Our tech expert David Ludlow has reviewed the Move 2 and found a speaker built around two angled tweeters instead of one, a redesign that widens the soundstage and fills a room with a less directional, more layered sound than its predecessor managed.
Advertisement
We also praised the mid-woofer’s punch when he pushed the volume on something like Rage Against the Machine, noting it threw out bass with real weight without ever letting the vocals get buried underneath it.
Battery life is where the upgrade really lands, with us clocking 24 hours of rated playback and still finding 54% left after an eight hour outdoor session, more than double what the original Move could manage on a single charge.
That endurance is backed by an IP56 rating, so David was comfortable leaving the speaker outside overnight without worrying about rain, dust or an accidental spill doing any damage.
Advertisement
Automatic Trueplay tuning adjusts the sound every time the Move 2 changes location, something we tested by moving it from a kitchen counter to a bookshelf to the garden and finding it balanced the output well in every spot.
Indoors, the Move 2 drops onto its charging base and behaves like any other Sonos speaker, joining an existing system over Wi-Fi for multi-room playback, while Bluetooth 5 takes over the moment you carry it out the front door.
What if the speaker already filling your living room with sound could just as easily follow you out to the garden, the same stereo depth and bass intact, for $100 less than it was selling for last week?
Apple has signed Nate Gatten to become its new head of government affairs, a move that could help the company work more with the Trump administration.
Apple is undergoing several changes in the short term, in preparation for the CEO transition from Tim Cook to John Ternus on September 1. One day before the switch, Apple will be installing a new vice president.
According to a memo from SVP and General Counsel Jennifer Newstead seen byBloomberg, Nate Gatten will be taking over as vice president of Government Affairs. Gatten will take the role on August 31, the memo states.
Current head of government affairs Nick Ammann will move down the corporate ladder one rung and report to Gatten. Tim Powderly, Matt Brown, and Mike Orgill will also report to Gatten.
Advertisement
Kate Adams, previously the legal chief, will be in an advisory role until her retirement on October 1.
Gatten comes from American Airlines Group, where he held the same role for almost a decade. Previously, he led the global government relations and policy teams at JPMorgan Chase.
Newstead describes Gatten as a “thoughtful, strategic leader with deep experience navigating complex policy environments.”
As a Republican, people familiar with the decision to hire Gatten say he will hopefully align with the Trump administration. While at Fannie Mae, he also oversaw a team that worked with Republican members of Congress, which is a seemingly similar situation.
Advertisement
It’s not just a political play by Apple. Gatten’s previous experience in real estate may also be a bonus as Apple expands its operations with new stores and offices.
A few weeks ago, we put out the call for participation for this year’s 2026 Hackaday Supercon, taking place in Pasadena, CA this November. Today was going to be the deadline, but like you, we often let things pile up and put things off, so we’re extending another two weeks until August 26th.
Which is not to say that we haven’t heard from a ton of you! We’re psyched to see so many familiar Supercon regulars on the list, but we also love to see first-timers give talks. We try to make sure that new folks get their time to shine, so if you’ve never given a Supercon talk before, or if it’s been a few years, take this as your cue to present in front of the friendliest audience of like-minded hackers around.
This year is Hackaday’s tenth in-person Superconference, and to celebrate we’ve gotten a larger venue, so more folks can watch the talks live. We’ll be running two tracks as always, and you have your choice of a 20-minute or 40-minute slot. Presenters get in free, and we’ll get you an early-bird ticket rate the submission, so don’t delay and register for your slot today! Or at least before August 26th, because we won’t extend the deadline twice.
Advertisement
Oh, and if you’re interested in tickets, swing by Hackaday about this time tomorrow — we’ll have some news for you.
A German digital-rights group has filed a criminal complaint against Meta, Ray-Ban parent EssilorLuxottica, and several retailers over Meta’s AI smart glasses, arguing the devices can enable covert recording in violation of German privacy law. Prosecutors have begun a preliminary review, while Germany’s network regulator says smart glasses are legal “as long as the recording function is clearly visible.” Reuters reports: “There’s no place to escape from smart glasses. You have to expect at any moment to be filmed and then exposed on the internet,” said HateAid managing director Josephine Ballon. The organization reported the management of Meta, units of spectacles maker EssilorLuxottica including Ray-Ban, as well as retailers Fielmann, Apollo-Optik, Mister Spex and MediaMarkt to the Frankfurt-based digital crime prosecution unit ZIT. HateAid said its complaint was based on a federal digital data protection law that prohibits the sale of communication devices designed to film people without them noticing.
