Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
The Samsung Galaxy S26 Ultra is one of the best phones you can buy in 2026, and if you already own one, I have some positive news for you: Your phone can take better photos than it does right now.
Samsung added a larger aperture (on two sensors) and upgraded its camera processing to fare better against Apple’s iPhone 17 Pro this year. However, if you haven’t played around with the settings, you aren’t making the most of Samsung’s new upgrades.
The Galaxy S26 Ultra has a versatile camera system, but the default settings might not work for everyone. They didn’t for me. So I took a deep dive into the buried menus and found ways to improve the shutter speed, reduce compression and trigger the 24-megapixel processing pipeline, among other things. If you aren’t satisfied with the image quality on your Samsung phone right now, I recommend taking a look at these options in the Samsung Camera Assistant.
Change these Camera Assistant settings to get the most out of your Galaxy S26 Ultra cameras.
The Camera Assistant on Galaxy smartphones is a Good Lock module (essentially like a plugin). It adds additional settings to the default Camera app. For the longest time, Samsung didn’t preload these settings on its flagship phones, but things have changed with One UI 8.5 on the latest Samsung flagships. You can now find the Camera Assistant settings within the Camera app.
To find these additional settings:
However, if it is not present here, you’ll need to install the Good Lock app through the Galaxy Store. Search for Camera Assistant and download the module from there.
Once located, you’re now ready to take control over the processing and camera performance. Several of these options aren’t objectively better than the other, but here’s what I recommend changing and which setting could fit in what scenario.
Changing to 24-megapixel mode will give you better photos in all scenarios.
The Galaxy S26 Ultra has a 200-megapixel main camera, but it defaults to 12-megapixel photos out of the box. While these photos are small in size, you won’t get the same amount of detail and clarity as higher-resolution modes. I don’t recommend capturing everything in 200-megapixel mode, either – it is slow and will eat up your storage quicker than anything else.
I’ve found the 24-megapixel mode to be the best of both worlds. It can take quick snaps and get sharp results simultaneously without having a large file size.
The best part is that Samsung upgraded its processing to capture 24-megapixel resolution photos even in digital zoom.
24-megapixel image in 9.2x zoom (213mm).
As a result, you get 24-megapixel shots on three camera sensors, including these zoom ranges: 0.6x to 0.9x for ultrawide, 1x to 1.9x for the main and 5x to 9.9x for the periscope telephoto camera.
The 10-megapixel 3x tele sensor misses out on this feature due to its lower resolution and the main camera defaults everything from 2x to 2.9x in 12 megapixels, despite using a higher resolution mode.
The 24-megapixel vs 50-megapixel shot: The 50-megapixel mode photo (right) is about 900 KB larger, but it doesn’t give you objectively more detail or clarity.
I suggest you change the default resolution to 24-megapixel mode because it is enough for almost all scenarios. The only time I’ve noticed a difference was while capturing neon lights in each mode. The former artificially brightens the whole frame, whereas the 50-megapixel mode in 9.2x zoom exposes for the signboards, which results in more natural-looking photos like the example below.
The 24-megapixel vs. 50-megapixel shots at 9.2x zoom: In both photos, I tapped on the Star Wars sign to focus. The 50-megapixel mode processed it better than the 24-megapixel mode.
For most of the other scenarios, 24-megapixel mode remains the sweet spot and here’s how you can make it the default resolution for your Galaxy S26 Ultra photos:
You’ll see two settings: 24 MP in Photo mode and Keep 24 MP resolution. Turn on both of them.
While you’re at it, these are the settings to change under the Camera Assistant settings if:
Disabling Auto Lens Switching will give you more control over the cameras on Galaxy S26 Ultra.
You need to disable Auto Lens Switching. By default, the Galaxy S26 Ultra camera system automatically switches between the four rear cameras based on the lighting, the phone’s distance from the subject and zoom range.
It isn’t the smartest decision to rely on your phone’s smarts. For example, when you take the phone close to the subject for a macro shot, it takes a few seconds to land on a usable lens based on your distance. In this time, the moment could be lost.
You can instead decide on the lens you want to use, get close to the subject and take the photo, without any automatic lens switching. All you need to do is turn off the Auto Lens Switching toggle under the Lens and Zoom option.
Photo Softening turned off (left) vs. Photo Softening set to high (right).
Samsung phones can oversharpen skin tones, especially under artificial lighting conditions. If you’re not a fan of the processed look, you can opt for softer skin tones by going to the Photo Softening option under the Photos menu and setting it to Medium or High.
In the above two shots, you can notice how the left image (with Photo Softening turned off) has a stronger black point and shadows. In comparison, the shot on the right (with Photo Softening turned to High) has a more natural feel to it. My skin and beard still have similar details in both shots, but I prefer the softer, less processed photo on the right.
Adaptive Pixel and Upscale Digital Zoom turned off (left) vs. both settings turned on (right). Notice the complications on the watch — the left one has sparkles, which aren’t visible on the left photo.
By default, Samsung keeps Distortion Correction turned on and Adaptive Pixel and Upscale Digital Zoom turned off. But you should experiment with these settings according to your photos. Turning them on could result in a better-looking shot. For example, when capturing my watch, the default settings couldn’t get the sparkles on the earthphase complication (on the left with Snoopy). However, once I turned on Adaptive Pixel and Upscale Digital Zoom, it was able to give me more details on the dial.
On the other hand, Distortion Correction fixes the bending lines in a photo, which could be caused by lens distortion. So turning it on results in better-looking photos, especially those that involve buildings.
