Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tech
Routing, Privacy, Trust and Key Differences
A VPN and Tor can both hide your normal public IP address from websites, but they use fundamentally different trust and routing models. A conventional VPN sends covered traffic through one provider-controlled endpoint, while Tor sends traffic through multiple relays so no single ordinary relay normally knows both where the connection originated and which destination it ultimately reaches.
Here, Tor means the Tor network as most people use it through Tor Browser. It does not mean the separate Tor VPN Beta, which the Tor Project currently describes as testing software that should not be relied on for sensitive activity.
Quick Take
- A VPN concentrates an important part of the connection’s trust in one VPN provider. Tor deliberately distributes route knowledge across multiple relays.
- Both can replace the public IP address a normal website sees, but Tor Browser also includes browser-level protections designed to reduce fingerprinting and tracking.
- A conventional VPN is commonly designed to cover broader device or application traffic, while Tor Browser protects its browser traffic by default and other applications require appropriate Tor configuration.
- Neither tool guarantees anonymity if you sign in to identifying accounts, reveal personal information, use a compromised device, or face an adversary outside the technology’s threat model.
VPN vs Tor at a Glance
The easiest way to compare VPN and Tor is to separate routing, trust, browser privacy, and application coverage. Neither option is universally better because they solve overlapping but different privacy problems.
| Feature | VPN | Tor / Tor Browser |
|---|---|---|
| Routing path | Covered traffic is routed through a VPN endpoint operated by the chosen provider or organization. | Traffic is routed through multiple Tor relays before reaching an ordinary internet destination. |
| Trust model | Places substantial routing trust in the VPN operator. | Distributes route knowledge across relays so one ordinary relay does not know the complete path. |
| Public IP seen by website | Normally the VPN server’s public IP for traffic exiting through the VPN. | Normally the Tor exit relay’s public IP for ordinary websites. |
| What the local ISP sees | For covered traffic, typically a connection to VPN infrastructure rather than the final tunneled destination. | When connecting directly to Tor, normally a connection to Tor nodes rather than the final destination. |
| Browser fingerprinting defenses | A VPN tunnel does not provide them by itself. | Tor Browser includes defenses intended to make users harder to distinguish by browser configuration. |
| Typical traffic scope | Can cover broad device or application traffic according to VPN routing policy. | Tor Browser covers its browser traffic by default; other compatible applications require appropriate Tor configuration. |
| Performance profile | Uses an additional VPN route and endpoint; performance depends on server, route, protocol, and network conditions. | Can add latency because traffic passes through multiple volunteer relays and is affected by network load and route conditions. |
| Onion-service support | Not a normal VPN function. | Tor Browser can access onion services through the Tor network. |
| Primary privacy model | Encrypted client-to-VPN transport plus an alternate network exit under a chosen provider. | Distributed onion routing plus Tor Browser privacy defenses. |
The table shows why “which one hides my IP?” is too narrow a comparison. Both can change the address a destination sees, but the more consequential difference is which parties can observe the user, the route, and the destination.
The Biggest Difference Is Where You Place Trust
A conventional VPN primarily changes the network intermediary you rely on. Your device establishes an encrypted tunnel to a VPN server, and covered traffic exits through that provider’s infrastructure before continuing toward its destination.
Cloudflare’s VPN explanation describes the client-to-server encrypted tunnel and the VPN server’s role as the network endpoint visible to destinations. The useful privacy question is therefore not whether a VPN removes trust, but whether you are comfortable placing that routing role with the VPN operator.
Tor takes a different approach. The Tor Project explains that ordinary Tor traffic passes through multiple relays, with layered encryption and different information available at each position. Its comparison with one-hop proxy services says Tor normally routes traffic through at least three servers before the destination.
For an ordinary web circuit, the first relay is the guard or entry relay. It receives the user’s connection but does not know the final destination. A middle relay connects adjacent parts of the circuit. The exit relay connects to the ordinary public internet but does not receive the user’s original public IP as the source of that exit-side connection.
The Tor client also negotiates separate encryption keys for each hop. The Tor Project’s technical overview of Tor circuits explains that each relay knows only its adjacent hops rather than the complete route.
Info
A VPN concentrates an important part of the route in one provider. Tor deliberately distributes route knowledge across multiple relays. That does not make Tor invulnerable, but it removes the ordinary requirement that one routing intermediary know both the incoming user connection and the final destination.
If you are comparing single-intermediary routing models, the distinction between a proxy and a VPN provides useful context. Tor differs from both by deliberately distributing the route across multiple relays.
What Your ISP, VPN Provider, Tor Relays and Websites Can See
Privacy claims make more sense when you identify the observer instead of asking whether traffic is simply “hidden.”
With a VPN
Your internet service provider still carries the connection to the VPN infrastructure. For traffic actually routed through the VPN, the ISP sees that VPN connection rather than directly carrying each covered connection to its final website.
The VPN operator occupies the next major trust position because traffic reaches its infrastructure before exiting toward internet destinations. A website normally sees the VPN server’s public IP address for traffic leaving through that endpoint.
HTTPS remains a separate protection layer. A VPN tunnel can end at the VPN server while an HTTPS connection remains encrypted between your browser or application and the website.
With Tor
The Tor Project says that when you connect directly to Tor, a local internet provider or other local observer can normally tell that you are communicating with Tor nodes but does not receive the final browsing destination from the normal Tor route. Websites instead see a connection coming from the Tor network rather than from your normal public IP. Tor’s protection overview explains this separation through its multi-hop routing model.
The guard relay sees the incoming client IP because it receives the connection. The exit side knows which ordinary internet destination it connects to. The design goal is that one ordinary relay does not receive both pieces of information as part of normal circuit operation.
This is why statements such as “Tor relays cannot see anything” are inaccurate. Each relay has information required for its role; the protection comes from separating those roles.
A useful follow-up distinction is what your ISP can see with Tor or a VPN, because local-network visibility and destination-side visibility are different parts of the same connection.
Privacy Is Not the Same as Anonymity
Neither VPN routing nor Tor routing prevents you from identifying yourself voluntarily.
If you sign in to an email account connected to your real identity, the service can still associate the session with that account. The same applies if you submit your name, phone number, address, payment details, or other identifying information.
The Tor Project makes this boundary explicit. Its Tor Browser safety guidance says perfect anonymity cannot be guaranteed and explains that signing into a website or supplying personal information identifies you to that service even though Tor may still hide your normal network location.
A conventional VPN has another limitation: its network tunnel does not automatically change the browser environment. Cookies, signed-in sessions, extensions, fonts, screen characteristics, and other browser signals can remain available to websites even when your public IP changes.
IP privacy is therefore only one part of online identifiability.
Tor Browser Adds Protections a VPN Tunnel Does Not
Browser fingerprinting combines observable browser and device characteristics that can help distinguish one browser from others. Signals may include operating-system information, fonts, browser capabilities, extensions, screen characteristics, cookies, and other state.
A VPN tunnel does not standardize those properties. Its primary function is network tunneling and routing.
Tor Browser is designed around a broader browser-privacy model. Tor Project documentation says the browser is modified to prevent or reduce several forms of identifying leakage and to make Tor users look more alike.
The distinction is important enough that the Tor Project strongly recommends against using ordinary browsers as substitutes for Tor Browser. Its current guidance specifically warns about real-IP exposure through DNS or WebRTC, fingerprinting through operating-system details, fonts and plugins, and persistent tracking state such as cookies and cache.
This does not mean Tor Browser makes every user indistinguishable under every circumstance. It means its privacy model includes browser-level defenses that a VPN tunnel by itself does not provide.
The same distinction explains why Tor Browser and private browsing should not be treated as equivalent simply because both can limit some browsing state.
Where Encryption Starts and Stops
Both VPN and Tor comparisons become misleading when “encrypted” is treated as one uninterrupted property from the device to every destination.
VPN encryption
A conventional VPN protects covered traffic inside its tunnel between the VPN client and VPN endpoint. After that point, the application’s own protocol determines what protection continues toward the destination. For ordinary modern web browsing, HTTPS can independently protect the browser-to-website session even though the VPN tunnel itself ends at the VPN server.
Tor and ordinary websites
Tor applies layers of encryption inside its relay circuit, but an ordinary website reached through an exit relay still relies on destination-side encryption such as HTTPS to protect application data on the public-internet side of the route.
The Tor Project’s Tor and HTTPS explanation treats the two protections separately. Tor changes network routing and conceals the user’s normal public IP from the destination, while HTTPS protects data exchanged with an HTTPS website.
Onion services use a different path
An onion service does not use the same public-internet exit pattern. The Tor Project’s onion-service documentation explains that both the client and service establish Tor circuits and meet through a rendezvous point, while onion-service traffic is encrypted between the client and onion host.
A `.onion` service is therefore not simply an ordinary website viewed through a Tor exit. The service connection remains inside Tor rather than emerging through a public exit relay to reach an ordinary public web server.
Tor Distributes Trust, but It Still Has Limits
Tor’s distributed design prevents one ordinary relay from simply receiving the complete source-and-destination relationship, but that is not the same as protection against every possible observer.
The Tor Project explicitly documents traffic-correlation and timing attacks as a remaining limitation. An observer capable of seeing both the user’s side of a connection and the relevant destination or exit side may compare timing patterns. Tor’s documentation on remaining attacks states that Tor does not defend against an observer that can see both ends of the communication channel.
That limitation does not make the relay architecture meaningless. It defines the threat model. Tor still prevents ordinary single relays, destination websites, and local network observers from automatically receiving the complete source-to-destination relationship.
Tor can also lose anonymity through application behavior rather than a break in onion routing. The Tor Project notes that circuits may carry multiple TCP connections, so mixing anonymous and identifying traffic or using applications carelessly can create additional correlation risks.
