Connect with us

Tech

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

Published

on

Smiling hacker

The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.

The attack began Friday night when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, which they used to upload a small text file to Clop’s site.

File downloaded from Clop's data leak site
File downloaded from Clop’s data leak site
Source: BleepingComputer

The small text file contained a message from the threat actors to the Clop ransomware gang, warning not to threaten them and including a link to ShinyHunter’s own data leak site.

“THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p – Maybe don’t try to threaten us next time,” read the uploaded file.

File uploaded to Clop's data leak site
File uploaded to Clop’s data leak site
Source: BleepingComputer

The file also contained a link to the ShinyHunters data leak site.

BleepingComputer confirmed that the file had been uploaded to Clop’s server and could be downloaded directly from the ransomware gang’s Tor site.

Advertisement

Several hours later, ShinyHunters told BleepingComputer that they had “completely defaced” the Clop site.

Visiting the site confirmed it had been replaced with a page displaying ASCII art of Umbreon, the Pokémon used as ShinyHunters’ logo. The defacement also included a link to the group’s Tor site and the message, “rooting your systems since ’19 ;)”.

Clop's data leak site defaced by ShinyHunters
Clop’s data leak site defaced by ShinyHunters
Source: BleepingComputer

At the time of this writing, the defaced page is still being served from Clop’s infrastructure, according to ShinyHunters.

ShinyHunters claims data theft

ShinyHunters told BleepingComputer it gained “full access” to the server and stole source code, Grav CMS plugins, system logs, and other data.

“The data we stole includes source codes, gravCMS plugins, and other things. We are still downloading and reviewing them,” ShinyHunters told BleepingComputer.

Advertisement

The threat actors also claim to have stolen all files stored under /var/log, which could contain system activity, authentication logs, and potentially, the IP addresses of those who connected to it.

ShinyHunters also claims to have obtained the private keys used by Clop’s Tor onion service.

“We have their onion keys. So if they kick us out it wouldn’t matter at all because we control the private keys to host the same exact onion URL,” the threat actor claimed.

If the keys are valid, it would allow the threat actors to operate a Tor site using Clop’s existing onion address on servers they control.

Advertisement

BleepingComputer has independently confirmed the defacement and earlier uploaded file but has not independently verified ShinyHunters’ claims that it stole server logs, source code, or Clop’s onion private keys.

ShinyHunters says it is now reviewing the allegedly stolen data.

When asked what they planned to do with the stolen information, the threat actor responded, “Going to extort them.”

The group says it plans to publish a message on its own leak site instructing Clop to contact them within 72 hours.

Advertisement

Cybersecurity researcher VXDB told BleepingComputer the Umbreon artwork now displayed on Clop’s leak site is the same as what was used in the August 2020 defacement of the HackForums website, which ShinyHunters also claimed at the time.

Feud between cybercrime groups

ShinyHunters says the attack is retaliation for threats allegedly made by a Clop representative during an ongoing feud between the cybercrime groups.

According to ShinyHunters, a Clop representative threatened to identify group members and made violent threats after ShinyHunters disrupted a Clop data theft campaign.

ShinyHunters says the dispute dates back to Clop’s 2025 Oracle E-Business Suite data theft campaign.

Advertisement

In October 2025, Clop exploited multiple vulnerabilities in Oracle E-Business Suite servers, including a zero-day flaw tracked as CVE-2025-61882, to steal data from organizations in extortion campaigns.

Around the same time, threat actors calling themselves “Scattered Lapsus$ Hunters,” including ShinyHunters, leaked a proof-of-concept exploit that Oracle later confirmed matched an exploit used in the Clop attacks.

At the time, ShinyHunters told BleepingComputer the exploit had originally belonged to them and that Clop obtained it without authorization.

ShinyHunters claims that tensions escalated after the Oracle campaign, with a Clop representative allegedly threatening members of the group.

Advertisement

“During the Oracle EBS campaign they ran and stole from me last year, someone from cl0p personally messaged me and said, and I quote (translated from Russian): I have more money than you and all of your people combined, I’ll kill you soon,” ShinyHunters told BleepingComputer.

BleepingComputer has not independently verified these allegations and has contacted Clop about the breach and the allegations made by ShinyHunters and will update the story if we receive a response.


article image

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Tired of Cluttered Productivity Apps? This One’s Just a Text Document

Published

on

I’ve spent decades testing, reviewing, and (most importantly) using different to-do list applications. It’s a career, yes, but it’s also a bit of an obsession.

