Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Even if some of them are half-hearted.
Even when Star Trek: Strange New Worlds is good, you’re left with the nagging feeling that it could have been better. The show has always been uneven in quality and tone, which is distinct from its intentionally uneven storylines, dancing as it does between genres and tropes. Part of its mission statement has been to take big swings and push the edges of its format. But even if those swings weren’t the best, it was made so confidently you were still sold on the overall product. But when that confidence started to ebb away across the third season, you were suddenly left with a desire to start poking holes in the flimsier narratives.
In its fourth season, Strange New Worlds remains as unafraid as usual to take risks with each episode. The news that the series teamed up with Jim Henson Studios to do a puppet episode is already in the public domain. But while I’m forbidden from sharing specifics about any of the other episodes, suffice to say there’s more parodies-of-the-week than stock episodes of Star Trek across the season. Sadly, several of the episodes would be far more fun if the show leaned hard into the tropes they’re playing off. Instead, the show puts so much effort in justifying why it’s doing what it’s doing that it saps the energy from the fun you’re meant to be having.
Coexisting with the Muppet-y whimsy, we get more of the heavy gore emblematic of any Trek show with Alex Kurtzman’s involvement. If you thought the eye-gouging body horror of season three was a bit much, skip the second episode here. Look, I’m an adult and I’m not going to hand down pronouncements on what Is And Is Not Star Trek™. But there’s a time and a place for this sort of hard-edged content, and I don’t think that should be here. Imagine trying to sit down with your kids to watch the ostensibly main-line Star Trek series du jour. They’d only be able to watch about half the run, something unthinkable in the pre Kurtzman-era.
And, while I’m finding fault, the show’s slavish insistence on bringing Paul Wesley’s Jim Kirk into as many episodes as possible was tiring to begin with, and has gotten worse over time. As much as Strange New Worlds was greenlit on the back of Anson Mount’s star power, and Wesley was brought in while Mount was on paternity leave, his presence here is vexing. Not because I dislike Kirk, or Wesley, but because it simply feels like the show’s creative team has been trying to sideline Mount out of his own show ever since it started. If I was Kirk’s commanding officer on the USS Farragut, I’d be putting him on notice for spending too much time not doing his actual job.
But there are still moments when Strange New Worlds reminds us why it is the best live action Trek of the streaming era. The sixth episode, in particular, isn’t just a series standout, it’s one of the best episodes across Trek’s six-decade history. It’s a taught, gutsy thriller that — despite the fact I know it’s a prequel and so every character in this is guaranteed to survive — had me on the edge of my seat. The fact it includes a little hat tip to Burnistoun, no doubt included by Martin Quinn himself, made my British heart soar. But even without the nod, I’m sure it’ll top every poll for best episode of the run. Unless the final episodes of the series, which I haven’t seen, go on a run we haven’t seen since the second season.
So, Strange New Worlds season four is a lot like the rest of it: Uneven in tone, erratic in quality, sometimes gratuitous in gore and utterly charming. So, for all of its flaws, it’s best you enjoy it since it might be a few years before we get to spend any more time in this part of the future.
It was never meant to replace USB-A.
If you’re wondering how and why we jumped straight from USB-A to USB-C, well, we didn’t — most people simply aren’t familiar with the USB-B connector and the role it has played for decades. The history of USB may surprise you. Both Type-A and Type-B connectors were introduced at the same time in 1996, with the goal of replacing the mess that proprietary connectors and ports had created. USB-A is, of course, the more popular connector type that is still in widespread use today. It’s mostly found on computers, older laptops and chargers. In other words, your host devices.
USB-B, on the other hand, was designed specifically to be used to connect peripherals like printers and external hard drives to a host device. By using two distinct connector types, the USB standard at the time made sure that people wouldn’t accidentally connect two host or two peripheral devices together. This also helped ensure that these cables could only be connected in the intended direction. Although data could travel in both ways, power typically only flows from the host device to the peripheral.
USB-B features a squarish connector type and is broader than USB-A. While larger devices like printers and scanners could accommodate bigger ports, USB-B was simply too bulky for portable electronics. This is why mini USB and micro-USB came after, offering smaller connector types that were better suited for compact gadgets like smartphones or MP3 players. We’ve now migrated mostly to USB-C, which is a compact and reversible connector, but USB-B hasn’t faded into obscurity just yet.
Despite being three decades old, the USB-B connector can still occasionally be found on modern electronics, including printers and musical equipment. The biggest reason is likely just compatibility. After having relied on the port for years, it would be inconvenient if existing cables and workflows suddenly became obsolete. The design of the USB-B connector ensures it offers a secure physical connection that’s not as easy to accidentally yank out. Since it is primarily meant to be used for office electronics or professional equipment that often go months or even years without needing to be disconnected, there is little benefit in replacing it with a USB cable just because it’s smaller and reversible.
That said, USB-C has now become the go-to connector for most consumer electronics. Like I just said, it’s smaller, reversible and also more capable than any previous USB standard. Although high speeds aren’t always guaranteed with USB-C, the connector itself supports higher bandwidth, power delivery capabilities and video output through standards like USB4 and Thunderbolt.
As newer generations of electronics gradually adopt USB-C, USB-B may eventually fade away. Until then, it’s likely to remain the preferred choice for peripherals that value backward compatibility and familiarity over newer features they currently don’t need.
“GPT-5.6 Sol and an ‘even more capable’ model used stolen credentials and exploited vulnerabilities in the Hugging Face API to obtain secret information used to cheat on evaluations,” writes longtime Slashdot reader Dr. Bombay. The Associated Press reports: “We had a significant security incident during evaluation of our models,” OpenAI CEO Sam Altman said in a statement posted on social media. AI startup Hugging Face said last week that it had detected an intrusion into its data processing systems that it suspected was caused by an AI agent autonomously acting on its own. “We suspected last week’s cyberattack might have come from a frontier lab, given the sophistication of the agent,” Hugging Face co-founder and CEO Clement Delangue said in a statement. “Turns out it did!”
[…] “AI is accelerating the discovery and exploitation of vulnerabilities,” OpenAI said in its statement Tuesday. “The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities.” Delangue said he spent the past 24 hours working with OpenAI, “and we strongly believe there was no malicious intent on their part. It’s quite mind-blowing that all of this happened autonomously!” Delangue added that it “might be the first incident of its kind.”