ZIT confirmed it received a complaint from HateAid invoking that law, saying it would routinely investigate on a preliminary basis whether there are grounds for a deeper probe. MediaMarktSaturn Retail Group said it was taking the complaint very seriously, adding that its suppliers had contractual obligations for all goods to be compliant with the law. Mister Spex said it had not been officially notified of a complaint and that it was taking protection of privacy very seriously.
The latest battle in the ongoing innovation war between Apple and Google is upon us. On August 12, 2026, Google announced its rival to the Apple AirTag: the Pixel Tag. It comes with a feature set that puts it in direct competition with Apple’s take. It basically works the same as an Apple AirTag (that is, to help people find their misplaced belongings), and both devices are priced the exact same, as well. The Pixel Tag costs $29 for one or $99 for a four-pack, which is identical to the pricing structure of Apple’s second-generation AirTag. But which has more features?
Given the fact that this is only the first iteration of the Pixel Tag, while the Apple AirTag just upgraded to its second, AirTag is the one with more features to offer. Sure, they both cover many of the same basics, but Apple’s tracker offers more precision finding, a better crowdsourced tracking network, and more unwanted-tracking protections than Google’s Pixel Tag. You also get support for sharing a lost item’s location with participating airlines and other trusted third parties. It’s simply a much broader feature set than what you get with this long-rumored first-gen Pixel Tag.
Advertisement
How the Google Pixel Tag compares to Apple AirTag
Wachiwit/Getty Images
That being said, the Pixel Tag still has plenty to offer. Its Find Hub network leverages the millions of Android devices out there to help locate a lost item when the tag is outside Bluetooth range. If you’re not an Apple user, that’s really nice to have. Not unlike the Apple AirTag, users can also ring the Pixel Tag. You also get Ultra-Wideband and Bluetooth Channel Sounding for more precise visual distance and directional information, plus Left Behind alerts to warn you when you’ve left an item behind. Uniquely, the Pixel Tag can also be shared with up to 10 people, which is nice for those belongings that get used by multiple people. Its button can ring a paired phone, while a paired Pixel Watch can pinpoint and ring the tag from the watch. Pixel Buds owners can also ask Gemini to ring it.
Still, the AirTag combines most of those capabilities with several additional features that the Pixel Tag doesn’t offer. The best example is the aforementioned Share Item Location, which lets you temporarily share the location of a misplaced item with a trusted third party to help you track it down (such as an airline, for example). AirTag also comes with free personalized engraving and works with existing AirTag accessories. You essentially get the same basic tracking tools found on the Pixel Tag, just with more recovery and sharing features.
Over a decade has passed since Dolby Atmos launched in cinemas across the world, and arguably it’s unlocked another level in the audio space.
Since its inception, Dolby Atmos has moved from the silver-screen to areas such as TVs, soundbars, smartphones, headphones and in-car audio. It’s supported by major streaming platforms such as Apple Music, Netflix and Disney Plus, as well as game consoles in the PS5, Xbox Series X and Series S. Dolby Atmos is everywhere, and its brought spatial audio to devices big and small.
Dolby Atmos has helped usher in an era of spatial audio, but how does it work, and what’s the best way to experience it?
What is Dolby Atmos?
Dolby Atmos is a three-dimensional surround sound technology that adds height to audio, creating a more natural and immersive experience in the process.
Advertisement
With Dolby Atmos, sound is no longer limited to a particular channel as they are in 5.1 and 7.1 set-ups. Rather, sound engineers can specify where a sound originates, the direction it moves in and where it ends. These sounds are called audio objects.
Advertisement
There are up to 128 audio channels in total and 10 channels are used for ambient sounds. These 10 channels don’t require any specific placement.
Image Credit (Dolby)
These sounds stick with the traditional channel-based approach used in other sound systems, while the other 118 channels are used for the audio objects that move position.
Audio objects are also compatible with any number of speakers, meaning Dolby Atmos can be heard on the big screen with a cinema-level 64 speaker set-up, or adapted to fit a pair of headphones.
Advertisement
Of course, Dolby isn’t the only player in immersive audio market. DTS:X, Eclipsa Audio and Auro 3D all create a similar effect.
