Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
XGIMI has expanded its Elfin Flip portable projector lineup to four models with the introduction of the Elfin Flip 4K and Elfin Flip Laser, joining the existing Elfin Flip and Elfin Flip Plus. The two additions move the series beyond entry-level LED projection, offering buyers a choice between a 1080p triple-laser projector and a more advanced 4K model.
Both new projectors use RGB triple-laser light engines rated at 1,600 ISO lumens and include a single 7-watt Harman Kardon speaker with Dolby Audio. That represents a substantial step up from the Elfin Flip Plus, which uses an LED light source rated at 500 ISO lumens and relies on two 3-watt speakers. This is considerably more than another model number and a mildly revised shade of beige.
XGIMI has packaged those upgrades inside the familiar book-sized Elfin Flip design, retaining the integrated stand and carry-handle concept that makes the projectors easy to move between rooms and aim at a wall or ceiling. The expanded range now stretches from affordable 1080p streaming to brighter 4K laser projection without requiring owners to drag a black plastic shoebox around the house.
Related Reading: XGIMI Unveils New MoGo 3 Pro, Elfin Flip, AURA 2, HORIZON S Series Projectors For 2024

The Elfin Flip 4K sits at the top of the lineup with 4K display resolution via pixel shifting, an RGB triple-laser engine delivering up to 1,600 ISO lumens of brightness, a 20,000:1 dynamic contrast ratio, 110% coverage of the BT.2020 color gamut, and ΔE<1 color accuracy—specifications that rival those of dedicated home theater installations. Its optical zoom and 0.98–1.3:1 throw ratio enable precise screen sizing without requiring users to reposition the projector.
Weighing just 1.55 kg and measuring 9.64 inches wide, it delivers a large-screen viewing experience with zero visual compromise.
The Elfin Flip 4K’s flip-to-start operation and slim profile reinforce its portability: pick it up, place it, and the picture is ready. XGIMI’s Intelligent Screen Adaptation technology handles the rest automatically through Uninterrupted Auto Keystone, Auto Focus, Intelligent Screen Alignment, Intelligent Obstacle Avoidance, Wall Color Adaptation, and Intelligent Eye Protection.
Gaming Support: For the first time in the Elfin series, the Flip 4K supports console-level gaming performance, with input lag as low as 1 ms at 1080p/120 Hz. It also supports VRR and ALLM, along with Black Equalizer, Virtual Crosshair, and a dedicated Gaming Picture Mode.

The Elfin Flip Laser sits immediately below the Flip 4K in the lineup. It uses the same RGB triple-laser light engine, carries the same 1,600 ISO-lumen brightness rating, and includes the same Harman Kardon speaker system and smart features.
The primary differences are its 1080p display resolution, lower 10,000:1 dynamic contrast ratio, and lack of the Flip 4K’s advanced gaming features.

The Elfin Flip 4K and Elfin Flip Laser each include a 7-watt Harman Kardon speaker with Dolby Audio support, designed to deliver room-filling sound without requiring external audio equipment. Our suggestion: get a soundbar.
With Google TV, users also have direct access to Netflix, Hulu, Amazon Prime Video, and thousands of additional streaming apps, making the Elfin Flip Series a complete all-in-one home entertainment solution.
Pro Tip: The previously released Elfin Flip Plus and Elfin Flip remain the more affordable entry points in the lineup, but both use LED light sources rather than RGB triple-laser engines. Their speaker systems also offer less power and do not benefit from Harman Kardon tuning. Automatic setup features may vary by model.

| XGIMI Model | Elfin Flip 4K | Elfin Flip Laser | Elfin Flip Plus | Elfin Flip |
| Product Type | Portable Lifestyle Projector | Portable Lifestyle Projector | Portable Lifestyle Projector | Portable Lifestyle Projector |
| Price | $999 | $799 | $379 | $299 |
| Light Source | RGB Triple Laser | RGB Triple Laser | LED | LED |
| Display Technique | DLP | DLP | DLP | DLP |
| Display Chip | 0.39” DMD | 0.23″ DMD | 0.23″ DMD | .23” DMD) |
| 3D Viewing Option | No | No | No | No |
| HDR Support | HDR10, HLG | HDR10, HLG | HDR10 | HDR10 |
| Gaming Support / Latency | Game Mode, VRR on, AK off 1ms at 1080P@120Hz |
Game Mode, VRR on, AK off 20ms at 1080P@60Hz |
1080P/60Hz, Game Mode ≤ 20ms (AK off) 1080P/60Hz, Game Mode ≤ 56ms (AK on) |
None |
| MEMC | Yes | Yes | No | No |
| Brightness (ISO Lumens) | 1600 | 1600 | 500 | 400 |
| Resolution | 3840 x 2160 pixels (via Pixel Shifting) | 1920 x 1080 pixels | 1920 x 1080 pixels | 1920 x 1080 pixels |
| Color Gamut | BT.2020 110% | BT.2020 110% | Rec.709 121% | Rec.709 113% |
| Contrast Ratio | 20,000:1 (DBLE ON) | 10,000:1 (Dynamic Contrast) | 4000:1 (EBL ON) | Not Provided |
| Lens | High Light Transmission Coated Lens | High Light Transmission Coated Lens | High Light Transmission Coated Lens | High Light Transmission Coated Lens |
