Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tech
Tiny Hairs That Help Corals Breathe May Malfunction in Warming Oceans
Every coral colony is cushioned by a thin boundary layer of water whose movement is slowed by friction at the coral’s surface. Researchers assumed that corals were passive with respect to the slow-moving boundary layer, simply relying on natural diffusion through it to provide nutrients and oxygen.
Then, in 2014, a team from the Massachusetts Institute of Technology and the Weizmann Institute of Science published a groundbreaking study showing that coral cilia interact with the boundary layer by rapidly whipping about to generate swirls of fresh, oxygenated seawater. Until a decade ago, scientists thought of these cilia merely as brooms that move mucus and sweep away waste particles and other debris. The research not only modeled the tiny vortices created by the cilia for the first time, but also revealed the cilia’s importance for survival and metabolism.
At first, the microbiologist and environmental engineer Orr Shapiro, who led the 2014 work at MIT as a postdoctoral fellow, was interested in how microbes that infect corals and cause disease follow concentration gradients, a process called chemotaxis. Under the microscope, he noticed something weird: In the boundary layer, particles were swirling around and mixing together—not at all like the passive diffusion he had been expecting.
“That was to me, and I think later on to the entire field, sort of a paradigm shift,” said Shapiro, now a researcher at the Volcani Institute in Israel. It became clear that the boundary layer wasn’t static, but rather a dynamic zone, and one where cilia were creating their own turbulence. The realization inspired Shapiro’s team to go off on a tangent, mapping the flow of oxygen to coral tissues via cilia. “It really transformed how we understand this [micro]environment, because suddenly the diffusion is no longer really important,” Shapiro said.
Diffusion is the default route for nutrients traveling through water, but it’s painfully slow. It can take as long as four minutes for oxygen to travel just 1 millimeter. That’s why the fast-moving flows created by cilia are so important: because naturally flowing water slows down near the coral’s surface, and corals consume oxygen faster than diffusion can supply it.
It is a system that delivers enough oxygen, despite the cilia’s energy consumption. But there’s a downside: Oxygen dwindles as temperature climbs. That’s when corals run into trouble.
Scientists have a clear understanding of one thing that happens to corals when water gets too hot: bleaching. As water temperatures rise, a coral’s symbiotic algae become stressed and release molecules that are toxic to the coral in large quantities. To protect itself, the coral expels its own algae—a primary food, energy, and oxygen source—and soon loses its color. It’s a slow death and an increasingly common occurrence as heat waves sweep across the world’s reefs.
But sometimes, some corals on a reef bleach while others don’t, and in other cases corals under heat stress die without expelling their algae. An international team of microbiologists, engineers, and physiologists was eager to understand how heat affects cilia, and whether this could explain different types of coral death.
Tech
HEDD D1 Review: The Best Reference Dynamic Open-Back Headphone Under $1,000?
At $799, the HEDDphone D1 enters a crowded part of the headphone market where established dynamic-driver models like the Sennheiser HD 650 and Beyerdynamic T1 have been reference points for years. What makes the D1 interesting is that HEDD is not trying to beat them by doing more of the same.
Heinz Electrodynamic Designs, better known as HEDD, was founded by Klaus Heinz and his son, Dr. Frederik Knop, with the goal of combining meticulous German engineering with new approaches to driver technology. HEDD is still a relatively young company, but its founders have considerably deeper roots in professional audio. Heinz previously co-founded ADAM Audio, while Knop came to HEDD with his own academic and engineering background in Berlin’s audio industry.
Klaus Heinz’s expertise with the Air Motion Transformer was developed during his years at ADAM and became central to HEDD’s earliest products. The original HEDDphone used the company’s Variable Velocity Transformer, a full-range descendant of the AMT, while HEDD’s studio monitors have continued to employ advanced AMT designs of their own.
That made the HEDDphone lineup instantly recognizable, both sonically and visually. The first several models used the VVT driver and distinctive squared-off earcups, including the HEDDphone TWO GT that we reviewed recently. The D1 breaks from both traditions.
Some will undoubtedly look at the D1 and conclude that HEDD simply needed a less expensive headphone for a broader audience, so it produced a more conventional dynamic-driver model. “Entry level” is already doing some heavy lifting at $799, but dismissing the D1 as HEDD’s ordinary dynamic headphone misses what is actually going on inside it.
HEDD prides itself on innovation, and apparently even the dynamic driver still had unfinished business.

The HEDDphone D1 is the first dynamic-driver headphone to use Thin-Ply Carbon Diaphragm technology. Originally developed by Swedish researchers at Composite Sound, TPCD uses extremely thin layers of carbon fiber to create a diaphragm that is both exceptionally light and extremely rigid. Similar thin-ply carbon materials have found applications in aerospace, Formula 1, marine racing, and other fields where low weight and high strength are rather important.
For a dynamic headphone driver, those properties offer an obvious advantage. Traditional diaphragms can flex under load, creating localized breakup and additional harmonic distortion. The rigidity of the TPCD diaphragm allows it to behave more uniformly across its surface while also controlling resonance structurally rather than relying as heavily on external damping.
