Tech
Skyworth C2 Canvas Art TV Takes on Samsung The Frame With a Brighter QD Mini LED Screen
Art TVs have spent years asking buyers to accept a peculiar bargain: your television can look like framed artwork when nobody is watching it, provided you are willing to surrender some picture quality when everyone sits down for movie night.
Skyworth thinks that compromise has gone on long enough.
The new Skyworth C2 Canvas Art TV, making its official debut at CEDIA Expo 2026, takes several of the display technologies introduced with the company’s much more expensive CE1 Canvas Elite and brings them to 55, 65 and 75-inch screen sizes.
The headline upgrade is QD Mini LED backlighting with more than 400 full-array local dimming zones, combined with 1,000 nits of claimed peak brightness, a 144Hz refresh rate and Skyworth’s OmniView Matte Screen. HDR support includes both Dolby Vision and HDR10+. That makes the C2 considerably more interesting than another television wearing a decorative wooden frame.
Related: Best TVs Of 2026: Editors’ Choice Podcast
This Is a Huge Upgrade Over the Skyworth C1
The difference between the existing C1 Canvas Art TV and the new C2 is substantial.
Skyworth’s current C1 uses a conventional LED backlight, operates at 60Hz and is rated at just 300 nits of brightness. It already offers a matte anti-glare screen, flush mounting, Art Mode and an included wood grain frame, but its specifications clearly place aesthetics ahead of serious HDR performance.
The C2 changes that equation with 1,000 nits, 144Hz and full-array local dimming with more than 400 zones. In other words, this is not Skyworth changing the frame, adding three new Van Goghs and calling it a product cycle.
The additional brightness should provide significantly more headroom for HDR content, while local dimming gives the television far greater control over dark and bright portions of an image than the C1’s conventional LED backlight can provide. How well those 400-plus zones actually control blooming and black levels will require testing, but the underlying hardware represents a major step forward.
The 144Hz refresh rate also makes the C2 considerably more appropriate for gaming and fast-moving content than its 60Hz predecessor, although Skyworth has not yet provided a complete C2 connectivity specification or confirmed its HDMI configuration in the announcement.
That omission is worth keeping in mind before anyone starts assigning HDMI 2.1 ports that Skyworth has not actually announced.

How Close Is It to the Canvas Elite CE1?
Skyworth introduced the CE1 Canvas Elite at CEDIA Expo 2025 in 86 and 100-inch sizes, and eCoustics subsequently named the 100-inch model our Best Art TV at CEDIA 2025.
The CE1 remains the superior display on paper. It uses QD Mini LED technology with more than 1,000 local dimming zones, reaches a claimed 2,000 nits, offers a 144Hz refresh rate and uses the same OmniView Matte Screen technology. The 86-inch model is currently listed at $3,999 and the 100-inch version at $5,999.
The C2 therefore does not duplicate CE1 performance. It effectively moves some of the flagship’s display architecture further down the Canvas range, with roughly half the claimed peak brightness and substantially fewer dimming zones.
That is actually the more important story.
A 100-inch $5,999 lifestyle television is impressive, but it is not going into most living rooms. A 55, 65 or 75-inch version using full-array QD Mini LED technology has the potential to compete for considerably more wall space.
Pricing will determine whether that potential becomes reality.

Is the Skyworth C2 Really Unique?
Not entirely, and this is where the marketing department needs to put the champagne back in the refrigerator.
Mini LED is no longer exclusive to Skyworth among televisions designed to double as artwork. Samsung’s 2026 The Frame Pro uses its Neo QLED Mini LED platform and supports 144Hz operation, while TCL has also introduced QD Mini LED technology in its premium NXTVISION Art TV lineup.
What makes the C2 Canvas Art TV noteworthy is the combination Skyworth is bringing into its standard Canvas range: full-array QD Mini LED backlighting, 400-plus local dimming zones, 1,000-nit claimed brightness, 144Hz operation, Dolby Vision, HDR10+ and a matte display.
There is another important distinction. Skyworth supports Dolby Vision, which Samsung still does not offer on its televisions.
The company has also integrated a subwoofer and Dolby Atmos audio into the C2. Skyworth goes so far as to suggest an external soundbar is unnecessary. We will reserve judgment on that one until somebody actually listens to it; physics has not yet received notice that it has been cancelled.
CEDIA Is Also Part of the Story
The C2 is not being positioned solely as another television destined for a pallet at Costco.
Skyworth says the new models will be distributed through its authorized custom integration dealer network, which helps explain the CEDIA Expo debut. The company supports integration with control platforms including Control4 and Crestron, while installers can order customizable frames through Skyworth’s partnership with Hydro Frames.
Standard frame finishes include black, silver, gold, white and walnut, with additional custom patterns and colors available.
That flexibility matters in a category where the television is supposed to disappear into the room rather than announce that somebody bought another 75-inch black rectangle.
Skyworth Is Becoming Harder to Ignore
The C2 also arrives during a much more consequential year for Skyworth in North America.
Earlier in 2026, Panasonic announced a strategic partnership with Skyworth for its U.S. television business, with Skyworth USA assuming a major operational role covering sales, marketing and logistics while the relationship also leverages Skyworth’s manufacturing scale. That development followed Skyworth’s growing push into premium Art TVs and outdoor displays in the American market.
That makes products like the C2 worth watching beyond their individual specifications. Skyworth is no longer merely another enormous Chinese television manufacturer trying to establish name recognition with American consumers. Its role in the North American television business is expanding rather quickly.
The Bottom Line
The Skyworth C2 Canvas Art TV looks like a far more consequential product than the C1 it follows.
Moving from a 300-nit, 60Hz conventional LED platform to 1,000 nits, 144Hz and more than 400 full-array local dimming zones changes the conversation from “television that looks attractive on the wall” to something that could potentially deliver credible home theater performance as well. It is not the first premium Art TV to embrace Mini LED, and Skyworth still needs to reveal important details including pricing, complete connectivity and final availability.
But if the C2 arrives at the right price, Samsung, Hisense and TCL will have another serious competitor hanging on the wall. And this one appears rather more interested in what happens after you stop looking at the Monet.
Price & Availability
The Skyworth USA website currently lists pricing at $1,399 to $2,499, but we haven’t received any information when it will become available yet.
