Tech
Styrofoam Turned Gasoline Can Be Used to Run a Generator

Most people toss old packaging foam in the trash without a second look. Joel from the Lowered Expectations channel decided to turn a pile of it into something that powers a small engine instead. His recent experiment starts with ordinary closed-cell extruded polystyrene, the same light material used for shipping and insulation, and ends with a liquid that lights off in a generator and produces real electricity.
Joel began with a respectable 356 grams of foam, or approximately 12 1/2 ounces, which he dissolved in some gasoline rescued from a previous distillation of used fuel. The foam was extremely thirsty, and it simply crumbled into a thick gloopy sludge after absorbing the liquid. Around 240 cc of gasoline became caught inside the mixture. That sludge was then poured directly into a boiling flask, which was outfitted with a rudimentary glassware setup and a fractional column to keep things from getting out of hand.
Sale
GTPLAYER Gaming Chair, Computer Chair with Footrest and Lumbar Support, Height Adjustable Game Chair with…
- Most Comfortable And Relaxing: Equipped with headrest and lumbar pillow. When your neck feels sore from gaming or working with head down for a long…
- More Stable Than Others: Common gaming chairs are equipped with plastic legs generally to save costs, but we still insist on applying the same…
- Liberate Your Feet: Will you feel tired for sitting all the time? Sure. Then you can choose the chair with footrest to relax your feet. When you…

A mantle with a thermostat provided heating to keep things from becoming too wild. Early fractions began to emerge about 60 degrees Celsius, with more liquid appearing as the temperature rose over 100 degrees. The majority of the good material began to collect around 120 degrees, and the process continued to 220 degrees. He performed a second, simpler distillation of the collected liquid to clean it up a little more, stopping at 150 degrees. Before calling it a day, he added some fuel stabilizer to the finished product. There were some concerns about styrene monomers recombining, so he had to exercise caution, as he had proposed using inhibitors in the larger approach discussion.

He was able to blend 300 milliliters of the completed distillate with a modest amount of automatic transmission fluid before stuffing it into a generator. Starting with a cold engine, the machine fired up immediately on the first pull, with the choke still on. Once warm, it began on its own and ran well under load for 18 minutes, producing 0.42 KWH. A matched test with regular fuel yielded 0.41 KWH in the same time frame. The power output was nearly identical across the brief run.

In terms of energy, the entire pyrolysis and distillation process consumed 2.06 KWH over 13 hours and 27 minutes, equating to around 37 cents of electricity. That’s a rough calculation, but it works out to roughly 3.17 KWH per liter of product. The published energy density for similar polystyrene pyrolysis liquids is usually between 10.5 and 11.5 KWH per liter, so even with my clunky setup, the values look fairly decent.

Then, after the test, he looked inside the engine, and the situation grew much less promising. A borescope revealed a shiny, gloopy deposit all over the piston, rather than the typical carbon buildup. Instead of the typical pure pump gasoline, the foam created a complex mixture of hydrocarbon chains and leftover styrene pieces. Make no mistake: the longer you run it, or the tighter / more delicate the tolerances and injectors are, the more probable you are to have residue problems.

Joel is extremely open about the risks involved. Styrene is a known health hazard, the fumes are not pleasant to be around, auto-polymerisation may be rather frightening if the inhibitors aren’t ideal, and the overall situation is far beyond what most people would consider safe household chemistry. He emphasizes that no one should replicate his efforts, since this is only a display of chemistry curiosity, not a plan for running a backyard fuel business.
[Source]
Tech
Google Antigravity just built an AI translator that works without the internet
Google has shown off a new AI project that could make language barriers a little less intimidating, and it doesn’t need an internet connection to do it. The company has introduced the Gemma Translator, a compact prototype built in collaboration with Antigravity. Unlike most AI translation tools that rely on cloud processing, this device runs entirely offline using Gemma 4 E2B, Google’s lightweight open model. Everything happens locally on the device, making it both portable and independent of an internet connection. The prototype is powered by a Raspberry Pi 5 and includes a microphone and speaker inside a custom 3D-printed enclosure, creating a self-contained translator you can carry almost anywhere.
AI translation, without the cloud
The demonstration shows just how far AI models have come. Instead of depending on remote servers, the Gemma Translator processes speech directly on the Raspberry Pi, translating conversations on-device.
That approach offers a few obvious advantages. Travelers could use it in places with unreliable connectivity, while businesses or organizations handling sensitive conversations wouldn’t have to send voice data to the cloud. Running everything locally could also reduce latency, making conversations feel more natural. Although Google hasn’t positioned the project as a commercial product, it highlights what’s now possible with efficient AI models that can operate on affordable hardware.
A glimpse of what’s coming next
The Gemma Translator is more of a technology showcase than a product announcement. Still, it points toward a future where AI assistants don’t always need powerful data centers to be useful.

As open models continue to shrink while becoming more capable, devices like this could eventually find their way into travel gadgets, accessibility tools, classrooms, or even emergency response kits where internet access isn’t guaranteed. For now, Google’s latest prototype serves as a reminder that some of AI’s most interesting innovations are being squeezed into tiny devices that can work almost anywhere.
Tech
Anthropic’s New AI Model Can Identify More Software Bugs Than Ever. Microsoft Is Struggling To Fix Them Fast Enough.
from the keeping-up-with-the-ai dept
This story was originally published by ProPublica. Republished under a CC BY-NC-ND 3.0 license.
On an afternoon in mid-May, dozens of Microsoft engineers and their managers gathered online and in a conference room at the company’s Redmond, Washington, headquarters to discuss Project Glasswing.