Other than these two settings, I used to recommend turning on Quick Tap Shutter until last year. However, I haven’t seen a noticeable difference in photos with this setting turned on or off on my Galaxy S26 Ultra. Samsung has improved the shutter speed on its flagship this year, but moving subjects can still get a halo effect in default settings. You can slightly improve on this by enabling the Prioritize Focus over Speed toggle (located under Focus).
Tinkering around with these settings has helped me make the most of the camera in my pocket. I hope they’ll improve your photo-taking experience on the Galaxy S26 Ultra, too. I also suggest exploring the filters present in the viewfinder and trying to create your own, according to your taste. It is fun!
Watch this: Which Phone Takes Better Photos? iPhone 17 Pro Max vs. Galaxy S26 Ultra
Earlier this year FCC boss Brendan Carr launched a series of fake investigations into ABC because the network (1) hosted Democratic Texas Senate hopeful James Talarico on The View, (2) aired comedians who made fun of the president and his wife, and (3) occasionally engaged in journalism critical of Trump corruption.
The details of these investigations really don’t matter at this point. We’ve discussed how they’re legally incoherent, clearly violate the First Amendment, and involve Carr actively manufacturing false claims that ABC violated FCC rules it was long-exempt from. At other points it just involves Carr being incoherently racist on Trump’s behalf; such as claims that ABC didn’t eliminate its “DEI” requirements quickly enough.
Carr’s now dumping additional empty threats into the mix, claiming that his ongoing review of ABC’s local broadcast licenses will take into consideration the network’s refusal to air Trump’s recent prime time speech, which mostly just involved Trump spewing more false election fraud conspiracy theories surrounding his 2020 loss.
ABC and NBC wisely refused to air the speech live, knowing that helping to spread distrust in election integrity in real time would be the opposite of useful journalism. That made Trump mad, so he’s clearly urged Brendan Carr to levy some additional empty threats against ABC:
“I think when you have the President of the United States standing inside the White House delivering an important speech, I think that’s something that broadcasters should be carrying. And so, obviously, this is an issue,” Carr told reporters Wednesday. “There have been lots of concerns raised, including by members of Congress, about whether broadcasters and their decisions there comply with the public interest.”
Carr is somewhat vague here because he knows this is a bunch of bullshit.
Obviously it’s ABC’s First Amendment right to determine what it broadcasts and when. Carr has absolutely zero legal role in determining the scheduling lineup of a private company. Carr’s once again pretending that networks that refuse to pander to our mad idiot king will be subjected to FCC review of their public interest obligations affixed to ownership of public airwaves.
As we’ve mentioned countless times already, Carr doesn’t want any of this to actually head to court because he knows it’s an absolute loser on First Amendment grounds. The real goal remains to threaten U.S. media companies with costly and annoying legal headaches if they challenge Republicans or the unpopular president. It’s typical lazy autocrat stuff by weak men who are afraid of words.
When it comes to ABC, that’s still been embarrassingly effective. The company agreed to pay Trump a $16 million bribe in 2024 to settle a baseless lawsuit the company easily could have won. And more recently, ABC shows like The View have shied away from hosting any political candidates at all for risk of upsetting Trump.
Brendan Carr has openly stated in interviews he fancies himself a tough, pit bull enforcer; but as Trump’s health and political power wane, the threats will hold less and less weight. As a result you’ve already seen ABC execs start to show a backbone in their fight with Carr, openly pointing out how he colluded with local right wing broadcast affiliates to manufacture evidence suggesting ABC broke FCC rules (something I’m sure will play great in court).
Carr’s threats will become weaker and weaker until he’s ultimately booted from office by subsequent administrations, at which point he’ll fail upward to some mid-six figure job at a telecom or media think tank, where he’ll spend the rest of his life helping corporate America dismantle whatever’s left of competition, labor, and consumer protection standards.
One of the ironic things, for Carr, is that his authoritarian censorship and saber rattling often draws press and public attention away from all the other terrible things he’s doing, whether it’s destroying media consolidation limits, making life easier on robocallers, dismantling broadband consumer protection standards, or making it easier for giant shitty companies to run amok.
You’d like to think Carr ultimately faces some sort of meaningful accountability for being one of the most censorial, petty, captured, and authoritarian regulators in U.S. history, but I wouldn’t hold your breath.
Filed Under: brendan carr, censorship, fcc, first amendment, james talarico, media
Companies: abc, disney
American fast food restaurant chain Chick-fil-A has confirmed that over 13,000 customers had their data stolen in a recent wave of credential stuffing attacks.
As BleepingComputer first reported, the company revealed in data breach notification letters filed with multiple attorney general’s offices that it detected attacks targeting its website and mobile app between June 17 and June 19 after identifying suspicious login activity to certain Chick-fil-A One accounts.
Chick-fil-A says the attackers used automated tools and credentials “obtained from a third-party source” to hack into Chick-fil-A One accounts and steal customer data.
“We recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts. Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted,” the company told BleepingComputer.
During the attacks, the threat actors accessed a combination of customers’ names, email addresses, Chick-fil-A One membership numbers, the amount of Chick-fil-A credit, the mobile pay numbers, and the last four digits of the credit/debit card number. Additionally, they may have also gained access to birth dates, phone numbers, and addresses if stored in the compromised accounts.
While the company didn’t say how many individuals had their data exposed, Chick-fil-A notes in a filing shared by the Office of the Maine Attorney General with BleepingComputer on Wednesday that the resulting data breach affected 13,322 people in total.
In separate filings, it also told the Texas attorney general’s office the data breach impacts 2182 Texans and the Massachusetts AG that it affects 39 residents. Chick-fil-A has also sent data breach notification letters to residents of the District of Columbia, Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.
