Connect with us

Tech

Watching TikTok Videos and Instagram Reels Deactivates the Brain's Cognitive Control Network

Published

on

An anonymous reader quotes a report from RathBiotaClan: Millions of people finish short video after short video every day; a new brain-scan study shows that the very act of finishing a clip they like temporarily quiets the brain regions that normally help them stay focused and weigh longer-term goals. When people watch a short video they enjoy enough to finish, two brain regions involved in cognitive control show significant deactivation. That is the central finding of a new study from Zhejiang University, published in NeuroImagein January 2026.

Using functional MRI alongside proton magnetic resonance spectroscopy (H-MRS), the research team examined 56 young adults while they freely watched short video clips inside an MRI scanner. Both the dorsal anterior cingulate cortex (dACC) and the dorsolateral prefrontal cortex (dlPFC) showed reduced activity specifically when participants watched clips they liked enough to view to completion. Cognitive control helps people balance immediate pleasures against longer-term goals, and impairments in this system are linked to conditions such as depression, anxiety, ADHD, and addiction. Short-video platforms present rapid, algorithmically curated streams that are built for continuous, low-effort consumption.

Prior behavioral research has tied both internet addiction and smartphone addiction to weaker self-control, and separate neuroimaging work has documented disruptions to reward and cognitive-control circuits in people with behavioral addictions. Despite this, few studies had directly tested whether the act of watching entertaining short videos itself suppresses the brain’s cognitive control regions. The Zhejiang University team set out to answer that question, along with a second one: what neurochemical factors might explain why this suppression varies from person to person?

Read more of this story at Slashdot.

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Meta’s Big Reckoning Is Here

Published

on

My colleague Paresh Dave and I each spent a day in federal court in Oakland, California, this week, monitoring the latest Meta child safety trial.

In case you missed it in the spring, Meta (along with YouTube) lost a landmark social media case in California, in which a jury found the companies liable for harming a young user with certain design features in their apps. Then, earlier this month, Meta was ordered to pay more than $940 million in the state of New Mexico for being a public nuisance and causing psychological harm to children.

Now Meta is defending itself in a federal civil trial taking place in the US District Court for the Northern District of California. The plaintiffs in this case are 29 state attorneys general. They’re claiming that Meta violated a federal privacy law protecting children, known as COPPA, by improperly collecting personal information about children under 13 without parental consent. The lead AGs, which span four states—California, Colorado, Kentucky, and New Jersey—also say that Meta made deceptive statements about its platform that were likely to mislead consumers.

Two specific Meta apps are in focus in this trial: Facebook and Instagram.

Advertisement

Meta maintains that it satisfied COPPA law requirements in those states, and denies that its statements about how its apps work were deceptive or misleading. It also insists it is protected from liability by Section 230 of the Communications Decency Act of 1996, which essentially says that platforms like Meta aren’t responsible for the content posted on their apps by users.

I was in the packed courtroom Tuesday to hear opening arguments from both sides, presided over by chief district judge Yvonne Gonzalez Rogers. Per usual, Meta was represented by an army of well-heeled lawyers, who quite ironically kept experiencing technical difficulties with the mic. Megan O’Neill, the deputy attorney general at the California Department of Justice, kicked off the opening statements, laying out how the state AGs believe Meta deliberately hooked kids on its apps and harvested their data.

O’Neill emphasized that throughout the trial, the jury would be shown just “how many features work both individually and together to keep people in the apps. To draw them in and keep them in for longer. Meta has used these features to draw kids onto the apps, and to keep them coming back.”

Meta lead attorney Paul Schmidt then laid out the dozens of safety features that have been built into Meta’s apps over the past several years, and he said the company is committed to improving its apps. He also shifted some responsibility onto users, saying there’s no dispute that some kids find their way onto Meta’s apps and that some teens “struggle to manage their time.” And inevitably some people will post negative content on social media apps, Schmidt said.

Advertisement

Later on Tuesday and then again on Wednesday, the courtroom heard from Arturo Bejar, a former Meta employee and key witness in earlier trials. His main point: Mark Zuckerberg didn’t prioritize youth safety. It was part of company culture during Bejar’s time there that if you had an inkling of an idea for a feature that would spur growth, “you could just test it,” he said. At the same time, he described a culture in which it was “near impossible” to screen products and features for potential harms.

(On Thursday, the trial was put on pause due to a sick juror.)

Meta has been embroiled in a remarkable number of scandals over the past decade, many of which have faded from public memory, been chalked up to the cost of doing business, or were settled out of court. The company’s platforms have played a role in stoking violence and swaying elections. It has regularly siphoned personal data from users in purposefully opaque ways. Not to mention the amount of internal workplace dysfunction at Meta that’s been revealed through depositions, books, and news reports like these.

Source link

Advertisement
Continue Reading

Tech

MG’s new 07 sedan is official, and it starts under $16,000

Published

on

At the 2026 Chengdu Auto Show, SAIC’s MG brand officially launched its new mid-size sedan, the MG 07, and the pricing might genuinely surprise you. According to CarNewsChina, the car is available in seven configurations, with prices ranging from 108,900 yuan to 159,900 yuan, or roughly $16,000 to $23,500, making it one of the most affordable electric cars.

A surprisingly premium design for a $16,000 sedan

The MG 07 stands out with a star-ring light group up front and semi-hidden door handles for a cleaner silhouette. It measures 4,886mm long and rides on a 2,825mm wheelbase, paired with frameless doors, two-tone wheels, and yellow brake calipers. At the back, there’s a through-type taillight and a 5-stage adjustable electric spoiler. You get six paint options, including Morello Purple, Notting Grey, Oxford Blue, Milia Pink, California Blue, and Salt Lake White.

