Sunday, 2 August 2026

Apple Reclaims the Crown: How a Cautious Approach to AI Spending Fuels Its Return to Market Dominance

Apple has done it again. The tech giant reclaimed its position as the world’s most valuable publicly traded company this week. Its market capitalization hit roughly $4.9 trillion. That edged out Nvidia. The move ends a streak of more than a year without the top spot. The longest such period since Apple first claimed the title back in 2011.

Shares climbed as investors rotated away from companies pouring hundreds of billions into data centers and graphics chips. Apple took a different path. It stayed relatively asset-light. Its capital expenditures over the past 12 months reached only $11 billion. Compare that to the $200 billion annual pace set by Microsoft, Alphabet and Amazon. The contrast could not be sharper.

But Apple’s resurgence rests on more than just lower spending. The company has spent years building artificial intelligence features that run directly on its devices. Privacy remains a core selling point. On-device processing means user data never leaves the iPhone or Mac unless the owner chooses to share it. That strategy stands in marked opposition to cloud-heavy rivals who rely on massive server farms.

Recent demonstrations of Apple Intelligence show the payoff. The system can generate briefings drawn from a user’s own calendar, emails and notes. In one demo shared on social media, a voice assistant describes the day ahead while a 3D chart of AAPL stock rises in augmented reality. Meeting timelines float into view. Maps appear at the right moment. The experience feels personal. It draws on real user data rather than generic training sets.

Analysts have taken notice. A Motley Fool article published today points out that Apple’s approach avoids the risks now weighing on hyperscalers. Alphabet disclosed $811 billion in future commitments tied to its data-center buildout. The disclosure triggered a sell-off in its shares despite solid growth in cloud revenue and advertising. Similar fears have spread to Nvidia. If returns on all that AI infrastructure disappoint, demand for its processors could slow.

The rotation feels like a flight to safety. Capital-intensive models carry execution risk and high fixed costs. Apple’s model generates enormous gross margins from hardware and services. Its installed base of more than two billion active devices gives it a distribution advantage few can match. Software updates can push new AI capabilities to hundreds of millions of users overnight without new capital outlays.

Still, the stock no longer looks cheap. Apple trades at about 39 times forward earnings. That multiple sits well above the 16-to-26 range for faster-growing cloud giants. Expected earnings growth sits in the 10-to-16 percent range over the next few years. Some investors question whether the premium is justified.

Yet the market seems willing to pay for predictability. Apple’s services business continues to expand at double-digit rates. The App Store, Apple Music, iCloud and advertising all throw off cash with minimal incremental cost. Those recurring revenues provide a buffer against any slowdown in iPhone unit sales. They also fund research into new categories such as spatial computing and health sensors.

Partnerships add another layer. Apple’s integration with OpenAI brings powerful cloud-based models into its ecosystem while keeping the user interface under tight control. The arrangement lets the company offer best-in-class generative features without bearing the full cost of training frontier models. It’s a pragmatic compromise. One that balances innovation speed against capital discipline.

Recent market moves reflect this logic. On July 27, Apple’s shares rose more than 1 percent while Nvidia fell nearly 5 percent. The New York Times reported the exact moment Apple overtook the chipmaker, pushing its valuation to $4.9 trillion. The crossover happened after weeks of mounting concern over the sustainability of AI-related capital spending. Nvidia’s own market cap had briefly topped $5 trillion earlier this summer before giving ground.

Broader sentiment on social platforms echoes the shift. Traders note that companies once criticized for high spending now face scrutiny. One recent post highlighted how fears around AI infrastructure could cost Apple suppliers nearly $500 billion in combined market value if chip shortages worsen. Yet Apple itself appears insulated. Its supply chain for custom silicon remains tightly managed. Long-term agreements, such as a $30 billion commitment with Broadcom for U.S.-based manufacturing, signal steady investment without the spectacle of hyperscale data-center construction.

The company’s history offers context. Apple lost the most-valuable crown to Microsoft in May 2025. Nvidia passed both firms the following month. For more than a year the iPhone maker watched from second or third place. That absence marked an unusual stretch. Now the crown sits back on its head. And the reasons extend beyond any single product launch.

Device intelligence features rolling out in iOS updates demonstrate tangible progress. Users can ask their phones to summarize long threads, rewrite emails in different tones, or create images from text prompts entirely on-device for simpler tasks. More complex requests route to private cloud servers or, with permission, to partner models. The architecture protects privacy while delivering performance. It’s a formula the market increasingly rewards.

Of course risks remain. Competition in consumer AI intensifies. Google continues to push Gemini features across Android. Microsoft embeds Copilot throughout its productivity suite. Yet Apple’s focus on consumer hardware gives it a direct relationship with end users that enterprise-focused rivals lack. That relationship translates into loyalty. It also creates a moat around its services revenue.

So what happens next? If concerns over AI returns persist, capital-light businesses like Apple could enjoy a prolonged period of outperformance. Its balance sheet carries more than $100 billion in net cash. That war chest supports share buybacks, dividends and selective acquisitions. Meanwhile the hyperscalers remain locked into multi-year construction commitments that are hard to scale back.

Investors appear to be voting with their dollars. Apple’s stock has climbed steadily in recent weeks, setting repeated record highs. The valuation premium reflects confidence that its measured approach will deliver sustainable growth even as the AI hype cycle matures. Not every company needs to spend $200 billion a year to stay relevant.

The coming quarters will test that thesis. Earnings reports from the hyperscalers will reveal whether their massive outlays translate into accelerating revenue. Apple’s own results will show whether new AI features can lift iPhone replacement rates and services uptake. Early signs look promising. But the market’s patience is not unlimited.

