike is equipped with a high-performance 750W motor(1500W peak power) with 2 to 3 speed settings…
【Upgraded Removable Battery】 Powered by a 48V 15Ah removable battery, the ebike can be fully charged in just 6-7 hours and can ride up to 60 miles…
【Comfortable Riding Experience】 This fat tire electric bike is equipped with front and rear suspension system, which absorbs most of the bumps and…
Then there were the wall rides, which would provide a moment of solid grip, just long enough to make you think you’re good to go, before the surface shifted beneath you again, and you’d be scrambling to maintain your balance. It would be a difficult decision to choose between bouncing across the ladder bridge on the poles and threading a sliver of a board along the edge. Then there are the zigzag parts, which are basically tight 90-degree twists on boards that are narrower than your tire, and the final length is just a tightrope-style pole run, where any slip sends you out into the liquid below.
Earlier that day, a few pro UK riders attempted the entire length, but none of them made it to the other side without getting drenched, as each effort ended with a large splash. That set the tone when the two Red Bull squad riders arrived. MacAskill switched from his typical trials bike to a trail bike since he’s known for being quite exact on a bike, but he was up against a new type of bike for the day. Kyle, on the other hand, has a history in BMX and chose a mountain bike. He ditched the bike he was regularly riding; having a shared platform for his BMX history and MacAskill’s trials upbringing required them to change riding techniques and learn to balance on bikes they were unfamiliar with.
Kyle stepped right in and launched a full-fledged all-out attack, throwing the aggressive style he’s known for at the floating sections while repeating the difficult elements until he was too exhausted to continue. Water got to him several times, but he kept going and made it all the way to the end. He’d clear a lot of portions and make it to the final poles on multiple runs, but the last bit always got the best of him. Eventually, his arms gave up and he lost control of the bike. He got within a hair’s breadth of the finish line several times, but ultimately ended up swimming.
MacAskill worked in a very different way. For a time, he just sat there, observing and studying to see how the entire floating section behaved, and then gradually built together larger and longer successful bits by connecting the smaller ones he’d already mastered. He solved each new challenge systematically, as is typical of his approach. Most of the day, he merely stayed dry by keeping his calm and working steadily through the course. First, the early sections were under control. The ladder bridge eventually gave way to the zigzags that had been wreaking havoc on the pro UK riders all day. By late afternoon, after hours of tinkering around, the light was beginning to fade. Everyone was exhausted, and their legs and arms were spent, but they still had at least one clean effort left.
Facepalm: Most people choosing a username would never imagine that someone with an almost identical handle – differing by just one character – was engaged in illegal activity, let alone soliciting a minor. This exact situation is what landed a Nova Scotia resident in prison for over a year for a crime committed by someone thousands of miles away in another country.
A Halifax man was recently cleared of all charges after spending a year and a half behind bars because an investigative error led to his conviction for possessing child sexual abuse material. The mix-up occurred because the police missed a single underscore while investigating a suspect’s username.
According to court documents, in 2018, investigators discovered that a 12-year-old girl in Wisconsin had been exchanging explicit messages and photos and participating in video chats with a man identified under the username “fus__roh_da” (after the shout from The Elder Scrolls V: Skyrim) on the messaging platform Kik. However, when Wisconsin police requested the man’s email address from Kik, they received an email address associated with the username “fus_roh_da” with one underscore between “fus” and “roh” instead of two.
Fattack
Advertisement
Whether the police or Kik misspelled the username remains unclear, but a single missing underscore is likely an easily missed detail, especially if the information was entered manually. Unfortunately for Brandon Klayme, the error would have life-changing consequences.
The misspelled username led investigators to Klayme’s Google account, after which Google provided them with his IP address. In 2021, Halifax authorities searched Klayme’s home and seized several of his electronic devices.
Despite finding no evidence linking him to the inappropriate chats, a Nova Scotia court convicted Klayme of child luring, making sexually explicit material available to a child, and possession of CSAM in 2023. In 2024, he was sentenced to 18 months in prison and 18 months of probation. Although police had obtained an image of the suspect from the chats and a physical description from the victim, CBC News reports that they could not extensively interview the girl, who was receiving treatment for depression.