Related Reading:
Tech
Take-Two’s Leak Burying DMCA Attempts Snared GameStop & Gaming Journalist That Did Nothing Wrong
from the ready-fire-aim dept
I have mostly stayed away from the whole saga surrounding the drip-drip leaks of Grand Theft Auto 6 content prior to the big reveal on Netflix because, frankly, I am quite wary of giving companies the kind of guerilla marketing wins that sometimes look like this sort of thing. That being said, I really don’t think any of this was some attempt to Streisand what is perhaps already the most anticipated game of all time into wider news coverage, and that is backed up by the DMCA blitz Take-Two has gone on to try to bury all of these leaks.
Those attempts shouldn’t surprise anyone, honestly. Take-Two and Rockstar have historically abused copyright law to try to bury all kinds of content it doesn’t like, whether it’s been game leaks in the past, or cheats for its games, or mods it doesn’t like.
But it sure would be nice if the partners Take-Two has doing the abusing of the law could bother to be somewhat accurate and not ensnare a gaming journalist for the crime of posting publicly available court documents.
On August 26, Stephen Totilo — the longtime Kotaku editor-in-chief who now runs the Game File newsletter — was locked out of his X account over a DMCA notice filed on Take-Two’s behalf. Totilo’s offense, by his own account, was an August 21 post reporting that judges in New York had cleared Take-Two to subpoena Microsoft and Discord in the leak hunt.
Attached were three screenshots: the two court orders, and a tweet from Xbox CTO Scott Van Vliet pledging Microsoft is “working closely with Take-Two and Rockstar Games.” No leaked footage. No gameplay. The orders are public records that never once use the words Grand Theft Auto.
After Totilo complained both to ExTwitter and on ExTwitter, his account and the original tweet were restored and the DMCA claim had been rescinded. There is no indication that Take-Two or the vendor it was using to police the internet for these leaks have said anything publicly or privately to Totilo. They just nuked his account over a bullshit claim that ten seconds of review would indicate contained no infringing material, then restored it when the mistake was called out, and now are trying to Homer Simpson back into the bushes as though nothing happened.
But what makes this all the more frustrating is that the DMCA notice doesn’t make a copyright claim. It appears to make a trademark claim, instead.
It asserts Take-Two’s international figurative trademark on Grand Theft Auto — a trademark on the logo — and argues there is a likelihood of confusion, the legal test for whether the public might mistake someone else’s goods for the brand’s.
In plain English: a copyright takedown form was used to make a logo complaint, against images that contain neither the logo nor a single frame of the game.
The notice describes the reported content — federal court orders included — as “video/audiovisual recording,” and certifies all of it as accurate under penalty of perjury, the line that makes knowingly lying on the form a federal offense.
Everyone in this portion of the story, save Totilo, sucks at their jobs. Take-Two has clearly partnered with a company, Ebrand, that is not up to the task of properly policing IP on the internet. Ebrand messed this up badly, asserting a trademark claim via a copyright mechanism. ExTwitter, for its part, apparently demonstrated just how little review is done on this sort of thing, having taken down the tweet and suspending a journalist’s account over this absolute mess of a DMCA claim. It’s a full cornucopia of stupid on display for the world to see.
And this isn’t a one-off. Gamestop was also ensnared in Take-Two’s DMCA blitz. Its crime appears to be sharing a promotional screenshot for GTA6 that Rockstar specifically made available for use publicly.
Its August 20 post promoting a story on the billions in market value Take-Two shed as the leaks spread got struck, and the image X wiped was Rockstar’s own official GTA 6 screenshot, straight from the press gallery on Rockstar’s site.
That exact shot has run on dozens of outlets since May 2025, IGN and Mashable included. Take-Two’s vendor filed federal paperwork against a promotional asset Rockstar distributes so that outlets will use it.
There is simply no point to the DMCA’s “under penalty of perjury” language if it can’t be employed in a situation like this. At the very, very best, Ebrand and Take-Two are guilty of unbelievable negligence in issuing these DMCA takedowns and copyright strikes. When we’re talking about even temporary takedowns of the work of journalists, the First Amendment implications become obvious.
To allow these companies to simply slink away without penalty is why this sort of thing keeps happening. If there are no consequences to a carpet-bomb approach to copyright (trademark?) takedowns, then they will, and do, continue.
Filed Under: copyright, dmca, grand theft auto 6, journalism, leaks, stephen totilo, trademark, video games
Companies: ebrand, gamestop, take two, x
Tech
AMD’s Threadripper Halo is a local-AI workstation for researchers with deep pockets
On-PREM
AI workstation promises to put up to 576 GB of HBM3e and 16 TB/s of memory bandwidth on your desk
Machine learning researchers have a new and expensive option for doing local AI. AMD just raided its spare parts bin and cobbled together a DGX Station rival boasting up to 576 GB of HBM3e memory that it’s calling the Threadripper Halo.
Announced at IFA 2026, the system, which is set to launch next year, marks the first time that AMD’s Instinct accelerators have been offered in a workstation form factor.
But much like the AI Halo we reviewed earlier this year, the Threadripper Halo isn’t packing anything we haven’t seen before. The liquid-cooled system is powered by a 96-core Threadripper PRO 9995WX, which you may recall made its debut in 2025. The CPU is backed by up to 2 TB of DDR5 memory and up to 2.6 TB of combined system memory.
As you probably already guessed, AMD is positioning the box as a local AI workstation for researchers. From what we gather, the system can be had with up to four of the company’s PCIe-based Instinct GPUs — though the systems displayed at IFA only showed two installed.
Launched back in May, the MI350P is essentially half of an MI350X that’s been crammed into a PCIe form factor. Each accelerator packs 144 GB of speedy HBM3e good for 4 TB/s of memory bandwidth, and up to 4.6 petaFLOPS of FP4 compute. But we’ll note that it’s in its 600 W configuration. When deployed in the Threadripper Halo, we expect AMD will be running the cards in the more sedate 450 W config.
Combined, the Threadripper Halo promises up to 576 GB of HBM3e and 16 TB/s of memory bandwidth, enabling the system to run models exceeding a trillion parameters in size (at four-bit precision) entirely in GPU memory. By offloading some of the model to system memory, the system should be able to run the largest open weights models, like Moonshot.AI’s 2.8 trillion-parameter Kimi K3.