For now the crown is back where many investors believe it belongs. Apple has reminded Wall Street that discipline can be its own competitive advantage. In an industry obsessed with scale and speed, sometimes the smartest move is to move deliberately. And let the balance sheet do the talking.



from WebProNews https://ift.tt/lnfa6Ou

Saturday, 1 August 2026

Google’s Pixel Tag Emerges as Android’s Long-Awaited AirTag Counterpart

Google has finally shown its hand on a tracker of its own. The device, dubbed the Pixel Tag, surfaced this week in fresh leaks and retailer listings just weeks before the company’s August hardware event. An image obtained by 9to5Google reveals an oblong shape unlike most rivals. It stands taller than Samsung’s Galaxy SmartTag and echoes the silhouette of a Fitbit bandless Air. No mounting hole appears on the body. Owners will likely depend on separate cases, much as they do with Apple’s offering.

Model number GA12506. Color name Fog Light, expected to shorten to Fog at retail. Those details come straight from European listings that began popping up in recent days. One retailer prices it near €30, hinting at a possible $30 U.S. tag. The timing feels deliberate. Google plans to launch the Pixel 11 series on August 12. Bundling the tracker makes sense. Android users have waited years for a native solution.

Android Police captured the moment well. The publication noted the surprise element amid a wave of Pixel 11 leaks. “We’ve seen quite a few leaks over the past couple of weeks,” its reporter wrote. “But the Pixel Tag comes as a bit of a surprise.” Hopes run high for ultra-wideband support and the new Channel Sounding feature arriving in Android 15. Either capability would sharpen location accuracy beyond what current third-party Android tags deliver.

The marketing text pulled from listings strikes a familiar tone. “The Google Pixel Tag smart tracker helps you quickly and reliably locate your lost items using the secure ‘Find My Device’ network,” it reads. “Never waste time searching for your keys, wallet or luggage again.” It describes the unit as compact, lightweight and durable. A loud speaker aids nearby searches. Privacy protections get explicit mention. Google built the Find My Device network to blanket the planet with Android phones. Now it ships hardware to tap that mesh directly. The network rolled out fully in 2024. Support for third-party trackers followed months later. A first-party device completes the picture.

But. The absence of confirmed UWB specs still nags. Early listings stay silent on battery type. Replaceable coin cell? Rechargeable pack? Unknown for now. Droid Life echoed the same marketing copy and added that the shape resembles “a little puck.” Price speculation aligns at roughly $30. That positions it competitively against Apple’s second-generation AirTag, which carries a $29 starting point in many markets. Apple’s latest model improved speaker volume and added better anti-stalking alerts. Google must match or exceed that bar.

Android Police reminded readers what success looks like. Apple’s AirTag “offers a tracking experience that’s simple and highly accurate.” The sequel raised the bar further. Samsung, Motorola and others sell compatible tags today. None command the same mindshare. A Pixel-branded unit could shift buying habits. It would integrate cleanly with Pixel phones, of course. Yet Google promises broad Android compatibility. That matters. The installed base exceeds three billion devices. Even a fraction of those reporting location pings would create dense coverage.

Privacy remains a flashpoint. Apple baked in anti-tracking features after early AirTag abuse reports. Google’s listing language signals awareness. “Designed with your privacy and personal data in mind.” Details will matter at launch. How loud is the speaker? How long does the battery last in real conditions? Does it support precision finding on non-Pixel Android phones? Early coverage leaves those questions open.

And the design choice intrigues. Oblong rather than round. Taller profile. No built-in loop. It suggests Google optimized for pocket or bag placement over keychain duty out of the box. Cases will fill that gap. Third-party accessory makers stand ready. The ecosystem around AirTag proves the market exists.

Recent coverage adds urgency. 9to5Google argued earlier this year that Apple’s AirTag 2 only heightens the need for a Google equivalent. The piece ran in January 2026. Now, seven months later, the product appears. Timing suggests internal development accelerated once the rival launched. Google had teased tracker ambitions years earlier, yet nothing shipped. The Find My Device network rollout in April 2024 acted as foundation. Hardware followed.

Tech Advisor noted the same momentum three days ago. Its report framed the Pixel Tag as a direct AirTag rival slated for the August event. The piece linked the tracker to broader Android momentum. Pixel 11 renders leaked alongside it. Matte finishes. New colors. Incremental design changes overall. The tracker may generate more excitement than the phones themselves in some circles.

Google stayed quiet. No official statement. No spec sheet. Retail leaks forced the reveal. That pattern repeats across the industry. Suppliers list products early. Images surface. Speculation fills the gap until the stage lights come on. August 12 will likely bring confirmation, pricing and full feature list. Expect hands-on footage the same day. Real-world tests will follow quickly.

Until then, the Pixel Tag exists as promise and prototype image. Oblong. Fog colored. Speaker equipped. Tied to a network now spanning billions of handsets. Android users finally get a native tracker story. Whether it outperforms the competition depends on details still hidden. The foundation looks solid. The network works. Privacy language reassures. Execution will decide if this becomes the tracker Android has lacked for years.

One thing feels clear. The wait ends soon. Google no longer watches from the sidelines. It ships hardware. The Pixel Tag marks that shift. Industry watchers and everyday users both pay attention. The Find My Device network finally gets its flagship tag.



from WebProNews https://ift.tt/fpuFLMi

Friday, 31 July 2026

Human Error Causes Most Data Breaches: Why Employees Are the Biggest Risk

The biggest data leaker is probably not who you think it is

Most organizations spend considerable time and resources worrying about sophisticated hackers, state-sponsored cyber operations, and insider threats from disgruntled employees. Yet year after year, the single largest source of exposed sensitive information comes from a far less dramatic culprit: ordinary employees making everyday mistakes. According to multiple independent analyses, including reports from TechRadar, human error consistently accounts for a majority of data breaches and unintended exposures across industries. This pattern holds true whether examining records from cybersecurity firms, government regulators, or insurance underwriters who track claim patterns.

