Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Apple obviously knows, and perhaps some of its retail staff have at least a clue, but for the rest of us, here’s the best estimate of when the iPhone 18 Pro will be announced.
No question, it’ll be in September. Apple has held its iPhone launches in October, but since 2011 the only time it has done that was during COVID.
The question is when in September we’ll find out the all-important updates and, more than ever this time, the all-important prices. Not to drag this out, the smart money says Wednesday, September 9, 2026.
That’s the most probable date that has been recently rumored. It’s in the first full week of September 2026, which is also when Labor Day is.
Since 2011 when Apple moved its iPhone launches away from their original announcements in June, the unveiling has been close to Labor day three times. In 2015, 2016, and 2022, and each time Apple has made its announcements on the following Wednesday.
In the 15 years since that move to the last quarter of the year, Apple has launched iPhones on Wednesdays five times. It’s launched them on Tuesdays nine times, and on Mondays just once, in 2024.
With the exception of the October launches in 2011 and 2020, every iPhone has been unveiled in the first two weeks of September. The latest date was September 14, in 2021 with the iPhone 13 range.
Then the earliest is a tie between 2016 and 2022, which were both on September 7.
Despite occasional leaks, we obviously won’t know for certain when the iPhone launch is until Apple announces the date. But the company has form on even those invitations, too.
It’s a form that seems to be lengthening, too. Back around 2013, it was common for Apple to issue invitations to the launches one week ahead of the event.
Expect another gorgeously-designed invitation like this one from 2025, which will then be studied intently for clues – image credit: Apple
That happened several times, such as in 2015, 2016, 2018, and again in 2021. Then for the iPhone 14 event on September 7, 2022, Apple revealed the date two weeks before with an AR invite.
There was again two weeks’ notice for the iPhone 15 in 2023, and the iPhone 16 in 2024.
In fact, from the iPhone 14 onwards, Apple has consistently issued invitations two weeks to the day before the event. That means it is now always during the last week of August that it reveals the date.
So expect the 2026 invitation and event date to be announced on Wednesday, August 26. Expect the event to be on Wednesday, September 9, 2026.
Which just leaves the question of when the new iPhones will be available to pre-order. Typically that happens on the Friday immediately following the event, and that won’t be changed because of the unveiling being on a Wednesday instead of a Tuesday.
It might be changed because the Friday is September 11. Apple has avoided doing anything on that date since the World Trade Centers were destroyed on September 11, 2001.
Then Apple isn’t likely to delay taking orders by very much, if at all, but it might have to push back shipping dates. Typically buyers start getting their iPhones by the Friday after pre-orders open, and that’s also when retail Apple Stores get their first stocks.
For the first time since COVID, though, there are likely to be delays in production. In this case it’s because of the global chip shortage, which could conceivably mean a longer than usual gap between launch and shipping.
Or it might be that Apple launches on its usual schedule, but will then take longer than normal to fulfil orders.
That’s specifically been rumored for the expected iPhone Fold, but it’s possible for the iPhone 18 Pro and iPhone 18 Pro Max too.
Then if the invitation date, event date, pre-order and shipping dates aren’t enough, Apple looks like it will have one more whole set of dates to look out for. Perhaps because of the chip shortage, Apple is strongly rumored to split its iPhone launch for the first time.
If this is correct, the presumption is that Apple will launch its biggest sellers, the Pro models, first. So the regular iPhone 18 may launch in the Spring instead.
It isn’t as likely to get an event, though, so at least there’s just the launch, pre-order and shipping dates to wonder about then.
Over 120,000 Flock cameras are found along roads throughout the United States, surveilling 6,000 communities. While these artificial intelligence cameras are meant to be used to record license plates for related crimes, residents have remained skeptical, accusing Flock cameras of putting personal information beyond just plates in nationwide databases that don’t have proper oversight. It certainly hasn’t helped that there have been over 50 cases of police officers misusing the information gathered from Flock cameras, most often to spy on women.
Georgia is one of the most Flock-heavy states, with Atlanta boasting the most cameras in the country at 5,000. Ten officers from the state have been arrested for misusing the license plate information collected from the Flock cameras, with additional officers still under investigation. Former Police Chief Michael Steffman had used the cameras to monitor his ex-girlfriend’s location around Atlanta over 600 times, reported The Washington Post, resulting in stalking, harassment, and license plate reader misuse charges. He was found dead before he went to trial.
The Institute For Justice has been reviewing the privacy and security concerns associated with Flock cameras, noting that the most common reason for surveillance abuse has been stalking partners, exes, and even attractive strangers.
There are currently around 30 cases of police officers using Flock cameras to stalk their romantic interest. In Georgia, Deputy Christian Brewer was fired and arrested after using Flock cameras to track his partner. Sergeant Michael Palitz resigned after stalking a female officer in Texas. Florida Detective Brandy Almany was fired and charged for using data to track her husband’s ex-wife. Deputy Lamar Roman in Florida was able to eventually pull over a woman he’d been stalking with Flock cameras.
Flock Safety (Flock’s official blog) has stated that there are internal safeguards to prevent misuse, including logging every search and providing audit tools to identify unusual usage. However, the Institute For Justice reported that most stalking incidents were not internally investigated and were only found out once the victim realized they were being followed and contacted police. With no required warrant, every police officer has the ability to look at all private information captured by Flock cameras — and it seems to go unnoticed. To fight against Flock cameras’ invasiveness, drivers have started mapping out where the cameras are located and checking if they have been stalked on HaveIBeenFlocked.