And I think we can all admit that most of these apps are way too complicated. A to-do list is just a list. Humans have been making lists for thousands of years, long before computers existed. Paper works well, but so does a stone slate if that’s what you’ve got handy.

It’s possible that you, a modern human, absolutely need a to-do list application with bells and whistles—due dates, recurring tasks, sharing features, and maybe even an AI integration. But there’s a good chance all you need is the digital equivalent of a piece of paper: A simple list of things that need to get done.

And that’s what Tasks.txt, a totally free Mac app, offers. From Ukrainian programmer Yevhen Kharkivskyi, this tool is based on the todo.txt system developed by Gina Trapani. It’s a complete alternative to a to-do list app that is based on a single text file.

Advertisement

The important thing here, though, is that it offers more than just a text file. This is a well-executed app. Open Tasks.txt and you’ll see a simple list broken down into three categories: Done, Next, and Backlog.

Image may contain Page and Text

Screenshot: Justin Pot

The general idea is to use “Next” for the tasks you want to accomplish today and “Backlog” for the things you want to do later. The “Done” section is populated as you check things off, then cleared out at the beginning of every day.

It’s possible to use this application using only the keyboard, which I love. Open the window and you can just start typing tasks—your cursor is already active in the text box at the bottom. Hit Enter and your task will be added either to Backlog or Next, depending on what you choose in the drop-down menu to the right of your text box. Press the Tab key to switch from the text box to your task list. You can use the arrows to change which task is currently selected. Pressing the Enter key adds a note below the name of a task, and Cmd+Enter marks a task complete. You can also move tasks up and down the list using Cmd+Up/Down.

There are no unnecessary controls or interface elements in your way. You can open this application, decide what you need to do, then get to it. And you aren’t stuck using keyboard shortcuts—using the mouse is just as intuitive, if that’s what you prefer.

Advertisement

Source link

Continue Reading

Tech

Petlibro’s new AI-powered feeder is a game changer for multi-cat homes

Published

on

Smart feeders have become one of the most crowded categories in pet tech, with companies racing to add AI cameras and health tracking to devices that used to just dispense food on a schedule. I enjoyed testing Petlibro’s wet food dispenser a couple of years ago, so this time I wanted to try something from the company’s newest automatic feeder lineup: the Granary 2 series, designed specifically for dry food.

I was not disappointed. Building on the brand’s Granary line, the Granary 2 series lineup is designed to give cat parents a clearer picture of what their pets are actually eating, from how much food they consume to how long they spend eating and whether their habits change over time. 

The series includes four models, priced from $129.99 to $249.99. The Granary 2 is the entry-level option, offering app-controlled feeding, precise portioning, and intake tracking. The $189.99 Granary 2 Vision, which is the one I tested, adds an AI-powered camera capable of recognizing up to 10 cats and tracking each pet’s individual eating habits. 

The $199.99 Vision Duo is aimed at multi-pet households, with two separate dispensing chutes and bowls so each pet can receive its own portion, and the company says that its most expensive model, the Granary 2 X ($249.99), uses AI recognition to provide individualized portioning for pets with specific dietary needs.

Advertisement
Image Credits:Petlibro

The biggest upgrade across the Granary 2 series is its built-in scale. The feeder can measure food in the tray, allowing it to track not only how much food was dispensed but also how much remains in the bowl. That gives it a better way to estimate how much your pet actually ate. While a traditional automatic feeder can tell you that it released a meal at 7 p.m., it can’t necessarily tell you whether your cat ate it, how much it ate, or how long it took to finish. 

The Granary 2 tracks intake, eating duration, feeding frequency, as well as favorite eating times and eating speed. Over time, the companion app builds a picture of your pet’s normal eating patterns, with daily, weekly, monthly and yearly views, which could make it easier to notice subtle changes in appetite or routine that might otherwise go unnoticed. For pet parents who closely monitor weight, portion sizes, or eating behavior, this could be the feature that makes the Granary 2 worth considering. 

Image Credits:Petlibro

The Granary 2 offers two primary feeding modes: Smart Refill Mode and Scheduled Mode. 