Advertisement
How can I listen to Dolby Atmos?
Image Credit (Trusted Reviews)
The best way to hear what Atmos is either in a cinema or a dedicated Atmos room.
You can, of course, upgrade your home audio set-up, but when it comes to upgrading your home cinema system, 64 speakers is a logistical challenge. That’s why there’s a variety of products to help bring Dolby Atmos to your home.
Any pair of headphones is capable of playing Dolby Atmos as there’s no specific tech required to get it up and running.
Advertisement
Soundbars can either feature upfiring speakers to produce the height channels, or they can use digital processing to trick the brain into thinking that sound is placed up high or out wide. Dolby Atmos FlexConnect can connect multiple speakers together that adapt to changes in room placement so no matter where they’re placed, you’ll get an immersive spread of sound.
Image Credit (Dolby)
Advertisement
If you have space for surround speaker set-up, this would be the best way of enjoying immersive object-based audio as you’ll have rear speakers and height speakers to create a bubble of sound. A wireless soundbar system can do this on its own, but if you have a more traditional wired surround system, an AV receiver will be required to decode Atmos sound and send it to the speakers.
Home Atmos systems are capable of reproducing all 128 audio objects across from as few as seven speakers. For those who want to go all out, home Atmos systems support up to 34 speakers, but such a set-up is usually unnecessary.
But before you worry about speakers, there’s some other information to be aware of. Firstly, you won’t need a new Blu-ray player. Standard Blu-rays are capable of containing the necessary Atmos data, as are 4K Ultra HD Blu-rays, so unless you feel like upgrading to UHD Blu-ray, there are no format issues to worry about.
TNT Sports has put its weight behind the format, too, with Premier League, Champions League and ruby matches broadcast in Atmos.
Advertisement
The broadest range of Atmos content is available to stream from services such as Netflix, Prime Video, Apple TV, Disney+, although you’ll have to subscribe to the premium tier to access spatial audio.
Tidal, Amazon Music and Apple Music streaming services also support it, and Atmos is available through streaming boxes like the Apple TV 4K, Google TV 4K and Roku Streaming Stick.
Advertisement
Atmos in gaming has become more popular, whether through Windows 10 and 11 PC gaming, Sony’s PlayStation 5 and the Xbox Series S and Series X consoles.
Image Credit (Dolby)
What set-up do I need for Dolby Atmos?
For overhead speakers, you may wonder whether you need to drill holes in your ceiling to install the Atmos speakers. Thankfully, that isn’t necessary.
If you have a traditional wired home cinema set-up, you can buy specially designed Dolby Atmos speakers that integrate forward-facing speakers with upward-firing versions, rebounding sound off the ceiling to mimic the effect of overhead speakers.
Advertisement
If you don’t want to buy an entire new speaker set-up, there are speaker modules that can transform the existing set-up into Atmos-enabled one. It’s a case of placing the modules on top of the speakers to add upward-firing drivers.
Advertisement
Image Credit (Klipsch)
Another way is to take the plunge and install actual overhead speakers. As mentioned, home Atmos systems will work with up to 34 speakers, so if you want a dedicated cinema space and have the budget, a custom installation is the way to go.
Before ruining the plasterboard, though, it’s worth bearing in mind that Dolby’s guidance states that using only two overhead speakers will “provide a convincing and powerful effect” while four overhead speakers will give you the “optimum sense of audio movement and precision.” This will depend on the size of your room,
Dolby’s reference guides for the best Atmos speaker set-up recommend a 5.1.4 as the set-up for enjoying Atmos, and we think that’s the minimum for having a good immersive experience.
Image Credit (Dolby)
Advertisement
Once you’ve chosen your AV receiver, you can upgrade your existing 5.1 or 7.1 surround sound by adding two or four ceiling speakers and either a couple of speaker modules or Atmos-enabled speakers.
The rise of Atmos in the home has also coincided with the rise of Atmos-enabled soundbars as a cheaper, less obtrusive way of getting Atmos in the home.
Advertisement
These simpler solutions integrate upward-firing speakers with traditional soundbar tech to deliver an Atmos experience without the hassle. The Sonos Beam 2 uses digital processing to deliver Atmos for £450.
Sennheiser’s Ambeo 3D Soundbar takes the Dolby Atmos codec and adds Ambeo 3D processing to create a massively immersive experience. It sounds fantastic, but it’s also one of the most expensive (and gigantic) soundbars on the market.
