Connect with us

Tech

Sidec’s AI & semiconductor summit 2026, happening Oct 14-17

Published

on

[This is a sponsored article written in collaboration with Selangor Information Technology & Digital Economy Corporation (Sidec).]

The world is getting hungrier for more chips, and no, not the crispy kind you get at the supermarket. 

With AI fueling the chip demand, Deloitte projects the global chip marketing will hit US$975 billion in annual sales this year. And Malaysia already has our cards in it. In fact, we rank as the sixth largest semiconductor exporter in the world, handling roughly 13% of global ATP (assembly, testing, and packaging) capacity.

Yet, there’s a crucial gap that has to be addressed for us to continue being a prominent semiconductor player. 

Advertisement

Just earlier this year, PwC reported that local universities are producing 5,000 graduates annually in the semiconductor industry. But we actually need around 10x more homegrown talents to move up the semiconductor value chain.

This is where AiSEM@Selangor, or better known by its former name SDEC, comes in. This October 14 to 17, the annual summit will return at KLCC and Grand Hyatt KL as one of the flagship components of the Selangor International Business Summit (SIBS) 2026.

Here is what’s happening across the four days and how you can get involved.

Image Credit: Sidec

Why did SDEC rebrand to AiSEM@Selangor & why does it matter?

For the past decade, SDEC served as Selangor’s smart city and e-commerce platform, featuring forums, exhibitions, and awards for the region’s top digital players.

Now that Al and semiconductors has increasingly become a vital aspect in Selangor’s digital economy, Sidec has rebranded the event to AiSEM@Selangor to match the region’s evolving technology landscape.

Advertisement
Image Credit: Sidec

Name change aside, AiSEM@Selangor continues SDEC’s legacy of promoting technological innovation and providing a platform for industry players. But with a stronger focus on AI and semiconductors this time.

This year’s theme is “Designed By Malaysia: Building a Globally Competitive AI Semiconductor Ecosystem” and the scale remains as substantial as ever: 15,000 visitors, over 150 exhibitor booths, and two flagship conferences.

Globally esteemed leaders will be sharing their industry insights, including names such as:

Image Credit: Sidec

Sharing the stage with them are some of our very own Malaysian chip companies—QES Group Berhad, Oppstar Berhad, Alphaswift Industries, SkyeChip Berhad, Infinecs Systems, and SiliconX.

The homegrown chips taking centre stage 

For years, Malaysia’s semiconductor reputation has rested on the back end — assembly, testing, and packaging chips designed somewhere else. That’s still true, and it’s still valuable but our nation has since grown to contribute more than that.

At AiSEM@Selangor, six Malaysian companies are stepping up to prove it, in a showcase aptly named Design by Malaysia: Meet the Six Homegrown Chips that’s happening on Day 3. 

Advertisement

Each will take the stage to present technology that’s designed or developed entirely in-house:

  1. HBM3E Controller by SkyeChip
  2. AI PC and Server by MaiStorage
  3. Malaysia and Southeast Asia’s First FPGA Chip by SiliconX
  4. Maxwell Automotive Grade Low Dropout Regulators by Infinecs
  5. Space ASIC by Weeroc
  6. Alphaswift FC Mini by Alphaswift Industrie

From memory controllers and AI computing to automotive electronics, space technology, and drones, the lineup spans a broad range of applications. They’re also a reminder that Malaysia’s semiconductor story isn’t just about what happens on the factory floor anymore.

It’s worth carving out time for, especially if you’ve been hearing about Malaysia’s semiconductor industry mostly in terms of ATP. This gives you a look into the other side of the semiconductor story that’s brewing locally.

Day 1 (October 14) at Plenary Theatre, KLCC: Startup pitches before the talks even begin

In the tradition of SDEC, AiSEM@Selangor doesn’t start with talks. Instead, you’ll get front row seats to the Selangor Triple Accelerator Programme Grand Final Demo Day.

Image Credit: Sidec

Participants of three Sidec accelerator tracks—Retail-X, Deep-X, and Token-X—will pitch their solutions to investors, corporates, and ecosystem leaders. The top eight companies from each of these accelerators will compete for top honours, including further exposure to industry players, mentorship, funding access, and market expansion support.

For context, in the eight years since its launch, the programme has run 11 cohorts, drawn nearly 1,900 applications, and helped 380 companies raise RM212 million in funding collectively. 

Advertisement

With that kind of track record, there’s plenty to look forward to as the latest batch of startups takes the stage for the Grand Final Demo Day!

Image Credit: Sidec

Day 2 (October 15) at Grand Hyatt KL: All things semiconductor

On the second day, the summit moves to Grand Hyatt KL for the Semiconductor Conference, where over 20 speakers will dig into supply chain resilience, global partnerships, and funding pathways for chip startups. 

The second day’s panels will cover:

Image Credit: Sidec

Day 3 (October 16) at Grand Hyatt KL: All things AI

Continuing at Grand Hyatt KL, the summit’s lens will shift from chips to the AI systems running on them at the AI Conference.