It’s August, which means one thing if you follow smartphones even remotely closely: new Pixels are almost here. Google is holding its next Made by Google event on August 12, and this year, we’re expecting another packed lineup of phones. The Pixel 11, Pixel 11 Pro, Pixel 11 Pro XL, and Pixel 11 Pro Fold are all expected to take the stage. Yes, that’s the same four-phone lineup Google gave us last year, but the interesting part will obviously be what’s changing underneath. Between the usual camera improvements, new hardware, and whatever AI tricks Google has been cooking up, there should be plenty to talk about.
And the phones may only be part of the story. Google is expected to have a few more announcements up its sleeve, making this one of its biggest hardware events of the year. So, if you’re planning to tune in, here’s when the Made by Google event starts, how you can watch it, and everything we expect Google to announce.
First up, and probably the reason most people will be tuning in, is the Pixel 11 series. At this point, though, Google may not have many surprises left to pull out of its pocket. The phones have leaked extensively over the past few months, and if those leaks are accurate, anyone hoping for a dramatic redesign might want to temper their expectations. From everything we’ve seen so far, Google appears to be sticking with the design language it established with the Pixel 10 family. That isn’t necessarily a bad thing — I quite like the current Pixel look. Still, the Pixel 11 series probably won’t be one of those upgrades you can immediately identify from across the room. There is one addition that could make it stand out, though. Google has already teased a new light built into the camera bar, reportedly called HiLight or Pixel Glow. It appears to borrow its look from Gemini’s rainbow-like visual language, potentially lighting up while you’re interacting with Gemini or waiting for the AI to finish thinking. But I’m much more curious about what Google does with it beyond AI. Imagine different colors appearing for notifications, charging status, timers, or even incoming calls. If Google gives developers access to it, that little light could end up being far more useful for users.

The bigger changes should be happening inside. Google’s new Tensor G6 chip is expected to power the Pixel 11 lineup, replacing the Tensor G5 from last year. A faster processor is always welcome, but raw performance isn’t really what I’m interested in here. After using recent Pixels extensively, I want to see how the G6 behaves when you’re actually pushing the phone — shooting photos and videos, navigating on mobile data, jumping between apps, or simply using it outside on a hot afternoon. Better thermal management would mean much more to me than another impressive-looking benchmark score. Battery life and charging are equally high on my list. Samsung has finally started embracing silicon-carbon battery technology and faster charging with its Galaxy Z Fold 8 series, so I’d love to see Google make similar progress rather than playing things safe for another generation. A phone can have all the AI features in the world, but none of them are particularly exciting when you’re hunting for a charger halfway through the day. Then there’s the price. Android Headlines has reported that the Pixel 11 Pro could start at $1,099 in the US and €1,199 in Europe. If accurate, that would make the US model $100 more expensive than the Pixel 10 Pro, which launched at $999. The reported colors are Dune, Light Fog, Midnight Haze, and Pine, although those names apparently aren’t finalized yet. Still, with Google’s event only days away, I wouldn’t treat any leaked pricing or naming as gospel. We won’t have to wait much longer to find out what the Pixel 11 series actually costs — and, more importantly, whether Google has done enough this year to justify paying more for one.
Next up is easily the announcement I’m most excited about: the Pixel Tag. Google has somehow gone this long without making its own Bluetooth tracker, but if the recent leak spotted by 9to5Google is accurate, that could finally change at this year’s event. And honestly, it’s about time. Apple has had AirTags for years, Samsung has its SmartTag lineup with a third-generation model reportedly on the way, while Pixel owners have largely had to rely on third-party trackers. A proper Pixel Tag could finally fill that rather obvious hole in Google’s hardware ecosystem.

The leaked tracker has an oblong design and is expected to work with Google’s Find Hub network, which would allow nearby Android devices to help locate something you’ve lost anonymously. The feature I’m really hoping makes the cut, though, is Ultra-Wideband. That could give the Pixel Tag much more precise directional finding when you’re close to a lost item — the kind of experience that makes hunting for keys buried somewhere around the house considerably less annoying. There is one slightly amusing design choice, however. The Pixel Tag reportedly won’t have a built-in lanyard hole, meaning Google could follow Apple’s approach of making you use a separate accessory if you want to attach one to your keys or bag. Samsung’s rumored Galaxy SmartTag 3 is apparently heading in the same direction, too. So it’s quite clear that Bluetooth trackers have collectively decided that holes are no longer fashionable. Still, if Google gets the fundamentals right — particularly UWB tracking and tight integration with Find Hub — the Pixel Tag could be one of the smallest announcements at the event, but potentially one of the most useful.
Of course, it wouldn’t really feel like a Made by Google hardware event without a new Pixel Watch showing up, and this year, that should be the Pixel Watch 5. Visually, Google doesn’t appear to be tearing up the rulebook, but the upgrades happening underneath could be much more interesting. Battery life is the first thing I’ll be watching. The Pixel Watch 5 is expected to squeeze slightly larger batteries into both sizes, which is always welcome on something you’re supposed to wear all day, track workouts with, sleep in, and somehow still have enough juice left for the next morning. It’s also rumored to use a faster version of Qualcomm’s Snapdragon W5 Gen 2 chip, which should hopefully make everyday interactions feel quicker and smoother.