Klayme’s lawyers did not discover the mix-up until spring of 2026, after he had already spent over a year in jail. The legal team claims that tracing the correct username would have likely led police to a California-based user.
Advertisement
The case highlights not only the dangers of clerical errors, but also the amount of identifying information that Google and social media companies can provide to authorities.
Photo credit: Sarang Sheth Insta360 keeps filing patents that point straight at the same light, easy-to-carry drones DJI has been selling to casual pilots and creators. The latest one, utility model CN223865117U, describes a compact aircraft with arms that fold completely into the body and a ring-shaped guard around the propellers. Images from the filing, first noticed in mid-July, show a small black chassis stamped with the company logo and a simple locking system that holds the arms open or closed. The entire package is designed to stay under 250 grams, the legal limit that lets many countries skip the more complicated registration rules.
These designs are more concerned with folding up and taking off than with camera features. Two structural arms rotate on a shaft and tuck together when folded to snuggle against one other. You have clearance areas between them to keep the propellers and motors from colliding when the contraption is folded up. There is a separate lock to keep everything safe until the pilot decides to take the thing flying. The end result is a form that resembles a thick smartphone rather than a traditional drone with fixed arms poking out. Early prototype photographs released accompanied the patent show the same black body and ring protectors during outdoor tests, and the drone is occasionally placed next to a shoe for size to get a sense of how little it is.
Insta360 already sells a high-end drone under their Antigravity sub-brand, the A1. That model weighs less than 249 grams and has a dual-lens camera capable of recording 8K 360-degree video. However, the new patent appears to be geared at a second, more basic machine that will not overlap with the A1. According to some sources, the new drone may still have a 360-degree camera for later refinding, while others point out that the patent drawings do not even show the fisheye lens. That could imply that the new drone will only feature a simpler fixed camera, resulting in a significantly lower price. In any case, the folding mechanism and protecting rings provide the design a distinct practical edge for anyone looking for something that can withstand being crammed in a backpack or jacket pocket.
DJI’s Neo 2 is in the same weight class as a standard rigid one-piece frame and has a flying time of around 19 minutes. It launches from the palm of your hand and has several extremely rapid cinematic modes that are simple to operate and take little expertise. Insta360’s method takes some of that simplicity and allows you to fold the drone flat to better protect the spinning parts while traveling. The company has spent years improving its FlowState stabilization and automated tracking in its cameras, so such features are likely to be here if the drone ever hits shelves. You can definitely expect on palm takeoff and simple one-button shots, as it follows a similar path to the Neo series.
Testing of the second prototype began as early as August 2025. Leaked photographs show it flying alongside the Antigravity A1, implying that Insta360 views the two vehicles as companions rather than competitors. One focuses on immersive 360-degree aerial footage, and the other strives for everyday portability at a lower price range, possibly around $200 if the camera remains basic. The release date is likely to be late 2026 or early 2027, after the company has completed refining the fold and the software that controls it. [Source]
Workers who use Microsoft software seem to be having as many conversations with Copilot AI as with real humans in Outlook and Teams, Microsoft said Wednesday during its fiscal year 2026 fourth-quarter earnings call.
“The number of conversations per [Copilot] user nearly doubled year over year,” Microsoft CEO Satya Nadella said on the call. “Average weekly engagement is on par with Outlook and Teams.”
There are over 30 million paid Microsoft 365 Copilot seats. And the way these workers are using AI is changing, too. Two months after Microsoft introduced Agent 365, a way for its business customers to build and use agentic AI, it has registered nearly 40 million agents across more than 10,000 companies, Nadella said.
“The agentic era is being built on GitHub,” Nadella said, referring to the developer platform Microsoft owns. “Every major coding agent runs on the platform, and one in three pull requests on GitHub now involves an agent.”
