Connect with us

Tech

Pollen Robotics’ Microduck aims to make training physical AI far less fragile and cheaper

Published

on

Pollen Robotics and Hugging Face are back with another robot, and this one is delightfully unhinged. Microduck is a 25cm tall waddling biped built to take AI off your screen and onto your desk. Preorders open today, with first deliveries targeted before Christmas 2026.

Unlike its predecessor, the Reachy Mini, Microduck is built entirely around action. It runs on 15 motors, with an articulated beak for picking up objects, a camera, a depth sensor, two IMUs, and enough balance to walk, crouch, and even roller-skate.

Built to take a tumble

Training movement models in the real world usually means expensive hardware and long repair bills when things go wrong. Microduck flips that dynamic. Measuring roughly 10 inches by 5.5 inches and weighing less than two pounds, it is tiny enough that a fall ends in a mild thud rather than a costly disaster.

Advertisement

What’s even better is that it picks itself back up after most falls, so you won’t have to babysit it while testing new behaviours. Pollen Robotics says its duck-like aesthetic and waddling gait weren’t something the company planned. They emerged naturally from its proportions, and the company just went along with it.

Despite its toy-like appearance, Microduck isn’t exactly targeted at kids. It’s aimed at developers who want to train their own physical behaviours, serving as an approachable testbed for sim-to-real machine learning.

More than just a desk toy

Out of the box, Microduck supports gamepad controls, laser-following, and seven trained moves, and each unit generates its own voice the first time it wakes up. On the surface, that makes it look more like a desk toy than a dev kit. However, the stack underneath is aimed at developers training their own behaviors.

Advertisement

Pollen Robotics has published the SDK, the robot software, and its reinforcement learning and sim-to-real tools on GitHub. The goal here is to keep physical hardware development as collaborative as open-source software, making it easier for developers to share trained neural network models, training recipes, and custom environments the same way they share language models.

Microduck comes in four colors, Cream, Graphite, Lavender, and Sky, and is available for pre-order starting today at $399 before taxes and shipping. If you want to jump straight into training without waiting for hardware, Pollen Robotics has also published an interactive browser-based simulator to start testing code right away.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

OpenAI Is Developing a ‘Persistent’ AI Agent

Published

on

OpenAI is developing a proactive, highly persistent version of its flagship AI agent, Codex, WIRED has learned.

In recent days, OpenAI has started adding code for a new “Persistent mode” setting to its command line version of Codex, according to changes made to the product’s code base reviewed by WIRED. Changes to the Codex command line tool are made public by default, and new features tend to surface there before making their way to OpenAI’s other agent products, such as the Codex desktop app and ChatGPT Work.

Persistent mode has not been broadly rolled out or announced yet, but could be in the future. An OpenAI spokesperson confirmed to WIRED that the company is testing this feature, but said there are no immediate plans to launch it.

“OpenAI is a very bottoms up culture and many different things are explored on the open source repo which is a bit of our shared playground,” said Thibault Sottiaux, OpenAI’s head of core products, in a statement to WIRED.

Advertisement

The feature appears to be OpenAI’s latest attempt to make AI agents that people will actually want to use. OpenAI, Anthropic, and Meta are racing to deliver general-purpose agent products that will help people automate tasks across their work and personal lives, such as filing expense reports or scheduling doctor’s appointments. So far, the people who use AI agents are largely software engineers, but Silicon Valley believes the tech could be a major line of business with a much broader customer base.

Persistent mode appears in Codex’s “reasoning effort” menu, in which users can select the level of computing power, tokens, and time they want to allow for an AI model to “think” before answering a prompt. It seems to be one of OpenAI’s most computationally intensive settings. When users have selected Persistent mode, OpenAI’s code base reads that Codex will “continue working until put to sleep.” That’s a stark contrast to currently available modes, which will stop working on a task after a few minutes or hours, even if it’s not complete.

In another file in the code base, OpenAI describes a feature within Persistent mode called “proactivity.” This appears to be a type of system prompt for agents in Persistent mode, which are told that their work is not done when they finish answering a user’s request. Instead, the agent is instructed to proactively create follow-up tasks for itself. The agent is capable of working on those tasks across sessions and using past user interactions and “knowledge of the user” to decide what to work on. It also has a tool to message the user without being asked but is told to send these sparingly.

The instructions also set limits for the agent, according to the file. The agent is told that Persistent mode does not expand what it is allowed to do and that altering anything outside the user’s own system requires the user’s approval first—seemingly intended to limit how dangerous a persistent AI agent could be. The file sits in the shared core of Codex rather than in the code specific to the terminal, seeming to suggest the proactivity feature is intended for more than the command line tool.

Advertisement

In recently aired podcasts, interviews, and private investor meetings, OpenAI CEO Sam Altman has described his desire to turn ChatGPT into a proactive, always-on AI agent. OpenAI hopes these changes will drive up adoption of the company’s most advanced AI models, which today are used by only a fraction of ChatGPT’s total user base.

Source link

Continue Reading

Tech

5 SUV Redesigns That Totally Missed The Mark

Published

on





Striking looks haven’t always been at the top of the priority list when it comes to shopping for new SUVs. How much practicality and reliability they offer is usually what draws customers, and if it looks cool as well, that’s a nice bonus. A lot of the time, the simplicity subsequently made for timeless designs that still hold up today. In recent years, though, manufacturers have been putting extra care into the design of their SUVs to help stand out, now that the segment is so incredibly dominant. This has given us some pretty special SUVs that do wonders with the inescapable boxy philosophy, and others not so special.

While getting all the proportions right with an SUV can make it look great, it’s easy to create something very awkward or uninspiring. Brand image is, of course, a huge driving factor behind all car designs, and sometimes, brands go to far in a bid to adhere to that image that it throws the design style off completely, leaving a car that doesn’t much character at all. And if it does have character, it’s for the wrong reasons. Here’s a look at five times SUVs were redesigned and unfortunately missed the mark.

Advertisement

2025 BMW X3

As BMW’s third smallest SUV in production, the X3 has historically championed the smooth yet sharp-edged design philosophy pretty well over the years. However, for the latest iteration introduced for the 2025 model year, it softens or completely does away with all the harder lines that the previous generations did a great job of defining the proportions to reach this incredibly minimalistic look.

Advertisement

Quite a few other nameplates in the lineup are also starting to take on much cleaner design styles, which work out quite nicely in some cases. For the X3, however, the changes make for a rather flat, disconnected SUV rather than the sophistication we’re used to. There’s only so much you can do to make an SUV not look boxy, but BMW seems to have gone the other way with the front-end, squaring it off with a much larger kidney grille that would look far better if it were a bit smaller. There’s also not much else going on up front either.