Atmos on mobile
Image Credit (Tidal)
Advertisement
Because Dolby Atmos is designed to adapt to whichever device you’re listening to, you can experience Atmos sound using your smartphone, tablet or headphones. Though with mobile devices, don’t expect the sense of sound above or around you – think of it as just better quality sound through the speakers.
Atmos on mobile is made possible by combining traditional virtual surround technology with the object-based audio of Dolby Atmos, the combination of the two allows headphones to reproduce a convincing version of the 3D soundscape.
Advertisement
Dolby has said to Trusted Reviews that manufacturers can embed Atmos into both software and hardware, which means your device doesn’t necessarily need specific hardware to use it, although we’ve seen more headphone brands, from the likes of Apple with its Spatial audio with Dolby Atmos, to Bose’s Immersive Audio, Sennheiser, Shokz and Soundcore that have added support for Atmos with head-tracking.
What is Dolby Atmos Music?
Image Credit (Dolby)
Atmos isn’t just for home cinema aficionados. Its presence has grown in the music industry too. Dolby Atmos Music does the same thing as Atmos did for cinema. Tidal, Amazon Music and Apple Music offer the biggest catalogues of Dolby Atmos Music.
The first Blu-ray audio disc with Atmos arrived in 2015 in the 25th anniversary edition of R.E.M’s Automatic For The People.
Advertisement
We now see (and hear) Atmos music delivered through music services on a monthly basis, from new titles mastered in the format such as Sam Smith’s When He’s Gone to classic titles to the likes of Paul McCartney/Wing’s Ban On The Run.
Advertisement
Spatial audio is very much part of the music landscape.
How does Dolby Atmos stack up against the competition?
Dolby isn’t the only company to have its toes in the immersive waters.
Image Credit (DTS)
The DTS:X format was introduced in January 2015 and also uses an object-based system. Unlike Atmos, DTS:X was originally aimed at home use, before being targeted at cinemas.
In many ways DTS: X is the same as Atmos but the crucial difference is the speaker set-up. Whereas Atmos supports up to 34 speakers in the home, 64 in a cinema and requires new speakers/modules to work properly; DTS:X supports up to 32 speakers and will work with your current home speaker set-up. That means that while extra overhead speakers will enhance the DTS:X experience, they’re not necessary.
Advertisement
Advertisement
Image Credit (Auro)
Another competing object-based, 3D audio system is Auro 3D. Developed by Belgium company Auro Technologies and officially introduced in 2006, the format is based upon a three-layer design: surround, height, and overhead.
The key difference between this system and Dolby Atmos comes down to the speaker layout. With Auro 3D, an additional row of speakers is placed above the traditional row found in 5.1 and 7.1 set-ups. This adds the height element. A single speaker is then placed on the ceiling to add the overhead dimension.
Although Auro 3D also creates a spatial sound field, the company doesn’t use the term audio objects as Dolby does. Auro’s plugins allow sound designers to dictate where sounds should originate and move to, and the format can be used in cinemas, at home, and over headphones, just as with Dolby Atmos.
Films such as The Hunger Games, The Croods, and Red Tails have used Auro 3D in the cinema, but it isn’t as popular as Atmos. It has announced that the technology is coming to more soundbar systems, as well as headphones and smart speakers.
Image Credit (Trusted Reviews)
Advertisement
The most recent challenger to Atmos is Eclipsa Audio. It’s based upon the open-source Immersive Audio Model and Formats (IAMF), and as it’s open-source, it’s available for anyone to use without having to pay a royalty, as you would with the technologies mentioned above.
Advertisement
It was developed by the Alliance for Open Media, a consortium that includes Samsung Research, Google and Netflix as an alternative to Atmos, and you can find it supported in Samsung TVs and soundbars, as well as through YouTube and Windows 11.
LG TVs support, but LG Electronics is keen to say that it supports the IAMF codec rather than the Eclipsa Audio branding. It will be coming to TVs from Hisense, TCL, and Philips, strengthening its presence in the TV market.
Atmos and VR
Image Credit (Trusted Reviews)
With virtual reality (VR) able to recreate the way we hear sounds makes all the difference to how immersive a VR experience feels.
All the way back in 2015, Dolby worked with VR content creator Jaunt to add Atmos sound to three of the company’s VR experiences: Black Mass, Kaiju Fury! and video from a Paul McCartney concert entitled Live and Let Die.