The scale of these incidents surprises many executives. In one recent twelve-month period, misconfigured cloud storage buckets alone exposed billions of records containing personal information, financial details, and proprietary business data. These mistakes rarely involve malicious intent. Instead they stem from rushed configurations, misunderstood permissions, or simple oversights during routine system updates. A marketing team might upload a customer database to a public folder for easy collaboration, while an engineer could leave test credentials in a publicly accessible code repository. Each case represents a preventable leak that could have been avoided with basic checks.

Cloud services have amplified the problem significantly. When companies moved their operations to platforms like Amazon Web Services, Microsoft Azure, and Google Cloud, they gained flexibility and scalability. However, they also inherited new responsibilities for security configurations that were previously handled by specialized data center teams. Many organizations discovered too late that default settings often prioritize accessibility over protection. A single checkbox left unticked or an overly broad access policy can turn a private repository into a public data fountain accessible to anyone with an internet connection.

Research from various security organizations shows that these configuration errors occur across all company sizes and sectors. Healthcare providers have exposed patient records through improperly secured backup systems. Financial institutions have leaked transaction details via test environments that were never properly decommissioned. Even technology companies, which presumably understand these risks better than most, have suffered embarrassing exposures of customer lists and source code snippets. The common thread in nearly every case involves someone who simply did not realize the full implications of their actions at the time.

Several factors contribute to this persistent vulnerability. First, modern development practices emphasize speed and collaboration above almost everything else. Development teams are encouraged to ship features quickly, share resources openly, and avoid anything that might slow down progress. Security reviews sometimes get treated as bureaucratic hurdles rather than essential safeguards. When deadlines loom, corners get cut. A database that should require authentication gets temporarily opened to simplify testing, and nobody remembers to close it again after the project moves forward.

Training programs often fail to address the practical realities employees face. Generic awareness courses that warn about phishing emails and strong passwords do little to help a system administrator understand the nuances of identity and access management in a multi-cloud environment. The terminology alone can overwhelm people who lack specialized security backgrounds. Terms like least privilege, zero trust, and role-based access control sound theoretical until a misconfiguration exposes customer data and triggers regulatory fines.

The regulatory environment has grown stricter, yet penalties have not always produced better outcomes. Organizations face increasing pressure to report breaches quickly, which has improved transparency but also created incentives to downplay human error in official statements. Companies prefer to describe incidents as sophisticated attacks rather than admit that an employee left a server unprotected. This reluctance to acknowledge the true cause prevents organizations from addressing root problems and perpetuates the cycle of repeated mistakes.

Technical solutions exist but require consistent implementation. Automated scanning tools can detect open storage containers and overly permissive access policies before data escapes. Version control systems can scan for hardcoded credentials in code repositories. Data loss prevention systems can monitor for sensitive information moving to unauthorized locations. Yet these tools only work when properly configured and regularly maintained. Too often they get deployed as part of a compliance checklist and then ignored until an incident occurs.

Organizational culture plays a decisive role in determining whether human errors lead to major breaches. Companies that treat security as a shared responsibility across all departments tend to experience fewer serious incidents. When executives discuss security metrics with the same regularity as revenue figures, employees pay closer attention to details. Regular simulations that demonstrate how simple mistakes can cascade into major exposures help build intuition that generic training cannot provide.

Some organizations have begun experimenting with different approaches. Rather than adding more rules, they focus on reducing complexity. Simplified permission models that default to minimal access require deliberate steps to expand privileges. Automated cleanup routines that remove test data and temporary configurations after set periods prevent forgotten resources from becoming liabilities. Clear ownership assignments ensure that someone remains accountable for every database, application, and storage container.

The financial impact of these preventable leaks extends beyond immediate remediation costs. Regulatory fines from bodies like the European Union’s GDPR or California’s CCPA can reach tens of millions of dollars for a single incident. Class action lawsuits from affected customers add another layer of expense. Insurance premiums rise after each claim. Most damaging of all, customer trust erodes when people discover their information appeared on public forums or dark web marketplaces due to basic carelessness.

Small and medium-sized businesses often face greater risks than large corporations in this area. They typically lack dedicated security teams and rely on general IT staff who juggle multiple responsibilities. Limited budgets mean fewer tools for automated monitoring. Yet the consequences can be equally severe. A single exposed customer database can destroy a growing company’s reputation before it has time to recover. The perception that smaller organizations represent softer targets also attracts opportunistic attackers who scan for easy configuration mistakes.

Recent trends suggest the problem may worsen before it improves. The continued adoption of hybrid work arrangements means more employees configure systems from home networks with varying security standards. The proliferation of low-code and no-code platforms allows people without technical backgrounds to create applications and databases. While these tools democratize technology, they also spread configuration responsibilities more widely across organizations. Without corresponding education and guardrails, the potential for accidental exposures grows.

Security professionals increasingly advocate for a shift in perspective. Rather than viewing employees as the weakest link, they recommend treating them as critical components of the defense system. This means designing systems that account for human limitations instead of expecting perfect compliance with complex policies. Interface designs that make secure choices easier than insecure ones reduce cognitive load. Contextual warnings that explain risks in plain language at the moment of decision help people understand consequences before they click.

The contrast with traditional threat actors highlights why human error deserves more attention. While nation-state hackers and professional cybercriminal groups develop increasingly sophisticated techniques, they still require specific vulnerabilities to exploit. Many of their most successful operations begin with reconnaissance that identifies systems left exposed through basic misconfigurations. In effect, accidental leakers often create the entry points that more malicious actors then use. Closing these gaps would force attackers to work harder and reduce overall successful breach rates.

Industry analysts predict that artificial intelligence and machine learning tools will help address some aspects of this challenge. Automated systems can continuously scan for anomalous permission changes and flag configurations that deviate from established patterns. Natural language processing can analyze documentation and code comments to identify potential security oversights. However, these technologies will not eliminate the need for human judgment and accountability. They serve as force multipliers rather than replacements for careful practices.