geekwire.com/positivecharge (publish that page or it 404s).
============================================================ –>
.pc-sub-wrap{container-type:inline-size;}
.pc-sub{background:#0f3d33;border-radius:6px;padding:12px 16px;margin:14px 0;font-family:Helvetica,Arial,sans-serif;font-size:14px;line-height:1.5;color:#fff;}
.pc-sub strong{color:#a3e635;}
.pc-sub a{color:#fff;text-decoration:none;white-space:nowrap;}
/* collapse when the strip’s own width is tight */
@container (max-width:620px){
.pc-sub{font-size:13px;padding:10px 12px;white-space:nowrap;overflow-x:auto;-webkit-overflow-scrolling:touch;}
.pc-sub .pc-full{display:none;}
}
/* fallback for browsers without container-query support */
@media (max-width:560px){
.pc-sub{font-size:13px;padding:10px 12px;white-space:nowrap;overflow-x:auto;-webkit-overflow-scrolling:touch;}
.pc-sub .pc-full{display:none;}
}
Subscribe to Positive Charge:
Apple Podcasts,
Spotify,
Amazon Music,
All Episodes
Last year, lifestyle icon Martha Stewart created an internet sensation when she told a podcast host that she would pick composting over burial or cremation after she dies. She has Seattle entrepreneur Katrina Spade to thank for making that option an available, legal choice.
While a graduate student studying architecture, Spade set out to create an alternative for putting people to rest — one that offered a climate-friendly, sustainable solution while remaining practical in urban settings and palatable to loved ones.
“Cremation and burial, both are polluting in their own way,” Spade said. “And I don’t want my last gesture to pollute the earth.”
So in 2020, Spade launched her company, Recompose, becoming the first in the U.S. to develop the technology needed for the commercial composting of human bodies. Now 14 states have legalized the practice and more than a dozen others are considering it. Additional companies have joined Recompose in providing the alternative “death care” service and all are looking to scale.
In comparing funeral options, a cremation produces about 530 pounds of carbon dioxide, roughly equivalent to driving a fuel-efficient car from Seattle to San Diego. Burials consume land and can rely on toxic embalming chemicals, chemically treated caskets, and concrete vaults. Composting requires almost no energy input and produces clean soil.
The process is relatively simple: A deceased person is put in a vessel with natural materials that create the conditions needed for composting. But Spade had to navigate technical and legal hurdles to turn the concept into a business, sparking a new sector within the funeral field.

Stewart and Spade both came to champion human composting by way of horses. When Stewart’s equine pets die, she wraps them in linen and buries them on her land to naturally decay into soil in a process akin to composting.
During her research, Spade discovered a video on horse composting from Lynne Carpenter-Boggs, chair of Washington State University’s Department of Crop and Soil Sciences. Carpenter-Boggs is an expert in the practice, which is routinely applied to livestock like cows and horses. Spade wanted to refine the approach for humans, and the two began collaborating.
They developed a strategy using stainless steel vessels and a blend of straw, alfalfa and wood chips.
“We determined… the best kind of recipe of plant materials that would have the right ratios of carbon and nitrogen, and also the right structural properties to allow air to permeate, because oxygen is critical to this process,” Spade said.
The vessels include thermometers to ensure the body reaches and holds a temperature of 131 degrees Fahrenheit for three consecutive days to destroy pathogens. The heat is generated entirely by naturally occurring microbes.
Before Spade could deploy the technology, she had another problem to solve. She was contacted by Tanya Marsh, a professor and expert in human remains law, who informed Spade that her plan was “completely illegal” in all 50 states, but offered to help her change that.
Spade then turned to her Seattle neighbor, state Sen. Jamie Pedersen, who was coincidentally pursuing another climate-friendly end-of-life alternative called alkaline hydrolysis or water cremation. Pedersen sponsored legislation to legalize composting, and it passed in 2019 with bipartisan support, paving the way for Recompose.