Storage could get a surprisingly big bump, too. Rumors point to the Pixel Watch 5 offering twice as much storage as its predecessor. That might sound excessive for a watch, but it starts making more sense when you consider how heavily Google is leaning into Gemini Intelligence. With Wear OS 7 pushing smartwatches toward becoming more contextually aware and capable of handling tasks on your behalf, that extra room could eventually become quite useful. As for the hardware itself, the familiar 41mm and 45mm sizes are expected to stick around, along with the same IP68 dust and water resistance and 5ATM rating. So, if you already like the circular Pixel Watch design, Google apparently sees very little reason to mess with it. Pricing could remain familiar as well. According to GSMArena, the 41mm Pixel Watch 5 is expected to start at $399, with LTE adding another $100, while the larger 45mm model could begin at $429.
Those are the announcements I’d put firmly at the top of the list, but Google could still have a couple of surprises waiting in the wings. And this is where things get a little more interesting. Earlier this year, Google confirmed that it was working on a new generation of laptops that would bring Android and ChromeOS much closer together. We haven’t heard much about the project since, but Google previously pointed to a fall launch, which puts us awfully close to that window. I’m not necessarily expecting Google to roll out a laptop on stage on August 12, but a teaser, a name, or even a proper look at what it has been building certainly wouldn’t feel out of place. The interesting bit is that these so-called Googlebooks aren’t expected to replace Chromebooks. Instead, they could sit above them as a more premium option, built around a unified operating system and much tighter integration with Android phones.

Then there are smart glasses, because apparently every tech company has looked at Meta’s Ray-Bans and decided our faces are the next great computing platform. Samsung has already given us a glimpse of its own plans, and Google has been steadily building toward Android XR glasses as well. That makes the Made by Google stage a pretty tempting place to show them off again. I wouldn’t necessarily count on being able to buy a pair immediately, but a fresh demo or even a launch window would be enough to get my attention. And that’s what makes this event particularly interesting. We already have a pretty good idea of what’s coming from the Pixel 11 family, but it’s the things Google hasn’t spent the past few months leaking all over the internet that could end up providing the biggest surprises.
All of that sounds exciting, but there’s one rather important detail left: how do you actually watch Google announce everything? Google is doing things a little differently this year — Google will share its announcements earlier in the day before holding the Made by Google show later that evening.
The event takes place on August 12 at 3 PM PT, and you’ll be able to watch the entire thing live on YouTube. So, whether you’re here for the Pixel 11 series, desperately waiting for the Pixel Tag like I am, or simply curious to see whether Google has a surprise tucked away for the end, you can tune in and watch everything unfold in real time. And considering how much hardware could be on the table this year, it might be worth sticking around until the very last announcement.
Gen Threat Labs followed two H1 2026 campaigns where attackers used legitimate accounts, browser settings and blockchain data as part of the attack path.
The Gen Threat Report is a twice-yearly examination of the biggest cyber threats shaping the digital landscape, offering an in-depth look at the trends affecting consumers around the world. Gen’s H1 2026 Threat Report has its share of headline numbers.
Scams accounted for almost 46% of Gen threat detections in the first half of the year. Malvertising represented almost another 30%. Gen blocked 114.2 million e-shop scam attacks and 20.3 million tech support scam attacks during the same period.
Those figures are useful, but they compress very different attacks into a handful of categories. A detection count does not show how the first lure became script execution, how the script became a browser or proxy change, or how a wallet address was replaced before the victim signed a transaction.
Two H1 investigations are worth looking at in detail. In the first, a banking-malware campaign started with compromised corporate mailboxes and ended with proxy and browser manipulation.
In the second, a cryptocurrency campaign used a Rust-based clipper and retrieved command-and-control infrastructure pointers from Binance Smart Chain.
The payloads were different, but neither campaign depended on breaking the trusted system in front of the user. The banking campaign used a legitimate account to deliver the lure. The clipper let the blockchain record a valid transaction after changing the destination address locally.
The banking campaign targeted users in Czechia, Slovakia, Poland and Lithuania. The lures looked like normal business emails: shipment notices, invoice-related messages and scanned document notifications. One simply told the recipient that a scanned copy of a shipment was attached.
In several cases, the messages were sent from compromised corporate mailboxes. The email was not made to look like it came from a legitimate company. It came from a legitimate account that attackers had already taken over.
SPF and DKIM can still pass when a message is sent through authorized infrastructure, while reputation systems may see a sender with a legitimate history.
The attachment launched a JavaScript dropper. From there, the chain moved through PowerShell stages before reaching shellcode and banking functionality. The available indicators pointed towards GepyS.
The malware modified proxy settings and installed a browser add-on, placing itself close to the victim’s banking session.
At a simplified level, the chain looked like this: compromised mailbox -> JavaScript dropper -> PowerShell stages -> shellcode loader -> proxy and browser manipulation.
One stage-three payload used a 32-bit position-independent loader. Static analysis showed MMX and SSE junk instructions, jumps into the middle of instructions, and a decryption routine based on an LFSR-generated keystream followed by XOR.
None of those techniques was new, but together they added enough friction to make a quick static pass less productive.
Across the chain, the email only had to get the user to open the attachment. JavaScript and PowerShell handled the staging, the loader slowed analysis, and the proxy and browser changes moved the operation into the banking session.
Comparable H1 campaigns used similar regional and operational patterns with different payloads. In Italy, fake invoice PDFs, including Booking.com-themed lures, led to Vercel-hosted scripts with per-victim JavaScript obfuscation, Blogspot-hosted PowerShell stages and XWorm.
In Poland, invoice-themed phishing delivered a steganographic .NET loader that installed Remcos RAT.
Gen Threat Labs analyzed H1 2026 activity across scams, malware, identity exposure, privacy and AI-driven threats.
The full report includes telemetry, case studies and guidance on how attacks are moving through trusted workflows.