Education initiatives have started adapting to these realities. Some universities now incorporate practical cloud security exercises into their computer science curricula. Professional certification programs emphasize hands-on labs where participants must correctly configure secure environments rather than simply memorizing theory. Companies that invest in these targeted training approaches report measurable reductions in configuration-related incidents over time.

The persistence of human error as the dominant data leak source reveals something fundamental about technology adoption. Organizations have enthusiastically embraced new capabilities while treating the associated responsibilities as afterthoughts. Moving forward requires recognizing that security represents an integral part of system design rather than an add-on feature. Every database, application, and storage solution should incorporate protection by default rather than requiring teams to bolt it on later.

Business leaders who acknowledge this pattern and allocate appropriate resources tend to see better outcomes. They treat security configuration management with the same seriousness as financial controls or quality assurance processes. Regular audits become standard procedure rather than reactions to incidents. Cross-functional teams that include both technical experts and business users develop practical guidelines that balance security with operational needs.

The evidence from years of breach reports makes the conclusion difficult to avoid. While dramatic stories about advanced persistent threats capture headlines, the majority of exposed data results from preventable mistakes by authorized users. Organizations that continue focusing exclusively on external threats while neglecting internal processes will likely experience repeated incidents. Those willing to examine their practices honestly and implement systematic improvements stand a much better chance of protecting the sensitive information entrusted to them.

This reality does not diminish the importance of defending against malicious actors. Strong perimeter defenses, threat intelligence, and incident response capabilities remain essential. However, they cannot compensate for basic errors that leave data completely unprotected. True security requires addressing both categories of risk with appropriate attention and resources. Until organizations recognize accidental leakers as their primary concern, they will continue fighting the wrong battle while data spills out through the most obvious gaps in their defenses. The solution lies not in more complex technology but in better processes, clearer responsibilities, and a culture that values careful execution over mere speed. Companies that embrace this perspective will likely find themselves with fewer embarrassing headlines and stronger relationships with the customers whose information they have successfully protected.



from WebProNews https://ift.tt/qTUuxe0

Thursday, 30 July 2026

Why Agentic AI Security Demands a Rethink of Old Rules, Not New Ones

Security teams face a quiet upheaval. AI agents now plan tasks, select tools and execute actions with little oversight. The shift blurs lines between software and decision-maker. Yet many leaders chase brand-new frameworks. They shouldn’t. The core ideas that protected systems for decades still apply. They just need fresh application.

Reframing Familiar Controls for Autonomous Agents

Autonomous agents interpret goals. They draft plans. They reach for external data and act on it. This creates attack paths that target machine behavior instead of human error. A TechRadar article by Craig Hale captures the point exactly. “For the first time ever, that long-standing assumption is being turned on its head,” Hale writes. Humans no longer sit at the center of every interaction.

But fundamentals endure. Least privilege. Strong authentication. Separation of duties. These ideas don’t vanish. They expand. Agents require their own identities, complete with owners, defined purposes and expiration dates. Without them, abandoned agents linger like forgotten service accounts, quietly holding permissions that no one reviews. Zendesk Chief Security Officer Vinay Patel told Hale in an exclusive interview: “Expiry dates or periodic recertification are important because agents can otherwise become long-lived access paths that are harder to govern than human users.”

Short sentences drive the risk home. Agents don’t clock out. They don’t change jobs. They simply keep running. And that persistence turns small oversights into persistent exposure.

Visibility matters first. Security teams must discover agents wherever they appear: inside SaaS platforms, internal automation scripts, development sandboxes or third-party connectors. Patel stressed the need for inventory. “Companies need inventory and discovery across the places agents can be created or embedded, including SaaS platforms, internal automation tools, development environments, and third-party integrations,” he said. Without that map, governance stays blind.

Recent analysis from Palo Alto Networks reinforces the view. Its cyberpedia entry explains that agentic AI security protects reasoning, memory, tools, actions and interactions so autonomy doesn’t open fresh misuse routes. The piece, published in 2025, notes these risks surface only during multi-step tasks or external tool use. Palo Alto Networks calls for securing the components that drive agent behavior rather than bolting on after-the-fact fixes.

IBM’s February 2026 guide takes the conversation further. Author David Zax reports that 79% of organizations already deploy AI agents while 88% of executives plan budget increases. Yet no consensus best practices exist. IBM suggests treating agents as “digital insiders,” a behavioral lens borrowed from longstanding insider-threat programs. McKinsey’s framing, cited there, pushes threat modeling beyond technology to conduct. IBM lists early principles: continuous monitoring, containment, and full awareness of the machine-learning supply chain.

But. Traditional IAM breaks under the weight. Static credentials and long-lived roles cannot match agents that spin up for single tasks then vanish. The Cloud Security Alliance examined this gap. Its paper argues that credentials must stay task-specific, short-lived and instantly revocable. Zero-trust assumptions become mandatory because agent compromise counts as a realistic event. Cloud Security Alliance recommends isolation, continuous verification and strict least privilege to contain fallout.

NIST research echoes the urgency. A concept paper stresses verifiable records of agent intent, data sources, actions and outputs. Guidance on visibility, control and accountability is in development, yet agents already run in production. Many lack those safeguards. The NIST document urges organizations to act before scale makes retrofitting impractical.

Accountability cannot wait for incidents. Patel insists it must be assigned in advance. “Accountability should not collapse onto a single party by default,” he told Hale. Responsibility spreads across the user issuing instructions, the owner setting governance, the developer who built the model, the platform supplying controls and the enterprise that deployed it. “Accountability must be defined before deployment, not reconstructed after an incident.”