The tech giant was racing to fix weaknesses in its code that a new AI model known as Mythos was uncovering at an unprecedented clip. The AI behemoth Anthropic, which developed Mythos, had given access to select organizations that make software used by regular people, companies and governments across the world. The goal was to find and fix the vulnerabilities before hackers and adversarial governments like China began using similar tools to find and exploit them for espionage and sabotage.
As the group settled in, one engineer asked the question that loomed over the meeting: Did Mythos “live up to the hype that Anthropic claimed it would have had?”
“Yes,” a manager responded, according to a recording of the meeting viewed by ProPublica.
The version being used by Microsoft, Claude Mythos Preview, was surfacing bugs faster than the tech giant could patch them, and engineers, the manager said, were now in “a mad dash” to close the gap.
One slide in that day’s presentation showed that in April alone, Mythos had uncovered 90 “critical” bugs and 141 “important” ones in SharePoint, Microsoft’s widely used collaboration software. In the first half of May it found even more.
“Please, please, please if your org has any April bugs, drive those down,” engineering manager Hans Andersen implored the group. They had roughly two weeks “to find as many things and do as much good as we can with this access.”
May 31, he explained, “is considered the day when the rest of the world will have caught up.”
The engineers on the call poked at that assertion, with one of them summing up the predicament: “So basically you’re saying if it’s released on June 1, then on June 2 the adversaries will have our bugs?”
Yep, one person responded. Yep, another echoed.
Ever since Anthropic kick-started a national conversation about the bug-hunting power of AI in April, when Project Glasswing was made public, national security experts predicted that the U.S. would have a window of opportunity to fix flaws before adversaries would have similar models capable of discovering the same weaknesses. In late June, the international alliance of intelligence agencies known as the Five Eyes — whose members are the U.S., Australia, Canada, New Zealand and the U.K. — warned in an unusual joint statement that in a matter of months, that window would be closing. But the recording of the Microsoft meeting, along with internal documents reviewed by ProPublica, suggest the day of cyber reckoning may already be here.
Given the deluge of flaws Mythos has identified, Microsoft so far has focused on patching those it considers most dangerous, which are classified critical or important, according to the presentation as well as the company’s own public patch updates. The internal records indicate that Microsoft plans to eventually address “moderate”-severity flaws uncovered by Mythos. The documents made no mention of “low”-severity bugs.
The company’s approach reflects the triage system that is typical in the industry. Just as the sickest patients are the first to be treated in the emergency room, vulnerability triage prioritizes issues that are likely to cause the most damage if exploited by hackers.
But that strategy carries its own risk in this AI-powered bug-finding era, in which new tools are unearthing a record-breaking volume of weaknesses in the products we use every day. Mythos, for example, is able to chain together a string of bugs that build on one another, meaning that the low- and moderate-severity vulnerabilities that remain unpatched could create an opening to carry out devastating attacks.
“The problem now is that you can chain four low-level flaws, and that can equal a high severity,” said Vinh Nguyen, a senior technical adviser to Anthropic and a senior fellow for AI at the Council on Foreign Relations who formerly served as chief AI officer and chief data scientist at the National Security Agency. “If you’re Microsoft, the current triage strategy may be underpricing risks.”
In emailed responses to ProPublica’s questions, Microsoft stood by its approach, saying its triaging decisions are based on a number of factors, including exploitability and the impact on customers. The company presentation did not mention chaining, but a spokesperson told ProPublica that the technique “has long been considered as part of vulnerability assessment and risk analysis.”
Asked about the internal presentation and the then-looming May 31 deadline, the spokesperson downplayed its significance, saying that “accelerated targeting and exploitation of new vulnerabilities is not a new phenomenon.” That said, he added, the comments made during the meeting reflect how the company “feels a sense of urgency to help our customers at this time.”
“What was heard on that call and is true today is that security is Microsoft’s most important priority and teams across the company are prioritizing using AI to discover and remediate vulnerabilities as quickly as possible.”
Microsoft declined to answer questions about how many bugs engineers had patched since the presentation.
Anthropic declined to comment.
The internal Microsoft presentation and accompanying slides predicted that the group of staffers working on SharePoint, which is used by governments and businesses worldwide to manage data and documents, “will be busy for months,” first working through the highest-priority critical bugs then tackling the important ones in August. Microsoft says vulnerabilities it categorizes as critical include so-called worms that can crash systems and spread malware as they race across computer networks. Important ones could result in “compromise of the confidentiality, integrity, or availability of user data” as well as the “availability of processing resources.” After those categories were cleared, the group would begin work on roughly 300 “moderate” bugs, according to the presentation.
While the internal documents reviewed by ProPublica do not include updates on the entire breadth of Microsoft’s offerings, they do give a sense of the scale of the problem. One document noted that, since the company started using Mythos earlier this year, it had collectively found hundreds of bugs that Microsoft categorized as either critical or important in popular products such as Microsoft 365, the Teams conferencing platform and the Copilot AI tool. As of mid-May, most of them had yet to be patched.
“They’re not profound and exotic, but they’re real,” Andersen, the engineering manager, said during the meeting. “And a lot of them are exploitable.”
It’s unclear whether hackers have exploited any specific bug identified by Mythos, but some have tapped AI to automate attacks and appear to be using Mythos-like tech to find and exploit weaknesses.
