Connect with us
DAPA Banner
DAPA Coin
DAPA
COIN PAYMENT ASSET
PRIVACY · BLOCKDAG · HOMOMORPHIC ENCRYPTION · RUST
ElGamal Encrypted MINE DAPA
🚫 GENESIS SOLD OUT
DAPAPAY COMING

Tech

Silent Ransom Group targets law firms with fake IT support calls

Published

on

Hacker shhing

The Silent Ransom Group extortion gang is actively targeting U.S. law firms and professional services organizations in social engineering attacks that often lead to data theft within hours of initial contact, according to a new report by cybersecurity firm Mandiant.

The report follows an FBI FLASH advisory published last week warning that the Silent Ransom Group was targeting U.S. law firms in social engineering and even in-person data theft attacks, with Mandiant now providing additional technical details about how the intrusions are conducted.

Mandiant says the threat group, tracked as UNC3753, Luna Moth, and Chatty Spider, targeted dozens of organizations across the legal, financial, and professional services sectors between January and May 2026. 

image

Mandiant warned that legal firms remain especially attractive targets because they store large volumes of highly sensitive client information and may feel pressured to resolve extortion incidents to avoid reputational and regulatory damage.

“Legal services firms represent high-value targets for extortion actors. They maintain concentrated repositories of extremely sensitive client transaction files, merger and acquisition plans, client trade secrets, and corporate regulatory reports,” explains Mandiant

Advertisement

“Threat groups recognize that legal entities are subject to heavy reputational and regulatory exposure and may be highly motivated to resolve extortion situations quietly to protect their professional standing.”

The researchers say the attacks begin with invoice-themed phishing emails from consumer email accounts. These emails do not contain malicious links or attachments and instead serve as a precursor for follow-up phone calls from attackers impersonating corporate IT staff.

Conducting attacks via voice calls has been an ongoing tactic by these threat actors for years, which they previously used in BazarCall social engineering campaigns tied to Ryuk and Conti ransomware attacks. A callback phishing attack is when threat actors send benign-looking phishing emails containing alarming or IT-related lures that prompt the recipient to call them back at an enclosed phone number.

In the current campaign, the Silent Ransom Group impersonates IT help desks and convinces employees to join remote support sessions via Microsoft Teams, Zoom, Quick Assist, or Microsoft Terminal Services.

Advertisement

During these sessions, the threat actors trick the target into installing remote monitoring and management tools such as AnyDesk, Zoho Assist, Bomgar, or SuperOps, thereby granting them initial access to the corporate network.

Silent Ransom Group attack flow
Silent Ransom Group attack flow

Mandiant also discovered phishing domains tied to the campaign that impersonate internal IT portals using naming patterns such as:


-itdesk[.]com
-it[.]com
-helpdesk[.]com

The researchers say the threat actors also use privnote[.]com, a self-destructing messaging service, to share installation links and commands with targets during remote support sessions. According to Mandiant, this tactic helps reduce forensic artifacts left in browser histories or corporate chat logs.

Once inside a network, the group searches for sensitive legal and financial documents, including contracts, tax records, Social Security numbers, and merger or acquisition files. The attackers commonly target document management platforms and cloud storage repositories before exfiltrating the data using tools such as WinSCP or Rclone.

Mandiant says the extortion operation is highly aggressive, with ransom demands often arriving within 30 minutes of the attackers leaving the victim environment. 

Advertisement

“These highly aggressive extortion letters give organizations a three-day deadline to respond and initiate ransom negotiations. If the victim organization is unresponsive, the threat actors declare they will call and email target employees and external clients directly to alert them of the data breach,” reports Mandiant.

“The extortion letters explicitly emphasize that the leak will compromise client trust, invite substantial regulatory fines, and suggest that external clients sue the victim organization for data mishandling.”

The report also references the FBI’s recent advisory in which law enforcement warned that the Silent Ransom Group was targeting U.S. law firms with in-person data theft attacks.

According to the FBI, attackers impersonate internal IT staff over phone calls and emails, then attempt to gain remote access or physically visit offices to “image” computers or create backups while secretly stealing files.

Advertisement

While Mandiant said there was limited forensic evidence, the researchers believe these in-person attacks are likely linked to UNC3753 based on similarities in targeting, timelines, and operational behavior.

The Silent Ransom Group has been active since at least 2022, when it was part of the Ryuk and Conti cybercrime syndicate. 

As previously reported by BleepingComputer, the threat actors were previously linked to BazarCall callback phishing campaigns that provided initial access in Conti and Ryuk ransomware attacks.

After the Conti syndicate shut down in 2022, the group shifted to standalone data theft and extortion operations under the Silent Ransom Group branding.

Advertisement

Researchers say the group no longer relies on traditional ransomware encryption and instead focuses entirely on data-theft extortion, in which they steal sensitive data and pressure victims into paying to prevent leaks.

