The REI Half Dome 2 is the best budget two-person backpacking tent. I’ve toted it on many backpacking trips and found it plenty sturdy, quick to set up, and capable of fitting two people along with their gear. It even comes with a footprint (which I never bother with, but it’s nice to have it if you have to deal with pointy rocks).
The Big Agnes Copper Spur series is our top pick among freestanding ultralight tents. This is the bike-packing model, which features shorter pole segments that are easier to haul on a bike, but I really prefer it for the more subdued colors. The Copper Spur is a high-quality, well-designed tent that’s lightweight, easy to set up, and roomy enough to be livable in the backcountry. The “awning” design (with trekking poles or sticks) is a nice extra.
Nemo’s Dragonfly tents are roomy for the weight. There’s a generous amount of mesh at the top, which provides some nice ventilation on warm summer nights and is perfect for falling asleep under the stars when the weather permits. The Osmo fabric is a blend of nylon and polyester that absorbs less water than pure nylon rainflies.
MSR’s Groundhog stakes aren’t cheap, but they’re the best tent upgrade you can make. They’re superstrong—I’ve never had one bend or pull out on me—and considering their strength, they’re pretty lightweight. I suggest carrying a mix of stakes when backpacking—some of these, some carbon fiber pegs, and some shepherd hooks. That way, no matter the terrain, you’ve got something that’ll work.
Advertisement
Deals on Outdoor Clothing
Now is a great time to score some new base layers and mid layers ahead of the cooler months.
Photograph: Scott Gilbertson
Smartwool’s 100 percent merino base layer is my top pick for cooler weather in our guide to the Best Base Layers. Its loose fit allows it to work as a long-sleeve T-shirt in the shoulder seasons. That extra bit of roominess also makes it possible to use it as a second light layer over something thinner. Note that colors and sizes are limited on this deal.
This is an REI Outlet deal because it’s been discontinued, which is a shame (hopefully that just means new colors are coming next year). REI’s 100 percent merino base layers are some of the best values around, even at full price. On sale, they’re a true steal. I like this half-zip for the extra ventilation the zipper provides, but if you prefer, the regular top (on sale for $30) is also on sale, as is the base layer bottom (on sale for $30).
Nothing says outdoors like a hatchet loop on your pants. Fjällräven Vidda Pro trousers give you that and great ventilation. The Vidda Pro uses Fjällräven’s G-1000 fabric, a 65 percent recycled polyester and 35 percent cotton blend, with pockets everywhere and extras like ventilation zippers, reinforced knees (with openings for pads), and that sweet, sweet hatchet loop on the leg.
Advertisement
This deal is limited to one color, with sizes disappearing fast, but it’s a pretty outstanding deal. The Ghost Whisperer Down Jacket is my top pick for a backpacking puffer jacket. The men’s large I tested weighs just 7.3 ounces, packs down to a tiny little thing (stuffing into its own pocket), and the 800-fill-power goose down offers one of the best warmth-to-weight ratios on the market.
Camp Stove and Water Filter Deals
Nothing says camping like roasting marshmallows over open flames and burning beans on the camp stove. Check out our guides to the best backpacking stoves and best camping stoves for more picks.
Photograph: Scott Gilbertson
MSR’s PocketRocket Deluxe is our top pick for a backpacking stove. It wins the title thanks to its larger burner area, which allows the flame to spread out for faster boil times and better fuel efficiency, especially with larger pots. It also fared better in the wind than smaller burners. The genius of the deluxe model is the small curved lip around the burner, which helps keep wind from getting to the base of the flame. It’s a small design element, and one that you certainly want. During long-term testing, I found it more effective at maintaining a simmer in the wind, should you want to do any actual cooking.
Advertisement
You can put together a lighter cooking setup, but Jetboil’s Stash is the lightest all-in-one system out there, and it does boil water a bit faster than the rest. The heat diffuser design speeds up boil times (Jetboil claims 2.5 minutes, which I could only match indoors in still air), but the real appeal is how this kit packs down into itself and how simple it is to use.
Jetboil’s larger all-in-one cooking system, the Flash, offers a larger capacity 1-liter pot that combines an integrated pot and burner into an easy-to-use system. I prefer the more compact Stash above, but if you’re cooking for two and are all-in on dehydrated meals, this stove is popular for good reason.
While I prefer the larger burner head of the Deluxe model above, the MSR PocketRocket 2 is lighter at 2.6 ounces compared to the Deluxe’s 2.9. It still has wide enough arms to support just about any one- or two-person pot. It’s simple to use, even while wearing gloves, and it’s efficient. At 947-foot elevation, it boiled 1 liter of water in 3 minutes, 47 seconds. You can even get it to simmer, though the flame radius is small, so fancier cooking isn’t easy.
Photograph: Scott Gilbertson
MSR’s WhisperLite series is probably the most popular backpacking stove ever made. They last forever (mine is over 30 years old and still works great), and this model, the Universal, can use just about any fuel you can imagine—white gas, kerosene, unleaded gasoline, and isobutane-propane canisters, to be precise. The only downside is that it can be fiddly compared to stoves like the Jetboil. But if you’re headed out on a long trip, buying fuel as you go, this is the most flexible option out there.
Advertisement
This is by far the most compact two-burner stove I’ve tested. It’s my pick for any situation where space is at a premium—whether that’s canoeing or just because you have a small car. The burners are large, and with some practice, I could get a light, simmer-friendly flame. My main gripe is the windscreen, which is not the best. The Basecamp version, with fitted pots, is also on sale for $300 ($100 off).
Courtesy of Coleman
My favorite stove in Coleman’s current lineup, the Coleman Cascade 3-in-1 features heavy-duty cast-iron grates and comes with a cast-iron griddle and grill. It’ll comfortably fit a 12-inch pan and a 10-inch pan side by side, and it’s significantly sturdier and more robust than other Coleman stoves, making it worth the extra money if you use it often. That said, the much cheaper stove below will get you by if you’re only using it a few nights a year.
This stove is ubiquitous at campgrounds for a reason. It’s well-built, sturdy on a table, and just works. It’s not the most powerful stove, and it lacks frills like push-button ignition, but it’s capable of holding a low flame, simmering soups, and cooking scrambled eggs without browning them. It’s also incredibly durable.