You’ll get to learn from Robert Li on how AI-powered EDA tools are transforming semiconductor innovation, and how to harness AWS and agentic AI for next-generation semiconductors from Umar Shah. 

Here’s what else is on the agenda:

Advertisement
Panel Session Description
Funding Malaysia’s Deep-Tech Future: Unlocking Capital for Next Generation of AI & Chip Champions Discusses funding gaps, investment readiness, and what it takes to build globally competitive deep-tech champions.
Closing the Global Chip Talent Gap: Powering a Chip-First Economy Examines how Malaysia can strengthen its semiconductor talent pipeline amid growing global competition for highly skilled engineers and technical specialists.

All four days (October 14 to 17): Discover new technologies and careers

While the conferences run at Grand Hyatt, KLCC will be equally bustling with the AiSEM Exhibition & Showcase. 

150 companies are set to exhibit their technologies, from global chipmakers like Intel and Sandisk, to Malaysian players like Oppstar and SkyeChip. Alongside them will be agencies such as MIDA, MRANTI, and several Selangor local councils.

Image Credit: Sidec

Beyond the booths, Sidec is providing a comprehensive summit ecosystem for industry players to learn and grow together. You’ll be treated to:

  • Startup Street, a dedicated zone for early-stage companies 
  • Investor Lounge and Business Matching, structured spaces for funding conversations and networking, with a special opportunity to link up with delegations from Japan and the UK
  • Autonomous Showcase, where robotics, drones, and intelligent mobility technologies are put on display
  • ChampionCHIP eXperience Competition Demo Day, grand finale of the high-energy integrated circuit (IC) design competition

Running alongside it is the Malaysia Semiconductor Recruitment Day, which is Sidec’s most direct shot at the 10x talent gap mentioned. Here, 35 semiconductor companies meet engineering and technical talent face-to-face, no cover letter required.

Image Credit: Sidec

The employer list spans multinationals and local firms alike: Intel, Sandisk, STMicroelectronics, NXP Semiconductors, Melexis, X-FAB, Tektronix, Toppan, Altera, Greatech Technology, SkyeChip, MaiStorage, Infinecs, Alphaswift, Weeroc, Oppstar, Sophic, and more.

Oh, and did we mention it’s free entry?

Where this fits into Malaysia’s bigger plan

AiSEM@Selangor lands just months after Malaysia launched the National AI Action Plan 2026–2030, the country’s blueprint for becoming an “AI Nation”. With it carries ambitious goals of becoming among the top 10 countries on the Global AI Index and 300,000 new AI-related jobs by the end of the decade.

Advertisement

The event’s theme, “Advancing Malaysia’s Intelligent Future”, reflects that broader ambition, bringing together the people and businesses working to move the country’s technology ecosystem forward.

Whether you’re looking for your next career opportunity, hoping to pitch your startup, or keen to connect with industry players, this is one event you should not pass up.

Tickets are available here. Conference passes are RM399 for a 2-day all-access pass, or RM299 for a single day. Early bird and other discounts may apply. 

Image Credit: Sidec
  • Learn more about Sidec and AiSEM@Selangor here.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

How To Stop Meta Training Its AI Models On Your Smart Glasses’ Visual Data

Published

on

The setting affects whether workers can review photos and videos from your glasses.

Meta has started to roll out the setting that allows people who use its smart glasses to opt out of allowing the company to use “visual data” collected by the device for AI training. The setting is now available within the Meta AI app.

The company has begun notifying glasses owners about the change with a pop-up in the Meta AI app. “Your Al glasses can translate a menu, identify a plant and more,” it says. “You can opt out of providing visual data from these experiences to Meta for product improvement. If you opt out, that data isn’t stored after processing.”

The notification directs users to the relevant settings page, but you can also find it directly by navigating to the settings for your glasses, selecting “Meta AI” and scrolling down to “store visual data from AI experiences.” You’ll need to have your glasses out of their case and connected to your phone in order to change the setting. If you have multiple pairs of glasses, you’ll need to repeat this step for each pair.

Advertisement

Opting out may prevent you from being able to use certain features with the glasses, Meta says. This includes “visual reminders,” like looking at an object and asking Meta AI to remind you to buy it next week. It’s not clear if any other features are affected.

Along with the new setting, Meta has also published a more detailed description of how it uses “visual data” in a help center article that explicitly mentions the possibility of human review. “When you use AI experiences on your Meta glasses – like asking about something you’re looking at or using live AI – Meta stores the resulting visual data and may use it to power glasses features and improve Meta products,” the company explains. “This includes the process of training and improving AI models, which may be automated or manual (human).”

The company goes on to note that it only stores “visual data” collected while using certain AI features, including Live AI. Visual data, the company says, does not include “photos and videos you capture with your glasses when the capture LED is on.”

Advertisement

Source link

Continue Reading

Tech

Thieves Stole ‘Nvidia’ Trailers. They Got 20 Tons of Sand

Published

on

On Thursday morning, a top executive at self-driving truck developer PlusAI received an unexpected congratulatory text message from an acquaintance. “I have been proud of you for your adventure and success at Plus. Just saw two of your trucks near my work place! :)” the message said.

