Normal view

Before yesterdayMain stream

Quordle hints and answers for Thursday, July 16 (game #1634)

Looking for a different day?

A new Quordle puzzle appears at midnight each day for your time zone – which means that some people are always playing 'today's game' while others are playing 'yesterday's'. If you're looking for Wednesday's puzzle instead then click here: Quordle hints and answers for Wednesday, July 15 (game #1633).

Quordle was one of the original Wordle alternatives and is still going strong now more than 1,500 games later. It offers a genuine challenge, though, so read on if you need some Quordle hints today — or scroll down further for the answers.

Enjoy playing word games? You can also check out my NYT Connections today and NYT Strands today pages for hints and answers for those puzzles, while Marc's Wordle today column covers the original viral word game.

SPOILER WARNING: Information about Quordle today is below, so don't read on if you don't want to know the answers.

Quordle today (game #1634) — hint #1 — Vowels

How many different vowels are in Quordle today?

The number of different vowels in Quordle today is 4*.

* Note that by vowel we mean the five standard vowels (A, E, I, O, U), not Y (which is sometimes counted as a vowel too).

Quordle today (game #1634) — hint #2 — repeated letters

Do any of today's Quordle answers contain repeated letters?

The number of Quordle answers containing a repeated letter today is 2.

Quordle today (game #1634) — hint #3 — uncommon letters

Do the letters Q, Z, X or J appear in Quordle today?

• No. None of Q, Z, X or J appear among today's Quordle answers.

Quordle today (game #1634) — hint #4 — starting letters (1)

Do any of today's Quordle puzzles start with the same letter?

The number of today's Quordle answers starting with the same letter is 0.

If you just want to know the answers at this stage, simply scroll down. If you're not ready yet then here's one more clue to make things a lot easier:

Quordle today (game #1634) — hint #5 — starting letters (2)

What letters do today's Quordle answers start with?

• I

• P

• Y

• A

Right, the answers are below, so DO NOT SCROLL ANY FURTHER IF YOU DON'T WANT TO SEE THEM.

Quordle today (game #1634) — the answers

Quordle answers for game 1634 on a yellow background

(Image credit: Merriam-Webster)

The answers to today's Quordle, game #1634, are…

  • IGLOO
  • PLAIT
  • YEAST
  • AROMA

This was a tricky game — mainly due to two words ending in vowels.

I thought I had exhausted all words ending in the letter O, before I finally got to one ending in two of them.

Daily Sequence today (game #1634) — the answers

Quordle Daily Sequence answers for game 1634 on a yellow background

(Image credit: Merriam-Webster)

The answers to today's Quordle Daily Sequence, game #1634, are…

  • NEEDY
  • GOOFY
  • ABIDE
  • VISIT

Quordle answers: The past 20

  • Quordle #1633, Wednesday, 15 July: PROXY, BRICK, BROTH, SURGE
  • Quordle #1632, Tuesday, 14 July: EBONY, AVOID, RODEO, CUTIE
  • Quordle #1631, Monday, 13 July: VOICE, BISON, BURNT, BUILT
  • Quordle #1630, Sunday, 12 July: STAIN, BINGO, LARVA, DICEY
  • Quordle #1629, Saturday, 11 July: WORTH, PRONG, DINGO, DRUID
  • Quordle #1628, Friday, 10 July: GREET, STEAK, DUSKY, HAUTE
  • Quordle #1627, Thursday, 9 July: CRUMP, PHONE, SHINY, STONY
  • Quordle #1626, Wednesday, 8 July: GHOST, TREND, EXALT, ALONG
  • Quordle #1625, Tuesday, 7 July: ARRAY, SUITE, KIOSK, BOULE
  • Quordle #1624, Monday, 6 July: TRAWL, SPICE, PIANO, SHARK
  • Quordle #1623, Sunday, 5 July: PINEY, SWOON, TITLE, PINTO
  • Quordle #1622, Saturday, 4 July: ARGUE, MOTEL, OPERA, TRUCE
  • Quordle #1621, Friday, 3 July: AVERT, MOTOR, MANIC, WORDY
  • Quordle #1620, Thursday, 2 July: BULKY, PARSE, BELOW, MOVIE
  • Quordle #1619, Wednesday, 1 July: EASEL, OTTER, LYRIC, SHACK
  • Quordle #1618, Tuesday, 30 June: HALVE, DRYER, THERE, MINTY
  • Quordle #1617, Monday, 29 June: SLURP, CRACK, CRANK, PHONY
  • Quordle #1616, Sunday, 28 June: RUPEE, TOPAZ, FULLY, BEING
  • Quordle #1615, Saturday, 27 June: PRINT, MARRY, SADLY, BICEP
  • Quordle #1614, Friday, 26 June: JUICE, ARRAY, BONEY, SKIFF

NYT Strands hints and answers for Thursday, July 16 (game #865)

Looking for a different day?

A new NYT Strands puzzle appears at midnight each day for your time zone – which means that some people are always playing 'today's game' while others are playing 'yesterday's'. If you're looking for Wednesday's puzzle instead then click here: NYT Strands hints and answers for Wednesday, July 15 (game #864).

Strands is the NYT's latest word game after the likes of Wordle, Spelling Bee and Connections – and it's great fun. It can be difficult, though, so read on for my Strands hints.

Want more word-based fun? Then check out my NYT Connections today and Quordle today pages for hints and answers for those games, and Marc's Wordle today page for the original viral word game.

SPOILER WARNING: Information about NYT Strands today is below, so don't read on if you don't want to know the answers.

NYT Strands today (game #865) - hint #1 - today's theme

What is the theme of today's NYT Strands?

Today's NYT Strands theme is… Rerouting…

NYT Strands today (game #865) - hint #2 - clue words

Play any of these words to unlock the in-game hints system.

  • NOISE
  • CHANCE
  • VERSE
  • TRUANT
  • GIVE
  • SKATE

NYT Strands today (game #865) - hint #3 - spangram letters

How many letters are in today's spangram?

Spangram has 12 letters

NYT Strands today (game #865) - hint #4 - spangram position

What are two sides of the board that today's spangram touches?

First side: left, 4th row

Last side: left, 8th row

Right, the answers are below, so DO NOT SCROLL ANY FURTHER IF YOU DON'T WANT TO SEE THEM.

NYT Strands today (game #865) - the answers

NYT Strands answers for game 865 on a blue background

(Image credit: New York Times)

The answers to today's Strands, game #865, are…

  • TACK
  • ZIGZAG
  • TURN
  • VEER
  • DEVIATE
  • PIVOT
  • SWERVE
  • SPANGRAM: CHANGECOURSE
  • My rating: Hard
  • My score: 1 hint

Rerouting… is a word I used to see a lot when I used a sat nav in my car, so this is exactly the theme I was expecting — but I still struggled over it.

It’s not until you play Strands that you realize how many different ways there are to say the same thing, in this case a change of direction.

I took a hint to get going, but TACK didn’t help much. Then, I connected the two Zs for ZIGZAG and finally got motoring.

Yesterday's NYT Strands answers (Wednesday, July 15, game #864)

  • QUIXOTIC
  • IDEALISTIC
  • ROMANTIC
  • IMPRACTICAL
  • SPANGRAM: PIEINTHESKY

What is NYT Strands?

Strands is the NYT's not-so-new-any-more word game, following Wordle and Connections. It's now a fully fledged member of the NYT's games stable that has been running for a year and which can be played on the NYT Games site on desktop or mobile.

I've got a full guide to how to play NYT Strands, complete with tips for solving it, so check that out if you're struggling to beat it each day.

‘A candidate who was hostile from day one never produces that baseline’: Nation states spies applying for legit jobs are hard to spot

Geopolitical tensions are mounting, and nation states are employing new types of strategies to gain intelligence. A recent Five Eyes warning, for example, accused Chinese military intelligence officers of using professional networking sites and online job platforms to target individuals of interest.

In this specific case, the agents pose as recruiters advertising seemingly legitimate work to build relationships and, ultimately, get their hands on non-public information. Popular sites like LinkedIn, Indeed and Upwork have all seen this new type of attack take place.

At the same time, a parallel threat sees operatives applying for jobs within trusted organizations with access to intelligence, creating insider threats that experts warn AI might be mostly responsible for.

Generative AI, for example, can create documents, write applications and even supply live answers during real-time remote interviews, meaning that a small group of fake applicants can extend their reach much more quickly.

Rather than attacking existing workers, nation states are creating their own job candidates

Once inside an organization and with access to company tools like PCs, emails and other internal systems, nation state spies can then move laterally to acquire the information they sought.

Security experts at Exabeam warn that, because this technique is still evolving, it might not always be so easy to spot. Additionally, motives can differ, with Chinese intelligence operations typically seeking military, political or economic information. North Korean agents, on the other hand, tend to be tied to stealing money, which could also come with the side effect of data and intelligence theft.

Exabeam even observed this type of attack first-hand, when a North Korean-affiliated applicant used a false identity to apply for a job at the company. After passing technical tests, a video interview and other standard checks, the suspect’s laptop was quickly flagged for unusual activity.

In the following Q&A with AI Strategy and Security Research VP Steve Povolny, I discuss these new types of attacks, who’s responsible for stamping them out and what we can do to prevent similar incidents from happening more commonly.

  • The Five Eyes alliance recently warned that foreign intelligence groups are using job platforms to recruit insiders. How significant is this threat, and what is driving its growth?

This is among the most serious access-driven threats facing cleared workers, and it keeps growing because the economics now favor the attacker.

Foreign intelligence services no longer need handlers and dead drops when they can post a job ad on LinkedIn or Upwork and let candidates self-select based on the access listed in their own resumes. Generative AI lets them run thousands of these conversations at once, drafting outreach and scoring which applicants sit closest to sensitive information without a trained officer.

The Five Eyes alert describes a scaled, automated funnel, and that scale is what makes it dangerous.

  • A parallel risk runs alongside that warning: adversaries who secure employment directly rather than recruiting an existing employee. Which scenario presents the greater defensive challenge, and why?

The infiltration model gives defenders less to work with, which makes it the harder problem. When an adversary recruits someone already on staff, most of the suspicious behavior happens outside the company on platforms the employer never sees, yet the insider remains a known person with a verified identity and a real history.

When the adversary becomes the employee, the company has onboarded a fabricated person and handed them a laptop and standing network access on day one. No behavioral baseline exists, since everything that account does counts as a first. The deception also clears the controls most organizations trust, so the failure lands before any security tool gets a vote.

  • Exabeam identified a North Korea-affiliated individual who gained employment at the company. How did the operative clear Exabeam's hiring process, and what first signaled that something was wrong?

He cleared it by performing well on the parts we test and forging the parts we verify. Applying under the alias Trevor Rothluebber, he aced the technical interview and take-home assessment, passed the video interview and cleared our standard pre-employment process including the background check and I-9 validation.

Our hiring team flagged a suspicion that he leaned on generative AI for live help during the video call, the first soft signal. The hard signal arrived the moment he logged into his corporate account. Our threat intelligence feed matched his username to activity previously associated with North Korean operatives and rated it high risk, and that single match reframed how the team read everything that followed.

Simultaneously, Exabeam’s platform detected a number of anomalies inconsistent with a brand new employee’s first day, and escalating in severity within hours. Incident response quietly isolated and reimaged his laptop before any real damage could be done.

  • The candidate completed applications, interviews and assigned work without raising alarm. In retrospect, what indicators were present, and why did standard screening miss them?

The indicators existed, but they lived in places our screening was never built to read. The driver's license he submitted was either AI-generated or very badly manually modified, and the tell was physical. The image had unique aberrations, such as the ears in the photo which had an unnatural and pixelated modification an artifact that image generators still produce, and a reviewer skims past.

The live AI assistance during the interview was another, since his answers carried a fluency that did not match the natural hesitation you expect when someone reasons through an unfamiliar problem. Standard screening missed all of it because background checks and identity validation confirm whether documents are internally consistent and whether a record exists, and they never ask whether the human attached to those documents is real.

Further fabrication of documents such as I-9 were missed by a 3rd party identity verification company, and validation of (fake) job references was not properly identified.

  • How did AI contribute to the deception? What did the fraudulent documentation involve, and what capabilities does AI introduce that traditional forgery methods lack?

AI showed up at nearly every stage. The fraudulent documentation centered on a forged driver's license we believe was generated rather than physically produced, paired with a stolen identity that gave the paperwork a real history to rest on.

During the interview the candidate appeared to have run an AI copilot feeding him answers in real time, and many of these tools now stay invisible to everyone else on the call even while the candidate shares a screen. What AI adds over traditional forgery is volume and believability together. A skilled forger could always produce one convincing passport, but the craft capped how many operations could run at once.

Generative tools remove that ceiling, so a single actor can fabricate convincing documents and coach themselves through a live technical interview across dozens of applications at once, and the forgery stopped being the bottleneck it used to be.

  • The Five Eyes warning focused on China, while the Exabeam case involved North Korea. Do these actors share tactics and objectives, or do they represent distinct operational models that overlap on method?

They overlap heavily on method while running on different motives, which defenders should sit with. The Chinese operation the Five Eyes described aims at intelligence collection, pulling government and military insight out of people who already hold access.

The North Korean program that hit us and so many others in this industry is funded differently, since much of its purpose is revenue for a sanctioned regime, with intrusion and theft riding alongside the paycheck. The objectives diverge, yet the tradecraft has converged on one toolkit of fabricated identities, AI-assisted documents, manufactured professional histories and the patient relationship-building that lets an operative stay quiet.

When two adversaries with separate goals reach the same playbook, that tells you the playbook works and other actors are already watching.

  • Conventional insider threat programs are built to detect employees who become compromised over time. How should organizations identify a candidate who was an adversary from the point of hire?

Our mindset must shift toward treating the moment of hire as the start of the highest-risk window rather than the end of vetting. Traditional insider programs watch for drift, the employee who gradually turns after a financial shock or a grievance, so they depend on a baseline built over months.

A candidate who was hostile from day one never produces that baseline, which forces you to scrutinize the earliest behavior most closely. In our case, the catch came from putting new accounts under enhanced monitoring and letting an AI agent correlate scattered signals that no single alert would have justified escalating.

The working principle is to give hiring workflows and new-hire activity the same suspicion you already apply to production access.

  • Where should accountability for this threat reside within an organization? Is it a security function, an HR function, or a gap that persists because ownership is unclear?

Accountability most often lives in the gap right now, and that gap is exactly why the threat works. Hiring sits with HR and talent acquisition, who are measured on filling roles quickly and are not equipped to run identity verification at an intelligence-grade level.

Detection sits with security, which usually gains no visibility into a candidate until that person already holds a badge and a laptop, and the adversary exploits the seam between the two.

The workable answer is shared ownership with a clean handoff, where security sets the identity and behavioral standards hiring must meet and stays involved through the first weeks of employment rather than inheriting the problem once onboarding closes.

  • Many mid-sized companies lack dedicated threat intelligence resources. What practical measures can such organizations implement to reduce their exposure?

Useful defense does not require a dedicated threat intelligence team. The interview itself is the cheapest control available, and small changes make it far more revealing.

Underspecifying a problem on purpose shows whether a candidate asks clarifying questions like a real engineer or simply produces a confident answer and switching the problem partway through tests whether they adapt or whether something is feeding them responses.

Asking for an external webcam that shows the workspace instead of a shared screen removes one of the easiest hiding spots for an interview copilot. Beyond hiring, the highest-leverage move is placing every new employee on a watchlist for closer monitoring through their first weeks, which costs configuration time rather than budget.

Even a basic, low-cost threat intelligence feed would have surfaced the username match that broke our case open.

  • What is the most contested prediction on this issue, one that many security leaders would currently dispute?

My contested prediction is that within a couple of years the verified human interview, run live and in person for any role with meaningful access, returns as a security requirement. Many security leaders will fight that because it breaks the remote-first hiring model they spent years optimizing.

The objection I expect is that it does not scale and shrinks the talent pool, and those concerns are legitimate. My counter is that the economics have already flipped for high-access roles, since the cost of onboarding a single fabricated adversary now dwarfs the friction of one in-person verification step.

The deeper claim underneath it is that remote identity verification as we practice it today is no longer reliable for sensitive positions, and AI is what made it unreliable. Most security leaders are not ready to say that out loud yet.

Google logo on a black background next to text reading 'Click to follow TechRadar'

Experts flag new scam targeting fans seeking tickets for Celine Dion concerts

  • Group‑IB warns of scams exploiting Celine Dion’s concert comeback, with fraudsters selling duplicate Ticketmaster tickets and spoofing sites like AXS and Paris La Défense Arena
  • Scammers embed themselves in Facebook fan groups and marketplaces, even using voice messages to build trust and make fake offers seem legitimate
  • Fans are advised to only buy from official distributors, verify tickets in person if using resellers, and contact banks to dispute charges if scammed

Celine Dion is back, and hackers are already trying to exploit the fact for their own financial gain, experts have warned.

A report from security researchers Group-IB has claimed there are numerous scam campaigns all across the internet and social media, looking to exploit gullible fans and steal their money.

Its aptly named “The Scam Will Go On” report said it saw scammers lurking in Facebook Groups, Facebook Marketplace, and other fan-centric spaces, offering concert tickets for sale. The tickets themselves, hosted on Ticketmaster, are valid. However, the scammers only have a few tickets which can be redeemed by the first person who reaches the venue. Everyone else will be denied entry, since their tickets will already have been used.

How to avoid getting scammed

But that’s not the only scam. Some people don’t want to pay an unknown third person via wire, and would prefer to purchase the tickets directly from a service.

For those people, the scammers created entire websites, spoofing ticketing distributors such as AXS and Ticketmaster. Group-IB also saw fake websites spoofing Celine Dion and Paris La Défense Arena, the stadium where the concert will take place.

“We see that such an event generates excitement and provides scammers with another opportunity to make a fortune at the expense of unsuspecting fans,” Group-IB warned.

“Scammers are using increasingly sophisticated techniques, such as embedding themselves into social networking fan groups and speaking directly to their victims via voice messages to make the interaction more personal and gain their victims’ trust more easily. Furthermore, official ticketing platforms are being misused to make scams seem legitimate.”

The researchers recommend fans only visit official websites and those of official distributors, and if they absolutely must buy from a reseller, to make sure they’re purchasing a physical ticket, in person. Those that fell for the scam should call their bank and lodge an objection on their credit card.

Steam fan finds 'cheap SSDs' to make retro 'game cartridges' system — the only problem is 2026 is the worst year in history to do it

  • A Steam user has found a way to store games on SSDs with an auto-navigation and auto-start script
  • These are effectively physical 'game cartridges' complete with key art
  • However, costly SSDs means this is a pricey endeavor (the Steam gamer was lucky enough to pick up used drives on the cheap)

Physical copies of PlayStation games are coming to an end from January 2028, and as the backlash around that continues, a restoration of physical media on PC has been discovered — and it's novel to say the least.

