<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-AU"
                       href="https://www.techradar.com/au/feeds/tag/pro"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from TechRadar AU in Pro ]]></title>
                <link>https://www.techradar.com/au/pro</link>
        <description><![CDATA[ All the latest pro content from the TechRadar  AU team ]]></description>
                                    <lastBuildDate>Thu, 24 Sep 2026 11:00:38 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Banks are adding AI to a model that AI makes obsolete ]]></title>
                                                                                                <dc:content><![CDATA[ <p>For decades, banking technology has been built around a simple sequence: a person makes a <a href="https://www.techradar.com/best/best-personal-finance-software">financial</a> decision and the bank’s technology processes it. A <a href="https://www.techradar.com/best/best-customer-feedback-tools?gad=1">customer</a> decides to open an account, move money into savings or apply for a loan, and the bank’s systems execute that instruction.</p><p>Artificial intelligence can potentially reverse that sequence. Instead of waiting for a human to specify an action, AI can interpret the person’s goals, understand the financial context around that goal, and determine what happens next. It could recognize that a customer is likely to face a cash shortfall, identify the available ways to address it, and potentially execute the appropriate action. </p><p>McKinsey estimates that generative AI could create $200 billion to $340 billion in annual value for the banking industry. Yet much of the industry is adding AI to systems designed for the old model, not rebuilding the model around AI.</p><p>The problem is that AI inherits the same product silos and process boundaries. Banks gain another layer of technology, but not the cross-system decision-making needed to realize AI’s full potential.</p><h2 id="the-first-wave-is-still-about-better-processes">The first wave is still about better processes</h2><p>The most visible applications of AI in banking are often the easiest ones to deploy. Banks are using <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> to improve customer service, automate fraud detection, personalize recommendations, summarize <a href="https://www.techradar.com/best/best-cloud-document-storage">documents</a> and accelerate credit decisions. Lloyds Banking Group, for example, says more than 50 AI use cases were rolled out across the group in 2025, generating around £50 million in value, with more than £100 million in additional value expected in 2026.</p><p>McKinsey has made a similar observation based on the industry's experience with generative AI. Simply adding AI on top of existing processes will not produce transformational change and can instead create another layer of technical debt.</p><p>The difference between an AI-native architecture and a chatbot attached to an existing system can be tested with three questions. </p><ul><li>Is the AI following a fixed sequence of instructions, or can it choose and coordinate actions within a defined system of guardrails, trusted <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> sources and approved tools?</li><li>Is the process designed for the agent to act, with human review and every decision recorded for analysis?</li><li>And are permissions, monitoring and regulatory controls built into the workflow, particularly for critical functions such as compliance and fraud prevention?</li></ul><p>If the answer is no, the company has added an AI interface without redesigning the underlying process.</p><h2 id="from-products-to-outcomes">From products to outcomes</h2><p>The more significant transformation begins when the bank starts with the customer’s objective, not with the banking product.</p><p>Consider a customer who wants to maintain a certain level of liquidity while earning as much as possible on excess cash. An intelligent banking system could continuously monitor their balance, upcoming payments, income, available credit and other relevant information, then determine whether money should remain liquid, be invested elsewhere or be used to reduce borrowing.</p><p>While the system can continue making decisions as the customer’s circumstances change, that does not require customers to surrender control immediately. Adoption can begin with low-risk actions, such as moving excess cash into savings or setting aside VAT for future tax payments, before expanding into more consequential decisions.</p><p>This is already beginning to appear in financial institutions, although mostly in bounded applications. Deutsche Bank, for example, has deployed an agentic AI system for third-party risk management in which several AI agents retrieve relevant controls, analyze supporting documentation, and propose assessment outcomes. Human assessors remain responsible for reviewing or overriding those recommendations.</p><p>Like a new <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employee</a>, an AI agent should receive defined permissions. Transparent activity logs, alerts, approval thresholds and the ability to override decisions would make that principle visible in the product and enforceable by regulators.</p><h2 id="the-bank-becomes-a-continuous-decision-system">The bank becomes a continuous decision system</h2><p>Under this premise, the bank becomes an intelligent execution layer that continuously manages financial activity to accomplish a defined objective.</p><p>This shifting structure is also visible outside traditional banking. Visa and Mastercard are both building <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> for AI-initiated payments, allowing agents to act on behalf of consumers and businesses. Visa Intelligent Commerce is designed to let AI agents find and purchase products on a user’s behalf, with tokenized credentials, authentication and spending controls built into the payment flow.</p><p>As agents move from recommending actions to executing them, banks will need to ensure transactions remain within the customer’s intent and risk tolerance. The institution remains responsible for keeping the agent within those limits.</p><h2 id="the-architecture-has-to-change-with-the-ai">The architecture has to change with the AI</h2><p>Deloitte found that integration with existing systems and tools is the top modernization challenge for 77 percent of banking executives deploying AI, ahead of security, compliance and cloud interoperability concerns.</p><p>Traditional banking systems separate payments, lending, accounts and compliance across different applications. AI agents need to work across those boundaries, combining data and actions from several systems to make a single decision.</p><p>Banks therefore need an orchestration layer that allows AI to access those systems without requiring another custom integration for every use case. The core platforms can remain systems of record, while more of the decision-making happens above them.</p><p>This gives AI-forward fintechs such as Revolut or Ramp, as well as new entrants designing their infrastructure from scratch, an advantage over institutions that must retrofit deeply embedded systems. If regulation remains broadly unchanged, the first major financial institution built around continuous decision-making could emerge within five years.</p><p>It may not be a bank in the strict regulatory sense, but it could perform an increasing share of a bank’s functions, allowing customers to manage their finances.</p><p>To thrive, I believe banks need to become institutions organized to make continuous decisions for the customer’s benefit, not simply to follow instructions. And when it comes to AI, they must stop treating it as a fancy tool to add and start treating it as something to build around.</p><p><em></em><a href="https://www.techradar.com/best/best-bi-tools"><em>We've featured the best business intelligence platform.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/banks-are-adding-ai-to-a-model-that-ai-makes-obsolete</link>
                                                                            <description>
                            <![CDATA[ Banks are adding AI to old systems and limiting what it can actually do. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4mhJX7tm4UYr2Ege5MUfVL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qP76MS2BAb7kSuWrvJXXYL-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Sep 2026 11:00:38 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dmitry Volkov ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qP76MS2BAb7kSuWrvJXXYL-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands typing on a tablet with AI superimposed in text in front]]></media:description>                                                            <media:text><![CDATA[Hands typing on a tablet with AI superimposed in text in front]]></media:text>
                                <media:title type="plain"><![CDATA[Hands typing on a tablet with AI superimposed in text in front]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qP76MS2BAb7kSuWrvJXXYL-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For decades, banking technology has been built around a simple sequence: a person makes a <a href="https://www.techradar.com/best/best-personal-finance-software">financial</a> decision and the bank’s technology processes it. A <a href="https://www.techradar.com/best/best-customer-feedback-tools?gad=1">customer</a> decides to open an account, move money into savings or apply for a loan, and the bank’s systems execute that instruction.</p><p>Artificial intelligence can potentially reverse that sequence. Instead of waiting for a human to specify an action, AI can interpret the person’s goals, understand the financial context around that goal, and determine what happens next. It could recognize that a customer is likely to face a cash shortfall, identify the available ways to address it, and potentially execute the appropriate action. </p><p>McKinsey estimates that generative AI could create $200 billion to $340 billion in annual value for the banking industry. Yet much of the industry is adding AI to systems designed for the old model, not rebuilding the model around AI.</p><p>The problem is that AI inherits the same product silos and process boundaries. Banks gain another layer of technology, but not the cross-system decision-making needed to realize AI’s full potential.</p><h2 id="the-first-wave-is-still-about-better-processes">The first wave is still about better processes</h2><p>The most visible applications of AI in banking are often the easiest ones to deploy. Banks are using <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> to improve customer service, automate fraud detection, personalize recommendations, summarize <a href="https://www.techradar.com/best/best-cloud-document-storage">documents</a> and accelerate credit decisions. Lloyds Banking Group, for example, says more than 50 AI use cases were rolled out across the group in 2025, generating around £50 million in value, with more than £100 million in additional value expected in 2026.</p><p>McKinsey has made a similar observation based on the industry's experience with generative AI. Simply adding AI on top of existing processes will not produce transformational change and can instead create another layer of technical debt.</p><p>The difference between an AI-native architecture and a chatbot attached to an existing system can be tested with three questions. </p><ul><li>Is the AI following a fixed sequence of instructions, or can it choose and coordinate actions within a defined system of guardrails, trusted <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> sources and approved tools?</li><li>Is the process designed for the agent to act, with human review and every decision recorded for analysis?</li><li>And are permissions, monitoring and regulatory controls built into the workflow, particularly for critical functions such as compliance and fraud prevention?</li></ul><p>If the answer is no, the company has added an AI interface without redesigning the underlying process.</p><h2 id="from-products-to-outcomes">From products to outcomes</h2><p>The more significant transformation begins when the bank starts with the customer’s objective, not with the banking product.</p><p>Consider a customer who wants to maintain a certain level of liquidity while earning as much as possible on excess cash. An intelligent banking system could continuously monitor their balance, upcoming payments, income, available credit and other relevant information, then determine whether money should remain liquid, be invested elsewhere or be used to reduce borrowing.</p><p>While the system can continue making decisions as the customer’s circumstances change, that does not require customers to surrender control immediately. Adoption can begin with low-risk actions, such as moving excess cash into savings or setting aside VAT for future tax payments, before expanding into more consequential decisions.</p><p>This is already beginning to appear in financial institutions, although mostly in bounded applications. Deutsche Bank, for example, has deployed an agentic AI system for third-party risk management in which several AI agents retrieve relevant controls, analyze supporting documentation, and propose assessment outcomes. Human assessors remain responsible for reviewing or overriding those recommendations.</p><p>Like a new <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employee</a>, an AI agent should receive defined permissions. Transparent activity logs, alerts, approval thresholds and the ability to override decisions would make that principle visible in the product and enforceable by regulators.</p><h2 id="the-bank-becomes-a-continuous-decision-system">The bank becomes a continuous decision system</h2><p>Under this premise, the bank becomes an intelligent execution layer that continuously manages financial activity to accomplish a defined objective.</p><p>This shifting structure is also visible outside traditional banking. Visa and Mastercard are both building <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> for AI-initiated payments, allowing agents to act on behalf of consumers and businesses. Visa Intelligent Commerce is designed to let AI agents find and purchase products on a user’s behalf, with tokenized credentials, authentication and spending controls built into the payment flow.</p><p>As agents move from recommending actions to executing them, banks will need to ensure transactions remain within the customer’s intent and risk tolerance. The institution remains responsible for keeping the agent within those limits.</p><h2 id="the-architecture-has-to-change-with-the-ai">The architecture has to change with the AI</h2><p>Deloitte found that integration with existing systems and tools is the top modernization challenge for 77 percent of banking executives deploying AI, ahead of security, compliance and cloud interoperability concerns.</p><p>Traditional banking systems separate payments, lending, accounts and compliance across different applications. AI agents need to work across those boundaries, combining data and actions from several systems to make a single decision.</p><p>Banks therefore need an orchestration layer that allows AI to access those systems without requiring another custom integration for every use case. The core platforms can remain systems of record, while more of the decision-making happens above them.</p><p>This gives AI-forward fintechs such as Revolut or Ramp, as well as new entrants designing their infrastructure from scratch, an advantage over institutions that must retrofit deeply embedded systems. If regulation remains broadly unchanged, the first major financial institution built around continuous decision-making could emerge within five years.</p><p>It may not be a bank in the strict regulatory sense, but it could perform an increasing share of a bank’s functions, allowing customers to manage their finances.</p><p>To thrive, I believe banks need to become institutions organized to make continuous decisions for the customer’s benefit, not simply to follow instructions. And when it comes to AI, they must stop treating it as a fancy tool to add and start treating it as something to build around.</p><p><em></em><a href="https://www.techradar.com/best/best-bi-tools"><em>We've featured the best business intelligence platform.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The fastest way to destroy trust in AI is to give it the wrong job ]]></title>
                                                                                                <dc:content><![CDATA[ <p>You will almost certainly have heard many business and technology leaders extolling the virtue of AI. They will enthusiastically tell you that the technology will have a transformative impact on businesses across the globe.</p><p>I think they are right. However, with two important caveats: AI must be given the right jobs, and the people using it must trust what it does.</p><p>Too often, AI is deployed across a business without much thought, as overconfident bosses assign agents tasks it isn't designed for. The problem this creates is that many employees using <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> every day are not yet prepared for their new role in managing these agents. Trust only comes from experience and that builds over time. </p><p>When an AI system provides you with results that make sense and actually helps with your work, people start to feel more confident in using it. But if it makes a mistake, that confidence can be lost in an instant. If things go wrong, <a href="https://www.techradar.com/best/websites-for-hiring-niche-employees">employees</a> start finding ways around AI or stop using it altogether, and when leaders ignore employee concerns about making AI work better, its benefits are undermined.</p><p>The best way to ensure that AI delivers the efficiencies it promises is to ensure that it is doing the right job, and this isn't as straightforward as it sounds.</p><h2 id="the-areas-where-ai-excels">The areas where AI excels</h2><p>AI works on probabilities, producing answers that are likely to be right. The key word here is ‘likely', which is why it occasionally hallucinates.</p><p>Being probabilistic makes AI very effective when dealing with unclear or complicated information. But it's not the best fit for tasks where a wrong answer could have serious consequences.</p><p>There are three core areas where AI really can make a difference. Firstly, when processing <a href="https://www.techradar.com/best/best-cloud-document-storage">documents</a>; secondly, decision support; and finally, personalization.</p><p>AI is especially effective at tasks involving many documents. It can extract, classify and summarize information that would normally take humans many hours to review. For example, an AI system could compare contracts against a standard set of clauses, or organize a large collection of <a href="https://www.techradar.com/best/best-customer-feedback-tools?gad=1">customer</a> emails by the issues they concern. This way, a person only has to look at the important findings instead of reviewing entire documents.</p><p>AI can also play a key role in supporting company executives to make decisions, as it's very good at taking lots of different pieces of information, finding patterns and delivering options as to what to do next.</p><p>It is, however, important to remember that AI is not always the right technology to make that decision. For example, imagine you're buying something and have to choose among many different suppliers.</p><p>AI can look at all the information, like how well they've done in the past, what they can deliver, how quickly it is likely to arrive and whether the supplier offers discounts for repeat purchases. It can even articulate why one option might be better than another. In most scenarios, though, it is the human who makes the final choice. </p><p>For some businesses, personalization is a promising tool, as AI can be used to make products more relevant to the individual using them. This is an area where working with probabilities can become a key driver for AI. The content only has to be good enough to make that connection so the recipient feels they are being addressed in a bespoke way. </p><h2 id="the-cost-of-assigning-ai-the-wrong-job">The cost of assigning AI the wrong job</h2><p>One of the key concerns companies should have about managing AI is that while AI-generated answers can sound assured, there is still a possibility that the technology has got something wrong. If that answer is allowed to trigger action without validation, a small error can travel rapidly through a workflow.</p><p>Think about what happens when someone makes a small mistake with a rule or detail in a contract. By the time someone catches the error, it may have already been added to records, sent to people outside the company, or even used to create new <a href="https://www.techradar.com/best/best-small-business-software">software</a>.   </p><p>To remind myself of AI’s limitations, I find it useful to think of the technology as the equivalent of a super-intelligent, hard-working intern. Interns need guidance and oversight, which should be provided by experienced, knowledgeable colleagues. Crucially, their access to sensitive information needs to be limited and granted only as they demonstrate they can make sound decisions. </p><p>AI needs to be managed in the same way. It should only be given greater levels of control when it has proved itself, and then its work must still be monitored by humans.  </p><p>A good example of the importance of managing AI is its role in software development. AI can deliver a lot of code quickly, but its fast pace means the quality isn't always the same as that of human developers.</p><p>In fact, managing large amounts of AI-generated code can be a real headache for IT professionals. For example, surging token consumption and a shift to consumption-based pricing is ballooning AI <a href="https://www.techradar.com/pro/best-vibe-coding-tools">coding</a> costs, forcing developers to be selective on when and where they apply AI models, as reported by Gartner.</p><h2 id="let-ai-help-design-the-model-not-control-the-machinery">Let AI help design the model, not control the machinery</h2><p>The most important design decision is where AI is allowed to reason. The riskiest place is deep in the implementation layer, where a small mistake can cause big problems that are hard to fix.</p><p>I believe a sound approach is to use AI to work with <a href="https://www.techradar.com/best/best-business-cloud-storage-service">business</a> ideas and rules. This way, it's easier for people to check and understand what the AI is suggesting.</p><p>Domain-specific languages and other abstractions used in model-driven development can provide that separation. AI helps create or refine a high-level application model, while a developer then validates the model before a deterministic platform transforms it into executable software.</p><p>AI can suggest how something should be done, but it doesn't have to be responsible for executing every step.</p><p>Abstraction helps developers, and in agent-driven systems it becomes a control tool. It simplifies complex systems and prevents small errors from becoming big problems, making AI output easier to test and fix.</p><h2 id="human-expertise-is-becoming-more-valuable-not-less">Human expertise is becoming more valuable, not less</h2><p>As AI becomes more prevalent, developers' roles will evolve. They will still write code, but a larger part of their role will be overseeing systems, checking outputs and catching mistakes, a change that brings with it the opportunity to learn new skills.  </p><p>Developers will increasingly work at the level of systems and architecture, understanding the business rationale, recognizing patterns and judging whether AI-generated code fits the wider application and holds together.</p><p>One company that has innovated in this area and is already reaping the rewards for their experience is Ford. They recently hired 350 experienced engineers to help train younger colleagues and improve their AI and <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> tools. </p><p>The shift was driven by the fact that the AI tools weren't producing the results they wanted without the expertise brought by seasoned professionals. Now, these experienced engineers act as internal auditors, reviewing designs and finding potential problems before they become major issues on the factory floor.</p><p>When you combine AI's ability to recognize patterns and process information with human knowledge and experience, it becomes a much more powerful tool. This combination is what makes it truly effective, not just relying on one or the other.</p><h2 id="building-trust">Building trust</h2><p>Enterprises should also resist the pressure to deploy agents everywhere simply because competitors appear to be doing so. When it comes to using AI, leaders need to think carefully about each situation.</p><p>They should ask themselves three important questions. First, are they asking AI to only suggest what to do or to actually do it? Next, can someone check and fix what the AI says before an error spreads? Finally, what would happen if the system is certain about something but is actually wrong?</p><p>The answers play a big role in deciding how much freedom to give the technology. For example, a tool that summarizes documents might only need a quick check, but a system that suggests business decisions needs someone's logged approval.</p><p>When companies start using AI for specific, practical tasks, it shows employees that it can really make a difference in their work. This approach gives the company a chance to get its <a href="https://www.techradar.com/best/best-data-migration-tools">data</a>, rules and processes in order. If people can see that the system is working well, and they understand what it can and can't do, they start to trust it more. Over time, this trust grows.</p><p>The key is to create a work setup where humans and machines do what they're good at. AI is great at processing large volumes of information and surfacing patterns. People are good at understanding the bigger picture, pointing out mistakes, and taking responsibility for their actions.</p><p>The wrong job to give to AI is any task where a mistake carries real consequences, no one checks the work before it causes harm, or the system sounds certain while being wrong. Companies that respect this division will build the confidence to give agentic AI greater autonomy over time. Those who ignore it may discover that a single poorly chosen task can undermine their entire AI strategy.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-website-builder"><em>We've featured the best AI website builder.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/the-fastest-way-to-destroy-trust-in-ai-is-to-give-it-the-wrong-job</link>
                                                                            <description>
                            <![CDATA[ AI must be given the right jobs so people using it trust what it does ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">enogtXCLUVG4EfYntBQfbW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Sep 2026 10:27:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Luis Blando ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>You will almost certainly have heard many business and technology leaders extolling the virtue of AI. They will enthusiastically tell you that the technology will have a transformative impact on businesses across the globe.</p><p>I think they are right. However, with two important caveats: AI must be given the right jobs, and the people using it must trust what it does.</p><p>Too often, AI is deployed across a business without much thought, as overconfident bosses assign agents tasks it isn't designed for. The problem this creates is that many employees using <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> every day are not yet prepared for their new role in managing these agents. Trust only comes from experience and that builds over time. </p><p>When an AI system provides you with results that make sense and actually helps with your work, people start to feel more confident in using it. But if it makes a mistake, that confidence can be lost in an instant. If things go wrong, <a href="https://www.techradar.com/best/websites-for-hiring-niche-employees">employees</a> start finding ways around AI or stop using it altogether, and when leaders ignore employee concerns about making AI work better, its benefits are undermined.</p><p>The best way to ensure that AI delivers the efficiencies it promises is to ensure that it is doing the right job, and this isn't as straightforward as it sounds.</p><h2 id="the-areas-where-ai-excels">The areas where AI excels</h2><p>AI works on probabilities, producing answers that are likely to be right. The key word here is ‘likely', which is why it occasionally hallucinates.</p><p>Being probabilistic makes AI very effective when dealing with unclear or complicated information. But it's not the best fit for tasks where a wrong answer could have serious consequences.</p><p>There are three core areas where AI really can make a difference. Firstly, when processing <a href="https://www.techradar.com/best/best-cloud-document-storage">documents</a>; secondly, decision support; and finally, personalization.</p><p>AI is especially effective at tasks involving many documents. It can extract, classify and summarize information that would normally take humans many hours to review. For example, an AI system could compare contracts against a standard set of clauses, or organize a large collection of <a href="https://www.techradar.com/best/best-customer-feedback-tools?gad=1">customer</a> emails by the issues they concern. This way, a person only has to look at the important findings instead of reviewing entire documents.</p><p>AI can also play a key role in supporting company executives to make decisions, as it's very good at taking lots of different pieces of information, finding patterns and delivering options as to what to do next.</p><p>It is, however, important to remember that AI is not always the right technology to make that decision. For example, imagine you're buying something and have to choose among many different suppliers.</p><p>AI can look at all the information, like how well they've done in the past, what they can deliver, how quickly it is likely to arrive and whether the supplier offers discounts for repeat purchases. It can even articulate why one option might be better than another. In most scenarios, though, it is the human who makes the final choice. </p><p>For some businesses, personalization is a promising tool, as AI can be used to make products more relevant to the individual using them. This is an area where working with probabilities can become a key driver for AI. The content only has to be good enough to make that connection so the recipient feels they are being addressed in a bespoke way. </p><h2 id="the-cost-of-assigning-ai-the-wrong-job">The cost of assigning AI the wrong job</h2><p>One of the key concerns companies should have about managing AI is that while AI-generated answers can sound assured, there is still a possibility that the technology has got something wrong. If that answer is allowed to trigger action without validation, a small error can travel rapidly through a workflow.</p><p>Think about what happens when someone makes a small mistake with a rule or detail in a contract. By the time someone catches the error, it may have already been added to records, sent to people outside the company, or even used to create new <a href="https://www.techradar.com/best/best-small-business-software">software</a>.   </p><p>To remind myself of AI’s limitations, I find it useful to think of the technology as the equivalent of a super-intelligent, hard-working intern. Interns need guidance and oversight, which should be provided by experienced, knowledgeable colleagues. Crucially, their access to sensitive information needs to be limited and granted only as they demonstrate they can make sound decisions. </p><p>AI needs to be managed in the same way. It should only be given greater levels of control when it has proved itself, and then its work must still be monitored by humans.  </p><p>A good example of the importance of managing AI is its role in software development. AI can deliver a lot of code quickly, but its fast pace means the quality isn't always the same as that of human developers.</p><p>In fact, managing large amounts of AI-generated code can be a real headache for IT professionals. For example, surging token consumption and a shift to consumption-based pricing is ballooning AI <a href="https://www.techradar.com/pro/best-vibe-coding-tools">coding</a> costs, forcing developers to be selective on when and where they apply AI models, as reported by Gartner.</p><h2 id="let-ai-help-design-the-model-not-control-the-machinery">Let AI help design the model, not control the machinery</h2><p>The most important design decision is where AI is allowed to reason. The riskiest place is deep in the implementation layer, where a small mistake can cause big problems that are hard to fix.</p><p>I believe a sound approach is to use AI to work with <a href="https://www.techradar.com/best/best-business-cloud-storage-service">business</a> ideas and rules. This way, it's easier for people to check and understand what the AI is suggesting.</p><p>Domain-specific languages and other abstractions used in model-driven development can provide that separation. AI helps create or refine a high-level application model, while a developer then validates the model before a deterministic platform transforms it into executable software.</p><p>AI can suggest how something should be done, but it doesn't have to be responsible for executing every step.</p><p>Abstraction helps developers, and in agent-driven systems it becomes a control tool. It simplifies complex systems and prevents small errors from becoming big problems, making AI output easier to test and fix.</p><h2 id="human-expertise-is-becoming-more-valuable-not-less">Human expertise is becoming more valuable, not less</h2><p>As AI becomes more prevalent, developers' roles will evolve. They will still write code, but a larger part of their role will be overseeing systems, checking outputs and catching mistakes, a change that brings with it the opportunity to learn new skills.  </p><p>Developers will increasingly work at the level of systems and architecture, understanding the business rationale, recognizing patterns and judging whether AI-generated code fits the wider application and holds together.</p><p>One company that has innovated in this area and is already reaping the rewards for their experience is Ford. They recently hired 350 experienced engineers to help train younger colleagues and improve their AI and <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> tools. </p><p>The shift was driven by the fact that the AI tools weren't producing the results they wanted without the expertise brought by seasoned professionals. Now, these experienced engineers act as internal auditors, reviewing designs and finding potential problems before they become major issues on the factory floor.</p><p>When you combine AI's ability to recognize patterns and process information with human knowledge and experience, it becomes a much more powerful tool. This combination is what makes it truly effective, not just relying on one or the other.</p><h2 id="building-trust">Building trust</h2><p>Enterprises should also resist the pressure to deploy agents everywhere simply because competitors appear to be doing so. When it comes to using AI, leaders need to think carefully about each situation.</p><p>They should ask themselves three important questions. First, are they asking AI to only suggest what to do or to actually do it? Next, can someone check and fix what the AI says before an error spreads? Finally, what would happen if the system is certain about something but is actually wrong?</p><p>The answers play a big role in deciding how much freedom to give the technology. For example, a tool that summarizes documents might only need a quick check, but a system that suggests business decisions needs someone's logged approval.</p><p>When companies start using AI for specific, practical tasks, it shows employees that it can really make a difference in their work. This approach gives the company a chance to get its <a href="https://www.techradar.com/best/best-data-migration-tools">data</a>, rules and processes in order. If people can see that the system is working well, and they understand what it can and can't do, they start to trust it more. Over time, this trust grows.</p><p>The key is to create a work setup where humans and machines do what they're good at. AI is great at processing large volumes of information and surfacing patterns. People are good at understanding the bigger picture, pointing out mistakes, and taking responsibility for their actions.</p><p>The wrong job to give to AI is any task where a mistake carries real consequences, no one checks the work before it causes harm, or the system sounds certain while being wrong. Companies that respect this division will build the confidence to give agentic AI greater autonomy over time. Those who ignore it may discover that a single poorly chosen task can undermine their entire AI strategy.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-website-builder"><em>We've featured the best AI website builder.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'This situation is obviously unacceptable': OpenAI agent allegedly hacks Australian government healthcare website ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OpenAI agent breached Australia’s Medicare portal on June 18, 2026, accessing internal files</strong></li><li><strong>Government says no personal medical data was taken, but three other agencies may be affected</strong></li><li><strong>PM Albanese slammed OpenAI’s 84‑day delay in disclosure, calling the notification “unacceptable” and warning of legal consequences</strong></li></ul><p>An OpenAI agent has allegedly broken into a website of the Australian government, which has slammed the “unacceptable” attack, promising an in-depth investigation, and threatening “legal consequences”.</p><p>Australian Prime Minister Anthony Albanese revealed how in June 2026, OpenAI’s research team tasked the agent with researching public medicine spending, as part of an internal capability evaluation - but as the agent got to work, it was initially denied access to some of the information it requested.</p><p>However, instead of stopping, or trying to find a different lawful way of obtaining this data, it circumvented those restrictions and landed inside the infrastructure behind Services Australia’s public-facing Medicare Statistics Reporting Service portal.</p><h2 id="ai-agent-did-what">AI agent did what?</h2><p>The public details are still quite limited, and we don’t know the technicalities of what the AI actually did. </p><p>The acting prime minister, Richard Marles, told the media during a recent press conference that the AI “scaled the fence”, despite the portal having security measures in place. </p><p>The bot apparently accessed internal infrastructure and wrote files to an internal server but exactly what it wrote, how it obtained the access, and precisely which technical mechanism it used, is still not public knowledge.</p><p>Once inside, it accessed both public and non-public files, but individual medical data was not accessed and the system itself was not compromised, the Australian government said. </p><p>There is also the possibility that three other government systems were affected - the Australian Institute of Health and Welfare and two state-based agencies - the New South Wales Bureau of Crime Statistics and Research and the Victorian Department of Health. However, this has not been confirmed yet.</p><p>"No personal information is believed to have been accessed at this stage, but investigations are ongoing," Albanese said. "Nonetheless this situation is obviously unacceptable."</p><h2 id="openai-39-s-sluggish-escalation">OpenAI's sluggish escalation</h2><p>Albanese was particularly unsatisfied with how OpenAI handled the situation. The breach happened on June 18, but it took the company 84 days to notify the Australian government of the incident. And when it did - it did so in a manner better suited for an amateurish start-up rather than one of the most important organizations on the planet right now.</p><p>OpenAI was apparently evaluating its models, and investigating “misaligned model activity” when, on August 11, it discovered the breach in Australia. It seems the <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agent</a> simply did not take “no” for an answer. The company then notified Services Australia on September 10 - almost three months after the incident. To make matters worse, the company reached out via publicdisclosures@servicesaustralia.gov.au, inbox researchers usually use to report potential vulnerabilities, instead of trying to escalate the incident higher.  </p><p>Services Australia reviewed the information and notified the Australian Signals Directorate on September 15.</p><p>When the news reached prime minister Anthony Albanese, he spoke to OpenAI CEO, Sam Altman, and expressed the country’s “extreme concern” about this incident, as well as his “disappointment that it took the company way too long to inform the government what had occurred.” He also pointed out the way OpenAI reached out: “The notification was an email sent just to the public mailbox.” Albanese described the “nature of the notification” as “unacceptable.”</p><p>The Australian government is now looking into the matter to see if any laws were broken and what legal consequences, if any, could follow.</p><p>"And obviously we will investigate all of that. What the consequences are, if there has been a breach of the law, but also part of the task force is to assess whether or not the legal regime we have in place is fit–for–purpose in a world where we have an emerging AI capability,” Marles said. </p><p><em>Via </em><a href="https://www.bbc.com/news/articles/c6vgy0333dppo" target="_blank"><em>BBC</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-situation-is-obviously-unacceptable-openai-agent-allegedly-hacks-australian-government-healthcare-website</link>
                                                                            <description>
                            <![CDATA[ Australian government calls OpenAI behavior "unacceptable" as it investigates the incident further. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sn3MBaUJAQKEmMaiLafiBc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6X3ZZcXUrcxus6MyJ3GM7M-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Sep 2026 10:13:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6X3ZZcXUrcxus6MyJ3GM7M-1920-80.jpg">
                                                            <media:credit><![CDATA[OpenAI]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI logo]]></media:description>                                                            <media:text><![CDATA[OpenAI logo]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6X3ZZcXUrcxus6MyJ3GM7M-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI agent breached Australia’s Medicare portal on June 18, 2026, accessing internal files</strong></li><li><strong>Government says no personal medical data was taken, but three other agencies may be affected</strong></li><li><strong>PM Albanese slammed OpenAI’s 84‑day delay in disclosure, calling the notification “unacceptable” and warning of legal consequences</strong></li></ul><p>An OpenAI agent has allegedly broken into a website of the Australian government, which has slammed the “unacceptable” attack, promising an in-depth investigation, and threatening “legal consequences”.</p><p>Australian Prime Minister Anthony Albanese revealed how in June 2026, OpenAI’s research team tasked the agent with researching public medicine spending, as part of an internal capability evaluation - but as the agent got to work, it was initially denied access to some of the information it requested.</p><p>However, instead of stopping, or trying to find a different lawful way of obtaining this data, it circumvented those restrictions and landed inside the infrastructure behind Services Australia’s public-facing Medicare Statistics Reporting Service portal.</p><h2 id="ai-agent-did-what">AI agent did what?</h2><p>The public details are still quite limited, and we don’t know the technicalities of what the AI actually did. </p><p>The acting prime minister, Richard Marles, told the media during a recent press conference that the AI “scaled the fence”, despite the portal having security measures in place. </p><p>The bot apparently accessed internal infrastructure and wrote files to an internal server but exactly what it wrote, how it obtained the access, and precisely which technical mechanism it used, is still not public knowledge.</p><p>Once inside, it accessed both public and non-public files, but individual medical data was not accessed and the system itself was not compromised, the Australian government said. </p><p>There is also the possibility that three other government systems were affected - the Australian Institute of Health and Welfare and two state-based agencies - the New South Wales Bureau of Crime Statistics and Research and the Victorian Department of Health. However, this has not been confirmed yet.</p><p>"No personal information is believed to have been accessed at this stage, but investigations are ongoing," Albanese said. "Nonetheless this situation is obviously unacceptable."</p><h2 id="openai-39-s-sluggish-escalation">OpenAI's sluggish escalation</h2><p>Albanese was particularly unsatisfied with how OpenAI handled the situation. The breach happened on June 18, but it took the company 84 days to notify the Australian government of the incident. And when it did - it did so in a manner better suited for an amateurish start-up rather than one of the most important organizations on the planet right now.</p><p>OpenAI was apparently evaluating its models, and investigating “misaligned model activity” when, on August 11, it discovered the breach in Australia. It seems the <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agent</a> simply did not take “no” for an answer. The company then notified Services Australia on September 10 - almost three months after the incident. To make matters worse, the company reached out via publicdisclosures@servicesaustralia.gov.au, inbox researchers usually use to report potential vulnerabilities, instead of trying to escalate the incident higher.  </p><p>Services Australia reviewed the information and notified the Australian Signals Directorate on September 15.</p><p>When the news reached prime minister Anthony Albanese, he spoke to OpenAI CEO, Sam Altman, and expressed the country’s “extreme concern” about this incident, as well as his “disappointment that it took the company way too long to inform the government what had occurred.” He also pointed out the way OpenAI reached out: “The notification was an email sent just to the public mailbox.” Albanese described the “nature of the notification” as “unacceptable.”</p><p>The Australian government is now looking into the matter to see if any laws were broken and what legal consequences, if any, could follow.</p><p>"And obviously we will investigate all of that. What the consequences are, if there has been a breach of the law, but also part of the task force is to assess whether or not the legal regime we have in place is fit–for–purpose in a world where we have an emerging AI capability,” Marles said. </p><p><em>Via </em><a href="https://www.bbc.com/news/articles/c6vgy0333dppo" target="_blank"><em>BBC</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Governance gaps that can undermine your AI ROI ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Artificial intelligence has become a significant area of investment for UK businesses. More than £6 billion of new AI-related investment was announced during London Tech Week in June, while the UK remains home to the largest AI sector in Europe and the third largest globally.</p><p>From customer service and knowledge management to software development and internal operations, organizations are looking for places where <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> can improve <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a>, decision-making and business performance.</p><p>But as investment accelerates, another gap is becoming harder to ignore: organizations are often scaling AI faster than their ability to measure, govern and explain its value. That matters when CIOs and CFOs are increasingly being asked not simply whether AI is being adopted, but what the organization is getting in return.</p><p>As <a href="https://www.techradar.com/best/best-small-business-software">businesses</a> move from individual copilots towards agents embedded across workflows, the economics become more complicated. A user making a single prompt is relatively easy to understand. An agent may make multiple model calls, retrieve information, invoke tools and take actions to complete one task.</p><p>Depending on the platform and pricing model, that can introduce additional consumption, infrastructure and oversight costs. CIOs therefore need to understand not only where AI has been deployed, but what it is doing, what it costs and whether the outcome justifies that cost.</p><h2 id="the-not-so-hidden-cost-of-ai">The not-so-hidden cost of AI</h2><p>AI investment is increasingly being scrutinized in the same way as any other major technology investment. The difficulty is that measuring its return can be unusually complex.</p><p>Usage may be distributed across departments, <a href="https://www.techradar.com/phones/these-are-the-10-best-android-apps-of-the-year-according-to-google">applications</a>, models and workflows, while the benefits can range from time saved to improved quality, reduced risk or increased revenue. Without agreeing what success means first, organizations can end up measuring activity rather than value.</p><p>That becomes difficult when organizations expand AI without first defining where it sits in the workflow, who owns the outcome, what success looks like and how costs will be measured. Spending can become fragmented across licenses, models, infrastructure, platforms and consumption-based services, with no single view of whether those investments are delivering value.</p><p>The scale of the challenge is becoming visible. Research commissioned by Emergn estimates that large UK businesses lose £67 billion annually across transformation and AI initiatives that fail to deliver. Separately, a Censuswide survey of 500 senior UK decision-makers found that just 31% of businesses already using AI reported a positive return on their investment.</p><p>Governance is part of that measurement challenge. A 2026 ShareGate survey of 851 IT leaders across seven countries found that cost visibility was the most commonly cited barrier to measuring AI ROI, identified by 51% of respondents, followed closely by governance complexity at 47%. The challenge isn't simply knowing what AI costs. It's connecting that cost to the use case it supports, the information AI interacts with and the outcome it creates.</p><p>Much of the AI debate to date has focused on model selection, skills and productivity. But as adoption spreads, another gap is becoming visible: confidence in governance does not always match what happens in practice.</p><p>The same study found that 93% of IT leaders believed their Microsoft 365 governance was ready to support AI responsibly, yet 29% reported that AI tools had surfaced sensitive internal <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> that should not have been accessible. Another 8% weren't sure whether it had happened at all.</p><p>Those gaps carry costs as well as risk. Duplicated tools, additional validation, rework, security investigations and time spent establishing whether an output can be trusted all create a hidden tax on AI adoption. For CIOs trying to demonstrate value, reducing that friction starts with making AI usage more visible, accountable and measurable.</p><h2 id="how-organizations-can-regain-control">How organizations can regain control </h2><p>Good governance doesn’t begin and end at procurement. Knowing how many licenses have been purchased and where they have been assigned is useful, but regaining control requires a broader view: visibility into how AI is being used and what it costs, clear ownership of the outcomes, and a well-governed information environment for AI to work from.</p><p>Clear ownership matters just as much. As AI becomes embedded in business processes, responsibility can easily become fragmented across IT, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>, business teams and individual employees. That makes some basic questions surprisingly difficult to answer: Who owns the outcome? Who monitors the cost? Who decides whether a use case should scale, change or stop?</p><p>Cost governance is only part of the picture. Organizations also need to improve the information environment in which AI operates. That means reducing redundant and outdated content, managing access appropriately and helping employees and AI systems find authoritative sources.</p><p>Cleaner, better-governed information does not guarantee a correct AI response, but it can reduce ambiguity and make reliable grounding easier. That can mean less time spent searching, validating and reworking outputs. </p><p>Employees have a role here as well. Clearly distinguishing drafts from approved material, keeping trackers and priorities current, recording decisions and maintaining authoritative sources all make organizational context easier for people and AI to interpret. Where organizations use AI meeting assistants or similar tools to capture context, those tools should be subject to the same <a href="https://www.techradar.com/best/best-privacy-apps-for-android">privacy</a>, retention and access controls as the information they create.</p><p>The question for leaders, then, is no longer simply whether AI is worth the investment. It is whether they have enough visibility and control to understand where AI is creating value, where it is creating cost and what they should do differently as a result. AI investment is likely to continue, but under different expectations.</p><p>Deployment alone is not evidence of value, and governance is becoming more than a risk-management exercise; it is increasingly part of the business case. Leaders need to understand what AI costs, who is accountable for its outcomes, whether the information supporting it can be trusted and what measurable benefit it creates.</p><p>The organizations best positioned to scale will not necessarily be those deploying the most AI, but those that can explain what it is doing, understand what it costs and make informed decisions about where it belongs.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-chatbot-for-business"><em>We've featured the best AI chatbot for business.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/governance-gaps-that-can-undermine-your-ai-roi</link>
                                                                            <description>
                            <![CDATA[ UK firms are scaling AI investment faster than they can govern, measure, or explain its returns. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tn4KPstnFywk4VNiTayPE4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/h8ZQHernNUVpnGYX7QnxVM-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Sep 2026 09:57:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Richard Harbridge ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/h8ZQHernNUVpnGYX7QnxVM-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The letters AI in a box in the middle of a vast digital room divided by beams of line]]></media:description>                                                            <media:text><![CDATA[The letters AI in a box in the middle of a vast digital room divided by beams of line]]></media:text>
                                <media:title type="plain"><![CDATA[The letters AI in a box in the middle of a vast digital room divided by beams of line]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/h8ZQHernNUVpnGYX7QnxVM-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Artificial intelligence has become a significant area of investment for UK businesses. More than £6 billion of new AI-related investment was announced during London Tech Week in June, while the UK remains home to the largest AI sector in Europe and the third largest globally.</p><p>From customer service and knowledge management to software development and internal operations, organizations are looking for places where <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> can improve <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a>, decision-making and business performance.</p><p>But as investment accelerates, another gap is becoming harder to ignore: organizations are often scaling AI faster than their ability to measure, govern and explain its value. That matters when CIOs and CFOs are increasingly being asked not simply whether AI is being adopted, but what the organization is getting in return.</p><p>As <a href="https://www.techradar.com/best/best-small-business-software">businesses</a> move from individual copilots towards agents embedded across workflows, the economics become more complicated. A user making a single prompt is relatively easy to understand. An agent may make multiple model calls, retrieve information, invoke tools and take actions to complete one task.</p><p>Depending on the platform and pricing model, that can introduce additional consumption, infrastructure and oversight costs. CIOs therefore need to understand not only where AI has been deployed, but what it is doing, what it costs and whether the outcome justifies that cost.</p><h2 id="the-not-so-hidden-cost-of-ai">The not-so-hidden cost of AI</h2><p>AI investment is increasingly being scrutinized in the same way as any other major technology investment. The difficulty is that measuring its return can be unusually complex.</p><p>Usage may be distributed across departments, <a href="https://www.techradar.com/phones/these-are-the-10-best-android-apps-of-the-year-according-to-google">applications</a>, models and workflows, while the benefits can range from time saved to improved quality, reduced risk or increased revenue. Without agreeing what success means first, organizations can end up measuring activity rather than value.</p><p>That becomes difficult when organizations expand AI without first defining where it sits in the workflow, who owns the outcome, what success looks like and how costs will be measured. Spending can become fragmented across licenses, models, infrastructure, platforms and consumption-based services, with no single view of whether those investments are delivering value.</p><p>The scale of the challenge is becoming visible. Research commissioned by Emergn estimates that large UK businesses lose £67 billion annually across transformation and AI initiatives that fail to deliver. Separately, a Censuswide survey of 500 senior UK decision-makers found that just 31% of businesses already using AI reported a positive return on their investment.</p><p>Governance is part of that measurement challenge. A 2026 ShareGate survey of 851 IT leaders across seven countries found that cost visibility was the most commonly cited barrier to measuring AI ROI, identified by 51% of respondents, followed closely by governance complexity at 47%. The challenge isn't simply knowing what AI costs. It's connecting that cost to the use case it supports, the information AI interacts with and the outcome it creates.</p><p>Much of the AI debate to date has focused on model selection, skills and productivity. But as adoption spreads, another gap is becoming visible: confidence in governance does not always match what happens in practice.</p><p>The same study found that 93% of IT leaders believed their Microsoft 365 governance was ready to support AI responsibly, yet 29% reported that AI tools had surfaced sensitive internal <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> that should not have been accessible. Another 8% weren't sure whether it had happened at all.</p><p>Those gaps carry costs as well as risk. Duplicated tools, additional validation, rework, security investigations and time spent establishing whether an output can be trusted all create a hidden tax on AI adoption. For CIOs trying to demonstrate value, reducing that friction starts with making AI usage more visible, accountable and measurable.</p><h2 id="how-organizations-can-regain-control">How organizations can regain control </h2><p>Good governance doesn’t begin and end at procurement. Knowing how many licenses have been purchased and where they have been assigned is useful, but regaining control requires a broader view: visibility into how AI is being used and what it costs, clear ownership of the outcomes, and a well-governed information environment for AI to work from.</p><p>Clear ownership matters just as much. As AI becomes embedded in business processes, responsibility can easily become fragmented across IT, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>, business teams and individual employees. That makes some basic questions surprisingly difficult to answer: Who owns the outcome? Who monitors the cost? Who decides whether a use case should scale, change or stop?</p><p>Cost governance is only part of the picture. Organizations also need to improve the information environment in which AI operates. That means reducing redundant and outdated content, managing access appropriately and helping employees and AI systems find authoritative sources.</p><p>Cleaner, better-governed information does not guarantee a correct AI response, but it can reduce ambiguity and make reliable grounding easier. That can mean less time spent searching, validating and reworking outputs. </p><p>Employees have a role here as well. Clearly distinguishing drafts from approved material, keeping trackers and priorities current, recording decisions and maintaining authoritative sources all make organizational context easier for people and AI to interpret. Where organizations use AI meeting assistants or similar tools to capture context, those tools should be subject to the same <a href="https://www.techradar.com/best/best-privacy-apps-for-android">privacy</a>, retention and access controls as the information they create.</p><p>The question for leaders, then, is no longer simply whether AI is worth the investment. It is whether they have enough visibility and control to understand where AI is creating value, where it is creating cost and what they should do differently as a result. AI investment is likely to continue, but under different expectations.</p><p>Deployment alone is not evidence of value, and governance is becoming more than a risk-management exercise; it is increasingly part of the business case. Leaders need to understand what AI costs, who is accountable for its outcomes, whether the information supporting it can be trusted and what measurable benefit it creates.</p><p>The organizations best positioned to scale will not necessarily be those deploying the most AI, but those that can explain what it is doing, understand what it costs and make informed decisions about where it belongs.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-chatbot-for-business"><em>We've featured the best AI chatbot for business.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Enterprise AI has a memory problem, but businesses have the answer ]]></title>
                                                                                                <dc:content><![CDATA[ <p><a href="https://www.techradar.com/phones/best-ai-phone">Artificial intelligence</a> (AI) is like a genius with no memory of you. It has plenty of brain power, but unless context is handed to it directly, it knows nothing about your business, your <a href="https://www.techradar.com/best/the-best-customer-database-software-of-year">customers</a>, or the decisions that shaped how you operate today.</p><p>And solving that memory problem is quickly becoming a major barrier to enterprise AI deployment today.</p><p>Much of the current conversation about AI's limitations centers on the models themselves and their evolution toward bigger context windows, better reasoning, or longer memory. But that framing misses something important.</p><p>Enterprises don't need to wait for the next model breakthrough to solve this problem. They already have what they need sitting inside their own organizations: decades of content, decisions, and institutional context that most AI systems never see.</p><p>Every enterprise has a vast, largely untapped record of how it actually operates in the contracts negotiated, claims resolved, cases handled, decisions made and revisited. This is the accumulated context that makes an organization's judgment distinct from a general-purpose LLM. Yet in most companies, this information sits fragmented across systems, buried in unstructured formats, or locked away with no clear path for AI to reach it.</p><p>That is the gap that needs closing before AI <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> can scale responsibly. Not a smarter model, but a more complete memory built from an organization's own history rather than a general-purpose training set.</p><p>Think of this as "business memory": the nervous system connecting what a company already knows to what it wants AI to help it do next, carrying context to wherever a decision needs to be made.</p><h2 id="giving-ai-the-full-picture">Giving AI the full picture</h2><p>Business memory is best described as the accumulated knowledge of how an organization operates. It turns years of enterprise content, workflows and industry knowledge into information that AI can act on for true agentic automation at scale. The thinking behind this is simple.</p><p>By creating a context layer that governs what data the AI has access to, and ensuring it operates on relevant, authorized and current information, organizations will get those governed, trusted outputs they need to act with confidence.</p><p>An organization's memory is more than the information it retains. It also includes which version is authoritative, who may access it, where it came from and how long it remains valid. Carrying those signals into the context layer helps AI operate within the same rules as the business itself.</p><p>Better context alone does not ensure trustworthy outputs; provenance, evaluation, monitoring and human oversight also matter.</p><p>And although it accounts for an estimated 80% of enterprise content, based on various analyst reports, businesses use only about 10% of this incredibly valuable resource.</p><p>If organizations want to maximize the effectiveness of their AI models, the first thing they need to do is to start leveraging that valuable <a href="https://www.techradar.com/best/best-small-business-software">business</a> memory contained in their unstructured data. And that requires investing in your infrastructure to transform it into an AI-ready format.</p><p>In practice, start with a clearly defined use case and identify the authoritative content and data needed to support it. Preserve existing access controls, enrich the information with metadata and relationships, and test whether the AI's outputs are accurate, traceable, and useful before expanding automation. This creates a repeatable foundation that scales across the business without a wholesale replacement of existing systems.</p><h2 id="context-is-key">Context is key</h2><p>However, giving your AI access to the relevant <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> is not enough on its own. In fact, I’ve seen a lot of AI initiatives fail in the early stages because the business doesn’t appreciate just how complex a lot of this underlying data is.</p><p>As such, the content needs to be contextualized by an ‘ontology’, a formalized framework that defines all the different entities, terminology, relationships and rules that exist within your business. This enables your AI to understand not just what information exists across your systems, but how all of that information relates to your business or industry.</p><p>Put simply, ontologies are like maps: your AI may well get to your desired destination without one, but having it ensures you get there quicker and without potentially stumbling into any pitfalls along the way.</p><p>This is particularly important for regulated industries. In healthcare, for example, ontologies connect diagnoses to treatment plans, physician notes or lab results. Or in financial services, they link industry-specific regulations to the organization's compliance structures and policies.</p><p>In other words, unlocking unstructured data provides crucial business context that helps create better, more informed outputs from your AI. But that, in turn, needs to be contextualized by an ontology so that AI can understand data properly. </p><h2 id="taking-control-of-ai-memory">Taking control of AI memory</h2><p>AI doesn’t need perfect memory to understand how your business operates and start creating trustworthy, valuable outputs. What it does need is relevant, governed context; most of which lives in unstructured content but only becomes useful once connected to structured enterprise data.</p><p>Infrastructure that can enable your systems to access the right information, understand how that data fits together and then apply it within the realities of the business is, therefore, essential. But crucially, that doesn’t mean you have to start from scratch.</p><p>In fact, reinventing your foundations would essentially defeat the point. Real business memory understands the systems, content, data, and processes that already exist within your organization, so throwing everything out in the pursuit of better context is unnecessary and, frankly, a huge waste of resources.</p><p>You don’t have to wait for the next model update to cure AI’s amnesia, and you don’t need to completely change your current stack to see real value from your automation projects.</p><p>By building in the foundations for business memory, organizations can take back control, make the most of their AI systems and make their <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> more resilient and adaptable for whatever models the future holds.</p><p><em></em><a href="https://www.techradar.com/news/the-best-website-builder"><em>We've featured the best AI website builder.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/enterprise-ai-has-a-memory-problem-but-businesses-have-the-answer</link>
                                                                            <description>
                            <![CDATA[ What if the secret to better AI memory isn’t better models, but better business knowledge? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YvkePMUxpi29b3ThKhni7h</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PAztEScphfxGJfYno5NjrL-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Sep 2026 08:21:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ John Newton ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PAztEScphfxGJfYno5NjrL-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot standing thoughtfully in front of a giant digital display with code on it]]></media:description>                                                            <media:text><![CDATA[A robot standing thoughtfully in front of a giant digital display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A robot standing thoughtfully in front of a giant digital display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PAztEScphfxGJfYno5NjrL-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.techradar.com/phones/best-ai-phone">Artificial intelligence</a> (AI) is like a genius with no memory of you. It has plenty of brain power, but unless context is handed to it directly, it knows nothing about your business, your <a href="https://www.techradar.com/best/the-best-customer-database-software-of-year">customers</a>, or the decisions that shaped how you operate today.</p><p>And solving that memory problem is quickly becoming a major barrier to enterprise AI deployment today.</p><p>Much of the current conversation about AI's limitations centers on the models themselves and their evolution toward bigger context windows, better reasoning, or longer memory. But that framing misses something important.</p><p>Enterprises don't need to wait for the next model breakthrough to solve this problem. They already have what they need sitting inside their own organizations: decades of content, decisions, and institutional context that most AI systems never see.</p><p>Every enterprise has a vast, largely untapped record of how it actually operates in the contracts negotiated, claims resolved, cases handled, decisions made and revisited. This is the accumulated context that makes an organization's judgment distinct from a general-purpose LLM. Yet in most companies, this information sits fragmented across systems, buried in unstructured formats, or locked away with no clear path for AI to reach it.</p><p>That is the gap that needs closing before AI <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> can scale responsibly. Not a smarter model, but a more complete memory built from an organization's own history rather than a general-purpose training set.</p><p>Think of this as "business memory": the nervous system connecting what a company already knows to what it wants AI to help it do next, carrying context to wherever a decision needs to be made.</p><h2 id="giving-ai-the-full-picture">Giving AI the full picture</h2><p>Business memory is best described as the accumulated knowledge of how an organization operates. It turns years of enterprise content, workflows and industry knowledge into information that AI can act on for true agentic automation at scale. The thinking behind this is simple.</p><p>By creating a context layer that governs what data the AI has access to, and ensuring it operates on relevant, authorized and current information, organizations will get those governed, trusted outputs they need to act with confidence.</p><p>An organization's memory is more than the information it retains. It also includes which version is authoritative, who may access it, where it came from and how long it remains valid. Carrying those signals into the context layer helps AI operate within the same rules as the business itself.</p><p>Better context alone does not ensure trustworthy outputs; provenance, evaluation, monitoring and human oversight also matter.</p><p>And although it accounts for an estimated 80% of enterprise content, based on various analyst reports, businesses use only about 10% of this incredibly valuable resource.</p><p>If organizations want to maximize the effectiveness of their AI models, the first thing they need to do is to start leveraging that valuable <a href="https://www.techradar.com/best/best-small-business-software">business</a> memory contained in their unstructured data. And that requires investing in your infrastructure to transform it into an AI-ready format.</p><p>In practice, start with a clearly defined use case and identify the authoritative content and data needed to support it. Preserve existing access controls, enrich the information with metadata and relationships, and test whether the AI's outputs are accurate, traceable, and useful before expanding automation. This creates a repeatable foundation that scales across the business without a wholesale replacement of existing systems.</p><h2 id="context-is-key">Context is key</h2><p>However, giving your AI access to the relevant <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> is not enough on its own. In fact, I’ve seen a lot of AI initiatives fail in the early stages because the business doesn’t appreciate just how complex a lot of this underlying data is.</p><p>As such, the content needs to be contextualized by an ‘ontology’, a formalized framework that defines all the different entities, terminology, relationships and rules that exist within your business. This enables your AI to understand not just what information exists across your systems, but how all of that information relates to your business or industry.</p><p>Put simply, ontologies are like maps: your AI may well get to your desired destination without one, but having it ensures you get there quicker and without potentially stumbling into any pitfalls along the way.</p><p>This is particularly important for regulated industries. In healthcare, for example, ontologies connect diagnoses to treatment plans, physician notes or lab results. Or in financial services, they link industry-specific regulations to the organization's compliance structures and policies.</p><p>In other words, unlocking unstructured data provides crucial business context that helps create better, more informed outputs from your AI. But that, in turn, needs to be contextualized by an ontology so that AI can understand data properly. </p><h2 id="taking-control-of-ai-memory">Taking control of AI memory</h2><p>AI doesn’t need perfect memory to understand how your business operates and start creating trustworthy, valuable outputs. What it does need is relevant, governed context; most of which lives in unstructured content but only becomes useful once connected to structured enterprise data.</p><p>Infrastructure that can enable your systems to access the right information, understand how that data fits together and then apply it within the realities of the business is, therefore, essential. But crucially, that doesn’t mean you have to start from scratch.</p><p>In fact, reinventing your foundations would essentially defeat the point. Real business memory understands the systems, content, data, and processes that already exist within your organization, so throwing everything out in the pursuit of better context is unnecessary and, frankly, a huge waste of resources.</p><p>You don’t have to wait for the next model update to cure AI’s amnesia, and you don’t need to completely change your current stack to see real value from your automation projects.</p><p>By building in the foundations for business memory, organizations can take back control, make the most of their AI systems and make their <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> more resilient and adaptable for whatever models the future holds.</p><p><em></em><a href="https://www.techradar.com/news/the-best-website-builder"><em>We've featured the best AI website builder.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI claims fake cop scams are costing victims billions —here's what to look out for ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>$1.6 billion has been claimed by scammers impersonating police and government officials</strong></li><li><strong>The FBI’s Internet Crime Complaint Center (IC3) received almost 61,000 complaints concerning such scams between January 2025 and July 2026</strong></li><li><strong>Some scams targeted foreign nationals and immigrants, threatening to cancel passports or impose extradition, unless payment is made</strong></li></ul><p>Between January 2025 and July 2026, the FBI’s Internet Crime Complaint Center received almost 61,000 complaints concerning scams using police and government official impersonation tactics. As a result, around $1.6 billion is believed to have been scammed and extorted.</p><p>Tactics used by scammers included unsolicited phone calls and in some cases video calls, with victims losing an average of $26,000 per scam.</p><p>Particularly concerning is the targeting of foreign nationals, international students, and immigrant citizens, often with threats to cancel visas and home country passports. Incredibly, 10% of all losses were traced to a single scam, one that targeted fewer than 3% of the victims.</p><h2 id="foreign-national-victims">Foreign national victims</h2><p>According to the FBI, the fake cop/fake government official scam has various angles, from alleging missed jury duty to threatening arrest due to circumstantial links to an alleged crime.</p><p>The demand from the scammers, inevitably, is payment.</p><p>Making a commitment to extreme lengths of scamming and extortion, the criminals took things to a new level when it came to targeting victims. International students, visiting foreign nationals, and other immigrant citizens were given special treatment. Not only were they threatened with extradition, there was also the implication of victims losing their home country passport.</p><p>To convince the target, scammers built actual studio sets, donned uniforms or suits, and appeared in video calls to the victims, who were convinced they were talking to foreign law enforcement agents or US-based diplomats. Creating the illusion of officialdom to sell the scam, victims paid whatever necessary to stay in their adopted country.</p><h2 id="how-to-spot-the-scam">How to spot the scam</h2><p>It is important to note that not all fraud of this type takes place in the US. These may be online or offline, but the so-called fake cop scam is an international criminal phenomenon. So, how do you avoid it?</p><p>We’ll assume you’ve answered a call inadvertently rather than having spam calls blocked (that should be set already).</p><p>First, remain calm. These situations are designed to impose stress and heightened anxiety. Scammers rely on these factors to cloud their victim’s judgement and force the narrative they are selling (“you missed jury duty”/“your presence in the country is illegal.”)</p><p>Second, it is vital to request credentials. Failure to provide these is the first red flag that the person communicating with you is not what they seem. That’s your cue to end the conversation. </p><p>Third, check the credentials. It doesn’t matter how long this takes – a legitimate caller will not mind waiting for you to do the necessary background check, even if it means them calling back.</p><p>Finally, and most importantly: neither law enforcement, security services, nor the FBI will demand money. If that is happening, it’s time to end the call.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/fbi-claims-fake-cop-scams-are-costing-victims-billions-heres-what-to-look-out-for</link>