But PlusAI’s trucks weren’t supposed to be near this person’s office, in Newark, California. As of the last the company knew, the trailers were docked outside its warehouse, half a mile away. Soon, according to a police statement, cops were on the scene to help recover the two trailers, emblazoned with logos for PlusAI and Nvidia, the most valuable company in the world. The two companies are working together on AI software and autonomous truck technology.

That’s when PlusAI employees gave police a hint as to why whoever hooked their own cabs up to the trailers and drove away might have abandoned the whole thing after breaking them open: Each trailer was full of about 20,000 pounds of sand.

“PlusAI uses simulated loads in its trailers to assist with research and development testing,” says Lauren Kwan, a company spokesperson. The trailers were recovered with “40,000 pounds of sand intact.”

Advertisement

PlusAI’s tech-enabled truck cabs—where the driver typically sits and controls the vehicle—were parked inside its warehouse and weren’t taken, Kwan says. The trailers were secured with hand locks, which were broken.

The case is under investigation, and no arrests have been made, says Amy Gee, a spokesperson for the Fremont Police Department.

Nvidia didn’t immediately respond to a request for comment.

The incident comes at a time of rising theft targeting high-value computer equipment, especially chips and other electronics meant for use in data centers. In August, WIRED revealed two California incidents in which thieves deliberately struck the vehicles of security escorts that follow high-value tech loads to ensure they reach their destinations. The trucks involved were then driven to another destination. As of August, millions of dollars of data center equipment onboard had not been recovered.

Advertisement

This year, thieves have also targeted Tesla batteries and various bitcoin mining machines. Authorities have arrested suspects in some cases, but many crimes remain unsolved.

Some of the most common targets of cargo theft in recent months across the US include metals and enterprise-grade computer and networking equipment, according to Verisk CargoNet, an analytics and risk assessment firm.

This story has a happier ending. By Thursday afternoon, the sand trailers were back with PlusAI, the Fremont Police Department said.

Source link

Advertisement
Continue Reading

Tech

Kiteworks urges 6-hour server shutdown over potential zero-day attacks

Published

on

Kiteworks

Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack.

According to German technology publication Heise, Kiteworks CISO Frank Balonis emailed customers warning that the company had received “credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend.”

“We strongly recommend you shut down your Kiteworks system for six hours,” the notification reportedly states.

Heise says the shutdown window applies to customers worldwide, with affected time zones ranging from Australian Eastern Standard Time (AEST) to Pacific Daylight Time (PDT).

Advertisement

In Central Europe, customers were instructed to shut down Kiteworks systems between 4:00 a.m. and 10:00 a.m. on Saturday, September 26. In New York, the shutdown window would be from 10:00 p.m. Friday to 4:00 a.m. Saturday.

The company reportedly recommends shutting down the servers before the scheduled window and says customers should take systems offline even if they are not directly accessible from the Internet.

The company confirmed the warning to BleepingComputer, stating it received intelligence from federal authorities that a threat actor may attempt to target some customer systems.

“Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers,” the company told BleepingComputer.

Advertisement

“Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we and our law enforcement partners work through the matter.”

Kiteworks stressed that the warning is precautionary rather than a response to a confirmed breach.

“We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach,” the company said.

“All known vulnerabilities are addressed in our current release, 9.5.1, and we continue to recommend customers run the latest version.”

Advertisement

Potential zero-day concerns

While Kiteworks has not confirmed that attackers are exploiting an unknown vulnerability, Heise reports that Kiteworks customer support said the shutdown recommendation is intended to protect customers against potential zero-day attacks.

“The reason we’re asking you to shut down the servers is to protect against any potential zero-day attacks,” Kiteworks support reportedly told Heise when the publication contacted the company to verify the warning.

However, neither the statement provided to BleepingComputer nor the customer notification quoted by Heise confirms that a zero-day vulnerability has been discovered or exploited.

Instead, Kiteworks says all currently known vulnerabilities are fixed in version 9.5.1 and describes the shutdown as a precaution based on intelligence received from authorities.

Advertisement

Kiteworks develops secure file-transfer and communications products used by government organizations, financial institutions, and enterprises.

Because secure file-sharing platforms commonly store sensitive documents, they are a valuable target for cybercriminals who conduct data-theft extortion attacks.

While it is not known which threat actor is linked to these potential attacks, the Clop extortion gang has a long history of targeting enterprise platforms in data-theft attacks, including Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer.

The U.S. Department of State now offers a $10 million reward for any information linking the cybercrime gang’s attacks to a foreign government.

Advertisement

article image

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Source link

Continue Reading

Tech

Chinese cities offer subsidies and cheap computing to lure AI film studios

Published

on

Local governments across China are competing to attract AI filmmakers with subsidised rent, living allowances and cheap computing power, Reuters reported on Friday.

Zhu Zhili set up an AI film studio in Shenzhen two years ago. He told the agency that officials from big cities and small towns now call him every day, asking him to move his technology or his company to them.