The second campaign abused a much smaller user interaction: copying and pasting a cryptocurrency address.
The final payload was a Rust-compiled clipboard hijacker. It monitored copied content for wallet addresses across 21 blockchain types, including BTC, ETH and LTC. When the malware recognized a supported address, it replaced it with an attacker-controlled one.
From the victim’s point of view, the transaction could still look normal: copy an address, paste it into a wallet or exchange, and approve the payment.
The blockchain was not compromised and the wallet’s cryptography was not broken. The transaction itself was valid, but the destination had already been changed locally before signing.
Wallet addresses are long, visually noisy strings and difficult for humans to verify. Many users check only the first and last few characters, giving attackers room to use replacement addresses that survive a quick glance.
The command-and-control design added another layer. The malware used Binance Smart Chain as part of its C2 resolution through EtherHiding. It did not store the full backend on-chain. Instead, it read infrastructure pointers from data stored in a smart contract and used them to reach attacker-controlled infrastructure.
The resolved domain, URL or IP address could be blocked, taken down or replaced. The smart-contract data remained publicly readable, useful as an investigative pivot and harder to remove through normal takedown processes.
A simple network IoC list therefore aged quickly in this setup.
The contract address, the method used to read its data, the returned value and the infrastructure reached afterwards belonged in the same investigation.
For the banking chain, sender authentication needs to be paired with post-delivery telemetry. An attachment launching JavaScript, PowerShell retrieving additional stages, shellcode execution, proxy changes and a new browser extension should be correlated as one sequence rather than handled as unrelated events.
A sender’s legitimate history should not lower the priority of that activity when the mailbox itself may be compromised.
Where operationally possible, organizations can restrict script interpreters for users who do not need them, apply application-control policies to downloaded attachments and alert on unexpected proxy or browser-extension changes.
Monitoring for mailbox takeover remains part of the same detection problem because the compromised account is also the delivery infrastructure.
For the crypto campaign, defenders can monitor clipboard-modifying processes, wallet-address pattern matching and blockchain queries from applications that have no reason to make them. The smart-contract pointer and the infrastructure it resolves should be tracked together rather than treating the current C2 domain as the complete indicator set.
Users making cryptocurrency payments should verify the full destination shown by the signing device or wallet immediately before approval.
Address books or allowlists reduce repeated manual entry, while first-time or changed destinations deserve a full comparison rather than a check of only the opening and closing characters.
In both campaigns, the first trust decision could look legitimate while the surrounding workflow had already been changed. Detection and verification need to cover the steps between the authenticated email, the copied value and the final action.
Gen’s H1 2026 Threat Report covers the broader picture across scams, malware, identity exposure, privacy and AI-driven attacks.
Sponsored and written by Gen Digital.
Levi Strauss & Co. (Levi’s) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines.
The company has disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC), saying that its response was sufficiently quick to prevent the compromise of consumer data.
“Based on preliminary findings from the Company’s investigation, the Company believes that certain corporate information was accessed and exfiltrated as a result of the incident,” Levi’s says.
“As of the date of this filing, the Company believes that its rapid response efforts successfully contained and terminated the unauthorized access, and that no consumer data was impacted.”
The company added that it has not experienced any interruption in business operations as a result of the incident.
Levi’s clothing giant has 19,000 employees and an annual revenue of $6.3 billion, best known for its signature 501-line jeans.
The company operates at least 3,300 stores worldwide, and its products can also be found in numerous third-party retail shops, both “brick and mortar” and online.
The firm says it recently detected a cybersecurity incident in which an unknown attacker social-engineered three of its employees, resulting in the breach of company-issued computers.
The investigation launched in response to the incident remains ongoing, and additional notifications will be provided to affected parties as required.
Based on the findings of the investigation to date, Levi’s does not believe the incident will have a material impact on its business or financial position.
Levi’s also noted that it has not experienced any operational disruptions as a result of this breach.
BleepingComputer could not identify online any threat actors claiming the attack on Levi’s.
However, some media outlets have linked this incident to UNC6671, which Google’s Threat Intelligence Group (GTIG) associated with a recent wave of voice phishing attacks targeting hundreds of organizations.
Although Levi’s stated that no customer data was impacted, until more information becomes available, holders of Levi’s shop accounts should monitor for suspicious activity and promptly report it to the firm.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
One of Apple’s memory suppliers is making a massive investment to expand chip production amid global shortages, but it won’t make your next iPhone any cheaper.
On Friday, SK hynix announced that it has approved a 54 trillion won ($38.3 billion) investment to build two new semiconductor fabrication plants in South Korea.
The investment includes 35.2 trillion won ($24 billion) towards the Yongin Y2 facility, which will produce high-bandwidth memory (HBM) and next-generation DRAM products. Construction will begin in 2027 and wrap up by 2029.
A 19.1 trillion won ($13.6 billion) investment will go towards building the Cheongju M17 facility set to open in late 2028. The facility would serve as a NAND production base, geared toward enterprise SSD and AI inference storage.
SK hynix is one of the world’s largest memory chip manufacturers. It’s one of Apple’s key memory suppliers and provides components used across Apple’s lineup, including the iPhone, iPad, and Mac.
Unfortunately, neither of these investments directly helps the average Apple consumer. Instead, the new facilities are being built to serve high-growth AI and enterprise markets, not traditional consumer electronics.
Of course, one could argue that by creating dedicated facilities for increasing enterprise products, SK hynix could give itself breathing room to manufacture consumer-grade products.
And, maybe that’s true.
Even still, SK hynix’s investment isn’t going to solve issues anytime soon. After all, the plants aren’t even slated to open until late 2028 at the earliest.