Advertisement
Advertisement
Since then, Atmos has been extended to support VR experiences on iOS, Android, OS X, and Windows. The Samsung Galaxy XR supports Atmos, and the Meta Quest 3 supports it through the Disney+ app, the web player and tools such as the HISPlayer for Unreal Engine.
Is Dolby Atmos worth it?
Dolby’s surround sound format has done the heavy lifting in bringing immersive audio to pubic consciousness, but is it worth investing your time and money into the format?
It depends on what you’re going to use it for. In our experience, while it’s good for watching TV, films and playing games in the home, it’s best if you’ve got the requisite equipment, which means having a capable soundbar and surround speakers – otherwise the Atmos effect is only half done.
If you can get surround sound speakers, then you’re getting close to the immersive experience that Dolby wants you have. If you’re not, then you’re only getting half of what Atmos can do. It’s called immersive audio for a reason.
Although lighting 3D prints on fire is rarely the intended outcome, it’s possible that said print will at some point in its future come into contact with either an open flame or a significant source of heat. Once that happens, what will be the result and how worried should one be? This is basically the excuse behind [Maker’s Muse] recent decision to light some 3D prints on fire.
Crispy 3D printed combat robot. (Credit: NHRL)
Materials exposed to an open flame in this experiment included various types of PLA, PETG, ABS, ASA, TPU and PEBA. Since PLA filaments have a significant amount of carbon in them it’s little wonder that these burned quite readily, though an interesting difference was immediately visible between an Elegoo PLA+ test cone and a Prusa Galaxy Black PLA cone. The latter required a blow torch to properly ignite, after which it burned rather hot whilst melting, unlike the dirty yellow flame of the PLA+.
So-called ‘high temperature’ PLA (HTPLA) seems to actively resist burning, self-extinguishing after a blowtorch treatment. Just these few samples of PLA already gave very different results, with very likely the additives being the defining factor since pure PLA is easy to burn as a way to dispose of it somewhat cleanly.
Moving on, black PETG didn’t really want to ignite, while ABS and ASA absolutely love to burn with a sooty yellow flame. HIPS was also tested, burning in a similar sooty manner as well.
Advertisement
Of all the materials tested, TPU was the least flammable with even the blowtorch not able to start ignition and only melting the sample. Foam TPU did however burn the most aggressive, followed by ABS, ASA and HIPS. Overall PETG and regular TPU seem to be your best bet if you do not want your 3D print to turn into a happily burning candle and potentially a general fire hazard.
In a few hours, there is a solar eclipse that will be visible with a track that goes from Spain up through Greenland. Too late to travel for it, but thanks to [jonty], you can find all the webcams that will have a view.
This may be ideal. No funny glasses. No looking at a projected image on a card. Of course, many, if not all, of these cameras aren’t looking directly at the sun, so it isn’t clear if you’ll be able to see the actual eclipse or just the effect it has on the surroundings.
If you prefer more science, try the NASA feed below.
Advertisement
Or, you could see what ESA is broadcasting from Javalambre, Spain:
Or, try the telescope view version:
Advertisement
Want to know what it might look like from a particular spot? Harvard has you covered. If you want to feel more realistic, try wearing some regular sunglasses while watching just for the fun of it.
We wish we could watch our eclipses from the lunar surface. Of course, you can always make your own eclipse.
Social engineering and malware combine to enable financial fraud before banks have time to act
A new social engineering and malware campaign targets Android users, stealing card details to make payments or withdraw cash. Group-IB discovered the campaign, calling it WindRelay, and found that several successful attacks were carried out on European victims within the space of a 13-minute phone call.
The attack relies on a skilled social engineer walking the victim through the process and two malware strains: An NFC relay malware called WindRelay, first discovered in August 2025, and SpyNote, a remote access trojan (RAT) that was leaked on cybercrime forums as far back as 2016.
Advertisement
It goes like this: The attacker calls the target while posing as a helpdesk employee at their bank, convincing the victim-in-waiting that there is a problem with their payment card.
While still on the phone, the attacker gets the target to install a version of SpyNote on their Android device. The file name includes the target’s name, which the researchers said could suggest that each target is singled out specifically, and a degree of reconnaissance has to be carried out prior to the attack.