The ability to run large frontier-class models on your desk won’t come cheap and may not be available in every market, at least not without an electrical service upgrade. AMD hasn’t shared pricing, but as configured, we expect it to sell for somewhere between $100,000 and $150,000.
A quad MI350P system is going to push the limits of a standard North American power outlet unless AMD either underclocks the cards from 600 W to 300 W or it mandates a 20 amp circuit. This might explain why the system AMD showed off at IFA only had two.
At this price and power level, the system is well positioned to compete with Nvidia’s own high-end AI workstation, the DGX Station. Announced at GTC in 2025, the DGX Station features a 252 GB B300 GPU and a 72-core Grace CPU along with 496 GB of LPDDR5x memory, and it retails for around $100,000 if you can find one in stock.
The House of Zen boasts that the system offers up to 3.4x the total system memory and more than twice the memory bandwidth of the DGX Station, which should give an edge in LLM inference, assuming tensor parallel operations don’t bottleneck on the CPU’s PCIe bus.
AMD says the Threadripper Halo will be available starting next year. ®
Tech
Startup Spotlight: Food photographer uses 25-year archive to build an AI tool that eliminates costly reshoots

Longtime Seattle food photographer Scott Pitts spent 25 years capturing commercial imagery for major brands, and now he’s using that quarter-century archive to train Pallat. The new AI-powered production system is designed to eliminate costly reshoots while keeping real studio craft at the center of generative creative tech.
@media (max-width: 600px) {
.gw-founder-box { float:none !important; max-width:100% !important; margin:20px 0 !important; padding:16px 18px !important; }
.gw-founder-box .gw-label { font-size:12px !important; margin-bottom:8px !important; }
.gw-founder-box .gw-hero { font-size:19px !important; }
.gw-founder-box .gw-byline { font-size:15px !important; }
.gw-founder-box .gw-meta { font-size:12px !important; margin-bottom:14px !important; }
.gw-founder-box .gw-facts { padding-top:14px !important; }
.gw-founder-box .gw-facts li { margin-bottom:12px !important; }
.gw-founder-box .gw-facts li:last-child { margin-bottom:0 !important; }
.gw-founder-box .gw-value { font-size:15px !important; line-height:1.45 !important; }
}
The platform combines fine-tuned open-weight models with Pitts’ extensive archive, allowing art directors to modify existing campaign assets — like swapping a topping, adjusting lighting, or changing a backdrop — in minutes through software rather than starting from scratch back on set.
Pitts, a non-technical founder operating Pallat out of his Seattle photo studio, SP Studio, leads a nimble five-person team and believes domain experience is key to competing with generic AI platforms.
“We are close to the problem, and we’re looking at it from a photographic eye,” he said. “We’re making sure those outputs look photoreal, that they’re not going to get labeled as AI slop.”
To show how the tech works in practice, Pitts points to a recent shoot for a national steakhouse client. After completing a complex setup for a burger — carefully layering the bun, patty, sauce, and greens — the brand asked if they had shot a version with tomatoes. Rather than calling back the food stylist and rebuilding the set, Pitts dropped the final image into Pallat, prompting it to add two tomato slices with subtle condensation, natural translucency, and accurate drop shadows cast onto the cheese below.
In another instance, a commercial seafood brand prepared packaging imagery for a buyer presentation, only for the client to ask to see the fish presented on a white plate instead. Pallat to the rescue.

Commercial photographers have long tweaked images using tools like Photoshop, but Pitts sees AI as the natural next step for advertising workflows — distinct from news photography, where image manipulation remains out of bounds. Where Photoshop requires painstaking manual editing to adjust a scene, Pallat handles complex lighting, translucency, and material physics in minutes based on a simple prompt.
The startup recently signed its first enterprise customer and is currently working directly with brands as a hands-on production partner while building toward full software access.
Pitts sees the technology not as a threat to his craft, but as a natural progression. He started his career shooting four-by-five film, then transitioned to digital and video. AI is another progression.
“My hope is that me building Pallat is sort of this bridge between tech and creative,” Pitts said. “Craft is still important. Judgment and taste are still probably some of the most important things.”
Continue reading for Pitts’ answers to our Startup Spotlight questionnaire.
In 50 words or less, give us your startup’s elevator pitch.
Pallat is a photographer-led AI production system built for food and beverage brands, born from a working photo studio. It combines licensed photography with generative workflows to help brands scale photo-centric content while maintaining the creative control expected from commercial photography.
What problem are you obsessed with solving?
I’ve spent 25 years watching brands solve the same problem: invest in a shoot, then ultimately need more usable imagery than the initial shoot was designed to deliver. Generic generative tools can create images, but weren’t built around the quality, control and production standards food and beverage brands require.
I’m obsessed with using AI to close the gap. Pallat gives brands a way to extend photography they’ve already invested in and create new production-ready imagery grounded in a licensed dataset and the standards of a traditional photoshoot.
What surprised you after talking to customers?
Because we’re so close to the problem we’re solving, their need for a solution and high bar for quality didn’t surprise me.
What did was how much generated imagery disrupted their existing workflows. There is no obvious owner, no review path and no shared vocabulary for feedback and approvals. Brands are asking us to help establish new workflows, and that has turned out to be almost as important as building the tech itself.
How has AI changed the way you build your company?
AI is a big part of why a five-person team can build something like this. Our tech stack is built on open-weight models that we fine-tune using proprietary training data, while foundation models support planning and a handful of day-to-day operations.
Not to oversimplify it, but in many ways my role at Pallat parallels production. I built a team of experts, defined the problem we’re solving and established the criteria for the output. A growing part of my work is getting those standards out of my head and structuring evals so they hold when I’m not in the room.
What’s one thing people misunderstand about your startup?
That Pallat is trying to replace photography. It’s far from it.
Practical photos are important inputs, and our studio continues to create net-new ones to expand the system. Visual trends are always evolving, so datasets powering creative tech cannot be static. The future of production is hybrid: practical photography and generative imaging working together, with each deployed where it creates the most value.
What’s the toughest decision you’ve made in the past year?
Resisting the urge to broaden Pallat before we establish product-market fit. The goal isn’t to automate every step as quickly as possible. It’s to understand which problems in the workflow are best solved through software.