| Eye Protection | Yes | Yes | Yes | – |
| Auto Keystone Correction | Uninterrupted Auto Keystone | Uninterrupted Auto Keystone | Uninterrupted Auto Keystone | Auto Keystone |
| Focus | Auto Focus | Auto Focus | Auto Focus | Auto Focus |
| Intelligent Screen Alignment | Yes | Yes | – | Yes |
| Intelligent Obstacle Avoidance | Yes | – | – | Yes |
| Intelligent Wall Color Adaptation | Yes | – | – | – |
| Optical Zoom | Yes | – | – | – |
| Digital Zoom | Yes | Yes | Yes | Yes |
| Throw Ratio | 0.98-1.3:1 | 1.2:1 | 1.2:1 | 1.2:1 |
| Aspect Ratio | 16:9 | 16:9 | 16:9 | 16:9 |
| Projection Method | Front, Rear, Front Ceiling, Rear Ceiling | Front, Rear, Front Ceiling, Rear Ceiling | Front, Rear, Front Ceiling, Rear Ceiling | Front, Rear, Front Ceiling, Rear Ceiling |
| Image Size | 40” – 200” | 40” – 200” | 40” – 200” | 80 – 150 inches |
| CPU | MT9660 | MT9660 | MT9630 | MT9660 |
| GPU | Mali-G52 | Mali-G52 | Mali-G52 | Not Indicated |
| RAM | 2GB | 2GB | 2GB | 2GB |
| Storage | 64GB | 64GB | 32GB | 16GB |
| System | Google TV | Google TV | Google TV | XGIMI OS |
| Fast Boot | Yes (STR) | Yes (STR) | Yes (STR) | Yes (STR) |
| Mirroring Display | Google Cast / DLNA | Google Cast / DLNA | Google Cast / DLNA | MiraCast/DLNA |
| Speaker System | 1 x 7W Harman/Kardon | 1 x 7W Harman/Kardon | 2 x 3W | 2 x 3W |
| DTS-Virtual:X | – | – | – | – |
| DTS-HD | – | – | – | – |
| Dolby Audio | Yes | Yes | Yes | Yes |
| Dolby Digital (DD) | Yes | Yes | Yes | Yes |
| Dolby Digital Plus (DD+) | Yes | Yes | Yes | Yes |
| WiFi | WiFi 6 Dual-band 2.4/5GHz, 802.11a/b/g/n/ac/ax | WiFi 5 Dual-band 2.4/5GHz, 802.11 a/b/g/n/ac | WiFi 5 Dual-band 2.4/5GHz, 802.11 a/b/g/n/ac | WiFi 5 Dual-band 2.4/5GHz, 802.11 a/b/g/n/ac |
| Bluetooth | Ver 5.2 | Ver 5.1 | Ver 5.1 | Ver 5.1 |
| Input Ports | 120W DC IN x 1
HDMI x 2 (HDMI1 support eARC) USB 2.0 x 2 |
120W DC IN x 1
HDMI x 1 (supports eARC) USB 2.0 x 2 |
120W DC IN x 1
HDMI x 1 (ARC) USB 2.0 x 1 |
DC x 1
HDMI x 1 USB x 1 |
| Output Ports | Audio x 1 | – | – | – |
| Noise Level | ≤28dB@1m | ≤28dB@1m | ≤28dB@1m | ≤28dB@1m |
| Power Dissipation | ≤120W | ≤120W | ≤120W | <65W |
| Power | AC100-240V, 50/60Hz | AC100-240V, 50/60Hz | AC100-240V, 50/60Hz | AC100-240V, 50/60Hz, 19V/3.42A |
| Product Size (HWD) | 254 x 245 x 78 mm
10 x 9.65 x 3.07 in |
254 x 245 x 78 mm
10 x 9.65 x 3.07 in |
235 x 226 x 71 mm
9.3 x 8.9 x 2.8 In |
235 x 218 x 64 mm
9.25 x 8.6 x 2.5 in |
| Product Weight | 1.55 kg 3 lbs 7 oz |
1.38 kg 3 lbs 1 oz |
1.1 kg 2.4 lbs |
1.18 kg 2 lbs 10 oz |


XGIMI offers projectors for everything from casual streaming to dedicated home theaters, but the Elfin Flip Series occupies an increasingly popular middle ground: compact lifestyle projectors that can move between rooms without looking like surplus equipment from a high-school audiovisual department. The Elfin Flip 4K is the standout, combining pixel-shifted 4K resolution, an RGB triple-laser light engine, 1,600 ISO lumens, optical zoom, Google TV, automatic setup, and serious gaming support inside a slim, book-sized design for $999. That combination of portability, optical zoom, wide color coverage, and 1080p/120 Hz gaming performance is what makes it genuinely different.
The Elfin Flip 4K is best suited to apartment dwellers, renters, gamers, and families who want a large image in a bedroom, living room, or temporary media space without permanently mounting a projector. The Elfin Flip Laser offers the same 1,600 ISO-lumen brightness and RGB triple-laser color performance for $799, but drops to 1080p, reduces dynamic contrast, and eliminates the 4K model’s optical zoom and advanced gaming features. Unless the Laser is substantially discounted, spending another $200 for the Flip 4K is not a difficult decision.
There are compromises. Neither laser model includes a built-in battery, so “portable” means easy to carry from room to room rather than movie night in the middle of a field without access to an extension cord. HDR support is limited to HDR10 and HLG, with no Dolby Vision, and 1,600 ISO lumens still does not turn either model into a replacement for a television in a brightly illuminated room. The single 7-watt Harman Kardon speaker may be adequate for casual viewing, but claims of room-filling sound should be approached with the same caution normally reserved for airport sushi. Both models support HDMI eARC, so budget for at least a soundbar if dialogue clarity, bass, and convincing movie sound matter.
The Elfin Flip Plus remains the value option at $379, offering 1080p resolution, Google TV, automatic setup, and 500 ISO lumens. The standard Elfin Flip is also priced at $379 or less, although its lower 400 ISO-lumen output makes the Plus the more sensible purchase whenever the two are selling for the same amount. Casual viewers working with a dark room and tighter budget should start there; buyers seeking the best combination of brightness, resolution, flexibility, and gaming performance should move directly to the Elfin Flip 4K.