Photograph: Scott Gilbertson
The MSR Gravity Autoflow filter is a must-have for backpacking with a group. To use this filter, scoop up 10 liters of water in the dirty water bag, attach the hose, connect your water bottle, and sit back and relax. The filter is good enough to keep you safe from all the usual protozoa and bacteria, and the flow rate is a solid 1.5 liters per minute when the filter is clean.
Advertisement
The MSR Guardian is our pick for trips with sketchy water sources because it filters down to 0.02 microns, which will even remove viruses. It is heavy at 22 ounces and may be overkill for trips in the US, but it’s a great option for overseas adventures. I really like that it’s designed to be self-cleaning, which makes field maintenance incredibly easy, and that it screws right onto a Nalgene bottle. Also, because it’s a pump filter, it’s very fast. You can crank out a couple of liters in hardly any time at all. The gravity-fed version is also on sale at Backcountry for $232 ($78 off).
Camping Gear Deals
Courtesy of Kelty
This camp chair is the coziest way to hang out around the fire. It is somewhat huge, heavy, and awkward to fold up and carry, but so long as you have room for it in your vehicle, there’s no better way to relax under the stars with your loved ones.
The thing to keep in mind when you shop REI brand gear is the company’s basic proposition: You get 90 percent of the designer item for 70 percent of the price. It’s a strategy that works well and has produced some great, affordable gear. This chair is a good example: It’s comfortable (it does wobble a little, side-to-side when you move, though) and less than half the price of competitors.
I’ve noticed that when people try to lighten their load with a smaller, lighter-weight backpack, they struggle to fit all their gear. The answer for sleeping bags and clothing is this compression stuff sack, which smashes anything soft down to about half the size of the same item in a regular stuff sack. This works well with sleeping bags and clothing, especially puffer jackets, but also fleece and merino wool.
Advertisement
Sleeping Bag Deals
Photograph: Scott Gilbertson
Our favorite backpacking sleeping bag, the Bishop Pass 15 offers the best warmth-to-weight ratio while packing down small and staying affordable. I have slept in this bag for more than two weeks, with nighttime temps ranging from 28 to 65 degrees Fahrenheit, and, yes, it was too warm in the heat, but on those warmer nights, I unzipped it and used it as a blanket. It isn’t perfect, but it’s a versatile bag.
REI’s Magma line of down gear is some of the best value around. The Magma 15 sleeping bag has long been an affordable option that’s perfect for shoulder-season trips when the temperature potentially swings lower than you expect (the comfort rating is 21). There are three lengths and three widths, which makes it easy to find a perfect fit for your body, and the 850-fill-power goose down (Bluesign-approved) packs down nicely and small. If you don’t need the shoulder-season coverage, the Magma 30 is also on sale for $262 ($87 off), and makes a great summer sleeping bag.
This down mummy bag has a spoon-shaped design for side sleepers and extra room in the elbows and knees so you can roll over onto your side without feeling like you’re slipping into a straitjacket. It’s built for temps down to 30 degrees Fahrenheit and has zippered gills you can open to avoid overheating when it’s warmer.
Photograph: Scott Gilbertson
The best budget ultralight quilt, the Magma Trail is a great value for the money. The lower price does mean that this one is a bit heavier (it uses 850-fill-power down), though at 24 ounces for the long, wide version I have, it’s competitive on the scale. The straps for attaching it to your sleep pad aren’t as nice as what you’ll get with something like the Enlightened Equipment’s Revelation Quilt, but it’s just as warm and does a respectable job of keeping out drafts. There’s even a zippered foot box with a drawstring for cooler nights.
Advertisement
Nemo’s Pulse quilt uses RDS-certified, gold-infused 1,000-fill-power ExpeDRY down, which does a good job of shedding moisture from tent condensation and reportedly dries faster than standard down, though I’ve never figured out a good way to test this. The Karo Step baffle stitching keeps down well distributed, and at 12 ounces for the regular, this one is pretty dang lightweight.
Courtesy of REI
This is our favorite sleeping bag for car camping. The REI Siesta is plenty warm and affordable. It’s also not a mummy bag because you’re not climbing Denali here. The rectangular cut makes for a much roomier, more comfortable sleeping experience. The 20-degree-Fahrenheit rating makes it warm enough for three seasons, and unlike most rectangular bags, the Siesta has a hood, which helps on those cold nights.
The Kindercamp makes a great car camping bag if you’ve got young children. Once your kids are about 4 feet tall, an adult sleeping bag works just fine. Prior to that, they’ll benefit from a kids’ sleeping bag like the Kindercamp, which is cut smaller so your little ones don’t have to heat up a huge, adult-size sleeping bag to stay warm.
Deals on Action Cameras and Gadgets
If you snap a selfie in the woods and Instagram isn’t around to see it, did it happen? You’ll never have to answer that question if you’ve got one of our favorite action cameras or 360 cameras with you.
Advertisement
Photograph: Scott Gilbertson
Insta360’s X6 360 camera just launched—our review will be coming soon—but the X5 is still a great option, especially on sale. The twin 1/1.28-inch sensors capture 8K video, which means you can reframe your footage to fit rectangular video formats and still have nearly 4K clips sharp enough to mix with footage shot with your phone. The dynamic range is impressive, and the X5 also has great battery life.
If you’re going to turn your action camera on yourself, consider the Ace Pro 2, our top pick for vlogging. It has a great lens and sensor co-engineered with Leica, is capable of recording 8K video at up to 30 frames per second (fps), and has some pretty darn nice color even in the default settings. My guess is that the Ace Pro 3 is coming pretty soon, but this is still a good deal.
Sure, phones have some of the features you’ll get with a satellite messenger, but we still think you’re better off with a dedicated device. Garmin’s new inReach Mini 3 Plus now offers some of those phone features—like voice messaging—along with the emergency features and excellent service worldwide. It’s also still tiny, well-built, and it has great battery life. A non-Plus model, which doesn’t have a speaker and mic, is also on sale.