A separate report released this week by Resecurity found that the gang is also operating fast-flux infrastructure to hide and protect its data-leak platforms.

DNS fast flux is a method where attackers constantly rotate a domain’s IP addresses through a large pool of compromised devices to hide their infrastructure and make takedowns or blocking far more difficult.

According to the company, the infrastructure uses residential IP addresses across multiple countries and ISPs to make takedowns more difficult.

Advertisement

Resecurity said the group’s “business-data-leaks[.]com” leak site and related infrastructure rely on residential proxy networks spread across Latin America, Eastern Europe, Central Asia, the Middle East, and Asia. The researchers also linked the infrastructure to other cybercrime-related services and domains.

To defend against the attacks, both Mandiant and the FBI recommend implementing strict verification procedures for IT support interactions, limiting remote access tools, enforcing MFA, restricting USB storage devices, and training employees to recognize voice phishing attempts.


For organizations looking to defend against phishing, BEC, and account takeover attacks, BleepingComputer is hosting a webinar with Abnormal titled “Stop chasing alerts: Automating email security with behavioral AI.

The webinar will explore how behavioral AI can help security teams detect and respond to modern phishing attacks, automate investigations and remediation, and reduce the operational burden caused by alert fatigue and increasingly sophisticated social engineering campaigns.

Advertisement

article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Why SAP says enterprise AI agents need knowledge graphs and governance

Published

on

Presented by SAP


At VB Transform 2026, Max McPhee, senior solution advisor at SAP, spoke with Rob Stretchay, lead analyst at VentureBeat Research, about what it takes for enterprises to move beyond chatbots to autonomous AI agents that can execute real business processes. He argued that the difference comes down to grounding those agents in a company’s own context rather than general knowledge.

“Where we’re starting to see more emergent behavior of it feeling like a coworker rather than an assistant, is where we’re able to provide context on the actual enterprise rather than being able to use more of the standard knowledge,” McPhee said.

Advertisement

That’s the gap that still separates most enterprise chat software from genuinely agentic systems.

Building enterprise context with knowledge graphs

The same principles companies use to onboard new employees also apply to agents, adapted for software that retrieves information differently than humans do.

“When you are onboarding a new agent, I think it’s important to acknowledge how you might onboard a new employee, but tune that for an agent,” McPhee said. “The way that is really powerful is using knowledge graphs and having vector-embedded data, because that’s a really easy format for an agent to be able to find and retrieve information.”

That same grounding is also what keeps an agent from stumbling over an enterprise’s internal shorthand, a problem that’s acute in SAP’s world.

Advertisement

“Being able to provide that tribal knowledge in the format that’s easy for it to consume helps to provide a really nice result with your agents versus a chatbot that might say, ‘Well, what does that acronym mean?’” he said.

Bringing governance, identity, and security to autonomous agents

Governance is an area where SAP’s history works in its favor, and the controls have been evolving for systems that act with more flexibility than earlier automation did.

“That’s where SAP really has a good home, around that governance and process control,” McPhee said. We’re a 50-year-old process company, modernizing that governance to be able to handle the flexibility that comes with agents running.”

One consequence is a renewed role for machine learning in validating agent behavior.

Advertisement

“It’s becoming a bit of a revival of machine learning,” he added, pointing to customers that run agents within a process but then layer in anomaly detection and machine-learning-based validation as a guardrail. This is the same approach SAP had long used for intelligent approval recommendations.

Identity and permissions carry that governance into execution. Under this model, both the human and SAP’s Joule, the generative AI assistant embedded across the company’s cloud applications and Business Technology Platform, must hold the rights to access a given system. Even if a user has permission to access S/4, they cannot do so through Joule unless the assistant has also been provisioned for that access, closing off the risk of using an agent to route around access controls.

Balancing standard SAP with customized enterprise landscapes

Much of McPhee’s work involves reconciling SAP’s own knowledge with decades of customer customization and non-SAP systems. As he put it, many customers tell SAP, “You’re only 10% of my landscape,” a reality that has shaped the company’s recent strategy.

Recent acquisitions such as LeanIX, which McPhee likened to “Google Maps for your architecture,” and process-mining company Signavio are intended to help map that non-SAP majority so SAP’s agents can understand how enterprise systems interconnect. The company has also invested in Berlin-based automation company n8n and is embedding it natively into Joule Studio, its intent-based, low-code environment for building agents.

Advertisement

McPhee warned that companies also need to modernize older on-premises systems or risk running into limitations as they expand the use of autonomous agents.

“You’re going to probably run into throughput issues, and you’re kind of trying to drive a Ferrari around a dirt track,” he said. “You’ve got to upgrade the track first if you want to drive a Ferrari.”


Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact sales@venturebeat.com.

Source link

Advertisement
Continue Reading

Tech

Today’s NYT Mini Crossword Answers for Tuesday, July 28

Published

on

Need some help with today’s Mini Crossword? The first two clues require you to know a little bit about different alphabets. Read on for all the answers.