The more detailed architecture behind Tor guards, middle relays, exit nodes, and onion routing explains why these protections and limitations follow from the network design.
VPN vs Tor for Speed and Everyday Compatibility
A VPN and Tor both alter the normal network path, but they do so differently.
A conventional VPN generally sends covered traffic through one VPN endpoint before forwarding it toward the destination. Real performance depends on factors such as server location, congestion, protocol, route quality, device limits, and the underlying internet connection. If a VPN is unusually slow, VPN slowdown diagnosis works best by comparing the same connection with the VPN off and on before changing several settings at once.
Tor routes traffic through multiple volunteer relays. The Tor Project says Tor Browser can sometimes feel slower because traffic passes through relays in different locations and performance depends on network load and latency. It also notes that users may not always notice a meaningful speed difference.
The distinction matters most for workloads that are sensitive to latency. Interactive voice, video, gaming, and similar applications may react more strongly to additional delay than ordinary page loading, although actual results depend on route and network conditions.
Application coverage also differs. Many VPN clients are designed to route broad device traffic according to their routing policy. Tor Browser is configured for safe web browsing through Tor by default. Core Tor can be used by other compatible applications, but the Tor Project says it has not researched safe anonymity configurations for every program and recommends Tor Browser for normal browsing.
Tor should therefore not be reduced to “a slower VPN.” Its extra relays and application constraints follow from a different privacy architecture.
Should You Use a VPN and Tor Together?
Not by default.
Combining two privacy technologies does not automatically create stronger privacy. It changes which parties occupy different positions in the connection, introduces additional configuration, and can create new failure modes.
The Tor Project’s current Tor Browser known-issues guidance says VPNs tend to interfere with Tor and does not recommend using VPN and Tor together unless the user is advanced and understands how to configure both without compromising privacy.
There is therefore no general rule that stacking the technologies provides “double anonymity.” Whether a combined design changes privacy in a useful way depends on the exact routing arrangement, threat model, VPN operator, and configuration.
This comparison does not provide VPN-over-Tor or Tor-over-VPN configuration instructions. Those designs require a more specific threat model than the general comparison here.
Which option should you choose?
VPN
Choose this if: you want broader device or application traffic routed through an encrypted client-to-server tunnel, ordinary application compatibility matters, and you are prepared to place substantial routing trust in the VPN provider or organization operating the endpoint.
Avoid this if: your main privacy requirement is to avoid relying on one routing operator that occupies both the incoming client side and the outbound destination side of the VPN path.
Main trade-off: broad traffic coverage and simpler application compatibility come with a concentrated provider trust relationship, while the VPN tunnel itself does not provide Tor Browser’s anti-fingerprinting defenses.
Tor / Tor Browser
Choose this if: distributing route knowledge across multiple relays matters to your threat model, browser-level anti-fingerprinting protections are important, or you need access to onion services without relying on one VPN operator for the full route.
Avoid this if: your primary requirement is straightforward coverage for arbitrary device applications or a workflow that depends heavily on low latency and does not fit Tor’s application model.
Main trade-off: Tor reduces reliance on a single routing intermediary but introduces a multi-relay route, application constraints, and an anonymity model that still depends on how you use Tor Browser and what information you reveal.
Bottom Line
VPN and Tor overlap in one visible result: either can cause a normal website to see an address other than your ordinary public IP. Their privacy architectures are otherwise substantially different.
A conventional VPN gives you an encrypted path to one VPN endpoint and asks you to trust the operator occupying that position. Tor distributes route knowledge across multiple relays and, when used through Tor Browser, adds browser-level privacy defenses that a VPN tunnel alone does not provide. The useful choice depends on your threat model, application needs, tolerance for latency, and whether concentrating or distributing network trust better matches the problem you are trying to solve.
Tech
Big whoop and more Apple Watch nagging
In this week’s Sunday Reboot, the Apple Watch is better for your health, but maybe the rumored screen-free wearable could be better for your peace of mind.
Sunday Reboot is a weekly column covering some of the lighter stories within the Apple reality distortion field from the past seven days. All to get next week underway with a good first step.
Keeping customers alive with simplification
The September event schedule usually covers the key portable touch points Apple has with its customers. That is, iPhone, AirPods, and the Apple Watch. This year was no different, and for the wearable side, that meant new wrist-mounted models.
There’s a lot to talk about, including things like Audio Intelligence and the privacy implications, as well as Siri‘s overhaul. But health is a big thing here, too.
It is a bit for me too, on a personal note. After attending a funeral earlier in the week, it certainly makes you think about your life and about doing something that stops you from being the perennially overweight guy. But I digress.
Apple’s added a new health-sensing system with an expanded electrode surface area, more electrodes, and a better photodiode array. It’s now checking your heart every five seconds, so you know how your heart varies throughout the day.
The new Readiness score also sounds like a decently simple way to measure your capacity to work out, or quite frankly, to deal with the day ahead. It’s a fairly clear signal to anyone that they need to care more about themselves.
It’s not quite the Apple Watch screaming “Get more sleep!” or “Work out more!” but it’s going to be helpful to some of its audience.
This all plays into Apple’s changes in the Health app on iPhone and iPad, with a greater use of Apple Intelligence. Though I fear many will look at Health Age with some trepidation.
Some people will see Apple Intelligence comparing them to someone five years younger and think they’re extremely fit for their age. Others will see a Health Age that’s added a few too many years, and quietly laugh it off if it’s brought up by anyone.
I fear that if I check that figure out, I’ll face questions from Apple Intelligence asking how I’m not dead yet.
Would you just stop already?
These notifications and metrics also tie into something else that came up this week. There were rumors that Apple was prototyping a new fitness and health tracker.
Specifically, a tracker that isn’t intended to be a mini iPhone on your wrist, but more a collection of sensors that hands off the data to your iPhone. Something similar to trackers like the ones sold by Whoop, which collects data on your activity and nothing else.
You may consider it to be a dumb Apple Watch, and you’re right. It’s not going to provide you with information directly, but that is the point.
I have been a long-time user of the Apple Watch Series 4, specifically the Nike Edition one. As if the swoosh will make me do more exercise.
I have written before about how the Apple Watch is great at data collection, but also that it is also insanely good at nagging you. Every so often, your wrist dings as yet another notification comes in, and you’re too lazy to keep looking at your iPhone for once.
The amount of dings I get every day on my wrist is infuriating at times. On many occasions, I have wanted to punt the Apple Watch through a window because I hear the chime and immediately do Pavlov proud by looking at my wrist.
I have, in recent months, started wearing the Apple Watch with Do Not Disturb enabled. It has certainly helped me become less wound up and more relaxed because I’m able to ignore those wrist pings, but it doesn’t stop me from checking.
This is a problem that Apple has partially solved. With the introduction of the fitness tracking capability in the Beats Powerbeats Pro 2, it does mean I can do some workouts and exercise without the Apple Watch at all.
However, if I want to check my health from throughout the day, that’s not an option. I still have to stick with the Apple Watch and live with the potential auditory distraction.
At least the Whoop-like tracker will be there for keeping tabs on my day.
It’ll still be silently judging me, but that’s the point.
Last week’s Sunday Reboot discussed the Battersea Power Station Apple Store, and how it should be a more-used design in Apple’s retail landscape
Tech
Russia targets Ukraine’s data centers as attacks disrupt internet access for 100,000 households
What just happened? It appears that Russia has followed in Iran’s footsteps and decided to target data centers in its hostilities. A Russian drone hit a business centre in the Ukrainian capital Kyiv on Friday, killing four people and damaging a data center, which Russia later confirmed had been a target.
The September 25 attack struck Kyiv’s Solomianskyi district. Mayor Vitali Klitschko said seven people were injured, including a child, while three of those killed were found in a parking lot outside the building. The blast damaged the facade and shattered windows.
The facility belonged to Ukrainian telecommunications company Datagroup. It said none of its employees were injured and customer data remained safe. Services continued operating from backup sites, with specialists assessing the damage and working to restore the infrastructure.
“All this affects people’s ability to stay connected, study, work,” said Ukraine President Volodymyr Zelensky in a social media post. He also wrote, “The Russians are constantly expanding their escalation operation: American and other businesses, data centers, internet providers – for Russia, all ordinary life is simply a target. It is important that the world responds to all of this and that Russia feels the response to its terror.”
Russia’s defence ministry acknowledged the strike, claiming the data center processed and transmitted intelligence for Ukraine’s armed forces. Moscow also claimed attacks on facilities operated by New Telco, United DC, Kyivstar, and Parkovyi earlier in the week.
Ukraine’s digital transformation ministry said around 100,000 households in Kyiv and the surrounding region experienced internet problems following Wednesday’s attack, which damaged infrastructure belonging to providers Pavutyna and UTELS.
Some companies are already moving data from damaged servers to facilities outside Ukraine, according to the BBC, helping businesses keep their digital infrastructure beyond the reach of Russian strikes.
Losing connectivity in a war zone is obviously more serious than being unable to stream Netflix. Foreign Minister Andrii Sybiha said the strikes disrupted access to mobile air raid warnings. Banks, online payments, businesses, and government services also depend on the infrastructure now coming under attack.
There is some reassurance, however. The Institute for the Study of War’s September 25 assessment cited Ukrainian officials reporting no indications of damage to military or state communications. Providers also said Ukraine’s extensive, distributed networks make a complete internet shutdown unlikely, although repairs could push up customers’ bills.
Data centers are becoming a common target in conflicts. It was reported earlier this month that Iran’s attacks on Amazon’s Middle Eastern infrastructure left AWS unable to recover resources and data hosted exclusively in its Bahrain region. Resources in one UAE availability zone were also destroyed. Datagroup’s backups appear to have prevented a similar data-loss disaster in Ukraine.
Back in July, Iran claimed it had destroyed Amazon’s main data hub in Bahrain with cruise missiles. Tehran had also threatened the Stargate AI data center in Abu Dhabi, backed by OpenAI and Nvidia.
Image credit: DSNS Kyiv
Tech
FLIP Fluid on Flip Dots Turns a Simple Pun Into Months of Hard Labor