Advertisement
Microsoft beat investor expectations, reporting 18% revenue growth year-over-year for the quarter, which the company attributed to its AI and cloud services. Azure surpassed $100 billion in revenue for the first time ever. The company also attributed a $3.2 billion gain to its stake in Claude maker Anthropic. (Xbox severance and “impairment” charges were noted as hurting Microsoft’s financial health, as the parent company laid off 3,200 Xbox employees earlier this month, but that didn’t stop Microsoft from reporting just over $35 billion in net income.)
Like every other tech company, Microsoft has invested significant money and manpower behind its AI system, Copilot. And it seems its expensive bet on AI is possibly returning some cash on its investment; Nadella said Copilot revenue increased 60% quarter-over-quarter. But the spending isn’t slowing down; Microsoft added 31 new data centers across five continents.
The Redmond-based company has steadily and insistently integrated its AI into its software, which was already the backbone of corporate America. US adults say help with work is one of the main reasons they use AI, second only to searching for information, according to a recent Pew Research Center report.
Now, the company is betting not only that its customers will adopt AI, but that it will be so thoroughly integrated that it “transforms” how work is done – and how success is measured.
Advertisement
Moving past ‘time saved with AI’
In the early days of AI adoption, executives and tech enthusiasts were invested in the idea that AI tech could help employees do their work faster. Stories of AI automating repetitive processes and saving people hours of work were common.
Now, in the age of agentic AI, with agents that can autonomously complete tasks, the way people are using AI is changing.
Ideally, this should lead to “deeper cognitive work across the ecosystem,” Matt Firestone, general manager of product marketing for Copilot, tells me.
AI-native workers can distinguish between when they only need a quick answer from AI and when they need to use more advanced models or tools to handle more complex tasks, where there is also more human direction, engagement and approval.
Advertisement
“It’s not just about automating everything that we need to do to be more efficient. It’s about developing that judgment,” says Firestone.
And Microsoft has been busy building these more advanced, autonomous AI tools to help with those more complex assignments. Its Copilot Cowork uses a team of agents to write reports, send messages and do personalized analysis, all of which is grounded in your documents and messages. It’s very similar to Claude Cowork, which sparked fear across Wall Street when investors saw how productive it is at software tasks when it was released at the beginning of 2025. When testing Copilot Cowork and Claude Cowork with a Microsoft 365 connector, Microsoft found that using its own Cowork tool was on average 30% to 40% cheaper to run.
Microsoft has leaned all the way in on agentic AI. Scout, which Microsoft calls an “always-on personal agent,” was introduced shortly after at Microsoft Build; it’s specific to your Teams and Outlook messages, flagging important notes and helping you with meetings and assignments.
Having agents assist with deeper cognitive work, not just answering questions, helps companies prove the usefulness of AI – a way to expand the metrics by which we judge its success or failure. Instead of just looking at time saved, companies are now looking at how agents enhance workflows, do analysis that couldn’t be done by hand and handle specialized tasks outside of just software development.
Take Kantar, for example. The marketing data and analytics company has been steadily and thoroughly integrating Copilot AI and agents into its operations over the past two years, with its HR team, not software, leading the way. It used a system of 10 agents, grounded in the company’s existing policies and procedures, to handle some employee inquiries to HR, like requesting and generating employment verification letters. AI took over 40% of those kinds of requests since the tech was implemented, with a goal of reaching 95% by the end of the year.
Advertisement
Microsoft Copilot is increasingly present in the lives of workers who use Microsoft’s software.Adobe Stock
The human HR experts’ time was saved, but the AI agents also increased output, allowing human workers to focus on other projects. John Dicken, senior director of AI people solutions, says that applying an organizational lens to the company’s AI integration helped the company.
“A lot of people I talk to think of AI tooling as tech. I think of it as capability,” Dicken says. “It’s a technical solution to bring in capability to the organization in a different way, to bring new skills, new understanding, new knowledge, new approaches, new thought design.”
For some folks, that ability to take on more work means getting to tackle projects they’ve been waiting to have the time to do. But for others, it means having to do more work for the same pay. That can lead to a kind of AI-powered burnout, a University of California, Berkeley study found, where even with AI, we end up with longer workdays and worse work-life balance.