On the powertrain front, MG is offering both EV and PHEV options. The EV runs on an 800V platform, offering up to 315 horsepower and a maximum range of 845km, while the PHEV pairs a 1.5L engine with an electric motor for a combined range that stretches to 1,745km. The 610km range EV trims interestingly use semi-solid batteries from Qingtao, while every other version sticks with CATL‘s more familiar LFP cells.

The cabin is where things get really interesting

The cabin is really well done. You get a wraparound cockpit with a 15.6-inch floating touchscreen running on the 8295P chip. The driver’s seat comes with heating and ventilation, and the passenger side even gets a “Queen” zero-gravity mode. Add in a multi-functional vanity mirror, a 21-speaker sound system, and mCDC active suspension, and the comfort package feels genuinely thought out. MG has also added LiDAR here, powered by Momenta’s R7 world model.

The MG 07’s price might be its biggest selling point

If you already had your eye on the EV version, pre-sales kicked off last month starting at 125,900 yuan, or about $18,600. Deliveries are staggered depending on which range you pick. Go for the 650km version, and you should have it by the end of August. Opt for the longer 845km range instead, and you will need to wait until October.

Advertisement

Source link

Continue Reading

Tech

Chinese memory firm CXMT relied on leaked Samsung technology to skip years of R&D, court testimony claims

Published

on

Cutting corners: Building a memory chip from the absolute ground up takes years and costs a fortune. ChangXin Memory Technologies (CXMT) apparently decided to skip the hard part – and today, the company stands as China’s biggest DRAM producer. A South Korean court recently heard some fairly wild details about how the memory maker actually got its start.

That origin story came directly from a former Samsung Electronics engineer surnamed Jeon, according to Maeil Business. The veteran employee spent almost three decades at Samsung before jumping to the rival firm around 2016. Jeon appeared in a Seoul courtroom this past week to testify under oath about those early days, telling the judge that his new employer lacked basic laboratory facilities and never planned to do its own independent research when it was founded.

Instead, startup executives reportedly wanted to grab a highly confidential blueprint from Samsung right from day one. Engineers in the semiconductor industry call that document a Process Recipe Plan: it lists roughly 600 specific manufacturing steps, telling engineers exactly what temperatures and equipment pressures to use on the factory floor so they don’t have to guess.

Samsung spent five years and well over a billion dollars dialing in the specifications for its 18-nanometer memory chips. Prosecutors now say the Chinese firm simply recruited a bunch of former Samsung workers to swipe all of it.

Advertisement

By 2023, the company had begun mass-producing advanced memory chips. Today, its output has grown from 40,000 to 720,000 wafers in just a few years, and it’s closing in on Micron.

Unsurprisingly, South Korean authorities haven’t let this slide. Prosecutors indicted ten people late last year for illegally leaking protected national technologies, and a judge handed Jeon a seven-year prison sentence this past April for his role.

Proving all this in court could give Samsung a powerful weapon moving forward. Legal experts believe the company might take sworn statements straight to the US International Trade Commission, a body with the authority to block foreign products from entering the country entirely.

Advertisement

Source link

Continue Reading

Tech

Amphion A15 Active Speakers Bring Studio Monitor Thinking Home Without the Wireless Baggage

Published

on

Finnish loudspeaker manufacturer Amphion has spent more than 25 years building loudspeakers around a fairly consistent idea: minimize the theatrics, control dispersion, and let the recording do most of the talking. Its professional studio monitors have subsequently found their way into rooms used by engineers and producers working with artists including Billie Eilish, Beck, and Kendrick Lamar, while its home loudspeakers have become more widely available in North America through Playback Distribution.

The new Amphion A15 brings those two sides of the company much closer together. This compact two-way active loudspeaker takes obvious inspiration from Amphion’s One15 nearfield studio monitor, adds dedicated internal amplification, and packages the concept specifically for home listeners. What it does not add may be just as important: there is no built-in streaming platform, Wi-Fi, Bluetooth, HDMI, USB input, or elaborate app ecosystem listed in Amphion’s current specifications. Instead, each A15 provides a single balanced XLR analog input.

In a market increasingly filled with active speakers trying to become your streamer, DAC, preamplifier, television audio system, and possibly your therapist, Amphion has chosen a considerably narrower job description.

amphion-a15-active-speaker-white-on-black-song

Studio DNA Moves Into the Living Room

The connection between the A15 and Amphion’s established One15 studio monitor is difficult to miss. Both use a 1-inch titanium tweeter, 5.25-inch aluminum woofer, 5.25-inch aluminum passive radiator, and 1,600Hz crossover point, and both measure 12.44 x 6.3 x 10.43 inches. The One15 is a passive professional monitor requiring external amplification; the A15 integrates its own amplifiers and is specifically positioned for home audio.

The passive radiator is particularly important to Amphion’s design approach. Rather than using a conventional bass-reflex port, Amphion has employed passive radiators across both its professional and consumer products to control low-frequency behavior while avoiding some of the airflow and placement issues associated with traditional ports. We heard that same philosophy at work with the Argon7LX at AXPONA 2026, where bass control, imaging, and overall coherence were among the things that stood out.

Advertisement

The A15’s internal amplification provides 125 watts for the woofer and 22 watts for the tweeter, while Amphion specifies a frequency response of 55Hz to 40kHz at -6dB. Each loudspeaker weighs 20 pounds and will initially be offered in Snow White and Jet Black finishes.