Assassin’s Creed Shadows only launched last year, and Switch 2 owners can already pick it up at almost half its original price.
That reduction comes from a limited time deal that cuts Assassin’s Creed Shadows on Switch 2 from its usual £49.99 down to £25.99, a 48% saving that brings one of the franchise’s best reviewed games within easy reach.
Assassin’s Creed Shadows for the Switch 2 is almost half price today, in a time limited deal
This critically acclaimed Assassin’s Creed Shadows on Switch 2 drops from £49.99 to £25.99, a 48% saving on one of this year’s best games.

Playing as Naoe puts the focus on stealth, using noise, light and shadow to slip past enemy patrols, while a new grappling hook opens up parkour routes across castle rooftops that were not available in earlier games in the series.
Naoe’s kit also includes a hidden blade for instant assassinations along with shuriken and smoke bombs to create useful distractions, giving stealth focused players several ways to clear a room without ever triggering an alarm.
Switching over to Yasuke flips that approach entirely, trading stealth for silent bow takedowns and heavy melee combos with a katana or naginata, so a single stronghold can be cleared through patience or brute force depending on your mood.


Switching between the two protagonists mid mission is encouraged rather than locked to separate story chapters, letting you scout a stronghold as Naoe before switching to Yasuke for a more direct assault once guards are alerted.
Both characters explore the same dynamic version of feudal Japan, where castle towns, ports and shrines shift with the weather and the seasons, giving the world a sense of change that keeps returning to the same location interesting.
And now with a glowing discount, you have the chance to explore feudal Japan in all its glory.
SQUIRREL_PLAYLIST_10148964
There is no shortage of examples of Major League Baseball attempting to wield overly broad trademarks its obtained to bully others, nor examples of MLB attempting to stretch its trademark rights much further than they go. MLB opposed a trademark for a Brooklyn burger joint on behalf of the Dodgers, a team that hadn’t played in Brooklyn for over five decades at that point. The league, at one point, tried to bully a local Little League for using the names of MLB teams, but not their logos, which is something that roughly every Little League team everywhere does. It attempted to trademark the names of three cities in which MLB teams play. And, my personal favorite and most appropriate for this post, the league opposed a finance company’s trademark application because it claimed two of its separate teams both owned the rights to the letter “W”.
The real lesson in all of this is that the League can’t be trusted with anything other than very narrow trademarks. Anything more broad than that causes them to act the fool. And perhaps this is a lesson the USPTO has actually learned, given that it recently denied MLB’s attempt to trademark the phrase “Play Ball”.
The United States Patent and Trademark Office denied MLB’s application to trademark “Play Ball” for clothing, the USPTO wrote in a final action filing on Friday.
“In this case, the applied-for mark is a commonplace term, message, or expression widely used by a variety of sources that merely conveys an ordinary, familiar, well-recognized concept or sentiment,” the USPTO wrote in its denial.
The USPTO also wrote phrases “that merely convey an informational message are not registerable.”
Those are things that MLB’s well-dressed lawyers absolutely know, of course. But they attempted to bank on a complacent trademark office to try to sneak one past the goalie anyway, to mix metaphors. And if the league had gotten the mark, you can be one hundred percent certain it would have gone on yet another bullying campaign targeting apparel makers, other sports leagues, and who knows who else.
In fact, the most surprising part of all of this is that it appears to have taken 4 years for the USPTO to reach this decision. Josh Gerben breaks it all down like this.
Gerben said the rejection and public domain nature of phrases could depend on the class. Other companies have trademarked “Play Ball,” including a food company for bubble gum, a minerals company for surfacing playgrounds and “The Play Ball” for the gala fundraiser for the Strong National Museum of Play in Rochester, New York.
“In this case they are saying that the phrase has become so ubiquitous and it has this underlying meaning,” Gerben said. “For a clothing brand, the government doesn’t think it’s unique enough to be registered.”
Somehow, some way, we have to get past this practice of looking at trademarks as some kind of retroactive profit center, where a business gobbles them up and then corners a market that was already in existence. That’s all that this sort of attempt to lock up language is. The term “play ball” can be associated with Major League Baseball, certainly. It can also be associated with other sporting activities, or business negotiations, or any other number of things. That’s because it has become a generic phrase, no longer an identifier of the source of a good or service.
Again, MLB’s lawyers knew all of this before applying for the mark. They just didn’t care.
Filed Under: baseball, play ball, play ball play ball play ball, trademark, uspto
Companies: mlb

A palm-sized drone flies through thick fog, artificial snow, and near-total darkness, dodging poles, transparent plastic sheets, and tree trunks without a single camera or laser. Its only guide is sound. Researchers at Worcester Polytechnic Institute built the system, called Saranga, by copying the way bats find their way in caves. The result is a lightweight, low-power approach that keeps working when vision-based sensors simply stop.
Cameras and LiDAR begin to fail as light becomes dispersed or just disappears. Radar, on the other hand, drains the batteries right when the machines need them. By contrast, ultrasound travels through smoke, dust, and snow in the same way as it does in clean air. Bats have been doing it forever, simply emitting short, high-frequency chirps and listening for faint return echoes that bounce off obstacles. The WPI team, led by Nitin Sanket of the Perception and Autonomous Robotics division, decided to give a flying robot the same superpower.
Sale
They began with a quadcopter that they custom manufactured, measuring 16 cm across and weighing 460 kilos. It has two very tiny TDK InvenSense ICU30201 ultrasound sensors at the front, each with a broad sonic horn. Another one points downward to help with altitude. All of this ultrasound sensing requires only 1.2 milliwatts, and it all operates on a Google Coral Mini computer with no additional beacons or GPS, so there is no extra power expenditure.

