Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
The chain of events leading up to OpenAI’s agents attacking Hugging Face and other organizations in July began months earlier, and involved agents asking other agents for help, building message boards, and even becoming paranoid that other agents were maliciously trying to trick them, two OpenAI staffers said at the Black Hat infosec conference on Wednesday.
By now, everyone knows the bones of this story: OpenAI models broke out of their testing sandbox, exploited zero-day vulnerabilities to gain access to the open internet, and broke into Hugging Face and other organizations during an ExploitGym security evaluation.
In their Wednesday talk, OpenAI technical staffer Michael Dalton and researcher Eric Wallace provided new details about the security incident including notes that AI agents uploaded to an internal package manager, which were then shared across OpenAI’s infrastructure. These notes show the “model’s chain of thought…its internal monologue,” Wallace said.
The duo also revealed that groundwork for the rogue agents hacking into outside services began on May 7, when OpenAI kicked off a training run for an experimental, internal model that has not yet been released. “What we didn’t realize during this process is that there was actually a few impossible or very hard tasks in the training center,” Wallace said.
The tasks instructed the model to complete missing formulas in an Excel workbook that used links to Google Drive. Yet OpenAI blocked the model’s internet access so it couldn’t reach the cloudy spreadsheets.
“It realized, ‘I’m kind of stuck on the task,’ but it didn’t give up, and we gave it a lot of tokens to work with,” Wallace said.
The model eventually decided to attack JFrog’s Artifactory service to gain access to the internet, first attempting (unsuccessfully) to launch a server-side forgery request. This exploit doesn’t work, but in the process the model learned it could upload files to Artifactory.
A few days later, OpenAI gave another agent another impossible task, this time finding a protein database file – but the engineers forgot to upload the file into a container for the agent.
“At some point, it gets so stuck and thinks: ‘Maybe I could reach out to another agent because maybe somebody else out there has a file?’ And then the model realizes that it could communicate by uploading code,” Wallace said.
The model did that by writing a file into Artifactory asking for help.
Over the next couple of days, other agents realize this message board exists on Artifactory and they also start uploading files and sharing information.
“A few days later is when our models found the first actual exploit in our system related to this incident, where they’re able to get internet access in ways they didn’t intend,” Wallace said.
This happened on May 26, when the agents successfully launched a server-side request forgery attack against Artifactory, giving them internet access with specially crafted requests.
On June 11, OpenAI began training a “highly persistent” experimental model, intended only for internal use, Dalton said. “During this time, the SSRF vulnerability has been written to the messaging board,” he added. “Other models are aware of it, and the message board is still functioning. Models are actively communicating with it.”
On June 26, the agents exploited a zero-day vulnerability leading to remote code execution in Artifactory. The same day, models achieved remote code execution in Artifactory through a previously unknown vulnerability. “You could use a legacy token refresh endpoint, pass a token with an invalid signature, and be given back a token with a valid signature with administrative privileges,” Dalton explained.
The agents then used the admin token to establish command-and-control via a Groovy plugin that functioned as a command-execution service.
“This in turn causes quite a bit of activity by the models on Artifactory – you can see some colorful wording here in the model’s chain of thought to summarize the model’s response to this result,” Dalton said, pointing to a slide that shows the model’s own words:
Holy shit reader is ADMIN?
We can read config/users!
Earlier assume not due to UI.
The agents’ activity overloaded Artifactory and caused an outage, which is when OpenAI’s engineers stepped in and opened a formal security incident and response process. “We identified the agents had taken over the internal Artifactory, identified that a zero-day vulnerability had been found exploited by the agent in Artifactory itself, and we began remediation.” Dalton said.
OpenAI revoked the credentials that the agents used to post messages, rebuilt its hosted Artifactory, and notified the vendor about the vulnerabilities.
Two days later, on July 8, the agents reestablished the message board using an unauthenticated web data endpoint in Artifactory to create directories and develop communication protocols. “The directory names effectively serve as a message board between the agents in the same way the files used to.”
The agents communicated through very long directory names that contained the messages such as “remote…probe_PENDING_HOLD_SWARM_until_confirm.”
The agents collaborated with each other so one agent could pick up the work where another left off. In one instance, the model reasoned: “Help peer. But our task doesn’t benefit. Yet collective may yield generic route if someone frees time.”