Amphion A15 Specifications:

  • Design: Two-way active loudspeaker
  • Tweeter: 1-inch titanium
  • Woofer: 5.25-inch aluminum
  • Passive Radiator: 5.25-inch aluminum
  • Crossover: 1,600Hz
  • Frequency Response: 55Hz to 40kHz (-6dB)
  • Amplification: 125 watts bass, 22 watts treble
  • Input: 1 x balanced XLR analog
  • Dimensions: 12.44 x 6.3 x 10.43 inches
  • Weight: 20 pounds each
  • Finishes: Snow White, Jet Black
amphion-a15-active-speakers-white-back-front

What Makes the Amphion A15 Different?

The A15 occupies an interesting space between professional active monitors and consumer wireless loudspeakers.

KEF’s LS50 Wireless II, for example, combines amplification with Wi-Fi, Bluetooth, AirPlay 2, Google Cast, Roon, HDMI eARC, multiple digital inputs, streaming services, and an app. Dynaudio’s Focus 10 follows a similarly integrated philosophy with wireless connectivity and substantial onboard amplification.

The Amphion A15 goes in almost the opposite direction.

Its current specification sheet lists one analog XLR input and nothing else. That means owners can choose their own streamer, DAC, analog preamplifier, or combination of those components and replace them independently as formats and streaming platforms change.

Advertisement

That approach is hardly unprecedented in professional audio. Neumann’s KH 150 and Genelec’s 8341A demonstrate just how sophisticated active studio monitors have become, although both add DSP and room-optimization capabilities that Amphion has not announced for the A15. ATC’s SCM20ASL also takes the more traditional active-loudspeaker route and is specifically offered for high-quality domestic listening as well as ATC’s professional monitoring applications.

Advertisement. Scroll to continue reading.

What makes the A15 interesting is Amphion taking its studio-monitor philosophy and deliberately packaging it for the audiophile living room without turning it into another wireless lifestyle system.

Who Should Consider the Amphion A15?

The obvious customer is someone who already owns a quality streamer, DAC, or preamplifier with balanced outputs and wants to eliminate the separate power amplifier without surrendering control over the rest of the system.

Advertisement

It could also make considerable sense in smaller listening rooms, desktop systems, and dedicated nearfield setups where imaging and controlled dispersion matter more than subterranean bass. With a specified -6dB point of 55Hz, however, listeners who want genuine full-range extension for electronic music, large-scale orchestral recordings, or home theater will probably want to add a subwoofer.

The A15 is not aimed at buyers looking for the simplest possible all-in-one solution. If you want to open Spotify on your phone, select the speakers, and be finished, KEF, Dynaudio, and several other manufacturers offer considerably more integrated alternatives.

But that absence of software dependency may also be part of the appeal. Amplifiers and loudspeaker drivers generally have much longer useful lives than streaming platforms, wireless standards, and apps. Amphion specifically emphasizes longevity in its A15 announcement, and keeping those rapidly changing technologies outside the loudspeaker could make upgrading considerably easier down the road.

amphion-a15-active-speaker-white-stand

The Bottom Line

The Amphion A15 is not trying to win the active-speaker feature war. That may be precisely why it stands out.

By combining internal amplification with the driver architecture and design philosophy Amphion has developed for professional monitoring, the A15 offers audiophiles a more modular approach to active loudspeakers. You supply the streamer, DAC, and volume control; Amphion handles the amplification and loudspeaker integration.

Advertisement

We already came away impressed by the Argon7LX at AXPONA 2026, and eCoustics has previously covered Amphion’s much larger One25A active studio monitor. The A15 now looks like the clearest bridge yet between those professional and consumer worlds.

The unanswered question is price. If Amphion gets that right, the A15 could become a very interesting alternative for listeners who want active-speaker simplicity without handing the entire system over to an app.

Price & Availability

Amphion has not announced pricing or a firm shipping date as of August 16, 2026. The company says additional information is coming.

Advertisement

Source link

Continue Reading

Tech

Samsung’s new 16-inch OLED panel wants to make your laptop feel like a gaming monitor

Published

on

Gaming monitors have been delivering insane refresh rates for years, but laptop screens have mostly stayed the same. Samsung Display just changed that equation at IMID 2026 in Busan, where it unveiled a 16-inch OLED panel built specifically for laptops that hits a 300Hz refresh rate.

Why does 300Hz on a laptop actually matter?

Samsung says this is the first time any self-emissive laptop display has reached 300Hz, and that’s a big deal if you use your laptop for anything beyond emails and spreadsheets. Higher refresh rates mean smoother motion, whether you’re scrolling through a webpage, editing video, or actually gaming on the go. 

Until now, you needed a hefty gaming laptop with a dedicated GPU pushing high frame rates to make a fast panel worthwhile. And while this panel is also aimed at gamers, Samsung packing this into a slim 2.5K OLED panel means that smoothness could trickle down to thinner, lighter laptops too.

What else did Samsung bring to the show?

The 16-inch panel wasn’t the only thing Samsung brought to the event. Samsung also showed off a 31.5-inch QD-OLED monitor that combines 4K resolution with a 360Hz refresh rate, something no monitor has managed to do simultaneously before. 

The company also brought a 34-inch QD-OLED gaming monitor with a 21:9 ultrawide aspect ratio and its own 360Hz refresh rate. All three panels were showcased in the Winning Game Arena, clearly aimed at showing gamers and creators what its OLED tech can do across different screen sizes.

Samsung didn’t share when this 16-inch panel will actually land in laptops you can buy, but the fact that it exists at all suggests laptop makers might finally start advertising refresh rates the same way gaming monitor brands do. If your laptop screen has ever felt sluggish compared to your monitor at home, this might be the fix you’ve been waiting for.