The ROI on AI is not just a matter of corporate talking points. Big and small businesses are paying big bucks to tech companies for the ability to run, license and personalize AI tools. And those tech companies, in turn, are asking investors for eye-watering sums to keep developing the models that power chatbots and agents.
It’s created a monster of a trillion-dollar industry, and measuring its success in multiple ways, beyond time saved, may be vital to proving its usefulness and avoiding popping the AI bubble.
Advertisement
Katelyn Chedraoui
Reporter 2
Katelyn is a reporter with CNET covering artificial intelligence, including chatbots, image and video generators. Her work explores how new AI technology is infiltrating our lives, shaping the content we consume on social media and affecting the people behind the screens. She graduated from the University of North Carolina at Chapel Hill with a degree in media and journalism. You can reach her at kchedraoui@cnet.com.
See full bio
Artificial intelligence came at just about the right time, speeding up app and software development as the world started to contend with skills shortages, but it changed the pace so much that security teams have not been able to keep up.
Recently, we’ve seen AI being applied across multiple other domains with role-specific agents and tools, but that’s introduced its own challenges. While tools like Claude Code have proven a hit for generating, reviewing and editing code in seconds, security-focused tools like Anthropic’s Claude Mythos family of models are having broader impacts on the industry.
Anthropic itself has even admitted that Mythos is so powerful that the worry it could be abused by malicious criminals is extremely real – the Preview model is currently only available to a select number of pre-approved partners.
Advertisement
Latest Videos FromTechRadar
So with AI now capable of inspecting code, discovering vulnerabilities and suggesting fixes, do organizations even need as many human workers on the case, or can they get by with significantly fewer humans in the loop serving as AI reviewers? Recent layoffs have certainly implied as much.
The evolving role of security workers in an AI-first world
But with the entire lifecycle of development now amplified by AI, experts are warning that companies could actually be creating more work for themselves, and more than they could ever handle, leaving them facing strains from angles they weren’t previously exposed to.
Advertisement
For example, fewer than one in 10 companies now fix 90% of identified vulnerabilities within 90 days – implying that the volume of vulnerabilities is indeed increasing, rather than that fix efficiency is slipping.
Anthropic even revealed that its around 50 early Mythos Preview partners discovered more than 10,000 high- or critical-severity vulnerabilities – and thousands more of lesser significance.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Advertisement
Checkmarx CEO Sandeep Johri predicts we could soon find a balance, where vulnerabilities volume matters less and we revert our focus back toward exploitable risks. I spoke with Johri about the evolution of AppSec, where AI is and isn’t useful, and how organizations can balance speed and control.
With the rise of AI coding tools and AI-generated software, some are questioning whether traditional application security practices are becoming outdated. Is AppSec actually becoming obsolete, or is it evolving?
Traditional application security is not obsolete. It is evolving to meet the reality of how software is being built today.
For years, the process was fairly linear: developers wrote code, security teams scanned it, and vulnerabilities were addressed later. That approach becomes much harder when software is being created at a much faster pace with the help of AI.
AI accelerates development and risk simultaneously: 70% of developers say AI-generated code created more vulnerabilities in 2025, according to our research. As code volume and complexity compound, security needs to move earlier into the development process, giving developers the tools and guidance they need while they are building.
Advertisement
Security teams will continue to play a critical role to help organizations develop software and maintain confidence in their enterprise applications. But their focus needs to shift from finding vulnerabilities to remediating them at scale, because we are tracking an enormous gap in most companies. Our data finds that fewer than 10% of organizations fix 90% of identified vulnerabilities in 90 days.
AI coding tools are helping developers create software faster than ever before. What new security challenges does this introduce for organizations adopting these technologies at scale?
The biggest challenge is that development speed is increasing faster than many security processes can keep up with. AI coding tools allow teams to create and deploy software quickly, but the code generated by AI still needs to be reviewed, tested, and secured.
Companies that ship 81-100% of their code with AI are nearly three times more likely to ship vulnerable code than those who use AI 1-20% of the time. This volume can overwhelm security teams with thousands of findings, many of which don’t represent meaningful risk. The priority needs to be identifying the vulnerabilities that actually create exposure and helping teams fix those issues faster.