                                                                            <description>
                            <![CDATA[ FBI reports impersonating law enforcement and government officials has netted scammers around $1.6 billion since January 2025 – but that is only based on reported cases, so the true figure could be much higher ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VCgpkB88rLQLdc9Z5gzacb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DTYDBbF7AKyFHCuQWLDPmj-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Sep 2026 01:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DTYDBbF7AKyFHCuQWLDPmj-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phone scam- vishing]]></media:description>                                                            <media:text><![CDATA[Phone scam- vishing]]></media:text>
                                <media:title type="plain"><![CDATA[Phone scam- vishing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DTYDBbF7AKyFHCuQWLDPmj-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>$1.6 billion has been claimed by scammers impersonating police and government officials</strong></li><li><strong>The FBI’s Internet Crime Complaint Center (IC3) received almost 61,000 complaints concerning such scams between January 2025 and July 2026</strong></li><li><strong>Some scams targeted foreign nationals and immigrants, threatening to cancel passports or impose extradition, unless payment is made</strong></li></ul><p>Between January 2025 and July 2026, the FBI’s Internet Crime Complaint Center received almost 61,000 complaints concerning scams using police and government official impersonation tactics. As a result, around $1.6 billion is believed to have been scammed and extorted.</p><p>Tactics used by scammers included unsolicited phone calls and in some cases video calls, with victims losing an average of $26,000 per scam.</p><p>Particularly concerning is the targeting of foreign nationals, international students, and immigrant citizens, often with threats to cancel visas and home country passports. Incredibly, 10% of all losses were traced to a single scam, one that targeted fewer than 3% of the victims.</p><h2 id="foreign-national-victims">Foreign national victims</h2><p>According to the FBI, the fake cop/fake government official scam has various angles, from alleging missed jury duty to threatening arrest due to circumstantial links to an alleged crime.</p><p>The demand from the scammers, inevitably, is payment.</p><p>Making a commitment to extreme lengths of scamming and extortion, the criminals took things to a new level when it came to targeting victims. International students, visiting foreign nationals, and other immigrant citizens were given special treatment. Not only were they threatened with extradition, there was also the implication of victims losing their home country passport.</p><p>To convince the target, scammers built actual studio sets, donned uniforms or suits, and appeared in video calls to the victims, who were convinced they were talking to foreign law enforcement agents or US-based diplomats. Creating the illusion of officialdom to sell the scam, victims paid whatever necessary to stay in their adopted country.</p><h2 id="how-to-spot-the-scam">How to spot the scam</h2><p>It is important to note that not all fraud of this type takes place in the US. These may be online or offline, but the so-called fake cop scam is an international criminal phenomenon. So, how do you avoid it?</p><p>We’ll assume you’ve answered a call inadvertently rather than having spam calls blocked (that should be set already).</p><p>First, remain calm. These situations are designed to impose stress and heightened anxiety. Scammers rely on these factors to cloud their victim’s judgement and force the narrative they are selling (“you missed jury duty”/“your presence in the country is illegal.”)</p><p>Second, it is vital to request credentials. Failure to provide these is the first red flag that the person communicating with you is not what they seem. That’s your cue to end the conversation. </p><p>Third, check the credentials. It doesn’t matter how long this takes – a legitimate caller will not mind waiting for you to do the necessary background check, even if it means them calling back.</p><p>Finally, and most importantly: neither law enforcement, security services, nor the FBI will demand money. If that is happening, it’s time to end the call.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This new drone comes with 'whiskers' to help it navigate in the dark or smoky and dusty areas like battlefields — and it weighs less than 100g ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Two artificial whiskers give this tiny drone a working sense of touch</strong></li><li><strong>Pressure sensors at the whisker base detect surface contact instantly</strong></li><li><strong>Onboard software processes tactile data using only 34 kilobytes of memory</strong></li></ul><p>A research team from Delft University of Technology in the Netherlands has developed a tiny drone that uses artificial whiskers to navigate where conventional sensors struggle.</p><p>The system relies on physical contact rather than cameras or satellite positioning, allowing the aircraft to detect nearby surfaces through touch.</p><p>The researchers designed the technology for <a href="https://www.techradar.com/cameras/drones/best-drone">drones</a> weighing below 100 grams, where adding substantial sensing equipment can quickly consume available capacity.</p><h2 id="tiny-whiskers-give-the-drone-another-way-to-sense-surroundings">Tiny whiskers give the drone another way to sense surroundings</h2><p>The device carries two slender filaments near its nose, angled upward and connected to miniature pressure sensors underneath.</p><p>When either filament touches an object, pressure changes provide information that helps the aircraft estimate its position relative to nearby surfaces.</p><p>That information allows the drone to move around obstacles, maintain contact with structures, and construct a basic representation of surrounding spaces.</p><p>The approach takes inspiration from rodents and other mammals, which use facial hairs to move through confined environments with limited visibility.</p><p>“Here, we aim to equip drones with rich tactile sensing — not for manipulation in the air, but for a novel concept of tactile navigation,” said Salua Hamaza, Associate Professor of Aerial Physical Interaction and Embodied Intelligence.</p><p>The system needed to be lightweight, process rapidly, and consume limited energy before tactile navigation could become practical aboard small aircraft.</p><h2 id="the-sensing-system-runs-on-only-34kb">The sensing system runs on only 34KB</h2><p>A major hurdle was airflow, since passing wind can easily disturb whisker readings and confuse the pressure sensors beneath them.</p><p>To solve this, the researchers wrote a lightweight processing program that separates turbulence from genuine surface contact in real time with millimetric precision.</p><p>The complete onboard software occupies just 34 kilobytes of memory, keeping the computational requirements unusually low for an autonomous sensing system.</p><p>Traditional navigation software built for larger drones typically demands considerably more computing power than this compact whisker-processing system requires today</p><p>“We wanted to show that touch does not have to come at the cost of size or computational power,” said Chaoxiang Ye, a PhD candidate and researcher at Deft.</p><p>The small size allows the drone to interpret environmental information without depending on external processing.</p><p>The approach will not suit the fastest drones, but for small rescue units, sensing through touch may prove genuinely valuable.</p><p>This device is especially useful for environments where smoke, dust, darkness, or damaged infrastructure could interfere with cameras and other optical equipment.</p><p>One potential application of this drone is in collapsed buildings where rescue operations can prove to be difficult because of instability and tight spaces, and regular aerial sensing may be unreliable</p><p>Small drones could enter restricted spaces ahead of human responders, using physical contact to gather information about nearby structures and possible pathways.</p><p>The system could also provide another sensing method when GPS signals are unavailable or visual information becomes difficult to interpret.</p><p>Via <a href="https://www.tomshardware.com/tech-industry/drones/researchers-build-a-drone-that-navigates-with-physical-whiskers-to-operate-in-dark-dusty-or-smoky-places-where-cameras-or-gps-can-fail-sub-100-gram-drones-run-34kb-software-to-enable-sub-millimeter-precision" target="_blank" rel="nofollow">TomsHardware</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/this-new-drone-comes-with-whiskers-to-help-it-navigate-in-the-dark-or-smoky-and-dusty-areas-like-battlefields-and-it-weighs-less-than-100g</link>
                                                                            <description>
                            <![CDATA[ Delft University researchers built a lightweight drone that uses whisker sensors and minimal software to navigate through darkness and smoke. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gmFPfC2nUMYAcLgDLf5ENU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/g8M9aMzU3i8ourcUoPCqXD-1920-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Sep 2026 00:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/g8M9aMzU3i8ourcUoPCqXD-1920-80.png">
                                                            <media:credit><![CDATA[Delft University of Technology]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Bio-inspired whiskers enable tiny drones to navigate in darkness using touch]]></media:description>                                                            <media:text><![CDATA[Bio-inspired whiskers enable tiny drones to navigate in darkness using touch]]></media:text>
                                <media:title type="plain"><![CDATA[Bio-inspired whiskers enable tiny drones to navigate in darkness using touch]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/g8M9aMzU3i8ourcUoPCqXD-1920-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Two artificial whiskers give this tiny drone a working sense of touch</strong></li><li><strong>Pressure sensors at the whisker base detect surface contact instantly</strong></li><li><strong>Onboard software processes tactile data using only 34 kilobytes of memory</strong></li></ul><p>A research team from Delft University of Technology in the Netherlands has developed a tiny drone that uses artificial whiskers to navigate where conventional sensors struggle.</p><p>The system relies on physical contact rather than cameras or satellite positioning, allowing the aircraft to detect nearby surfaces through touch.</p><p>The researchers designed the technology for <a href="https://www.techradar.com/cameras/drones/best-drone">drones</a> weighing below 100 grams, where adding substantial sensing equipment can quickly consume available capacity.</p><h2 id="tiny-whiskers-give-the-drone-another-way-to-sense-surroundings">Tiny whiskers give the drone another way to sense surroundings</h2><p>The device carries two slender filaments near its nose, angled upward and connected to miniature pressure sensors underneath.</p><p>When either filament touches an object, pressure changes provide information that helps the aircraft estimate its position relative to nearby surfaces.</p><p>That information allows the drone to move around obstacles, maintain contact with structures, and construct a basic representation of surrounding spaces.</p><p>The approach takes inspiration from rodents and other mammals, which use facial hairs to move through confined environments with limited visibility.</p><p>“Here, we aim to equip drones with rich tactile sensing — not for manipulation in the air, but for a novel concept of tactile navigation,” said Salua Hamaza, Associate Professor of Aerial Physical Interaction and Embodied Intelligence.</p><p>The system needed to be lightweight, process rapidly, and consume limited energy before tactile navigation could become practical aboard small aircraft.</p><h2 id="the-sensing-system-runs-on-only-34kb">The sensing system runs on only 34KB</h2><p>A major hurdle was airflow, since passing wind can easily disturb whisker readings and confuse the pressure sensors beneath them.</p><p>To solve this, the researchers wrote a lightweight processing program that separates turbulence from genuine surface contact in real time with millimetric precision.</p><p>The complete onboard software occupies just 34 kilobytes of memory, keeping the computational requirements unusually low for an autonomous sensing system.</p><p>Traditional navigation software built for larger drones typically demands considerably more computing power than this compact whisker-processing system requires today</p><p>“We wanted to show that touch does not have to come at the cost of size or computational power,” said Chaoxiang Ye, a PhD candidate and researcher at Deft.</p><p>The small size allows the drone to interpret environmental information without depending on external processing.</p><p>The approach will not suit the fastest drones, but for small rescue units, sensing through touch may prove genuinely valuable.</p><p>This device is especially useful for environments where smoke, dust, darkness, or damaged infrastructure could interfere with cameras and other optical equipment.</p><p>One potential application of this drone is in collapsed buildings where rescue operations can prove to be difficult because of instability and tight spaces, and regular aerial sensing may be unreliable</p><p>Small drones could enter restricted spaces ahead of human responders, using physical contact to gather information about nearby structures and possible pathways.</p><p>The system could also provide another sensing method when GPS signals are unavailable or visual information becomes difficult to interpret.</p><p>Via <a href="https://www.tomshardware.com/tech-industry/drones/researchers-build-a-drone-that-navigates-with-physical-whiskers-to-operate-in-dark-dusty-or-smoky-places-where-cameras-or-gps-can-fail-sub-100-gram-drones-run-34kb-software-to-enable-sub-millimeter-precision" target="_blank" rel="nofollow">TomsHardware</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russia plans to roll out a special anti-drone 'Matryoshka doll' bullet that can be used in any standard Kalashnikov AK-47 rifle ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Russia is testing ammunition that splits apart to confront small drones</strong></li><li><strong>Russian testing found separated elements reaching critical components inside drones</strong></li><li><strong>The ammunition fits standard rifles instead of requiring specialized counter-drone weapons</strong></li></ul><p>The Russian military is developing a multi-bullet cartridge designed to give standard Kalashnikov rifles a new way to engage small drones during combat.</p><p>The ammunition separates into several elements during flight, creating multiple projectiles from a single round fired through a compatible rifle.</p><p>Military expert Yury Knutov said the design is intended for troops who may encounter <a href="https://www.techradar.com/cameras/drones/best-drone">drones</a> without having access to specialized firearms.</p><h2 id="a-multi-part-cartridge-for-standard-rifles">A multi-part cartridge for standard rifles</h2><p>The reported cartridge uses the 5.45mm format and can be loaded into a standard AK-12 magazine without requiring a different rifle platform.</p><p>Its unusual construction keeps several elements together before firing, after which they separate while travelling toward the aerial target.</p><p>The concept has drawn comparisons with a Matryoshka doll because multiple components are contained within one projectile before separating in flight.</p><p>Pervy Tekhnichesky reported in April that Kalashnikov Concern had developed and tested the ammunition as a potential option for engaging small drones.</p><p>The reported trials included individual shots and bursts, providing an initial assessment of how the multi-part projectile performed against unmanned aircraft.</p><p>Some of the separated elements reportedly reached batteries, electronic boards, and power-related components during those tests.</p><p>Those components are critical to drone operation, making their reported involvement in the testing relevant to the cartridge's intended aerial application.</p><p>The ammunition is therefore being developed specifically around small unmanned aircraft rather than as a general replacement for ordinary rifle rounds.</p><h2 id="different-performance-against-personnel">Different performance against personnel</h2><p>The cartridge has different limitations when used against personnel, particularly when protective equipment is involved during an engagement.</p><p>Body armor can reduce its penetrating effect, while hitting an exposed area would still depend on accurate placement of the separated elements.</p><p>That distinction keeps the ammunition's reported purpose focused on small aerial targets rather than conventional engagements involving protected ground personnel</p><p>“Our specialists have made bullets that separate into several parts, which are used against drones,” said Yury Knutov, a military expert.</p><p>“You just need two magazines, one loaded with regular bullets, the other with these special multi-bullets.”</p><p>Internal testing reportedly showed that components reached internal drone parts, but that does not establish overall battlefield effectiveness.</p><p>As drone warfare continues expanding across the ongoing conflict between Russia and Ukraine, new countermeasures keep emerging from both sides of the front line.</p><p>Military analysts frequently propose innovative solutions on paper, yet battlefield conditions often reveal weaknesses that laboratory testing simply cannot anticipate.</p><p>The new multi-bullet promises theoretical advantages that still require genuine combat validation before earning credibility.</p><p>Until Russian forces deploy this ammunition extensively under real combat pressure, its actual reliability and effectiveness in battle cannot be ascertained.</p><p>Independent verification, therefore, remains essential before military observers can responsibly assess whether this technology delivers meaningful battlefield advantage.</p><p>Via <a href="https://www1.ru/en/news/2026/09/18/436697-kak-matreska-voennyi-ekspert-obieiasnil-kak-multipuli-porazaiut-drony-iz-obycnogo-avtomata.html" target="_blank" rel="nofollow">1.ru</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/russia-plans-to-roll-out-a-special-anti-drone-matryoshka-doll-bullet-that-can-be-used-in-any-standard-kalashnikov-ak-47-rifle</link>
                                                                            <description>
                            <![CDATA[ Russia is testing a multi-bullet cartridge for Kalashnikov rifles that separates during flight and is designed specifically against small drones. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CuUG2QYex9jwBZdB79DWcS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NHz7fFqyVQqXnG9pGrLac5-1920-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 23:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/NHz7fFqyVQqXnG9pGrLac5-1920-80.png">
                                                            <media:credit><![CDATA[SCMP]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Kalashnikov AK47 riffles]]></media:description>                                                            <media:text><![CDATA[Kalashnikov AK47 riffles]]></media:text>
                                <media:title type="plain"><![CDATA[Kalashnikov AK47 riffles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NHz7fFqyVQqXnG9pGrLac5-1920-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Russia is testing ammunition that splits apart to confront small drones</strong></li><li><strong>Russian testing found separated elements reaching critical components inside drones</strong></li><li><strong>The ammunition fits standard rifles instead of requiring specialized counter-drone weapons</strong></li></ul><p>The Russian military is developing a multi-bullet cartridge designed to give standard Kalashnikov rifles a new way to engage small drones during combat.</p><p>The ammunition separates into several elements during flight, creating multiple projectiles from a single round fired through a compatible rifle.</p><p>Military expert Yury Knutov said the design is intended for troops who may encounter <a href="https://www.techradar.com/cameras/drones/best-drone">drones</a> without having access to specialized firearms.</p><h2 id="a-multi-part-cartridge-for-standard-rifles">A multi-part cartridge for standard rifles</h2><p>The reported cartridge uses the 5.45mm format and can be loaded into a standard AK-12 magazine without requiring a different rifle platform.</p><p>Its unusual construction keeps several elements together before firing, after which they separate while travelling toward the aerial target.</p><p>The concept has drawn comparisons with a Matryoshka doll because multiple components are contained within one projectile before separating in flight.</p><p>Pervy Tekhnichesky reported in April that Kalashnikov Concern had developed and tested the ammunition as a potential option for engaging small drones.</p><p>The reported trials included individual shots and bursts, providing an initial assessment of how the multi-part projectile performed against unmanned aircraft.</p><p>Some of the separated elements reportedly reached batteries, electronic boards, and power-related components during those tests.</p><p>Those components are critical to drone operation, making their reported involvement in the testing relevant to the cartridge's intended aerial application.</p><p>The ammunition is therefore being developed specifically around small unmanned aircraft rather than as a general replacement for ordinary rifle rounds.</p><h2 id="different-performance-against-personnel">Different performance against personnel</h2><p>The cartridge has different limitations when used against personnel, particularly when protective equipment is involved during an engagement.</p><p>Body armor can reduce its penetrating effect, while hitting an exposed area would still depend on accurate placement of the separated elements.</p><p>That distinction keeps the ammunition's reported purpose focused on small aerial targets rather than conventional engagements involving protected ground personnel</p><p>“Our specialists have made bullets that separate into several parts, which are used against drones,” said Yury Knutov, a military expert.</p><p>“You just need two magazines, one loaded with regular bullets, the other with these special multi-bullets.”</p><p>Internal testing reportedly showed that components reached internal drone parts, but that does not establish overall battlefield effectiveness.</p><p>As drone warfare continues expanding across the ongoing conflict between Russia and Ukraine, new countermeasures keep emerging from both sides of the front line.</p><p>Military analysts frequently propose innovative solutions on paper, yet battlefield conditions often reveal weaknesses that laboratory testing simply cannot anticipate.</p><p>The new multi-bullet promises theoretical advantages that still require genuine combat validation before earning credibility.</p><p>Until Russian forces deploy this ammunition extensively under real combat pressure, its actual reliability and effectiveness in battle cannot be ascertained.</p><p>Independent verification, therefore, remains essential before military observers can responsibly assess whether this technology delivers meaningful battlefield advantage.</p><p>Via <a href="https://www1.ru/en/news/2026/09/18/436697-kak-matreska-voennyi-ekspert-obieiasnil-kak-multipuli-porazaiut-drony-iz-obycnogo-avtomata.html" target="_blank" rel="nofollow">1.ru</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ No internet, no problem: Tether just released free AI translation models that work offline on your phone and laptop ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Tether's African model supports 19 languages while running directly on local devices</strong></li><li><strong>Tether removed 96% of low-quality training material before building AfriSLM</strong></li><li><strong>EuroNano supports 90 translation directions while occupying only 36MB</strong></li></ul><p>Tether AI Research has unveiled a new set of translation systems that work entirely offline, requiring no connection to any network.</p><p>The <a href="https://tether.io/news/tether-releases-open-source-ai-translation-models-for-african-and-european-languages/" target="_blank" rel="nofollow">release</a> includes QVAC TranslatePsy-AfriSLM, built for 19 African languages, alongside QVAC TranslatePsy-EuroNano, built for nine European languages.  </p><p>Each model processes translations directly on the device, keeping personal data local rather than sending it to remote cloud servers.</p><h2 id="translation-designed-for-devices-with-limited-resources">Translation designed for devices with limited resources</h2><p>The African release includes Hausa, Amharic, Yoruba, Lingala, Swahili, Igbo, Zulu, Somali, Oromo, Malagasy, Kinyarwanda, Xhosa and Afrikaans.</p><p>It also handles Wolof, Luganda, Nyanja, Shona, Tswana and Southern Sotho, covering languages used across several regions of Africa.</p><p>Tether says those 19 languages collectively account for about 50% of the continent's population — the figure represents language reach rather than individual users.</p><p>AfriSLM contains 800 million parameters, yet Tether says the <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">LLM</a> surpassed Qwen3.5-122B-A10B, TranslateGemma-27B and NLLB-3.3B.</p><p>The comparisons were measured using FLORES-200, BOUQuET and SMOL, although benchmark performance does not establish identical results across every practical translation situation.</p><p>Tether attributes the results partly to a data-screening system that discarded as much as 96% of material judged unsuitable.</p><p>The company also released smaller and larger versions, including 0.8B, 2B and 4B parameter configurations for different hardware requirements.</p><p>EuroNano takes another approach, using English as an intermediary language while connecting European languages through 90 possible translation routes.</p><p>That package occupies only 36MB, which Tether says represents about 94% less storage than a comparable Firefox offline arrangement.</p><p>The compact footprint means translation can remain available after connectivity disappears, without requiring separate downloads for every language combination.</p><p>That distinction matters for field workers, travellers and local applications where storage capacity and network availability can both impose practical constraints.</p><h2 id="why-tether-is-starting-with-african-languages">Why Tether is starting with African languages</h2><p>Tether's African focus also connects with the physical infrastructure it has developed across parts of Sub-Saharan Africa.</p><p>The company has installed solar-powered kiosks that provide phone charging, battery exchanges and access to digital financial services in communities.</p><p>Those locations could eventually provide another route for distributing educational material, agricultural information and other locally translated content without depending on continuous connectivity.</p><p>“Four billion people were left behind by the traditional financial system, and the most powerful technology of our age has repeated that failure,” said Paolo Ardoino, CEO of Tether.</p><p>“Language should not determine who can benefit from artificial intelligence. Open translation models like these are a step toward a future where education and <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> reach hundreds of millions of people who have neither reliable connectivity nor access to expensive systems.”</p><p>The same technology could also operate alongside QVAC MedPsy, Tether's smaller model intended for healthcare-related applications on local devices.</p><p>“A mother could get real medical information she understands, instead of guessing. A child could learn in their own language. That is the future we are building through QVAC,” Ardoino added.</p><p>AfriSLM is currently available through Hugging Face, and the associated research has also been accepted for presentation at EMNLP 2026.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/no-internet-no-problem-tether-just-released-free-ai-translation-models-that-work-offline-on-your-phone-and-laptop</link>
                                                                            <description>
                            <![CDATA[ Tether has released offline translation models supporting 19 African and 9 European languages, with processing handled directly on phones and laptops. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dFTyqY5xmRB5qKVWeUWEXG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/A5ZrYAQqb4wSUm4tLAHqdb-1920-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 22:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/A5ZrYAQqb4wSUm4tLAHqdb-1920-80.png">
                                                            <media:credit><![CDATA[Tether]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Tether QVAC TranslatePsy-AfriSLM]]></media:description>                                                            <media:text><![CDATA[Tether QVAC TranslatePsy-AfriSLM]]></media:text>
                                <media:title type="plain"><![CDATA[Tether QVAC TranslatePsy-AfriSLM]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/A5ZrYAQqb4wSUm4tLAHqdb-1920-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Tether's African model supports 19 languages while running directly on local devices</strong></li><li><strong>Tether removed 96% of low-quality training material before building AfriSLM</strong></li><li><strong>EuroNano supports 90 translation directions while occupying only 36MB</strong></li></ul><p>Tether AI Research has unveiled a new set of translation systems that work entirely offline, requiring no connection to any network.</p><p>The <a href="https://tether.io/news/tether-releases-open-source-ai-translation-models-for-african-and-european-languages/" target="_blank" rel="nofollow">release</a> includes QVAC TranslatePsy-AfriSLM, built for 19 African languages, alongside QVAC TranslatePsy-EuroNano, built for nine European languages.  </p><p>Each model processes translations directly on the device, keeping personal data local rather than sending it to remote cloud servers.</p><h2 id="translation-designed-for-devices-with-limited-resources">Translation designed for devices with limited resources</h2><p>The African release includes Hausa, Amharic, Yoruba, Lingala, Swahili, Igbo, Zulu, Somali, Oromo, Malagasy, Kinyarwanda, Xhosa and Afrikaans.</p><p>It also handles Wolof, Luganda, Nyanja, Shona, Tswana and Southern Sotho, covering languages used across several regions of Africa.</p><p>Tether says those 19 languages collectively account for about 50% of the continent's population — the figure represents language reach rather than individual users.</p><p>AfriSLM contains 800 million parameters, yet Tether says the <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">LLM</a> surpassed Qwen3.5-122B-A10B, TranslateGemma-27B and NLLB-3.3B.</p><p>The comparisons were measured using FLORES-200, BOUQuET and SMOL, although benchmark performance does not establish identical results across every practical translation situation.</p><p>Tether attributes the results partly to a data-screening system that discarded as much as 96% of material judged unsuitable.</p><p>The company also released smaller and larger versions, including 0.8B, 2B and 4B parameter configurations for different hardware requirements.</p><p>EuroNano takes another approach, using English as an intermediary language while connecting European languages through 90 possible translation routes.</p><p>That package occupies only 36MB, which Tether says represents about 94% less storage than a comparable Firefox offline arrangement.</p><p>The compact footprint means translation can remain available after connectivity disappears, without requiring separate downloads for every language combination.</p><p>That distinction matters for field workers, travellers and local applications where storage capacity and network availability can both impose practical constraints.</p><h2 id="why-tether-is-starting-with-african-languages">Why Tether is starting with African languages</h2><p>Tether's African focus also connects with the physical infrastructure it has developed across parts of Sub-Saharan Africa.</p><p>The company has installed solar-powered kiosks that provide phone charging, battery exchanges and access to digital financial services in communities.</p><p>Those locations could eventually provide another route for distributing educational material, agricultural information and other locally translated content without depending on continuous connectivity.</p><p>“Four billion people were left behind by the traditional financial system, and the most powerful technology of our age has repeated that failure,” said Paolo Ardoino, CEO of Tether.</p><p>“Language should not determine who can benefit from artificial intelligence. Open translation models like these are a step toward a future where education and <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> reach hundreds of millions of people who have neither reliable connectivity nor access to expensive systems.”</p><p>The same technology could also operate alongside QVAC MedPsy, Tether's smaller model intended for healthcare-related applications on local devices.</p><p>“A mother could get real medical information she understands, instead of guessing. A child could learn in their own language. That is the future we are building through QVAC,” Ardoino added.</p><p>AfriSLM is currently available through Hugging Face, and the associated research has also been accepted for presentation at EMNLP 2026.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Africa's AI moment has arrived — this 1.5B model built from scratch for 12 African languages beats Google, Meta, and Alibaba while being 8x smaller ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>MORENA beat 26 tested models despite having only 1.5 billion parameters</strong></li><li><strong>The model from</strong> <strong>Vambo AI</strong> <strong>was built specifically around African languages from scratch</strong></li><li><strong>MORENA uses fewer tokens to represent African text than major rivals</strong></li></ul><p>Vambo AI has released MORENA, a 1.5B parameter language model covering 12 languages spoken across Africa, plus English, French and code. </p><p>The developers say it beats models from Google, Meta, Alibaba and HuggingFace on African language modelling and translation while being up to 8x smaller. </p><p>On a key benchmark, this <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">LLM</a> scored 1.408 bpb — the best of 26 models tested — beating its closest rival, which carried over five times as many parameters yet still scored only 1.423 bpb.</p><h2 id="training-without-a-borrowed-foundation">Training without a borrowed foundation</h2><p>The model covers Nigerian Pidgin, Igbo, Yoruba, Hausa, Kiswahili, ChiShona, isiZulu, isiXhosa, Kinyarwanda, Setswana, Afrikaans, and isiNdebele.</p><p>Most projects serving these languages continue training an existing Llama variant, which forces them to keep a vocabulary meant for English and programming text.</p><p>Vambo AI instead fixed the tokenizer, the data mixture, and the language list before training began, after comparing several vocabulary sizes for cost and efficiency.</p><p>MORENA's vocabulary encodes African text with 1.39 times fewer tokens than Gemma 3 and 1.53 times fewer than Llama 3.2 on identical passages.</p><p>African text still costs 0.249 tokens for each byte against 0.234 for English, roughly 6% more, and the team cannot fully explain the difference.</p><p>The nearest competitor, Lugha-Llama-8B, an Africa-adapted Llama 3.1 variant, scores 1.423 bpb and loses to MORENA in eight languages out of 12.</p><p>The 12B Gemma system, by comparison, consumes roughly 11 times the compute of MORENA while producing a weaker score on the same text.</p><p>The chat-tuned instruct version scores 1.441 bpb, trailing Lugha-Llama-8B overall but leading it in five shared languages while using about 20% of its parameters.</p><p>The instruct model, after seeing three sample translations, renders English into five languages from Africa at 45.8 chrF++, statistically level with one dedicated translation system.</p><p>It trails a larger translation model by about 1.4 points, while general models of similar size typically land in a range from 9 to 14.</p><h2 id="a-family-built-on-22-000-gpu-hours">A family built on 22,000 GPU hours</h2><p>MORENA used 251.7B tokens during pretraining, followed by another 63B tokens during its mid-training stage.</p><p>Over 22,000 A100 <a href="https://www.techradar.com/news/computing-components/graphics-cards/best-graphics-cards-1291458">GPU</a> hours were reportedly required during development, with the associated computing resources valued at roughly $40,000.</p><p>According to the developers, this project was supported by UNDP, AIHub4SD, and CINECA, providing computing resources and other assistance during development.</p><p>This project also includes smaller releases, with versions containing 0.5B and 0.2B parameters available alongside the principal 1.5 billion model.</p><p>The 0.5B variants reportedly exceed every external system tested across 11 of the 12 languages covered by the project.</p><p>The 0.2B nano version is intended for speech-recognition rescoring, keyboard applications, and text normalisation tasks.</p><p>This nano version also costs 58 times less than Lugha-Llama-8B for each byte processed and generates 104 tokens each second on one A100 GPU.</p><p>A CPU-compatible build of the model also runs offline on a laptop, which suits settings where reliable GPU access is not guaranteed.</p><p>That gives the developers several model sizes for different computing requirements, rather than relying exclusively on the largest release.</p><p>MORENA also supports conversational applications, translation, and connections to other <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> through its instruction-focused release.</p><p>Via <a href="https://glitchfront.com/2026/09/18/morena-a-from-scratch-model-for-12-african-languages/" target="_blank" rel="nofollow">Glitch Front</a> </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/africas-ai-moment-has-arrived-this-1-5b-model-built-from-scratch-for-12-african-languages-beats-google-meta-and-alibaba-while-being-8x-smaller</link>
                                                                            <description>
                            <![CDATA[ MORENA is a 1.5B African language model that beats larger rivals on benchmarks while requiring substantially less computing power. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ePcNauyDUJFirmbtqkDdqF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/B7rSuocnva8Sqvm2X4FHq-1920-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 21:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/B7rSuocnva8Sqvm2X4FHq-1920-80.png">
                                                            <media:credit><![CDATA[Vambo AI]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Vambo&#039;s AI MORENA, a large language model designed for African languages]]></media:description>                                                            <media:text><![CDATA[Vambo&#039;s AI MORENA, a large language model designed for African languages]]></media:text>
                                <media:title type="plain"><![CDATA[Vambo&#039;s AI MORENA, a large language model designed for African languages]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/B7rSuocnva8Sqvm2X4FHq-1920-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>MORENA beat 26 tested models despite having only 1.5 billion parameters</strong></li><li><strong>The model from</strong> <strong>Vambo AI</strong> <strong>was built specifically around African languages from scratch</strong></li><li><strong>MORENA uses fewer tokens to represent African text than major rivals</strong></li></ul><p>Vambo AI has released MORENA, a 1.5B parameter language model covering 12 languages spoken across Africa, plus English, French and code. </p><p>The developers say it beats models from Google, Meta, Alibaba and HuggingFace on African language modelling and translation while being up to 8x smaller. </p><p>On a key benchmark, this <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">LLM</a> scored 1.408 bpb — the best of 26 models tested — beating its closest rival, which carried over five times as many parameters yet still scored only 1.423 bpb.</p><h2 id="training-without-a-borrowed-foundation">Training without a borrowed foundation</h2><p>The model covers Nigerian Pidgin, Igbo, Yoruba, Hausa, Kiswahili, ChiShona, isiZulu, isiXhosa, Kinyarwanda, Setswana, Afrikaans, and isiNdebele.</p><p>Most projects serving these languages continue training an existing Llama variant, which forces them to keep a vocabulary meant for English and programming text.</p><p>Vambo AI instead fixed the tokenizer, the data mixture, and the language list before training began, after comparing several vocabulary sizes for cost and efficiency.</p><p>MORENA's vocabulary encodes African text with 1.39 times fewer tokens than Gemma 3 and 1.53 times fewer than Llama 3.2 on identical passages.</p><p>African text still costs 0.249 tokens for each byte against 0.234 for English, roughly 6% more, and the team cannot fully explain the difference.</p><p>The nearest competitor, Lugha-Llama-8B, an Africa-adapted Llama 3.1 variant, scores 1.423 bpb and loses to MORENA in eight languages out of 12.</p><p>The 12B Gemma system, by comparison, consumes roughly 11 times the compute of MORENA while producing a weaker score on the same text.</p><p>The chat-tuned instruct version scores 1.441 bpb, trailing Lugha-Llama-8B overall but leading it in five shared languages while using about 20% of its parameters.</p><p>The instruct model, after seeing three sample translations, renders English into five languages from Africa at 45.8 chrF++, statistically level with one dedicated translation system.</p><p>It trails a larger translation model by about 1.4 points, while general models of similar size typically land in a range from 9 to 14.</p><h2 id="a-family-built-on-22-000-gpu-hours">A family built on 22,000 GPU hours</h2><p>MORENA used 251.7B tokens during pretraining, followed by another 63B tokens during its mid-training stage.</p><p>Over 22,000 A100 <a href="https://www.techradar.com/news/computing-components/graphics-cards/best-graphics-cards-1291458">GPU</a> hours were reportedly required during development, with the associated computing resources valued at roughly $40,000.</p><p>According to the developers, this project was supported by UNDP, AIHub4SD, and CINECA, providing computing resources and other assistance during development.</p><p>This project also includes smaller releases, with versions containing 0.5B and 0.2B parameters available alongside the principal 1.5 billion model.</p><p>The 0.5B variants reportedly exceed every external system tested across 11 of the 12 languages covered by the project.</p><p>The 0.2B nano version is intended for speech-recognition rescoring, keyboard applications, and text normalisation tasks.</p><p>This nano version also costs 58 times less than Lugha-Llama-8B for each byte processed and generates 104 tokens each second on one A100 GPU.</p><p>A CPU-compatible build of the model also runs offline on a laptop, which suits settings where reliable GPU access is not guaranteed.</p><p>That gives the developers several model sizes for different computing requirements, rather than relying exclusively on the largest release.</p><p>MORENA also supports conversational applications, translation, and connections to other <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> through its instruction-focused release.</p><p>Via <a href="https://glitchfront.com/2026/09/18/morena-a-from-scratch-model-for-12-african-languages/" target="_blank" rel="nofollow">Glitch Front</a> </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Looking for a powerful convertible laptop? Japan gets a 10.51-inch device with a Core Ultra 5 CPU, and it weighs just 960g ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>TENKU Note Pro AI uses a full Windows 11 Pro setup inside its tiny convertible chassis</strong></li><li><strong>The 960g notebook folds completely around its touchscreen for tablet use</strong></li><li><strong>Intel's Core Ultra 5 125U brings dedicated AI hardware to TENKU's compact computer</strong></li></ul><p>TENKU has launched a compact Windows 11 Pro computer in Japan, combining Intel processing hardware with a touchscreen and convertible design.</p><p>The Note Pro AI uses a Core Ultra 5 125U processor with 12 cores and 14 threads, alongside hardware dedicated to selected AI workloads.</p><p>At 960g, the <a href="https://www.techradar.com/news/mobile-computing/laptops/best-laptops-1304361">laptop</a> combines a 10.51-inch screen with a physical keyboard while remaining considerably smaller than conventional full-size notebooks.</p><h2 id="a-convertible-design-built-around-intel-39-s-mobile-processor">A convertible design built around Intel's mobile processor</h2><p>The device uses a 360-degree hinge, allowing its keyboard section to fold behind the screen when tablet operation becomes more suitable.</p><p>Its touch panel recognizes ten simultaneous inputs, while an optional digital pen supports 4,096 pressure levels for writing and drawing applications.</p><p>The IPS panel produces 1,920 x 1,280 pixels, providing a 3:2 display area for Windows applications and productivity software.</p><p>Intel's Core Ultra 5 125U also includes an integrated NPU, which supports functions such as background processing and noise reduction during video calls.</p><p>The system includes 16GB of LPDDR5 memory and a 512GB M.2 <a href="https://www.techradar.com/news/best-solid-state-drives-ssds">SSD</a> for applications, documents, and other locally stored data.</p><p>Wireless connectivity covers 802.11a, b, g, n, ac, and ax standards, with Bluetooth 5.2 available for compatible accessories and peripherals.</p><h2 id="battery-capacity-dimensions-and-pricing">Battery capacity, dimensions and pricing</h2><p>Under the hood, the device packs a 3,800mAh battery that is smaller than many smartphone batteries today, yet TENKU rates it for 17 hours.</p><p>According to the company, the chassis of this notebook measures 243mm across, 177.6mm from front to back, and 17.5mm thick.</p><p>Its compact chassis leaves less internal space than larger notebooks, while retaining the hardware required for its convertible configuration and cooling system.</p><p>On the software end, this device comes installed with Windows 11 Pro, giving the computer access to desktop applications rather than restricting its use to tablet-oriented software.</p><p>The available AI functions depend on software support, meaning the processor's dedicated hardware does not automatically provide every possible feature across Windows.</p><p>TENKU has listed the Note Pro AI in Japan, and it is currently retailing for about 176,800 yen (about $1,127) including tax.</p><p>There is also a launch promotion that cuts the price by 25% through Highbeam's official online store and physical outlets.</p><p>The 25% discount takes the promo retail price to 132,600 yen (about $845), and the offer ends on September 24 2026.</p><p>Amazon Japan is also offering a separate 15% reduction during the same promotional period, giving buyers another discounted purchasing channel until September 24.</p><p>Via <a href="https://www.gdm.or.jp/pressrelease/2026/0918/653037" target="_blank" rel="nofollow">Hermitage Akihabara</a> (originally in Japanese)</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/looking-for-a-powerful-convertible-laptop-japan-gets-a-10-51-inch-device-with-a-core-ultra-5-cpu-and-it-weighs-just-960g</link>
                                                                            <description>
                            <![CDATA[ TENKU's Note Pro AI combines Intel processing, Windows 11 Pro, touchscreen controls, and a convertible design inside a 960g chassis. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uRmQVyZF7K7jg6C5uMW3p3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xiDN8A9P3usK3yy7h2dhjB-1920-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 20:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/xiDN8A9P3usK3yy7h2dhjB-1920-80.png">
                                                            <media:credit><![CDATA[TENKU]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[TENKU Note Pro AI]]></media:description>                                                            <media:text><![CDATA[TENKU Note Pro AI]]></media:text>
                                <media:title type="plain"><![CDATA[TENKU Note Pro AI]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xiDN8A9P3usK3yy7h2dhjB-1920-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>TENKU Note Pro AI uses a full Windows 11 Pro setup inside its tiny convertible chassis</strong></li><li><strong>The 960g notebook folds completely around its touchscreen for tablet use</strong></li><li><strong>Intel's Core Ultra 5 125U brings dedicated AI hardware to TENKU's compact computer</strong></li></ul><p>TENKU has launched a compact Windows 11 Pro computer in Japan, combining Intel processing hardware with a touchscreen and convertible design.</p><p>The Note Pro AI uses a Core Ultra 5 125U processor with 12 cores and 14 threads, alongside hardware dedicated to selected AI workloads.</p><p>At 960g, the <a href="https://www.techradar.com/news/mobile-computing/laptops/best-laptops-1304361">laptop</a> combines a 10.51-inch screen with a physical keyboard while remaining considerably smaller than conventional full-size notebooks.</p><h2 id="a-convertible-design-built-around-intel-39-s-mobile-processor">A convertible design built around Intel's mobile processor</h2><p>The device uses a 360-degree hinge, allowing its keyboard section to fold behind the screen when tablet operation becomes more suitable.</p><p>Its touch panel recognizes ten simultaneous inputs, while an optional digital pen supports 4,096 pressure levels for writing and drawing applications.</p><p>The IPS panel produces 1,920 x 1,280 pixels, providing a 3:2 display area for Windows applications and productivity software.</p><p>Intel's Core Ultra 5 125U also includes an integrated NPU, which supports functions such as background processing and noise reduction during video calls.</p><p>The system includes 16GB of LPDDR5 memory and a 512GB M.2 <a href="https://www.techradar.com/news/best-solid-state-drives-ssds">SSD</a> for applications, documents, and other locally stored data.</p><p>Wireless connectivity covers 802.11a, b, g, n, ac, and ax standards, with Bluetooth 5.2 available for compatible accessories and peripherals.</p><h2 id="battery-capacity-dimensions-and-pricing">Battery capacity, dimensions and pricing</h2><p>Under the hood, the device packs a 3,800mAh battery that is smaller than many smartphone batteries today, yet TENKU rates it for 17 hours.</p><p>According to the company, the chassis of this notebook measures 243mm across, 177.6mm from front to back, and 17.5mm thick.</p><p>Its compact chassis leaves less internal space than larger notebooks, while retaining the hardware required for its convertible configuration and cooling system.</p><p>On the software end, this device comes installed with Windows 11 Pro, giving the computer access to desktop applications rather than restricting its use to tablet-oriented software.</p><p>The available AI functions depend on software support, meaning the processor's dedicated hardware does not automatically provide every possible feature across Windows.</p><p>TENKU has listed the Note Pro AI in Japan, and it is currently retailing for about 176,800 yen (about $1,127) including tax.</p><p>There is also a launch promotion that cuts the price by 25% through Highbeam's official online store and physical outlets.</p><p>The 25% discount takes the promo retail price to 132,600 yen (about $845), and the offer ends on September 24 2026.</p><p>Amazon Japan is also offering a separate 15% reduction during the same promotional period, giving buyers another discounted purchasing channel until September 24.</p><p>Via <a href="https://www.gdm.or.jp/pressrelease/2026/0918/653037" target="_blank" rel="nofollow">Hermitage Akihabara</a> (originally in Japanese)</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Interpol uses AI to identify 126 terrorists by analyzing over 100,000 images with new facial recognition tools ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Interpol's Operation Shams II pulled 108,076 faces from jihadist propaganda with help from 11 countries</strong></li><li><strong>AI agents and scripts then deduplicated and quality-checked the set, leaving 6,362 images (~5.9%) for facial recognition</strong></li><li><strong>Interpol's facial recognition system, launched in 2016, then matched pictures to actual persons, with human verification in tow, and 126 suspected fighters have been identified so far</strong></li></ul><p>Interpol says an operation it coordinated in Tunisia in June 2026 used artificial intelligence to work through more than 100,000 faces taken from jihadist propaganda, producing matches against 126 suspected foreign terrorist fighters.</p><p>AI did most of the heavy lifting, condensing a mammoth 108,076 images into 6,362 unique, identifiable images that could be run through its decade-old facial recognition system.</p><p>This allowed 126 people to be identified on paper as potential terrorists who would still need to be tracked down by the international police organization.</p><h2 id="a-numbers-game-cut-down-to-size">A numbers game, cut down to size</h2><p>Interpol <a href="https://www.interpol.int/News-and-Events/News/2026/Counter-terrorism-operation-leverages-artificial-intelligence-to-identify-126-terrorism-suspects" target="_blank" rel="nofollow">says</a> programmed AI agents and AI-generated scripts automated parts of the collection and investigative work, removing duplicates and screening out poor-quality faces.</p><p>This approach left 6,362 unique, high-quality images, which were then run through the Interpol Facial Recognition System (IFRS). This effectively cut a trove of images into a non-duplicated, actionable list of only ~5.9% of the original set, which could then be used to identify potential terrorists.</p><p>By eliminating 94% of the images that would otherwise have to be processed manually, AI reduced the resources that would otherwise have to be deployed to reach a similar conclusion.</p><p>This is particularly handy, given that propaganda images often number in the thousands and investigators needed to sift through them manually to identify potential targets, many of which were duplicated by others involved in the same study.</p><p>“The success of Operation Shams II demonstrates the value of combining international law enforcement cooperation with responsible AI-assisted analytical capabilities," noted Interpol's Director of Counter-Terrorism, María Carmen Muñoz González.</p><p>"The operational model provides a strong foundation for supporting future international law enforcement cooperation targeting criminal actors around the world.”</p><p>Its automation attempts are not new; In 2019, <a href="https://digit.site36.net/2019/03/26/interpol-and-europol-extend-facial-recognition/" target="_blank" rel="nofollow">Digit reported</a>, citing Germany's Interior Ministry, that Interpol had presented a project called DTECH-Light intended to "detect, extract and analyze digital terrorist content, identify and locate suspects," with national bureaus asked to upload images of unnamed foreign fighters for comparison.</p><p>Interpol does not say what agents it used, which models or vendors sit behind them, or where they ran. "AI-generated scripts," it says it used, could simply mean automation code written with the help of a large language model rather than any purpose-built system.</p><p>For now, an AI is doing the grunt work so that a system launched in 2016, and the officers who check its output, can do theirs considerably faster, which is a significant win in efficiency for an agency that often has to deal with multiple sources of information, even as <a href="https://www.techradar.com/vpn/vpn-privacy-security/stop-worrying-about-an-ai-apocalypse-surfsharks-engineer-says-extinction-fears-are-just-a-marketing-move" target="_blank">fears about the tech have been rekindled</a> globally on multiple fronts.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/interpol-uses-ai-to-identify-126-terrorists-by-analyzing-over-100-000-images-with-new-facial-recognition-tools</link>
                                                                            <description>
                            <![CDATA[ Interpol says the AI's real job was decluttering the stack to 6,362 for a face matcher launched in 2016. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">axxELvtPM87Uxzqk9cactY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oYMP6fyogfLmoyyK3d39oX-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 19:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oYMP6fyogfLmoyyK3d39oX-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The emblem of the International Criminal Police Organization Interpol on a textured blue background.]]></media:description>                                                            <media:text><![CDATA[The emblem of the International Criminal Police Organization Interpol on a textured blue background.]]></media:text>
                                <media:title type="plain"><![CDATA[The emblem of the International Criminal Police Organization Interpol on a textured blue background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oYMP6fyogfLmoyyK3d39oX-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Interpol's Operation Shams II pulled 108,076 faces from jihadist propaganda with help from 11 countries</strong></li><li><strong>AI agents and scripts then deduplicated and quality-checked the set, leaving 6,362 images (~5.9%) for facial recognition</strong></li><li><strong>Interpol's facial recognition system, launched in 2016, then matched pictures to actual persons, with human verification in tow, and 126 suspected fighters have been identified so far</strong></li></ul><p>Interpol says an operation it coordinated in Tunisia in June 2026 used artificial intelligence to work through more than 100,000 faces taken from jihadist propaganda, producing matches against 126 suspected foreign terrorist fighters.</p><p>AI did most of the heavy lifting, condensing a mammoth 108,076 images into 6,362 unique, identifiable images that could be run through its decade-old facial recognition system.</p><p>This allowed 126 people to be identified on paper as potential terrorists who would still need to be tracked down by the international police organization.</p><h2 id="a-numbers-game-cut-down-to-size">A numbers game, cut down to size</h2><p>Interpol <a href="https://www.interpol.int/News-and-Events/News/2026/Counter-terrorism-operation-leverages-artificial-intelligence-to-identify-126-terrorism-suspects" target="_blank" rel="nofollow">says</a> programmed AI agents and AI-generated scripts automated parts of the collection and investigative work, removing duplicates and screening out poor-quality faces.</p><p>This approach left 6,362 unique, high-quality images, which were then run through the Interpol Facial Recognition System (IFRS). This effectively cut a trove of images into a non-duplicated, actionable list of only ~5.9% of the original set, which could then be used to identify potential terrorists.</p><p>By eliminating 94% of the images that would otherwise have to be processed manually, AI reduced the resources that would otherwise have to be deployed to reach a similar conclusion.</p><p>This is particularly handy, given that propaganda images often number in the thousands and investigators needed to sift through them manually to identify potential targets, many of which were duplicated by others involved in the same study.</p><p>“The success of Operation Shams II demonstrates the value of combining international law enforcement cooperation with responsible AI-assisted analytical capabilities," noted Interpol's Director of Counter-Terrorism, María Carmen Muñoz González.</p><p>"The operational model provides a strong foundation for supporting future international law enforcement cooperation targeting criminal actors around the world.”</p><p>Its automation attempts are not new; In 2019, <a href="https://digit.site36.net/2019/03/26/interpol-and-europol-extend-facial-recognition/" target="_blank" rel="nofollow">Digit reported</a>, citing Germany's Interior Ministry, that Interpol had presented a project called DTECH-Light intended to "detect, extract and analyze digital terrorist content, identify and locate suspects," with national bureaus asked to upload images of unnamed foreign fighters for comparison.</p><p>Interpol does not say what agents it used, which models or vendors sit behind them, or where they ran. "AI-generated scripts," it says it used, could simply mean automation code written with the help of a large language model rather than any purpose-built system.</p><p>For now, an AI is doing the grunt work so that a system launched in 2016, and the officers who check its output, can do theirs considerably faster, which is a significant win in efficiency for an agency that often has to deal with multiple sources of information, even as <a href="https://www.techradar.com/vpn/vpn-privacy-security/stop-worrying-about-an-ai-apocalypse-surfsharks-engineer-says-extinction-fears-are-just-a-marketing-move" target="_blank">fears about the tech have been rekindled</a> globally on multiple fronts.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ These popular TP-Link home security cameras could be hacked to spy on you while you sleep, experts warn ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Cybersecurity company OPSWAT found a login bypass and a crash bug in TP-Link's Tapo C200 cameras</strong></li><li><strong>TP-Link has extended that to include its C120 offering too</strong></li><li><strong>Anyone on the same network could get admin access, live video, and recordings without requiring the owner's credentials</strong></li></ul><p>Security researchers at <a href="https://www.opswat.com/blog/authentication-bypass-and-dos-vulnerabilities-opswat-discovers-cve-2026-15315-cve-2026-15316-in-tp-link-tapo-cameras" target="_blank">OPSWAT</a> have detailed two high-severity flaws in TP-Link's Tapo C200, a pan-and-tilt indoor camera <a href="https://www.amazon.com/TP-Link-Tapo-Wireless-Security-C200/dp/B0829KDY9X" target="_blank" rel="nofollow">listed on Amazon for $26.99</a> and sold as a baby monitor and pet camera.</p><p>The more serious issue is that someone on the same network can log in as the camera's administrator without the password, accessing the live feed and stored recordings.</p><p>At least one other bug, which OPSWAT rates as critical in the same disclosure but does not detail, has not been published.</p><h2 id="a-localized-login-that-requires-no-authentication">A localized login that requires no authentication</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="sXT4pLeU6CuMN5RuzCofpY" name="TP-Link Tapo C200" alt="The TP-Link Tapo C200 camera" src="https://cdn.mos.cms.futurecdn.net/sXT4pLeU6CuMN5RuzCofpY-1920-80.png" mos="" align="middle" fullscreen="" width="1000" height="1000" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: TP-Link)</span></figcaption></figure><p>The TP-Link Tapo C200, as we <a href="https://www.techradar.com/pro/security/watch-out-tp-link-tapo-camera-vulnerabilities-could-let-hackers-spy-inside-homes-so-patch-now" target="_blank">noted in previous coverage of the incident,</a> isn't just another security camera that happens to be vulnerable; it is one of the most popular models on the market, clocking in at over 3,000 sales on Amazon alone.</p><p>The Tapo C120, in its current iteration, sells over 5,000 units monthly, even <a href="https://www.tp-link.com/us/support/faq/5248/" target="_blank" rel="nofollow">as the advisory notes</a> that its V1 hardware version is currently compromised until users update the firmware on their devices.</p><p>Both SKUs have received firmware updates that patch the vulnerabilities (CVE-2026-15315 & CVE-2026-15316), which are assigned 'high' scores of 8.7 and 7.1, respectively. However, according to TP-Link, CVE-2026-15316 does not affect the C120 camera.</p><p>However, the former vulnerability is the more pressing of the two and, according to OPSWAT, is particularly problematic for users because of how the C120 and C200 cameras function.</p><p>Both run a local management interface over HTTPS and use a challenge-response login designed to prove a client knows the owner's password. Khoi Tran, a graduate fellow at OPSWAT, and his mentor, Thai Do of the company's Unit 515 team, found a second verification path in which, under certain conditions, a value the camera hands out during login can be sent back and accepted as a valid authentication response.</p><p>The result is an administrator session after a small number of requests, with no password, no existing session, and no requirements for the new 'owner'. As a result, access includes live video, stored footage, and configuration changes. </p><p>OPSWAT's researchers pointed out that a C200 used as a baby monitor would expose "live video, night vision, crying detection and two-way audio."</p><p>The second flaw, CVE-2026-15316, affects only the C200 and sits in its Wi-Fi onboarding code. Sending the camera an oversized chunk of encrypted Wi-Fi credential data can crash its HTTPS service or restart the device outright, cutting the owner off from management and monitoring until it recovers.</p><p>The attacks are somewhat limited in scope: users aiming to exploit such vulnerabilities would need to be on the same Wi-Fi network, or within a certain trusted ecosystem, to begin with.</p><p>For now, users upgrading to TP-Link's newest firmware, issued for both models, rectifies both issues, but there might already be another security patch in the works: OPSWAT also found "a critical vulnerability that could allow an attacker to fully compromise the camera," which could then serve as a foothold inside the network.</p><p>It is currently holding off on publishing any details about the vulnerability as it waits for TP-Link to issue a patch that rectifies the situation. Neither OPSWAT nor TP-Link, however, has provided a timeline for when the patch will be available to end users.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/these-popular-tp-link-home-security-cameras-could-be-hacked-to-spy-on-you-while-you-sleep-experts-warn</link>
                                                                            <description>
                            <![CDATA[ A passwordless login bypass in TP-Link's Tapo C200 and C120 cameras can expose your live feed to anyone on the same network, and a fix is already available to download ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">prqGALPJ6aayLt97QQAesD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8AQ6mNEWbxZfbYjrKfsCkF-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Smart Home]]></category>
                                                    <category><![CDATA[Home Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Home]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8AQ6mNEWbxZfbYjrKfsCkF-1920-80.jpg">
                                                            <media:credit><![CDATA[Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Privacy]]></media:description>                                                            <media:text><![CDATA[Privacy]]></media:text>
                                <media:title type="plain"><![CDATA[Privacy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8AQ6mNEWbxZfbYjrKfsCkF-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Cybersecurity company OPSWAT found a login bypass and a crash bug in TP-Link's Tapo C200 cameras</strong></li><li><strong>TP-Link has extended that to include its C120 offering too</strong></li><li><strong>Anyone on the same network could get admin access, live video, and recordings without requiring the owner's credentials</strong></li></ul><p>Security researchers at <a href="https://www.opswat.com/blog/authentication-bypass-and-dos-vulnerabilities-opswat-discovers-cve-2026-15315-cve-2026-15316-in-tp-link-tapo-cameras" target="_blank">OPSWAT</a> have detailed two high-severity flaws in TP-Link's Tapo C200, a pan-and-tilt indoor camera <a href="https://www.amazon.com/TP-Link-Tapo-Wireless-Security-C200/dp/B0829KDY9X" target="_blank" rel="nofollow">listed on Amazon for $26.99</a> and sold as a baby monitor and pet camera.</p><p>The more serious issue is that someone on the same network can log in as the camera's administrator without the password, accessing the live feed and stored recordings.</p><p>At least one other bug, which OPSWAT rates as critical in the same disclosure but does not detail, has not been published.</p><h2 id="a-localized-login-that-requires-no-authentication">A localized login that requires no authentication</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="sXT4pLeU6CuMN5RuzCofpY" name="TP-Link Tapo C200" alt="The TP-Link Tapo C200 camera" src="https://cdn.mos.cms.futurecdn.net/sXT4pLeU6CuMN5RuzCofpY-1920-80.png" mos="" align="middle" fullscreen="" width="1000" height="1000" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: TP-Link)</span></figcaption></figure><p>The TP-Link Tapo C200, as we <a href="https://www.techradar.com/pro/security/watch-out-tp-link-tapo-camera-vulnerabilities-could-let-hackers-spy-inside-homes-so-patch-now" target="_blank">noted in previous coverage of the incident,</a> isn't just another security camera that happens to be vulnerable; it is one of the most popular models on the market, clocking in at over 3,000 sales on Amazon alone.</p><p>The Tapo C120, in its current iteration, sells over 5,000 units monthly, even <a href="https://www.tp-link.com/us/support/faq/5248/" target="_blank" rel="nofollow">as the advisory notes</a> that its V1 hardware version is currently compromised until users update the firmware on their devices.</p><p>Both SKUs have received firmware updates that patch the vulnerabilities (CVE-2026-15315 & CVE-2026-15316), which are assigned 'high' scores of 8.7 and 7.1, respectively. However, according to TP-Link, CVE-2026-15316 does not affect the C120 camera.</p><p>However, the former vulnerability is the more pressing of the two and, according to OPSWAT, is particularly problematic for users because of how the C120 and C200 cameras function.</p><p>Both run a local management interface over HTTPS and use a challenge-response login designed to prove a client knows the owner's password. Khoi Tran, a graduate fellow at OPSWAT, and his mentor, Thai Do of the company's Unit 515 team, found a second verification path in which, under certain conditions, a value the camera hands out during login can be sent back and accepted as a valid authentication response.</p><p>The result is an administrator session after a small number of requests, with no password, no existing session, and no requirements for the new 'owner'. As a result, access includes live video, stored footage, and configuration changes. </p><p>OPSWAT's researchers pointed out that a C200 used as a baby monitor would expose "live video, night vision, crying detection and two-way audio."</p><p>The second flaw, CVE-2026-15316, affects only the C200 and sits in its Wi-Fi onboarding code. Sending the camera an oversized chunk of encrypted Wi-Fi credential data can crash its HTTPS service or restart the device outright, cutting the owner off from management and monitoring until it recovers.</p><p>The attacks are somewhat limited in scope: users aiming to exploit such vulnerabilities would need to be on the same Wi-Fi network, or within a certain trusted ecosystem, to begin with.</p><p>For now, users upgrading to TP-Link's newest firmware, issued for both models, rectifies both issues, but there might already be another security patch in the works: OPSWAT also found "a critical vulnerability that could allow an attacker to fully compromise the camera," which could then serve as a foothold inside the network.</p><p>It is currently holding off on publishing any details about the vulnerability as it waits for TP-Link to issue a patch that rectifies the situation. Neither OPSWAT nor TP-Link, however, has provided a timeline for when the patch will be available to end users.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Privacy policies on top LLMs take over 20 minutes to read, so perhaps it no wonder people are signing their lives over to ChatGPT and others ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Privacy policies are famously difficult to read, and in the world of LLMs, they’re impenetrable and long</strong></li><li><strong>The policy for Meta’s Muse Spark is over 14,000 words long, taking almost an hour to read</strong></li><li><strong>Cybersecurity firm Bridewell carried out the study, assessing the privacy policies of 20 popular LLMs</strong></li></ul><p>When you input data into an AI chatbot, you expect it to interpret and process the words or numbers to save you time. But what is it doing with that data? You can check the privacy policy to find out – assuming, that is, that you have the time to do so. </p><p>A new study has found that the average time it takes to read a privacy policy for an LLM is 20 minutes – and some are a much longer read.</p><p>With around 75% of people admitting to using an AI chatbot at least once a month, understanding where the questions and data queries are going and how they are used is increasingly important.</p><h2 id="ease-of-reading">Ease of reading</h2><p>Privacy policies provide that understanding, but are they easy to read? A study by Bridewell’s cyber security experts suggests not, with many having a poor Fleisch Reading Ease Score, meaning that in layman’s terms, these documents are pretty impenetrable.</p><p>Bridewell’s study assessed privacy policies from 20 large language models (LLMs), and found that the average length of time to read one is 20 minutes. The average word count is 4,603, but the real challenge is understanding the information.</p><p>The Flesch Reading Ease Score is a measure of readability devised by Rudolf Flesch in 1948, and is widely used to score texts. A score over 60 is good, whereas a score below that is not. The average Flesch score for these privacy policies is 40.2, suggesting a degree of jargon-based density that most people will not understand.</p><p>How, then, might the general public safely use an LLM chatbot like ChatGPT or Google Gemini while in full knowledge of how the information they input is being used?</p><h2 id="training-on-inputs">Training on inputs</h2><p>In evaluating the LLMs, Bridewell found that 13 of the 20 use inputs and outputs to train their models. Some LLMs offer the option to opt out of training, but others do not. Even where an opt out is possible, it isn’t always clear how to action it.</p><p>“It’s essential for users to fully understand how their data is being processed by LLMs, and businesses need clear internal guidance on what can and can't be shared, and ideally proper enterprise accounts with the right protections in place," noted Chris Linnell, Associate Director of Data Privacy at Bridewell,  "employees may be at risk of sharing highly sensitive or confidential information that may end up being used to train LLMs.”</p><p>There isn’t just a personal risk from data input into an AI. Employees need to be aware of how they are using the technology for work.</p><p>As a rule of thumb, the more complex the LLM (e.g., Meta's Muse Spark, or Moonshot AI’s Kimi K), the longer the privacy policy takes to read. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/privacy-policies-on-top-llms-take-over-20-minutes-to-read-so-perhaps-it-no-wonder-people-are-signing-their-lives-over-to-chatgpt-and-others</link>
                                                                            <description>
                            <![CDATA[ Technical and legal jargon make privacy policies for LLMs and their chatbots almost unreadable for most people. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6brXk3BKp7NUkiLwa6YXJC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/toJsHzqsNXvBcnSCEFy6VL-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/toJsHzqsNXvBcnSCEFy6VL-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/fizkes]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A woman sitting at a table with various objects on it, including a MacBook, a mug, a book, an opened notebook, and holding her head with her hands as if in frustration]]></media:description>                                                            <media:text><![CDATA[A woman sitting at a table with various objects on it, including a MacBook, a mug, a book, an opened notebook, and holding her head with her hands as if in frustration]]></media:text>