What’s the one piece of advice you give to other entrepreneurs?
I truly believe some of the most interesting AI companies will come out of service businesses where the founder knows the industry exceptionally well — where the friction lives, which shortcuts a client will notice, and what excellence looks like in their vertical.
I spent a long time assuming my 25 years in photography was the past and AI was the future, and I had that backwards. The years on set that sharpened my taste and judgment, our dataset and the client relationships are the true compounding assets.
We’ll know our company has made it when…
When an art director at a food or beverage brand drafts a shot list dividing it into two columns: “Capture as Practical Photography” and “Generate in Pallat.”
When that becomes a normal way of planning, Pallat will have done what we set out to do.
Tech
This is the folding iPhone, if case manufacters are right
Ahead every iPhone release event, case manufacturers generate dummy units to see if their cases will fit properly. We’ve got our hands on these faked iPhone 18 Pro and folding iPhone models, so let’s take a look.
The dummy unit “industry” is bigger than ever this year, as you’d expect when there are three flagship models coming out, not just two. In recent weeks we’ve seen 3D prints and metal blanks, of what case manufacturers think that iPhone 18 Pro, iPhone 18 Pro Max, and folding iPhone will look like.
It’s also crucial to recognize that these are just useful to visualize the design and size of the new units. They give zero insight into the internals of the phone or what features it may support.
iPhone 18 Pro
Let’s look at the iPhone 18 Pro and iPhone 18 Pro Max first.
As the rumors suggested, the iPhone 18 Pro and iPhone 18 Pro Max will keep almost exactly the same form factor as the iPhone 17 Pro. Taking some calipers to these models, they’re almost exactly the same size as last year’s flagships.
Side by side, the plastic dummies are nearly indistinguishable. We’ve heard that there may be some minor differences in the camera bump. It’s hard to tell with certainty here because of the poor tolerances on the engineering sample plastic.
Comparing the dummy iPhone 18 Pro Max next to our iPhone 17 Pro, we couldn’t tell much of a difference at all in the camera bump size. Perhaps the final models will have some slight tweaks here, but case manufacturers are already repackaging existing cases for the iPhone 17 Pro to suit.
So, right now, it seems that new cases will be backwards compatible, but not all older iPhone 17 cases will be forward compatible. Cases for iPhones are a billion-dollar industry, and it can be risky to start producing cases early when there may be these slight deviations.
The most likely way to tell an iPhone 18 Pro or iPhone 18 Pro Max device from an older one will be the colors. As it has ever been, there has been a lot of debate around the final colors.
It seems a dark cherry red will be in the mix, and our dummy unit has a version of this rumored dark red color. It looks nice, but it’s probably not for everybody.
It’s too early to judge though, as this is just based off the rumor. Don’t expect Apple’s color to perfectly match, or have the same semi-gloss finish.
One question we’ve had is on the Dynamic Island and whether or not it will see its size adjusted. Dummy units though, still can’t tell us anything on below-the-screen components.
The folding iPhone
More interesting to users is likely Apple’s long-rumored folding iPhone, commonly referred to as iPhone Ultra. Compared to early 3D printed models or dummies, our dummy is far more finished.
It has working hinges, pressable buttons, and a more polished camera plateau. Looking at the rear cameras, it does seem that aside from the wide and ultra-wide lenses, we’ll see a True Tone flash and possibly LiDAR located just to the right of the lenses.
We’re unsure if the depth of the camera lenses is accurate, but if so, they stick out quite a bit. Since the body of the phone is so thin, and the plateau is thinner than on the iPhone Air, it makes the lenses protrude quite a bit on their own.
There are the volume buttons on top of the right side when open. Camera Control and power are on the right edge, and USB-C is on the bottom-left when open.
When unfolded, the speakers are on opposite corners of the device. This should allow for stereo or possibly even Spatial Audio. This will help Apple avoid the problem of one-sided audio, which is a major complaint about the iPhone Air.
On the inside, the screen shows a fold down the middle, something Apple is rumored to have mostly solved on the real thing. You can see a small camera coming through the screen in the top-left corner.
We’re not too concerned about what we feel is a flaw in the model. When closed, the hinge side has sharper corners, which isn’t super comfortable when held in the left hand.
The corners opposite the hinge are rounded, which do fit nicely into your palm while holding the dummy. It will be interesting if Apple chooses to round the right two corners of the display but keeps the left ones at a right angle, or if it rounds all four.
Otherwise, the form factor feels excellent in the hand. The exterior screen is a perfect size to reach all four corners with one hand and the interior screen is big and spacious, just a bit smaller than an iPad mini, and perfect for split-screen apps.
If the prevailing rumors are accurate, this foldable will lack Face ID. It’s said that the device is too thin, but that doesn’t make a lot of sense, given that the iPhone Air has it. We’ll see.
Not only can we not determine if there is any TrueDepth camera system behind the display, we can’t tell which button may house the Touch ID sensor. It could theoretically be behind the screen too.
In all likelihood, if included, Touch ID will be contained in the power button, the same as it is on the iPad mini.
When opened, as you’d expect, the foldable is about as thin as the iPhone Air.
With the larger screen size, that makes the device feel even more futuristic than the iPhone Air.
The real thing is coming soon
Ultimately, these devices don’t do much more than confirm many of the rumors we’ve heard regarding the size, shape, and camera layouts. They’re a great physical representation of those rumors and an opportunity to see them in the real world.
These stoke interest further, building hype, and leaves us with more questions.
Software execution is just as important as hardware design and implementation. We don’t know for sure if it has vapor chamber cooling, if there is MagSafe, and if there’s Face ID.
Regardless, the new phones will be announced on September 9th at Apple’s Surprise and Shine event. And we’ll be there to cover it.
Tech
39 New Methods That Compromise Passkey Authentication
Passkeys were introduced with a strong security proposition. Replace passwords with public key cryptography, bind the credential to the legitimate service, keep the private key away from the server, and many of the phishing and credential theft attacks that have plagued enterprise security for decades become dramatically harder.
All of that is true. But the security conversation has changed very quickly.
There are now at least 39 publicly documented methods, attack paths, research techniques, and exploitation scenarios involving passkeys and the infrastructure around them. Many already have working proof of concept tools or published research showing exactly how the techniques can be executed. Some are already appearing in real world attack patterns.