There have been outward signs of Microsoft’s internal struggle to deal with the growing list of bugs to be patched. Each month, the company publicly releases fixes for its software vulnerabilities in what’s known as “Patch Tuesday.” In June, it released patches for more than 200 bugs, which industry experts then said was an all-time high. But on July 14, the company blew through that record and released patches for more than 600 bugs. Only seven were categorized as low- or moderate-severity, one of which hackers were actively exploiting, according to Dustin Childs, leader of the Zero Day Initiative bug bounty program, which is part of cybersecurity company TrendAI. The rest were important or critical.
“Well folks. Here we are. The bug apocalypse has fully descended upon us,” Childs wrote in a blog post on July 14.
Microsoft told ProPublica that the overall volume of bugs “will not be plateauing for a bit,” but a spokesperson said the company has “invested heavily in both people as well as AI-powered triage solutions that scale quickly to handle the growing number of vulnerabilities.”
Given the new realities of the AI age, including the chaining capabilities, companies like Microsoft might need to rethink their entire approach to triage, said Nguyen, the NSA’s former AI chief. Rather than shunting what are now considered low-risk flaws aside, companies should be dedicating staff to developing and testing patches for the entire spectrum of vulnerabilities, he said. In other words, the cyber ER needs more doctors and nurses treating illnesses that are life-threatening as well as the minor wounds that could later turn deadly.
“There’s no alternative,” Nguyen said. “The patients are coming in fast and furious.”
Microsoft told ProPublica it’s “always going to be reevaluating and considering whether things that were previously lows or moderates be upgraded or thought about differently. With these AI systems, it makes us rethink some of these things. Across the industry, we’re all looking to see how drastic of a change it will be.”
Microsoft’s users may be particularly vulnerable. The popularity of its offerings, used the world over, makes it a frequent and lucrative target for hackers. In addition, many of its products contain “legacy” code. Developed decades ago using now-outdated technology, this code contains unaddressed flaws and contributes to what is known in the industry as “technical debt.”
But the challenge of fixing the flood of newly found bugs also extends to the rest of the software industry, and to open-source software code that is typically free to use and largely maintained by volunteers. Open-source software underpins internet infrastructure and is incorporated into much of the world’s modern technology, including products offered by major tech companies such as Microsoft.
“Nobody has really figured out how to deal with this, and everybody is casting around for what they need to do,” said J. Michael Daniel, a former cybersecurity adviser to President Barack Obama and the president of the Cyber Threat Alliance, a nonprofit organization focused on cybersecurity. “Our tech debt is coming due.”
Ben Edwards, a data scientist who specializes in managing software vulnerabilities, said the software industry was handling an “intense volume even before AI.”
“It was like drinking from a garden hose on the jet setting before, and now it’s like drinking from a fire hose,” Edwards said. “They might have had the teams that could handle that garden hose. Whether they can handle the fire hose is something else.”
Although the volume of vulnerabilities has grown over the years, Microsoft’s internal group responsible for fielding them, the Microsoft Security Response Center, has been perennially understaffed. Even before the crush of AI-identified bugs, the center fielded hundreds or even thousands of reports a month, pushing the group to its limits, ProPublica has reported.
The size of the center reflects Microsoft’s corporate philosophy: Plugging security holes is a cost center, while making new products is a profit center, former employees said. The company is loath to tie up its best engineers with making security patches — a cost center — instead of developing new products and features that will generate profits, ProPublica has reported.
Microsoft told ProPublica that it does not discuss internal staffing decisions but has made investments in recent years to “focus our teams on keeping our customers secure.” The company “continuously evaluates the staffing, processes, and technologies required to support security response and vulnerability management,” a spokesperson said.
According to the slides that accompanied the May internal presentation, Anthropic provided Mythos access to roughly 50 full-time Microsoft employees, with a goal to “harden critical services before publicly available models catch up.” A slide titled “What’s Next” predicted that the Microsoft Security Response Center would see continued case volume “as public tools catch up” to Mythos.
During the May meeting, one staffer appeared to take comfort in the belief that adversaries “don’t have the source code” that such an AI tool would scan for weaknesses. His colleagues, however, quickly corrected him. Portions of Microsoft’s code have, in fact, fallen into hackers’ hands over the years.
“It might not be this week’s source code,” one person said. “But they’ve got source code. It’s out there.”
In a statement to ProPublica, Microsoft downplayed the comment, saying engineers “design our security processes on the expectation that determined adversaries may gain access to code.”
Filed Under: ai, bug hunting, bug patching, cybersecurity, mythos, security, vulnerabilities
Companies: anthropic, microsoft
Tech
Trump Admin Hijacked $21 Billion In Taxpayer Money Earmarked For Internet Access And Then Went Mute
from the this-is-why-we-can’t-have-nice-things dept
I’ve written a few times now about how the Trump administration hijacked a $42.5 billion broadband investment fund included in the 2021 infrastructure bill, stripped away requirements that the resulting broadband be fairly deployed and affordable, and instead redirected billions of dollars to Elon Musk and Jeff Bezos in exchange for slower, more expensive satellite connectivity they’d already planned to deploy without subsidies.
Basically, this redirected tens of billions of dollars away from higher-capacity, faster, more reliable fiber access, and toward Low-Earth Orbit satellite services, which have a long list of problems I’ve explored in detail. The Trump administration then falsely claimed that they’d “saved” taxpayers roughly $21 billion (you can read my recent piece at The Verge for more detail on what that means for real people).
Here’s the thing. This $21 billion in “non-deployment funds” the Trump administration claims it “saved” is technically supposed to go to the states. Congress (aka, the law) specifically stated that the full $42.5 billion included in this Broadband Equity, Access, And Deployment (BEAD) was supposed to be spent on internet access or something very closely adjacent (digital skills training, telehealth tools).