OWASP launched its Agentic Security Initiative to study exactly these questions. The project examines frameworks such as LangGraph, AutoGPT and CrewAI plus new capabilities in models like Llama 3. Its “State of Agentic AI Security and Governance 2.01” offers a snapshot of risks, governance gaps and regulatory moves worldwide. OWASP positions the work as collaborative research rather than vendor prescription.

Martin Fowler published a detailed examination in late 2025. He highlights a core LLM weakness: no rigorous separation exists between instructions and data. Anything an agent reads could alter its behavior. Fowler calls the result a new class of risk that feels fundamental. His article supplies practical mitigations alongside the problems. Martin Fowler’s site remains one of the clearest overviews available to architects and engineers.

Industry vendors have moved quickly. Strata Identity treats agents as first-class identities with ephemeral lifespans, delegated authority and cross-domain reach. Its 2026 guide lists eight concrete strategies, from adaptive authentication to audit trails that survive agent termination. Strata argues that identity must anchor every control.

CyberArk focuses on privilege. Its platform enforces tight controls so agents receive only the rights they need for the moment. A survey of financial and technology leaders revealed a gap between adoption speed and actual controls in place. CyberArk pushes an identity-first model built on least-privilege principles extended to machine actors.

Microsoft advances similar thinking. Its security business now emphasizes agentic-era tools. A recent GeekWire profile of security chief Hayete Gallot details the company’s push to help customers adopt these systems safely. Posts on X this week highlighted the interview as evidence that major vendors now treat agentic security as board-level strategy. One Microsoft 365 FastTrack architect shared the link with evident approval.

Security Onion 3.2.0, released this month, integrates agentic AI directly into its detection pipeline. The open-source tool now uses autonomous agents to triage alerts and reduce analyst fatigue. Its blog post notes the addition alongside other updates, signaling that even community-driven projects see value in autonomy when controls stay tight. Security Onion blog frames the feature as practical evolution rather than hype.

So the pattern repeats across sources. Definitions converge. Agentic AI security means protecting systems that plan, decide and act with minimal human input. It demands identity management, behavioral monitoring, short-lived permissions and clear accountability chains. None of this requires discarding decades of practice. It asks practitioners to map those practices onto a new actor that never sleeps and rarely asks permission.

Enterprises that treat agents as digital colleagues from day one gain speed without proportional risk. They assign owners. They set purpose statements. They enforce expiration. They log both the human who commissioned the task and the agent that carried it out. They monitor behavior against declared intent. When something deviates, they contain it fast.

Recent X discussions show practitioners already wrestle with these questions. One thread examined MCP authorization specs and issuer validation to block IdP mix-up attacks. Another noted that not every agent receives every tool, a deliberate security choice that limits blast radius. These operational details matter as much as high-level strategy.

Vendors such as Salt Security, Vectra and Microsoft publish buyer guides and 101 explainers that repeat the same refrain: the attack surface grows when agents touch APIs, call external services or collaborate with one another. Controls must follow them everywhere. Yet the tone stays measured. No one claims these problems are entirely new. They are extensions of familiar ones, sharpened by autonomy.

That sharpening deserves attention. An agent granted read access to customer data might also gain write access to downstream systems if its reasoning chain wanders. Memory persistence across sessions can leak context from one task into another. Tool selection introduces supply-chain risk if the chosen service carries vulnerabilities. Each vector traces back to the same root: the agent makes choices that humans once made.

Leaders who reframe existing playbooks avoid two traps. They neither freeze adoption while waiting for perfect standards nor race ahead without guardrails. Instead they extend zero-trust thinking, treat every agent as potentially compromised, and demand auditable provenance for every action. The result looks less like science fiction and more like disciplined identity and access management, updated for machines that think.

Preparation beats reaction. Define accountability before the first production agent ships. Build discovery into procurement and deployment pipelines. Test agent behavior under adversarial conditions. Review permissions at regular intervals just as access reviews happen for employees. These steps feel incremental. Their impact compounds.

The hybrid workplace of the near future mixes human workers, conventional software and autonomous agents. Success belongs to organizations that secure all three without pretending any one replaces the others. The principles already exist. The task is to apply them with clarity and speed.



from WebProNews https://ift.tt/hIMlkAQ

Outdated OpenVPN Code Persists in Top VPN Apps, Exposing Users to Known Attacks

Many users assume a fresh VPN app download shields them from threats. The reality proves far more complicated. An audit of popular Windows clients reveals that more than half bundle OpenVPN versions over a year old. Some rely on code untouched for five years or longer. This gap leaves millions exposed even after they click update.

TechRadar examined 32 commercial VPN applications. The results startled security teams. Fifty-six percent ran OpenVPN releases more than 12 months behind current. Forty-one percent exceeded two years. Seven apps carried code from four years prior. Four still used builds dating back over five years. Providers such as Turbo VPN and VyprVPN operated on OpenVPN 2.4.7 from April 2019. TechRadar laid out the numbers in stark detail.

Contrast that with leaders. NordVPN, Windscribe and Proton VPN integrated versions as recent as April 2026. Their CTOs and engineers stressed the value of staying current. Yet the broader industry shows inertia. VPN firms ship slick interfaces and marketing features. The core tunneling engine often stays frozen.

OpenVPN itself records a steady stream of fixes. Six CVEs landed in 2025. Six more appeared in 2024. Each patch hardens the codebase against known attack paths. An attacker need not discover fresh flaws. They simply consult the changelog. Jason Xu, senior app developer at Windscribe, put it plainly. “An attacker doesn’t even need to find a new bug; they can just read the changelog.”

Microsoft researchers took a closer look in 2024. They uncovered four vulnerabilities that together enable remote code execution and local privilege escalation on Windows systems. The flaws sit inside openvpnserv.exe, the Windows TAP driver and the plugin system. CVE-2024-27459 triggers a stack overflow when the service reads a user-controlled byte count into a fixed stack buffer. CVE-2024-24974 grants unprivileged processes access to the named pipe \\openvpn\\service. From there adversaries can launch openvpn.exe with attacker-supplied configurations.