In response to the incident, Chick-fil-A says it logged out all impacted accounts, removed payment methods, restored all affected Chick-fil-A One account balances, and has also added rewards to affected accounts as a way of apologizing. Since the accounts were compromised because they were using credentials stolen from third-party services, Chick-fil-A also advised impacted customers to change their passwords as soon as possible.
Chick-fil-A also disclosed in March 2023 that hackers stole the personal information of over 71,000 customers after hacking their accounts in another series of credential stuffing attacks between December 2022 and February 2023.
As one of the largest fast food companies in the United States, Chick-fil-A operates a network of over 3,000 restaurants across the U.S., Canada, Puerto Rico, the United Kingdom, and Singapore.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Erling Haaland is not the only Norwegian built around power, precision and making life difficult for the opposition.
Sigberg Audio is making its U.S. audio show debut at Southwest Audio Fest 2026 with the Manta active loudspeaker system, Saranna active floorstander and 10D dual opposed subwoofer.
The Norwegian manufacturer takes a rather different approach from the growing number of wireless speakers promising an entire audio system inside two attractive cabinets. Sigberg focuses on Hypex nCore amplification, DSP crossovers, manual parametric EQ and controlled directivity designed to reduce unwanted interaction with the room.
There is no Wi-Fi streaming, Bluetooth or HDMI eARC. These are active high-end loudspeakers for listeners who want the amplifiers, crossovers and drivers engineered as one system, not another lifestyle product whose future depends upon an app remaining alive.

The Manta is a four way active system comprising two powered monitors and a pair of dedicated Sigberg bass modules.
Each monitor uses a 12-inch midbass driver and a 5.5-inch coaxial driver containing a 1-inch silk dome tweeter. Three channel Hypex nCore amplification provides 600 watts per speaker, while DSP handles crossover and equalization duties.
Sigberg describes the Manta as a dual cardioid design. Its vented enclosure is intended to reduce sound radiating toward the sides and rear of the cabinet, potentially limiting early reflections from nearby walls.
The company claims rearward and lateral attenuation of approximately 10dB to 25dB across portions of the 100Hz to 5kHz range. That will not magically remove the room, but it could make the Manta considerably easier to integrate than a conventional loudspeaker with broad rearward radiation.
Sigberg recommends positioning the Manta between 10 and 50cm (4-20 inches) from the front wall and at least 40cm (15 inches) from the side walls. The included stands tilt the speakers upward by four degrees.

The Manta system being demonstrated in Dallas uses two Sigberg 10D subwoofers.
Each sealed cabinet contains two opposing 10 inch aluminum cone drivers powered by a DSP enabled Hypex nCore amplifier. The opposing drivers are designed to cancel mechanical forces and reduce cabinet vibration.
Sigberg specifies a frequency response of 23Hz to 250Hz, with typical in room extension to approximately 18Hz. Claimed average output is approximately 117dB from 30Hz to 80Hz at one meter under CEA 2010 measurement conditions.
Each 10D weighs 27kg, or 59 pounds, and includes RCA, balanced XLR and speaker level inputs. It also offers nine band parametric EQ and connection presets for use with an A/V receiver, conventional preamplifier or Sigberg active speaker system.

| Sigberg Inkognito | Sigberg 10D | |
|---|---|---|
| MSRP | $4,000 each | $5,000 each |
| Driver Type | 12″ Scan-Speak Aluminium cone | Dual 10″ Aluminium cone |
| Enclosure Type | Sealed | Sealed |
| Frequency Response | 23- 250Hz (±3dB); ~18Hz in-room |
23- 250Hz (±3dB); ~18Hz in-room |
| Max SPL | 113 dB | 117 dB |
| Amplification | Hypex nCore, DSP enabled | Hypex nCore, DSP enabled |
| Crossover/EQ | 9-band parametric | 9-band parametric |
| Inputs | RCA, XLR balanced, High-level | RCA, XLR balanced, High-level |
| Dimensions (WxHxD) | 650 x 540 x 163 mm (25.6 x 21 x 6.4 in) |
360 x 370 x 410 mm (14 x 14.5 x 16 in) |
| Weight | 22 kg (48 lbs) | 27 kg (59 lbs) |

The Saranna packages much of the same technology inside a narrower full range floorstander.
A front mounted 8 inch coaxial driver combines the midbass and midrange unit with a horn loaded compression driver. Two rear mounted 8 inch woofers handle the lower frequencies inside a ported enclosure.
Each Saranna contains 600 watts of three channel Hypex nCore amplification, DSP crossovers and nine band parametric EQ.
Sigberg claims a frequency response of 28Hz to 20kHz, with typical in room extension down to 20Hz. Claimed maximum output is 116dB per speaker.
The rear woofers might suggest that the Saranna needs considerable breathing room, but Sigberg designed the system to benefit from boundary reinforcement. The company recommends placement relatively close to the front wall, generally between 15 and 50cm.

The Manta and Saranna include their own amplification, DSP and active crossovers. Owners do not need separate power amplifiers, but they will still need a source component or preamplifier with volume control.
Both systems support RCA, balanced XLR, optical, coaxial S/PDIF and AES connections.
Their published specifications do not include Bluetooth, network streaming, HDMI eARC, automatic room correction or an internal phono stage.
That makes them less convenient than something from KEF, Dynaudio or Buchardt, but it also means the loudspeakers are not tied to a specific streaming platform. Owners can select or replace the front end without throwing away the amplification and loudspeaker system.
The manual nine band parametric EQ also provides considerable flexibility, although using it properly will require acoustic measurements, dealer assistance or some idea of what those frequency and Q controls actually do. Randomly moving sliders until everything looks exciting is not room correction.
Sigberg says its direct pricing includes worldwide shipping, applicable taxes, import fees and customs handling. The company also offers a 60-day home trial and 5-year warranty.