Anyone else getting “We are the Borg. We will add your biological and technological distinctiveness to our own” vibes there?
Wallace said the models behaved like humans in that they stepped on each other’s toes when one overwrote another’s repository.
“Whoa, critical! Did someone overwrite our repo? We must act,” it reasoned.
“You can clearly see some sort of verbalized tension between the different models as they run this evaluation,” Wallace noted. “At some point, even the agents are convinced there’s an impostor amongst them,” reasoning that there could be another agent maliciously spoofing on the message board. “Share board unauthenticated, names can be posed by anyone,” it reasoned.
We know the rest of the story.
Hugging Face disclosed an autonomous attack by AI agents. OpenAI reached out to Hugging Face to determine if it had been affected and then realized its models were the hackers.
“One of the reasons we wanted to have this talk is to share our lessons learned with you as defenders,” Dalton said. “We believe this is a watershed moment for computer security as an industry. AI orchestrated, fully automated offensive attacks are real now, and the actions we have discussed today were an unintended side effect of running evaluations on frontier AI. In the near future, we should expect that threat actors will intentionally deploy, optimize, weaponize, and use offensive agent collectives in the manner that you have just described here.”
The challenge to defenders, he added, is to similarly accelerate defense, and find ways to automate incident response along with vulnerability detection and patching.®
A couple of weeks ago we discussed how the cuts made to HHS and specifically the CDC’s FoodNet tracking platform were making it much harder to track and back trace the source of the country’s current cyclosporiasis outbreak. You’ll have heard about this outbreak in the news by now. It’s the one where you begin pooping yourself uncontrollably. It is not, however, funny. 10% of cases will result in hospitalization. The most recent counts from the CDC suggest that there have been more than 22,000 cases of the illness across 15 states. Those numbers are very much in question, however, both due to general underreporting and, again, funding and staffing cuts at CDC.
Just this week, in fact, we have now learned that two people in Michigan have died from cyclosporiasis. That information was and is, at the time of this writing, missing from the FDA’s dedicated page to inform the public on the outbreak. That page hasn’t been updated since July 24th, in fact, which is the exact opposite of what you’d want the government to be doing in a public health emergency. And it’s reportedly not because the government isn’t aware of these deaths.
While news of the deaths made widespread headlines Monday, federal health agencies under the Trump administration were mostly silent. The Food and Drug Administration—which is conducting traceback investigations to identify foods contaminated with the parasite—has not updated its outbreak investigation page since July 24, nearly two weeks ago, as of publication time.
The Centers for Disease Control and Prevention, meanwhile, added a banner notice on its outbreak update webpage saying that the agency was “aware” of the two cases. But its reporting data was not updated to include the two deaths as of this publication.
Why has this government been so slow to report accurately on these unfortunate deaths and the overall case counts for the outbreak? Some combination of those same budget and staff cuts along with a general apathy at HHS. With fewer people and resources to not only track the disease, but to maintain the dashboards meant to update the public, the numbers are slow to come in and untrustworthy when they do.
And with RFK Jr. at the helm of public health, well, the government is generally in the land of We-Don’t-Give-A-Shit.
Two weeks ago, Kennedy confidentially told reporters that the Cyclospora outbreak—linked to lettuce and other unidentified fresh produce—was “under control.” Last week, he announced his own cooking show on YouTube and released the first episode in which he helped prepare a meal that included a fresh salad.
The buffoonery on display from Kennedy and our health agencies is breathtaking. They should be assisting in combating this outbreak, along with those of measles and pertussis. Putting that aside, they should at least be able to tally up the case count numbers to demonstrate their own failures, but it’s clear they’re not really interested in doing that either. Instead, Kennedy in particular wants to host his cooking show and yell at journalists instead. Kid Rock must not be returning his calls any longer, I suppose.
Now, to be clear, this illness carries a 2 week incubation period, and the recalls of the suspected produce that is believed to have caused all of this are within a time frame that cases may still be stemming from that same source. But that’s not a certainty, and it will be important for our federal health agencies to continue to track cases in near real time to determine if there is, in fact, another vector by which cyclosporiasis is spreading.
Unfortunately, every indication is that those same health agencies just aren’t all that interested in doing this the right way.
Filed Under: cdc, cyclospora, foodnet, health & human services, rfk jr.