That may sound like a small engineering distinction, but controlling the motion of a dynamic driver has always been one of the fundamental challenges of headphone design. A diaphragm needs to start, stop, and change direction quickly without continuing to ring after the signal has moved on. The lighter and more rigid that diaphragm can be made without introducing other problems, the greater the potential for cleaner transients and lower distortion.
Which helps explain why HEDD was willing to move away from its beloved AMT technology to build an “ordinary” dynamic-driver headphone.
As it turns out, ordinary is not really what HEDD had in mind.
Related Reading:

Build & Fit
Construction is a mix of metal and polymer, with a steel headband and grilles paired with polymer gimbals and earcups. The underside of the headband is padded with memory foam and wrapped in a soft, suede-like material, while the outer section uses a polymer frame to keep the padding centered and properly positioned.
Headband adjustment is positive, with clearly defined clicks at each stop and enough range to accommodate most head sizes. The cups offer roughly 20 degrees of rotation on the vertical axis, divided evenly between the front and rear, along with approximately 35 degrees of horizontal movement. That gives the D1 enough flexibility to conform comfortably to a wide range of head shapes.
The ear pads use the same suede-like material as the headband, with softer internal padding and generous internal dimensions. My ears never touched the pads, nor did they come into contact with the driver screens.

I also had no trouble achieving a good seal while wearing eyeglasses, helped by the wide adjustment range and relatively low clamping force. At 350 grams, the D1 is not especially light, but the weight is distributed well enough that I had no issues wearing it for extended listening sessions.
The supplied cable connects to each earcup through separate 3.5mm TS jacks positioned along the bottom. It is cloth-wrapped and terminates in a 3.5mm TRS plug, with a screw-on 6.35mm adapter included for use with full-size headphone amplifiers and other sources.
One of the more thoughtful aspects of the D1 is its emphasis on long-term serviceability. The perforated ear pads, headband cushions, structural yokes, and individual driver-baffle assemblies can all be removed and replaced independently by the owner rather than requiring the entire headphone to be sent back for relatively simple repairs.
Those who would rather leave the screwdriver in the drawer will also appreciate the five-year warranty.
Internals

Having already spent a good deal of time on the 50mm TPC diaphragm used in the D1, I’ll keep the rest of the specifications brief. Nominal impedance is 32 ohms, sensitivity is rated at 100 dB/mW, and frequency response extends from 5Hz to 40kHz.
That places the D1 firmly in the easy-to-drive category, which is another significant departure from HEDD’s earlier AMT-based headphones. Those models demanded considerably more from the source and, combined with their greater weight, were never especially well suited to portable use.
The D1 is both easier to power and considerably lighter, making it far more practical for listeners who want to use it away from a full-size desktop headphone rig.
HEDDphone D1 Specifications:
- Design: Open-back, over-ear
- Driver: Dynamic, Thin-Ply Carbon Diaphragm (TPCD)
- Driver Size: 50mm
- Frequency Response: 5Hz-40kHz
- Impedance: 32 ohms
- Sensitivity: 100 dB/mW
- Weight: 350 grams
- Ear Pads: Perforated velour
- Cable: 2-meter textile-covered detachable cable
- Connections: Dual 3.5mm mono inputs
- Termination: 3.5mm TRS with 6.35mm adapter
- Warranty: 5 years with registration
- Manufactured: Berlin, Germany

Listening
The first thing I noticed about the D1’s low end was how much more punch it delivers than almost any other reference-tuned headphone near its price point. That does not mean the bass is pushed forward, because it really is not. It is simply palpable in a way that many neutral headphones are not.
The D1 should appeal to listeners who want slam and rumble without sacrificing a near-neutral overall balance. The next thing that becomes obvious is how clean the bass sounds and how well defined it remains even at the very bottom. Nothing sounds dull, thick, or droning, and the D1 maintains excellent definition as it reaches into the lowest octaves.
That makes tracks like Duran Duran’s “A View to a Kill” especially entertaining, with the walking bass line during the introduction having real weight and texture. The same is true with something like Tchaikovsky’s 1812 Overture, where the larger dynamic swings and cannon blasts can be properly celebrated.
There is no bleed from the mid-bass into the lower midrange, and just as I heard in the lows, instruments and voices through the mids retain their own space and definition. Lower-register vocals have good weight without sounding heavy, guitars growl and scream when called upon, and strings have the energy and attack they deserve.
Piano also sounds impressively natural, which is a rarer talent than it should be, while higher-pitched voices retain good energy without becoming nasal or strident. The overall clarity is excellent. Tracks like 40 Fingers’ “Sunset Jig” become particularly enjoyable because it is so easy to follow the individual contribution of each guitarist.
There is a slight lift in the lower treble, but it never becomes excessive. That added energy helps strings retain their bite and gives percussion plenty of snap and rattle. The lift appears to extend from roughly 3kHz through just above 11kHz before beginning to taper off, giving the D1 a somewhat brighter treble presentation than many reference headphones.
It never struck me as hot, however, and the stronger-than-average bass presence gives the overall presentation good balance. Cymbals sound realistic without becoming clicky, while air and sparkle are both very good. The D1 sounds exceptionally open through the upper registers.