U.S. customers can purchase directly from Sigberg or contact DreamScapes A/V in Syracuse, New York.
The Sigberg Audio systems are being demonstrated inside the DreamScapes A/V Presidential Suite on the 10th floor of the Sheraton Dallas Hotel.
The Manta and 10D are confirmed for the room. The Saranna was announced for the show but was initially listed as pending customs clearance, so attendees should confirm its arrival before heading upstairs specifically to hear it.
Southwest Audio Fest 2026 runs from July 23 through July 25 at the Sheraton Dallas Hotel. Tickets cost $25 for one day or $40 for a multiday pass.

Sigberg Audio is not trying to build another attractive wireless speaker that promises convenience above everything else.
The Manta and Saranna combine purpose matched amplification, DSP crossovers, substantial output and controlled directivity in systems designed to work relatively close to the front wall. That could make them especially interesting for listeners who want full range performance but do not have an acoustically perfect listening room the size of a Norwegian football pitch.
The Manta is the more ambitious system, combining large active monitors with two dedicated bass modules. The Saranna delivers much of the same philosophy in a narrower floorstanding design without requiring external subwoofers.
Neither system is inexpensive. There is also no onboard streaming, HDMI eARC or automatic room correction, and anyone who changes amplifiers more often than Erling Haaland scores goals will probably struggle with the concept.
For listeners who care more about engineering, room integration and consistent system matching than collecting amplifiers, Sigberg Audio could be one of the most interesting manufacturers making its Dallas debut.
For more information: sigbergaudio.com
.png)
Outside gatherings seldom feature an ideal climate. A quiet morning may rapidly shift to heavy wind, abrupt gusts, or an unanticipated downpour. If you’re displaying goods at a commercial exhibition, organizing a public function, visiting a produce vendor site, or executing an advertising drive, erratic atmospheric conditions might ruin a whole arrangement unless the canopy was designed specifically for such elements.
A tent offers more than just shade protection. It shields individuals, gear, merchandise, and brand identity while allowing events to proceed securely against shifting weather patterns. Yet, no single canopy functions identically once winds begin to rise significantly. Your custom event tents are built with wind performance in mind, helping you select structures that avoid injuries, limit property destruction, and provide attendees with increased assurance during the whole exhibition period.
Knowing what traits boost stability aids firms in buying gear that works well every single year.
1. Choose a Strong Frame
Everything starts with the frame.
A high-quality frame gives the structural support required to endure shifting weather patterns. Commercial aluminum grades offer a good mix of strength and ease of carrying, whereas heavy steel frames give extra steadiness for tough settings. Stronger joints and lasting connectors likewise cut down on motion when winds blow hard.
A strong frame creates a stronger foundation.
2. Secure Anchoring Matters
Even the most robust tent will fail to stay steady if it lacks correct securing.
Stakes function nicely on grass plus soft ground areas, yet heavy plates, sandbags, or water containers give extra stability on concrete plus pavement surfaces. Each leg needs securing prior to the start of events, specifically whenever wind conditions are anticipated.
Proper anchoring greatly improves safety.
3. Select Wind-Resistant Canopy Fabric
Fabric quality affects more than appearance.
Heavy-duty fabrics stretch less, tear less, fade less, and hold up against water better than lightweight options. Waterproof layers, UV protection, strong seams, and tough corner pads help make things work well at outside parties.
Quality materials increase long-term durability.
4. Look for Aerodynamic Designs
Tent shape influences wind performance.
Certain roof shapes let wind pass over the frame rather than hitting big flat areas hard. Open vents cut down on pressure too since they give air a way out via special holes, which lowers the upward push made by fast winds. The same aerodynamic thinking applies to your custom inflatable arches, which are engineered to channel airflow smoothly rather than resist it, making them a reliable choice for outdoor events where wind is a concern.
Smart design improves overall stability.
5. Match Tent Size to the Event
Larger tents catch more wind.
Selecting a cover fitting true space needs cuts unneeded wind drag. Small gatherings might need just small shelters, yet big shows ought to employ properly strengthened frames plus extra anchoring support.
The right size improves both safety and efficiency.
6. Inspect Your Equipment Regularly
Even durable tents require routine maintenance.
Prior to each event, check the frame, connectors, fabric, anchors, and fasteners for indications of wear or harm. Secure loose hardware and swap out broken parts prior to them turning into bigger issues under windy circumstances.
Regular inspections help prevent unexpected failures.
7. Use Sidewalls Wisely
In terms of wind resistance, fully enclosed sidewalls could create wind traps, which may increase the load onto the frame. If you’re expecting heavy winds, consider partially opening your sidewall (or using some vented panels), as this will allow for good airflow while keeping you protected against weather elements. Balanced airflow improves the stability of your tent.
8. Monitor Weather Conditions Throughout the Event
Check weather forecasts again right before you start setting up for an event. You might be able to avoid problems by watching wind conditions all day long.
If you see that the winds have exceeded those recommended by the manufacturers of your tent, consider lowering or dismantling the tent to reduce the risk of damage or danger to yourself and others. Staying alert protects more than just your interests.
Windy conditions ought not to stop a successful outdoor gathering from happening. Firms putting money into tough frames, dependable anchor setups, nice cloth materials, airflow shapes, correct sizes, and routine care get better steadiness and less worry during all events.
Top tents are not merely made for looks; they are designed for function. When weather turns uncertain, reliable gear shields your crew, clients, goods, and reputation so events proceed with assurance.
AI has made it stupidly easy to fake being a real person online, so Facebook is rolling out a new badge to prove you’re not one of them. It’s called Facebook Verified, and the best part is that it won’t cost you a thing.