We’ve said it before, and we’ll say it again: this is going to get worse before it gets better.
Currently, DRAM prices are edging up to an untenable level for even large corporate customer bases, with nothing to say of the average consumer.
DDR-5 DRAM prices have very nearly sextupled on average on the consumer side. In February 2025, two 16GB sticks of DDR5-6000 RAM sold for about $100.
Present pricing is around $600.
We’ve most recently seen the effects as Apple increased prices on most of its product lineup.
The increase wasn’t surprising. Inflation and supply chain issues often drive prices “up like a rocket,” especially on consumer-level products.
The market, bolstered by consumers at all levels rushing to buy products “before they get any more expensive,” stands to make a good profit. That is, at least, until people genuinely can’t afford the costs.
And while we’ll likely see a drop in pricing due to increased manufacturing and market correction, I wouldn’t expect it to be fast or dramatic.
Instead, prices will float “down like a feather.” Slowly, and likely in a sine-wave pattern.
The point, as it often is, is that asymmetric price transmission is a real pain in the ass for the end consumer.
Global supply chain shortages are a real thing. The boom of AI has put a lot of stress on manufacturers to keep up with demand.
But let’s not point the accusatory finger purely at data centers and general market scarcity. There’s plenty of blame to go around.
It’s important to remember that SK hynix is also one of the companies targeted in a recent price fixing suit.
The complaint centers on DRAM, the working memory used in computers, smartphones, tablets, servers and many other electronic devices. Samsung, SK hynix and Micron dominate the global DRAM market, giving them enormous influence over memory supply.
Allegedly, Samsung, SK hynix and Micron shifted manufacturing capacity toward HBM, which commands much higher prices from AI companies. This shift has left DRAM supplies dwindling across the tech industry.
And yes, companies are allowed to pursue more profitable products. But the real question is whether these companies coordinated the production decisions or reached them independently.
Ultimately, whatever investments SK hynix makes right now doesn’t solve the immediate problem. Suppliers have already sold their entire production capacity of memory at high prices through 2027.
Get ready to unleash your inner demon when Overwatch Season 4 begins on Aug. 11. The game’s next chapter brings new tank hero D.Mon, who comes from the same robot suit-piloting Meka Squad as launch hero D.Va but brings a different style of gameplay to the hero shooter’s tank roster.
Yuna “D.Mon” Lee enters the roster as the first new tank hero since Domina back in February. The mech pilot has been in the lore since 2018, when she appeared in D.Va’s Shooting Star cinematic, and the community has been begging for more mech heroes ever since.
And here she is: the new leader of South Korea’s Meka Squad. D.Mon is an “untouchable, cool ice queen,” according to Eleni Rivera, a narrative designer for Overwatch. That’s an interesting contrast to the Meka team’s former leader as mentioned in the lore, who was much louder and more in your face. D.Va was a bit more of an individualistic leader, doing her own thing, Rivera said, whereas D.Mon is much more about being a cool, collected team player.
In a group media interview, Lead Hero Producer Kenny Hudson said, “The story of this hero has been great attention to detail, and pride in the craft.” Much like the rest of the community, the Overwatch team has had high expectations for this hero for years.

In contrast to D.Va’s design, which fulfilled a more ballistics-based mech fantasy, D.Mon brings agile, sci-fi sword and shield gameplay to Overwatch. Referencing the popularity of the game’s iconic, hammer-swinging tank, Reinhardt, Hudson said the team wanted to expand the melee tank roster, aiming to “give those players who like to play up-close and personal with their tanks more to choose from.”
D.Mon’s primary fire swings a plasma sword in an arc in front of her, while her secondary fire pulls up a shield. While the shield is up, you can activate primary fire to lunge forward with the sword, dealing damage and knocking back enemies. She also has a Fusion Repeater ability that gives her a few seconds of ranged damage and a resource-based horizontal dash ability that boosts her quickly along the ground.

Hudson said D.Mon’s design was partly inspired by the team wanting to see what happens when you have a melee tank with more mobility. As a result, she’s able to dash around while holding up her shield, giving her a distinct feel from other melee tanks, who generally lack movement abilities.
Her ultimate ability, called Limit Break, charges up the plasma sword before swinging through a wide arc. The maneuver grants D.Mon overhealth, and any enemies hit take damage from the swipe while also receiving increased damage from other attacks for a brief duration.
Like D.Va, D.Mon switches to pilot form if her mech is destroyed and can build up ultimate charge to call down a new mech. When she does, nearby enemies take damage and are knocked back.
Hudson said that, based on internal playtests, D.Mon is very effective at taking space and works well in rush comps that feature speed boosts from supports like Lúcio or Juno. Her ultimate ability also pairs well with other damage hero ultimates, thanks to the damage amplification element, Hudson said, while noting that D.Mon had to play heavily around cooldowns — especially the fuel for her dash.

I’m interested to see where D.Mon fits into the overall roster. While her design has echoes of Reinhardt, D.Mon appears to be significantly more maneuverable, though she lacks Reinhardt’s raw melee damage and larger team-friendly shield. And unlike her Meka Squad teammate, D.Mon can’t boost into the air to quickly claim high ground or circumvent shields. Instead, she’ll have to rely on the quick bursts of horizontal movement to circle around (or maybe plow straight through) enemy teams.
Her dash ability and melee weapon should be a tough matchup for tanks like Domina and Sigma, who rely on barriers and distance to stay safe. I also imagine her being effective against low-mobility heroes like Cassidy, Ana and Illari, who might not be able to escape a D.Mon dashing in with shields up.