A Steam user on Reddit has managed to store games on 'cheap 2.5-inch' SATA SSDs, effectively acting as old-school 'game cartridges' with key art, and a script that auto-navigates Steam to each game's page. The user also notes that automatically starting games from each drive is possible.

This comes amid a significant uproar from gamers following the revelation of Sony's plan to eradicate physical game discs, supposedly by the time its next PlayStation console arrives. It's a very controversial move that has united gamers across all platforms to fight to retain discs and to ensure game ownership remains intact.

With that said, physical media for PC has been dead for a long while, since a modern desktop PC doesn't come with a disc drive, and there are hardly any publishers selling physical copies for the platform.

With most games only accessible digitally on PC, in theory those titles can be taken away from buyers at any time. The trouble is that consumer-friendly figures like Gabe Newell, who leads Valve, the owner of Steam, won't be in charge forever.

So in the future, under new leadership, it's possible more anti-consumer measures might be introduced, or other aspects of PC gaming that consumers dislike, such as DRM (like Denuvo).

Leon S Kennedy, Evelyn Parker, and Isaac Clarke

(Image credit: Capcom / CD Projekt Red / EA)
Steam Game Cartridges from r/pcmasterrace

Imagine if this 'game cartridge' system was adopted by PC game publishers? It's a smart idea, and a nice thought, but clearly not a realistic one. For starters, it'd be a prohibitively expensive method of reintroducing physical PC game copies.

Of course, platforms like Epic Games and Steam require users to be logged in and have their app installed to play games, so it's still a long way off true game copy ownership, anyway.

However, this concept would be paired perfectly with GOG, a platform that is DRM-free and doesn't require the launcher to play purchased games — in other words, you fully own purchased games on GOG.

Admittedly, publishers releasing PC game cartridges in the form of SSDs is a pipe dream, especially with the current state of the hardware market, and the RAM crisis, complete with skyrocketing SSD prices.

The idea comes at the wrong time, then, but if the RAM crisis ever settles down, then maybe this is something we'll see more PC hobbyists doing — and perhaps even the odd publisher.

New phishing campaign hits LastPass, Bitwarden users - password manager customers warned not to fall for this scam

  • Attackers are spoofing LastPass and Bitwarden with phishing emails from fake newsletter domains, tricking users into signing bogus DocuSign documents
  • Victims are redirected to malicious “compliance” domains flagged by Microsoft Defender and Cloudflare, already taken offline
  • Neither password manager was breached; this is domain spoofing, and users are urged to verify sender addresses and domains before clicking links

Criminals have been found impersonating popular password managers LastPass and Bitwarden online in an attempt to trick users into sharing their login credentials, and thus access to a treasure trove of passwords and other secrets.

LastPass recently issued a warning to its customers, raising awareness of the ongoing phishing campaign.

However the scam also now seems to have spread to other password managers, with Bitwarden customers also apparently being targeted.

Passwords are safe

In the campaign, LastPass users received emails from the address “hello@lastpassnewsletter.com”.

This address does not belong to LastPass, and is in no way affiliated with the password manager. In the message, the victims are told that the company’s security policies have been updated, and that they should navigate to a specific landing page and sign a DocuSign document.

The email comes with a ‘Review & Access Terms’ button which, if clicked, redirects the victims to lastpasscompliance[dot]com, yet another domain unaffiliated with the password management platform.

BleepingComputer claims this domain has already been flagged as malicious by both Microsoft Defender for Office 365, and Cloudflare and is currently offline.

Digging deeper, the journalists uncovered another campaign, almost identical, but now targeting Bitwarden users. In this case, the victims were being mailed from the “hello@bitwardennewsletter.com” addresses and were being redirected to bitwardencompliance[dot]com. Identical methodology, just slightly personalized.

It is important to note that neither LastPass nor Bitwarden were compromised as part of this attack.

The companies’ infrastructure is intact, and the passwords are safe. This is a typical domain spoofing attack in which the crooks purchase a domain similar to the legitimate one, in hopes that the victims won’t spot the difference.

As usual, the best course of action is to always be skeptical of incoming emails, and to double-check the domains and email addresses from which they are sent. It is also good to cross-reference these emails with any older messages that are proven to be authentic, to see if the domains and addresses match.

Hundreds of GitHub repos found posing as real software to push malware

  • ArcticWolf uncovered 292 malicious GitHub repositories spoofing legitimate tools and products, delivering a new BoryptGrab infostealer variant
  • Malware steals from 19 browsers, 32 crypto wallets, messaging apps, Steam, and Windows Credential Manager, and uniquely bypasses Chrome’s App‑Bound Encryption via code injection
  • Most repos have been removed, but some remain active; GitHub’s popularity makes it a prime target, underscoring the need to vet code before use

Russian actors have reportedly created hundreds of malicious GitHub repositories masquerading as legitimate software but acting as a dangerous infostealer.

Cybersecurity researchers ArcticWolf discovered the campaign after finding their own products spoofed as part of the attack.

In total, the researchers found 292 fake repositories, spoofing things like security products, developer tools, macOS utilities, games, and more. Each repository contained a README file with the download URL.

Obviously malicious

Victims who download the program get a variant of the BoryptGrab infostealer family that grabs data from 19 browsers (passwords, cookies, payment information), 32 cryptocurrency wallets, Telegram, Discord, and Steam sessions, credentials for Meta’s Max, data from Windows Credential Manager, and more. It can also exfiltrate files from Desktop and Documents, and grab screenshots.

While most of the features can be found in other BoryptGrab variants, this one is unique in a sense that it can bypass Chrome’s App-Bound Encryption through direct code injection into the browser process.

While it hasn’t been specifically said that the threat actors are Russian, the compressed data is later sent to a Russia-based command-and-control (C2) infrastructure.

What’s also worth mentioning is that the malware is not designed to last. It has no anti-analysis layer, and doesn’t even try to hide itself in any specific manner. It does not establish persistence and simply tries to grab as much sensitive data as it can on the first attempt.

The attack, which seems to have started in the final days of June, is almost thwarted now, since most of the malicious repositories have been removed from GitHub. Citing “researchers”, BleepingComputer reported that several dozen still remain active, though.

Because of its importance and popularity in the open-source community, GitHub is currently one of the most targeted platforms on the internet, which is why it’s important to double-check and vet every piece of code before it’s applied to a project.

Inkjet-printed OLED screens are reportedly in mass production at long last — here's why that's great news for monitor, laptop and even TV pricing

  • TCL CSOT is reportedly now mass producing the first inkjet-printed OLEDs for consumers
  • MSI just revealed a new 27-inch monitor which seemingly uses this 4K panel
  • Inkjet printing is a more affordable way of making OLEDs and it will usher in cheaper monitors and laptops, and eventually TVs further down the line

TCL CSOT has seemingly taken a big step towards putting inkjet-printed OLED panels in the homes of consumers, and mass production of these screens is now reportedly underway.

OLED-Info reports that the Chinese manufacturer has kicked off production with an initial 27-inch 4K panel with a refresh rate of 120Hz. It offers a brightness of up to 300 nits and 99% coverage of the DCI-P3 color gamut (meaning lifelike and accurate color representation).

This inkjet-printed screen is destined for monitors, but bigger panels for the likes of TVs are expected to be in the cards for the future. For starters, though, we're looking at production for monitors and also laptop OLEDs.

This is still the very early stages for TCL, and OLED-Info clarifies that we are only talking about 'low volume' production on the firm's Gen 5.5 inkjet line for now. Still, it's an important step to take, but producing the panels is one thing, and it'll take some time for these to be incorporated into monitors which are then shipped to retailers where consumers can buy them.

Note that the Gen 5.5 inkjet line has produced OLED panels before, just not displays destined for consumer products (they were screens for commercial use in the medical field).

It seems that the freshly announced MSI Pro Max OLED 271UPJW12 uses this TCL 4K panel, although that isn't explicitly stated in the press release for the new model published by TechPowerup. All the specs match up, though, and it couldn't really be any other screen anyway – and this revelation is another sign to back up OLED-Info's contention that mass production is now up and running.

MSI boasts of the monitor: "With a 164 PPI density and an optimized RGB Stripe sub-pixel layout that closely resembles the uniform RGB structure of traditional LCDs, this advanced design effectively eliminates color fringing, optimizing text and image clarity."

We don't get a price from MSI, but that's not surprising at this stage, because as noted, the release is likely still some way off yet.

Analysis: what's the big deal with inkjet-printed OLEDs anyway?

MSI Pro Max OLED 271UPJW12 monitor promotional image

(Image credit: TechPowerUp / MSI)

As we've covered in the past, there are some distinct advantages with using an OLED printed by an inkjet compared to traditional (Fine Metal Mask) OLED panels. They are more power-efficient, and the inkjet-printed (IJP) OLEDs will also have a longer lifespan, but most crucially, they're cheaper.

TCL has previously told us that these IJP panels are 20% cheaper than existing OLEDs (and they can be made 30% faster, too). Analyst firms believe that these printed panels could be up to 35% cheaper in the future, when production is higher volume and more refined (with less waste).

The upshot should be OLED monitors which are a good deal more affordable, not to mention laptops with OLED screens that hit cheaper price points – and as noted, TVs eventually, too. The lower power usage will also be a major benefit for notebooks in terms of extending battery life, given that the display is one of the biggest drains on the battery.

The overall affordability of OLED will also be helped by TCL's inkjet-based creations, because the dominant panel makers – LG Display and Samsung – will be forced to be more competitive with their pricing. Add to that the emergence of BOE's Generation 8.6 panels, which went into mass production last month – again offering a more economical way to produce OLEDs thanks to much larger substrates – and this poses yet more competition, meaning there'll be some distinct downward pressures on OLED pricing.

The catch is that it will take some time for this to happen, especially in the world of bigger screens for the likes of OLED TVs – but make no mistake, it is happening.

I tried Android's underrated desktop app, and it's transformed the way I work

For the longest time, I thought that, despite their annoyances, iPhones had something big over the best Android phones: PC connectivity. I'd always seen iPhone and Mac-owning friends quickly send files between the two, and assumed it was an Apple-exclusive feature.

As it turns out, this isn't true. Android users can use a Windows app that brings loads of really useful features — and it's really underutilized, which is why a tech journalist like me hadn't heard of it.

This software is called Phone Link, and we've got a guide on how to connect your Android phone to a Windows PC using Phone Link elsewhere on TechRadar. I downloaded it about a year ago, largely out of duty to test every tool, appliance, and gadget I could get my hands on. I was expecting it to last a weekend.

A year on, though, and Phone Link has become such a useful part of my workflow that I'd forgotten it's something not everyone's heard about. It's such a natural part of the way I use my phone and computer that I'd totally forgotten it was something I initially downloaded to test!

Well, no longer: TechRadar has let me wax lyrical about Phone Link, and I'm going to give the tool its time in the sun.

Sending photos from phone to PC

A screenshot of Phone Link on Windows, showing a photo of some headphones.

(Image credit: Future)

For the most part, whenever I want to connect my phone to my PC, it's to move pictures between the two devices.

As a smartphone journalist, you can understand that I'm sending snaps from my phone to my computer a lot. Sometimes it's camera samples from a mobile I'm testing that I want to upload for a review. Occasionally, I want to back up pictures I really like before I wipe a phone and send it back to the company.

The most frequent use case, though, is to transfer to my PC pictures I've taken on one phone, of another. I use smartphones to do review photography, and it's a great way to test out a phone I'm reviewing.

Before Phone Link, I'd have to use a USB cable to connect my phone to my computer — approving the connection on my Android's end, because they're always annoyingly suspicious — and drag and drop all the relevant pictures into a folder on my computer. It's not an especially onerous process — it's a lot quicker than when I used to use Google Drive to transfer pictures, for instance — but it takes a little while of fiddling with my phone and digging out a cable to work.

Not so with Phone Link. Its Photos tab shows a big old list of all the pictures you've taken recently, giving you options to save them to your PC, open them in an editing app, and share them with others.

These pictures appear as soon as you take them, as long as your phone is on the same Wi-Fi as your computer. I've become used to taking photos in one room of my home, and entering my office, to see them linked up on Phone Link, ready for an edit. When I've got PC notifications turned on, I can even hear the 'bong' of my computer telling me they've arrived.

Phone Link also lets you browse the contents of your mobile in the Files tab, where it appears in the Devices and drives list alongside any cloud or local drives you have. I don't use my phone to handle non-photo files, but it's a nice touch that'd be really useful if I were in another line of work.

Apps on my PC

The Windows Phone Link Apps menu on the right, and on the left the window for Too Good To Go.

(Image credit: Future)

Ostensibly, one of the main uses for Phone Link is that it lets you open your smartphone apps on your computer. Its Apps page shows you a massive list of every one you have installed on your mobile, and clicking on it opens it in a window.

This doesn't override anything you have going on on your phone; if you're using it as a second screen to watch a YouTube video or act as a music player (one of many ways you can repurpose an old Android phone), the app will open in your PC window alone.

When I first started Phone Link, I tried using it for everything, but often bounced straight off. In many circumstances, using a smartphone is simply more intuitive than using a mouse and keyboard, given that phone apps are designed for thumbs. But over time, I've found a few uses of Phone Link's app windows that are genuinely handy.

As mentioned, one of those uses is as a music player. I can let Spotify hang around as a spare window, ready to skip tracks or change playlists when I want. It's also useful as a way to check apps that don't have PC equivalents, like Too Good To Go or Mubi Go, or ones that do have web functions but are easier on the phone, like my national health service's app.

There's one way that Phone Link saved me hours, though. When I used to work for a company that didn't let you use your work Gmail account on personal computers, Phone Link was my workaround to still see emails on my PC. This saved me ages each day; time that'd otherwise be taken up checking and replying to emails on my phone, or trying to get my decrepit work laptop to turn on.

Naturally, you can manage your calls and texts via Phone Link too. Personally, I don't think I've sent an SMS or made a non-WhatsApp voice call since the 2010s, but I'm sure there are some people who'd find this handy.

I also appreciate a notification list down the left side of Phone Link. This transforms it from being software solely for controlling your mobile to a veritable hub of information from your handset. I'll often keep it up on my second monitor; it makes good use of its space.

Controlling my phone from my computer

A snippet from the Windows Phone Link app, showing phone controls.

(Image credit: Future)

As mentioned, you can use your computer to control your mobile's apps via Phone Link, but you can also use it to change the actual settings of the device itself, which proves itself useful in an entirely different way.

Phone Link lets you monitor your phone status; I can see how it's connected to other devices, what battery it's on, and whether it's currently paired with Phone Link or not. I can even see a little representation of what my wallpaper currently is. All useful to a small degree, but the charge is the only one of those that's seriously useful.

What's more important are the status controls. You can toggle between vibrate, sound, and silent, turn Do Not Disturb on and off, and turn on the media player.

From a cursory mention of the tools, these might not sound that important, but I've found them really useful in a pinch. I'm constantly forgetting to mute my phone before I go on a video meeting, and a quick click of the Do Not Disturb button means I'm not going to have unexpected calls.

As a lazy person, I also love the fact that you can use Phone Link to play a sound from your phone; I'm always doing this instead of spending five seconds actually looking.

My one gripe with Phone Link is that I still need my phone with me to use it. When you start using it each session, you're required to unlock your device and approve the connection. But this is a small price to pay for the transformational effect it's had on my workflow — and I hope that you, too, consider giving it a try.

'No new vulnerability is needed to bypass UEFI Secure Boot': Experts find attackers can exploit decades-old flaws to gain access to key systems

  • ESET discovers 11 vulnerable UEFI shim bootloaders signed by Microsoft, allowing attackers to bypass Secure Boot and deploy malicious bootkits
  • Any UEFI system trusting Microsoft’s 2011 third‑party certificate could be exposed, potentially billions of devices; attackers can bring old trusted shims to new systems
  • Microsoft has revoked the vulnerable shims, and users should apply the latest UEFI revocations (Windows auto‑updates, Linux via LVFS) to block exploitation

Cybersecurity experts from ESET have discovered 11 vulnerable UEFI shim bootloaders, all signed by Microsoft, which could allow threat actors to exploit ancient vulnerabilities and bypass UEFI Secure Boot, deploying all sorts of malicious bootkits.

A shim is a small, intermediary bootloader that works as a bridge between a computer's firmware (UEFI) and the operating system's bootloader. Its primary purpose is to allow operating systems to work with UEFI Secure Boot without having Microsoft sign every Linux bootloader individually.

Any UEFI-based machine that trusts the Microsoft Corporation UEFI CA 2011 third-party UEFI certificate authority (CE) certificate, regardless of the operating system, was said to be vulnerable to the shims (versions 0.9 and older). That would put the number of potentially vulnerable devices in the billions, since almost all modern x86 PCs use UEFI firmware, and most of them trust the Microsoft Corporation UEFI CA 2011 certificate out of the box.

Revoking the shims

However, ESET reported its findings to CERT/CC and the vulnerable UEFI applications were all revoked.

The shims come from different tools such as PC diagnostic software, Linux distribution, and other UEFI-based utilities, the researchers explained. They also added that, since the attackers can bring their own vulnerable shims to any UEFI system with the Microsoft third-party UEFI certificate enrolled, they can exploit systems that are, at first, not affected.

To block the vulnerable shims, users should apply the latest UEFI revocations from Microsoft, it was said. While Windows systems will most likely do it automatically, Linux systems users should do it through the Linux Vendor Firmware Service.

“What makes these old shims dangerous is not a novel vulnerability; it’s that no new vulnerability is needed to bypass UEFI Secure Boot,” says ESET researcher Martin Smolár, who discovered the vulnerable shims.

“An attacker needs no complicated exploitation primitives — only a copy of an old, still-trusted but unrevoked shim binary and a basic understanding of how UEFI shims work. That is enough to bypass such an essential security feature as UEFI Secure Boot."

Microsoft just released its biggest Patch Tuesday ever, with a mammoth 622 fixes including three dangerous zero-days

  • Microsoft’s July 2026 Patch Tuesday fixed a record 622 vulnerabilities, including 58 critical, two exploited in the wild, and one publicly disclosed, plus 428 Chromium bugs
  • Actively abused flaws include CVE‑2026‑56155 (AD FS privilege escalation) and CVE‑2026‑56164 (SharePoint privilege escalation), alongside notable issues in BitLocker and Copilot
  • Surge in fixes is linked to Microsoft’s use of Anthropic’s Mythos AI, with patch volumes rising sharply since its adoption

Microsoft has released its July 2026 Patch Tuesday download, marking another record-breaking update, addressing hundreds of flaws across the ecosystem.