He also runs the AI-generated content department at China Wit Media, a Shenzhen production company.

The incentives follow the playbook China used to build its electric vehicle, solar and robotics industries.

Advertisement

In May, Shanghai started giving computing capacity and hosting AI models to micro-drama producers. Beijing has set up a 260 million yuan ($39 million) fund for film and video technology.

Beijing’s Huairou district, a centre of the Chinese film industry, also hands out vouchers that cut computing bills for AI short dramas. Shenzhen, for its part, offers technical support and cheaper rent to AI film talent.

Production costs have dropped fast. According to state broadcaster CCTV, making a minute of AI short drama cost 5,000 yuan at the start of 2026 and only a few hundred yuan by mid-year.

Pan Xiaojun, a film-directing student in Hainan, told Reuters he could create a surreal wedding scene with AI for 1,400 yuan, against 60,000 yuan for a conventional shoot. Local subsidies and rent waivers brought his computing costs down further.

Advertisement

Streaming platforms have joined in. iQIYI chief executive Gong Yu said in August that the company was going all in on AI, and it now subsidises some creators who publish AI content on its service.

The National Film Administration has also cleared Sanxingdui: Future Memories, a 90-minute science-fiction film from Bona Film Group, for cinema release. No other AI film from a major Chinese studio has received that approval.

Supply may already be outrunning demand, however. Between January and June, 221,900 AI shows went up on Douyin, ByteDance’s Chinese TikTok. Only 1,055 of them passed 100 million views, according to data firm DataEye.

The backlash is growing too. Actors worry about the use of their likenesses, voice actors fear for their jobs, and viewers complain about plagiarism. Some saw the box-office success of Niu Lai, a crudely animated film made without AI, as a reaction against the trend.

Advertisement

China already requires AI-generated content to carry clear labels, but it has yet to set copyright rules. Filmmaker Cao Yiwen, who premiered an AI-animated film in Cannes in April, told Reuters that Europe is waiting to see whether China writes those laws.

Source link

Advertisement
Continue Reading

Tech

HP built a calculator to prove cloud AI is a money pit, then dropped a laptop price you won’t expect

Published

on


  • HP’s new workstation carries 192GB of memory for demanding local AI workloads
  • The ZBook Ultra G3a can reportedly handle models reaching 300 billion parameters
  • The workstation combines a 96Wh replaceable battery with an 180W adapter

HP has debuted the ZBook Ultra G3a 16, a workstation built around AMD’s Ryzen AI Max+ PRO 495 processor and substantial unified memory.

The laptop combines up to 192GB of LPDDR5X memory with integrated Radeon graphics and support for demanding local AI workloads.

Source link

Continue Reading

Tech

GIGABYTE and CAPCOM Announce Street Fighter Giveaway for Indian Gamers

Published

on

The much-awaited Street Fighter movie is just around the corner. And GIGABYTE has just partnered with CAPCOM to celebrate the movie’s release with a new giveaway campaign in India. The promotion gives buyers of select GIGABYTE OLED gaming monitors a chance to win a one-of-a-kind Street Fighter-themed custom gaming PC powered by an NVIDIA GeForce RTX 5080 and AMD Ryzen 7 9800X3D.

The limited-time campaign runs from September 17 to November 1, with product registration closing on November 15, 2026.

A custom Street Fighter gaming PC is up for grabs

Street Fighter themed PC

GIGABYTE has created a collector-focused custom build inspired by the visual style of 1990s Street Fighter. The system blends arcade-inspired artwork with futuristic mechanical design, making it as much a display piece as a high-end gaming machine.

Inside, the PC features the GIGABYTE X870E AERO X3D DARK WOOD motherboard alongside the AORUS GeForce RTX 5080 MASTER 16GB graphics card. The build is powered by AMD’s Ryzen 7 9800X3D, one of the company’s flagship gaming processors, and is paired with GIGABYTE’s 27-inch GO27Q24G OLED gaming monitor. The motherboard itself recently won the Red Dot Design Award 2026, combining a wood-inspired finish with support for AMD’s latest X3D gaming platform.

The giveaway highlights GIGABYTE’s premium OLED gaming monitor portfolio, with the GO27Q24G serving as the featured display. It offers a 27-inch QHD WOLED panel, 240Hz refresh rate, 0.03ms response time, and support for both NVIDIA G-SYNC Compatible and AMD FreeSync Premium.

Advertisement

The promotion also includes several higher-end AORUS OLED models. The AORUS FO32U2P features a 32-inch 4K OLED display with DisplayPort 2.1 UHBR20 connectivity, while the FO27Q2 offers a 27-inch 2K QD-OLED experience. For ultrawide gamers, the AORUS CO49DQ brings a 49-inch Dual QHD OLED panel with panoramic gameplay.

How to Enter?

To participate, customers need to purchase an eligible GIGABYTE OLED gaming monitor from an authorized retailer in India between September 17 and November 1, 2026. After purchase, you also need to register the product on the official GIGABYTE AORUS campaign website before November 15. The eligible models include the AORUS FO32U2P, FO27Q2, and CO49DQ OLED monitors.