The flatness carries down the rear end as well, with the incredibly small back window keeping on level with the high beltline, leaving enough space beneath it to throw the proportions off even more. Reactions to the X3’s redesign were polarizing to say the least, and while we found M50 xDrive trim a lot of fun to drive, there’s not much you can really do about the outline to change it. 

Advertisement

2011 Infiniti QX56

Moving over to a much smaller competitor in the premium/luxury segment, Infiniti has acted as the high-end subdivision of Nissan since 1989. The brand has recently unveiled a new lineup of SUVs as part of the model overhaul, trying to bring some of the excitement back to the badge that it started to lose. These new SUVs are pretty tidy, which can’t be said for a specific redesign that was introduced back in 2011.

At that time, the full-size QX56 was the brand’s flagship model, and from 2004 to 2010, the design wasn’t jaw-dropping, but it was a strong-looking, albeit simple, SUV. It didn’t have an instantly recognizable outline, but when Infiniti tried to give it one, it became one of the most peculiar-looking SUVs on the market. Instead of the more functional, generic design, Infiniti added as much curvature onto the QX56’s bodywork to try and create one of those instantly recognizable nameplates. Unfortunately, though, it won’t cause an extra head turn if it drives past you. Just about every panel and component is rounded off, making it look bloated instead of the smooth, sleek concept the redesign was seemingly hoping to achieve.

Advertisement

2013 Nissan Pathfinder

This next example of an SUV redesign that deviated from its predecessor for all the wrong reasons is the Nissan Pathfinder. Not the current model, though, which is arguably one of the most visually intriguing mid-sized SUVs you can buy at the moment. It blends a sleek, modern design with practicality. In 2013, however, the Pathfinder went from its renowned rugged, boxy, imposing design to a painfully simple SUV that looked like so many others in the segment at the time.

Putting the body-on-frame third-gen Pathfinder next to the 2013 model, you wouldn’t believe they have the same name on the back. For the latter, it follows suit with some other redesigns on this list by embracing minimalistic curvature far too much, leaving no room for much personality or memorability. While base power was only down by 6 horsepower compared to the previous generation, the major selling point of being able to use the body-on-frame SUV just about anywhere was essentially removed entirely by the switch to a unibody platform.

Advertisement

2027 Audi Q7

One of the many Audi nameplates that has been completely redesigned for the 2027 model year is the Q7, which is set to be available in the U.S. before the year’s end. The Q7 case is very similar to the new X3, in the sense that its distinct, unmistakable Audi silhouette has been sacrificed for a forward-thinking design that doesn’t quite sit right.

Advertisement

Only sitting below the Q9 in size, which looks to be going down a similar route stylistically, the previous Q7 had plenty of space to use the muscular curves the Audi badge has become synonymous with, with its proportions always looking natural whichever way you look at it. For the upcoming 2027 model, the Q7 flattens down a lot of its shapes, subsequently looking much too wide up front. It looks taller thanks to also taking away dimensions from the side profile, and the much longer, vertical rear window connecting to the roof makes it so boxy you can’t instantly tell it’s an Audi anymore. 

To give the new Q7 some credit, it’s not an ugly SUV, especially from certain angles. But compared to even other current Audi SUVs, the athletic nature has been lost. Even small changes such as making the grille a touch smaller would make a big difference for the better.

Advertisement

2014 Jeep Cherokee

Despite being under a different name, the Jeep Liberty was essentially the next iteration of the Cherokee, being first introduced for the 2002 model year. In fact, the Cherokee name was still used in other countries, and the two SUVs were practically identical. Overall, the philosophy of the Liberty remained the same until it was discontinued in 2013, blending pickup ruggedness with a bit more focus on tarmac driving as well. It kept the boxier shape the Cherokee was built upon. But for 2014, the Cherokee name returned to the U.S. in a much, much different fashion.

This is one of those redesigns that changes the fundamentals of the SUV. The functional design was changed to a safe, modern compact crossover that fell in line with conventional industry standards rather than remaining a unique option in the segment. If you went for higher trim levels such as the Trailhawk, you could retain the off-roading capability, but that doesn’t fix the main issue with it: looks. 

The rear of the SUV doesn’t have anything weird going on, but up front, the choice to split the front end with a panel line creates an awkward, unnatural angle. The grille stretching over the line only pronounces it, almost making it look like it’s being pinched. Luckily, the facelift added some more bulk to the front fascia and reconnected the headlights, and the new-gen hybrid model does away with it altogether.

Advertisement



Source link

Advertisement
Continue Reading

Tech

Why Is The New Model More Expensive?

Published

on

What are the differences between the two and is the $50 price hike all about RAM?

Samsung just introduced the Galaxy S26 FE at its Unpacked August 2026 launch event. The company’s latest Fan Edition smartphone is a follow up to the Galaxy S25 FE that was introduced in September 2025. One thing you might notice is the higher price. The Samsung Galaxy S25 FE started at $649 while the Samsung Galaxy S26 FE starts at $699, which is $50 more.

There are a few possible reasons for this increase, including a slight bump in specs. It likely also has something to do with the RAM supply crisis, which has resulted in rising prices for tech across the board. When looking at how these two phones compare and what you get with the Galaxy S26 FE that you don’t with the Galaxy S25 FE, however, there isn’t a huge difference. That might give you pause when deciding which one to get or if it’s worth the upgrade.

Advertisement

The performance and spec upgrades

Both phones have identical screens with the same specs, including a 6.7-inch FHD+ Dynamic AMOLED 2x display with up to 120Hz refresh rate. But the new Samsung Galaxy S26 FE runs on a slightly boosted Exynos 2500 (3nm) processor compared to the Exynos 2400 (4nm) processor in the Galaxy S25 FE. While we haven’t yet tested them against one another, head to head benchmarks for these two processors suggest that you’ll get better gaming performance with the Exynos 2500 along with slightly improved battery efficiency.

The Galaxy S26 FE comes with Android 17 and One UI 9 out of the box. Being a year old, the Galaxy S25 FE comes with Android 16 and One UI 8, but you can update it to the new OS. 

Both storage options available in the US (128GB and 256GB) tap out at 8GB of RAM, like the S25 FE. The 2025 and 2026 phones both have 4,900mAh batteries and support the same 45W wired charging speeds as well (along with fast wireless). However, a 30-minute charge will get you to 69 percent battery levels with the Galaxy S26 FE versus 65 percent with the Galaxy S25 FE. That might not sound like a lot, but when you’re in the red, every bit of power counts!

Advertisement

Cameras, AI and more

Surprisingly, there’s no bump to the camera specs, which would have at least helped justify the price hike as well as the existence of the S26 FE altogether. Both have a 12MP ultrawide camera, 50MP main camera, 8MP telephoto camera with 3x optical zoom and 12MP front camera.