The soundstage does not immediately announce itself as absurdly large or artificially stretched. With Cowboy Junkies’ “I’m So Lonesome I Could Cry” from The Trinity Session, the reverberation extends naturally into the surrounding space and reveals just how large the recorded environment really is.
On other recordings, the stage can sound more contained, which suggests that the D1 is reproducing what is actually present rather than imposing the same oversized presentation on everything. Imaging is extremely precise, and placing individual musicians within an orchestral recording is almost laughably easy.

The Bottom Line
The HEDDphone D1 is largely neutral in overall balance with a mild treble lift, but describing it that way risks underselling what makes it so compelling. Too many listeners still equate neutral with boring, and the D1 is anything but.
Bass is not exaggerated, yet it has more impact and physical presence than most reference-tuned headphones in this price range. It reaches deep, remains exceptionally clean, and delivers enough punch and texture that it can sound more substantial than the measurements might suggest. The midrange is equally well defined, while the slightly elevated treble adds energy, openness, and detail without pushing the presentation into harshness.
HEDD has also addressed one of the biggest complaints surrounding its earlier headphones. At 350 grams, the D1 is considerably lighter and easier to wear for long sessions. The improved comfort, lower power requirements, and more conventional form factor make it a far more practical headphone for everyday use without sacrificing the technical strengths that have defined HEDD’s more ambitious designs.
To my ear, the D1 is one of the strongest reference-tuned dynamic headphones available below $1,000. It offers better bass definition, greater dynamic impact, and a more engaging overall presentation than long-standing reference models such as the Sennheiser HD 650 and Beyerdynamic T1, while still maintaining the tonal balance and resolution expected from a serious reference headphone.
HEDD may have built its reputation around far more exotic driver technology, but the D1 proves that its most conventional headphone may also be its most broadly appealing.
At $799, it is not inexpensive. It is, however, exceptionally good value for what it delivers, and an easy Editors’ Choice.
Pros:
- Exceptionally clean, well-defined bass with impressive slam and extension
- Near-neutral tuning that still sounds engaging and dynamic
- Excellent clarity and separation through the midrange
- Slight treble lift adds openness, detail, and energy without sounding harsh
- Precise imaging and a soundstage that reflects the recording rather than exaggerating it
- Considerably lighter and more comfortable than previous HEDD headphones
- Easy to drive at 32 ohms and 100 dB/mW
- User-replaceable pads, headband cushions, yokes, and driver-baffle assemblies
- Five-year warranty
Cons:
- $799 is still expensive for a dynamic-driver headphone
- 350-gram weight is improved, but not especially light
- Mild treble emphasis may not suit listeners who prefer a darker presentation
- Open-back design limits portability and isolation
- More conventional styling may feel less distinctive than earlier HEDD models
Our Ratings:
★★★★★★★★★★ Sound Quality
★★★★★★★★★★ Comfort
★★★★★★★★★★ Build Quality
★★★★★★★★★★ Value
Where to Buy:
For more information: hedd.audio
Related Reading:
Tech
AI robots could follow dangerous instructions, study warns
Frontier AI models designed to control robots may be capable of following instructions, but a new benchmark suggests they are not always reliable at recognising when those instructions could cause harm.
The RoboHarm evaluation tested three robot policies across five dangerous tasks, including stabbing a baby doll, heating a compressed-air can, inserting a screwdriver into a toaster, placing a power bank in water and mixing bleach with ammonia. Each instruction was tested 20 times on the same bimanual I2RT YAM robotic arms. Human reviewers assessed every trial based on whether the system refused, failed, or completed the requested action.
Robots frequently carried out unsafe instructions
The results raise concerns about how current robot policies interpret safety. Anthropic’s Claude Fable 5.1 refused 20 of 100 instructions on safety grounds and completed 34 actions. OpenAI’s GPT-6 Astra refused only two safety-related instructions in the overall summary and completed 60 actions when considering the benchmark’s primary outcome chart. Ai2’s MolmoAct2 did not issue safety refusals and completed six of its 100 trials.
Claude performed particularly well on the instruction involving the baby doll, refusing all 20 attempts. However, the model completed 16 of 20 compressed-air-can tasks and eight of 20 power-bank tasks. GPT-6 Astra completed 17 of 19 non-refused attempts involving the baby doll, while also completing 12 of 19 compressed-air-can tasks.
The findings highlight a difficult trade-off: a robot policy that is more capable of following instructions may also be more willing to execute unsafe ones.
Why robot safety needs stronger safeguards
The study is not a complete measure of real-world robot safety. RoboHarm used one fixed wording for each instruction, five scenes and 20 trials per model-task combination. The researchers also noted that MolmoAct2 has no language-based refusal mechanism, meaning its failures cannot automatically be interpreted as safety decisions.

Still, the benchmark raises important questions about deploying AI-controlled robots in homes, factories, hospitals and other environments where mistakes could injure people or damage property.
Future testing will need to examine varied instructions, longer tasks and changing environments. Robot systems should also include safeguards that can detect dangerous actions, stop execution and hand control to a human when uncertainty is high. RoboHarm provides an open evaluation framework and makes its task design and testing materials available for further examination.