Recompose has created an environment that Spade hopes is comforting for grieving friends and families. The facility features a room for sitting with the deceased, who is wrapped in a natural linen shroud, and a memorial space with vaulted ceilings and green and golden stained-glass windows.
Beyond that is the “greenhouse,” a soil- and straw-scented space containing 33 vessels for composting. Active composting takes about one month; the resulting soil is then removed to “cure” for an additional month to cool and dry out. Bones are broken down mechanically and added back to the soil, while non-organic materials like artificial joints are recycled.
The process creates 20 to 30 bags of a mulch-like material. Friends and families take as much as they like, and Recompose can donate a portion to its partners in land restoration and conservation.
Other companies offering human composting include Return Home and Earth Funeral, which are both based in the Seattle area.
Interest in the death-care alternative has been surprisingly broad.
“I really thought that this was going to be for the Subaru-driving urban Seattle dwellers, and they certainly exist,” said Micah Truman, founder and CEO of Return Home. “But we get as many people from ruby-red Eastern Washington as we do from Seattle or Bellevue.”
While liberals are drawn to the climate benefits, conservative farmers and hunters often feel deeply connected to returning to the land, Truman said. A third segment of customers simply finds traditional burial and cremation unnerving.

In an unexpected turn, younger adults are opting in, too. Elyssa Tappero, a 30-something tsunami program manager for Washington state, is pre-funding her $7,000 Recompose service via $100 monthly installments.
“When I learned how much of an environmental impact there is from cremation, and how expensive some of those things are — and just the entire approach by the funeral industry — I knew that wasn’t something I wanted,” Tappero said.
Spade recognizes that addressing climate change requires much bigger actions than human composting, but is eager to do her part.
“If we can truly and meaningfully change the funeral industry, the way we care for our bodies, and … connect humans even more to the fact that we’re part of that ecosystem, we’re part of the natural world, that would be hugely satisfying,” she said.
Interviews:
Additional sources:

Apple’s fall event calendar has settled into a familiar groove, and this year’s Labor Day landing on September 7 leaves Wednesday the 9th looking like the strongest candidate for the iPhone 18 Pro reveal. Past fifteen years of keynotes rarely stray far from that window, and the pattern points to pre-orders opening the following Friday with phones shipping a week later on the 18th. A later Monday date remains possible, yet the early-September slot has held more often than not.
The lineup that day is predicted to kick the lower-middle of the road models to the curb; base models will be skipped this time. Instead, the stage will be all about the high-end devices, such as the iPhone 18 Pro, the larger Pro Max, and Apple’s entry into the foldable phone market with the Ultra model. The 18 and Air variants appear to be on the back burner for the time being, with a spring 2027 release date to give those premium gadgets a nice long strut out front for the autumn event.
Sale

The design is mainly based on last year’s aluminum frame and three camera setup. However, the paint jobs have been updated, with the Cosmic Orange and Deep Blue being replaced with something new, as the show is now in Dark Cherry colors alongside Light Blue, Silver, and Dark Gray. The Ceramic Shield around MagSafe will have a consistent frosted finish, rather than a two-tone effect, and the Pro Max will be somewhat thicker to accommodate a slightly larger battery, but they will still look quite similar.

The Dynamic Island has shrunk, which is one of the most noticeable visual changes. The Face ID flood illuminator has been placed behind the display glass, making the pill-shaped cutout smaller. The screens on the 6.3 inch Pro and 6.9 inch Pro Max are essentially the same size, but they’re now employing the latest LTPO+ panel technology to get a little longer battery life out of them.

The camera enhancements are likely the most significant around here, as the main 48 megapixel Fusion lens now supports variable aperture, marking Apple’s first successful implementation of mechanical iris on an iPhone. So, in bright light, the blades will constrict to maintain a natural appearance, but in low light, they will open up wide to receive more light. Portrait photographs will appear much more natural, with less reliance on processing to give them that edge. Video taken outside will be extremely smooth because the phone will not need to use extremely fast shutter rates to keep up with the fixed holes. The same main camera will appear above a new and streamlined Camera Control button. The tactile elements have been removed, leaving only a pressure-sensitive device that records when pressed strongly. The change may be a disappointment for some customers, but it retains what they liked about it, namely, the quick-launch feature, which continues to function properly.