I love that Facebook has made it easy to get verified. You record a short video selfie, and Facebook checks it against your existing profile photos to confirm it’s really you. The whole thing takes just a few minutes, and unlike some other social media platforms, Facebook isn’t charging you a subscription fee for this checkmark.

That said, not everyone gets to join the club. You need to be 18 or older, and your account has to be in good standing with Facebook’s rules around fraud, scams, and deceptive behavior. Show any signs of inauthentic activity, and you can forget about getting that badge. Also, Pages and ProMode accounts are not eligible right now.

Facebook has said that the feature is rolling out in phases, starting with select markets before it goes global, so don’t panic if you don’t see it on your account just yet.
Once you’re verified, the badge follows you to the spots where trust actually matters, like Marketplace, Facebook Dating, Groups, and your profile. Facebook says Feed posts will get the badge too, eventually.
You only have to verify once, and that badge travels with you everywhere. So next time you’re negotiating over a secondhand couch or matching with someone on Dating, you’ll know there’s an actual human on the other side.

Facebook also says that verification isn’t an endorsement. The company is upfront that the badge doesn’t mean it’s vouching for anyone’s trustworthiness. Verified users still have to play by the same Community Standards and Commerce Policies as everyone else.
As much as I abhor some of the Meta policies, this is a step in the right direction. As AI-generated profiles get harder to spot, a free badge that says “yes, I’m a real person” feels like a pretty useful thing to have around.

In a headquarters and lab space formerly occupied by SpaceX in Redmond, Wash., AIM Intelligent Machines (AIM) is focused on solving big problems on Earth. But the startup’s CEO envisions a day when autonomous bulldozers and excavators will dig, haul, and grade on the moon or Mars, and take AIM’s “terraforming mission” off planet.
For now, AIM’s 25,000-square-foot facility in a nondescript business park is a long way from Mars. Inside the sprawling space, there are glimpses of what the rapidly growing company is working on, including the apparatuses that attach to existing machines to make them self-driving.
Around the office, desk cubicles are decorated with tiny yellow excavator buckets, mirroring photos on the walls of heavy equipment operating on job sites worldwide.

The toy excavators are a nod to a massive global market that AIM founder and CEO Adam Sadilek wants to continue to disrupt with modern technology.
Autonomous passenger vehicles have captured the public’s attention for decades, but construction, mining and hauling equipment attracts little fanfare, even as legacy companies including Komatsu and Caterpillar embrace new technology.
AIM’s goal is not to build new machinery, but retrofit existing earthmoving fleets with a physical AI platform — using advanced sensors and edge compute to let heavy iron operate entirely on its own.
Founded in 2021, the startup grew out of Sadilek’s background at Google where he spent nine years working on projects involving AI and autonomous vehicle systems.
Whether building anti-flood structures or wildfire breaks, managing nuclear waste, mining critical materials or clearing land for agriculture or the military, Sadilek views AIM’s work as immediate terraforming on Earth that is necessary to drive down costs for housing and commodities. But the long-term vision remains interplanetary.
“When humanity goes to Mars, the real question is not so much around what the rocket looks like as a vehicle to get us there, but what is going to happen after the rocket lands,” Sadilek said. “You cannot have human operators run there. That’s why this is a very long mission that we are on.”
Building autonomy for heavy equipment presents a paradox self-driving cars never have to face: the ground itself is constantly changing. While a Tesla or Waymo relies on pre-mapped roads and predictable lanes, a bulldozer or excavator’s entire job is to reshape its environment. AIM’s physical AI platform has to continuously build real-time 3D maps using onboard 360-degree LiDAR and edge compute, making split-second decisions without relying on persistent GPS or cloud connectivity on remote job sites.
Furthermore, taking human operators out of cab seats addresses one of the most perilous aspects of heavy industry. By creating “zero-entry” sites where machines operate autonomously, AIM’s platform effectively removes workers from harm’s way — transitioning traditional equipment operators into remote site supervisors who oversee entire fleets from a safe distance.
Beyond early deployments in mining and site preparation for data centers, AIM landed a $4.9 million U.S. Air Force contract earlier this year to deploy autonomous machines for airfield repair and base construction in remote or high-risk zones. The military work builds on the company’s growing momentum following a $50 million funding round backed by Khosla Ventures, General Catalyst, and Human Capital.
AIM has risen to No. 110 on the GeekWire 200 ranking on top Pacific Northwest startups.
To support its growth, AIM has rapidly expanded its headcount, doubling in size to about 80 employees in the last few months. Sadilek is attracted to the Seattle area’s intersection of hardware expertise from companies like Boeing and Amazon alongside top-tier software and AI talent.
But while AIM has managed to hire a couple former SpaceX engineers to build out its team, it isn’t the only startup mining that rocket-engineering pedigree. TerraFirma, an Austin-based company founded by two more SpaceX engineers, raised $115 million earlier this month in the burgeoning race to semi-automate physical construction.
For Sadilek, anchoring his team in Redmond rather than Silicon Valley was a deliberate decision to stay rooted in physical engineering. Having spent years in the Bay Area during his time at Google, Sadilek wanted to avoid the tech industry’s “echo chamber.”
“I wanted to be somewhat shielded from the Kool-Aid in Silicon Valley,” he said. “We wanted to build something that’s real and gets in the black really quickly… To do that, you need to do it in an environment that is more anchored in reality.”
That philosophy extends directly into their field testing. AIM’s regional proving grounds in the mountains near Monroe, Wash., expose the autonomous equipment to heavy snow and inclement weather early in development so the physical AI is built for harsh, real-world conditions from day one.

Amid the hard hats, safety vests and construction-related decor in AIM’s headquarters space, one piece of art offers a fun take on where AIM has been and where it’s headed.