Mitxela wanted noise. Years of fluid simulations on LEDs had given him mercury-like sloshing on screens and a tiny wearable pendant, yet every version stayed silent. Flip-dot panels solve that problem by themselves. Each pixel is a physical disk with magnets that slaps from black to yellow and back, and a few thousand of those slaps at once sound like water moving in a shallow tray. The name sealed it. FLIP already stood for Fluid Implicit Particle. Putting that algorithm on flip dots was too cool to ignore.
Commercial high-speed flip-dot walls from places like Breakfast Studio may cost a whopping $50,000, and they simply do not bother with smaller budgets. In contrast, Mitxela struck gold when he discovered eight excess Hanover panels from 2007, the most of which had been given after sitting idle in a friend’s stash of antiquated technology. Each panel is 13 dots tall by 28 broad, and 8 of them set up in a 2 by 4 grid provide a reasonable 3000 pixels and a square meter of display space. Mitxela had originally planned a truly massive setup with 18 panels and a giant gimbal system that visitors could use to physically flip the entire thing, but with only two weeks until Electromagnetic Field 2026, he scaled the design back down to 8 panels on a static plywood frame so that the local hackspace’s laser cutter could handle the parts in one go.
Sale
MNN 15.6″ FHD 60Hz Portable Monitor USB-C HDMI IPS HDR Gaming Laptop
- Full HD Portable Monitor – MNN 15.6inch portable laptop monitor with 1920*1080 resolution, advanced IPS glossy screen support 178° full viewing…
- Double Type-C Port -For Plug & Play, the MNN monitor provides 2 Full Feature Type-C ports. Only One USB Type-C Cable is required to connect to the…
- Lightweight Ultra Slim for Travel – As a portable external monitor,MNN portable laptop monitor easily accommodate to every suitcase and backpack and…