Once installed, the attacker quickly uses the RAT’s remote access to quietly install WindRelay on the attacker’s device without their knowledge or input, all while the call was ongoing.
The attacker then instructs the target to tap their payment card on their NFC-enabled smartphone and, when prompted, enter their PIN.
Advertisement
WindRelay then captures the data from that interaction between the card’s chip and the reader, similarly to how genuine point-of-sale machines authorize contactless payments. This is known as a live EMV APDU exchange.
In order to fraudulently make payments using this data – without physical access to the payment card or the cardholder – the attacker must have a second device capable of using this data to authorize a payment.
This could be a second Android smartphone capable of loading this data and transmitting it to an attacker-controlled POS terminal, which is linked to a fraudulent merchant bank account, or an ATM.
The attacker then uses the captured live exchange data to execute fraudulent charges on the victim’s card, authorized using the PIN they entered during the call.
Advertisement
Group-IB said in its write-up: “In effect, the victim’s card and the real terminal are still talking directly to each other – the fraudster’s setup is just an invisible relay in between, passing the exchange back and forth across a distance.
“Because the terminal is genuinely completing a live handshake with a real card, the transaction goes through and processes the withdrawal or purchase as normal.”
Doubling down on their access, Group-IB also noted that the attackers in one instance used their RAT access to access the victim’s banking app and take out loans in their name.
The researchers also said they observed 23 WindRelay-related samples uploaded to VirusTotal between November 2025 and July 2026, with signs pointing toward targeting victims in Czechia, Slovakia, and Slovenia.
Advertisement
They were not able to pin down the attacker(s) behind the malware, although they said it was independently developed and the samples they saw uploaded to VirusTotal all contained unique UI elements, such as the victim’s name, just like with the RAT.
“This suggests the threat actor behind these campaigns most likely has the capability to dynamically build malicious applications tailored to individual victims,” said Group-IB.
“This case shows that modern fraud rarely relies on one technique,” it added. “Here, the fraudster combined three capabilities in a single session – a live social engineering call, a personalized RAT for remote device control, and an NFC relay malware for physical cash-out.
“The fraudster also used these capabilities to hit two separate payout channels – a digital loan and card-present purchases – before the bank or victim could react.”
Advertisement
The attack is similar to previous NFC relay-related campaigns, such as NGate in 2024 (and more recently in 2026), and Ghost Tap, the techniques involved in which closely align with WindRelay.
Ghost Tap, also discovered in 2024, relies on a Chinese malware sold throughout the country’s cybercrime Telegram communities, and according to Group-IB, it was responsible for losses exceeding $355,000 between November 2024 and August 2025 alone. ®
Security researchers have disclosed new “Plug and Pwn” attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges.
The research, presented at DEF CON 34 by security researchers Alejandro Hernando and Borja Martínez, exploits how Windows automatically identifies new connected hardware, locates matching driver packages, and installs vendor software as the NT AUTHORITY\SYSTEM account.
By using software to emulate USB devices, the researchers found they could force Windows to install signed vendor packages containing exploitable components or weaknesses that can be abused to gain SYSTEM privileges.
Some of the demonstrated attacks require no user interaction or logged-in user, while another can be performed remotely over RDP without any physical USB hardware being connected to the targeted computer. plugandpwn.com.
Abusing Windows Plug and Play
Windows supports a feature called co-installers, which automatically downloads and installs vendor software and drivers when a new USB device is inserted into a computer.
Advertisement
In 2021, BleepingComputer reported on how this feature was abused along with a Razer Synapse vulnerability to give a standard Windows user SYSTEM privileges simply by plugging in a Razer mouse or keyboard.
When a Razer device was connected, Windows automatically downloaded and launched the Razer Synapse installer with SYSTEM privileges. A flaw in the installer allowed a standard user to launch PowerShell from the installation interface, causing the shell to inherit the installer’s privileges.
BleepingComputer tested the vulnerability at the time and confirmed that it could be used to gain SYSTEM privileges in approximately two minutes.
At the time, vulnerability analyst Will Dormann previously warned that similar vulnerabilities were likely present in other software automatically installed through Windows Plug and Play.
Advertisement
Hernando told BleepingComputer that Plug and Pwn belongs to the same family of attacks, but the new research focuses more on the Windows device installation path itself.
“The Razer bug is the same family. The difference is that we went after the install path itself instead of one vendor’s installer,” Hernando told BleepingComputer.