Source link

Advertisement
Continue Reading

Tech

Review: Frank Zappa’s ‘Freak Out!’ 60th Anniversary Super Deluxe Edition Adds Rare Mono Mixes and 5CD/Blu-ray Box Set

Published

on

Widely influential and uncompromisingly timeless, Frank Zappa’s 1966 debut with The Mothers of Invention, Freak Out!, is one of the ground-zero, game-changing releases from the dawn of the psychedelic revolution. A crossroads marker between the pop music that came before and everything that followed, the album inspired no less than The Beatles in the creation of Sgt. Pepper’s Lonely Hearts Club Band.  

Freak Out! honored and deconstructed musical conventions in the same breath. Now 60 years old, the album has prompted Universal Music and Zappa Records to take a fresh deep dive into the archives for a wonderful 5CD/1Blu-ray Super Deluxe Edition boxed-set extravaganza.

Most notably, it marks the return of the highly sought-after, punchy original mono mix of Freak Out! Out of print since 1966 because the master tapes were lost, this new remaster was assembled from three surviving single-release tapes, along with a well-made needle drop from a pristine original pressing. They did a great job with it, and the results sound remarkably good, very similar to my original mono pressing.

frank-zappa-freak-out-turns-60

Also remarkable is a newly unearthed “pre-master” stereo mix, sourced from a fan collector, dating from before the engineers added their final production touches. Arguably a generation lower in the analog food chain, this mix feels much less constrained and more widescreen, with little to no compression or EQ. Many details jump out that were previously somewhat buried, and I hear some different edits as well.

Two CDs of bonus material include a wealth of very cool demos and 1966 live concert recordings from San Francisco’s legendary Fillmore Auditorium. Featuring the Freak Out!-era Mothers in full flower and performing without a net on a bill that reportedly included Lenny Bruce, these archival-quality soundboard recordings are imperfect but fascinating, offering plenty of revelations.

Advertisement
frank-zappa-freak-out-60th-anniversary-menu

The Blu-ray offers multiple ways to enjoy Freak Out! Given that the producers were working from, at best, four-channel multitrack recording sources, it is remarkable how much immersion they achieved with the surround mixes. The Dolby Atmos mix delivers a room-filling perspective that can, at times, feel less discrete and a little blurred, almost like multichannel mono.

This mix is at its best on the more experimental tracks, such as “Who Are the Brain Police?” and “Return of the Son of Monster Magnet,” where the trippy special effects and sound collages sometimes seem to explode around you. That said, I found the 5.1 Dolby TrueHD mix a bit more immersive and more discrete overall. Both versions are compelling, so I found myself switching back and forth between them. Having that choice is definitely a good thing.

frank-zappa-freak-out-fillmore-live

The Blu-ray also includes high-resolution versions of the 1966 stereo and mono mixes, as well as the new “pre-master” mix, presented in 96kHz/24-bit and 192kHz/24-bit resolution. You could sit and listen to Freak Out! on this disc alone for more than four hours, exploring all of these different mixes.

Other goodies in the set include a foldout reproduction of the “Freak Out Hot Spots Map,” a rarity for many years that was originally available only by mail order in 1966 from an address listed on early LP pressings. Extra kudos go to the designers of the Blu-ray screensaver, which features a little car, and periodically even tanks, driving around the map while occasionally dropping tiny bombs and causing other assorted mayhem. It’s quite a production.

frank-zappa-freak-out-60th-anniversary-super-deluxe-set

The 60th anniversary Freak Out! set includes a booklet with new essays and a section called “Even More Relevant Quotes,” a reference to the original Freak Out! liner-notes section titled “Relevant Quotes.” For this new edition, the producers reached out to notable fans around the world who were influenced by the music, and if you look closely, you’ll see your friendly neighborhood eCoustics freelance music writer, Mark Smotroff, included as well.

I’m humbled and honored to be in such esteemed company as a lifelong fan who has also been reporting on Zappa reissues and archival releases for many years.

Advertisement
Advertisement. Scroll to continue reading.

I’m still exploring this set but in a nutshell, if you love this album and Zappa’s music, you definitely need to pick up a copy sooner than later. You can order the Freak Out! 60th anniversary super deluxe box set on Amazon for just $65.88. There is also a companion 5LP version of the set for those of you like vinyl available for $149.88 at Amazon.

Our Ratings

★★★★★★★★★★ Music

★★★★★★★★★★ Sound

Advertisement

★★★★★★★★★★ Packaging

Where to Buy:


Mark Smotroff is a deep music enthusiast / collector who has also worked in entertainment oriented marketing communications for decades supporting the likes of DTS, Sega and many others. He reviews vinyl for Analog Planet and has written for Audiophile Review, Sound+Vision, Mix, EQ, etc. You can learn more about him at LinkedIn.

Source link

Advertisement
Continue Reading

Tech

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

Published

on

Hacker holding a cube

The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability.