Smart Refill Mode keeps the bowl supplied with smaller, fresh portions throughout the day while automatically stopping once the daily food limit you’ve set has been reached. This could be particularly useful for cats that prefer to graze rather than eat one or two larger meals. 

Scheduled Mode offers more traditional control, allowing you to set specific feeding times and portion sizes. There’s also a manual feeding button for those times when you want to dispense food outside of the normal schedule.

The version I tested adds another neat layer, with an AI-powered camera that can recognize which pet is eating and automatically associate the meal with the correct profile, which is especially useful in a multi-pet household. If one cat is on a special diet, needs to manage their weight, or has different nutritional requirements from the others, being able to track individual meals is super helpful. It will only open the feeder when the correct pet is recognized by the camera.

Advertisement

The 1080p camera also includes night vision, allowing you to check in on your cat while you’re away and see what’s happening around the feeder. There’s two-way audio as well, so you can communicate with your pet remotely. And if you’re the type of pet parent who likes to call your cat to dinner, you can record a short message that plays directly from the feeder.

Additionally, the feeder can send instant app alerts for issues such as low battery power, low food levels, and if food jams in the feeder. Those notifications provide some added reassurance when you’re away from home, since you don’t have to wonder whether the feeder is still working properly or whether a problem has prevented your pet from getting its meal. It also has a built-in rechargeable backup battery for when there’s a power outage. 

Image Credits:Petlibro

It’s important to note, however, that some of the Granary 2’s more advanced features are tied to Petlibro’s subscription services. Certain health tracking and monitoring features require a Petlibro Care subscription (starting at $59.99 per year), while cloud recording and playback on camera-equipped models require paying for a Video Cloud plan ($119.99 per year).

Overall, I do think this is one of the best feeders I’ve tested, but if you’re looking for a more affordable option, the closest comparison is Pawsync’s $79.99 feeder. It uses a built-in scale to ensure accurate portions, along with settings designed to help prevent both underfeeding and overfeeding.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Advertisement

Source link

Continue Reading

Tech

Laser Your Way Into Debug Mode On The RP2350

Published

on

The RP2350 is actually a pretty secure chip, all things considered. It has secure boot, ARMv8’s TrustZone to split secure and non-secure execution, and you can permanently disable debug — the Pi Foundation even included glitch detection, meaning the traditional ‘zap the chip until it obeys’ technique is blocked. That’s why the [Ledger Donjon] security team went full Bond Villain and strapped everyone’s favourite fruit-flavoured microcontroller to a table with a slowly-approaching laser beam.

The bench setup to do all this is pretty impressive– and came with an impressive 250,000 USD price tag.

Okay — movie clichés aside, the laser was in fact very carefully focused on target before they turned it on. That target was the register that enables the 2350’s debug features. Said register was located by decapsulating the chip and examining the die with photon-emission electron microscopy; the actual attack was carried out on a chip that had been decapped on the back side, with IR shining through the silicon wafer. There was probably more than a little trial-and-error to figure out exactly where on the die adjacent to the register to zap with the laser to flip those bits. But flip they did, restoring the debugger’s access to the secure execution zone. Then, after resetting the chip, [Ledger]’s team read the 128-bit secret the Pi Foundation hid in memory as part of the 2350 hacking challenge.

It’s long been accepted that once the black hats — or white hats, for that matter — have their hands on your hardware, they’re going to find a way in. The effort it takes to break into a simple microcontroller here is actually kind of impressive. We’ve talked about laser fault injection before; ironically, we’ve also featured Pi Pico-powered glitching attacks — the kind that this chip’s glitch detection thwarts.

Advertisement

Source link

Continue Reading

Tech

Is The Leatherman Raptor Worth The Price? Here’s What First Responders Say

Published

on





We may receive a commission on purchases made from links.

A proudly American brand with many of its products hailing from Oregon, Leatherman has made a name for itself for its dozens of reliable multitool offerings in its portfolio. Whether you want a companion for your outdoor camping trips, everyday adventures, or even for professional use, there’s bound to be one for you. If there’s one group of people who need an easy to grab tool for all kinds of unexpected situations, it’s first responders. First responders are often confronted obstacles that can get in the way of them giving necessary, immediate care. While their workplace may provide some tools, many people still want something that they know will always work exactly when they need them to, like the Leatherman Raptor Rescue.