While Samsung touts the Galaxy camera and AI experiences of the Galaxy S26 FE, you can access most of those with the Galaxy S25 FE as well. There are new features like My FanCam that come natively with the Galaxy S26 FE, as well as the new Galaxy Z Fold 8 line announced in July. With this feature, you can select a specific subject from a video and change framing to follow them, much like you can track with a gimbal camera. This reduces the amount of manual editing needed for a video. The feature is part of One UI 9, but it requires advanced neural processing, so you won’t be able to access it on the Galaxy S25 FE.

Advertisement

There’s also Horizontal Lock, introduced with the Galaxy S26 series phones, an upgrade to Super Steady mode that captures video in a consistent orientation, even if you physically rotate the device. While it’s possible this feature could come to the Galaxy S25 series, it’s not confirmed.

The new phone also brings forward features like New Brief, Now Nudge and Circle to Search. But there are enhancements. With Now Brief, you get customizable briefing cards for things like weather and wellness, and can even create your own. Now Nudge now includes support for third-party apps and notifications. And with Circle to Search, you can look up multiple items in a photo at the same time. But again, all these features come with an OS update that should carry over to the Galaxy S25 FE as well.

Advertisement

Why the Galaxy S26 FE costs more

So, when you break it down, the Samsung Galaxy S26 FE’s main updates are its boosted processor, presumed slightly better battery efficiency and charging speed (dependent on real-world testing), potentially exclusive camera and AI features like My FanCam, the latest OS version out of the box and one extra year of support. It’s possible those all added up to cost you $50 more. More than likely, however, the biggest reason for the upgrade in price is the RAM supply crisis, which sadly shows no signs of slowing down.

The similar specs between these phones confirms that the Galaxy S26 FE is nothing more than an iterative update. That’s disappointing considering that our Galaxy S25 FE reviewer pointed out that this last-gen phone was also an iterative update from the Galaxy S24 FE before it. So, there’s no reason to upgrade, and if you’re buying new, you may even find more value in saving that $50 and going for the Galaxy S25 FE instead.

Conversely, you may want to consider spending the extra $100 to get the base Samsung Galaxy S26, which is on sale at the time of this writing for $799.99. With it, you get double the starting storage at 256GB, a Snapdragon 8 Elite Gen 5 processor and more RAM at 12GB. Though it does have a smaller battery, it is also a more compact device with a 6.3-inch display. But you might find you get more value out of that model.

Advertisement

Source link

Continue Reading

Tech

Tiny Mechanical TV Drum Delivers Shockingly Sharp 4K

Published

on

I never intended to join the cutting edge of electromechanical television. I just wanted to make a nice clock. But sometimes you have to go where the engineering takes you, and in my case it took me to the Scanwheel, a pocket-size wide-screen electromechanical TV with a resolution of 4,096 by 20 pixels. Yup, that’s 4K by 20.

The major components of the Scanwheel TV The 3D-printed drum [top] is spun by a motor controlled by a driver board [second row, from top]. The driver board, in turn, is controlled by a Raspberry Pi Pico [middle], which also controls the LEDs [second row, from bottom], which are mounted in the 3D-printed casing [bottom] so that the holes pass over them as the drum turns.James Provost

Electromechanical television was the first form of practical television, developed by John Logie Baird in the 1920s. He used a so-called Nipkow disk, which has a spiral of holes punched through it. As the disk rotates, the holes pass one by one in front of a light source. By varying the brightness of the light as a hole travels across it, you can draw one scan line of a video frame. Spin the disk fast enough, and persistence of vision makes it look like an entire frame is being displayed simultaneously. Commercial electromechanical TV sets were produced in the United Kingdom, with regular broadcasts provided by the BBC in the 1930s.

Although cathode-ray tubes replaced electromechanical televisions in the 1940s, hobbyists have continued to build them and even improve on the original technology. For example, in the June 2022 installment of IEEE Spectrum’s Hands On, Markus Mierse presented a desktop-size 3D-printed color version.

I built an electromechanical display myself some years ago, but it had a traditional design with a Nipkow disk made from a vinyl record with holes drilled in it. Recently I started tinkering with electromechanical TV again as an outgrowth of my YouTube channel. There I’ve been focusing on developing volumetric displays, which create 3D pixels floating within a volume of space. In particular, I was interested in borrowing some ideas from plenoptic cameras, which use pinholes and lenses to capture multidimensional light fields of samples.

Advertisement

I wondered if I could run the process in reverse, to create light fields rather than capture them. I often explore ideas in two dimensions before expanding to the third, so I thought I’d first demonstrate a 2D display. I decided to make an electromechanical device into a clock. After all, you don’t need high resolution to display digits.

How Does the Scanwheel Display Work?

Thinking about the display as a clockface pushed me toward some key ideas. First, instead of having just one display area, I would use five light sources to create multiple areas—four to represent hours and minutes, and a central area for a separator that would blink each second. Second, to align the digits in a readable row rather than have them spread around an arc, I swapped the Nipkow disk for an established alternative: a Nipkow drum.

With a drum, the holes run along the curved cylindrical surface in a stair-step pattern. This means they always trace a straight line from the perspective of a viewer looking from the side, so the clock’s digits would be horizontally aligned.

“In tests, I’ve pushed the horizontal resolution to more than 8,000 pixels.”

Advertisement

These two decisions turned out to be key to achieving both miniaturization and high horizontal resolution. A disk needs a fairly wide diameter so that the scan lines aren’t ridiculously curved. But curvature isn’t a problem with a drum. A drum can be much smaller than a disk that has the same number of scan lines. (And unlike in the 1920s, packing multiple light sources close together inside a small drum isn’t a problem with modern LEDs.) I settled on a 6-centimeter-wide drum, turning the device from desktop-size to something you could carry in your pocket.

I then realized my five display zones could work in concert to create one single wide screen. Because it’s possible to modulate the brightness of an LED at very high rates, the horizontal resolution can also be very high. My system currently has 4K horizontal resolution, and this is primarily limited by the amount of onboard memory I have available. This memory holds the buffer that stores pixel data for each frame before it is read out to the LEDs and displayed. In tests, I’ve pushed the horizontal resolution to more than 8,000 pixels.

Despite the Scanwheel’s low vertical resolution—at 20 pixels, it has fewer scan lines than Baird’s 30-line televisions—its high horizontal resolution makes the legibility of the display surprisingly good: I can display not just crude digits but video streamed into the frame buffer.