CVE-2024-27903 lets the plugin mechanism load libraries from arbitrary paths. Combine that with a malicious plugin and the door swings open. A fourth issue, CVE-2024-1305, creates an integer overflow in the TAP driver. All four affected releases before OpenVPN 2.6.10 and 2.5.10. Microsoft reported them through coordinated disclosure in March 2024. The fixes arrived later that summer. Microsoft urged immediate upgrades and published detection queries for Defender XDR.

But many VPN vendors lag. They cite compatibility testing, custom modifications and internal backports. Marijus Briedis, CTO at NordVPN, explained the tension. “Because OpenVPN — like any project — regularly patches vulnerabilities, hardens its codebase, and improves performance, running a version that’s years behind might miss security components that current up-to-date versions offer.”

Dr. Peter Membrey, chief research officer at ExpressVPN, warned of mounting debt. “Being several years behind can indicate a growing body of security, compatibility, and operational debt. The further behind you fall, the harder each upgrade gets.” Some providers apply selective patches without bumping the full version string. Others remove deprecated drivers or swap in their own transport layers. The result? Users see a current app version yet inherit yesterday’s risks.

Recent months added fresh warnings. In May 2026 Cisco Talos disclosed TALOS-2026-2381, tracked as CVE-2026-35058. The reachable assertion sits inside TLS Crypt v2 client key extraction. A sequence of crafted network packets crashes the process. OpenVPN 2.6.x and early 2.8_git builds fall victim. Emma Reuter of Cisco ASIG found the bug. The Talos team noted that an attacker on the network path could trigger denial of service with minimal effort. Cisco Talos included the finding in a larger vulnerability roundup that also touched Norton VPN and other tools.

OpenVPN’s own security page lists additional advisories. CVE-2025-13086 affects Access Server copies of the 2.6 branch and enables remote denial of service. Updates to 3.0.2 close the hole. Other 2025 and 2026 CVEs target buffer issues, authentication bypasses and privilege escalation on macOS via background services. The pattern holds. New flaws surface. Patches follow. Yet adoption inside commercial clients remains uneven.

Why does this persist? Open source code grants freedom. It also creates fragmentation. VPN companies fork the project, strip features or layer proprietary obfuscation. Each change demands regression testing across Windows, macOS, Android and iOS. Enterprise customers demand stability. A single crash during a critical remote session can cost contracts. So teams accept six-to-eighteen month delays if they believe critical patches receive backports.

Karolis Kaciulis, lead systems engineer at Surfshark, called that window reasonable when urgent fixes ship quickly. Proton VPN takes a different stance. Spokespeople describe OpenVPN as “slow and bloated” compared with WireGuard. The company now steers users toward its Stealth protocol and plans to phase out OpenVPN inside client apps altogether.

Enterprises face steeper consequences. A compromised VPN client can serve as initial access for ransomware crews or espionage operations. Microsoft’s chained attack requires valid credentials first. That hurdle drops when phishing or endpoint malware steals them. Once inside the named pipe, the rest unfolds with modest Windows knowledge. Detection relies on watching for suspicious pipe events or unexpected plugin loads. Few organizations monitor at that granularity.

Smaller providers sometimes lack resources to track upstream changes. Larger ones weigh user experience against theoretical risk. Norton, for instance, told TechRadar it evaluates each OpenVPN update for stability and performance impact before rolling forward. The calculus favors caution. But caution carries its own cost when known vulnerabilities sit unpatched for years.

Users hold limited visibility. Release notes rarely list the exact OpenVPN build. Logs sometimes expose the version string. Savvy administrators can query client settings or run packet captures to infer the protocol details. Most consumers never look. They trust the green lock icon and the brand name.

And the threat environment keeps shifting. State actors and criminal groups scan for VPN endpoints with known weaknesses. Supply-chain attacks on open source components grow more sophisticated. A single outdated library linked deep inside the VPN binary can undermine the entire encryption promise. OpenSSL versions bundled in older OpenVPN releases carry their own history of high-severity bugs.

So what should security teams do? First, audit every VPN client in the fleet. Check the embedded OpenVPN version against the latest community release. Ask vendors for transparency on patch timelines and backport policies. Consider migrating high-risk users to WireGuard where supported. The protocol ships with a smaller attack surface and faster updates in many commercial offerings.

Where OpenVPN remains mandatory, enforce strict access controls. Rotate credentials frequently. Segment client traffic. Monitor for anomalous connection attempts or crashes that could signal exploitation. Tools from Microsoft Defender can flag named-pipe abuse. Open-source scanners can fingerprint client binaries for outdated libraries.

Vendors must do better. Treating the OpenVPN component as a black box invites trouble. Regular upstream merges, automated testing pipelines and clear version reporting would close the transparency gap. A few already follow that path. More should follow.

The lesson cuts across the industry. An app update alone no longer suffices. Security hinges on every layer, including the quiet protocol engine running beneath the surface. Ignore it and the protection you advertise becomes little more than theater. Users and enterprises alike deserve more.



from WebProNews https://ift.tt/U8q7Tie

Samsung Galaxy S26 FE Faces Sharp Price Hikes as Leaks Reveal Flagship-Inspired Design and Exynos 2500 Power

Samsung’s Fan Edition phones have long served as the practical choice for buyers who crave flagship polish without the flagship bill. Yet fresh leaks suggest the Galaxy S26 FE may test that formula. A recent report from Android Authority points to notable increases across Europe. The base 128GB model could start at €749 in France. That marks a €50 jump from its predecessor.