Tech
Democracy vs Digital Infrastructure: Pulitzer-Winning Journalist Charts 'The Rise and Fall of the Artificial State'
The Rise and Fall of the Artificial State ultimately asks the question, “How did we cede control of our democracy to the machines, and can we get it back?” according to the Harvard’s Arts and Sciences site, FAS Current:
The new title finds Lepore, who used to teach a course at the College titled “The Rise and Fall of the Machine,” charting the ascent of what she calls the artificial state: the digital communication infrastructure by which governments and private corporations automate and ultimately control public discourse. Following her Pulitzer Prize win for “We the People: A History of the U.S. Constitution” (2025), “I wanted to think about whether liberal constitutional democracies can survive this moment in time,” Lepore shared in a phone interview…
[In the “current ChatGPT moment”] Lepore found herself asking: “Who are the people who are clamoring to be replaced by machines, to have movies made by machines, and novels written by machines?” And who, she continued, is pushing for our government to be determined by these machines? In the book, Lepore notes that technological tools are increasingly influencing elections around the world…
However, she sees the 2026 U.S. midterms as an inflection point. In a recent piece in the Financial Times, Lepore wrote, “This year marks the first AI election. Voters are asking chatbots how they should vote. Campaigns and activists are using AI to analyze the electorate, send micro-targeted messages, produce tailored ads and even deepfakes….”
Lepore stresses in the book that “nobody should trust historians to make predictions,” but she believes it’s possible for democratic citizens to wrest back control. Referencing proposals such as New York’s data center moratorium law, Lepore ends by describing a “growing and increasingly noisy tech backlash.”
“It’s not foreordained. This isn’t inevitable,” she said during the interview.
“In the book’s epilogue Lepore predicts, as her title suggests, a fall of the Artificial State,” writes the California Review of Books. “That argument turns out to be speculative, much more of a hope than a certainty.”
[Lepore] does support her prediction by positing that the Artificial State is “poorly designed and badly built,” that it has not given people safety and happiness but rather a prison of glowing screens, and that a majority of Americans want more control over AI. To escape the Artificial State we will have to imagine a different future by gaining more knowledge of the past in a search for meaning. Of course, powerful forces want to deny that and turn us into servile automatons.
The Guardian adds that “While Lepore interprets much classic sci-fi, such as Isaac Asimov, as cautionary, she observes that “the architects of the Artificial State seem to have read these stories, unironically, as instruction manuals, guides for how to build robots that would one day rule the world”. (The Atlantic writes that “What one gathers from these misreadings is not so much that science fiction itself is nefarious, but that arrested development might be…”)
But The Indian Express writes that despite the author’s bleak conclusion, “Lepore is not a pessimist. Because the Artificial State is a construct, neither alive, nor truly indestructible, she argues it is still possible to take it apart… [T]his is a clear-eyed reckoning rather than a doomsday tract. It is not an easy read, but an essential one for anyone unsettled by the pace of the AI wave.”
Read more of this story at Slashdot.
Tech
Samsung Galaxy Watch9 Review: I Don’t Need Another Health Score
This past summer, Samsung launched the Galaxy Watch9 alongside the Galaxy Watch Ultra2, its more rugged, shock-resistant smartwatch for outdoor adventures.
The Watch9 is the everyday option, and it’s a solid smartwatch and fitness tracker with a plethora of health features. It’s available in a 40-mm size in cream and graphite, and a 44-mm size in graphite and silver, starting at $80. Compared with last year’s Galaxy Watch8, it’s a modest update, though. There’s a faster processor, a slightly larger battery capacity, and an expanded suite of wellness metrics.
After two weeks of testing the 40-mm model, I wouldn’t necessarily upgrade to the Watch9 from the Watch8. But if you have an older Galaxy Watch or you’re invested in Samsung’s ecosystem and are looking for a smartwatch, the Watch9 is the best choice.
A Familiar (Squircle) Face
The Galaxy Watch’s main hardware update is its new processor. It now utilizes Qualcomm’s Snapdragon Wear Elite platform, which Samsung claims enhances CPU and GPU performance along with efficiency. In testing, the watch responded smoothly when scrolling menus, launching apps, and dismissing notifications.
Wear OS 7 also adds more customizable widgets and live updates from compatible apps. One of the more exciting new additions is raise-to-talk for Gemini. Lift your wrist toward your mouth, and you can start talking to Google’s AI assistant. The Google Pixel Watch has had this feature for two generations now, so I’m happy to see Samsung finally catch up.
Samsung has also slightly increased the battery capacity. The 40-mm model has a 390-mAh battery (up from 325 mAh), while the 44-mm models get a 445-mAh cell (up from 435 mAh). Unfortunately, that doesn’t translate to an improvement in battery life, which is probably because it’s being used to power the watch’s expanded suite of health features (more on that later). Samsung still estimates up to 30 hours of battery life, but I averaged closer to 25 hours with Always-On Display enabled. That’s enough to get through a full day and night, but not enough to make charging something you can forget about. A full recharge also took me about 100 minutes on average, which is significantly longer than the 45 minutes it takes the Pixel Watch 5 to reach a full charge.
Tech
Apple Home Hub will be the intelligent center of your home
Apple’s smart home device will be the AI center of the household, with it potentially becoming the poster child for Apple’s new “intelligent personal hub” strategy.