But after the Trump NTIA retooled the program last year (causing all sorts of new delays and problems) they basically just went mute on what happens next. They refuse to meaningfully answer questions on where that money is going to go:
“It’s anybody’s guess if nondeployment funds will ever be released. It’s now been 13 months since the NTIA changed the rules for nondeployment funds, and they are obviously in no hurry to see these funds ever get spent.”
This hasn’t gotten a ton of attention in a U.S. press that finds infrastructure too boring to cover, but it still obviously matters. There were various clumsy attempts to hijack these “non-deployment funds” for other purposes (Sen. Joni Ernst proposed using it reduce the federal deficit, others have wanted to throw it at AI data centers), but that would be technically illegal (for whatever that means anymore).
It seems likely that the Trump administration just hopes that people forget about the funding so it can be pocketed by crony capitalism and associates, but that hasn’t been easy. State leaders and even many Republicans have consistently peppered the NTIA with letters asking them what happens next to these funds, only to be met with more delays or silence.
It’s worth remembering that last election season, Republicans (with Ezra Klein and the “abundance” crew’s help) made a giant stink about how this program was taking way too long to connect anybody. For the whole 2024 election season, Republicans blasted the BEAD program’s bureaucracy and promised how once they were in power, they’d completely revamp it, speed everything up, and save taxpayer billions.
When that “revamp” arrived it involved creating all manner of costly new delays, stripping all the language out of the program ensuring funds were spent fairly and wisely, dumping a whole bunch of money into the laps of Elon Musk and Jeff Bezos, and then running off with half of the program’s funds and refusing to tell anybody what happens next.
In the interim, delays, high costs (from pointless tariffs and wars), and bureaucracy have resulted in even more original BEAD subsidy bidders backing off of their plans for widespread fiber, resulting in bid defaults, even more delays, and even more taxpayer money being thrown at Bezos and Musk for satellite broadband that’s too congested to handle the full load.
Great stuff. Very populist. Incredibly well thought out government efficiencies.
Filed Under: bead, broadband, elon musk, fiber, howard lutnick, infrastructure bill, internet access, jeff bezos, ntia, satellite, subsidies
Tech
Podcast: Dolby Vision 2 Max Is Coming to Hisense TVs. What Will Viewers Actually Gain?
When Dolby Vision 2 was announced in late 2025, the next generation of Dolby’s dynamic HDR technology arrived with plenty of promises and almost as many unanswered questions. Ten months later, the picture is finally coming into focus, with Hisense confirming that select 2026 UX, UR9, UR8, and U7 televisions will receive Dolby Vision 2 Max through software updates rolling out in the coming weeks. The upgrade will apply to supported Google TV and VIDAA models across multiple regions, making Hisense one of the first manufacturers to bring Dolby’s next-generation HDR platform to televisions already in consumers’ homes.
In this podcast, eCoustics founder Brian Mitchell, Senior Reviewer Al Griffin, and Editor at Large Chris Boylan break down the latest developments surrounding Dolby Vision 2 and Dolby Vision 2 Max, including what has changed, which Hisense TVs will support the technology, and what consumers can expect over the coming weeks and months.
Read the full breaking-news report here.
Watch the full podcast on YouTube.
This episode was recorded on July 29, 2026.
On the Panel:
Tech
The browser is where attacks land. Why is security still focused on the endpoint?
Presented by CloudMosa
Enterprise work now happens increasingly inside the browser, and that shift has made the browser a primary point of entry for cyberattacks as well. Browser-based attacks have surged over the past two years, according to industry reports, while Gartner projects that more than 85% of enterprise workloads will be accessed through the browser by 2027.
And yet most enterprise security architecture is still built to protect the device rather than the browser session where that work, and those attacks, actually take place, says Shioupyn Shen, founder and CEO of CloudMosa, the company behind Puffin Cloud Security.
“CloudMosa originally built its cloud architecture to improve browser performance and accessibility, with the expectation that enterprise work would increasingly move into the browser,” Shen says. “Today’s AI-assisted hacking has validated that architecture, demonstrating that what was designed for performance also provides a strong foundation for modern enterprise security.”
The browser as the enterprise’s operating environment
SaaS platforms, CRM and ERP systems, and collaboration tools have made the browser the primary gateway, and often the central workspace, for enterprise operations. As LLM-powered workflows and autonomous AI agents increasingly operate through that same environment, this shift has also redefined what a threat looks like.
In a device-centric world, security teams could focus much of their attention on endpoints and networks they could monitor, manage and patch on schedule. But because web code now executes locally on the user’s device, every open browser tab can become a potential entry point for malicious scripts, credential theft, supply chain compromise and other browser-based exploits.
The browser now interprets and executes remote code, manages authenticated sessions across enterprise applications, and increasingly serves as the execution layer for AI workflows and agents.
“The browser is no longer just another application running on the endpoint,” Shen says. “In practice, it has become the central operating environment for modern enterprise work. Traditional browsers were never designed to carry this level of enterprise responsibility. They were built as local interpreters of remote code, not as enterprise-grade execution environments with strong isolation and policy enforcement.”
Why detection-first security fails against browser-based attacks
Detection-first security has a timing problem: it typically begins only after risky code has reached the device and started executing inside the browser. Because modern browsers execute dynamic, often obfuscated JavaScript and WebAssembly locally, attacks can act on the device before endpoint tools have time to respond. Short-lived or fileless attacks may steal credentials, exfiltrate data or complete their objective before a security team can intervene.
“It is no longer sufficient to ask only whether a threat can be detected,” Shen says. “The stronger approach is to prevent risky or malicious code from ever reaching the device in the first place.”