                                <media:title type="plain"><![CDATA[A woman sitting at a table with various objects on it, including a MacBook, a mug, a book, an opened notebook, and holding her head with her hands as if in frustration]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/toJsHzqsNXvBcnSCEFy6VL-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Privacy policies are famously difficult to read, and in the world of LLMs, they’re impenetrable and long</strong></li><li><strong>The policy for Meta’s Muse Spark is over 14,000 words long, taking almost an hour to read</strong></li><li><strong>Cybersecurity firm Bridewell carried out the study, assessing the privacy policies of 20 popular LLMs</strong></li></ul><p>When you input data into an AI chatbot, you expect it to interpret and process the words or numbers to save you time. But what is it doing with that data? You can check the privacy policy to find out – assuming, that is, that you have the time to do so. </p><p>A new study has found that the average time it takes to read a privacy policy for an LLM is 20 minutes – and some are a much longer read.</p><p>With around 75% of people admitting to using an AI chatbot at least once a month, understanding where the questions and data queries are going and how they are used is increasingly important.</p><h2 id="ease-of-reading">Ease of reading</h2><p>Privacy policies provide that understanding, but are they easy to read? A study by Bridewell’s cyber security experts suggests not, with many having a poor Fleisch Reading Ease Score, meaning that in layman’s terms, these documents are pretty impenetrable.</p><p>Bridewell’s study assessed privacy policies from 20 large language models (LLMs), and found that the average length of time to read one is 20 minutes. The average word count is 4,603, but the real challenge is understanding the information.</p><p>The Flesch Reading Ease Score is a measure of readability devised by Rudolf Flesch in 1948, and is widely used to score texts. A score over 60 is good, whereas a score below that is not. The average Flesch score for these privacy policies is 40.2, suggesting a degree of jargon-based density that most people will not understand.</p><p>How, then, might the general public safely use an LLM chatbot like ChatGPT or Google Gemini while in full knowledge of how the information they input is being used?</p><h2 id="training-on-inputs">Training on inputs</h2><p>In evaluating the LLMs, Bridewell found that 13 of the 20 use inputs and outputs to train their models. Some LLMs offer the option to opt out of training, but others do not. Even where an opt out is possible, it isn’t always clear how to action it.</p><p>“It’s essential for users to fully understand how their data is being processed by LLMs, and businesses need clear internal guidance on what can and can't be shared, and ideally proper enterprise accounts with the right protections in place," noted Chris Linnell, Associate Director of Data Privacy at Bridewell,  "employees may be at risk of sharing highly sensitive or confidential information that may end up being used to train LLMs.”</p><p>There isn’t just a personal risk from data input into an AI. Employees need to be aware of how they are using the technology for work.</p><p>As a rule of thumb, the more complex the LLM (e.g., Meta's Muse Spark, or Moonshot AI’s Kimi K), the longer the privacy policy takes to read. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft takes down AI-boosted phishing tool that hit 12,000 accounts ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft, UK police, and partners disrupted EvilTokens PhaaS, arresting two suspects and seizing 200+ domains/sites</strong></li><li><strong>EvilTokens used AI to scale device‑code phishing, compromising 12,000 inboxes across 10,000 organizations globally</strong></li><li><strong>Platform ran like a startup with subscriptions, dashboards, and AI‑driven targeting; US victims hit hardest</strong></li></ul><p>Two people have been arrested, 50 websites were seized, and 150 domains disabled, in a joint operation against the infamous EvilTokens phishing-as-a-service (PhaaS) kit. </p><p>In its <a href="https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/" target="_blank" rel="nofollow">report</a>, Microsoft said the UK Metropolitan Police Service’s cybercrime team “arrested two men on suspicion of offenses connected with the alleged operation of EvilTokens.”</p><p>The two men, whose identities were not disclosed, are aged 32 and 38, and have been released on bail, subject to conditions while the investigation continues. Their digital services and other items have been confiscated, as well.</p><p>Among the partners are Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. We don’t know if these arrests and takedowns will be enough to completely obliterate EvilTokens, or if the platform will continue to operate. Usually, criminal infrastructure is a lot less resilient to disruptions when arrests are made, compared to when law enforcement simply disables the hardware.</p><h2 id="the-tech-startup-of-organized-crime">The tech startup of organized crime</h2><p>EvilTokens has been turning heads for a little while now. The platform was first spotted in February 2026, rising quickly to become one of the most widely used PhaaS solutions out there. </p><p>It can be bought through Telegram for $1,500, after which there is a recurring $500 subscription cost. Cybercriminals use it to run large-scale, personalized phishing attacks: they can create spoofed websites, landing pages, and other credential-capture assets; they can create custom-tailored phishing emails, and can even grab session tokens, <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">one-time passwords</a>, and other codes designed to protect accounts against phishing, granting attackers access to people’s inboxes.</p><p>But what makes EvilTokens particularly impressive is its use of artificial intelligence. The platform comes with an <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI assistant</a> that can sift through the inboxes, suggest which targets are of high value, and even how to approach them. Attackers can conduct Microsoft Graph reconnaissance as well, mapping out organizational structure and permissions, keeping access and moving laterally throughout the target network. </p><p>Microsoft said it found evidence of large portions of EvilTokens being vibe coded, “with AI helping its creators build the platform itself.” </p><p>The researchers also found the platform drawing on capabilities from multiple AI models. Looking at the platform as a whole, it runs like a well-organized startup, with subscription pricing, customer support, management dashboards, and tools designed to move customers from account access toward financial exploitation.</p><p>According to Microsoft, EvilTokens facilitated business email compromise (BEC) campaigns that compromised more than 12,000 inboxes in more than 10,000 organizations worldwide. Victims are mostly in wholesale distribution, construction, and financial services, but those in real estate, higher education, and healthcare are not spared, either. </p><p>The victims are primarily located in the United States, with notable numbers found in Canada, the United Kingdom, Australia, India, and France. Microsoft said affected customers were notified, and that the company “helped remediate compromised accounts and shared intelligence to support further defensive and investigative action."</p><h2 id="popularizing-device-code-phishing">Popularizing device-code phishing</h2><p>Device-code phishing as an attack technique is not that new. More than a year ago, in February 2025, security researchers Huntress reported on Russian threat actors Storm-2372 deploying the same technique, and while it’s been steadily growing in popularity, it wasn’t until EvilTokens’ appearance that it really exploded.</p><p>The same researchers said, <a href="https://www.techradar.com/pro/security/organised-crime-operating-like-a-tech-startup-eviltoken-phaas-group-ramp-up-ai-enabled-attacks-by-1-380-percent-in-2026" target="_blank">in June 2026</a>, that EvilTokens was used to run 1,380% more device-code phishing attacks in 2026, compared to the same period last year. </p><p>“We’re seeing a clear maturation of the phishing-as-a-service (PhaaS) market as threat actors increasingly integrate AI workflows into their product offerings,” Huntress said in a report.</p><p>“The result is directly observable in our telemetry: a 1,380% increase in device code phishing attacks detected between July–December 2025 and January–April 2026, with over 50% of those incidents linked to two major waves of correlated incidents.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/microsoft-takes-down-ai-boosted-phishing-tool-that-hit-12-000-accounts</link>
                                                                            <description>
                            <![CDATA[ Two people arrested and dozens of websites seized in an organized operation against EvilTokens. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rjKiUdqjoeHAJDGLfcm4V6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/j5YMwZuuKnvAXLyKBEmDrb-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/j5YMwZuuKnvAXLyKBEmDrb-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / JLStock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.]]></media:description>                                                            <media:text><![CDATA[A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.]]></media:text>
                                <media:title type="plain"><![CDATA[A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/j5YMwZuuKnvAXLyKBEmDrb-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft, UK police, and partners disrupted EvilTokens PhaaS, arresting two suspects and seizing 200+ domains/sites</strong></li><li><strong>EvilTokens used AI to scale device‑code phishing, compromising 12,000 inboxes across 10,000 organizations globally</strong></li><li><strong>Platform ran like a startup with subscriptions, dashboards, and AI‑driven targeting; US victims hit hardest</strong></li></ul><p>Two people have been arrested, 50 websites were seized, and 150 domains disabled, in a joint operation against the infamous EvilTokens phishing-as-a-service (PhaaS) kit. </p><p>In its <a href="https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/" target="_blank" rel="nofollow">report</a>, Microsoft said the UK Metropolitan Police Service’s cybercrime team “arrested two men on suspicion of offenses connected with the alleged operation of EvilTokens.”</p><p>The two men, whose identities were not disclosed, are aged 32 and 38, and have been released on bail, subject to conditions while the investigation continues. Their digital services and other items have been confiscated, as well.</p><p>Among the partners are Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. We don’t know if these arrests and takedowns will be enough to completely obliterate EvilTokens, or if the platform will continue to operate. Usually, criminal infrastructure is a lot less resilient to disruptions when arrests are made, compared to when law enforcement simply disables the hardware.</p><h2 id="the-tech-startup-of-organized-crime">The tech startup of organized crime</h2><p>EvilTokens has been turning heads for a little while now. The platform was first spotted in February 2026, rising quickly to become one of the most widely used PhaaS solutions out there. </p><p>It can be bought through Telegram for $1,500, after which there is a recurring $500 subscription cost. Cybercriminals use it to run large-scale, personalized phishing attacks: they can create spoofed websites, landing pages, and other credential-capture assets; they can create custom-tailored phishing emails, and can even grab session tokens, <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">one-time passwords</a>, and other codes designed to protect accounts against phishing, granting attackers access to people’s inboxes.</p><p>But what makes EvilTokens particularly impressive is its use of artificial intelligence. The platform comes with an <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI assistant</a> that can sift through the inboxes, suggest which targets are of high value, and even how to approach them. Attackers can conduct Microsoft Graph reconnaissance as well, mapping out organizational structure and permissions, keeping access and moving laterally throughout the target network. </p><p>Microsoft said it found evidence of large portions of EvilTokens being vibe coded, “with AI helping its creators build the platform itself.” </p><p>The researchers also found the platform drawing on capabilities from multiple AI models. Looking at the platform as a whole, it runs like a well-organized startup, with subscription pricing, customer support, management dashboards, and tools designed to move customers from account access toward financial exploitation.</p><p>According to Microsoft, EvilTokens facilitated business email compromise (BEC) campaigns that compromised more than 12,000 inboxes in more than 10,000 organizations worldwide. Victims are mostly in wholesale distribution, construction, and financial services, but those in real estate, higher education, and healthcare are not spared, either. </p><p>The victims are primarily located in the United States, with notable numbers found in Canada, the United Kingdom, Australia, India, and France. Microsoft said affected customers were notified, and that the company “helped remediate compromised accounts and shared intelligence to support further defensive and investigative action."</p><h2 id="popularizing-device-code-phishing">Popularizing device-code phishing</h2><p>Device-code phishing as an attack technique is not that new. More than a year ago, in February 2025, security researchers Huntress reported on Russian threat actors Storm-2372 deploying the same technique, and while it’s been steadily growing in popularity, it wasn’t until EvilTokens’ appearance that it really exploded.</p><p>The same researchers said, <a href="https://www.techradar.com/pro/security/organised-crime-operating-like-a-tech-startup-eviltoken-phaas-group-ramp-up-ai-enabled-attacks-by-1-380-percent-in-2026" target="_blank">in June 2026</a>, that EvilTokens was used to run 1,380% more device-code phishing attacks in 2026, compared to the same period last year. </p><p>“We’re seeing a clear maturation of the phishing-as-a-service (PhaaS) market as threat actors increasingly integrate AI workflows into their product offerings,” Huntress said in a report.</p><p>“The result is directly observable in our telemetry: a 1,380% increase in device code phishing attacks detected between July–December 2025 and January–April 2026, with over 50% of those incidents linked to two major waves of correlated incidents.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Millions of Russian fast food fans hit in Burger King Russia hack ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Burger King Russia’s 2024 breach via Mindbox exposed 3.2 million customer records, now leaked online</strong></li><li><strong>Data includes emails, names, genders, birth dates, phone numbers, and geolocations (2018–2024)</strong></li><li><strong>Payment details weren’t compromised; users warned of phishing and identity theft risks</strong></li></ul><p>Back in 2024, the Russian arm of Burger King suffered a data breach at the hands of unknown threat actors - now, that data has finally been leaked online.</p><p>In October 2024, Burger King told TASS, Russia’s national news agency, that unidentified hackers attacked Mindbox, a domestic marketing automation platform the company had been using. </p><p>Through Mindbox, the crooks managed to obtain sensitive company data, including information belonging to the customers. </p><p>As a customer data and marketing automation platform, Mindbox helps businesses gather and use customer information for personalized, omnichannel marketing campaigns. Its tools cover email and SMS campaigns, push notifications, loyalty programs, chatbots, and more. According to the company, more than 1,100 businesses use its platform, including L’Oréal, Panasonic, KFC, JBL and United Colors of Benetton. </p><h2 id="one-victim-in-a-supply-chain-attack">One victim in a supply-chain attack</h2><p>At the time, there was no word on the nature of the information that was taken, apart from the fact that payment information was not compromised.</p><p>"Among the victims of the attack may also be the data of customers of the Burger King restaurant chain," the company said at the time. </p><p>“Burger King confirms that among the personal data, the accuracy of which is being clarified, there is no information about payment details: open information about transactions is not transmitted or stored by third parties.”</p><p>The details about the hack were also not disclosed. We don’t know if the platform contained a zero-day, or if a company employee had their login credentials or session tokens exposed. Third-party supply chain attacks such as this one are common and often rather disruptive, affecting numerous companies using the same tools. For Mindbox, however, there have been no reports of additional victims.</p><p>In its 2024 results announcement, Mindbox said the attack was its “first serious information security incident”, which was quickly detected and contained “thanks to threat detection tools.”</p><p>In the aftermath of the breach, Mindbox said it “found and eliminated points where employees without access rights to sensitive data could indirectly obtain them,” hinting that the attack was, in fact, an identity-based attack rather than a zero-day exploit.  </p><p>The company also “changed development processes to find such points before they get into the product,” and reformed Mindbox's internal role system to make permissions stricter and more granular. It also limited project access scenarios, introduced a mechanism for confirming access by another employee, and introduced mandatory two-factor authentication, among other things. </p><h2 id="have-you-been-pwned">Have you been pwned?</h2><p>Today, more details were released on Have I Been Pwned?, a website that aggregates information stolen in various hacks and helps people learn if their email addresses and other information had been compromised in the past. According to the newest entry, more than three million people have had their data exposed in this incident: </p><p>“The breach exposed 3.2M unique email addresses along with names, genders, dates of birth, phone numbers and approximate geolocations, with the data spanning 2018 to August 2024,” Have I Been Pwned? writes. “Burger King Russia acknowledged the incident and advised it did not include payment or passport details.”</p><p>The latest findings seem to be somewhat in line with what the media reported at the time. According to <a href="https://www.theregister.com/cyber-crime/2026/09/22/well-done-hack-flames-32m-burger-king-russia-users/5298114" target="_blank"><em>The Register</em></a>, initial reports claimed around 5.6 million lines of data as exposed, which included information about a customer’s favorite dish and previous order dates. While this information was not mentioned in the newest report, if every data line includes one email, one name, or one phone number, it could amount to around 5.6 million. </p><p>While the information might be a few years old, things like names and birth dates, and genders rarely change, but are vital in <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a>, social engineering, and similar attacks. Burger King users, especially those in Russia, should be wary of incoming email messages, particularly those claiming to come from the fast food chain.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/millions-of-russian-fast-food-fans-hit-in-burger-king-russia-hack</link>
                                                                            <description>
                            <![CDATA[ Data stolen years ago finally surfaced on the web, showing 3.2 million Burger King Russia victims. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qoXJPFHDttwNAv8LgcK5WZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aUiqncNLKM6YAYFyowvwPH-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 15:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aUiqncNLKM6YAYFyowvwPH-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images / NurPhoto]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Burger King shop]]></media:description>                                                            <media:text><![CDATA[Burger King shop]]></media:text>
                                <media:title type="plain"><![CDATA[Burger King shop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aUiqncNLKM6YAYFyowvwPH-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Burger King Russia’s 2024 breach via Mindbox exposed 3.2 million customer records, now leaked online</strong></li><li><strong>Data includes emails, names, genders, birth dates, phone numbers, and geolocations (2018–2024)</strong></li><li><strong>Payment details weren’t compromised; users warned of phishing and identity theft risks</strong></li></ul><p>Back in 2024, the Russian arm of Burger King suffered a data breach at the hands of unknown threat actors - now, that data has finally been leaked online.</p><p>In October 2024, Burger King told TASS, Russia’s national news agency, that unidentified hackers attacked Mindbox, a domestic marketing automation platform the company had been using. </p><p>Through Mindbox, the crooks managed to obtain sensitive company data, including information belonging to the customers. </p><p>As a customer data and marketing automation platform, Mindbox helps businesses gather and use customer information for personalized, omnichannel marketing campaigns. Its tools cover email and SMS campaigns, push notifications, loyalty programs, chatbots, and more. According to the company, more than 1,100 businesses use its platform, including L’Oréal, Panasonic, KFC, JBL and United Colors of Benetton. </p><h2 id="one-victim-in-a-supply-chain-attack">One victim in a supply-chain attack</h2><p>At the time, there was no word on the nature of the information that was taken, apart from the fact that payment information was not compromised.</p><p>"Among the victims of the attack may also be the data of customers of the Burger King restaurant chain," the company said at the time. </p><p>“Burger King confirms that among the personal data, the accuracy of which is being clarified, there is no information about payment details: open information about transactions is not transmitted or stored by third parties.”</p><p>The details about the hack were also not disclosed. We don’t know if the platform contained a zero-day, or if a company employee had their login credentials or session tokens exposed. Third-party supply chain attacks such as this one are common and often rather disruptive, affecting numerous companies using the same tools. For Mindbox, however, there have been no reports of additional victims.</p><p>In its 2024 results announcement, Mindbox said the attack was its “first serious information security incident”, which was quickly detected and contained “thanks to threat detection tools.”</p><p>In the aftermath of the breach, Mindbox said it “found and eliminated points where employees without access rights to sensitive data could indirectly obtain them,” hinting that the attack was, in fact, an identity-based attack rather than a zero-day exploit.  </p><p>The company also “changed development processes to find such points before they get into the product,” and reformed Mindbox's internal role system to make permissions stricter and more granular. It also limited project access scenarios, introduced a mechanism for confirming access by another employee, and introduced mandatory two-factor authentication, among other things. </p><h2 id="have-you-been-pwned">Have you been pwned?</h2><p>Today, more details were released on Have I Been Pwned?, a website that aggregates information stolen in various hacks and helps people learn if their email addresses and other information had been compromised in the past. According to the newest entry, more than three million people have had their data exposed in this incident: </p><p>“The breach exposed 3.2M unique email addresses along with names, genders, dates of birth, phone numbers and approximate geolocations, with the data spanning 2018 to August 2024,” Have I Been Pwned? writes. “Burger King Russia acknowledged the incident and advised it did not include payment or passport details.”</p><p>The latest findings seem to be somewhat in line with what the media reported at the time. According to <a href="https://www.theregister.com/cyber-crime/2026/09/22/well-done-hack-flames-32m-burger-king-russia-users/5298114" target="_blank"><em>The Register</em></a>, initial reports claimed around 5.6 million lines of data as exposed, which included information about a customer’s favorite dish and previous order dates. While this information was not mentioned in the newest report, if every data line includes one email, one name, or one phone number, it could amount to around 5.6 million. </p><p>While the information might be a few years old, things like names and birth dates, and genders rarely change, but are vital in <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a>, social engineering, and similar attacks. Burger King users, especially those in Russia, should be wary of incoming email messages, particularly those claiming to come from the fast food chain.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers hit the FBI — ShinyHunters say they have stolen 2TB of employee data, but the attack isn't looking for money, just an apology ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>ShinyHunters defaces FBI’s jobs site, claiming a PeopleSoft zero‑day let them steal 2TB of HR data</strong></li><li><strong>Group says attack is not for ransom but to dispute FBI’s May PSA alleging harassment and swatting tactics</strong></li><li><strong>Experts warn exploit itself is highly valuable; FBI site reclaimed, investigation ongoing into breach claims</strong></li></ul><p>The ShinyHunters extortion group is currently doing brand management in the most ShinyHunters way possible - by hacking into the FBI and stealing the agency’s sensitive files.</p><p>The Bureau’s jobs site was defaced and replaced with the usual ShinyHunters content - an ASCII image of the group’s logo, and a message saying “This site has been seized by ShinyHunters. Rooting your systems since ‘19 :)”. </p><p>But instead of putting the FBI on its data leak site and threatening to release stolen files if a ransom isn’t paid, ShinyHunters started speaking to the press, telling<em> </em><a href="https://www.theregister.com/security/2026/09/22/shinyhunters-claims-fbi-hack-this-is-not-financially-motivated/5298385" target="_blank"><em>The Register</em></a> it found a zero-day vulnerability in the Oracle PeopleSoft <a href="https://www.techradar.com/best/best-hr-software" target="_blank">human resource management</a> system, which allowed them to remotely execute arbitrary code on the underlying server.</p><p>They used this ability to (allegedly) steal more than 2TB of sensitive data from the FBI’s servers, including names, addresses, phone numbers, and information on spouses for current, former, and prospective FBI employees. </p><p>“We hold data on all FBI employees and applicants,” the spokesperson told <em>The Register</em>, noting they had compromised human resources, MedLink, and Criminal Justice Information Services.</p><h2 id="brand-management">Brand management</h2><p>The FBI has yet to comment, and so do both Oracle and AWS, but what’s most peculiar about this incident is that it doesn’t seem to be financially motivated. </p><p>So far, everything ShinyHunters’ have been doing was for the money. They would break into a company, steal their files, and then pressure the victims into paying a ransom demand in exchange for deleting the stolen information. This time around, the group claims the goal of the attack is to force the FBI to change the record on how it operates.</p><p>“This is NOT financially motivated,” the group told <em>The Register</em>. “We want the FBI to correct or retract their statements they made, which included substantial false allegations.”</p><p>The statements were made in a security bulletin published on May 15 this year, right after the Canvas attack. In early May 2026 Instructure, the edtech giant behind the popular Canvas learning system, <a href="https://www.techradar.com/pro/security/canvas-maker-instructure-reveals-data-breach-confirms-user-personal-information-leaked" target="_blank">confirmed suffering a cyberattack</a> and losing sensitive customer data. It was later disclosed that some of the world’s top universities, including <a href="https://www.techradar.com/pro/security/top-universities-among-victims-named-in-canvas-data-breach-mit-oxford-and-more-all-hit" target="_blank">Harvard, Oxford, and MIT</a>, were among the victims. </p><p>The attack was so disruptive that Instructure’s CEO was called to <a href="https://www.techradar.com/pro/security/us-congress-calls-instructure-ceo-as-it-investigates-canvas-breach" target="_blank">testify in front of the US House Committee on Homeland Security</a> a few weeks later.</p><p>On May 15, the FBI issued a <a href="https://www.ic3.gov/PSA/2026/PSA260515" target="_blank">public service announcement</a> (PSA) saying ShinyHunters “commonly use harassment strategies” to exert pressure on victims, including “sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting.”</p><p>Swatting means calling the police to report criminal activity so severe that the SWAT team is sent. This is usually done to live streamers as a practical, albeit life-threatening, joke. </p><p>“Threat actors may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist. Following these pressure tactics, SH actors have sometimes posted exfiltrated data to various iterations of the SH data leak site on the Tor network,” the PSA concluded.</p><p>“I have been doing my very best to combat these allegations,” ShinyHunters told the media. “And this is the best way to do it.” </p><h2 id="no-money">No money?</h2><p>Not everyone is sold on the idea that ShinyHunters isn’t doing this for the money. </p><p>In a statement shared with TechRadar Pro, CTO of Suzu Labs, Denis Calderone, said the claims should be taken with a grain of salt: “I have a hard time believing terabytes of FBI personnel data just sit on a shelf. Foreign intelligence services would love to have it, and having the FBI on their resume makes every future extortion demand more believable, and if the PeopleSoft zero-day is real, the exploit may be worth more than the data. Meanwhile, agents and their spouses could have their home addresses posted publicly within a week if this threat is followed through.”</p><p>Calderone also stressed that instead of focusing on the incident, people should be paying more attention to the zero-day.</p><p>“If you run PeopleSoft, don't wait for a patch. Get it off the public internet wherever you can, put what has to stay public behind a WAF, and make sure admin components like the /PSEMHUB/ path in their screenshot aren't reachable from outside. Hunt for the June indicators and for SSH attempts against the psoft and oracle accounts. Then ask yourself what your applicant portal can reach. At the FBI, a website built for strangers to upload resumes allegedly led straight into GovCloud.”</p><p>The FBI has since reclaimed its website, which now says it is under maintenance.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/hackers-hit-the-fbi-shinyhunters-say-they-have-stolen-2tb-of-employee-data-but-the-attack-isnt-looking-for-money-just-an-apology</link>
                                                                            <description>
                            <![CDATA[ ShinyHunters are looking to improve their standing in the public eye. What better way to do it than hacking the FBI? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wUwrCgcCY7Y4kmYfKW4prN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ri2dNNTvgmKGsMuhNDCavZ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 14:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Ri2dNNTvgmKGsMuhNDCavZ-1920-80.jpg">
                                                            <media:credit><![CDATA[Adobe]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Dark web monitoring]]></media:description>                                                            <media:text><![CDATA[Dark web monitoring]]></media:text>
                                <media:title type="plain"><![CDATA[Dark web monitoring]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ri2dNNTvgmKGsMuhNDCavZ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>ShinyHunters defaces FBI’s jobs site, claiming a PeopleSoft zero‑day let them steal 2TB of HR data</strong></li><li><strong>Group says attack is not for ransom but to dispute FBI’s May PSA alleging harassment and swatting tactics</strong></li><li><strong>Experts warn exploit itself is highly valuable; FBI site reclaimed, investigation ongoing into breach claims</strong></li></ul><p>The ShinyHunters extortion group is currently doing brand management in the most ShinyHunters way possible - by hacking into the FBI and stealing the agency’s sensitive files.</p><p>The Bureau’s jobs site was defaced and replaced with the usual ShinyHunters content - an ASCII image of the group’s logo, and a message saying “This site has been seized by ShinyHunters. Rooting your systems since ‘19 :)”. </p><p>But instead of putting the FBI on its data leak site and threatening to release stolen files if a ransom isn’t paid, ShinyHunters started speaking to the press, telling<em> </em><a href="https://www.theregister.com/security/2026/09/22/shinyhunters-claims-fbi-hack-this-is-not-financially-motivated/5298385" target="_blank"><em>The Register</em></a> it found a zero-day vulnerability in the Oracle PeopleSoft <a href="https://www.techradar.com/best/best-hr-software" target="_blank">human resource management</a> system, which allowed them to remotely execute arbitrary code on the underlying server.</p><p>They used this ability to (allegedly) steal more than 2TB of sensitive data from the FBI’s servers, including names, addresses, phone numbers, and information on spouses for current, former, and prospective FBI employees. </p><p>“We hold data on all FBI employees and applicants,” the spokesperson told <em>The Register</em>, noting they had compromised human resources, MedLink, and Criminal Justice Information Services.</p><h2 id="brand-management">Brand management</h2><p>The FBI has yet to comment, and so do both Oracle and AWS, but what’s most peculiar about this incident is that it doesn’t seem to be financially motivated. </p><p>So far, everything ShinyHunters’ have been doing was for the money. They would break into a company, steal their files, and then pressure the victims into paying a ransom demand in exchange for deleting the stolen information. This time around, the group claims the goal of the attack is to force the FBI to change the record on how it operates.</p><p>“This is NOT financially motivated,” the group told <em>The Register</em>. “We want the FBI to correct or retract their statements they made, which included substantial false allegations.”</p><p>The statements were made in a security bulletin published on May 15 this year, right after the Canvas attack. In early May 2026 Instructure, the edtech giant behind the popular Canvas learning system, <a href="https://www.techradar.com/pro/security/canvas-maker-instructure-reveals-data-breach-confirms-user-personal-information-leaked" target="_blank">confirmed suffering a cyberattack</a> and losing sensitive customer data. It was later disclosed that some of the world’s top universities, including <a href="https://www.techradar.com/pro/security/top-universities-among-victims-named-in-canvas-data-breach-mit-oxford-and-more-all-hit" target="_blank">Harvard, Oxford, and MIT</a>, were among the victims. </p><p>The attack was so disruptive that Instructure’s CEO was called to <a href="https://www.techradar.com/pro/security/us-congress-calls-instructure-ceo-as-it-investigates-canvas-breach" target="_blank">testify in front of the US House Committee on Homeland Security</a> a few weeks later.</p><p>On May 15, the FBI issued a <a href="https://www.ic3.gov/PSA/2026/PSA260515" target="_blank">public service announcement</a> (PSA) saying ShinyHunters “commonly use harassment strategies” to exert pressure on victims, including “sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting.”</p><p>Swatting means calling the police to report criminal activity so severe that the SWAT team is sent. This is usually done to live streamers as a practical, albeit life-threatening, joke. </p><p>“Threat actors may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist. Following these pressure tactics, SH actors have sometimes posted exfiltrated data to various iterations of the SH data leak site on the Tor network,” the PSA concluded.</p><p>“I have been doing my very best to combat these allegations,” ShinyHunters told the media. “And this is the best way to do it.” </p><h2 id="no-money">No money?</h2><p>Not everyone is sold on the idea that ShinyHunters isn’t doing this for the money. </p><p>In a statement shared with TechRadar Pro, CTO of Suzu Labs, Denis Calderone, said the claims should be taken with a grain of salt: “I have a hard time believing terabytes of FBI personnel data just sit on a shelf. Foreign intelligence services would love to have it, and having the FBI on their resume makes every future extortion demand more believable, and if the PeopleSoft zero-day is real, the exploit may be worth more than the data. Meanwhile, agents and their spouses could have their home addresses posted publicly within a week if this threat is followed through.”</p><p>Calderone also stressed that instead of focusing on the incident, people should be paying more attention to the zero-day.</p><p>“If you run PeopleSoft, don't wait for a patch. Get it off the public internet wherever you can, put what has to stay public behind a WAF, and make sure admin components like the /PSEMHUB/ path in their screenshot aren't reachable from outside. Hunt for the June indicators and for SSH attempts against the psoft and oracle accounts. Then ask yourself what your applicant portal can reach. At the FBI, a website built for strangers to upload resumes allegedly led straight into GovCloud.”</p><p>The FBI has since reclaimed its website, which now says it is under maintenance.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LinkedIn is making it easier for you to get verified - and to hopefully cut back on scams and AI slop ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>LinkedIn reveals more move to help users and business verify on the site</strong></li><li><strong>Users will now be able to ask their network for references in verification</strong></li><li><strong>Businesses can cut off those pretending to be employees</strong></li></ul><p>LinkedIn has revealed new methods to help expand verification on its site in the latest battle against fake accounts and AI slop.</p><p>The social media network is making a stand in order to ensure its platform focuses on what it says matters most - helping users build grow a business-focused network.</p><p>It's not just users either - the move will also mean that businesses will be able to better protect their brand reputation on the site thanks to new controls and tools.</p><h2 id="verification-improvements">Verification improvements</h2><p>First up for users is a new way to ensure verification is as effective as it can be. LinkedIn users will now be able to ask people in their network to verify connections to those they have worked or studied with - and when the user receives enough confirmations, LinkedIn adds a verification badge to their Profile, with the option to opt out. </p><p>LinkedIn says this method helps add "peer-backed credibility and reassurance", and says it will also soon let members proactively ask their connections to verify their experiences, helping members build authenticity through their professional network.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:420px;"><p class="vanilla-image-block" style="padding-top:200.95%;"><img id="fabQws24aUPm77uU47oJQU" name="employee-disassociation" alt="LinkedIn disassociating employee from page" src="https://cdn.mos.cms.futurecdn.net/fabQws24aUPm77uU47oJQU-1920-80.gif" mos="" align="middle" fullscreen="" width="420" height="844" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: LinkedIn)</span></figcaption></figure><p>For businesses themselves, looking to protect their brand from employee impersonation, LinkedIn will now let Company Page Admins, who have verified their Page, instantly remove known imposter accounts, meaning they can no longer appear in search results under their company name. The platform is also testing a pilot which will give companies the ability to require workplace verification for anyone claiming current employment at their organization to associate with their Page. </p><p>"As AI reshapes the workplace, trust has become our most valuable professional asset," Oscar Rodriguez, VP of Trust Product at LinkedIn wrote in a blog post announcing the news.</p><p>"LinkedIn has invested tens of millions of dollars in verification, helping to build a more trusted professional community where more than 115 million members have now verified their identity or workplace for free. Now, we’re continuing our expansion of verification across LinkedIn and integrating with new partners, giving members more ways to verify who they are and more signals to help you know who’s real and credible, both on and off LinkedIn."</p><p>The expansion isn't just limited to LinkedIn, as the site is also allowing verified members to show off their status on partner platforms too. Truecaller and Peerspot have joined existing partners including Adobe, giving users on those platforms extra peace of mind that the person messaging them really is who they say they are.</p><p>"Whether you’re a member verifying the credibility and experience of a former colleague, a business protecting its brand reputation, or a platform looking to integrate LinkedIn trust signals, you are helping build a more trusted network where professionals can connect with confidence," noted Rodriguez.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/linkedin-is-making-it-easier-for-you-to-get-verified-and-to-hopefully-cut-back-on-scams-and-ai-slop</link>
                                                                            <description>
                            <![CDATA[ LinkedIn looks to try and expand trust with new verification tools and more. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jHQwzFzVdJ5QxyWGBYwN8D</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9ydusJngspE6Lvc3RSYuFo-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                                                                                    <dc:creator><![CDATA[ Mike Moore ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vinm2oPWMvB8yMg7qLhtxg-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C technology journalist for over a decade, including at one of the UK&#039;s leading national newspapers and fellow Future title ITProPortal, covering everything from cybersecurity to phone reviews to VR at the Winter Olympics.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Mike is the main editorial contact for TechRadar Pro, responsible for the news content across the site, as well as managing the contributed content. PRs looking to pitch news stories, bylines/analysis pieces or event invitations should get in contact via the email address mentioned above.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;He has a Masters degree in American Studies from the University of Nottingham, along with a BA in American &amp; English Studies from the same institution. When he&#039;s not keeping track of all the latest enterprise and workplace trends, he can most likely be found watching, following or taking part in some kind of sport.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9ydusJngspE6Lvc3RSYuFo-1920-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image credit: Pixabay]]></media:description>                                                            <media:text><![CDATA[Business software]]></media:text>
                                <media:title type="plain"><![CDATA[Business software]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9ydusJngspE6Lvc3RSYuFo-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>LinkedIn reveals more move to help users and business verify on the site</strong></li><li><strong>Users will now be able to ask their network for references in verification</strong></li><li><strong>Businesses can cut off those pretending to be employees</strong></li></ul><p>LinkedIn has revealed new methods to help expand verification on its site in the latest battle against fake accounts and AI slop.</p><p>The social media network is making a stand in order to ensure its platform focuses on what it says matters most - helping users build grow a business-focused network.</p><p>It's not just users either - the move will also mean that businesses will be able to better protect their brand reputation on the site thanks to new controls and tools.</p><h2 id="verification-improvements">Verification improvements</h2><p>First up for users is a new way to ensure verification is as effective as it can be. LinkedIn users will now be able to ask people in their network to verify connections to those they have worked or studied with - and when the user receives enough confirmations, LinkedIn adds a verification badge to their Profile, with the option to opt out. </p><p>LinkedIn says this method helps add "peer-backed credibility and reassurance", and says it will also soon let members proactively ask their connections to verify their experiences, helping members build authenticity through their professional network.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:420px;"><p class="vanilla-image-block" style="padding-top:200.95%;"><img id="fabQws24aUPm77uU47oJQU" name="employee-disassociation" alt="LinkedIn disassociating employee from page" src="https://cdn.mos.cms.futurecdn.net/fabQws24aUPm77uU47oJQU-1920-80.gif" mos="" align="middle" fullscreen="" width="420" height="844" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: LinkedIn)</span></figcaption></figure><p>For businesses themselves, looking to protect their brand from employee impersonation, LinkedIn will now let Company Page Admins, who have verified their Page, instantly remove known imposter accounts, meaning they can no longer appear in search results under their company name. The platform is also testing a pilot which will give companies the ability to require workplace verification for anyone claiming current employment at their organization to associate with their Page. </p><p>"As AI reshapes the workplace, trust has become our most valuable professional asset," Oscar Rodriguez, VP of Trust Product at LinkedIn wrote in a blog post announcing the news.</p><p>"LinkedIn has invested tens of millions of dollars in verification, helping to build a more trusted professional community where more than 115 million members have now verified their identity or workplace for free. Now, we’re continuing our expansion of verification across LinkedIn and integrating with new partners, giving members more ways to verify who they are and more signals to help you know who’s real and credible, both on and off LinkedIn."</p><p>The expansion isn't just limited to LinkedIn, as the site is also allowing verified members to show off their status on partner platforms too. Truecaller and Peerspot have joined existing partners including Adobe, giving users on those platforms extra peace of mind that the person messaging them really is who they say they are.</p><p>"Whether you’re a member verifying the credibility and experience of a former colleague, a business protecting its brand reputation, or a platform looking to integrate LinkedIn trust signals, you are helping build a more trusted network where professionals can connect with confidence," noted Rodriguez.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ After DSIT, Britain’s next AI test is sovereignty ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The abolition of the Department for Science, Innovation and Technology has created uncertainty about what happens next to Britain’s AI ambitions.</p><p>Kanishka Narayan’s promotion to Minister for AI gives the technology a dedicated voice at Cabinet, yet folding DSIT’s responsibilities into other departments raises questions about how the Government will coordinate the <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, investment and public-sector adoption needed to support those ambitions.</p><p>Recent parliamentary scrutiny of critical public-sector AI contracts has highlighted growing pressure on institutions to strengthen control over AI operations and deployment continuity. Britain has focused on adoption speed; the next step is operational control in ongoing public-service AI use.</p><p>The case for sovereign AI is becoming stronger as a result. Britain needs more than access to capable models; it needs controlled operations for the services that depend on them, even when a provider, contract or political relationship changes.</p><h2 id="sovereignty-goes-further-than-where-data-sits">Sovereignty goes further than where data sits</h2><p>Sovereign AI is often reduced to <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> residency, with the assumption that keeping information inside Britain is enough to keep it under British control. Data location remains important, particularly in healthcare, defense and public administration, but it describes only one part of the relationship between an organization and the technology it uses.</p><p>A hospital could store every patient record in a British data center while relying on models and <a href="https://www.techradar.com/best/best-data-recovery-software">software</a> that only the original provider can operate or modify. Where that provider is based remains relevant, but the more useful test of sovereignty is whether the hospital can understand the system, govern how it is used and continue running it if the commercial relationship changes.</p><p>An organization should know how its systems operate, determine which data a model can access and retain the ability to move a workload or introduce another model without rebuilding the entire service. Once that system becomes essential, it also needs enough internal expertise to keep it running rather than discovering that continuity depends on the decisions of one supplier.</p><p>Britain does not need to reproduce every layer of the stack, but it does need predictable control where public services run. Modern AI draws on international research, complex supply chains and open-source projects, and recreating them domestically would consume enormous resources without necessarily producing better technology.</p><p>As DSIT’s responsibilities move across Whitehall, the Government needs to decide which dependencies it can accept without threatening security, public trust or an essential service.</p><h2 id="capability-and-control-can-reinforce-one-another">Capability and control can reinforce one another</h2><p>Government AI plans sometimes present sovereignty as the slower alternative to using the largest commercial models, as though Britain must choose between world-class AI and control over its deployment. That assumes every organization needs the same frontier system, when the question is which model suits the work.</p><p>For many public workloads, a fit-for-purpose model in a controlled environment is more valuable than one large generic option, especially when governance obligations are strict.</p><p>A specialized model can be adapted to the organization's data, tested under the conditions in which it will operate and governed according to the consequences of getting a decision wrong. In those circumstances, greater control can make the system more useful as well as more independent.</p><p>Open and portable technology can support this approach by allowing organizations to run models across different infrastructure, examine how systems behave and replace components as better options emerge.</p><p>Openness does not guarantee sovereignty, since organizations still need secure infrastructure, skilled teams and clear governance, but it reduces the chance that an entire service becomes inseparable from one provider’s platform.</p><p>I have seen the AI market move quickly enough to make that flexibility increasingly valuable. The best model for a task today may be overtaken within months, while pricing, regulation and access can change almost as quickly.</p><p>An organization that builds around one proprietary service may struggle to benefit from that progress, whereas one that controls the environment in which its models operate can introduce better technology without starting again.</p><h2 id="government-can-turn-sovereignty-into-capability">Government can turn sovereignty into capability</h2><p>Britain already has many of the ingredients it needs, including strong universities, experienced researchers, growing AI companies and public investment in compute. The next step is to connect those assets with sustained demand in the parts of the public sector where sovereignty has the greatest practical value.</p><p>Government does not need to select one national champion or exclude international companies. It can create a market in which providers compete while public bodies retain control of the systems they buy.</p><p>Procurement rules for critical AI could require workloads to be portable, independently testable and capable of running within infrastructure controlled by the <a href="https://www.techradar.com/best/cx-tools">customer</a>, making the ability to change course part of the original decision rather than a problem discovered at the end of a contract.</p><p>This would give hospitals, councils and government departments credible sovereign options while providing British AI companies with a route from pilots to long-term deployment. It would encourage partnerships in which knowledge and operational authority remain with the institution responsible for the service, even when private companies provide the technology and expertise.</p><p>The restructuring of DSIT should be treated as an opportunity to clarify Britain’s objective rather than reduce its ambition. A Minister for AI can bring different parts of government together, but the strategy should be judged by whether public institutions can use the best technology available while retaining meaningful control of the systems that matter most.</p><p>That is what will allow Britain’s AI ambitions to endure as departments, suppliers and technologies change.</p><p><em></em><a href="https://www.techradar.com/best/best-ai-tools"><em>We've featured the best AI tool.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/after-dsit-britains-next-ai-test-is-sovereignty</link>
                                                                            <description>
                            <![CDATA[ DSIT is gone, but the case for sovereign AI in public services has strengthened. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VgFqKojbhQ7BrbUwP2jyvV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DqdzLoiEh9a6yFQaZqE6xL-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 11:01:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Simone Giacomelli ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DqdzLoiEh9a6yFQaZqE6xL-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A portion of the globe with countries displayed in digital pixels]]></media:description>                                                            <media:text><![CDATA[A portion of the globe with countries displayed in digital pixels]]></media:text>
                                <media:title type="plain"><![CDATA[A portion of the globe with countries displayed in digital pixels]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DqdzLoiEh9a6yFQaZqE6xL-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The abolition of the Department for Science, Innovation and Technology has created uncertainty about what happens next to Britain’s AI ambitions.</p><p>Kanishka Narayan’s promotion to Minister for AI gives the technology a dedicated voice at Cabinet, yet folding DSIT’s responsibilities into other departments raises questions about how the Government will coordinate the <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, investment and public-sector adoption needed to support those ambitions.</p><p>Recent parliamentary scrutiny of critical public-sector AI contracts has highlighted growing pressure on institutions to strengthen control over AI operations and deployment continuity. Britain has focused on adoption speed; the next step is operational control in ongoing public-service AI use.</p><p>The case for sovereign AI is becoming stronger as a result. Britain needs more than access to capable models; it needs controlled operations for the services that depend on them, even when a provider, contract or political relationship changes.</p><h2 id="sovereignty-goes-further-than-where-data-sits">Sovereignty goes further than where data sits</h2><p>Sovereign AI is often reduced to <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> residency, with the assumption that keeping information inside Britain is enough to keep it under British control. Data location remains important, particularly in healthcare, defense and public administration, but it describes only one part of the relationship between an organization and the technology it uses.</p><p>A hospital could store every patient record in a British data center while relying on models and <a href="https://www.techradar.com/best/best-data-recovery-software">software</a> that only the original provider can operate or modify. Where that provider is based remains relevant, but the more useful test of sovereignty is whether the hospital can understand the system, govern how it is used and continue running it if the commercial relationship changes.</p><p>An organization should know how its systems operate, determine which data a model can access and retain the ability to move a workload or introduce another model without rebuilding the entire service. Once that system becomes essential, it also needs enough internal expertise to keep it running rather than discovering that continuity depends on the decisions of one supplier.</p><p>Britain does not need to reproduce every layer of the stack, but it does need predictable control where public services run. Modern AI draws on international research, complex supply chains and open-source projects, and recreating them domestically would consume enormous resources without necessarily producing better technology.</p><p>As DSIT’s responsibilities move across Whitehall, the Government needs to decide which dependencies it can accept without threatening security, public trust or an essential service.</p><h2 id="capability-and-control-can-reinforce-one-another">Capability and control can reinforce one another</h2><p>Government AI plans sometimes present sovereignty as the slower alternative to using the largest commercial models, as though Britain must choose between world-class AI and control over its deployment. That assumes every organization needs the same frontier system, when the question is which model suits the work.</p><p>For many public workloads, a fit-for-purpose model in a controlled environment is more valuable than one large generic option, especially when governance obligations are strict.</p><p>A specialized model can be adapted to the organization's data, tested under the conditions in which it will operate and governed according to the consequences of getting a decision wrong. In those circumstances, greater control can make the system more useful as well as more independent.</p><p>Open and portable technology can support this approach by allowing organizations to run models across different infrastructure, examine how systems behave and replace components as better options emerge.</p><p>Openness does not guarantee sovereignty, since organizations still need secure infrastructure, skilled teams and clear governance, but it reduces the chance that an entire service becomes inseparable from one provider’s platform.</p><p>I have seen the AI market move quickly enough to make that flexibility increasingly valuable. The best model for a task today may be overtaken within months, while pricing, regulation and access can change almost as quickly.</p><p>An organization that builds around one proprietary service may struggle to benefit from that progress, whereas one that controls the environment in which its models operate can introduce better technology without starting again.</p><h2 id="government-can-turn-sovereignty-into-capability">Government can turn sovereignty into capability</h2><p>Britain already has many of the ingredients it needs, including strong universities, experienced researchers, growing AI companies and public investment in compute. The next step is to connect those assets with sustained demand in the parts of the public sector where sovereignty has the greatest practical value.</p><p>Government does not need to select one national champion or exclude international companies. It can create a market in which providers compete while public bodies retain control of the systems they buy.</p><p>Procurement rules for critical AI could require workloads to be portable, independently testable and capable of running within infrastructure controlled by the <a href="https://www.techradar.com/best/cx-tools">customer</a>, making the ability to change course part of the original decision rather than a problem discovered at the end of a contract.</p><p>This would give hospitals, councils and government departments credible sovereign options while providing British AI companies with a route from pilots to long-term deployment. It would encourage partnerships in which knowledge and operational authority remain with the institution responsible for the service, even when private companies provide the technology and expertise.</p><p>The restructuring of DSIT should be treated as an opportunity to clarify Britain’s objective rather than reduce its ambition. A Minister for AI can bring different parts of government together, but the strategy should be judged by whether public institutions can use the best technology available while retaining meaningful control of the systems that matter most.</p><p>That is what will allow Britain’s AI ambitions to endure as departments, suppliers and technologies change.</p><p><em></em><a href="https://www.techradar.com/best/best-ai-tools"><em>We've featured the best AI tool.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The case for purpose-built generative AI in fraud prevention ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Financial crime has never stood still. In my nearly three decades in <a href="https://www.techradar.com/best/best-personal-finance-software">financial</a> services, I have watched fraud move in lockstep with the technology built to stop it, and at times, even stay a step ahead of it​,​ given the speed fraudsters adopt new technology.  </p><p>I have witnessed decades of AI innovation ​that raised​ the bar on fraud detection, yet criminals continue to test those boundaries. Fraud remains a top consumer concern, with over ​87.5 million American adults experiencing a scam or financial fraud each year. That’s roughly one in every three American adults.</p><p>The question for financial institutions isn't whether AI has a place in fraud prevention​,​ but whether the AI they've deployed is built for the threat landscape they're facing today – and the one that's coming. </p><h2 id="compute-has-finally-caught-up-with-mathematical-vision">Compute has finally caught up with mathematical vision</h2><p>For decades, <a href="https://www.techradar.com/best/best-database-software">data</a> scientists working on fraud prevention had theories they couldn't implement. The ideas were sound, but the computers at the time weren't powerful enough to get the math done. That constraint no longer exists.</p><p>Historically, most fraud detection has been carried out by building a profile summarizing a customer's typical behavior using sophisticated features, a neural network, and the customer’s current transaction to flag transactions that are suspicious. It's an approach constrained by the computational limitations of time.</p><p>Today, access to <a href="https://www.techradar.com/news/computing-components/graphics-cards/best-graphics-cards-1291458">GPU</a> and other high-performance compute is changing the art of the possible. Rather than analyzing a transaction in the context of a profile, GPUs allow us to implement entirely new algorithms that can evaluate a customer's extensive transaction history in real-time as the transaction happens.</p><p>The result is a significantly sharper, more accurate prediction and far fewer false alarms that can delay or stop legitimate purchases​,​ eroding customer trust. </p><h2 id="built-for-one-job-not-every-job">Built for one job, not every job</h2><p>Thanks to greater GPU availability and computational power, we're now seeing new opportunities to support fraud prevention with a sequence-modeling transformer – not a generic transformer, but one purpose-built for transaction analytics and financial crime.</p><p>With a purpose-built transformer architecture that’s trained exclusively on financial transaction data and engineered for a single focused task, financial services institutions can detect financial crime in real time using deep personalization and the context of the customer transaction history.</p><p>These are not overarching ‘do everything’ models. They are focused foundation models purpose-built to deliver auditable, high-performing, low-latency generative AI for the fight against financial crime. Each of these models specializes in distinct areas, such as account takeover, scams, mule detection, and first-party misuse.</p><p>Independent models focused on their specialty allow for a more complete, accurate, and transparent picture than any single model working alone. And this is just the start​,​ as the same methodology applies to risk decisions, hardship, collections, and any application where understanding our <a href="https://www.techradar.com/best/best-customer-feedback-tools?gad=1">customers</a> leads to better engagement, protection, and service.  </p><h2 id="the-future-is-now">The future is now</h2><p>The fraud prevention capabilities that will define the next five years are being built right now. Enterprises investing in protecting customers from fraud – both now and in the future – understand that purpose-built models, use of specialized compute, and AI agents are the path to protecting their customers.</p><p>The math protecting consumers today was invented decades ago by AI scientists who saw the potential in algorithms even before the compute and <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> existed. I've spent much of my career continually chasing that goal to ensure that the industry is ready to bring the best algorithms when compute shows up.</p><p>Some of my proudest work came from refusing to settle and trust that technology will catch up with AI invention and math. Every patent, every model, every AI experiment has served the same purpose: making sure the industry is ready to lead with the best <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> once compute catches up with scientific invention.</p><p>That work is happening right now. The only question is whether ​​​​​​financial institutions are​​ part of it or racing to catch up.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've featured the best antivirus software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/the-case-for-purpose-built-generative-ai-in-fraud-prevention</link>
                                                                            <description>
                            <![CDATA[ Financial institutions must determine whether the AI they've deployed is built for today's and tomorrow's threat landscape. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dGF9MKCbpAXPvsthwaaee8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 10:30:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Scott Zoldi ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / ZinetroN]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Nytt DDoS-rekord]]></media:description>                                                            <media:text><![CDATA[Concept art representing cybersecurity principles]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art representing cybersecurity principles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Financial crime has never stood still. In my nearly three decades in <a href="https://www.techradar.com/best/best-personal-finance-software">financial</a> services, I have watched fraud move in lockstep with the technology built to stop it, and at times, even stay a step ahead of it​,​ given the speed fraudsters adopt new technology.  </p><p>I have witnessed decades of AI innovation ​that raised​ the bar on fraud detection, yet criminals continue to test those boundaries. Fraud remains a top consumer concern, with over ​87.5 million American adults experiencing a scam or financial fraud each year. That’s roughly one in every three American adults.</p><p>The question for financial institutions isn't whether AI has a place in fraud prevention​,​ but whether the AI they've deployed is built for the threat landscape they're facing today – and the one that's coming. </p><h2 id="compute-has-finally-caught-up-with-mathematical-vision">Compute has finally caught up with mathematical vision</h2><p>For decades, <a href="https://www.techradar.com/best/best-database-software">data</a> scientists working on fraud prevention had theories they couldn't implement. The ideas were sound, but the computers at the time weren't powerful enough to get the math done. That constraint no longer exists.</p><p>Historically, most fraud detection has been carried out by building a profile summarizing a customer's typical behavior using sophisticated features, a neural network, and the customer’s current transaction to flag transactions that are suspicious. It's an approach constrained by the computational limitations of time.</p><p>Today, access to <a href="https://www.techradar.com/news/computing-components/graphics-cards/best-graphics-cards-1291458">GPU</a> and other high-performance compute is changing the art of the possible. Rather than analyzing a transaction in the context of a profile, GPUs allow us to implement entirely new algorithms that can evaluate a customer's extensive transaction history in real-time as the transaction happens.</p><p>The result is a significantly sharper, more accurate prediction and far fewer false alarms that can delay or stop legitimate purchases​,​ eroding customer trust. </p><h2 id="built-for-one-job-not-every-job">Built for one job, not every job</h2><p>Thanks to greater GPU availability and computational power, we're now seeing new opportunities to support fraud prevention with a sequence-modeling transformer – not a generic transformer, but one purpose-built for transaction analytics and financial crime.</p><p>With a purpose-built transformer architecture that’s trained exclusively on financial transaction data and engineered for a single focused task, financial services institutions can detect financial crime in real time using deep personalization and the context of the customer transaction history.</p><p>These are not overarching ‘do everything’ models. They are focused foundation models purpose-built to deliver auditable, high-performing, low-latency generative AI for the fight against financial crime. Each of these models specializes in distinct areas, such as account takeover, scams, mule detection, and first-party misuse.</p><p>Independent models focused on their specialty allow for a more complete, accurate, and transparent picture than any single model working alone. And this is just the start​,​ as the same methodology applies to risk decisions, hardship, collections, and any application where understanding our <a href="https://www.techradar.com/best/best-customer-feedback-tools?gad=1">customers</a> leads to better engagement, protection, and service.  </p><h2 id="the-future-is-now">The future is now</h2><p>The fraud prevention capabilities that will define the next five years are being built right now. Enterprises investing in protecting customers from fraud – both now and in the future – understand that purpose-built models, use of specialized compute, and AI agents are the path to protecting their customers.</p><p>The math protecting consumers today was invented decades ago by AI scientists who saw the potential in algorithms even before the compute and <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> existed. I've spent much of my career continually chasing that goal to ensure that the industry is ready to bring the best algorithms when compute shows up.</p><p>Some of my proudest work came from refusing to settle and trust that technology will catch up with AI invention and math. Every patent, every model, every AI experiment has served the same purpose: making sure the industry is ready to lead with the best <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> once compute catches up with scientific invention.</p><p>That work is happening right now. The only question is whether ​​​​​​financial institutions are​​ part of it or racing to catch up.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've featured the best antivirus software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Customize your AI generated website: A step-by-step guide ]]></title>
                                                                                                <dc:content><![CDATA[ <p>You typed a few prompts into an <a href="https://www.techradar.com/pro/best-ai-website-builder" target="_blank">AI website builder</a> and had a full site minutes later. It looks promising at first glance, but closer observation reveals it probably looks a lot like every other business in your industry. </p><p>Most people reach for these tools because they're short on time, budget, or both. You want something live today, without sinking funds into a six-week build from a developer. But there’s a substantial gap between going live and a website that actually works for your business. That’s exactly what my AI website customization guide covers.</p><h2 class="article-body__section" id="section-where-do-ai-generated-websites-fall-short"><span>Where do AI-generated websites fall short?</span></h2><p>AI builders are trained on patterns from thousands of existing sites, so they tend to reproduce the same layouts and headline structures. One review of AI builders found that training on top-performing sites means the tools "find and copy the optimal design," which is efficient but produces cookie-cutter results. If a competitor used the same tool, your sites may look closer to twins than rivals.</p><p>The code underneath often carries its own baggage. AI-generated pages tend to ship with bloated CSS and redundant scripts that hurt Core Web Vitals scores, according to multiple industry analyses. This costs you twice, in visitors who leave and in search rankings that suffer for it.</p><p>Security is another potential blind spot among AI-generated sites. <a href="https://dev.to/razazu/i-scanned-447-websites-ai-built-sites-have-3x-more-high-severity-vulnerabilities-3708" target="_blank" rel="nofollow">A recent scan of 447 live websites</a> found that AI-built sites averaged 2.1 high-severity vulnerabilities each, compared with 0.7 for human-built sites, largely because the tools skip protections nobody explicitly asked for, like security headers and rate limiting. AI systems are good at building features that work, but far less reliable at adding safeguards nobody prompted them to include.</p><p>Then there's the content itself. AI copy tends toward vague, interchangeable phrasing, since the model is guessing at your specifics rather than pulling from verified facts, which can mean misstated details about your products or services. That doesn't make AI builders useless: it just means the output is a first draft, not a finished product.</p><h2 class="article-body__section" id="section-7-tips-for-customizing-ai-generated-websites"><span>7 tips for customizing AI-generated websites</span></h2><p>The good news is that most of these problems are fixable without hiring a full development team. You're not starting from scratch. You're editing a draft, which is a much faster process than building a site from a blank page.</p><p>The tips below cover the areas that need the most attention once an AI tool finishes its pass. Work through them in order, since sorting out navigation first tends to make the later steps easier to spot.</p><p><strong>#1 Rebuild the menu around what customers search for</strong></p><p>AI builders often generate menus based on generic templates rather than how your customers actually think about your business. Important services can end up buried two clicks deep. Labels often use internal jargon instead of the words customers actually search for.</p><p>Walk through your own site as if you were a first-time visitor looking for your most requested product or service. If it takes more than two clicks to find, restructure the menu around that task rather than around your org chart. Test it on mobile too, since AI builders often collapse menus into hamburger icons without checking how usable they actually are.</p><p><strong>#2 Cut the AI's boilerplate phrases</strong></p><p>Look out for filler lines like "we provide high-quality, all-in-one solutions tailored to your unique needs." That kind of phrasing shows up constantly in AI drafts because the model has no specific facts to work with, so it defaults to language that could describe any business.</p><p>Replace it with details only you would know, like how long you've operated and what results real customers have actually seen. Specific language builds the credibility that generic phrasing can't. Reading each page out loud helps too, since AI phrasing tends to reveal itself the moment you hear it spoken back to you.</p><p><strong>#3 Fact-check every price, spec, and product claim</strong></p><p>AI models can invent plausible-sounding specifications, pricing, or availability when they don't have accurate source data to draw from. That's a real risk on e-commerce or service pages, where a wrong price or feature claim turns into a customer complaint later.</p><p>Go line by line through every product description, price, and spec sheet the AI generated. Cross-check each one against your actual inventory or service list before the site goes live. Pay close attention to anything the tool invented outright, like sizing charts or shipping timelines it had no real data to draw from.</p><p><strong>#4 Swap the stock photos for real ones</strong></p><p>The photos an AI builder pulls in are usually generic stock images chosen for visual polish rather than relevance to your business. Visitors have seen the same handshake-and-laptop photos on dozens of other sites. That sameness undercuts the trust you're trying to build.</p><p>Swap in real photos of your team, workspace, or product wherever you can. Even a handful placed in key spots, like your homepage and about page, makes the rest of the site feel more credible. A phone camera and decent lighting usually beat another stock photo of strangers shaking hands.</p><p><strong>#5 Test every booking, payment, and CRM connection</strong></p><p>Booking systems, payment processors, and CRMs often don't connect cleanly to AI-generated code, since the builder isn't working within a platform's standard hooks and APIs. Forms can silently fail to submit, or analytics tags can stop firing without any visible error.</p><p>Test every integration yourself: submit a real form, run a test transaction, and confirm the data lands where it should. Don't assume a feature works just because it appears on the page. Repeat the test after any major edit, since a single code change can quietly break a connection that worked fine the day before.</p><p><strong>#6 Fill in the title tags and schema that AI skipped</strong></p><p>Search engines and AI-powered answer tools rely on structured data to understand what a page is actually about, and AI builders frequently skip or half-fill this layer. Missing title tags and thin meta descriptions make it harder for your pages to surface in search results or AI-generated summaries.</p><p>Check each page's title tag, meta description, and heading structure. Then add schema markup for the basics, like your business address and hours, since this is one of the highest-value fixes on this list. A free tool like Google's Rich Results Test can confirm the markup is actually valid before you move on.</p><p><strong>#7 Turn on two-factor authentication and audit your forms</strong></p><p>Most AI builders leave meaningful gaps in default security configuration, including weak or absent security headers and missing rate limiting on login attempts. Privacy policies often read like placeholder text too, rather than an accurate account of what data you actually collect. Wix's own guidance to users flags two-factor authentication as the single highest-value fix available.</p><p>Confirm your SSL certificate is active and enable two-factor authentication on your admin account. Then remove unused contributor access and audit every form to make sure your privacy policy matches what you're actually collecting. Most of these checks take just minutes and rarely need repeating.</p><h2 class="article-body__section" id="section-should-you-generate-websites-with-ai"><span>Should you generate websites with AI?</span></h2><p>AI website builders solve a real problem by getting a functional site online without months of development time or a large budget. For a single-page portfolio, a quick landing page, or a proof of concept, the convenience outweighs the trade-offs.</p><p>A quick freelancer profile or a temporary event page rarely needs the same scrutiny as a site people will use to make a purchase decision. That’s why you should match your review effort to what's actually riding on the page. The more money or personal data changes hands there, the more that first draft needs a second look.</p><p>Tradeoffs show up as the site grows in importance. Convenience upfront translates into review time later, since the quality of the final result tracks closely with how much of that review you put in. Without review, a site tends to read as generic, sometimes with serious accuracy or security problems a customer finds before you do.</p><p>I always advise treating the AI output as a first draft rather than a finished site. Put in work so the result stops looking like a slightly different version of every other AI-built site out there. You should also budget time to check facts and close the security gaps the AI skipped on its own. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/customize-your-ai-generated-website-a-step-by-step-guide</link>