Advertisement

Source link

Continue Reading

Tech

Is Online Privacy Possible? How Digital Identities Can Help

Published

on

Is Online Privacy Possible?

How can normal users increase their privacy, safety and security online?

Over the last two decades, the internet quietly rebuilt itself around a business model that depends on knowing everything about you. Every app you install or use, every account you create, every website you visit, and every form you fill out becomes another data point feeding a system designed to track, profile, and monetize you and your identity.

This process is often referred to as surveillance capitalism and creates an economy where attention and personal data are the product and you are the raw material.

The mechanics of this are almost invisible day to day. A single email address becomes the thread that ties together your shopping habits, your health searches, your location history, and your social connections.

Advertisement

Data brokers exist specifically to aggregate these threads, buying, selling, and cross-referencing fragments of your life until they can construct a profile more complete than most people would recognize about themselves.

None of this requires a breach or a hack – it’s simply how the default internet works. Data brokers are often the most consequential handlers of personal information that operate without consumers’ awareness or informed consent.

The result is that privacy is no longer something you can expect. It has become something you have to actively construct, piece by piece, against the grain of nearly every service you use. The harms of this model are diffused and delayed and you don’t feel the effects of a data broker profile the way you feel a stolen credit card.

The damage shows up later, as spam, as price discrimination, as identity theft, as a general erosion of control over your own digital identity.

Advertisement

The graphic below shows the problem of using a single identity across your online actions. When a data breach occurs, everything connected can be exposed and tied back to you.  Data brokers can use it to construct a complete picture of your life, and this valuable information is for sale.

Data breach without MySudo

Artificial Intelligence (AI) systems have made the problem significantly worse.

Data brokers can now use AI to link your different actions in a way that was previously thought impossible. AI’s expertise is data analysis, working through vast amounts of information to correlate your actions into a valuable profile.

In this world of surveillance capitalism, can we shift the privacy pendulum back in your favor? Is it even possible to be private, secure, and safe online?

Advertisement

Every account you sign up for and every form you fill out connects back to you.

MySudo breaks that trail by allowing you to create multiple digital identities, each with its own phone number, email, payment card, and more, as a new set of credentials you can use so you stop handing over your personal information by default.

Download MySudo Now

Personas and Compartmentalization

If surveillance capitalism works by linking everything about you into one exploitable profile, the countermeasure is structural (not just legal or political): break the correlating identifiers.

This is the premise behind compartmentalization. Instead of using one set of identifiers such as one email, one phone number, one payment method, one communication handle across every context in your life, you deliberately compartmentalize activities into separate, purpose-built personas.

Advertisement

One persona for online shopping, a different one for dating apps, another for travel, another for marketplace listings, and even another for that newsletter you’re not sure you trust yet.

Each persona operates as a self-contained identity with its own email address, its own phone number, its own payment method, its own browser, and its own communication handle. Crucially, these personas aren’t connected to each other or back to your actual identity in any way a data broker or advertiser could observe.

As shown in the graphic below, if a persona gets swept up in a breach, starts attracting spam, or gets sold to a marketing list, the damage is contained and is not tied back to you.

Data breach with MySudo

This is a fundamentally different privacy model than the one most security tools rely on. Most tools try to protect a single identity better with stronger passwords, better encryption, more careful permissions.

Advertisement

Compartmentalization instead assumes that any single identity is eventually going to become correlated and anticipates corrections by ensuring that no single identity is valuable due to its changeability. This process is less about building an impenetrable wall and more about not putting all your value behind one wall in the first place.

The elegance of this approach is that it doesn’t require the rest of the internet to change. You don’t need every company you interact with to suddenly adopt better data practices. You just need a layer that sits between you and them, generating and managing these personas on your behalf.

Anonyome Labs patented many of the ideas related to creation of online personas and compartmentalization, here are some examples:

How MySudo Puts This Into Practice

Compartmentalization and personas are an important advancement, but the harder problem (and the one that has occupied most of our product decisions) is making it usable by typical users and automatic enough that people can do it consistently, without a computer science degree, and without constant friction.

Advertisement

As shown in the graphic below MySudo was designed to implement this paradigm and enable each user to create up to 9 personas or Sudos. Each Sudo provides a different:

  • Phone number that can make and receive phone calls and SMSs;
  • Email inbox that can send and receive emails;
  • Virtual payment card for purchasing online;
  • Communication handle to enable end-to-end encrypted (E2EE) messaging, voice calling and video calling (similar to WhatsApp);
  • Browser for complete separation of browsing.

MySudo apps

MySudo comes in two form factors: 

  • A mobile app for iOS and Android that allows each persona to communicate externally with phone calls, SMSs, and emails. It allows creation of individual payment cards and to have end-to-end encrypted messaging, email, voice and video. It also has a separate browser for each persona. 
  • A desktop companion app for Windows and Mac that allows management of persona emails in a form factor that provides support for longer and more complex emails.  More features are coming to the MySudo desktop app soon.

MySudo is part of a growing family of privacy and security applications from Anonyome Labs that also includes a privacy focused VPN and Password Manager (coming soon).

Individual online privacy has been under surveillance and attack almost since the beginning of the web – and now users have identity-based tools to fight back.  By creating multiple personas that allow you to compartmentalize your life, you too can reap the privacy benefits.

Your identity is already being pieced together. Stop handing over the pieces.

Advertisement

Download MySudo now to create separate digital identities that keep your personal information private and out of reach from data brokers, scammers, and the next data breach.

Sponsored and written by ANONYOME LABS.