BMW is about to release their most screen-dependent vehicles ever, reports Car and Driver:
Step into the BMW iX3, and you’ll notice something is missing: real buttons. The climate controls are fettered to the center screen, as is nearly every other feature, save for a handful located in the center console — at least the window switches are still on the doors…
But don’t blame a desire for larger profit margins; BMW’s move away from physical switchgear and toward touchscreen dependence is the fault of younger buyers, according to one executive. In an interview with CarExpert, Vikram Pawah, the CEO of BMW Group Australia, said that young buyers prefer the newer controls… According to the executive, younger customers are less patient with their technology. “They want things done quickly, and they’re multitasking,” Pawah said. “And we have to keep that in mind. That’s how customers are evolving. They are multitasking….”
Tesla has always forced functions to its center screen; newer players such as Rivian do the same. And in recent years, established brands like Mazda and Mercedes-Benz have moved more and more functions to touchscreens.
Advertisement
BMW’s iX3 also includes a new safety feature — a side-radar that detects if a cyclist or vehicle is approaching, and delays the release of the electronic door lock “until the danger passes.”
The best endpoint protection software is judged by how well it detects and automatically shuts down threats across every device and cloud workload you run, not by how long its feature list reads on a sales page. Get that comparison right and the rest of the decision, the vendor name, the price tier, the extra modules, tends to sort itself out.
Quick Take
Pick endpoint protection by working backward from your actual environment, not from a rankings list. Map what you’re protecting (laptops, servers, cloud workloads, remote and IoT devices) before you look at a single vendor. Then verify three things directly instead of trusting a spec sheet: how detection holds up against unknown threats, how much of your cloud footprint the tool actually reaches, and how much manual tuning its automation needs before it’s trustworthy. Run a real pilot before you sign anything longer than a month.
Prerequisites
You can’t evaluate endpoint protection software in the abstract, only against a specific environment. Before you take a single vendor call, get three things straight.
Know what you’re actually protecting. Write down company laptops and desktops, on-prem servers, cloud workloads, remote employee devices, and anything IoT or operational-technology-adjacent that touches your network. A tool that’s excellent on Windows laptops and thin on Linux servers or container workloads isn’t a good fit if half your infrastructure sits server-side.
Know your risk profile. A five-person accounting firm and a 400-person healthcare provider shop in the same product category but need very different levels of automation and compliance reporting. Naming your actual biggest cybersecurity risks up front, rather than treating “cyber threats” as one undifferentiated blob, tells you which EPP features are load-bearing and which are nice-to-have.
Know who’s actually running this day to day. If you don’t have a security team watching alerts, self-managed EPP alone will quietly turn into a pile of unread notifications within a few weeks, which is one reason a broader set of cybersecurity solutions for your business, not just an endpoint tool, usually outperforms any single product bought in isolation.
What Endpoint Protection Software Actually Does
Strip away the marketing, and endpoint protection software does two things: it detects malicious activity on a device, and it responds to it, whether that’s quarantining a file, killing a process, or isolating the machine from the network entirely. CrowdStrike’s definition of an endpoint protection platform names prevention, detection, enforcing least-privileged access, threat hunting, threat intelligence, and vulnerability management as the pieces that make those two functions actually work in practice, not a single antivirus engine bolted onto an agent.
It helps to know where EPP sits relative to two terms you’ll hear constantly while shopping: EDR and XDR. Palo Alto Networks’ comparison of EPP, EDR, and XDR lays out the hierarchy cleanly: EPP is baseline prevention against known threats, EDR adds continuous monitoring and threat-hunting to catch what prevention missed, and XDR extends that monitoring across email, identity, and cloud systems, not just the endpoint. Most vendors now sell EPP and EDR bundled as one product with tiered pricing, which is convenient, but you should still know which capability you’re paying for at each tier, since a sales call will happily blur the line if you let it.
Advertisement
A Step-by-Step Framework for Evaluating EPP Vendors
One branch point worth flagging before you start: if you’re a small team without dedicated security staff, weight Steps 5 and 7 below most heavily, and seriously consider whether a managed option changes your shortlist entirely. If you have a SOC or a dedicated security engineer, Steps 2 and 6 deserve the closest scrutiny, since your team can handle tuning and cross-checking analyst opinions itself. Either way, run every step, but know which two matter most for your situation.
Step 1: Map Your Real Environment First
Before comparing feature lists, sketch a real map of your environment: which devices are company-owned versus BYOD, which servers live on-prem versus in the cloud, and which parts of your workforce work remotely or hybrid. This isn’t busywork. An EPP that assumes a tidy corporate LAN will leave gaps the moment someone logs in from a home network or a coffee shop.
Remote and hybrid work changed what “endpoint” even means. This shift in cybersecurity with remote work is worth reading in full: VPNs and zero-trust models became load-bearing rather than optional, and the number of devices connecting to your network multiplied well past what a single office ever had. Most EPP vendors will claim full remote coverage; few actually extend real behavioral monitoring to a laptop that’s been off the corporate network for weeks. If your team relies heavily on remote access tools, weighing the benefits of remote access against its security trade-offs up front tells you exactly what gaps your EPP still needs to close.
Step 2: Verify AI and Behavioral Detection Depth, Not the Marketing Claim
Every vendor now claims “AI-powered” detection. The distinction that actually matters is whether that AI does behavioral analysis, watching what a process does rather than matching it against a database of known bad files. Signature-based detection can only catch threats that have already been cataloged, and it’s largely useless against anything new. That’s the entire reason behavioral and AI-driven detection exist: to flag deviations from a device’s normal activity even when nothing matches a known signature.
Advertisement
This matters more now because attackers use the same technology. Palo Alto’s research on AI-driven threats points to AI-crafted phishing as one clear example: messages personalized well enough, and delivered convincingly enough, that the signals security-aware employees are trained to spot don’t show up anymore. If your evaluation only asks “does it have AI,” that’s the wrong question. Ask for specifics: does it flag fileless execution, credential-stuffing patterns, or a legitimate binary suddenly behaving abnormally? A guide to defending against AI phishing attacks is worth reading alongside this step, since detection software is one layer against AI-generated social engineering, not a complete answer by itself.
Step 3: Test Cloud and Hybrid Workload Coverage Specifically
Most businesses today run some mix of on-prem and cloud, whether that’s a deliberate hybrid strategy or just years of SaaS tools accumulating. An EPP that stops at the laptop and ignores your cloud workloads is protecting half your attack surface at best.