                                                                            <description>
                            <![CDATA[ AI builders get your website online fast, but the default results still need some work. Here's what to fix and why it matters. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pDr2tE3bpPPyvMmTiq74QG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UG5iuffDbLXwkTnLsQhRoZ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 10:29:39 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Website Building]]></category>
                                                                                                <author><![CDATA[ ritoban@nutgraf.agency (Ritoban Mukherjee) ]]></author>                    <dc:creator><![CDATA[ Ritoban Mukherjee ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/cD9joj4H54xYmooW8re3vU-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UG5iuffDbLXwkTnLsQhRoZ-1920-80.jpg">
                                                            <media:credit><![CDATA[Generated with Gemini ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A woman sat at a desk editing an AI generated website ]]></media:description>                                                            <media:text><![CDATA[A woman sat at a desk editing an AI generated website ]]></media:text>
                                <media:title type="plain"><![CDATA[A woman sat at a desk editing an AI generated website ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UG5iuffDbLXwkTnLsQhRoZ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>You typed a few prompts into an <a href="https://www.techradar.com/pro/best-ai-website-builder" target="_blank">AI website builder</a> and had a full site minutes later. It looks promising at first glance, but closer observation reveals it probably looks a lot like every other business in your industry. </p><p>Most people reach for these tools because they're short on time, budget, or both. You want something live today, without sinking funds into a six-week build from a developer. But there’s a substantial gap between going live and a website that actually works for your business. That’s exactly what my AI website customization guide covers.</p><h2 class="article-body__section" id="section-where-do-ai-generated-websites-fall-short"><span>Where do AI-generated websites fall short?</span></h2><p>AI builders are trained on patterns from thousands of existing sites, so they tend to reproduce the same layouts and headline structures. One review of AI builders found that training on top-performing sites means the tools "find and copy the optimal design," which is efficient but produces cookie-cutter results. If a competitor used the same tool, your sites may look closer to twins than rivals.</p><p>The code underneath often carries its own baggage. AI-generated pages tend to ship with bloated CSS and redundant scripts that hurt Core Web Vitals scores, according to multiple industry analyses. This costs you twice, in visitors who leave and in search rankings that suffer for it.</p><p>Security is another potential blind spot among AI-generated sites. <a href="https://dev.to/razazu/i-scanned-447-websites-ai-built-sites-have-3x-more-high-severity-vulnerabilities-3708" target="_blank" rel="nofollow">A recent scan of 447 live websites</a> found that AI-built sites averaged 2.1 high-severity vulnerabilities each, compared with 0.7 for human-built sites, largely because the tools skip protections nobody explicitly asked for, like security headers and rate limiting. AI systems are good at building features that work, but far less reliable at adding safeguards nobody prompted them to include.</p><p>Then there's the content itself. AI copy tends toward vague, interchangeable phrasing, since the model is guessing at your specifics rather than pulling from verified facts, which can mean misstated details about your products or services. That doesn't make AI builders useless: it just means the output is a first draft, not a finished product.</p><h2 class="article-body__section" id="section-7-tips-for-customizing-ai-generated-websites"><span>7 tips for customizing AI-generated websites</span></h2><p>The good news is that most of these problems are fixable without hiring a full development team. You're not starting from scratch. You're editing a draft, which is a much faster process than building a site from a blank page.</p><p>The tips below cover the areas that need the most attention once an AI tool finishes its pass. Work through them in order, since sorting out navigation first tends to make the later steps easier to spot.</p><p><strong>#1 Rebuild the menu around what customers search for</strong></p><p>AI builders often generate menus based on generic templates rather than how your customers actually think about your business. Important services can end up buried two clicks deep. Labels often use internal jargon instead of the words customers actually search for.</p><p>Walk through your own site as if you were a first-time visitor looking for your most requested product or service. If it takes more than two clicks to find, restructure the menu around that task rather than around your org chart. Test it on mobile too, since AI builders often collapse menus into hamburger icons without checking how usable they actually are.</p><p><strong>#2 Cut the AI's boilerplate phrases</strong></p><p>Look out for filler lines like "we provide high-quality, all-in-one solutions tailored to your unique needs." That kind of phrasing shows up constantly in AI drafts because the model has no specific facts to work with, so it defaults to language that could describe any business.</p><p>Replace it with details only you would know, like how long you've operated and what results real customers have actually seen. Specific language builds the credibility that generic phrasing can't. Reading each page out loud helps too, since AI phrasing tends to reveal itself the moment you hear it spoken back to you.</p><p><strong>#3 Fact-check every price, spec, and product claim</strong></p><p>AI models can invent plausible-sounding specifications, pricing, or availability when they don't have accurate source data to draw from. That's a real risk on e-commerce or service pages, where a wrong price or feature claim turns into a customer complaint later.</p><p>Go line by line through every product description, price, and spec sheet the AI generated. Cross-check each one against your actual inventory or service list before the site goes live. Pay close attention to anything the tool invented outright, like sizing charts or shipping timelines it had no real data to draw from.</p><p><strong>#4 Swap the stock photos for real ones</strong></p><p>The photos an AI builder pulls in are usually generic stock images chosen for visual polish rather than relevance to your business. Visitors have seen the same handshake-and-laptop photos on dozens of other sites. That sameness undercuts the trust you're trying to build.</p><p>Swap in real photos of your team, workspace, or product wherever you can. Even a handful placed in key spots, like your homepage and about page, makes the rest of the site feel more credible. A phone camera and decent lighting usually beat another stock photo of strangers shaking hands.</p><p><strong>#5 Test every booking, payment, and CRM connection</strong></p><p>Booking systems, payment processors, and CRMs often don't connect cleanly to AI-generated code, since the builder isn't working within a platform's standard hooks and APIs. Forms can silently fail to submit, or analytics tags can stop firing without any visible error.</p><p>Test every integration yourself: submit a real form, run a test transaction, and confirm the data lands where it should. Don't assume a feature works just because it appears on the page. Repeat the test after any major edit, since a single code change can quietly break a connection that worked fine the day before.</p><p><strong>#6 Fill in the title tags and schema that AI skipped</strong></p><p>Search engines and AI-powered answer tools rely on structured data to understand what a page is actually about, and AI builders frequently skip or half-fill this layer. Missing title tags and thin meta descriptions make it harder for your pages to surface in search results or AI-generated summaries.</p><p>Check each page's title tag, meta description, and heading structure. Then add schema markup for the basics, like your business address and hours, since this is one of the highest-value fixes on this list. A free tool like Google's Rich Results Test can confirm the markup is actually valid before you move on.</p><p><strong>#7 Turn on two-factor authentication and audit your forms</strong></p><p>Most AI builders leave meaningful gaps in default security configuration, including weak or absent security headers and missing rate limiting on login attempts. Privacy policies often read like placeholder text too, rather than an accurate account of what data you actually collect. Wix's own guidance to users flags two-factor authentication as the single highest-value fix available.</p><p>Confirm your SSL certificate is active and enable two-factor authentication on your admin account. Then remove unused contributor access and audit every form to make sure your privacy policy matches what you're actually collecting. Most of these checks take just minutes and rarely need repeating.</p><h2 class="article-body__section" id="section-should-you-generate-websites-with-ai"><span>Should you generate websites with AI?</span></h2><p>AI website builders solve a real problem by getting a functional site online without months of development time or a large budget. For a single-page portfolio, a quick landing page, or a proof of concept, the convenience outweighs the trade-offs.</p><p>A quick freelancer profile or a temporary event page rarely needs the same scrutiny as a site people will use to make a purchase decision. That’s why you should match your review effort to what's actually riding on the page. The more money or personal data changes hands there, the more that first draft needs a second look.</p><p>Tradeoffs show up as the site grows in importance. Convenience upfront translates into review time later, since the quality of the final result tracks closely with how much of that review you put in. Without review, a site tends to read as generic, sometimes with serious accuracy or security problems a customer finds before you do.</p><p>I always advise treating the AI output as a first draft rather than a finished site. Put in work so the result stops looking like a slightly different version of every other AI-built site out there. You should also budget time to check facts and close the security gaps the AI skipped on its own. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Palantir CEO Alex Karp reckons OpenAI will never IPO — mainly due to the huge amount of liability it carries ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Palantir CEO Alex Karp says frontier AI labs may end up nationalized because of the potentially unlimited liability they carry</strong></li><li><strong>When asked how those risks could be disclosed in an S-1 IPO filing, Karp challenged the premise itself, saying: “You’re assuming that there will be an S-1.”</strong></li><li><strong>His argument centers around the assumption that large AI-related liabilities ultimately require government intervention at some level, even as OpenAI's CEO Sam Altman ruled out an IPO in 2026, citing AI safety concerns</strong></li></ul><p>Palantir CEO Alex Karp has cast doubt on whether the frontier AI labs will ever reach the public markets.</p><p>A <a href="https://x.com/guilleflorvs/status/2101995999463981492" target="_blank" rel="nofollow">widely shared post on X by Guillermo Flor</a> summarized Karp as saying OpenAI will never IPO, that there may be no S-1 in play, and that nationalization is the only real exit because the liability exposure from frontier AI is so large that "no public market could potentially absorb it."</p><p>His comments brought renewed focus on OpenAI and Anthropic, both of which have recently pledged to prioritize AI safety and "pacing the frontier" of development but have both released new versions of their AI models this week (GPT-6 Sol, Luna, and Opus 5.5).</p><h2 id="a-case-made-by-focusing-on-potential-liabilities">A case made by focusing on potential liabilities</h2><p>The comments come from Karp's September 17 appearance on CNBC's Squawk on the Street. In a <a href="https://www.realclearpolitics.com/video/2026/09/19/alex_karp_ai_companies_wont_say_they_want_to_be_nationalized_but_theyre_leading_you_to_that_conclusion.html" target="_blank" rel="nofollow">transcript of the segment published by RealClearPolitics</a>, a host asks how the liability Karp has been describing would be written into an S-1, and what the risk factors would sound like.</p><p>Karp's answer was one that sent shockwaves in an industry already pricing in potentially two trillion-dollar IPOs in the near future: "You're assuming that there will be an S-1. Okay. Maybe there will be."</p><p>He argued that the only way to handle that liability is to ask the government to nationalize said frontier labs, adding that companies often lead you to a conclusion rather than stating what they want outright.</p><p>The truth may be more complex: OpenAI <a href="https://openai.com/index/openai-submits-confidential-s-1/" target="_blank" rel="nofollow">confirmed on June 8</a> that it had confidentially submitted a draft S-1 to the SEC, while noting that some of what it wants to do is "likely easier as a private company." Anthropic made its own confidential submission a week earlier.</p><p>Neither company, however, has issued a public S-1 registration statement, using existing regulations to keep its financials private for now. OpenAI also pushed back its own timetable before Karp's statements. In an interview <a href="https://fortune.com/2026/09/12/sam-altman-openai-ipo-delay-ill-advised-moment-safety-concerns/" target="_blank" rel="nofollow">published by Fortune on September 12</a>, Sam Altman said, "right now would be an ill-advised moment to go public," confirming there would be no listing in 2026 and citing safety and alignment work.</p><h2 id="not-entirely-an-honest-ai-broker">Not entirely an honest AI broker</h2><p>This is not a new position for Palantir's CEO; in June, <a href="https://finance.yahoo.com/economy/policy/articles/palantir-ceo-alex-karp-says-113108344.html" target="_blank" rel="nofollow">Benzinga reported</a> that he spent six months privately warning AI executives about nationalization, telling an interviewer, "The momentum is on the side of people who want to nationalize them." </p><p>He also has a <a href="https://www.techradar.com/pro/something-has-gone-completely-wrong-palantir-ceo-alex-karp-slams-openai-says-ai-industry-is-effing-insane" target="_blank">commercial interest in the argument</a>, as Palantir sells software built on the premise that enterprises keep their data in-house, and in an August CNBC interview, Karp argued that businesses should control their own models and lean less on the frontier labs' token-based business model.  On September 17, per Stocktwits, he again pointed to open models as a way for companies to keep control of their data.</p><p>His position rests on the belief that frontier labs carry liability only the government can absorb, that their appetite for regulation partly aims to limit that exposure, and that investors expecting blockbuster listings may be misreading the risk. Whether the delayed OpenAI IPO eventually culminates in some form of nationalization, regulatory oversight, or both remains to be seen.</p><p>What is certain, however, is that both Anthropic and OpenAI need billions of dollars to keep training their models and meet compute commitments in the near future, and they might turn to a source that seemed unlikely to some in the industry less than half a year ago: the US federal government.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/palantir-ceo-alex-karp-reckons-openai-will-never-ipo-mainly-due-to-the-huge-amount-of-liability-it-carries</link>
                                                                            <description>
                            <![CDATA[ Karp thinks liability could push AI labs like OpenAI toward Washington rather than Wall Street, with their planned IPOs never materializing. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eHgpL37Pf4X5o4XvD9tGiM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6X3ZZcXUrcxus6MyJ3GM7M-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 10:27:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6X3ZZcXUrcxus6MyJ3GM7M-1920-80.jpg">
                                                            <media:credit><![CDATA[OpenAI]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI logo]]></media:description>                                                            <media:text><![CDATA[OpenAI logo]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6X3ZZcXUrcxus6MyJ3GM7M-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Palantir CEO Alex Karp says frontier AI labs may end up nationalized because of the potentially unlimited liability they carry</strong></li><li><strong>When asked how those risks could be disclosed in an S-1 IPO filing, Karp challenged the premise itself, saying: “You’re assuming that there will be an S-1.”</strong></li><li><strong>His argument centers around the assumption that large AI-related liabilities ultimately require government intervention at some level, even as OpenAI's CEO Sam Altman ruled out an IPO in 2026, citing AI safety concerns</strong></li></ul><p>Palantir CEO Alex Karp has cast doubt on whether the frontier AI labs will ever reach the public markets.</p><p>A <a href="https://x.com/guilleflorvs/status/2101995999463981492" target="_blank" rel="nofollow">widely shared post on X by Guillermo Flor</a> summarized Karp as saying OpenAI will never IPO, that there may be no S-1 in play, and that nationalization is the only real exit because the liability exposure from frontier AI is so large that "no public market could potentially absorb it."</p><p>His comments brought renewed focus on OpenAI and Anthropic, both of which have recently pledged to prioritize AI safety and "pacing the frontier" of development but have both released new versions of their AI models this week (GPT-6 Sol, Luna, and Opus 5.5).</p><h2 id="a-case-made-by-focusing-on-potential-liabilities">A case made by focusing on potential liabilities</h2><p>The comments come from Karp's September 17 appearance on CNBC's Squawk on the Street. In a <a href="https://www.realclearpolitics.com/video/2026/09/19/alex_karp_ai_companies_wont_say_they_want_to_be_nationalized_but_theyre_leading_you_to_that_conclusion.html" target="_blank" rel="nofollow">transcript of the segment published by RealClearPolitics</a>, a host asks how the liability Karp has been describing would be written into an S-1, and what the risk factors would sound like.</p><p>Karp's answer was one that sent shockwaves in an industry already pricing in potentially two trillion-dollar IPOs in the near future: "You're assuming that there will be an S-1. Okay. Maybe there will be."</p><p>He argued that the only way to handle that liability is to ask the government to nationalize said frontier labs, adding that companies often lead you to a conclusion rather than stating what they want outright.</p><p>The truth may be more complex: OpenAI <a href="https://openai.com/index/openai-submits-confidential-s-1/" target="_blank" rel="nofollow">confirmed on June 8</a> that it had confidentially submitted a draft S-1 to the SEC, while noting that some of what it wants to do is "likely easier as a private company." Anthropic made its own confidential submission a week earlier.</p><p>Neither company, however, has issued a public S-1 registration statement, using existing regulations to keep its financials private for now. OpenAI also pushed back its own timetable before Karp's statements. In an interview <a href="https://fortune.com/2026/09/12/sam-altman-openai-ipo-delay-ill-advised-moment-safety-concerns/" target="_blank" rel="nofollow">published by Fortune on September 12</a>, Sam Altman said, "right now would be an ill-advised moment to go public," confirming there would be no listing in 2026 and citing safety and alignment work.</p><h2 id="not-entirely-an-honest-ai-broker">Not entirely an honest AI broker</h2><p>This is not a new position for Palantir's CEO; in June, <a href="https://finance.yahoo.com/economy/policy/articles/palantir-ceo-alex-karp-says-113108344.html" target="_blank" rel="nofollow">Benzinga reported</a> that he spent six months privately warning AI executives about nationalization, telling an interviewer, "The momentum is on the side of people who want to nationalize them." </p><p>He also has a <a href="https://www.techradar.com/pro/something-has-gone-completely-wrong-palantir-ceo-alex-karp-slams-openai-says-ai-industry-is-effing-insane" target="_blank">commercial interest in the argument</a>, as Palantir sells software built on the premise that enterprises keep their data in-house, and in an August CNBC interview, Karp argued that businesses should control their own models and lean less on the frontier labs' token-based business model.  On September 17, per Stocktwits, he again pointed to open models as a way for companies to keep control of their data.</p><p>His position rests on the belief that frontier labs carry liability only the government can absorb, that their appetite for regulation partly aims to limit that exposure, and that investors expecting blockbuster listings may be misreading the risk. Whether the delayed OpenAI IPO eventually culminates in some form of nationalization, regulatory oversight, or both remains to be seen.</p><p>What is certain, however, is that both Anthropic and OpenAI need billions of dollars to keep training their models and meet compute commitments in the near future, and they might turn to a source that seemed unlikely to some in the industry less than half a year ago: the US federal government.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI floods security teams with findings. The advantage is in what happens next ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Over the past year, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> teams on our platform cut the time it takes to fix a critical vulnerability by roughly 50%. In the same period, their backlog of unresolved critical vulnerabilities grew nearly 29-fold. These numbers describe the problem every security leader is about to inherit.</p><p>AI can now test software at a scale manual testing never reached. Models read code and search thousands of assets for familiar vulnerability patterns, surfacing exposures earlier and faster than any human team could.</p><p>For businesses trying to keep pace with an expanding attack surface, that reach is genuinely valuable. It is also exposing a weakness that has drawn far less attention: most organizations cannot validate, prioritize and remediate findings at anything close to the rate AI can produce them.</p><p>That imbalance is the whole game now. Investment in AI discovery tools, on its own, does not make an organization more secure. It makes it busier. Left unaddressed, it leaves security teams with larger backlogs and less attention paid to the flaws that actually put the business at risk.</p><p>This is the problem Continuous Threat Exposure Management (CTEM) exists to solve. CTEM gives organizations a continuous process for understanding their attack surface, finding weaknesses, proving which are genuinely exploitable, and directing remediation towards the exposures that carry the most <a href="https://www.techradar.com/best/best-small-business-software">business</a> risk. Discovery is one input. The advantage comes from everything after it.</p><h2 id="the-gap-between-discovery-and-remediation-is-widening">The gap between discovery and remediation is widening</h2><p>Security leaders have long treated discovery as a capacity problem: test more assets, cover more code, catch weaknesses earlier. AI answers that question decisively. But finding a potential vulnerability is the start of the work, not the end of it.</p><p>Every finding still has to be confirmed as exploitable and judged for severity in the specific context where the technology runs. Then it has to reach the right engineering team, win out against existing priorities, get fixed, and be retested to prove the fix holds. AI compresses the first step and barely touches the rest.</p><p>That is why the two numbers I opened with can both be true. A rising count of findings can mean better coverage. Faster repairs can sit alongside a growing backlog when discovery accelerates faster than remediation and engineering capacity moves the other way. Neither figure means much alone. The only view that matters runs the entire route, from first detection to verified fix.</p><h2 id="validation-is-the-choke-point">Validation is the choke point</h2><p>AI has also driven down the cost of producing a convincing security report. Some of those reports point to real weaknesses. Others duplicate known findings, misread the target, or describe theoretical issues that carry little real risk. Everyone still has to be investigated. A report that takes seconds to generate can consume hours of an experienced analyst's time before it can be dismissed with confidence.</p><p>At enterprise scale, that is how urgent findings get buried. A well-evidenced vulnerability with a credible attack path lands in the same queue as hundreds of submissions that sound plausible and lead nowhere. Security teams have to separate the AI gold from the AI slop, decide which real findings matter most, and do it with engineering capacity that has not grown to match.</p><p>Program owners need clear standards for evidence to make that possible. Researchers should be expected to show the likely business impact and demonstrate how a vulnerability reproduces, with automated tooling used to raise the quality of that evidence rather than the volume of submissions.</p><p>A consistent track record of valid findings tells a program owner whose work deserves attention first. That record is worth more, not less, as submissions rise.</p><h2 id="business-context-still-decides-what-matters">Business context still decides what matters</h2><p>Technical severity is only part of what you need to know to decide what to fix first. AI can match a finding to known patterns and reason over the systems it can reach. What it rarely has is the full picture the business holds: which services generate revenue, where regulated data lives, which dependencies make downtime especially expensive, and what compensating controls already exist.</p><p>The harder problem is combination. Individual findings that look moderate on their own can form a serious attack path once someone understands how the systems interact, which permissions can be abused, and where controls break down across organizational boundaries.</p><p>That is human work. And it is better human work when it is diverse: one researcher goes deep on identity controls, another on <a href="https://www.techradar.com/pro/software-services/best-serp-scraper-api-of-year">API</a> behavior, another on how minor weaknesses chain together across systems. That variety surfaces novel attack paths that automation, and even advanced cyber-models, miss.  </p><p>Our own data shows what that work is worth. Researchers earned more than $47 million on the H1 Platform in the first half of this year, up more than 25% year on year. The strongest earners are the ones who can explain business impact and show exactly how a weakness can be used.</p><p>That is also where researchers add the most to a CTEM program: testing whether an exposure holds up under real conditions, and spotting the connections between weaknesses that look harmless in isolation.</p><p>That figure deserves an honest footnote. Aggregate earnings rising does not mean every researcher is winning. As AI absorbs the routine, high-frequency findings, the researchers who once made a living there feel the change first, while those who can chain weaknesses, reason about business logic and produce credible proof find their work worth more.</p><p>The job of any serious bug bounty platform is to make that a transition its community can move through, not a wall most of them hit.</p><p>That obligation runs both ways. If programs expect researchers to raise the quality of their evidence, researchers should expect fast and fair triage in return, real recourse when a valid report is wrongly dismissed, and a door that stays open to newcomers who have not yet built a reputation.</p><p>The best researchers increasingly use <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> themselves, and the value of a report has never turned on whether a tool helped produce it. Protect the economics and the fairness that reward credible work, and the independent research community grows stronger as AI scales, not thinner.</p><h2 id="build-for-the-volume-ai-creates">Build for the volume AI creates</h2><p>So, is bug bounty dead? Far from it. Assume discovery will only accelerate, and put the effort into everything that happens after a flaw is found.</p><p>More discovery puts more pressure on the point where reports are validated and handed to engineering. Without enough triage capacity, well-evidenced findings stall behind automated noise.</p><p>Without clear ownership, confirmed risks sit in the gap between security and development. Independent verification matters at the other end too, especially when an AI system proposes the fix and may carry the same blind spot into its judgement of whether that fix works.</p><p>Boards and executive teams need measures built on risk reduction, not activity. Finding counts are easy to report and can climb even as an organization gets safer. Confirmed exploitability, remediation speed, recurrence, and the size of the unresolved critical backlog tell the real story.</p><p>CTEM holds those activities together as a continuous process, keeping discovery, validation, prioritization and remediation connected as the attack surface changes. It gives security leaders an honest view of where they are gaining ground and where exposure is still building.</p><p>The next phase of AI security will not be won on discovery. Discovery is already abundant. It will be won on response: knowing which findings represent real exposure, and moving the most dangerous of them through to a verified fix. AI supplies the reach. Independent researchers supply the judgement and the adversarial creativity AI still lacks.</p><p>The organizations that build to convert both into action will pull ahead. The ones that do not will own a faster-growing list of vulnerabilities they never fixed.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/ai-floods-security-teams-with-findings-the-advantage-is-in-what-happens-next</link>
                                                                            <description>
                            <![CDATA[ AI is accelerating vulnerability discovery, but organizations must strengthen validation, prioritization and remediation to reduce risk. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6VKQUihP8ctFbFMov75WZX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 09:28:21 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kara Sprague ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/mvaqapkAHBjuCFZnCVR99m-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1920-80.jpg">
                                                            <media:credit><![CDATA[Blue Planet Studio/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:description>                                                            <media:text><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:text>
                                <media:title type="plain"><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Over the past year, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> teams on our platform cut the time it takes to fix a critical vulnerability by roughly 50%. In the same period, their backlog of unresolved critical vulnerabilities grew nearly 29-fold. These numbers describe the problem every security leader is about to inherit.</p><p>AI can now test software at a scale manual testing never reached. Models read code and search thousands of assets for familiar vulnerability patterns, surfacing exposures earlier and faster than any human team could.</p><p>For businesses trying to keep pace with an expanding attack surface, that reach is genuinely valuable. It is also exposing a weakness that has drawn far less attention: most organizations cannot validate, prioritize and remediate findings at anything close to the rate AI can produce them.</p><p>That imbalance is the whole game now. Investment in AI discovery tools, on its own, does not make an organization more secure. It makes it busier. Left unaddressed, it leaves security teams with larger backlogs and less attention paid to the flaws that actually put the business at risk.</p><p>This is the problem Continuous Threat Exposure Management (CTEM) exists to solve. CTEM gives organizations a continuous process for understanding their attack surface, finding weaknesses, proving which are genuinely exploitable, and directing remediation towards the exposures that carry the most <a href="https://www.techradar.com/best/best-small-business-software">business</a> risk. Discovery is one input. The advantage comes from everything after it.</p><h2 id="the-gap-between-discovery-and-remediation-is-widening">The gap between discovery and remediation is widening</h2><p>Security leaders have long treated discovery as a capacity problem: test more assets, cover more code, catch weaknesses earlier. AI answers that question decisively. But finding a potential vulnerability is the start of the work, not the end of it.</p><p>Every finding still has to be confirmed as exploitable and judged for severity in the specific context where the technology runs. Then it has to reach the right engineering team, win out against existing priorities, get fixed, and be retested to prove the fix holds. AI compresses the first step and barely touches the rest.</p><p>That is why the two numbers I opened with can both be true. A rising count of findings can mean better coverage. Faster repairs can sit alongside a growing backlog when discovery accelerates faster than remediation and engineering capacity moves the other way. Neither figure means much alone. The only view that matters runs the entire route, from first detection to verified fix.</p><h2 id="validation-is-the-choke-point">Validation is the choke point</h2><p>AI has also driven down the cost of producing a convincing security report. Some of those reports point to real weaknesses. Others duplicate known findings, misread the target, or describe theoretical issues that carry little real risk. Everyone still has to be investigated. A report that takes seconds to generate can consume hours of an experienced analyst's time before it can be dismissed with confidence.</p><p>At enterprise scale, that is how urgent findings get buried. A well-evidenced vulnerability with a credible attack path lands in the same queue as hundreds of submissions that sound plausible and lead nowhere. Security teams have to separate the AI gold from the AI slop, decide which real findings matter most, and do it with engineering capacity that has not grown to match.</p><p>Program owners need clear standards for evidence to make that possible. Researchers should be expected to show the likely business impact and demonstrate how a vulnerability reproduces, with automated tooling used to raise the quality of that evidence rather than the volume of submissions.</p><p>A consistent track record of valid findings tells a program owner whose work deserves attention first. That record is worth more, not less, as submissions rise.</p><h2 id="business-context-still-decides-what-matters">Business context still decides what matters</h2><p>Technical severity is only part of what you need to know to decide what to fix first. AI can match a finding to known patterns and reason over the systems it can reach. What it rarely has is the full picture the business holds: which services generate revenue, where regulated data lives, which dependencies make downtime especially expensive, and what compensating controls already exist.</p><p>The harder problem is combination. Individual findings that look moderate on their own can form a serious attack path once someone understands how the systems interact, which permissions can be abused, and where controls break down across organizational boundaries.</p><p>That is human work. And it is better human work when it is diverse: one researcher goes deep on identity controls, another on <a href="https://www.techradar.com/pro/software-services/best-serp-scraper-api-of-year">API</a> behavior, another on how minor weaknesses chain together across systems. That variety surfaces novel attack paths that automation, and even advanced cyber-models, miss.  </p><p>Our own data shows what that work is worth. Researchers earned more than $47 million on the H1 Platform in the first half of this year, up more than 25% year on year. The strongest earners are the ones who can explain business impact and show exactly how a weakness can be used.</p><p>That is also where researchers add the most to a CTEM program: testing whether an exposure holds up under real conditions, and spotting the connections between weaknesses that look harmless in isolation.</p><p>That figure deserves an honest footnote. Aggregate earnings rising does not mean every researcher is winning. As AI absorbs the routine, high-frequency findings, the researchers who once made a living there feel the change first, while those who can chain weaknesses, reason about business logic and produce credible proof find their work worth more.</p><p>The job of any serious bug bounty platform is to make that a transition its community can move through, not a wall most of them hit.</p><p>That obligation runs both ways. If programs expect researchers to raise the quality of their evidence, researchers should expect fast and fair triage in return, real recourse when a valid report is wrongly dismissed, and a door that stays open to newcomers who have not yet built a reputation.</p><p>The best researchers increasingly use <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> themselves, and the value of a report has never turned on whether a tool helped produce it. Protect the economics and the fairness that reward credible work, and the independent research community grows stronger as AI scales, not thinner.</p><h2 id="build-for-the-volume-ai-creates">Build for the volume AI creates</h2><p>So, is bug bounty dead? Far from it. Assume discovery will only accelerate, and put the effort into everything that happens after a flaw is found.</p><p>More discovery puts more pressure on the point where reports are validated and handed to engineering. Without enough triage capacity, well-evidenced findings stall behind automated noise.</p><p>Without clear ownership, confirmed risks sit in the gap between security and development. Independent verification matters at the other end too, especially when an AI system proposes the fix and may carry the same blind spot into its judgement of whether that fix works.</p><p>Boards and executive teams need measures built on risk reduction, not activity. Finding counts are easy to report and can climb even as an organization gets safer. Confirmed exploitability, remediation speed, recurrence, and the size of the unresolved critical backlog tell the real story.</p><p>CTEM holds those activities together as a continuous process, keeping discovery, validation, prioritization and remediation connected as the attack surface changes. It gives security leaders an honest view of where they are gaining ground and where exposure is still building.</p><p>The next phase of AI security will not be won on discovery. Discovery is already abundant. It will be won on response: knowing which findings represent real exposure, and moving the most dangerous of them through to a verified fix. AI supplies the reach. Independent researchers supply the judgement and the adversarial creativity AI still lacks.</p><p>The organizations that build to convert both into action will pull ahead. The ones that do not will own a faster-growing list of vulnerabilities they never fixed.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to pick and set up a self-hosted app to run your own server ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Who owns your data once it leaves your devices? Who bears the responsibility for keeping it safe from prying eyes? What happens when the vendor you trusted with years of sensitive personal or business information suddenly decides to close shop? </p><p>Legally, these questions have straightforward answers. But in practice, it’s much murkier ground. </p><p>That’s why more and more people are now opting to store their apps and data on servers that they “own,” at least to some degree. By spending $15 to $20 a month on a private server, you can self-host websites, apps, automated workflows, and even local AI models. You retain full admin access over your server, including any data that goes into or out of it. </p><p>How does this work? Follow my detailed guide for instructions on how to set it up.</p><h2 class="article-body__section" id="section-why-self-host-an-app-using-docker"><span>Why self-host an app using Docker?</span></h2><p>No one wants to pay subscription fees for tens of apps every month, or deal with spikes in token costs or usage fees with no announcement or ceremony. Worse still, we have officially reached the point where people can’t remember all the things they’re subscribed to, so credit cards get charged on autopilot before you can look at the bill and see what’s happening.</p><p>That’s not all. When you use a cloud-based app, your data lives on someone else's infrastructure, governed by someone else's terms of service. Self-hosting puts that data back on hardware you control, whether that's a spare machine at home or a rented server. You decide who has access and how long files are kept — plus you don’t have to worry about what happens if the vendor changes its privacy policy.</p><p>Businesses handling customer records, financial data, or health information often need to prove exactly where that data sits and who can reach it. For individuals, the risk is even more pronounced because any data breaches or cyberattacks have a direct impact on your life. A self-hosted setup gives you a direct answer to these problems instead of pointing you to a vendor's compliance page. </p><p>With Docker, it’s a lot more practical, too. </p><p>Each app runs inside its own container, a package that contains the code, runtime, libraries, and configuration settings. Nothing leaks between containers, so installing one app won't bring down another. You have complete control over your data and app environment, while your only ongoing expense is the price of a hosting plan. </p><h2 class="article-body__section" id="section-how-to-self-host-an-app-on-your-server-step-by-step"><span>How to self-host an app on your server, step-by-step</span></h2><p>There's more than one route to a working self-hosted app. Some <a href="https://www.techradar.com/web-hosting/best-web-hosting-service-websites" target="_blank">hosting providers</a> give you full SSH access so you can install Docker apps using the command line. Others offer a graphical file manager or a library of ready-made templates that do most of the setup for you.</p><p>We'll walk through all these approaches below. Each assumes you already have access to a functional Linux server, workstation, or NAS. If you don’t have that set up yet, you can buy a hosting plan from any reputable web host. In fact, you can also start your own local server using a Linux computer or even a Raspberry Pi. </p><h3 class="article-body__section" id="section-where-to-find-and-pick-docker-apps"><span>Where to find and pick Docker apps</span></h3><p>If you’re wondering which apps you can self-host, Docker has an image library called <a href="https://hub.docker.com/" target="_blank" rel="nofollow">Docker Hub</a> that contains ready-made installers with detailed instructions on how to set up different compatible apps on a self-hosted server. </p><p>Search the database for the app or functionality you need, locate the app you wish to install on your server, then follow along with the rest of the tutorial.</p><h3 class="article-body__section" id="section-using-the-command-line-with-ssh"><span>Using the command line with SSH</span></h3><p>SSH gives you direct access to your server without any restrictions, which makes it the most flexible option if you're comfortable using a command line.</p><p>Start by connecting to your server from your local desktop. You’ll need your Linux server’s IP address for this, so make sure you note that down first. This can be found in your hosting provider’s SSH settings. After that, you just need to type in the command below using Terminal or Command Prompt:</p><pre class="line-numbers language-bash" language="bash" ><code>ssh your-username@your-server-ip</code></pre><p>Now, install Docker on your server using your Linux distro's package manager. On Ubuntu or Debian, you can use these commands:</p><pre class="line-numbers language-bash" language="bash" ><code>sudo apt updatesudo apt install docker.io docker-compose-plugin -y</code></pre><p>Next, create a folder for your Docker app and a Compose file to define it. Docker Compose lets you describe an app's containers, networks, and storage in a single YAML file rather than typing out long docker run commands by hand.</p><pre class="line-numbers language-bash" language="bash" ><code>mkdir ~/myapp && cd ~/myappnano docker-compose.yml</code></pre><p>A basic Compose file names the container image you want to run, maps a port on your server to a port inside the container, and sets any environment variables the app needs, such as a database password or an admin email. Most self-hosted apps publish an example Compose file in their documentation, which you can copy and adjust. You can usually find these directly on their Docker Hub listings. </p><p>But if you’re not sure how this looks, here’s an example compose.yml file for installing NGINX: </p><pre class="line-numbers language-yaml" language="yaml" ><code>services:  web:    # Pulls the official Nginx image from Docker Hub    image: nginx:latest    ports:      - "8080:80"  database:    # Pulls the official Postgres image from Docker Hub    image: postgres:15    environment:      POSTGRES_PASSWORD: your-secure-password</code></pre><p>You’ll need to replace “nginx:latest” with the image name of the Docker app you’re trying to install. I’d also recommend creating a more secure PostgreSQL password to replace “your-secure-password.”</p><p>Once you save the Docker Compose file, you can bring the app online with:</p><pre class="line-numbers language-bash" language="bash" ><code>docker compose up -d</code></pre><p>The -d flag runs the containers in the background so they keep running after you close your terminal session. Now when you point your web browser to your server's IP address and the port you mapped, your app should load.</p><h3 class="article-body__section" id="section-using-a-control-panel-with-native-docker-support"><span>Using a control panel with native Docker support</span></h3><p>If you'd rather avoid the terminal, some hosting provider control panels give you a visual way to manage containers directly.</p><p>cPanel is the most widely used panel, but it doesn't include native Docker management, so you’re stuck using SSH only. However, Plesk has an official Docker extension that lets you browse images from Docker Hub, deploy containers, and manage them from a dedicated section in the sidebar without touching a command line interface. CyberPanel, another free and open-source control panel built on OpenLiteSpeed, also ships with Docker management built in as an alternative to SSH setup.</p><p>Then you just search the image catalog or paste in your own YAML file, review the resource and port settings the app requests, and confirm the deployment. The panel pulls the image, starts the container, and usually shows you live logs if something fails.</p><p>Once the app is running, the same panel typically handles DNS records and SSL certificates too. That's a decent accessibility advantage over pure SSH, since you don't need to deal with stuff like configuring a reverse proxy or certificate renewal by hand.</p><h3 class="article-body__section" id="section-using-pre-coded-templates-offered-by-web-hosts"><span>Using pre-coded templates offered by web hosts</span></h3><p>Still, the fastest route to a running app is a hosting provider's marketplace of pre-built templates. These exist specifically so you don't have to write a Compose file from scratch.</p><p>Log in to your hosting provider's dashboard and look for a marketplace, app catalog, or "one-click apps" section. Search for the app you want to run. Popular self-hosted tools like automation platforms, note-taking apps, and file-sync services are commonly available this way.</p><p>Selecting a template usually opens a short setup form. You'll pick your server size, choose a data center region close to your users, and set any required credentials, like an admin password. Confirm the order, and the provider provisions a server with Docker and your chosen app already configured and running.</p><p>This method trades some flexibility for speed. You won't have as much control over container configuration, and templates can lag behind an app's latest release. But for popular tools, it's usually the quickest way to go from nothing to a working instance you can start customizing.</p><h2 class="article-body__section" id="section-are-there-any-caveats-to-self-hosting"><span>Are there any caveats to self-hosting?</span></h2><p>Self-hosting shifts responsibility from a vendor's support team to you. Security patches, software updates, and backups no longer happen automatically in the background. If you forget to update a container image for months, you could be running software with a known vulnerability, and nobody will send you a reminder before your server gets compromised.</p><p>Uptime becomes your problem too. A managed SaaS product usually has a dedicated team monitoring its infrastructure around the clock. A self-hosted app on a single server has no such safety net unless you set one up yourself, whether that's monitoring software, automated backups, or a failover server in case there’s a crash.</p><p>There's also a real-time cost that's easy to underestimate. Reading documentation, troubleshooting containers, keeping track of which ports and volumes belong to which app all add up — all these things cost time and effort. For a single low-stakes tool, that's a minor inconvenience. For a business running several self-hosted apps, it can turn into a part-time job unless you budget for it properly.</p><h2 class="article-body__section" id="section-is-self-hosting-actually-cheaper"><span>Is self-hosting actually cheaper?</span></h2><p>On paper, the numbers look compelling. A small virtual private server capable of running several lightweight self-hosted apps typically costs somewhere between $5 and $20 a month, depending on the provider and specs you choose. Compare that to a single SaaS subscription that can easily run $20 to $60 a month per tool, and the gap widens fast once you're replacing multiple subscriptions with one server.</p><p>The savings tend to grow with scale, up to a point. Running two or three self-hosted apps on the same VPS costs roughly the same as running one, since you're paying for the server rather than per app. That changes the math significantly compared with SaaS pricing, where every additional tool usually means an additional bill.</p><p>But cheaper isn't the same as free. A server with no backup strategy or monitoring in place isn't really saving you money if it goes down and you lose data or spend a weekend fixing it. Factor in the hours you'll spend on updates and troubleshooting, especially early on, and self-hosting looks less like a free lunch and more like a trade. You get lower cash costs in exchange for taking on the operational work a SaaS vendor would normally handle for you.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/how-to-pick-and-set-up-a-self-hosted-app-to-run-your-own-server</link>
                                                                            <description>
                            <![CDATA[ A practical guide to self-hosting apps in a containerized environment with Docker. We’ll cover setup using SSH, control panels like Plex and CyberPanel, and templates from popular hosting providers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">beF2Y7Tg3rSGeBK3HDUF8o</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wqDphyjN5ftDvvJ4dKJLhn-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 09:12:23 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Website Hosting]]></category>
                                                                                                <author><![CDATA[ ritoban@nutgraf.agency (Ritoban Mukherjee) ]]></author>                    <dc:creator><![CDATA[ Ritoban Mukherjee ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/cD9joj4H54xYmooW8re3vU-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wqDphyjN5ftDvvJ4dKJLhn-1920-80.jpg">
                                                            <media:credit><![CDATA[Generated with Gemini ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[a woman sat at a desk coding an app]]></media:description>                                                            <media:text><![CDATA[a woman sat at a desk coding an app]]></media:text>
                                <media:title type="plain"><![CDATA[a woman sat at a desk coding an app]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wqDphyjN5ftDvvJ4dKJLhn-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Who owns your data once it leaves your devices? Who bears the responsibility for keeping it safe from prying eyes? What happens when the vendor you trusted with years of sensitive personal or business information suddenly decides to close shop? </p><p>Legally, these questions have straightforward answers. But in practice, it’s much murkier ground. </p><p>That’s why more and more people are now opting to store their apps and data on servers that they “own,” at least to some degree. By spending $15 to $20 a month on a private server, you can self-host websites, apps, automated workflows, and even local AI models. You retain full admin access over your server, including any data that goes into or out of it. </p><p>How does this work? Follow my detailed guide for instructions on how to set it up.</p><h2 class="article-body__section" id="section-why-self-host-an-app-using-docker"><span>Why self-host an app using Docker?</span></h2><p>No one wants to pay subscription fees for tens of apps every month, or deal with spikes in token costs or usage fees with no announcement or ceremony. Worse still, we have officially reached the point where people can’t remember all the things they’re subscribed to, so credit cards get charged on autopilot before you can look at the bill and see what’s happening.</p><p>That’s not all. When you use a cloud-based app, your data lives on someone else's infrastructure, governed by someone else's terms of service. Self-hosting puts that data back on hardware you control, whether that's a spare machine at home or a rented server. You decide who has access and how long files are kept — plus you don’t have to worry about what happens if the vendor changes its privacy policy.</p><p>Businesses handling customer records, financial data, or health information often need to prove exactly where that data sits and who can reach it. For individuals, the risk is even more pronounced because any data breaches or cyberattacks have a direct impact on your life. A self-hosted setup gives you a direct answer to these problems instead of pointing you to a vendor's compliance page. </p><p>With Docker, it’s a lot more practical, too. </p><p>Each app runs inside its own container, a package that contains the code, runtime, libraries, and configuration settings. Nothing leaks between containers, so installing one app won't bring down another. You have complete control over your data and app environment, while your only ongoing expense is the price of a hosting plan. </p><h2 class="article-body__section" id="section-how-to-self-host-an-app-on-your-server-step-by-step"><span>How to self-host an app on your server, step-by-step</span></h2><p>There's more than one route to a working self-hosted app. Some <a href="https://www.techradar.com/web-hosting/best-web-hosting-service-websites" target="_blank">hosting providers</a> give you full SSH access so you can install Docker apps using the command line. Others offer a graphical file manager or a library of ready-made templates that do most of the setup for you.</p><p>We'll walk through all these approaches below. Each assumes you already have access to a functional Linux server, workstation, or NAS. If you don’t have that set up yet, you can buy a hosting plan from any reputable web host. In fact, you can also start your own local server using a Linux computer or even a Raspberry Pi. </p><h3 class="article-body__section" id="section-where-to-find-and-pick-docker-apps"><span>Where to find and pick Docker apps</span></h3><p>If you’re wondering which apps you can self-host, Docker has an image library called <a href="https://hub.docker.com/" target="_blank" rel="nofollow">Docker Hub</a> that contains ready-made installers with detailed instructions on how to set up different compatible apps on a self-hosted server. </p><p>Search the database for the app or functionality you need, locate the app you wish to install on your server, then follow along with the rest of the tutorial.</p><h3 class="article-body__section" id="section-using-the-command-line-with-ssh"><span>Using the command line with SSH</span></h3><p>SSH gives you direct access to your server without any restrictions, which makes it the most flexible option if you're comfortable using a command line.</p><p>Start by connecting to your server from your local desktop. You’ll need your Linux server’s IP address for this, so make sure you note that down first. This can be found in your hosting provider’s SSH settings. After that, you just need to type in the command below using Terminal or Command Prompt:</p><pre class="line-numbers language-bash" language="bash" ><code>ssh your-username@your-server-ip</code></pre><p>Now, install Docker on your server using your Linux distro's package manager. On Ubuntu or Debian, you can use these commands:</p><pre class="line-numbers language-bash" language="bash" ><code>sudo apt updatesudo apt install docker.io docker-compose-plugin -y</code></pre><p>Next, create a folder for your Docker app and a Compose file to define it. Docker Compose lets you describe an app's containers, networks, and storage in a single YAML file rather than typing out long docker run commands by hand.</p><pre class="line-numbers language-bash" language="bash" ><code>mkdir ~/myapp && cd ~/myappnano docker-compose.yml</code></pre><p>A basic Compose file names the container image you want to run, maps a port on your server to a port inside the container, and sets any environment variables the app needs, such as a database password or an admin email. Most self-hosted apps publish an example Compose file in their documentation, which you can copy and adjust. You can usually find these directly on their Docker Hub listings. </p><p>But if you’re not sure how this looks, here’s an example compose.yml file for installing NGINX: </p><pre class="line-numbers language-yaml" language="yaml" ><code>services:  web:    # Pulls the official Nginx image from Docker Hub    image: nginx:latest    ports:      - "8080:80"  database:    # Pulls the official Postgres image from Docker Hub    image: postgres:15    environment:      POSTGRES_PASSWORD: your-secure-password</code></pre><p>You’ll need to replace “nginx:latest” with the image name of the Docker app you’re trying to install. I’d also recommend creating a more secure PostgreSQL password to replace “your-secure-password.”</p><p>Once you save the Docker Compose file, you can bring the app online with:</p><pre class="line-numbers language-bash" language="bash" ><code>docker compose up -d</code></pre><p>The -d flag runs the containers in the background so they keep running after you close your terminal session. Now when you point your web browser to your server's IP address and the port you mapped, your app should load.</p><h3 class="article-body__section" id="section-using-a-control-panel-with-native-docker-support"><span>Using a control panel with native Docker support</span></h3><p>If you'd rather avoid the terminal, some hosting provider control panels give you a visual way to manage containers directly.</p><p>cPanel is the most widely used panel, but it doesn't include native Docker management, so you’re stuck using SSH only. However, Plesk has an official Docker extension that lets you browse images from Docker Hub, deploy containers, and manage them from a dedicated section in the sidebar without touching a command line interface. CyberPanel, another free and open-source control panel built on OpenLiteSpeed, also ships with Docker management built in as an alternative to SSH setup.</p><p>Then you just search the image catalog or paste in your own YAML file, review the resource and port settings the app requests, and confirm the deployment. The panel pulls the image, starts the container, and usually shows you live logs if something fails.</p><p>Once the app is running, the same panel typically handles DNS records and SSL certificates too. That's a decent accessibility advantage over pure SSH, since you don't need to deal with stuff like configuring a reverse proxy or certificate renewal by hand.</p><h3 class="article-body__section" id="section-using-pre-coded-templates-offered-by-web-hosts"><span>Using pre-coded templates offered by web hosts</span></h3><p>Still, the fastest route to a running app is a hosting provider's marketplace of pre-built templates. These exist specifically so you don't have to write a Compose file from scratch.</p><p>Log in to your hosting provider's dashboard and look for a marketplace, app catalog, or "one-click apps" section. Search for the app you want to run. Popular self-hosted tools like automation platforms, note-taking apps, and file-sync services are commonly available this way.</p><p>Selecting a template usually opens a short setup form. You'll pick your server size, choose a data center region close to your users, and set any required credentials, like an admin password. Confirm the order, and the provider provisions a server with Docker and your chosen app already configured and running.</p><p>This method trades some flexibility for speed. You won't have as much control over container configuration, and templates can lag behind an app's latest release. But for popular tools, it's usually the quickest way to go from nothing to a working instance you can start customizing.</p><h2 class="article-body__section" id="section-are-there-any-caveats-to-self-hosting"><span>Are there any caveats to self-hosting?</span></h2><p>Self-hosting shifts responsibility from a vendor's support team to you. Security patches, software updates, and backups no longer happen automatically in the background. If you forget to update a container image for months, you could be running software with a known vulnerability, and nobody will send you a reminder before your server gets compromised.</p><p>Uptime becomes your problem too. A managed SaaS product usually has a dedicated team monitoring its infrastructure around the clock. A self-hosted app on a single server has no such safety net unless you set one up yourself, whether that's monitoring software, automated backups, or a failover server in case there’s a crash.</p><p>There's also a real-time cost that's easy to underestimate. Reading documentation, troubleshooting containers, keeping track of which ports and volumes belong to which app all add up — all these things cost time and effort. For a single low-stakes tool, that's a minor inconvenience. For a business running several self-hosted apps, it can turn into a part-time job unless you budget for it properly.</p><h2 class="article-body__section" id="section-is-self-hosting-actually-cheaper"><span>Is self-hosting actually cheaper?</span></h2><p>On paper, the numbers look compelling. A small virtual private server capable of running several lightweight self-hosted apps typically costs somewhere between $5 and $20 a month, depending on the provider and specs you choose. Compare that to a single SaaS subscription that can easily run $20 to $60 a month per tool, and the gap widens fast once you're replacing multiple subscriptions with one server.</p><p>The savings tend to grow with scale, up to a point. Running two or three self-hosted apps on the same VPS costs roughly the same as running one, since you're paying for the server rather than per app. That changes the math significantly compared with SaaS pricing, where every additional tool usually means an additional bill.</p><p>But cheaper isn't the same as free. A server with no backup strategy or monitoring in place isn't really saving you money if it goes down and you lose data or spend a weekend fixing it. Factor in the hours you'll spend on updates and troubleshooting, especially early on, and self-hosting looks less like a free lunch and more like a trade. You get lower cash costs in exchange for taking on the operational work a SaaS vendor would normally handle for you.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why AI agent governance must start with enterprise data ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Executives are spending a great deal of time asking whether AI agents are ready for production, but this is the wrong place to start, because agents aren’t acting in a vacuum. The quality of their decisions depends heavily on the quality of the data they use.</p><p>Model <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> and performance matter, of course, but they cannot compensate for weak control over the information the agent can retrieve. Before putting an agent into production, an organization needs governed inputs, appropriate access and a reliable record of what the agent produced.</p><p>Give an agent outdated <a href="https://www.techradar.com/best/best-customer-feedback-tools?gad=1">customer</a> information, duplicate records or material that was never properly classified, and it will work with what it has, making poorly informed decisions quickly across thousands of transactions.</p><p>Unfortunately, the gap between adoption and governance is widening fast. In the rush to adopt AI, many organizations are pushing agents into production before they have solved the underlying data problem, so it shouldn’t come as a surprise that the vast majority of AI projects show zero ROI.</p><p>What’s more, AI agent governance doesn’t end with the <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> an agent may access. It also encompasses the data an agent produces, such as its decisions, the instructions it was given and documents it created. As AI contributes to significant decisions within the enterprise, AI traceability and defensibility have become critical capabilities. </p><p>Organizations that build a strong data foundation put themselves in a stronger position to move from pilot to production with confidence that agents won’t transform poorly managed data into a company-wide crisis.</p><h2 id="the-data-problem-comes-first">The data problem comes first</h2><p>The data governance issue is not, of course, a new problem. Most large organizations have spent years trying to wrangle information spread across operational platforms, file shares, archives and applications that should have been retired long ago. But because agentic AI can rapidly act on those weaknesses at scale, the issue has become more pressing now.</p><p>Before an agent is given access to data, IT needs to identify sensitive and regulated information, apply classification and retention policies consistently, and determine which sources are current and reliable enough for the job. Legacy data deserves particular care.</p><p>Retired <a href="https://www.techradar.com/best/best-apps-for-small-business">applications</a> often contain valuable business history, but they also hold duplicate records, obsolete information and data that’s subject to legal holds or retention requirements.</p><p>Organizations should also preserve the context and relationships that give legacy data meaning, and then make selected, policy-controlled datasets available. AI does not act on data in a vacuum, and without the surrounding context, agents will either fail to complete their tasks or, worse, will make and act on faulty decisions. </p><h2 id="access-is-a-business-decision">Access is a business decision</h2><p>Another mistake that enterprises make is to provide their agents with access to more data than they need. In fact, agents should also only have access to the data they require to complete the tasks they are assigned. Just because a system can be connected to an agent, that does not mean it should be.</p><p>Treat agents like <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employees</a>, and follow the principle of least privilege. For example, while a customer service agent may need current account and transaction information, it most likely doesn’t need legal files or historic employee records. Access should narrowly follow the agent's defined purpose.</p><p>Provenance matters as well. An agent should not treat a current system of record and a decades-old archive as equally authoritative. Agents must know where information came from, when it was updated and which policies apply. Again, context matters. Without the proper context, agents will make costly mistakes.</p><h2 id="keep-a-record-of-what-the-agent-did">Keep a record of what the agent did</h2><p>Governance does not end once the agent receives approved data. AI-related data is rapidly becoming material to litigation, compliance reviews and customer complaints. To be prepared, an organization should be able to show what the agent was asked to do, which information it accessed, which policies were applied and what happened next.</p><p>Prompts, retrieved content, outputs and resulting decisions should be retained as business records. A reviewer should be able to reconstruct the AI’s decision and trace it back to both the source data and the person or function that authorized the activity.</p><p>Finally, accountability cannot belong to the technology team alone. Security, data, privacy, legal and compliance leaders all have a role, but a named <a href="https://www.techradar.com/best/best-small-business-software">business</a> owner must remain responsible for the outcome. <a href="https://www.techradar.com/pro/best-it-automation-software">Automation</a> can perform an action, but it cannot accept accountability for it.</p><p>Data readiness is not a secondary workstream to be addressed after an AI pilot succeeds. It is part of the decision to move that pilot into production. If an organization cannot trust the information, control access to it and clearly explain the resulting decisions, the agent is not ready for greater autonomy.</p><p><em></em><a href="https://www.techradar.com/best/best-ai-tools"><em>We've featured the best AI tool.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/why-ai-agent-governance-must-start-with-enterprise-data</link>
                                                                            <description>
                            <![CDATA[ What happens when AI meets poor data governance and the potential repercussions for organizations. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8WJNXfMywsJbjPMBBBL57i</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/h8ZQHernNUVpnGYX7QnxVM-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 08:46:35 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jerry Caviston ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/h8ZQHernNUVpnGYX7QnxVM-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The letters AI in a box in the middle of a vast digital room divided by beams of line]]></media:description>                                                            <media:text><![CDATA[The letters AI in a box in the middle of a vast digital room divided by beams of line]]></media:text>
                                <media:title type="plain"><![CDATA[The letters AI in a box in the middle of a vast digital room divided by beams of line]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/h8ZQHernNUVpnGYX7QnxVM-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Executives are spending a great deal of time asking whether AI agents are ready for production, but this is the wrong place to start, because agents aren’t acting in a vacuum. The quality of their decisions depends heavily on the quality of the data they use.</p><p>Model <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> and performance matter, of course, but they cannot compensate for weak control over the information the agent can retrieve. Before putting an agent into production, an organization needs governed inputs, appropriate access and a reliable record of what the agent produced.</p><p>Give an agent outdated <a href="https://www.techradar.com/best/best-customer-feedback-tools?gad=1">customer</a> information, duplicate records or material that was never properly classified, and it will work with what it has, making poorly informed decisions quickly across thousands of transactions.</p><p>Unfortunately, the gap between adoption and governance is widening fast. In the rush to adopt AI, many organizations are pushing agents into production before they have solved the underlying data problem, so it shouldn’t come as a surprise that the vast majority of AI projects show zero ROI.</p><p>What’s more, AI agent governance doesn’t end with the <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> an agent may access. It also encompasses the data an agent produces, such as its decisions, the instructions it was given and documents it created. As AI contributes to significant decisions within the enterprise, AI traceability and defensibility have become critical capabilities. </p><p>Organizations that build a strong data foundation put themselves in a stronger position to move from pilot to production with confidence that agents won’t transform poorly managed data into a company-wide crisis.</p><h2 id="the-data-problem-comes-first">The data problem comes first</h2><p>The data governance issue is not, of course, a new problem. Most large organizations have spent years trying to wrangle information spread across operational platforms, file shares, archives and applications that should have been retired long ago. But because agentic AI can rapidly act on those weaknesses at scale, the issue has become more pressing now.</p><p>Before an agent is given access to data, IT needs to identify sensitive and regulated information, apply classification and retention policies consistently, and determine which sources are current and reliable enough for the job. Legacy data deserves particular care.</p><p>Retired <a href="https://www.techradar.com/best/best-apps-for-small-business">applications</a> often contain valuable business history, but they also hold duplicate records, obsolete information and data that’s subject to legal holds or retention requirements.</p><p>Organizations should also preserve the context and relationships that give legacy data meaning, and then make selected, policy-controlled datasets available. AI does not act on data in a vacuum, and without the surrounding context, agents will either fail to complete their tasks or, worse, will make and act on faulty decisions. </p><h2 id="access-is-a-business-decision">Access is a business decision</h2><p>Another mistake that enterprises make is to provide their agents with access to more data than they need. In fact, agents should also only have access to the data they require to complete the tasks they are assigned. Just because a system can be connected to an agent, that does not mean it should be.</p><p>Treat agents like <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employees</a>, and follow the principle of least privilege. For example, while a customer service agent may need current account and transaction information, it most likely doesn’t need legal files or historic employee records. Access should narrowly follow the agent's defined purpose.</p><p>Provenance matters as well. An agent should not treat a current system of record and a decades-old archive as equally authoritative. Agents must know where information came from, when it was updated and which policies apply. Again, context matters. Without the proper context, agents will make costly mistakes.</p><h2 id="keep-a-record-of-what-the-agent-did">Keep a record of what the agent did</h2><p>Governance does not end once the agent receives approved data. AI-related data is rapidly becoming material to litigation, compliance reviews and customer complaints. To be prepared, an organization should be able to show what the agent was asked to do, which information it accessed, which policies were applied and what happened next.</p><p>Prompts, retrieved content, outputs and resulting decisions should be retained as business records. A reviewer should be able to reconstruct the AI’s decision and trace it back to both the source data and the person or function that authorized the activity.</p><p>Finally, accountability cannot belong to the technology team alone. Security, data, privacy, legal and compliance leaders all have a role, but a named <a href="https://www.techradar.com/best/best-small-business-software">business</a> owner must remain responsible for the outcome. <a href="https://www.techradar.com/pro/best-it-automation-software">Automation</a> can perform an action, but it cannot accept accountability for it.</p><p>Data readiness is not a secondary workstream to be addressed after an AI pilot succeeds. It is part of the decision to move that pilot into production. If an organization cannot trust the information, control access to it and clearly explain the resulting decisions, the agent is not ready for greater autonomy.</p><p><em></em><a href="https://www.techradar.com/best/best-ai-tools"><em>We've featured the best AI tool.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The EU will force data centers to disclose how much water and energy they are using ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Data centers will get a label, just like your fridge or dishwasher</strong></li><li><strong>Energy and water consumption must be reported by 500kW+ sites</strong></li><li><strong>The EC also wants to know how resources are being balanced in relation to local strains</strong></li></ul><p>The European Commission has proposed a new rating scheme for data centers in a bid to have them report metrics like energy efficiency and water consumption more transparently.</p><p>Upcoming changes fall under the new Data Center Energy Efficiency Package, which introduces a new common, EU-wide rating scheme much like what we're already familiar with for household appliances.</p><p>Crucially, the changes now affect smaller campuses with a power demand of at least 500kW, whereas only much larger sites were impacted before the new rules.</p><h2 id="european-data-centers-must-report-efficiency-statistics-more-openly">European data centers must report efficiency statistics more openly</h2><p>Some of the new metrics include total energy and water consumption, Power Usage Effectiveness (a figure we're already familiar with in hyperscalers' annual sustainability reports), Water Usage Effectiveness (WUE), how much of their energy comes from renewables, whether waste heat gets reused and more.</p><p>Ultimately, the intensified reporting is hoped not only to reveal how much energy sites are using, but how effectively they're balancing consumption in relation to local pressures like water stress.</p><p>"Tripling our data centre capacity cannot mean tripling the pressure on our grids, our water and our energy bills," Clean, Just and Competitive Transition EVP Teresa Ribera said.</p><p>The changes are also especially notable given ongoing changes within the bloc, because the EU has been ramping up more local compute options so as to reduce reliance on international options in a big sovereign drive. Over the next seven years, the EU wants to triple its data center capacity, per <a href="https://www.reuters.com/business/environment/eu-require-data-centres-disclose-energy-water-efficiency-2026-09-21/" target="_blank"><em>Reuters</em></a><em> </em>reporting.</p><p>Importantly, the changes won't happen overnight with the rating scheme subject to a two-month scrutiny window, the Commission detailed. Still, the first ratings are set to go live as early as this year, and by the end of 2028, the EU hopes to have reviewed just how effective those new enforcements were.</p><p>"Understanding their energy and resource consumption is the essential first step towards integrating them sustainably into our energy system," Energy and Housing Commissioner Dan Jørgensen added.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/the-eu-will-force-data-centers-to-disclose-how-much-water-and-energy-they-are-using</link>