But the hikes don’t stop there. The 256GB version sits at €809. A €90 increase. And the 512GB option lands at €929. That’s €150 more than before. Memory chip shortages and rising component costs appear to drive the shift. Samsung already lifted prices on its main S26 lineup. The FE series, once a refuge for value seekers, now carries some of that pressure.

Colors remain understated. Graphite and Aqua Green return. A third shade falls somewhere between blue and purple. The palette feels safe. Nothing flashy. Storage tiers hold at 128GB, 256GB and now 512GB. The top option gives users breathing room. Yet the 128GB base survives here even as the flagship S26 dropped it entirely.

Launch timing looks firm. Expect shelves to open around September 1, 2026. The date lines up with last year’s S25 FE rollout. No surprises on that front. But the pricing news lands harder than many anticipated. And recent certifications add weight to the story.

The device, model SM-S741, surfaced in a Wireless Power Consortium listing. Android Central first highlighted the entry. It includes an image of the phone. The camera housing rises prominently. Lenses cluster together near the top edge. The look borrows directly from the Galaxy S26 flagships. Previous FE models kept a flatter, more modest bump. This change signals Samsung wants the budget-friendly phone to feel closer to its expensive siblings.

Performance details fill in further. Geekbench results tied to the SM-S741U variant confirm an Exynos 2500 chipset. The same 3nm processor powered the Galaxy Z Flip 7. Single-core scores hover near 2,426. Multi-core reaches 8,004. Eight gigabytes of RAM pair with it. Android 17 ships at launch, wrapped in One UI 9. Those numbers suggest capable daily use. AI features should run smoothly enough. Yet the chip trails the latest Snapdragon 8 Elite inside the main S26 series.

Battery capacity looks set for a modest gain. Rumors point to roughly 5,000mAh or slightly more. The S25 FE carried 4,900mAh. A 45W wired charger returns, confirmed in a fresh UL Demko certification spotted by 91mobiles. Wireless charging stays at 15W. Nothing groundbreaking. The setup matches patterns from earlier FE generations.

Cameras stay conservative too. A 50-megapixel main sensor leads. Twelve-megapixel ultrawide and eight-megapixel 3x telephoto follow. The 12-megapixel selfie camera rounds it out. PhoneArena notes this configuration carried over from the S25 FE with uneven low-light results on the secondary lenses. No major sensor upgrades appear in current leaks. Buyers chasing photography leaps may feel disappointed.

The display holds steady at 6.7 inches. Dynamic AMOLED 2X technology brings 120Hz refresh and HDR. Peak brightness could reach 1,900 nits. Materials step up from plastic found in cheaper Galaxy A phones. Flat aluminum frame meets Gorilla Glass on front and back. The phone runs a touch larger than the S26 Plus despite sharing the same screen size. That extra bulk accommodates the bigger battery and different internals.

Software support stretches seven years. Galaxy AI tools arrive from day one. Circle to Search, Photo Assist and natural-language Bixby enhancements make the list. Android 17 brings Gemini integration. The long update promise keeps the S26 FE relevant longer than many midrange rivals.

Price reactions spread quickly on X. One post from @sammygurus noted the possible September 1 launch alongside new colors and up to 512GB storage. European hikes drew particular attention. Another from @Androidheadline flagged the heavier price tag. Users weighed whether the Exynos 2500 and refreshed design justify the extra cost. Some called it a flagship tax in disguise.

Comparisons to the S25 FE reveal incremental gains. Better processor. Slightly larger battery. Flagship-like camera island. Yet RAM caps at 8GB while the standard S26 offers 12GB. Camera hardware shows little progress. The value equation grows tighter. Android Central captured the sentiment. “The S26 FE might not be a Fan Edition anymore – it’s a flagship tax in disguise.”

Memory shortages ripple across the industry. Samsung raised S26 and S26 Plus prices by $100 each in some markets. The Ultra saw tiered increases up to $140. The FE line historically avoided steep jumps. This time feels different. A U.S. starting price near $650 still looks plausible according to PhoneArena estimates. But European figures suggest $50 to $150 bumps could cross the Atlantic in some form.

Certification activity accelerated in recent weeks. IMDA approval in Singapore and the UL Demko listing both surfaced within days of each other. The phone is clearly in late-stage testing. Global variant SM-S741B appeared in benchmarks alongside the U.S. model. Consistent results point to unified hardware choices this cycle. No Snapdragon variant rumored so far.

Design cues from the flagship line could help sales. The raised camera module gives a premium impression at a glance. Graphite, Aqua Green and that blue-purple mix offer variety without venturing into bold territory. Storage reaching 512GB appeals to power users who skip cloud backups. Still, the absence of microSD expansion, a feature dropped years ago, remains a pain point for some.

Buyers holding older devices stand to gain most. Anyone on a Galaxy S23 FE or earlier A-series phone will notice faster performance and modern AI capabilities. Those already on a 2025 flagship gain little reason to switch. The S26 FE occupies the space between premium midrange and true flagships. Its success depends on how Samsung prices it in each market and whether real-world Exynos 2500 efficiency matches the hype.

More leaks will surface in coming weeks. Camera samples, battery tests and hands-on images should follow the certification trail. For now the picture shows a phone that borrows heavily from the S26 while accepting targeted compromises. The bigger question is whether fans will accept the higher asking price. Samsung bets they will. Early online chatter suggests the debate has only begun.



from WebProNews https://ift.tt/Clr8Rv3

AI Takes On Undeciphered Scripts: Promise and Pitfalls in Cracking Ancient Codes

Linear A has resisted every attempt to read it for more than a century. The Bronze Age script from Crete stands alone, without bilingual texts or clear linguistic relatives to serve as guides. Etruscan inscriptions from pre-Roman Italy offer slightly more footholds yet still withhold their full grammar and vocabulary. Now artificial intelligence enters the picture. Not as a magic solver. But as a tireless assistant that can test hunches at speeds no human team could match.