The Clop leak site was breached earlier this month by the ShinyHunters extortion gang, which first uploaded a small text file and later replaced the site with a full-page defacement displaying its Umbreon Pokémon logo and a link to its own data leak site.

Clop data leak site defaced by ShinyHunters
Clop data leak site defaced by ShinyHunters

ShinyHunters later claimed on its own data leak site that it stole source code, Grav CMS plugins, server logs, and the private keys used by Clop’s Tor onion service. The group then issued a ransom demand, threatening to leak the stolen files if Clop did not pay.

Clop has now announced a new onion address and says the old domain will remain accessible temporarily before being retired.

Clop also denied having any relationship or ongoing negotiations with ShinyHunters.

Advertisement

“We do not know them, we have never worked with them, and at the moment we are not in contact with them; furthermore, we have not provided them with any information, nor will we do so—either now or in the future,” Clop told BleepingComputer.

When asked whether the group had determined how ShinyHunters breached the leak site, Clop confirmed that its Grav installation had not been fully updated.

However, the Russian ransomware gang disputes ShinyHunters’ claims that valuable operational or financial data was stolen from the compromised server.

“We didn’t update the Grav plugin — though it happened eventually—but the server contained nothing but content (meaning there was absolutely no data or financial activity there, nor could there have been). Therefore, their claim is worthless—as are their words,” Clop said.

Advertisement

While Clop says they are not communicating with the other threat actors, they have since been quietly removed from ShinyHunters’ data leak site, which commonly happens when negotiations are taking place.

When questioned about the removal, ShinyHunters told BleepingComputer that they did not want to answer any further questions about this.

Grav confirms flaw used in attack

Grav CMS has now confirmed that the vulnerability and exploitation details shared by ShinyHunters with BleepingComputer are accurate.

ShinyHunters told BleepingComputer that the compromised Clop server was running Grav CMS 1.7.43 and claimed it exploited an unauthenticated file upload flaw in Grav’s form upload handling.

Advertisement

According to the threat actor, the vulnerable code used values supplied through form-related POST parameters when creating temporary upload directories without first validating them as safe filesystem path components.

The group specifically identified the __unique_form_id__ parameter and said the value was added into a temporary path like:


tmp/forms//

ShinyHunters claimed that by supplying directory traversal sequences, such as ../../../shhq, for the unique form identifier, it could cause Grav to create an upload path outside the intended tmp/forms directory.

The uploaded file could then be written elsewhere under the Grav installation.

Advertisement

After BleepingComputer shared the technical details with Grav, the CMS developers confirmed that the threat actor’s description was accurate.

“Yes, it’s a legitimate flaw, and the threat actor’s description is accurate,” Grav told BleepingComputer.

Grav said the flaw is tracked as CVE-2026-42608 and is a path traversal vulnerability that was privately reported and fixed in Grav 2.0 (2.0.0-beta.2) earlier this year, with the advisory published on April 27.

The fix added a sanitizeId() function that only accepts identifiers matching the allowlist:

Advertisement

[A-Za-z0-9,_-]{1,64}

Grav confirmed that this sanitization method is the same mitigation described by ShinyHunters to BleepingComputer.

However, while current Grav 2.x releases had already been protected, the fix had not been backported to the older Grav 1.7 branch, leaving installations such as Clop’s 1.7.43 deployment vulnerable.

“The gap was the 1.7 line,” Grav told BleepingComputer. “Grav 2.0 is the current major version, but plenty of sites are still on 1.7, and that fix hadn’t been backported there yet.”

After BleepingComputer shared the exploitation details with Grav, the developers backported the fix to the 1.7 branch and released Grav 1.7.53.4 yesterday.

Advertisement

Grav also clarified that the vulnerability is located in Grav core rather than the Form plugin.

“The bug lives in Grav core, not the Form plugin, so the Form plugin version (7.3.0 in their example) doesn’t change whether a site is vulnerable. It’s the core version that matters,” Grav said.

Grav is urging anyone still running the 1.7 branch to upgrade to version 1.7.53.4. Users of current Grav 2.x releases have already been protected from the vulnerability for months.


article image

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Source link

Advertisement
Continue Reading

Tech

Social Media Bans for Kids Need Smarter Safety Design

Published

on

Even before France approved legislation banning social media for children under 15 last January, 13-year-old Benjamin was already wondering what life without social media would look like. “If we want to play football, we won’t be able to organize it. What will we do? Send letters instead?” he joked in an interview for Le Monde.

His reaction captured the central challenge behind the growing wave of youth social media bans: Removing access is one thing; understanding what those platforms mean in children’s lives is another.

Within weeks of Australia’s similar ban, the country’s eSafety Commissioner reported that platforms had restricted access to 4.7 million under-16 accounts. Two months later, though, one in five Australian teenagers under 16 was still using TikTok and Snapchat, according to a parental-control data company. But even if all children’s social media accounts were to disappear, do such bans actually make children safer online?