A team of D.Mon along with flankers, like Shion, Tracer or Genji, and a backline of healers, with Juno, Ana or Kiriko, sounds good to me on paper. The flankers can match D.Mon’s engagement, especially with the help of a speed-boosting Hyper Ring, and can help the tank burst down key targets. A similar team with one flanker subbed out in favor of someone like Cassidy or Sojourn may also work, with D.Mon and the flanker causing havoc and creating space for the ranged damage player to do their thing.
At the same time, I imagine D.Mon having trouble against an enemy team full of ranged damage heroes that can maintain their distance, especially on maps with high ground, or against highly mobile teams that are hard to pin down. D.Mon seems like she would struggle against a Winston or Wrecking Ball with Tracer, Echo or Pharah dealing damage from afar and extremely mobile supports like Kiriko, Lúcio and Jetpack Cat, all of whom would be hard to pin down with a plasma sword.
Exciting new tank heroes are the best thing Overwatch can add to the game. The tank role is the least popular because it’s the one that most challenges your map knowledge, macro strategy and — based on personal experience — overall mental fortitude. Most players, me included, generally find it more fun to just run around shooting things or healing teammates.
With a good team, though, playing tank can feel electrifying. The glory of being the team leader, drawing enemy attention and clearing space for your teammates is a unique type of thrill in Overwatch. Sadly, it’s too often undermined by any combination of uncoordinated teammates, enemy counter-swapping or just generally having every single resource and crowd-control ability thrown in your direction.

Junker Queen has become my go-to tank because she’s a little more self-sufficient, thanks to her damage abilities’ bonus self-healing — and because she depends on smart use of those abilities. A Junker Queen who lands every knife and axe swing will dominate a lobby; one who misses most of them will immediately crumple.
I’m hoping that D.Mon offers a similar experience. Her Fusion Repeater can get bonus damage on a head shot, rewarding precise aim, and I’m hoping that her dash ability supports enough skill expression to reward practiced and creative uses. I can already envision the thrill of turning a losing fight with a well-timed Limit Break, keeping D.Mon alive with sudden overhealth while helping your team cut through the remaining enemies.
I’ve been playing more tank for the past week just in anticipation of D.Mon’s release, and seeing her kit in detail has only made me more excited about yeeting myself into the frontlines. That may or may not last over the course of the season, but it’s the first time since Junker Queen launched in 2022 that I’ve been excited about playing tank, and that itself is an achievement.
See you on the battlefield in season 4.
A go-kart track is an odd location to launch a tech initiative in the nation’s biggest city. Yet last month there was New York City mayor Zohran Mamdani, zipping around the 900-foot oval at Coney Island’s Luna Park before stepping up to a podium to unveil a program called Public Interest Technology (PIT) Crews. Thus the go-kart theme.
PIT will consist of five “game-changing” teams that, Mamdani promised, will “raise the bar for what New Yorkers can expect from City Hall.” Working closely with city agencies, these small groups of engineers and designers will strive to change the hidebound and confusing tenor of current city services by using state-of-art skills to rapidly whip up specialized apps that solve real problems. “We want to transform how New Yorkers interact with the government,” said the mayor. “We want to raise expectations on what government can deliver, because we really can deliver.”
Do those words sound familiar? If you follow government tech, they might. Because Mamdani’s message could have fit quite comfortably in the pitch that Barack Obama’s chief technology officer, Todd Park, delivered in 2014 while recruiting tech talent for what would become the United States Digital Service. The USDS was an idealistic effort to bring top Silicon Valley talent into the executive branch to bypass the logjams caused by outdated and inefficient IT, by building great, user-centric software.
The agency somehow survived the first Trump administration and kept going through the Biden term. But in 2025, Elon Musk and his DOGE wrecking crew infiltrated the agency and pulled the plug on much of the useful stuff. (Now, with the National Design Service, the Trump administration is ostensibly trying to revive some of what it destroyed.)
Mamdani’s PIT crew initiative adopts much of the original USDS ethos, with a timely twist: It embraces Silicon Valley expertise while taking a skeptical, almost adversarial, stance toward Big Tech itself. The combination of mayoral charisma and a chance to make software that doesn’t serve advertisers, the military, or the pocketbooks of centibillionaires makes the Mamdani team an attractive, high-status, mid-career change of pace for some techies. Suddenly, one of the sexiest places in geekdom is the Brooklyn headquarters of New York City’s Office of Technology and Innovation.
Mamdani’s transition team set the stage for an urban, democratic-socialist-adjacent, USDS-style tech squad when it tapped Lisa Gelobter for the city’s chief technology officer job. Gelobter’s résumé includes stints at big companies and startups, but the standout item was her post at the United States Digital Service, where she was embedded in the Department of Education. She led the effort to create a College Scorecard that focused on nuts-and-bolts criteria like costs and graduation rates. To this day, she gets misty when recalling her Washington experience; she even remembers what she was wearing when the USDS team took a group picture with Obama just before he left office.
“I’m really excited about trying to recapture that essence, that energy here,” she says. Her budget for the program is $5.24 million, with an additional $2 million grant from the Rockefeller Foundation, which will fund one of the crews.
Gelobter says she brings an engineering mindset to New York City government. “I know how to build software,” she says. “I know how to run a technology organization from a technology perspective.” It’s also a cultural thing for her. “I’m wearing jeans to work—not because I don’t look great in a suit, but it’s a statement, right?” she says. (The same norm-breaking happened in the USDS, which had to overcome objections from bureaucrats who didn’t want to meet with anyone wearing a hoodie.) Naturally, the two people Gelobter hired to run the PIT crew program are also USDS veterans, Luke Farrell and Maya Israni.