AI-generated malware strains signature-based detection
AI is a force multiplier that lets attackers automate the creation, mutation and deployment of malware at a scale signature-based tools were never designed to handle. It can generate large volumes of malware variants and help attackers adapt fileless and browser-delivered techniques faster than defenders can analyze them and update signatures.
That matters because polymorphic malware can alter its code or behavior from one instance to the next, making a known signature less reliable. And when attacks are malware-free — relying instead on legitimate tools, compromised sessions or malicious web content — there may be no conventional file signature to detect at all.
Enterprises have seen an 89% increase in attacks by AI-enabled adversaries over the past year, as increasingly automated and adaptive attacks compress the window available for detection and response.
“Defenders are no longer just chasing more threats, they are chasing a machine that can keep creating new ones,” Shen says. “What was good enough in the past 10 years will not be sufficient in the next six months,” he adds.
Building architecture that removes the attack surface
Rather than continuing to refine detection, the more durable response is to change where web code is allowed to execute in the first place.
“In a conventional browser, the risk comes to the device,” Shen says. “In an isolated cloud model, the risk is kept away from it.”
That principle underlies Puffin Cloud Security. Rather than incrementally improving the browser itself, the platform shifts browser execution into isolated cloud environments. That architectural change improves both performance and security.
The platform runs the original web session, including its JavaScript, WebAssembly, and other executable payloads, inside a disposable cloud environment and streams only a rendered pixel view to the device. Users keep full interactive control over clicking, typing, and scrolling, but the device itself never parses, executes, or stores the original active code.
CloudMosa says display rasterization — the layer responsible for the pixel stream — accounts for roughly 5% of the browser’s total workload, while the more compute-intensive HTML rendering remains isolated in the cloud. As a result, zero-day exploits and AI-generated polymorphic malware have no executable code to run on the endpoint, while fileless attacks or supply chain compromises within SaaS tools remain contained in the cloud.
“In CloudMosa’s view, that means moving from good-enough security on the device to airtight security in the cloud,” Shen says.
Fitting browser isolation into SWG, CASB and ZTNA stacks
Puffin is designed to extend existing security infrastructure rather than replace it. Secure web gateways, cloud access security broker platforms, and zero trust network access tools remain effective at routing traffic, enforcing policy, and controlling access. But none can fully stop local execution once risky content reaches the browser.
Puffin closes that gap by routing high-risk sessions through isolated cloud environments and enforcing browser-level policy, whether a user connects over a VPN, a home network, a managed device or an unmanaged, bring-your-own-device setup.
“Organizations can start with narrow use cases, such as high-risk SaaS access or AI agent workflows, and expand without disrupting tools already in place,” Shen says. “The goal is not to undo existing investments, but to make them more complete.”
The choice between faster detection or endpoint isolation
Detection will always have a role in enterprise security, but the more consequential question is no longer how quickly a threat can be caught, but whether attackers can reach the endpoint at all. Recent 2026 surveys found 92% of security professionals are concerned about the impact of AI agents, with 48% naming agentic AI the top attack vector of the year. Shen noted that agents acting autonomously with user-level privileges are especially exposed to prompt injection, session hijacking, and indirect compromise through compromised web content.
In designing Puffin Cloud Security, CloudMosa has been “paranoid by design,” meaning it invested in an architecture built for worst-case scenarios and for a threat environment where endpoint security and detection alone may not be enough.
“This is not just a philosophy, but something that is reflected directly in the architecture itself,” Shen says. “CloudMosa built earlier for a harsher threat model than most other organizations did, but today’s AI-assisted attacks are now making that posture feel increasingly relevant.”
By dividing a full browser into a very small layer on the device and a much larger layer in the cloud, CloudMosa designed this approach to improve both performance and security at the same time: In Puffin Cloud Security’s architecture, an AI agent’s browser activity takes place inside isolated cloud sandboxes. The endpoint receives only a pixel stream, not the original active code, preventing malicious web content from interacting directly with the device, its credentials or connected systems.
“AI-assisted hacking represents the kind of structural shift that rewards companies willing to rethink browser from the ground up,” Shen says. “And so security leaders now have a choice: redesign for foresight, or wait until hindsight makes the lesson unavoidable.”
Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact sales@venturebeat.com.
Tech
Samsung’s Galaxy Z Fold8 Turns Movie Nights and Marathon Gaming Sessions Into Something You Actually Want to Keep Going

Samsung took a hard look at how people actually use big foldable screens and decided the tall, narrow shape everyone had gotten used to was not the full story. The Galaxy Z Fold8, priced at $1,900 with $350 Amazon GC, arrives with a shorter, wider body that feels closer to a passport than a phone book, and that single change unlocks a far better experience for videos, games, and everything in between.
When you open the cover, you’ll notice a 5.5-inch Dynamic AMOLED 2x panel running at up to 120Hz. With a 10:16 aspect ratio, you can watch vertical clips on Instagram, YouTube Shorts, or TikTok without the awful letterboxing we saw on the Fold Ultra. It also has brightness and a Gorilla Glass Ceramic 3 layer, so no matter how tough you use it, it will not break or become dark on you. Furthermore, its modest size allows you to surf through feeds or answers with just your thumb.