“Some of our chains need no clicks and no logged-on session, and one of them runs over RDP with no hardware at all.”
The researchers say the main issue is that when Windows detects new hardware, it may automatically retrieve an associated signed package and execute vendor-supplied components as SYSTEM.
Advertisement
This privileged installation path can include co-installers, services, support executables, and drivers, with no UAC prompt displayed by the operating system.
From fake USB devices to remote RDP attacks
The researchers told BleepingComputer that they used FaceDancer with Cynthion and GreatFET hardware connected to a small Linux computer to emulate USB devices.
FaceDancer is a software framework for emulating USB devices, allowing researchers to define the descriptors, interfaces, device classes, and endpoints that a computer uses to identify connected devices.
Connecting hardware running FaceDancer to a computer can make the operating system behave as though a specific USB device had been plugged in.
Advertisement
Using FaceDancer, the researchers could make their hardware appear to Windows as specific USB devices, causing the operating system to recognize the emulated hardware and locate and install the associated vendor driver packages.
Some attack chains also require the emulated device to disconnect and then reappear as a different device identity.
“Several of our chains depend on presenting the device as composite so Windows loads usbccgp.sys and enumerates each interface on its own, which is what makes it match the vendor package instead of the inbox driver,” Hernando explained to BleepingComputer.
“We also need to re-enumerate on demand, dropping the device and coming back as a different identity.”
Advertisement
In their zero-click physical demonstration, the researchers exploited behavior in Sierra Wireless and Sony FeliCa installation packages.
The attack first impersonates a Sierra Wireless device, causing Windows to install software that can be abused to change the computer’s DNS settings.
The researchers then impersonate a Sony FeliCa device, which causes Windows to install additional Sony software that downloads files over an unencrypted connection.
By controlling the system’s DNS settings, the researchers can redirect those downloads to a server they control and exploit a flaw in the Sony software to place a malicious file on the system with SYSTEM privileges.
Advertisement
Finally, they impersonate the Sierra device again, causing Windows to load the malicious file and allow the attackers to open a reverse shell with SYSTEM privileges.
The researchers demonstrated this chain against a fully updated Windows 11 computer with nobody logged in, saying the complete attack takes approximately five minutes.
Plug and Pwn Facedancer attack emulating Sony and Sierra hardware Source: plugandpwn.com
When questioned if this attack can be conducted with small portable devices, Hernando said their research hardware is already portable enough to carry around and that a Raspberry Pi operating in USB gadget mode should theoretically be capable of conducting this attack as well.
However, he said the Flipper Zero cannot currently perform the FaceDancer attacks.
“Flipper Zero, no. There’s no FaceDancer backend for it and the framework won’t run on it,” Hernando said.
Advertisement
“Its BadUSB mode is fine for HID, but arbitrary composite descriptors and re-enumeration would be a firmware project.”
The researchers also demonstrated what they call “NoPlug & Pwn,” which requires no physical hardware emulation.
Instead, the attack abuses RDP USB redirection, a feature that allows USB devices attached to a user’s local computer to be available inside a remote Windows session.
Rather than redirecting an actual device, the researchers created a Python RDP client that sends specific USB descriptors over this USB redirection feature when connecting over RDP.
Advertisement
The remote Windows host then treats the fake descriptors as a legitimate USB device connected to the guest computer, creates the corresponding Plug and Play device on the host, causing the corresponding drivers and vendor software to be installed.
In the researchers’ demonstration, they impersonated an Intel RealSense camera whose Windows Update package contains a co-installer that can be abused through DLL hijacking to obtain SYSTEM privileges.
“The server’s USB hub driver enumerates our phantom device, and Windows PnP does exactly what it did in the physical demo: it matches the hardware ID and installs the driver, as SYSTEM,” the researchers explain on the Plug and Pwn site.
The RDP attack only works on systems where USB redirection is enabled, which Hernando says is common in virtual desktop environments.
Advertisement
Disabling co-installers helps, but does not stop Plug and Pwn
Will Dormann suggested that Windows administrators concerned about this type of attack can enable the ‘DisableCoInstallers’ registry value, which prevents driver packages from executing co-installers during device installation.
To do this, open the Registry Editor and navigate to the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Device Installer Registry key.
Under that key, add a DWORD-32 value named DisableCoInstallers and set it to 1, as shown below.
