Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tech
Seattle’s Nuance Labs raises $50M to give AI models human expression and nuance

Nuance Labs, a Seattle-based artificial intelligence startup developing a foundational AI model designed to perceive and respond to real-time human expression, raised $50 million in Series A funding.
Founded in early 2025 by former Apple PhD researchers Fangchang Ma, Edward Zhang, and Karren Yang, the research lab is developing a single “full-duplex” foundation model designed to process and generate conversational cues simultaneously.
@media (max-width: 600px) {
aside.callout { float:none !important; max-width:100% !important; margin-left:0 !important; margin-right:0 !important; }
aside.callout .callout-img { display:none !important; }
}
Unlike traditional setups that chain together separate tools for transcription, text generation, and voice or animation, Nuance’s model ingests live audiovisual signals like tone, gaze, and timing to stream real-time facial and vocal responses.
Existing avatars and voice tools fail because they force humans to adapt to the machine rather than the other way around, according to Ma, Nuance’s CEO.
“The most productive collaboration comes from being able to express yourself freely, in words, tone, gesture, and expression, the way you would with a friend or close colleague, with all the nuance in the back-and-forth that turns talking into understanding,” Ma said in a news release. “That’s what we’re building at Nuance Labs: AI that understands the many ways we express ourselves and responds the way a person does, in the moment.”
In a demo video accompanying the announcement (below), the startup showcased an avatar built to function as an active listener, adjusting its facial expressions and verbal cues dynamically as the user speaks.
Zhang, Nuance’s CTO, earned his PhD in computer graphics from the University of Washington and met Ma at Apple’s engineering office in Seattle. The two spoke to GeekWire last fall about building in Seattle rather than Silicon Valley and how they want Nuance “to be the premier research lab in Seattle.”
The startup plans to release a public research preview of its model later this year, giving users their first hands-on test of the interactive face-to-face avatar. Nuance targets applications where real-time human expression drives outcomes, including sales, customer service, professional coaching, and education.
Returning investor Lightspeed Venture Partners led the round, which also included participation from existing backers Accel and South Park Commons, alongside new investments from NVIDIA and Define Ventures.
The financing brings Nuance Labs’ total capital raised to $60 million following its $10 million seed round last year.
Nuance, which employs 27, plans to use the fresh capital to accelerate model development and hire researchers and engineers across modeling, data, evaluation, and real-time serving as it expands its team.
Tech
Malware bypasses browser checks to force install Chrome, Edge extensions
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data.
Researchers at Elastic Security Labs found that the malicious extensions bypass Chromium’s integrity mechanisms and load in browsers as if they had been approved by the user.
The infection chain starts after the target user opens a JavaScript file disguised as a bank receipt, invoice, payment record, or business document.
After passing anti-sandbox checks, the file triggers a fake error while simultaneously downloading Node.js, establishing persistence through a scheduled task, and retrieving the additional payload location from an Ethereum smart contract.
Despite the name, KREMLIN is linked to a Brazilian operation responsible for at least seven campaigns since May 2025 that use lures impersonating 12 banks.
Installing Chrome and Edge add-ons
A standout feature of KREMLIN is its capability to install extensions on Chrome and Edge browsers without asking the user to approve them.
It waits for the browser to close or terminates it when it detects idle status, and then copies the extension into the app’s profile directories. Next, it enables developer mode and adds the extension to Chromium’s Secure Preferences.
To hide its activity, the malware uses the encryption keys the browser uses to protect sensitive data and then recreates the integrity checks Chrome uses to detect changes in browser preferences.
This makes the malicious extension appear valid to the browser despite never being approved by the user, a documented but rarely used technique according to the researchers.
“KREMLIN uses a documented technique rarely observed in malware: it manually copies the extension into the browser’s profile directories and registers it in the Secure Preferences file,” Elastic explains.
“Because Chromium protects these entries with cryptographic integrity checks, the malware must retrieve the required keys and regenerate the associated HMACs and encrypted hashes.”
Once installed, the extension masquerades as AVSync and performs the following actions:
- Steals cookies, local storage, and session storage
- Keylogs text entered into forms, including passwords
- Captures screenshots and page source
- Enumerates open tabs and browsing history
- Intercepts HTTP request bodies and headers
- Injects attacker-controlled HTML into websites
- Redirects clicks to attacker-selected destinations
- Receives commands through a WebSocket connection
Apart from the malicious extension, the KREMLIN toolkit also acts as an info-stealer that can archive and exfiltrate browser databases, cookies, installed extensions, and the App-Bound cryptographic keys needed to decrypt protected data.