Using the RP2040 Chip’s Special Silicon

That frame buffer lives on a Raspberry Pi Pico microcontroller board, based around the RP2040 microcontroller. The RP2040 is ideal for this project because of the chip’s dedicated PIO silicon. PIO stands for programmable input/output, and it’s a block of four coprocessors that uses a very limited instruction set. Each coprocessor can be set up to chew through input/output streams completely independently of the RP2040’s two CPU cores.

Advertisement

An illustration comparing the arched lines of a disk display versus the straight lines of a drum. The first mechanical TVs used disks, which had to be wide to minimize image distortion but allowed bulky light sources. With small, modern light sources, a smaller drum can create images with minimal distortion.James Provost

It’s thanks to the PIO that I’m able to keep up with the spinning drum and modulate each of the five LEDs simultaneously as holes pass over them, a task complicated by the fact that the center LED is not a monochrome LED, but a color LED with separate red, green, and blue channels. In fact, the PIO does nearly all the work, pulling data from the frame buffer and controlling the LEDs and the spinning of the drum. The code running on the CPU (written in MicroPython) is primarily responsible for setting up the PIO and then leaving well enough alone.

A stepper motor connected to a driver board spins the drum, with power provided by the USB jack on the Pi Pico. All the Pi Pico has to do controlwise is send the board a pulse to incrementally advance the drum’s position once every millisecond. Video data is streamed into the Pi Pico via a network interface. You can set up the Scanwheel to mirror a portion of your computer’s screen, or to act as a separate display.

The casing, including the drum, is 3D printed. Now for a neat bit: In the Scanwheel’s GitHub repository at https://github.com/AncientJames/Scanwheel/tree/main, alongside all the other files you’ll need to make this project yourself, there’s an OpenSCAD file that generates the 3D-print file for the drum based on adjustable parameters. This means you can easily make a taller drum and add more scan lines, or try other customizations for your very own portable electromechanical display. You can even use it as a clock!

From Your Site Articles

Advertisement

Related Articles Around the Web

Source link

Continue Reading

Tech

Plaud One Is a Reinvention of Headphones for the AI Note-Taking Age

Published

on

Last year, I made a bold declaration: There’s no need to invent a new AI wearable, because the ultimate wearable technology is one you already own. I was referring to headphones — something most of us have used for decades.

Plaud — one of the world’s biggest AI note-taking companies — seems to agree, as it’s now built its industry-leading agentic AI into a pair of headphones. The company announced its latest device ahead of IFA 2026 in Berlin next week, where I’ll be able to see the headphones in person for the first time.

At first glance, they don’t look any different to any other earbuds. They have a sleek and discreet design, and they come in an off-white color. I’m keen to find out how comfortable they’ll be and how good the audio quality, is in addition to the device’s AI capabilities.

Plaud One
Plaud One look like any other earbuds.

Plaud is known for its slim, wallet-like device, which attaches inconspicuously to the back of your phone, and for its wearable pins. Both of these devices function as hardware gateways to the company’s true secret sauce — its agentic AI and software platform. The same is true of the Plaud One headphones, which have the same software built in.

The headphones will capture and upload ongoing conversations around you, as well as phone calls, using the built-in eSIM with 4G LTE. We’d always recommend informing people that you’re using a recording device, and it’s important to note that recording phone calls without permission from all participants can be illegal in some states.

Advertisement

Plaud’s software will then provide automatic transcriptions of your meetings, and can turn these into summaries, follow-ups or reports. The company’s agent allows for native integration with other tools you likely rely on, including Google, Gmail, Slack and Notion.

“AI agents become truly useful when they understand the context in which human intent is formed,” said Nathan Xu, CEO and Co-founder of Plaud.

“That context lives in conversation.”

The added bonus of Plaud One is that it allows for a two-way dialog between you and Plaud’s AI. You can speak directly to the agent, asking it questions or giving it instructions in a way that hasn’t been possible with Plaud’s previous devices. To activate the AI, you either need to say “Hey Plaud” while wearing the earbuds, or hold down the agent button on the case.

Advertisement

The Plaud One Explorer edition is available for preorder now for £229 ($311) and will come with £150 ($204) of Plaud credits. Plaud expects devices to start shipping later in the fall.

Source link

Continue Reading

Tech

4 Sports Cars That Can Deliver 30 MPG

Published

on





Gas prices have made headlines over and over in 2026. At time of writing, the national average for a gallon of regular fuel is more than $4, and it’s well over $5 in some states, including California and Washington. Filling up this year has felt like a financial rollercoaster, and you may think high prices mean leaving your sports car in the garage. After all, having fun at the wheel typically means pain at the pump.

According to iSeeCars, the average fuel efficiency for a sports car is 26 mpg. That’s actually not too shabby for an average. Popular vehicles like the Dodge Charger and the Chevrolet Corvette see far less. It may surprise you, then, to learn that there are a few sports cars that can deliver up to 30 mpg, which means that instead of leaving these fun drives at home, you can take them on your daily commute — even when gas prices make the news again. But bear in mind, these sports cars only see 30 mpg or more on an open highway; city driving and traffic drops that number fast.

Advertisement

Ford Mustang

If you’re considering a Steel Pony but you’re worried about fuel efficiency, Ford has you covered. The base EcoBoost model sees up to 33 mpg on the highway, though that number drops to 22 mpg in the city. Buyer beware, however, that only the base trim sees such good numbers. Models with the larger V8 engine don’t get close to 30 mpg, even on the highway.

The 2026 Mustang has an MSRP of $32,995, making it a more affordable option that many other high-performance vehicles. The 2.3-liter engine puts out 315 horsepower and is paired with a 10-speed automatic transmission. It can go from zero to 60 mph in under five seconds, faster than others in its class. Other standard features include 18-inch alloy wheels, cloth upholstery inside, a large 13.2-inch touch screen, and Apple CarPlay and Android Auto. Buyers will also appreciate the Wi-Fi hot spot and six-speaker audio system, along with a long list of standard safety features like forward automatic emergency braking and rear parking sensors. If you add the Mustang RTR Package, you’ll also get anti-lag turbocharger technology.

Advertisement

The Mustang comes in a wide array of colors, including your standard bright red, an eye-catching orange, and a classy dark green. Inside, you can have more fun with seat belt colors in orange, blue, or black with a red stripe.

Advertisement

Mazda MX-5 Miata

It may come as no surprise to some that the 2026 Mazda MX-5 Miata offers great fuel efficiency for a sports car. This convertible is small but mighty, offering 181 horsepower in the base Sport trim. With a starting price of $30,430, it’s also extremely affordable, just don’t expect much in the way of cargo space! Your color choices are also extremely limited, though Mazda is reportedly adding an eye-catching metallic green option to the 2027 model.