Figuring out how to connect the dots proved to be a far greater problem than finding them. The original manufacturing electronics can refresh an entire panel in roughly a second, which is simply too sluggish for the fluid animation Mitxela desired. So he created his own driver boards, which sit on top of the original PCB and are crammed with H-bridge chips, shift registers, and a cheap CH32V003 microcontroller to monitor things via an RS485 link. It took a long time to get all of the solder joints to function on each panel, which there were over 400 of. The copper traces had to be carefully cut with a Dremel and diamond wheel, and the capacitors went through several iterations, from tiny ceramics that kept failing to 47-microfarad electrolytics, and finally to banks of eight 1000-microfarad cans per panel, just to get the 12-volt supply to cope with the massive 50-amp inrush when all the coils fired at the same time. Eventually, the whole device was able to pull more than 10-15 amps from a reworked 40 amp supply. A few dead coils had to be unwound and resoldered, short circuits on the standoffs had to be repaired, and at one point, one of the panels was erected upside down and had to be broken down and rebuilt.

A two-panel prototype was already chugging along smoothly at about 40 frames per second using a Raspberry Pi Pico 2, but the final motherboard is an STM32H7R3 running at 600 MHz and connected up to all eight of the decoder boards, it talks to a throwaway joystick Mitxela picked up from AliExpress (aptly labeled GRAVITY CONTROL) and even listens out for any movement from an accelerometer so the whole thing can respond properly to being physically tilted, and the whole frame weighs in at a quite substantial 15 kg. Viscosity, of course, was adjusted to zero, so the energy just sort of… dribbles away as the particles knock into the walls, and the display eventually settles into all sorts of bizarre, beautiful patterns that look like they belong in an art gallery.

The finished piece sat four days in the EMF lounge tent before anyone began to play with the joystick, and at nite, when the tent was quiet and nobody was troubling the item, the fluid would simply drift into those zero-gravity formations. A handful of the dots proved to be fragile and died owing to dust or over-enthusiastic fiddling by curious observers, but the most were easily repaired. Overall, the parts and boards cost less than five hundred pounds, or a few penny per dot, assuming you ignore the donated panels and the months of sweaty evenings Mitxela spent sweatily soldering it all together. When you consider the time and work required to create it, the commercial price tag appears much more acceptable.
[Source]
Tech
This wireless eGPU claims to deliver RTX 5090-like performance over Wi-Fi
First look: External graphics cards have so far been limited by their need for high-bandwidth ports such as OCuLink and Thunderbolt 5. WiCi aims to address the issue by transmitting a GPU’s horsepower over Wi-Fi. The company claims that multiple devices on a network can share an eGPU’s compute for gaming and AI workloads.
WiCi recently began inviting interested parties to sign up for updates about the WiCi One, which aims to become the first successful wireless external graphics card. The device, sponsored by Nvidia’s Inception Program, aims to support popular AI tools, games, tablets, laptops, and phones.
A few companies have floated eGPUs as a way to achieve desktop-class GPU performance on smaller devices such as laptops and mini PCs. However, to maintain the bandwidth a desktop GPU normally uses over PCIe, eGPUs have so far required the latest cable technologies such as OcuLink, Thunderbolt 5, and USB4, which many devices still do not support.

WiCi believes that Wi-Fi 7 networks can support GPU instructions across multiple devices. In one demonstration, the eGPU appears as a Wi-Fi network that a user logs into on a modest-looking laptop. Although the video does not show the exact graphics settings used, the Cyberpunk 2077 benchmark can be seen running at over 90fps. The firm says the WiCi One also handles various AI models and tools such as Hugging Face, Ollama, Blender, Unreal Engine, CapCut, OBS Studio, and more, all without modifications.
The WiCi One is expected to begin shipping in the fourth quarter of 2026 with two available models. The cheaper variant, which uses an Nvidia RTX 5060 Ti, starts at $2,000 for early birds but carries a $2,600 MSRP. Pricing information for the other version, equipped with an RTX 5090, will be available closer to launch.
According to WiCi’s internal benchmarks, the 5060 Ti edition handles Cyberpunk 2077 at approximately 80fps and Black Myth: Wukong at 60fps in 4K at ultra settings using DLSS. Meanwhile, the 5090 variant achieves 110fps in Cyberpunk and 90fps in Wukong.

Regarding LLM throughput, the 5060 Ti edition runs DeepSeek V4 Flash at 8 tok/s and Gemma 4 at 140 tok/s, while the premium model reaches 20 tok/s in DeepSeek and more than 500 tok/s in Gemma. Meanwhile, CapCut can export to 4K at 75fps on the 5060 Ti and 90fps on the 5090, while Adobe Premiere Pro can output 4K H.264 videos at 70fps and 90fps, respectively.
Interested parties can also win a WiCi One for free by submitting ideas for use cases, with prizes going to the 10 most interesting concepts.
Tech
The Velvet Underground’s 1969 ‘Closet Mix’ Returns on AAA Vinyl
The Velvet Underground spent its first two albums demonstrating how much noise, distortion, drones, sexual unease, drug references, and general discomfort could be squeezed onto a record without causing the pressing plant to call the authorities. Then, in 1969, Lou Reed and company did something arguably more surprising: they turned the volume down.
The band’s self-titled third album, The Velvet Underground, traded much of the confrontation of The Velvet Underground & Nico and White Light/White Heat for something quieter, more melodic, and considerably more intimate. More than five decades later, UMe’s Vinylphyle series is returning to the album using one of its most interesting original sources: Lou Reed’s 1969 “Closet Mix” stereo master, cut AAA by Joe Nino-Hernes and pressed at RTI on 180-gram black vinyl. The new pressing sells for $39.98 and is available exclusively through uDiscover Music.
Related Reading:

Why The Velvet Underground Matters
Released in March 1969, the album was the group’s first after co-founder John Cale departed, with Doug Yule joining Reed, Sterling Morrison, and Maureen Tucker. It was also the first Velvet Underground album produced and arranged by the band itself.
Anyone expecting another “Sister Ray” was in for a fairly substantial shock.
Songs including “Candy Says,” “Pale Blue Eyes,” “Jesus,” “I’m Set Free,” and “After Hours” revealed a far more vulnerable side of Reed’s songwriting, while “What Goes On” and “Beginning to See the Light” proved the Velvets had not suddenly misplaced their guitars. “The Murder Mystery,” meanwhile, made it clear that normality was never going to become a permanent condition.
The stylistic shift was significant. Instead of trying to make White Light/White Heat louder, uglier, or stranger, Reed pushed the band toward spare arrangements and intensely personal songs. That quieter approach anticipated a substantial part of his later solo work while offering another blueprint for subsequent generations of alternative and indie musicians who discovered that emotional directness could be every bit as subversive as distortion.
Naturally, the album failed to become a major commercial success at the time. The Velvet Underground were extremely good at influencing musicians who would eventually sell far more records than they did.