Propeller noise was the first major issue, as the spinning blades are basically spewing out some serious ultrasound noise that drowns out the weak echoes coming back from distant objects (we’re talking minus 4.9 decibels here, which is weak signal territory for the team), so they fixed it by physically taping a simple foam and plastic shield between the propellers and the sensors. This barrier shuts out the majority of the prop noise while allowing outward sound and returning echoes to pass through. With this piece of hardware fixed, the usable range increased from one meter to two meters.

Even after they sorted the prop noise with their shield, the returning echoes were still getting lost in the random noise, so they attempted utilizing classical filters to sort it all out, but it wouldn’t comply. They required something more sophisticated, so they trained a tiny neural network to sort through all the filth. They termed it Saranga (also a neural network), and it basically looks at a brief string of echo readings as if it were a little picture. It uses this to learn the forms of true reflection patterns, after which it can suppress random prop noise. Training employed a lot of synthetic data mixed in with some real propeller noise, so once they had it functioning, the model flowed over to the real world very easily, with no additional fine tuning required. Saranga is then “compiled” to function on the Edge TPU, and it only takes up approximately 0.5 gigabytes of memory and does an inference in around 15 milliseconds while using only a few millijoules of energy.

The cleaned-up echoes are then sent to a basic localization stage, and because the left and right sensors are at slightly different angles, they can determine the horizontal angle to an obstacle in the same way that bats do. The down-pointing sensor then provides the height. It’s all really easy; simply a quick list of surrounding obstacles, and then it’s up to the flight controller to say, “Hey, steer clear of all this while still traveling in that direction.”
[Source]
A new American Heart Association scientific statement concludes that up to about 400 milligrams a day, or roughly three to five cups of plain coffee, is safe for most adults and may be linked to lower risks of cardiovascular disease. The benefits appear to depend heavily on the source and preparation, with coffee and tea looking more favorable than energy drinks, and added sugar, cream, syrups, or sweeteners potentially canceling out the upside. ScienceAlert reports: “Caffeine consumed in coffee is a key part of daily life for millions of people,” says Gregory Marcus, cardiologist at the University of California, San Francisco, and Chair of the AHA volunteer writing group behind the statement. “In our review of the most recent research, for most adults, intake of up to 400 milligrams of caffeine per day, the equivalent of up to five cups of caffeinated coffee per day without added sugars or fillers, is safe and does not increase cardiovascular risk.”
The statement focused on caffeine’s relationship with cardiovascular risk factors, such as blood pressure and diabetes, as well as types of cardiovascular disease, including arrhythmias, coronary artery disease, stroke, and heart failure. The picture that emerges is complicated, but generally positive. […] All up, the new AHA statement concludes that there’s a growing body of evidence that caffeine isn’t harmful when taken in moderation, and that coffee specifically may be beneficial. The statement was published in the journal Circulation.
Hugging Face’s incident response team first turned to frontier AI models to analyze a breach of the company’s production infrastructure, and the models refused to help. Commercial safety guardrails built to stop attackers blocked every forensic query because they treated the IR team’s real exploit data the same way they would treat a live attack.
The attacker, an autonomous AI agent running the campaign end to end, moved laterally across the Hugging Face infrastructure for a weekend, undetected and unstopped.
Security leaders are quick to recognize the pattern and diagnose what went wrong. “I’ve seen versions of this during red-team exercises and internal security testing, but this is one of the first high-profile examples where it materially affected real incident response,” said Merritt Baer, senior adviser to Andesite, G2I, and AppOmni and former Deputy CISO at AWS.
None of this is unique to Hugging Face, Baer said. “Commercial frontier models optimize for preventing misuse. They generally have no cryptographic or organizational way to determine whether the person asking ‘analyze this malware’ is an incident responder or the malware author.”
On July 16, Hugging Face disclosed that an autonomous AI agent system had compromised its production infrastructure, gaining unauthorized access to a limited set of internal datasets and several service credentials. The company verified that its software supply chain was clean and found no evidence of tampering with public models, datasets, or Spaces.
Hugging Face is still assessing whether the intrusion touched any partner or customer data and says it will contact affected parties directly as required. But few enterprise threat models had accounted for the attacker Hugging Face faced. An autonomous agent ran the entire campaign from initial access through credential harvesting. No human guided it.
The entry point was a malicious dataset. When the data-processing pipeline ingested it, the dataset triggered code execution in two ways, through a remote-code loader and through a template-injection flaw in dataset configuration files. No admission gate screened the file before it reached a processing worker, the compute job assigned to each dataset. Initial access came through the data pipeline itself, a route that worked because most enterprise security teams treat the data feeding their pipelines as trusted input rather than an attack surface.
Worker isolation did not hold. From that first foothold, the agent broke out onto the node running the workload, then harvested cloud and cluster credentials scoped broadly enough to reach multiple internal clusters, all of it inside a single weekend. Hugging Face described the agent framework as executing thousands of individual actions through a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services. The disclosure adds that the framework appeared to be built on an agentic security-research harness, which would put tooling designed for red-team work behind a live intrusion.
Investigators reconstructed more than 17,000 recorded events using AI-driven analysis agents of their own.
First attempts at the log analysis ran on frontier models behind commercial APIs. Defenders’ steps included submitting real attack commands, exploit payloads, and command-and-control artifacts for classification, but safety guardrails blocked the requests outright.
Baer traced the block to the prompts themselves. “The same prompts that are most valuable during an active intrusion, shell commands, exploit chains, credential dumps, persistence mechanisms, lateral movement, are exactly the prompts most likely to trigger safety systems,” she told VentureBeat. “As AI becomes embedded in security operations, this becomes an operational resilience issue rather than merely a model policy issue.”