All three available MX-5 Miata models see 26 mpg in the city but drivers should easily see more than 30 mpg on the highway, with an estimate of 34 mpg on the open road. Buyers should note that the Sport and Club trims are only available with a manual transmission, while the top-tier Grand Touring model is available with either a manual or an automatic transmission. If you opt for the automatic transmission, you will see even slightly better fuel efficiency on the highway.

The cabin is comfortable if you’re not too tall, but not particularly modern. The infotainment screen is only 8.8 inches and is controlled with a central command dial, which can be cumbersome and distracting. The base model has wired Apple CarPlay and Android Auto. The list of standard safety features is also small compared to competitors but does include forward automatic emergency braking and blind-spot monitoring. Still, the MX-5 Miata provides a lively drive with excellent fuel economy and a starting price that can’t be beat.

Advertisement

Subaru BRZ

Subaru may not be the first automaker that comes to mind when you think about sports cars, but the BRZ is praised by U.S. News & World Report as a “real sports car for the people.” This Subaru is another sporty option available for under $40,000, with a starting price of $35,860, though it is the most expensive vehicle on this list. Both available trims have a 2.4-liter four-cylinder engine with 228 horsepower. On the highway, drivers should see up to 30 mpg if they select an automatic transmission. If buyers opt for a manual transmission, which is standard, they will see slightly less. If you’re interested in the BRZ, take note that it takes Premium unleaded gasoline, so you will shell out a bit more at the pump.

Described by the automaker as a “classic rear-wheel drive sports car,” the BRZ, which stands for “Boxer engine, Rear-wheel drive, and Zenith” is an oddity in Subaru’s all-wheel drive lineup. Inside, the cabin is designed with the driver in mind, with sport seating and customizable digital displays. The back seat is tiny and really only suitable for kids or for use as cargo space. There’s an 8-inch touch screen that supports Apple CarPlay and Android Auto. The 2026 model is a Consumer Reports Recommended Model. The basic bumper-to-bumper warranty is for three years or 36,000 miles.

Advertisement

Toyota GR86

Toyota’s GR86 is another affordable, rear-wheel drive sports car that delivers up to 30 mpg on the highway. Buyers interested in the 2027 model should opt for the base trim with a six-speed automatic transmission for the best fuel efficiency. The base GR86 can go from zero to 60 mph in 6.6 seconds and has a top speed of 134 mph. Additional trims offer the same engine, but with higher top speeds and decreased fuel economy. This Toyota has a starting price of $31,500.

Advertisement

U.S. News & World Report ranks the GR86 at the top of its list of sports cars, and Car and Driver says the 2027 model is a “joy to drive.” It offers a light, agile drive with Sport and Track modes, a sleek profile, and a unibody frame made of both high-strength steel and lightweight aluminum for peak performance. Inside, standard options include a digital gauge cluster, an eight-inch touch screen with Android Auto and Apple CarPlay, and seating for four, though the back seats are tiny. Instead of carpooling, most drivers use them for extra storage. The standard Active Safety Suite includes a pre-collision braking system, lane departure warning, adaptive cruise control, and 24-hour roadside assistance. Toyota offers a three-year / 36-month basic warranty and a 60-month / 60,000-mile powertrain warranty.

According to some reviewers, the ride can be noisy, especially at high speeds, but let’s be real, that comes with the territory at this price point.

Advertisement



Source link

Continue Reading

Tech

Fitbit and Pokemon Made a Fitness Tracker That Might Actually Help Me Catch My Zs

Published

on

When Pokemon Sleep was first announced in 2019, I wondered if the company behind one of the most iconic animations was dreaming too big. Getting people out of their houses and onto streets and parks with Pokemon Go was already a huge success. But did people care as much about their sleep hours as they did about their steps?

After several delays, Pokemon Sleep finally launched in 2023 to high interest, becoming the most downloaded sleep game app in the world, according to the Japanese news outlet Famitsu.

On Thursday, the Pokemon Company is partnering with Google and Fitbit to help people take their sleep even more seriously – while still having fun – with the new $129 special-edition Fitbit Air.

It’s a pairing that makes a lot of sense. The minimal design of the Fitbit Air is tailored for extended wear, including for sleep tracking, and Pokemon Sleep gamifies the resting experience so you hopefully rest for longer each night.

Advertisement
The full spread of items when you unbox the Fitbit Air Pokemon Sleep edition.
Here’s everything that’s included in the box.Kerry Wan/CNET

The stylistic touches will resonate with fans

I’ve been wearing the new special-edition Fitbit Air for half a day now, and it comes with a deep blue woven wristband and a cutesy Pikachu etching above the adhesive. On the wrist, it feels a lot like the original tracker, which launched earlier this year.

That’s a good thing, as CNET lead reviewer Vanessa Hand Orellana found the Fitbit Air slim, lightweight, and comfortable to wear during testing. Like the standard model, you can also pop out the pebble, which encapsulates the optical heart rate monitor, gyroscope, and other health-tracking sensors, and swap out the band.

A blue Fitbit Air on the wrist.
The Fitbit Air with the Sleepy Blue wristband.Kerry Wan/CNET

Unfortunately for Pokemon fans who already have a Fitbit Air, Google tells me that the new band won’t be sold separately

Beyond the special-edition fitness tracker, I spotted some tasteful Easter eggs that decorate the box and packaging. I noticed various sleepy Pokemon, including Psyduck and Slowpoke, on the flipside of the cover, and a Mew that’s hidden on the wristband holder.

Everyone can play (and sleep)

The special edition Fitbit Air can sync with both the Google Health app and the Pokemon Sleep app, so you can track metrics like your daily movement, heart rate and cardio load during the daytime. Then you can more accurately log the duration and quality of your sleep overnight.

Google says the Pokemon Sleep app will sync with the special edition Fitbit Air, as well as all other Google and Fitbit wearables, including the Pixel Watch. That means you now have more wearable options to help build up your Drowsy Power, the in-game mechanic that determines how many wild Pokemon appear in your campsite, and how rare their sleeping styles are.

Advertisement

Previously, you either had to set your phone beside your pillow or wear a now-discontinued Pokemon Go Plus band to properly track and record your sleep.

The Fitbit Air on top of its packaging box.
The latest special edition Fitbit Air is geared toward Pokemon fans.Kerry Wan/CNET

Availability and release date

The Fitbit Air Special Edition Pokemon Sleep, in its sleepy blue color, is now available for preorder online or at the Google Store and Target for $129. 

That’s $30 more than the retail price of the standard Fitbit Air, but it does come with the thematic wristband, a unique code that gets you Pikachu Incense in Pokemon Sleep, and a three-month trial of Google Health Premium.

Orders will start shipping on Sept. 15, just a day before the release of Pokemon’s 30th Celebration TCG set, in light of the company’s anniversary.