That does not mean criminals have operationalized all 39. It does mean the playbook is being written in public, and attackers no longer have to invent these techniques themselves.
More importantly, the research exposes a fundamental distinction that enterprises need to understand. The cryptography inside FIDO2 can remain completely intact while the account protected by the passkey is still compromised.
The Target Is No Longer Just the Passkey
A modern passkey authentication ceremony crosses an extraordinary number of trust boundaries. It can involve the web application, browser, operating system, password manager, cloud synchronization service, mobile device, Bluetooth transport, account recovery system, enrollment process, help desk, and ultimately the human being approving the authentication.
Researchers are attacking almost every one of those layers. Published techniques now include assertion mining, assertion replay, circuit breaker attacks, assertion phishing, browser hooking, assertion capture, challenge injection, detour replay, user verification manipulation, and user presence manipulation.
SpecterOps demonstrated the significance of this problem in its Pass the Passkey research. One of its most important observations was that malware does not necessarily need to extract a private key.
A malicious Windows application can ask the legitimate WebAuthn infrastructure to generate a signed assertion. The user sees what appears to be a legitimate Windows authentication experience, completes verification, and the attacker receives the resulting assertion.
The private key never left its protected location. The cryptography was not cracked. Yet the authentication process was successfully manipulated.
That distinction is central to understanding the new passkey threat model.
Passkeys are not completely secure unless they are tied to dedicated biometric hardware.
Learn how attackers exploit passkey enrollment rather than breaking passkey cryptography, and why dedicated biometric hardware strengthens enterprise identity assurance.
Even the Passkey Prompt Is an Attack Surface
Several of the 39 published techniques target the user interface surrounding authentication.
Researchers have demonstrated passkey prompt flooding, credential interface deception, application metadata spoofing, window handle spoofing, remote desktop passkey phishing, and FIDO interface overlay attacks.
This recreates a problem the security industry already encountered with push-based MFA. Users become accustomed to authentication prompts. Once authentication becomes a routine visual interaction, attackers can manufacture, repeat, disguise, or strategically time those interactions.
SpecterOps demonstrated tooling capable of repeatedly invoking legitimate looking Windows passkey prompts. Researchers also demonstrated techniques that can make malicious authentication activity appear to originate from an application the employee already trusts.
The lesson is important. Phishing resistance at the cryptographic protocol layer does not guarantee deception resistance across the operating system, browser, application, and user interface layers surrounding that protocol.
Shareable Passkeys Expand the Attack Surface
The attack surface grows significantly when passkeys can be shared, synchronized, exported, restored, or moved between devices.
The published inventory now includes synced vault compromise, Apple or Google account takeover, cloud recovery takeover, stolen or compromised phones, mobile malware, rooted mobile devices, hybrid authentication manipulation, KeePassXC export theft, Bitwarden export theft, credential exchange theft, malicious browser extensions, and attacks involving CTAP and Bluetooth communication.
This is not fundamentally a cryptography problem. It is an architectural problem.
Once a credential can move between devices, synchronize through a cloud account, be exported from a vault, be restored using another identity, or be recovered through another process, the security boundary expands far beyond the original authenticator.
An attacker no longer needs to defeat FIDO2. The attacker needs to compromise one sufficiently trusted component somewhere in the surrounding ecosystem.
A synchronized passkey can therefore use extremely strong cryptography while still inheriting the weaknesses of the phone, operating system, password manager, cloud account, browser, recovery process, and synchronization system responsible for managing it.
Enrollment and Recovery Create Another Opening
Some of the most consequential attacks do not steal an existing passkey at all. They simply create another one.
Published techniques include shadow passkeys, enrollment vishing, attacker phone enrollment, attacker controlled passkey registration, help desk takeover, temporary credential abuse, SIM based recovery, reverse vishing, and migration pretext attacks.
Consider what happens when an attacker gains enough control of an employee account to initiate legitimate passkey registration. Instead of extracting the employee’s existing credential, the attacker registers an entirely new credential on a device controlled by the attacker.
Nothing has been cracked. Nothing has necessarily been stolen from the existing authenticator. The legitimate service itself creates a perfectly valid credential for the adversary.
This leads to an increasingly important identity principle. Phishing resistant authentication is insufficient if enrollment, replacement, recovery, and device registration are not protected to the same standard.
Dedicated Biometric Hardware Changes the Attack Surface
Dedicated biometric hardware approaches the problem very differently from passkeys stored on general purpose devices.
A purpose-built biometric authenticator can retain the private credential inside secure hardware with no cloud synchronization, no export mechanism, and no password manager responsible for moving the credential between devices.
Authentication can require a live fingerprint directly on the authenticator as well as physical proximity to the endpoint requesting access.
Just as importantly, a dedicated authenticator does not need to contain a traditional general-purpose operating system, an application store, a browser, or a screen.
That distinction eliminates enormous portions of the attack surface.
There are no third-party applications for an attacker to replace with malicious versions. Rogue applications cannot simply be installed on the authenticator. There is no browser extension ecosystem to compromise. There is no screen on which malware can present a deceptive authentication interface.
There is no consumer operating system filled with unrelated applications, permissions, background services, and update dependencies.
The authenticator performs a very small number of security specific functions and nothing else.
This drastically changes the economics of attacking it. Instead of attempting to compromise a huge general purpose computing environment, an attacker is confronting a tightly controlled hardware device designed specifically to protect cryptographic credentials and verify biometric identity.
It also makes the authentication process far more resistant to employee manipulation. An employee can be persuaded to visit a website, answer a telephone call, or follow instructions from someone claiming to be technical support. But social engineering cannot install a rogue application onto hardware that does not run ordinary applications.
It cannot manipulate a screen that does not exist. It cannot synchronize a credential through a cloud service that the authenticator does not use.
In that sense, properly designed dedicated biometric hardware becomes both highly resistant to attackers and highly resistant to mistakes made by employees.
Correct Service Configuration Is Critical
Dedicated hardware alone is not enough. The relying service must be configured to preserve the security model.
For sensitive enterprise environments, authentication and enrollment should be restricted to approved authenticator classes. The relying party should validate authenticator identity, enforce user verification, properly validate challenges and sessions, use appropriate signature counter protections, and prevent weaker methods from becoming fallback authentication paths.