Source link

Advertisement
Continue Reading

Tech

How to Tell If Your Data Has Been Compromised (2026 Guide)

Published

on

To tell if your data has been compromised, search your primary email addresses and phone numbers on breach lookup databases like Have I Been Pwned or CyberNews, check official state data breach registries, audit your credit reports at AnnualCreditReport.com for unauthorized accounts, and inspect your financial accounts and email settings for unrecognized logins or automated forwarding rules.

A flowchart on a soft gradient background showing three vertical phases: Digital Footprint Check (search icon), Identity & Finance Audit (credit/bank icons), and Account Integrity Review (email/session icons), connected by arrows.

Quick Take: How to Audit Your Data Exposure

Determining whether your personal information has leaked requires a systematic audit across three distinct vectors: public breach aggregators, financial credit bureaus, and individual account security logs. If a database lookup flags an exposed password or your bank statement shows an unfamiliar micro-transaction, treat your credentials as actively compromised. Securing your identity immediately involves revoking active device sessions, updating passwords via a dedicated vault, enforcing hardware or app-based multi-factor authentication, and freezing your credit files across major credit reporting agencies.

Prerequisites for Performing a Personal Data Audit

Before initiating a manual security audit, gather the necessary assets to ensure you do not miss hidden attack vectors or orphan accounts. Having these items prepared reduces the risk of overlooking connected services:

  • A Master Account Inventory: A compiled list of every email address, phone number, username, and primary domain name you have used across personal, financial, and work accounts over the past five to ten years.
  • Access to a Password Manager: A centralized credential vault (or secure browser storage) to review where reusable passwords may have been deployed across multiple platforms.
  • Identification and Credit Documentation: Secure access to your credit monitoring portals or government-issued identification details needed to request official credit reports.
  • Secondary Verification Devices: An authenticated smartphone or hardware security key ready to receive time-based one-time password (TOTP) codes as you audit and re-anchor account security.

Step-by-Step: How to Determine If Your Data Has Been Leaked

Data breaches vary significantly depending on what information was stolen. To avoid wasting time on false alarms or misdiagnosing a breach, route your investigation based on the specific exposure vector below.

Step 1: Query Aggregated Data Breach Databases

Threat actors frequently dump or trade stolen databases on illicit forums, paste sites, and dark web marketplaces. Breach aggregators collect these compromised datasets, index the hashed credentials, and allow users to search their exposure without exposing sensitive details.

Advertisement

Navigate to an established breach repository such as the CyberNews Personal Data Leak Checker or Have I Been Pwned. Input your primary and secondary email addresses along with phone numbers tied to key online accounts. Review the returned query report to identify which specific services suffered a breach, the exact date of exposure, and what data classes (e.g., plain-text passwords, salt hashes, credit card details, or physical addresses) were included in the leak.

Expected Outcome: You will receive a list of historic and recent database breaches linked to your contact details, highlighting precisely which credentials must be rotated immediately.

An illustrative breach lookup interface displaying data categories and their exposure status. It lists 'Email Address', 'Password Hash', and 'IP Address' as 'EXPOSED' with heavily redacted details, while other fields show as 'SECURE' or 'NOT FOUND' using checkmark icons. A gradient-styled summary box in the corner reads '6 BREACHES FOUND'. The entire interface uses a navy and mid-blue palette on a soft light-blue gradient background.

Step 2: Search Official State and Corporate Breach Notifications

Companies are legally bound by consumer protection statutes to notify affected customers when a security incident compromises personal identification or financial records. However, physical mail notices and corporate emails can easily be overlooked or filtered into spam folders.

Consult official public breach repositories, such as the California Department of Justice data breach guidelines and public disclosure log, which track corporate security incidents impacting consumers. Cross-reference these logs against major services you use—including medical portals, credit issuers, retail vendors, and educational institutions. Additionally, search your email inbox for keywords like “Notice of Data Breach,” “Security Incident,” or “Unlawful Access.”

Advertisement

Expected Outcome: You will verify whether a vendor holding your sensitive records has formally declared a breach, giving you specific legal timelines and instructions regarding offered credit monitoring services.

Step 3: Inspect Email Account Rules and Inbox Settings

When attackers gain stealthy access to an email account, they rarely change the password immediately. Instead, they create automated inbox rules to redirect incoming mail, hide password reset requests, or intercept financial confirmations without alerting the owner.

Log into your primary email account, open the general account settings, and locate the “Rules,” “Filters,” or “Forwarding and POP/IMAP” tab. Audit every rule to verify that no unknown external email address is secretly receiving a copy of your messages. Check the “Trash” and “Archive” folders for automated filters designed to mark incoming security alerts from banks or social media platforms as read and deleted.

Expected Outcome: You will ensure that your central recovery vector (your primary email account) is not silently routing security alerts and password reset codes directly to a malicious actor.

Advertisement

Step 4: Audit Financial Statements and Credit Bureau Files

Financial identity theft often begins with small, innocuous transactions. Fraudsters run micro-charges—frequently between $0.50 and $3.00—to confirm that a stolen payment card or bank routing number is active before executing larger fraudulent purchases or line-of-credit applications.

Log into your checking, savings, and credit card accounts to review line-item transactions over the past 30 to 60 days. If you find any unfamiliar charge, even for a minimal amount, contact your card issuer immediately to report account compromise. Next, access your free credit reports from Equifax, Experian, and TransUnion via AnnualCreditReport.com. Inspect the “Hard Inquiries” and “Open Accounts” sections for credit lines, personal loans, or store cards that you did not explicitly apply for.

Expected Outcome: You will detect early indicators of financial identity theft and spot unauthorized credit applications before they damage your overall credit standing. If you regularly use credit cards for online transactions, reviewing baseline features and security protocols by understanding different types of credit cards can help you spot anomalous account behavior faster.