What Exactly Is the “Closet Mix”?
The Velvet Underground exists in two principal stereo mixes from 1969.
MGM/Verve engineer Val Valentin created the version that ultimately became the more widely distributed mix. Reed also prepared his own version, placing greater emphasis on the vocals and reducing the prominence of some of the instrumentation. Guitarist Sterling Morrison dubbed it the “Closet Mix” because he thought it sounded as though the album had been recorded in a closet. Not exactly the type of testimonial a modern record label would put across the top of an advertisement, but the name stuck.
The differences are not merely subtle EQ adjustments. Most notably, the two mixes use different performances of “Some Kinda Love” from the original recording sessions. Reed’s mix also creates a more intimate, vocal-forward presentation that fits particularly well with the inward-looking character of the material.
The Closet Mix appeared on some of the earliest U.S. LP pressings before the Valentin version became more common. It later resurfaced digitally on the 1995 Peel Slowly and See box set and again as part of the extensive 45th Anniversary Super Deluxe Edition in 2014, so this is not some previously unheard tape discovered behind Lou Reed’s sofa.
What is notable about the new Vinylphyle edition is the source and production chain.
AAA From the 1969 Stereo Master
UMe specifies the source as the 1969 “Closet Mix” stereo album master, with Joe Nino-Hernes handling the new all-analog cut. The finished record is pressed at RTI on 180-gram black vinyl. No digitally reconstructed master, mystery file, or creatively worded “mastered from the original recordings” language is required here: this one is AAA.
The packaging is appropriately traditional as well. Buyers get a tip-on wrapped gatefold jacket with a satin-matte finish, an archival poly-lined sleeve, and a four-panel insert containing newly commissioned liner notes from four-time Grammy nominee and author Scott B. Bomar, along with scans of the source tapes.
This also continues UMe’s Vinylphyle series, which launched in November 2025 and previously tackled The Velvet Underground & Nico. eCoustics has also examined the series through its restoration of Erykah Badu’s Mama’s Gun, where the available source material required a very different mastering approach.
And that is part of what makes Vinylphyle potentially interesting. The label is not forcing every album through precisely the same process simply so somebody can slap “audiophile” across the shrink wrap in 36-point type.
The Bottom Line
Forty dollars is hardly bargain-bin vinyl, but this is also refreshingly free of colored-vinyl gimmicks, enormous box-set architecture, or dubious anniversary arithmetic. What you are paying for is much easier to understand: Lou Reed’s original 1969 mix, the original stereo master, an all-analog cut, and an RTI pressing of one of the Velvet Underground’s most important albums.
Price & Availability
The Vinylphyle edition of The Velvet Underground is $39.98 and currently available through uDiscover Music in the United States. Orders are limited to four copies per customer, and the title is excluded from the retailer’s sitewide discounts.
Where to buy: $39.98 at uDiscover Music (ships on September 30, 2026).
Related Reading:
Tech
Beyerdynamic DT 30 IE Review: A $149 Professional IEM Built for the Stage
Beyerdynamic has built its reputation making headphones and in-ear monitors for working professionals, spending decades refining products for studio and stage use. It should therefore come as little surprise that the company has introduced a new entry-level model for aspiring sound professionals, the DT 30 IE.
Priced at $149.99, the DT 30 IE brings some of the thinking behind Beyerdynamic’s more expensive DT 70-73 IE series stage monitors to a price point that students, musicians, engineers, and other working users can more realistically afford.
That matters because the professional market has very different priorities from the broader headphone category. While much of the industry continues to push wireless connectivity, ANC, apps, and spatial audio, Beyerdynamic is addressing a more practical problem: professionals still need durable, low-latency wired monitors that can survive daily use and deliver consistent sound without depending on batteries, codecs, or software.
For musicians and engineers, an in-ear monitor is a tool first. Sound quality matters, but so do isolation, fit, durability, and the ability to trust what you are hearing every time you plug in. Expectations are high, even at the entry level, because unreliable monitoring can become a much bigger problem than simply having a bad listening experience.
Related Reading:

Design, Fit & Durability
The DT 30 IE retains the basic shape and appearance of the earlier DT 70-series in-ears, but the earpieces are made from clear polymer rather than the black material used for their higher-end siblings. The cable is also similar in design to the DT 70-series version, with MMCX connectors, memory wires, a chin slider, and a 3.5 mm plug. Once again, color distinguishes the two, with the DT 30 IE sporting a white cable.
The case and accessories are also extremely similar to those supplied with the DT 70 series. A small square clamshell case holds the cable and earpieces separately, along with several sizes of both foam and silicone ear tips.
The overall construction feels purposeful rather than luxurious. This is an earphone meant to be used, packed away, and used again, not displayed. The clear polymer is deceptively tough. I had some initial concerns because I’ve encountered other products with what appeared to be similar construction that broke the first time they were knocked off a desk.

I put the DT 30 IE through a workout, some of it intentional and some accidental, and I can assure readers that the earpieces will survive a drop from table or even ear height. The cable is sturdy as well and should hold up to repeated gigs with reasonable care. Everything about the DT 30 IE suggests that this is an entry-level professional product rather than one designed primarily for consumers.
I selected the largest silicone tips, attached the cable, and prepared to begin my listening sessions, only to run into an issue. The DT 30 IE sits fairly shallowly in the ear, and while I could achieve a good seal when inserting the earpieces, the moment I wrapped the memory wire over my ear, that seal would break.
I tried repeatedly, both with and without my glasses, and never achieved an acceptable seal using the silicone tips. With glasses, it was a complete no-go. Without them, the earpiece would seal initially but pop loose as soon as I moved my head.
Back to the kit I went for the largest pair of foam tips. Those solved the problem, providing a good seal even with my glasses pressing against the memory wires. I also tried an Estron cable and found that it did not create the same issue, allowing me to use the large silicone tips without having to fight with the fit.
Fit is crucial with any in-ear monitor, and the DT 30 IE sounds very thin when the seal is compromised. Because of its relatively shallow insertion depth, some listeners may need to use a larger tip than they normally would to maintain a proper seal. The foam tips also retain more low-end energy than the silicone alternatives, so anyone auditioning the DT 30 IE should spend some time with both before deciding which works best.

Internals & Drive Requirements
The DT 30 IE uses a single 11 mm dynamic driver rather than one of Beyerdynamic’s Tesla designs. Specific details about the diaphragm materials are difficult to come by, with Beyerdynamic describing it simply as a German-designed 11 mm driver.
Nominal impedance is rated at 18 ohms, with a frequency response of 5 Hz to 20 kHz and a sensitivity of 111 dB/mW. Those specifications place the DT 30 IE firmly in the extremely easy-to-drive category, making it suitable for everything from portable recorders and interfaces to phones and dongle DACs.
That high sensitivity does come with a potential downside. Pair the DT 30 IE with an amplifier or source with a higher noise floor, and some background hiss may become audible. There is also very little need for aggressive volume settings here; the DT 30 IE reaches useful listening levels with minimal power.