Enrollment and recovery deserve particular attention. Adding a new authenticator should require proof from an already authorized authenticator rather than merely proving control of an account through a weaker recovery channel.
Configured correctly, this architecture prevents an attacker from simply enrolling an ordinary passkey from another laptop, phone, software vault, or security key. Cloud account takeover does not yield the credential. Password manager compromise does not yield it. Mobile malware cannot infect the authenticator.
A malicious application cannot be installed on it. And a remote attacker cannot manufacture the combination of dedicated hardware, biometric verification, physical proximity, and legitimate service interaction required to authenticate.
What the 39 Attacks Really Tell Us
The existence of 39 published attack methods does not mean FIDO2 cryptography failed. In many ways, it demonstrates the opposite.
Researchers repeatedly attack the software, synchronization systems, enrollment processes, operating systems, browsers, recovery mechanisms, and people surrounding the credential because defeating properly implemented cryptographic hardware directly is considerably more difficult.
That should tell security leaders where the next identity boundary needs to be.
For high value enterprise identities, credentials should not be freely shareable across consumer devices and cloud ecosystems. They should be bound to dedicated biometric hardware, the verified individual, the legitimate service, and an enterprise controlled enrollment and recovery process.
Passkeys solved a large part of the password problem. The 39 published attacks show us what attackers are targeting.
Dedicated biometric hardware, correctly implemented from enrollment through authentication and recovery, removes virtually all of that surrounding attack surface before an attacker ever gets the opportunity to use it.
Download the Token passkey security ebook to explore many published attack methods and see how dedicated biometric hardware changes the enterprise identity trust model.
Sponsored and written by Token.
Tech
Google brings its best AI music model Lyria 3.5 to the Gemini app
Google has added Lyria 3.5, its most advanced music generation model yet, to the Gemini app. Previously available through Google’s AI filmmaking tool Flow, the model is now rolling out to all Gemini users, making it easier to generate polished songs, instrumentals, and soundtracks from simple text prompts or even photos.
Lyria 3.5 makes AI-generated music sound more natural

Google says Lyria 3.5 delivers richer arrangements, more expressive vocals, and better prompt comprehension than previous versions. The model builds out full songs complete with actual verses, choruses, and bridges, rather than just looping a short melodic clip.
Inside Gemini, you can now pick or describe a genre, choose between vocal or instrumental styles, and decide whether you want a short clip or a longer track. If you are a beginner, you can use templates to get started and generate background music for a video, a custom jingle, or a personalized ringtone.
However, keep in mind that once a track is generated, you can’t edit it mid-prompt. Google is also making Lyria 3.5 available through the Gemini API, allowing developers to integrate AI music generation into their own apps and services.
Lyria 3.5 arrives at a chaotic moment for AI music
AI music has flooded music platforms like Deezer, where AI-generated songs now make up 44% of daily uploads, and a large share of the streams they’ve pulled in were later found to be fraudulent. This is why every track Lyria makes carries a SynthID watermark – an invisible marker meant to flag it as AI-generated content.
Lyria’s guardrails specifically block cloning an artist’s voice or reproducing copyrighted lyrics, following a recent European court ruling against Suno, a rival AI music company, over copyright issues. That ruling isn’t the final word on the matter, though. It’s still subject to appeal, so the legal picture around AI generated music remains unsettled for now.
Tech
Ctrl-Alt-Speech: License To Spill | Techdirt
from the ctrl-alt-speech dept
Ctrl-Alt-Speech is a weekly podcast about the latest news in online speech, from Mike Masnick and Everything in Moderation‘s Ben Whitelaw.
Subscribe now on Apple Podcasts, Overcast, Spotify, Pocket Casts, YouTube, or your podcast app of choice — or go straight to the RSS feed. To get extended episodes with additional coverage, support us on Patreon.
In this week’s episode, Mike and Ben cover:
And in the extended episode for Patreon supporters, they cover:
Our fun links this week include a Korean AI dance generator and defrag your Windows PC.
Follow us on Instagram, YouTube, and Bluesky for video clips from this week’s episode!
If you’re already a Patreon supporter, you can get the extended episode on Patreon.
Filed Under: age verification, ai, artificial intelligence, content moderation, cybersecurity, trust and safety
Companies: openai
Tech
Two unreleased Apple game controllers found in macOS code
Apple already supports nearly every major game controller, but new evidence suggests that the company may want to add its own hardware to the mix.
Apple may be looking to expand its ambitions beyond software and platform support. Newly discovered code references two unreleased controllers with notably different feature sets.
The references appeared within code briefly included in macOS 26.7, first spotted by pdfu, a MacRumors forum regular. The controllers in question are identified as “T6502” and “T1057”.
The game controllers will likely be similar to others that already exist on the market. There are notable differences between T6502 and T1057, though.
Both will feature a four-button ABXY layout, two clickable thumbtacks, shoulder buttons, analog triggers, and Home and Menu buttons. Essentially, they’ll have the same functionality as any of the first- or third-party PlayStation- or Xbox-like controllers out there.
T6502, the more basic of the pair, will also see the addition of an Options button. It will connect via USB only, and does not feature motion sensors or motion input through Apple’s GCMotion interface.
There will be no touchpad-like controls, rear buttons, speakers, microphones, or other advanced features.
Perhaps the most interesting part is Apple’s haptic channels. T6502 will utilize four separate haptic channels in software: Left, Left (Synthetic), Right, and Right (Synthetic).
According to pdfu, this may be created to let two software haptic request channels share the same physical motor. This should allow for proper feedback and reduce distortion and clipping.
T1507 seems to be the higher-end of the pair. It will connect via USB, as well as Bluetooth and Beats USB; it will not feature an Options button.
Its motor system doesn’t divide out synthetic channels. Instead, it has a single, addressable actuator motor.
It also includes an accelerometer and gyroscope. This should allow for input via acceleration and gyroscope readings on the X, Y, and Z axes.
The code was initially customer-facing. As pdfu notes, the references were pulled in the second release of macOS 26.7.
Late to the game
It’s not entirely clear why Apple would be creating a game controller now. The controller market is crowded with well-established first- and third-party options.