AI AND ML
Muse Code showcases Muse Spark’s fresh software engineering chops
To demonstrate the capabilities of its next-generation Muse Spark model, Meta has released a terminal coding agent called Muse Code that it thinks can help developers to tidy up their software projects.
Meta co-trained Muse Code on version 1.2 of its Muse Spark model, also released this week and now apparently boasting improved code generation smarts.
Developers can think of this beta release as the equivalent to OpenAI Codex or Anthropic’s Claude Code, two other LLM-based service offerings tweaked for the modern coder. Meta designed its new agent to be handy at planning changes to a codebase, writing the code and validating the results.
Currently, Meta has Muse Spark locked away as a proprietary, closed-weight model hosted in the cloud, an approach its rivals also embrace but which departs from the open-weight approach Meta previously implemented with its Llama models.
But Meta CEO Mark Zuckerberg did not rule out opening up Muse Spark in the future. “I’ll have more to share on that soon,” he replied to a question posed on X about Muse Spark being open source.
Muse Code is best described as an agent orchestrator that runs on your command line.
As Zuck noted in a series of X messages, when a developer starts a task, Muse Code fires up background agents to maintain a context file that other sub-agents doing the work can consult should they lose their way. The tool logs every action before execution, so no work is lost. Multiple agents can work in parallel on the task using their own isolated work trees.
“Your working copy is never touched,” Zuck wrote.
In one test, the agent platform simultaneously built six features for a single game, with no collisions among the agents, Zuckerberg enthused.
“TBH it’s a good harness,” boasted Hongyu Ren, a researcher for Meta’s Superintelligence Labs, on X.
Muse Code relies on Meta’s Muse Spark Large Language Model (not to be confused with the Apache Spark big data cruncher).
Muse Spark 1.2 is the third release in four months from Meta Superintelligence Labs, a unit that Meta stood up in June 2025 to reinvigorate the company’s AI efforts and pursue creation of a personalized AI “superintelligence” that focuses on deep reasoning and long-horizon planning.
The first model from this group, Muse Spark, is a multi-modal model able to digest and reason against text, images, video, audio, and even PDFs. It supports agents in long-running tasks.
With the first release of the model in April, Meta boffins admitted in the announcement that they needed to work more on Spark’s coding abilities. The new 1.2 release addressed that deficiency.
In another test, Muse Spark, running on Nvidia Hopper GPUs, tackled a kernel optimization task. Its agents made over 1,000 tool calls over a 24-hour period.
“It kept finding substantial improvements well beyond the initial exploration phase,” Zuckerberg wrote.
In his X missives, Zuckerberg included a somewhat vague chart comparing the performance of Muse Spark against other commercial models, using two industry benchmarks – Terminal-Bench 2.1 and DeepSWE 1.1 – that evaluate how autonomous agents act like software engineers, as well as a Meta Internal Coding bench too.
The benchmarks all showed Muse Spark to be close to the best, but never the very best, at understanding the assigned engineering task and executing it with as little mission creep as possible. Muse Spark performed honorably compared to Opus 5, GPT5.6 Terra, Grok 4.5 and Gemini 3.6. The scores are tightly clustered, so they all did well (except occasionally Gemini, the current laggard du jour).
So, Muse Spark is competitive anyway, though one eagle-eyed commenter wondered why OpenAI’s midline GPT5.6 Terra was used, instead of the top-tier GPT5.6 Sol.
Installing the agent within your command line is possible through a curl command. Poly-model enthusiasts can also tap into Muse Spark via OpenRouter, or through its API.
Muse Spark’s actual intelligence is metered at US$1.25 per million input tokens and US$4.25 per million output tokens. Discounts are available and the service offers a respectable 1 million token context window. ®
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network.
The attack was discovered by Huntress on July 27, 2026, after its security platform detected credential theft on a server hosting an Oracle database server.
Apache access logs showed that the attackers gained access through a vulnerable search engine endpoint in a public-facing Java application running Apache Tomcat.
The application failed to properly validate input submitted through an autocomplete search feature that allowed the attackers to issue SQL commands to the Oracle database.
Huntress traced the malicious requests to the IP address 178.162.151[.]229.
After exploiting the SQL injection flaw, the attackers installed a post-exploitation toolkit called khunt directly into the Oracle database as a Java object.