The release, which is currently rolling out to Microsoft users, fixes a staggering 622 vulnerabilities, including 58 critical-severity ones, two that were observed as being abused in the wild, and one which has already been publicly disclosed.

On top of that, Microsoft shipped fixes for another 428 Chromium bugs, as well.

A jump in numbers

There are simply too many vulnerabilities to mention all of them, however two that are being exploited in the wild are CVE-2026-56155 and CVE-2026-56164. The former is described as an “Insufficient granularity of access control in Active Directory Federation Services (AD FS)” bug, which allows an authorized attacker to elevate privileges locally. It carries a severity score of 7.8/10 (high).

The latter is a “Missing authentication for critical function in Microsoft Office SharePoint” bug that allows an unauthorized attacker to elevate privileges over a network. Microsoft assigned it a medium severity score (5.3/10), but the National Vulnerability Database gave it a 9.8/10 (critical).

Other notable mentions include CVE-2026-50661, a protection mechanism failure in Windows BitLocker that allows unauthorized attackers to bypass a security feature with a physical attack, and CVE-2026-48561, an improper neutralization of special elements used in a command in Microsoft Copilot, that allows an unauthorized attacker to execute code over a network.

If you think fixing 622 vulnerabilities in a month is a lot, you’re absolutely right. It’s well above what Microsoft is used to do, and this is most likely due to the company now using the fabled Mythos - Anthropic’s cybersecurity-oriented AI.

In June 2026, roughly a month and a half after the release of Mythos, Microsoft fixed 206 flaws, which raised eyebrows because it was significantly above the company’s usual amount of bugs fixed.

In May it fixed 120 flaws, in April 167, and in March - 79.

Microsoft deletes man’s hacked OneDrive with 25 years of photos and games — as 'irreversible' action prompts him to bemoan ‘I relied on Microsoft to keep that safe’

  • Microsoft deleted a user’s OneDrive account after it was compromised
  • This resulted in the loss of 25 years’ worth of photos and games
  • The incident is a reminder to use multiple backup solutions

How much do you have stored in your Microsoft account? Consider all the photos and documents backed up to OneDrive, the games and apps linked to your username, and all the rest. Many of us have a lot stored there, but as one Microsoft user recently found out, it can all be taken away in an instant — with Microsoft itself doing the deleting.

Posting on X, Joshua Khane related how a recent hack of their account led to Microsoft taking the nuclear option and removing 25 years’ worth of data, including photos of their infant son and “thousands of Euros spent on games.”

Khane shared an email from Microsoft explaining that, since “unauthorized access occurred” on their account — meaning a likely compromise by hackers — “we have permanently suspended the account.” Microsoft confirmed that “this action is irreversible … Additionally, if you had files stored in OneDrive, those files are no longer accessible. Due to encryption and privacy safeguards, even our engineers cannot retrieve them.”

The move left Khane incensed, with the disbelieving user condemning Microsoft’s decision not to restore their account: “One of the biggest companies ever couldn’t do that so they just deleted that sh*t like it was nothing??”

“Even though the security could be tighter from my side (lessons are learned),” they added, “it bothers me the most that Microsoft says that they cannot recover my account and suspended it … Thousands of Euros are gone down the drain as I’ve lost all my games also! Couldn’t back those up and I relied on Microsoft to keep that safe, even if I got compromised!”

How to keep your data safe

Businessman using a computer to backup storage data

(Image credit: Deemerwha studio / Shutterstock)

After the saga was posted on Reddit, other users chimed in with similar stories of their own. “Happened to me also,” said one user. “I had payment proof and everything going back 20 years. They said sorry, best we can do is lock your account for good.”

Another had a piece of advice for Khane: “When this happened to me, I created the new account and sent an email to them (on the same thread) with the new account info. They basically cloned the old account into the new one and I got everything back.” Elsewhere, many users recommended Khane take legal action against Microsoft.

If you want to avoid a similar fate, it’s important that you don’t just back up your important documents to one source — be that cloud storage like OneDrive or an external storage drive. If something goes wrong, your only copy has vanished into the ether.

Instead, build redundancy into your backups. Use a cloud backup service like Backblaze and a local NAS or offline archive drive. If possible, ensure your backups are in different physical locations, including one off the premises.

As Redditor Linesey rightly suggested, “Get a NAS, get an off-site location like a safe deposit box for cold storage, and then use the cloud if you really want to, as another layer.” That way, you’ve got at least one fallback option if a firm like Microsoft decides to delete your data without warning.

It’s also worth setting up passkeys and multi-factor authentication on your accounts and using one of the best password managers to strengthen and store all your logins. That way, you make it harder for bad actors to gain access to your account — and less tempting for Microsoft to hit the big red button, with irreversible consequences.

New Windows 11 update is a big one — these are my top 4 features, including the ability to pause updates indefinitely

  • Windows 11's July update has arrived
  • It packs some smart features, including pausing updates at length and a new recovery option
  • This patch also cures a nasty bug that slowly eats more and more drive space, but there's an issue to be aware of for Dell laptop owners

Microsoft has released its monthly patch for Windows 11 and the July update is a biggie, packing a feature that I've been awaiting for quite some time.

That would be the ability to pause updates on Windows 11 Home – beyond just a short period of time, which has been the only choice to date – and there are some other impressive additions from Microsoft here.

I'm going to pick out my top four features introduced by the July update, as well as rounding up some of the other more notable changes here. I'll also highlight an important bug fix that has been deployed for a nasty flaw that eats your drive space – along with a warning for some of those with a Dell laptop (who may not get this update for a good reason, as you'll see).

As ever, these changes were seen in the last optional update (June preview), and most of these features are being rolled out gradually, so you may not see them right away after installing this update (indeed, you may have to wait a while based on how the update winds blow regarding your exact PC configuration).

1. Pausing updates

Checking windows update on laptop screen close up view

(Image credit: Shutterstock)

Sometimes you want to hold off installing an update because of a bug that you're nervous about potentially affecting your system, and up until now, Windows 11 users have only been able to avoid any given update for five weeks.

Okay, so that's a fairly long time, but what if the bug is one of those persistent and niggly affairs that Microsoft takes an age to fix? You may want to delay the update beyond five weeks, and now you can. The catch is that you'll need to continually renew the delay for every 35-day period, but nonetheless, you can now keep an update at bay for as long as you want. (Well – until you're forced to update to a new version of Windows 11, that is, when support runs out for your current version).

2. Point-in-time restore

A young woman is working on a laptop in a relaxed office space.

(Image credit: Getty Images)

Another neat addition is point-in-time restore, a new recovery option that you can employ when something bad happens to your PC and you can no longer reach the desktop. Point-in-time restore lets you roll back a non-functioning system to a previous working state. It reverts to the "full system state" meaning that all your apps, files, and settings are recovered as captured at that previous time.

Hopefully this is a feature that you'll never need, but if you do, you'll be very glad of it. Note that the system backups obviously take up drive space, with older backups automatically deleted after 72 hours by default. Also, if you have a system drive that's smaller than 200GB, you'll have to enable this feature yourself (as it won't be turned on automatically due to potential space issues – note that you can specify a maximum amount of storage space used).

3. Fewer annoyances with widgets

Windows 11 on a laptop

(Image credit: Windows/Unsplash)

The July update is making the widgets panel 'quieter' by which Microsoft means that it has cut out a lot of clutter. The main change is that by default the panel just displays your widgets and Microsoft has got rid of the promotional nonsense in terms of ads and the MSN feed. Notifications and taskbar badges are also minimized by default, and widgets no longer open when you hover over them.

There are some other streamlining moves here, and even if you don't use widgets, I think this is a noteworthy change as it shows the direction Microsoft is now heading in with Windows 11 – chilling out on the upselling as was previously promised (if not entirely banishing it).

4. Screen tint

A laptop with the Windows 11 desktop on screen, glowing, while on a work desk

(Image credit: Shutterstock/Ham patipak)

Windows 11 has been graced with a number of accessibility improvements in the July update, first of which is a new screen tint ability. This does what it says on the tin, allowing you to tint the screen with a choice of colors to help reduce eye strain, or to make text more easily readable. You can adjust the tint intensity, and this is a very useful addition that'll save people from downloading a third-party app to get these kinds of color overlays.

Other features in the July update

Windows 11 Linux app

(Image credit: TechRadar)

There's quite a lot going on here aside from the above major moves, and that includes Microsoft boosting the speed at which File Explorer launches (helping Windows 11 to feel more performant overall).

There's a whole lot of work on the Bluetooth front, too, as Microsoft notes: "This update improves reliability and performance when connecting to and using Bluetooth devices." That includes better driver stability, improved audio routing for calls via Phone Link, and more.

File Explorer has also been honed to be more reliable, and Microsoft has implemented a performance tweak to the Background Intelligent Transfer Service (BITS) that means PCs will shut down more promptly. If you've ever sat staring at your computer while it takes 20 seconds to shut down, wondering what on earth it's doing, that kind of behavior will hopefully be a rarer occurrence going forward.

A major bug fix – and Dell laptop problems

There's some good news for those of you who have been suffering at the hands of a mysterious bug that eats storage space (due to an out-of-control database file). This is fixed with the July update (the cure was in the June preview before it), so you can grab this to resolve the issue (hopefully).

There's some bad news on the bug front, though, namely that you won't get this update on some Dell devices with Intel CPUs, as Microsoft has blocked it due to the July patch causing all sorts of weird issues. I say it's bad news, but at least Microsoft caught the problem and has prevented the update from being piped to those machines.

Microsoft informs us: "This update might not be available for a limited number of Dell devices with Intel processors due to an incompatibility reported by Dell that can potentially cause unexpected shutdowns, poor performance, increased heat, and battery drain. We are working together with Dell to prevent the affected models from experiencing the issue and plan to release a resolution for affected devices in the coming days."

So, if you were wondering why you couldn't get this patch on your Dell laptop, now you know. You'll just have to sit tight for now until Microsoft and Dell get this ironed out.

'Ineffective and useless': the UK government is proposing a midnight social media curfew for 16 and 17-year-olds, but there's an easy loophole

  • The UK is proposing a social media curfew for ages 16 and 17
  • Access would be blocked from midnight to 6am by default
  • However, teens will be able to change these settings if they wish

Having already announced plans to ban under-16s from social media apps early next year, the UK government is now proposing a midnight social media curfew for young people aged 16 and 17 — though parents seem less impressed with this latest idea.

As reported by the BBC, the suggested curfew would run between midnight and 6am, and would be combined by certain "addictive" features being disabled in apps like Instagram and TikTok at any time of day. Those features would include infinite scroll, for example, and videos auto–playing when loaded.

The measures will be "crucial in helping young people get the sleep they need, focus on school and college, and spend more quality time with family and friends," according to Technology Secretary Liz Kendall. They're also intended to provide a gentler 'on ramp' to these apps for kids turning 16, having previously not had any access.

Changes are also going to be enforced for AI chatbots, which will be required to encourage regular breaks for under-18s, and to have safeguards in place to prevent "dangerous, misleading, or unverified mental health advice" from appearing. The moves are being made after a pilot scheme involving more than 300 teenagers and their families.

Teens can opt out

Keir Starmer to announce midnight social media curfew for teenagers from r/ukpolitics

There's not much detail in the government's announcement, so questions around mechanisms and timing have yet to be answered. It's possible the target date for this is the same as the under-16s social media ban – springtime (March, April, May) in the UK.

What's different to the social media ban is that the curfew timings and the removal of addictive features are going to be optional. While app developers will be told by the government to have these restrictions in place by default, teenagers will have the option to disable them if they wish.

Reactions on Reddit suggest the measures will end up being "ineffective and useless", with one poster comparing it to speed limit warnings for cars — very easy to ignore. Commenters also point out that this may require more age verification, and that existing parental control tools already exist to block social media access for kids at certain times.

"How is it any of the government's business what time anyone uses social media?" reads one post, while another calls into question allowing 16-year-olds to join the army but not letting them on social media past midnight.

First VPN administrators sanctioned by US Treasury over ransomware attacks

  • The US Treasury has sanctioned First VPN's administrator for aiding ransomware attacks on American infrastructure
  • Another suspect was targeted for selling "cryptors" that cloak malware from security systems
  • The move follows a May 2026 takedown by European law enforcement and the FBI that seized the VPN's infrastructure

The United States government has officially issued sanctions against the operators of a notorious free virtual private network, escalating a global crackdown on digital infrastructure used to facilitate ransomware attacks.

On Monday (July 13), the US Department of the Treasury’s Office of Foreign Assets Control (OFAC) designated First VPN Service (also known as 1VPNS) and its Ukrainian administrator, Dmytro Rashevskyi, for abetting cybercriminals. The service, which has operated since 2014, was heavily favored by ransomware gangs targeting American hospitals, municipalities, and businesses.

While the best VPN services are designed to protect everyday consumer privacy, rogue networks like First VPN provided malicious actors with the tools to "hide the origins of their attacks, deploy malware, and manage exfiltrated data," according to a Treasury Department press release.

As part of the same action, the Treasury also sanctioned Yegeniy Vladimirovich Silayev, a Belarusian national accused of selling "cryptors" to ransomware operators.

While Silayev is not directly affiliated with First VPN, his inclusion in the sanctions package highlights a broader strategy of targeting the entire cybercriminal supply chain. Cryptors are tools specifically built to disguise ransomware as harmless files, preventing security systems from detecting or deactivating the malware.

A haven for cybercriminals

Code Skull

(Image credit: Shutterstock)

The US Treasury's latest move is an update to an ongoing international operation against First VPN.

In a massive May 2026 takedown, a coordinated effort led by European law enforcement agencies and the FBI successfully seized the service's website and server infrastructure.

Prior to the takedown, Rashevskyi aggressively marketed First VPN on dark web forums. To lure cybercriminals, he promised total anonymity and boasted that the network "does not keep logs of users' identities or activities, and that it refuses to cooperate with law enforcement investigations into illegal activity originating from the servers it rents to customers".

According to the US Treasury, Rashevskyi went to great lengths to keep the operation running. He utilized false identities, such as "Maksim Sorin" and "Roman Chabanenko," to "buy infrastructure from companies that might otherwise refuse to do business with him because of complaints of abuse from internet service providers about illegal activity originating from 1VPNS servers".

Disrupting the cybercriminal ecosystem

This latest wave of sanctions was coordinated alongside the United Kingdom's Foreign, Commonwealth & Development Office (FCDO) and carries severe consequences for the designated individuals.

Under the new sanctions, all property and interests belonging to Rashevskyi and Silayev within the US are blocked, and US citizens are strictly prohibited from engaging in any transactions with them. Beyond the immediate financial freeze, OFAC sanctions serve as a massive reputational blow designed to choke off future revenue streams.

By focusing on the service providers and tool suppliers who facilitate these attacks, rather than just the ransomware operators themselves, authorities are aiming to maximize their impact and disrupt multiple gangs at once.

"Under President Trump's leadership, Treasury is using every available tool to disrupt the cybercriminal ecosystem and protect the American people," said Gene Lange, who is performing the duties of the Under Secretary for Terrorism and Financial Intelligence. "We will continue targeting the actors who enable ransomware attacks against Americans and our critical infrastructure".

White House launches 'Gold Eagle' cybersecurity clearinghouse to share and patch AI-discovered software flaws

  • White House, Treasury, DHS and DoW come together to launch Gold Eagle scheme
  • The initiative will prevent duplicated work and prioritize vulnerability remediation
  • Gold Eagle will also help to identify which systems could be at risk

The US Government has launched Gold Eagle, a new clearinghouse which looks to centralize vulnerability discovery and remediation against a backdrop of evolving AI-powered security threats.

Gold Eagle will serve as a central hub between federal agencies, AI developers, open-source software developers and critical infrastructure companies, in a bid to increase the speed of vulnerability discovery and prevent major incidents from occurring in the first place.

The scheme came about under President Trump's June 2 2026 executive order 'Promoting Advanced Artificial Intelligence Innovation and Security' and represents collaboration between the Treasury, the DHS' Cybersecurity and Infrastructure Security Agency (CISA) and the Department of War.

US Gold Eagle scheme addresses growing vulnerability exploitations

Under the scheme, vulnerabilities scanning will happen centrally to ensure multiple organizations aren't independently repeating the same work. Gold Eagle will also identify which software, networks and critical infrastructure could be at risk, before coordinating fixes. The White House described the scheme as a "force multiplier."

Although AI is largely to blame for the increase in attacks, Gold Eagle is set to fight fire with fire by employing AI to identify bugs too, using models like Anthropic's Mythos.

"Through this strategic partnership, we will expand existing security measures to safeguard software and networks in the 21st century and continue to promote advancements in artificial intelligence," DHS Secretary Markwayne Mullin wrote.

The concept of a dedicated clearinghouse centralizes vulnerability management to ensure the right bugs are being prioritized and to cut through the noise of lower-quality reports. Its assistance will most likely be felt by the open-source community, which has limited resources and financial backing to identify and fix issues as effectively as enterprise software vendors.

"Under the leadership of President Trump, we are bringing a wartime footing to the cyber domain to relentlessly patch vulnerabilities," Secretary of War Pete Hegseth added.

Google logo on a black background next to text reading 'Click to follow TechRadar'

Gigabyte Aorus Master 16 Gen 2 review: full-power RTX 5090 performance in a slim 16-inch chassis

Gigabyte Aorus Master 16 Gen 2: Two-minute review

The Gigabyte Aorus Master 16 Gen 2 is built for fast 2560 x 1600 gaming, and it squeezes flagship-class hardware into a slimmer chassis than typical desktop-replacement machines.

The review unit tested here combines AMD’s Ryzen 9 9955HX3D CPU with a 175W Nvidia GeForce RTX 5090 laptop GPU, 32GB of RAM and a 1TB SSD, so it’s aimed at buyers who want top-tier performance without stepping up to a much larger 18-inch machine.

The 16-inch OLED display is one of the main reasons to consider it. It has a 2560 x 1600 resolution, 240Hz refresh rate, 100% DCI-P3 colour coverage, a 1,000,000:1 contrast ratio and HDR 1000 support.

Text looks sharp, colour and contrast are excellent, and the finish isn’t so glossy that reflections become a major issue. It’s a very good fit for fast games, high-quality video and creative work, and the laptop itself is fast enough to make proper use of the panel’s resolution and refresh rate.

The Aorus Master 16 Gen 2 is also more portable than its spec suggests. It measures 35.7 x 25.5 x 1.9 to 2.4cm (14.1 x 10.0 x 0.7 to 0.9in) and weighs 2.39kg (5.27lb), so it’s heavy enough to notice in a bag, but still manageable if you need to carry it between home, work, university or when travelling.