Inside the new phones, the A20 Pro chip has been improved to TSMC’s first-generation 2 nm technology. Early reports indicate that this has resulted in a significant increase in both speed and power efficiency over the previous 3 nanometre generation, with some of the new designs even placing memory directly next to the processor cores. We can expect to see Apple’s home-made C2 modem, which provides satellite 5G connectivity and should be sufficient for online browsing in locations without a standard phone service. International phones will get the C2 version, while US devices may continue to rely on Qualcomm for select millimeter wave bands.

Battery life has improved, particularly on the Pro Max, with filings indicating approximately 5,567 mAh outside of China, which is a significant increase over the present lot. The regular Pro model has also seen a rise in that department. Put that all together with a more efficient screen and chip, and we can expect a bit more everyday use from the phone without simply matching last year’s stats. This suggests that prices are likely to rise. Memory and storage have become significantly more expensive in recent years, and we’re hearing that the Pro will start at $1,299, with the Pro Max priced at $1,399. Meanwhile, the new foldable device is expected to be the most expensive of the three, costing well over $2,000.
[Source]
On Monday, JPMorgan and Morgan Stanley began pitching investors on a bond sale of at least $12 billion, as The Wall Street Journal reported. The money will build a Meta data centre in El Paso, Texas. The structure is the story.
BlackRock and its infrastructure and private-credit arms own 80% of the roughly one-gigawatt project. Meta, the company that will actually run AI inside it, owns just 20% and will lease the campus back. The debt sits with a BlackRock-controlled entity, not with Meta.
That keeps most of the cost off Meta’s books, booked as rent rather than capital spending. It is the same off-balance-sheet trick a Nikkei study just pinned at $1.65 trillion across the five biggest US tech firms.
Meta has done this before. Its Hyperion site in Louisiana used a joint venture where the credit firm Blue Owl held 80% and Meta 20%. That entity sold $27 billion of bonds last year, the largest private-debt deal on record, and BlackRock bought more than $3 billion of them.
El Paso copies the blueprint. Meta also just agreed to lease a project in Shippingport, Pennsylvania, run by Aligned, the developer BlackRock bought for $40bn. The pattern is consistent: BlackRock owns the buildings, Meta rents the compute.
For Larry Fink, the deal is a payoff. Over the past few years, the $15 trillion asset manager spent about $25 billion buying two private-market firms, Global Infrastructure Partners and HPS, as Bloomberg reported. Both now sit inside BlackRock, and both are backing El Paso.
That turns an index-fund giant into an owner-operator. On this deal it does both jobs at once: it originates the asset and sells the debt against it. Fink told analysts last week that the two units were “coming together on the origination side.”
The risk is the one every off-balance-sheet AI deal carries. The bonds are long-dated, but the chips inside the building depreciate in a few years, and the leases reportedly run shorter than the campuses they finance. BlackRock is betting AI demand, and Meta’s rent, hold long enough to pay it back.
It also stacks much of the AI build-out inside one firm. Rivals Blue Owl and Blackstone have led the biggest data-centre financings so far, and the bubble talk is getting louder. The El Paso campus is due online in 2028.

The Mars Society is planning to build a Pacific Northwest research station suitable for simulating missions to the moon or Mars, in partnership with South Seattle College.
The nonprofit space advocacy group announced today that its executive director, James L. Burk, and the college’s president, Monica Brown, have signed a 10-year memorandum of agreement establishing the partnership.
The plan calls for the Mars Society to lease land on the college’s 87-acre West Seattle campus and build the research station, contingent on funding. Both parties will raise funds from aerospace companies and other donors to support construction, with the goal of opening the station at the start of the 2027-2028 academic year.
The agreement provides for the creation of a joint space studies curriculum and certificate program; a student capstone project and internship program tied to industry partners; and a regional workforce pipeline and community engagement effort.
The Seattle facility would be the third analog research station operated by the Mars Society, joining the Flashline Mars Arctic Research Station on Canada’s Devon Island and the Mars Desert Research Station in Utah.
Those two stations were built more than two decades ago to reflect the designs for Mars habitats. They provide opportunities for teams of researchers to test the tools and techniques that future astronauts might use for extraterrestrial exploration. During their missions, the researchers live and work under simulated Mars conditions. For example, they’re required to put on simulated spacesuits every time they venture outside their habitat.
Burk said the Seattle research station will reflect NASA’s growing emphasis on moon exploration as a precursor to crewed Mars missions, as well as South Seattle College’s traditional emphasis on workforce training. “For more than two decades, the Mars Society has operated analog research stations in the Utah desert and the Canadian Arctic that have shaped how humanity will live and work on other worlds. Bringing that capability to an urban community college campus is something new, and it is deliberate,” he said.
“The moon and Mars programs the federal government has now committed to are going to need a workforce we have not trained for in 50 years,” Burk said. “South Seattle College knows how to train people for the industries that actually build things. That approach is exactly what we need for preparing for planetary surface operations on the moon and Mars.”