Source link

Continue Reading

Tech

How Threat Research and MDR Help SMBs Build a Defensive Edge

Published

on

Person on a computer

Corporate IT and security teams have the unenviable task of keeping relentless and increasingly sophisticated adversaries at bay. They’re often faced with limited resources and expanding attack surfaces, but recruiting and retaining top-tier security professionals to run an in-house Security Operations Centre (SOC) is out of reach for many organizations.

At the same time, threats continue to evolve and adversaries hone their techniques, leading to incidents that often grind business operations to a halt.

To avoid being caught on the back foot, defenders need an approach that’s proactive and combines prevention, detection, remediation with accurate and timely threat intelligence. If building that capability in-house is impractical, then renting or buying it as a service is a more realistic option.

This isn’t a new concept, of course – smaller organizations have enjoyed the benefits of new IT innovations for decades through bureaux, managed services providers and cloud computing.

Advertisement

There’s a strong argument to be made for doing the same with advanced cybersecurity services, and this where Managed Detection and Response (MDR) can make a major impact. MDR gives organizations a proactive, expert-driven and scalable threat monitoring and hunting capability, without the cost of an elite SOC.

Not so long ago, an MDR was expensive and complex – if less so than a dedicated in-house set-up. It’s now increasingly practical for smaller organizations to consider, too.

In a recent conversation, Director of ESET Threat Research Jean-Ian Boutin discussed the work of his team and how threat research and intelligence feed into MDR workflows.

He also shared where the combination of cutting-edge technology and human expertise provides the most practical value, especially for SMB environments.

Advertisement

What do most small business users gain from ESET Threat Research? How does that change when they use ESET MDR?

ESET has a threat research team spread across multiple regions; I’m with the team in Montreal, but we have researchers spread across Europe and in the US, too.

There’s stuff everyone can see: our publications on WeLiveSecurity, and talks and presentations at cybersecurity conferences worldwide.

Then there are things that only ESET business customers get: all kinds of “tips and tricks”; that is, information about threat actors: what they’re doing, how they’re operating – all things that help our customers stay safe.

Advertisement

When it comes to managed detection and responsethreat intelligence is a key component that helps our detection and response team understand how the various threat actors are operating and how they can use that information to protect our customers from breaches.

What if your security team had the backing of global threat researchers? 

ESET MDR is powered by world-class threat intelligence and security experts who help uncover attacker tactics, investigate suspicious activity, and respond quickly when threats emerge.

Learn more about ESET MDR

You talked a bit about the tip of the iceberg – all of the back end of MDR that users rarely see, but that is absolutely critical. Could you explain that?

Advertisement

The various alerts that might be occurring in your console will sometimes be endpoint detections that we want to investigate. And my team is responsible for making sure that all the new samples and threats are being handled and detected in customer environments. So part of the team’s role is really to make sure that all these new trends, all these new samples are looked at, investigated and then detected on our customers’ premises. This is one of the key aspects.

We take great care in organizing threat intelligence data on e-crime, ransomware, APT groups, and nation-state actors targeting global organizations. Our researchers use these insights to link new breaches with past cases.

They assess the severity of the breach as well, and we can also assess what could be the purpose behind the attack. It really gives the customer a complete view into what might have happened, whether or not a breach happened, or even the specific group that targeted them.

What does MDR add on top of existing ESET endpoint protection?

Advertisement

MDR is more tailored, and the relationship with the customer is improved and increased. But the output of my team is distributed across the entire product set.

There’s been some talk of ESET private reports recently: how relevant are they to what most small and midsize businesses face? Are they facing targeted attacks? What about nation-state actors?

The threat profile will vary from one organization to another, and a nation state actor will typically have predefined goals, and they will be targeting victims that align well with those goals.

In terms of e-crime, this is broad. This is mass targeted. We see a lot of infostealers. We see a lot of ransomware as well.

Advertisement

So, our role is to understand how all these groups operate and make sure that if they have new techniques, we can actually act very swiftly and make sure that we block all the attempts.

This is the ultimate goal, but equally, so many threat actors are out there doing these types of things, and there are so many more families of malware. It’s really a daily job to make sure that the customers are protected. No shortage of work, definitely.

James Rodewald, one of ESET’s security analysts, uses this concept of triangulation: seeing something in the wild, hearing from an affected customer, and checking in with the threat intelligence team. An example he has used is an attack involving FamousSparrow. Can you elaborate on that from your perspective?

It’s important to have close relationships with the people who are actually dealing with these types of cases, because the main role of my team is to look at the telemetry, so the data is gathered from all the endpoints, and we are trying to find interesting cases, and the cases that we need to work on to improve the overall protection.

Advertisement

But sometimes the MDR team stumbles on something that we’ve seen in the past, and that also allows us to have a greater understanding of how the threat actor is actually operating.

In that specific case, that was eye-opening for us, because we haven’t seen this threat actor for quite some time. Whenever there’s a case involving a customer using MDR, it’s better in terms of research, because the closer relationship with the customer means that we know more about their infrastructure, so we can help them better. We can have a better understanding of the impact of the case. And that is then fed to other threat intelligence customers, so we are trying to be as close as possible to all these teams and link these incidents so that we can improve our coverage and improve our understanding of all these threats.

You talked about the working relationships with the MDR analysts and the D&R (Detection and Response) team. How does that change the way that you do your work and your understanding of threats when you have that kind of one to one relationship with the analysts and maybe the customer as well?

It changes everything, because with MDR, we already have a working relationship with the person who’s in charge of security for this organization, so we can very rapidly understand the scope of the attack, what exactly happened, why the attackers were there, and so on.

Advertisement

The information available to us is exponentially greater than what we can get with regular endpoints. So for us, this relationship is invaluable in terms of insights, visibility and our understanding of the case.

There was something of a spate of attacks in the UK last year that compromised large organizations like Jaguar Land Rover and Marks & Spencer via outsourced helpdesk services. Small and midsized companies also have outsourced services like this as part of their supply chain, and often they’re also the less well-protected parts of a bigger company’s supply chain themselves. Should they be concerned?

The risk posed by supply chain attacks is significant. There have been numerous documented instances over the years where threat actors target vulnerabilities in the supply chain, often focusing on third-party providers with less stringent security measures. By compromising such providers, attackers may obtain initial access to an organization’s network.

With respect to MDR, an advantage is the extensive visibility it provides, ensuring a comprehensive view of all detections and alerts. This capability enables us to identify even minor anomalies more effectively. Given that our team continuously monitors these organizations for potential incidents, we are able to detect and respond to subtle threat actor errors promptly.

Advertisement

Supply chain attacks present significant challenges due to the difficulty in securing all third-party entities. However, implementing an effective solution enhances our ability to react swiftly and efficiently to such events.