Samsung Galaxy Z Fold8 Unlocked Cell Phone + $350 Gift Card, 256GB, Cream
- PRE-ORDER NOW: Get an Amazon gift card when you pre-order Samsung Galaxy Z Fold8. You will receive an email once your gift card is available after the…
- CREATED FOR YOUR CONTENT: Any way you turn it, the new Galaxy Z Fold8 gives you a fuller viewing experience. Designed with your content in mind, this…
- WORLD’S LIGHTEST FOLD¹: Galaxy Z Fold8 is the newest foldable phone for content on the go. Unfolded, it fits movies and books for an immersive…
When you unfold the device, the main attraction emerges: a 7.6-inch Dynamic LTPO AMOLED 2x screen measuring 1828 by 2448 pixels in a tidy 4:3 ratio. This is also quite bright; 3000 nits at peak brightness is a lot to take in, and the HDR10+ support allows for some very deep blacks and brilliant colors. Plus, with an anti-reflective coating, it may be used outside, and what about the fold crease? Samsung did a much better job at reducing it this time. As you rotate the device, the screen shifts to a 16:10 aspect ratio, comparable to that of a tablet or laptop. So, watching a movie on Netflix or Disney+ does not result in black bars along the sides. Alternatively, if you prefer action games, the larger screen is a significant improvement; no more cramped UI elements or cutscenes.
Along with all that screen real estate, you’ll get some significant power under the hood. The Snapdragon 8 Elite Gen 5 Samsung Galaxy, along with an Adreno 840 graphics processor, performs even the most demanding games with easily, with several reviewers claiming flawless performance even at higher settings. Don’t worry about it being too hot; it does warm up little over a long gaming session, but it recovers quickly. You have 12 GB of RAM, so you can have tons of apps and gaming files simply sitting there ready to go, no need to reload every time, and the stereo speakers do a really nice job of delivering crisp dialogue and some reasonable bass.
As you’d expect, given all that screen time, the battery life is fairly decent as well; according to Samsung, a 4800 mAh dual-cell pack provides up to 26 hours of continuous video playback, and in practice, you can go through a day of streaming, browsing, and small gaming spurts without needing to recharge. Charging it back up is also quick; 45 watts wired puts you over 60% in 30 minutes, but 20 watt wireless gives you a slower top-up. At 201 grams, it’s light enough to handle for hours without tiring, and the folded-up thickness of only 4.5mm makes that large screen feel much less substantial.
Tech
How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore
By Thyaga Vasudevan, EVP of Product at Skyhigh Security
For decades, enterprise security was largely focused on endpoints and networks. By protecting corporate end-user devices, establishing secure connectivity, and controlling access to on-premises resources, teams could effectively keep their centralized servers secure from intrusion.
Eventually, these priorities evolved as enterprises embraced software-as-a-service (SaaS) models and cloud services, shifting to include new cloud security, data protection, and identity-based controls.
Then employees began working from anywhere, on any device, and the network expanded even further. And if that wasn’t enough, the artificial intelligence (AI) boom came along and made the threat landscape even more complicated.
When users can be in person, remote, or hybrid, and access data from a corporate computer or a personal laptop—then turn around and share that data with third-party AI models—endpoint and network measures alone are no longer sufficient.
Even as enterprise networks become increasingly distributed and complex, there is one common thread that connects users, applications, data, and AI models: the browser. It is the primary interface for modern work, acting as a gateway to business-critical tools, platforms, and more.
Because of this, securing the browser has taken on even more significance, emerging as a critical component of modern security strategies designed to protect data wherever it is accessed—even by AI models.
How AI Revealed an Existing Blind Spot
The excitement around AI has understandably focused enterprise attention on the new risks associated with these models. Security teams worry about employees copying and pasting sensitive information, uploading private files, or inadvertently exposing intellectual property while using AI services and workflows.
Because of this, they focus on protecting sanctioned enterprise AI tools while discouraging the use of unsanctioned shadow AI models, trying to promote adoption while avoiding new threats.
While this is well and good, these growing AI security concerns point to a broader issue that enterprises have long been able to ignore: employees have been moving sensitive data through browser-based applications for years; all AI did was accelerate the volume and visibility of these kinds of interactions.
Think about the everyday actions that take place within a browser session. Users copy and paste information between applications, upload files, download reports, print documents, and share content with partners and collaborators. And this is all done across different devices and locations.
This browser-based activity mirrors much of today’s AI usage, demonstrating that we’re not dealing with an entirely new security challenge, but an evolution of an existing one.
The problem enterprises must now solve is how to govern browser activity effectively without disrupting or greatly inhibiting the user experience.
Business happens in the browser. So do modern attacks.
Add comprehensive security to every existing browser in your network with enterprise-grade controls, all without disrupting users.
Why Traditional Security Approaches Are Struggling
The shift to primarily browser-based work has exposed key weaknesses in traditional enterprise security methods. Historically, controls were designed to inspect and secure traffic crossing the network perimeter, or to protect managed corporate devices at network endpoints.
While these methods remain important to overall enterprise security, they were not designed to govern the growing number of user interactions taking place within browser-based applications, services, and models.
The rise of hybrid work only adds to these challenges. As employees, contractors, and external partners access corporate resources from various devices—both managed and unmanaged—enforcing consistent access and security policies becomes increasingly difficult.
Because of this, enterprises often find themselves with strong protections on company-owned devices, but far less visibility into how data is accessed, shared, or manipulated once it moves beyond managed environments.
AI usage further expands this potential threat landscape, providing additional avenues through which data can quickly and easily leave protected corporate networks. While organizations can restrict access to applications and monitor data as it moves across the network, they still need to govern these kinds of actions that create risk in the first place.
Whether it’s copying sensitive information into an AI prompt, uploading a confidential document to a cloud platform, or downloading proprietary data to a personal device, teams need to find a way to control and manage browser-based activity.