The completed NYT Mini Crossword puzzle for July 28, 2026.

Mini across clues and answers

1A clue: Letter after alpha, in the Greek alphabet
Answer: BETA

5A clue: Letter after Alfa, in the NATO phonetic alphabet
Answer: BRAVO

6A clue: Barrier reef organism
Answer: CORAL

7A clue: Bout of sniffling and sneezing, say
Answer: COLD

Advertisement

8A clue: Blue expanse
Answer: SKY

Mini down clues and answers

1D clue: “Babbling” body of water
Answer:
BROOK

2D clue: Before expected
Answer:
EARLY

3D clue: Broadcast commercial, for short
Answer:
TVAD

Advertisement

4D clue: Big name in early email
Answer:
AOL

5D clue: Brings into an email thread discreetly
Answer:
BCCS

ExpressVPN

Get CNET’s top-rated VPN for privacy and usability

Advertisement

Source link

Advertisement
Continue Reading

Tech

New Certighost PoC exploit lets attackers hijack Windows domains

Published

on

Windows warning

A proof-of-concept exploit for “Certighost,” a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain.

Tracked as CVE-2026-54121, the vulnerability was fixed by Microsoft as part of the July 2026 Patch Tuesday security updates.

“An authenticated attacker could manipulate attributes associated with a machine account and obtain a certificate from Active Directory Certificate Services that allows authentication as that machine via PKINIT,” Microsoft explained.

image

If the attacker can target a domain controller account, Microsoft says they could authenticate as the domain controller and perform privileged Active Directory operations.

Security researchers H0j3n and Aniq Fakhrul reported the vulnerability to Microsoft on May 14, 2026, with Microsoft fixing the flaw in the July security updates.

Advertisement

Last week, the researchers publicly disclosed the technical details regarding the vulnerability, including the release of an exploit that can be used to gain domain-level administrative capabilities.

“Certighost is an Active Directory Certificate Services (AD CS) vulnerability that allowed a low-privileged domain user to impersonate a Domain Controller and achieve domain compromise in the tested AD CS configuration,” reads the researchers’ technical writeup.

Abusing the AD CS chase mechanism

Active Directory Certificate Services (AD CS) is Microsoft’s public key infrastructure for Windows domains and is used to issue certificates for authentication and secure communications.

During certificate-based authentication, the domain controller verifies which Active Directory account the certificate belongs to and then issues Kerberos credentials.

Advertisement

Certighost affects a fallback mechanism used by AD CS during certificate enrollment requests, which the researchers refer to as a “chase,” that uses two certificate request values:

  • cdc, or Client DC, identifies the server the Certification Authority should contact.

  • rmd, or Remote Domain, identifies the account the CA should search for.

When both attributes are supplied, the CA connects to the server specified in the cdc value and searches for the specified rmd.

However, systems previously did not verify that the server supplied through the attacker-controlled cdc value was a legitimate domain controller.

Advertisement

This allowed an attacker to run rogue SMB, LSA, and LDAP services, direct the CA to the attacker-controlled system, and return false directory information for a targeted machine account.

Certighost attack flow
Certighost attack flow
Source: H0j3n and Aniq Fakhrul

In the attack demonstrated by the researchers, a low-privileged user first creates a machine account, which is permitted under the default ms-DS-MachineAccountQuota configuration.

“A machine account created through the default ms-DS-MachineAccountQuota setting is a valid domain principal,” reads the report.

“This allowed the attacker-controlled chase endpoint to satisfy the authentication checks needed for the CA to continue, even though it was not the Domain Controller being impersonated.”

The attacker then submits a certificate request that directs the CA to the rogue services and targets a domain controller account. Because the CA trusts the identity information returned by the attacker-controlled services, it issues a certificate that can be used to authenticate as that domain controller and perform Active Directory operations.

Advertisement

The released certighost.py proof-of-concept automates this process by using the certificate to authenticate through PKINIT as the targeted domain controller, saving the resulting Kerberos credentials to a .ccache file and extracting the account’s NT hash.

The researchers then demonstrated using the saved Kerberos credentials with Impacket’s secretsdump tool to perform a DCSync attack and retrieve the krbtgt account’s credentials.

“A Domain Controller account has directory replication rights. With the resulting Kerberos credential, the attacker can request account secrets, including the krbtgt secret,” explained the researchers.

Using the DC's Kerberos credentials to perform a DCSync attack
Using the DC’s Kerberos credentials to perform a DCSync attack
Source: H0j3n and Aniq Fakhrul

Microsoft fixed the vulnerability as part of the July Patch Tuesday updates by adding validation to this chase process.

The CA now verifies that the server specified in the cdc attribute maps to a legitimate domain controller in Active Directory and confirms that the returned identity matches the expected account. 