Specifications:
- Type: Wired in-ear monitor
- Driver: Single 11 mm dynamic driver
- Driver Design: Non-Tesla
- Frequency Response: 5 Hz – 20 kHz
- Impedance: 18 ohms
- Sensitivity: 111 dB/mW
- Earpiece Material: Clear polymer
- Cable Connection: MMCX
- Cable: Detachable white cable with memory wire and chin slider
- Source Connector: 3.5 mm
- Ear Tips: Multiple sizes of silicone and foam tips
- Included Case: Square clamshell carrying case

Listening
The first thing that stands out about the DT 30 IE is its sense of balance. It does not push the bass forward merely to create instant excitement, nor does it chase the exaggerated upper-treble brightness that is sometimes mistaken for detail.
Sub-bass extension is good, but you have to look for it. Tracks that do not emphasize the lowest frequencies can make the DT 30 IE sound somewhat deficient in this region, but recordings with meaningful sub-bass content reveal that it is more capable than first impressions might suggest.
Bass is tight and reasonably deep, with enough weight to give kick drums and electric bass a proper foundation. It is not especially tactile or punchy, but presence and control are both good, which fits the DT 30 IE’s professional focus.
The midrange is its strongest area. Vocals have excellent intelligibility, acoustic guitars retain their texture, and electric guitars have enough edge without becoming abrasive. Strings have good energy without turning harsh, while piano is reproduced with convincing body and clarity.
Treble is clean, moderately detailed, and reasonably extended. Cymbals have definition without sounding tinny, and smaller recording details are generally easy to locate. The tuning is slightly polite in this region, which helps reduce fatigue during long listening sessions or extended set lists.
That does not mean the DT 30 IE glosses over poor recordings. Nasal vocal tones and sibilance are still easy enough to hear when they are present, so the softer treble balance should not be mistaken for an overly forgiving presentation.
The soundstage is fairly intimate, with slightly more width than depth. Imaging benefits from solid instrument separation, and placing individual performers within an orchestral recording is relatively straightforward. Stereo separation is also good, and layered arrangements remain coherent at moderate volume, although some congestion begins to appear as volume increases with particularly dense material.
Overall, the DT 30 IE is especially well suited to vocal-heavy music, small jazz ensembles, acoustic recordings, and live performances. That balance between clarity, separation, and long-term listenability feels very much in line with what Beyerdynamic intended for an entry-level professional monitor.
The Bottom Line
The Beyerdynamic DT 30 IE is aimed squarely at musicians, students, engineers, and working professionals who need an affordable, durable in-ear monitor with balanced tuning and low listening fatigue. Its controlled bass, articulate midrange, and restrained treble make it better suited to monitoring vocals, instruments, and live performances than chasing oversized bass or exaggerated detail.
Fit is the main caveat. Eyeglass wearers may struggle with the supplied memory-wire cable, and some listeners may need foam tips or an alternative cable to maintain a proper seal.

At $149.99, the DT 30 IE is an easy recommendation as a reliable backup for performers already using custom IEMs or Beyerdynamic’s more expensive DT 70-series models. For the gig bag, that kind of inexpensive insurance makes a lot of sense.
Pros:
- Balanced, professional-focused tuning
- Excellent midrange clarity and vocal intelligibility
- Tight, controlled bass
- Non-fatiguing treble
- Good imaging and instrument separation
- Very easy to drive
- Durable construction
- Detachable MMCX cable
- Foam and silicone tips included
- Strong value as a primary or backup stage monitor
Cons:
- Sub-bass can sound restrained
- Limited punch and physical bass impact
- Soundstage is fairly intimate
- Some congestion at higher volumes with dense recordings
- Stock memory-wire cable can create fit issues
- Eyeglass wearers may need foam tips or a different cable
- High sensitivity may expose hiss from noisier sources
Our Ratings:
★★★★★★★★★★ Sound Quality
★★★★★★★★★★ Build Quality
★★★★★★★★★★ Comfort (cable/tip issues)
★★★★★★★★★★ Value
Where to Buy:
Related Reading:
Tech
TechCrunch Mobility: AV companies pick their lanes
Welcome back to TechCrunch Mobility, your hub for the future of transportation and now, more than ever, the role AI is playing in it. To get this in your inbox, sign up here for free — just click TechCrunch Mobility!
Autonomous vehicle technology is not yet ubiquitous or mainstream. Readers here might shout, “It’s everywhere!” but I can tell you that it is not — although I understand why folks in the San Francisco Bay Area might disagree.
The tech is, however, being commercialized and that transition from testing to commercial product has me thinking about scale. A few strategies are emerging.
Scale through partnerships. A couple of announcements this week highlighted this strategy. Wayve locked in a commercial partnership with Mercedes-Benz to integrate the startup’s automated driving tech into at least one model set to be deployed within the next two years. This is a Level 2 type product, meaning it handles certain driving maneuvers but still requires the human driver to remain engaged. While this is not a Level 4, or fully driverless product, it gives Wayve reach and follows similar deals with Nissan and Stellantis. Those partnerships have also opened doors for its fully driverless product. Earlier this year, Wayve announced a partnership with Nissan and Uber to launch a robotaxi service in Tokyo.
Widespread and concentrated, all at once. As I wrote this week, Waymo’s commercial robotaxi ramp-up looks expansive, both in geographic reach and ridership. And by almost every measure, it is — until you pay attention to where the bulk of those robotaxis are actually showing up.
I looked at vehicle registration data and found that, at least for now, Waymo is concentrating its efforts in just two states. About 80% of Waymo’s roughly 4,000 robotaxis are in California and Texas, and Texas is where the action is now: Waymo’s fleet there has grown by more than 49% in the past three weeks.
Waymo is also scaling by seeking out new kinds of users: teenagers.
I might put Aurora, a company developing and commercializing self-driving trucks, somewhere between these two categories. Aurora is clearly focused on Texas, but it has cast a wide net when it comes to partners. CEO Chris Urmson is also clearly bullish on how the company will scale over the next four years, noting this week that Aurora has “emerged from the building stage.” The company said it’s targeting more than 30,000 driverless trucks in operation by 2030. The company plans to have more than 200 driverless trucks by the end of the year.
A little bird

Our little bird items are typically just that: small yet notable nuggets of insider information from across the transportation industry. But every now and then, a tip turns into something much bigger.
That’s what happened a few weeks ago, when Zoox workers reached out to senior reporter Sean O’Kane about a problem with the company’s test fleet in Atlanta. Workers were getting sick, and they suspected it was from its test vehicles, Toyota Highlander SUVs equipped with Zoox’s self-driving system.
The TL;DR: Zoox grounded its autonomous vehicle test fleet in Atlanta after safety drivers were potentially exposed to carbon monoxide, carbon dioxide, or hydrogen sulfide gas inside its vehicles last month. Zoox says it only ever found evidence of CO2 in the vehicles.The repeated incidents led one worker to file a complaint with the Occupational Safety and Health Administration, which opened an inquiry and told Zoox to investigate the exposures.
You can, and should, read the whole story here.
Got a tip for us? Email Kirsten Korosec at kirsten.korosec@techcrunch.com or my Signal at kkorosec.07, or email Sean O’Kane at sean.okane@techcrunch.com.
Deals!