Many organizations are looking to AI to help identify and fix security vulnerabilities. Why shouldn’t companies rely solely on AI models to secure the code that AI is helping create?
AI is a valuable tool for security teams, but organizations still need accuracy, context, and human oversight. AI can help identify patterns, analyze code, and accelerate remediation, but security decisions require confidence in what risks actually matter.
Frontier models can uncover hidden exploit paths, but they can also deliver inconsistent findings and false positives. Their results may change depending on the prompt, and they can still miss known critical vulnerabilities.
The challenge with relying only on AI is that organizations may create a false sense of security, or “automation bias.” AI models can generate code and help analyze vulnerabilities, but they need to be paired with security expertise and proven security practices.
Advertisement
The most effective approach combines AI-driven capabilities with strong security foundations, so teams can move faster while maintaining control over risk.
As companies adopt more AI tools throughout the development process, what are the biggest security risks they need to consider beyond just AI-generated code?
Organizations need to think beyond the code itself and look at the entire AI ecosystem being introduced into software development. Many companies are adopting AI tools, models, agents, libraries, and other components faster than they can establish governance around them. This creates visibility challenges because security teams may not know what AI technologies are being used, where they exist in applications, or whether they meet security requirements.
Another concern is shadow AI, where employees use AI tools without formal approval or oversight. Organizations need visibility, clear policies, and a way to manage these technologies as part of their overall software supply chain.
Perhaps the most urgent problem is the expansion of the attack surface itself. With LLMs, it has never been faster, cheaper, or easier for bad actors to exploit software. Issues that sat undetected for years are now being surfaced and weaponized at machine speed. Of the vulnerabilities Mythos has found so far, 99% haven’t been patched, according to Gartner.
How does the rise of AI change the role of security teams? Does the traditional approach to finding vulnerabilities need to shift toward a model focused more on prioritization, remediation, and continuous protection?
Identifying vulnerabilities is no longer enough when organizations already have more findings than they can realistically address. Security has to become continuous, embedded in development workflows, working in lockstep with developers, to build securely from the start while maintaining visibility and control.
We are shifting the focus to understand which issues create the greatest risk to give developers the context to address them fast, where code is written in the IDE.
Advertisement
Fidelity now matters more than volume. One verified true positive is worth more than a hundred low-confidence findings. If developers can’t trust what they’re shown, they’ll start ignoring it. That’s why organizations are increasingly looking at metrics like F1 score, which measure precision and recall together, rather than raw finding counts.
What does the future of application security look like in an AI-driven software development world? Will organizations need a different approach to balancing speed, innovation, and security?
The future of application security will require a more integrated approach. Organizations are going to continue adopting AI because the productivity benefits are significant, but security needs to evolve alongside that innovation.
Security will become more agentic, more intelligent, and more closely connected to the development process. Part of that evolution is combining deterministic, rules-based scanning with AI-driven reasoning in a single process, rather than running them as separate, disconnected tools. Deterministic methods catch what’s already proven; AI reasoning catches what’s novel. Together they’re more complete than either alone.
In addition, deterministic models have real cost advantages. Asking a frontier model to reason its way to security (i.e. extra review passes, self-generated threat models) burns tokens fast. That cost compounds the longer a vulnerability survives: cheap to fix in the IDE, more expensive in CI/CD, most expensive once it’s live in runtime. And every time a developer has to stop and pull a vulnerability out of code that’s already shipped, that’s velocity lost to rework instead of innovation.
Teams will need technology that can help identify real risks, support faster remediation, and provide visibility across the entire software lifecycle. The organizations that succeed will be those that make security part of how they build software, allowing developers to move quickly while reducing unnecessary risk.
Advertisement
For organizations that are embracing AI coding tools today, what steps should they take to make sure they can innovate quickly without introducing unnecessary security risks?
The first step is visibility. Organizations need to understand where AI is being used, what tools are being introduced, and what impact those tools have on their applications.