Microsoft’s explanation of cloud workload protection gets at why this is a distinct problem, not just “cloud, but with an agent installed”: cloud resources get created and torn down constantly, and configurations drift in ways a static, device-based security check never sees. What you actually want to test during evaluation is whether the tool gives consistent policy and visibility whether a workload is running on a physical server, a VM, a container, or something serverless, not just whether it technically “supports cloud.” If your organization leans on cloud storage as part of daily operations, the reasons cloud storage matters for your business are also the reasons it needs its own layer of protection: convenience and accessibility cut both ways, and an EPP that can’t reach that layer is a blind spot by design, not by accident.
Step 4: Confirm Enterprise-Wide Visibility Across Every Asset Class
Visibility is the least glamorous EPP feature and the one that gets skipped over fastest in a sales demo, which is exactly why you should slow down on it. It means being able to see, from one place, what’s happening across every endpoint, cloud workload, and remote connection you mapped in Step 1: what’s running, who has access, and what changed in the last hour.
Advertisement
The test here is concrete: during a demo, ask the vendor to show you a single device or workload you don’t recognize, and watch how many clicks and different screens it takes to get its full history. If the answer involves switching between three consoles or exporting a CSV, that’s not enterprise-wide visibility, no matter what the datasheet says. The gap almost always shows up at the edges: IoT devices, contractor laptops, and anything spun up in the cloud outside your standard image are the places visibility quietly stops.
Step 5: Evaluate Response Automation and How Much Oversight It Still Needs
Automated response is what lets an EPP act at 3 a.m. without waking anyone up: quarantining a file, killing a process, or isolating a device the moment its behavior crosses a threshold. That’s genuinely valuable, and for a small team without 24/7 coverage, it’s often the difference between catching an incident in minutes and finding it a week later in the logs.
It’s also brittle if you don’t tune it. Automation configured with loose thresholds either misses real incidents or floods your team with false positives until someone disables half the rules out of fatigue, which defeats the purpose entirely. During evaluation, ask specifically how automated actions are scoped: can you set different response levels for a finance laptop versus a test server, and can a human easily review and reverse an automated action that turned out to be wrong? A tool that only offers “on” or “off” for automation, with nothing in between, will eventually either over-trigger on legitimate software or under-react to something real. Faster is only better here if it’s also controllable.
Step 6: Weigh Analyst and Peer Evaluations as One Input, Not the Final Word
Gartner’s Magic Quadrant used to be the single reference point everyone pointed to in this market, and it’s worth knowing the report itself has moved on: Gartner’s own market page for endpoint protection now labels it a report in transition, no longer simply “Magic Quadrant for Endpoint Protection Platforms.” Even analyst frameworks are moving targets, not permanent rankings.
Advertisement
Use it as one input, not the final word. Gartner explicitly frames its Peer Insights reviews as the opinions of individual users based on their own experience, not verified facts or a Gartner endorsement, which is worth remembering before letting five-star reviews substitute for your own testing. Where a Leader or Visionary placement is genuinely useful is as a shortlist filter for vendors worth demoing, not a purchase decision on its own. This is also the point in the process to decide whether you want to run the tool yourself or hand ongoing monitoring to a managed detection and response provider, since that choice changes which vendors and pricing tiers are even relevant to compare.
Step 7: Run a Scoped Pilot Before You Commit
Nothing in a demo or a spec sheet tells you how a tool behaves on your actual traffic, your actual users, and your actual mix of devices. Run a scoped pilot on a representative slice of your environment, not just the newest laptops in the IT closet, before signing anything longer than a month.
Huntress’s own comparison of enterprise options frames the decision as fundamentally dependent on your business context: team size, industry, deployment complexity, and whether you need a managed service layered on top, not a single “best” answer that applies universally. Build your pilot around that same logic. Give the tool two to four weeks, include at least one server and one remote or cloud endpoint, and track false positives and any real incidents alongside how much manual tuning the team had to do to get there. If a vendor pushes back hard on a real pilot and offers only a canned demo instead, treat that as information too.
Verification: How to Know You Picked Right
You’ll know you picked correctly a few weeks after rollout, not on day one. Track three numbers coming out of your pilot or early deployment:
Advertisement
False-positive rate: how often it flags legitimate software or activity as a threat.
Mean time to detect: how long it takes to flag a real issue once it starts.
Mean time to contain: how long it takes to shut the issue down once flagged.
Confirm your cloud and remote endpoints from Steps 1 and 3 are actually showing up in the same console as your on-prem devices, with the same level of detail, not a separate cloud dashboard with limited data. And check that automated responses from Step 5 are logged clearly enough that you could explain to an auditor, six months from now, exactly what the tool did and why. If any of those three checks come back thin, that’s a sign the tool looked right on paper but isn’t actually covering what you mapped in Step 1.
Common Evaluation Mistakes
These four show up more than any others, roughly in order of how often they happen:
Buying on the detection marketing alone. “AI-powered” and “next-gen” appear on nearly every vendor’s homepage regardless of what’s actually happening under the hood, and a glossy comparison chart won’t tell you which claims are real.
Ignoring service-model fit. A five-person team buying a self-managed EPP built for organizations with a full-time SOC will end up with a console full of unread alerts within a month; that’s not a product failure, it’s a mismatch that should have been caught back in Prerequisites.
Skipping the pilot. This is the mistake that costs the most later. A tool that looks identical to competitors on a spec sheet can behave completely differently on your actual traffic, and the only way to find that out is to run it, not read about it.
Missing cloud blind spots. These tend to surface only after rollout, once someone spins up a workload outside the standard image and it simply doesn’t appear anywhere in the console. Catching this deliberately during Step 3 is far cheaper than catching it during an actual incident.
Where This Approach Has Limits
Even a well-chosen EPP has a ceiling. Fileless attacks and advanced persistent threats are specifically built to operate without leaving the kind of artifact a prevention-focused tool is designed to catch, and Infosec Institute’s EPP limitations comparison is direct about it: an EPP solution alone cannot deal with these more skilled attacks. That’s not a knock on any specific vendor; it’s a structural limit of prevention-first tools, which is why EDR and XDR exist as layers on top, not replacements.