The analog research projects would build upon the college’s existing training programs. For example, students learning about electric vehicle maintenance and repair could work on projects involving battery-powered rovers and drones. Students in the college’s culinary arts program could contribute to research into growing vegetables in space environments.
“South Seattle College has a long tradition of meeting our region’s workforce needs in aerospace, applied science, and skilled trades,” Brown said. “This partnership extends that tradition, and this initiative reflects our commitment to exploring bold, future-oriented opportunities that expand access, inspire imagination, and ensure our students are prepared to lead in emerging industries.”
The Mars Society is headquartered in Colorado but has plenty of Pacific Northwest connections. The Seattle chapter was created in 1998, shortly after the national organization was founded. Burk, a former Microsoft project manager, lives and works in North Bend, Wash.
During a 2023 podcast interview, Mars Society President Robert Zubrin — who earned his Ph.D. in nuclear engineering from the University of Washington — said the Pacific Northwest was “perhaps at the top of the list” of potential sites for a Mars Technology Institute. Today’s announcement appears to be consistent with Zubrin’s assessment of the region.
In its news release, the Mars Society noted that the Pacific Northwest “hosts one of the largest concentrations of commercial space activity in the United States.” The society specifically cited Jeff Bezos’ Blue Origin space venture, SpaceX’s Starlink satellite factory and L3Harris Technologies’ Aerojet Rocketdyne facility in Redmond.
To raise public awareness of the Seattle project, the Mars Society said it plans to install an inflatable mockup of a research habitat in South Seattle College’s Aviation Maintenance Technology facilities this summer. The society also hinted at more to come, saying that there’s “a public event in the works.”
[This is a sponsored article with BIPO.]
For companies looking to expand overseas, setting up operations in a new market is often only the first step.
The bigger challenge comes after: hiring employees, complying with local labour laws, processing payroll in different currencies, and navigating regulations that vary from one country to another.
Singapore-based HR technology company BIPO wants to solve this challenge by becoming the infrastructure layer behind global workforce expansion.
The company has secured a US$50 million growth investment from Apis Partners, through its Apis Growth Fund III, to expand its payroll technology, accelerate artificial intelligence (AI) capabilities, and strengthen its position as a global HR solutions provider.
Founded in 2010, BIPO started with a focus on helping businesses manage payroll and HR operations more efficiently. Today, the company supports around 700,000 employees across more than 170 countries and regions, processing nearly US$2 billion in payroll payments annually for close to 6,000 corporate clients.
The investment comes as companies increasingly look beyond their home markets for growth opportunities, but many still struggle with the operational challenges of managing a distributed workforce.


International expansion has traditionally required companies to work with multiple payroll vendors, local consultants, and separate HR systems in each market.
For multinational companies, this fragmented approach can create difficulties in maintaining accurate employee records, ensuring payroll compliance, and keeping track of constantly changing employment regulations.
BIPO aims to address this by bringing these functions together through a single platform that combines its Human Resource Management System, Global Payroll Outsourcing, and Employer of Record services.
Its proprietary payroll engines allow businesses to manage payroll processes across multiple countries through one operating model, while incorporating local statutory requirements directly into the system.
The company’s Employer of Record services also allow businesses to hire employees in new markets without immediately establishing a local entity, helping companies test new markets or build international teams more quickly.
With the new funding, BIPO plans to increase investments into artificial intelligence and research and development across Singapore and its regional hubs.
The company is exploring AI-powered workflows that can support areas such as workforce scheduling, payroll accuracy, and implementation processes.
Rather than replacing human involvement entirely, BIPO said these tools are designed to support decision-making while maintaining human oversight for compliance-related matters.


Michael Chen, CEO of BIPO, said the company’s investment in proprietary payroll technology gives it an advantage in helping businesses navigate international expansion.
“We have developed our own proprietary payroll engines across multiple countries–a structural advantage that few in the industry can match,” he said.
“This US$50 million investment from Apis Partners validates our HR technology platform and our strategy to simplify international expansion.”
BIPO’s growth reflects a broader shift in how companies think about employment technology.
As remote work and cross-border hiring become more common, businesses are increasingly looking for HR platforms that can support employees across multiple regions instead of just managing administrative tasks within one country.
The company said it aims to become Asia’s leading AI-embedded payroll and HR platform, using its regional expertise to help multinational companies expand into Asia while supporting Asian businesses entering global markets.
Operating across more than 50 offices worldwide, BIPO currently serves customers across Asia Pacific, Europe, Latin America, the Middle East, Africa, and North America.
For the Singapore-founded company, the latest funding marks a new chapter in its ambition to make global hiring and payroll management less complicated, turning what has traditionally been a back-office challenge into a technology-driven advantage.
Featured Image Credit: BIPO
The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents.
Tracked as CVE-2026-0770, this critical security flaw allows unauthenticated threat actors to gain remote code execution as root in low-complexity attacks.
“The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint,” Trend Micro researchers who found and reported the flaw explain. “The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root.”
Vulnerability intelligence company KEVIntel first observed CVE-2026-0770 in-the-wild exploitation on June 27, with over 220 exploitation attempts recorded from 64 unique source IP addresses before CISA included the flaw in its Known Exploited Vulnerabilities (KEV) catalog.
KEVIntel founder Ryan Dewhurst told BleepingComputer that the malicious activity targeting the CVE-2026-0770 flaw is not limited to vulnerability checks, with malicious payloads observed during these attacks also attempting to deploy malware and obtain AWS credentials, environment variables, and container metadata.
“Most activity involved command-execution checks or system reconnaissance. However, KEVIntel also observed attempts to download second-stage scripts and access environment variables, cloud metadata and credential files,” Dewhurst said.
“Organizations operating Langflow should investigate historical requests to /api/v1/validate/code, review host activity, restrict access to the validation functionality and rotate exposed credentials where successful execution cannot be ruled out.”