Advertisement

For admins who cannot install the July security updates, the researchers say that you can disable the optional chase fallback using the following commands:


certutil -setreg policy\EditFlags -EDITF_ENABLECHASECLIENTDC
Restart-Service CertSvc -Force

However, the researchers stress that this workaround is only a temporary mitigation and has not been fully tested in production environments. Therefore, admins should prioritize installing the latest security updates as soon as possible.


article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Advertisement
Continue Reading

Tech

Cursor makes its biggest India push yet ahead of SpaceX acquisition with localized pricing

Published

on

Weeks before its expected acquisition by SpaceX closes, AI coding startup Cursor is making its biggest push into India yet, launching its first country-specific subscription as the company bets on one of the world’s largest developer markets to drive its next stage of growth.

On Monday, the startup introduced Cursor Start, a ₹649-a-month (about $7) subscription built specifically for India — and priced well below Cursor’s standard $20-a-month Pro subscription.

The move reflects India’s growing importance to Cursor’s business. The startup says India is already its third-largest market globally and home to its highest concentration of power users, with its user base in the country more than tripling over the past year.

That scale, coupled with India’s deep pool of software engineering talent, made it the first market where Cursor chose to localize pricing, Simon Green, Cursor’s head of Asia-Pacific and Japan, told TechCrunch. “We felt that we had an opportunity there to right-size the commercial model and drive scale,” Green said. “The technical competency of the country and the engineering talent that already exists make it a very natural fit.”

Advertisement

India has emerged as one of the world’s largest software developer hubs. Earlier this year, GitHub said that the country has more than 27 million developers on its platform, second only to the U.S., with more than two million joining in 2026 alone.

Cursor Start includes access to Cursor’s Composer 2.5 model and Grok 4.5, with higher usage limits than the free tier, alongside cloud agents, its iOS app, plugins, Model Context Protocol support, hooks, and skills. The startup said the plan is aimed at developers who need more AI-assisted coding capacity than the free tier offers without upgrading to its full Pro subscription.

The lower-priced plan is intended to broaden access rather than replace Cursor’s flagship offering, Green said. Unlike the $20-a-month Pro subscription, Start does not include access to frontier AI models from providers such as OpenAI and Anthropic, or advanced features including Bugbot, Auto Mode, Automations, and the Cursor SDK.

The plan is billed in Indian rupees and supports payments through credit and debit cards as well as India’s Unified Payments Interface (UPI).

Advertisement

Green told TechCrunch that Cursor would use multiple checks to ensure the India-only subscription is available only to individual users in the country, including measures to deter people from accessing the plan through virtual private networks (VPNs).

Cursor is not alone in tailoring its pricing for India. OpenAI and Anthropic have also rolled out India-specific plans over the past year as global AI companies compete for users in one of the world’s fastest-growing AI markets.

While Cursor Start is initially limited to India, Green told TechCrunch that the startup could expand localized pricing to other markets if the model proves successful.

“We will continue to do everything we can to fuel the demand and serve those clients that are using us,” Green said. “Now, if this model proves that we could take it to other markets, perhaps we will. But I think it’d be crazy to say we would never do it elsewhere.”

Advertisement

OpenAI provides one precedent for this strategy, having launched its sub-$5 ChatGPT Go in India before expanding the lower-priced subscription to other markets.

In addition to the localized pricing strategy, Cursor is also expanding its presence in India through new hires. Green told TechCrunch that the startup recently hired its first salesperson in India and expects another leader to join in Delhi. The company is also building out its a government affairs office, alongside three technical customer support hires, as it expands its presence in Bengaluru, Chennai, Hyderabad, and Mumbai.

Cursor’s enterprise push is still in its early stages in India, Green said, where adoption has so far been driven largely by individual developers, startups, and universities. He said Cursor sees significant opportunities in sectors including banking and large enterprises as it expands its local sales efforts.

Green said, the India-specific pricing was designed to be commercially sustainable rather than a loss leader. He said the lower-priced plan is viable because it is built around Cursor’s own AI models, which carry lower operating costs than relying primarily on third-party frontier models.

Advertisement

Cursor’s India expansion comes a little over a month after Elon Musk’s SpaceX agreed to acquire the AI coding startup in a $60 billion all-stock deal, following SpaceX’s blockbuster initial public offering. The acquisition is expected to close in Q3. However, SpaceX has been partnered with Cursor since April to develop a next-generation “coding and knowledge work AI.”

Green said Cursor will continue to operate independently until the transaction closes and that the company’s India expansion plans were already in motion before the deal. Once the acquisition closes, however, Green said SpaceX’s existing presence in India through Starlink could help Cursor expand faster by lowering commercial and operational barriers.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Source link

Advertisement
Continue Reading

Tech

Banjo and Kazooie Unreal Engine 5 Remake Makes the Duo Finally Feel Like They Belong in 2026

Published

on

Banjo and Kazooie Unreal Engine 5 Remake Remaster
Twenty-eight years after a honey bear and a red-crested bird first scrambled across Spiral Mountain, a fresh batch of Unreal Engine 5 footage has arrived that makes the wait for an official return feel almost unbearable. François Montagud, the same creator who previously rebuilt Doom 3 in the engine for his portfolio, has posted seven uninterrupted minutes of his Banjo-Kazooie fan remake. It will never ship. You cannot download it. Yet the short video already does more to answer the quiet question hanging over the series than any corporate teaser has managed in years.