There’s also a layer EPP was never built to cover: the application itself. If your business runs custom or cloud-native applications, endpoint protection won’t see an attack that exploits application logic at runtime rather than the operating system underneath it. That’s a separate discipline, and the case for RASP over traditional app defenses is worth evaluating alongside your EPP rather than assuming one tool covers both layers.
Key Takeaways
Endpoint protection software earns its keep on two things: how well it detects what hasn’t been seen before, and how completely it reaches every device and workload you actually run, not just the ones easiest to secure.
Map your environment before you take a single vendor call; a tool that’s strong on laptops and thin on servers or cloud workloads isn’t a fit if that’s where half your infrastructure lives.
Verify AI-driven detection and cloud coverage directly instead of trusting a spec sheet, and never skip a real pilot on your own traffic.
Treat Gartner and peer reviews as a shortlist filter, not a purchase decision.
Go in knowing EPP has a ceiling: fileless attacks, advanced persistent threats, and application-layer risk need additional layers, not a bigger EPP budget.
FAQ
Is free antivirus software the same thing as an EPP?
No. Free antivirus tools generally rely on signature-based detection alone and offer little to no automated response, centralized visibility, or cloud workload coverage. They can be a reasonable stopgap for a single personal device, but they’re not built for the enterprise-wide visibility and response automation an EPP is expected to provide.
How much does endpoint protection software cost?
Pricing varies enough by vendor, deployment size, and whether you add managed detection services that any single number would be misleading here. Treat pricing as something to get in writing for your specific environment during the pilot in Step 7, rather than from a public price list, since per-device costs typically shift once you factor in server coverage, cloud workloads, and support tiers.
Advertisement
How often should I re-evaluate my endpoint protection vendor?
Revisit the decision on a fixed schedule, not only when something goes wrong. An annual review against the framework above, tightened to every six months if you’re in a fast-changing environment like hybrid cloud, catches vendor drift, a tool that’s quietly stopped keeping pace with new threats, before an incident forces the conversation.
Late in 2008, NComputing boxed a full-height PCI card, five palm-sized terminals, and a disc of vSpace software and sold the kit as the X550 for $449. One kit added five extra seats to a single desktop. Seat six stayed on the host itself, so six people could work at once, each with a private monitor, keyboard, mouse, and speakers. A second kit in a second PCI slot pushed the same tower to eleven sessions.
Each XD2 access device was 119 by 82 by 27 millimeters, weighed nearly nothing, and lacked several components, including a fan, a disk drive, and a built-in CPU. A little green LED on the front lit up, indicating that the device was powered on and had a live connectivity. Round in the rear were three ports: VGA, two PS/2 connectors for keyboard and mouse, and an RJ45 jack that appeared to be an Ethernet connection but was actually something else entirely.
【DUAL BAND AX TRAVEL ROUTER】Products with US, UK, EU Plug; Dual band network with wireless speed 574Mbps (2.4G)+2402Mbps (5G); 2.5G Multi-gigabit…
【VPN CLIENT & SERVER】OpenVPN and WireGuard are pre-installed, compatible with 30+ VPN service providers (active subscription required). Simply log…
【OpenWrt 21.02 FIRMWARE】The Beryl AX is a portable wifi box and mini router that runs on OpenWrt 21.02 firmware. It supports more than…
The power, video, and inputs were all routed through a single cable from the PCI card in the host PC. Even unshielded Cat 5e UTP cabling was limited to 5 meters, whereas shielded Cat 6 cabling could reach 10 meters. Going any further would result in an image on the screen while the keyboard and mouse went dark, which is not what you want. The problem is that adding a hub or switch in the middle of the run would terminate the connection because there is no network traffic present. The best thing is that no external power adapter was needed at all. Each additional computer used approximately 1 watt from the host PC.
On the host machine, vSpace would partition the entire system into individual sessions for each user. They’d join in with their own accounts, find their own files, settings, and desktop, and then proceed to operate a variety of apps simultaneously, such as a browser, office suite, email, educational software, or even full-screen video. But, and this is a huge but, any application that refused to run a second copy of itself would simply not function with two users simultaneously. USB devices plugged into the host can be assigned to a single station or shared by everyone, depending on your preferences. Any audio signals were routed straight to the speaker socket, remaining local to each monitor. Finally, if you needed to reboot or shut down the host, each session would be terminated simultaneously.
The host PC hardware requirements were rather low for the time. One kit specified a 2.4 GHz processor or any dual-core chip, 1 GB of RAM, and a single free PCI slot. Two kits required a bit more power, specifically a 3.5 GHz CPU and 2 or 3 GB of RAM. They also supported Windows XP Pro, Windows Server 2003, Windows Server 2008, and a few Linux variants such as Ubuntu, albeit XP was more particular about how many additional sessions it would allow. Desktop resolutions included 800×600, 1024×768, 1280×1024, and 1440×900, all with 16-bit color and 60 Hz. NComputing always urged buyers to test their software before assuming it could support six or eleven users.
Schools, libraries, internet cafés, and small offices were all very interested in this piece of hardware, especially since most were on a tight budget and one machine was much easier to operate than six. The marketing material went so far as to claim that acquisition and support expenses might be reduced by up to 70%, and given that a normal additional PC would consume approximately 115 watts of power while an XD2 would consume only one watt. As a side note, the X550 received a CES Innovations 2009 Design and Engineering Award, and the X300 kit, which functioned similarly but for three extra users at a lower price, had already reached a million users by 2008.
Those who have never lived in a cold climate might romanticize winters around a fire, keeping warm under blankets while snow gently falls outside. While it certainly can be a cozy experience, using a woodstove comes with a number of pitfalls, and when operated improperly can even cause house-destroying chimney fires. Modern stoves operated properly with properly dried wood make this possibility extremely remote, but it’s still worth keeping an eye on. Reddit user [nas886] built a system called Oru which takes a lot of the guesswork out using one of these pieces of heating equipment.
The real danger of a woodstove isn’t necessarily running the fire too hot, although that can be a problem, but running it too cold. Without full combustion of the wood, flammable creosote builds up on the inside of the chimney which eventually can combust. This system uses a probe placed in the stovepipe to monitor the temperature of the exhaust gasses. If it’s too low an ESP32 notifies [nas886] remotely with with a status LED inside a seperate custom-built walnut enclosure so that more wood can quickly be added or airflow increased to bring up the temperature, and in the case that the fire gets too hot the LED changes to a different color and the air can be closed off a bit.