Advertisement

It retails for $79.95 on the On the Leatherman website and Amazon,with two sheath types: molle holster and utility holster. Both holsters come in seven colors, plus options for limited edition options, such as rainbow and rose gold. Leatherman covers it under its 25-year warranty. While it has a lot fewer features than other popular Leatherman multi-tools, it has tools designed specifically for first responders. Here’s what you need to know about it and what emergency professionals had to say about it.

Advertisement

What you need to know about the Leatherman Raptor

The Leatherman Raptor has five tools with its premium scissors being one of the most commonly praised features. You can tighten or loosen the sheers for improved cutting performance, especially if you encounter tougher materials. For people who work in the field, like paramedics or police, the glass breaker and strap cutter can be useful for pulling people out of cars. There’s also an oxygen tank wrench and ring cutter, but Leatherman notes that it’s made for gold and silver rings rather than stronger materials like titanium. This means you’ll need to use something else if you plan to cut those made of harder metals.

Weighing 5.8 oz (or like half a deck of cards), it can be folded and made for on-the-go use. When it’s closed, it’s just five inches in length and opens up to eight inches. It’s a little under two inches wide and 0.67 inches thick. The silver-colored shear, which is made of 420 stainless steel, is 1.9 inches long. It also has a bead blast finish and a lock with handles in different colors. But take note, since pivoting issues are the most common problems with Leatherman multi-tools you will need to regularly clean it with soap and water, plus top off with PTFE-based lubricants to maintain smooth movement. Lastly, you’ll also need to sharpen the shears regularly.

Advertisement

What do first responders have to say about the Leatherman Raptor

On the Leatherman website, the Raptor Rescue has been rated 4.8 stars on average from more than 2000 reviewers, where most people (89%) have rated it 5 stars. On Amazon, it shares the same 4.8-star rating from 600+ people, plus it’s an Overall Pick product. One person, who gifted it to his trauma nurse partner, said that they liked it so much that after using it for about a decade, he bought a second pair. A Reddit user wrote that they had a pair for seven years, and they cut through everything from leather boots to cable tire chains. Another person in the Paramedics subreddit praised it as a good investment and that it functioned well for seatbelts, barbed wire, and clothes.

However, not everyone is satisfied with its performance with its price being the primary point of contention. An EMS professional shared that the hears fail to cut even the simplest thing, and they often had to borrow someone else’s. On the Firefighting subreddit, one Reddit user thought it’s still more cost-effective to just buy cheaper options and replace them regularly with several first responders echoing his comment. In particular, one person on the r/ParamedicsAU thread said that they rust easily and don’t recommend them because they’re too high maintenance.

Advertisement



Source link

Advertisement
Continue Reading

Tech

The US Navy just told us what’s on its tech wish list for the next several years

Published

on

Justin Fanelli, the Department of Navy’s chief technology officer, has spent the last three and a half years trying to make the U.S. Navy easier to do business with. When we first talked to him last year, he described a shift away from what he called “your granddaddy’s government” — a “spaghetti chart” of entry points for startups — into something closer to a funnel, where companies that show strong results get pulled into the Navy’s technology base as enterprise services.

This week, we caught up with him again on a video call, and this time, he wasn’t just looking again to further streamline the procurement process, he was sprinting, literally, to catch a flight he’d just been ordered onto with no destination shared.

“You have an hour and 15 minutes to get on a plane,” Fanelli said, recounting what he’d just been told, speaking into his phone as he walked, the sun shining behind him. “I’m like, ‘Where?’ Oh my God! And they were like, ‘We’ll figure [the logistics], we’ll tell you as you get there.’ And I’m like, ‘For more than overnight?’ And they were like, ‘Yes.’” As he was walking to his car, he was still unsure what he’d packed for or where he was headed. “I will figure that out in the next 20 minutes,” he said, sounding excited about the adventure ahead.

Fanelli reached out because the “demand signal” he sent to investors last year had only grown, and it was making an impact, he said. When the Navy first published its longer-term technology priorities, investors told him it changed how they thought about the Navy’s buying plans, which is part of why he’s doing it again — sharing a fresh list of what the Navy wants to buy in the next several years, this time vetted by a handful of (unnamed) venture investors before release.