Apple has spent years expanding support for controllers that players likely already own, including those from PlayStation, Xbox, Nintendo, and countless third-parties. With plenty of options available at nearly every price point, an Apple-made controller would need to offer something more than just bog-standard game controls.
That isn’t to say it wouldn’t sell well if they did. There will always be a market for things Apple makes, a lesson we’ve learned from products like the iPhone Pocket and the original $19 Polishing Cloth.
Tech
RFK Jr. Wants Your Medical Records
from the seems-bad dept
This article is republished from The Conversation under a Creative Commons license. Read the original article.
You might assume that what you tell a doctor stays between you, your physician and perhaps your insurer. But the reality is more complicated.
The Health Insurance Portability and Accountability Act, the federal privacy law that governs health information and is commonly known as HIPAA, is narrower than its reputation suggests. It regulates hospitals, physicians, insurers and their business associates, but not the health data you generate everywhere else: not the period-tracking application on your phone, the internet search you ran about a diagnosis, the DNA you mailed to a genealogy company or the wearable that counts your heartbeats.
Even the records HIPAA does cover can be shared, sold or handed to the government in ways that might surprise you.
This gap in protection matters more than ever because the U.S. government is pushing hard to gather health data domestically and abroad. This is happening even as a growing body of research shows that the safeguard which these efforts to collect data lean on – anonymizing data by removing identifying information to make it difficult to trace back to an individual – is far weaker than officials claim.
As a professor of law at Indiana University, I study health information privacy and medical data regulation, which includes tracing how sensitive health information moves among clinics, government agencies and law enforcement. As a co-investigator on a federally funded study about opioid prescribing, I rely on health data in my own research. I appreciate its value for science, and I also see the danger of collecting it without meaningful safeguards.
Limits of medical privacy
HIPAA gives you several rights: You can see your health records, demand corrections and expect that a covered provider will not casually disclose your information.
But the law also permits release of some information without your consent. A hospital fully bound by HIPAA may release certain types of records without your authorization and without telling you. There are roughly a dozen such categories. Information about treatment, payment and routine healthcare logistics require no sign-off. Neither does information released for public health reporting, law enforcement, judicial and administrative proceedings, health plan oversight, research or the broad catchall of essential government functions.
The statute is also thick with additional exceptions. In practice, much of your health information can be shared through these many open doors. And once data is sent outside the system covered by HIPAA, the HIPAA limits fall away.
For instance, prescription drug monitoring programs, which every state now operates, assemble detailed logs of who filled which controlled substance prescription and when. Federal law enforcement can often access these logs with a self-issued administrative subpoena – an order that doesn’t require a judge’s approval or oversight.
These programs have expanded beyond opioids into a dragnet that shares health data across state lines, exposing patients who seek reproductive or gender-affirming healthcare to surveillance far from home.
Health records can flow to many destinations under different rules. A given disclosure might feel more like a violation depending on who decides where it can go and who can then see it.
RFK Jr.’s push to access Americans’ health records
Since the spring of 2025, Health and Human Services Secretary Robert F. Kennedy, Jr. has sought federal access to Americans’ medical records to investigate whether vaccines cause autism. The scientific community has studied this question for decades and has shown decisively that they do not.
According to KFF Health News, HHS has been courting state health information exchanges – the little-known systems that let hospitals and clinics swap detailed, identifiable patient records – and asking how those records might be used for vaccine research. One proposal floated by state organizations would give HHS data on 90% of Americans’ medical records by 2028. In Nebraska, millions of federal grant dollars have flowed to a statewide health information exchange nonprofit that has cooperated with the effort.
Large health datasets can be useful. Pooled records can expose drug side effects, track outbreaks and reveal disparities in care that smaller studies miss. Public health has always depended on some surrender of individual privacy for collective benefit.
The concern is not that the government should never collect health data. It is that meaningful safeguards have not kept pace with the scale of collection and capabilities of modern data analytics.
In seeking access to Americans’ medical records for a vaccine and autism study, HHS has declined to say how many states are involved, what data it collects, who can see it or how it will be protected.
Building a comprehensive repository to chase a question that science has already answered inverts the logic of research. Usually a hypothesis justifies the data collected, rather than the reverse.
Collecting identifiable records for tens of millions of people in a single database also creates a target for breaches, secondary uses that no one consented to and abuses by current or future administrations with different priorities.
‘Anonymized’ doesn’t protect your health privacy
Officials have offered reassurances that data will be aggregated and stripped of identifiers so no individual can be singled out.
Decades of computer science research undercuts that promise. A study published in Nature in June 2026 sharpened the point, showing that in this age of artificial intelligence, stripping identifiers from patient records to protect identity does not protect all patients equally.
The researchers audited AI diagnostic models trained on clinical data, including chest X-rays, electrocardiograms and electronic health records. They asked whether an outsider could tell if a particular person’s data had been used to build the model. For instance, confirming that someone’s record helped train a cancer-prediction tool can reveal that that person has cancer. This exploit is known as a membership inference attack.
The research team found that while the average risk of being identified from data stripped of identifying information often looked reassuringly low, some patients faced near-certain reidentification The burden fell unevenly: Underrepresented groups, sorted by race, insurance status or diagnosis, were most at risk. Those most exposed were frequently already most vulnerable to discrimination.
Researchers have long established that removing identifiers from rich datasets does not reliably protect the people in them, and that identification gets easier the more information you have. Today’s AI technology makes it possible to carry out these attacks remotely and quickly.
The same privacy problems, exported
The U.S. government’s appetite for health data does not stop at the border. As ProPublica reported in June 2026, the State Department has been conditioning lifesaving aid to African nations on access to their citizens’ health data.
Under the Trump administration’s global health plan, Uganda agreed to give the United States real-time access to nine of its health data systems for seven years, including the central repository of the nation’s health information and the system managing individual electronic medical records, in exchange for up to US$1.7 billion over five years, a sum that shrinks each year and falls below prior U.S. support. Kenya struck a similar deal; Zambia, Zimbabwe and Ghana walked away from the initial terms.
The U.S. government has promised that the data will be aggregated and anonymized, but privacy experts warn that the agreements are vague and omit standard limits on how much data is taken and how it can be used. A Ugandan digital rights lawyer called the choice his country faced the essence of digital colonialism: Accept the deal and risk exploitation, or refuse it and watch people die.