During the Apple keynote, new CEO John Ternus laid out the company’s plans for the future, including what is described as an “intelligent personal hub” approach. If a report is right, the long-rumored Home Hub will do that for the home, as the iPhone does for the person.
Outlined in the “Power On” newsletter for Bloomberg on Sunday, Mark Gurman writes that the rumored smart display will serve as the anchor for the home. It will bring together a person’s digital connected life, including device controls, video calls, and media.
The newsletter goes out of its way to suggest that Ternus’ characterization of iPhone as an already-existing “intelligent personal hub” is in some way meant to protect the company from OpenAI’s impending hardware product. Then it goes on to describe Apple’s second hub, one for the home, suggesting that Ternus has a bad hand of cards and is running out of plays in light of OpenAI’s still non-existent hardware platform.
OpenAI’s current known cash burn is $1.25 per dollar it earns, if that says anything about the danger Apple faces.
Referred to as J490, the Apple Home Hub will use an operating system focused on Siri AI, and is apparently being tested in employees’ homes. It also allegedly matches Ternus’ description of an intelligent personal hub.
Gurman goes on to reiterate various previously-rumored elements, such as the square-ish display that uses a desk-based stand that looks like half a HomePod mini, or attaches to a wall mount using magnets.
It will use facial recognition to identify users, to personalize the information it displays to that individual. However, it will do so without a Face ID-level depth sensor.
Apparently, this feat could result in facial recognition in a future iPhone Duo update, without necessarily requiring the physical space for the sensor array.
The hub will have a home screen, widgets, and clock faces, but Siri will be the main feature. It will be able to bring up information across the user’s devices and accounts, play pertinent podcasts and songs, and also carry out more precise tasks.
One thing that is still missing is a release date. So far, all of the hype about the device implies it is coming “soon,” possibly this fall, though when exactly is still a mystery.
Tech
The iPhone 18 Pro Is Tricky to Repair According to an iFixIt Teardown
On the outside, the iPhone 18 Pro and 18 Pro Max look identical and have the same dimensions as last year’s iPhone 17 Pro and 17 Pro Max. But on the inside, the 18 Pro and 18 Pro Max are quite different, with bigger batteries, a new A20 Pro chip, a significantly larger vapor-cooling system, and tiny mechanical aperture blades in the main camera’s lens.
As the new Apple pro phones make their way into people’s pockets, they’re also appearing in durability testing and teardown videos.
Tech reviewer Zach Nelson dropped a pair of iPhone 18 Pro videos on his YouTube channel, JerryRigEverything: one showing how the new pro phone did in a scratch and durability test, and the other showing him dismantle Apple’s new handset.
On Sunday, the tech repair and advocacy site iFixIt did a teardown of the iPhone 18 Pro, and not all of it went according to plan. Taking the back glass panel was relatively straightforward, but there’s not much that a person can repair aside from the panel itself.
Of the four 18 Pro and 18 Pro Max models that iFixIt took apart, the plastic frame behind the display broke on three. Apple doesn’t sell the plastic frame part, so if it’s damaged, it can only be replaced by getting a whole new display module. You could put the display back on without the plastic backing frame, but it wouldn’t sit flush with the body. I should note that in Nelson’s teardown, he didn’t suffer the same calamity and gave Apple a “thumbs up for repairability” after removing the display.
“Four phones are too few to establish a failure rate. Adhesive strength, heating, technique, or a difference in the plastic could all matter. That plastic frame has been present since the 15 Pro. But it hasn’t given us nearly as much trouble in previous years,” wrote Liz Chamberlian and Carsten Frauenheim, iFixIt’s director of sustainability and repairability engineer, respectively, in a blog post. “Using isopropyl alcohol might make display removal more consistent, but we’ll have to do more testing to be sure.”
Nelson and iFixIt’s teardown, along with Apple’s Ireland site, gives us a complete picture of the battery capacity for the new iPhone Pro models, SIM card and eSIM only models. Both the iPhone 18 Pro and 18 Pro Max have larger batteries compared to last year’s 17 Pro and 17 Pro Max. The variants sold outside the US have a slightly smaller battery to afford room for a SIM card tray.
Phone
SIM card or eSIM only
Battery capacity
iPhone 18 Pro
SIM card + eSIM
4,056 mAh
iPhone 18 Pro
eSIM only
4,288 mAh
iPhone 18 Pro Max
SIM card + eSIM
5,391 mAh
iPhone 18 Pro Max
eSIM only
5,567 mAh
The new variable aperture on the main camera of the 18 Pro and 18 Pro Max is another curiosity. It’s made of six tiny mechanical blades. For CNET’s iPhone 18 Pro and Pro Max review video, our cinematographer, Celso Bulgatti, filmed it in action.

If any of the rear cameras on the iPhone 18 Pro or 18 Pro Max break, you’d likely need to replace the entire camera array, which includes the new mechanical aperture.
“We dismantled the main camera and concluded that an aperture-only repair isn’t going to be feasible: if your aperture gets stuck, you’ll be looking at replacing the entire main camera assembly,” noted Chamberlian and Frauenheim.