As the head of a threat research team, what’s the difference that you see MDR having on customers? What’s the impact for an organization that has an MDR service, and an organization that might not necessarily make that leap just yet?

In general, as I’ve mentioned before, continuous visibility is much greater with MDR. If your organization is affected by a campaign, you’ll have better tools to piece together all the different actions taken by attackers and understand what they did within your network.

Simply put, MDR provides deeper insight into attacks. From a threat research standpoint, this is the top advantage, and another key reason to value such visibility is the speed of response. With MDR, there’s already a secure channel between researchers and your company, making it easier to reach someone who can take steps to contain a breach quickly.

Advertisement

Final question: What would you say to organizations that might think of MDR as too complicated or expensive?

MDR acts like an insurance policy, helping to identify threats such as ransomware early – often before major problems arise. Attackers typically use initial access brokers to gain entry, but several warning signs can be detected in advance. While paying a ransom is never advised, recovery can still be disruptive. MDR supports business continuity so you can keep focusing on your core offerings.

Sponsored and written by ESET.

Advertisement

Source link

Continue Reading

Tech

Visa ships a security AI that patches production code before any human reviews it

Published

on

Visa’s open-source security harness now finds the vulnerability, writes the fix, and turns an adversarial panel on its own patch before any human reviews it. The whole loop ships on by default. A plain scan of the Visa Vulnerability Agentic Harness runs all 11 stages and edits source files in the target repo unless the operator caps it at detection.

The announcement Thursday pairs the release with an expansion of the Visa Consulting & Analytics advisory practice. Visa is shipping that default 18 days after Tenet Security demonstrated GhostJacking on the DEF CON 34 main stage, an attack chain in which an agent read an attacker’s payload out of a log file and rewrote DNS with a valid credential. Two days earlier, Steve Wilson, Chief AI and Product Officer at Exabeam and project co-lead for the OWASP Top 10 for LLM Applications, made the case in VentureBeat for the opposite default. “The first thing I’d do is put an authorization gate outside the model,” Wilson said in written responses. “The agent can propose the exact DNS change, but it cannot grant itself the authority to make it.”

The bottleneck moved, so Visa moved the pipeline

Rajat Taneja, Visa’s president of technology, rejects the premise that the default is a risk decision and calls it the product. “The bottleneck has moved,” Taneja told VentureBeat in an exclusive interview. “AI is finding vulnerabilities faster than humans can in the history of our technology industry. The new bottleneck is fixing and proving we have fixed things.”

VVAH grew out of Visa’s participation in Anthropic’s Project Glasswing, where the company aimed Claude Mythos at the network behind billions of daily transactions and watched the model chain minor weaknesses into working exploits, a hunt VentureBeat covered in July. “VVAH initially was completely only using Mythos, and that’s when all of us, as part of Project Glasswing, realized the power of this new class of models that does semantic reasoning,” Taneja said.

Advertisement

The harness went to GitHub in June and has climbed from 595 stars and 97 forks on July 20 to more than 2,300 stars and 300 forks as of August 25, with a clone-to-visitor ratio Taneja put near 9%. “We have got some very high-profile companies that have started using this harness,” he said.

Why give it away? Taneja’s answer starts with Visa’s technology DNA and a harness built “to protect Visa and our ecosystem.” The reason he leaned on hardest was obligation, “to do good by doing right” for “companies who may not have the same level of investments or knowledge in cybersecurity.”

Contribution runs one way. The repo states it is not currently accepting external code contributions, so the harness that edits adopters’ source takes no code into its own.

Thursday’s release extends the pipeline past the report. “We’re going from discover, verify, and report, and then fix it, to discover it, verify it, remediate it, validate it, and iterate it,” Taneja said. “If a fix doesn’t negate the exploit, then there should be a structured, automated feedback that preserves the learnings from the first run and then enhances it.” Underneath that loop, the release refactors scanning around an abstract syntax tree call graph that maps subroutine calls and the traversal paths an attacker could reach. Taneja argued the change cuts token counts while delivering “better reasoning, context, and better exploitability analysis.” On top sits MTTA observability across the stages, what he called a window pane, plus real-time progress views. “A pretty good step function,” he said of the release.

Advertisement

One metric, three definitions

Mean Time to Adapt, the metric Visa invented alongside the harness, gets a shorter definition in this release. The short form is the time between discovery and resolution of attack paths, with some resolutions, Visa claims, shrinking from weeks to hours. Visa published a wider construction in June, and the Project Glasswing white paper tracks MTTA along three dimensions that include inventory freshness, exploitable paths per release, and validation cycle time. The repo carries a third, elapsed time from AI-discovered exploitability to a validated fix in production. Board slides will quote the shortest interval. Ask for all three, because a resolution count that skips validation is what MTTA was invented to replace.

Taneja ranks MTTA as “the most strategically important metric” because it shifts the focus from scanning to how fast an enterprise adapts. His shorthand is blunter. “It’s not the finding. It’s the fixing that matters,” he said.

The default and the gate

Wilson’s argument went past naming the gate. “We have to remember that security rules written inside prompts may shape the model’s behavior, but they are still suggestions to the model, not enforceable security controls,” he wrote. He also priced the control honestly. “The tradeoff is that the agent loses the ability to improvise arbitrary, high-impact infrastructure changes on its own, while retaining autonomous investigation and routine, bounded remediation,” Wilson said.

The harness ships no approval step between patch and edited file. Where the human sits was the first question VentureBeat put to Visa in writing.

Advertisement

The company’s own June white paper sets the bar. “AI agents are identities” sits among its 12 non-negotiable practices, requiring scoped permissions, least privilege, audit trails, and IAM governance for every agent that modifies a system. VVAH’s shipped default is that agent.

“A lot of the traditional systems that are used today are basically signal providers,” Taneja told VentureBeat. “They are telemetry, and then it’s a lot of human analysis, and your SOC and your security and incident response teams doing a lot of the heavy lifting when they respond,” and that, he said, cannot work at this scale. He pointed to the Hugging Face incident and “other frontier models escaping sandboxes to do things more autonomously” as the preview. “We have seen the trailer of this movie,” Taneja said, and “every company in the world should prepare and rethink their architecture.”

What the harness automates is the adversarial step. Before a fix counts as validated, the panel scores whether the patch negates the exploit, Taneja’s test for done, with failed fixes feeding the next attempt, the iterate step Taneja described. Stage 11 itself runs read-only, per the README, and VVAH does not compile, build, or run tests against the patched tree. Taneja calls that wrapper “the governance architecture on top of that,” and chaining findings into working exploits takes threat modeling and business context, which is why he argued “the harness with a model is far more effective than somebody using the model by itself.”