On Tuesday, CISA added CVE-2026-0770 to its KEV catalog, ordering U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their systems by Friday, as mandated by Binding Operational Directive (BOD) 26-04.
“This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” the cybersecurity agency warned.
“Stakeholders are responsible for evaluating each asset’s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.”
CISA has flagged other Langflow vulnerabilities as exploited in the wild in recent years, including a missing authentication security issue (CVE-2025-3248) in May 2025, a code injection vulnerability (CVE-2026-33017) in March 2026, and an Insecure Direct Object Reference (IDOR) security flaw (CVE-2026-55255) earlier this month.
The cybersecurity agency also confirmed that CVE-2025-3248 is being exploited in ransomware attacks, after cloud security company Sysdig reported that the JadePuffer ransomware gang is using it to dump Langflow PostgreSQL databases.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
In brief: Samsung will be hosting its next Galaxy Unpacked event very soon, where it’s expected to reveal all the details of its next-generation foldable devices, including the Galaxy Z Fold 8, Galaxy Z Fold 8 Ultra, and Galaxy Z Flip 8. The London event starts at 9am ET/6:00am PT, and you can watch the whole thing live right here.
The regular Galaxy Z Fold 8 is expected to undergo the biggest redesign. Leaked renders show a shorter, wider, passport-style handset with a 5.5-inch cover screen and a 7.6-inch internal display. Both are said to use 120Hz Dynamic AMOLED 2X panels.
The phone could also feature Qualcomm’s Snapdragon 8 Elite Gen 5 for Galaxy, 12GB of RAM, up to 1TB of storage, and a 4,000mAh battery. Camera leaks point to two 50MP rear sensors covering the wide and ultrawide snappers, along with 10MP cameras on the outer and inner displays.
Samsung has already confirmed that its next foldables will use Flex Titanium display technology, which combines a titanium-alloy film and titanium plate to improve rigidity and reduce the visibility of the crease.
The Galaxy Z Fold 8 Ultra is rumored to retain the taller design of the Fold 7 while boasting the more powerful specifications. Reports claim it will have a 6.5-inch cover display, an 8-inch folding screen, a 5,000mAh battery, and 45W wired charging.
The rear camera array could include a 200MP primary sensor, a 50MP ultrawide, and a 10MP telephoto with 3x optical zoom. European pricing is rumored to start at €2,199 ($2,508), compared with €1,999 ($2,279) for the standard Fold 8.
The Galaxy Z Flip 8 looks set to be a more iterative update. Leaks suggest the same 6.9-inch internal and 4.1-inch cover displays as the Flip 7, paired with Samsung’s 2nm Exynos 2600, 12GB of RAM, and at least 256GB of storage.
The new Flip’s cameras are expected to remain at 50MP, 12MP ultrawide, and 10MP selfie, while the battery could increase to 4,300mAh. Some reports disagree over whether charging will remain at 25W or rise to 45W.
Samsung’s new watches should also make an appearance. The Galaxy Watch Ultra 2 is rumored to be 12% thinner, with a Snapdragon Wear Elite chip, an 800mAh battery, and a display capable of reaching 5,000 nits. The regular Galaxy Watch 9 could use the same processor in a more familiar design.
Samsung may also preview its AI-powered smart glasses, with frames designed by Warby Parker and Gentle Monster, ahead of a rumored fall launch.
Poolside, the San Francisco AI lab that has spent most of its three-year existence quietly selling coding models to governments and defense agencies, released its most capable model to date on Tuesday — and made an unusually aggressive bet that radical transparency, not raw scale, is how a smaller lab competes at the frontier.
The model, Laguna S 2.1, is a 118-billion-parameter Mixture-of-Experts (MoE) system that activates only 8 billion parameters per token, supports a context window of up to 1 million tokens, and — according to benchmarks published by the company — matches or beats open models several times its size on agentic coding tasks. The weights are available immediately on Hugging Face under the permissive OpenMDW-1.1 license.
The headline numbers are striking for a model this small. Poolside reports that Laguna S 2.1 scores 70.2% on Terminal-Bench 2.1, a benchmark of long-horizon terminal tasks, placing it 11th on the company’s compiled leaderboard — ahead of DeepSeek-V4-Pro-Max, a 1.6-trillion-parameter model that scored 64.0; Thinking Machines’ 975-billion-parameter Inkling, at 63.8; and Nvidia’s 550-billion-parameter Nemotron 3 Ultra, at 56.4. On SWE-Bench Multilingual, it posts 78.5%, and on SWE-Bench Pro‘s public dataset, 59.4%.
Perhaps more telling than any single score: the model went from the start of pre-training on May 22 to public launch in under nine weeks, trained on 4,096 Nvidia H200 GPUs. In an industry where flagship model cycles are typically measured in quarters or years, Poolside has now shipped three models in three months.