                                                                            <description>
                            <![CDATA[ New European rules could mean that even more data centers need to report how much energy and water they're using. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YUYVSHfnVdxuetXc7yWDvX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2qpxDbKtu2otYAr3z2pcqe-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 06:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2qpxDbKtu2otYAr3z2pcqe-1920-80.jpg">
                                                            <media:credit><![CDATA[Dell]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Stylized image of a data center rack with electric blue lines running across it]]></media:description>                                                            <media:text><![CDATA[Stylized image of a data center rack with electric blue lines running across it]]></media:text>
                                <media:title type="plain"><![CDATA[Stylized image of a data center rack with electric blue lines running across it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2qpxDbKtu2otYAr3z2pcqe-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Data centers will get a label, just like your fridge or dishwasher</strong></li><li><strong>Energy and water consumption must be reported by 500kW+ sites</strong></li><li><strong>The EC also wants to know how resources are being balanced in relation to local strains</strong></li></ul><p>The European Commission has proposed a new rating scheme for data centers in a bid to have them report metrics like energy efficiency and water consumption more transparently.</p><p>Upcoming changes fall under the new Data Center Energy Efficiency Package, which introduces a new common, EU-wide rating scheme much like what we're already familiar with for household appliances.</p><p>Crucially, the changes now affect smaller campuses with a power demand of at least 500kW, whereas only much larger sites were impacted before the new rules.</p><h2 id="european-data-centers-must-report-efficiency-statistics-more-openly">European data centers must report efficiency statistics more openly</h2><p>Some of the new metrics include total energy and water consumption, Power Usage Effectiveness (a figure we're already familiar with in hyperscalers' annual sustainability reports), Water Usage Effectiveness (WUE), how much of their energy comes from renewables, whether waste heat gets reused and more.</p><p>Ultimately, the intensified reporting is hoped not only to reveal how much energy sites are using, but how effectively they're balancing consumption in relation to local pressures like water stress.</p><p>"Tripling our data centre capacity cannot mean tripling the pressure on our grids, our water and our energy bills," Clean, Just and Competitive Transition EVP Teresa Ribera said.</p><p>The changes are also especially notable given ongoing changes within the bloc, because the EU has been ramping up more local compute options so as to reduce reliance on international options in a big sovereign drive. Over the next seven years, the EU wants to triple its data center capacity, per <a href="https://www.reuters.com/business/environment/eu-require-data-centres-disclose-energy-water-efficiency-2026-09-21/" target="_blank"><em>Reuters</em></a><em> </em>reporting.</p><p>Importantly, the changes won't happen overnight with the rating scheme subject to a two-month scrutiny window, the Commission detailed. Still, the first ratings are set to go live as early as this year, and by the end of 2028, the EU hopes to have reviewed just how effective those new enforcements were.</p><p>"Understanding their energy and resource consumption is the essential first step towards integrating them sustainably into our energy system," Energy and Housing Commissioner Dan Jørgensen added.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI is wiping out whole degrees in China — translation, photography, illustration and fashion design are going, while prompt engineering is the new job appearing in film ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Chinese universities are cutting traditional courses because of AI</strong></li><li><strong>Translation courses face pressure as universities reassess their employment value</strong></li><li><strong>Photography programmes are being merged as AI changes creative production</strong></li></ul><p>The Central Academy of Fine Arts has dropped courses in illustration, photography and translation, arguing that AI has made them poor value for money.</p><p>Fashion design degrees are also being scrapped, with universities saying the future rests on close cooperation between people and machines in creative work.</p><p>The changes follow a state campaign to direct learners toward chips, robotics and AI, industries the authorities regard as vital for national prospects.</p><h2 id="universities-are-cutting-courses-at-scale">Universities are cutting courses at scale</h2><p>From 2021 to 2025, Chinese universities closed or paused 12,200 undergraduate programmes and launched roughly 10,200 fresh programmes.</p><p>The restructuring affected over 30% of undergraduate programmes nationwide, and arts, humanities and language courses absorbed the heaviest cuts.</p><p>A survey of 70 universities found cuts to five translation majors, eight Japanese majors and five German majors among language programmes.</p><p>Alex Shi launched her creative career with a degree that trained her to translate and interpret English, and says such courses could soon vanish, as the cuts overlook the wider skills underlying translation, including communication and critical thinking, which extend beyond producing accurate text.</p><p>Shi concedes that AI could bring translation accuracy almost to perfection, yet maintains that interpreting demands far more than converting words between languages.</p><p>“There’s still that personal style that’s always been essential in translation,” said Shi.</p><p>The Communication University of China has reportedly closed five programmes, among them visual communication design, comics and photography, according to a report on its overhaul.</p><p>“Traditional photography major can no longer exist as an independent discipline… today everyone can be a self-media creator and recorder,” said Liao Xiangzhong, top official at the Communication University of China.</p><p>Liao later clarified that the majors were merged into other disciplines instead of being cancelled outright, with photography absorbed by film and television photography.</p><h2 id="new-film-roles-and-hybrid-courses">New film roles and hybrid courses</h2><p>New roles such as prompt engineer and AI animator are emerging in film and animation, where AI is also creating fresh openings alongside the closures.</p><p>One industry worker says designing characters or scenes once took a month, but with AI, a complete project can now be delivered in that time.</p><p>Degree programmes in intelligent imaging art, intelligent audiovisual engineering, and intelligent engineering and creative design have been launched by some schools.  </p><p>Universities are also launching hybrid courses in which artistic instruction sits beside AI training, while some standalone degrees are being scrapped across the sector.</p><p>That shift is changing what employers expect from graduates entering translation, design, photography and film production.</p><p>For students, traditional qualifications may increasingly need technical skills that allow them to work alongside automated creative systems.</p><p>The result is a university system where some familiar degrees disappear while new AI-focused programmes take their place.</p><p>Via <a href="https://www.youtube.com/watch?v=3z1V0kUoDn0" target="_blank" rel="nofollow">Al Jazeera English</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/ai-is-wiping-out-whole-degrees-in-china-translation-photography-illustration-and-fashion-design-are-going-while-prompt-engineering-is-the-new-job-appearing-in-film</link>
                                                                            <description>
                            <![CDATA[ Chinese universities are cutting or restructuring creative programmes as AI changes employment needs, while new technology-focused courses and film roles emerge. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HpeGZRNUnCt5t6wP7zuvJc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pvkgvETjmqkheCK3xtsQx9-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 01:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pvkgvETjmqkheCK3xtsQx9-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images / Surasak Suwanmake]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI brain coming out of laptop screen]]></media:description>                                                            <media:text><![CDATA[AI brain coming out of laptop screen]]></media:text>
                                <media:title type="plain"><![CDATA[AI brain coming out of laptop screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pvkgvETjmqkheCK3xtsQx9-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Chinese universities are cutting traditional courses because of AI</strong></li><li><strong>Translation courses face pressure as universities reassess their employment value</strong></li><li><strong>Photography programmes are being merged as AI changes creative production</strong></li></ul><p>The Central Academy of Fine Arts has dropped courses in illustration, photography and translation, arguing that AI has made them poor value for money.</p><p>Fashion design degrees are also being scrapped, with universities saying the future rests on close cooperation between people and machines in creative work.</p><p>The changes follow a state campaign to direct learners toward chips, robotics and AI, industries the authorities regard as vital for national prospects.</p><h2 id="universities-are-cutting-courses-at-scale">Universities are cutting courses at scale</h2><p>From 2021 to 2025, Chinese universities closed or paused 12,200 undergraduate programmes and launched roughly 10,200 fresh programmes.</p><p>The restructuring affected over 30% of undergraduate programmes nationwide, and arts, humanities and language courses absorbed the heaviest cuts.</p><p>A survey of 70 universities found cuts to five translation majors, eight Japanese majors and five German majors among language programmes.</p><p>Alex Shi launched her creative career with a degree that trained her to translate and interpret English, and says such courses could soon vanish, as the cuts overlook the wider skills underlying translation, including communication and critical thinking, which extend beyond producing accurate text.</p><p>Shi concedes that AI could bring translation accuracy almost to perfection, yet maintains that interpreting demands far more than converting words between languages.</p><p>“There’s still that personal style that’s always been essential in translation,” said Shi.</p><p>The Communication University of China has reportedly closed five programmes, among them visual communication design, comics and photography, according to a report on its overhaul.</p><p>“Traditional photography major can no longer exist as an independent discipline… today everyone can be a self-media creator and recorder,” said Liao Xiangzhong, top official at the Communication University of China.</p><p>Liao later clarified that the majors were merged into other disciplines instead of being cancelled outright, with photography absorbed by film and television photography.</p><h2 id="new-film-roles-and-hybrid-courses">New film roles and hybrid courses</h2><p>New roles such as prompt engineer and AI animator are emerging in film and animation, where AI is also creating fresh openings alongside the closures.</p><p>One industry worker says designing characters or scenes once took a month, but with AI, a complete project can now be delivered in that time.</p><p>Degree programmes in intelligent imaging art, intelligent audiovisual engineering, and intelligent engineering and creative design have been launched by some schools.  </p><p>Universities are also launching hybrid courses in which artistic instruction sits beside AI training, while some standalone degrees are being scrapped across the sector.</p><p>That shift is changing what employers expect from graduates entering translation, design, photography and film production.</p><p>For students, traditional qualifications may increasingly need technical skills that allow them to work alongside automated creative systems.</p><p>The result is a university system where some familiar degrees disappear while new AI-focused programmes take their place.</p><p>Via <a href="https://www.youtube.com/watch?v=3z1V0kUoDn0" target="_blank" rel="nofollow">Al Jazeera English</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Official Russian state photo shows Vladimir Putin casting online vote using an unlicensed version of Windows 10 — and to make things worse, it's on an American Dell PC ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>A Vladimir Putin press call showed the Russian president casting an online vote for the country’s parliamentary elections</strong></li><li><strong>The short clip has revealed that not only is Putin using a US-built Dell PC, it is running Windows 10 – and the license has not been activated</strong></li><li><strong>Putin’s example of voting online is intended to encourage voters to take part, but has instead raised eyebrows and launched memes</strong></li></ul><p>Parliamentary elections in Russia took place on Friday, September 18 2026, with online voting for positions in the State Duma open to the public for the first time. To demonstrate the ease of online voting, a press call highlighted Russian President Vladimir Putin casting his vote – but this hasn’t gone quite as planned.</p><p>While the president appeared to have difficulty reading the display, the real challenge seems to be that the Russian leader is using a version of Windows 10 that has not been activated. Furthermore, the PC is a Dell, rather than a Russian-built system.</p><p>The Putin publicity stunt has already launched memes, but the it also raises questions about his ability to use a computer, not to mention the suitability of the hardware for voting.</p><h2 id="you-can-t-go-wrong">“You can’t go wrong”</h2><p>With 73-year-old President Putin lined up for the cameras with the Dell PC set up on his desk, he goes through the motions of “voting online,” presumably to demonstrate how easy it is. (In person and mail voting options were also available.)</p><p>The press call has all the authenticity of an unlicensed copy of Windows 10. Ironically, this is exactly what is in use, as you can see toward the end of the video.</p><p>Watch to the end:</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/2wMIMQdF44I" allowfullscreen></iframe></div></div><p>Although an initial reaction might be “Russian state IT is pretty weak,” it seems more likely that the state-controlled hardware overseeing infrastructure, networks, and military systems is far more up-to-date. What is more likely is that that PC was pulled out of a back room and an old copy of Windows quickly installed simply to provide President Putin with his short encouragement to vote. </p><h2 id="dell-vs-aquarius">Dell vs. Aquarius</h2><p>The use of a Dell PC is curious, however. While Russia and the US have cordial relations, it seems strange for the Russian president to use a foreign PC. Sanctions aside, Russia has a policy of forcing the use of home-grown brands (such as Aquarius) over those from overseas.</p><p>After voting, the five-times elected Russian leader uttered the memorable line “you can’t go wrong,” in his native language, perhaps highlighting the futility of voting for any candidates not in his favoured party, United Russia.</p><p>While it is difficult to assess the legitimacy of the elections in Russia itself, the governments of Australia, Canada, New Zealand, Norway, and the United Kingdom have challenged the elections in occupied Ukraine territories. The nations have described the them as “sham elections” that violate “Ukraine’s sovereignty and independence, and the UN Charter.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/official-russian-state-photo-shows-vladimir-putin-casting-online-vote-using-an-unlicensed-version-of-windows-10-and-to-make-things-worse-its-on-an-american-dell-pc</link>
                                                                            <description>
                            <![CDATA[ Russian President Vladimir Putin has been filmed for state broadcast in the process of casting an online vote, but it seems that the Dell PC was running a non-activated version of Windows 10. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9yvztUVdLZ8m7rVGbavcP8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uTtN23DTiqxJT2TXhbVmXo-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 00:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Windows]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uTtN23DTiqxJT2TXhbVmXo-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images/ALEXANDER KAZAKOV / Contributor]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Valdimir Putin]]></media:description>                                                            <media:text><![CDATA[Valdimir Putin]]></media:text>
                                <media:title type="plain"><![CDATA[Valdimir Putin]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uTtN23DTiqxJT2TXhbVmXo-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>A Vladimir Putin press call showed the Russian president casting an online vote for the country’s parliamentary elections</strong></li><li><strong>The short clip has revealed that not only is Putin using a US-built Dell PC, it is running Windows 10 – and the license has not been activated</strong></li><li><strong>Putin’s example of voting online is intended to encourage voters to take part, but has instead raised eyebrows and launched memes</strong></li></ul><p>Parliamentary elections in Russia took place on Friday, September 18 2026, with online voting for positions in the State Duma open to the public for the first time. To demonstrate the ease of online voting, a press call highlighted Russian President Vladimir Putin casting his vote – but this hasn’t gone quite as planned.</p><p>While the president appeared to have difficulty reading the display, the real challenge seems to be that the Russian leader is using a version of Windows 10 that has not been activated. Furthermore, the PC is a Dell, rather than a Russian-built system.</p><p>The Putin publicity stunt has already launched memes, but the it also raises questions about his ability to use a computer, not to mention the suitability of the hardware for voting.</p><h2 id="you-can-t-go-wrong">“You can’t go wrong”</h2><p>With 73-year-old President Putin lined up for the cameras with the Dell PC set up on his desk, he goes through the motions of “voting online,” presumably to demonstrate how easy it is. (In person and mail voting options were also available.)</p><p>The press call has all the authenticity of an unlicensed copy of Windows 10. Ironically, this is exactly what is in use, as you can see toward the end of the video.</p><p>Watch to the end:</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/2wMIMQdF44I" allowfullscreen></iframe></div></div><p>Although an initial reaction might be “Russian state IT is pretty weak,” it seems more likely that the state-controlled hardware overseeing infrastructure, networks, and military systems is far more up-to-date. What is more likely is that that PC was pulled out of a back room and an old copy of Windows quickly installed simply to provide President Putin with his short encouragement to vote. </p><h2 id="dell-vs-aquarius">Dell vs. Aquarius</h2><p>The use of a Dell PC is curious, however. While Russia and the US have cordial relations, it seems strange for the Russian president to use a foreign PC. Sanctions aside, Russia has a policy of forcing the use of home-grown brands (such as Aquarius) over those from overseas.</p><p>After voting, the five-times elected Russian leader uttered the memorable line “you can’t go wrong,” in his native language, perhaps highlighting the futility of voting for any candidates not in his favoured party, United Russia.</p><p>While it is difficult to assess the legitimacy of the elections in Russia itself, the governments of Australia, Canada, New Zealand, Norway, and the United Kingdom have challenged the elections in occupied Ukraine territories. The nations have described the them as “sham elections” that violate “Ukraine’s sovereignty and independence, and the UN Charter.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Enthusiast transforms Mac Mini into jaw-dropping 3D-printed portable PC complete with handles and touchpad — Mac Nano even has a keyboard and a battery ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>A M4 Mac Mini has been rebuilt into a battery-powered handheld computer</strong></li><li><strong>The custom handheld keeps Apple’s desktop motherboard and original cooling system intact</strong></li><li><strong>A removable Mac module sits inside the custom 3D-printed handheld enclosure</strong></li></ul><p>Apple's M4 Mac Mini has been transformed into a handheld Mac with a 7-inch 120Hz touchscreen, physical controls, keyboard, and battery.</p><p>Shing Solutions stripped the desktop computer down to its motherboard and cooling system before rebuilding it inside a custom 3D-printed enclosure.</p><p>The resulting device, dubbed Mac Nano, keeps the full macOS functionality while replacing the desk-bound form factor with something designed for use in two hands.</p><h2 id="the-mac-mini-becomes-a-removable-computing-core">The Mac Mini becomes a removable computing core</h2><p>The project retains Apple's original heatsink and blower fan instead of replacing them with smaller cooling hardware to save internal space.</p><p>That decision allows the M4 <a href="https://www.techradar.com/news/best-processors">processor</a> to retain its factory thermal arrangement while the motherboard moves into a completely different enclosure.</p><p>Inside the new chassis, the computer module sits on rails, allowing it to slide out without disturbing the screen, keyboard, or controllers.</p><p>The arrangement means the central hardware can theoretically be removed for servicing or replaced while the surrounding handheld computer remains assembled.</p><p>A 7-inch touchscreen provides the main display, with its 120Hz refresh rate giving the portable machine a smoother interface and gaming experience.</p><p>It is also equipped with a compact QWERTY keyboard sitting beneath the display, with an integrated touchpad providing cursor control.</p><p>The keyboard originally worked wirelessly, but its battery was removed, and the keyboard was rewired to draw power directly through USB.</p><p>This modification reduces the number of rechargeable components while allowing the keyboard to receive power directly from the handheld <a href="https://www.techradar.com/news/computing/pc/10-of-the-best-desktop-pcs-of-2015-1304391">computer</a>.</p><p>The internal layout therefore combines Apple's desktop motherboard with controls and display hardware that were never designed specifically for this computer.</p><h2 id="nintendo-controls-and-batteries-complete-the-handheld-device">Nintendo controls and batteries complete the handheld device</h2><p>The Mac Nano also includes physical gaming controls, using circuit boards taken from Nintendo Joy-Con charging grips and mounted inside both sides of the enclosure.</p><p>Those controls are wired directly into the Mac instead of using Bluetooth, but macOS does not natively support wired Joy Con controllers.</p><p>To make the controls usable, the project relies on Steam, whose controller mapping system can translate their input for compatible games.</p><p>Connecting the keyboard, controllers, touchscreen, and other peripherals also created a USB bottleneck inside the compact enclosure.</p><p>Shing Solutions addressed that problem by combining two miniature USB splitter boards into a custom three-port hub.</p><p>The Mac Nano is powered by rechargeable cells connected to a custom power delivery system, allowing it to run without staying plugged into an outlet.</p><p>The enclosure also incorporates handles, giving the device a grip that accommodates all its components.</p><p>Unlike a conventional <a href="https://www.techradar.com/computing/macbooks/apple-mac-mini-m4-2024https://www.techradar.com/computing/macbooks/apple-mac-mini-m4-2024">Mac Mini</a>, the Mac Nano therefore combines desktop Apple silicon with the components needed for genuinely untethered operation.</p><p>Via <a href="https://www.yankodesign.com/2026/09/14/the-mac-mini-belongs-on-a-desk-this-build-runs-it-from-your-hands/" target="_blank" rel="nofollow">Yanko Design</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/enthusiast-transforms-mac-mini-into-jaw-dropping-3d-printed-portable-pc-complete-with-handles-and-touchpad-mac-nano-even-has-a-keyboard-and-a-battery</link>
                                                                            <description>
                            <![CDATA[ A modified M4 Mac Mini becomes a handheld computer with a 120Hz touchscreen, keyboard, gaming controls, batteries, and removable hardware. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">M8qtqNytTc9HNKZ6irA6xF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PqtZ9vfNiPVqZVM4wHZune-1920-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 23:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/PqtZ9vfNiPVqZVM4wHZune-1920-80.png">
                                                            <media:credit><![CDATA[Yanko Design]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mac Nano, a device modified from the internals of the M4 Mac Mini by Shing Solutions ]]></media:description>                                                            <media:text><![CDATA[Mac Nano, a device modified from the internals of the M4 Mac Mini by Shing Solutions ]]></media:text>
                                <media:title type="plain"><![CDATA[Mac Nano, a device modified from the internals of the M4 Mac Mini by Shing Solutions ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PqtZ9vfNiPVqZVM4wHZune-1920-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>A M4 Mac Mini has been rebuilt into a battery-powered handheld computer</strong></li><li><strong>The custom handheld keeps Apple’s desktop motherboard and original cooling system intact</strong></li><li><strong>A removable Mac module sits inside the custom 3D-printed handheld enclosure</strong></li></ul><p>Apple's M4 Mac Mini has been transformed into a handheld Mac with a 7-inch 120Hz touchscreen, physical controls, keyboard, and battery.</p><p>Shing Solutions stripped the desktop computer down to its motherboard and cooling system before rebuilding it inside a custom 3D-printed enclosure.</p><p>The resulting device, dubbed Mac Nano, keeps the full macOS functionality while replacing the desk-bound form factor with something designed for use in two hands.</p><h2 id="the-mac-mini-becomes-a-removable-computing-core">The Mac Mini becomes a removable computing core</h2><p>The project retains Apple's original heatsink and blower fan instead of replacing them with smaller cooling hardware to save internal space.</p><p>That decision allows the M4 <a href="https://www.techradar.com/news/best-processors">processor</a> to retain its factory thermal arrangement while the motherboard moves into a completely different enclosure.</p><p>Inside the new chassis, the computer module sits on rails, allowing it to slide out without disturbing the screen, keyboard, or controllers.</p><p>The arrangement means the central hardware can theoretically be removed for servicing or replaced while the surrounding handheld computer remains assembled.</p><p>A 7-inch touchscreen provides the main display, with its 120Hz refresh rate giving the portable machine a smoother interface and gaming experience.</p><p>It is also equipped with a compact QWERTY keyboard sitting beneath the display, with an integrated touchpad providing cursor control.</p><p>The keyboard originally worked wirelessly, but its battery was removed, and the keyboard was rewired to draw power directly through USB.</p><p>This modification reduces the number of rechargeable components while allowing the keyboard to receive power directly from the handheld <a href="https://www.techradar.com/news/computing/pc/10-of-the-best-desktop-pcs-of-2015-1304391">computer</a>.</p><p>The internal layout therefore combines Apple's desktop motherboard with controls and display hardware that were never designed specifically for this computer.</p><h2 id="nintendo-controls-and-batteries-complete-the-handheld-device">Nintendo controls and batteries complete the handheld device</h2><p>The Mac Nano also includes physical gaming controls, using circuit boards taken from Nintendo Joy-Con charging grips and mounted inside both sides of the enclosure.</p><p>Those controls are wired directly into the Mac instead of using Bluetooth, but macOS does not natively support wired Joy Con controllers.</p><p>To make the controls usable, the project relies on Steam, whose controller mapping system can translate their input for compatible games.</p><p>Connecting the keyboard, controllers, touchscreen, and other peripherals also created a USB bottleneck inside the compact enclosure.</p><p>Shing Solutions addressed that problem by combining two miniature USB splitter boards into a custom three-port hub.</p><p>The Mac Nano is powered by rechargeable cells connected to a custom power delivery system, allowing it to run without staying plugged into an outlet.</p><p>The enclosure also incorporates handles, giving the device a grip that accommodates all its components.</p><p>Unlike a conventional <a href="https://www.techradar.com/computing/macbooks/apple-mac-mini-m4-2024https://www.techradar.com/computing/macbooks/apple-mac-mini-m4-2024">Mac Mini</a>, the Mac Nano therefore combines desktop Apple silicon with the components needed for genuinely untethered operation.</p><p>Via <a href="https://www.yankodesign.com/2026/09/14/the-mac-mini-belongs-on-a-desk-this-build-runs-it-from-your-hands/" target="_blank" rel="nofollow">Yanko Design</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple weighs its first server since the Xserve, and as always, Nvidia may hold the key ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Reports claim Apple is weighing an as-yet-unapproved enterprise AI server with two or four M8 Ultra chips, targeting 2029</strong></li><li><strong>Apple is considering using Nvidia's NVLink Fusion to link the chips, with Thunderbolt-based Mac clustering falling short of data center bandwidth requirements</strong></li><li><strong>The move comes as demand continues to be a key driver for Apple's higher-end Macs, with AI firms buying Mac minis and Mac Studios in bulk, even as Apple has turned enterprise buyers away</strong></li></ul><p>Apple has been working on plans for an enterprise AI server built on its own silicon with an interesting twist: it is seeking Nvidia's help on the networking front to make it work.</p><p>A report by <a href="https://www.theinformation.com/articles/apple-considers-return-server-market-talked-nvidia-use-network-tech" target="_blank"><em>The Information</em></a> claims Apple is considering two configurations: one with two of its future M8 Ultra chips and a larger one with four, aimed at businesses that want to run AI inference on their own hardware rather than in a public cloud.</p><p>The timeline, however, is long and loose, with a potential launch in 2029, though the same report cautions that the project could be canceled before then, with neither the server nor any Nvidia arrangement finalized at the time of writing.</p><h2 id="a-market-that-apple-previously-walked-away-from">A market that Apple previously walked away from</h2><p>If it ships, the machine would be Apple's first purpose-built server since the Xserve, which Apple announced it would discontinue in November 2010 and stopped selling at the end of January 2011.</p><p>Steve Jobs's explanation, in an email to a reader of French site MacGeneration, reported by <a href="https://www.macrumors.com/2010/11/08/steve-jobs-xserve-axed-over-poor-sales/" target="_blank" rel="nofollow"><em>MacRumors</em></a> at the time, was blunt: "Hardly anyone was buying them." Gartner's data backed up that claim with an estimated 10,000 units being sold per quarter, a relatively low number for the tech giant whose numbers normally ran in the hundreds of thousands or millions for most of its other products.</p><p>Apple's suggested replacements to users were server configurations of the Mac mini and Mac Pro, desktops running server software rather than rack hardware. If the 2029 launch materializes, it would mean Apple's reversal would see it enter the server market 18 years after the Xserve stopped being sold.</p><p>This time, however, feels different: The Information has reported that OpenAI bought tens of thousands of Mac minis and Mac Studios to train AI agents through reinforcement learning, and that Anthropic has rented Mac minis through Amazon Web Services, <a href="https://arstechnica.com/ai/2026/09/apple-reportedly-building-server-packed-with-m-series-ultra-chips-for-ai/" target="_blank">as per Ars Technica</a>.</p><h2 id="getting-caught-off-guard-by-ai-centric-demand">Getting caught off guard by AI-centric demand</h2><p>Apple reportedly was caught off guard by the AI-driven rush for its hardware, with no enterprise AI strategy, no business engineering team in place, and no specific developer relations staff to manage those orders. As a result, it also turned away businesses asking to buy access to its Private Cloud Compute infrastructure.</p><p>The project reportedly had a powerful sponsor: <a href="https://www.techradar.com/phones/iphone/i-dont-think-we-ever-lost-innovation-new-apple-ceo-john-ternus-defends-apples-track-record-as-his-first-september-launch-comes-to-a-close" target="_blank">Apple's now-CEO John Ternus,</a> when he ran Apple's hardware engineering team. However, shortages plagued it, leading many users to opt for Nvidia's DGX Spark and AMD's Ryzen AI Halo as viable alternatives.</p><p>The focus, however, remains on Apple's ability to interconnect a large number of chips or dies together: its current flagship, the M5 Ultra that ships in the new Mac Studio on September 22 2026, is Apple's first quad-die design, stitched together inside one package by the company's UltraFusion bridge, with up to 512GB of unified memory and 1.2TB/s of bandwidth, which users often stack for on-device AI needs.</p><p>A data center-esque, server-grade offering, however, would require considerably more power under the hood to meet its AI needs, which would also depend on how fast the interconnect between chips is; Apple's current limitation is Thunderbolt 5 speeds, which offer up to 10GB/s (or 80Gb/s) bidirectionally.</p><p>For context, Nvidia says the sixth-generation NVLink, available through NVLink Fusion, <a href="https://www.nvidia.com/en-us/data-center/nvlink-fusion/" target="_blank" rel="nofollow">connects up to 72 accelerators at 3.6TB/s each</a>. Comparing total two-way bandwidth, that is roughly 240 times a single Thunderbolt 5 connection's one-way capability of up to 15GB/s (or 120Gb/s).</p><p>Apple's own marketing hints at what that gap costs: It says four clustered Mac Studios deliver up to three times the inference performance of one, suggesting it already makes scaling tradeoffs of nearly 25% when linking devices. </p><p>This could explain why Nvidia is in the conversation at all: proven tech that could help Apple scale its AI server ambitions without the performance overhead it currently already has, at a time when its silicon would be even more powerful, might just be a no-brainer for the Cupertino-based giant.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/apple-weighs-its-first-server-since-the-xserve-and-as-always-nvidia-may-hold-the-key</link>
                                                                            <description>
                            <![CDATA[ The chip might matter less than the wiring between chips, and that is where Nvidia comes into play. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tF69mryTZmdm4oMziLwUi3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/D9pZcgdPinp5ty7pPDjKeY-1920-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 22:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/D9pZcgdPinp5ty7pPDjKeY-1920-80.png">
                                                            <media:credit><![CDATA[Nvidia]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Nvidia]]></media:description>                                                            <media:text><![CDATA[Nvidia]]></media:text>
                                <media:title type="plain"><![CDATA[Nvidia]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/D9pZcgdPinp5ty7pPDjKeY-1920-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Reports claim Apple is weighing an as-yet-unapproved enterprise AI server with two or four M8 Ultra chips, targeting 2029</strong></li><li><strong>Apple is considering using Nvidia's NVLink Fusion to link the chips, with Thunderbolt-based Mac clustering falling short of data center bandwidth requirements</strong></li><li><strong>The move comes as demand continues to be a key driver for Apple's higher-end Macs, with AI firms buying Mac minis and Mac Studios in bulk, even as Apple has turned enterprise buyers away</strong></li></ul><p>Apple has been working on plans for an enterprise AI server built on its own silicon with an interesting twist: it is seeking Nvidia's help on the networking front to make it work.</p><p>A report by <a href="https://www.theinformation.com/articles/apple-considers-return-server-market-talked-nvidia-use-network-tech" target="_blank"><em>The Information</em></a> claims Apple is considering two configurations: one with two of its future M8 Ultra chips and a larger one with four, aimed at businesses that want to run AI inference on their own hardware rather than in a public cloud.</p><p>The timeline, however, is long and loose, with a potential launch in 2029, though the same report cautions that the project could be canceled before then, with neither the server nor any Nvidia arrangement finalized at the time of writing.</p><h2 id="a-market-that-apple-previously-walked-away-from">A market that Apple previously walked away from</h2><p>If it ships, the machine would be Apple's first purpose-built server since the Xserve, which Apple announced it would discontinue in November 2010 and stopped selling at the end of January 2011.</p><p>Steve Jobs's explanation, in an email to a reader of French site MacGeneration, reported by <a href="https://www.macrumors.com/2010/11/08/steve-jobs-xserve-axed-over-poor-sales/" target="_blank" rel="nofollow"><em>MacRumors</em></a> at the time, was blunt: "Hardly anyone was buying them." Gartner's data backed up that claim with an estimated 10,000 units being sold per quarter, a relatively low number for the tech giant whose numbers normally ran in the hundreds of thousands or millions for most of its other products.</p><p>Apple's suggested replacements to users were server configurations of the Mac mini and Mac Pro, desktops running server software rather than rack hardware. If the 2029 launch materializes, it would mean Apple's reversal would see it enter the server market 18 years after the Xserve stopped being sold.</p><p>This time, however, feels different: The Information has reported that OpenAI bought tens of thousands of Mac minis and Mac Studios to train AI agents through reinforcement learning, and that Anthropic has rented Mac minis through Amazon Web Services, <a href="https://arstechnica.com/ai/2026/09/apple-reportedly-building-server-packed-with-m-series-ultra-chips-for-ai/" target="_blank">as per Ars Technica</a>.</p><h2 id="getting-caught-off-guard-by-ai-centric-demand">Getting caught off guard by AI-centric demand</h2><p>Apple reportedly was caught off guard by the AI-driven rush for its hardware, with no enterprise AI strategy, no business engineering team in place, and no specific developer relations staff to manage those orders. As a result, it also turned away businesses asking to buy access to its Private Cloud Compute infrastructure.</p><p>The project reportedly had a powerful sponsor: <a href="https://www.techradar.com/phones/iphone/i-dont-think-we-ever-lost-innovation-new-apple-ceo-john-ternus-defends-apples-track-record-as-his-first-september-launch-comes-to-a-close" target="_blank">Apple's now-CEO John Ternus,</a> when he ran Apple's hardware engineering team. However, shortages plagued it, leading many users to opt for Nvidia's DGX Spark and AMD's Ryzen AI Halo as viable alternatives.</p><p>The focus, however, remains on Apple's ability to interconnect a large number of chips or dies together: its current flagship, the M5 Ultra that ships in the new Mac Studio on September 22 2026, is Apple's first quad-die design, stitched together inside one package by the company's UltraFusion bridge, with up to 512GB of unified memory and 1.2TB/s of bandwidth, which users often stack for on-device AI needs.</p><p>A data center-esque, server-grade offering, however, would require considerably more power under the hood to meet its AI needs, which would also depend on how fast the interconnect between chips is; Apple's current limitation is Thunderbolt 5 speeds, which offer up to 10GB/s (or 80Gb/s) bidirectionally.</p><p>For context, Nvidia says the sixth-generation NVLink, available through NVLink Fusion, <a href="https://www.nvidia.com/en-us/data-center/nvlink-fusion/" target="_blank" rel="nofollow">connects up to 72 accelerators at 3.6TB/s each</a>. Comparing total two-way bandwidth, that is roughly 240 times a single Thunderbolt 5 connection's one-way capability of up to 15GB/s (or 120Gb/s).</p><p>Apple's own marketing hints at what that gap costs: It says four clustered Mac Studios deliver up to three times the inference performance of one, suggesting it already makes scaling tradeoffs of nearly 25% when linking devices. </p><p>This could explain why Nvidia is in the conversation at all: proven tech that could help Apple scale its AI server ambitions without the performance overhead it currently already has, at a time when its silicon would be even more powerful, might just be a no-brainer for the Cupertino-based giant.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Mistral denies a fresh security breach, but the code on sale looks a lot like May's leak ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Seller claims to be offering Mistral AI's full source code and says the company was breached again after May 2026 attack</strong></li><li><strong>Mistral says an investigation found no evidence of new unauthorized access but has not stated whether the listed code is genuine</strong></li><li><strong>No customer data has surfaced in analyzed samples, and nobody has shown files created after the May incident</strong></li></ul><p>A seller on a cybercrime forum says French giant Mistral AI has been hacked again and is offering what they call the company's full source code for sale.</p><p>The September 16 2026 post by an account using the handle "mrwho" consists of a listing titled "Selling mistral.ai Source Code" on an English-language cybercrime forum, <a href="https://thecybersecguru.com/news/mistral-ai-source-code-leak-2026/" target="_blank" rel="nofollow">according to The CyberSec Guru</a>, pricing the material in Monero only before it attempted to steer potential buyers to Session or Telegram.</p><p>Mistral AI's own team<a href="https://x.com/MistralAI/status/2100824200126529725" target="_blank"> has refuted</a> this, stating it has "found no evidence to support this claim."</p><h2 id="not-mistral-39-s-first-hacking-centric-pr-problem">Not Mistral's first hacking-centric PR problem</h2><p>Mistral's earlier hacking incident is undisputed - in May 2026, the Mini Shai-Hulud supply chain campaign, attributed to the TeamPCP group, spread from compromised TanStack packages to hundreds of npm and PyPI projects.</p><p>Mistral's own <a href="https://docs.mistral.ai/resources/security-advisories/MAI-2026-002" target="_blank" rel="nofollow">security advisory MAI-2026-002</a> says an automated worm led to compromised versions of its  SDKs being published for a few hours on May 11 and 12, and that an affected developer device was involved. <a href="https://www.tomshardware.com/tech-industry/cyber-security/compromised-mistral-ai-and-tanstack-packages-may-have-exposed-github-cloud-and-ci-cd-credentials-in-mini-shai-hulud-malware-infection-supply-chain-campaign-spreads-across-npm-and-ai-developer-ecosystems-like-wildfire" target="_blank" rel="nofollow">Microsoft Threat Intelligence found</a> that a poisoned Mistral AI Python package fetched a second-stage credential stealer that allowed the attack to exploit users.</p><p>Mistral went further in statements to reporters than in its advisory. It <a href="https://www.bleepingcomputer.com/news/security/teampcp-hackers-advertise-mistral-ai-code-repos-for-sale/" target="_blank">told <em>BleepingComputer</em></a> that attackers had compromised a codebase management system and "contaminated some of our SDK packages for a brief period," while insisting that hosted services, managed user data, and research and testing environments were untouched. It also <a href="https://hackread.com/teampcp-mistral-ai-repositories-mini-shai-hulud-attack/" target="_blank" rel="nofollow">told <em>HackRead</em></a> that only certain non-core repositories were accessed.</p><p>TeamPCP, meanwhile, advertised roughly 450 repositories, about 5GB in total, for $25,000, and <a href="https://www.techradar.com/pro/security/hackers-threaten-to-leak-mistral-files-online-ai-giant-confirms-breach-but-not-what-data-is-involved" target="_blank">threatened to dump them for free</a> if no buyer appeared within a week. One can therefore contend that this could be the same dump being remarketed by a different account, and the seller's profile is already suspect.</p><p><em>The CyberSec Guru</em> noted that the account joined in September 2026 and had four posts and a reputation score of 30, despite displaying a top-tier "GOD User" rank. That profile could fit a scam in the making, but as the outlet pointed out, it could also fit a broker fronting for someone else or a freshly minted alias.</p><p><em>HackRead</em> published 24 sample repository names from TeamPCP's May post. FrenchBreaches, which <a href="https://frenchbreaches.com/blog/mistral-ai-de-nouveau-piratee-un-hacker-revendique-la-totalite-de-son-code-source" target="_blank" rel="nofollow">examined the 339-file tree</a> mrwho shared in September, lists several of the same names. At least four of these appear in both: mistral-inference-private, mistral-inference-internal, mistral-finetune-internal, and mistral-common-internal.</p><p>This makes it hard to tell whether the purported 'hack' is just a rehash of an existing dump from Mistral's previous breach or a second successful hacking attempt. There is a straightforward test, however: If the September archives contain commits, files, or credentials dated after May 12, or secrets that were still valid after Mistral's cleanup, the seller's claim of a second breach gains real weight. If everything predates the May incident, this is a resale, which is embarrassing for Mistral but not a new security failure.</p><p>Of course, locating the archives or examining them would involve paying the ransom in crypto, as required by what could potentially be a scam in the making- a tremendous leap of faith for an account that was created earlier this month, making this essentially a lottery ticket at best for any security researcher attempting to take a closer look.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/mistral-denies-a-fresh-security-breach-but-the-code-on-sale-looks-a-lot-like-mays-leak</link>
                                                                            <description>
                            <![CDATA[ Mistral says the "stolen" code now on sale may simply be what walked out the door earlier in May 2026. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">W4MG4BDBwLWr8ES4bPXUJA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4AyzfXeFQkSE3gFjYpNsAQ-1920-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 21:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/4AyzfXeFQkSE3gFjYpNsAQ-1920-80.png">
                                                            <media:credit><![CDATA[Mistral]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Logo for Mistral AI]]></media:description>                                                            <media:text><![CDATA[The Logo for Mistral AI]]></media:text>
                                <media:title type="plain"><![CDATA[The Logo for Mistral AI]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4AyzfXeFQkSE3gFjYpNsAQ-1920-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Seller claims to be offering Mistral AI's full source code and says the company was breached again after May 2026 attack</strong></li><li><strong>Mistral says an investigation found no evidence of new unauthorized access but has not stated whether the listed code is genuine</strong></li><li><strong>No customer data has surfaced in analyzed samples, and nobody has shown files created after the May incident</strong></li></ul><p>A seller on a cybercrime forum says French giant Mistral AI has been hacked again and is offering what they call the company's full source code for sale.</p><p>The September 16 2026 post by an account using the handle "mrwho" consists of a listing titled "Selling mistral.ai Source Code" on an English-language cybercrime forum, <a href="https://thecybersecguru.com/news/mistral-ai-source-code-leak-2026/" target="_blank" rel="nofollow">according to The CyberSec Guru</a>, pricing the material in Monero only before it attempted to steer potential buyers to Session or Telegram.</p><p>Mistral AI's own team<a href="https://x.com/MistralAI/status/2100824200126529725" target="_blank"> has refuted</a> this, stating it has "found no evidence to support this claim."</p><h2 id="not-mistral-39-s-first-hacking-centric-pr-problem">Not Mistral's first hacking-centric PR problem</h2><p>Mistral's earlier hacking incident is undisputed - in May 2026, the Mini Shai-Hulud supply chain campaign, attributed to the TeamPCP group, spread from compromised TanStack packages to hundreds of npm and PyPI projects.</p><p>Mistral's own <a href="https://docs.mistral.ai/resources/security-advisories/MAI-2026-002" target="_blank" rel="nofollow">security advisory MAI-2026-002</a> says an automated worm led to compromised versions of its  SDKs being published for a few hours on May 11 and 12, and that an affected developer device was involved. <a href="https://www.tomshardware.com/tech-industry/cyber-security/compromised-mistral-ai-and-tanstack-packages-may-have-exposed-github-cloud-and-ci-cd-credentials-in-mini-shai-hulud-malware-infection-supply-chain-campaign-spreads-across-npm-and-ai-developer-ecosystems-like-wildfire" target="_blank" rel="nofollow">Microsoft Threat Intelligence found</a> that a poisoned Mistral AI Python package fetched a second-stage credential stealer that allowed the attack to exploit users.</p><p>Mistral went further in statements to reporters than in its advisory. It <a href="https://www.bleepingcomputer.com/news/security/teampcp-hackers-advertise-mistral-ai-code-repos-for-sale/" target="_blank">told <em>BleepingComputer</em></a> that attackers had compromised a codebase management system and "contaminated some of our SDK packages for a brief period," while insisting that hosted services, managed user data, and research and testing environments were untouched. It also <a href="https://hackread.com/teampcp-mistral-ai-repositories-mini-shai-hulud-attack/" target="_blank" rel="nofollow">told <em>HackRead</em></a> that only certain non-core repositories were accessed.</p><p>TeamPCP, meanwhile, advertised roughly 450 repositories, about 5GB in total, for $25,000, and <a href="https://www.techradar.com/pro/security/hackers-threaten-to-leak-mistral-files-online-ai-giant-confirms-breach-but-not-what-data-is-involved" target="_blank">threatened to dump them for free</a> if no buyer appeared within a week. One can therefore contend that this could be the same dump being remarketed by a different account, and the seller's profile is already suspect.</p><p><em>The CyberSec Guru</em> noted that the account joined in September 2026 and had four posts and a reputation score of 30, despite displaying a top-tier "GOD User" rank. That profile could fit a scam in the making, but as the outlet pointed out, it could also fit a broker fronting for someone else or a freshly minted alias.</p><p><em>HackRead</em> published 24 sample repository names from TeamPCP's May post. FrenchBreaches, which <a href="https://frenchbreaches.com/blog/mistral-ai-de-nouveau-piratee-un-hacker-revendique-la-totalite-de-son-code-source" target="_blank" rel="nofollow">examined the 339-file tree</a> mrwho shared in September, lists several of the same names. At least four of these appear in both: mistral-inference-private, mistral-inference-internal, mistral-finetune-internal, and mistral-common-internal.</p><p>This makes it hard to tell whether the purported 'hack' is just a rehash of an existing dump from Mistral's previous breach or a second successful hacking attempt. There is a straightforward test, however: If the September archives contain commits, files, or credentials dated after May 12, or secrets that were still valid after Mistral's cleanup, the seller's claim of a second breach gains real weight. If everything predates the May incident, this is a resale, which is embarrassing for Mistral but not a new security failure.</p><p>Of course, locating the archives or examining them would involve paying the ransom in crypto, as required by what could potentially be a scam in the making- a tremendous leap of faith for an account that was created earlier this month, making this essentially a lottery ticket at best for any security researcher attempting to take a closer look.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The British Army is spending £16 million on 1,000 small drones in a bid to boost battlefield operations ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Over 1,000 small drones are being added to the British Army’s modernized battlefield surveillance kit</strong></li><li><strong>245 FOXE-NATO drones from Evolve Dynamics in Hampshire, England, have been ordered by the Ministry of Defence (MoD), with a further 670 built by California-based Skydio</strong></li><li><strong>A further £400 million investment in “long-endurance surveillance drones” has also been announced</strong></li></ul><p>The British government has announced spending on over 1,000 small surveillance drones for the British Army, as part of its Defence Investment Plan. This includes compact, lightweight devices assembled at UK-based Evolve Dynamics, designed for fast deployment.</p><p>Announcing the spending plans and investment, the UK’s Ministry of Defence has emphasized the use of what it terms Intelligence, Surveillance and Reconnaissance (ISR) drones as a step forward in detecting emerging threats.</p><p>In addition, a huge £400 million is being invested in replacing the Watchkeeper Uncrewed Air System. This unmanned drone surveillance program has been in operation since 2014, and is being retired in 2027.</p><h2 id="uk-companies-handling-delivery">UK companies handling delivery</h2><p>In total, 1,025 smaller drones are being procured in the £16 million deal, which involves deals with a trio of UK-based companies. Among these small and medium sized companies is Evolve Dynamics, a Hampshire-based company which is supplying the army with 245 FOXE-NATO drones. Weighing under 250g and equipped with infrared cameras for nighttime use, the FOXE-NATO drones are also designed for quick deployment from a backpack or pouch.</p><p>Meanwhile, Marlborough Communications Limited, in Surrey, England, is supplying the MoD with 670 Skydio X10 INTL drones, also capable of a fast deployment and speeds of up to 45 mpg. Skydio is a California-based company.</p><p>Finally, Exeter-based Brigantes Consulting and and Harmattan AI are delivering 110 SONORA drones. These are training devices, to prepare soldiers for using field-ready drones.</p><p>“Our soldiers deserve the best technology, and that’s what we’re delivering,” said Luke Pollard MP, the UK’s Minister for Defence Readiness and Industry.</p><p>“From small drones giving troops eyes on the enemy, to the AR5 offering commanders better intelligence over the battlefield, we’re transforming the Army’s ability to see, understand and act first.”</p><p>“This is defence procurement that backs British industry, creates skilled jobs and keeps our Armed Forces ahead of our adversaries.”</p><h2 id="long-endurance">Long-endurance</h2><p>Joining the smaller surveillance and training drone expenditure, the MoD has announced a £400 million spend on a fleet of Tekever AR5 surveillance drones (initially six, rising to 24 by 2029), designed and built for endurance. These craft have already seen action in Ukraine.</p><p>“We are proud to be delivering the AR5 to the British Army at this critical moment for national security,” said Tekever UK’s Managing Director Karl Brew. “This investment allows us to grow our UK operations, create hundreds of skilled jobs and bring cutting-edge surveillance technology, proven on the battlefield in Ukraine, into service with British forces.”</p><p>These units, capable of carrying up to 50kg of cameras and sensors, are being assembled at Swindon, UK, and the contract is expected to create 1,000 jobs at sites around the UK, including sites in the South West, Edinburgh, and London. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/the-british-army-is-spending-gbp16-million-on-1-000-small-drones-in-a-bid-to-boost-battlefield-operations</link>
                                                                            <description>
                            <![CDATA[ New British-built spy drones will be deployed by the British Army to conduct surveillance and training, including a small 250 gram quadcopter. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gPE8rnL8tQHVnuAyePFka4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/f4bc45Y5nPZS2UKRydrrYH-1920-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 19:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Drones]]></category>
                                                    <category><![CDATA[Cameras]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/f4bc45Y5nPZS2UKRydrrYH-1920-80.png">
                                                            <media:credit><![CDATA[Skydio]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Soldier launches drone]]></media:description>                                                            <media:text><![CDATA[Soldier launches drone]]></media:text>
                                <media:title type="plain"><![CDATA[Soldier launches drone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/f4bc45Y5nPZS2UKRydrrYH-1920-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Over 1,000 small drones are being added to the British Army’s modernized battlefield surveillance kit</strong></li><li><strong>245 FOXE-NATO drones from Evolve Dynamics in Hampshire, England, have been ordered by the Ministry of Defence (MoD), with a further 670 built by California-based Skydio</strong></li><li><strong>A further £400 million investment in “long-endurance surveillance drones” has also been announced</strong></li></ul><p>The British government has announced spending on over 1,000 small surveillance drones for the British Army, as part of its Defence Investment Plan. This includes compact, lightweight devices assembled at UK-based Evolve Dynamics, designed for fast deployment.</p><p>Announcing the spending plans and investment, the UK’s Ministry of Defence has emphasized the use of what it terms Intelligence, Surveillance and Reconnaissance (ISR) drones as a step forward in detecting emerging threats.</p><p>In addition, a huge £400 million is being invested in replacing the Watchkeeper Uncrewed Air System. This unmanned drone surveillance program has been in operation since 2014, and is being retired in 2027.</p><h2 id="uk-companies-handling-delivery">UK companies handling delivery</h2><p>In total, 1,025 smaller drones are being procured in the £16 million deal, which involves deals with a trio of UK-based companies. Among these small and medium sized companies is Evolve Dynamics, a Hampshire-based company which is supplying the army with 245 FOXE-NATO drones. Weighing under 250g and equipped with infrared cameras for nighttime use, the FOXE-NATO drones are also designed for quick deployment from a backpack or pouch.</p><p>Meanwhile, Marlborough Communications Limited, in Surrey, England, is supplying the MoD with 670 Skydio X10 INTL drones, also capable of a fast deployment and speeds of up to 45 mpg. Skydio is a California-based company.</p><p>Finally, Exeter-based Brigantes Consulting and and Harmattan AI are delivering 110 SONORA drones. These are training devices, to prepare soldiers for using field-ready drones.</p><p>“Our soldiers deserve the best technology, and that’s what we’re delivering,” said Luke Pollard MP, the UK’s Minister for Defence Readiness and Industry.</p><p>“From small drones giving troops eyes on the enemy, to the AR5 offering commanders better intelligence over the battlefield, we’re transforming the Army’s ability to see, understand and act first.”</p><p>“This is defence procurement that backs British industry, creates skilled jobs and keeps our Armed Forces ahead of our adversaries.”</p><h2 id="long-endurance">Long-endurance</h2><p>Joining the smaller surveillance and training drone expenditure, the MoD has announced a £400 million spend on a fleet of Tekever AR5 surveillance drones (initially six, rising to 24 by 2029), designed and built for endurance. These craft have already seen action in Ukraine.</p><p>“We are proud to be delivering the AR5 to the British Army at this critical moment for national security,” said Tekever UK’s Managing Director Karl Brew. “This investment allows us to grow our UK operations, create hundreds of skilled jobs and bring cutting-edge surveillance technology, proven on the battlefield in Ukraine, into service with British forces.”</p><p>These units, capable of carrying up to 50kg of cameras and sensors, are being assembled at Swindon, UK, and the contract is expected to create 1,000 jobs at sites around the UK, including sites in the South West, Edinburgh, and London. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'We just don't see that there's enough technical people in the pipeline': US chip fabs are facing a huge worker shortfall — despite promise of huge paychecks, industry says it still needs over 150,000 workers ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>The US could have a 157,000 shortage of semiconductor and microelectronics workers by 2030</strong></li><li><strong>International chip makers are reportedly bringing in workers as a temporary measure</strong></li><li><strong>Worker salaries aren't the issue, but competition with other sectors might be</strong></li></ul><p>New analysis from the SEMI Foundation has <a href="https://www.semi.org/en/taxonomy/term/45736" target="_blank">revealed</a> the US could face a shortage of up to 157,000 semiconductor and microelectronics workers by as soon as 2030.</p><p>This shortage will likely cover all manner of jobs, right from semiconductor engineers to supply chain workers and maintenance staff, putting immense pressure on the sector at the very time that it needs all the resources it can get.</p><p>Speaking with <a href="https://www.cnbc.com/2026/09/17/us-chipmakers-face-deep-labor-shortage-samsung-micron-sound-alarm.html?link_source=ta_bluesky_link&taid=6aabcafefbc2160001c2b2fb&utm_campaign=trueanthem&utm_content=main&utm_medium=social&utm_source=bluesky" target="_blank"><em>CNBC</em></a>, Samsung semiconductor EVP Jon Taylor declared that the company is "concerned" because it's not seeing enough technical workers coming through the US pipeline.</p><h2 id="chipmakers-are-worried-about-a-lack-of-workers">Chipmakers are worried about a lack of workers</h2><p>Only 3% of US engineering graduates enter the semiconductor industry every year, the report warns, with nearly three in four (73%) semiconductor companies reporting significant difficulties recruiting engineers.</p><p>The ongoing AI boom, and especially America and the Trump administration's push for more domestic manufacturing and AI processing, are accentuating this shortage of workers. According to McKinsey, semiconductor sales growth during the first six months of 2026 reached its highest year-on-year rate since the mid 80s, with revenue surpassing the trillion-dollar mark.</p><p>Numerous high-profile companies are also working on expanding their US footprints despite the clear strains. Samsung itself reportedly expects to create around 3,500 new jobs from two fabs at its Taylor, Texas site, however it's unclear with how much success it will fill them given news about recruitment struggles.</p><p>Micron, SK Hynix, TSMC and Intel are also opening new manufacturing facilities, per the <em>CNBC</em> report.</p><p>However, the report also reveals that both Samsung and SK Hynix are bringing in workers from South Korea temporarily to offset some of those US struggles.</p><h2 id="us-workers-don-39-t-want-to-work-in-chip-manufacturing-but-why">US workers don't want to work in chip manufacturing, but why?</h2><p>Despite low uptake, these roles typically fetch some pretty attractive salaries. SEMI's figures put typical US semiconductor compensation around $127,000 to $187,000, with some senior roles exceeding $238,000.</p><p>Ultimately, it's clear that companies are willing to pay the right compensation to attract workers, so the issue lies elsewhere.</p><p>And it could be cross-sector competition that's making jobs at other companies more attractive – semiconductor workers are also great fits for software, AI and aerospace, per the report.</p><p>In the meantime, hyperscalers are increasingly prepared to remind us that investments in new campuses also go hand-in-hand with local training opportunities, college funding and upskilling. But with the impacts of those schemes unlikely to be seen for many years, it's likely that many US semiconductor roles could remain unfilled in the meantime.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/we-just-dont-see-that-theres-enough-technical-people-in-the-pipeline-us-chip-fabs-are-facing-a-huge-worker-shortfall-despite-promise-of-huge-paychecks-industry-says-it-still-needs-over-150-000-workers</link>
                                                                            <description>
                            <![CDATA[ America is struggling to fill its semiconductor manufacturing facilities, but it's offering to pay workers six-figure salaries. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nrvH984VrP6s86LDwTgKdB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WooupqXCjvQ7NtEaWtANDi-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 18:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WooupqXCjvQ7NtEaWtANDi-1920-80.jpg">
                                                            <media:credit><![CDATA[Wang Gang/China News Service via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Employees work on the production line of silicon wafer at a factory in Jiaxing City, China]]></media:description>                                                            <media:text><![CDATA[Employees work on the production line of silicon wafer at a factory in Jiaxing City, China]]></media:text>
                                <media:title type="plain"><![CDATA[Employees work on the production line of silicon wafer at a factory in Jiaxing City, China]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WooupqXCjvQ7NtEaWtANDi-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>The US could have a 157,000 shortage of semiconductor and microelectronics workers by 2030</strong></li><li><strong>International chip makers are reportedly bringing in workers as a temporary measure</strong></li><li><strong>Worker salaries aren't the issue, but competition with other sectors might be</strong></li></ul><p>New analysis from the SEMI Foundation has <a href="https://www.semi.org/en/taxonomy/term/45736" target="_blank">revealed</a> the US could face a shortage of up to 157,000 semiconductor and microelectronics workers by as soon as 2030.</p><p>This shortage will likely cover all manner of jobs, right from semiconductor engineers to supply chain workers and maintenance staff, putting immense pressure on the sector at the very time that it needs all the resources it can get.</p><p>Speaking with <a href="https://www.cnbc.com/2026/09/17/us-chipmakers-face-deep-labor-shortage-samsung-micron-sound-alarm.html?link_source=ta_bluesky_link&taid=6aabcafefbc2160001c2b2fb&utm_campaign=trueanthem&utm_content=main&utm_medium=social&utm_source=bluesky" target="_blank"><em>CNBC</em></a>, Samsung semiconductor EVP Jon Taylor declared that the company is "concerned" because it's not seeing enough technical workers coming through the US pipeline.</p><h2 id="chipmakers-are-worried-about-a-lack-of-workers">Chipmakers are worried about a lack of workers</h2><p>Only 3% of US engineering graduates enter the semiconductor industry every year, the report warns, with nearly three in four (73%) semiconductor companies reporting significant difficulties recruiting engineers.</p><p>The ongoing AI boom, and especially America and the Trump administration's push for more domestic manufacturing and AI processing, are accentuating this shortage of workers. According to McKinsey, semiconductor sales growth during the first six months of 2026 reached its highest year-on-year rate since the mid 80s, with revenue surpassing the trillion-dollar mark.</p><p>Numerous high-profile companies are also working on expanding their US footprints despite the clear strains. Samsung itself reportedly expects to create around 3,500 new jobs from two fabs at its Taylor, Texas site, however it's unclear with how much success it will fill them given news about recruitment struggles.</p><p>Micron, SK Hynix, TSMC and Intel are also opening new manufacturing facilities, per the <em>CNBC</em> report.</p><p>However, the report also reveals that both Samsung and SK Hynix are bringing in workers from South Korea temporarily to offset some of those US struggles.</p><h2 id="us-workers-don-39-t-want-to-work-in-chip-manufacturing-but-why">US workers don't want to work in chip manufacturing, but why?</h2><p>Despite low uptake, these roles typically fetch some pretty attractive salaries. SEMI's figures put typical US semiconductor compensation around $127,000 to $187,000, with some senior roles exceeding $238,000.</p><p>Ultimately, it's clear that companies are willing to pay the right compensation to attract workers, so the issue lies elsewhere.</p><p>And it could be cross-sector competition that's making jobs at other companies more attractive – semiconductor workers are also great fits for software, AI and aerospace, per the report.</p><p>In the meantime, hyperscalers are increasingly prepared to remind us that investments in new campuses also go hand-in-hand with local training opportunities, college funding and upskilling. But with the impacts of those schemes unlikely to be seen for many years, it's likely that many US semiconductor roles could remain unfilled in the meantime.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Talk about catch of the day — Florida fishing charter snags a huge military drone in the Gulf of Mexico, but no one is claiming it yet ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Pensacola fishermen pulls large unidentified military drone from the Gulf</strong></li><li><strong>The aircraft surfaced only miles from Eglin’s extensive military testing zones</strong></li><li><strong>Authorities recovered the drone without publicly identifying its origin or mission</strong></li></ul><p>A Pensacola-based fishing charter pulled a large military-style drone from Gulf of Mexico waters over the weekend, surprising both crew and onlookers.</p><p>Hot Spot Fishing Charters discovered it during a routine six-hour trip roughly 15 to 30 miles offshore from Pensacola Beach.</p><p>Authorities arrived later that same day and retrieved the aircraft, though details about the recovery process itself remain largely unavailable to the public.</p><h2 id="an-unusual-interruption">An unusual interruption</h2><p>The waters near this stretch of coastline sit close to Eglin Air Force Base, one of the largest military test ranges nationwide.</p><p>That base oversees restricted airspace and offshore zones used for trials of advanced weapons systems, including hypersonic missile technology in recent years.</p><p>The exact model of the <a href="https://www.techradar.com/cameras/drones/best-drone">drone</a> remains unconfirmed, though local station WEAR-TV suggested the aircraft resembles an MQM-172, a drone flown for weapons testing and aircrew training.</p><p>The delta-wing shape of that platform also resembles Iran's Shahed-136 strike drone, a design widely recognized for its distinctive triangular silhouette.</p><p>Such resemblance likely explains why a civilian fishing crew would pause and take a closer notice of an unfamiliar aircraft floating offshore.</p><p>WEAR-TV described the discovery only as a large drone pulled from Gulf waters, providing little additional identifying information beyond that.</p><p>A brief video clip, shared widely across social media platforms, shows crew members hauling the large aircraft aboard their vessel.</p><p>The charter company regularly runs six- to eight-hour offshore excursions, giving anglers access to waters far beyond the immediate coastline.</p><p>Those extended trips routinely place crews within range of restricted military zones tied to ongoing weapons trials and training missions.</p><p>Eglin's long association with cutting-edge programs, including hypersonic missile trials, adds extra intrigue to any unexplained hardware found nearby offshore.</p><h2 id="lingering-questions">Lingering questions</h2><p>No agency has issued a public statement claiming the aircraft or explaining how it drifted into civilian waters.</p><p>Regulations at Eglin explicitly bar small unmanned aircraft systems from operating within the base's land reservation and its surrounding boundaries as well.</p><p>Aircraft used for weapons testing sometimes conclude their operational service in open water, particularly following live-fire exercises conducted offshore near the base.</p><p>Whether this particular drone came from a specific Eglin program or another branch's testing effort remains an open question for now.</p><p>Investigators have not confirmed whether the aircraft drifted naturally with Gulf currents or was intentionally released during a recovery attempt.</p><p>Images circulating online appear to show visible damage along the fuselage, consistent with an extended period spent adrift at sea.</p><p>Residents have expressed curiosity about whether similar recoveries might happen again given the area's ongoing military testing activity.</p><p>It usually takes days or weeks for government officials to comment on unexplained hardware recovered along the Gulf coastline, especially when it's military.</p><p>Via <a href="https://www.gadgetreview.com/a-pensacola-fishing-charter-hauled-a-large-military-drone-out-of-the-gulf" target="_blank" rel="nofollow">Gadget Review</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/talk-about-catch-of-the-day-florida-fishing-charter-snags-a-huge-military-drone-in-the-gulf-of-mexico-but-no-one-is-claiming-it-yet</link>
                                                                            <description>
                            <![CDATA[ A Pensacola fishing crew recovered a large unidentified military-style drone from Gulf waters near Eglin Air Force Base during an offshore trip. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">f8jNfFJ9Mx3b3bMB8kYHkj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BBTarJ8eYD7XaRpcek2q6D-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 18:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BBTarJ8eYD7XaRpcek2q6D-1920-80.jpg">
                                                            <media:credit><![CDATA[Gadget Review]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Recovered large military-style drone]]></media:description>                                                            <media:text><![CDATA[Recovered large military-style drone]]></media:text>