Woodstoves themselves have quite a bit of variability in the size wood they can burn, the amount they can hold at once, their efficiency, and their thermal mass, so this could find utility for anyone from those with tiny stoves that have to be fed constantly to those trying to get all-night burns in massive units, all without having to constantly sit by the fire and monitor it. [nas886] found initial success selling a few of these custom units and plans to put it into further production as well, but the general idea is not too difficult to replicate for most of us here either.
Buying a new or used car can be a stressful and time-consuming process, and dealerships have long looked for ways to reduce the friction. One method some have embraced is at-home test drives, where a salesperson takes a vehicle to a potential buyer’s home or office so they can take it for a spin without needing to get themselves to a showroom. That’s undeniably convenient, but there are a few things to keep in mind when doing so, in addition to the questions you should be asking yourself (like “What’s my budget?”) and the classic mistakes to avoid (like revealing your budget). First, you may not get to drive the actual model you’re interested in, depending on which vehicles the seller chooses to use as demos. Second, you may find the dealer unwilling to talk about terms or financing — let alone seal the deal — without going to the dealership.
At-home test drives have been popular with luxury brands for decades, but became even more popular during the COVID pandemic when many people sought to avoid public transport or unnecessary in-person interactions. Tesla’s started using the technique in 2025 to demonstrate its full self-driving (supervised) feature. At-home test drives are offered by the likes of Nissan and Kia, and sometimes on a dealer-by-dealer basis for brands that don’t offer the service themselves. What’s common regardless of marque, though, is that salespeople are reluctant to talk terms, because of Federal Trade Commission (FTC) rules and regulations around door-to-door sales. In essence, if you get down to brass tacks with a salesperson during a test drive in the U.S., you may be entitled to a three-day cooling-off period during which you can change your mind. That’s good news for buyers, but it means dealers are more cautious.
Advertisement
What the FTC says
Praetorianphoto/Getty Images
The FTC’s cooling-off rule states that “it is unfair and deceptive for sellers engaged in ‘door-to-door’ sales valued at more than $25 to fail to provide consumers with disclosures regarding their right to cancel the sales contract within three business days of the transaction.” The rule covers any transaction made at a place other than the seller’s place of business, so a driveway or curbside sale counts. There are a couple of key caveats to keep in mind, though. First, sellers should remember that, even if the buyer requested the test drive, the rule still applies. However, buyers should bear in mind that if they’ve already visited a dealership and negotiated the terms, and the driveway interaction is only a delivery or signature or other perfunctory process, the cooling-off rule doesn’t apply.
There’s also an exception for deals closed at auctions, pop-ups, roadshows, or other temporary sales locations that aren’t the seller’s lot, but also aren’t the buyer’s home or office. If someone does a driveway deal and the seller doesn’t inform them of the three-day cooling-off period, the seller can be fined up to $53,088. So while salespeople might try to get you to a dealership afterward, at-home test drives can still be incredibly convenient for would-be buyers. Making sure you do a test drive is important. It’s one of our top tips when buying any car, whether new or used.
A billion-dollar video game budget may seem surprising at first glance, but it starts to make sense once you consider that a modern game often has just as many moving pieces as a Hollywood production. You need actors, writers, programmers, animators, designers and composers among others to make an expansive open-world game. And short of a few outliers like the Avatar series, movies are typically in active production for a couple of years. GTA VI has been in active development for closer to a decade. Once a game is nearing completion, it usually goes through a rigorous testing process that requires yet another team.
Apart from a handful of indie breakthroughs, it’s common for game budgets to quickly spiral into the double or triple-digit millions these days. Game development can also take several years, with hundreds of employees dedicated to a single project.
Development costs and timelines have been steadily rising, though. In 2023, court documents revealed that Sony Interactive Entertainment had spent $212 million on Horizon Forbidden West and $220 million on The Last of Us: Part II.
More recently, another court filing revealed that Activision’s development costs for Call of Duty: Black Ops Cold War topped $700 million over the course of the game’s life cycle. Modern live service games require constant development resources for additional maps, game modes, and new content in general. The initial budget for the base game was almost certainly lower than $700 million.
Advertisement
GTA VI is poised to break that threshold, based on even conservative estimates. And that’s before you even consider its online mode, which, barring a huge surprise, will not debut alongside the single-player experience in November 2026.
So will it all pay off? Even though it’s been over a decade since GTA V‘s Online mode released, leaked revenue data suggests Rockstar still earns millions of dollars in weekly revenue from microtransactions and GTA+ memberships.
With that much money on the table, it’s perhaps not surprising that Rockstar and publisher Take-Two Interactive are willing to spend hundreds of millions of dollars or even billions on GTA VI. The single-player experience is expected to eventually sell hundreds of millions of copies and the online mode could have a loyal fanbase for the next decade and beyond. In 2013, GTA V generated $800 million in sales within a single day of its launch, with its total revenue now standing somewhere around the $10 billion mark.
Before this week, the dominant story about Nvidia went something like this: For the first few years of the AI boom, Nvidia was the only source for state-of-the-art GPUs, which became immensely profitable as the industry scaled out. In the last few years, hyperscalers like Amazon and Google have started building their own chips, and Nvidia is no longer the only game in town, leading many investors to wonder how durable its advantage really is.
It’s a compelling story, and mostly true. After growing its market cap 10x between the start of 2023 and mid-2025, Nvidia shares have been on a more modest trajectory for the past year, driven by concerns about GPU competition.
A new narrative has taken shape since the company’s earnings on Wednesday and investors are starting to realize that Nvidia’s advantage goes far beyond GPUs. As AI’s compute grows into the gigawatt scale, orchestration has become an increasingly complex task. Not surprisingly, Nvidia has built much of the state-of-the-art hardware needed to handle it, giving the company a huge advantage in the systems that surround the GPU even as it sees increased competition on the GPUs themselves.
For all the talk of compute as a commodity, it’s still incredibly difficult to operate a megascale data center at peak efficiency — and as deployments get bigger and faster, that challenge is only growing.