Montagud’s idea with this one was to bring back the original game’s charm while also incorporating all of the improvements that modern hardware would provide. The end result is that the grass swings in the breeze, the leaves catch the light in a realistic way, and the rock faces suddenly have a degree of detail that the old N64 games couldn’t match. The lighting is stunning, casting shadows that stretch and shrink as Banjo moves around, and you can see how clean the water is, whereas the old cartridge merely hinted at how good it could appear. The environments feel lived-in rather than thrown together.


Nintendo Switch 2: Choose Your Game Bundle
  • Kick off the fun with a Nintendo Switch 2 system, your choice of a select digital game, and a savings* of up to $29.99!
  • Includes choice of either the Mario Kart World, Donkey Kong Bananza, or Pokémon Pokopia digital game download
  • One system, three play modes: TV, Tabletop, and Handheld

Banjo and Kazooie Unreal Engine 5 Remake Remaster
The camera follows the duo through some big open areas as well as some tighter spots, and you can still see Banjo trudging along in that typical manner, while Kazooie, of course, bursts out of the backpack at the appropriate times, and leaping around still produces all of those cheery little “woohoo”s and “wheeee”s that you have always enjoyed. When they go underwater, the soundtrack turns to bubbles and muted sounds, which is actually very convincing.

Banjo and Kazooie Unreal Engine 5 Remake Remaster
Vegetation is arguably the most improved, because plants and trees no longer sit there like flat billboards; they have volume. Light passes through the leaves, creating all these gorgeous soft patterns on the ground. The far hills have a lot more texture, yet it doesn’t take away from the game’s gentle, storybook appeal. The color scheme is still warm and inviting, and the balance is perfect. None of it has been pushed too far into photorealism, which would clash with Banjo’s nicely rounded design or Gruntilda’s appropriate cartoon menace. That’s significant because it helps the game feel like it belongs in this universe.

Banjo and Kazooie Unreal Engine 5 Remake Remaster
Montagud has been open about this, stating that he did it for his portfolio and that it would most likely remain offline, similar to his Doom 3 work. There are no plans for a public build, but this does not diminish the footage’s effect. Fans who have been waiting since Nuts & Bolts, through the Smash Bros. debut, and through the numerous speculations finally have a tangible visual reference for what a properly done remake could look like.
[Source]

Source link

Advertisement
Continue Reading

Tech

AI Systems Out-Persuade Expert Humans, Including Professional Canvassers And World Championship Debaters

Published

on

from the what-would-Jane-Austen-say? dept

Persuasion plays a key role in society. Whether it is political or financial decisions, workplace or family choices, or simply reading a book or article (like this one), often someone is trying to persuade someone else to agree with them, possibly by changing their mind. This raises an interesting question: if persuasion is such an important part of life, how good are the latest AI systems in this domain? Are they, for example, better than humans? That is what a research project has just investigated, and on an impressively large scale:

in a series of four preregistered experiments (n = 18,978 conversations from 6,923 people), we pitted AI systems against a range of human persuaders, including laypeople, winners of a separately preregistered four-round online persuasion tournament, professional canvassers, and world championship debaters.

The results were unequivocal:

We found that AI systems were reliably more persuasive than expert humans, even when expert humans chose their issues, researched in advance, underwent hours of live, structured practice, and were incentivized with £1,000 cash bonuses. In a follow-up study, AI’s advantage persisted after experts received a coaching tool that let them practice against the AI that beat them, review their performance history, and see what AI would have said at key moments.

An arguably more demanding test found that AI systems were not just persuasive when it came to opinions, but also in terms of real-world actions: they managed to elicit substantially more real-money donations to charity than well-paid professional canvassers. The researchers were able to pin down the two key factors that helped AI to out-perform the best human persuaders in all these tests:

We found converging evidence that AI’s advantage stemmed from rapidly deploying larger quantities of information: after coaching, expert humans could tie an AI constrained to respond at human speeds and with human-length messages.

That is, AI systems were more persuasive largely thanks to the range of knowledge they could demonstrate, and the speed with which they could present it — precisely those aspects of AI that are improving all the time. Which means that frontier AI systems are likely to become even more persuasive in the future. That sounds a rather bleak prospect, but a commentary from Tom Stafford, professor of psychology at the University of Sheffield, and co-author of the book Mind Hacks, points out that things may not be as bad as they seem:

Advertisement

fact-based persuasion may indeed be effective, but that is good news for human reasonableness, not bad. The way the AI works isn’t some sinister magic; if it produces more facts, it is more persuasive. The constraint that persuasion requires evidence means that what anyone can be persuaded of will ultimately ground out on what can reasonably be claimed about reality. If AI is a tool which produces better-informed citizens and more respect for facts, that can be a positive thing.