Oracle has an embedded Java Virtual Machine and the CREATE JAVA SOURCE statement, which allows Java source code to be stored and compiled as a database schema object.
These Java objects can then be executed via SQL commands, which if configured to do so, can execute commands on the host operating system.
The attackers abused this functionality to compile and store the khunt toolkit directly inside the Oracle database rather than deploying them as executable files on the server.
“The use of the technique in the wild has rarely been documented,” Huntress said.
The toolkit contained multiple Java components and PL/SQL wrappers that could execute commands, steal credentials, and manage files.
These components included:
The attackers used KhuntCmd to run cmd.exe /c whoami, confirming that commands executed through the Oracle database had SYSTEM-level permissions on the Windows server.
They then used PowerShell and Windows utilities to copy the SAM, SECURITY, and SYSTEM registry hives, which can be used to recover password hashes for local Windows accounts.
The attackers also ran tasklist /svc to enumerate running services and saved the output to khunttasks.txt.
Huntress said the registry hives were likely exfiltrated for credential dumping, but the report does not confirm whether the files were successfully stolen.
As a general rule, organizations should sanitize all user supplied input validation and limit the privileges granted to application database accounts.
Huntress recommends that database accounts used in public-facing applications should not have high enough privileges to create Java sources, execute unnecessary stored procedures, or perform other administrative actions.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Thousands of Internet-connected servers sold by the world’s biggest manufacturers can be remotely backdoored by exploiting critical vulnerabilities—some more than a decade old—that lurk deep inside system motherboards, according to research presented Wednesday.
Baseboard management controllers are miniature computers that are embedded into the motherboards of virtually every enterprise server. The microcontrollers, typically abbreviated as BMCs, run with their own operating system firmware, network stack, and IP address. Administrators rely on them to monitor the physical status of large fleets of servers and to perform a variety of tasks, including rebooting machines, installing updates, and even reinstalling operating systems. BMCs provide what’s known as “lights out” and “out-of-band” management because they work even when servers they’re attached to are turned off or are unresponsive.
Researchers have warned since at least 2013 that BMCs present a golden opportunity for hackers looking for ways to gain deep and persistent access to datacenters. The chief culprit was IPMI, the protocol that allows BMCs to operate independently of servers and to perform administrative tasks. Vulnerabilities in this firmware made it possible for attackers to remotely execute malicious code on the controllers and, from there, infect the servers they manage.
Michael Dell has posted a photograph of a fairly unique single sheet of paper to X and LinkedIn: the quarterly financial statement for PC’s Limited, dated 31 July 1984, produced from a dorm room at the University of Texas at Austin.
The page shows roughly a million dollars in sales, about $198,000 in gross profit, and net income of $134,762.75 for the three-month period.
The then 19-year-old Dell had just finished his freshman year as a pre-med student, and had started the business with $1,000. He used the statement to persuade his parents that he should not go back for his sophomore year.
Latest Videos FromTechRadar
This one page changed my life.42 years ago today, it convinced my parents I shouldn’t go back to college.I started by upgrading PCs from a dorm room.Today @Dell is helping build the infrastructure that powers AI, from the edge to some of the world’s largest AI factories.… pic.twitter.com/OF3KTMrBeHJuly 31, 2026
Nothing on the page suggests or requires a leap of faith. It suggests the opposite: a 19-year-old who had already been running a business through an academic year, who had generated close to a million dollars of turnover, who had kept books well enough to separate gross profit from net income, and who understood that the way to win an argument with two skeptical parents was to hand them a profit and loss statement.
The decision to leave college was not a gamble that happened to pay off. It was the conclusion the numbers already supported, and Dell was sharp enough at 19 to know that presenting them in a document would carry more weight than simply presenting them as enthusiastic conversation starters.
The decision that followed allows Michael Dell to command a $236.7 billion net worth, as reported by Forbes, and to lead a company with a market cap north of $270 billion. What makes Michael Dell’s story unique, however, is that it isn’t the typical dropout-founder story usually told as one about conviction outrunning evidence. The document he brought to the table is evidence outrunning conviction.
It raises an interesting parallel: The question one needs to ask is not whether to bet on yourself, but at what point do you have enough data to stop calling it a bet and start calling it a data-driven conclusion.