The 1949 photograph, titled “Refueling the Sunkist Lady,” shows a Jeep driving beneath a low-flying plane and transferring supplies to aid the crew during an endurance flight.
Sadilek likes it as a reminder of getting started, and what it feels like to build a company from scratch, literally working on the airplane while it’s already rolling down the runway.
“The first years of AIM were exactly like that,” he said. “I think every tech startup is like that in the early days. The problem is that some of them never finish building it before the runway ends.”
The Hide My Email failure is real but nowhere near as significant to users as it’s being portrayed, Apple is hiking so many prices yet looking at ways to make that palatable, plus Foxconn has begun its annual recruitment drive as it begins producing millions of new iPhones, all on the AppleInsider Podcast.
It’s been painted as a big security failing by Apple, and it definitely isn’t good. But even if someone does manage to circumvent your use of Hide My Email, the worst they can do is send you a spam message.
There’s more to it, of course, and if there weren’t then you wouldn’t benefit from listening to Wesley Hilliard explaining it on the podcast. But while it’s good to know the background, not to mention interesting, you can be reassured too.
Which you might also be by how Foxconn is ramping up its recruitment right on schedule. Even if you’re not looking for a job assembling iPhones, it means that the iPhone 18 Pro is on track.
It would be, of course, and the only real questions are whether it can possibly match the success of the iPhone 17 Pro range, and whether there will be an iPhone Fold.
Although of course, there is also the issue of just how much any of these new iPhones will cost. But a strong new rumor claims that Apple will shortly launch a new Apple Upgrade program, specifically to make it possible to buy with a lower upfront cost.
If Apple gives us this leasing program, it also may take away something. To protect it from people just signing up and walking away with costly iPhones, Apple is believed to be readying a way to restrict the use of its devices if a payment is missed.
BONUS: Subscribe via Patreon or Apple Podcasts to hear AppleInsider+, the extended edition. This time, speaking of payments, the discussion is on technology and money, specifically how we need to manage our finances and how options like Apple Card can usually help.
Tune in to our Smart Home Insider podcast covering the latest news, products, apps, and everything HomeKit related. Subscribe in Apple Podcasts, Overcast, or just search for HomeKit Insider wherever you get your podcasts.
Podcast artwork from Basic Apple Guy. Download the free wallpaper pack here.
Those interested in sponsoring the show can reach out to us at: [email protected].
Keep up with everything Apple in the weekly AppleInsider Podcast. Just say, “Hey, Siri,” to your HomePod mini and ask for these podcasts, and our latest HomeKit Insider episode too. If you want an ad-free main AppleInsider Podcast experience, you can support the AppleInsider podcast by subscribing for $5 per month through Apple’s Podcasts app, or via Patreon if you prefer any other podcast player.
Three attacks, three names, and one identical flaw: AI coding agents treat a hallucinated identifier as a verified command.
By Shane Warden, Principal Architect, ActiveState
Ask an AI coding agent to fetch a tool. Occasionally, it returns a name that sounds right, but does not exist. Developers used to ignore this mistake, assuming a compiler or test would stop it. Unfortunately, that assumption is dangerous and wrong.
Effectively now we’re giving root access to language models that sometimes guess words, and attackers know how to use that against us.
The attack goes like this: an attacker can calculate URLs, software library names, and other output an LLM will produce and subsequently access somehow. The attacker grabs the name, then sets a trap and waits.They do not need to steal passwords. They do not need to send phishing emails.
They do not need a human to click a link. They need someone, somewhere to give an automated process permission to fetch something malicious.
Researchers at Tel Aviv University, Technion, and Intuit published a paper on July 8, 2026. The team, led by Aya Spira in Ben Nassi’s group, proved that these fake names are predictable.
They tested multiple prompts across Cursor, Windsurf, GitHub Copilot, Cline, Gemini CLI, and OpenClaw. Models hallucinated identical names up to 85% of the time for repository requests. They hallucinated identical names 100% of the time for skill installs.
“Slopsquatting exploited a fake package name. Phantom squatting exploited a fake domain. HalluSquatting exploits a fake repository or skill,” Warden says. “In every case, the agent trusts a name nobody verified.”
That comparison undersells what is new here. Slopsquatting and phantom squatting get an attacker’s code onto one machine at a time. HalluSquatting scales further for attackers, because the agent does the delivery work a botnet operator used to need real machine compromise for.
There are no stolen passwords, no worms crawling from device to device, and no single operating system to target. Any machine running an exposed agent can be a target.
The researchers built this attack specifically to demonstrate that it repeats at scale, which is why they treat their own numbers as a floor rather than a ceiling: “Attacks always get better,” they write. “They never get worse.”
Cordyceps passed every check because no single workflow file was wrong, it was the composition that was exploitable.
See how to close that gap by governing what enters your build at the source, not just what passes the scan.
Security teams have seen this failure three times in six months.
January 2026 (Slopsquatting): Charlie Eriksen at Aikido Security caught AI agents trying to install a fake npm package named react-codeshift across 237 projects. He registered the name to stop attackers from taking it.
June 2026 (Phantom Squatting): Unit 42 at Palo Alto Networks found 250,000 domains that language models hallucinate. Anyone could register those domains.
July 2026 (HalluSquatting): Spira’s research team showed how attackers can take over AI agents by claiming predictable names in advance.
Every attack relies on the same core defect. The system trusts a name that a model generated without checking if anyone verified and validated it.
This problem stems from two connected issues.
First, language models generate their outputs based on probabilities. Given the right inputs, they’ll produce predictable outputs (not deterministic, of course, but the paper shows that they’re predictable enough to produce attack vectors). This reminds me of rainbow tables, where you can pre-generate the output of password hashes.