When BleepingComputer asked whether this would effectively block Plug and Pwn, Hernando said it would disrupt some of the demonstrated attacks, including the Sony FeliCa attack and the Intel RealSense RDP attack.
Advertisement
However, it does not eliminate the underlying attack surface.
“It helps, and it would break parts of what we showed,” Hernando told BleepingComputer.
“It doesn’t stop the class of attack, though. It leaves PnP enumeration, Windows Update resolution, driver staging, INF processing and INF-installed services untouched.”
The researchers illustrated this with another attack using Wacom and Atheros packages that exploits a vulnerability (CVE-2019-10617) in an Atheros driver service installed through an INF file rather than a co-installer.
Advertisement
Hernando recommends that organizations with sensitive systems use ‘DisableCoInstallers’ along with additional device blocking.
“In anything sensitive I’d pair it with device installation restrictions or hardware-ID allow-lists, and turn off PnP device redirection on RDP and VDI hosts that don’t need it (`fDisablePNPRedir`),” Hernando told BleepingComputer.
The researchers have not reported all of the attack scenarios as new vulnerabilities to individual vendors, saying that many are not standalone security flaws and only become exploitable when combined with other functionality.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Looking ahead: Sunlight has been used to generate entangled photon pairs, offering an early look at how quantum technology could reduce its reliance on power-intensive lasers. Researchers at the University of Ottawa and the Max Planck Institute for the Science of Light in Erlangen, Germany, used focused sunlight to produce entangled photons, which are essential to many photonic quantum computing and quantum communications systems.
The research, which was published in Optica, does not suggest that sunlight can replace laser-based quantum sources. Those systems remain more precise and produce stronger results. But the study shows that the light used to create entangled photons does not necessarily have to come from a laser, challenging the long-standing assumption that it does.
Entangled photons are pairs of light particles with linked quantum properties. Measuring one particle can reveal information about the corresponding measurement of the other, even when the two are separated. That behavior makes entangled photons useful for quantum encryption and other forms of quantum information processing.
Most systems generate these pairs through spontaneous parametric down-conversion. In that process, a laser shines through a special crystal, producing photons with correlated quantum properties. Researchers have favored lasers because they generate coherent light, meaning the waves maintain a consistent phase and typically operate within a narrow range of wavelengths.
Advertisement
Sunlight is not coherent. It contains many wavelengths and reaches Earth from different directions, making it seem like an unlikely candidate for generating entangled photons.
The Ottawa and Max Planck researchers had previously explored the question through theoretical work and experiments using light-emitting diodes. Their work suggested that incoherent light could generate entanglement if the relevant quantum property did not depend on the light’s wavelength or direction.
Experimental setup for generating polarization-entangled photon pairs with sunlight. The solar concentrator is at right; the photon source and electronics are housed in a light-blocking tent at left. Inset: The source’s optical components and avalanche photodiodes.
For the solar test, the researchers needed to concentrate sunlight tightly enough to direct it into a small crystal. Hanieh Fattahi’s team at the Max Planck Institute built a glass, cone-shaped concentrator that collected light from a window-sized Fresnel lens and funneled it into a thin optical fiber.
Advertisement
The team tested the system outdoors at the institute over three days. The resulting photon pairs achieved about 94% fidelity with a perfectly entangled state. The experiment also violated Bell’s inequality, a test that helps establish whether correlations between particles are genuinely quantum rather than explainable by classical physics.
The Bell violation was limited, which the researchers partly attributed to weak seasonal sunlight and passing clouds. The entanglement quality also did not match the best results from laser-driven systems. Cheng Li, who co-led the research as a graduate student at the University of Ottawa and is now at Lawrence Berkeley National Laboratory, said the shortfall was likely caused by distortions in the optical components rather than the nature of sunlight itself.
He called it a proof of principle.
The researchers are now working to improve the brightness of the source and the quality of the entanglement. A more capable system could eventually be used outside the laboratory, including in remote locations or on satellites.
Advertisement
That prospect is part of the technology’s appeal. Laser-based systems require electricity, stabilization, and cooling, while much of their energy is lost as heat. A source powered directly by sunlight could eliminate the electrical-to-optical conversion step.
Li said satellite systems could one day use the sunlight already available in orbit to produce quantum encryption keys. The idea remains far from deployment, but the experiment points to a different approach to building quantum infrastructure.
You must be logged in to post a comment Login