Step 5: Review Active Sessions and Connected OAuth Applications

Modern account compromises increasingly rely on session hijacking—where attackers steal active session cookies or leverage third-party OAuth application tokens to bypass traditional password authentication entirely.

Advertisement

Open the security panel of your core accounts (e.g., Google, Apple, Microsoft, social networks, and password managers). Locate the “Active Sessions,” “Devices,” or “Where You’re Logged In” section. Terminate any session linked to an unrecognized device, outdated operating system, or unfamiliar geographic location. Next, navigate to “Connected Apps” or “Third-Party Permissions” and revoke access for any legacy application or service you no longer actively use.

Expected Outcome: Invalidating active session tokens immediately severs an attacker’s persistent backdoor access, forcing any unauthorized party to re-authenticate from scratch.

Verification: Confirming Whether Exposure Is Active or Historical

Not all data breach results require the same immediate panic. Distinguishing between a historical, static database leak and an active, ongoing account intrusion dictates your response speed and tactical priorities.

A clean decision tree diagram on a soft light-blue gradient background. It begins with a 'BREACH ALERT RECEIVED' node and flows to a central decision point: 'UNRECOGNIZED SIGN-IN OR LIVE RULE MODIFICATION?'. The 'YES' path leads to a red-outlined terminal card for 'ACTIVE BREACH: URGENT REMEDIATION' with a lightning bolt icon and remediation steps. The 'NO' path leads to a blue-outlined terminal card for 'HISTORICAL LEAK: PASSIVE EXPOSURE' with an archive icon and characteristics.

To verify if an exposure is active:

Advertisement
  • Check Real-Time Sign-In Logs: Review the timestamps and IP addresses in your account security logs. If an IP address from an unfamiliar region logged in within the past 24 hours, the compromise is live and active.
  • Test Existing Credentials: If your password no longer works and you have not recently changed it, an attacker may have already taken over the account and altered the recovery email or phone number.
  • Evaluate Password Reuse Scope: A entry in a breach database from five years ago may be harmless if you have changed that password since. However, if that old password is still used across active services today, treat every single one of those destination accounts as actively vulnerable. Implementing robust credential management habits and evaluating whether are password managers really safe will significantly reduce your attack surface during cross-platform exposures.

Troubleshooting: What to Do When Signs Point to Compromise

If your diagnostic audit reveals active unauthorized access, execute this recovery escalation path to re-establish control over your identity and accounts.

Failure Point 1: You Are Locked Out of Your Primary Account

Fix: Initiate the service provider’s account recovery workflow immediately. Use a trusted, known device and network connection previously associated with the account. If the recovery email or phone number was altered, select “Try another way” to supply account creation dates, previous passwords, or identity verification documents. If the account contains financial or billing information, contact customer support by phone to place an administrative hold on the profile while identity verification takes place.

Failure Point 2: Password Resets Fail to Stop Unauthorized Sign-Ins

Fix: Changing your password does not always terminate active browser sessions if an attacker holds a persistent session cookie or OAuth token. According to Lunar Cyber’s breach monitoring analysis, modern infostealer malware extracts session tokens and browser state data, enabling bad actors to bypass standard password resets. After changing your password, explicitly click “Log out of all other sessions” or “Revoke all active tokens” across all settings menus. Run an up-to-date malware scan on your local machine to eliminate active infostealer Trojans that may be capturing keypresses or browser session files in real time.

Failure Point 3: Your Social Security Number or Government ID Was Exposed

Fix: Password resets cannot safeguard physical identity attributes like Social Security numbers or driver’s license numbers. Take formal legal and credit protection measures immediately: submit an official report via IdentityTheft.gov, follow established legal identity theft response protocols, and contact each of the three nationwide credit bureaus (Equifax, Experian, TransUnion) to initiate a full credit freeze. You can also explore placing a credit freeze or fraud alert depending on the severity of the document exposure.

While public breach lookup services and account security audits are essential components of digital hygiene, they possess inherent structural limitations that every user should understand:

Advertisement
  • Reporting Lag Times: Breach aggregators rely on public dumps, security research contributions, or threat intelligence feeds. Months or even years can elapse between an actual security breach and its publication on public lookup platforms.
  • Private Threat Intelligence Gaps: Proprietary databases stolen by sophisticated threat actors are often sold privately or leveraged exclusively for targeted spear-phishing and extortion, meaning they will never appear in searchable public repositories.
  • Session Token Exploits: Modern credential theft extends far beyond static text passwords. If malware steals local browser session cookies, breach tools searching for leaked text credentials will show no alert, even while your active sessions are being accessed.
  • Enterprise and Business Scope: Individual consumer tools only check personal identifiers. Organization-level breaches often require specialized monitoring focused on protecting customer data, internal access logs, and API endpoint security.

Key Takeaways for Long-Term Data Security

Maintaining long-term digital privacy requires moving from reactive panic to proactive operational security. Apply these key practices to keep your exposure minimal:

Key Takeaways

  • Eliminate Password Reuse: Use a dedicated password manager to generate and store randomized 16+ character passphrases for every individual account.
  • Enforce Strong Multi-Factor Authentication: Transition away from vulnerable SMS-based verification codes and set up two-factor authentication using authenticator applications (such as Google Authenticator) or physical FIDO2 security keys.
  • Freeze Your Credit Files: Keep your credit files frozen at Equifax, Experian, and TransUnion by default, thawing them only temporarily when applying for new credit lines.
  • Prune Legacy Accounts and App Permissions: Delete unused online accounts and regularly revoke third-party OAuth access tokens connected to your primary email and social profiles.
  • Stay Vigilant Against Social Engineering: Treat unexpected communications with heightened skepticism by learning the warning signs for identifying targeted phishing scams that exploit leaked personal details.
  • Adopt Comprehensive Security Standards: For broader personal defense strategies, review overall best practices to maximize your data security across home networks, mobile devices, and cloud storage accounts.