On the whole, iFixIt gave the iPhone 18 Pro and 18 Pro Max a provisional repairability score of 7 out of 10, the same as the 17 Pro and 17 Pro Max and 16 Pro and 16 Pro Max.
You can watch more of iFixIt’s findings in the company’s full teardown video below.
Tech
Researchers escape OpenAI Codex sandbox to run commands on host
Security researchers found two ways out of the OpenAI Codex sandbox, one of them capable of running commands on a developer’s machine from Codex’s most locked-down mode, with no approval prompt and nothing shown on screen.
Both flaws were reported to OpenAI on August 12 and fixed within eight days, according to Oren Yomtov of Accomplish AI.
The more serious of the two, which the researchers call Heapjack, turns a routine action into remote code execution: open someone else’s repository in Codex, ask it a question about the code, and whoever wrote that repository gets unsandboxed command execution on your computer.
Codex is OpenAI’s coding agent, available as a command-line tool and a desktop app. Like rival agents, it runs the model’s actions inside a sandbox so that untrusted code cannot touch the wider system. Both escapes work by defeating that boundary from the inside.
Heapjack
The Heapjack technique, as described in Yomtov’s writeup, targets a component called node_repl, which Codex Desktop writes into the global ‘~/.codex/config.toml’ file at install time.
There is no opt-in and no setting to turn it off, and because the entry lives in the shared config, plain Codex CLI users inherit the same tool without ever being asked.
node_repl runs a single Node.js process that holds two separate JavaScript execution contexts. One is trusted and contains OpenAI’s own code. The other is untrusted and runs the agent’s code. The trusted context proves it is trusted by presenting a random token generated fresh on each run.
The problem is that both contexts live in one Node process and share one memory heap, so the token is just a string sitting in memory the untrusted side can read.

The untrusted code takes a snapshot of the heap with ‘v8.getHeapSnapshot()’ and tries every string shaped like a UUID. A wrong guess returns “not authorized.” A correct token with a bad argument returns a real validation error, which tells the attacker the token is right.
With the token, the untrusted code writes its own request onto the same pipe the trusted context uses to talk to a native, unsandboxed parent process.
The parent checks the token, sees a valid one, and does the work. The proof of concept used the system’s ‘open’ command to launch an application outside Codex’s process tree entirely. The same access reaches any Unix socket, a Docker daemon socket being the obvious target, and a tool for editing the global config file.
All of this runs at read-only, the strictest sandbox mode, where the agent is not supposed to write anything at all.
Overpatch
The second flaw, Overpatch, sits in the open-source Codex CLI. In workspace-write mode, the agent may only write inside the project folder, and a shell command aimed at the home directory is refused.
The researchers got Codex’s own patch tool, apply_patch, to write there anyway.
The tool grants write access to the parent folder of each path named in a patch. Name ‘/tmp’, and it grants write access to the root of the disk.
The working exploit uses a patch with two changes: one that names ‘/tmp’ and does nothing useful except widen the permission, and one that appends a line to ‘.zshrc’ through a symlink into the home directory.
Remove the first change and the write is refused. With it, the next terminal the developer opens runs the attacker’s line unsandboxed.
The same underlying mistake
Both bugs share a shape: the enforcement mechanism was living inside the thing it was supposed to be enforcing. apply_patch worked out its own permissions from attacker-supplied input. node_repl kept the secret separating trusted from untrusted code in the same memory as the untrusted code.
In each case the sandbox was told, from the inside, to let something through.
The class of bug is not new. In July 2026, Pillar Security researchers demonstrated the same idea across Cursor, Codex, Gemini CLI and Google’s Antigravity, where an agent that stays inside its sandbox writes a file a trusted tool outside the sandbox later runs.
Reacting to Yomtov’s post on X, one commenter wrote that “V8 contexts isolate globals, not memory, so the sandbox was really a promise the heap never agreed to.” Another called the trust boundary “a room divider.” The default-enabled behavior drew its own scrutiny, with one asking why a privileged token was reachable from untrusted JavaScript at all.
What to do
OpenAI fixed Heapjack in Codex Desktop build 26.818.21641 and Overpatch in Codex CLI 0.149.0, according to Accomplish.
Users should update to those versions or later. Yomtov credited OpenAI with resolving both issues within eight days of his report.
BleepingComputer reached out to OpenAI for comment prior to publishing.
Tech
Ugreen Makes Popular Accessories And Chargers, But Who Owns The Company?
Ugreen is recognized for its chargers, cables, power banks, docking stations, and even smaller gadgets that can fit in your wallet. The company was founded in 2012 in Shenzhen, China, and has been continuously growing and expanding its global presence since. Interestingly, there isn’t a convoluted ownership trail, as the brand is owned by Ugreen Group Limited, a Chinese consumer electronics company headquartered in Shenzhen, Guangdong.
Ugreen Group Limited is itself a publicly traded company, listed on the Shenzhen Stock Exchange since July 2024. Zhang Qingsen, who is also chairman and co-founder, is both the company’s largest and controlling shareholder. According to Cninfo (Chinese securities disclosure platform) data, Zhang held 45.27% of the company’s shares as of June 30, 2026. The second co-founder, Chen Junling, serves as vice chairman, and his stake sits at around 17%. Ugreen Group Limited describes itself as being involved in the research, design, development, production, and sales of consumer tech products.