That may be true in general, but the original researchers note that there are other factors at play here. For example, access to resources is clearly important:

power could flow to whoever can most readily access and deploy the most capable systems. In practice, that could mean the actors who already command the most resources, such as large private corporations, political campaigns, or nation states. These actors spend heavily to influence public opinion and consumer behaviour, and although the per-message effects of such efforts can be modest, such AI could raise their effectiveness, deepening existing imbalances in who can sway the public.

Another issue is that the persuasive power that comes with the deployment of leading AI systems could increase the clout of top AI companies:

in persuasion contests where both sides can secure access to the most capable systems, such AI could consolidate power by giving significant leverage to the actors that build and control those systems. These actors could tilt the outcome of such contests by, for example, deciding which positions their models will, and will not, argue for. In this case, power would flow not to the users of persuasive AI but to its suppliers, and consolidation of their influence would occur even when access among users is perfectly equal.

More positively, the researchers point out that as constant improvements in technology push down the cost of using persuasive AI

it could help under-resourced actors (e.g., pro se litigants and public defenders, small charities, grassroots activists) compete against more established and better-funded rivals, narrowing long-standing gaps in access to justice and assisting civic advocacy more broadly.

In his blog post, Stafford mentions another factor to consider:

Advertisement

In a world where every surface becomes filled with persuasive text, I don’t think it is inevitable that people will open themselves to being pulled in every direction. Not only do people have a significant degree of native scepticism, tending to resist persuasive efforts as they seek to maintain stability in their existing views, but they also have agency to open themselves, or not, to persuasive effects. The studies reported in this paper asked for an average of 14 minutes of conversation from participants. 14 minutes of sincere engagement might be a lot more than most of us give to alternative points of view in our daily lives.

In other words, we don’t really know yet what impact these highly-persuasive AI systems will have on politics, business, and everyday life. But given their superior ability to convince it seems likely that we will be encountering them more frequently in their role of indefatigable persuader, whether we want that or not.

Follow me @glynmoody on Mastodon and on Bluesky.

Filed Under: ai, canvassing, charities, coaching, donations, facts, grassroots, investment, persuasion, politics, pro se, public defender, tom stafford, university of sheffield

Advertisement

Source link

Continue Reading

Tech

Prep for Siri AI on Apple Vision Pro with visionOS 26.6

Published

on

The end-of-cycle updates are often devoid of anything user-facing, but that doesn’t mean you should delay updating to visionOS 26.6. Security patches and preparation for Siri AI are worth the update.

Not every operating system update is going to have some flashy headlining feature. As we await the OS 27 releases in the fall, the OS 26 cycle is still getting needed updates.

Apple has released visionOS 26.6 today alongside the other operating systems with minor changes. The release notes don’t mention anything beyond the usual bug fixes and performance enhancements.

The release build for visionOS 26.6 is number 23O770.

Advertisement

Even though users won’t get any new user-facing features, there has been some evidence that Apple will begin indexing users’ devices before releasing Siri AI in September. The index would occur in the background and not be accessible to the user in visionOS 26, but would be ready for visionOS 27.

Indexing every piece of data available across all of a user’s devices is time-consuming and can affect performance. It is also not an ideal situation given that users hoping to try the new Siri AI might be disappointed to find errors when their data isn’t indexed.

Outside of that, there isn’t anything of note in visionOS 27. Since the update offers the usual bug fixes and performance enhancements, it is best to install the update as soon as is reasonable.

Advertisement

Source link

Continue Reading

Tech

Ma Rainey 5CD Box Set Review: 118 Rare Recordings Restore the Legacy of a Feminist Blues and Jazz Pioneer

Published

on

It is rather refreshing that, in an era of artificial intelligence and faceless machine made music, there is not only interest in, but genuine demand for, a multidisc, 118 track boxed set dedicated to recordings by Gertrude “Ma” Rainey, the “Mother of the Blues,” including four previously unreleased alternate takes.

Ma Rainey: Mother of the Blues, The Complete Paramount Recordings 1923 to 1928 promises improved sound while offering a compelling portrait of this underappreciated artist. The set also includes a 100 page book featuring unpublished photographs, detailed biographies, notes for each track, news clippings, period advertisements, and a complete discography.

ma-rainey-booklet

A pioneer on many levels, Rainey was a successful Black female musician who maintained control over her work in an industry that continues to exploit and mislead artists. The official materials accompanying the set explain:

By the time Paramount signed her in 1923, she had the standing to negotiate on her own terms. She managed her own career for nearly thirty years and, according to registered copyrights, wrote or co wrote at least a third of what she recorded, at a time when almost no performer, and few women anywhere in the business, held that kind of control.”