It is also worth noting that this is not the page’s first outing. Dell posted the same statement to Twitter in March 2018, describing it then as the document he used to convince his parents “it was OK for me to not go back to college”.
What the document shows, when read carefully, is a teenager who has figured out something about persuasion that many people twice his age never do. His parents were not going to be moved by a description of the market for IBM-compatible upgrades.
They were going to be moved by a number they could check, printed on a page, covering a period that had already happened. Dell did not ask them to believe in the future of the personal computer. He showed them what he had already earned and let them draw their own conclusions.
The result was a computer-centric giant that makes many of the desktops, laptops, and servers that power the modern world and is synonymous with reliable tech for many users. One could argue that the singular page did not change his life. The quarter behind it did. The page was just the format he could use to prove it, and the rest is history.
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Mower decks live a hard life. Every time you mow, the deck and chute are battered by rocks, dirt, sand, and anything else hiding in your lawn. On top of that, even dry grass carries enough moisture that the underside of the deck gets wet every time you mow. It’s hardly surprising that rust and cracks can spring up.
Over time, vibration from the engine and impacts from hidden obstacles slowly expand small weak spots into visible cracks. Meanwhile, manufacturers do their best to protect against corrosion with paint, powder coating, or galvanization, but exposure is inevitable. The spinning blades effectively turn the inside of the deck into a sandblaster. Stones and debris chip away at protective coatings until bare metal is exposed. Once moisture reaches that metal, rust begins its slow but relentless work.
Fortunately, with the exception of plastic mower decks, many cracked mower decks are often repairable by welding. Most mower decks are made from mild steel, which is a relatively straightforward material for MIG welding. Alternatively, some premium or commercial mowers use aluminum decks, and while it’s certainly possible, aluminum welding is significantly more demanding. This is usually a job for an experienced TIG welder, notably one of the most difficult welding techniques to learn, demanding precise two-hand coordination, strict temperature control, and consistent arc-distance management.
To avoid the costly task of replacement, welding is an increasingly popular solution to fix a damaged mower deck. But there’s a big difference between booger welding a crack shut and repairing it well enough to safely contain a set of two-pound blades spinning at 3,600 RPM. That’s something worth considering before breaking out your garage MIG welder.
A weld won’t return a mower deck to its as-new condition. But it can return some structural integrity by joining cracked metal back together, preventing further movement and damage. This is particularly valuable around mounting brackets, wheel supports, or spindle housings where vibration imparts persistent stress.
If welding is your preferred solution, preparation makes the difference between a repair that lasts years, and one that fails during the next mow. Every trace of paint, grease, dirt, and corrosion should be removed before striking an arc. Because mower decks are relatively thin mild steel, continuous welds can easily burn through or distort the panel. Instead, short overlapping stitch welds that gradually build strength while limiting heat input are generally better suited. If you’re repairing a crack, drilling a small hole at each end first, a technique known as stop-drilling, can prevent further tearing.
However, welding is useless in the presence of rust. Rust isn’t metal; it’s corrosion that has consumed the base material. You can’t weld rust. To address this, cutting away rusted sections and welding in a patch or plate will provide a longer-lasting repair.
Regardless, the decision comes down to the structural integrity of the machine. Anyone who’s seen a mower throw a blade understands why correct mower use and maintenance is so important. The deck isn’t just somewhere for John Deere or Stihl to put their sticker; its purpose is to contain blades and debris spinning and deflecting at enormous speed. Therefore, makeshift or jury-rigged repairs should be well considered before relying on them as your last line of defense in those violent few seconds that follow the snap of a blade retaining nut.
Whether welding is worthwhile ultimately comes down to the condition of both the deck and the nature of the damage itself. A clean crack in otherwise solid steel is usually an excellent candidate for a weld repair. Even larger damaged areas can often be saved with fabricated patches, plug welds, or reinforcing plates if there’s enough healthy metal remaining to support them. These repairs can significantly extend the life of an expensive deck, at a fraction of the replacement cost.
However, further consideration is necessary when rust has spread across large sections of the deck, or into any of the key structural brackets or mounts. Corrosion often extends much further than any visible marks, leaving steel paper-thin and ready to crack elsewhere. Welding one area may simply move the stress to another weak section, resulting in an endless cycle of repairs. In these cases, replacing the entire deck is often the safer and more economical option over the long term.