Advertisement
Rack by Rack
You can see some of this just by looking at the details of what Nvidia is actually selling. The company is currently rolling out its Vera Rubin architecture, which pairs the Rubin GPU with a collection of other units, including the Vera CPU, the Groq 3 LPX inference accelerator and similar racks for storage and networking.
Over the past week, I’ve been talking to folks at Nvidia about what those systems actually do, and the results have been surprising. Like the Rubin GPU itself, they’re extremely specialized systems, but instead of churning through tokens, they’re making sure everything outside the GPU works as efficiently as possible. If the GPU is the engine, these are the rest of the car.
The Vera CPU in particular is focused on the problem of orchestrating data. “Vera is important because there’s only so much memory that you can put in a single server or any sort of compute platform,” Jason Hardy, Nvidia’s VP of storage technology, told me.
As data centers have scaled up computing power, memory capacity has scaled up too, which is why companies like Micron have gotten rich in the second wave of the infrastructure boom. But getting that data to the GPU at the right time isn’t straightforward — and as companies look to drive tokens-per-watt lower and lower, they’re realizing how important that kind of traffic direction is.
Advertisement
“We saw upwards of 3x improvement in these operations, where the Vera CPU is allowing for acceleration,” Hardy said. “So now we can use our flash to its fullest potential, because we can get all that performance out of it without bottlenecking.”
You can see versions of the same problem outside of Nvidia. When OpenAI developed its Jalapeño chip, a major focus was avoiding these challenges entirely by minimizing the amount of data that needs to be moved around.
“We designed Jalapeño to minimize data movement and communication delays,” the company said in a blog post earlier this month. “Its large domain allows the entire workload to remain within one connected system, minimizing data movement and helping the complete request stay fast and efficient from beginning to end.”
It’s a different approach, avoiding data movement entirely by conducting a workload within one integrated chip. But the overall logic is the same, increasing efficiency with smarter traffic control instead of just more processor cycles. That in turn opens up a whole new layer of infrastructure for companies to compete over.
Advertisement
This new focus on data orchestration isn’t automatically a win for Nvidia. The company will have to compete with rival chipmakers and hyperscalers just as it has with GPUs. But the competition has moved to a new layer, where building a rival GPU matters less than being able to make the entire system work efficiently.
And at least in the early stages, Nvidia looks to have a commanding lead.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
AWS and DuckLabs have been working together since 2024.
Amazon is acquiring Amsterdam-based DuckLabs, the company behind the open-source analytical database DuckDB.
Details of the transaction were not disclosed, however, DuckDB is not included in the acquisition and will remain free and open source under the independent nonprofit that oversees the project, the company clarified.
The company’s team of more than 30 employees are set to join Amazon Web Services (AWS), while co-founders Hannes Mühleisen and Mark Raasveldt are expected to continue leading the team and DuckDB’s technical direction, alongside working on data lakehouse DuckLake and the Quack protocol.
Advertisement
“For almost a decade, the DuckDB team has worked with the idea of building a tool that lets people work with data, with confidence. I find that sentiment – not just making data easy to work with, but actively empowering people to ask questions, build, and really innovate with data – is exactly in line with how AWS and our customers think about data,” said Andy Warfield, Amazon’s vice-president.
“We’ve been working closely with the DuckLabs team for the past two years, and I am so excited at the opportunity to work with them even more closely.”
Amazon’s cloud business, AWS, has been working with DuckLabs since 2024. The 2021-founded start-up said that the acquisition gives it access to resources to help widen its reach to developers and pursue ideas on a much larger scale.
“Together, we plan to use DuckDB, DuckLake and Quack to help power a new generation of data services. Our ambition is to reach people who may eventually depend on the Duck Stack every day, whether they interact with it directly or encounter it quietly inside the products and services they use,” the founders said in a joint statement.
Advertisement
DuckLabs has refused venture capital funding since its launch, and has instead been owned fully by its founders and the development team.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
The Los Angeles Times first calls Ridley Scott’s newest movie “a postapocalyptic thriller that trades zombies for pandemics and asks whether hope can outlast catastrophe.” But besides
The Dog Stars, Scott is also working on an adaptation of Robert Louis Stevenson’s “Treasure Island” starring Hugh Jackman, and is thinking about turning one of his past films into a musical. (“I can’t tell you which one because they’re being difficult.”) The common theme, they suggest, is a director who allows his stories to “speak through evocative, immersive images rather than unnecessary exposition.”
The British director says it’s because he got his start in advertising after attending the Royal College of Art in London. After 1982’s neon-coated sci-fi thriller “Blade Runner,” Scott notably made the iconic Apple Macintosh computer ad “1984,” a memorable Orwellian-themed clip that contained suggestions of the dystopias that would continue to fascinate Scott in his filmmaking. “Advertising in England at that point became a competitive art form,” he says, pointing to the notorious “Adland Five,” a group of directors that included Hugh Hudson, Adrian Lyne, Alan Parker, Scott and his brother Tony. “I’ve got a show reel which is 50 years old which would entertain the s — out you. Hasn’t aged at all. Our visual drive changed the face of how films looked.”
That’s apparent in Scott’s latest, “The Dog Stars” (in theaters Friday), a film about survival after the end of the world. It’s based on Peter Heller’s 2012 novel and set in Colorado 10 years in the future after an aggressive flu has decimated much of the population. Those remaining alive use any means necessary to stay that way, resulting in instability, brutality and, more hopefully, connection…
These days, Scott develops movies with his production company, Scott Free, which he founded with his late brother Tony in 1995. Before that he says he struggled to find good scripts. And rarely has someone handed one to him. “I’ve only ever had three films land on my desk,” he says. “One was ‘Alien,’ which I was fifth choice for after Robert Altman.” He makes a face. “Can you imagine offering Robert Altman ‘Alien’? How stupid can you get?”
Another was 2015 space adventure “The Martian,” which Scott says had been sitting on a shelf for two years before it was sent to him. Scott’s grounded, semi-comedic take on Andy Weir’s novel resulted in seven Oscar nominations. The third screenplay to materialize was “The Dog Stars.” “I read it and I was blown away,” Scott says.
Deadline notes that Scott is already re-writing the third prequel to Alien, citing Scott’s comments to French outlet AlloCiné.