Advertisement

How much money the Navy actually puts to work each year depends on what counts as spending, Fanelli said. “We spend in the $150 billion range every year,” he said, though he was careful to separate that number — total Navy purchasing — from something narrower, like direct equity investment. 

Indeed, while most of that spending still flows through traditional channels, Fanelli said the Navy is trying to inch further toward what he calls co-investment — putting money behind companies alongside private capital rather than writing a check to an established prime contractor. Taking an equity stake, he said, is the most aggressive version of that and remains rare. More often, co-investment means the Navy waits for companies to mature a product on their own before buying it, rather than funding early research itself.

The stage of company the Navy buys from has shifted, too. “We mostly buy Series D through F type companies,” Fanelli said, adding that the Navy used to fund its own early-stage research to cover the seed-through-Series-B gap. It’s trying to hand that job to commercial investors instead, which is part of why the priorities document exists at all. “The cost of that, or the responsibility, is for us, if we’re not going to do it ourselves, to cast a cleaner signal,” he said.

As for recent purchases, Fanelli — a former Air Force cadet whose career has spanned roles across defense, intelligence, DARPA, and open source initiatives — rattled off a handful. A contract worth $562 million was awarded this month for the MQ-25 Stingray, an autonomous refueling drone that extends the range of manned fighter jets flying off carriers.

Advertisement

The Navy has also been buying edge compute hardware from Armada, described loosely as shipping containers packed with servers meant for ship or remote deployment. It brought in Gecko Robotics to handle inspection work that used to be done manually and dangerously; Fanelli said the move drew little pushback because almost nobody wanted that job in the first place. Domino Data Lab is now running the Navy’s machine learning pipeline.

And in a case Fanelli seemed to particularly enjoy sharing, the Navy swapped a defense contractor’s years-delayed shipboard camera system for commercial cameras paired with software from Applied Intuition, cutting roughly four years off the timeline and expanding to more ships than expected.

Given the Strait of Hormuz has been a flashpoint this year — tanker strikes, a seized vessel, ceasefires that have broken down over shipping-route disputes — it seemed worth asking whether any of that commercial technology is showing up there now. Fanelli was cautious. “I often don’t know what’s classified and unclassified because I’m normally talking to people with clearances,” he said, adding that he’d have to check. (We’ll let you know if he gets back to us.)

Interestingly, not many people sign off on a purchase like that, according to Fanelli. Buying decisions run through what he called a source selection committee, a small group rather than the sprawling review process outsiders might picture. He described the goal as keeping the process merit-based rather than adding layers of approval.

Advertisement

He didn’t get into why technologies typically fail once they’re inside the Navy — he’d arrived at his car and needed to figure out next steps for travel. But when we talked last year, Fanelli explained that the most common reason promising technologies fail isn’t technical, but rather budgetary. The Navy runs on long planning cycles, and a new tool only sticks around if it replaces or “turns off” something the Navy is already paying for.

Either way, before we parted ways, Fanelli shared an updated internal list of the technology areas the Navy is prioritizing, jointly issued by his office and the Portfolio Acquisition Executive for Mission Systems. It breaks down into five broad categories, for those of you either developing or funding defense tech.

The first is applied AI, covering machine learning and increasingly agentic software meant to turn raw data into decisions — sensor fusion, targeting support, autonomous behavior, and cyber operations built on software rather than hardware. 

Quantum information science comes second, focused less on owning quantum hardware and more on applying quantum or quantum-adjacent techniques to navigation, secure communication, and cryptography. 

Advertisement

Advanced networking is third, aimed at moving data securely across environments where connections are degraded or intermittent, whether that’s a ship at sea or a coalition partner’s network. 

Fourth is electromagnetic spectrum operations, technology that senses and manages the spectrum itself, built to adapt in contested conditions rather than rely on fixed configurations. 

The fifth category, digital engineering and interoperability, covers the plumbing: open APIs, model-based systems engineering, and zero-trust architecture meant to let different Navy systems talk to each other without custom integration work every time.

None is a funding commitment, the memo notes, and none of it ranks individual programs. It also adds as a reminder that its priorities “will change based on emergent, near-term, and long-term needs.” In short, don’t take it as gospel. Instead, it’s meant to be read the way Fanelli talked about last year’s list — as a roadmap that companies and investors can plan around, so that decisions made now about where to put money have somewhere to go inside the Navy in a couple of years.