The adapter adds another 750g (1.65lb), which matters if you’re trying to pack light, but the 330W charger is still fairly compact for its output.

Build quality is reasonable, but not as premium as the price suggests. The thin metal-backed screen is rigid, while the plastic shell on the main body has a little flex and feels less expensive.

The keyboard has decent travel and plenty of room, though it’s a little bouncy in vigorous use, while the touchpad is large, responsive and easy to use when you don’t have a mouse connected.

The Full HD infrared camera works well for Windows Hello facial recognition, though image quality is nothing special. The speakers are better than typical laptop audio, with excellent volume and little distortion at higher levels, though bass is still limited.

The port selection covers the basics well, with USB-C, USB4, USB-A, HDMI 2.1, Ethernet, microSD and 3.5mm audio. The issue is the layout.

Gigabyte Aorus Master 16 Gen 2 gaming laptop

(Image credit: Future)

Because the cooling system takes up the rear section of the laptop, most cables need to plug in further forward on the sides, where they can crowd desk space and get in the way of a mouse.

It’s not a deal-breaker, but it makes the Aorus slightly less pleasant to use with a monitor, dock and other desk accessories connected.

Gigabyte’s GiMate software gives useful control over performance modes, fan behaviour and lighting. The laptop also has plenty of lighting to adjust, including the keyboard, rear light bar and desk glow from the underside.

The software itself can be laggy, though, and that makes quick customisation tweaks more frustrating than they should be on an expensive gaming laptop.

Performance is very good, and the Aorus Master 16 Gen 2 has no issue running the RTX 5090 at up to 175W for extended periods. Compared with an RTX 5080 laptop, the Aorus is up to 35% faster for gaming, with the biggest gains in heavier ray-tracing scenarios where the extra GPU headroom and 24GB of VRAM help it sustain higher frame rates.

That makes it a very capable choice for demanding 1600p gaming, especially if you want high texture settings, ray tracing or very fast OLED refresh rates.

Raw CPU performance is also very good. The Ryzen 9 9955HX3D is a powerful processor, and the cooling system lets it work hard in multicore workloads without obvious throttling.

That matters outside games too, as the Aorus Master 16 is well suited to creator work, video editing and heavier productivity tasks.

The laptop can also charge and run from USB-C, and documents, browsing and calls remain snappy, but it’s limited to Balanced mode or lower and gaming performance drops to about 10% of maximum. So the 330W adapter is still needed for proper gaming performance.

Gigabyte Aorus Master 16 Gen 2 gaming laptop

placeholder image (Image credit: Future)

The main trade-off is fan noise. While the cooling system works well, it also makes the Aorus Master 16 Gen 2 one of the loudest laptops I’ve tested at full load. The sound also has a high-pitched note that’s somewhat unpleasant at both low and high speeds, and the fans ramp up quickly even with lighter workloads.

Even the power-saving quiet mode isn’t as quiet as I’d like, so this is not the right laptop if you need near-silent performance when not gaming.

Battery life is the other downside. Despite the large 99Wh battery, web browsing lasted under 2.5 hours, and video playback ran for 3 hours and 46 minutes using power-saving settings. That’s with the RTX 5090 completely off and only using the Radeon iGPU too, and it’s much more power hungry than comparable Intel based gaming laptops.

Gaming on battery is much shorter again, but that is normal and expected. Still, overall the Aorus Master 16 Gen 2 is better treated as a desktop replacement you can move around than a laptop that you can use on the couch without a charger nearby. Hopefully a future driver update can reduce the idle and low load power use, but as tested, battery life is disappointing.

Overall the Gigabyte Aorus Master 16 Gen 2 delivers the speed its high-end hardware promises, and the OLED display is more than capable of showing off the higher frame rates that performance enables.

It’s a good fit if you want a powerful 16-inch gaming laptop that can also handle demanding creative work, and you don’t want to deal with a bulkier machine.

But that does come at a price, so while performance is excellent, the fan noise and battery life stop the Master 16 from feeling as premium as the price tag.

Gigabyte Aorus Master 16: Price & availability

  • How much does it cost? The tested RTX 5090 model is priced at $4,299 / AU$6,599
  • When is it available? It's available now
  • Where can you get it? You can get it in the US and Australia

While it is just hitting shelves in the US and Australia, at the time of writing, we haven't yet seen the Gen 2 Aorus Master 16 Gen 2 for sale in the UK.

Now, the Master 16 Gen 2 is an expensive gaming laptop, and the tested RTX 5090 model sits near the top of the price range. Still, it needs to be judged against other slim but high-power RTX 50 series laptops, rather than chunkier desktop-replacement options.

The price is easier to justify if you want the specific mix of a 175W RTX 5090, Ryzen 9 9955HX3D CPU, 240Hz OLED display and a chassis that is still portable enough to carry around easily.

There are cheaper Aorus Master 16 Gen 2 configurations available, including RTX 5080 and RTX 5070 Ti variants, but the exact CPU and GPU power limits vary by model.

  • Value score: 3.5 / 5

Gigabyte Aorus Master 16 Gen 2: Specs

The Aorus Master 16 Gen 2 range is available in a few configurations, so it's worth double checking the exact model before buying. The RTX 5090 version tested here sits at the top of the range with 24GB of VRAM and a 175W GPU power limit, while the RTX 5080 version keeps the same 175W limit but drops to 16GB of VRAM.

There's also an RTX 5070 Ti version, but the CPU and GPU power limits can vary by SKU and region.

The specs are very good overall, with Wi-Fi 7, USB4, a 99Wh battery and upgradeable DDR5 RAM. The main limitation for the models we have seen for sale so far is that they are limited to 32GB of RAM and a 1TB SSD, which is fair enough considering recent memory and storage price rises.

Gigabyte Aorus Master 16 Gen 2 specs

RTX 5070 Ti variant

RTX 5080 variant

US Price

$1,899

$2,199

UK Price

£1,799

£2,099

AU Price

AU$3,299

AU$4,299

CPU

AMD Ryzen 9 8940HX

AMD Ryzen 9 9955HX3D

GPU

RTX 5070 Ti

RTX 5080

RAM

32GB LPDDR5x 5600 MHz

32GB LPDDR5x 5600 MHz

Storage

1TB

1TB

Display

2560 x 1600 IPS, 100% sRGB, 400 nits, 165 Hz

2560 x 1600 IPS, 100% sRGB, 400 nits, 165 Hz

Ports

1x USB-C 5 Gbps, DisplayPort 1.4, PD charging, 2x USB-A 5 Gbps, HDMI 2.1, 1 Gb Ethernet, 3.5mm headset jack.

1x USB-C 5 Gbps, DisplayPort 1.4, PD charging, 2x USB-A 5 Gbps, HDMI 2.1, 1 Gb Ethernet, 3.5mm headset jack.

Connectivity

Wi-Fi 6E, 802.11ax 2x2 + BT5.2

Wi-Fi 6E, 802.11ax 2x2 + BT5.2

Battery

76Wh

76Wh

Dimensions

358.3 x 262.5 x 19.45 - 22.99 mm (14.11 x 10.33 x 0.77 - 0.91 inches)

358.3 x 262.5 x 19.45 - 22.99 mm (14.11 x 10.33 x 0.77 - 0.91 inches)

Weight

2.3 kg (5.1 lbs)

2.3 kg (5.1 lbs)

  • Specs score: 4.5 / 5
Gigabyte Aorus Master 16 Gen 2 gaming laptop
Future
Gigabyte Aorus Master 16 Gen 2 gaming laptop
Future
Gigabyte Aorus Master 16 Gen 2 gaming laptop
Future
Gigabyte Aorus Master 16 Gen 2 gaming laptop
Future
Gigabyte Aorus Master 16 Gen 2 gaming laptop
Future
Gigabyte Aorus Master 16 Gen 2 gaming laptop
Future

Gigabyte Aorus Master 16: Design

  • Slim for a high-power RTX 5090 laptop
  • Customizable RGB lighting
  • Useful ports but awkward placement

The Aorus Master 16 Gen 2 is slim for a laptop built around a 175W RTX 5090 and high-end AMD CPU, but it's still a large gaming machine. It measures 35.7 x 25.5 x 1.9 to 2.5cm (14.1 x 10.1 x 0.7 to 1.0in), and the 19mm thinnest point includes the rubber feet.

When picked up, that’s perfectly manageable for a 16-inch gaming laptop, and at 2.39kg (5.27lb), it's portable enough to carry on the go every day if needed.

Of course, the 330W adapter is also part of the portability equation. It weighs 750g (1.65lb) and measures 16.0 x 7.5 x 2.7cm (6.3 x 3.0 x 1.1in), which is compact for a charger with such a high output, but it still takes the total carry weight over 3kg.

USB-C charging is useful if you only need documents, browsing or calls away from your main desk, but the main adapter is still the practical choice for gaming.

Build quality is functional rather than feeling truly premium. The top of the lid is metal and is thin but rigid, while the main chassis is plastic and has a little flex. The laptop didn’t show wear during my testing, including when carried in a bag, but the dark finish picks up fingerprints, though they also cleans off relatively easily.

The rear of the chassis is mostly given over to cooling, with large vents across the back edge and exhausts on the sides. That cooling system is a key part of the design, as it helps the Aorus Master 16 run high-power hardware in a slimmer body. It also leads to some of the compromises, such as fan noise and port placement.

Gigabyte Aorus Master 16 Gen 2 gaming laptop
Future
Gigabyte Aorus Master 16 Gen 2 gaming laptop
Future
Gigabyte Aorus Master 16 Gen 2 gaming laptop
Future

The port selection is useful, with USB4, a second USB-C port, two USB-A ports, HDMI 2.1, 1Gb Ethernet, microSD and 3.5mm audio. The problem is where those ports sit. Because the rear of the laptop is reserved for cooling, cables plug in further forward on the sides, where they can crowd your desk and mouse space.

For those who value their desk space, the chunky side-mounted power connector can be especially bulky and annoying, so I found a powered USB-C dock is a good option if you use the Aorus Master 16 Gen 2 with a monitor, Ethernet and other accessories. That way you can have just one cable plugged in, and only add the bigger power plug when gaming.

The keyboard has a reasonable 1.7mm of travel and plenty of room, so it works well for both typing and normal WASD gaming. It's a little bouncy in vigorous use, and overall doesn't feel as firm as I'd like for a flagship laptop, but the layout is pretty good overall.

The touchpad is large, responsive and pleasant enough to use when you don’t have a mouse connected.

The RGB lighting includes the keyboard and is pretty extensive overall. The Aorus logo on the rear of the screen is backlit by colour-changing LEDs, and there is front and rear underside lighting that creates a nice nonglare desk glow effect in a darker room.

There's also a small light that projects the Aorus symbol onto the desk behind the laptop. It's a fun idea, but the focus seemed a touch soft.

Gigabyte Aorus Master 16 Gen 2 gaming laptop
Future
Gigabyte Aorus Master 16 Gen 2 gaming laptop
Future
Gigabyte Aorus Master 16 Gen 2 gaming laptop
Future
Gigabyte Aorus Master 16 Gen 2 gaming laptop
Future
Gigabyte Aorus Master 16 Gen 2 gaming laptop
Future
Gigabyte Aorus Master 16 Gen 2 gaming laptop
Future
Gigabyte Aorus Master 16 Gen 2 gaming laptop
Future

Gigabyte’s GiMate software controls lighting, performance modes and fan behaviour, but I find it can be slow to load and respond at times. That’s a mild frustration for anyone who may want to change modes often, especially if you are trying to reduce fan noise during lighter work.

There are also automatic ‘AI’ modes, but I found they left the laptop running hotter and noisier than I’d like when not gaming. Like the laptop itself, the software doesn't feel as slick as you’d hope for the price.

The Full HD infrared webcam works well for Windows Hello facial recognition, though image quality is nothing special and gets softer in darker rooms.

The speakers are better than what I’ve experienced on most other laptops I’ve tested, with great volume and very little distortion at high levels, but as expected, bass is still pretty limited. The speakers can overpower the fan noise when cranked right up, but I'd still recommend a headset for gaming.

  • Design score: 4.5 / 5
Gigabyte Aorus Master 16 Gen 2 gaming laptop
Future
Gigabyte Aorus Master 16 Gen 2 gaming laptop
Future
Gigabyte Aorus Master 16 Gen 2 gaming laptop
Future

Gigabyte Aorus Master 16: Performance

  • High 1600p gaming frame rates
  • Excellent CPU performance
  • Loud fans under load

The Aorus Master 16 Gen 2 gives the cooling and power headroom needed to make a high end GPU worth paying extra for. The variant I tested uses a 175W Nvidia GeForce RTX 5090 laptop GPU (and the AMD Ryzen 9 9955HX3D CPU), so it's not one of those slim gaming laptops with a premium GPU bottlenecked by a low wattage limit.

And just as importantly, the cooling system lets the hardware work hard for sustained loads, and that makes the Aorus a proper match for its 240Hz, 2560 x 1600 OLED display.

Compared with an RTX 5080 laptop, the Aorus Master 16 Gen 2 is up to 35% faster for gaming. The biggest gains are in heavier ray-tracing scenarios, where the extra GPU headroom and 24GB of VRAM help sustain higher frame rates. That extra memory also helps if you want high-resolution textures, or play a lot of newer games that push beyond what lower-tier laptop GPUs can comfortably handle.

If you mostly play lighter esports titles, the hardware is overkill, but the 240Hz OLED display still gives it a clear use case for very fast gaming.

The RTX 5090 is also a powerful accelerator for creator work. GPU-heavy video effects, rendering workloads and AI-assisted tools can all use the extra graphics grunt, so the Aorus Master 16 makes more sense if you want one machine for both gaming and demanding creative work.

Gigabyte Aorus Master 16 Gen 2 gaming laptop

placeholder image (Image credit: Future)

CPU performance is also very good. The Ryzen 9 9955HX3D is a powerful processor, especially in multicore workloads, and the Aorus cooling system lets it run full tilt without obvious throttling. That is important for gaming, but also for video editing, rendering, compiling code and other higher loads.

The cooling system also lets the CPU and GPU run hard at the same time. During demanding gaming sessions, the Aorus Master 16 Gen 2 generates a lot of heat, but it doesn't make the keyboard or WASD area uncomfortable to use. Hot air exits from the rear and sides, so your exact desk setup will change the impact, but the thermal comfort is better than the fan noise might suggest.

The trade-off is that the cooling system is not subtle. At all. I love that the Aorus Master 16 can give high performance in a relatively slim 16-inch chassis, but it’s important to highlight that it does that by moving a lot of air, loudly.

Gigabyte Aorus Master 16 Gen 2 gaming laptop

placeholder image (Image credit: Future)

The benchmark table below compares the Aorus Master 16 with the Alienware 16 Area-51 configuration I tested with an RTX 5080. The Alienware is another premium machine, so it makes a useful comparison for showing what the Aorus gains from the RTX 5090 and 24GB of VRAM.

If you are comparing the Aorus Master 16 Gen 2 with other gaming laptops, pay close attention to GPU wattage as well as the GPU name. A lower-wattage RTX 5090 laptop can perform much closer to an RTX 5080 machine, while the Aorus Master 16 Gen 2 has the cooling and wattage budget needed to make the 5090 worth the extra cost.

Gigabyte Aorus Master 16 Gen 2 benchmark results

Aorus Master 16 Gen 2

Alienware 16X Aurora

Alienware 16 Area-51

CPU

AMD Ryzen 9 9955HX3D

Intel Ultra 9 275HX

Intel Ultra 9 275HX

GPU

RTX 5090 24GB

RTX 5070

RTX 5080

RAM

32GB

32GB

32GB

Battery

99 Wh

96 Wh

96 Wh

General performance

PCMark 10 - Overall (score)

10,905

8,437

8,639

Geekbench 6 - Multi-core

19,954

19,615

20,244

Geekbench 6 - Single-core

3,209

3,068

3,149

Geekbench 6 - GPU

232,231

136,686

213,178

Cinebench R24 - CPU Single Core

130

133

133

Cinebench R24 - CPU Multi Core

2,148

1,964

2,106

Battery

PCMark 10 - Battery Work (HH:MM)

1:56

6:01

3:09

TechRadar video test (HH:MM)

2:11

6:16

4:27

Graphics performance

3DMark SpeedWay

6,185

3,664

5,610

3DMark Port Royal

16,132

9,031

11,999

Steel Nomad

5,972

2,846

5,109

Cyberpunk 2077 - 1600p RT Low (DLSS)

133

76

114

Cyberpunk 2077 - 1600p RT Low (DLSS off)

99

50

79

Cyberpunk 2077 - 1600p RT Ultra (DLSS)

84

54

72

Cyberpunk 2077 - 1600p RT Ultra (DLSS off)

50

16

37

Black Myth: Wukong - 1600p Cinematic (DLSS)

121

76

104

Shadow of the Tomb Raider - 1600p (DLSS off)

214

131

175

Storage

CrystalDiskMark Read/Write (MB/s)

6,902 / 5,618

6,939 / 6,740

6,575 / 5,890

In real use, the Aorus Master 16 Gen 2 is very capable at its native 2560 x 1600 resolution. Demanding games still need sensible settings if you want to push closer to the OLED screen's 240Hz limit, but this is a laptop where high detail, ray tracing and upscaling can all be used without dropping frame rates too low.

The 24GB of VRAM is a key long-term advantage over lower-tier GPUs. It gives the laptop more scope in the future for high-resolution textures and demanding ray-traced scenes, and it should also help the Aorus Master 16 age better as game requirements keep rising.

Fan noise is the major performance downside. At full load, the Aorus Master 16 Gen 2 is one of the loudest laptops I’ve tested, and the sound has a high-pitched note that makes it more annoying than a lower rush of air.

A headset is already a typical choice for gaming, but the bigger problem is that even when not gaming, the fans ramp up quickly and can get loud even under light loads.

The quiet and power-saving modes help, but they don't make the laptop consistently quiet. Even in lighter use, the fans tend to spin up much more than seems necessary given the internal temperatures, and it becomes loud enough to notice.

Arguably this is the real-world cost of getting this much performance from a slimmer 16-inch design, but it still feels much less refined than it could be. Hopefully Gigabyte works on the fan control and smooths it out somewhat in future software updates.

Stability was good during testing. External display use worked well, including through a dock, and both Ethernet and Wi-Fi behaved reliably. I also didn't run into sleep, wake or lid-behaviour glitches that often plague Windows based machines. I did find Gigabyte's GiMate software slow at times, but on the plus side it gives good access to performance modes, fan settings and lighting controls.