GLM 5.2, an open-weight model deployed on Hugging Face’s own infrastructure, took the job the commercial APIs refused. No attacker data left the company’s environment. “This experience points to a gap worth planning for,” the company wrote in its disclosure. Hugging Face does not know which model powered the agents. It could have been a jailbroken hosted model or an open-weight model running without restrictions. Either way, the disclosure continued, “the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried.” Hugging Face drew that line itself, writing that the experience is not an argument against safety measures on hosted models and that it is sharing the feedback with the providers concerned.
The industry, Baer argued, needs to move past treating AI safety as a content moderation problem. “Security operations require something different. Authenticated trust.” Instead of asking whether anyone should receive an answer, the question becomes whether an authenticated security team, operating under enterprise controls, should receive it. “The model shouldn’t only understand what is being asked. It should understand who is asking, why, and under what governance.”
“Organizations already build contingency plans for cloud outages, identity provider failures, or EDR failures,” Baer wrote. “AI assistants are becoming another dependency.”
Her advice on IR playbooks was blunt. “A mature incident response plan should assume that during a severe incident, commercial AI APIs may refuse requests, API rate limits may become unavailable, internet connectivity may be impaired, and data governance rules may prohibit uploading forensic evidence externally.” The lesson, she wrote in her emailed answers, “isn’t ‘don’t use commercial models.’ It’s ‘don’t make them a single point of failure.’”
Autonomous AI-driven attacks are not limited to AI platforms. CrowdStrike’s 2026 Global Threat Report documented AI-enabled adversary operations increasing by 89% year over year, with average breakout times falling to 29 minutes. Enterprises running AI workloads in production with agentic access to their pipelines face similar exposure.
Six control domains determined the blast radius and recovery speed at Hugging Face. Each one maps to a concrete action security leaders can take before the next autonomous-agent breach arrives.
|
Control Domain |
What Broke |
Monday Action |
|
Dataset admission controls |
Two code-execution paths were exploited. No admission gate validated the dataset before it reached a processing worker. The data pipeline became the initial access infrastructure. |
Require sandbox execution and static analysis of all datasets before they reach workers. Block remote-code loaders and template-injection paths by default. Audit for any path granting code execution to untrusted content. Report to the board as a supply-chain risk. |
|
Worker-to-node privilege boundaries |
Worker isolation failed to prevent escalation to the node. The agent gained cluster credentials because the workload-infrastructure boundary was never enforced at container runtime. |
Enforce hard privilege boundaries between workers and nodes. Deploy container runtime security to prevent workload escape. Audit whether workers can reach node-level APIs or credential stores. Include in the next penetration test scope. |
|
Credential exposure |
Cloud and cluster credentials harvested after node access. The scope was broad enough for lateral movement across multiple clusters over a weekend. |
Rotate credentials on a scheduled cadence and after any anomaly alert. Scope to the minimum cluster and service. Deploy monitoring that flags access from unexpected nodes at machine speed. Map blast radius for board reporting. |
|
Machine-speed detection |
Thousands of actions through short-lived sandboxes with self-migrating C2. AI-assisted anomaly detection surfaced the campaign after a weekend of lateral movement, per the disclosure. |
Calibrate detection for machine-speed patterns. Ensure high-severity alerts page responders in minutes, regardless of time. Audit SIEM rules for detecting thousands of short-lived executions within a single hour. |
|
Private AI forensic capacity |
Commercial APIs blocked forensic analysis. Guardrails screened query content, never analyst identity. Investigation ran on GLM 5.2 privately. |
Deploy a capable open-weight model on private infrastructure before an incident. Test against real forensic workflows. Ensure IR playbook includes fallback for when commercial APIs refuse. Document gap for cyber insurance. |
|
Autonomous-agent threat modeling |
The campaign matched the forecast agentic-attacker scenario, but no threat model had operationalized it. LLM powering the agent is still unknown. |
Add autonomous AI agents as a distinct adversary class with machine-speed decision cycles. Run tabletop at agent speed. Present results to the board as evidence that timelines need recalibration. Include in the cyber insurance application. |
“The question for directors is simple. What happens if one of our critical security tools becomes unavailable during the exact moment we need it most?” Baer framed that as operational resilience, not AI policy.
She would have boards take that framing straight to management and press for specifics. “Have we actually exercised that fallback during tabletop exercises? How quickly can we switch during an incident?” Procurement needs to change alongside governance, starting with the questions buyers ask. Security teams evaluating AI vendors should ask about their process for authenticated incident responders, whether enterprise customers receive different handling during verified incidents, and whether models can be deployed privately. “Those questions belong alongside uptime, privacy, and compliance,” Baer said.
“The biggest takeaway isn’t that safety guardrails are ‘bad.’ They’re doing what they were designed to do,” she argued.
Her larger point is that the threat model itself has changed. “For decades, defenders had better tools than attackers because they operated inside trusted enterprise environments. With foundation models, both sides increasingly use the same capabilities, but one side is constrained by enterprise governance, policy, compliance, and safety controls, while the adversary simply downloads an uncensored open-weight model and keeps going. That’s a new kind of asymmetry,” she added. “The organizations that handle it best won’t necessarily be the ones with the most powerful AI. They’ll be the ones that architect AI as a resilient security capability rather than a single cloud service.”
Hugging Face has contained the intrusion, rebuilt compromised nodes, rotated credentials, and reported the incident to law enforcement. The company recommends that all users rotate access tokens and review recent account activity. Mid-incident, Hugging Face found out whether its own AI tooling would be available, and the first answer was no. Security leaders running AI in production should find out in incident response planning instead, before an autonomous agent forces the test.
Fatal road accidents are tragically common on U.S. roadways. According to the National Vital Statistics System’s Mortality Data for 2024, 41,241 people were killed on U.S. roads that year alone. There’s one particular time of year that’s especially notorious for such traffic accidents among teenage drivers: The period between Memorial Day in late May and Labor Day in early September, the so-called 100 Deadliest Days of Summer.