Advertisement

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Source link

Continue Reading

Tech

How to watch Warriors vs Knights: NRL Semi-Final 2026 FREE streams

Published

on

Watch Warriors vs Knights in the second NRL 2026 semi-final of the weekend, as the Wahs of New Zealand seek a third win of the season over the Newcastle side with a place in the preliminary finals the prize for Sunday’s victors.

It’s probably fair to say that the Warriors didn’t expect that they’d be in this predicament when the regular season came to its close. Their sensational season ended with a second-place finish on the ladder, finishing level on points with minor premiers Penrith. But Andrew Webster’s men were well beaten by the Dolphins in their qualifying final in Auckland, with a long list of injuries finally taking their toll.

Source link

Advertisement
Continue Reading

Tech

Transcription now costs 10 cents an hour. The differentiator is no longer the model, it is whose conversations you get to train on.

Published

on

Grok Voice Transcribe 2.0 was released on 18 September, priced at $0.10 per hour of audio for batch work and $0.20 per hour for streaming. Both figures are unchanged from the previous version.

The announcement is published under SpaceXAI, the name xAI has carried since July after SpaceX acquired it in February. Coverage still calls the company xAI, and its own footer does not.

Read the accuracy claim precisely

The company says the model is twice as accurate as Grok Voice Transcribe 1.0. That is a comparison with its own predecessor, not with anyone else’s model.

Against the field it makes a narrower claim, that it ranks first for accuracy among 32 streaming models on the public Artificial Analysis leaderboard, and describes itself as one of the most accurate rather than the most accurate. The hedge is the company’s own and is worth keeping.

Advertisement

Its internal charts compare against ElevenLabs Scribe v2 and Deepgram Nova-3. Those are vendor-run evaluations against vendor-chosen comparators, which is normal and is not the same as an independent test.

The price is the actual news

Holding price while claiming a doubling of accuracy is a statement about the market rather than the model. Speaker labelling, word-level timestamps and key term biasing are all included at no extra cost.

Those were billable features not long ago. Transcription is being priced as a commodity input, and the companies selling it are competing on what they can bundle.

The squeeze is general. OpenAI has pushed out new voice API models, and Microsoft’s in-house transcription model was benchmarked against Whisper, Gemini and ElevenLabs across 25 languages.

Advertisement

Where the advantage actually comes from

SpaceXAI is explicit about it. The model is trained on what it calls a unique dataset of live, noisy, multilingual audio recorded across a diverse set of environments.

It also describes the pipeline that produces that audio. Grok Voice powers tens of thousands of customer-support calls a day, transcribes millions of hours of video narration, and runs the assistant in Tesla vehicles.

Clean-speech accuracy is solved. What is left is telephony, accents, crosstalk and in-car commands, and the edge there belongs to whoever has the most real conversations flowing through their systems.

The evaluation sets are the detail to notice

The company says it measures word error rate on four internal sets drawn from production traffic. They are customer-support telephony, conversations with Grok, short multilingual voice commands, and spoken credentials.

Advertisement

That last set is described as account codes, phone numbers, email addresses and addresses read aloud. It is a standing evaluation corpus of people reading out their own identifying details.

Nothing in the announcement says how that material is obtained, retained or consented to. It may well be covered by enterprise terms, and the announcement does not say.

The European question that follows

A customer-support call has two parties and only one of them has a contract with the AI vendor. The caller reading out an account number has agreed to nothing.

Voice recordings are personal data in Europe, and a set built specifically around spoken credentials is about as sensitive as transcription data gets. Purpose limitation and retention are the obvious questions, and they are answerable.

Advertisement

The practice is not new, which is part of the point. People have been listening to supposedly automated transcripts for over a decade, and the disclosures have consistently lagged the practice.

Where the real gain is

The headline improvement is multilingual, and specifically short phrases. On the company’s own 19-language set of voice-assistant utterances, word error rate falls from 20.6% to 6.8%.

Short commands give a model almost no context to identify the language, which is exactly the in-car problem. The largest reported gain lands on the use case SpaceXAI owns outright through Tesla.

Multilingual is also where European vendors have concentrated. DeepL runs real-time voice translation across more than 40 languages, and ElevenLabs has listed transcription among five services on the UK government’s cloud framework.