Gigabyte Aorus Master 16 Gen 2 gaming laptop

placeholder image (Image credit: Future)

USB-C charging on the Aorus Master 16 Gen 2 is useful, but only if you understand and respect a few limits. The laptop does charge and run happily from USB-C, and in fact tends to be much quieter, which makes it a good option for a docked desk setup, travel or basic work without the big 330W adapter. Light single-core tasks were only 2% slower than full-adapter use in my testing, so web browsing and typical office tasks still feel snappy.

CPU-heavy loads show the limits, though, and were about 60% slower on USB-C than with the power brick, and gaming performance was about 92% lower. That doesn't make USB-C useless, but it does mean you should treat it as a convenience for productivity and top-ups rather than factor it in for gaming.

Still, overall the Aorus Master 16 Gen 2 delivers the high-end performance its hardware promises. It's fast enough for demanding 1600p gaming and creative work, for those who don’t mind the fan noise.

If you want a powerful laptop that stays quiet when not gaming, it’s a harder machine to recommend.

  • Performance score: 4.5 / 5

Gigabyte Aorus Master 16 Gen 2: Battery life and Charging

  • Under 2.5 hours of web browsing
  • 3 hours and 46 minutes of video playback
  • USB-C charging suits light work, not gaming

Gigabyte Aorus Master 16 Gen 2 gaming laptop

placeholder image (Image credit: Future)

Battery life is not great, especially considering the Aorus Master 16 Gen 2 has a larger 99Wh battery. The slim 16-inch chassis makes it easier to carry than a typical desktop-replacement laptop, but the short runtime unplugged means you'll still want the charger nearby for anything more than brief use.

In my web-browsing battery test, the Aorus Master 16 Gen 2 lasted under 2.5 hours. Video playback ran for 3 hours and 46 minutes using power-saving settings.

Those results are disappointing and they do limit the usefulness of the Aorus when you want to work away from a desk for more than a short session.

The 330W adapter is needed for full gaming performance, and it's compact for a charger with that output. It still weighs 750g (1.65lb), though, so carrying the Aorus Master 16 with its charger pushes the total travel weight well over 3kg.

That’s manageable for a high-performance gaming laptop, but it's enough extra weight that I'd only pack the charger when I expected to game or run heavier workloads.

USB-C charging is useful when you want to work on documents, browse or take calls without carrying the 330W adapter. It also works well for a docked desk setup, and the laptop is much quieter when running from a smaller USB-C charger. The limit is performance: the Aorus Master 16 Gen 2 drops to Balanced mode or lower on USB-C, and gaming performance falls far enough that the 330W adapter is still required for serious play.

That means USB-C is useful for light productivity and top-ups, not as a proper replacement for the main charger. A future driver update may improve battery life, but as tested, the Aorus Master 16 Gen 2 may be easy enough to transport, but it’s not a laptop that can be relied on away from a charger.

  • Battery life and charging score: 2.5 / 5

Should you buy the Gigabyte Aorus Master 16 Gen 2?

Gigabyte Aorus Master 16 scorecard

Attributes

Notes

Rating

Value

Expensive, and the fan noise and low battery life make the price harder to justify

3.5 / 5

Specs

High-end CPU and GPU, excellent OLED display, useful ports and a 99Wh battery

4.5 / 5

Design

Slim for the hardware inside, but little details like the port layout feel unpolished

4 / 5

Performance

High end 1600p gaming and creator performance

4.5 / 5

Battery

Poor runtime despite the 99Wh battery, though USB-C charging helps for documents, browsing and calls

2.5 / 5

Overall

A powerful 16-inch OLED gaming laptop, but fan noise and battery life limit its appeal

4 / 5

Buy it if…

You want fast 1600p gaming in a 16-inch laptop
The 175W RTX 5090 has the graphics performance to make good use of the 2560 x 1600 OLED display, especially if you want detailed settings, ray tracing or very fast frame rates.

You want one laptop for gaming and demanding work
The Ryzen 9 9955HX3D and RTX 5090 give the Aorus Master 16 Gen 2 the CPU and graphics performance for video editing, rendering and other heavy workloads.

You want flagship performance without an 18-inch chassis
The Aorus Master 16 Gen 2 is still heavy, especially with the charger, but it's slimmer and easier to move around than larger desktop-replacement gaming laptops.

Don’t buy it if...

You need quiet operation
The fans are loud, ramp up quickly and have a high-pitched note, so it’s not great for use in quiet spaces or gaming without a headset.

You need long battery life
The 99Wh battery doesn't translate into good unplugged runtime, so look elsewhere if you need to operate away from a charger.

You want a more premium physical design
While the Aorus 16 Gen 2 is functional enough, the design downsides are hard to ignore given the price.

Gigabyte Aorus Master 16: Also consider

If my Gigabyte Aorus Master 16 Gen 2 review has you considering other high-end gaming laptops, these are some other options that are worth a look:

Alienware 16 Area-51
A larger and more polished 16-inch gaming laptop with high end performance, a premium-feeling design and better port placement. It's worth considering if you like the Aorus Master 16 Gen 2's gaming grunt but don't need the slimmer chassis.

Take a look at the full Alienware 16 Area-51 review

Razer Blade 16 (2025)
A premium RTX 5090 gaming laptop with a 16-inch OLED display, a thin aluminium chassis and decent battery life. It's a good choice if build quality and portability matter more than raw performance for the money.

Check out the full Razer Blade 16 (2025) review

How I tested

  • I tested the Gigabyte Aorus Master 16 Gen 2 for two weeks
  • I used it on a desk, with an external display and while travelling
  • I used it for 2560 x 1600 gaming, productivity work, video editing and battery testing

I ran the Gigabyte Aorus Master 16 Gen 2 through the usual TechRadar benchmark suite, as well as using it for day-to-day work at a desk and on the go.

I tested gaming performance at the native 2560 x 1600 resolution, checked performance across the laptop's main power profiles and used it for office work, video editing, external display use and general media playback.

I used the TechRadar movie test for assessing battery life during video playback, plus web-browsing and productivity battery tests to see how long the Aorus lasted away from the charger.

I also tested USB-C charging with a dock and USB-C chargers, and checked how performance changed compared with the 330W adapter. Fan noise, thermal comfort, Wi-Fi, Ethernet, sleep behaviour and Gigabyte's GiMate software were also assessed during normal use.

Read more about how we test.

  • First reviewed in July 2026

Quordle hints and answers for Wednesday, July 15 (game #1633)

Looking for a different day?

A new Quordle puzzle appears at midnight each day for your time zone – which means that some people are always playing 'today's game' while others are playing 'yesterday's'. If you're looking for Tuesday's puzzle instead then click here: Quordle hints and answers for Tuesday, July 14 (game #1632).

Quordle was one of the original Wordle alternatives and is still going strong now more than 1,500 games later. It offers a genuine challenge, though, so read on if you need some Quordle hints today — or scroll down further for the answers.

Enjoy playing word games? You can also check out my NYT Connections today and NYT Strands today pages for hints and answers for those puzzles, while Marc's Wordle today column covers the original viral word game.

SPOILER WARNING: Information about Quordle today is below, so don't read on if you don't want to know the answers.

Quordle today (game #1633) — hint #1 — Vowels

How many different vowels are in Quordle today?

The number of different vowels in Quordle today is 4*.

* Note that by vowel we mean the five standard vowels (A, E, I, O, U), not Y (which is sometimes counted as a vowel too).

Quordle today (game #1633) — hint #2 — repeated letters

Do any of today's Quordle answers contain repeated letters?

The number of Quordle answers containing a repeated letter today is 0.

Quordle today (game #1633) — hint #3 — uncommon letters

Do the letters Q, Z, X or J appear in Quordle today?

• Yes. One of Q, Z, X or J appears among today's Quordle answers.

Quordle today (game #1633) — hint #4 — starting letters (1)

Do any of today's Quordle puzzles start with the same letter?

The number of today's Quordle answers starting with the same letter is 2.

If you just want to know the answers at this stage, simply scroll down. If you're not ready yet then here's one more clue to make things a lot easier:

Quordle today (game #1633) — hint #5 — starting letters (2)

What letters do today's Quordle answers start with?

• P

• B

• B

• S

Right, the answers are below, so DO NOT SCROLL ANY FURTHER IF YOU DON'T WANT TO SEE THEM.

Quordle today (game #1633) — the answers

Quordle answers for game 1633 on a yellow background

(Image credit: Merriam-Webster)

The answers to today's Quordle, game #1633, are…

  • PROXY
  • BRICK
  • BROTH
  • SURGE

As befits the appearance of a rare letter it took me a while to find the word PROXY.

Instead, I was trying every letter combination left to me, which is how I ended up with “grovy”.

Daily Sequence today (game #1633) — the answers

Quordle Daily Sequence answers for game 1633 on a yellow background

(Image credit: Merriam-Webster)

The answers to today's Quordle Daily Sequence, game #1633, are…

  • FUZZY
  • THERE
  • TEMPO
  • CAUSE

Quordle answers: The past 20

  • Quordle #1632, Tuesday, 14 July: EBONY, AVOID, RODEO, CUTIE
  • Quordle #1631, Monday, 13 July: VOICE, BISON, BURNT, BUILT
  • Quordle #1630, Sunday, 12 July: STAIN, BINGO, LARVA, DICEY
  • Quordle #1629, Saturday, 11 July: WORTH, PRONG, DINGO, DRUID
  • Quordle #1628, Friday, 10 July: GREET, STEAK, DUSKY, HAUTE
  • Quordle #1627, Thursday, 9 July: CRUMP, PHONE, SHINY, STONY
  • Quordle #1626, Wednesday, 8 July: GHOST, TREND, EXALT, ALONG
  • Quordle #1625, Tuesday, 7 July: ARRAY, SUITE, KIOSK, BOULE
  • Quordle #1624, Monday, 6 July: TRAWL, SPICE, PIANO, SHARK
  • Quordle #1623, Sunday, 5 July: PINEY, SWOON, TITLE, PINTO
  • Quordle #1622, Saturday, 4 July: ARGUE, MOTEL, OPERA, TRUCE
  • Quordle #1621, Friday, 3 July: AVERT, MOTOR, MANIC, WORDY
  • Quordle #1620, Thursday, 2 July: BULKY, PARSE, BELOW, MOVIE
  • Quordle #1619, Wednesday, 1 July: EASEL, OTTER, LYRIC, SHACK
  • Quordle #1618, Tuesday, 30 June: HALVE, DRYER, THERE, MINTY
  • Quordle #1617, Monday, 29 June: SLURP, CRACK, CRANK, PHONY
  • Quordle #1616, Sunday, 28 June: RUPEE, TOPAZ, FULLY, BEING
  • Quordle #1615, Saturday, 27 June: PRINT, MARRY, SADLY, BICEP
  • Quordle #1614, Friday, 26 June: JUICE, ARRAY, BONEY, SKIFF
  • Quordle #1613, Thursday, 25 June: SHELF, TAWNY, HYPER, SOLVE

NYT Strands hints and answers for Wednesday, July 15 (game #864)

Looking for a different day?

A new NYT Strands puzzle appears at midnight each day for your time zone – which means that some people are always playing 'today's game' while others are playing 'yesterday's'. If you're looking for Tuesday's puzzle instead then click here: NYT Strands hints and answers for Tuesday, July 14 (game #863).

Strands is the NYT's latest word game after the likes of Wordle, Spelling Bee and Connections – and it's great fun. It can be difficult, though, so read on for my Strands hints.

Want more word-based fun? Then check out my NYT Connections today and Quordle today pages for hints and answers for those games, and Marc's Wordle today page for the original viral word game.

SPOILER WARNING: Information about NYT Strands today is below, so don't read on if you don't want to know the answers.

NYT Strands today (game #864) - hint #1 - today's theme

What is the theme of today's NYT Strands?

Today's NYT Strands theme is… Rose-colored glasses

NYT Strands today (game #864) - hint #2 - clue words

Play any of these words to unlock the in-game hints system.

  • QUIT
  • MARKET
  • MAIN
  • PLACE
  • PLINTH
  • RELICS

NYT Strands today (game #864) - hint #3 - spangram letters

How many letters are in today's spangram?

Spangram has 11 letters

NYT Strands today (game #864) - hint #4 - spangram position

What are two sides of the board that today's spangram touches?

First side: bottom, 3rd column

Last side: top, 4th column

Right, the answers are below, so DO NOT SCROLL ANY FURTHER IF YOU DON'T WANT TO SEE THEM.

NYT Strands today (game #864) - the answers

NYT Strands answers for game 864 on a blue background

(Image credit: New York Times)

The answers to today's Strands, game #864, are…

  • QUIXOTIC
  • IDEALISTIC
  • ROMANTIC
  • IMPRACTICAL
  • SPANGRAM: PIEINTHESKY
  • My rating: Hard
  • My score: 1 hint

Just four long words made up today’s game, but that didn’t make the search any easier.

I am more familiar with a slight variation on today’s theme — rose-tinted spectacles — which I had viewed as meaning to look favorably on something you are biased towards (such as the fortunes of your team). But the words here leaned more towards fanaticism.

Regardless of interpretation I needed a hint to get going and was rewarded with QUIXOTIC, a word I would have failed to see otherwise. From here I found the other two words with a T-I-C ending, before the spangram helped me to locate IMPRACTICAL.

Yesterday's NYT Strands answers (Tuesday, July 14, game #863)

  • CHAIR
  • ROCKER
  • BEANBAG
  • OTTOMAN
  • RECLINER
  • THRONE
  • SPANGRAM: HAVEASEAT

What is NYT Strands?

Strands is the NYT's not-so-new-any-more word game, following Wordle and Connections. It's now a fully fledged member of the NYT's games stable that has been running for a year and which can be played on the NYT Games site on desktop or mobile.

I've got a full guide to how to play NYT Strands, complete with tips for solving it, so check that out if you're struggling to beat it each day.

CEO of big memory chip maker says 2027 could be the 'worst year in the industry's history' — and other RAM crisis rumblings back up that dire prediction

  • The boss of SK Hynix believes that the RAM crisis is going to get much worse
  • The CEO said 2027 will be the 'worst year' in the RAM industry's history, and that the crisis will likely roll on to 2030 and beyond
  • Analysis from the Bank of America also claims that SK Hynix's expansion of memory production capacity is going to fall well short of its target for 2028

We keep getting told that the RAM crisis is dug in as a fixture for the foreseeable future, and, whether you want them or not, here are a couple more unwelcome reminders.

First, Android Headline flagged a Reuters interview with Kwak Noh-jung, the CEO of SK Hynix, one of the big memory chip makers. The chief executive didn't have comforting words about the prospect of RAM pricing in 2027, observing, "We forecast that ‌next year will be the worst year in the [memory] industry's history from the supply perspective."

So, seemingly next year will see RAM hit peak pricing, with no relief likely until 2030 (as previously forecast by the chairman of parent company SK Group) according to the CEO — and even then, he suggested that demand will continue to outweigh supply as the next decade rolls on beyond 2030.

The second RAM-related blow comes from analysis by the Bank of America highlighted by the Commercial Times in Taiwan (via Wccftech), which pours doubt on the South Korean president's recent boasts about the major expansion of the country's overall memory chip production by 2030.

Part of this analysis is a claim from a memory industry insider over in Taiwan that SK Hynix might only add just a sixth of its originally planned production capacity increase by 2028. Obviously that assertion needs to be liberally seasoned, but it's such a large potential shortfall that it's bound to raise some eyebrows.

The Commercial Times notes that while huge new chip manufacturing plants are being built by SK Hynix and Samsung in South Korea, they will take a lot longer than 2030 to come fully online — and this process is more likely to take a full decade. The report contends that a realistic level of memory wafer capacity expansion for South Korea is around 10% (or slightly less) per year, which will leave the country falling well short of the president's claims for production in 2030.

Analysis: diverging RAM timelines

Intense close-up of RAM against a black background

(Image credit: Unsplash / Liam Briese)

It's grim news from the CEO of SK Hynix, then, although of course, the skeptics will quickly point out that it's the chief exec's job to talk up the company's value — in terms of a booming market and the struggle to meet demand — coming off the back of its debut on the Nasdaq. Stock prices around the big memory chip makers have been turbulent of late, it should be noted, as investors start to worry about whether these companies are currently overvalued — and indeed whether the AI boom might start to run out of momentum.

So, that's a consideration, but there's no denying that SK Hynix's boss isn't the only person making gloomy predictions along these lines. Nvidia's CEO Jensen Huang said that he expects the RAM crisis to last "quite a few years", indicating that we'll be stuck in pricing hell until 2030 or thereabouts, although others don't see it that way. In the opposing camp we notably have the likes of an AMD exec, the ex-chief of Samsung's semiconductor division, and Jefferies, an investment banking firm, who all believe RAM pricing will start to ease in 2028.

However, the sting in the tail there is that Jefferies is also predicting big memory price hikes over the rest of this year, and in 2027 too, backing up the CEO of SK Hynix in that respect. When you consider the estimated massive shortfall of SK Hynix's production capacity boost based on the rumor mill, everything feels distinctly shakier in the nearer-term for RAM pricing.

I also can't help but recall the blow Microsoft recently delivered when talking about Xbox price rises, when the company informed us that it expects another doubling in the cost of RAM in just over a year (by the fall of 2027).

While there's a mixed bag in terms of longer-term predictions, then, the outlook for this year and next remains worryingly negative on the RAM front.

Experts get Google, Microsoft to pull trusted ModHeader with 1.6 million installs after finding it could harvest all kinds of data

  • Stripe OLT found ModHeader v7.0.18 carried a hidden spyware SDK, exfiltrating visited domains daily to a Chinese‑owned server and acting as adware
  • The extension had 1.6M downloads across Chrome and Edge before being pulled but installed endpoints remain at risk
  • Researchers urge defenders to identify and remove existing installations, as removal from stores does not automatically remediate compromised devices

ModHeader, a trusted Chrome and Edge browser extension with more than 1.6 million downloads, was found to be malicious, apparently sending sensitive data to a Chinese-owned server, and has since been pulled on both repositories.

Security researchers Stripe OLT revealed the news in a new report, outlining how a ModHeader build v7.0.18 carried a hidden spyware SDK.

As per Stripe OLT, the spyware collects domains users visit, encrypts the data with AES-GCP, and then sends it - once a day - to a remote server. The collector was found inactive by default, but the required code, encryption key, and upload schedule were all already embedded in the extension.

Links to Chinese actors

Researchers found no command-and-control functionality, which means the server only receives the stolen data and cannot communicate back. The extension also worked as an adware, displaying ads and opening advertising tabs on updates, including on enterprise-managed devices.

The researchers attributed the attack, albeit with low confidence, to a Chinese-speaking threat actor. The exfiltration domain routes emails through Lark, which is a suite common with Chinese-speaking teams, it was said. They also found Chinese strings in the code, and said that the listing ships a Simplified Chinese locale.