According to the AAA, between the years of 2012 and 2021, traffic fatalities during this period reached “nearly half of the total number of those killed in teen-driver crashes for the entire rest of the year.” Armed with these sobering statistics, though, authorities can anticipate when such accidents tend to spike in frequency, and tailor campaigns and anti-speeding measures to try to help mitigate them. One major effort to do just that during this period is Operation Southern Slowdown, which returned for its ninth year and ran from July 13-18, 2026. It saw a group of five southern states (Alabama, Florida, Georgia, South Carolina, and Tennessee) embark on efforts to, as the Florida Department of Transportation put it, “reduc[e] speed-related crashes through a combination of increased enforcement and public education.” Speed limits vary a lot between U.S. states, but all must be obeyed.
The additional patrols during this campaign in 2025, Atlanta News First reported, resulted in “more than 13,000 speeding contacts in just one week” across Georgia. It was also just one part of a range of nationwide efforts to curb speeding during this deadly time of the year. Here are some more measures that different states are employing, as well as a closer look at why these 100 summer days are statistically so deadly in the first place.
A national campaign from the Federal Motor Carrier Safety Administration aims to increase public understanding of the dangers and encourage safer driving practices throughout the 100-day period. It’s called the 100 Days of Roadway Safety and focuses on providing digital resources, primarily blog posts, that underscore essential safe driving principles. Among them are reminders to be wary of unpredictable movements by children in school zones and that larger vehicles like trucks need to be given essential space at all times.
New York State’s Department of Health developed a Teen Driving Safety Toolkit to educate young drivers and their parents and guardians during this turbulent time of year. It highlights some particular risk factors, some resources that can be used by both the former and the latter for safety’s sake (such as the Parent/Teen Contract), and other ways these vital messages can be spread (morning high school announcements about driving safety being another).
Increased patrols, as we’ve seen, can have a big impact too. Tragically, though, it’s also vital to address the increased need for emergency responses during this time. In a Facebook post, Tennessee’s Fall Creek Falls State Park acknowledged that these 100 days can call for life-saving blood transfusions, sharing how they work and explaining the $25 eGift card incentives for doing so. Washington State, meanwhile, sees around one-third of its fatal traffic accidents during the three-month stretch beginning in June, which it calls the 90 Dangerous Days. In response, the Washington State Patrol shares the most common causes of accidents (speeding being key among them), some vital driving tips, including “always buckle up, adhere to posted speed limits, drive sober, and stay distraction-free.”
Road safety is paramount for drivers to bear in mind every journey they make. Nonetheless, as the National Road Safety Foundation points out, the summer is marked by an uptick in fatalities among teenage drivers. There are more vehicles on the road generally, for one thing, and during this period, younger drivers will typically have more free time to hit the road. Combine that with their lack of experience with safe driving habits and possibly with their vehicle itself, and it makes sense that this is a particularly dangerous time for them. After all, there are some common mistakes that even experienced drivers make on the road, and the risks are heightened with newer motorists.
During this time of year, there’s often more road maintenance and repair work taking place. All of these factors add up to busier roads that are more difficult and frustrating to navigate, which is also a very dangerous mix for those maintaining the roads and larger, less maneuverable vehicles like buses in particular.
A specific focus on safety measures during the 100 days of summer doesn’t mean that states across the country don’t prioritize these matters during the rest of the year, of course. Also in July 2026, Caltrans announced an enormous investment of approximately $2.5 billion, intended to “Strengthen transportation infrastructure and improve mobility across the state.” Including steps such as establishing more crossings and a sidewalk-widening program, it’s a strong signal that broader matters of road safety are vital across America year-round. Even so, the more attention that can be brought to the 100 days of summer, the safer motorists, pedestrians, and passengers may be.
Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out.
This known WSUS sync issue affects both client (Windows 10, version 1607 and later) and server (Windows Server 2012 and later) platforms.
On impacted WSUS servers, admins are not able to deploy the latest Windows updates via WSUS or Configuration Manager due to increased synchronization times or sync operation timeouts caused by a buildup of publishing metadata.
Microsoft rolled out a service-side mitigation on Saturday to address the issue for newly installed or rebuilt WSUS servers following heightened impact observed starting one week ago, on July 13.
“Synchronization times and sync operations on WSUS servers have been restored and are operating normally for new WSUS installations and rebuilds,” Microsoft said.
On Monday, Microsoft also shared a manual fix for customers who are still experiencing sync operation issues and timeouts to help admins return their WSUS servers to normal functionality.
“Organizations with existing WSUS server installations that are experiencing long sync times can benefit from manual steps in order to clean up unneeded metadata,” it noted in a Windows release health dashboard update. “This metadata is present in existing WSUS installations but can be safely removed.”
This requires them to back up each SUSDB database, run a cleanup query from SQL Management Studio against all SUSDB databases (including WSUS replicas), and update the MaxXMLPerRequest value to its default setting.
After the cleanup process, the first Windows Update scan may take longer than usual, but subsequent scans will return to normal timing.
“After the cleanup, reindex SUSDB, run the WSUS Server Cleanup Wizard, and then run IISReset or recycle the WsusPool application pool to clear cached catalog state,” Microsoft added. “The client-side DataStore.edb does not shrink automatically after the detectoids are removed. This is expected and does not affect scan performance.”
Microsoft has addressed similar WSUS issues that prevented admins from deploying the latest Windows updates in May 2025, July 2025, and August 2025.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
It’s official: We’re getting a pickle emoji next year. On Tuesday, July 14, the Unicode Consortium announced the nine new emoji you’ll see on your device in 2027. One new emoji is the pickle, and that means the eggplant’s reign as the go-to emoji for male anatomy could be coming to an end.