Zillow Group’s layoffs will eliminate 91 jobs in Washington state, landing heavily on senior staff, according to a notice the company filed with the state Employment Security Department.
The filing under the federal Worker Adjustment and Retraining Notification (WARN) Act is the first detailed accounting of who was affected by the more than 500 layoffs the company announced Tuesday. The cuts hit about 7% of its global workforce, which stood at 7,058 as of March 31.
Zillow Group is officially headquartered in Seattle, but the relatively small share of the layoffs in its home state (18%) reflects how distributed it has become. The company adopted a remote-first model it calls “Cloud HQ” in 2020, at the height of the pandemic, and it has continued to bet on remote work as other tech companies pulled employees back to the office.
The list of affected job titles in Washington state is dominated by senior positions. It includes five directors and three senior directors, 14 principal-level roles, and a long list of senior managers and senior individual contributors. Relatively few junior positions appear on the list.
Product and engineering absorbed the most. Senior Product Manager is the single largest line at seven positions, followed by Senior Software Development Engineer, Software Development Engineer and Senior UX Researcher at four each. Together, product and engineering roles account for more than a third of the Washington cuts.
The list also includes AI and machine learning positions: a Senior Machine Learning Engineer, a Senior Manager of Machine Learning Engineering, a Senior Applied Scientist, a Senior Manager of Research Science, and an Annotation Lead, associated with labeling data to train AI models.
@media (max-width: 600px) {
aside.callout { float:none !important; max-width:100% !important; margin-left:0 !important; margin-right:0 !important; }
aside.callout .callout-img { display:none !important; }
}
Zillow told GeekWire on Tuesday that AI did not drive the layoffs. “Today’s changes are about better positioning Zillow for the path ahead, which includes having the right people in the right roles and being able to move faster,” a company spokesperson said.
The WARN notice adds a detail Zillow did not mention publicly: “Some of these terminations are the result of, or are expected to result in, the relocation or contracting out of operations and/or employee positions.”
Affected employees were notified Aug. 4 and will be terminated effective Oct. 5, more than 60 days later as required under state and federal law. They will continue to receive pay and benefits until then, according to the filing. Employees who are offered and accept another role at the company before that date will not be terminated.
The cuts affect workers at Zillow Group’s headquarters at 1301 Second Ave. in downtown Seattle and employees working from home elsewhere in Washington. The company said in the filing that its headquarters will remain open. None of the affected employees are represented by a union.
Zillow Group reports second-quarter earnings Wednesday afternoon.
networks
Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again
N-able has confirmed attackers exploiting an N-central zero-day made it into customer networks, as the vendor pushes out a second mandatory hotfix just days after the first.
The security shop published an update on Thursday detailing what happened after attackers exploited CVE-2026-18577, the critical N-central flaw that can hand an unauthenticated attacker administrative access to the remote monitoring and management platform.
According to N-able, attackers exploited vulnerable N-central servers remotely, then used the platform’s Take Control feature to connect to systems inside the environments being managed through them.
Once there, they registered a new Cloudflare Tunnel service to keep their foothold even after being booted from the N-central server – behavior that Huntress had already observed in the wild.
N-able has now confirmed that its own investigation found the same activity, and says a “limited number” of customers were affected. It hasn’t said how many customers that means, how many downstream systems attackers reached, or what they did once they had established persistent access.
N-Able didn’t answer these questions when asked by The Register, instead providing a statement saying it is “proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques.”
The firm’s limited disclosure comes alongside Hotfix 2, version 2026.3.1.10, which N-able says customers running N-central on-premises must install immediately – including those that already installed the first emergency fix released on August 2.
“This is not a duplicate of our previous communication,” N-able warned. “Hotfix 2 is required, even if you already applied the earlier hotfix.”
The company says the new update supersedes Hotfix 1 and adds further hardening measures as it monitors threat actors and watches them “evolve their attack techniques.”
Exactly what prompted the second round of defenses isn’t clear. N-able hasn’t said whether attackers found a way around Hotfix 1, and its latest description says the exploited vulnerability affected N-central servers running versions prior to 2026.3.1.7, the first hotfix. Hosted N-central environments have already received the latest mitigations, according to the vendor.
N-able first became aware of the attacks on July 31, after its Adlumin managed detection and response service picked up suspicious activity at a customer. Further digging uncovered a zero-day being actively exploited against an N-central server.
CVE-2026-18577 was subsequently disclosed, and the first hotfix was released on August 2. CISA added the bug to its Known Exploited Vulnerabilities catalog and gave US federal agencies until August 6 to fix it – an unusually short three-day deadline reserved for vulnerabilities the agency considers an urgent risk.
N-central is particularly attractive territory for attackers because managed service providers use the software to administer large numbers of customer systems from one place. Compromising the management platform can therefore provide a route into machines belonging to the MSP’s customers rather than leaving attackers stuck on the original server.
Huntress previously described successful exploitation as giving an attacker the same level of N-central access normally reserved for trusted network operations and engineering staff. Its investigation found attackers using that access to launch remote-control sessions against managed endpoints.
N-able has now published 10 IP addresses it says were used in the attacks and released a service template that customers can use to hunt for known indicators of compromise on Windows endpoints.
The company is warning customers not to take a clean scan as an all-clear, however, saying the tool only checks for indicators identified so far and that more may emerge as its investigation continues.