Source: Elastic
Disrupting the operation
Elastic Security Labs researchers found that KREMLIN malware campaigns use Ethereum smart contracts as dead-drop resolvers and also abuse the Internet Archive service to host payloads hidden inside JPEG images.
In more recent campaigns, the threat actor deployed the REMCOS remote access tool, but past operations pushed the Pulsar RAT. According to the researchers, the switch was likely due to REMCOS being more feature rich.
By connecting the dots through infrastructure analysis and code artifacts, the researchers found the Ethereum wallet that deployed and updated the smart contracts
According to the researchers, the wallet handled roughly 20,800 USDT (Tether) and 19,000 USDT in incoming and outgoing transfers, respectively. Elastic has confirmed 1,515 infected systems, almost all located in Brazil.
The security firm disrupted the current KREMLIN campaign by registering a domain that the malware used as an anti-sandbox canary, causing the loader to stop due to false flags on systems that would otherwise qualify for infection.
Elastic Security Labs researchers shared the tactics and techniques used in KREMLIN attacks, as well as a set of indicators of compromise.
Tech
Adafruit's New CircuitPython 'Turbo' Brings Native Code To Tiny Boards
Targeting students and beginners, Adafruit released “CircuitPython” in 2017 (as a derivative of the MicroPython microcontroller-optimized programming language).
Now Adafruit managing director Phillip Torrone (also long-time Slashdot reader ptorrone) brings this update:
Adafruit has published CircuitPython Turbo, a workflow that compiles selected Python functions into native machine code on a computer, then loads them onto compatible microcontroller boards.
It builds on MicroPython’s Native and Viper emitters. In a documented Metro RP2040 fixed-point Mandelbrot test, Viper cut computation time from 8.335 seconds to 0.423 seconds, a 19.71x speedup over bytecode. The rest of the application stays in Python. The guide includes benchmarks, source code and hardware demos. The speedup is for the measured computation, not the whole application.
“Turbo support is now included in the latest official CircuitPython builds for RP2040 and RP2350 boards…” explains Torrone’s announcement at Adafruit.com. “The new Turbo in CircuitPython helps when the board spends time calculating: making neopixel effects, drawing fractals, processing audio, filtering sensor readings, or preparing lots of pixels. Those projects can get smoother animation, quicker responses, or room to do more things at once.”
With Turbo, it’s easier, better, and now even faster to make LED light up costumes that also reacts to sound at the same time, a sensor dashboard with animated graphics, or a tiny game doing physics while drawing the screen. Turbo speeds up the busy Python parts. It won’t make a slow sensor or display connection faster… Your computer turns selected functions into instructions the chip can run directly. Python still handles the rest.
We have measured speedups, real display captures, and examples you can pull apart to see what happened. None of this arrived alone. CircuitPython, MicroPython, PyMCU, compiler tools, open hardware, and people sharing their work gave us pieces to connect. The Bao experiments take that idea somewhere else, handing calculations to four helper cores. Now we get to make those paths easier to use, compare results, and find the next useful thing. Maybe that’s smoother animation, a responsive instrument, or an idea we haven’t tried yet.
That’s what I like about open source. Someone shares a piece, someone else sees a possibility, and we get to keep building it together.
Read more of this story at Slashdot.
Tech
Apple is reportedly developing an enterprise server built on its own chips
Apple is developing an enterprise server built on its own M8 Ultra chips and has discussed using Nvidia’s NVLink Fusion to connect them, aiming at AI developers, companies and governments from around 2029, The Information reported. The European Commission proposed its Cloud and AI Development Act in June, grading public cloud contracts by how far a provider sits outside third-country control.
Apple is working on an enterprise server built on its own chips and has discussed using Nvidia’s networking equipment, The Information reported. It would sell the machine to AI developers, companies and governments.
Two versions are described, one carrying two of Apple’s forthcoming M8 Ultra chips and a larger one carrying four. Nvidia’s NVLink Fusion would connect them, the interconnect it already licenses to Qualcomm, Arm, Fujitsu, Marvell and others.
Nothing would reach the market before 2029. The effort could be cancelled, or proceed without Nvidia’s technology at all. Shares in both companies barely moved on the report.
Apple already builds servers, for itself. Private Cloud Compute ran only on Apple silicon until June, when the company extended it to Google Cloud running on Nvidia GPUs and Intel processors.
It has not sold one since 2011, when the Xserve was discontinued after a run of nearly nine years.
Governments is the interesting word.
The Commission’s June proposal for a Cloud and AI Development Act would grade public contracts by tiers of sovereignty assurance. The highest tier, meant for defence and national security, requires a European cybersecurity certificate and effective control over every software component. No third country may control a provider’s design, development or maintenance.