Advertisement

While collectors understandably prize original 78 RPM recordings such as these, the reality is that discs produced before tape and digital technology, during the nascent and effectively direct to disc era of recorded music, are exceptionally rare. It is therefore especially encouraging to see this music preserved and improved through the latest technology and restoration expertise. Although the original discs have survived for more than a century, no doubt because of careful collectors, they will eventually deteriorate.

ma-rainer-box-cover

Featuring audio restoration by engineer Doug Benson, the set compiles the best surviving version of each 78 RPM side, as the individual recordings were known. Modern demixing software apparently does not work particularly well with early acoustic recordings, which account for roughly half of this collection, so the producers instead chose to remaster the material while remaining faithful to the sound of the original releases. Some surface noise is inevitable, but preserving it ultimately helps retain the music’s overall fidelity.

So how does it sound, you ask? While the label could not send me the entire boxed set for review, I did receive a very useful 22 song advance sampler CD that provides a strong overview. In short, it is highly enjoyable and, considering that these recordings are now roughly 100 years old, the sound quality is remarkably good. Do not expect Abbey Road by The Beatles or the latest Billie Eilish album, but this remains a vivid and authentic listening experience.

The recordings appear to be in remarkably good condition, given their age and scarcity. The music itself is often astonishing, particularly in its explicit, honest, and direct treatment of sexuality and independence on songs such as the groundbreaking “Prove It on Me,” “Shave ’Em Dry,” and “Dead Drunk Blues.”

Advertisement
ma-rainey-cd-box-set-group

Available now from Black Swan Records, named in tribute to the pioneering Black owned label founded in the 1920s, the set also reflects an important historical connection. J. Mayo Williams, who distributed the original Black Swan label, became Paramount’s recording director during the year Rainey signed with the company. Ma Rainey: Mother of the Blues, The Complete Paramount Recordings 1923 to 1928 can be ordered through the official website or Jazzology for $125.

Our Ratings

★★★★★★★★★★ Music

★★★★★★★★★★ Sound Quality

Advertisement. Scroll to continue reading.
Advertisement

Mark Smotroff is a deep music enthusiast / collector who has also worked in entertainment oriented marketing communications for decades supporting the likes of DTS, Sega and many others. He reviews vinyl for Analog Planet and has written for Audiophile Review, Sound+Vision, Mix, EQ, etc.  You can learn more about him at LinkedIn.

Source link

Advertisement
Continue Reading

Tech

macOS 26.6 is out, but expect minimal feature changes

Published

on

Apple has released macOS 26.6 to the public, but don’t expect much in the way of big changes to features this time around.

Apple has concluded its beta testing program for updates to its current-gen operating systems. After five developer betas and a release candidate, it has now shipped macOS Tahoe 26.6.

At the same time, Apple has also brought out updates for earlier macOS versions. There are updates available for macOS Sequoia 15.7.8 and macOS Sonoma 14.7.7.

As usual for any system update, it is advisable to install the update, due to Apple including various bug fixes, performance improvements, and security refinements. However, unlike the macOS 27 Golden Gate beta program, you’re not going to see any real feature-based additions.

Advertisement

Instead, users may be forgiven for not seeing any real updates to macOS 26.6 at all. However, release notes for the betas and the RC edition show that there are some changes.

The release notes for the RC build mention some small improvements, including the deprecation of encrypted HFS+, which won’t be supported in macOS 28.

It also resolves a problem with deprecation notifications where it incorrectly identifies an app as Intel-only. This occurred when a system plugin loader like the Color Picker loads x86 code into the host process.

HealthKit also adjusted temporally-weighted average statistics queries for discrete quantity types, such as resting heart rate. It was occasionally returning high values in cases when sample times overlapped.

Advertisement

For Messages, the build fixes HDR screenshots that can appear garbled when sent to other users.

How to update to macOS 26.6

To update, open System Preferences, then General, followed by Software Update. If there is a software update available, select to install it.

Source link

Advertisement
Continue Reading

Tech

4 Drawbacks Of Buying A Google Pixel Phone

Published

on





Google has been in the business of making smartphones ever since the early days of Android. However, Google’s early phones, the Nexus lineup, were actually manufactured by other companies like HTC, Samsung, LG, and Huawei, resulting in different hardware designs and feature sets every time. The company finally found its footing with the Pixel lineup that debuted in 2016 and, in more recent years, has established a stronger identity with a consistent design language.

If you’re buying a Pixel smartphone today, you’re doing it primarily for the software experience. Google offers up to seven years of Android updates across its Pixel lineup. Since it also happens to develop the Android operating system, Pixel users enjoy these updates on day one. Pixels have also garnered a reputation for offering some of the best camera systems in a smartphone. Despite these benefits, Pixels aren’t always as easy to recommend as other Android phones.