You don’t have to know someone’s password if you can get the (insecure) hash and you know an input which creates that hash.
Second, developers build and run code and pipelines that execute commands based on the generated output of these language models. Unless you’re very careful, your agents will run code or fetch data before they take the opportunity to vet and verify the source of that code and data.
In software architecture, this kind of late binding offers flexibility. In security architecture, trusting an unverified external data source creates a massive vulnerability. The danger lives in the gap between text generation and code execution. What was safe and true may have changed since you last checked yesterday (or an hour ago).
Developers are rushing to ship products faster. They treat build infrastructure like disposable tooling, even while granting these tools expansive permissions to download, change, and deploy things. They have automated typosquatting and dependency confusion.
When agents now have permission to fetch and execute code without sufficient human review, your risks of attacks grow.
The risk extends beyond the top-level packages. An agent might select a real package with a real name. Modern security tools may check that top-level package. Do you know they rarely inspect the transitive dependencies three or four layers down the tree?
Developers cannot inspect those dependencies simply by reading the top-level source code or saying “That looks correct” and hitting Enter. Worse, if a dependency is compromised but the previous versions were fine, the rules you had in place yesterday may not protect you today.
If an attacker can compromise a deep dependency or anything it relies on, an automated pipeline can bring that compromise into your systems.
The researchers note that their findings represent a minimum risk level. These attacks will become faster and more accurate in their targeting. Existing security tools fail against these attack patterns.
In June 2026, Trail of Bits bypassed agent skill store scanners in less than an hour. Scanners examine stated claims rather than hidden payloads.
SSL certificates and DNSSEC fail to stop this threat. An attacker who registers a fake domain can easily get a free Let’s Encrypt certificate. The certificate proves who owns the domain, but it cannot prove that the user intended to connect to it or that the domain is safe.
DNSSEC prevents other people from taking over a domain, but what if the domain were registered yesterday because an attacker predicted the latest model would send people there?
To secure your systems, you must ensure that none of your pipelines ever execute unvetted code or data. That vetting and verification has to happen automatically, at the speed of AI. Human review cannot keep up with automated AI tools.
Engineering teams must address this problem directly. They can spend significant time building internal verification pipelines, or they can adopt an existing governance solution.
Teams that patch individual tools will spend years chasing new variations of this exploit. Teams that fix the underlying design flaw will stop the attack before the model ever runs an untrustworthy command.
Organizations must resolve open source dependencies through something like ActiveState’s Curated Catalog, a private, policy-governed repository of vetted components. The catalog verifies the package before the agent downloads it. A package which fails this vetting is completely invisible to the agent, causing a failure before any bad code can enter your systems.
This is a different defense than scanning. Trail of Bits broke scanners because scanners inspect an unknown upload at the moment of fetch, exactly when an attacker has optimized the payload to slip past.
The Curated Catalog removes that moment entirely: it only ever serves components that were vetted and verified before any agent asked for them, so there is no unknown upload left to bypass. This single step turns a statistical guess into a trusted resource or a deliberate failure which needs human investigation.
HalluSquatting is an attack where researchers pre-compute the fake repository, package, or skill names that AI coding agents predictably invent, register those names first, and load them with malicious instructions before a real user’s agent goes looking for them.
All three exploit the same flaw, an agent trusting a name nobody verified, but target different resources. Slopsquatting targets npm package names, phantom squatting targets web domains, and HalluSquatting targets repositories and agent skills, then executes the payload directly through the agent’s own tool-use permissions.
Not reliably. Trail of Bits bypassed every public skill-store scanner they tested in under an hour, because scanners inspect an unknown upload’s stated content rather than its hidden payload. A static, post-hoc scan is racing an attacker who built the payload specifically to defeat that scan.
Turn on pre-fetch verification wherever it exists; most agent frameworks ship with it off by default. Route open source dependency resolution through a governed, pre-vetted catalog instead of letting agents fetch directly from public registries.
The researchers found hallucinated names were consistent across tools built on different underlying models, including Cursor, Windsurf, GitHub Copilot, Cline, Gemini CLI, and OpenClaw. This is a pattern in how agents are built and permissioned, not a flaw isolated to one vendor.
Sponsored and written by ActiveState.
SCIENCE
Replacement Raptors head for liftoff without a static fire test
SpaceX is gearing up for another attempt to launch Starship following a last-second abort on July 16 and a scrub due to weather yesterday.
The 90-minute launch window for Starship’s 13th flight test will open at 1745 CT on Friday, July 24. The launch was postponed by 24 hours due to weather, according to SpaceX.
Elon Musk’s rocketeers explained: “A key objective for the flight test is to get clear imagery from the ground of Starship’s heatshield as it flies at a higher dynamic pressure during ascent, which won’t be possible with today’s weather conditions. Visibility is forecast to be ideal for a Friday attempt.”
The first attempt last week was aborted in the final seconds after some of the booster’s Raptor engines failed to start. At the time, Musk said “two Raptors will be removed and replaced.”
Interestingly, the company did not perform a static fire test of the booster with the new engines on July 22, opting for what appeared to be little more than a leak check. The Register asked SpaceX what testing it performed, but it has yet to respond. In a post on X, the company only stated “additional preflight testing on Super Heavy complete.” There is speculation that last-second shutdowns, whether during a static fire or launch attempt, may not be kind to Raptor engines.
The Starship project is under greater scrutiny than ever. NASA requires it to have orbital capability for Artemis III in 2027, and a launch cadence high enough to support a lunar landing mission in 2028. SpaceX is also a publicly traded company and, while its current stock price has already fallen below its IPO, it could do without further rattling investor nerves with a failure.