Europe has already shown what it accepts in practice, and it is less absolute than that sounds.
A six-year, EUR 180M sovereign cloud framework went to four groups in April. One was a Proximus-led consortium including a Thales and Google venture, alongside Mistral AI. American infrastructure qualified.
Non-European technologies, operated within a strict and appropriate framework, can meet the minimum level of sovereignty required, the Commission said at the time. Bidders were judged against eight objectives, from legal exposure to supply chain transparency.
The distinction is between sovereign operation and sovereign technology. A machine a government owns and runs in its own building is an easier argument to make than a service somebody else runs.
The Act covers cloud services rather than hardware, so a server sale would sit outside it altogether. The procurement instinct behind it would not, and buyers write their own conditions.
Europe is short of the thing no regulation conjures. You cannot regulate your way to sovereignty, as Dan Toma argued here last month, when the silicon is American either way.
Tech
Providence to receive $1.1B from Nike co-founder to build women’s health hospital in Oregon

Providence will receive $1.1 billion — one of the largest gifts ever pledged to a U.S. healthcare institution — from Nike co-founder Phil Knight and his wife, Penny. The donation will allow the nonprofit health network to build Oregon’s first hospital focused on women’s health, increase support for cardiovascular services and improve patient care.
“Penny and I have always believed that real breakthroughs come from people willing to take on the toughest challenges,” Phil Knight said in a statement. “Providence has shown that kind of ambition in cardiovascular care, and we see the same opportunity to do something truly distinctive for women’s health.”
The funds are being directed to Portland’s Providence St. Vincent Medical Center and to Providence Heart Institute.
The new women’s hospital will be located on the campus of the medical center and provide care in specialties including gynecology, pregnancy, labor and delivery, menopause and cardiovascular care. Providence leaders note that many pregnant patients are also managing hypertension, diabetes, behavioral health and substance abuse, requiring more specialized services.

The Knights have previously donated $200 million over the course of 10 years to Providence Heart Institute, which sees nearly 63,000 patients each year across the Pacific Northwest, up from 40,000 a decade ago. Cardiovascular disease is the leading cause of death and hospitalization in the U.S.
The added support for the institute will help pay for diagnostic cardiac imaging, additional clinical trials, and the recruitment of leading doctors.
Knight, 88, co-founded Nike with Bill Bowerman in Eugene, Ore., in 1964. The business was originally called Blue Ribbon Sports before rebranding seven years later. Knight is currently worth an estimated $25.4 billion, according to Forbes.
“The Knights’ extraordinary gift is a generational investment, leading to bold and innovative ideas that will shape healthcare in Oregon for decades to come,” said Jennifer Burrows, chief executive of Providence Oregon.
Tech
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide.
The malware features data theft and espionage capabilities that collect email, Telegram, and WhatsApp communications, take screenshots, and record audio.
The threat actor primarily targeted individuals in the U.S., U.K., and the Netherlands, whose cybersecurity agencies published a joint advisory with the FBI.
A typical attack begins with social engineering messages impersonating trusted contacts or technical support agents, sent to targets via WhatsApp or Telegram.
The threat actor tricks victims into opening malicious files disguised as legitimate applications (e.g., Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, KeePass), often suggesting they launch them on personal devices to bypass corporate security blocks.
Depending on the pretext used, the hackers sometimes used even medical-related lures, the agencies found.

Source: NCSC
The apps display a convincing interface that matches the lure, while silently installing CHOSEN BRICK in the background and securing persistence through Windows Registry Run keys.
The malware adds Microsoft Defender exclusions to evade detection and connects to a unique Telegram bot that matches the victim’s ID and provides command-and-control (C2).
Once launched, CHOSEN BRICK can perform the following actions:
- Collect system information
- Enumerate running processes
- Capture screenshots
- Record audio through the microphone
- Steal email content
- Steal Telegram or WhatsApp browser data
- Download additional payloads to “C:\Windows \SysWOW64”
- Delete files
- Wipe the entire host system
The stolen data is exfiltrated through Telegram or cloud services like VultrObjects and StorjShare, while newer CHOSEN BRICK variants route traffic through SOCKS5 proxies to conceal the activity.
The advisory notes that the stolen data sometimes ends up on pro-Iranian leak sites, serving as a form of harassment and increasing the physical risk for dissidents abroad.
“Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists,” the government agencies say.
“In some cases, the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, who they perceive as enemies of the regime.”
Potential victims and organizations should inspect Registry Run entries for suspicious entries, search logs for indicators of compromise (IoCs) shared in the advisory.