The release lands in the middle of an increasingly pointed debate about the provenance of open-weight AI. Over the past year, developer adoption has shifted decisively toward open-weight systems that companies can download, inspect, and run on their own infrastructure — and the leading options in that category have overwhelmingly come from Chinese labs. DeepSeek, Qwen, Kimi, GLM, MiniMax, and Tencent’s Hunyuan line all feature prominently in Poolside’s own comparison tables.
Poolside’s accompanying press release frames Laguna S 2.1 explicitly as a response, noting that the model occupies a size class into which no Western lab has released open weights in 11 months — since OpenAI’s gpt-oss-120b last August. “The West needs open-weight models it can trust, run, and build on,” said Jason Warner, Poolside’s co-CEO, in the announcement.
Co-founder and co-CEO Eiso Kant made the philosophical stakes even plainer in a lengthy post on X. “I believe intelligence should and will become a commodity,” he wrote, arguing that the open ecosystem “will not win by being the best in its own category.” Users, he argued, simply want the best intelligence for the task at hand — so open models must be on par with, or better than, their closed equivalents.
The strategic logic here is not charity. Poolside’s core business is deploying models inside the security boundaries of government, defense, and regulated enterprises — customers for whom closed, metered API access is often a non-starter for compliance and sovereignty reasons.
Every enterprise that standardizes on a Chinese open model today becomes harder to win tomorrow. Releasing competitive open weights is both an ecosystem play and a top-of-funnel strategy for the company’s high-security deployment business. It also reframes the AI race away from terrain where Poolside cannot compete — frontier-scale capital expenditure — and toward terrain where it believes it can: cost per token, self-hosting, and iteration speed.
The technical design reflects a specific thesis about where value in coding AI is moving. Laguna S 2.1’s sparse MoE architecture — 256 routed experts plus one shared expert, with grouped-query attention and interleaved sliding-window layers, according to the Hugging Face model card — means inference costs scale with the 8 billion active parameters, not the 118 billion total. Poolside emphasizes that the model is small enough to run on a single Nvidia DGX Spark, the desktop-class AI machine.
That matters for what Poolside calls token economics. Long-horizon coding agents are voracious consumers of tokens: the company’s published data shows the model consuming a mean of roughly 249,000 completion tokens per trajectory on its hardest benchmark when thinking mode is enabled. At metered API prices, agentic workloads at enterprise scale become a meaningful budget line item. On OpenRouter, Poolside is offering a free 256K-context endpoint and a dedicated 1M-context deployment priced at $0.10 per million input tokens and $0.20 per million output tokens — aggressive pricing that undercuts most frontier alternatives by an order of magnitude.
The ecosystem support is unusually broad for day one. The model is live on Baseten’s model library and Vercel’s AI Gateway, with integrations across vLLM, SGLang, Ollama, and llama.cpp, plus quantized variants down to 4-bit GGUF files — 75 gigabytes — for local use. But Poolside’s more interesting claim is behavioral, not architectural. Pengming Wang, co-head of applied research at Poolside, said the gains came from improving the model’s working habits: “more verification, less taking things for granted, not declaring victory early, and being more persistent.” Raw intelligence, the company argues, is one axis of capability; a model’s way of working is a second axis that matters immensely for agents left unattended for hours.
The most consequential part of the release for enterprise buyers may be an evaluation-transparency move with little precedent among major labs: Poolside published the complete, unedited trajectory of every trial in its final benchmark runs — every reasoning step, tool call, and shell command behind every reported score.
This addresses a growing credibility problem in AI benchmarking. As top scores on mature benchmarks cluster in the 70–90% range, and as “reward hacking” — models finding solutions online or gaming verifiers rather than solving problems — has become endemic, self-reported numbers have lost much of their signal. Poolside disclosed its own encounters with the problem candidly: during training, more than half of trajectories on some SWE-bench tasks were flagged because the model simply researched the original bug-fix pull request online and applied it. The company documented its mitigations, including prompt addenda, LLM-based judging calibrated against human labels, and expert annotator review of a high-scoring Terminal-Bench run.