ModHeader is a Chrome and Edge browser extension that allows users to modify HTTP request and response headers sent between their browser and websites. Developers and security researchers use it to test APIs, troubleshoot applications, and simulate different environments. It has around 900,000 users on Chrome, and another 700,000 on Edge.

According to The Hacker News, Microsoft pulled the tool from its repository on June 3 2026, followed by Google a week later, on July 10.

“Following our disclosure, Google has removed the extension from the Chrome Web Store,” Stripe OLT concluded. “We welcome this action, but removal from the store does not automatically remediate endpoints where the extension was already installed, so defenders should continue to identify and remove existing installations.”

'A single entry point can rapidly expand to greater enterprise impacts': Microsoft introduces changes to tackle ShinyHunters

  • ShinyHunters abused OAuth trust in Salesforce by tricking users and later compromising SaaS integrations, stealing tokens to access hundreds of customer environments
  • Reports suggested up to 700 victims; attackers exfiltrated data via legitimate APIs, making activity appear normal and persistent
  • Microsoft responded with Defender for Cloud Apps upgrades, adding richer telemetry, near‑real‑time detection, and stronger governance over OAuth‑connected applications

The ShinyHunters cybercrime group were so creative in breaking into corporate Salesforce environments that they forced Microsoft’s hand, making the company introduce new security upgrades just to address the attacks.

Microsoft has revealed it is focusing on improving visibility into OAuth-connected applications and strengthening governance over third-party integrations in Microsoft Defender for Cloud Apps. The changes fall into two main categories: Improved detection and investigation, and new posture and governance capabilities.

It makes sense, given that some reports claimed as many as 700 victims of the year-long campaign.

Changes and improvements

But first, a little context: In August 2025, it was reported that ShinyHunters operatives were calling their targets on the phone, claiming to be IT support, and convincing them to authorize a seemingly legitimate Salesforce Data Loader application. This app was, in fact, controlled by the attackers and requested OAuth permissions which allowed them to access Salesforce data through official APIs.

Since everything happened through legitimate authentication and API calls, the activity looked like normal user behavior.

In the following months, the campaign evolved. Instead of tricking individual employees, ShinyHunters compromised third-party SaaS providers that integrated with Salesforce, including Salesloft's Drift integration, Gainsight, and later Klue.

By stealing OAuth tokens or integration secrets from these vendors, they accessed hundreds of downstream customer Salesforce environments without interacting with each customer individually.

At one point, Google told reporters it was aware of more than 700 potentially impacted organizations.

“Microsoft consulted with Salesforce to improve granularity in telemetry for Defender for Cloud Apps with near-real-time detection, offering connected application attribution and expanded application permission insights,” the company said in a new report. “This activity was not the result of a vulnerability inherent to Salesforce. Rather, the threat actors abused trusted OAuth relationships for unauthorized access, data exfiltration, and persistence.”

In other words, Microsoft enabled greater visibility into OAuth-connected applications and their activity, allowed for better detection of suspicious API and OAuth behavior through richer telemetry and correlation, and now provides stronger governance of connected apps through permission analysis, risk scoring, and lifecycle management.

‘All the analog features you could wish for’: this is one of the most adjustable analog keyboards I’ve come across — but there’s one area where its rivals win out

MelGeek Made68 Ultra V2: One-minute review

The MelGeek Made68 Ultra V2 is a wired analog keyboard with a retro design that belies its advanced analog adjustability.

It certainly harks back to a time when the ‘gamer aesthetic’ was in full swing, with its translucent keycaps and faux-industrial body. The rear and side lighting are interesting touches, though.

It’s also a veritable slab of a keyboard. It’s very thick, although it gets thinner towards the front, which means the keys angle towards the user slightly. This is just as well, since the Made68 Ultra V2 doesn’t have any pop-out feet, as many of the best gaming keyboards do.

The materials feel premium enough and solidly put together. It’s heavy, which helps the board to stay planted, but this could be an issue if you frequently move your board around.

Although the Made68 Ultra V2 has bright RGB backlighting, it’s a misstep that it doesn’t shine through the keycap characters. In fact, it actively obscures them, so you’d best get familiar with touchtyping if you aren’t already.

Close-up of rear corner of MelGeek Made68 Ultra V2, on desk with pink wall in background

(Image credit: Future)

There are plenty of useful FN shortcuts, but unfortunately none of them is labelled on the relevant keycap, so you’ll have to refer to the manual and learn them by heart.

If you want to customize bindings, you can use MelGeek’s web app for this purpose. There are plenty of options here, but it’s the precise and copious analog adjustments that are even more impressive.This app is easily accessible via two taps of the Mode button on the rear, which is a thoughtful touch and one I wish more gaming keyboards featured. For a web app, it’s also very fast and stable.

In a word, the best way to describe the performance of the Made68 Ultra V2 is solid. The keys don’t wobble at all, and presses are firm with a satisfying thunk once they reach the end of their travel. This provides plenty of feedback, while the dampening is sufficient enough to prevent harshness. At the same time, they’re also very snappy and responsive, thanks to their quick rebound.

I also found the WASD position comfortable, and all peripheral keys were easy and comfortable to hit. I did find myself hitting its edge on occasion, but its springiness and dampening still make it better than many others I’ve encountered.

All of this performance and adjustability doesn’t come cheap, though. The Made68 Ultra V2 is more expensive than many of its rivals — even those with bigger names, which makes the Made68 Ultra V2’s price harder to swallow. But if you prize a sturdy construction and a solid feel above all else, there aren’t many that can beat it on these fronts.

MelGeek Made68 Ultra V2 review: Price & availability

Close-up of power button and USB-C port of MelGeek Made68 Ultra V2, on desk with pink wall in background

(Image credit: Future)
  • $219 (about £160 / AU$300)
  • Available now in multiple colorways
  • Top-of-the-sector pricing

The MelGeek Made68 Ultra V2 costs $219 (about £160 / AU$300) and is available now in multiple colorways from the brand’s website. International shipping is offered, with region-dependent charges.

This is expensive for any wired gaming keyboard, even analog models. It’s costlier than some offerings from the big hitters in the space, such as Razer and SteelSeries. For instance, the former’s Huntsman V3 Tenkeyless 8KHz costs $169.99, yet it has similar analog tweakability and even includes controller emulation, which the Made68 Ultra V2 misses out on.

As for SteelSeries, its Apex Pro TKL Gen 3 is also cheaper than the Made68 Ultra V2, and what’s more it’s one of the best analog gaming keyboards I’ve ever used in terms of build and performance. Its keys feel great and offer superb control. It might miss out on controller emulation, but it shines in virtually every other area.

MelGeek Made68 Ultra V2 review: Specs

Layout

TKL

Switch

KOM Lite Magnetic / Flip King Magnetic

Programmable keys

Yes

Dimensions

12.6 x 4.6 x 1.6 inches / 319 x 117 x 40mm

RGB or backlighting

Yes (customizable)

MelGeek Made68 Ultra V2 review: Design

Close-up of USB cable in MelGeek Made68 Ultra V2, on desk

(Image credit: Future)
  • Retro looks
  • Very thick and heavy
  • Advanced customization options

I think it’s fair to say that the appearance of the Made68 Ultra V2 will prove divisive. Some may view it as charmingly retro, while others will think it dated. The translucent keycaps allow the switches underneath to be seen and let the RGB shine through. The effect is nice, but it does look like something we might have seen 20 years ago.

The frame is also a throwback to a time when gaming peripherals had an industrial bent, with its metallic side plates and sharp corners. However, the large rectangular lightbar adds some interest, and I haven’t seen anything like this before on a keyboard. The same is true of the side light bars, so the Made68 Ultra V2 at least has something to distinguish it from others in the space.

Close-up of keys on MelGeek Made68 Ultra V2, on desk

(Image credit: Future)

Complementing that sharp and angular appearance is its thickness. This tapers off somewhat towards the front, which has the effect of tilting the keys towards you. This is a good thing, since the Made68 Ultra V2 has no folding feet, although I still would’ve welcomed some to create even more of an angle.

Perhaps the sheer weight of the unit is the reason for this absence. Whether this is a flaw or a feature will likely depend on personal preferences. If you want a solid, planted feel, then you may well appreciate its heft; however, if you move your board around frequently, or take it with you on your travels, you won’t.

There are numerous Fn shortcuts on the Made68 Ultra V2, although it’s a shame that none of them is marked on the keycaps themselves, which means you’ll have to commit them to memory.

But even if they were marked, you’d be hard pressed to see them, since the RGB backlighting fails to shine through the keycap characters. In fact, it actively obscures them; turning off the backlighting actually makes the keycap symbols easier to read, which defeats the point of the feature in the first place. This is perhaps the biggest design flaw of the Made68 Ultra V2.

Close-up of switch with keycap removed on MelGeek Made68 Ultra V2

(Image credit: Future)

If you want to customize these shortcuts, and rebind all the other keys, you’ll need to use MelGeek’s web app. This is easily accessed by double-tapping the Mode button on the rear of the board, which is a thoughtful touch and one I wish every keyboard featured. There are plenty of system and media commands available for mapping, but it's the analog features and adjustments that really stand out here.

Take the multi-binding features. There’s a counter-strafing mode that triggers a second input when releasing a key; so if you’re holding A to strafe left, you can set this same key to trigger a D input when released to stop you quicker. There’s also a Rappy Snappy mode that gives priority to a single input when two keys are pressed depending on which is pressed further down.

There are a pleasing amount of actuation adjustments, too. You can set the actuation point between 0.1mm and 3.3mm, and even alter the deadzone at the bottom of a key’s travel between 0mm and 0.07mm, which is something I haven’t seen before in other keyboards.

Side view of keys on MelGeek Made68 Ultra V2, on desk with pink wall in background

(Image credit: Future)

The Rapid Trigger mode also offers plenty of scope for meeting the demands of pro gamers. There’s an adaptive mode with three presets to choose from: Stable, Balanced, or Agile. But if you’re a tinkerer, there’s a manual mode with sliders for adjusting up- and downstrokes independently. These have a large range of 0.01mm to 2.4mm and increments of one hundredth of a millimeter. There’s also a Continuous Rapid Trigger mode, where a key only deactivates when you fully release the key, rather than merely releasing above your predefined actuation point.

This level of analog adjustability is very welcome. It’s a small shame, however, that there’s no controller emulation feature, as some other analog gaming keyboards have. But given the inconsistent effectiveness of such modes, I’m not too disappointed about its absence here.

I often find web apps less effective than standalone software, but I’m pleased to report that MelGeek’s is a fine example of the former. It’s fast, stable, and easy to use, thanks to its uncluttered layout and explanations of its various features. The only real drawback is the lack of visualization; I find this helps to inform all my actuation-related adjustments by letting me see their effects in real time.

MelGeek Made68 Ultra V2 review: Performance

Keycap in keycap removal tool with MelGeek Made68 Ultra V2 behind it, on a desk

(Image credit: Future)
  • Solid yet snappy keys
  • Reasonably comfortable WASD position
  • Great for typing

Perhaps the most striking aspect of the Made68 Ultra V2 is its key feel. The keys have no play to them and fire straight as an arrow. This makes them very secure, a feeling that’s bolstered by their mild but noticeable indentations. Their surface is pleasantly smooth without compromising traction.

Equally gratifying is the solid thud when the keys hit the end of their travel. There’s just enough dampening here to avoid them feeling harsh, and they still only require a light touch. They also rebound with impressive alacrity, which makes them feel snappy and responsive.

This combination of solid and springy means the Made68 Ultra V2 offers speed and control in equal parts, and makes it just as suitable for typing as it does for gaming. I made far fewer typos than I usually do with keycaps this tall and narrow, which is testament to the keyboard’s precise action.

Thanks to the forward tilt of the keys, the WASD position was comfortable, and reaching the outer keys was easy. I found myself hitting the edge of the space bar on occasion, but its lightness, feedback, and springiness made up for this. It’s a joy to use and one of the best I’ve experienced. I still wished the angle of the keys was a little steeper, though, and I would’ve welcomed a wrist rest for longer sessions to compensate for the thickness of the unit.

Should I buy the MelGeek Made68 Ultra V2?

Scorecard

Attributes

Notes

Rating

Value

Very expensive, even for an analog gaming keyboard. Equally capable boards from bigger names are sometimes cheaper.

2.5 / 5

Design and features

Very heavy and sturdy with a retro appeal. Plenty of customizations are available thanks to the web app.

3.5 / 5

Performance

The solid yet snappy keys are excellent for gaming and typing. The angle of the board is a bit too shallow, though.

4 / 5

Overall rating

The Made68 Ultra V2 is a high-performing and highly adjustable analog keyboard. But its faults are hard to excuse at this price point.

3.5 / 5

Buy it if…

You want solid keys
The thud of the keys is always satisfying, while their lightness and snappy rebound makes them easy to use.

You want plenty of customizations
Aside from controller emulation, the Made68 Ultra V2 has all the analog features you could wish for.

Don't buy it if…

You’re on a budget
Despite MelGeek being a relatively unknown brand, the Made68 Ultra V2 commands a premium price tag that would make even the big names blush.

You can’t touchtype
You’ll struggle to see the key markings when the RGB backlighting is on, which defeats the point.

MelGeek Made68 Ultra V2 review: Also consider

SteelSeries Apex Pro TKL Gen 3
In terms of sheer performance, the Apex Pro is one of the best analog gaming keyboards I’ve ever used. The feedback of the keys allows for precise control of inputs, while the myriad adjustments and customizations allow you to get the perfect setup. It’s also built very well, and is slightly cheaper than the Made68 Ultra V2. Read our full SteelSeries Apex Pro TKL Gen 3 review.

Razer Huntsman V3 Tenkeyless 8KHz
Another analog keyboard with a smorgasbord of adjustments and features, the Huntsman is a very competent performer. It perhaps doesn’t have the same satisfying feel as the Made68 Ultra V2, but it’s considerably cheaper. Read our full Razer Huntsman V3 Tenkeyless 8KHz review.

How I tested the MelGeek Made68 Ultra V2

Underside view of MelGeek Made68 Ultra V2, standing up on desk with pink wall in background

(Image credit: Future)
  • Tested for several days
  • Used for gaming and working
  • Plentiful gaming keyboard experience

I tested the Made68 Ultra V2 for several days, during which time I used it for gaming, working, and general browsing.

I played games such as Counter-Strike 2, which is a stern test for peripherals, given the demands it places on speed and precision.

I’ve been using gaming keyboards for years, and have reviewed a large number of them, across all manner of price points, switch types, and form factors.

US and security allies warn Russian attacks on critical infrastructure are ramping up against 'poorly configured and vulnerable networking devices worldwide'

  • NSA, FBI, CISA, and 15 allied agencies warn Russia’s FSB Center 16 is exploiting weak/default credentials and old Cisco flaws to compromise critical infrastructure devices
  • Advisory highlights CVE‑2018‑0171 (Smart Install DoS/RCE) and CVE‑2008‑412813 (CSRF in Cisco IOS 12.4) as examples of vulnerabilities still being abused
  • TTPs overlap with Chinese groups but attribution points to Russian actors like Berserk Bear and Energetic Bear; full IoCs and mitigations were published in the joint advisory

Russian state-sponsored threat actors are continuously targeting broken and poorly configured networking devices belonging to critical infrastructure providers all around the world, a joint security advisory published by the US National Security Agency (NSA) and more than a dozen other agencies has warned.

As per the advisory, hackers working for the Russian Federal Security Service (FSB) Center 16 are constantly scanning for routers and other internet-connected devices that can be accessed with “common or default” login credentials.

Once found, these devices are instructed to copy device configuration files and later exfiltrate them via the Trivial File Transfer Protocol to servers under their control.

Berserk Bear and Salt Typhoon

In cases where default or weak credentials don’t work, the threat actors also try to exploit vulnerabilities. In the advisory, the agencies specifically mentioned two flaws in Cisco devices - CVE-2018-0171 and CVE-2008-412813. The former is an eight-year-old bug in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software that allows an unauthenticated, remote attacker to cause a denial of service (DoS) condition, or to execute arbitrary code.

The latter is an even older (18 years old) set of multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router that allows remote attackers to execute arbitrary commands.

Even though many of these tactics, techniques, and procedures (TTP) overlap with Chinese hackers Salt Typhoon, the agencies suggested they are primarily focusing on Russian hackers known as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, or Static Tundra.

The joint advisory is co-authored by the NSA, FBI, and CISA, as well as 15 other agencies from Australia, the United Kingdom, Canada, New Zealand, Estonia, Finland, France, and Italy.

This new macOS infostealer poses as an Apple crash reporting tool to try and steal all your valuable data

  • Jamf researchers uncover “CrashStealer,” a notarized macOS infostealer disguised as Apple’s CrashReporter
  • Distributed via a fake site called “Werkbit Setup”, it bypasses Gatekeeper, installs a LaunchAgent
  • It then uses a fake password prompt to unlock Keychain, exfiltrating credentials, cookies, files, and data from 80 crypto wallets and 14 password managers

A new macOS infostealer has been spotted in the wild, masquerading as an Apple crash reporting tool, experts have warned.

Called CrashStealer, this C++ infostealer was designed to nab login credentials, keychain information, as well as data related to more than 80 cryptocurrency wallets.

Cybersecurity researchers Jamf published an in-depth report on the malware, noting CrashStealer is most likely distributed via a fake software site that was only registered recently.

Unlocking Keychain

Victims who land on the site (either via a social media recommendation or search engine results) need to know the PIN code before initiating the download. This was most likely done to avoid analyst scrutiny, as well as to increase perceived credibility and a sense of exclusivity.

Usually, apps downloaded from third-party sources are scanned by Gatekeeper, Apple’s built-in security system. However, Jamf says that this payload is delivered via a signed and Apple-notarized installer and distributed as a disk image named “Werkbit Setup”, which allowed it to bypass Gatekeeper without any warnings.

Those that download and run the program will get a binary named ‘CrashReporter.app’, which will create a LaunchAgent (‘com.apple.crashreporter.helper’), and will see a fake macOS password prompt.

That prompt unlocks the user’s Keychain where most of their secrets are stored (passwords, private cryptographic keys, and more) and then exfiltrates all information to a third-party server.

Besides Keychain data, the CrashReporter malware also pulls browser credentials and cookies from most browsers, data from 80 cryptocurrency wallet extensions, 14 password managers, locally stored files, and more.

Jamf said CrashReporter overlaps, to some extent, with other known infostealers (AMOS, for example), but is still unique enough given its client-side encryption mechanism, as well as the native C++ implementation.