Unexpected connections to Telegram’s API, Backblaze B2, VultrObjects, StorjShare, IPRoyal, and LightningProxies should be investigated as suspicious.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tech
GIGABYTE Expands Its AIO Cooler Lineup With New EAGLE 360 Series
GIGABYTE has added two new models, the EAGLE 360 and the EAGLE 360 ICE AIO Liquid Coolers, to its family of PC coolers. These models feature a 360mm radiator and are designed for gaming and intensive creation work. They were designed to work with GIGABYTE EAGLE motherboards and GPUs. The EAGLE 360 is black, while the EAGLE 360 ICE is white. Both models also focus on easy installation and a clean-looking PC build.
Cooling Performance and Key Features
The GIGABYTE EAGLE 360 series uses a 3,200 RPM pump to handle CPU heat during heavy workloads. The pump is paired with three air-intensive PWM fans and a 360mm radiator, helping keep modern Intel and AMD CPUs consistently cool. In addition, the cooling solution simplifies PC assembly for the manufacturer. GIGABYTE pre-installs the fans on the radiator. Simplified cabling helps keep the inside of the PC cleaner.
The coolers also use simplified cabling to reduce clutter inside the PC. A single mounting bracket supports both Intel and AMD platforms. This means builders do not need separate mounting hardware for different supported sockets.
Design, RGB, and Availability

The EAGLE 360 series also focuses on design and customization. The pump features a magnetic EAGLE Accent Cover that users can easily remove and rotate. This lets users align the EAGLE logo with their PC build’s orientation. The pump and fans also feature subtle RGB lighting for added customization.
Users can adjust the lighting to their preference and sync it with other compatible devices. The black EAGLE 360 suits any standard PC build, while the EAGLE 360 ICE offers a white variant and is best for a white-themed PC build. Both models will be available through GIGABYTE’s authorized retailers. GIGABYTE has not yet announced pricing details for the new coolers.
Tech
Windows 11 KB5124008 update breaks domain trust for some users
Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials.
Administrators report on Reddit and Microsoft’s Q&A forums that affected computers lose their secure channel with Active Directory after the Windows 11 update is installed and devices reboot.
Last week, Microsoft confirmed to BleepingComputer that it is aware of the reports and is investigating.
“Microsoft is aware of these reports and is investigating. We will share guidance as it becomes available,” Microsoft told BleepingComputer.
While Microsoft has not confirmed the root cause, reports indicate that the failures are linked to the Windows Machine Identity Isolation security feature, especially when it is enabled in audit or enforcement mode.
Domain trust breaks after installing KB5124008
In Windows Active Directory, domain-joined computers use machine account credentials to maintain a secure channel with domain controllers.
If those locally stored credentials no longer match what Active Directory expects, the secure channel can fail. This can cause users to receive domain trust errors or be told their username or password is incorrect even though their credentials are valid.
Alex Turner, a Windows administrator who reported the issue on Microsoft’s Q&A forums, said Windows 11 25H2 workstations worked normally before KB5124008 was installed. However, after installing the update, the devices started having domain login failures after a reboot.
Cached credentials continued to work while the systems were offline, indicating the problem was tied to domain authentication rather than the users’ passwords.
The administrator said testing showed the computer’s secure channel with Active Directory had broken and that the issue could be reproduced consistently. Uninstalling KB5124008 and repairing the domain relationship restored access, while reinstalling the update caused the failure to return.
Another administrator on Reddit reported that 11 Windows 11 25H2 Enterprise devices out of approximately 256 devices lost domain trust after being updated.
The administrator also found numerous Kerberos authentication failures followed by NTLM and Netlogon fallbacks on affected systems.
Another administrator said every Windows 11 25H2 workstation on their network began rejecting valid domain credentials after installing the updates.
Turner later linked the failures to a Windows security setting called “Machine Identity Isolation,” which he said was set to ‘2’, or enforcement mode, after KB5124008 was installed.
Another administrator investigating the issue reported seeing the same behavior, saying ‘MachineIdentityIsolation’ was set to ‘2’ after the update and that disabling the feature stopped Windows from discarding the machine account LSA secret without requiring KB5124008 to be removed.
The feature is part of Windows’ Virtualization-Based Security and Credential Guard configuration and isolates machine account credentials used by domain-joined computers to authenticate with Active Directory.
In enforcement mode, Windows moves the machine account secret into Credential Guard and removes the copy stored in LSA.
The setting can be controlled through the following registry value:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"MachineIdentityIsolation"
Some administrators have restored affected systems by setting ‘MachineIdentityIsolation’ to ‘0’, rebooting, and then repairing the machine’s secure channel using PowerShell.