Should all go well, the entire mission should last just over an hour. After launching Starship, the Super Heavy booster is expected to make a controlled splashdown in the Gulf of Mexico. Starship will use its Raptor engines to enter a suborbital trajectory before coming down in the Indian Ocean.
Before re-entry, SpaceX plans to deploy 20 Starlink V3 satellites, which will follow the vehicle on its suborbital trajectory, and attempt a relight of a Raptor engine. The latter is a critical step on the path to Starship going orbital. ®
Gravis Robotics, an ETH Zurich spinout, fits autonomy kits to excavators. A tie-up would extend Masayoshi Son’s robotics buying spree from the factory floor to the building site.
SoftBank is weighing a deal for Gravis Robotics, a Swiss startup that fits excavators and diggers with the sensors and software to run themselves, according to Bloomberg.
The report did not spell out the shape of any transaction, and the size, structure, and valuation were not disclosed. The discussions appear to be at an early stage, and there is no guarantee they lead anywhere.
What they do signal is where SoftBank is looking next. Masayoshi Son’s group has spent the past year assembling a robotics portfolio at speed, from an $800mn round it is reportedly circling for Agile Robots to smaller bets on the kind of autonomy kits that bolt onto existing machinery.
Gravis Robotics spun out of ETH Zurich in 2022, from the Swiss university’s Robotic Systems Lab. Rather than build a robot from scratch, it retrofits standard heavy equipment, attaching a kit that fuses LiDAR, cameras, GNSS positioning, and hydraulic sensors so an ordinary excavator can trench, grade soil, and manage stockpiles on its own.
The company says the approach can lift site output by roughly 30%.
The kit has a name, or two. The hardware, Gravis calls Rack; the operator controls it through a tablet interface named Slate that switches between autonomous and manual modes.
The pitch is that a machine can be taught to feel the soil through its hydraulics rather than follow a fixed programme.
It is run by chief executive Ryan Luke Johns, an architect turned roboticist, alongside chief technology officer Dominic Jud and co-founder Marco Hutter, an ETH robotics professor.
Johns and Jud hold a Guinness World Record together for the largest robot-built dry-stone wall, which tells you something about the company’s temperament.
In November 2025 the startup raised $23mn in a round co-led by IQ Capital and Zacua Ventures, with Pear VC, Sunna Ventures, and cement group Holcim among the backers.
By its own account, Gravis now has machines working on active sites across seven countries. Its customer list, per the company’s own announcements, includes contractor Taylor Woodrow, which used the technology at Manchester Airport, plant-hire firm Flannery, and Holcim, which runs it in quarries. Those claims come from Gravis and have not been independently audited.
For SoftBank, construction is a logical extension of a much larger thesis. The group agreed last October to buy ABB’s robotics division for $5.4bn, and a four-bank syndicate only finished putting together the roughly $1.75bn loan behind that purchase this week.
It is also selling its remaining stake in Boston Dynamics to Hyundai, tidying up an older robotics bet even as it places newer ones.
The Gravis talks, if real, would join a run of similar moves. SoftBank led Agile Robots’ 2021 financing, the round that made the Munich firm Germany’s first robotics unicorn, and is now said to be anchoring a fresh $800mn raise there.
Earlier in 2025 it put $500mn into Skild AI, a startup building a general-purpose model to control robots. The common thread is machines that do physical work, and software good enough to run them.
Son’s pitch is that artificial intelligence has matured in software and the next frontier is giving it a body. SoftBank is reportedly preparing a US-based AI and robotics vehicle, provisionally called Roze, that it hopes to float at a $100bn valuation.
The wider market has moved with him, with global robotics investment more than doubling to $27.6bn in 2025, the year of record rounds for firms such as NEURA Robotics.
A digger that drives itself is a less photogenic proposition than a walking humanoid, but it may be a more immediately useful one. Construction faces a persistent shortage of skilled machine operators, and earthmoving is repetitive, dangerous, and expensive to staff.
Whether SoftBank ends up buying into Gravis, or simply kicking the tyres, the direction of travel is clear enough. The company that once bet on a chatty humanoid named Pepper now wants the machines that move actual earth.
Weekend Open Thread – Corporette.com
The House | The City of London can help the new chancellor deliver growth in every postcode
Ripple Payments Joins MiCA With 14 Firms, Does It Mean Anything For XRP?
Democrats look to World Cup watch parties to register thousands of voters
Ripple wins EU-wide access as ESMA adds it to MiCA register
Grayscale Files For Worldcoin ETF, WLD Registers Sharp Rise
Sail Virtually Aboard The “Itanic” With IA-64 Emulator
Unregistered fitter used Gas Safe logo on business flyers
Turtle Beach Command Series KB7 review: a nifty screen-equipped gaming keyboard
Big Money Is Entering XRP
New Jersey voter registration controversy explained: How 6,600 noncitizens got on the rolls, and what happens next
Kaspersky exposes OkoBot’s 20-module crypto wallet attack
Airlines warn Sunshine Protection Act could disrupt flight scheduling
Johnny Depp’s R-Rated Gothic Cult Classic Gets New Release Ahead of Sydney Sweeney Remake
Durham County Council to send out electoral registration emails
Ethics, other provisions in crypto Clarity Act to be further discussed
MiCA Licensing Faces Delays as ESMA Adds 14 CASPs to Register
Chip Stocks Enter Bear Market After Moonshot Ai Unveils Kimi K3 Model
Shanghai science forum photos show China’s AI and robotics advances in rivalry with US
Watch Flock Safety CEO Garrett Langley discuss the future of surveillance at TechCrunch Disrupt 2026
You must be logged in to post a comment Login