Securing the Browser Without Replacing It
As things stand, enterprises have adopted several different approaches to enhanced browser security. Some choose to deploy entirely new secure browser environments that employees must adopt, while others rely on virtual desktop infrastructure (VDI) or remote browser isolation (RBI) to keep browser activity separated from endpoints.
These methods, while effective, are not perfect. They tend to suffer from deployment complexity, infrastructure overhead, user adoption challenges, and limited coverage for unmanaged devices.
In response to these inefficiencies, a new model has emerged that focuses directly on securing sessions without replacing or largely restricting browsers. These solutions apply inline security controls across common browsers like Chrome, Edge, Safari, and Firefox, allowing organizations to govern user actions within browser sessions without upending existing workflows or inhibiting secure experimentation with new AI models.
Skyhigh Security’s Secure Browser Controls solution is an example of this new, dynamic approach to browser security. Built to work within existing browser and security service edge (SSE) architectures, this solution enables organizations to deter common risk activities, including:
- Controlling copy-and-paste activity involving sensitive data
- Restricting uploads and downloads to sanctioned applications and AI services
- Preventing unauthorized printing or screen capture of sensitive information
- Governing drag-and-drop actions and other methods of data movement between applications
- Applying data protection policies to AI prompts, file uploads, and other browser-based interactions in real time
Protecting Work Where It Happens
As enterprise applications, collaboration tools, and AI services continue to converge inside the browser, security teams must be able to apply controls wherever users interact with data.
Skyhigh Security’s Secure Browser Controls help align security controls with where work is actually happening in enterprise networks, rather than applying them strictly at endpoints and system borders.
The rise of AI may have intensified the conversation around browser security, but the underlying trend extends beyond these newer tools.
By recognizing the browser as a critical control point for enterprise security—and protecting it as such—organizations can ensure their sensitive data is kept safe while supporting browser-based collaboration and innovation.
Request a free a demo of Skyhigh Secure Browser Controls now.
Sponsored and written by Skyhigh Security.
Tech
This 2TB Samsung SSD deal is genuinely good compared to the rest
Nearly £50 off a 2TB drive that reads at 7,250 MB/s isn’t a discount you stumble across every day.
This 2TB Samsung 990 EVO Plus, already considered one of the best SSDs you can buy right now, has dropped from £297.89 to £249.99, a saving of £47.90 that brings serious NVMe speed down to a genuinely reasonable price.
This 2TB Samsung SSD just dropped by nearly £50, and it’s one of the fastest NVMe drives around
This spacious 2TB Samsung SSD has just dropped in price by nearly £50, and it still ranks among the fastest NVMe drives you can buy right now.

Drives with these read and write speeds usually sit much closer to the £300 mark, so seeing a 2TB Gen 5 capable SSD priced under £250 makes this one of the stronger storage deals around at the moment for anyone building or upgrading a PC.
That speed isn’t just a number on a spec sheet either, since read speeds up to 7,250 MB/s and write speeds up to 6,300 MB/s mean games load faster, large files copy almost instantly and heavier work stops feeling like it’s waiting on the drive.
Part of what makes this drive worth considering is its dual interface support, running on PCIe Gen 4.0 in most current systems while staying ready for PCIe Gen 5.0 boards, so it doesn’t become outdated the moment you next upgrade your motherboard.


Samsung’s in-house controller also brings smart heat control into the mix, keeping performance consistent under sustained loads instead of the throttling that can quietly slow down cheaper drives once they’ve been working hard for a while.
Setup is straightforward too, since the drive works with both Windows and Mac systems and pairs with Samsung’s own Magician software for monitoring health, running firmware updates and keeping performance optimised without needing any real technical know-how.
Everyday reliability gets covered too, with AES 256-bit encryption to keep your files protected and a five-year manufacturer’s guarantee that should outlast several upgrade cycles, which matters if this drive is going to be holding onto photos, projects or a growing game library.
With speeds like these and almost £50 shaved off the price, is there a genuinely smarter way to future-proof your PC right now than grabbing the Samsung 990 EVO Plus while it’s still this cheap?
SQUIRREL_PLAYLIST_10148964
Tech
This is our first look at the Googlebook
Google’s rumoured Googlebook laptop is leaking again, this time in what appears to be its first outing from Asus.
The leaked device, reportedly called the Asus Googlebook CX9406 (snappy, eh?), surfaced briefly on the iF Design website before the listing was removed. While the page described it as a Chromebook, several details suggest otherwise.
Most notably, the listing references an operating system called “Aluminium OS”, rather than ChromeOS. Previous leaks have pointed to Google’s upcoming laptop platform using the same name internally. However, it’s still unclear whether Aluminium OS will be the final branding when the devices launch.


The hardware itself also hints at something different. Images show an LED “Glowbar” positioned above the Asus logo on the lid. This is expected to work similarly to the HiLight notification strip rumoured for Google’s upcoming Pixel 11 phones. The keyboard also swaps the traditional Windows key for Google’s familiar “Go” logo.
Port selection appears reasonably generous, although the images don’t make every connection easy to identify. Based on the renders, the laptop seems to include two USB-C ports, two USB-A ports, an HDMI output and a 3.5mm headphone jack. The chassis also adopts a darker grey finish than the lighter Lenovo prototypes that surfaced earlier this week.
The now-removed listing offered a handful of hardware details, though its accompanying text appeared unfinished. It claims the laptop is built from an “Ultra-Ceramic Light Alloy” chassis that is 34% lighter and 13% stronger. However, the wording becomes garbled in places, making those claims difficult to verify. No processor, memory or storage specifications were included.
Even so, the growing number of leaks suggests Google’s laptop plans are gathering pace. Lenovo and Asus are now both linked with Googlebook hardware, while Acer, Dell and HP have previously been named as manufacturing partners.