One administrator said the following PowerShell command, run as administrator, restored the secure channel after disabling the feature:
Test-ComputerSecureChannel -Repair -Credential(Get-Credential)
“After a reboot, I had to restore the secure channel by ‘Test-ComputerSecureChannel -Repair -Credential(Get-Credential)’. Since then, the computer is running without loosing the secure channel anymore,” explained Marcel Zehnder.
However, administrators should be careful about disabling Machine Identity Isolation as it could also cause similar problems.
Another administrator warned that changing the setting from audit or enforcement mode to disabled caused domain trust failures across their environment, including on systems that had never installed KB5124008.
Microsoft’s documentation also warns that if Machine Identity Isolation was previously enabled in enforcement mode, disabling it will break domain authentication and require the device to be unjoined and rejoined to the domain.
Microsoft has not yet confirmed that Machine Identity Isolation is the root cause of the KB5124008 failures and has not published an official workaround.
BleepingComputer will update the story when Microsoft provides additional information about its investigation.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tech
Court: The First Amendment Allows You To Tell The ICE Director He’s A ‘Sad, Despised Man’
You may recall that back in July we had the ridiculous story of how ICE decided to go all gestapo on its critics, including tracking down and threatening David Streever, who had emailed then-acting ICE director Todd Lyons back in January, after federal agents killed some peaceful protestors in Minnesota. Streever’s email was pretty straightforward:
“You are a monstrous human being and will go down in history as America’s Reinhard Heydrich, the butcher.
“The way you are protecting the obvious execution in Minnesota, even as we see the videos, will lead to your downfall. Even Trump will turn on you before the end, and you will be a sad, despised man who eats himself alive with shame at your own pathetic weakness.
“You will never know peace. You will seek to lose yourself, to escape the burden of knowing the truth about yourself. But wherever you go, you will find yourself. You will torment yourself until your last day on Earth.”
Honestly, pretty mild, given what monsters nominal immigration officials have become. But, alas, DHS couldn’t handle someone being mean on main to their boss. They sent federal law enforcement officials to try to find him at his home to leave him a “warning” about his email. When they found out that Streever was out of the country (taking his daughter to an amusement park in Finland), they tracked his flight home and showed up at the hotel near JFK where he was staying overnight, hoping — unsuccessfully — to meet with him. Agents also left a ridiculous “warning notice” with Streever’s wife:

As our initial article made clear, everything about this was bizarre, intimidating, and stupid. ICE’s “Office of Professional Responsibility” is supposed to be making sure that ICE agents are acting professionally and responsibly — not engaging in unprofessional and irresponsible investigations of people who are criticizing ICE leaders.
Streever, along with lawyers from FIRE, sued Homeland Security, and just received a big initial win. Judge Rudolph Contreras is not at all impressed with DHS’s arguments, and points out that criticizing public officials is kind of a big deal here, what with our First Amendment and all:
Americans have long voiced their displeasure with their government. The Declaration of Independence itself is a list of grievances between Americans and the British government. And Americans have not always indulged in the elevated prose of the Declaration. Government officials have long endured “vehement, caustic, and sometimes unpleasantly sharp attacks.” N.Y. Times Co. v. Sullivan, 376 U.S. 254, 270 (1964).
Today is no different. Plaintiff David Streever expressed his displeasure with the United States Immigration and Customs Enforcement (“ICE”) by sending a three-paragraph email to the agency’s Acting Director, Defendant Todd Lyons. Mr. Streever compared Acting Director Lyons to an infamous Nazi and predicted that he would become “a sad, despised man who eats himself alive with shame at [his] own pathetic weakness.”
What is different is how the government responded in this case. ICE dispatched agents to Mr. Streever’s home and delivered to him a “WARNING NOTICE.” The notice threatened him with prosecution if he did not “discontinue” his criticism of ICE. Because that notice likely violates Mr. Streever’s First Amendment right to free speech, the Court will grant, in part, Mr. Streever’s motion for preliminary injunction, enjoining Defendants from relying on the Warning Notice, issuing similar threats, or making good on the threats in the Warning Notice.
Note — as the court does — that nothing in Streever’s email to Lyons came anywhere close to being a “true threat” that would take it out of the protective cloak of the First Amendment. Hell, it’s not even remotely near what could be read as a threat:
More importantly, the email does not contain a physical threat. The email registered displeasure with Acting Director Lyons’s official conduct, forecasted that the Acting Director will lose favor with the President, and warned that the moral weight of the Acting Director’s actions will haunt him in the future…. Although Mr. Streever’s email was not kind, and may not have been particularly productive, it was a far cry from a “[t]rue threat[ ] of violence” sufficient for the email to shed its First Amendment protections.