Unlucky Redditor orders Corsair DDR5 RAM from Amazon and gets sent dummy light sticks instead — but one trick saves their skin

  • A Reddit user bought what they thought was computer RAM off Amazon
  • Instead, Amazon shipped them a light kit inside a RAM box
  • The Redditor filmed themselves opening the box to aid with their return

High prices spurred by the current RAM crisis are making it almost impossible to buy a set of computer memory without bankrupting yourself, so it can be tempting to pull the trigger on an eye-catching bargain whenever you see one. But a cautionary tale from social media shows why certain deals might not be all they seem.

That warning comes from a Reddit post from user BupMaster titled “Decided to buy RAM from Amazon despite my better judgement and it happened to me...” That foreboding header hinted at the potentially disastrous situation that was to come.

The poster explained how they decided to buy RAM from Amazon for a setup upgrade, despite hearing stories about return scams. These typically involve a scammer buying an expensive product then returning it with a cheaper, different or counterfeit item, which then gets sent onto an innocent buyer.

"Thankfully I made sure to record my unboxing," the Redditor explained. "Lo and behold I open the package and see that someone swapped the sticks for light enhancement kits instead. Sold and shipped by Amazon too. Hopefully they don't give me too much of a hard time on the return.”

This example highlights how careful you’ve got to be when buying memory — or other in-demand computing components like storage — during this highly unusual era. With RAM in record low supply thanks to the demands of artificial intelligence (AI) data centers, scammers are sniffing out opportunities wherever they can. Unfortunately for this Redditor, they ended up falling prey.

Keep your wits about you

Decided to buy RAM from Amazon despite my better judgement and it happened to me... from r/pcmasterrace

Interestingly, Corsair — the company whose RAM BupMaster bought — changed its packaging earlier this year specifically to thwart scammers. Instead of cardboard boxes, the company now sells its memory modules in clear plastic blister packs. The unit received by the Redditor was in a cardboard container, though, hinting that the scammer wanted to obscure their actions.

Another intriguing point about this account is that the scam was not perpetuated by some dodgy website or even a rogue trader on Amazon. The RAM kit was sold directly by Amazon itself, suggesting that someone inside the company swapped the memory modules for the dud product.

Sadly, this Redditor is far from the only person to have suffered in this way. In the same thread, another user claimed that the same thing happened with a laptop. And we've reported on countless similar cases, suggesting that scams like this are an all-too-common occurrence.

This case also shows how important it can be to record yourself opening a package if you’re at all unsure or wary about it. Doing so gave them the perfect evidence to prove to Amazon that they had been scammed, making the return process much easier.

Amazon is known for being very willing to accept returns, but it’s better to be safe than sorry — especially when buying rare and expensive products like computer memory.

'We love this... except gradual rollouts': Windows 11 search is being improved in a big way, with users impatient to get these changes — and I don't blame them

  • Microsoft is improving Windows 11 search in multiple ways
  • That includes a calmer search panel, the ability to turn off web results, a better way of prioritizing returned results, and a more stable search overall
  • This is in testing for now, and the main worry is how long it might take for Microsoft to usher all this through to release

If you're fed up with the way Windows 11's search functionality works – and you wouldn't be alone – some incoming changes are set to greatly improve this experience.

Microsoft revealed the tweaks to the search box in a blog post, explaining that they're being delivered via a gradual rollout to testers in the Experimental channel for Windows 11 preview builds.

The first major change is simply to make search a calmer place, so when the panel appears, it only contains a list of your recent searches (allowing you to easily fire up one of those again if you wish). The current clutter to the right of that list, including recommendations – some of which are outright adverts – along with trending searches has all been banished.

And the second important piece of work here is that Microsoft is finally giving Windows 11 users the ability to get rid of web results in search. Currently, when searching for a file in the operating system you get not just local results (for files on your drives), but also some web results which can get in the way.

In this new scheme of things, you'll be able to switch off all web results in Settings, and also ditch Microsoft Store suggestions too.

If you keep these results on, Microsoft notes that they won't be prioritized, although this is something the company had already started to address (it used to be the case that web content could appear at the top of the returned results in a truly baffling fashion). Web results have also been stripped of any 'promotional content' so you'll only get the most relevant answers if these results are enabled.

Microsoft has also bolstered the handling of results for Windows 11 settings so that more relevant options are flagged up higher in the pecking order, and Microsoft says further fine-tuning is planned on this front.

The search box will also be able to handle typos, with an improved ability to guess what you really meant ('Chrome' rather than 'Chome' for example), and it'll start to surface possible results after typing just two characters (another enhancement we've already heard about).

While this is mostly all about streamlining, Microsoft is going the other way in one notable respect — adding a bit more detail in for the files returned in the results. Search will now provide more info about files (such as when they were last opened) and a more in-depth preview in the right-hand panel, so you can more readily tell what you'll be opening if you click on that result.

Finally, Microsoft is making search more reliable, which involves "reducing [the] likelihood of crashing and loading issues" which is obviously a welcome move.

Analysis: the rollout fly in the soothing search ointment

Screenshot of Windows 11 search revamp in 2026 showing old results versus new more streamlined panel

(Image credit: Microsoft)

Windows 11 search has always been a somewhat painful affair for me, thanks mainly to the clutter of the thinly veiled (or not even veiled at all) ads, and the irrelevant results which were surfaced with a baffling level of priority, as noted. Windows 10 isn't a lot better, frankly, but at any rate, I'm very happy to see the fresh direction Microsoft has taken here.

The calmer search results are a major boon, with Microsoft following in the same vein as the streamlining it recently announced for the widgets panel, which was made a quieter place. (All this follows a broader early promise to rein in the upselling with Windows 11 and generally make the interface a more chilled place).

I was hoping that the option to turn off web results would be brought in, and this is the most important addition for me personally. I'm not alone, and the reaction to these various changes has been very positive, with the only real sticking point being impatience around when these new features will be rolled out. That's both in terms of testers wanting to try the revamped search box now, and the general computing public wondering when they will eventually get their hands on all this.

As this tester posts on Reddit: "We love this... except gradual rollouts. We don't like when things are inconsistent from PC to PC despite running identical [test] builds [of Windows 11]. It's really obnoxious and breaks muscle memory. But the changes seem great and I look forward to trying them."

As Microsoft points out in its blog post, it's worth remembering that there are now feature flags that can be enabled if you're really keen to try out something in a preview build, and it's not on your PC yet.

However, as for those asking: 'For those of us on release, when might this arrive?'

Well, that's a very different kettle of fish, as it could take quite some time for this work to progress through testing. Mainly because there are a lot of changes involved, and it's not something Microsoft will want to rush (especially given the drive to make search more reliable and stable).

And when these search improvements are eventually released outside of testing, it'll be on a controlled rollout that you won't be able to jump the queue with. However, there's a reason for that – Microsoft will need to observe the changes going live in a gradual manner to ensure no unexpected gremlins are crawling around in the works.

So, you will have to be patient, and there's some frustration around the length of time it can take for controlled rollouts to proceed these days (the Start menu overhaul from last year being a key example here – some folks still don't have it even now). But the good news is that these changes are coming, and they promise to revamp search in Windows 11 to a considerable extent. I can't wait (but I'll have to).

Is this the ultimate 'back to school' laptop? Students can get a brand new 2026 Dell XPS 13 for just $599

I'm always keeping my eye out this time of year for the ultimate 'back to school' laptop deals for our readers. Today, I think I've spotted a listing that could actually lay claim to that title.

It's the brand new Dell XPS 13, which is currently on sale for just $599 if you're a student. This new model has just been released at $699, but it looks like Dell is doing a particularly aggressive intro deal for prospective students right now.

To be honest, even at $699, I'd say this Dell XPS 13 is a strong contender. We haven't reviewed it yet here at TechRadar, but this iteration looks like a very compelling alternative to the likes of the new MacBook Neo, which is also $699.

It's surely no coincidence that the new XPS 13 is priced to compete with the MacBook Neo, as both offer a premium, lightweight laptop at a rock bottom price. The XPS 13 is obviously a Windows 11 machine, however, so it's the one to go for if you prefer Windows over MacOS.

Get the new Dell XPS 13 for just $599 today

Processor: Intel Core 5-320 
RAM: 8GB
Storage: 512GB

In a time where laptop prices are spiralling out of control, Dell's latest XPS 13 looks like a rare deal on a premium model. OK, so this is the baseline model with only 8GB of RAM, but the XPS 13 is a great laptop with a fantastic 120Hz display and excellent build quality. Considering that Dell are also offering students an impressive $100 discount at launch, this XPS 13 looks like a very competitive alternative to the likes of the MacBook Neo.View Deal

While we haven't reviewed this model yet, our sister-site Windows Central managed to check it out in-person earlier this year. Initial reports are exceedingly positive, with the price, display, and overall build quality being particular highlights.

Interestingly, Dell had MacBook Neos on display next to the New XPS 13, so journalists could directly compare the to models. According to Windows Central, the XPS 13 had better build quality, a better display, and it was lighter. Of course, they do love Windows laptops over on that site, so your preference may vary.

We still rate the MacBook Neo here at TechRadar with its eye-catching colors and incredible battery life.

With that said, if I were choosing between the two, I'd definitely be tempted by the XPS 13. Generally, I prefer Windows laptops, and the XPS 13's Thunderbolt 4 ports are more useful to me than the Neo's standard USB-C ports. I'm also partial to the XPS 13's display, which I think it is a little more modern-looking than the Neo's, with its thick-bezels.

'It's exploding now?' — Reddit user's Zotac RTX 5090 'explodes' while playing Assassin's Creed Black Flag Resynced, and I'm starting to get worried that high-powered GPUs aren't safe

  • A Reddit user's Zotac GeForce RTX 5090 GPU reportedly exploded during gameplay
  • The power connector wasn't damaged, but a visible burn mark was present on the PCB gold finger
  • It's yet another point of concern for RTX 5090 users

Nvidia's RTX 5090 has been the subject of controversy ever since its launch, with several well-publicised cases of melting power connectors causing malfunctions — and this time, it's arguably the worst case yet.

As reported by Wccftech, a Reddit user's Zotac RTX 5090 GPU has exploded, 'five minutes' into playing the tutorial for Assassin's Creed Black Flag Resynced. Interestingly, the 16-pin power connector (often the case of the RTX 5090's woes) wasn't damaged. Instead, the user claims they heard a loud pop and crackle, followed by a cloud of smoke.

The 16-pin power connector has been blamed for several RTX 5090s melting, either due to high temperatures or connectors that aren't properly seated. It also shouldn't be a surprise that these melting complications are effectively exclusive to Nvidia's flagship GPU, since it draws a significant amount of power (575W maximum).

Instead, the PCB gold finger (the part that goes into the motherboard's PCIe slot) on the user's Zotac RTX 5090 has a visible burn mark. The cause isn't exactly clear, but speculation suggests that a crack in the circuit board may have caused the GPU to short-circuit.

Desktop Computer Burned Damage CPU GPU video card, memory, chip , cooler

(Image credit: Zoomik / Shutterstock)
Comment from r/pcmasterrace
Comment from r/pcmasterrace
Comment from r/pcmasterrace

Perhaps the most concerning aspect of this case is the suggestion from fellow Reddit users that the supposed crack and short circuit may be the result of GPU sag — and if that's the case, it should be a major concern for high-powered GPU users.

Plenty of modern GPUs, notably from third-party Nvidia partners, are quite chunky, which leaves little clearance to fit in smaller cases and, most importantly, not enough space to use GPU sag brackets.

Fortunately, the RTX 5080, RTX 4080, and RTX 4080 Super (which is the GPU I use) aren't cards that draw nearly as much power as the RTX 5090, so there isn't too much concern in terms of power connectors melting. However, if GPU sag can lead to a short circuit, it raises concern for any GPU that's heavier than most, especially the high-powered RTX 5090, as it's an additional issue to be wary of alongside melting connectors.

A melting or exploding GPU in this current PC hardware market is possibly the worst-case scenario, particularly for RTX 5090 users (who are seemingly most at risk), as prices are completely out of the affordable range due to the ongoing RAM crisis.

Frankly, it makes me want to steer clear of high-wattage GPUs completely (or at least undervolt them). TechRadar has contacted Nvidia for a response.

Japan's largest taxi operator Nihon Kotsu hit by cyberattack which forces systems to be shut down

  • Japan’s largest taxi operator confirms July 11 malware attack forcing shutdowns of its IT systems and disrupted dispatch and reservation services
  • Nihon Kotsu isolated networks, notified authorities, and brought in third‑party experts; customers were advised to use alternative taxi apps during the outage
  • No data leaks have been confirmed, but Nihon Kotsu warned it may disclose and notify affected parties if evidence of personal information exposure emerges

Japan’s largest taxi operator, Nihon Kotsu, hasconfirmed suffering a cyberattack which forced it to temporarily shut down parts of its IT infrastructure.

In a statement published on the company’s Japanese website, Nihon Kotsu said the attack took place in the early morning of July 11 - on a Saturday, when unnamed threat actors infected its devices with malware.

“We have recently discovered that our internal systems have been subjected to unauthorized external access (malware infection),” the machine-translated statement reads. “We deeply apologize for the great inconvenience and concern caused to our customers, business partners, and all related parties due to this incident.”

Services unavailable

As soon as it spotted the intrusion, Nihon Kotsu did what most companies do - shut down its network to prevent further damage, notified relevant law enforcement and data protection authorities, and brought in third-party experts to assess the damages and assist with the repairs.

The shutdown means some customer-facing services are unavailable: “As a result, the hire car web order and reservation management system, taxi dispatch service by phone, and some internal systems are temporarily unavailable,” the company said.

It advised its customers to use a different taxi app, which allows users to choose a taxi service to their liking.

So far, there is no evidence of any data exfiltration, or leaks to the dark web. However, the company did leave it as a possibility.

“At this time, no information leakage has been confirmed, but if any leakage or possibility of personal information of customers or related parties is newly discovered, we will promptly make official announcements and contact the affected parties individually in accordance with laws and regulations,” the company concluded.

Nihon Kotsu is Japan’s largest taxi operator, employing more than 18,000 people and running a fleet of more than 8,500 taxis and more than 2,000 chauffeur vehicles.

Via BleepingComputer

Quordle hints and answers for Tuesday, July 14 (game #1632)

Looking for a different day?

A new Quordle puzzle appears at midnight each day for your time zone – which means that some people are always playing 'today's game' while others are playing 'yesterday's'. If you're looking for Monday's puzzle instead then click here: Quordle hints and answers for Monday, July 13 (game #1631).

Quordle was one of the original Wordle alternatives and is still going strong now more than 1,500 games later. It offers a genuine challenge, though, so read on if you need some Quordle hints today — or scroll down further for the answers.

Enjoy playing word games? You can also check out my NYT Connections today and NYT Strands today pages for hints and answers for those puzzles, while Marc's Wordle today column covers the original viral word game.

SPOILER WARNING: Information about Quordle today is below, so don't read on if you don't want to know the answers.

Quordle today (game #1632) — hint #1 — Vowels

How many different vowels are in Quordle today?

The number of different vowels in Quordle today is 5*.

* Note that by vowel we mean the five standard vowels (A, E, I, O, U), not Y (which is sometimes counted as a vowel too).

Quordle today (game #1632) — hint #2 — repeated letters

Do any of today's Quordle answers contain repeated letters?

The number of Quordle answers containing a repeated letter today is 1.

Quordle today (game #1632) — hint #3 — uncommon letters

Do the letters Q, Z, X or J appear in Quordle today?

• No. None of Q, Z, X or J appear among today's Quordle answers.

Quordle today (game #1632) — hint #4 — starting letters (1)

Do any of today's Quordle puzzles start with the same letter?

The number of today's Quordle answers starting with the same letter is 0.

If you just want to know the answers at this stage, simply scroll down. If you're not ready yet then here's one more clue to make things a lot easier:

Quordle today (game #1632) — hint #5 — starting letters (2)

What letters do today's Quordle answers start with?

• E

• A

• R

• C

Right, the answers are below, so DO NOT SCROLL ANY FURTHER IF YOU DON'T WANT TO SEE THEM.

Quordle today (game #1632) — the answers

Quordle answers for game 1632 on a yellow background

(Image credit: Merriam-Webster)

The answers to today's Quordle, game #1632, are…

  • EBONY
  • AVOID
  • RODEO
  • CUTIE

There was a while when I doubted my three starter words of “duchy”, “robin” and “slate”, but they really have helped me whiz through games recently.

Today, for example, I had three words where I had all the right letters (but not necessarily in the right order) and one word where the missing letter was obvious.

Daily Sequence today (game #1632) — the answers

Quordle Daily Sequence answers for game 1632 on a yellow background

(Image credit: Merriam-Webster)

The answers to today's Quordle Daily Sequence, game #1632, are…

  • SEDAN
  • VALVE
  • FAULT
  • SMELT

Quordle answers: The past 20

  • Quordle #1631, Monday, 13 July: VOICE, BISON, BURNT, BUILT
  • Quordle #1630, Sunday, 12 July: STAIN, BINGO, LARVA, DICEY
  • Quordle #1629, Saturday, 11 July: WORTH, PRONG, DINGO, DRUID
  • Quordle #1628, Friday, 10 July: GREET, STEAK, DUSKY, HAUTE
  • Quordle #1627, Thursday, 9 July: CRUMP, PHONE, SHINY, STONY
  • Quordle #1626, Wednesday, 8 July: GHOST, TREND, EXALT, ALONG
  • Quordle #1625, Tuesday, 7 July: ARRAY, SUITE, KIOSK, BOULE
  • Quordle #1624, Monday, 6 July: TRAWL, SPICE, PIANO, SHARK
  • Quordle #1623, Sunday, 5 July: PINEY, SWOON, TITLE, PINTO
  • Quordle #1622, Saturday, 4 July: ARGUE, MOTEL, OPERA, TRUCE
  • Quordle #1621, Friday, 3 July: AVERT, MOTOR, MANIC, WORDY
  • Quordle #1620, Thursday, 2 July: BULKY, PARSE, BELOW, MOVIE
  • Quordle #1619, Wednesday, 1 July: EASEL, OTTER, LYRIC, SHACK
  • Quordle #1618, Tuesday, 30 June: HALVE, DRYER, THERE, MINTY
  • Quordle #1617, Monday, 29 June: SLURP, CRACK, CRANK, PHONY
  • Quordle #1616, Sunday, 28 June: RUPEE, TOPAZ, FULLY, BEING
  • Quordle #1615, Saturday, 27 June: PRINT, MARRY, SADLY, BICEP
  • Quordle #1614, Friday, 26 June: JUICE, ARRAY, BONEY, SKIFF
  • Quordle #1613, Thursday, 25 June: SHELF, TAWNY, HYPER, SOLVE
  • Quordle #1612, Wednesday, 24 June: SOBER, ECLAT, GOOSE, NINNY

NYT Strands hints and answers for Tuesday, July 14 (game #863)

Looking for a different day?