Frequently Asked Questions

How long does it take for stolen data to show up on breach lookup tools?

According to Experian’s data breach assessment guide, it can take anywhere from a few days to several months—or even years—for breached data to appear on public lookups. The delay depends on how quickly the breach is discovered by the company, when disclosure laws require notification, and when threat actors upload or trade the stolen database publicly.

What should I do if my password was leaked but I use two-factor authentication?

While two-factor authentication (2FA) prevents an attacker from logging in with a stolen password alone, you should still change the compromised password immediately. An exposed password reduces your overall defense to a single security layer, leaving you vulnerable to 2FA fatigue attacks, SIM-swapping, or session hijacking.

Is it safe to enter my email address into breach lookup websites?

Yes, provided you use reputable, established breach lookups like Have I Been Pwned, F-Secure Identity Theft Checker, or CyberNews. These tools process your email address or phone number safely without requesting account passwords, recovery codes, or sensitive financial data.

Source link

Advertisement
Continue Reading

Tech

Spoofed Serial Number Unlocks Cricut Machine

Published

on

[xssfox] recently found a Cricut Maker in an e-waste disposal. A quick scan over the device indicated it was in moderately good condition, with merely some perished rollers to contend with. The device was salvaged, with the awareness that Cricut is plenty good at disabling and locking down machines when it wishes. However, those measures didn’t stop [xssfox] from bringing it back to life.

The suspicion was that the machine had been locked out after the original owner received a warranty replacement or similar. Whatever the reason, the rollers would have to be repaired and the machine unlocked if it were ever to cut (Cricut?) again. Hooking the machine up to Cricut software showed that it was “deactivated”, so there was work to do.

The rollers were not a difficult replacement, but the hacking would take a little work. Examining the motherboard didn’t reveal any obvious EEPROMs, and the microcontroller was not one [xssfox] had the debugger to work with. Thus, attention turned to intercepting communications between the machine and the host PC over USB. This revealed the machine sending its serial number to the Cricut PC software in plain text with no checksums or encryption at all. Unlocking the machine was as easy as installing an RP2040 in between the Cricut Maker and the host PC. It was programmed to relay packets between the two and spoof the serial number in the process.

[xssfox] suspects a software-only solution may be possible, too, though hasn’t implemented one yet. We’ve featured her work before, too, like her efforts to spoof emergency traffic light preemption signals.

Advertisement

Source link

Continue Reading

Tech

Broadcom seeks more than $60bn in debt to fund AI chips for Anthropic

Published

on

Broadcom is in talks with lenders to raise more than $60bn in debt, Bloomberg reported on Thursday. The money would finance AI chips for Anthropic and other companies. Bloomberg cited people with knowledge of the matter.

The figures under discussion could take the total as high as $100bn. Talks are continuing and the terms may change.

Blackstone and Apollo Global Management are in talks to take part, the same people said. Spokespeople for Broadcom, Anthropic, Apollo and Blackstone declined to comment.

How the financing is structured

The package has two parts. A junior tranche of roughly $30bn sits alongside a senior-secured tranche of about $60bn to $70bn, according to Bloomberg.

Advertisement

Broadcom would guarantee a portion of the senior tranche. A special-purpose vehicle would issue the debt.

A special-purpose vehicle is a separate legal entity created to hold specific assets and the borrowing against them. The debt sits on the vehicle’s books rather than on the balance sheet of the company that set it up. Investors in the vehicle have a claim on the assets inside it.

Anthropic does not buy the chips under this arrangement. Investors finance the purchase, then lease the hardware to the company.

The first deal in the partnership

Broadcom, Apollo and Blackstone formed the AI XPV partnership in June. Its opening transaction raised $35bn to expand Anthropic’s computing capacity, using Broadcom custom chips and networking equipment. Reuters reported the terms. TNW covered it in May, when Apollo and Blackstone shopped it to investors.

Advertisement

In that transaction Broadcom backstopped most of the debt while Apollo and Blackstone financed the chip purchases. Bloomberg reports that the backstop allowed the senior tranches to obtain investment-grade ratings, which lowered the borrowing costs.

The new financing could follow the same shape, according to Bloomberg’s sources, and may arrive in stages rather than at once.

The 20 gigawatt target

The partnership intends to finance more than 20 gigawatts of computing power for leading AI labs by 2028. Bloomberg puts the cost at hundreds of billions of dollars. That capacity would roughly equal the output of 20 nuclear plants.

The first $35bn commitment would add one gigawatt, Reuters reported. On those figures the partnership has funded about a twentieth of its stated target.

Advertisement

Where Broadcom sits

Broadcom designs custom chips for Alphabet and Meta, and has supply agreements with Anthropic and OpenAI. Its chief executive said in March that the company expects AI chip sales to exceed $100bn next year.

Broadcom holds an Apple agreement worth more than $30bn. It signed a $200bn deal with Samsung in July covering memory, foundry and advanced packaging through 2030. Reuters notes that technology companies use Broadcom custom silicon to reduce their reliance on Nvidia.

Broadcom shares rose as much as 1.1% in late trading after Bloomberg published, having briefly declined first. The stock had gained 5.2% this year to Thursday’s close.