The court notes that ICE had apparently “closed” the investigation after delivering that bizarre notice to Streever’s wife, but never informed Streever that the investigation was closed. However, when Streever sued, DHS decided to respond publicly to a post by FIRE about the lawsuit:

If you can’t see that, it’s DHS angrily posting:
Any allegation DHS and its components are attempting to ‘squash’ free speech is categorically FALSE.
ICE investigates all credible threats towards its employees and officers, including threats to the ICE Director. As a matter of policy, we do not comment on any ongoing investigations.
Our law enforcement officers are on the frontlines arresting terrorists, gang members, murderers, child sex abusers, and rapists. They are experiencing coordinated campaigns of violence against them and facing a 1,300% increase in assaults against them, a 3,300% increase in vehicular attacks, and an 8,000% increase in death threats.
ANYONE who assaults or threatens our law enforcement officers will face the consequences.
Thing is, a federal judge now says that’s bullshit, and that this was obviously an attempt to squash free speech. Indeed, this very tweet comes back to hurt DHS, as the judge sees that it is clearly designed to further intimidate Streever and others.
Still, the judge rejects part of Streever’s request for an injunction against being investigated, noting that ICE claims they closed the investigation into him. Streever points out that the tweet suggests otherwise, but the judge accepts that ICE’s investigation is over.
But he is greatly troubled by that bullshit “warning notice” left at his home, and notes that even if the investigation is closed, the “warning notice” and its speech suppressing statements are still in effect:
The Warning Notice is a different matter. Defendants have not disavowed the Warning Notice, nor do they deny that it remains in effect. The Warning Notice therefore provides a continuing injury over which Mr. Streever has standing to sue.
The Supreme Court has recognized that when the government directly threatens a party with future enforcement actions targeting their First Amendment activity, it creates an on-going injury at least where there is a “distinct possibility of” enforcement.
And since the notice orders Streever to self-censor to avoid future trouble, the court sees it as a real First Amendment problem for DHS:
Mr. Streever likewise faces a distinct possibility of prosecution for future speech. The Warning Notice requests that Mr. Streever “discontinue” his political speech and threatens prosecution, if he does not.
And here’s where that raging tweet harms DHS’s case even further:
Even if the Warning Notice were not explicit enough, a DHS spokesperson later posted on social media, in response to a post about Mr. Streever’s lawsuit, specifically referencing a purported “credible threat towards . . . the ICE Director” and warned that “ANYONE who assaults or threatens our law enforcement officers will face the consequences.” Homeland Security (@DHSgov), X (July 6, 2026, at 3:06 p.m.). This public statement and the reference to “consequences” further underscores that Mr. Streever faces a credible threat of government reprisal.
Judge Contreras does not buy DHS’s retort that they’re simply warning Streever not to violate federal law, pointing out that there’s no way you can read the Warning Notice that isn’t an attempt to suppress Streever’s speech:
Defendants dismiss the Warning Notice as merely a reminder to Mr. Streever “not to violate federal law” and argue it represents at most a past injury. Defs.’ Opp’n at 19. The Warning Notice, however, is not quite so innocuous. In the opening paragraph, it identifies Mr. Streever’s January email and states that OPR “has reason to believe [it] may constitute a violation of Title 18 of the U.S. Code.” Compl., Ex. 2. It then requests that Mr. Streever “promptly remove and/or discontinue the aforementioned behavior.” Id. (emphasis added). Defendants seem to understand “aforementioned behavior” to refer to criminal threats generally. But because of the immediately preceding reference to Mr. Streever’s email to Acting Director Lyons, this request is fairly read as a demand that Mr. Streever refrain from criticizing Acting Director Lyons.
The notice also warns Mr. Streever of the potential for prosecution. After describing Mr. Streever’s email as a potential “violation of Title 18,” the notice goes on to describe various crimes under that title and remind Mr. Streever that “[v]iolations of these or related laws could subject you to both federal and state prosecution.” Id. (emphasis removed). If that were not enough, the letter closes by telling Mr. Streever that “[r]eceipt of this Notice will be taken into consideration, should you continue to be involved in any criminal activities described above.” Id. The use of “continue” implies that Mr. Streever’s email already exposed him to criminal liability and, critically, that any similar speech by Mr. Streever in the future will be viewed the same way.