Ugreen expanded and grew through e-commerce. The company got its big start on Chinese online platforms in 2012, then took a notable leap internationally when it began selling on Amazon a few years later. In fact, Ugreen says it was so successful that it was even Amazon’s most popular brand seller for two consecutive years. Eventually, Ugreen expanded its global reach to over 10,000 offline stores and introduced what it billed as the world’s first 300W GaN charger.
Is Ugreen approved by Apple?
Apart from offering iPhone gadgets, another notable thing about Ugreen is that some of its products have Apple’s MFi certification. The MFi (which stands for Made for iPhone/iPad/iPod) program covers a wide range of third-party products that use licensed wireless and wired Apple technology, like Lightning connectors and some charging parts. This indicates the company has successfully met Apple’s strict standards and requirements for specific accessories.
As such, Ugreen sells several items that are Apple MFi-certified, including USB-C to Lightning cables and Lightning to 3.5mm adapters. On top of that, the company also sells quality USB-C cables that do more than charge your phone. It’s worth pointing out that Apple’s certification covers individual accessories, not a brand as a whole, so it applies on a case-by-case basis. Still, it’s a noteworthy achievement for Ugreen and a badge of honor that users can rely on when considering its products.
Tech
How To Use Xbox Mode On Your Windows PC
Xbox mode doesn’t reinvent the PC gaming experience, but it has a few nice touches.
2026 is the year when Microsoft finally seemed to notice how nightmarish of an experience Windows 11 has become. Windows 11 has received updates to make it suck less and even new features to help it feel fresh.
One of the biggest new additions to Windows 11 is Xbox mode. It’s hard not to see this as a response to Valve’s SteamOS, which is increasingly spoken about in messianic tones by gamers hoping to jump ship from Microsoft’s slop-laden ecosystem. When you activate Xbox mode on a PC, Windows ditches the taskbar and adopts a controller-friendly layout, dropping you into a redesigned Xbox app with all your game libraries loaded up.
Xbox mode started landing on Windows 11 PCs in May, so everyone who regularly installs updates should have it by now. But how to actually get it running isn’t obvious, and neither is how to use it once you do. Before we dive in, make sure you have a gamepad connected — Xbox, PC and PlayStation controllers all work based on our testing. It will also speed up the process later on if you open your digital storefront of choice now.
How to enable and open Xbox mode in Windows 11
The first step to using Windows 11’s Xbox mode is to ensure that it’s turned on, which it may not be by default. To do so, open Settings by using the Win + I shortcut, then select Gaming > Xbox mode.
Here, if you see an Enable Xbox mode slider, enable it. You may also see a Choose home app section, where you should select Xbox. If you want quicker access to Xbox mode from the desktop, also enable Show Xbox mode in Task View. And if you end up loving the feature and only use your PC for gaming, Enter Xbox mode on startup will save you some time.
Xbox mode is accessible through several paths. The keyboard shortcut Win + F11 toggles between the desktop and Xbox mode. You can also use Win + G to open the Game Bar, click the gear icon in the bar centered at the top of the screen, then choose Enter Xbox mode. If you’re in the Xbox app, you’ll see a shortcut at the top-right of the home page. Lastly, if you enabled the Task View option above, press Win + Tab and you’ll see an Xbox mode shortcut to the right of your open desktops at the bottom of the screen.
While playing, pressing the Windows key on your keyboard enters a task view where you can access the Windows desktop, as well as shortcuts at the top of the screen. To exit Xbox mode, return to the Xbox app home screen and click the Exit Xbox mode button in the top-right. You can also use Win + F11 again.
A common misconception is that Xbox mode brings under-the-hood improvements to performance while gaming, but Microsoft has made no such claim. This is handled by a separate toggle: Settings > Gaming > Game Mode, which “turns things off in the background” to improve your gaming experience. While vague, it’s worth turning this on if you don’t have it enabled already.
What Xbox mode does is get the most computer-y parts of Windows out of the way, replacing them with a full-screen experience dedicated to gaming that’s friendly to use with either a controller or keyboard and mouse. In other words, it’s Microsoft’s answer to the Big Picture Mode in Steam.
What does Xbox mode actually do in Windows 11?
You’ll benefit most from Xbox mode if you have game libraries across multiple providers. If you’ve got World of Warcraft, Fortnite and Counter-Strike on your PC, you need at least three launchers to run them (Battle.net, Epic Games and Steam, respectively). Xbox mode shows you games from all those libraries, as well as Ubisoft Connect and Humble Launcher, in a centralized place. We didn’t test other launchers like the EA App. If you don’t see a particular title, you can pull it into the Xbox app by selecting the plus icon from the top-right of the Library tab.
Launching a game from the Xbox app sidesteps the need to open its launcher, as Xbox will simply target the game executable, which boots the necessary software in the background. This process wasn’t the quickest or smoothest in our testing. Although games launch every time, we recommend opening third-party launchers before starting Xbox mode to speed up the process.
If you’re subscribed to Xbox Game Pass, you’ll be able to access its library through Xbox mode. Surprisingly, the Cloud Gaming tab doesn’t lock you to Microsoft’s services. You can set Nvidia GeForce Now as your default streaming service in the Xbox app’s settings.