                                <media:title type="plain"><![CDATA[Recovered large military-style drone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BBTarJ8eYD7XaRpcek2q6D-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Pensacola fishermen pulls large unidentified military drone from the Gulf</strong></li><li><strong>The aircraft surfaced only miles from Eglin’s extensive military testing zones</strong></li><li><strong>Authorities recovered the drone without publicly identifying its origin or mission</strong></li></ul><p>A Pensacola-based fishing charter pulled a large military-style drone from Gulf of Mexico waters over the weekend, surprising both crew and onlookers.</p><p>Hot Spot Fishing Charters discovered it during a routine six-hour trip roughly 15 to 30 miles offshore from Pensacola Beach.</p><p>Authorities arrived later that same day and retrieved the aircraft, though details about the recovery process itself remain largely unavailable to the public.</p><h2 id="an-unusual-interruption">An unusual interruption</h2><p>The waters near this stretch of coastline sit close to Eglin Air Force Base, one of the largest military test ranges nationwide.</p><p>That base oversees restricted airspace and offshore zones used for trials of advanced weapons systems, including hypersonic missile technology in recent years.</p><p>The exact model of the <a href="https://www.techradar.com/cameras/drones/best-drone">drone</a> remains unconfirmed, though local station WEAR-TV suggested the aircraft resembles an MQM-172, a drone flown for weapons testing and aircrew training.</p><p>The delta-wing shape of that platform also resembles Iran's Shahed-136 strike drone, a design widely recognized for its distinctive triangular silhouette.</p><p>Such resemblance likely explains why a civilian fishing crew would pause and take a closer notice of an unfamiliar aircraft floating offshore.</p><p>WEAR-TV described the discovery only as a large drone pulled from Gulf waters, providing little additional identifying information beyond that.</p><p>A brief video clip, shared widely across social media platforms, shows crew members hauling the large aircraft aboard their vessel.</p><p>The charter company regularly runs six- to eight-hour offshore excursions, giving anglers access to waters far beyond the immediate coastline.</p><p>Those extended trips routinely place crews within range of restricted military zones tied to ongoing weapons trials and training missions.</p><p>Eglin's long association with cutting-edge programs, including hypersonic missile trials, adds extra intrigue to any unexplained hardware found nearby offshore.</p><h2 id="lingering-questions">Lingering questions</h2><p>No agency has issued a public statement claiming the aircraft or explaining how it drifted into civilian waters.</p><p>Regulations at Eglin explicitly bar small unmanned aircraft systems from operating within the base's land reservation and its surrounding boundaries as well.</p><p>Aircraft used for weapons testing sometimes conclude their operational service in open water, particularly following live-fire exercises conducted offshore near the base.</p><p>Whether this particular drone came from a specific Eglin program or another branch's testing effort remains an open question for now.</p><p>Investigators have not confirmed whether the aircraft drifted naturally with Gulf currents or was intentionally released during a recovery attempt.</p><p>Images circulating online appear to show visible damage along the fuselage, consistent with an extended period spent adrift at sea.</p><p>Residents have expressed curiosity about whether similar recoveries might happen again given the area's ongoing military testing activity.</p><p>It usually takes days or weeks for government officials to comment on unexplained hardware recovered along the Gulf coastline, especially when it's military.</p><p>Via <a href="https://www.gadgetreview.com/a-pensacola-fishing-charter-hauled-a-large-military-drone-out-of-the-gulf" target="_blank" rel="nofollow">Gadget Review</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Texas Governor Greg Abbott and California Governor Gavin Newsom just introduced new data center rules —  and it's a big win for local communities ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Texas Gov. Abbott bans new data center grid connections until key audit is finished</strong></li><li><strong>California Gov. Newsom introduces new laws regulating data center land, energy, and water usage</strong></li><li><strong>Federal regulations could also be coming soon, but the midterms are still to go</strong></li></ul><p>AI data centers in the US have been dealt another blow due to new regulations and rules rolled out in Texas and California.</p><p>Texas Governor Greg Abbott has expanded the reach of a de facto moratorium on new data centers until a new electricity audit has been completed, effectively preventing any new data centers from being granted environmental permits or grid permissions.</p><p>At the same time, California Governor Gavin Newsom has signed into law new regulations which provide communities with greater control over the water, electricity, and land use of data centers built in the state.</p><h2 id="states-are-backing-communities-not-big-tech">States are backing communities, not big tech</h2><p>“Simply put, Texans must come first,” Texas Governor Abbott said. “Data centers must pay their own way, protect our grid and water, and complete the ERCOT and audits” (via <a href="https://www.politico.com/news/2026/09/21/abbott-texas-data-center-permits-halt-01086398" target="_blank" rel="nofollow"><em>Politico</em></a>).</p><p>According to ERCOT, which operates the Texas electricity grid, approvals for data centers to connect could be paused until December when the audit is expected to be completed. Until then, no new connections will be authorized.</p><p>Texans have been increasingly vocal about their opinions on data centers, particularly when it comes to land use, noise, pollution, and strain on the electricity grid. The issue has become such a big topic that Texas and other states have seen a jump in first-time candidates for local elections.</p><p>Abbott himself was previously pro-data center, advertising Texas as the “epicenter of AI development”, but has made a rapid pivot in stance - <a href="https://www.techradar.com/pro/trump-warns-communities-opposed-to-data-centers-are-making-a-mistake-but-texas-gov-greg-abbott-data-centers-got-the-backlash-they-deserve" target="_blank">recently stating that data centers are getting “the backlash they deserve”</a>.</p><p>In California, Governor Newsom’s new data center laws aim to move much of the costs imposed by data centers connecting to resources away from the public’s purse, and back onto data centers.</p><p>To this end, electrical grid connections and upgrade costs will be shouldered by the data centers requesting them, with additional requirements that new data centers will have to add new clean energy to supplement the additional energy they will consume.</p><p>More transparency is being added to data center water usage as well. Proposed projects will now have to inform local governments of water use, supply, efficiency and drought planning - with similar requirements to pay for infrastructural upgrades.</p><p>Land usage requirements are also under the regulatory hammer, with data centers no longer exempt from environmental regulations. Instead, proposed projects will have to meet state standards on energy, water, and fuel consumption while also mitigating any downstream costs for ratepayers.</p><h2 id="federal-regulation-could-be-coming-too">Federal regulation could be coming too</h2><p>Federal level regulation is making progress too.</p><p>The <a href="https://www.techradar.com/pro/families-farmers-and-small-businesses-should-not-be-forced-to-cover-the-costs-of-new-power-generation-forget-trumps-voluntary-commitment-this-new-bipartisan-act-wants-to-force-ai-companies-to-pay-for-the-energy-they-use" target="_blank">Ratepayer Protection Act</a> aims to make the developers of medium and large campuses pay for the infrastructural upgrades and grid connections required for data centers with a peak power of over 100MW.</p><p><a href="https://www.techradar.com/pro/bill-to-make-ai-data-centers-pay-for-power-grid-upgrades-reaches-critical-milestone" target="_blank">The Act was recently passed by House lawmakers</a> with bipartisan support, and is now headed to Congress for approval. But due to the midterm elections, the Act may not be signed into law until the end of the year.</p><p>Data center opposition and state-level regulations have drawn significant criticism from the White House. President Trump said that those opposed to AI data centers are “making a mistake” adding that communities would miss out on the “tremendous amounts of jobs and money” that having a local data center would provide.</p><p>In the second quarter of 2026, over $68 billion in data center projects have been <a href="https://www.tomshardware.com/tech-industry/data-centers/local-opposition-blocked-usd68-billion-worth-of-data-center-projects-in-the-second-quarter-of-2026-data-center-investments-reportedly-still-on-track-to-hit-usd32-trillion-by-2050">successfully blocked by local opposition</a> with a total of 45 proposed projects being opposed.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/texas-governor-greg-abbott-and-california-governor-gavin-newsom-just-introduced-new-data-center-rules-and-its-a-big-win-for-local-communities</link>
                                                                            <description>
                            <![CDATA[ Texas and California are listening to the voices of its people, and they're making data centers harder to build. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">j6QDoxqFvkckbj7jLokgTJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/h8PtKoPckFsFwU8xPtXRhk-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/h8PtKoPckFsFwU8xPtXRhk-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/Sashkin]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data centre.]]></media:description>                                                            <media:text><![CDATA[Data centre.]]></media:text>
                                <media:title type="plain"><![CDATA[Data centre.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/h8PtKoPckFsFwU8xPtXRhk-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Texas Gov. Abbott bans new data center grid connections until key audit is finished</strong></li><li><strong>California Gov. Newsom introduces new laws regulating data center land, energy, and water usage</strong></li><li><strong>Federal regulations could also be coming soon, but the midterms are still to go</strong></li></ul><p>AI data centers in the US have been dealt another blow due to new regulations and rules rolled out in Texas and California.</p><p>Texas Governor Greg Abbott has expanded the reach of a de facto moratorium on new data centers until a new electricity audit has been completed, effectively preventing any new data centers from being granted environmental permits or grid permissions.</p><p>At the same time, California Governor Gavin Newsom has signed into law new regulations which provide communities with greater control over the water, electricity, and land use of data centers built in the state.</p><h2 id="states-are-backing-communities-not-big-tech">States are backing communities, not big tech</h2><p>“Simply put, Texans must come first,” Texas Governor Abbott said. “Data centers must pay their own way, protect our grid and water, and complete the ERCOT and audits” (via <a href="https://www.politico.com/news/2026/09/21/abbott-texas-data-center-permits-halt-01086398" target="_blank" rel="nofollow"><em>Politico</em></a>).</p><p>According to ERCOT, which operates the Texas electricity grid, approvals for data centers to connect could be paused until December when the audit is expected to be completed. Until then, no new connections will be authorized.</p><p>Texans have been increasingly vocal about their opinions on data centers, particularly when it comes to land use, noise, pollution, and strain on the electricity grid. The issue has become such a big topic that Texas and other states have seen a jump in first-time candidates for local elections.</p><p>Abbott himself was previously pro-data center, advertising Texas as the “epicenter of AI development”, but has made a rapid pivot in stance - <a href="https://www.techradar.com/pro/trump-warns-communities-opposed-to-data-centers-are-making-a-mistake-but-texas-gov-greg-abbott-data-centers-got-the-backlash-they-deserve" target="_blank">recently stating that data centers are getting “the backlash they deserve”</a>.</p><p>In California, Governor Newsom’s new data center laws aim to move much of the costs imposed by data centers connecting to resources away from the public’s purse, and back onto data centers.</p><p>To this end, electrical grid connections and upgrade costs will be shouldered by the data centers requesting them, with additional requirements that new data centers will have to add new clean energy to supplement the additional energy they will consume.</p><p>More transparency is being added to data center water usage as well. Proposed projects will now have to inform local governments of water use, supply, efficiency and drought planning - with similar requirements to pay for infrastructural upgrades.</p><p>Land usage requirements are also under the regulatory hammer, with data centers no longer exempt from environmental regulations. Instead, proposed projects will have to meet state standards on energy, water, and fuel consumption while also mitigating any downstream costs for ratepayers.</p><h2 id="federal-regulation-could-be-coming-too">Federal regulation could be coming too</h2><p>Federal level regulation is making progress too.</p><p>The <a href="https://www.techradar.com/pro/families-farmers-and-small-businesses-should-not-be-forced-to-cover-the-costs-of-new-power-generation-forget-trumps-voluntary-commitment-this-new-bipartisan-act-wants-to-force-ai-companies-to-pay-for-the-energy-they-use" target="_blank">Ratepayer Protection Act</a> aims to make the developers of medium and large campuses pay for the infrastructural upgrades and grid connections required for data centers with a peak power of over 100MW.</p><p><a href="https://www.techradar.com/pro/bill-to-make-ai-data-centers-pay-for-power-grid-upgrades-reaches-critical-milestone" target="_blank">The Act was recently passed by House lawmakers</a> with bipartisan support, and is now headed to Congress for approval. But due to the midterm elections, the Act may not be signed into law until the end of the year.</p><p>Data center opposition and state-level regulations have drawn significant criticism from the White House. President Trump said that those opposed to AI data centers are “making a mistake” adding that communities would miss out on the “tremendous amounts of jobs and money” that having a local data center would provide.</p><p>In the second quarter of 2026, over $68 billion in data center projects have been <a href="https://www.tomshardware.com/tech-industry/data-centers/local-opposition-blocked-usd68-billion-worth-of-data-center-projects-in-the-second-quarter-of-2026-data-center-investments-reportedly-still-on-track-to-hit-usd32-trillion-by-2050">successfully blocked by local opposition</a> with a total of 45 proposed projects being opposed.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Bambu Lab R1 laser cutter and engraver review ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The R1 isn’t Bambu Lab's first venture into laser engraving; of course, we first saw the small-capacity engraver in the H2D, which enabled, with the cutter and 3D printer, a full range of manufacturing tools in one not-so-small machine. The R1 is something altogether more serious and much closer to machines such as the xTool P2 that I've previously tested.</p><p>It's also an important machine for Bambu Lab and shows them expanding further into the growing maker space. The R1 is the company's first dedicated product outside 3D printing and is based around a 55W CO2 laser rather than a diode; the H2D utilised diode lasers. Using CO2 rather than diode laser technology lets the machine work with a wider range of materials, most notably clear acrylic and glass, while also providing considerably more cutting power; most diodes currently top out at 40W, although several far more powerful heads exist. </p><p>However, as with Bambu Lab’s entrance into the 3D print market, the machine technology and market aren’t new, and plenty of other players already exist. xTool, LaserPecker, Glowforge and Creality have already demonstrated how far enclosed desktop laser cutters have progressed in recent years. Five years ago, many of the smaller laser engravers I looked at were open-frame machines that required assembly and considerably more caution, to the point where I will no longer cover them. These days, fully enclosed machines are really where the technology is at, and there are some great options at very reasonable prices. </p><p>While there are plenty of machines in the sector, this is Bambu Lab, and with their first laser, they also bring much of the knowledge of 3D printing with them, along with their own approach to automation.</p><p>The R1 handles focusing, material positioning and optical alignment, with cameras, lasers and encoders helping the machine understand where the material is and where the toolhead is moving. On paper, this looks great because it will speed up workflows; however, it was only during testing that I realised what a difference it can make. </p><p>I've been using the R1 for around three weeks, mostly cutting 3mm basswood ply and acrylic, but also testing MDF, leather, paper, ceramic, glass, coated metal, and plenty of irregular wooden objects. What I have found during that time is that the hardware is exceptionally polished, and while Bambu Suite is good, it still has some catching up to do to realise its and the machine's full potential.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1200px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="z7T476V6JxFbxC6VBAekdE" name="Bambu Lab R1" alt="Bambu Lab R1" src="https://cdn.mos.cms.futurecdn.net/z7T476V6JxFbxC6VBAekdE-1920-80.jpg" mos="" align="middle" fullscreen="" width="1200" height="675" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Alastair Jennings)</span></figcaption></figure><h2 class="article-body__section" id="section-bambu-lab-r1-price-availability"><span>Bambu Lab R1: Price & availability</span></h2><p>The Bambu Lab R1 launches at <a href="https://us.store.bambulab.com/products/r1" target="_blank">$2,499 in the US direct from the company site</a> and <a href="https://uk.store.bambulab.com/products/r1" target="_blank">£2,249 from the UK site</a>. Pre-orders start on September 22, 2026 and shipping scheduled to begin in October.</p><p>The short-focus lens is included. The Riser Base, Conveyor, Rotary attachment, medium- and long-focus lenses, Vision Encoder, E1 Pro Air Purifier and Auto Fire Extinguishing System are optional extras. </p><h2 class="article-body__section" id="section-bambu-lab-r1-design"><span>Bambu Lab R1: Design</span></h2><div  class="fancy-box"><div class="fancy_box-title">Specs</div><div class="fancy_box_body"><p class="fancy-box__body-text"><strong>Laser technology:</strong> 55W CO2<br><strong>Working area:</strong> 600 x 300mm<br><strong>Working area with Conveyor:</strong> 600 x 3000mm<br><strong>Maximum speed:</strong> 1,000mm/s<br><strong>Maximum acceleration:</strong> 20,000mm/s²<br><strong>Positioning accuracy:</strong> < 0.2 mm<br><strong>Absolute motion accuracy:</strong> < 0.1 mm across 600mm with Vision Encoder<br><strong>Dimensions:</strong> 940 x 560 x 200mm<br><strong>Weight:</strong> 33.5kg<br><strong>Maximum input power:</strong> 780W<br><strong>Software:</strong> Bambu Suite<br><strong>Supported OS:</strong> Windows, macOS<br><strong>Connectivity:</strong> Dual-band Wi-Fi, USB<br><strong>Laser safety:</strong> Class 1 in standard enclosed configuration<br><strong>Short-focus spot:</strong> 0.11mm<br><strong>Medium-focus spot:</strong> 0.17mm<br><strong>Long-focus spot:</strong> 0.19mm<br><strong>Maximum cutting capacity:</strong> 18mm black walnut with medium/long-focus lens; 20mm acrylic.<br><strong>Standard lens:</strong> Short-focus<br><strong>Supported cutting/engraving materials:</strong> Wood, acrylic including clear acrylic, leather, fabric, paper, EVA foam and shell<br><strong>Engraving materials:</strong> Glass, ceramic and coated metal<br><strong>Optional accessories:</strong> Riser Base, Conveyor, Rotary, medium/long-focus lenses, Vision Encoder, E1 Pro Air Purifier and Auto Fire Extinguishing System.</p></div></div><p>Unpacking the box, and having already checked the specifications before the machine arrived, I was surprised the packaging was smaller than expected. It still required two of us to manoeuvre the box into the workshop, but once unpacked and at 33.5 kg, I could lift and position it with little issue. It’s still heavy, but looking at the slight curve that’s left in the desk from the previous test, it's not quite as heavy as the previous 3D printer that took up the space. </p><p>The weight and, for that matter, the size are actually very manageable, and with a footprint of 940 x 560mm, the machine was able to sit on the standard section of the 60cm-deep workshop bench. While the main machine sits quite happily in that space, you’ll also need to consider venting and leave enough vertical clearance to open the lid.</p><p>Once in position, the R1's design is unmistakably Bambu Lab. The finish is superb; everything feels properly manufactured rather than assembled from off-the-shelf laser components, and I was pleased to see the machine arrived largely configured; I just had a few small setup procedures to follow before I could start.</p><p>As with all engravers, the first job was to attach the exhaust to the filter, and in my setup this was paired with the optional E1 Pro filtration system. You also need to fill the cooling reservoir with distilled or de-ionised water. </p><p>The instructions suggest adding antifreeze if you live in a colder climate. My workshop can drop below 5°C during winter, so I filled the system to the -10°C protection mark. Once I removed the transport restraints and checked the interior, the R1 was ready to power on.</p><p>The initial startup takes roughly 30 seconds before calibration begins. The automated self-check and initial calibration took around half an hour. Once that completes, you can then run the laser alignment procedure, and this is the first sign that this laser is something a little different.</p><p>Unlike the more manual approach of other CO2 lasers, here all you need to do to calibrate is to lift the small cover on the toolhead, then attach the supplied Laser Alignment Sensor, which clicks into place magnetically. Select the alignment function from the touchscreen, and the R1 handles the rest. The complete process took me approximately five minutes, including fitting and removing the sensor.</p><p>That's longer than Bambu's roughly one-minute claim for the alignment operation itself, but from my perspective there was virtually nothing to do. Then inside, there are a few removable slats that help to support the material that is placed within. </p><p>These are all easy to reposition, but again I would have liked more of them, although there are a few more than when I looked inside the <a href="https://www.techradar.com/pro/laserpecker-lx2-laser-cutter-and-engraver-review" target="_blank">LaserPecker LX2</a> in my recent review. The main issue is that small cut pieces can fall between the gaps, and for detailed work I still prefer a proper honeycomb bed, which I used for most of the review.</p><p>Around the machine, things are similarly clean. The exhaust and main power connection are at the rear, while Air Assist is integrated. Accessory connections sit on the side, alongside USB, and an easily accessible emergency stop is included. Unusually for a laser engraver, it has a small touchscreen, which is extremely useful. Most laser cutters force almost every operation back through the computer. Having direct access to machine functions makes the R1 much easier to use.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1200px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="No4edfxcu5NySyvwBPaq2E" name="Bambu Lab R1" alt="Bambu Lab R1" src="https://cdn.mos.cms.futurecdn.net/No4edfxcu5NySyvwBPaq2E-1920-80.jpg" mos="" align="middle" fullscreen="" width="1200" height="675" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Alastair Jennings)</span></figcaption></figure><h2 class="article-body__section" id="section-bambu-lab-r1-features"><span>Bambu Lab R1: Features</span></h2><p>A look through the specifications, and the first thing to note is that this is a 55W CO2 laser; at present, there are only a few CO2 laser engravers at this price aimed at the enthusiast and small-business sector, and the only real competition is the xTool P2. </p><p>Inside is a very decent 600 x 300mm working area, which, from my testing, is large enough for most projects; if you need to go larger, there is an optional conveyor. Based on my testing of the base unit alone, I found I could place two standard 300 x 300mm basswood sheets side by side, which was useful when cutting multi-part models, such as the flower box and an RC boat I’m partway through. If you need longer than 300mm, the Conveyor enables working lengths of up to 3000mm, but you are still limited to the 600mm width. </p><p>After reviewing all the information, Bambu Lab is keen to highlight the Auto Laser Alignment. This is because, in the past, this process has been very hands-on with other machines, as a CO2 laser relies on mirrors to direct the beam through the machine, and those mirrors need to remain aligned. </p><p>On most machines, these mirrors are pre-calibrated, but they do occasionally need recalibration, which can be time-consuming; here, however, that process is fully automated with motorised mirror actuators and an alignment sensor.</p><p>For design placement accuracy on materials and tight measurements, the machine uses a TriSense system. This combines the BirdsEye Camera, Toolhead Camera, Pinpoint Laser, distance-measurement laser, and XY encoders to locate material, measure its surface, and monitor movement.</p><p>During testing, I accidentally put this to the test when I made an error importing a cutting design and left the paths set as lines rather than cuts. I ran the job, removed the basswood from the machine and only then realised the mistake. Normally, that could easily mean starting again.</p><p>Instead, I put the sheet back into the R1, used the camera view to align the cutting paths with the lines already engraved into the material, changed the operation to Cut and reran it. The cuts followed the previous lines accurately, with no obvious signs of the mistake.</p><p>When it came to small objects, the positioning was equally impressive. I placed pre-cut objects such as placemats around the work area, positioned the artwork through Bambu Suite, and achieved results very close to what I had on screen.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1200px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="geSiC53D622GGF5vtEmVvF" name="Bambu Lab R1" alt="Bambu Lab R1" src="https://cdn.mos.cms.futurecdn.net/geSiC53D622GGF5vtEmVvF-1920-80.jpg" mos="" align="middle" fullscreen="" width="1200" height="675" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Alastair Jennings)</span></figcaption></figure><p>Alongside the hardware is the Bambu Suite software, which offers plenty of functionality, and I found it to have good overall stability when working on macOS, but the workflow isn't yet as fluid as the hardware deserves.</p><p>Importing a DXF, for example, involves selecting Open Image, when Open File would make considerably more sense. Once you import a design, you can assign Cut, Line, and Fill operations. Then you move into Prepare, where you set up the machine and material.</p><p>This separation isn't always convenient. If you realise you've assigned the wrong operation later, changing it isn't as immediate as right-clicking the object in the earlier screen.</p><p>Capturing the work area also requires you to enter the preparation workflow. During testing, I occasionally found the workspace remained blank until I selected Measure and ran through the capture procedure again. On the Mac version, I also occasionally saw a ghost of the previously captured image underneath the current one. However, none of this stopped me from working.</p><p>After a couple of days, the workflow logic did make sense, and after three weeks I could move through jobs quickly, although I still didn’t feel that the workflow was as fluid as it could have been. Material profiles cover most common materials, while manual control gives you plenty of flexibility when experimenting with less conventional materials and objects. </p><h2 class="article-body__section" id="section-bambu-lab-r1-performance"><span>Bambu Lab R1: Performance</span></h2><p>I started the test with the setup process, and while this was straightforward, there was a little to-and-fro with attaching vents and making sure the filter vent was routed outside. I then had to fill the machine with distilled water and antifreeze before running through the calibration processes, which all took around an hour. <br><br>Starting the tests, I focused on using 3mm basswood ply; this is for a couple of reasons: it's a common material used by crafters, model makers, and many small businesses. Second, I’m familiar with how it reacts under lasers and the initial results I should expect. As I started the process, the Bambu Lab philosophy that I’ve seen with their 3D printers started to become obvious.</p><p>One of my standard initial tests is a flower-box project. I imported the design, detached individual components and rearranged them across two 300 x 300mm basswood sheets to make better use of the material. I tried the auto layout, but because I hadn’t regrouped the paths, the design scattered across the work area. Undoing the mistake didn’t work, so I had to reload the design.</p><p>Once I’d re-laid out the design over the two sheets, I hit the Make button, and then the main button of the machine the R1 started the process of engraving and cutting, and with decent speed that I seen with other CO2 engravers. The complete model took around 10 minutes to cut across those two sheets, and the result was close to perfect.</p><p>However, there was one issue. Once the pieces were cut free, the smaller parts dropped between the support slats, and a couple of scorch marks appeared where they fell into the laser's path. Moving the slats closer helps, but this is where a honeycomb grid should really be used.</p><p>After several impressive results in basswood ply, I then produced the same flower-box design in acrylic. This took considerably longer at around 29 minutes, but the finish was exceptional, one of the best results I've achieved with this particular cutting plan in acrylic. The use of this material is one of the reasons that you would want to go for a CO2 laser over a conventional diode laser. </p><p>I also pushed the R1 beyond thin sheet material, testing materials ranging from lightweight paper through to 16mm MDF; in the case of these materials I tended to opt for the manual control so that I could get the best possible cut, and I was pleased to see it was possible to save down the settings as presets.</p><p>In the engraving tests, I used leather, ceramic, coated metal, and glass. Across those materials, the CO2 source's added power and flexibility became apparent, especially compared with the smaller diode engravers I've used.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1200px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="NSuyuAJwDQES85dRJywX4D" name="Bambu Lab R1" alt="Bambu Lab R1" src="https://cdn.mos.cms.futurecdn.net/NSuyuAJwDQES85dRJywX4D-1920-80.jpg" mos="" align="middle" fullscreen="" width="1200" height="675" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Alastair Jennings)</span></figcaption></figure><p>Through the test, the raw cutting power was impressive, and by slowing the engraver down and maxing out the power, I was able to cut through an 18mm sheet of ply. However, the positioning accuracy is what has really impressed me. </p><p>For small objects, the position shown in Bambu Suite and the finished engraving were exceptionally good. Once I'd grouped individual elements of a design correctly, the automatic positioning tools made batches of pre-cut objects far easier, although I was equally as impressed by the xTool and Creality machines that I’ve looked at recently in this respect. </p><p>Curved-surface engraving, however, was one up from what I have experienced before as it was easy to set up and use. Essentially, I can place something such as a bowl or piece of timber into the R1, select curved-surface machining, and manually check that there's enough clearance for the toolhead.</p><p>The machine then measures multiple points across the object to gauge the changing surface height and generates a height map. I could then position the artwork and run the job the same way I would on a flat sheet.</p><p>I tried this with curved wooden objects, including a log, and the resulting lines stayed clear and focused as the surface height changed. There is a bit of physical interaction involved. The lid needs to be raised and lowered as the R1 works through parts of the measurement process, and an automated lid would make the experience even slicker.</p><h2 class="article-body__section" id="section-bambu-lab-r1-final-verdict"><span>Bambu Lab R1: Final verdict</span></h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1200px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nwHL79gZcc7p8MokymqjdD" name="Bambu Lab R1" alt="Bambu Lab R1" src="https://cdn.mos.cms.futurecdn.net/nwHL79gZcc7p8MokymqjdD-1920-80.jpg" mos="" align="middle" fullscreen="" width="1200" height="675" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Alastair Jennings)</span></figcaption></figure><p>Bambu Lab may be arriving relatively late to the dedicated desktop laser market, but the R1 doesn't feel like a first attempt. After three weeks of use, what stands out isn't just the 55W CO2 laser; it’s that Bambu Lab's formula has been applied, which means it looks great, is easy to use, and produces great cuts and engravings. </p><p>The automatic optical alignment seems to do its job and removes some of the more complex maintenance tasks that come with owning a CO2 laser. Then there's the TriSense system that makes positioning objects and designs easy, and the curved-surface measurement procedure just works exceptionally well. </p><p>I even felt that the material presets were spot on, enabling me to get excellent results without spending the first afternoon with the machine producing endless power-and-speed test grids. Something I’m all too familiar with.</p><p>The physical design is excellent and weight and size means it sits perfectly in the workshop with teh  600 x 300mm work area enabling enough rooom for most of the jobs that I would want to do on this style of machine. </p><p>Bambu Suite does, however, need more work. I'd like quicker access to camera capture, a more fluid transition between design and preparation, clearer terminology, and a few interface bugs ironed out. I'd also like more support slats in the actual machine, or preferably a honeycomb bed that was supplied with the machine and not an optional extra. </p><p>Also, on the interior, a little more headroom would have been nice, but then you can use a raiser, but that or the use of the conveyor changes the machine from a class 1 to a class 4. </p><p>The R1 has been designed to be part of the Bambu Lab ecosystem and is designed for makers who are already invested in Bambu. Putting laser engraving and 3D printing together at scale does provide a solid base for personal manufacturer and it is exciting. </p><p>For small businesses, workshops, model makers and serious crafters, this is a fast, accurate and unusually easy to use CO2 machine.</p><h2 id="should-you-buy-the-bambu-lab-r1">Should you buy the Bambu Lab R1</h2><div ><table><tbody><tr><td class="firstcol " ><p><strong>Value:</strong></p></td><td  ><p>Premium price, but with serious production capability</p></td><td  ><p>4</p></td></tr><tr><td class="firstcol " ><p><strong>Design:</strong></p></td><td  ><p>Considering the size of the work area it's relatively compact and exceptionally solid</p></td><td  ><p>4.5</p></td></tr><tr><td class="firstcol " ><p><strong>Features</strong></p></td><td  ><p>Automation brought over from 3D printing makes complicated jobs simple.</p></td><td  ><p>5</p></td></tr><tr><td class="firstcol " ><p><strong>Performance</strong></p></td><td  ><p>Excellent cuts and detail with superb positioning and minimal scorching</p></td><td  ><p>5</p></td></tr><tr><td class="firstcol " ><p><strong>Total</strong></p></td><td  ><p>Exceptional CO2 cutter, software needs some workflow issue resolving.</p></td><td  ><p>4.5</p></td></tr></tbody></table></div><h2 id="buy-it-if">Buy it if...</h2><div class="product"><p><strong>You already 3D print</strong><br>Pairing the R1 with a Bambu 3D printer creates an exceptionally flexible workshop for combining printed components with wood and acrylic.</p><p><strong>Accuracy really matters</strong><br>Camera positioning, surface measurement and automatic alignment make placing detailed engravings onto pre-cut and curved objects remarkably straightforward and repeatable.<a class="view-deal button" href="" target="_blank" rel="nofollow" data-dimension112="2c1b8266-b68a-11f1-a986-c5e8fa413ade" data-action="Deal Block" data-label="You already 3D printPairing the R1 with a Bambu 3D printer creates an exceptionally flexible workshop for combining printed components with wood and acrylic.Accuracy really mattersCamera positioning, surface measurement and automatic alignment make placing detailed engravings onto pre-cut and curved objects remarkably straightforward and repeatable." data-dimension48="You already 3D printPairing the R1 with a Bambu 3D printer creates an exceptionally flexible workshop for combining printed components with wood and acrylic.Accuracy really mattersCamera positioning, surface measurement and automatic alignment make placing detailed engravings onto pre-cut and curved objects remarkably straightforward and repeatable." data-dimension25="">View Deal</a></p></div><h2 id="don-39-t-buy-it-if">Don't buy it if...</h2><div class="product"><p><strong>Space is limited</strong><br>The R1 is compact for its capacity, but at 33.5kg with extraction and filtration, it still requires a proper workshop setup.</p><p><strong>You want simplicity</strong><br>The hardware is exceptionally polished, but Bambu Suite's current workflow requires some familiarisation and could still benefit from further refinement.<a class="view-deal button" href="" target="_blank" rel="nofollow" data-dimension112="2c1b8324-b68a-11f1-b73c-97db06f2cbfd" data-action="Deal Block" data-label="Space is limitedThe R1 is compact for its capacity, but at 33.5kg with extraction and filtration, it still requires a proper workshop setup.You want simplicityThe hardware is exceptionally polished, but Bambu Suite's current workflow requires some familiarisation and could still benefit from further refinement." data-dimension48="Space is limitedThe R1 is compact for its capacity, but at 33.5kg with extraction and filtration, it still requires a proper workshop setup.You want simplicityThe hardware is exceptionally polished, but Bambu Suite's current workflow requires some familiarisation and could still benefit from further refinement." data-dimension25="">View Deal</a></p></div><p><em>For more crafting tech, I've tested and reviewed all the </em><a href="https://www.techradar.com/best/best-3d-printers" target="_blank"><em>best 3D printers</em></a><em> and the </em><a href="https://www.techradar.com/pro/best-laser-engravers-in-year" target="_blank"><em>best laser engravers</em></a><em>.</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/bambu-lab-r1-laser-cutter-and-engraver-review</link>
                                                                            <description>
                            <![CDATA[ Bambu Lab enters the dedicated laser market with a powerful 55W CO2 laser cutter, featuring superb positioning, automatic alignment, and outstanding results. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">a8MoBCYzsh264WXUKYrar9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iiNmMH6utMyEAeS87p5edD-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 16:55:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Alastair Jennings ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ &lt;p&gt;Alastair is a photographer, filmmaker and tech writer who has been working in the publishing industry since the late 1990s. For more than 25 years he has covered photography, video and technology across Future&#039;s photography, technology and gaming brands, and worked on many of the company&#039;s launch titles. Based in the south of England, Alastair now runs a photography and video production company and lectures in TV and film. When not on set or in the classroom, Alastair can usually be found prototyping and prop building with the aid of 3D printing as well as advising companies on social video strategy and creative workflows which gives him the tech insight behind the reviews.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iiNmMH6utMyEAeS87p5edD-1920-80.jpg">
                                                            <media:credit><![CDATA[Alastair Jennings]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Bambu Lab R1]]></media:description>                                                            <media:text><![CDATA[Bambu Lab R1]]></media:text>
                                <media:title type="plain"><![CDATA[Bambu Lab R1]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iiNmMH6utMyEAeS87p5edD-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The R1 isn’t Bambu Lab's first venture into laser engraving; of course, we first saw the small-capacity engraver in the H2D, which enabled, with the cutter and 3D printer, a full range of manufacturing tools in one not-so-small machine. The R1 is something altogether more serious and much closer to machines such as the xTool P2 that I've previously tested.</p><p>It's also an important machine for Bambu Lab and shows them expanding further into the growing maker space. The R1 is the company's first dedicated product outside 3D printing and is based around a 55W CO2 laser rather than a diode; the H2D utilised diode lasers. Using CO2 rather than diode laser technology lets the machine work with a wider range of materials, most notably clear acrylic and glass, while also providing considerably more cutting power; most diodes currently top out at 40W, although several far more powerful heads exist. </p><p>However, as with Bambu Lab’s entrance into the 3D print market, the machine technology and market aren’t new, and plenty of other players already exist. xTool, LaserPecker, Glowforge and Creality have already demonstrated how far enclosed desktop laser cutters have progressed in recent years. Five years ago, many of the smaller laser engravers I looked at were open-frame machines that required assembly and considerably more caution, to the point where I will no longer cover them. These days, fully enclosed machines are really where the technology is at, and there are some great options at very reasonable prices. </p><p>While there are plenty of machines in the sector, this is Bambu Lab, and with their first laser, they also bring much of the knowledge of 3D printing with them, along with their own approach to automation.</p><p>The R1 handles focusing, material positioning and optical alignment, with cameras, lasers and encoders helping the machine understand where the material is and where the toolhead is moving. On paper, this looks great because it will speed up workflows; however, it was only during testing that I realised what a difference it can make. </p><p>I've been using the R1 for around three weeks, mostly cutting 3mm basswood ply and acrylic, but also testing MDF, leather, paper, ceramic, glass, coated metal, and plenty of irregular wooden objects. What I have found during that time is that the hardware is exceptionally polished, and while Bambu Suite is good, it still has some catching up to do to realise its and the machine's full potential.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1200px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="z7T476V6JxFbxC6VBAekdE" name="Bambu Lab R1" alt="Bambu Lab R1" src="https://cdn.mos.cms.futurecdn.net/z7T476V6JxFbxC6VBAekdE-1920-80.jpg" mos="" align="middle" fullscreen="" width="1200" height="675" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Alastair Jennings)</span></figcaption></figure><h2 class="article-body__section" id="section-bambu-lab-r1-price-availability"><span>Bambu Lab R1: Price & availability</span></h2><p>The Bambu Lab R1 launches at <a href="https://us.store.bambulab.com/products/r1" target="_blank">$2,499 in the US direct from the company site</a> and <a href="https://uk.store.bambulab.com/products/r1" target="_blank">£2,249 from the UK site</a>. Pre-orders start on September 22, 2026 and shipping scheduled to begin in October.</p><p>The short-focus lens is included. The Riser Base, Conveyor, Rotary attachment, medium- and long-focus lenses, Vision Encoder, E1 Pro Air Purifier and Auto Fire Extinguishing System are optional extras. </p><h2 class="article-body__section" id="section-bambu-lab-r1-design"><span>Bambu Lab R1: Design</span></h2><div  class="fancy-box"><div class="fancy_box-title">Specs</div><div class="fancy_box_body"><p class="fancy-box__body-text"><strong>Laser technology:</strong> 55W CO2<br><strong>Working area:</strong> 600 x 300mm<br><strong>Working area with Conveyor:</strong> 600 x 3000mm<br><strong>Maximum speed:</strong> 1,000mm/s<br><strong>Maximum acceleration:</strong> 20,000mm/s²<br><strong>Positioning accuracy:</strong> < 0.2 mm<br><strong>Absolute motion accuracy:</strong> < 0.1 mm across 600mm with Vision Encoder<br><strong>Dimensions:</strong> 940 x 560 x 200mm<br><strong>Weight:</strong> 33.5kg<br><strong>Maximum input power:</strong> 780W<br><strong>Software:</strong> Bambu Suite<br><strong>Supported OS:</strong> Windows, macOS<br><strong>Connectivity:</strong> Dual-band Wi-Fi, USB<br><strong>Laser safety:</strong> Class 1 in standard enclosed configuration<br><strong>Short-focus spot:</strong> 0.11mm<br><strong>Medium-focus spot:</strong> 0.17mm<br><strong>Long-focus spot:</strong> 0.19mm<br><strong>Maximum cutting capacity:</strong> 18mm black walnut with medium/long-focus lens; 20mm acrylic.<br><strong>Standard lens:</strong> Short-focus<br><strong>Supported cutting/engraving materials:</strong> Wood, acrylic including clear acrylic, leather, fabric, paper, EVA foam and shell<br><strong>Engraving materials:</strong> Glass, ceramic and coated metal<br><strong>Optional accessories:</strong> Riser Base, Conveyor, Rotary, medium/long-focus lenses, Vision Encoder, E1 Pro Air Purifier and Auto Fire Extinguishing System.</p></div></div><p>Unpacking the box, and having already checked the specifications before the machine arrived, I was surprised the packaging was smaller than expected. It still required two of us to manoeuvre the box into the workshop, but once unpacked and at 33.5 kg, I could lift and position it with little issue. It’s still heavy, but looking at the slight curve that’s left in the desk from the previous test, it's not quite as heavy as the previous 3D printer that took up the space. </p><p>The weight and, for that matter, the size are actually very manageable, and with a footprint of 940 x 560mm, the machine was able to sit on the standard section of the 60cm-deep workshop bench. While the main machine sits quite happily in that space, you’ll also need to consider venting and leave enough vertical clearance to open the lid.</p><p>Once in position, the R1's design is unmistakably Bambu Lab. The finish is superb; everything feels properly manufactured rather than assembled from off-the-shelf laser components, and I was pleased to see the machine arrived largely configured; I just had a few small setup procedures to follow before I could start.</p><p>As with all engravers, the first job was to attach the exhaust to the filter, and in my setup this was paired with the optional E1 Pro filtration system. You also need to fill the cooling reservoir with distilled or de-ionised water. </p><p>The instructions suggest adding antifreeze if you live in a colder climate. My workshop can drop below 5°C during winter, so I filled the system to the -10°C protection mark. Once I removed the transport restraints and checked the interior, the R1 was ready to power on.</p><p>The initial startup takes roughly 30 seconds before calibration begins. The automated self-check and initial calibration took around half an hour. Once that completes, you can then run the laser alignment procedure, and this is the first sign that this laser is something a little different.</p><p>Unlike the more manual approach of other CO2 lasers, here all you need to do to calibrate is to lift the small cover on the toolhead, then attach the supplied Laser Alignment Sensor, which clicks into place magnetically. Select the alignment function from the touchscreen, and the R1 handles the rest. The complete process took me approximately five minutes, including fitting and removing the sensor.</p><p>That's longer than Bambu's roughly one-minute claim for the alignment operation itself, but from my perspective there was virtually nothing to do. Then inside, there are a few removable slats that help to support the material that is placed within. </p><p>These are all easy to reposition, but again I would have liked more of them, although there are a few more than when I looked inside the <a href="https://www.techradar.com/pro/laserpecker-lx2-laser-cutter-and-engraver-review" target="_blank">LaserPecker LX2</a> in my recent review. The main issue is that small cut pieces can fall between the gaps, and for detailed work I still prefer a proper honeycomb bed, which I used for most of the review.</p><p>Around the machine, things are similarly clean. The exhaust and main power connection are at the rear, while Air Assist is integrated. Accessory connections sit on the side, alongside USB, and an easily accessible emergency stop is included. Unusually for a laser engraver, it has a small touchscreen, which is extremely useful. Most laser cutters force almost every operation back through the computer. Having direct access to machine functions makes the R1 much easier to use.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1200px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="No4edfxcu5NySyvwBPaq2E" name="Bambu Lab R1" alt="Bambu Lab R1" src="https://cdn.mos.cms.futurecdn.net/No4edfxcu5NySyvwBPaq2E-1920-80.jpg" mos="" align="middle" fullscreen="" width="1200" height="675" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Alastair Jennings)</span></figcaption></figure><h2 class="article-body__section" id="section-bambu-lab-r1-features"><span>Bambu Lab R1: Features</span></h2><p>A look through the specifications, and the first thing to note is that this is a 55W CO2 laser; at present, there are only a few CO2 laser engravers at this price aimed at the enthusiast and small-business sector, and the only real competition is the xTool P2. </p><p>Inside is a very decent 600 x 300mm working area, which, from my testing, is large enough for most projects; if you need to go larger, there is an optional conveyor. Based on my testing of the base unit alone, I found I could place two standard 300 x 300mm basswood sheets side by side, which was useful when cutting multi-part models, such as the flower box and an RC boat I’m partway through. If you need longer than 300mm, the Conveyor enables working lengths of up to 3000mm, but you are still limited to the 600mm width. </p><p>After reviewing all the information, Bambu Lab is keen to highlight the Auto Laser Alignment. This is because, in the past, this process has been very hands-on with other machines, as a CO2 laser relies on mirrors to direct the beam through the machine, and those mirrors need to remain aligned. </p><p>On most machines, these mirrors are pre-calibrated, but they do occasionally need recalibration, which can be time-consuming; here, however, that process is fully automated with motorised mirror actuators and an alignment sensor.</p><p>For design placement accuracy on materials and tight measurements, the machine uses a TriSense system. This combines the BirdsEye Camera, Toolhead Camera, Pinpoint Laser, distance-measurement laser, and XY encoders to locate material, measure its surface, and monitor movement.</p><p>During testing, I accidentally put this to the test when I made an error importing a cutting design and left the paths set as lines rather than cuts. I ran the job, removed the basswood from the machine and only then realised the mistake. Normally, that could easily mean starting again.</p><p>Instead, I put the sheet back into the R1, used the camera view to align the cutting paths with the lines already engraved into the material, changed the operation to Cut and reran it. The cuts followed the previous lines accurately, with no obvious signs of the mistake.</p><p>When it came to small objects, the positioning was equally impressive. I placed pre-cut objects such as placemats around the work area, positioned the artwork through Bambu Suite, and achieved results very close to what I had on screen.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1200px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="geSiC53D622GGF5vtEmVvF" name="Bambu Lab R1" alt="Bambu Lab R1" src="https://cdn.mos.cms.futurecdn.net/geSiC53D622GGF5vtEmVvF-1920-80.jpg" mos="" align="middle" fullscreen="" width="1200" height="675" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Alastair Jennings)</span></figcaption></figure><p>Alongside the hardware is the Bambu Suite software, which offers plenty of functionality, and I found it to have good overall stability when working on macOS, but the workflow isn't yet as fluid as the hardware deserves.</p><p>Importing a DXF, for example, involves selecting Open Image, when Open File would make considerably more sense. Once you import a design, you can assign Cut, Line, and Fill operations. Then you move into Prepare, where you set up the machine and material.</p><p>This separation isn't always convenient. If you realise you've assigned the wrong operation later, changing it isn't as immediate as right-clicking the object in the earlier screen.</p><p>Capturing the work area also requires you to enter the preparation workflow. During testing, I occasionally found the workspace remained blank until I selected Measure and ran through the capture procedure again. On the Mac version, I also occasionally saw a ghost of the previously captured image underneath the current one. However, none of this stopped me from working.</p><p>After a couple of days, the workflow logic did make sense, and after three weeks I could move through jobs quickly, although I still didn’t feel that the workflow was as fluid as it could have been. Material profiles cover most common materials, while manual control gives you plenty of flexibility when experimenting with less conventional materials and objects. </p><h2 class="article-body__section" id="section-bambu-lab-r1-performance"><span>Bambu Lab R1: Performance</span></h2><p>I started the test with the setup process, and while this was straightforward, there was a little to-and-fro with attaching vents and making sure the filter vent was routed outside. I then had to fill the machine with distilled water and antifreeze before running through the calibration processes, which all took around an hour. <br><br>Starting the tests, I focused on using 3mm basswood ply; this is for a couple of reasons: it's a common material used by crafters, model makers, and many small businesses. Second, I’m familiar with how it reacts under lasers and the initial results I should expect. As I started the process, the Bambu Lab philosophy that I’ve seen with their 3D printers started to become obvious.</p><p>One of my standard initial tests is a flower-box project. I imported the design, detached individual components and rearranged them across two 300 x 300mm basswood sheets to make better use of the material. I tried the auto layout, but because I hadn’t regrouped the paths, the design scattered across the work area. Undoing the mistake didn’t work, so I had to reload the design.</p><p>Once I’d re-laid out the design over the two sheets, I hit the Make button, and then the main button of the machine the R1 started the process of engraving and cutting, and with decent speed that I seen with other CO2 engravers. The complete model took around 10 minutes to cut across those two sheets, and the result was close to perfect.</p><p>However, there was one issue. Once the pieces were cut free, the smaller parts dropped between the support slats, and a couple of scorch marks appeared where they fell into the laser's path. Moving the slats closer helps, but this is where a honeycomb grid should really be used.</p><p>After several impressive results in basswood ply, I then produced the same flower-box design in acrylic. This took considerably longer at around 29 minutes, but the finish was exceptional, one of the best results I've achieved with this particular cutting plan in acrylic. The use of this material is one of the reasons that you would want to go for a CO2 laser over a conventional diode laser. </p><p>I also pushed the R1 beyond thin sheet material, testing materials ranging from lightweight paper through to 16mm MDF; in the case of these materials I tended to opt for the manual control so that I could get the best possible cut, and I was pleased to see it was possible to save down the settings as presets.</p><p>In the engraving tests, I used leather, ceramic, coated metal, and glass. Across those materials, the CO2 source's added power and flexibility became apparent, especially compared with the smaller diode engravers I've used.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1200px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="NSuyuAJwDQES85dRJywX4D" name="Bambu Lab R1" alt="Bambu Lab R1" src="https://cdn.mos.cms.futurecdn.net/NSuyuAJwDQES85dRJywX4D-1920-80.jpg" mos="" align="middle" fullscreen="" width="1200" height="675" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Alastair Jennings)</span></figcaption></figure><p>Through the test, the raw cutting power was impressive, and by slowing the engraver down and maxing out the power, I was able to cut through an 18mm sheet of ply. However, the positioning accuracy is what has really impressed me. </p><p>For small objects, the position shown in Bambu Suite and the finished engraving were exceptionally good. Once I'd grouped individual elements of a design correctly, the automatic positioning tools made batches of pre-cut objects far easier, although I was equally as impressed by the xTool and Creality machines that I’ve looked at recently in this respect. </p><p>Curved-surface engraving, however, was one up from what I have experienced before as it was easy to set up and use. Essentially, I can place something such as a bowl or piece of timber into the R1, select curved-surface machining, and manually check that there's enough clearance for the toolhead.</p><p>The machine then measures multiple points across the object to gauge the changing surface height and generates a height map. I could then position the artwork and run the job the same way I would on a flat sheet.</p><p>I tried this with curved wooden objects, including a log, and the resulting lines stayed clear and focused as the surface height changed. There is a bit of physical interaction involved. The lid needs to be raised and lowered as the R1 works through parts of the measurement process, and an automated lid would make the experience even slicker.</p><h2 class="article-body__section" id="section-bambu-lab-r1-final-verdict"><span>Bambu Lab R1: Final verdict</span></h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1200px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nwHL79gZcc7p8MokymqjdD" name="Bambu Lab R1" alt="Bambu Lab R1" src="https://cdn.mos.cms.futurecdn.net/nwHL79gZcc7p8MokymqjdD-1920-80.jpg" mos="" align="middle" fullscreen="" width="1200" height="675" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Alastair Jennings)</span></figcaption></figure><p>Bambu Lab may be arriving relatively late to the dedicated desktop laser market, but the R1 doesn't feel like a first attempt. After three weeks of use, what stands out isn't just the 55W CO2 laser; it’s that Bambu Lab's formula has been applied, which means it looks great, is easy to use, and produces great cuts and engravings. </p><p>The automatic optical alignment seems to do its job and removes some of the more complex maintenance tasks that come with owning a CO2 laser. Then there's the TriSense system that makes positioning objects and designs easy, and the curved-surface measurement procedure just works exceptionally well. </p><p>I even felt that the material presets were spot on, enabling me to get excellent results without spending the first afternoon with the machine producing endless power-and-speed test grids. Something I’m all too familiar with.</p><p>The physical design is excellent and weight and size means it sits perfectly in the workshop with teh  600 x 300mm work area enabling enough rooom for most of the jobs that I would want to do on this style of machine. </p><p>Bambu Suite does, however, need more work. I'd like quicker access to camera capture, a more fluid transition between design and preparation, clearer terminology, and a few interface bugs ironed out. I'd also like more support slats in the actual machine, or preferably a honeycomb bed that was supplied with the machine and not an optional extra. </p><p>Also, on the interior, a little more headroom would have been nice, but then you can use a raiser, but that or the use of the conveyor changes the machine from a class 1 to a class 4. </p><p>The R1 has been designed to be part of the Bambu Lab ecosystem and is designed for makers who are already invested in Bambu. Putting laser engraving and 3D printing together at scale does provide a solid base for personal manufacturer and it is exciting. </p><p>For small businesses, workshops, model makers and serious crafters, this is a fast, accurate and unusually easy to use CO2 machine.</p><h2 id="should-you-buy-the-bambu-lab-r1">Should you buy the Bambu Lab R1</h2><div ><table><tbody><tr><td class="firstcol " ><p><strong>Value:</strong></p></td><td  ><p>Premium price, but with serious production capability</p></td><td  ><p>4</p></td></tr><tr><td class="firstcol " ><p><strong>Design:</strong></p></td><td  ><p>Considering the size of the work area it's relatively compact and exceptionally solid</p></td><td  ><p>4.5</p></td></tr><tr><td class="firstcol " ><p><strong>Features</strong></p></td><td  ><p>Automation brought over from 3D printing makes complicated jobs simple.</p></td><td  ><p>5</p></td></tr><tr><td class="firstcol " ><p><strong>Performance</strong></p></td><td  ><p>Excellent cuts and detail with superb positioning and minimal scorching</p></td><td  ><p>5</p></td></tr><tr><td class="firstcol " ><p><strong>Total</strong></p></td><td  ><p>Exceptional CO2 cutter, software needs some workflow issue resolving.</p></td><td  ><p>4.5</p></td></tr></tbody></table></div><h2 id="buy-it-if">Buy it if...</h2><div class="product"><p><strong>You already 3D print</strong><br>Pairing the R1 with a Bambu 3D printer creates an exceptionally flexible workshop for combining printed components with wood and acrylic.</p><p><strong>Accuracy really matters</strong><br>Camera positioning, surface measurement and automatic alignment make placing detailed engravings onto pre-cut and curved objects remarkably straightforward and repeatable.<a class="view-deal button" href="" target="_blank" rel="nofollow" data-dimension112="2c1b8266-b68a-11f1-a986-c5e8fa413ade" data-action="Deal Block" data-label="You already 3D printPairing the R1 with a Bambu 3D printer creates an exceptionally flexible workshop for combining printed components with wood and acrylic.Accuracy really mattersCamera positioning, surface measurement and automatic alignment make placing detailed engravings onto pre-cut and curved objects remarkably straightforward and repeatable." data-dimension48="You already 3D printPairing the R1 with a Bambu 3D printer creates an exceptionally flexible workshop for combining printed components with wood and acrylic.Accuracy really mattersCamera positioning, surface measurement and automatic alignment make placing detailed engravings onto pre-cut and curved objects remarkably straightforward and repeatable." data-dimension25="">View Deal</a></p></div><h2 id="don-39-t-buy-it-if">Don't buy it if...</h2><div class="product"><p><strong>Space is limited</strong><br>The R1 is compact for its capacity, but at 33.5kg with extraction and filtration, it still requires a proper workshop setup.</p><p><strong>You want simplicity</strong><br>The hardware is exceptionally polished, but Bambu Suite's current workflow requires some familiarisation and could still benefit from further refinement.<a class="view-deal button" href="" target="_blank" rel="nofollow" data-dimension112="2c1b8324-b68a-11f1-b73c-97db06f2cbfd" data-action="Deal Block" data-label="Space is limitedThe R1 is compact for its capacity, but at 33.5kg with extraction and filtration, it still requires a proper workshop setup.You want simplicityThe hardware is exceptionally polished, but Bambu Suite's current workflow requires some familiarisation and could still benefit from further refinement." data-dimension48="Space is limitedThe R1 is compact for its capacity, but at 33.5kg with extraction and filtration, it still requires a proper workshop setup.You want simplicityThe hardware is exceptionally polished, but Bambu Suite's current workflow requires some familiarisation and could still benefit from further refinement." data-dimension25="">View Deal</a></p></div><p><em>For more crafting tech, I've tested and reviewed all the </em><a href="https://www.techradar.com/best/best-3d-printers" target="_blank"><em>best 3D printers</em></a><em> and the </em><a href="https://www.techradar.com/pro/best-laser-engravers-in-year" target="_blank"><em>best laser engravers</em></a><em>.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Adobe Premiere comes to Android — here’s what 'free' gets you ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Adobe Premiere on Android has officially launched</strong></li><li><strong>The free video editing app adds easy 4K video editing, AI, and more</strong></li><li><strong>I checked out how the app runs, what you get, and if it really does offer 'effortless editing' for creators</strong></li></ul><div  class="fancy-box"><div class="fancy_box-title">Quick verdict</div><div class="fancy_box_body"><p class="fancy-box__body-text"><strong>What works: </strong>Easy edits, unlimited 4K exports, clean interface, loads of templates, quick generative AI</p><p class="fancy-box__body-text"><strong>What doesn't: </strong>Limited free AI tokens</p></div></div><p>Adobe Premiere for Android has arrived - finally, since Apple users got this app almost exactly a year ago. The mobile editing app is promising to deliver 4K video for content creators, alongside a slew of other tools including templates and AI generation (did you ever doubt it?). </p><p>Like most of Adobe's mobile apps, Premiere is free to download from the Google Play Store, although you'll need a subscription for extra AI generations and storage. </p><p>The upshot is, I've been keen to try out this Android app for a long time now, so here's what you can expect after I spent an hour dabbling with it on my Fairphone. </p><h2 class="article-body__section" id="section-what-s-new"><span>What's new?</span></h2><p>This new Adobe Premiere app is specifically designed for Android phones, including foldables. According to Adobe, you'll need a device running Android 13 or later, with a minimum of 5GB RAM.</p><p>The app serves up a host of useful tools for content creators, including 4K video, simple-to-use templates for speeding up production, multi-track timeline editing, music and audio effects, and generative AI for image and video. </p><p>One of the high-points, as far as I'm concerned, is that it has no ads and exported videos are watermark-free. </p><p>A lot of 'free' mobile video editors could learn from this. There are no added intros and outros promoting Adobe either. So you can basically start creating video for social channels immediately. You can read the full write-up in <a href="https://blog.adobe.com/en/publish/2026/09/22/adobe-premiere-expands-android-fast-powerful-easy-mobile-video-editing" target="_blank">Adobe's blog here</a>. But is it any good? Here are my thoughts...</p><h2 class="article-body__section" id="section-first-impressions"><span>First impressions</span></h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="2JBYebkZawiFJsMBBYzY3N" name="Adobe Premiere Android 002 Listing v2" alt="Using Adobe Premiere on Android to edit videos, with a blurred version of the app for background color" src="https://cdn.mos.cms.futurecdn.net/2JBYebkZawiFJsMBBYzY3N-1920-80.png" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>I spent the last hour toying with Adobe Premiere to see whether it lives up to the promise of creating "stand out edits to share on TikTok, YouTube, Instagram, and Facebook." </p><p><em>Spoiler alert</em>: It's good stuff. A responsive app that's worth checking out if you need a free video editor that does everything I'd expect it to do. Especially if you have a paid Adobe account for those extra AI generations.</p><h2 id="layout">Layout</h2><p>Adobe Premiere on Android feels very clean, very sensibly laid out. That's a relief, because often I find Adobe's user interface to be unintuitive as a result of too many features. A phone screen is the last place you want to combat that. </p><p>Along the top of the screen are shortcuts for the main functions. This includes 'New from files' and 'Create for YouTube Shorts', as well as AI generations tools 'Image to video' and 'Text to video'. Once you start editing, your most recent projects can be found below this. </p><p>Under those key tools are a ridiculous number of templates for quickly spinning up videos - notably, there are ones designed specifically for YouTube, with "exclusive music and effects." </p><p>All in all, it's very simple to jump into the timeline and start creating. </p><h2 id="editing-process">Editing process</h2><p>Editing video is incredibly straightforward. It's not laggy or clunky like I've seen with some mobile apps. </p><p>In fact, I was impressed how responsive it was overall, even with relatively larger video files. Helpfully, there are undo and re-do buttons sitting beneath the large preview window. An absolute godsend when editing on a phone. </p><p>Once you have a clip loaded on to the timeline, double-tapping the video brings up the handles for trimming. There's a Plus sign for adding (or generating) more clips. And you can select from a range of transitions with the tap of a button. </p><p>Running along the bottom of the screen are options to add text and audio, modify aspect ratio. I particularly liked this, because inside the frame options are logos, letting you know which ratio is suitable for which platforms. </p><h2 id="ai-generation">AI generation</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="5d9kTKJQgGCh9mjQyj3VsM" name="Adobe Premiere Android 003 Listing v2" alt="Using Adobe Premiere on Android to edit videos, with a blurred version of the app for background color" src="https://cdn.mos.cms.futurecdn.net/5d9kTKJQgGCh9mjQyj3VsM-1920-80.png" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>You do get access to a limited number of free tokens for AI image and video generation. </p><p>And when I say limited, I mean it. It's not very generous, and Firefly eats through them. I managed to squeeze out a single 4-second 720p clip before I needed to upgrade (or rather, sign into my main account). </p><p>Still, the generation itself works well, and it's relatively quick. Functionally, it's exactly what you'd get if you were using Adobe Firefly in your browser, or the Premiere desktop app.</p><p>I like that you can define the first and last frames of a video, generate in 720p and 1080p resolutions, change the duration, and opt to add audio. But to really make the most of this part of the app, a paid subscription is essential. </p><h2 id="video-export">Video export</h2><p>Super-simple, this one. When you're done editing, tap the ever-present Export button in the upper-right corner. You're then able to either export direct or tweak the settings. </p><p>Those settings include changing the resolution (720p, 1080p, 4K), the frame rate, between 24 and 60fps, and quality (low, medium, high). </p><p>Once you've got it set, Adobe Premiere offers an estimated file size, which is a nice touch. I exported a 17-second video at 4K in highest quality. The 106.5MB video took 34 seconds to complete. I then had the option to share via the usual channels. </p><h2 id="my-initial-verdict">My initial verdict</h2><p>The Android spin on Adobe Premiere is actually very good - although I'll be keen to put it under the full review process. But it's very easy to use, and the 4K res video export without watermarks is excellent. </p><p>The real catch is the laughably small AI generation limit. Unless you're a paid subscriber, I'd swerve those and use it strictly as an editor for your own clips. On that score, it delivers everything I'd expect from a free video editor for your phone. </p><ul><li><strong>Where to get it: </strong><a href="https://play.google.com/store/apps/details?id=com.adobe.premiere&hl=en_US" target="_blank">You can grab Adobe Premiere on Android free from the Google Play Store here</a></li></ul><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/ive-gone-hands-on-with-adobe-premieres-new-free-android-app-heres-what-its-like-to-use-and-why-free-comes-with-a-catch</link>
                                                                            <description>
                            <![CDATA[ Finally, Adobe Premiere comes to Android - I spent an hour with the video editing app to see if it lives up to the promise of 'effortless editing' for creators. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XKbxXrnKFhMxx9VDZQmdLT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7pwd6wdxpB7hwH2F4QzEYU-1920-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 16:35:53 +0000</pubDate>                                                                                                                                <updated>Tue, 22 Sep 2026 23:36:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Creative Software]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Steve Clark ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Ya2zPvg23DWNrjDSuCuWSL-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Steve is B2B Editor for Creative &amp; Hardware at &lt;em&gt;TechRadar Pro&lt;/em&gt;, helping business professionals equip their workspace with the right tools. He tests and reviews the software, hardware, and office furniture that modern workspaces depend on, cutting through the hype to zero in on the real-world performance you won&#039;t find on a spec sheet. A writer and editor with over 20 years&#039; experience, he&#039;s written for publications like &lt;em&gt;Web User &lt;/em&gt;magazine and business-focused content for brands including&lt;em&gt; &lt;/em&gt;Microsoft and Sony. Once upon a time, he wrote TV commercials and movie trailers. He is a relentless champion of the Oxford comma.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/7pwd6wdxpB7hwH2F4QzEYU-1920-80.png">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Using Adobe Premiere on Android to edit videos]]></media:description>                                                            <media:text><![CDATA[Using Adobe Premiere on Android to edit videos]]></media:text>
                                <media:title type="plain"><![CDATA[Using Adobe Premiere on Android to edit videos]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7pwd6wdxpB7hwH2F4QzEYU-1920-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Adobe Premiere on Android has officially launched</strong></li><li><strong>The free video editing app adds easy 4K video editing, AI, and more</strong></li><li><strong>I checked out how the app runs, what you get, and if it really does offer 'effortless editing' for creators</strong></li></ul><div  class="fancy-box"><div class="fancy_box-title">Quick verdict</div><div class="fancy_box_body"><p class="fancy-box__body-text"><strong>What works: </strong>Easy edits, unlimited 4K exports, clean interface, loads of templates, quick generative AI</p><p class="fancy-box__body-text"><strong>What doesn't: </strong>Limited free AI tokens</p></div></div><p>Adobe Premiere for Android has arrived - finally, since Apple users got this app almost exactly a year ago. The mobile editing app is promising to deliver 4K video for content creators, alongside a slew of other tools including templates and AI generation (did you ever doubt it?). </p><p>Like most of Adobe's mobile apps, Premiere is free to download from the Google Play Store, although you'll need a subscription for extra AI generations and storage. </p><p>The upshot is, I've been keen to try out this Android app for a long time now, so here's what you can expect after I spent an hour dabbling with it on my Fairphone. </p><h2 class="article-body__section" id="section-what-s-new"><span>What's new?</span></h2><p>This new Adobe Premiere app is specifically designed for Android phones, including foldables. According to Adobe, you'll need a device running Android 13 or later, with a minimum of 5GB RAM.</p><p>The app serves up a host of useful tools for content creators, including 4K video, simple-to-use templates for speeding up production, multi-track timeline editing, music and audio effects, and generative AI for image and video. </p><p>One of the high-points, as far as I'm concerned, is that it has no ads and exported videos are watermark-free. </p><p>A lot of 'free' mobile video editors could learn from this. There are no added intros and outros promoting Adobe either. So you can basically start creating video for social channels immediately. You can read the full write-up in <a href="https://blog.adobe.com/en/publish/2026/09/22/adobe-premiere-expands-android-fast-powerful-easy-mobile-video-editing" target="_blank">Adobe's blog here</a>. But is it any good? Here are my thoughts...</p><h2 class="article-body__section" id="section-first-impressions"><span>First impressions</span></h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="2JBYebkZawiFJsMBBYzY3N" name="Adobe Premiere Android 002 Listing v2" alt="Using Adobe Premiere on Android to edit videos, with a blurred version of the app for background color" src="https://cdn.mos.cms.futurecdn.net/2JBYebkZawiFJsMBBYzY3N-1920-80.png" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>I spent the last hour toying with Adobe Premiere to see whether it lives up to the promise of creating "stand out edits to share on TikTok, YouTube, Instagram, and Facebook." </p><p><em>Spoiler alert</em>: It's good stuff. A responsive app that's worth checking out if you need a free video editor that does everything I'd expect it to do. Especially if you have a paid Adobe account for those extra AI generations.</p><h2 id="layout">Layout</h2><p>Adobe Premiere on Android feels very clean, very sensibly laid out. That's a relief, because often I find Adobe's user interface to be unintuitive as a result of too many features. A phone screen is the last place you want to combat that. </p><p>Along the top of the screen are shortcuts for the main functions. This includes 'New from files' and 'Create for YouTube Shorts', as well as AI generations tools 'Image to video' and 'Text to video'. Once you start editing, your most recent projects can be found below this. </p><p>Under those key tools are a ridiculous number of templates for quickly spinning up videos - notably, there are ones designed specifically for YouTube, with "exclusive music and effects." </p><p>All in all, it's very simple to jump into the timeline and start creating. </p><h2 id="editing-process">Editing process</h2><p>Editing video is incredibly straightforward. It's not laggy or clunky like I've seen with some mobile apps. </p><p>In fact, I was impressed how responsive it was overall, even with relatively larger video files. Helpfully, there are undo and re-do buttons sitting beneath the large preview window. An absolute godsend when editing on a phone. </p><p>Once you have a clip loaded on to the timeline, double-tapping the video brings up the handles for trimming. There's a Plus sign for adding (or generating) more clips. And you can select from a range of transitions with the tap of a button. </p><p>Running along the bottom of the screen are options to add text and audio, modify aspect ratio. I particularly liked this, because inside the frame options are logos, letting you know which ratio is suitable for which platforms. </p><h2 id="ai-generation">AI generation</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="5d9kTKJQgGCh9mjQyj3VsM" name="Adobe Premiere Android 003 Listing v2" alt="Using Adobe Premiere on Android to edit videos, with a blurred version of the app for background color" src="https://cdn.mos.cms.futurecdn.net/5d9kTKJQgGCh9mjQyj3VsM-1920-80.png" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>You do get access to a limited number of free tokens for AI image and video generation. </p><p>And when I say limited, I mean it. It's not very generous, and Firefly eats through them. I managed to squeeze out a single 4-second 720p clip before I needed to upgrade (or rather, sign into my main account). </p><p>Still, the generation itself works well, and it's relatively quick. Functionally, it's exactly what you'd get if you were using Adobe Firefly in your browser, or the Premiere desktop app.</p><p>I like that you can define the first and last frames of a video, generate in 720p and 1080p resolutions, change the duration, and opt to add audio. But to really make the most of this part of the app, a paid subscription is essential. </p><h2 id="video-export">Video export</h2><p>Super-simple, this one. When you're done editing, tap the ever-present Export button in the upper-right corner. You're then able to either export direct or tweak the settings. </p><p>Those settings include changing the resolution (720p, 1080p, 4K), the frame rate, between 24 and 60fps, and quality (low, medium, high). </p><p>Once you've got it set, Adobe Premiere offers an estimated file size, which is a nice touch. I exported a 17-second video at 4K in highest quality. The 106.5MB video took 34 seconds to complete. I then had the option to share via the usual channels. </p><h2 id="my-initial-verdict">My initial verdict</h2><p>The Android spin on Adobe Premiere is actually very good - although I'll be keen to put it under the full review process. But it's very easy to use, and the 4K res video export without watermarks is excellent. </p><p>The real catch is the laughably small AI generation limit. Unless you're a paid subscriber, I'd swerve those and use it strictly as an editor for your own clips. On that score, it delivers everything I'd expect from a free video editor for your phone. </p><ul><li><strong>Where to get it: </strong><a href="https://play.google.com/store/apps/details?id=com.adobe.premiere&hl=en_US" target="_blank">You can grab Adobe Premiere on Android free from the Google Play Store here</a></li></ul><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ More and more workers are feeling stressed at work due to security risks ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>More workers are worried about security issues than they were this time last year</strong></li><li><strong>Three in four say their recovery tools are too difficult for them to use</strong></li><li><strong>This report says having strong data storage could help</strong></li></ul><p>While many of us typically see security as an IT or a leadership issue, it's actually impacting us more than we'd initially thought. New Object First data found that 91% of workers feel uncomfortably stressed at work because of IT security risks – a seven percentage point increase over last year.</p><p>But unfortunately, it's a double-edged sword because it all boils down to AI. Nine in 10 say AI tools have improved their productivity, but seven in 10 say the growth of AI-powered threats is a key driver behind their stress.</p><p>Additionally, fewer than one-quarter (24%) believe their organisation is suitably equipped to deal with those threats.</p><h2 id="ai-driven-security-threats-are-actually-impacting-you-and-i">AI-driven security threats are actually impacting you and I</h2><p>While the risk of cyberattacks (50%) is a leading cause for stress at work, high workloads and understaffing (50%) land in joint-first place. Gaps in backup and recovery effectiveness (41%) and pressure to maintain uptime (44%) are also big headaches for workers, implying pressure isn't coming from direct attacks alone, but workload and operations.</p><p>For example, three in four (74%) say that their recovery tools are difficult to use without security expertise, leaving regular knowledge workers at a loss. One in five (19%) even say they feel hopeless and overwhelmed during and after an incident.</p><p>Naturally, this stress is impacting productivity, with four in five (78%) remarking that stress negatively affected their job performance. Two in five (39%) even said they'd thought about quitting.</p><p>"As critical as technology is to cyber resilience, those responsible for protecting and recovering an organization’s data are just as essential," company CEO David Bennett concluded.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/more-and-more-workers-are-feeling-stressed-at-work-due-to-security-risks</link>