All told, the Warning Notice demands that Mr. Streever “discontinue” his political speech criticizing Acting Director Lyons. It does so while reminding Mr. Streever of the risk of prosecution and warning him that if he “continue[s]” to criticize Acting Director Lyons and ICE, the fact that he has been warned for his past speech “will be taken into consideration,” implying future prosecutions. Political speech is not a crime, so that is hardly a reminder to follow the law. And because the Warning Notice speaks of “discontinu[ing]” Mr. Streever’s political speech and threatens consequences if he “continue[s]” to speak out, it represents a continuing, rather than a past, injury.
The court also rejects the argument from DHS that Streever is trying to block a “speculative” future harm of being arrested and or prosecuted. But as the judge points out, that’s not the issue here. The existing chilling effect on speech is already a harm:
Mr. Streever is not merely alleging that he will be injured at some point in the future because he will face an investigation or prosecution down the line. That would be closer to the risk of being subjected to a chokehold in the future in Lyons because it would rely on predicting the future actions of Mr. Streever and law enforcement. …
Mr. Streever’s injury is the loss of his freedom to engage in political speech now because the threat of such an investigation or prosecution looms over him like the sword of Damocles, and he is forced to self-censor under that threat…. That loss of speech is both imminent and certain because it does not rely on Defendants actually opening a new investigation. The Warning Notice works because Mr. Streever is too intimidated by the threat of future government action that he will not test whether the government will follow through on its threat. As the Supreme Court recently explained, “[t]he value of a sword of Damocles is that it hangs—not that it drops.” First Choice, 608 U.S. at 192 (quoting Arnett v. Kennedy, 416 U.S. 134, 231 (1974) (Marshall, J., dissenting)).
DHS also claims that because Streever doesn’t have any “concrete plans” to engage in more such speech in the future, then he can’t show harm. The court (rightly) finds that argument to be quite silly:
Even viewed through the lens of a future injury, Mr. Streever’s case is distinguishable from those cited by Defendants because the type of speech at issue here is different. Mr. Streever seeks to engage in speech through off-the-cuff emails and comments on social media…. This spontaneous speech is different in kind from the sorts of premediated future activities for which courts have expected concrete plans. … Given the spontaneous nature of the speech at issue here, it would be pedantic to require Mr. Streever to detail exactly when he anticipates speaking out against the government next and what he plans to say.
In the end, the court won’t bar the government from investigating Streever (again, ICE insists the investigation is closed) but it does vacate the “Warning Notice” outright, and bars DHS from leaning on it going forward. While the judge considers Streever’s request to block future investigations of his speech, the judge notes he’s not sure he can really do that. If future speech actually contains true threats or violates laws in other ways, an investigation has to be allowed. But clearly mindful of the chilling effects here, the court makes it clear that continuing to harass Streever over his political speech is not allowed.
The Court will, for the time being, vacate the Warning Notice; it will preliminarily enjoin Defendants from relying on the Warning Notice and Mr. Streever’s January email in future prosecutions and investigative demands; and it will preliminarily enjoin Defendants from issuing similar warnings to Mr. Streever that suggest he cannot engage in non-threatening criticism of the government.
DHS whined to the judge that ICE is facing oh so many threats (based on very bullshit claims by DHS), but the judge notes that this is a narrow injunction, one that still leaves ICE free to investigate actual threats. But it does mean that you are free to let ICE officers know that they are monstrous human beings who will be reviled in history, and that they are sad and despised.
Tech
Apple’s latest iOS 27.2 trick could keep you out of the doghouse
Apple only started rolling out iOS 27 yesterday, but Apple is already working on the next update, which has a small feature that could prove surprisingly useful. As MacRumors points out, the latest iOS 27.2 beta adds an anniversary reminder to Call Context, which can warn you about an important date just before you place a call.
Call Context itself arrived with iOS 27. We previously covered one of its more delightful tricks, where calling someone on their birthday brings up a reminder along with a small fireworks animation. The iOS 27.2 beta now takes that idea a little further by adding anniversaries into the mix.

Your iPhone can give you one last reminder
If an anniversary has been saved in someone’s contact card, iOS 27.2 can surface the date on the call screen when you contact them that day. Unlike birthdays, anniversaries do not get their own animation, so the fireworks remain exclusive to birthday calls for now.
Call Context can also pull relevant information from apps such as Mail when it may be useful during a call. Anniversary support gives the feature a more personal role alongside the practical information it already surfaces.
There is still one catch
The anniversary has to be saved in Contacts first. Apple includes an anniversary option under the date field, while supported Apple Intelligence devices can also use Siri AI to add it to a contact card. Apple has not released iOS 27.2 to the public yet, so the feature is currently limited to the beta build. The update is expected to roll out more broadly in October.