Jane Adkins, a PhD candidate at Dublin City University’s School of Computing, examined these cases in detail. Writing for The Conversation, she explained how every successfully decoded ancient language relied on an anchor. That anchor is usually a Rosetta Stone-style bilingual document or a known related tongue. Without one, progress stalls. AI cannot create such anchors from thin air. Yet it can accelerate the work once a researcher supplies a hypothesis.

Consider the claim that surfaced in June 2026. A self-taught AI engineer and amateur linguist proposed that Linear A belongs to the Semitic language family. He began with one guess. A word in a prayer inscription might stem from a Semitic root meaning “to dwell” or “to inhabit.” From there he built scripts that let AI scan the entire surviving Linear A corpus. The result? Values assigned to 40 signs and a lexicon of 408 words. The work remains under expert review. Still, the episode reveals AI’s current sweet spot.

It didn’t generate the initial idea. The engineer did. AI simply ran the numbers. Fast. Exhaustively. It checked whether that single assumption held across thousands of characters. What once demanded months of manual labor now finished in minutes. This pattern matters more than any single headline. Researchers supply creativity and context. Machines handle scale.

Pattern recognition stands out as one clear strength. AI spots repeated sequences that human eyes overlook after hours of staring at tablets. It predicts missing characters in damaged texts with surprising accuracy. Cross-lingual transfer offers another tool. Train a model on a known language. Feed it data from a related but undeciphered script. Patterns sometimes transfer. MIT researchers demonstrated the approach years ago on Ugaritic, a Semitic language from the late Bronze Age. The system translated the script once the family connection was established. Success hinged on that prior knowledge.

But limits appear quickly. Statistical models excel at predicting what signs follow others. They cannot assign real-world meaning without external validation. Linear A’s entire surviving body of text totals roughly 7,500 characters. That amount fits on one large screen. With so little data almost any hypothesis can cherry-pick supporting examples. Verification becomes tricky. No native speakers exist to confirm translations. Expert consensus takes decades to build. Short of new archaeological finds, claims rest on rigorous peer review rather than raw computational confidence.

Adkins stressed this distinction in her reporting. “It’s worth being precise about what AI did and didn’t do here. It didn’t have the idea. The engineer did.” The same caution applies across similar efforts. Ars Technica republished her analysis on July 29, 2026, reaching a wider technical audience. The piece underscores that AI functions best as an accelerant. It compresses years of cross-referencing into hours. It opens these puzzles to more independent researchers outside traditional institutions. Yet it does not eliminate the need for comparative anchors or human judgment.

Recent coverage echoes the same themes. On July 28, Down To Earth highlighted how AI spots patterns and tests theories but still requires bilingual texts or known relatives. Experts quoted in the story described the technology as a powerful research assistant while warning against overhyping isolated results. Similar discussions spread rapidly on X, with classicists and linguists sharing the Conversation article and debating the June Linear A claim.

Other applications show broader potential. Historians have deployed machine learning to restore missing verses in the Epic of Gilgamesh. The same techniques helped read carbonized scrolls from Herculaneum and fill gaps in 2,000-year-old Greek inscriptions. In each case the systems worked with partial anchors or related languages. Pure isolates remain far harder. Etruscan, for instance, has yielded some vocabulary from funerary texts but resists deeper structural analysis. Its speakers left no direct descendants whose modern tongues could provide clues.

The Minoan civilization that produced Linear A fascinates historians for other reasons. Monumental palaces. Sophisticated frescoes. Complex trade networks. Understanding their records could illuminate daily administration, religious practices, and economic life. Yet the script’s isolation has kept those details locked away. Some scholars once linked it to Greek or other Aegean languages. Most now classify it as a language isolate. That classification makes computational approaches both tempting and treacherous.

So where does this leave the field? AI will not replace linguists or archaeologists. It amplifies their strengths. A researcher with a plausible hunch can now explore its consequences across an entire corpus before investing months in manual checks. Models can generate multiple competing interpretations for human experts to evaluate. The bottleneck shifts from raw computation to data quality and scholarly validation.

But. New discoveries could change everything. A single bilingual inscription found at an excavation site might supply the missing anchor. Until then claims will face intense scrutiny. The June 2026 Linear A proposal illustrates both sides. The method was systematic. The results looked promising on paper. Independent verification will decide its fate. That process itself benefits from AI tools that let reviewers test alternatives quickly.

Funding patterns may shift as well. Universities and granting agencies increasingly support projects that combine traditional philology with machine learning expertise. Interdisciplinary teams become the norm. A computational linguist and a specialist in Aegean scripts can achieve more together than either could alone. This collaboration model has already produced gains in related areas such as restoring fragmented cuneiform tablets.

Still, hype requires restraint. Headlines sometimes blur the line between “AI detected a statistical pattern” and “AI read the language.” Those are not the same. One is a starting point. The other is the distant goal. Adkins captured the nuance perfectly. AI serves as a very fast assistant to a very old, very human puzzle. Its value lies in speed and scale. The insight and judgment remain ours.

Expect more experiments in coming months. Improved models trained on larger datasets of known ancient languages may uncover subtle connections previously missed. Yet the fundamental requirements stay constant. An anchor. Human oversight. Rigorous testing against all available evidence. Linear A and Etruscan have waited this long. They can withstand a few more rounds of careful, AI-assisted scrutiny.

Researchers like Adkins continue to map the boundary between what machines do well and where human expertise proves irreplaceable. Their work suggests a future in which AI handles the tedious heavy lifting. Scholars focus on creative leaps and contextual understanding. That partnership could finally crack scripts that have defied generations. Or it could simply illuminate why some codes remain unbroken. Either outcome advances knowledge. And that, after all, is the point.



from WebProNews https://ift.tt/QmxD9Bd