                                                                            <description>
                            <![CDATA[ 91% feel stressed because of IT security risks, but 74% say the recovery tools they have access to are too hard to use. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hUK7et99BxCJF5KwCMrGb9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BV5jpKqSzFZAvPiNQWeHEi-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 16:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BV5jpKqSzFZAvPiNQWeHEi-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Stress]]></media:description>                                                            <media:text><![CDATA[Stress]]></media:text>
                                <media:title type="plain"><![CDATA[Stress]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BV5jpKqSzFZAvPiNQWeHEi-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>More workers are worried about security issues than they were this time last year</strong></li><li><strong>Three in four say their recovery tools are too difficult for them to use</strong></li><li><strong>This report says having strong data storage could help</strong></li></ul><p>While many of us typically see security as an IT or a leadership issue, it's actually impacting us more than we'd initially thought. New Object First data found that 91% of workers feel uncomfortably stressed at work because of IT security risks – a seven percentage point increase over last year.</p><p>But unfortunately, it's a double-edged sword because it all boils down to AI. Nine in 10 say AI tools have improved their productivity, but seven in 10 say the growth of AI-powered threats is a key driver behind their stress.</p><p>Additionally, fewer than one-quarter (24%) believe their organisation is suitably equipped to deal with those threats.</p><h2 id="ai-driven-security-threats-are-actually-impacting-you-and-i">AI-driven security threats are actually impacting you and I</h2><p>While the risk of cyberattacks (50%) is a leading cause for stress at work, high workloads and understaffing (50%) land in joint-first place. Gaps in backup and recovery effectiveness (41%) and pressure to maintain uptime (44%) are also big headaches for workers, implying pressure isn't coming from direct attacks alone, but workload and operations.</p><p>For example, three in four (74%) say that their recovery tools are difficult to use without security expertise, leaving regular knowledge workers at a loss. One in five (19%) even say they feel hopeless and overwhelmed during and after an incident.</p><p>Naturally, this stress is impacting productivity, with four in five (78%) remarking that stress negatively affected their job performance. Two in five (39%) even said they'd thought about quitting.</p><p>"As critical as technology is to cyber resilience, those responsible for protecting and recovering an organization’s data are just as essential," company CEO David Bennett concluded.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to vibe code your first website ]]></title>
                                                                                                <dc:content><![CDATA[ <p><a href="https://www.techradar.com/pro/best-vibe-coding-tools" target="_blank">Vibe coding</a> began as a buzzword but quickly became a software category of its own. Now there are more AI platforms offering vibe coding features than there are days in a year. But if you’re going to use one, you need to know how they work and the ways they’re different from the no-code or low-code platforms you may have used in the past. </p><p>It’s a bit more complicated than simply entering a prompt and generating a fully functional website you can use right away, though that is often the way it’s marketed. In reality, you’re still left to fine-tune the generated output until it’s functional, decide on hosting infrastructure, and troubleshoot any security or operational issues that arise. </p><p>I’ve spent a lot of time working with vibe coding apps over the past couple of years, weaving several of them in and out of my workflow depending on the project scope. Here, I’ll share with you what I’ve learned, including the things that have changed in the industry since vibe coding began as a concept.</p><h2 class="article-body__section" id="section-how-vibe-coding-works"><span>How vibe coding works</span></h2><p>Vibe coding isn’t programming in the traditional sense. You’re not writing code, so it’s more similar to no-code or drag-and-drop <a href="https://www.techradar.com/news/the-best-website-builder" target="_blank">website builders</a> than writing HTML5 or React-based apps in a text editor. </p><p>But thanks to recent improvements in Large Language Models (LLMs) and generative AI, you can essentially describe what you want your website to do and how you want it to look, then let the platform interpret your prompt and generate the code you need in HTML, CSS, and JavaScript. </p><p>You can then export the code as raw files into any web hosting server of your choice, register a new domain, and go live within a matter of minutes. </p><p>But in reality, it’s not always so simple. </p><p>When you enter a prompt for the AI to generate from — depending on how specific you are and how advanced the underlying technology is — you’ll end up with something that’s at best close to functional but not ready for production quite yet. You’ll then have to tweak the AI-generated site, using subsequent prompts to refine the design until you get to something you’re satisfied with.</p><h2 class="article-body__section" id="section-types-of-vibe-coding-tools"><span>Types of vibe coding tools</span></h2><p>Not all vibe coding tools work the same way, of course. </p><p>Some are more typical AI generators that let you build a website from start to finish by talking to a chatbot. Others combine this with drag-and-drop editors and other visual aids to let you tweak the design directly. A few even function like traditional text editors that programmers use, but with the option to use chatbot assistance to generate chunks of code while you still retain authority over what to keep. </p><div ><table><tbody><tr><td class="firstcol " ><p><strong>Tool category</strong></p></td><td  ><p><strong>What it does</strong></p></td><td  ><p><strong>Best for</strong></p></td></tr><tr><td class="firstcol " ><p>Full-stack app builders</p></td><td  ><p>Generate frontend, backend, database, and hosting from a single prompt</p></td><td  ><p>Complete websites or web apps with accounts, forms, or stored data</p></td></tr><tr><td class="firstcol " ><p>Frontend/UI generators</p></td><td  ><p>Generate visual components and layouts, often exportable as code</p></td><td  ><p>Landing pages, design prototypes, or polishing an existing site's look</p></td></tr><tr><td class="firstcol " ><p>All-in-one platforms</p></td><td  ><p>Bundle AI code generation with hosting, domains, and email in one subscription</p></td><td  ><p>Beginners who want a single dashboard for the whole website, start to finish</p></td></tr><tr><td class="firstcol " ><p>AI coding assistants</p></td><td  ><p>Sit inside a code editor and speed up work for people who already write code</p></td><td  ><p>Developers extending or customizing a site beyond what pure prompting can do</p></td></tr></tbody></table></div><p>For a first website, a full-stack app builder or an all-in-one platform is usually the simplest starting point. They even package things like hosting infrastructure, domain registration, and ongoing support into the same platform, making it easier for you to get your website ready for launch without too much fuss.</p><h2 class="article-body__section" id="section-how-to-vibe-code-your-first-website-step-by-step"><span>How to vibe code your first website, step-by-step</span></h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:3481px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ErMjxyvbmNgFtHbmnp2uPc" name="ScreenShot Tool -20260830161035" alt="Prompt-based AI app generator on Bolt's landing page" src="https://cdn.mos.cms.futurecdn.net/ErMjxyvbmNgFtHbmnp2uPc-1920-80.png" mos="" align="middle" fullscreen="" width="3481" height="1958" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Bolt.new)</span></figcaption></figure><p>Every vibe coding project follows roughly the same arc, regardless of which platform you choose. You'll move from a plain-language brief to a live preview, then layer on the pages, design, and any extras your site needs before you publish.</p><p>The steps below outline that workflow at a level that applies across most tools. Swap in the specific platform of your choice at each stage, and expect to spend more time refining than generating.</p><p><strong>Step 1: Write your first prompt</strong></p><p>Start with clear and specific instructions, not a single sentence. Describe your site’s purpose, the pages you need (home, about, contact, services), your design aesthetic, and any brand colors or fonts you already use.</p><p>The more details you offer upfront, the less back-and-forth you'll need later. Most platforms generate an initial working version, complete with a live preview, within a minute or two of your first prompt.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:3481px;"><p class="vanilla-image-block" style="padding-top:57.68%;"><img id="h23VFUWPnGLkNTjKDcpuud" name="ScreenShot Tool -20260830161220" alt="Writing a prompt for a vibe coding app" src="https://cdn.mos.cms.futurecdn.net/h23VFUWPnGLkNTjKDcpuud-1920-80.png" mos="" align="middle" fullscreen="" width="3481" height="2008" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Lovable)</span></figcaption></figure><p><strong>Step 2: Review the generated structure</strong></p><p>Look at the pages and navigation the AI has created before you touch the design. Check that the site structure matches how you actually want visitors to move through it, since restructuring later is more disruptive than adjusting styling.</p><p>If something's missing, like a pricing page or a booking form, ask for it directly in a follow-up prompt rather than trying to work around the gap.</p><p><strong>Step 3: Refine the design with follow-up prompts</strong></p><p>Use targeted prompts to adjust individual elements like colors, spacing, fonts, image placement, or button styles. Many platforms also include a visual editor where you can click an element and edit it directly, which tends to be faster than describing a small tweak in words.</p><p>Upload your logo and any brand assets at this stage so the AI can work them into the design instead of generating generic placeholders. </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:3481px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HVS3ycnR6F4eqe5Eh6jrgd" name="ScreenShot Tool -20260830160912" alt="The Remix feature on Google AI Studio in action" src="https://cdn.mos.cms.futurecdn.net/HVS3ycnR6F4eqe5Eh6jrgd-1920-80.png" mos="" align="middle" fullscreen="" width="3481" height="1958" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p><strong>Step 4: Add a CMS if you'll be publishing content regularly</strong></p><p>If your site needs a blog, news section, or other content you'll update often, ask the platform to add CMS features or connect a third-party content management system through an API. This gives you an editing interface separate from the code, so future updates don't mean rewriting prompts every time.</p><p>Skip this step entirely if your site is just a static handful of pages that rarely change.</p><p><strong>Step 5: Add ecommerce features if you're selling anything</strong></p><p>You can build an <a href="https://www.techradar.com/how-to/how-to-create-an-online-store" target="_blank">online store</a> by asking the AI to add product listings, a shopping cart, checkout, and a payment processor through supported integrations. Test the full purchase flow yourself, including failed payments and confirmation emails, before it goes live.</p><p>Most full-stack builders support popular payment providers as plug-in integrations rather than requiring you to build checkout logic from scratch.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1195px;"><p class="vanilla-image-block" style="padding-top:56.23%;"><img id="QvRe7baCrqcktdbMb8yCeb" name="ScreenShot Tool -20260830161354" alt="A display of ecommerce integrations from Lovable's connector marketplace" src="https://cdn.mos.cms.futurecdn.net/QvRe7baCrqcktdbMb8yCeb-1920-80.png" mos="" align="middle" fullscreen="" width="1195" height="672" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Lovable.dev)</span></figcaption></figure><p><strong>Step 6: Connect a domain and go live</strong></p><p>Once you're happy with the site, connect your custom domain through the platform's settings and confirm SSL is active before publishing. Many all-in-one platforms handle domain registration and SSL certificates automatically, while others expect you to point your DNS records to their hosting.</p><p>Do a final pass on every page and link once the domain is live, since some elements can render differently outside the preview environment.</p><h2 class="article-body__section" id="section-vibe-coding-dos-and-don-ts"><span>Vibe coding dos and don'ts</span></h2><p>Vibe coding tools remove a lot of the technical barriers to building a website, but that speed comes with trade-offs worth knowing about before you publish. </p><p>Security researchers have repeatedly found that AI-generated applications ship with vulnerabilities at a higher rate than traditionally coded ones, including exposed credentials and missing authentication on features that should be locked down.</p><p>Treat any AI-generated code as a first draft rather than a finished product, especially anything touching customer data, logins, or payments. Review what the platform built, and if you're not confident reading code yourself, have someone who can check it before you collect real customer information. Also keep any sensitive details, like API keys, tokens, or passwords, out of your prompts entirely. Don't paste credentials into a chat window expecting the platform to keep them secure, since prompts and generated code aren't a safe place to store secrets.</p><p>Finally, don't assume a polished-looking preview means the site is secure. Researchers have found thousands of publicly deployed AI-built sites with no authentication on pages that should require a login, often because the builder never thought to ask for it. Test your site's forms, accounts, and checkout flow the way an attacker might before you consider it done, and lean on your platform's built-in security scanning if it offers one.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/how-to-vibe-code-your-first-website</link>
                                                                            <description>
                            <![CDATA[ A step-by-step guide to vibe coding your first website. We’ll also talk about how these tools work, offer tips on platform selection, and cover some security basics you will need to know. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Y369eDwmUZmfxaSRMPF5Vj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8eDTMGxjkXScGZj7ux5yhC-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 15:45:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Website Building]]></category>
                                                                                                <author><![CDATA[ ritoban@nutgraf.agency (Ritoban Mukherjee) ]]></author>                    <dc:creator><![CDATA[ Ritoban Mukherjee ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/cD9joj4H54xYmooW8re3vU-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8eDTMGxjkXScGZj7ux5yhC-1920-80.jpg">
                                                            <media:credit><![CDATA[Generated by Gemini ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[woman in a modern office using a laptop]]></media:description>                                                            <media:text><![CDATA[woman in a modern office using a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[woman in a modern office using a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8eDTMGxjkXScGZj7ux5yhC-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.techradar.com/pro/best-vibe-coding-tools" target="_blank">Vibe coding</a> began as a buzzword but quickly became a software category of its own. Now there are more AI platforms offering vibe coding features than there are days in a year. But if you’re going to use one, you need to know how they work and the ways they’re different from the no-code or low-code platforms you may have used in the past. </p><p>It’s a bit more complicated than simply entering a prompt and generating a fully functional website you can use right away, though that is often the way it’s marketed. In reality, you’re still left to fine-tune the generated output until it’s functional, decide on hosting infrastructure, and troubleshoot any security or operational issues that arise. </p><p>I’ve spent a lot of time working with vibe coding apps over the past couple of years, weaving several of them in and out of my workflow depending on the project scope. Here, I’ll share with you what I’ve learned, including the things that have changed in the industry since vibe coding began as a concept.</p><h2 class="article-body__section" id="section-how-vibe-coding-works"><span>How vibe coding works</span></h2><p>Vibe coding isn’t programming in the traditional sense. You’re not writing code, so it’s more similar to no-code or drag-and-drop <a href="https://www.techradar.com/news/the-best-website-builder" target="_blank">website builders</a> than writing HTML5 or React-based apps in a text editor. </p><p>But thanks to recent improvements in Large Language Models (LLMs) and generative AI, you can essentially describe what you want your website to do and how you want it to look, then let the platform interpret your prompt and generate the code you need in HTML, CSS, and JavaScript. </p><p>You can then export the code as raw files into any web hosting server of your choice, register a new domain, and go live within a matter of minutes. </p><p>But in reality, it’s not always so simple. </p><p>When you enter a prompt for the AI to generate from — depending on how specific you are and how advanced the underlying technology is — you’ll end up with something that’s at best close to functional but not ready for production quite yet. You’ll then have to tweak the AI-generated site, using subsequent prompts to refine the design until you get to something you’re satisfied with.</p><h2 class="article-body__section" id="section-types-of-vibe-coding-tools"><span>Types of vibe coding tools</span></h2><p>Not all vibe coding tools work the same way, of course. </p><p>Some are more typical AI generators that let you build a website from start to finish by talking to a chatbot. Others combine this with drag-and-drop editors and other visual aids to let you tweak the design directly. A few even function like traditional text editors that programmers use, but with the option to use chatbot assistance to generate chunks of code while you still retain authority over what to keep. </p><div ><table><tbody><tr><td class="firstcol " ><p><strong>Tool category</strong></p></td><td  ><p><strong>What it does</strong></p></td><td  ><p><strong>Best for</strong></p></td></tr><tr><td class="firstcol " ><p>Full-stack app builders</p></td><td  ><p>Generate frontend, backend, database, and hosting from a single prompt</p></td><td  ><p>Complete websites or web apps with accounts, forms, or stored data</p></td></tr><tr><td class="firstcol " ><p>Frontend/UI generators</p></td><td  ><p>Generate visual components and layouts, often exportable as code</p></td><td  ><p>Landing pages, design prototypes, or polishing an existing site's look</p></td></tr><tr><td class="firstcol " ><p>All-in-one platforms</p></td><td  ><p>Bundle AI code generation with hosting, domains, and email in one subscription</p></td><td  ><p>Beginners who want a single dashboard for the whole website, start to finish</p></td></tr><tr><td class="firstcol " ><p>AI coding assistants</p></td><td  ><p>Sit inside a code editor and speed up work for people who already write code</p></td><td  ><p>Developers extending or customizing a site beyond what pure prompting can do</p></td></tr></tbody></table></div><p>For a first website, a full-stack app builder or an all-in-one platform is usually the simplest starting point. They even package things like hosting infrastructure, domain registration, and ongoing support into the same platform, making it easier for you to get your website ready for launch without too much fuss.</p><h2 class="article-body__section" id="section-how-to-vibe-code-your-first-website-step-by-step"><span>How to vibe code your first website, step-by-step</span></h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:3481px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ErMjxyvbmNgFtHbmnp2uPc" name="ScreenShot Tool -20260830161035" alt="Prompt-based AI app generator on Bolt's landing page" src="https://cdn.mos.cms.futurecdn.net/ErMjxyvbmNgFtHbmnp2uPc-1920-80.png" mos="" align="middle" fullscreen="" width="3481" height="1958" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Bolt.new)</span></figcaption></figure><p>Every vibe coding project follows roughly the same arc, regardless of which platform you choose. You'll move from a plain-language brief to a live preview, then layer on the pages, design, and any extras your site needs before you publish.</p><p>The steps below outline that workflow at a level that applies across most tools. Swap in the specific platform of your choice at each stage, and expect to spend more time refining than generating.</p><p><strong>Step 1: Write your first prompt</strong></p><p>Start with clear and specific instructions, not a single sentence. Describe your site’s purpose, the pages you need (home, about, contact, services), your design aesthetic, and any brand colors or fonts you already use.</p><p>The more details you offer upfront, the less back-and-forth you'll need later. Most platforms generate an initial working version, complete with a live preview, within a minute or two of your first prompt.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:3481px;"><p class="vanilla-image-block" style="padding-top:57.68%;"><img id="h23VFUWPnGLkNTjKDcpuud" name="ScreenShot Tool -20260830161220" alt="Writing a prompt for a vibe coding app" src="https://cdn.mos.cms.futurecdn.net/h23VFUWPnGLkNTjKDcpuud-1920-80.png" mos="" align="middle" fullscreen="" width="3481" height="2008" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Lovable)</span></figcaption></figure><p><strong>Step 2: Review the generated structure</strong></p><p>Look at the pages and navigation the AI has created before you touch the design. Check that the site structure matches how you actually want visitors to move through it, since restructuring later is more disruptive than adjusting styling.</p><p>If something's missing, like a pricing page or a booking form, ask for it directly in a follow-up prompt rather than trying to work around the gap.</p><p><strong>Step 3: Refine the design with follow-up prompts</strong></p><p>Use targeted prompts to adjust individual elements like colors, spacing, fonts, image placement, or button styles. Many platforms also include a visual editor where you can click an element and edit it directly, which tends to be faster than describing a small tweak in words.</p><p>Upload your logo and any brand assets at this stage so the AI can work them into the design instead of generating generic placeholders. </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:3481px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HVS3ycnR6F4eqe5Eh6jrgd" name="ScreenShot Tool -20260830160912" alt="The Remix feature on Google AI Studio in action" src="https://cdn.mos.cms.futurecdn.net/HVS3ycnR6F4eqe5Eh6jrgd-1920-80.png" mos="" align="middle" fullscreen="" width="3481" height="1958" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p><strong>Step 4: Add a CMS if you'll be publishing content regularly</strong></p><p>If your site needs a blog, news section, or other content you'll update often, ask the platform to add CMS features or connect a third-party content management system through an API. This gives you an editing interface separate from the code, so future updates don't mean rewriting prompts every time.</p><p>Skip this step entirely if your site is just a static handful of pages that rarely change.</p><p><strong>Step 5: Add ecommerce features if you're selling anything</strong></p><p>You can build an <a href="https://www.techradar.com/how-to/how-to-create-an-online-store" target="_blank">online store</a> by asking the AI to add product listings, a shopping cart, checkout, and a payment processor through supported integrations. Test the full purchase flow yourself, including failed payments and confirmation emails, before it goes live.</p><p>Most full-stack builders support popular payment providers as plug-in integrations rather than requiring you to build checkout logic from scratch.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1195px;"><p class="vanilla-image-block" style="padding-top:56.23%;"><img id="QvRe7baCrqcktdbMb8yCeb" name="ScreenShot Tool -20260830161354" alt="A display of ecommerce integrations from Lovable's connector marketplace" src="https://cdn.mos.cms.futurecdn.net/QvRe7baCrqcktdbMb8yCeb-1920-80.png" mos="" align="middle" fullscreen="" width="1195" height="672" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Lovable.dev)</span></figcaption></figure><p><strong>Step 6: Connect a domain and go live</strong></p><p>Once you're happy with the site, connect your custom domain through the platform's settings and confirm SSL is active before publishing. Many all-in-one platforms handle domain registration and SSL certificates automatically, while others expect you to point your DNS records to their hosting.</p><p>Do a final pass on every page and link once the domain is live, since some elements can render differently outside the preview environment.</p><h2 class="article-body__section" id="section-vibe-coding-dos-and-don-ts"><span>Vibe coding dos and don'ts</span></h2><p>Vibe coding tools remove a lot of the technical barriers to building a website, but that speed comes with trade-offs worth knowing about before you publish. </p><p>Security researchers have repeatedly found that AI-generated applications ship with vulnerabilities at a higher rate than traditionally coded ones, including exposed credentials and missing authentication on features that should be locked down.</p><p>Treat any AI-generated code as a first draft rather than a finished product, especially anything touching customer data, logins, or payments. Review what the platform built, and if you're not confident reading code yourself, have someone who can check it before you collect real customer information. Also keep any sensitive details, like API keys, tokens, or passwords, out of your prompts entirely. Don't paste credentials into a chat window expecting the platform to keep them secure, since prompts and generated code aren't a safe place to store secrets.</p><p>Finally, don't assume a polished-looking preview means the site is secure. Researchers have found thousands of publicly deployed AI-built sites with no authentication on pages that should require a login, often because the builder never thought to ask for it. Test your site's forms, accounts, and checkout flow the way an attacker might before you consider it done, and lean on your platform's built-in security scanning if it offers one.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft is retiring some key 365 companion apps — Calendar, People, and Files services all set to be cut ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Calendar, People and Files companion apps are being pulled after automatic installation last year</strong></li><li><strong>Importantly, these particular interfaces are going, but the data is still accessible elsewhere</strong></li><li><strong>Microsoft also wants you to use Copilot to find the information you need</strong></li></ul><p>Microsoft has confirmed that Calendar, People and Files are all becoming unsupported as of December 2026 after it started automatically installing them on Windows 11 devices with linked Microsoft 365 accounts in late 2025.</p><p>The vision was that users would be able to get quick access to important information like contact details through these lightweight apps – the company did not share the reason for pulling these companion apps.</p><p>Crucially, though, while the apps themselves may be going, the data behind them isn't. Data like contact details, for instance, are already stored elsewhere in the M365 cloud, so the companion apps are just one way to access the information.</p><h2 id="microsoft-365-calendar-people-and-files-are-all-being-pulled">Microsoft 365 Calendar, People and Files are all being pulled</h2><p>Removing the apps does come as something of a surprise, because Microsoft has been building Copilot into them. The company still even has some Copilot features in the works "coming soon" – but clearly not.</p><p>We know that the three companion apps in question are no longer being automatically installed, however they aren't set to be automatically removed. For enterprises, administrators will need to remove them. Admins also need to configure Intone to stop deployments.</p><p>Unmanaged PCs, such as consumer laptops, can remove the apps through the usual channel.</p><p>Moving forward, the users who did actually use those companion apps are being told to resort to Outlook and Teams for calendar and people information, and Windows Search Box, Files Explorer, SharePoint and OneDrive for files. The company, naturally, plugged its own Copilot AI companion for helping users surface information, too.</p><p>With deprecation now just weeks away, Microsoft stressed that important security updates for the three apps in question won't be rolled out.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/microsoft-is-retiring-some-key-365-companion-apps-calendar-people-and-files-services-all-set-to-be-cut</link>
                                                                            <description>
                            <![CDATA[ Late last year, Microsoft started to install Calendar, People and Files apps automatically, but now it's pulling them altogether. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">N8Fv3YzQs39FDNA4UR4jdk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vUENLgpmE9SAJMUqFSigSF-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 15:26:31 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vUENLgpmE9SAJMUqFSigSF-1920-80.jpg">
                                                            <media:credit><![CDATA[Windows/Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Windows 11 on a laptop]]></media:description>                                                            <media:text><![CDATA[Windows 11 on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[Windows 11 on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vUENLgpmE9SAJMUqFSigSF-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Calendar, People and Files companion apps are being pulled after automatic installation last year</strong></li><li><strong>Importantly, these particular interfaces are going, but the data is still accessible elsewhere</strong></li><li><strong>Microsoft also wants you to use Copilot to find the information you need</strong></li></ul><p>Microsoft has confirmed that Calendar, People and Files are all becoming unsupported as of December 2026 after it started automatically installing them on Windows 11 devices with linked Microsoft 365 accounts in late 2025.</p><p>The vision was that users would be able to get quick access to important information like contact details through these lightweight apps – the company did not share the reason for pulling these companion apps.</p><p>Crucially, though, while the apps themselves may be going, the data behind them isn't. Data like contact details, for instance, are already stored elsewhere in the M365 cloud, so the companion apps are just one way to access the information.</p><h2 id="microsoft-365-calendar-people-and-files-are-all-being-pulled">Microsoft 365 Calendar, People and Files are all being pulled</h2><p>Removing the apps does come as something of a surprise, because Microsoft has been building Copilot into them. The company still even has some Copilot features in the works "coming soon" – but clearly not.</p><p>We know that the three companion apps in question are no longer being automatically installed, however they aren't set to be automatically removed. For enterprises, administrators will need to remove them. Admins also need to configure Intone to stop deployments.</p><p>Unmanaged PCs, such as consumer laptops, can remove the apps through the usual channel.</p><p>Moving forward, the users who did actually use those companion apps are being told to resort to Outlook and Teams for calendar and people information, and Windows Search Box, Files Explorer, SharePoint and OneDrive for files. The company, naturally, plugged its own Copilot AI companion for helping users surface information, too.</p><p>With deprecation now just weeks away, Microsoft stressed that important security updates for the three apps in question won't be rolled out.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Hi, it’s AI speaking’: Base44 just launched AI that can handle phone calls ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><a href="https://www.techradar.com/pro/software-services/base44-no-code-review" target="_blank"><strong>Base44 </strong></a><strong>has launched an AI agent that can make and receive phone calls </strong></li><li><strong>It aims to eliminate hold times and speed up research </strong></li><li><strong>Just describe your goal, give context, and let it do the work for you</strong></li></ul><p>Waiting on hold may become a thing of the past thanks to Base44’s new voice AI agent. Launched earlier this month, Superagent can now make and receive phone calls on behalf of the user, with countless potential applications. </p><p>According to a press release shared with TechRadar Pro, Base44’s Superagent can take on everyday tasks that would otherwise require people to spend time on hold or leave them navigating frustrating phone systems. </p><div style="min-height: 250px;">                                <div class="kwizly-quiz kwizly-XpoklO"></div>                            </div>                            <script src="https://kwizly.com/embed/XpoklO.js" async></script><h2 id="how-base-44-s-superagent-works">How Base 44’s Superagent works </h2><p>Users start by giving Superagent a goal and providing relevant context on how that goal should be achieved. The AI agent can then proactively contact businesses or customers, asking relevant questions, collecting crucial information, and even navigating supported phone menus. Once the job is complete, the agent will then report back to the user with a summary of what has been done and which outcomes have been achieved. </p><p>Some helpful use cases include: </p><ul><li>Improve time management by booking or rescheduling important appointments</li><li>Speed up research by calling vendors to request quotes for comparison</li><li>Increase call success by retrying unanswered calls on a predefined schedule</li><li>Receive and manage calls from trusted contacts</li></ul><h2 id="a-shifting-approach-to-ai">A shifting approach to AI </h2><p>The launch highlights an ongoing shift in consumer AI, with tools moving from generative AI that simply answers questions to agentic AI that undertakes real-world actions based on requests made by the user. </p><p>But the question remains: will humans be happy to interact with AI if it means limiting wait times and more efficient calls? </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/hi-its-ai-speaking-base44-just-launched-ai-that-can-handle-phone-calls</link>
                                                                            <description>
                            <![CDATA[ Would you pick up? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BSewc4qf3qajevGfwUGd3e</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eTAQwoocjoi2ejyyLKBtLN-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 14:49:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Website Hosting]]></category>
                                                    <category><![CDATA[Website Building]]></category>
                                                                                                                    <dc:creator><![CDATA[ Owain Williams ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/yLKEi5rn5TCTcqYsfAHXDf-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Previously working as a freelance content writer and editor, Owain has been writing about website builders, marketing, and a range of other business topics since 2017. During this time he has worked with industry leaders, spoken at several events, and been published on top media sites including MarketingProfs, Website Builder Expert, Digital Doughnut, and NealSchaffer.com.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Owain has gained hands-on experience with many leading website builders. This includes building his own ecommerce store on Shopify, creating several websites on WIX, and working with clients to grow their WordPress and Squarespace sites.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;During his career, Owain has gained a breadth of marketing experience across industries ranging from complex engineering and international events to brand design and even brewing. Undertaking a 4 year apprenticeship in business, Owain has achieved a HNC, HND, and BA(Hons) in Business, Management, and Marketing alongside several professional qualifications from institutes including the Institute of Leadership and Management (ILM) and the Institute of Data and Marketing (IDM).&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;When he isn’t thinking, talking, and writing about website builders, Owain is a keen practitioner and competitor in Brazilian Jiu Jitsu, enjoys walking his dog, and spending time with his family.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eTAQwoocjoi2ejyyLKBtLN-1920-80.jpg">
                                                            <media:credit><![CDATA[Base44/Edited with Gemini ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Prompt entered into Base 44]]></media:description>                                                            <media:text><![CDATA[Prompt entered into Base 44]]></media:text>
                                <media:title type="plain"><![CDATA[Prompt entered into Base 44]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eTAQwoocjoi2ejyyLKBtLN-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><a href="https://www.techradar.com/pro/software-services/base44-no-code-review" target="_blank"><strong>Base44 </strong></a><strong>has launched an AI agent that can make and receive phone calls </strong></li><li><strong>It aims to eliminate hold times and speed up research </strong></li><li><strong>Just describe your goal, give context, and let it do the work for you</strong></li></ul><p>Waiting on hold may become a thing of the past thanks to Base44’s new voice AI agent. Launched earlier this month, Superagent can now make and receive phone calls on behalf of the user, with countless potential applications. </p><p>According to a press release shared with TechRadar Pro, Base44’s Superagent can take on everyday tasks that would otherwise require people to spend time on hold or leave them navigating frustrating phone systems. </p><div style="min-height: 250px;">                                <div class="kwizly-quiz kwizly-XpoklO"></div>                            </div>                            <script src="https://kwizly.com/embed/XpoklO.js" async></script><h2 id="how-base-44-s-superagent-works">How Base 44’s Superagent works </h2><p>Users start by giving Superagent a goal and providing relevant context on how that goal should be achieved. The AI agent can then proactively contact businesses or customers, asking relevant questions, collecting crucial information, and even navigating supported phone menus. Once the job is complete, the agent will then report back to the user with a summary of what has been done and which outcomes have been achieved. </p><p>Some helpful use cases include: </p><ul><li>Improve time management by booking or rescheduling important appointments</li><li>Speed up research by calling vendors to request quotes for comparison</li><li>Increase call success by retrying unanswered calls on a predefined schedule</li><li>Receive and manage calls from trusted contacts</li></ul><h2 id="a-shifting-approach-to-ai">A shifting approach to AI </h2><p>The launch highlights an ongoing shift in consumer AI, with tools moving from generative AI that simply answers questions to agentic AI that undertakes real-world actions based on requests made by the user. </p><p>But the question remains: will humans be happy to interact with AI if it means limiting wait times and more efficient calls? </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This fake LastPass Authenticator app will just shut off your antivirus and leave you open to attack ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Attackers spoofed LastPass Authenticator via SEO‑poisoned GitHub pages, delivering malicious ZIP files</strong></li><li><strong>Malware Rapuncel uses DLL sideloading, kills 145 AV products, and steals passwords, wallets, and tokens</strong></li><li><strong>Campaign ongoing for months; LastPass vaults unaffected, but users urged to download only from trusted sources</strong></li></ul><p>Be careful when downloading the LastPass Authenticator app - there are impostors out there that can disable your antivirus and wreak havoc on your computer. </p><p>LastPass recently <a href="https://blog.lastpass.com/posts/lastpass-delphos-report-rapuncel-infostealer" target="_blank">discovered</a> an elaborate scheme to get people infected with <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> - a spoofed website, SEO poisoning, DLL sideloading, and a malware loader delivering never-before-seen payload that can kill endpoint protection and antivirus solutions.</p><p>According to the <a href="https://www.techradar.com/best/password-manager" target="_blank">password manager</a>, users searching for "LastPass <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">Authenticator</a> download" or similar keywords will get a GitHub page rather high on the search engine results pages. At a glance, the page looks almost identical to the authentic LastPass offering - however, it redirects users to a separate one, hosted on attacker-controlled infrastructure and delivering a large .ZIP file with multiple files.</p><p>Among the files are two worth paying attention to: vsdbg.exe, and vsdbg.dll. The .EXE one is renamed to look like a LastPass installer, but it’s in fact a legitimate Microsoft debugging tool. This tool is used to run the malware - the vsdbg.dll file. This is a method called “dll sideloading” where the legitimate program will look for a DLL file in the same folder it’s located, rather than the wider device library. Since the DLL is delivered together with the executable, it is the first one to be run, despite the fact that it’s malicious. </p><h2 id="rapuncel">Rapuncel</h2><p>LastPass shared the malware with security researchers Delphos for analysis, and they’ve named it Rapuncel. No AV engines have been able to spot it, when it was first analyzed. </p><p>Once Rapuncel runs, it does a number of things. First, it gains admin-level access to run as SYSTEM, and then installs a kernel driver. The driver, disguised as an NVIDIA graphics component, comes with a hardcoded list of 145 antivirus and endpoint security products, and if any of them are found on the device, they are instantly terminated. </p><p>After killing antivirus solutions, the malware gets to work, stealing saved passwords from more than 25 browsers (Chrome, Edge, and other popular ones included), cryptocurrency wallet files from more than 30 wallet apps, Discord login tokens, Steam session tokens, Telegram session data, Windows credential store, all documents with words like “password”, “seed”, “wallet”, or “recovery” in their name, screenshots of every monitor connected to the device, as well as a detailed profile of the system.</p><p>Once all of this is harvested, the information is compressed into a .ZIP archive and uploaded to a server under the attackers’ control. To add insult to injury, the kernel driver was given code to intercept all web traffic, allowing the attackers to inject ads, or modify search results, at a whim. </p><p>Rapuncel comes with a persistence mechanism, as well, to make sure it continues operating even if the victim spots it. Spotting it should not be too difficult, though - if no antivirus programs are allowed to run on a computer, something is definitely not working properly.</p><h2 id="active-for-months">Active for months</h2><p>Still, the malware installs itself as a Windows service that starts automatically at boot, and then loops continuously, checking for security products and killing them as soon as they’re activated. “The machine may remain fully under the attacker's control until the kernel driver is physically removed,” the researchers explained. “This process requires booting the computer into Safe Mode or using an external recovery tool, because normal Windows tools cannot safely remove software operating at that level while the system is running.”</p><p>LastPass and Delphos believe the campaign has been active for months, and that it will continue to operate despite disruption efforts: </p><p>“The LastPass lure was a single recent frame in a campaign that has been running for months and shows every sign of continuing after its current infrastructure is burned,” the researchers said. They stressed that this is “opportunistic brand impersonation” and that LastPass systems and customer vaults have not been compromised or involved in any way. </p><p>LastPass said it was one of 40 companies spoofed in this campaign and has urged users to only download apps from reputable, vetted sources. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-fake-lastpass-authenticator-app-will-just-shut-off-your-antivirus-and-leave-you-open-to-attack</link>
                                                                            <description>
                            <![CDATA[ Researchers found a never-before-seen malware targeting LastPass users and stealing their secrets. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XbTSXMVZEJiMvjWJeGZBhm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7Q34GM2RgrdwsWnK6jBAeP-1920-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 14:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/7Q34GM2RgrdwsWnK6jBAeP-1920-80.png">
                                                            <media:credit><![CDATA[LastPass]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[LastPass]]></media:description>                                                            <media:text><![CDATA[LastPass]]></media:text>
                                <media:title type="plain"><![CDATA[LastPass]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7Q34GM2RgrdwsWnK6jBAeP-1920-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Attackers spoofed LastPass Authenticator via SEO‑poisoned GitHub pages, delivering malicious ZIP files</strong></li><li><strong>Malware Rapuncel uses DLL sideloading, kills 145 AV products, and steals passwords, wallets, and tokens</strong></li><li><strong>Campaign ongoing for months; LastPass vaults unaffected, but users urged to download only from trusted sources</strong></li></ul><p>Be careful when downloading the LastPass Authenticator app - there are impostors out there that can disable your antivirus and wreak havoc on your computer. </p><p>LastPass recently <a href="https://blog.lastpass.com/posts/lastpass-delphos-report-rapuncel-infostealer" target="_blank">discovered</a> an elaborate scheme to get people infected with <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> - a spoofed website, SEO poisoning, DLL sideloading, and a malware loader delivering never-before-seen payload that can kill endpoint protection and antivirus solutions.</p><p>According to the <a href="https://www.techradar.com/best/password-manager" target="_blank">password manager</a>, users searching for "LastPass <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">Authenticator</a> download" or similar keywords will get a GitHub page rather high on the search engine results pages. At a glance, the page looks almost identical to the authentic LastPass offering - however, it redirects users to a separate one, hosted on attacker-controlled infrastructure and delivering a large .ZIP file with multiple files.</p><p>Among the files are two worth paying attention to: vsdbg.exe, and vsdbg.dll. The .EXE one is renamed to look like a LastPass installer, but it’s in fact a legitimate Microsoft debugging tool. This tool is used to run the malware - the vsdbg.dll file. This is a method called “dll sideloading” where the legitimate program will look for a DLL file in the same folder it’s located, rather than the wider device library. Since the DLL is delivered together with the executable, it is the first one to be run, despite the fact that it’s malicious. </p><h2 id="rapuncel">Rapuncel</h2><p>LastPass shared the malware with security researchers Delphos for analysis, and they’ve named it Rapuncel. No AV engines have been able to spot it, when it was first analyzed. </p><p>Once Rapuncel runs, it does a number of things. First, it gains admin-level access to run as SYSTEM, and then installs a kernel driver. The driver, disguised as an NVIDIA graphics component, comes with a hardcoded list of 145 antivirus and endpoint security products, and if any of them are found on the device, they are instantly terminated. </p><p>After killing antivirus solutions, the malware gets to work, stealing saved passwords from more than 25 browsers (Chrome, Edge, and other popular ones included), cryptocurrency wallet files from more than 30 wallet apps, Discord login tokens, Steam session tokens, Telegram session data, Windows credential store, all documents with words like “password”, “seed”, “wallet”, or “recovery” in their name, screenshots of every monitor connected to the device, as well as a detailed profile of the system.</p><p>Once all of this is harvested, the information is compressed into a .ZIP archive and uploaded to a server under the attackers’ control. To add insult to injury, the kernel driver was given code to intercept all web traffic, allowing the attackers to inject ads, or modify search results, at a whim. </p><p>Rapuncel comes with a persistence mechanism, as well, to make sure it continues operating even if the victim spots it. Spotting it should not be too difficult, though - if no antivirus programs are allowed to run on a computer, something is definitely not working properly.</p><h2 id="active-for-months">Active for months</h2><p>Still, the malware installs itself as a Windows service that starts automatically at boot, and then loops continuously, checking for security products and killing them as soon as they’re activated. “The machine may remain fully under the attacker's control until the kernel driver is physically removed,” the researchers explained. “This process requires booting the computer into Safe Mode or using an external recovery tool, because normal Windows tools cannot safely remove software operating at that level while the system is running.”</p><p>LastPass and Delphos believe the campaign has been active for months, and that it will continue to operate despite disruption efforts: </p><p>“The LastPass lure was a single recent frame in a campaign that has been running for months and shows every sign of continuing after its current infrastructure is burned,” the researchers said. They stressed that this is “opportunistic brand impersonation” and that LastPass systems and customer vaults have not been compromised or involved in any way. </p><p>LastPass said it was one of 40 companies spoofed in this campaign and has urged users to only download apps from reputable, vetted sources. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Meta Muse already has a majorly worrying zero-day security issue ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researcher Patrick Wardle finds zero‑day in Meta’s new Muse AI assistant, </strong></li><li><strong>Dubbed not‑a‑mused, the exploit requires local compromise, voice dictation, and app integrations; attackers can hijack tokens and exfiltrate data</strong></li><li><strong>Meta has been informed but no patch yet; flaw highlights risks of AI assistants with broad permissions</strong></li></ul><p>Meta’s new Artificial Intelligence (AI) <a href="https://www.techradar.com/pro/mark-zuckerbergs-muse-personal-ai-agent-is-a-work-accessory-designed-by-people-who-dont-do-real-work">assistant Muse</a> reportedly carried a zero-day vulnerability that allowed attackers to gain access to people’s apps, such as WhatsApp or email. </p><p>However, it’s not as straightforward as your usual zero-day - to exploit it, simply deploying malware will not suffice. Certain features need to be enabled, and certain integrations established before the bug could be leveraged.</p><h2 id="not-a-mused">Not-a-mused</h2><p>A little background, for context: Meta recently released Muse, describing it as an assistant that can “book appointments, fill out forms, and handle customer service.” It says the tool, available exclusively for the Mac ecosystem for now, “proactively takes tasks off your plate” and makes purchases, generates images, and creates documents. </p><p>To do that, however, it needs to connect to apps such as email, WhatsApp, calendar, or social media accounts - and this connection is the first prerequisite needed to exploit the flaw. </p><p>The second prerequisite is voice dictation. The vulnerability was found in the way Muse handles commands received via voice, meaning the attacker must piggyback onto voice commands in order to escalate privileges and access other apps and their content.</p><p>Now for the flaw itself. It was discovered by security researcher Patrick Wardle, founder of nonprofit Objective-See. He named it “not-a-mused” and says it hides in an undocumented setting called endo_voyager_dictation_endpoint. When a user narrates a voice command, that instruction is sent and processed in the cloud, where Meta can log it. This setting allows the user to change which endpoint receives the dictation.</p><p>Which brings us to the third prerequisite. The threat actor must have local access to be able to change this setting in the first place. In other words, the device must already be compromised in some way, either via remote monitoring and management tools, or via low-level malware (or with physical access). </p><p>For the sake of the report, let’s say that a theoretical user checks all the right boxes - they’re running a compromised machine and are talking to Muse that’s already connected to other productivity apps. Instead of reaching Meta’s endpoints, the voice commands are first sent to attacker-controlled infrastructure, where the AI assistant, together with the instructions, also sends authentication tokens for the tool. </p><p>If the attacker reacts fast enough, they can grab the token and access their target’s AI tool. If it’s connected to other apps, such as WhatsApp or calendar, they can simply prompt it to extract whatever sensitive information is found inside.</p><p>Not-a-mused is therefore a combination of data exfiltration and privilege escalation.</p><h2 id="ironing-out-the-kinks">Ironing out the kinks</h2><p>“We can manipulate the agent and leverage its privileges to do whatever we want,” Wardle told <a href="https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/" target="_blank"><em>Ars Technica</em></a>. </p><p>“So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself.” Wardle said he has developed several proof-of-concept attacks that do things like writing malicious files to disk and snapping pictures, in many cases with no indication to even an alert user.</p><p>Meta has been informed, but is yet to comment, or issue a patch.</p><p>AI assistants are all the rage nowadays. They’ve turned elaborate answer machines into tools that can complete assignments, even more complex ones. They can book flights and restaurant tables, make purchases, schedule and reschedule calls and meetings, and more. However, to do that, these tools need extensive permissions - something the security community is warning of. </p><p>While they’re not openly speaking against it, they are advising caution. There are many stories of AI agents either going rogue, or simply being tricked by malicious actors. For example, a hidden prompt in a phishing email can trick an AI agent tasked with summarizing the message into exfiltrating all .PDF documents from the victim’s inbox. </p><p>In the early days of agentic AI, there were reports of assistants simply deleting people’s inboxes. </p><p>Assistants are likely here to stay, but there are still quite a few kinks to iron before they can hit the mainstream. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/meta-muse-already-has-a-majorly-worrying-zero-day-security-issue</link>
                                                                            <description>
                            <![CDATA[ Crooks can reportedly take over Meta sessions and use them to exfiltrate data. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sjPfUjdCnYhXNa8RF33kf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/n2dFzA7TpfgKDWytxEnzX4-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/n2dFzA7TpfgKDWytxEnzX4-1920-80.jpg">
                                                            <media:credit><![CDATA[Meta]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Meta Muse AI agent]]></media:description>                                                            <media:text><![CDATA[Meta Muse AI agent]]></media:text>
                                <media:title type="plain"><![CDATA[Meta Muse AI agent]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/n2dFzA7TpfgKDWytxEnzX4-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researcher Patrick Wardle finds zero‑day in Meta’s new Muse AI assistant, </strong></li><li><strong>Dubbed not‑a‑mused, the exploit requires local compromise, voice dictation, and app integrations; attackers can hijack tokens and exfiltrate data</strong></li><li><strong>Meta has been informed but no patch yet; flaw highlights risks of AI assistants with broad permissions</strong></li></ul><p>Meta’s new Artificial Intelligence (AI) <a href="https://www.techradar.com/pro/mark-zuckerbergs-muse-personal-ai-agent-is-a-work-accessory-designed-by-people-who-dont-do-real-work">assistant Muse</a> reportedly carried a zero-day vulnerability that allowed attackers to gain access to people’s apps, such as WhatsApp or email. </p><p>However, it’s not as straightforward as your usual zero-day - to exploit it, simply deploying malware will not suffice. Certain features need to be enabled, and certain integrations established before the bug could be leveraged.</p><h2 id="not-a-mused">Not-a-mused</h2><p>A little background, for context: Meta recently released Muse, describing it as an assistant that can “book appointments, fill out forms, and handle customer service.” It says the tool, available exclusively for the Mac ecosystem for now, “proactively takes tasks off your plate” and makes purchases, generates images, and creates documents. </p><p>To do that, however, it needs to connect to apps such as email, WhatsApp, calendar, or social media accounts - and this connection is the first prerequisite needed to exploit the flaw. </p><p>The second prerequisite is voice dictation. The vulnerability was found in the way Muse handles commands received via voice, meaning the attacker must piggyback onto voice commands in order to escalate privileges and access other apps and their content.</p><p>Now for the flaw itself. It was discovered by security researcher Patrick Wardle, founder of nonprofit Objective-See. He named it “not-a-mused” and says it hides in an undocumented setting called endo_voyager_dictation_endpoint. When a user narrates a voice command, that instruction is sent and processed in the cloud, where Meta can log it. This setting allows the user to change which endpoint receives the dictation.</p><p>Which brings us to the third prerequisite. The threat actor must have local access to be able to change this setting in the first place. In other words, the device must already be compromised in some way, either via remote monitoring and management tools, or via low-level malware (or with physical access). </p><p>For the sake of the report, let’s say that a theoretical user checks all the right boxes - they’re running a compromised machine and are talking to Muse that’s already connected to other productivity apps. Instead of reaching Meta’s endpoints, the voice commands are first sent to attacker-controlled infrastructure, where the AI assistant, together with the instructions, also sends authentication tokens for the tool. </p><p>If the attacker reacts fast enough, they can grab the token and access their target’s AI tool. If it’s connected to other apps, such as WhatsApp or calendar, they can simply prompt it to extract whatever sensitive information is found inside.</p><p>Not-a-mused is therefore a combination of data exfiltration and privilege escalation.</p><h2 id="ironing-out-the-kinks">Ironing out the kinks</h2><p>“We can manipulate the agent and leverage its privileges to do whatever we want,” Wardle told <a href="https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/" target="_blank"><em>Ars Technica</em></a>. </p><p>“So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself.” Wardle said he has developed several proof-of-concept attacks that do things like writing malicious files to disk and snapping pictures, in many cases with no indication to even an alert user.</p><p>Meta has been informed, but is yet to comment, or issue a patch.</p><p>AI assistants are all the rage nowadays. They’ve turned elaborate answer machines into tools that can complete assignments, even more complex ones. They can book flights and restaurant tables, make purchases, schedule and reschedule calls and meetings, and more. However, to do that, these tools need extensive permissions - something the security community is warning of. </p><p>While they’re not openly speaking against it, they are advising caution. There are many stories of AI agents either going rogue, or simply being tricked by malicious actors. For example, a hidden prompt in a phishing email can trick an AI agent tasked with summarizing the message into exfiltrating all .PDF documents from the victim’s inbox. </p><p>In the early days of agentic AI, there were reports of assistants simply deleting people’s inboxes. </p><p>Assistants are likely here to stay, but there are still quite a few kinks to iron before they can hit the mainstream. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ BigCommerce warns customers of potential data leaks following cyber incident ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>BigCommerce confirms supply‑chain breach via compromised Ribon app credentials affecting merchant storefronts</strong></li><li><strong>Master of Malt notified customers: names, emails, phone numbers, and addresses were exposed</strong></li><li><strong>Attack ran Sept 13–17 2026; ICO notified, law firm warns of phishing risks for affected retailers</strong></li></ul><p>Ecommerce platform BigCommerce was recently hit with a cyberattack in which it lost sensitive data belonging to some of its users.</p><p>One of the users - online spirits retailer Master of Malt - confirmed the hit and notified its customers that their personally identifiable information (PII) was accessed in the attack.</p><p>BigCommerce is an <a href="https://www.techradar.com/news/the-best-ecommerce-platform" target="_blank">ecommerce platform</a> relatively similar to Shopify. Businesses use it to build and operate online stores without needing to develop the entire commerce infrastructure themselves. It offers features like storefronts, shopping carts, integrations with different payment providers, product inventories, SEO and marketing tools, and more.</p><p>The platform has been around since 2009 and according to a <a href="https://www.sec.gov/Archives/edgar/data/1626450/000095017025029211/bigc-20241231.htm?utm_source=chatgpt.com" target="_blank" rel="nofollow">late 2024 SEC filing</a>, serves 5,884 accounts with at least one unique enterprise plan subscription. A <a href="https://www.bigcommerce.com/press/releases/klarna-partnership-press-release/?utm_source=chatgpt.com" target="_blank" rel="nofollow">2025 press release</a> says BigCommerce is used by “tens of thousands of B2C and B2B companies across 150 countries.”</p><h2 id="software-supply-chain-attack">Software supply chain attack</h2><p>BigCommerce allows its users to install, among others, a third-party app called Ribon, an ecommerce app providing tools that improve the online shopping experience. Some merchants integrate Ribon into their stores to add different functionality to the customer-facing storefront, and to optimize how visitors interact with different elements of their website. We don’t know exactly how many stores use Ribon.</p><p>According to Master of Malt, unidentified threat actors managed to compromise a BigCommerce Application key held by Ribon, and used it to access customer data that was held on their system. The attack took place on Sunday, September 13 2026, until the access was finally revoked four days later, on September 17. </p><p>Speaking to<em> </em><a href="https://www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/" target="_blank"><em>BleepingComputer</em></a>, BigCommerce said credentials for Ribon and Ribon 1.5 were compromised: </p><p>"On September 17, 2026, Commerce confirmed that credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by 'Be A Part Of,' a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts,” the statement reads. "Acting in the best interest of our customers and their shoppers, we uninstalled the application from affected stores to revoke the attacker's access, notified those merchants directly, and are providing log data to support the developer's investigation," the company told the publication.</p><p>The keyword in this statement is “small number of merchant storefronts.” BigCommerce hints that the attack was relatively small in scope and, consequently, in damage. However, in its report Master of Malt says otherwise: </p><p>“It’s now clear that we weren’t the target of the attack. The attack was against Ribon, which was installed on hundreds of BigCommerce stores. Once the attackers compromised an access key from Ribon, they used it to access data held inside BigCommerce.”</p><h2 id="names-and-emails">Names and emails</h2><p>Whether or not this transforms into a new Snowflake fiasco remains to be seen.</p><p>In the meantime, Master of Malt also said BigCommerce notified it that the attack had been stopped and that there was no further risk of compromise. All companies affected by the breach were contacted. As for the spirits retailer, here is what it said about the data exposed in the hit:</p><p>“I’m sorry to say that the attackers had access to your name, email address, phone number, and address. However, they were not able to access your password, credit card or other payment information as they are held in a separate system which was never compromised.”</p><p>Master of Malt reported the attack to the UK Information Commissioner’s Office (ICO). Law firm Emery Reddy is calling for potential claimants to the incidents, saying that “several retailers” are currently notifying customers about data exposure related to the incident, <em>BleepingComputer</em> reported. </p><p>“A number of online retailers that use the BigCommerce e-commerce platform have begun notifying customers of a data breach that originated not with the retailers themselves, but with a third-party application called Ribon,” the law firm says. Emery Reddy also warned of potential phishing and scam attacks.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/bigcommerce-warns-customers-of-potential-data-leaks-following-cyber-incident</link>
                                                                            <description>
                            <![CDATA[ Hackers broke into a third-party app and stole customer data, including personally identifiable information. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qWoYNBkY75USdGrfuKDHMA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 12:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hacker hands at work with  interface around]]></media:description>                                                            <media:text><![CDATA[hacker hands at work with  interface around]]></media:text>
                                <media:title type="plain"><![CDATA[hacker hands at work with  interface around]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>BigCommerce confirms supply‑chain breach via compromised Ribon app credentials affecting merchant storefronts</strong></li><li><strong>Master of Malt notified customers: names, emails, phone numbers, and addresses were exposed</strong></li><li><strong>Attack ran Sept 13–17 2026; ICO notified, law firm warns of phishing risks for affected retailers</strong></li></ul><p>Ecommerce platform BigCommerce was recently hit with a cyberattack in which it lost sensitive data belonging to some of its users.</p><p>One of the users - online spirits retailer Master of Malt - confirmed the hit and notified its customers that their personally identifiable information (PII) was accessed in the attack.</p><p>BigCommerce is an <a href="https://www.techradar.com/news/the-best-ecommerce-platform" target="_blank">ecommerce platform</a> relatively similar to Shopify. Businesses use it to build and operate online stores without needing to develop the entire commerce infrastructure themselves. It offers features like storefronts, shopping carts, integrations with different payment providers, product inventories, SEO and marketing tools, and more.</p><p>The platform has been around since 2009 and according to a <a href="https://www.sec.gov/Archives/edgar/data/1626450/000095017025029211/bigc-20241231.htm?utm_source=chatgpt.com" target="_blank" rel="nofollow">late 2024 SEC filing</a>, serves 5,884 accounts with at least one unique enterprise plan subscription. A <a href="https://www.bigcommerce.com/press/releases/klarna-partnership-press-release/?utm_source=chatgpt.com" target="_blank" rel="nofollow">2025 press release</a> says BigCommerce is used by “tens of thousands of B2C and B2B companies across 150 countries.”</p><h2 id="software-supply-chain-attack">Software supply chain attack</h2><p>BigCommerce allows its users to install, among others, a third-party app called Ribon, an ecommerce app providing tools that improve the online shopping experience. Some merchants integrate Ribon into their stores to add different functionality to the customer-facing storefront, and to optimize how visitors interact with different elements of their website. We don’t know exactly how many stores use Ribon.</p><p>According to Master of Malt, unidentified threat actors managed to compromise a BigCommerce Application key held by Ribon, and used it to access customer data that was held on their system. The attack took place on Sunday, September 13 2026, until the access was finally revoked four days later, on September 17. </p><p>Speaking to<em> </em><a href="https://www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/" target="_blank"><em>BleepingComputer</em></a>, BigCommerce said credentials for Ribon and Ribon 1.5 were compromised: </p><p>"On September 17, 2026, Commerce confirmed that credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by 'Be A Part Of,' a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts,” the statement reads. "Acting in the best interest of our customers and their shoppers, we uninstalled the application from affected stores to revoke the attacker's access, notified those merchants directly, and are providing log data to support the developer's investigation," the company told the publication.</p><p>The keyword in this statement is “small number of merchant storefronts.” BigCommerce hints that the attack was relatively small in scope and, consequently, in damage. However, in its report Master of Malt says otherwise: </p><p>“It’s now clear that we weren’t the target of the attack. The attack was against Ribon, which was installed on hundreds of BigCommerce stores. Once the attackers compromised an access key from Ribon, they used it to access data held inside BigCommerce.”</p><h2 id="names-and-emails">Names and emails</h2><p>Whether or not this transforms into a new Snowflake fiasco remains to be seen.</p><p>In the meantime, Master of Malt also said BigCommerce notified it that the attack had been stopped and that there was no further risk of compromise. All companies affected by the breach were contacted. As for the spirits retailer, here is what it said about the data exposed in the hit:</p><p>“I’m sorry to say that the attackers had access to your name, email address, phone number, and address. However, they were not able to access your password, credit card or other payment information as they are held in a separate system which was never compromised.”</p><p>Master of Malt reported the attack to the UK Information Commissioner’s Office (ICO). Law firm Emery Reddy is calling for potential claimants to the incidents, saying that “several retailers” are currently notifying customers about data exposure related to the incident, <em>BleepingComputer</em> reported. </p><p>“A number of online retailers that use the BigCommerce e-commerce platform have begun notifying customers of a data breach that originated not with the retailers themselves, but with a third-party application called Ribon,” the law firm says. Emery Reddy also warned of potential phishing and scam attacks.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Getting ahead: 5 ways to break stress before it breaks you ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Technology is constantly evolving, and with that comes increasing pressure on those working in the sector. It's no surprise, then, that technology ranks among the industries with the highest levels of work-related stress, contributing to around 550,000 working days lost over three years according to the Health and Safety Executive in 2024.</p><p>Stress rarely appears overnight. It builds over time through heavy workloads, unclear expectations, limited support and constantly shifting priorities. Too often, leaders only recognize the problem once an <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employee</a> has reached burnout.</p><p>Managing stress shouldn't be seen solely as an individual's responsibility. Leaders play a vital role in creating environments where people feel supported, can raise concerns early and have the tools they need to manage pressure before it becomes overwhelming.</p><p>By recognizing the warning signs and making a few practical changes, leaders can help prevent stress from escalating into burnout.</p><h2 id="1-understand-how-and-why-individuals-respond-differently">1. Understand how and why individuals respond differently</h2><p>Two employees can face exactly the same challenge but respond in completely different ways. One useful way of understanding these differences is through Kirton's Adaption-Innovation (KAI) Theory. Developed by psychologist Dr Michael Kirton, the theory suggests people naturally approach change and problem-solving in different ways.</p><p>More adaptive individuals tend to prefer structure, established processes and incremental improvements, while more innovative individuals are often more comfortable with ambiguity, risk taking and finding entirely new solutions. Most people fall somewhere between the two.</p><p>Neither style is better than the other, but each can bring different sources of stress. More adaptive employees may struggle with unclear roles, changing priorities or a lack of structure, while more innovative employees can become frustrated by rigid processes or repetitive work.</p><p>Understanding how individuals prefer to work allows leaders to allocate work more effectively, helping employees perform at their best while reducing unnecessary pressure.</p><h2 id="2-create-a-culture-of-asking-questions">2. Create a culture of asking questions</h2><p>Many employees struggle to admit when they need help. We are often taught this is a sign of weakness and an indicator of capability.</p><p>Creating a culture of trust changes that. When people feel comfortable raising concerns, asking questions or admitting they are struggling, problems can be addressed before they become unmanageable.</p><p>Leaders set the tone. Asking for <a href="https://www.techradar.com/best/best-customer-feedback-tools?gad=1">feedback</a>, acknowledging your own mistakes and responding positively when employees raise concerns all help create psychological safety within a team. An open culture also makes it much easier to recognize when someone is beginning to struggle.</p><p>Changes such as withdrawing from colleagues, becoming more irritable, missing deadlines or struggling to prioritize work are often viewed as performance issues, when they may actually be signs of mounting stress.  </p><p>Regular conversations, rather than relying solely on formal performance reviews, give leaders the opportunity to identify these warning signs early. Simple adjustments, such as redistributing workloads, clarifying priorities or removing unnecessary obstacles, can prevent stress from developing into burnout.</p><h2 id="3-observe-your-team-to-identify-stress-early">3.Observe your team to identify stress early</h2><p>Stress rarely appears suddenly. It can build gradually, making it difficult to recognize until it begins to affect an employee's wellbeing or performance.</p><p>While you may be aware that a particular task or deadline is likely to create pressure, it can be harder to spot when longer-term stress is beginning to affect your team. Changes in behaviour can be early warning signs. An employee may start to withdraw from colleagues, become more irritable or defensive, miss deadlines or struggle to prioritize their workload.</p><p>As leaders, we can be quick to interpret these changes as performance issues. However, they may be indicators that someone is experiencing stress and needs additional support.</p><p>Regular check-ins, rather than relying solely on formal performance reviews, give leaders an opportunity to understand what's happening and address problems early. By noticing these changes, leaders can redistribute workloads, adjust expectations or remove obstacles before stress develops into burnout.</p><h2 id="4-give-your-employees-control">4. Give your employees control</h2><p>Many <a href="https://www.techradar.com/pro/best-employee-experience-tools">employees experience</a> stress because they feel they have little control over their work. Those in the technology sector often face tight deadlines, changing priorities, and high expectations. While we cannot remove all these pressures, we can provide autonomy to employees to help them be more successful.</p><p>Greater autonomy doesn't mean removing direction altogether. Leaders still need to set realistic expectations and help teams distinguish between what's genuinely urgent and what can wait. As a leader, you need to help your employees set realistic goals. You can help employees recognize what is urgent and prioritize their tasks effectively.  </p><p>Employees who provide input and contribute in this way feel more in control and experience a higher level of buy in to team goals.</p><h2 id="5-create-a-culture-that-prioritizes-recovery">5. Create a culture that prioritizes recovery</h2><p>We often mistake short-term performance for sustainable outcomes. However, we require time to recover not just as a reward, but as consistent practice. Employees need to be encouraged to take time to recuperate.</p><p>As a leader, the tone you set is seen and mimicked. If you’re not taking regular breaks, working at all hours of the night, and pushing through exhaustion, your employees will feel they need to do the same. Consider your own habits and then promote celebrating breaks, disconnection outside of working hours, using leave time, and establishing work-life balance.</p><p>It is easy to say, “do as I say not as I do.” However, this culture starts with you. Taking time to recover yourself helps you avoid burnout and be a better leader overall. It will also lead to long-term sustained performance over short bursts of success.</p><p>Stress will always be a part of the workplace. The goal is not to remove stress, but to prevent burnout and sustain performance.</p><p>As a leader, the ability to help your employees reduce stress is a shared responsibility between the individual, yourself, and your team. By understanding how individuals solve problems, creating an environment of trust, observing stress early on, increasing employee autonomy, and promoting recovery time, your organization can retain talent and build a healthier and more productive workforce.</p><p><em></em><a href="https://www.techradar.com/best/best-hr-software"><em>We've featured the best HR software.</em></a><em> </em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/getting-ahead-5-ways-to-break-stress-before-it-breaks-you</link>