Governments are moving ahead without answering that question as they follow Australia’s lead. Indonesia’s child-safety framework, which took effect in March, bars children under 16 from holding accounts on “high-risk” platforms. The U.K. government has announced plans to ban social media for under-16s, add default overnight social media curfews for 16- and 17-year-olds, and extend child-safety rules to cover risky AI features. And on 17 September, the European Commission proposed the EU KIDS Act, which would bar children under 13 from social media, set 15 as the EU-wide minimum age for opening an account independently, and require platforms to show that their services are age appropriate and safe by design.

Advertisement

But based on my experience working on Child Online Protection initiatives with the International Telecommunication Union (ITU) across Southeast Asia and the Pacific, I know the bans don’t address the real problems. Instead, we should be paying more attention to the systems that generate harm in the first place—namely, recommender algorithms, engagement-maximizing design, opaque moderation, and extractive data practices.

Account removals are not the same as online child safety

My experience working on protecting children’s online safety has taught me three main lessons:

First, the public institutions responsible for child online protection often lack the staff, budget, or technical capacity to enforce complex online safety policies.

Indonesia is illustrative. A 2026 UNICEF evaluation found capacity constraints among service providers, long-term funding uncertainty, and a need for specialized personnel. At the local level, some staff lacked digital skills, while budget constraints left some areas reliant on external support.

Advertisement

Second, many children, and often their parents, lack the digital literacy and critical thinking skills needed to navigate online risks safely. My policy research on child online protection in Indonesia, published earlier this year in Digital Society, found substantial gaps that account removals cannot repair: Many children lacked guidance on navigating the internet safely, and large numbers did not know how to report harmful experiences.

And third, the platforms have limited independent oversight as they identify underage users, design age-verification systems, and report their own compliance. In Indonesia, platforms themselves are responsible for carrying out age verification, while the Ministry of Communication and Digital Affairs oversees compliance. TikTok’s appeals process for users flagged as underage, for instance, can require a government-issued ID and selfies, which is a problem because it involves collecting the additional personal data on an ID card, beyond that needed to confirm age. Will government regulators ensure that TikTok handles that data responsibly?

The privacy paradox of proving age

Every age-based ban creates an engineering problem: How can a platform reliably determine that a user is old enough, without intruding on other information? Governments and companies may use identity documents, parental authorization, app-store checks, or facial age estimation. Each approach has trade-offs among accuracy, privacy, accessibility, and resistance to circumvention.

There are also technical issues. One tool, facial age estimation, draws on enormous databases but it is probabilistic, not exact, because people vary so much. It’s also been shown to misclassify both children and adults.

Advertisement

The challenge should not merely be to “verify age.” It should be to prove that someone is above a threshold, without disclosing their identity, birth date, or other information third parties might use to create a marketing profile. The European Commission’s age-verification blueprint challenges companies to verify ages without collecting all that additional information.

Privacy-preserving technologies offer promising ways to achieve this. Zero-Knowledge Proofs (ZKPs) can confirm that someone meets an age threshold without revealing their identity or exact date of birth. W3C Verifiable Credentials are cryptographically verifiable digital claims that can disclose only the information needed, such as “over 16.” And device-based age signals can allow a phone or app store to share an age range without revealing a user’s exact birth date. But these methods still require rigorous security testing, common standards, independent oversight, and clear limits on data retention. Otherwise, poorly designed child-safety policies risk creating permanent identity infrastructures in which businesses, not people, control personal data.

Where connection goes when a platform closes

Blocking access to a platform redirects some young people, but not always where expected. Early anecdotal reports in Australia pointed to teenagers migrating to smaller, less-regulated platforms like Yope, a pattern the Cato Institute flagged as a “whack-a-mole” problem for regulators. But industry data collected two months later found no broad-based shift of that kind, aside from a small uptick in WhatsApp use. Many teens simply found a way to stay on the banned platforms.

This points to a deeper gap in current society: the erosion of youth “third places“ physical spaces where young people have room to socialize and build identity outside home and school. As those spaces have diminished, commercial communications platforms have absorbed that role.

Advertisement

For many teenagers, social media workarounds are merely inconvenient. But for isolated, marginalized, disabled, or LGBTQ+ youth who depend on online communities for support that’s otherwise unavailable, displacement can mean losing certain kinds of belonging, or having to move to a platform with even weaker oversight.

How to design safer online systems for children

If blanket social media bans don’t work, then what will? The platforms have created many of the conditions that governments are now trying to contain: engagement-optimized recommenders, intrusive data practices, weak safeguards against unwanted contact, and features such as infinite scroll, autoplay, streaks, and persistent notifications.

These design patterns increasingly face regulatory scrutiny, including what’s required under the European Union’s Digital Services Act. A 2026 study from the 5Rights Foundation that tracked children’s device use minute by minute found that the user interfaces shape children’s attention, sleep, and well-being in real time.