For anyone running N-central on-premises, the immediate instruction is pretty straightforward: install Hotfix 2, even if Hotfix 1 is already in place. ®
I mean, they’ve been around forever.
The humble USB flash drive has been among the most enduring pieces of consumer technology. After unseating the floppy disk as the portable storage medium du jour, flash drives began to hit the consumer market in the early 2000s, and they’ve been collecting dust at the bottom of backpacks and desk drawers ever since. Whereas floppy disks held very little data, flash drives came off the top rope with multiple whole megabytes of capacity and much faster data transfer rates. Those figures improved over time, scaling as flash storage increased in capability. But has the flash drive finally reached the end of the road?
The Museum of Obsolete Media still rates USB flash drives at a 1, indicating a low risk of obsolescence. As long as USB ports don’t go the way of the dodo, neither will these convenient little drives. The increasing cost of other storage mediums is likely to prolong their popularity, too. But while there’s no direct evidence of declining flash drive sales, they’ve fallen out of favor as people deal more regularly with large files and faster data transfer capabilities on newer hardware. Increasingly, more capable devices are needed, especially for people working in IT or creative professions.
So, what are thumb drives still good for, and should you be transitioning away from them? That depends.
If flash drives no longer feel flashy, that can be chalked up to their increasing impracticality. Their relatively small capacities — most brands top out at 128GB — make them useless when dealing with large files. Many people now deal with larger files than ever. New smartphones can produce libraries of 4K video which take up roughly 1GB for every minute of footage at high frame rates. ZIP archives, smartphone or PC backups and other such files can easily exceed the capacity of a thumb drive. Even if your files fit on a flash drive, they’ll transfer at relatively slow speeds.
SSDs pick up the slack. The best SSDs tend to have larger capacities of 1TB or more and much faster transfer speeds. They’re also more durable, with portable SSDs often clad in protective housings, and they tend to use higher quality memory controllers. The ease with which they can outlast an average flash drive, all else being equal, makes them better long-term investments. And whereas older SSDs could be somewhat bulky, newer models are eminently pocketable. While not as small as flash drives, they hardly take up space in most bags.
Lastly, there’s USB-C, which is the only type of data port on some newer laptops. USB-C flash drives do exist, but SSDs make things much simpler by using a cable. Most popular portable SSDs include both a USB Type-A and Type-C cable, allowing the user to choose the better option for their personal needs.
Whatever downward trajectory the humble flash drive may have been on, the AI boom has upended that gravity. Thanks to the surge in demand for data center storage and memory, the price of an SSD has skyrocketed since late 2025, and PC sales have fallen. After stabilizing at dirt-cheap prices that made data hoarding more economical than ever, the rush of new demand sent prices into the stratosphere. The 4TB Samsung 990 Pro SSD I used in my last PC build cost me $318 in November 2025, but Amazon lists it for $1,100 at the time of this writing. As if to rub salt in the wound, Samsung’s slower 990 costs even more than the original.
Meanwhile, a cursory look at the Amazon listings for USB flash drives reveals a landscape much less likely to induce heart palpitations. They’ve increased in price, but the rate of increase has lagged that of SSDs and HDDs. Additionally, they come in lower storage capacities, which further reduces the per-unit cost. A five-pack of PNY 64GB USB 3.0 flash drives will only run you $43 as of this writing, which is a far lower per-gigabyte cost than that of the Samsung 990. For most people who aren’t shooting reams of 4K video and just need to move a few documents or store some tax filings, flash drives are once again the more attractive option. It’s no wonder that Google Trends data shows a massive spike in search interest beginning in early 2026 for terms like “USB flash drive portable” and “USB flash drive 128GB.”
Moreover, flash drives still have their traditional silver bullet use cases. Want to create bootable media to install a Linux distro or Windows 11 instance on a machine? No use wasting a whole SSD for that. Ditto for running portable, zero-footprint OSes like Tail OS, carrying around a toolbox of diagnostics and repair tools or simply throwing on a keychain so you have access to portable storage in a pinch.
Meta enters AI-training agreement with far-right ‘propaganda rag’ Newsmax
Zack Polanski: an incitement to murder Nigel Farage?
MicroStrategy Post-Earnings CLARITY Act Push Could Add New Catalyst for Its Stock
XRP Ledger v3.3.0 brings five institutional features
New York sues Kalshi over prediction market gambling
Crypto PAC spending tops $2M in Michigan House race
DTCR: Deleveraging And A Hedge Fund Collapse Point To A Possible AI Bottom
ESET tracks rise in malicious AI skills and adaptable malware
3 Fed Officials Just Explained Their Rate Hike Vote: Is Inflation Winning?
France Cricket implodes: letters hidden in a drawer and a board at war
XRP Ledger urges node upgrade after manifest flood
Moneyflip CEO charged in $40K murder-for-hire plot
Bruno Fernandes decision made as Man United ‘discuss’ striker transfer option
FIFA has scrapped $20 billion World Cup sell-off plan, New York Post reports
Financial Crash Expert: The 90-Day Collapse Timeline They Are Desperately Hiding.
Jordan Coyle & Cordiamo take Laya Arena Stakes at RDS
Commonwealth Games 2026 Live Updates | Day 9 CWG 2026: Lovlina Borgohain, Sachin Siwach Enter Final After Indian Judokas Script History
US Tech Stocks See Largest 5-Week Inflow in History: Can Nasdaq Break Its Downtrend?
Tourist plane on sightseeing flight in Peru crashes into a field, killing all 13 people on board
Arsenal reach full agreement with Newcastle over Bruno Guimaraes transfer | Football
You must be logged in to post a comment Login