“The one that just came out [2024’s Alien: Romulus] was OK. I think it needs some help. So, I’ve gone back in.” Scott continued, “I’ve already got a footprint for the next Alien…. I’m picking up where we left off in Covenant with Micheal Fassbender, who now thinks he’s Ozymandius.” With the sequel bringing back Fassbender’s futuristic AI droid, Scott sees an opportunity to explore the repercussions of artificial intelligence in our current world. “I like the fact that AI has gone off the rails,” said Scott of where the character is at the end of Covenant. “If we go AI, the moment we discover it’s off the rails is too late. It could switch every digital thing off in the world like that. You’d have fucking chaos. It’s that kind of stuff that’s scary.”
Advertisement
Scott tells the Los Angeles Times that the malfunctioning AI character fascinates him, and in the movie will be creating a “brave new world for himself… AIs can go off. And if they do, it’s like a bomb…”
So far, Scott says he hasn’t implemented AI technologies into his filmmaking. He holds up his “Treasure Island” Ridleygrams [hand-drawn storyboards] and shakes them at the camera. “I can compete with an AI without any problem making images,” he says. “But it’s coming, inevitably.”
Scott was not involved in the forthcoming Prime Video series “Blade Runner 2099,” out in November. “I can’t blame my lawyers and my agents at that time, but somehow we let ‘Blade Runner’ go,” he says. “And when you’re not the author of the actual written word, you don’t have a piece.” (He was more involved in Noah Hawley’s recent “Alien: Earth” series, which he calls “pretty damn good….”)
Does that mean he thinks about his legacy as a filmmaker? He does, but not often. “When you think of your legacy, you’re too near the end,” Scott says. “I’m not near the end.” He looks up from his drawings. “I’ve had a riotous time,” he says. He corrects himself: “I’m having a riotous time.”
Hollywood’s finest — the people accustomed to massive eight-figure checks and exotic movie sets — are now betting on something much smaller: microdramas.
Microdramas are short, scripted series designed to be watched on phones. Episodes typically run just a few minutes, and often feature soap opera-style plots, dramatic twists, and cliffhangers designed to keep viewers watching, and often paying, for the next episode.
The format took off in China before rapidly gaining traction internationally. Omdia estimates that U.S. revenue generated by microdramas is expected to reach $1.5 billion this year. A growing number of apps have emerged to capitalize, including ReelShort and DramaBox, and even TikTok has entered the market, launching its own app, PineDrama, earlier this year.
Now, Hollywood talent is starting to get involved, whether by starring in new series, launching their own companies, or investing in platforms.
Advertisement
It’s understandable. Movie studios are looking for cheaper and faster ways to produce content, and many talent and crew are going without work. At the same time, TikTok, Instagram Reels, and YouTube Shorts are capturing an ever-larger share of viewers’ attention, which is turning microdramas into an increasingly attractive new corner of the entertainment business.
Here are some of the most well-known names getting a slice of the microdrama pie.
The latest recognizable Hollywood actor to make the jump is James Franco, who stars in “Love, Lies & Frank,” streaming exclusively on Shortical.
Franco plays the CEO of an advertising agency that becomes mixed up in crime and werewolves. The premise seems to follow a similar formula to most microdramas, and is packed with outrageously dramatic scenes and a forbidden romance.
The project is notable for being one of the first microseries produced under SAG-AFTRA’s new verticals agreement, a union contract specifically for low-budget microdramas. This offers an early glimpse of how the format could create new opportunities for actors and other Hollywood talent.
Advertisement
Beyond that, Franco’s involvement has drawn attention for another reason: The project marks his attempt at a comeback following sexual misconduct allegations and a legal settlement in 2021. Variety’s review of the show wasn’t glowing, either, with the magazine writing that the actor “appears to be sleepwalking through his lines.”
What compelled Franco to take on a microdrama gig is anyone’s guess, but his casting is still notable. It’s rare to see a major actor who has made millions and starred in blockbuster projects headline a small series built for mobile screens.
Issa Rae
Image Credits:HBO
Issa Rae may be one of the most natural stars to embrace the microdrama boom. She created and starred in the 2011 web series “The Misadventures of Awkward Black Girl,” which helped launch her career.
In May, Issa Rae’s company Hoorae Media partnered with TikTok’s new PineDrama app to launch “Screen Time,” a thriller about a double date that takes a dark turn when a mysterious person hijacks the television and starts forcing the couples to confront their secrets.
The series quickly became a breakout hit, gathering nearly 75 million views in its first week and becoming the top-performing vertical series on TikTok and PineDrama at the time. It later surpassed 150 million views.
Advertisement
Jesse Tyler Ferguson
Image Credits:Chris Delmas / AFP / Getty Images
“Modern Family” star Jesse Tyler Ferguson is also getting into the business with “Theater Kids Vs. Zombies,” an upcoming musical comedy for vertical storytelling platform aTwist.
The premise is pretty much what the title suggests: A group of theater students finds their high school overrun by zombies, and realizes their best chance of survival is to put on a musical.
Ferguson’s entry could be significant, as this series doesn’t sound much like the romance and soap-opera formulae that dominate microdramas, instead leaning into comedy and theater-kid culture.
Taye Diggs
Image Credits:CandyJar
Not only did Taye Diggs star in a microdrama, he’s getting more deeply involved in the business, too.
In January, Diggs was announced as the star and executive producer of “Off Limits & All Mine” for platform CandyJar. He plays a widowed mogul who becomes involved in a forbidden romance with his best friend’s adult daughter.
More notably, Diggs has launched his own mobile-first, vertical storytelling platform, Microhouse Films, which aims to give filmmakers greater control over how they produce and monetize their projects. Eight projects were included in the platform’s debut launch, including “Tides of Temptation,” a series created in collaboration with Lifetime.
Advertisement
The move is significant because instead of just jumping on the microdrama trend, Diggs is now helping build the space itself.
Kim Kardashian
Image Credits:Nathan Congleton/NBC / Getty Images
Kim Kardashian’s involvement highlights another way celebrities are entering the market. While the celebrity hasn’t starred in a microdrama yet, she has already put money behind the business, investing in GammaTime alongside her mother, Kris Jenner, and other angel investors.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
You must be logged in to post a comment Login