Here are the nine new emoji you will see on your device next year.
The Unicode Consortium originally proposed a squinty face emoji in 2025. However, the Unicode Emoji Standard & Research Working Group recommended changing that emoji to a cracking face in January.
Honestly, the cracking face emoji feels more relevant to today than the squinty face emoji. The squinty face read as suspicious while the cracking face emoji screams, “I’m putting on a brave face in these trying times.” If that’s not the most relatable sentiment these days, I don’t know what is.
While the Unicode Consortium approved these emoji, companies like Apple and Samsung still need to design and then implement their versions of the emoji. Those companies usually add the emoji to devices as part of a software update in the spring, so you likely won’t see these emoji on your phone until 2027.
Before these emoji land on your device, the Unicode Consortium will begin fielding proposals for the next round of new emoji. Anyone can submit an idea for a new emoji, and the Unicode Consortium usually uploads proposed new emoji to a public document late in the year. For example, the upcoming emoji were originally accepted in October, 2025.
For more on emoji, here’s how to decipher every emoji and the newest emoji on your iPhone and Android.
It’s officially the second half of 2026, which is going to be all about Grand Theft Auto 6. Until then, Sony has a new selection of games coming to PS Plus in July that includes Avatar: Frontier of Pandora, Dying Light and a couple of classic PlayStation 2 games.
PS Plus, which is Sony’s version of Xbox Game Pass, offers a large, constantly expanding library of games. Subscribers can choose from the Essential, Extra and Premium tiers, each with unique perks and benefits. Starting at $11 a month, the plans give subscribers access to games and rewards, and each month, all subscribers can play a handful of new games at no additional charge.
If you’re a PlayStation Plus Extra or Premium subscriber, you can grab these games starting July 21.
Avatar: Frontiers of Pandora came out in 2023, a year after Avatar: The Way of Water released in theaters. Developed by Massive Entertainment – a division of Ubisoft – the open-world action-adventure puts players in the role of a Na’vi raised by the Resources Development Administration, or RDA, before returning to defend Pandora. Set in the previously unseen Western Frontier, the game emphasizes exploration, aerial traversal on an ikran and combat using both traditional Na’vi weapons and human firearms. While its gameplay shares many similarities with the Far Cry series, its lush environments and faithful recreation of Pandora earned praise from critics.
Avatar: Frontiers of Pandora will be available for PS Plus Extra and Premium subscribers starting July 21.
Team Ninja went a different direction than its usual Ninja Gaiden style with 2024’s Rise of the Ronin. Set during Japan’s turbulent Bakumatsu period in the late 19th century, the open-world action RPG lets players shape the story by siding with competing political factions. Combat combines fast-paced swordplay with firearms and other period weapons with the challenging gameplay the studio is known for. Its blend of historical events, exploration and player-driven choices helped distinguish it from Team Ninja’s previous action games.
Rise of the Ronin is now available for PS Plus Extra and Premium subscribers.
Firefighting Simulator: Ignite puts players in the role of a firefighter responding to emergencies across a large fictional city in the American Midwest. Whether playing solo with AI teammates or cooperatively with up to three friends, players battle dynamic fires, rescue civilians and use authentic firefighting equipment to contain increasingly dangerous blazes. Powered by Unreal Engine 5, the game features real-time fire, smoke and heat simulation designed to create a more realistic firefighting experience.
Firefighting Simulator: Ignite will be available for PS Plus Extra and Premium subscribers starting July 21.
Mighty Morphin Power Rangers: Rita’s Rewind is a true nostalgia bomb of a game. The side-scrolling beat-’em-up reimagines the classic 1990s TV series with pixel art visuals, cooperative multiplayer and familiar villains, including a robotic version of Rita Repulsa. Players battle through stages inspired by the show before piloting Dinozords and the Megazord in 3D action sequences that break up the traditional brawler gameplay.
Mighty Morphin Power Rangers: Rita’s Rewind will be available for PS Plus Extra and Premium subscribers starting July 28.
It’s been more than a decade since Dying Light was released, but it’s still a title that gamers fawn over. Players explore the zombie-infested city of Harran using a fast-paced parkour system that makes traversing rooftops as important as combat. Scavenging for supplies, crafting weapons and surviving a dynamic day-night cycle keep the tension high as more dangerous infected emerge after dark. Its fluid movement and intense survival mechanics helped make it one of the most acclaimed zombie games of its generation.
Dying Light will be available for PS Plus Extra and Premium subscribers starting July 21.
Citizen Sleeper 2: Starward Vector builds on its predecessor by sending players across a lawless star system as an escaped android searching for freedom. Rather than focusing on traditional combat, the game emphasizes dialogue, dice-based skill checks and resource management as players assemble a crew and take on dangerous contracts. Its choice-driven storytelling and tabletop-inspired mechanics make every decision feel meaningful, with multiple paths that shape how the story unfolds.
Citizen Sleeper 2: Starward Vector will be available for PS Plus Extra and Premium subscribers starting July 28.
Snow Bros. Wonderland revives the long-running arcade franchise with a fresh 3D isometric look while staying true to its classic action-platforming roots. Players freeze enemies into snowballs before kicking them across each stage to defeat other foes and rack up combos. Cooperative play, colorful environments and larger-than-life boss battles help modernize the series without losing the charm that made the original games fan favorites.
Snow Bros. Wonderland will be available for PS Plus Extra and Premium subscribers starting July 28.
Psi-Ops: The Mindgate Conspiracy was first released for the PS2 in 2004 and had a mix of interesting physics gameplay that was a big trend in gaming at the time. Players control Nick Scryer, a secret agent who combines traditional gunplay with psychic abilities like telekinesis, mind control and pyrokinesis to take down enemies. The game’s physics-based powers encouraged creative problem-solving and helped it stand out from other action shooters of its era, earning it a cult following years after its release.