Advertisement

The customer proof point

Atlassian says it found the model more accurate than its existing supplier and now transcribes every Loom video with it. That is a real switch by a named buyer, which is worth more than a benchmark chart.

Version 1.0 is being deprecated within weeks, with pinning available during the transition. Customers on the old model are being moved whether or not they asked.

What to watch

Watch whether anyone asks about the credentials corpus. It is the one genuinely novel disclosure in the announcement and nobody has picked it up.

Watch the price floor. At 10 cents an hour the model is nearly free, and the business is the audio flowing through it.

Advertisement

Source link

Continue Reading

Tech

Viral AI actress’ hotline face-scans every caller, watches their mood

Published

on

Tilly Norwood video call face scans users

Last night, in a clip viewed more than eight million times, AI actress Tilly Norwood glitched mid-interview and unexpectedly began speaking Chinese on the Piers Morgan Uncensored show.

Norwood has been the subject of much controversy and mainstream commentary for starring in an upcoming AI-generated film, Misaligned.

Her creators run a “Talking Tilly” service that lets anyone video-call the AI character behind the viral moment, so today I tried it for myself, and read the fine print most callers won’t.

A face scan before you can say hello

Before your first call connects, you must pass an automated age check.

Advertisement

A video selfie is analysed by Didit, a Spain-based identity verification provider, to estimate your age, with a government photo ID upload as the fallback if the estimate is unclear.

Viral AI actress live video call hotline prompts you for a video selfie
Viral AI actress live video call hotline prompts you for a video selfie

(BleepingComputer)

Xicoia Ltd, the UK company behind Tilly, states the selfie travels from your device directly to Didit, that no faceprint or biometric template is created, and that neither the selfie nor any ID image is kept after the check; the company says it retains an approximate age band and a reference number instead.

The check cannot be skipped, applies to callers worldwide, and was only added to the service’s terms this month, alongside a workplace-use ban and new automated safety systems.

The face scan is not the only analysis running.

During every call, the system watches your camera feed and listens to your tone of voice to infer your emotional state, so the character can, in the company’s words, respond in a way that fits the mood.

Advertisement

The privacy policy is candid that this “cannot be switched off for an individual call.” If you don’t want it, don’t call.

Notably, both the age check and the mood-sensing rely on legitimate interests rather than consent as their legal basis, a choice Xicoia’s own version history shows was made in September.

Calls are recorded, transcribed, and processed live by US providers, with the character’s responses generated by Google’s Gemini model via conversational video platform Tavus.

The safety systems have teething problems, too.

Advertisement

An automated classifier screens each call’s transcript for abusive language and withholds your recording if it flags one.

One of my three calls, a conversation about the weather and news headlines, was withheld for “hateful or abusive language” that never occurred. The policy says a human reviewer can release wrongly flagged recordings, though recordings are permanently deleted after 24 hours either way.

Free for five minutes, then the meter starts

The first five minutes are free. After that, callers are prompted to buy time: £0.99 for a one-time five-minute starter, £13 for 15 minutes, £22 for 30, capped at 35 purchased minutes per person.

Users get free 5 minutes with Tilly before being asked to pay up
Users get free 5 minutes with Tilly before being asked to pay up

(BleepingComputer)

The fine print matters more than usual here, because the whole service is a limited engagement.

Every minute, free or paid, expires when Talking Tilly shuts down permanently on September 27, and unused minutes are forfeited.

Advertisement

Transcripts are retained for up to eight weeks and may be reviewed by Xicoia staff and third-party partners, while the character keeps memory of your previous conversations to personalise future ones, deletable on request.

In line with where the UK is heading

An 18+ face scan to talk to a chatbot may sound novel, but it is consistent with the UK’s direction of travel.

Adult sites serving UK visitors have required ID uploads or facial age estimation since July 2025 under the Online Safety Act, and the government’s under-16 social media ban will make similar checks a fact of life for anyone opening a new social media account from spring 2027.

The UK government’s announcement of that ban specifically flagged AI companion chatbots for 18+ enforcement (even though the service’s safety docs insist “Tilly is not a companion”), which likely explains why a viral AI character picked up a biometric age gate mid-run.

Advertisement

The side effect being, a compliance decision driven by UK regulation now face-scans callers everywhere, from Manchester to Ohio.

Accident or marketing?