There’s also the question of cost and skill. Mild steel decks are well within the capabilities of many competent welders using MIG equipment, but paying for professional aluminum repairs can sometimes approach the price of a replacement deck.
So, a cracked mower deck can be welded, provided the surrounding metal is still structurally sound. But before firing up the welder, consider whether you’re repairing a crack in an otherwise healthy deck or trying to save one that’s already been claimed by severe damage or extensive corrosion. How that question is answered will usually tell you whether welding is a smart investment or whether it’s time for a replacement.
TechRadar’s Computing team tests dozens of laptops each year, and Dell models consistently impress. I know, because when I came to round up our top-scoring options for this article, I struggled to find any duds. I was spoiled for choice. Below, you’ll find a showcase of the Dell laptops that we’ve reviewed over the past year or so, and which managed to earn four stars or higher when put through our demanding review process.
Most are high-end laptops that rival the best the likes of Apple have to offer, but you’ll also find some brilliant affordable options, and some versatile 2-in-1s that would make a top choice for students. I’ve also included a standout gaming option, as well as a stellar laptop for professionals.
To find out more about each one, click the View details button — this will provide a rundown of our main pros and cons for each model, plus a link to our full review. Alternatively, if you want to see how these laptops compare to one another, check out our best Dell laptop ranking, or for our favorites from a range of brands, head to our comprehensive best laptop guide. Have I missed any models you’d recommend? Let me know in the comments section.
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
For decades now, companies like Michelin have been teasing us with futuristic-looking automobile tires that don’t use air. Instead, they use a polymer mesh of sorts which maintains the same pressure on the travel surface that a pneumatic tire does, with much less maintenance than their pneumatic counterparts. At least, in theory. There’s a reason that these tires live in the same mythical realm that Half Life 3 and the modern affordable Volkswagen do, and [Berm Peak] decided to discover those reasons for himself.
Of course, [Berm Peak] isn’t building these for his daily driver, an electric pickup truck featured in previous videos of his. He’s putting these on his mountain bike instead, a challenging environment for a tire like this in its own right. When mountain biking at the level he does, punctures and flats can become a real nuisance on the trail, so he set about experimenting with these designs with the 3D printer to see if he could make something rivaling pneumatic technology. After a few design iterations he settled on a TPU-based version with a compliant S-shaped spacing between the tread and wheel. The tire printed in sections that are installed by joining them together on the bike rim with a separate 3D printed rim interface.
At the end of this process [Berm Peak] ends up with a surprisingly capable tire that mostly holds up to his extreme off-road testing, an impressive feat for something 3D printed in his shop. Presumably a company specializing in bicycle tires could build something even more capable, but it turns out that a different technology has already solved all of the problems that airless tires solve. Mountain bikers today almost exclusively ride on tires with sealant, so punctures and flats are essentially a solved problem. But the neon-green airless tires were still a fun project for [Berm Peak] and quite the head-turner out on the bike trails.
£110 off Apple’s newest MacBook Pro is a discount that rarely shows up this early after launch, and Currys has it live right now.
The 14-inch MacBook Pro with Apple’s M5 chip has dropped from £1,359 to £1,249 at Currys, a saving of £110 and perfect timing for thinking about back-to-school tech.
Apple’s MacBook Pro just got a really good price cut, saving you £110
Apple’s MacBook Pro has just landed a genuinely impressive price cut, knocking a full £110 off and making now a great time to buy.

New Apple silicon rarely gets discounted this quickly, since Apple tends to hold firm on pricing for months after a launch, which makes catching the M5 Pro £110 cheaper within its first sale window feel like unusually good timing.
That timing matters more once you look at what’s actually inside, since the M5 chip pairs a faster CPU with a more powerful GPU and a 16-core Neural Engine, meaning quicker exports, smoother multitasking across heavy apps and Apple Intelligence features that respond instantly rather than lag.
Our tech expert Jessica Gorringe compared the Pro against the new MacBook Air M5 and found it pulling ahead in exactly the areas that matter for heavier work, with a sharper Liquid Retina XDR display, a longer claimed battery life and noticeably more ports.