Wall Street may be preoccupied by whether the buzziest AI companies will go public in 2026, but there is other IPO activity in other industries, including transportation. Many of these are companies located outside of the United States.
For instance, Carro, the used car marketplace backed by SoftBank, is considering dual listing on the Nasdaq and the Singapore Exchange. Two India-based companies — used car marketplace Spinny, which is back by Tiger Global, and electric bus company PMI Electro Mobility Solutions — have both filed confidentially for IPOs. Then there’s EcoCeres, a Hong Kong-based company that produces renewable fuels, which reportedly plans to raise about $1 billion in a Hong Kong initial public offering.
And don’t forget just last week the U.S.-based autonomous vehicle company May Mobility said it planned to go public via a merger with a blank-check company.
Other deals that got my attention …
Ultraviolette, the India-based electric motorcycle manufacturer, raised $85 million and has brought on Intel CEO Lip-Bu Tan as an adviser. Read our previous coverage on Ultraviolette here.
Notable reads and other tidbits

Comma, the startup founded by hacker George Hotz, is facing a federal investigation after five reported crashes involving the company’s aftermarket hands-off driver-assistance tech, two of which resulted in three deaths.
Einride, the Swedish autonomous and electric trucking company, said it plans to use Nvidia’s Hyperion platform to build the next generation of its self-driving system.
San Francisco-based PitPro Automation has developed a robot that can change tires and has now deployed it at a shop in Canada.
The Boring Company is working on “a simple precursor Hyperloop” between Austin and San Antonio that will reduce the journey between the two cities to less than 30 minutes, according to the tunneling startup’s founder, Elon Musk.
Tesla is finally handing over the first of its all-electric Semi trucks to customers. CEO Elon Musk is known for shaky timelines, but when I attended the Semi reveal event in 2017, I didn’t think it would take nearly a decade. One insider note from reporter Sean O’Kane: “Customers will be able to take delivery of the truck whenever they are ready, though charging infrastructure remains a hurdle.”
Does AI need a learner’s permit? MIT researcher Bryan Reimer, whose work I periodically share here, weighs in.
Volkswagen is reportedly delaying the return of its ID Buzz to the United States. Meanwhile, Volkswagen subsidiary MOIA America has partnered with Beep and is now launching its first passenger services in self-driving ID Buzz vehicles equipped with Mobileye self-driving tech in the Orlando community of Lake Nona. There is still a human operator on board.
One more thing …
We’re a couple of weeks away from Disrupt 2026, TechCrunch’s annual tech conference in San Francisco. I am interviewing Rivian CEO RJ Scaringe onstage October 13, and we have a lot of ground to cover. If you recall, Rivian has some lofty plans for its R2, robotaxis, and automated driving. And then there is Scaringe’s other projects, the spinout Also and Mind Robotics.
If you’re in San Francisco during Disrupt, you should come. And I’m offering you a 30% discount with code mobility30 by following this link. There are other interesting talks besides Scaringe, plus dozens of startups to check out. Check out the agenda here, which includes talks with folks from startup Bedrock Robotics, GM, and self-driving trucks company Waabi. Les Karpas, Nvidia’s head of physical AI, and Mark Wahlberg will also be there, among many, many others.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Tech
Trump to host Anthropic’s Dario Amodei at White House dinner, Axios reports
President Donald Trump plans to host Anthropic boss Dario Amodei at a private White House dinner on Sunday evening. Maria Curi and Marc Caputo broke the news for Axios, citing people familiar with the matter.
It would be the first one-on-one meeting between the two, according to Axios. TNW has not independently confirmed the dinner.
TNW is owned by Tekpon. Anthropic’s Claude is listed on Tekpon’s marketplace.
Amodei missed last week’s state dinner for Chinese President Xi Jinping, which OpenAI’s Sam Altman and Google’s Sundar Pichai attended, because of a scheduling conflict. Trump then invited him personally to Sunday’s dinner, Axios reported.
On Tuesday, Trump and House Speaker Mike Johnson are due to meet tech CEOs on AI at the White House. Johnson has said the talks will cover the companies’ responsibility to keep AI safe.
Anthropic’s ties with the White House have had ups and downs this year. In April, the White House opposed the company’s plan to widen access to its Mythos model.
In June, after meeting Amodei at the G7 summit, Trump said he no longer saw Anthropic as a national security threat. Even so, some top officials had told Trump not to meet him, Axios reported.
The dinner also comes after Amodei called this month for the whole AI industry to slow down, a call Trump has brushed aside.
“President Trump has been clear: America will lead the world in Super Intelligence, while protecting American consumers,” a White House official told Axios.
Tech
Some Pancreatic Cells Are Just One Genetic Tweak Away From Treating Diabetes
A human pancreas typically contains about a billion beta cells, the primary producers of insulin. Among people with diabetes, these cells are either missing or dysfunctional, and thus scientists have been looking for ways to replenish their numbers as a possible long-term treatment or even cure for the condition. A team of researchers recently took a step closer to that reality, genetically altering another type of pancreatic cell to produce and release insulin in response to high blood sugar.
The researchers engineered ductal cells, which—as some previous studies had found—occasionally transform into beta cells all on their own. This is an unusual phenomenon among cells in adult bodies, which tend to be firmly fixed in their identities, and it hinted to the scientists that these ductal cells would be a good place to start.
Scientists previously had no clue what genes were driving this metamorphosis, said Jian Li, a postdoctoral researcher at Harvard Medical School who led the recent study in Science Translational Medicine. The researchers therefore took an approach called a genetic screen, which involves breaking little bits of DNA all across the genome to see which are important for a certain biological process. It’s a bit like individually removing pieces of a car engine without a schematic and seeing what breaks to learn which components are involved in delivering fuel or are essential for steering.
Through this process, the researchers found that taking out a gene called ALDH3B2 turned ductal cells into beta-like cells at a higher rate. Without the genetic alteration, fewer than 1 percent of ductal cells spontaneously took on a beta-cell-like state, but when ALDH3B2 was silenced, that proportion increased to about 8.5 percent.
Those initial experiments were performed on human cells in a dish, which the researchers then transplanted into mice with diabetes. Human insulin began circulating in the mice, and the animals’ glucose levels dropped to near-normal levels. These effects persisted for six weeks.
Science has previously explored some gene therapies for diabetes with the hopes of offering long-term relief. For example, a clinical trial launched earlier this year is taking the creative approach of equipping muscle cells with the genetic instructions to make insulin. Other emerging treatments aim to generate new insulin-producing cells in the laboratory and then transplant them into the patient.
This comes with a few risks, namely activation of the immune system. This new study points to another possibility: harnessing the cells that already exist in the pancreas and causing them to change function by turning off some of the genetic switches that maintain their identity.
That method also has its own hurdles, one of the most important of which is ensuring that only the target cells are edited. ALDH3B2 is used by many cells in the body, not just in the pancreas, so precision is important to prevent unforeseen complications.