A more durable response would regulate those interfaces directly, treating children as legitimate users whose privacy, agency, and well-being are required protections, not afterthoughts. That means designing for safety from the outset. One example would be for children’s apps to have high-privacy defaults, such as private accounts and location sharing switched off for minors. They could also have recommender systems that explain the main factors shaping a feed and give young users more control over personalization. The European Commission has published age-appropriate interaction guidelines that limit unsolicited contact and prevent minors from being added to groups without consent. Rules could also prohibit engagement-maximizing features that demand users’ attention, such as autoplay, infinite scroll, usage streaks, read receipts, and push notifications, by disabling or limiting them by default.

Advertisement

Governments should define measurable outcomes and fund independent evaluation, platforms should give researchers meaningful data access, and engineers should audit age-assurance systems for bias and data leakage. Schools, parents, and children themselves need a seat in designing the technology that’s designed to protect children.

If policymakers still decide to remove an infrastructure for youth connection, they should offer something better in return. Social media bans may reduce some forms of exposure to harmful content and may be justified for particular ages, services, or risks. But they are just one tool, not a comprehensive substitute for safer design, accountable platforms, digital literacy, institutional capacity, and noncommercial digital “third places”—moderated communities, creative spaces, and public-interest platforms designed for youth participation rather than profit.

The first wave of social media restrictions isn’t enough to keep children safe. Governments are still measuring what’s easiest to count, while neglecting harder-to-measure outcomes such as children’s access to safe third places and meaningful social connection, both online and offline. Until governments can show evidence that harm has actually declined, they will keep mistaking account removal for safety.

From Your Site Articles

Advertisement

Related Articles Around the Web

Source link

Advertisement
Continue Reading

Tech

Thousands of banks can now sue over Apple Pay fees

Published

on

Thousands of U.S. banks and credit unions can pursue their Apple Pay fee claims together after a federal judge certified their antitrust lawsuit as a class action.

The financial institutions accuse Apple of blocking competing tap-to-pay wallets on iPhone while charging card issuers fees for transactions. They argue Apple could impose those fees because rival wallets couldn’t compete for contactless payments on the iPhone.

Judge Jeffrey White certified the class on September 23 and rejected Apple’s attempt to exclude the plaintiffs’ damages expert. The ruling doesn’t decide whether Apple violated antitrust law or owes the issuers money.

Card issuers pay Apple 0.15% of the value of credit card purchases made through Apple Pay and half a cent for each debit transaction, according to the credit unions’ lawsuit. For example, a $100 credit card purchase through Apple Pay costs the card issuer 15 cents in Apple Pay fees.

Advertisement

Affinity Credit Union, GreenState Credit Union, and Consumers Co-op Credit Union filed the lawsuit in 2022. They argue Apple couldn’t have sustained its Apple Pay fees with meaningful competition, pointing to Android wallets that don’t charge card issuers transaction fees.

The lawsuit alleges Apple blocked rival wallets from using the iPhone’s contactless payment hardware, leaving Apple Pay as the only option for tap-to-pay card transactions. The credit unions say the lack of competition let Apple charge inflated fees, which they want repaid along with changes to the challenged practices.

Apple previously tried to have the case dismissed. A 2023 ruling allowed the monopolization claim to continue while dismissing a separate allegation that Apple unlawfully tied iOS devices to Apple Pay.

Thousands of issuers can pursue the case together

The certified class covers U.S. entities that issued an Apple Pay-enabled card and paid Apple a fee for a transaction made with that card. The plaintiffs estimate that thousands of banks and credit unions qualify.

Advertisement

Apple didn’t dispute that the proposed class was large enough to meet the numerical requirement for certification. White found that the court can resolve key questions for the entire class rather than separately for every issuer.

The questions include whether Apple had monopoly power, harmed competition, and charged fees that injured card issuers. Apple’s uniform rates for credit and debit transactions could also provide a common way to calculate any overcharges if the issuers prove their case.

iPhone screen displaying Apple Pay setup with a blue Visa card centered on a dark background, showing partial card number and wallet interface icons at the top and bottomApple Pay setup on iPhone

The ruling also allows Christopher Vellturo, the plaintiffs’ damages expert, to testify. Vellturo compares Apple’s issuer fees with the zero-dollar issuer fees he attributes to competing mobile wallets, then uses that difference to estimate how much class members may have overpaid.

Apple challenged his methodology and asked the court to exclude his testimony. White instead found that Apple’s objections concern how convincing the analysis is, leaving the company free to attack its assumptions and conclusions as the case continues.

iPhone tap-to-pay access has changed since the lawsuit began

Apple’s restrictions have changed since the credit unions filed the lawsuit. Starting with iOS 18.1 in 2024, eligible third-party apps can handle contactless iPhone payments without routing them through Apple Pay, and users can choose an eligible app as their default for contactless transactions.

Advertisement

Developers still need Apple’s approval and a commercial agreement that includes applicable platform fees, according to Apple’s documentation. Apple’s developer fees are separate from the Apple Pay transaction fees challenged in the lawsuit.

The September 23 ruling lets the issuers pursue their claims together, including a request to change Apple’s practices. Expanded NFC access could affect what changes remain necessary, but it doesn’t resolve claims over fees already paid or establish that the fees were unlawful.

Source link

Advertisement
Continue Reading

Trending