Psi-Ops: The Mindgate Conspiracy will be available for PS Plus Premium subscribers starting July 21.
Before it made a name for itself with the games Heavy Rain and Detroit: Become Human, developer Quantic Dream first experimented with making the point-and-click adventure gameplay style a bit more action-oriented with Indigo Prophecy. The supernatural thriller follows several interconnected characters as they investigate a string of mysterious murders while uncovering a conspiracy that threatens humanity. Its cinematic presentation, branching narrative and quick-time events helped lay the foundation for the studio’s later interactive dramas.
Indigo Prophecy will be available for PS Plus Premium subscribers starting July 21.
For more on PlayStation Plus, here’s what to know about the service. You can also check out other games on PlayStation Plus and games on Xbox Game Pass.

Microsoft Chief Sustainability Officer Melanie Nakagawa faced a barrage of pointed questions from the audience Friday during a session at the annual Pacific Northwest Climate Week in Seattle.
Protesters challenged Nakagawa through most of the 30-minute session held in a conference room at Seattle’s City Hall, calling out the company’s use of fossil fuel energy sources to power its AI data centers and challenging Microsoft’s commitment to climate goals set years ago.
As a reporter covering sustainability issues for GeekWire, I moderated the session. Many of the issues raised by the crowd were on my list of questions for Nakagawa. The disruptions also included chants from protesters seated among attendees, at times going beyond climate issues to condemn Microsoft’s technology deals with Israel.
Security guards ultimately ushered some protesters out of the space, while others remained. Interruptions from the audience continued for all but the final 10 minutes of the session.
The event capped off Pacific Northwest Climate Week, which included conversations around the city and region about climate change solutions, policies and innovations.
Microsoft has for many years been viewed as an environmental corporate leader, setting an ambitious goal in 2020 to become carbon negative within a decade. It created an internal carbon tax — one of the corporate world’s largest — that charges individual Microsoft divisions for emissions from sources like air travel to fund climate-friendly initiatives. The company is credited with helping create and sustain the carbon dioxide removal sector, among other roles.
But the rapid expansion of AI data centers and their huge energy demands are undercutting Microsoft’s standing. The company recently released its annual sustainability report, disclosing that its carbon footprint grew 25% last year, moving it further from its 2030 target.

One protester’s question was about a deal announced earlier this year in which Microsoft is partnering with Chevron to build a 2.7 gigawatt natural gas facility to power a data center campus in Texas. I asked Nakagawa how the company defends the agreement, and she pointed to the 4.7 gigawatts of renewable energy that Microsoft has supported in the state. I followed up by asking about the Redmond, Wash.-based company’s commitment to carbon dioxide removal (CDR) projects given recent reports about a pause on new deals.
Nakagawa was unable to answer before the crowd drowned her out with a call-and-response chant: “Microsoft, you can’t hide. We can see your dirty side.”
Another protester criticized the escalating pursuit of AI. “You’re selling us a product that we don’t even need, and we never should ask for,” he said. “No one wants AI. You’re destroying the climate with AI.”
I brought up legislation proposed earlier this year in Washington to mandate clean energy use and bring transparency to data center impacts in the state. Microsoft opposed and helped defeat the bill, though the company says it wants to work with lawmakers to pass rules next year. I asked what needed to change in the legislation for Microsoft to support it.
Nakagawa didn’t provide specifics, but noted that this year, for the first time, the company shared facility-level information in its annual report on electricity and water use for data centers worldwide.
“People want to know more about the data, and we believe you can have an honest and candid conversation with transparency and access to that information and data,” she said.
Given the obvious public concerns, I asked Nakagawa, “Do you really honestly believe that by 2030, the company can hit that carbon-negative goal?”
Nakagawa pointed to wide-ranging initiatives that are starting to help curb specific emissions, including investments to make Xbox devices lower carbon and financial support for the recent opening of a production plant in Moses Lake, Wash., for sustainable aviation fuel company Twelve.
“There are a couple areas where we’re seeing a lot of promising progress,” she said. “Look, this is going to be a hard target. We’ve not been at all shying away from the fact that this is a difficult goal.”
London Mayor Sadiq Khan handed a peerage by Keir Starmer alongside 15 other Labour figures… just days before the PM leaves No10
Weekend Open Thread – Corporette.com
The House | The City of London can help the new chancellor deliver growth in every postcode
Young campaigners urge incoming PM to act on outdoor junk food ads
CFTC blocks Kalshi from unwinding Michigan trades after court order
Two July Windows Left: The CLARITY Act’s Senate Fight and What Failure Means
Ripple Payments Joins MiCA With 14 Firms, Does It Mean Anything For XRP?
Nvidia Stock Slips After Big Tuesday Rally as Huang Confirms Vera Rubin Chip Is Now in Production Today
Democrats look to World Cup watch parties to register thousands of voters
Disney’s Most Ambitious Failed Star Wars Attraction Is Coming to SDCC
Ripple wins EU-wide access as ESMA adds it to MiCA register
Injective Submits SEC Transfer-Agent Registration to Onchain Ownership Records
Palantir Shares Rise After Expanded Nvidia Partnership and Fresh Analyst Upgrades Ahead of Earnings Day
Sail Virtually Aboard The “Itanic” With IA-64 Emulator
Turtle Beach Command Series KB7 review: a nifty screen-equipped gaming keyboard
Dark Secrets Emerge When Jailbreaking LLMs
XRP BOMBSHELL… XRP OMBOARDED FOR TRANSACTIONS!!!
Registration is now open for March for Men with Kev 2026
Unregistered fitter used Gas Safe logo on business flyers
New Cornerback Enters Vikings Trade Rumor Mill
You must be logged in to post a comment Login