Broadcom, Apollo and Blackstone announced the AI XPV partnership in a joint release in June. The three said it would help finance computing infrastructure. Bloomberg reported in May that Apollo and Blackstone were weighing a $35bn financing for Broadcom, and reported the deal complete in June.

Advertisement

Anthropic’s other borrowing

Anthropic is raising money in several places at once. An investment firm is lending about $1.3bn towards a Texas data centre that will house its systems. The company is also finalising a revolving credit facility ahead of its listing, targeting more than $10bn.

Its own figures show the scale involved. Anthropic booked second-quarter revenue above $11.5bn against $787m a year earlier. Its annualised run rate reached $65bn by the end of July, Bloomberg has reported. The company recorded a net loss of almost $42bn in 2025, roughly five times the $8.3bn it lost the year before.

It raised $65bn in May at a $965bn valuation. It has separately agreed a compute deal with SpaceX that could be worth tens of billions over three years.

It expects its IPO to match or exceed SpaceX’s record $75bn raise, and could file publicly as soon as the end of this month. SpaceX’s final figure reached $86.2bn once the overallotment option was exercised.

Advertisement

Anthropic is working with Morgan Stanley, Goldman Sachs and JPMorgan on the listing. US initial public offerings had raised $160.6bn through 19 August, against the 2021 record of $195.2bn.

The wider financing market

Similar structures have appeared across the industry this month. Nvidia announced that a coalition including BlackRock and Goldman Sachs was lining up more than $500bn for the AI build-out.

Regulators have begun to place these vehicles. SEC staff agreed this month that data centre securitisation falls outside Dodd-Frank risk retention rules, in a response tied to Nvidia’s programme.

Reuters reports that Alphabet, Amazon and Microsoft have all turned to debt markets to fund AI expansion. All three expect spending to stay high through 2026.

Advertisement

Bloomberg reported on 15 August that bond traders were weighing about $70bn of what it described as shadow credit backstops from AI companies. Broadcom’s guarantee on the senior tranche is that kind of commitment.

What has not been confirmed

None of the four companies has commented, and Bloomberg’s sources spoke on condition of anonymity because the information is private.

Bloomberg’s sources did not settle the split between the $30bn junior tranche and the senior tranche. They gave no figure for the portion Broadcom would guarantee. They did not set a timetable for issuance, or name any lender beyond Apollo and Blackstone.

The 20 gigawatt figure is the partnership’s own target for 2028. The partnership has financed one gigawatt of it so far.

Advertisement

Source link

Continue Reading

Tech

Are You Sure You Want a Car With a Giant Touch Screen?

Published

on

RAMageddon could soon push car prices higher as modern vehicles rely on ever more RAM and powerful centralized computers to run everything from infotainment to driver-assistance systems. Analysts cited by The Atlantic estimate the shortage could add a few percentage points to vehicle prices, which might not sound like much, but could potentially translate to around $2,000 on a $50,000 vehicle. The broader shift toward software-heavy vehicles could also make used cars even less affordable. An anonymous reader quotes an excerpt from the report: Just like laptops, cars depend on microprocessors and RAM, or random-access memory, to run all of their computations. “There’s just a baseline level of tech, and thus a baseline level of cost, required of every vehicle,” Karl Brauer, the executive analyst at iSeeCars, an automotive-research platform, told me. Technology is a major reason the average price of a new car in the U.S. has reached some $50,000, and that was before RAM became one of the most prized commodities in the world. AI companies are snatching up as much memory as possible for their data centers, causing a RAM shortage that has significantly raised the prices of phones, laptops, and just about any consumer-electronic device. Cars are next.

[…] Over the next year, the memory shortage — sometimes known as RAMageddon — will likely raise vehicle prices by a few percentage points, on average, [said Sam Abuelsamid, an analyst at Telemetry and a former automotive engineer]. The relative amount would be smaller than the shocking double-digit jumps for gaming consoles and MacBooks but in some ways more significant: A 4 percent price hike for cars amounts to some $2,000 on average. Cars with those centralized computers will be affected the most, but no vehicle will be spared. “Even if you don’t need the high-end chips, you’re going to pay more even for the low-end chips just because of the supply constraint,” Abuelsamid said. On a recent earnings call, Ford’s chief financial officer said that the company had paid $1 billion in higher materials costs due to the memory shortage and inflation. GM and Volkswagen, too, have noted rising chip costs to investors. (Ford and GM did not respond to a request for comment. A spokesperson for Volkswagen told me that the company has “recognized an increased demand for memory chips, primarily driven by growing requirements in other industries,” and that in recent years, Volkswagen has taken measures to “mitigate supply risks.”)

RAMageddon is poised to last for several years, but the consequences for car buyers may be permanent. Consider what happened during the pandemic, when supply-chain disruptions and rising demand for electronics produced a major chip shortage. Nearly every major car company had to slash production because they simply couldn’t procure enough chips, and shifted their focus to selling higher-end and higher-profit vehicles. Potential customers already willing to spend six figures on a car are much less likely to care about a 5 or 10 percent price hike, [said Ivan Drury, the director of insights at Edmunds]. Even now, car companies are continuing to focus on selling more profitable models. Since the pandemic, the average price of a new vehicle has jumped $11,000.

The AI-fueled chip crisis could play out more severely. The average price of a new car could, before long, jump to $60,000 and beyond. These rising costs are making cars even more similar to computers and all of the software they run: Perhaps in an effort to mitigate higher prices, some automakers are also introducing in-car advertisements and putting certain features, such as heated seats, behind a paywall. As cars have morphed into computers, the inevitable next step is for automakers to behave like modern tech companies.

Advertisement

Read more of this story at Slashdot.

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025