Visa answers the gate question

VentureBeat put its questions to Visa in writing after the interview, and the answers arrived before publication. On why remediation ships on, the response repeated the bottleneck argument, then narrowed the scope. “VVAH is meant for authorized operators running against code they own, and in a controlled environment,” the company said in written responses.

Advertisement

The approval question drew the most specific answer. “VVAH is a harness, not a merge tool,” Visa wrote. “Stage 10 writes candidate fixes to a working copy of the repo. Stage 11 then runs an adversarial validation panel that scores each fix and returns one of three verdicts: validated, validation failed or needs review. None of these bypasses your normal build, test, and code review flow.” Humans, the company wrote, are “the gate in three places. Before running the tool. When reviewing the patches. And before anything gets merged.” “The final call on any fix stays with the security and engineering teams. In an enterprise, trust and auditability are not optional. The default flow is built around that.”

Set beside Wilson’s standard, the architecture lands close to his line and the sequence does not. Wilson’s gate clears an action before it happens. The default’s human gates open before the run and after the write. The attack is the automated part, and the three human gates sit outside the model, the boundary Wilson drew. “Our goal is to help security teams work at AI speed, not to replace them,” Visa wrote. “VVAH does the repetitive parts. It finds issues, tests whether they are real, and proposes fixes. Before a fix gets to a human, an adversarial validation panel at stage eleven tries to break it. That way the human is spending time on decisions that need judgment, not on triaging noise.”

Client zero got direct confirmation. “VVAH runs against Visa code today,” Visa wrote, and Taneja had volunteered the posture on the call. “We designed this and we were using it for ourselves, and we were client zero,” he said, adding “only when we saw the impact and the positive effect of what we were finding, we said every company would need this.” What adopters value, Visa says, is context. VVAH pulls in CMDB data, threat models, and business risk, and where “most tools stop at findings,” it “tries to answer, ‘which of these should you fix first, given how your business runs.’”

Model choice becomes a per-stage decision

Multi-model orchestration is the other substantive change. “Mythos has a very high recall, but the Opus model has very high precision,” Taneja said. “On stage one I want to use this model. On stage two I want to use this model,” is how Taneja framed the per-stage setup, with newer GPT releases in the ensemble and open-weight models where pricing stings, all through configuration rather than code changes. “The whole is greater than the sum of the parts,” as he put it. The harness was model-agnostic from day one, he added, and the evolution moved that choice into configuration, with prompt tuning and caching shared underneath. One boundary moved. In June, applying a fix required Anthropic backends, and OpenAI-compatible backends ran report-only. The current README extends remediation and validation to OpenAI-compatible and open-weight models through a shared model-agnostic runtime, with no single provider as a hard dependency, and the default routing for both stages stays Anthropic.

Advertisement

That flexibility lands on a market already churning. VentureBeat’s Q2 2026 Pulse research found 59% of enterprises plan to adopt or switch agent security tooling within the year, and 82% still rely on provider-native controls as the primary layer. Visa said Thursday it is contributing VVAH to Nvidia’s Open Secure AI Alliance as a model-agnostic framework and collaborating in Project Lightwell, the $5 billion IBM and Red Hat effort to harden open-source components.

Before turning fix mode on

Decision

What to establish first

Run posture

Advertisement

Start with –stop-after s9 and read the SARIF output before any run that can write to source files.

Approval gate

Map Visa’s three human gates onto the pipeline, at run, at patch review, and at merge, and name who holds each.

Validation scope

Advertisement

Stage 11 verdicts score the fix. Build, test, and code review stay in the team’s own flow, per Visa, so keep an exploit re-test before merge.

Repository scope

The tool runs with elevated privilege, per its own README. Fence which repos the harness can reach, and run scans in an ephemeral environment with scoped credentials, no production secrets, and network limited to the target repo and model endpoint. Write access to production code is the GhostJacking exposure class, an agent acting on data it read. Per the README’s egress warning, any role routed through the SDK, OpenAI, or DeepAgents backends sends prompt data to that provider’s endpoint.

Model roles

Advertisement

Assign models per stage deliberately. Recall and precision differ by model, per Taneja, the fix stages carry the highest blast radius, and the README states precision and recall figures are not yet published, so measure your own.

Consulting is the other half of Thursday’s announcement. Visa Consulting & Analytics is adding executive workshops, a VVAH-informed maturity assessment scored on a NIST one-to-five scale, and a cyber risk prioritization roadmap. “We were getting a lot of calls. Hey, can you help?” Taneja said, and the practice “became very important to handhold and help those who are using it.” Carl Rutstein, global head of Visa Consulting & Analytics, framed it the same way. “Finding vulnerabilities is no longer the hardest part. Speed to remediation is the new battleground.”

Source link

Advertisement
Continue Reading

Tech

Android 17 will finally stop ISPs from seeing which websites and apps you visit

Published

on

Even with HTTPS keeping your activity on a website private, your network provider and anyone snooping on the connection can still see exactly which sites and apps you’re visiting. This privacy gap has quietly existed for years, and Google is now closing it with four major network security upgrades built into Android 17.

How Android 17’s Encrypted Client Hello (ECH) blocks ISP tracking

Your phone has been announcing its destination out loud this whole time. Every time you connect to a site, there’s a moment in the handshake called TLS ClientHello, where your device essentially broadcasts which domain it’s about to visit, in plain, readable text. Anyone watching the network, your ISP included, can read that.

Encrypted Client Hello scrambles that data so it’s unreadable to anyone but the site you’re actually visiting. Pair that with Private DNS, and your ISP loses the ability to track where you go or stitch your browsing into a profile. Android is the first major mobile OS to roll this out broadly, built alongside Jigsaw, with developer support landing through OkHttp 5.5.0.

Three other Android 17 security features rolling out

Beyond ECH, Android 17 packs in three more upgrades that close smaller but still crucial privacy gaps:

  • Local Network Protection stops apps from silently scanning your home Wi-Fi to see what devices you own, whether that’s a smart TV, a security camera, or other connected gadgets, without asking your permission first.
  • Certificate Transparency, now enforced by default, requires every website certificate to be logged publicly, making it harder for a compromised or rogue certificate authority to issue a fake certificate and intercept your traffic without getting caught.
  • Zero-click 2G protection fights back against scams. Criminals use devices called SMS blasters to force nearby phones onto outdated, insecure 2G networks, then blast out phishing texts that slip past modern spam filters. Android 17 lets participating carriers disable 2G by default, shutting down that entire attack path automatically, with zero action required from you.

Together, these four changes will close some of the biggest privacy gaps still baked into how your phone connects to the world.

Advertisement

Source link

Continue Reading

Trending

Copyright © 2025