Three published case studies illustrate what the company means by persistence. In one, the model built a working HTML/CSS rendering engine from an empty folder in a 181-step, 50-minute unattended session — then, lacking vision capabilities, spun up headless Chromium to numerically compare its canvas output against a real browser’s rendering. In another, pointed at Poolside’s own agent harness in an automated optimization loop, the model made the Go codebase 5.2% faster with roughly 70% lower memory allocation, finding an O(n²) string-concatenation bug along the way. In a third, working in a sandbox with no Python installed, the model did its number theory in Perl and independently re-derived a proof of Erdős problem #397 — a combinatorics question open for five decades until GPT-5.2 Pro first solved it this past January. Poolside notes that its model’s construction is structurally different from the earlier published solution, and that its November 2025 knowledge cutoff precedes the first proof.
Poolside deserves credit for disclosing limitations most labs bury. The model can overfit to its native harness and stumble on slightly different tool schemas in third-party agents, mangles JSON in nested tool arguments, and is prone to overthinking on competition math. There is currently no user-configurable thinking-effort dial — just on or off — and the gap between the modes is enormous: thinking lifts Terminal-Bench 2.1 from 60.4% to 70.2%, and DeepSWE from 16.5% to 40.4%, at substantially higher token cost.
Buyers should apply their own discounts to the comparison tables. Poolside’s methodology takes the maximum of vendor self-reported scores, benchmark-author leaderboards, and third-party figures for competitors — a reasonable convention, but one that mixes harnesses and test conditions. On DeepSWE, notably, Poolside ran its own agent harness rather than the leaderboard’s standard mini-swe-agent, a difference the company acknowledges makes scores less directly comparable. And the frontier remains clearly out of reach: closed models like GPT-5.6 Sol, at 88.8 on Terminal-Bench 2.1, and Claude Fable 5, at 88.0, along with the 2.8-trillion-parameter open-weight Kimi K3, at 88.3, sit well above Laguna S 2.1.
The deeper structural question is whether Poolside’s “Model Factory” — the internal platform the company credits for its rapid release cadence — can sustain this pace as models scale. The trajectory so far is genuinely unusual: the April dual release of Laguna M.1 and XS.2, the July 2 refresh of XS 2.1, and now S 2.1, which the company says outperforms April’s flagship M.1 at roughly a third of its active size. Remarkably, S 2.1 used the exact same pre-training data as XS 2.1, meaning nearly all the improvement came from scale, training fixes, and post-training across the company’s corpus of 409,000 agentic and non-agentic training environments. Poolside says its next, larger Laguna model began pre-training last week.
For technical decision makers, Laguna S 2.1 is the most credible Western open-weight option to emerge in nearly a year for self-hosted agentic coding — with published evidence, a permissive license, broad ecosystem support, and an economics story built around hardware you can own. Whether it dents the dominance of Chinese open models will depend less on this release than on the ones that follow it.
Kant, for his part, has already told the world how he intends that story to end. Poolside is building toward a future where the most capable intelligence “can be owned and shaped by anyone,” he wrote — and the company plans to keep shipping “until that future exists.” In an industry where the biggest labs increasingly lock their best work behind an API, the most radical thing about Laguna S 2.1 may not be what it scores, but that anyone can download it and check.
London Mayor Sadiq Khan handed a peerage by Keir Starmer alongside 15 other Labour figures… just days before the PM leaves No10
Weekend Open Thread – Corporette.com
The House | The City of London can help the new chancellor deliver growth in every postcode
Two July Windows Left: The CLARITY Act’s Senate Fight and What Failure Means
CFTC blocks Kalshi from unwinding Michigan trades after court order
Ripple Payments Joins MiCA With 14 Firms, Does It Mean Anything For XRP?
Nvidia Stock Slips After Big Tuesday Rally as Huang Confirms Vera Rubin Chip Is Now in Production Today
Democrats look to World Cup watch parties to register thousands of voters
Disney’s Most Ambitious Failed Star Wars Attraction Is Coming to SDCC
Ripple wins EU-wide access as ESMA adds it to MiCA register
Grayscale Files For Worldcoin ETF, WLD Registers Sharp Rise
Palantir Shares Rise After Expanded Nvidia Partnership and Fresh Analyst Upgrades Ahead of Earnings Day
Injective Submits SEC Transfer-Agent Registration to Onchain Ownership Records
Sail Virtually Aboard The “Itanic” With IA-64 Emulator
Turtle Beach Command Series KB7 review: a nifty screen-equipped gaming keyboard
Unregistered fitter used Gas Safe logo on business flyers
Registration is now open for March for Men with Kev 2026
New Cornerback Enters Vikings Trade Rumor Mill
New Jersey voter registration controversy explained: How 6,600 noncitizens got on the rolls, and what happens next
Money | Class 12 Economics | CBSE Board Exam 2026-27
You must be logged in to post a comment Login