Remediation is far cheaper the earlier it happens — catching an issue in the IDE costs a fraction of catching it further down the pipeline. But there’s another unsettling gap in our research: nearly all developers have access to in-IDE security tools, but fewer than one in five actually secure code as they write it. The cost of fixing that issue compounds as it passes through later stages of development.
In addition, organizations need clear governance around AI adoption, because only 22% currently have formal AI governance policies in place. That means defining policies, monitoring usage, and making sure teams have the right security controls as they continue to innovate.
AI will continue to change software development. The companies that benefit most will be the ones that embrace the technology while building security into the process from the beginning.
The Federal Trade Commission is suing Hims & Hers, accusing the telehealth company of sharing customers’ sensitive health information with advertising platforms including Meta and Snap.
The complaint, filed on 29 July and joined by Utah and California, also alleges the company charged people without proper consent and made subscriptions deliberately hard to cancel.
The privacy claim is the most serious. The FTC says Hims & Hers passed customers’ health details to third-party advertisers, through uploaded customer lists and automatic tracking that fired off user actions to the platforms, echoing how hospital websites have leaked patient data despite promises to protect it.
The data at issue is not trivial. Hims & Hers sells treatments for conditions people rarely discuss in public, from hair loss to erectile dysfunction to mental health, which makes an alleged leak to ad platforms unusually sensitive.
Advertisement
Hims & Hers has grown into a telehealth giant on exactly these categories. It expanded into weight-loss drugs and built a subscription model that turned stigmatised prescriptions into a mass-market online business, which is why the data it holds is so revealing.
The billing allegations run alongside. The FTC says customers were charged the moment they submitted an intake form, even though the company implied they could speak to a provider first, and were enrolled in recurring subscriptions without a clear chance to review their options.
Then came the hard part: leaving. Before 2023, cancelling required contacting customer service by phone, email, or chat, and even after Hims added an online option, the FTC says it buried the cancel button behind multiple steps, a textbook dark pattern of the sort the agency has been chasing across the web.
The agency’s language was unsparing. Consumers were “unknowingly locked into recurring subscriptions” while their “most private health information” was disclosed to third parties, said Christopher Mufarrige, the FTC’s consumer-protection director.
The legal basis spans several laws. The complaint leans on the FTC Act, the Restore Online Shoppers’ Confidence Act, and consumer-protection and false-advertising laws in Utah and California, a multi-front case rather than a single charge.
Advertisement
The market reacted at once. Hims & Hers shares fell about 10% on the news, a sign investors read the suit as a real threat to a company whose growth has been built on frictionless online sign-ups.
The case is part of a wider reckoning. Regulators have spent the past few years pursuing health and wellness services that quietly fed sensitive data to ad platforms, and Hims & Hers, with its scale and its intimate categories, is a high-profile target.
Meta and Snap are not the defendants, but they hover over the case. The tracking tools at issue are the advertising pixels and data pipelines that power much of the online ad economy, and health data flowing into them has become a recurring legal flashpoint.
The legal gap is part of the problem. Federal health-privacy law was written for hospitals and insurers, not for ad-funded apps, which has let sensitive data flow to platforms in ways patients rarely understand.
Advertisement
The dark-pattern allegations may resonate more widely. Hard-to-cancel subscriptions are a familiar consumer grievance, and the FTC has made them a priority, so a case pairing privacy breaches with a buried cancel button is one it will want to win in public.
Hims & Hers did not comment in the FTC’s announcement. The company has grown fast by making telehealth feel as easy as ordering anything else online, and the suit argues that some of that ease came at the customer’s expense.
The commission voted 2-0 to file. The case now heads to federal court in northern California, where the questions will be whether the data sharing broke the law and whether the sign-up and cancellation flows crossed from aggressive into deceptive.
For a sector built on convenience, the message is pointed. Telehealth promised to strip the friction out of getting care, and the FTC is now testing how much of that friction was removed from the company’s side and quietly added to the customer’s.
We covered Amazon’s $99 AirPods 4 deal yesterday, and today AirPods Max 2 are $100 off, bringing the over-ear headphones down to $449.