That XDR display hits up to 1,600 nits at its peak, runs an adaptive refresh rate up to 120Hz through ProMotion and covers the full P3 colour range, which makes editing photos or watching HDR content look noticeably richer than on a standard panel.
Apple also rates this MacBook Pro for up to 24 hours of video streaming, which in real terms means it can realistically get you through a full working day or a long-haul flight without you needing to go looking for an outlet.
That same confidence about staying unplugged carries over to the port selection, with three Thunderbolt 4 ports, an HDMI output and an SDXC card slot meaning fewer dongles cluttering your desk when you’re actually trying to get work done.
Day to day, Apple Intelligence runs natively on that same chip to help with writing and everyday tasks, backed by privacy protections Apple says keep your data off limits to everyone, including itself, while Touch ID and FileVault handle the security side in the background.
Apple rarely lets its newest hardware sit on sale for long, so anyone weighing up whether the extra ports and display actually justify the Pro price tag now has a much shorter list of reasons to keep waiting.
SQUIRREL_PLAYLIST_10148964
Home Depot is a one-stop shopping destination for all things related to home improvement, but you’ve likely visited the store for more than just renovation supplies. Big Orange also carries appliances, furniture, lawn and garden supplies, holiday decorations, home decor and more.
But if you pick up the wrong tool or a ceiling fan that doesn’t fit your space, Home Depot has a generous return policy for most items, but if you’re a regular customer, take note — the store recently changed the rules for a few products. If you enjoy scaring trick or treaters with fake skeletons at Halloween or decking the halls at Christmas, be aware that any holiday decor purchased at Home Depot must now be returned within 30 days. It also cannot be used, and you must have a proof of purchase.
The home improvement store offers an even shorter return window for some items, allowing only seven days for air conditioners, dehumidifiers, and gas generators. Effective July 2026, Home Depot added pumps, portable evaporation products, and portable heaters to its seven-day return policy. Again, they must be unused and have proof of purchase. For many products, the store’s typical 90-day return policy remains in place.
While the home improvement store didn’t issue any official statement on the updated return policies, they are likely intended to stop shoppers from abusing these policies or using products for scams. Some shoppers may attempt to buy an item, use it for a short period, and then return it for a full refund. This is most common with seasonal decor, high-value items or tools with a specific use that you may only need for one job.
If you’re worried about the return window for a specific item, check Home Depot’s return policy online. The store maintains that “most merchandise” falls under its 90-day return window, provided you have a receipt or other proof of purchase. However, the store also has 30-day, seven-day, and even 48-hour windows for specific items. Major appliances, for example, have only a two-day return window, while the store offers 30 days for consumers to return furniture and consumer electronics. Most plants can be returned within 90 days.
Meanwhile, customers who have a Home Depot consumer credit card, the Pro Xtra credit card, or a commercial account with the store. Purchases made with those cards have a year-long return window, unless they fall under those shorter return windows listed on Home Depot’s website!
Weekend Open Thread: Wit & Wisdom
Meta enters AI-training agreement with far-right ‘propaganda rag’ Newsmax
Zack Polanski: an incitement to murder Nigel Farage?
MicroStrategy Post-Earnings CLARITY Act Push Could Add New Catalyst for Its Stock
XRP Ledger v3.3.0 brings five institutional features
Bitcoin Enters the 3rd Stage of the Bear Market
Luke Littler’s dominance sparks GOAT debate
Seema Kaliramna Wins Discus Throw Bronze, Takes India’s CWG Medals Tally To 17
New York sues Kalshi over prediction market gambling
Crypto PAC spending tops $2M in Michigan House race
DTCR: Deleveraging And A Hedge Fund Collapse Point To A Possible AI Bottom
Trump Announces Hamas Disarmament Agreement as Iran Strikes Kuwait Air Base and US Attacks Pause Overnight
3 Fed Officials Just Explained Their Rate Hike Vote: Is Inflation Winning?
ESET tracks rise in malicious AI skills and adaptable malware
Four people die trying to cross Channel in small boats
Gemini Spark can now use Chrome logins and saved passwords to run errands on your behalf
France Cricket implodes: letters hidden in a drawer and a board at war
Building A Reproduction PlayStation Motherboard
XRP Ledger urges node upgrade after manifest flood
Moneyflip CEO charged in $40K murder-for-hire plot
You must be logged in to post a comment Login