There’s also a major lingering question: How is this gene involved in turning ductal cells into beta cells? “That’s the part we need to verify first,” Li said. Then, “the next step is either gene therapy or to find specific small molecules to inhibit this gene to see if we can achieve a similar—or even better—effect.”
Even partial improvement could make a massive impact in the lives of the estimated 830 million people who have diabetes worldwide, including many who die each year due to related complications.
This story originally appeared on WIRED en Español and has been translated from Spanish.
Tech
Citrix confirms two NetScaler RCE zero-days exploited in attacks
Update: Article rewritten with official confirmation from Citrix.
Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.
The vulnerabilities are the same zero-days that cybersecurity researchers, IT providers, and national cybersecurity agencies began privately warning organizations about over the weekend.
NetScaler appliances are particularly valuable targets because organizations commonly deploy them as Internet-facing edge devices that provide remote access and application delivery services for internal corporate networks.
Compromising one of these devices can give attackers an initial foothold at the perimeter of a victim’s network and potentially provide a path to internal systems without first compromising an endpoint inside the organization.
The first signs of the incident appeared when Citrix administrators began reporting on Reddit that IT suppliers and security teams were privately contacting their organizations and advising them to shut down their NetScaler appliances.
“We got a call from our IT supplier’s security team, they couldn’t give any details but they advised to shut our Netscalers down immediately,” one administrator wrote.
Other administrators said law enforcement, CERTs, and national cybersecurity agencies had also been contacting organizations about the issue.
Cybersecurity firm watchTowr later publicly warned that it was “rapidly reacting to rumors” that multiple unpatched Citrix NetScaler remote code execution vulnerabilities were being exploited in the wild after verifying the information with “authoratitive sources.”
“We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild. While details are scarce, the information is credible,” watchTowr said.
Citrix confirms active exploitation
Citrix has now published security bulletin CTX697096, confirming the vulnerabilities and releasing patches for affected NetScaler ADC and NetScaler Gateway appliances.
CVE-2026-88771 is a remote code execution vulnerability caused by improper input validation, allowing an unauthenticated attacker to execute arbitrary commands. It has a severity score of 9.5.
Citrix says the flaw affects all NetScaler ADC and NetScaler Gateway deployments, including those using the default configuration, and does not require any additional feature to be enabled.
CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or a denial-of-service condition, also with a severity score of 9.5.
This vulnerability can be exploited when DTLS is enabled on a NetScaler ADC or NetScaler Gateway. Citrix notes that DTLS is enabled by default on VPN virtual servers.
Citrix has confirmed that both flaws have been exploited in attacks against NetScaler devices as zero-days.
“Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed,” Citrix said in the security bulletin.
Citrix says the following versions are affected:
- NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
- NetScaler ADC FIPS before 14.1-73.37 FIPS
- NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Citrix says the bulletin only applies to customer-managed NetScaler ADC and NetScaler Gateway appliances. Cloud Software Group is upgrading Citrix-managed cloud services and Citrix-managed Adaptive Authentication.
The security bulletin also fixes six other NetScaler vulnerabilities, bringing the total to eight flaws fixed in this update.
NCSC warned organizations before disclosure
Before Citrix publicly disclosed the vulnerabilities, the Dutch National Cyber Security Center (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands warning about two critical NetScaler zero-days.
Multiple people shared copies of the notification online, which said the agency had received information from a European partner CERT regarding two vulnerabilities that could independently lead to remote code execution.
According to the notice, one vulnerability allowed attackers to place shellcode directly into memory, while technical details about the second vulnerability were still being researched.
At the time, no CVE identifiers had been assigned, and Citrix had not yet published an advisory.
The notification said Citrix discovered the vulnerabilities while investigating incidents in customer environments and identified active exploitation.
It also said Citrix submitted a notification under the European Union’s Cyber Resilience Act after discovering the attacks.
The NCSC said exploitation had been identified at multiple Citrix customers worldwide, although it did not know whether the attacks were widespread.
The agency also warned that exploitation attempts could increase once Citrix released patches and additional technical details.
Because NetScaler upgrades can cause downtime, the NCSC said the warning was intended to give organizations time to prepare, implement safeguards where possible, and install patches quickly once they became available.
BleepingComputer contacted the Dutch NCSC to confirm whether the advisory circulating online was legitimate.
The agency declined to confirm the notification, saying it could not provide further information to organizations outside its constituency.
“As part of our role as the National CSIRT and sectoral CSIRT for designated organizations, the NCSC-NL monitors relevant developments and cyber threats affecting the Netherlands 24/7,” the NCSC-NL told BleepingComputer.
“We provide information and advice to organizations so that they can take appropriate measures. As you’re not part of our constituency, we cannot disclose any further information at this time.”
Now that Citrix has released fixes and confirmed exploitation, administrators should upgrade affected NetScaler ADC and NetScaler Gateway appliances to the patched versions as soon as possible.
Organizations that cannot apply the updates immediately should reduce Internet exposure where operationally possible until they can patch the appliances.
-
Fashion2 days agoWeekend Open Thread: J.McLaughlin – Corporette.com
-
Crypto World5 days agoGoldman Sachs and Deutsche Bank Agree: The S&P 500 Rally Isn't Over
-
Tech7 days agoResearchers escape OpenAI Codex sandbox to run commands on host
-
Fashion3 days ago8 iPhone Accessories That Add Personality
-
Crypto World7 days agoWho Needs CLARITY Anyway? ARB Could See 70X Increase: Hodler’s Digest
-
Entertainment5 days agoThese 17 Fall Amazon Dresses Seriously Look Like Anthropologie
-
Business7 days agoAnalog Devices (ADI) Bets $1.35 Billion on Chips that Let Machines Think for Themselves
-
Crypto World7 days agoCoinbase, Robinhood, Circle Seen as Tokenized-Stock Winners
-
Tech5 days agoReolink’s solar 4K security camera falls to its lowest price in months
-
Crypto World5 days agoThis Bearish Netflix Stock Trade Can Cash In On Video Streaming Giant’s Woes
-
Crypto World5 days agoTrump-Xi Polymarket Odds for Handshake Hit 50%
-
Tech6 days agoGoogle’s $899 Googlebook is a bet that you’ll buy a new laptop for Gemini
-
Crypto World4 days agoCrude Oil Prices Pressured by Diplomatic Hopes in the Middle East
-
Business5 days agoOil Price Today (September 23): Crude oil below $100 on hopes of US-Iran talks. What did Trump say?
-
Crypto World4 days agoBitcoin price tests $83,600 Supertrend support after $87K rejection
-
Crypto World4 days agoBitcoin Threatens Sub-$84,000 Breakdown as Long Liquidations Spike
-
Crypto World6 days agoMeta Jumps 11% As Muse Shines and Investors Show an Appetite for Advancing AI
-
Crypto World5 days agoDid Jim Cramer Just Give GameStop Stock the Kiss of Death When He Said the Turnaround Is Working?
-
Crypto World7 days agoBitcoin price holds above $81K as key catalysts line up
-
Crypto World5 days agoBitGo says Bitcoin absorbed Fed hike, CLARITY failure






You must be logged in to post a comment Login