AirPods Max 2, which were released in 2026, are $100 off at Amazon today, with all five color options eligible for the triple-digit markdown at press time.
This AirPods deal reflects the lowest price seen this month on the over-ear headphones. In our hands-on AirPods Max 2 review, we found the 2026 release delivers better active noise cancellation (ANC) and great call quality.
Advertisement
On the earbuds side, AirPods 4 and AirPods Pro 3 are on sale as well, with prices as low as $99.
Today’s best AirPods deals
AirPods Max 2 highlights
Powered by Apple’s H2 chip
Up to 1.5x stronger Active Noise Cancellation than first-gen AirPods Max
Transparency mode
Adaptive EQ
Lossless Audio and ultra-low latency audio via a wired USB-C connection (requires a supported service)
Netscape still ruled the browser market, but Microsoft had Windows 95, WorldNet, and a very valuable foothold
It is 30 years since AT&T handed Microsoft a valuable foothold in the browser wars by making Internet Explorer 3 the default for its WorldNet service.
Windows 95 was barely a year old when AT&T set out to challenge CompuServe and America Online with its WorldNet service in 1996. The telecommunications giant needed a browser. Netscape Navigator dominated the market, but Microsoft was keen to make up lost ground.
Advertisement
A promotion and distribution agreement was announced on July 25, 1996, with a further announcement in October.
Under the deal, AT&T WorldNet software was included in versions of Windows 95 supplied to PC manufacturers, with Internet Explorer 3 designated as the service’s default browser. Netscape Navigator remained available, but Internet Explorer secured the valuable default slot.
Microsoft’s browser-bundling strategy would later draw antitrust action on both sides of the Atlantic, including the EU’s browser choice screen in 2010.
At the time, Tom Evslin, Vice President for the AT&T WorldNet Service, said: “Users now will find that everything they need to sign up for AT&T WorldNet Service is pre-loaded on their new computers, along with the Microsoft Internet Explorer 3.0 browser.”
Advertisement
Thirty years on, Evslin told The Register the deal came down to price. AT&T had to pay per copy activated, and he reckoned Microsoft pretty much gave its browser away (but wasn’t completely sure – it was, after all, a long time ago). Netscape Navigator was, however, better known at the time, and so was offered as an option.
By January 1997, Microsoft claimed Internet Explorer’s corporate usage had more than tripled since August while Netscape’s share declined. WorldNet was also attracting users by offering straightforward internet access rather than another AOL-style walled garden.
It rapidly became the world’s largest ISP by one contemporary measure, although it eventually wheezed its last in 2010. Internet Explorer proved more influential, dominating the browser market for more than a decade before its grip began to loosen in the late 2000s.
AT&T’s choice was only one factor in Internet Explorer’s rise, but it put the browser before WorldNet’s growing audience just as users were moving beyond the walled gardens of AOL and CompuServe. Microsoft may have been late to the browser game, but it already controlled the operating system on millions of PCs.
Advertisement
Three decades later, the deal remains an early demonstration of the value of being the default. ®
[Evgenij Spitsyn] spotted a KVM build on these very pages some time ago. That inspired their own build, leveraging the versatility of the ESP32-P4 microcontroller.
The concept is straightforward. Named the ESPKVM, the device is designed to hook up to a computer’s HDMI and USB ports. It captures the video output, while presenting itself as a standard keyboard and mouse device. In this way, it allows remote control of the machine over IP. It achieves this feat with the aid of the Toshiba TC358743 HDMI-to-CSI bridge, which is essentially the video capture hardware of the build.
The video output of the machine is streamed in MJPEG or H.264 format. The device is capable of serving up storage from a micro SD card or the onboard flash, as well as handling things like power/reset control and wake-on-LAN. All in all, it’s a very complete package, and full of useful features. Just don’t use it over the public internet yet — [Evgenij] notes it hasn’t been reviewed for potential security holes yet, even though it has some basic authentication features baked in.