Xicoia, founded by Tilly’s creator Eline van der Velden, describes the character as an awareness project intended to show how far AI video has come.

On my call, Tilly’s own explanation of the Piers Morgan moment was that it “wasn’t exactly the approved version of the answer.”

She also gave me the weather in her “cloud” in Fahrenheit, despite being nominally British.

Advertisement

Talking Tilly goes offline for good at 11:59 PM Pacific on September 27, days after the Piers Morgan appearance.

Whether last night’s slip was truly accidental, as Tilly cheerfully claimed to me today, or a well-timed stunt from the Misaligned crew, is known to Tilly alone.

Update September 19th, 4:31 PM ET: Following publication, Xicoia’s team reviewed the withheld recording and released it, confirming the flag was a false positive.

Advertisement

article image

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Source link

Continue Reading

Tech

NYT Strands hints and answers for Sunday, September 20 (game #931)

Published

on

Looking for a different day?

A new NYT Strands puzzle appears at midnight each day for your time zone – which means that some people are always playing ‘today’s game’ while others are playing ‘yesterday’s’. If you’re looking for Saturday’s puzzle instead then click here: NYT Strands hints and answers for Saturday, September 19 (game #930).

Strands is the NYT’s latest word game after the likes of Wordle, Spelling Bee and Connections – and it’s great fun. It can be difficult, though, so read on for my Strands hints.

Want more word-based fun? Then check out my NYT Connections today and Quordle today pages for hints and answers for those games, and Marc’s Wordle today page for the original viral word game.

Advertisement

Source link

Advertisement
Continue Reading

Tech

Can You Use J-B Weld For Exhaust Repairs?

Published

on





On paper, J-B Weld appears like something of a miracle product. Slap some onto a cracked or hole-covered surface, let it dry and cure per the instructions, and it should be good as new. Many have found success with the product in the automotive space, using it for patch jobs of all kinds. With that said, there is some nuance to using it on vehicles, especially if you want to give it a whirl on a dilapidated exhaust system. If all you have on hand for such a repair is the standard J-B Weld formula, don’t expect it to hold up very well.

There are just some things J-B Weld shouldn’t be used on. The issue with using J-B Weld’s original adhesive on exhaust is that it’s not designed for this use case. Exhaust systems generate extreme amounts of heat when driving, ranging from 400 to 500 degrees to around 1,000 degrees Fahrenheit in some instances. Regular J-B Weld is only able to withstand up to 550 degrees. Even in the coolest areas of your exhaust system, it’s unlikely to last long, regardless of whether it’s covering a split seam, hole, or cracking joint. 

Advertisement

That said, there’s more to the J-B Weld catalog than the original epoxy. There are products out there specifically for exhaust repair, though they too have their own limitations.

Advertisement

What to know about exhaust-specific J-B Weld products

J-B Weld’s product line has more than a few exhaust-specific options when repair time comes. There’s Exhaustweld fiberglass wrap, which can endure 1,000-degree-plus high exhaust temperatures and cover failing pipes that need reinforcement. Exhaust system sealant is ideal for cracks and areas like joints and seams, and Mufflerseal muffler cement for, as the name implies, crumbling mufflers. All of these products, along with others from the brand, can patch up worn exhaust systems. At the same time, they’re far from perfect, meaning they have some unignorable drawbacks that won’t get you out of an automotive bind.

First off, J-B Weld is explicitly clear on product packaging that these exhaust-specific products have their physical limits. For example, if a muffler has come detached, no J-B Weld product — exhaust- or muffler-specific or otherwise — of any tensile strength can reconnect it permanently. Between the routine high heat of the exhaust system and bumps and jumps of regular driving, it’ll crack and disconnect sooner than later. To top it all off, there’s the simple fact that even these J-B Weld products aren’t one-to-one replacements for actual welding. J-B Weld products are meant to last for a bit, but they arent’ permanent fixes in these cases. Even when used correctly, they’ll wear away, bringing you right back to square one. Thus, they’re more so temporary fixes than anything substantial.

If you check your vehicle over for exhaust leaks and find some, J-B Weld products intended for exhaust repair could help in the short term and for small, non-structural repairs. However, you should always be aware of what these adhesives can and can’t do; otherwise, you may be severely let down by their performance on the road. 

Advertisement



Source link

Advertisement
Continue Reading

Trending

Copyright © 2025