The common thread
Domestic records collection and foreign data-for-aid deals rest on the same faith that anonymization neutralizes the risk of pooling sensitive health data.
The evidence says otherwise. This does not mean health data should never be gathered or studied, but I believe that the reassurances deserve skepticism, the safeguards deserve scrutiny, and the people whose bodies generated the data deserve a say. To safeguard privacy, a government seeking sensitive medical records should have to show why it needs them and how the safeguards it relies on hold up.
Privacy law was built for a world where data resided in filing cabinets. Governments from Kalamazoo to Kampala now operate in a world where even an anonymized digital record can point back to you.
Jennifer D. Oliva is Professor of Law, Indiana University
Filed Under: autism, hipaa, medical records, privacy, research, rfk jr., vaccines
Tech
Lamborghini Temerario Polizia Unveiled, Boasts 907 Horses for Italy’s Most Urgent Runs

On Friday at Lamborghini’s Sant’Agata Bolognese headquarters, Interior Minister Matteo Piantedosi stood with Chairman and CEO Stephan Winkelmann as a Temerario in official Polizia colors entered service. Prefect Renato Cortese attended for Police Chief Vittorio Pisani. A book called “I motori della Polizia,” a short record of the force’s working machines, was presented with the car.
The Polizia di Stato’s collaboration with Lamborghini began in 2004, when a Gallardo made its maiden organ run late that September. But we’re talking about a whole different generation of automobiles now, with the Gallardo LP 560-4, Huracán lined up along the autostrada, and a Urus Performante coming in 2023. In twenty-two years, we’ve seen six donated Lamborghinis cover over 200 organ and medical supply trips before attending more than 1,500 road-safety events, and Temerario is now joining the ranks. It joins a group that includes those six Lamborghinis, as well as a host of other vehicles, and they have no plans to retire the ones that are already in service
Sale
LEGO Technic Lamborghini Revuelto Super Sports Car Toy – Building Set for Girls & Boys – Lamborghini…
- REMOTE CONTROL TOY CAR – Builders ages 10+ can create a fully motorized LEGO Technic Lamborghini Revuelto supercar with authentic Italian styling…
- INTERACTIVE SUPERCAR MODEL – This car toy connects to the CONTROL+ app where drivers can steer the vehicle, activate lights, and monitor live…
- AUTHENTIC LAMBORGHINI FEATURES – The detailed car model includes glow-in-the-dark headlights, sleek aerodynamic body, and realistic proportions that…
The Temerario’s power comes from a fresh new 4.0-liter twin-turbo V8 and three electric motors that feed an eight-speed dual-clutch transmission. Overall, the combined output is 907 horsepower, with the V8 alone generating 800 CV, a staggering 10,000 rpm, and 730 Newton-meters of torque. Yeah, the factory-quoted time to 100 km/h is 2.7 seconds, and the top speed is 343 km/h. Oh, and the hybrid stack contains a 3.8-kilowatt-hour battery; this is the first plug-in hybrid in the police fleet’s history.

Temerario appears to be sporting the same livery that we’ve come to associate with the Gallardos from their inception: blue and white paint, Polizia branding on the doors, and the traditional tricolor flashing lights. There is a light bar on the roof, however we are unsure whether there is a separate chilled medical section for medical purposes.
You may be wondering why a mid-engine coupe like this one is wearing this type of livery; the simple answer is that it is for organ transport. The truth is, most of the time it’s conducting routine officer duty, such as teaching kids in schools and driving at events, and it won’t be purchased with taxpayer money because Lamborghini gives each one. Instant shove off the line, followed by a brief period of calm running before the V8 kicks in, which is essentially what the electric motors bring to the party. Handy when you get a call and need to get on the road right away, especially if it starts in a metropolis. The prior Lamborghini police cars employed naturally aspirated V10 engines, so this is a completely different ballgame.

You can tell that the Temerario transfer was portrayed as merely another chapter in what is turning out to be a remarkable collaboration between Lamborghini and the Polizia di Stato. Now it is up to Temerario to complete its next run on time.
-
Crypto World17 hours agoBitcoin price stalls near $82K as key resistance holds
-
Politics17 hours agoBest Gaming Laptops, CPUs, TVs, And Keyboards To Upgrade Your Set Up For GTA VI
-
Tech18 hours agoThe Birds Outside, Drawn For You Automatically
-
Crypto World20 hours agoIMF Says El Salvador’s Post-Review Bitcoin Purchases Used No Public Funds
-
Crypto World17 hours agoU.S. added stronger than expected 162,000 jobs in August as labor market bounced back
-
Sports20 hours agoAlexandre Pato consortium’s Northampton Town investment approved
-
Sports16 hours agoGolden Eaglets Drawn in Group B for 2026 WAFU B U17 Championship
-
Sports21 hours agoCommanders’ Chig Okonkwo is a top breakout fantasy football candidate
-
Crypto World15 hours agoXRP price breaks falling channel as bulls target $1.53
-
Politics23 hours agoA new European chapter for Gibraltar
-
Politics19 hours agoThe House | Bin the lectures, bring gossip and be ready to banter: how the new PM should prepare for his Trump encounter
-
Politics15 hours agoHow To Avoid Winter Colds: 4 Everyday Habits That Spread Germs, Says Pharmacist
-
Crypto World15 hours agoFrom warning to listing: UK’s largest retail investment platform opens access to crypto ETNs
-
Tech17 hours agoA Worthy Android Ereader, With Some Tradeoffs
-
Crypto World16 hours agoFinCEN flags $12.7B tied to Southeast Asia crypto investment scams
-
Crypto World16 hours agoTrezor Data Breach Impacts 67,000 More US Customers
-
Politics21 hours ago33 Cosy Autumn Home Decor Ideas: Blankets, Pumpkin Decorations, And Candles
-
Sports22 hours agoSeven wickets in 21 balls: Sri Lanka’s Chamari Athapaththu scripts history with record-breaking spell
-
Tech17 hours agoHow To Edit Claude’s Memory
-
Tech16 hours agobeyerdynamic AVENTHO Y Debuts at IFA 2026 and Makes Wireless Headphones Less Disposable











You must be logged in to post a comment Login