There are a few reasons behind this, ranging from performance compromises to slow-paced hardware improvements. It also doesn’t help that a flagship from Google costs more than the Samsung Galaxy S26, which has a similar screen size, a great camera system, a powerful system-on-a-chip (SoC), and more starting storage. Here’s a closer look at some of the corners the Google Pixel series cuts and why they might be dealbreakers to some people.

Advertisement

Google’s Tensor chip is falling behind

Your smartphone doesn’t have to be the most powerful portable computer you own, but when you’re paying close to $1,000 for a flagship, you’d expect it to at least keep up with the competition. All current-generation Google devices, except for the Pixel 10a, ship with the in-house Tensor G5 chip, which, on paper, is significantly slower than the latest from Qualcomm. The budget Pixel 10a doesn’t even get that, running the older Tensor G4 that debuted in the Pixel 9 series in 2024. According to NanoReview, the Snapdragon 8 Elite Gen 5 scores up to 2.7x higher than the Tensor G5 in AnTuTu benchmarks.

Of course, real-world use is more than just stress testing your phone’s CPU and GPU using synthetic benchmarks. In our review of the Pixel 10 Pro XL, we didn’t report any performance issues, but for people who are hoping to enjoy the most graphically demanding games out there, the Pixel’s weaker GPU performance may be a dealbreaker.

Advertisement

Some Pixel features are region-locked

Google is a software-first company, which is why many praise its Pixel devices, not because of their hardware, but because of the exclusive software features these phones offer. Unfortunately, a few of these headlining features are region-locked and might not be available to everyone. For instance, the enhanced call screening functionality is only available in select countries, including Germany, France, Australia, and India. In fact, for the feature to screen your calls automatically, you will have to be located in the United States.

Call Notes is another useful addition that lets you transcribe, summarize, and generate important points discussed during a conversation. Not only does this feature not work on Google’s budget A-series devices, but its availability is also restricted to a limited number of countries and languages. Other features like Hold for Me and Take a Message are also limited to certain regions. Even something as basic as Scam Detection isn’t as widely available as you might think.

Advertisement

Google is not the only brand that’s guilty of advertising region-locked features, as other companies like Apple and Samsung limit functionality based on where you live, too. However, if you’re planning to buy a Pixel primarily because one of these nice-to-have features caught your eye, it’s worth checking if it actually works on your device, in your location, and in your language.

Advertisement

Pixel phones may not appear to be that exciting

Modern Pixel smartphones are well built, typically pairing a glass sandwich construction with an aluminum frame. You also get a bright display with thin, uniform bezels and a flagship camera system. Yet, next to the rest of the Android field, it’s easy to realize just how safe the Pixel plays.

For instance, Oppo’s flagships are known for pushing the boundaries of camera hardware by including large sensors and periscope cameras like the Find X9 Ultra’s, which hits 10x optical zoom without an add-on lens. OnePlus, on the other hand, sells some of the most powerful smartphones that undercut other options in price. Many Chinese phone makers have also made the switch to using silicon-carbon batteries. These batteries are high-density and known to last long. Gaming phones, like ones from Red Magic, come with active cooling solutions and capacitive shoulder triggers, delivering an experience closer to an actual controller.

Some users even feel the software experience on Pixel phones is a bit bland. Compared to feature-rich Android skins like One UI and OxygenOS, the Pixel interface is more on the minimalistic side. In our review of the Pixel 10a, we noted how it was basically the same phone as last year’s. There’s nothing inherently wrong with recycling a formula that works, but it does come at the cost of seeming uninspired.

Advertisement

Pixel phones sometimes struggle with battery life

How long your phone lasts on a single charge depends on various factors, including the kind of workload you put it through, how bright your screen is on average, and if you’re relying more on 5G than a stable Wi-Fi connection. To combat the growing requirements of modern smartphones, manufacturers have been fitting their phones with increasingly larger batteries every year. In fact, the market now has many Android phones with silicon-carbon batteries that offer capacities of 7,000mAh or higher.

Even the mainstream manufacturers that are playing it safe are either doing great with optimization or simply packing in larger lithium-ion cells. Samsung’s most premium flagship, for instance, has shipped with the same 5,000mAh battery capacity since the Galaxy S20 Ultra in 2020, but has managed to deliver all-day battery life thanks to improvements in display and chipset efficiency. Phones from Chinese manufacturers like OnePlus and Xiaomi not only pack in larger batteries but also feature significantly faster charging speeds of up to 120W in certain regions.

The Google Pixel, on the other hand, doesn’t stand out for its battery life claims. In a comprehensive battery test carried out by YouTuber MrWhoseTheBoss, the Pixel 10 Pro XL came in last place with nine hours and 53 minutes, followed by the Samsung S25 Ultra with 10 hours and 43 minutes. 

Advertisement



Source link

Advertisement
Continue Reading

Trending

Copyright © 2025