Tech
Nvidia and AMD’s next gaming GPUs could be delayed until 2028, because AI pays better
Connecting the dots: Nvidia’s RTX 60 series Rubin GPUs and most of AMD’s RDNA 5-based Radeon 10000 series gaming cards have reportedly been pushed back to 2028. The delay would come down to persistent AI demand, which continues to make data center hardware far more profitable than consumer products.
Responding to a forum question about the release timing for Nvidia and AMD’s next-generation graphics cards, the generally reliable leaker Kepler_L2 said on the AnandTech forums that nearly the entire stack from both companies is now expected to arrive in 2028, as AI accelerator demand keeps eating into available capacity. The lone exception is AMD’s “AT2” GPU, still reportedly on track to launch next year.
Kepler_L2’s post appears to directly contradict a recent report from YouTube channel Moore’s Law is Dead, which claimed Nvidia was gearing up to launch its next-gen RTX 60 series – including the flagship RTX 6090 – in the first half of 2027. Kepler_L2 dismissed the claim outright.
Speaking to Dutch outlet Tweakers in June, several of AMD’s board partners said they had little clarity on the release window for the next-generation cards. Some expected shipments to begin by mid-to-late 2027; others said availability could slip into early 2028.
Neither Nvidia nor AMD has said much publicly about its next-generation gaming GPUs, but rumors point to the so-called AT2 as an RDNA 5-based die with 8 Shader Engines, each carrying 5 Compute Units, for 40 Compute Units in total. It’s expected to power an upper-midrange card, possibly with 12GB of VRAM on a 192-bit memory bus.
Also check out: Cost Per Frame: Nvidia Stops Offering Good Value GPUs to Gamers – see what’s the “best value” GPU in your region
AT2 could end up going up against Nvidia’s current GeForce RTX 5080, a step up from AMD’s existing flagship, the Radeon RX 9070 XT, which trades blows with the mid-range RTX 5070 Ti. All of this, though, comes from unverified third-party sources and should be treated as such.
Nvidia has already shown off its Vera Rubin “Superchip” for AI data centers, but has stayed quiet on the consumer side. AMD hasn’t said much about RDNA 5 either, though an earlier Kepler_L2 leak claimed the flagship Navi 5X GPU could hit clock speeds of up to 3.4GHz, with 12,288 cores and 32GB of GDDR7 memory.
-
Fashion5 days agoWeekend Open Thread – Corporette.com
-
Tech4 days agoThe Latest Weird Thing to Play Doom Is the Mapped-Out Brain of a Fruit Fly
-
Business6 days ago10 Most-Streamed Songs On Spotify In 2026 So Far, Led By Ella Langley’s Dominant Run On The Charts This Year
-
Crypto World6 days agoXAG/USD: Silver’s Short-Term Rally Meets Its Moment of Truth
-
Crypto World7 days ago2 Chip Stocks Broke Out This Week. Neither Was Nvidia
-
Tech6 days agoBattery life is the only iPhone 18 Pro and iPhone Duo upgrade I care about. Apple didn’t disappoint
-
Crypto World6 days agoOKX launches 10x OpenAI, Anthropic X-Perps in Europe
-
Crypto World6 days agoDiesel Tops $6 a Gallon for the First Time as 28 States Set Records
-
News Videos6 days agoFacing Financial Fears
-
Crypto World3 days agoElon Musk Drops a Bombshell: Grok 5 Could Be the AGI Breakthrough
-
Business7 days agoWestern Digital Slips 2.7% as AI Storage Rally Cools After Record Cash and Guidance
-
Business4 days agoRivals Sam Altman and Elon Musk Rally Behind Dario Amodei’s Call for a Slowdown in AI Development
-
Business7 days agoFive Leading AI Experts Warn Superintelligence Could Kill Humans and Explain Their Case
-
Crypto World6 days ago
Ethereum Price Analysis: Consolidation at $2.5K Tests Momentum as On-Chain Activity Surges
-
NewsBeat3 days ago‘Sick conspiracy’: Trump says only guardrails AI needs is ‘a strong and smart (High IQ!) president’ in all-caps rant
-
Crypto World2 days agoKraken Lets xStocks Holders Earn Yield Through DeFi
-
Crypto World7 days agoAnt International joins Visa, Mastercard to build AI agent payment standards
-
Crypto World5 days agoCan AI Build a Startup in 72 Hours? Elon Musk's Team Will Livestream the Test
-
Crypto World6 days agoUS CPI forecast at 3.4% as tariff risks build
-
Crypto World6 days agoBitcoin ETFs Pull $167M as 2026’s Best Inflow Run Slows



You must be logged in to post a comment Login