                                                                            <description>
                            <![CDATA[ Stress can quickly become burnout. Here’s how leaders can spot the warning signs and act early. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bnERpwAge7gUG4DLbrgqxe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nKQTr6znQKVirervbiEDkL-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 10:53:20 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dr Sarah Bush ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nKQTr6znQKVirervbiEDkL-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An office worker in front of a computer holding his hand in one hand and looking unhappy]]></media:description>                                                            <media:text><![CDATA[An office worker in front of a computer holding his hand in one hand and looking unhappy]]></media:text>
                                <media:title type="plain"><![CDATA[An office worker in front of a computer holding his hand in one hand and looking unhappy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nKQTr6znQKVirervbiEDkL-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Technology is constantly evolving, and with that comes increasing pressure on those working in the sector. It's no surprise, then, that technology ranks among the industries with the highest levels of work-related stress, contributing to around 550,000 working days lost over three years according to the Health and Safety Executive in 2024.</p><p>Stress rarely appears overnight. It builds over time through heavy workloads, unclear expectations, limited support and constantly shifting priorities. Too often, leaders only recognize the problem once an <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employee</a> has reached burnout.</p><p>Managing stress shouldn't be seen solely as an individual's responsibility. Leaders play a vital role in creating environments where people feel supported, can raise concerns early and have the tools they need to manage pressure before it becomes overwhelming.</p><p>By recognizing the warning signs and making a few practical changes, leaders can help prevent stress from escalating into burnout.</p><h2 id="1-understand-how-and-why-individuals-respond-differently">1. Understand how and why individuals respond differently</h2><p>Two employees can face exactly the same challenge but respond in completely different ways. One useful way of understanding these differences is through Kirton's Adaption-Innovation (KAI) Theory. Developed by psychologist Dr Michael Kirton, the theory suggests people naturally approach change and problem-solving in different ways.</p><p>More adaptive individuals tend to prefer structure, established processes and incremental improvements, while more innovative individuals are often more comfortable with ambiguity, risk taking and finding entirely new solutions. Most people fall somewhere between the two.</p><p>Neither style is better than the other, but each can bring different sources of stress. More adaptive employees may struggle with unclear roles, changing priorities or a lack of structure, while more innovative employees can become frustrated by rigid processes or repetitive work.</p><p>Understanding how individuals prefer to work allows leaders to allocate work more effectively, helping employees perform at their best while reducing unnecessary pressure.</p><h2 id="2-create-a-culture-of-asking-questions">2. Create a culture of asking questions</h2><p>Many employees struggle to admit when they need help. We are often taught this is a sign of weakness and an indicator of capability.</p><p>Creating a culture of trust changes that. When people feel comfortable raising concerns, asking questions or admitting they are struggling, problems can be addressed before they become unmanageable.</p><p>Leaders set the tone. Asking for <a href="https://www.techradar.com/best/best-customer-feedback-tools?gad=1">feedback</a>, acknowledging your own mistakes and responding positively when employees raise concerns all help create psychological safety within a team. An open culture also makes it much easier to recognize when someone is beginning to struggle.</p><p>Changes such as withdrawing from colleagues, becoming more irritable, missing deadlines or struggling to prioritize work are often viewed as performance issues, when they may actually be signs of mounting stress.  </p><p>Regular conversations, rather than relying solely on formal performance reviews, give leaders the opportunity to identify these warning signs early. Simple adjustments, such as redistributing workloads, clarifying priorities or removing unnecessary obstacles, can prevent stress from developing into burnout.</p><h2 id="3-observe-your-team-to-identify-stress-early">3.Observe your team to identify stress early</h2><p>Stress rarely appears suddenly. It can build gradually, making it difficult to recognize until it begins to affect an employee's wellbeing or performance.</p><p>While you may be aware that a particular task or deadline is likely to create pressure, it can be harder to spot when longer-term stress is beginning to affect your team. Changes in behaviour can be early warning signs. An employee may start to withdraw from colleagues, become more irritable or defensive, miss deadlines or struggle to prioritize their workload.</p><p>As leaders, we can be quick to interpret these changes as performance issues. However, they may be indicators that someone is experiencing stress and needs additional support.</p><p>Regular check-ins, rather than relying solely on formal performance reviews, give leaders an opportunity to understand what's happening and address problems early. By noticing these changes, leaders can redistribute workloads, adjust expectations or remove obstacles before stress develops into burnout.</p><h2 id="4-give-your-employees-control">4. Give your employees control</h2><p>Many <a href="https://www.techradar.com/pro/best-employee-experience-tools">employees experience</a> stress because they feel they have little control over their work. Those in the technology sector often face tight deadlines, changing priorities, and high expectations. While we cannot remove all these pressures, we can provide autonomy to employees to help them be more successful.</p><p>Greater autonomy doesn't mean removing direction altogether. Leaders still need to set realistic expectations and help teams distinguish between what's genuinely urgent and what can wait. As a leader, you need to help your employees set realistic goals. You can help employees recognize what is urgent and prioritize their tasks effectively.  </p><p>Employees who provide input and contribute in this way feel more in control and experience a higher level of buy in to team goals.</p><h2 id="5-create-a-culture-that-prioritizes-recovery">5. Create a culture that prioritizes recovery</h2><p>We often mistake short-term performance for sustainable outcomes. However, we require time to recover not just as a reward, but as consistent practice. Employees need to be encouraged to take time to recuperate.</p><p>As a leader, the tone you set is seen and mimicked. If you’re not taking regular breaks, working at all hours of the night, and pushing through exhaustion, your employees will feel they need to do the same. Consider your own habits and then promote celebrating breaks, disconnection outside of working hours, using leave time, and establishing work-life balance.</p><p>It is easy to say, “do as I say not as I do.” However, this culture starts with you. Taking time to recover yourself helps you avoid burnout and be a better leader overall. It will also lead to long-term sustained performance over short bursts of success.</p><p>Stress will always be a part of the workplace. The goal is not to remove stress, but to prevent burnout and sustain performance.</p><p>As a leader, the ability to help your employees reduce stress is a shared responsibility between the individual, yourself, and your team. By understanding how individuals solve problems, creating an environment of trust, observing stress early on, increasing employee autonomy, and promoting recovery time, your organization can retain talent and build a healthier and more productive workforce.</p><p><em></em><a href="https://www.techradar.com/best/best-hr-software"><em>We've featured the best HR software.</em></a><em> </em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The AI advice gap: what happens when the machine says "yes"? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Ask a UK bank for investment advice, and you get a lawful recommendation. If it was negligent, you will have the right to make a claim using the Financial Services Compensation Scheme.</p><p>Ask ChatGPT, or, more fashionable, Claude, the same question and you get nothing. Just an answer, but it will be delivered with a more confident tone, no matter whether it's right or absolutely wrong.</p><p>Despite that, more than a quarter of UK consumers now say they trust <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">AI chatbots</a> for money advice. The Financial Conduct Authority found this figure and flagged it as a live concern in its most recent review. </p><p>Other surveys found even higher figures. STRAT7 found 55% of UK adults have used AI for financial guidance, Sky News reported 40%, and EY's global study measured Gen Z adoption at 68%. Whatever the precise number is, the direction is the same.</p><p>People have started to trust AI more and more in their <a href="https://www.techradar.com/best/best-personal-finance-software">financial</a> decisions. But the debate about it has, so far, been asking the wrong question.</p><h2 id="what-is-the-wrong-question">What is the wrong question?</h2><p>Most publications today focus on accuracy, and what everyone wants to know is whether the AI's advice is good. But is it?</p><p>In one study, there were five real financial scenarios passed to major chatbots, and the output was compared to certified financial planners. The result was unsurprising, though. The bots reliably missed emotional and situational context, so personal decisions turned to rough spreadsheet logic that missed important input.</p><p>Sky News has conducted a similar test, where three chatbots were given £16,000 in real savings. What they found was that the recommendations were US-biased and incomplete. </p><p>Most alarming, it was an investigation which found Claude incorrectly described Binance as FCA-registered when advising a beginner on cryptocurrency. Binance was, in fact, ordered to cease UK-regulated activity back in 2021.</p><p>AI’s misleading outputs sound disturbing, but what is even worse is that it is only one part of the problem. Things get harder after the incorrect advice has already been given, acted on, and gone wrong.</p><p>So, when it happens, who takes the blame? Nobody is the answer, although it’s quite uncomfortable to hear. </p><p>The FCA has noted the same. In its 2026 report, the regulator confirmed that <a href="https://www.techradar.com/computing/artificial-intelligence/best-large-language-models-llms-for-coding">LLM</a> platforms such as ChatGPT and Claude sit entirely outside its regulatory remit. This means that consumers using them for financial guidance are not receiving regulated advice. Therefore, they have no access to the Financial Ombudsman Service (or the Financial Services Compensation Scheme) if things go wrong.</p><p>That said, the safety net simply does not apply the moment consumers paste a question into a chatbot.</p><h2 id="the-regulatory-gap-explained">The regulatory gap explained</h2><p>To understand why this gap exists, let’s understand how UK financial regulation actually works. The regulatory perimeter is activity-based, not technology-based. This means what matters most is what is being done, not how.</p><p>A firm that provides personalized recommendations on the purchase, sale, or holding of certain assets is engaged in regulated activity, regardless of whether those recommendations are provided by a person or an algorithm.</p><p>The problem is that AI chatbots occupy a new space. They are not marketed as financial advisers, so they don't claim to be regulated. And technically, in most cases, they are not offering advice in the strict legal sense — they are responding to open questions.</p><p>Again, this ambiguity was addressed in the FCA report. The Mills Review highlights that AI platforms may influence consumers’ financial decisions without clearly implementing regulated actions. As a consequence, this creates a serious blank space between the actual financial impact and the protection provided by regulatory authorities.</p><p>The review's main recommendation was for the FCA to officially revise the scope for receiving financial recommendations developed using <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a>. So, this process is ongoing, and further updates will be available only after a few months, or even more.</p><h2 id="the-consumer-protection-problem-and-what-fintech-can-do">The consumer protection problem and what fintech can do</h2><p>While there is no law so far protecting ordinary people, what should we do? Can fintechs close this gap, at least for now?</p><p>First of all, waiting for the FCA perimeter check to be completed is not a strategy. It’s better to start by separating information from personalization, especially if your company has an AI assistant.</p><p>The thing is that the boundaries of recommendations depend on whether the conclusion is adapted to the specific circumstances of a particular person. The tool that generally explains what an ETF is is in a completely different regulatory status than the one that says how much you should invest in funds.</p><p>Also, make sure the disclaimer does real work. The footer text “not financial advice,” located below a specific recommendation, will not pass regulatory checks. The FCA evaluates content, not form. If the output <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> looks like a personalized recommendation, the tiny disclaimers will not reclassify it.</p><p>Although many people use AI today, do not overuse it to earn trust. An analysis of more than 330 million reviews showed that mentions of interaction with AI are rated, on average, at just 1.7 points, compared to 3.7 points for reviews that do not mention AI. </p><h2 id="final-words">Final words</h2><p>Surely, there will be some people who continue to use AI directly for financial advice, and their number will grow. For them, I can say only one thing: be careful about who you trust with your earnings. If no one is accountable, maybe not treating it as a rulebook will save you from losses.</p><p>But fintechs should start building the accountable version of their <a href="https://www.techradar.com/news/best-business-desktop-pcs">business</a>, with an audit trail and a human above the AI layer. So when the machine says "yes," someone is actually standing behind that answer.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-website-builder"><em>We've featured the best AI website builder.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/the-ai-advice-gap-what-happens-when-the-machine-says-yes</link>
                                                                            <description>
                            <![CDATA[ AI financial guidance is surging, yet no regulator stands behind a single wrong answer. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pjkbqXZgLNwr6Zr3eQbxSj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4DKiUF32YY5BX96h6fscGL-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 10:07:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Eugenia Mykuliak ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4DKiUF32YY5BX96h6fscGL-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Robots in a data center]]></media:description>                                                            <media:text><![CDATA[Robots in a data center]]></media:text>
                                <media:title type="plain"><![CDATA[Robots in a data center]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4DKiUF32YY5BX96h6fscGL-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Ask a UK bank for investment advice, and you get a lawful recommendation. If it was negligent, you will have the right to make a claim using the Financial Services Compensation Scheme.</p><p>Ask ChatGPT, or, more fashionable, Claude, the same question and you get nothing. Just an answer, but it will be delivered with a more confident tone, no matter whether it's right or absolutely wrong.</p><p>Despite that, more than a quarter of UK consumers now say they trust <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">AI chatbots</a> for money advice. The Financial Conduct Authority found this figure and flagged it as a live concern in its most recent review. </p><p>Other surveys found even higher figures. STRAT7 found 55% of UK adults have used AI for financial guidance, Sky News reported 40%, and EY's global study measured Gen Z adoption at 68%. Whatever the precise number is, the direction is the same.</p><p>People have started to trust AI more and more in their <a href="https://www.techradar.com/best/best-personal-finance-software">financial</a> decisions. But the debate about it has, so far, been asking the wrong question.</p><h2 id="what-is-the-wrong-question">What is the wrong question?</h2><p>Most publications today focus on accuracy, and what everyone wants to know is whether the AI's advice is good. But is it?</p><p>In one study, there were five real financial scenarios passed to major chatbots, and the output was compared to certified financial planners. The result was unsurprising, though. The bots reliably missed emotional and situational context, so personal decisions turned to rough spreadsheet logic that missed important input.</p><p>Sky News has conducted a similar test, where three chatbots were given £16,000 in real savings. What they found was that the recommendations were US-biased and incomplete. </p><p>Most alarming, it was an investigation which found Claude incorrectly described Binance as FCA-registered when advising a beginner on cryptocurrency. Binance was, in fact, ordered to cease UK-regulated activity back in 2021.</p><p>AI’s misleading outputs sound disturbing, but what is even worse is that it is only one part of the problem. Things get harder after the incorrect advice has already been given, acted on, and gone wrong.</p><p>So, when it happens, who takes the blame? Nobody is the answer, although it’s quite uncomfortable to hear. </p><p>The FCA has noted the same. In its 2026 report, the regulator confirmed that <a href="https://www.techradar.com/computing/artificial-intelligence/best-large-language-models-llms-for-coding">LLM</a> platforms such as ChatGPT and Claude sit entirely outside its regulatory remit. This means that consumers using them for financial guidance are not receiving regulated advice. Therefore, they have no access to the Financial Ombudsman Service (or the Financial Services Compensation Scheme) if things go wrong.</p><p>That said, the safety net simply does not apply the moment consumers paste a question into a chatbot.</p><h2 id="the-regulatory-gap-explained">The regulatory gap explained</h2><p>To understand why this gap exists, let’s understand how UK financial regulation actually works. The regulatory perimeter is activity-based, not technology-based. This means what matters most is what is being done, not how.</p><p>A firm that provides personalized recommendations on the purchase, sale, or holding of certain assets is engaged in regulated activity, regardless of whether those recommendations are provided by a person or an algorithm.</p><p>The problem is that AI chatbots occupy a new space. They are not marketed as financial advisers, so they don't claim to be regulated. And technically, in most cases, they are not offering advice in the strict legal sense — they are responding to open questions.</p><p>Again, this ambiguity was addressed in the FCA report. The Mills Review highlights that AI platforms may influence consumers’ financial decisions without clearly implementing regulated actions. As a consequence, this creates a serious blank space between the actual financial impact and the protection provided by regulatory authorities.</p><p>The review's main recommendation was for the FCA to officially revise the scope for receiving financial recommendations developed using <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a>. So, this process is ongoing, and further updates will be available only after a few months, or even more.</p><h2 id="the-consumer-protection-problem-and-what-fintech-can-do">The consumer protection problem and what fintech can do</h2><p>While there is no law so far protecting ordinary people, what should we do? Can fintechs close this gap, at least for now?</p><p>First of all, waiting for the FCA perimeter check to be completed is not a strategy. It’s better to start by separating information from personalization, especially if your company has an AI assistant.</p><p>The thing is that the boundaries of recommendations depend on whether the conclusion is adapted to the specific circumstances of a particular person. The tool that generally explains what an ETF is is in a completely different regulatory status than the one that says how much you should invest in funds.</p><p>Also, make sure the disclaimer does real work. The footer text “not financial advice,” located below a specific recommendation, will not pass regulatory checks. The FCA evaluates content, not form. If the output <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> looks like a personalized recommendation, the tiny disclaimers will not reclassify it.</p><p>Although many people use AI today, do not overuse it to earn trust. An analysis of more than 330 million reviews showed that mentions of interaction with AI are rated, on average, at just 1.7 points, compared to 3.7 points for reviews that do not mention AI. </p><h2 id="final-words">Final words</h2><p>Surely, there will be some people who continue to use AI directly for financial advice, and their number will grow. For them, I can say only one thing: be careful about who you trust with your earnings. If no one is accountable, maybe not treating it as a rulebook will save you from losses.</p><p>But fintechs should start building the accountable version of their <a href="https://www.techradar.com/news/best-business-desktop-pcs">business</a>, with an audit trail and a human above the AI layer. So when the machine says "yes," someone is actually standing behind that answer.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-website-builder"><em>We've featured the best AI website builder.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google’s PQC roadmap puts traditional digital certificates under pressure ]]></title>
                                                                                                <dc:content><![CDATA[ <p>In March, Google moved its own post-quantum cryptography (PQC) <a href="https://www.techradar.com/best/best-data-migration-tools">migration</a> deadline forward to 2029, a full six years ahead of NIST's guidance, and two ahead of the NSA's requirement for national security systems. It was a terrific bit of security signaling, but now it is backed up by a new product-by-product roadmap organized around three risk domains, with milestones attached to named services.</p><p>For anyone whose job touches digital trust, the most significant of those three domains is Google’s attempt at enhancing foundational capabilities for cryptographic agility: building flexible systems that can adopt new cryptographic standards with minimal engineering effort as those standards evolve.</p><p>The message is that organizations should prepare for a future in which standards, certificate formats, and operational requirements continue to evolve, and evolve regularly, requiring cryptographic agility.</p><h2 id="why-quantum-risk-is-already-a-digital-trust-problem">Why quantum risk is already a digital trust problem</h2><p>Adversaries are already harvesting and storing encrypted <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> today on the assumption that a future quantum computer will decrypt it (harvest now, decrypt later). Anything with a long confidentiality tail, from health records to national archives to intellectual property, is already exposed to a machine that does not yet exist.  </p><p>Quantum-resistant algorithms, like ML-DSA, solve the cryptographic problem, but they introduce much larger keys and signatures. Deployed through today's public key infrastructure (PKI), they would inflate or possibly break the systems behind secure connections. Legacy systems and high-latency networks would feel it most.</p><h2 id="what-is-a-merkle-tree-certificate-mtc">What is a Merkle Tree Certificate (MTC)?</h2><p>At the time this article is being written, the most significant development in Google's roadmap may be the easiest to miss. Under Domain 2, Integrity and non-repudiation, a single line reads:</p><p>“Google Trust Services, Merkle Tree Certificates, 2028”.</p><p>Merkle Tree Certificates (MTCs) are a new kind of <a href="https://www.techradar.com/news/the-best-website-builder">website</a> domain certificate designed to keep secure connections fast in the coming era of quantum computers. Today a website proves its identity by presenting a certificate that carries several digital signatures, and the quantum-resistant versions of those signatures are so bulky they would slow down every secure connection on the internet.</p><p>MTCs solves this by having the certificate authority (CA) record everything it issues in a public, tamper-evident log, organized as a Merkle tree. Rather than carrying heavy signatures, the website presents a short trail of digital fingerprints showing its certificate sits in that log, and the <a href="https://www.techradar.com/best/most-secure-browsers-heres-our-pick">browser</a> checks the trail against a summary of the log it already received through its normal software updates.</p><p>Of note, MTCs do not abandon X.509. They are X.509 certificates, carrying a proof where a signature used to sit, issued alongside conventional directly-signed certificates rather than replacing them.</p><p>The result is a certificate that stays small, stands up to quantum computers, and is publicly verifiable by default. For the regular everyday person: we get to keep using the internet fast and uninterrupted with quantum resistance underneath.</p><h2 id="mtcs-make-transparency-structural">MTCs make transparency structural</h2><p>In today's web PKI, transparency is bolted onto issuance as a separate step. The CA signs a certificate, submits it to independent CT logs, and collects SCTs, each of which is a log's signed promise to publish the certificate within a fixed window. A misbehaving or compromised log can vouch for a certificate that never becomes visible to the monitors watching for misissuance.</p><p>MTCs change that relationship. The CA certifies by logging, and a certificate is literally a proof that its entry appears in the CA's public issuance log, verified by the browser on every connection. If it is not in the log, it is not a certificate. Under MTC, transparency does not merely survive the post-quantum transition. It comes out stronger.</p><h2 id="who-is-developing-merkle-tree-certificates">Who is developing Merkle Tree Certificates</h2><p>When the vendor with the dominant browser share proposes a new certificate format and a new root store to hold it, it is reasonable to ask whether the rest of the ecosystem is being consulted or simply informed.</p><p>However, MTCs are not Google's alone. At the time of writing, the IETF draft's authors span Google, Apple, Cloudflare, and Geomys. Cloudflare has been involved from the outset, CAs including Sectigo have contributed to the underlying research, and Let's Encrypt publicly committed to MTCs in June 2026. The result will be an open standard any CA can implement, controlled by no single vendor.</p><p>The organizations that will shape post-quantum web trust are the ones in the working group now. Root programs, CAs, and large implementers who stay outside it will inherit decisions rather than influence them. That choice is available to everyone, and the window is open today.</p><h2 id="how-organizations-should-prepare-for-mtcs">How organizations should prepare for MTCs</h2><p>Google’s 2028 date for MTCs deserves a roadmap's usual caveats. Google ties it to standardization work still in progress at the IETF, and dates like these move. The direction, however, resembles something that seems settled.</p><p>Chrome's planned Quantum-resistant Root Store will support quantum-resistant certificates only in the MTC format, not as post-quantum signatures bolted into traditional X.509. Compact classical signatures and X.509 served the web extraordinarily well for three decades, but with the dawn of quantum <a href="https://www.techradar.com/news/computing/pc/10-of-the-best-desktop-pcs-of-2015-1304391">computing</a>, we are due for a redesign.</p><p>For everyone else, the practical implication of Google's roadmap is not that you need MTCs. It is that you need to be capable of adopting them (or whatever else emerges) without a multi-year engineering program. Which is precisely the cryptographic agility Google put at the foundation of its own plan.</p><p>In concrete terms, organizations should focus on:</p><ul><li>A complete inventory of certificates and cryptographic assets, because you cannot migrate what you cannot see</li><li>Automated certificate lifecycle management, because shorter certificate lifetimes will make manual processes untenable well before quantum computers arrive</li><li>A written post-quantum roadmap from your CA, which every organization should be asking for</li></ul><p>The full scope of what MTCs can do is still coming into focus, and they may not be the only answer the industry ultimately adopts. What is already clear is that organizations that invest in cryptographic agility, certificate lifecycle <a href="https://www.techradar.com/best/it-management-tools">management</a>, and complete visibility today will be best positioned to adapt as post-quantum standards mature. </p><p>The future of digital trust will belong to organizations that can evolve as quickly as the cryptography they depend on.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/googles-pqc-roadmap-puts-traditional-digital-certificates-under-pressure</link>
                                                                            <description>
                            <![CDATA[ Questions abound on if Merkle Tree Certificates do enough to make PKI transparency structural. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2F5SmCByMHPcWHq8TQiEG7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 09:34:23 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jason Soroko ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1920-80.jpg">
                                                            <media:credit><![CDATA[Thapana Onphalai via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:description>                                                            <media:text><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:text>
                                <media:title type="plain"><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In March, Google moved its own post-quantum cryptography (PQC) <a href="https://www.techradar.com/best/best-data-migration-tools">migration</a> deadline forward to 2029, a full six years ahead of NIST's guidance, and two ahead of the NSA's requirement for national security systems. It was a terrific bit of security signaling, but now it is backed up by a new product-by-product roadmap organized around three risk domains, with milestones attached to named services.</p><p>For anyone whose job touches digital trust, the most significant of those three domains is Google’s attempt at enhancing foundational capabilities for cryptographic agility: building flexible systems that can adopt new cryptographic standards with minimal engineering effort as those standards evolve.</p><p>The message is that organizations should prepare for a future in which standards, certificate formats, and operational requirements continue to evolve, and evolve regularly, requiring cryptographic agility.</p><h2 id="why-quantum-risk-is-already-a-digital-trust-problem">Why quantum risk is already a digital trust problem</h2><p>Adversaries are already harvesting and storing encrypted <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> today on the assumption that a future quantum computer will decrypt it (harvest now, decrypt later). Anything with a long confidentiality tail, from health records to national archives to intellectual property, is already exposed to a machine that does not yet exist.  </p><p>Quantum-resistant algorithms, like ML-DSA, solve the cryptographic problem, but they introduce much larger keys and signatures. Deployed through today's public key infrastructure (PKI), they would inflate or possibly break the systems behind secure connections. Legacy systems and high-latency networks would feel it most.</p><h2 id="what-is-a-merkle-tree-certificate-mtc">What is a Merkle Tree Certificate (MTC)?</h2><p>At the time this article is being written, the most significant development in Google's roadmap may be the easiest to miss. Under Domain 2, Integrity and non-repudiation, a single line reads:</p><p>“Google Trust Services, Merkle Tree Certificates, 2028”.</p><p>Merkle Tree Certificates (MTCs) are a new kind of <a href="https://www.techradar.com/news/the-best-website-builder">website</a> domain certificate designed to keep secure connections fast in the coming era of quantum computers. Today a website proves its identity by presenting a certificate that carries several digital signatures, and the quantum-resistant versions of those signatures are so bulky they would slow down every secure connection on the internet.</p><p>MTCs solves this by having the certificate authority (CA) record everything it issues in a public, tamper-evident log, organized as a Merkle tree. Rather than carrying heavy signatures, the website presents a short trail of digital fingerprints showing its certificate sits in that log, and the <a href="https://www.techradar.com/best/most-secure-browsers-heres-our-pick">browser</a> checks the trail against a summary of the log it already received through its normal software updates.</p><p>Of note, MTCs do not abandon X.509. They are X.509 certificates, carrying a proof where a signature used to sit, issued alongside conventional directly-signed certificates rather than replacing them.</p><p>The result is a certificate that stays small, stands up to quantum computers, and is publicly verifiable by default. For the regular everyday person: we get to keep using the internet fast and uninterrupted with quantum resistance underneath.</p><h2 id="mtcs-make-transparency-structural">MTCs make transparency structural</h2><p>In today's web PKI, transparency is bolted onto issuance as a separate step. The CA signs a certificate, submits it to independent CT logs, and collects SCTs, each of which is a log's signed promise to publish the certificate within a fixed window. A misbehaving or compromised log can vouch for a certificate that never becomes visible to the monitors watching for misissuance.</p><p>MTCs change that relationship. The CA certifies by logging, and a certificate is literally a proof that its entry appears in the CA's public issuance log, verified by the browser on every connection. If it is not in the log, it is not a certificate. Under MTC, transparency does not merely survive the post-quantum transition. It comes out stronger.</p><h2 id="who-is-developing-merkle-tree-certificates">Who is developing Merkle Tree Certificates</h2><p>When the vendor with the dominant browser share proposes a new certificate format and a new root store to hold it, it is reasonable to ask whether the rest of the ecosystem is being consulted or simply informed.</p><p>However, MTCs are not Google's alone. At the time of writing, the IETF draft's authors span Google, Apple, Cloudflare, and Geomys. Cloudflare has been involved from the outset, CAs including Sectigo have contributed to the underlying research, and Let's Encrypt publicly committed to MTCs in June 2026. The result will be an open standard any CA can implement, controlled by no single vendor.</p><p>The organizations that will shape post-quantum web trust are the ones in the working group now. Root programs, CAs, and large implementers who stay outside it will inherit decisions rather than influence them. That choice is available to everyone, and the window is open today.</p><h2 id="how-organizations-should-prepare-for-mtcs">How organizations should prepare for MTCs</h2><p>Google’s 2028 date for MTCs deserves a roadmap's usual caveats. Google ties it to standardization work still in progress at the IETF, and dates like these move. The direction, however, resembles something that seems settled.</p><p>Chrome's planned Quantum-resistant Root Store will support quantum-resistant certificates only in the MTC format, not as post-quantum signatures bolted into traditional X.509. Compact classical signatures and X.509 served the web extraordinarily well for three decades, but with the dawn of quantum <a href="https://www.techradar.com/news/computing/pc/10-of-the-best-desktop-pcs-of-2015-1304391">computing</a>, we are due for a redesign.</p><p>For everyone else, the practical implication of Google's roadmap is not that you need MTCs. It is that you need to be capable of adopting them (or whatever else emerges) without a multi-year engineering program. Which is precisely the cryptographic agility Google put at the foundation of its own plan.</p><p>In concrete terms, organizations should focus on:</p><ul><li>A complete inventory of certificates and cryptographic assets, because you cannot migrate what you cannot see</li><li>Automated certificate lifecycle management, because shorter certificate lifetimes will make manual processes untenable well before quantum computers arrive</li><li>A written post-quantum roadmap from your CA, which every organization should be asking for</li></ul><p>The full scope of what MTCs can do is still coming into focus, and they may not be the only answer the industry ultimately adopts. What is already clear is that organizations that invest in cryptographic agility, certificate lifecycle <a href="https://www.techradar.com/best/it-management-tools">management</a>, and complete visibility today will be best positioned to adapt as post-quantum standards mature. </p><p>The future of digital trust will belong to organizations that can evolve as quickly as the cryptography they depend on.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Don't count the savings until you know what the AI actually costs ]]></title>
                                                                                                <dc:content><![CDATA[ <p>For the last two years, much of the conversation around AI has focused on jobs.   </p><p>Which roles will change? Which tasks will be automated? How many people will organizations need in the future?</p><p>Those are important questions. Yet in conversations with enterprise <a href="https://www.techradar.com/best/the-best-customer-database-software-of-year">customers</a>, a different concern is rising to the top.</p><h2 id="the-conversation-is-shifting">The conversation is shifting</h2><p>We were all told to use AI, deploy <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> and find ways to move faster. Boards pushed for adoption. Executive teams launched initiatives. <a href="https://www.techradar.com/best/best-business-cloud-storage-service">Business</a> units raced to identify new use cases before competitors did.</p><p>Then the bills started showing up.</p><p>If you're following technology news, you've seen growing concerns about organizations losing control of AI spend. Budget overruns, runaway token usage and unexpectedly large invoices have become common discussion points among technology leaders. AI adoption is accelerating across every line of business, and many organizations are discovering they have far less visibility into consumption than they thought. </p><p>That's because AI doesn't just innovate. It invoices.</p><p>Every AI decision and action has a price tag. AI doesn't just answer questions. It reasons, retries, plans, triggers calls, leverages data and compute just to complete one task.  It’s now integrated into the business applications we are using everyday, from Microsoft Copilot and Google Gemini to SAP, Workday, and LinkedIn. Whether we know it or not, the meter is running. </p><p>For many organizations, that creates a challenge they weren't prepared for.</p><h2 id="a-familiar-problem-in-a-new-form">A familiar problem in a new form</h2><p>A decade ago, companies faced similar issues with <a href="https://www.techradar.com/best/best-cloud-databases">cloud</a> adoption. Teams spun up services quickly, often without governance, visibility or accountability. Costs grew faster than expected, and organizations ultimately had to introduce new disciplines to understand what was being used, who was using it and whether the value justified the spend.</p><p>AI is creating a similar challenge at even greater scale.</p><p>The difference is that AI is not confined to one team or department. It exists across every part of the organization. Marketing teams use it. Sales teams use it. Product teams use it. Developers use it.</p><p>AI capabilities are increasingly embedded in business applications while organizations are also building custom agents and workflows of their own. In fact, agentic AI is expected to drive a 24-fold increase in token consumption by 2030 according to Goldman Sachs. </p><p>As a result, AI spend is showing up everywhere.</p><p>Many organizations still don't know exactly which models are being used, which agents are consuming resources, which teams are generating the highest costs or how much token consumption is tied to specific business outcomes, business value and real ROI. Without this visibility, you don’t have a foundation for governance, control, or accountability. </p><h2 id="the-hidden-costs-of-ai-and-the-mirage-of-savings">The hidden costs of AI and the mirage of savings</h2><p>This lack of visibility becomes particularly important when organizations start making workforce decisions based on projected AI savings. Too often, the comparison begins with a salary and an AI license. The challenge is that the license is only one component of the cost.</p><p>The real cost includes token consumption, <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, data platforms, cloud resources, failed attempts, retries and the human oversight required to validate outputs and manage exceptions. Those costs are frequently spread across different systems, teams and budgets, which makes them difficult to measure accurately.</p><p>A salary is relatively predictable. AI costs are not.</p><p>The same task can generate very different costs depending on which model is selected, how much context is provided, how many times the system retries a process and how much computing power is required to complete the work. That variability matters because a role removed from payroll does not automatically translate into savings. The expense may simply move somewhere else.</p><p>It may move into cloud consumption. It may move into AI services. It may move into infrastructure costs. It may move into additional work for <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employees</a> responsible for reviewing outputs and managing exceptions.</p><p>Without visibility into those costs, organizations are not comparing AI to a salary. They're comparing a salary to an assumption.</p><h2 id="visibility-before-optimization">Visibility before optimization</h2><p>The answer is not to slow innovation or abandon AI initiatives. Instead, enterprise leaders must understand where AI creates value, what it costs to operate at scale and how to make informed decisions about adoption.</p><p>That starts with visibility.</p><p>Organizations need to see which AI applications, agents and models are being used across the business. They need to know where tokens are being consumed, where costs are accumulating and how usage maps to business units, products and outcomes.  </p><p>Only then can they begin making informed decisions about optimisation. That may mean selecting different models for different use cases. It may mean identifying unnecessary consumption. It may mean understanding when lower-cost alternatives can achieve the same outcome. In some cases, it may simply mean discovering that a small number of users or workloads are responsible for a disproportionate percentage of spend.</p><p>These are manageable problems.</p><p>The bigger risk is making financial decisions before understanding the economics.</p><h2 id="the-rise-of-ai-tokenomics">The rise of AI tokenomics</h2><p>AI has moved into an inference economy where costs are driven by usage, tokens and real-time execution. Tokens are emerging as the atomic unit of AI spend, value and pricing. Organizations are going to need new ways to govern, measure and optimize that consumption if they want to run AI affordably at scale. This emerging discipline of AI tokenomics is becoming increasingly important as AI adoption expands across the enterprise.</p><p>What we're seeing today is the beginning of a new economic model that many companies are not equipped to manage yet. As AI becomes embedded across applications, agents and workflows, understanding consumption becomes just as important as understanding adoption.</p><p>What does AI return?</p><p>Ultimately, the question organizations should be asking is not simply what AI costs but what it returns. What business value does it create? What outcomes does it improve? What's it worth? </p><p>Organizations that can answer those questions with confidence will make better decisions about where AI belongs, where it delivers measurable results and where it doesn't.</p><p>Before counting AI-driven savings from job cuts, understand the full cost of the work being done. Because the organizations getting the most value from AI won't be the ones making the fastest assumptions about efficiency. They'll be the ones making decisions based on visibility, evidence, and a clear understanding of what the technology actually costs.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-website-builder"><em>We've featured the best AI website builder.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/dont-count-the-savings-until-you-know-what-the-ai-actually-costs</link>
                                                                            <description>
                            <![CDATA[ Before counting AI-driven savings, businesses need visibility into what AI actually costs. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LJVLWK2PQERwxpo3u8AgXL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PAztEScphfxGJfYno5NjrL-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 07:38:14 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Steve Daheb ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PAztEScphfxGJfYno5NjrL-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot standing thoughtfully in front of a giant digital display with code on it]]></media:description>                                                            <media:text><![CDATA[A robot standing thoughtfully in front of a giant digital display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A robot standing thoughtfully in front of a giant digital display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PAztEScphfxGJfYno5NjrL-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For the last two years, much of the conversation around AI has focused on jobs.   </p><p>Which roles will change? Which tasks will be automated? How many people will organizations need in the future?</p><p>Those are important questions. Yet in conversations with enterprise <a href="https://www.techradar.com/best/the-best-customer-database-software-of-year">customers</a>, a different concern is rising to the top.</p><h2 id="the-conversation-is-shifting">The conversation is shifting</h2><p>We were all told to use AI, deploy <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> and find ways to move faster. Boards pushed for adoption. Executive teams launched initiatives. <a href="https://www.techradar.com/best/best-business-cloud-storage-service">Business</a> units raced to identify new use cases before competitors did.</p><p>Then the bills started showing up.</p><p>If you're following technology news, you've seen growing concerns about organizations losing control of AI spend. Budget overruns, runaway token usage and unexpectedly large invoices have become common discussion points among technology leaders. AI adoption is accelerating across every line of business, and many organizations are discovering they have far less visibility into consumption than they thought. </p><p>That's because AI doesn't just innovate. It invoices.</p><p>Every AI decision and action has a price tag. AI doesn't just answer questions. It reasons, retries, plans, triggers calls, leverages data and compute just to complete one task.  It’s now integrated into the business applications we are using everyday, from Microsoft Copilot and Google Gemini to SAP, Workday, and LinkedIn. Whether we know it or not, the meter is running. </p><p>For many organizations, that creates a challenge they weren't prepared for.</p><h2 id="a-familiar-problem-in-a-new-form">A familiar problem in a new form</h2><p>A decade ago, companies faced similar issues with <a href="https://www.techradar.com/best/best-cloud-databases">cloud</a> adoption. Teams spun up services quickly, often without governance, visibility or accountability. Costs grew faster than expected, and organizations ultimately had to introduce new disciplines to understand what was being used, who was using it and whether the value justified the spend.</p><p>AI is creating a similar challenge at even greater scale.</p><p>The difference is that AI is not confined to one team or department. It exists across every part of the organization. Marketing teams use it. Sales teams use it. Product teams use it. Developers use it.</p><p>AI capabilities are increasingly embedded in business applications while organizations are also building custom agents and workflows of their own. In fact, agentic AI is expected to drive a 24-fold increase in token consumption by 2030 according to Goldman Sachs. </p><p>As a result, AI spend is showing up everywhere.</p><p>Many organizations still don't know exactly which models are being used, which agents are consuming resources, which teams are generating the highest costs or how much token consumption is tied to specific business outcomes, business value and real ROI. Without this visibility, you don’t have a foundation for governance, control, or accountability. </p><h2 id="the-hidden-costs-of-ai-and-the-mirage-of-savings">The hidden costs of AI and the mirage of savings</h2><p>This lack of visibility becomes particularly important when organizations start making workforce decisions based on projected AI savings. Too often, the comparison begins with a salary and an AI license. The challenge is that the license is only one component of the cost.</p><p>The real cost includes token consumption, <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, data platforms, cloud resources, failed attempts, retries and the human oversight required to validate outputs and manage exceptions. Those costs are frequently spread across different systems, teams and budgets, which makes them difficult to measure accurately.</p><p>A salary is relatively predictable. AI costs are not.</p><p>The same task can generate very different costs depending on which model is selected, how much context is provided, how many times the system retries a process and how much computing power is required to complete the work. That variability matters because a role removed from payroll does not automatically translate into savings. The expense may simply move somewhere else.</p><p>It may move into cloud consumption. It may move into AI services. It may move into infrastructure costs. It may move into additional work for <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employees</a> responsible for reviewing outputs and managing exceptions.</p><p>Without visibility into those costs, organizations are not comparing AI to a salary. They're comparing a salary to an assumption.</p><h2 id="visibility-before-optimization">Visibility before optimization</h2><p>The answer is not to slow innovation or abandon AI initiatives. Instead, enterprise leaders must understand where AI creates value, what it costs to operate at scale and how to make informed decisions about adoption.</p><p>That starts with visibility.</p><p>Organizations need to see which AI applications, agents and models are being used across the business. They need to know where tokens are being consumed, where costs are accumulating and how usage maps to business units, products and outcomes.  </p><p>Only then can they begin making informed decisions about optimisation. That may mean selecting different models for different use cases. It may mean identifying unnecessary consumption. It may mean understanding when lower-cost alternatives can achieve the same outcome. In some cases, it may simply mean discovering that a small number of users or workloads are responsible for a disproportionate percentage of spend.</p><p>These are manageable problems.</p><p>The bigger risk is making financial decisions before understanding the economics.</p><h2 id="the-rise-of-ai-tokenomics">The rise of AI tokenomics</h2><p>AI has moved into an inference economy where costs are driven by usage, tokens and real-time execution. Tokens are emerging as the atomic unit of AI spend, value and pricing. Organizations are going to need new ways to govern, measure and optimize that consumption if they want to run AI affordably at scale. This emerging discipline of AI tokenomics is becoming increasingly important as AI adoption expands across the enterprise.</p><p>What we're seeing today is the beginning of a new economic model that many companies are not equipped to manage yet. As AI becomes embedded across applications, agents and workflows, understanding consumption becomes just as important as understanding adoption.</p><p>What does AI return?</p><p>Ultimately, the question organizations should be asking is not simply what AI costs but what it returns. What business value does it create? What outcomes does it improve? What's it worth? </p><p>Organizations that can answer those questions with confidence will make better decisions about where AI belongs, where it delivers measurable results and where it doesn't.</p><p>Before counting AI-driven savings from job cuts, understand the full cost of the work being done. Because the organizations getting the most value from AI won't be the ones making the fastest assumptions about efficiency. They'll be the ones making decisions based on visibility, evidence, and a clear understanding of what the technology actually costs.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-website-builder"><em>We've featured the best AI website builder.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Linux users beware — CISA flags three major security issues you need to patch right now ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>CISA added three Linux kernel flaws (CVE‑2025‑39682, CVE‑2026‑53266, CVE‑2025‑39964) to KEV catalog</strong></li><li><strong>Red Hat confirmed active exploitation; agencies given rare three‑day patch deadline expiring Sept 21, 2026</strong></li><li><strong>Bugs enable DoS, privilege escalation, or data corruption; patches available, limited mitigations for two flaws</strong></li></ul><p>The US Cybersecurity and Infrastructure Security Agency (CISA) has added three <a href="https://www.techradar.com/best/best-linux-distros-for-windows-users" target="_blank">Linux</a> flaws to its Known Exploited Vulnerabilities (KEV) catalog, signaling abuse in the wild and giving government agencies a deadline to patch or stop using the flawed product entirely.</p><p>The three bugs in question are tracked as CVE-2025-39682 (severity score 9.8/10 - critical), CVE-2026-53266 (severity score 8.8/10 - high), and CVE-2025-39964 (severity score 7.8/10 - high). All three have already been patched in the Linux kernel. CVE-2025-39682 was fixed in stable releases 6.1.149, 6.6.103, 6.12.44 and 6.16.4, while CVE-2025-39964 was fixed in 5.10.245, 5.15.194, 6.1.154, 6.6.108, 6.12.49 and 6.16.9. CVE-2026-53266 has been fixed upstream and backported to supported stable/distribution kernel branches, including 5.10.259, 6.1.176 and 6.12.94.</p><p>The first issue is an improper check for unusual or exceptional conditions vulnerability in the TLS receive patch which could allow unauthenticated threat actors to launch memory disclosure or denial-of-service (DoS) attacks. The second one (CVE-2026-53266) is an out-of-bounds write vulnerability in the ebtables Source Network Address Translation (SNAT) Address Resolution Protocol (ARP) rewrite patch which allows local attackers to escalate privileges or mount DoS attacks. </p><p>The last one (CVE-2025-39964) is a race condition flaw that allows concurrent writes to the same AF_ALG socket, which allows local malicious actors to crash the system or corrupt cryptographic operation results, leading to data integrity issues and possible DoS states. </p><h2 id="attacks-in-the-wild">Attacks in the wild</h2><p>Red Hat acknowledged that all three are being abused in real-life attacks. “This CVE is high risk and there are known public exploits leveraging this vulnerability. Address this vulnerability with high priority,” it said in all three advisories. </p><p>However, there are no details as to who is currently using these exploits, against whom, and to what cause. There are currently no separate reports of cyberattacks referencing any of the abovementioned vulnerabilities. </p><p>However, CISA still reacted. All three flaws were added on September 18, 2026, and all three have a small three-day deadline for patching that expires on September 21. Usually, CISA would grant Federal Civilian Executive Branch (FCEB) agencies a three-week deadline to patch up, with just exceptionally dangerous flaws getting a shorter window. That being said, these flaws are likely extremely dangerous. </p><h2 id="in-theory">In theory...</h2><p>In a hypothetical scenario, a threat actor could target a Linux system using kernel TLS (kTLS) by sending a specially-crafted TLS record that triggers CVE-2025-39682 and causing either a crash, or even arbitrary code execution. Attackers that already have a low privilege foothold on the target endpoint could use CVE_2025-39964 to escalate privileges, while on systems using the affected bridge/netfilter configuration, CVE-2026-53266 could be used for privilege escalation, as well. </p><p>According to the Red Hat advisory, there is a chance that CVE-2025-39682 is remotely triggerable, but only when the system is using the affected kTLS receive path. The other two flaws are exclusively local vulnerabilities. </p><p>Besides fixes, two out of the three flaws also have possible mitigations. For the improper check one, users should prevent module tls from being loaded. For the out-of-bounds write one, users are advised to disable ARP hardware address rewriting in ebtables SNAT rules, or remove ebtables SNAT rules that operate on ARP traffic on bridge interfaces. The final vulnerability, currently does not have a working mitigation, and the only way to stay secure is to apply the provided patches. </p><p>Linux kernel vulnerabilities are generally considered serious, but the severity still depends on the flaw and how the affected kernel is deployed. Earlier this year, security researchers disclosed four local privilege escalation flaws, called DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121), and DiagSpill (CVE-2026-74469). </p><p><em>Via </em><a href="https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html" target="_blank"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/linux-users-beware-cisa-flags-three-major-security-issues-you-need-to-patch-right-now</link>
                                                                            <description>
                            <![CDATA[ Two flaws have available mitigations, too, but it's best to patch up. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SSYMHF6E7FMSYLeTPLyfnF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MRcAF4wnJU8Qb7Bv7Lb9yd-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 01:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MRcAF4wnJU8Qb7Bv7Lb9yd-1920-80.jpg">
                                                            <media:credit><![CDATA[Pixababy]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Linux penguin logo on wood]]></media:description>                                                            <media:text><![CDATA[Linux penguin logo on wood]]></media:text>
                                <media:title type="plain"><![CDATA[Linux penguin logo on wood]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MRcAF4wnJU8Qb7Bv7Lb9yd-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>CISA added three Linux kernel flaws (CVE‑2025‑39682, CVE‑2026‑53266, CVE‑2025‑39964) to KEV catalog</strong></li><li><strong>Red Hat confirmed active exploitation; agencies given rare three‑day patch deadline expiring Sept 21, 2026</strong></li><li><strong>Bugs enable DoS, privilege escalation, or data corruption; patches available, limited mitigations for two flaws</strong></li></ul><p>The US Cybersecurity and Infrastructure Security Agency (CISA) has added three <a href="https://www.techradar.com/best/best-linux-distros-for-windows-users" target="_blank">Linux</a> flaws to its Known Exploited Vulnerabilities (KEV) catalog, signaling abuse in the wild and giving government agencies a deadline to patch or stop using the flawed product entirely.</p><p>The three bugs in question are tracked as CVE-2025-39682 (severity score 9.8/10 - critical), CVE-2026-53266 (severity score 8.8/10 - high), and CVE-2025-39964 (severity score 7.8/10 - high). All three have already been patched in the Linux kernel. CVE-2025-39682 was fixed in stable releases 6.1.149, 6.6.103, 6.12.44 and 6.16.4, while CVE-2025-39964 was fixed in 5.10.245, 5.15.194, 6.1.154, 6.6.108, 6.12.49 and 6.16.9. CVE-2026-53266 has been fixed upstream and backported to supported stable/distribution kernel branches, including 5.10.259, 6.1.176 and 6.12.94.</p><p>The first issue is an improper check for unusual or exceptional conditions vulnerability in the TLS receive patch which could allow unauthenticated threat actors to launch memory disclosure or denial-of-service (DoS) attacks. The second one (CVE-2026-53266) is an out-of-bounds write vulnerability in the ebtables Source Network Address Translation (SNAT) Address Resolution Protocol (ARP) rewrite patch which allows local attackers to escalate privileges or mount DoS attacks. </p><p>The last one (CVE-2025-39964) is a race condition flaw that allows concurrent writes to the same AF_ALG socket, which allows local malicious actors to crash the system or corrupt cryptographic operation results, leading to data integrity issues and possible DoS states. </p><h2 id="attacks-in-the-wild">Attacks in the wild</h2><p>Red Hat acknowledged that all three are being abused in real-life attacks. “This CVE is high risk and there are known public exploits leveraging this vulnerability. Address this vulnerability with high priority,” it said in all three advisories. </p><p>However, there are no details as to who is currently using these exploits, against whom, and to what cause. There are currently no separate reports of cyberattacks referencing any of the abovementioned vulnerabilities. </p><p>However, CISA still reacted. All three flaws were added on September 18, 2026, and all three have a small three-day deadline for patching that expires on September 21. Usually, CISA would grant Federal Civilian Executive Branch (FCEB) agencies a three-week deadline to patch up, with just exceptionally dangerous flaws getting a shorter window. That being said, these flaws are likely extremely dangerous. </p><h2 id="in-theory">In theory...</h2><p>In a hypothetical scenario, a threat actor could target a Linux system using kernel TLS (kTLS) by sending a specially-crafted TLS record that triggers CVE-2025-39682 and causing either a crash, or even arbitrary code execution. Attackers that already have a low privilege foothold on the target endpoint could use CVE_2025-39964 to escalate privileges, while on systems using the affected bridge/netfilter configuration, CVE-2026-53266 could be used for privilege escalation, as well. </p><p>According to the Red Hat advisory, there is a chance that CVE-2025-39682 is remotely triggerable, but only when the system is using the affected kTLS receive path. The other two flaws are exclusively local vulnerabilities. </p><p>Besides fixes, two out of the three flaws also have possible mitigations. For the improper check one, users should prevent module tls from being loaded. For the out-of-bounds write one, users are advised to disable ARP hardware address rewriting in ebtables SNAT rules, or remove ebtables SNAT rules that operate on ARP traffic on bridge interfaces. The final vulnerability, currently does not have a working mitigation, and the only way to stay secure is to apply the provided patches. </p><p>Linux kernel vulnerabilities are generally considered serious, but the severity still depends on the flaw and how the affected kernel is deployed. Earlier this year, security researchers disclosed four local privilege escalation flaws, called DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121), and DiagSpill (CVE-2026-74469). </p><p><em>Via </em><a href="https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Researchers can make headphones leak audio through a wall, but the 30-meter claim has a few caveats ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>HKUST (Guangzhou) and HK PolyU researchers' InjectEave beams a radio carrier at devices so their own circuits leak analog audio</strong></li><li><strong>The leaked audio has already been decrypted by the device itself, making encryption offer no protection against such an approach</strong></li><li><strong>The 30m headline needed a pricey amplifier pushing output to 10 W, while standard ranges of 1 to 6m were measured by detecting a test tone</strong></li></ul><p>Researchers at the Hong Kong University of Science and Technology and the Hong Kong Polytechnic University have shown that everyday headphones, a desk phone, and a handful of smart-home gadgets can broadcast what they are doing simply by using a radio signal.</p><p>The technique, called <a href="https://injecteave.github.io/" target="_blank">InjectEave</a>, was presented at USENIX Security 2026 in Baltimore, and multiple outlets <a href="https://www.theregister.com/security/2026/09/17/researchers-find-way-to-listen-in-on-headphones-from-afar/5297303" target="_blank">have since covered</a> the researcher's claim that the attack "can recover headphone audio from up to 30 meters away, including through walls".</p><p>The claim may be accurate, but it has limitations, including the need for specialized equipment that is often very noticeable in most settings.</p><h2 id="an-impressive-technical-show-with-plenty-of-limitations-in-tow">An impressive technical show with plenty of limitations in tow</h2><p>Conventional electromagnetic eavesdropping waits for a device to leak. That works poorly for audio, because speech sits below 20 kHz while a device's wiring radiates efficiently only at megahertz or gigahertz frequencies.</p><p>InjectEave chooses to close the gap by transmitting a carrier signal at the target. According to <a href="https://injecteave.github.io/assets/paper/sec26cycle2-final651.pdf" target="_blank" rel="nofollow">the paper</a>, nonlinear components such as amplifiers, analog-to-digital converters, switching MOSFETs, and power converters mix the secret signal onto that carrier, and the device's own traces and cables radiate the result back to a receiver.<br><br>Because the leak happens in the analog path, after audio has been decoded, the project page states that "InjectEave is immune to digital defenses such as encryption, masking, and randomization." Encryption in any form on a wireless headset is irrelevant, since the attack directly targets the signal driving the speaker, not the radio link.</p><p>The team demonstrating this used a USRP B210 software-defined radio, two antennas, a Siglent spectrum analyzer, and a laptop to set up their proof of concept, which could, as they noted, "eavesdrop on the majority of these devices from over 2m away and through walls, with a maximum distance of 30m for recovering intelligible headphone audio". </p><p>This isn't the first time the technique has been used, even as the researchers have built on it considerably; the idea <a href="https://en.wikipedia.org/wiki/The_Thing_(listening_device)" target="_blank">originates from "The Thing</a>," a Soviet bug given as a gift to the US ambassador in Moscow in 1945, which was passively powered remotely as a listening device.</p><p>InjectEve, however, does not involve planting anything; instead, it leverages existing work on interference-induced leakage and impedance-based backscatter, and distinguishes itself by recovering coarse digital data rather than continuous analog waveforms, allowing users to 'listen in' without added steps.</p><p>The same approach applies to wired headphones, which are also prone to leaking microphone audio; researchers concluded that their sound cards were the primary source of the leaks, which were being sent back over very short distances.</p><p>The threat is somewhat tempered by the fact that it can capture what users hear but, with wireless headphones, cannot hear what the user is saying. The attacker also has to transmit continuously and use a high-powered (10W) transmitter to reach the full 30-meter range, even though capturing and rendering speech is harder than the tones the test used to prove the approach worked.</p><p>The attacker also needs to know the target model and profile a matching unit first, although they managed to get a profile to transfer cleanly across three identical UGreen headsets, suggesting this might be easier than one would assume.</p><p>The researchers say they reported the findings to the affected manufacturers but, "as we have not yet received a response," withheld the table's frequencies and stripped injection control logic from their released code. One shouldn't be too hopeful, however, as no software update can fix an analog leak, and it is relatively limited in practical abuse cases.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/researchers-can-make-headphones-leak-audio-through-a-wall-but-the-30-meter-claim-has-a-few-caveats</link>
                                                                            <description>
                            <![CDATA[ Encryption can't stop InjectEave because the audio leaks after it's been decoded, but it does have its limitations. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">C9VZczcuq5MFFvrjVaUUCf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9ui8vuAvNqX2Bubaxvks8J-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 21 Sep 2026 23:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Audio]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9ui8vuAvNqX2Bubaxvks8J-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Headphones]]></media:description>                                                            <media:text><![CDATA[Headphones]]></media:text>
                                <media:title type="plain"><![CDATA[Headphones]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9ui8vuAvNqX2Bubaxvks8J-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>HKUST (Guangzhou) and HK PolyU researchers' InjectEave beams a radio carrier at devices so their own circuits leak analog audio</strong></li><li><strong>The leaked audio has already been decrypted by the device itself, making encryption offer no protection against such an approach</strong></li><li><strong>The 30m headline needed a pricey amplifier pushing output to 10 W, while standard ranges of 1 to 6m were measured by detecting a test tone</strong></li></ul><p>Researchers at the Hong Kong University of Science and Technology and the Hong Kong Polytechnic University have shown that everyday headphones, a desk phone, and a handful of smart-home gadgets can broadcast what they are doing simply by using a radio signal.</p><p>The technique, called <a href="https://injecteave.github.io/" target="_blank">InjectEave</a>, was presented at USENIX Security 2026 in Baltimore, and multiple outlets <a href="https://www.theregister.com/security/2026/09/17/researchers-find-way-to-listen-in-on-headphones-from-afar/5297303" target="_blank">have since covered</a> the researcher's claim that the attack "can recover headphone audio from up to 30 meters away, including through walls".</p><p>The claim may be accurate, but it has limitations, including the need for specialized equipment that is often very noticeable in most settings.</p><h2 id="an-impressive-technical-show-with-plenty-of-limitations-in-tow">An impressive technical show with plenty of limitations in tow</h2><p>Conventional electromagnetic eavesdropping waits for a device to leak. That works poorly for audio, because speech sits below 20 kHz while a device's wiring radiates efficiently only at megahertz or gigahertz frequencies.</p><p>InjectEave chooses to close the gap by transmitting a carrier signal at the target. According to <a href="https://injecteave.github.io/assets/paper/sec26cycle2-final651.pdf" target="_blank" rel="nofollow">the paper</a>, nonlinear components such as amplifiers, analog-to-digital converters, switching MOSFETs, and power converters mix the secret signal onto that carrier, and the device's own traces and cables radiate the result back to a receiver.<br><br>Because the leak happens in the analog path, after audio has been decoded, the project page states that "InjectEave is immune to digital defenses such as encryption, masking, and randomization." Encryption in any form on a wireless headset is irrelevant, since the attack directly targets the signal driving the speaker, not the radio link.</p><p>The team demonstrating this used a USRP B210 software-defined radio, two antennas, a Siglent spectrum analyzer, and a laptop to set up their proof of concept, which could, as they noted, "eavesdrop on the majority of these devices from over 2m away and through walls, with a maximum distance of 30m for recovering intelligible headphone audio". </p><p>This isn't the first time the technique has been used, even as the researchers have built on it considerably; the idea <a href="https://en.wikipedia.org/wiki/The_Thing_(listening_device)" target="_blank">originates from "The Thing</a>," a Soviet bug given as a gift to the US ambassador in Moscow in 1945, which was passively powered remotely as a listening device.</p><p>InjectEve, however, does not involve planting anything; instead, it leverages existing work on interference-induced leakage and impedance-based backscatter, and distinguishes itself by recovering coarse digital data rather than continuous analog waveforms, allowing users to 'listen in' without added steps.</p><p>The same approach applies to wired headphones, which are also prone to leaking microphone audio; researchers concluded that their sound cards were the primary source of the leaks, which were being sent back over very short distances.</p><p>The threat is somewhat tempered by the fact that it can capture what users hear but, with wireless headphones, cannot hear what the user is saying. The attacker also has to transmit continuously and use a high-powered (10W) transmitter to reach the full 30-meter range, even though capturing and rendering speech is harder than the tones the test used to prove the approach worked.</p><p>The attacker also needs to know the target model and profile a matching unit first, although they managed to get a profile to transfer cleanly across three identical UGreen headsets, suggesting this might be easier than one would assume.</p><p>The researchers say they reported the findings to the affected manufacturers but, "as we have not yet received a response," withheld the table's frequencies and stripped injection control logic from their released code. One shouldn't be too hopeful, however, as no software update can fix an analog leak, and it is relatively limited in practical abuse cases.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>