Advertisement
If you’ve got an ESP32-P4 ready to go with a TC358743 HDMI bridge, you can actually head over to the ESPKVM website and flash the code right in your browser to get going. Meanwhile, if you found this build interesting, you might like to scope out the one that inspired it. If you’re cooking up similar utility hacks, be sure to notify the Hackaday tipsline.
Survey finds more workloads run off-site than at in-house corporate facilities for the first time
IT is going remote while sucking up more power.
Most corporate IT is now off-premises for the first time, according to Uptime Institute, while the average rack power density has crested above 11 kW for the first time as server fleets are gradually replaced with more powerful hardware.
Advertisement
Uptime’s Global Data Center Survey 2026 reveals how the industry is managing to adapt to challenging circumstances, with the usual evergreen concerns over rising costs plus staffing and skills shortages. The survey polls more than 800 datacenter owners and operators across multiple countries, with more than half (52 percent) in North America and Europe.
Off premise dominates: Every year, Uptime asks its enterprise respondents to estimate what percentage of their IT workloads are run in-house versus in third-party facilities.
For the first time, third-party sites have the larger share, accounting for 46 percent of IT workloads, compared with 44 percent residing in enterprise-owned corporate server farms.
Those figures don’t add up to 100 percent, as some respondents (10 percent) say they are using IT rooms and server cabinets rather than a dedicated facility.
Advertisement
Uptime’s experts estimate that, by 2028, the proportion of workloads in self-owned server halls will remain the same, while those running in third-party sites will expand to 48 percent, eating away at those currently based in IT rooms and server cabinets.
More power: While the headlines have featured AI infrastructure pushing IT infrastructure power density to 120 kW per rack or even higher, the reality is that most datacenters and servers operate at a much lower level than that.
This year, the average of the most typical rack densities now surpasses 11 kW, as a gradual ongoing shift toward higher-powered hardware was compounded by a small number of new high-density facilities with racks above 30 kW.
Without those few high-density facilities skewing the average, it sits at 7.8 kW, just slightly up from 7.5 kW in 2025.
Advertisement
The majority of facilities still do not have any racks of 30 kW or above, Uptime finds, but more respondents (24 percent) now say they have some of these, compared with 19 percent last year. The increase was mostly in the 50-plus kW ultra-high-density range, including some respondents deploying AI and GPU servers into racks configured for above 100 kW.
The trend for rising rack density will continue as organizations upgrade their infrastructure with newer hardware. Updated servers boost both workload capacity and energy performance, but maximizing these benefits means a corresponding rise in overall system power, Uptime states.
Refresh shortened: Some operators are also pursuing more aggressive technology refresh timelines of less than 4 years, the report claims. If true, this would be the reverse of what some hyperscalers such as Microsoft, Google and Meta have been doing in recent years, extending lifecycles out to 6 or 7 years to save on depreciation expenses.
Outages: When it comes to outages, this year’s report shows improvement for the sixth year in a row, with the number of respondents who experienced an outage in the past three years down by three percentage points.
Advertisement
But Uptime warns against complacency, noting that many of the factors behind outages, such as reduced or unstable power availability, local grid reliability, supply chain constraints, and extreme weather, are on the increase.
The flip side is that the costs of any outages that do occur continue to rise. This is because organizations have become more dependent on digital infrastructure, the report says, and so outages may have more financial impact than in the past.
Overall, 71 percent of survey respondents reported that their most damaging outage cost at least $100,000, compared with 57 percent a year ago.
Staffing shortage: Staffing has long been an issue for datacenter operators, and this year the greatest skills gaps reported were in electrical (38 percent of respondents), junior level operations (38 percent), operations management (35 percent) and mechanical roles (34 percent).
Advertisement
However, more than half (53 percent) of operators report difficulties finding qualified candidates for vacant roles, up from 46 percent a year ago.
Finally, Uptime found that financial pressure and resource constraints continue to grow among operators. In fact, the high prices of power, staff, and equipment, particularly for AI-related infrastructure, is the primary issue. Alongside that are escalating concerns over capacity forecasting, power availability and supply chain disruptions. ®
You must be logged in to post a comment Login