With multiple designs now appearing ahead of any official announcement, it looks increasingly likely that Google’s first wave of AI-powered Googlebooks is edging closer to launch.
Tech
Four Tons of SpaceX Falcon 9 Rocket Debris Carve a Fresh Crater Near Einstein on the Moon

After drifting aimlessly for more than a year and a half, a discarded SpaceX Falcon 9 upper stage finally ran out of empty space on Wednesday. The four-ton cylinder, roughly the size of a school bus and more than 40 feet long, slammed into the Moon at 5,400 miles per hour near Einstein Crater on the sunlit western limb.
SpaceX launched a rocket from pad 39A at the Kennedy Space Center on January 15, 2025. The aim was to launch two private lunar landers, Firefly Aerospace’s Blue Ghost and ispace’s Resilience, on a path to the Moon. Blue Ghost landed safely on the Moon’s surface, and then there was Resilience. Unfortunately, Resilience didn’t fare so well. Once the top stage had completed its burn and jettisoned the landers, it had no further instructions and insufficient fuel for any course correction. It was just lying there, floating, until the combined force of the sun’s gravity, the Earth’s gravity, and solar activity gradually began to alter its route, and the Moon became the inevitable destination.
LEGO Icons NASA Artemis Space Launch System – DIY Rocket Model Building Set for Adults, Ages 18+ – Gifts…
- NASA rocket model kit – Launch into a creative project with the LEGO Icons NASA Artemis Space Launch System model building project for adult space…
- What’s in the box? – This creative building set includes everything you need to craft a multistage rocket with 2 solid-fuel boosters, an Orion…
- Features and Functions – This NASA-themed rocket model features retractable launch tower umbilicals, rocket support and crew bridge, detachable…
Bill Gray, a skilled amateur astronomer who first raised the alarm a few months ago with available orbital data, calculated the impact window. When the time arrived for astronomers all across the world to focus their telescopes at the anticipated impact zone, they were unable to see anything. That was due to the fact that the impact zone was on the edge of the moon’s near side during daylight hours, which was not optimal for terrestrial observers. Marco Langbroek, a Dutch astronomer, trained in the area but discovered nothing, believing it was a long shot even before. Still, he believes the stage made it.
Confirmation came from a Boston University team led by Carl Schmidt, who discovered traces of a large plume of sodium and lithium streaming from the crash site.You could see this plume stretching for miles. Unfortunately for ground-based telescopes, it was shortly after daylight, so you wouldn’t get a good look. The European Southern Observatory’s Very Large Telescope in Chile was able to capture some images of the debris cloud, which lingered for at least 5 to 10 minutes, after which it was still unclear whether the impact had occurred, but Schmidt is certain that what his team saw was the impact. Both NASA’s Lunar Reconnaissance Orbiter and the South Korean Danuri spacecraft will hopefully be able to take before and after photos of the new crater when they pass over, as it is predicted to be 60 feet broad and 12 feet deep.
The blast produced when the rocket stage collided with the Moon was very small in comparison to the larger lunar impacts that occur on occasion, weighing approximately three tons of TNT, but nonetheless noteworthy. It hurled lunar dust and debris in all directions. Though astronomers point out that impacts of nearly the same energy occur on the Moon on a regular basis, the fact that these objects are man-made raises questions. Not to mention how frequently they occur these days. A similar incident occurred in March 2022, when a Chinese rocket stage formed a double crater on the moon’s far side under similar conditions.
[Source]
-
Fashion6 days agoWeekend Open Thread: Wit & Wisdom
-
Politics6 days agoMeta enters AI-training agreement with far-right ‘propaganda rag’ Newsmax
-
Politics4 days agoZack Polanski: an incitement to murder Nigel Farage?
-
Crypto World5 days agoMicroStrategy Post-Earnings CLARITY Act Push Could Add New Catalyst for Its Stock
-
Crypto World5 days agoXRP Ledger v3.3.0 brings five institutional features
-
Sports7 days agoSeema Kaliramna Wins Discus Throw Bronze, Takes India’s CWG Medals Tally To 17
-
Crypto World6 days agoNew York sues Kalshi over prediction market gambling
-
Crypto World4 days agoCrypto PAC spending tops $2M in Michigan House race
-
Business4 days agoDTCR: Deleveraging And A Hedge Fund Collapse Point To A Possible AI Bottom
-
Business6 days agoTrump Announces Hamas Disarmament Agreement as Iran Strikes Kuwait Air Base and US Attacks Pause Overnight
-
Crypto World6 days ago3 Fed Officials Just Explained Their Rate Hike Vote: Is Inflation Winning?
-
Tech4 days agoESET tracks rise in malicious AI skills and adaptable malware
-
Tech6 days agoGemini Spark can now use Chrome logins and saved passwords to run errands on your behalf
-
Sports5 days agoFrance Cricket implodes: letters hidden in a drawer and a board at war
-
Crypto World4 days agoXRP Ledger urges node upgrade after manifest flood
-
Tech6 days agoBuilding A Reproduction PlayStation Motherboard
-
Crypto World5 days agoMoneyflip CEO charged in $40K murder-for-hire plot
-
Sports6 days agoBruno Fernandes decision made as Man United ‘discuss’ striker transfer option
-
News Videos5 days agoFinancial Crash Expert: The 90-Day Collapse Timeline They Are Desperately Hiding.
-
NewsBeat7 days agoSpain sending troops as thousands enter enclave of Ceuta from Morocco




You must be logged in to post a comment Login