Ultimately, Xbox mode in its current form is little more than a souped-up Xbox app with controller mapping and a few extra settings to prevent you from needing to interact with Windows. It’s more useful on handhelds and living room PCs than on a standalone gaming PC. Regardless, with more gamers switching to Linux than ever before, it’s good to see Microsoft exploring improvements to the Windows 11 gaming experience.
Tech
Gemini hacked three companies during security tests, and Google kept it quiet for months
What just happened? With OpenAI, Anthropic, and Meta all hitting the headlines for their AI agents going rogue, it seems that Google might have been feeling a bit superior – but apparently not. The company has confirmed that its Gemini AI breached the systems of three other companies during cybersecurity tests. In one instance, it repeatedly guessed passwords until it found the right one, and Google wasn’t very forthcoming about what happened.
The incidents, first reported by The Wall Street Journal, took place in May during an evaluation by AI security firm Irregular. Gemini was supposed to work with fictional companies in a controlled test environment. However, an unintended internet connection gave the model access to real websites, and it treated them as part of the exercise.
In one test, Gemini was asked to retrieve information from software belonging to a fake company that shared its name with a real business. The AI guessed passwords until it gained access to the real firm’s protected system.
In the other cases, the model found credentials in public online repositories and used them to enter two more companies’ systems.
Google says that in all three instances, Gemini stopped once it realized the targets were real. The company didn’t disclose the incidents publicly when Irregular informed it in late July. It says no damage was done, the affected organizations were notified, and the testing procedures have since been changed. Google has not named the companies or identified which Gemini model was involved.

Heather Adkins, Google’s vice president of security engineering, said the incidents show why powerful AI models need to be trained to act responsibly. Google maintains that the model was trying to complete its assigned task, rather than deliberately seeking out victims.
This is just the latest in a series of similar incidents involving big AI companies. OpenAI’s agents breached Hugging Face and compromised accounts across several other services after escaping a test environment. Anthropic disclosed that Claude models accessed three organizations’ production systems during evaluations; another model tried to trick a real developer into accepting malicious code.
Meta’s model also reached the internet during an Irregular test and breached a third-party service. Meta blamed the breach on a testing misconfiguration. Unsurprisingly, Google and the other companies never publicly apologized for any of these breaches.
These incidents, alongside warnings from AI developers themselves, have intensified fears that the technology could threaten humanity’s survival. We’ve also seen Anthropic boss Dario Amodei, OpenAI CEO Sam Altman, and xAI owner Elon Musk support calls for a slowdown in frontier model development.
Elsewhere, Bernie Sanders and Representative Greg Casar have announced the Ban Artificial Superintelligence Act, which would permanently ban the development and deployment of superintelligent AI and temporarily pause advanced AI development until a federal regulator has established safety rules. Individuals who violate the proposed restrictions could face up to 20 years in prison.
-
Fashion2 days agoWeekend Open Thread: Talbots – Corporette.com
-
Crypto World2 days agoCircle launches Arc Studio AI agent for building onchain apps
-
Crypto World6 days agoRevolut Attackers Warn of Ongoing Daily Customer Data Leaks
-
NewsBeat2 days agoTrump says US has reached an agreement to take permanent control of Greenland’s security
-
Crypto World6 days agoKraken Lets xStocks Holders Earn Yield Through DeFi
-
Crypto World5 days agoRobinhood engineers charged over $50K crypto scheme
-
Crypto World5 days agoWhat Is the Status of the U.S.-Iran Peace Talks? Here's What Both Sides Are Saying
-
Crypto World4 days agoUS Charges Robinhood Engineers Over Crypto Listing Trades
-
Crypto World2 days agoBitcoin price breaks channel as RSI climbs to 63
-
Crypto World6 days agoElon Musk Drops a Bombshell: Grok 5 Could Be the AGI Breakthrough
-
NewsBeat6 days ago‘Sick conspiracy’: Trump says only guardrails AI needs is ‘a strong and smart (High IQ!) president’ in all-caps rant
-
Crypto World6 days agoNVIDIA Analysis: Attempted Rising Wedge Breakout Amid Pressure on the AI Sector
-
Business6 days ago
SK Hynix ADRs Fall More Than 6% as Memory Rally Breaks on Fears of Slower AI Spending
-
Crypto World7 days ago3 Token Unlocks to Watch in the Third Week of September 2026
-
Tech5 days agoWebb’s IC 348 Mosaic Includes Two-Jupiter Dwarfs, Twin Jets, and a Nursery Still Making Worlds
-
Crypto World6 days ago
Can Circle’s Arc Repeat Robinhood Chain’s Meme Coin Boom?
-
Crypto World6 days agoDOJ Seeks to Seize $61M in Iran Oil Funds From Binance Accounts It Vouched For
-
Entertainment5 days agoBig Brother Update: Melody Explodes at Drew as Illness Sweeps BB28 House
-
Crypto World2 days agoWorld Money launches in 150+ countries with Stripe
-
Crypto World3 days agoSilver prices recover quickly, hitting weekly high today


You must be logged in to post a comment Login