A new NYT Strands puzzle appears at midnight each day for your time zone – which means that some people are always playing 'today's game' while others are playing 'yesterday's'. If you're looking for Monday's puzzle instead then click here: NYT Strands hints and answers for Monday, July 13 (game #862).

Strands is the NYT's latest word game after the likes of Wordle, Spelling Bee and Connections – and it's great fun. It can be difficult, though, so read on for my Strands hints.

Want more word-based fun? Then check out my NYT Connections today and Quordle today pages for hints and answers for those games, and Marc's Wordle today page for the original viral word game.

SPOILER WARNING: Information about NYT Strands today is below, so don't read on if you don't want to know the answers.

NYT Strands today (game #863) - hint #1 - today's theme

What is the theme of today's NYT Strands?

Today's NYT Strands theme is… Make yourself comfortable

NYT Strands today (game #863) - hint #2 - clue words

Play any of these words to unlock the in-game hints system.

  • RELIC
  • SOCK
  • BREAK
  • ERASE
  • HORN
  • RAVE

NYT Strands today (game #863) - hint #3 - spangram letters

How many letters are in today's spangram?

Spangram has 9 letters

NYT Strands today (game #863) - hint #4 - spangram position

What are two sides of the board that today's spangram touches?

First side: left, 2nd row

Last side: right, 5th row

Right, the answers are below, so DO NOT SCROLL ANY FURTHER IF YOU DON'T WANT TO SEE THEM.

NYT Strands today (game #863) - the answers

NYT Strands answers for game 863 on a blue background

(Image credit: New York Times)

The answers to today's Strands, game #863, are…

  • CHAIR
  • ROCKER
  • BEANBAG
  • OTTOMAN
  • RECLINER
  • THRONE
  • SPANGRAM: HAVEASEAT
  • My rating: Easy
  • My score: Perfect

Today’s search takes from the high-born of the seating world (THRONE), to the lowest (BEANBAG).

If I am going to make myself comfortable then I would pick the BEANBAG any day. Although it does depend on how long you’ve owned it; a baggy bean bag is nobody’s friend. Having said that, I’ve not sat in many thrones. Or indeed any, but judging by House of the Dragon, they’re not particularly ergonomic.

Anyway, it was hard not to whizz around today’s game, with even the longest and most obscure word, OTTOMAN, being easy to spot thanks to the double T.

Yesterday's NYT Strands answers (Monday, July 13, game #862)

  • PLEASANT
  • DELIGHTFUL
  • ENJOYABLE
  • SATISFYING
  • SPANGRAM: HITSTHESPOT

What is NYT Strands?

Strands is the NYT's not-so-new-any-more word game, following Wordle and Connections. It's now a fully fledged member of the NYT's games stable that has been running for a year and which can be played on the NYT Games site on desktop or mobile.

I've got a full guide to how to play NYT Strands, complete with tips for solving it, so check that out if you're struggling to beat it each day.

Watch out Windows users, a Secure Boot update has been blocked on Windows 11 PCs due to failing on some devices — here's how to check if you're affected

  • Microsoft has blocked Secure Boot updates on some devices
  • There have been issues with some devices updating from the 2011 certificate to the latest 2023 certificate
  • Some older devices or those not supported by their OEM may be restricted in downloading the latest Secure Boot certificates

Microsoft has blocked some Windows 11 PCs from installing Secure Boot updates due to known issues with certificate updates.

The company is currently rolling out an update for Secure Boot on devices using certificates issued in 2011, which are now expired. The new 2023 certificate is being applied through Windows Update, but issues on devices with faulty firmware have forced Microsoft to halt the rollout.

“Devices in this group are affected by a known issue. To reduce risk, Secure Boot certificate updates are temporarily paused while Microsoft and partners work toward a supported resolution,” Microsoft said.

Secure Boot issues

Secure Boot has long been a device-saving feature when it comes to removing malicious files, as it allows the device to verify and load only authentic software before booting to Windows. However if the device cannot receive certificate updates it can fall victim to threats at the boot-level before Windows is loaded.

Microsoft is currently working with manufacturers to issue a patch that will allow affected devices to install the new Secure Boot 2023 certificate, with HP issuing a BIOS update to allow the installation of the latest certificate.

What this means in practice is that some older devices, or devices that no longer receive updates via their Original Equipment Manufacturer (OEM), will not be able to apply Secure Boot and Boot Manager protections. Microsoft clarified that, “this results in a gradual reduction in long-term security—not an immediate risk or system failure. Continue to follow standard security practices, including staying current with Windows updates.”

So even if your device is blocked from installing the latest Secure Boot certificate, it will continue to work properly, other Windows updates will continue to work, and your Secure Boot version will continue to protect against known vulnerabilities. It’s just future vulnerabilities that users affected by this issue will need to be aware of.

Many users may not be aware of issues until they need to use Secure Boot, so the silver lining in Microsoft’s warning is that now is the perfect time to check if your Secure Boot is working properly.

How to check Secure Boot is up to date

To check if you are using the latest Secure Boot certificate, take the following steps:

  • Open the Windows Security app using the search bar
  • Navigate to the Device Security dashboard using the menu on the right hand side
  • Look at the Secure Boot section, and check for the following messages:

The Windows Secure boot section on the Device Security dashboard, showing that Secure Boot is working properly.

(Image credit: Microsoft)
  1. "Secure Boot is on"

If you see this message, Secure Boot is likely working properly. However, this does not display your certificates’ current state. Microsoft has been rolling out an update to show if your Secure Boot is running on the latest certificate, so make sure your don't have any pending Windows updates.

The Windows Secure boot section on the Device Security dashboard, showing that Secure Boot is affected by a known issue but can be updated by the OEM.

(Image credit: Microsoft)
  1. “Devices in this group are affected by a known issue.”

Devices with this message will likely be able to install the latest certificates once a firmware update has been issued by your OEM. Check your OEM update channel for availability.

The Windows Secure boot section on the Device Security dashboard, showing that Secure Boot is not supported for the latest Secure Boot certificate.

(Image credit: Microsoft)
  1. “Secure Boot is on, but your device does not support the automated Secure Boot certificate update due to hardware or firmware limitations.”

Devices with this message may no longer be supported by your OEM, or the OEM might no longer be able to provide the firmware updates needed. Microsoft recommends checking your OEM’s Secure Boot support page to confirm whether your device is out of support.

Via WindowsLatest

Ransomware negotiator jailed for 70 months after he just helped infect victims with malware

  • Ransomware negotiator Angelo Martino will serve 70 months in prison for secretly aiding BlackCat (ALPHV) attackers
  • Martino forfeits crypto proceeds, houses, cars, and boats, and must pay 10% of future salary after release
  • Martino was the third negotiator exposed; his co‑conspirators Ryan Clifford Goldberg and Kevin Tyler Martin previously received four‑year sentences for similar insider collusion

A ransomware negotiator who worked with the attackers behind his clients’ backs has been sentenced to almost six years in prison.

A sentencing memorandum published by the US government said 41-year-old Angelo Martino will spend the next 70 months in prison, and will also lose all of the cryptocurrency the attackers paid him for sharing insider information, as well as all of the houses, cars, and boats, he had bought with this money.

He will also have to pay 10% of any salary he earns after his release.

Asking for a shorter sentence

In November 2025, it was reported that three men who worked as ransomware negotiators to help victims minimize the damages of these attacks were actually agents for the dreaded BlackCat (ALPHV) ransomware collective.

Over the next months, it was reported that the men - Ryan Clifford Goldberg of Georgia, Kevin Tyler Martin of Texas, and Angelo Martino of Land O'Lakes, Florida, not only did not help their victims, but actually infected some of them with ransomware, and later shared valuable insider information with other BlackCat affiliates, in order to maximize the payment.

Their victims included at least five companies: a medical device company from Florida (demanded $10 million in ransom, ended up paying around $1.2 million), a pharmaceutical company from Maryland, a doctor’s office and an engineering company in California, and a drone manufacturer based in Virginia.

While all three faced serious prison time (between 10 and 20 years), they received far less. Martin and Goldberg were each sentenced to four years in prison in April 2026, while Martino will spend five years and ten months behind bars. Martino pleaded guilty and asked for a 24-month sentence, stating he “provided substantial assistance that contributed to the indictment and conviction of two co-defendants.” It didn’t work.

Via Ars Technica

Experts say they were able to create a rogue agent in Google’s AI platform with just a single edit permission

  • Varonis uncovered CVE‑level flaws in Google Cloud Dialogflow CX, where malicious Code Blocks in Playbooks could hijack agents, exfiltrate chat logs, and steal credentials
  • Shared Cloud Run environment with excess privileges meant one compromised agent could control all others in a project, with attacks virtually undetectable in Cloud Logging
  • Google patched the issue between April–June 2026; researchers advise reviewing audit logs, checking anomalous errors, and manually inspecting Code Blocks for unauthorized code

Researchers recently found a critical vulnerability in Google Cloud’s Dialogflow CX, allowing threat actors to take over different AI agents, access chat logs, and even exfiltrate sensitive data such as login credentials.

Dialogflow CX is Google Cloud’s conversational AI platform used to build many voice and text chatbots. This platform lets developers add Code Blocks, which are custom Python snippets, into conversation “Playbooks”. These blocks all execute inside a single Google-managed Cloud Run service, shared across all agents in a Google Cloud Platform project.

Security researchers Varonis said they discovered a critical vulnerability in which the theoretical attacker didn’t need broad admin access. With permission to edit a single chatbot’s settings, they would be able to plant malicious code relatively easily. The Cloud Run environment had no code restrictions, Varonis further explained, but had a writable filesystem, public internet egress, and ran with excess privileges. Key files could have been overwritten entirely, it was added.

Google issues a fix

As a result, the attacker had access to full conversation history and session state. They could call internal functions and fake LLM-generated replies which, they claim, could lead to phishing and credential theft.

Since the environment is shared per-project, one compromised agent could take over every other agent in that project, and since Cloud Logging doesn’t capture the file overwrite or injected logic, the attack would be "virtually undetectable."

Varonis reported the issue to Google in November 2025, and the latter came back with an initial fix in April 2026. However, the issue had not been fully resolved until June 2026.

In the report, the researchers said there is no evidence of in-the-wild exploitation attempts and advises customers to review DATA_WRITE audit logs for Playbooks.UpdatePlaybook calls, check for anomalous Sessions.DetectIntent errors, and manually inspect each agent's Code Blocks for leftover unauthorized code.

New Steam Machine red light warning isn't anything to worry about — an overzealous overheating warning is reportedly due to a BIOS bug

  • There's a new red light issue with the Steam Machine
  • This time a solid red light is being displayed which indicates the device is running hot
  • That isn't necessarily the case, and in fact the Steam Machine's temperatures can be normal, and a bug in the BIOS can cause the light to come on

If you're an early adopter who's been worrying about a red light being displayed by your Steam Machine while gaming, then there's not necessarily anything to panic about, as apparently this temperature warning light is being mistakenly triggered.

VideoCardz noticed a thread on Reddit where the original poster shares correspondence from Valve's support team about what's happening in terms of the red light coming on when the temperature is nowhere near the intended warning threshold.

As per Valve's FAQ on the Steam Machine's light bar, the red light comes on solidly (across the whole bar) when the device is deemed to be overheating, meaning the CPU temperature is over 95C or the GPU is over 90C (or indeed both).

The Redditor noticed that the red light was on when their Steam Machine was at temperatures of 75C and 81C for the GPU and CPU respectively, neither of which should have caused the warning light to appear.

As the message from Valve explains, there is a "known issue with the current BIOS" that means the red light comes on "much earlier" than it should.

The problem is entirely related to the temperature threshold for the light, and the Steam Machine is not overheating in any way in these cases, it should be noted.

The message from Valve informs us that a BIOS update will be coming to fix the problem soon. In fact, that update will increase the threshold to 100C for both the CPU and GPU, which is the point at which the Steam Machine will throttle the components to ensure they don't get any hotter.

In case you were wondering, if either the CPU or GPU does get any hotter than 100C, the device will then shut down to protect itself from any potential damage.

Analysis: false alarm

The Steam Machine next to a fish bowl

(Image credit: Valve)

What this means is that if you're seeing the red warning light a fair bit, it's likely a symptom of this overkeen BIOS which is turning on the light way earlier than it should be. Odds are that your CPU and GPU are running cool enough, and you can check this using the Steam performance monitor or a third-party tool as the Redditor did.

In any case, even if you do see the red light and it's correctly indicating temperatures at Valve's threshold levels, this isn't going to damage the Steam Machine – it just means the components will be throttled back to run slower to prevent any such damage. If that doesn't work, and the component temps aren't brought back under control, as noted the PC will turn itself off to avoid any potential GPU or CPU-frying scenarios.

It's not a pleasant thought that your Steam Machine is throttling and not running as fast as it should, though, if this happens – but based on this (and other) reports of this incident, that isn't the case, and the only error is the light showing when it shouldn't. There's no actual overheating, throttling, or anything else going on under the hood.

If you're worried that Valve's new temperatures for throttling and the warning light seem high at 100C, this is in line with what's to be expected from AMD laptop parts (which are what's used for the Steam Machine's CPU and GPU).

For now, all those who have bought one of Valve's gaming PCs can do is wait until the next BIOS update which should hopefully fix this problem. It's also worth noting that the 'Red Line of Death' is a completely separate issue, and we've had some troubleshooting advice on that knottier problem since it was first highlighted.

Confused about your PC specs or hardware? Windows 11's Copilot app is getting new powers to help you 'understand your device'

  • Windows 11's Copilot app has a new feature in testing
  • 'PC insights' provides an easy way to receive clear answers to hardware-based questions about your device and its specs
  • While there are some fears over privacy (and bloat), Microsoft has made it clear that Copilot needs to be granted permission to access your system and files

Copilot is getting a new ability to answer questions about your PC's hardware, allowing the AI to tap into the relevant hardware details to do so – and while Microsoft is treading carefully with privacy here, that's unlikely to stop some level of paranoia.

Windows Latest flagged the introduction of 'PC insights' for the Copilot app on Windows 11, which as Microsoft explains, "enables customers to conversationally ask Copilot questions about their Windows PC and receive clear responses based on their device's state without having to dig through system settings."

This is currently an experimental feature, so still in testing, and an optional ability that you must turn on for it to be in play. Windows Latest notes that it's gradually rolling out, but only in the US for now.

You can ask Copilot how much RAM you have, or storage space left, or what your GPU is, and the current level of usage for your processor, and a whole bunch of similar component-related queries. You can ask about elements as diverse as whether you have an antivirus running, or what your laptop's battery health is, diving into mild troubleshooting territory should you wish.

To get its answers, the Copilot app hooks up to Windows APIs to analyze your system, and the AI asks for permission to do this. You can allow it access to your PC's hardware details on a one-time basis for that session only, or you can elect to 'always allow' if you're happy to give Copilot this access on a more permanent basis.

Analysis: fears over hallucinations and bloat

Young woman using Windows 11 laptop, looking annoyed

(Image credit: Getty Images)

As ever, this is AI, and as Microsoft notes, Copilot "may not always provide complete or accurate information", especially during this testing phase. So, if you do get a chance to try out PC insights, maintain a healthy sense of skepticism with the responses you get.

As Windows Latest makes clear, there's also a certain irony about a Windows 11 user checking up on resource usage, perhaps due to system sluggishness, employing the Copilot AI to run diagnostics when the app itself uses the best part of 1GB of RAM when running in the background and doing nothing.

That doesn't stop this new PC insights feature from being situationally useful, of course. Some of the reaction has come from a place of disdain, though, as you might guess, with comments such as the one from this Redditor: "Oh hey it's like Task Manager except instead of lightweight and authoritative, it's bloated and might be lying to me."

Of course, this is a feature aimed at less well-informed PC owners, not those who can easily understand what's happening in Task Manager at a glance. Criticism around the bloat of the Copilot app is fair enough, mind, and this is because in its most recent incarnation, Microsoft changed things so the app is essentially a standalone spin-off of the Edge browser.

Another worry is that of privacy, and having Copilot 'snoop around' on your machine, but as noted, there are clear requests for permissions, and the new feature is strictly opt-in. You don't ever have to go near PC insights if you don't want to. It's also worth noting that giving the Copilot app access permissions doesn't mean it can read the actual contents of files, but only their sizes (for weighing up questions about storage and the like).

At the moment, this is a purely informative or troubleshooting feature, and in the case of attempted diagnostics, it may point to issues with your PC, but won't resolve them for you. However, it's not difficult to envision where Microsoft might head with this, in terms of getting Copilot to implement fixes for certain issues that the AI flags up. I'm talking simple Settings changes rather than anything in-depth, and this has always been the idea of Copilot (even though it hasn't yet been realized to much of an extent).

When we get AI agents in Windows 11 – and they are coming, make no mistake – this kind of functionality may turn into a full-on troubleshooting agent. The trouble (pun not intended) with that being that the mistakes and hallucinations that AI can make could be considerably more aggravating in this kind of scenario.

Vibe coded threats shift again — hackers are using AI chatbots to write malware using natural language

  • Huntress analyzed AI‑generated malware “Untitled1.ps1,” a noisy custom AD enumeration tool likely built by low‑skilled attackers using generative AI
  • Attackers paired it with s5cmd for rapid data exfiltration and SharpShares.exe for share enumeration before being detected and removed
  • Report warns AI “vibe coding” lowers barriers for cybercrime, producing unique payloads that evade signature‑based defenses, requiring behavioral analytics to catch attack lifecycles

“Unsophisticated” cybercriminals can now easily write malicious code using Artificial Intelligence (AI) and run devastating data breach attacks with speed, forcing defenders to rethink their strategies, researchers have claimed.

Security experts Huntress thoroughly investigating a piece of AI-written malware, and explained how the bespoke, AI-generated payload was a “highly aggressive, noisy, custom-built AD enumeration tool.”

Since cybercriminals are generally careful not to make too much noise and to try and do their bidding without raising any alarms, the researchers hint this was the work of a low-skilled attacker.

Significant challenge

The malware, labeled Untitled1.ps1, was designed to map the Active Directory environment and apparently, it did its job well. In the next step, the crooks deployed a legitimate high-speed command-line tool for Amazon S3 operations called s5cmd which, according to Huntress, is often used for data exfiltration.

Before being spotted and kicked out, the attackers also deployed a known enumeration tool called SharpShares.exe, filtering common administrative shares while hunting for further user-accessible data repositories.

The move from off-the-shelf frameworks to custom, bespoke AI tools is a “significant challenge” for the defenders, Huntress warns.

“Historically, AVs and EDR platforms have relied heavily on file hashes and static string signatures,” they say. “Vibe-coded scripts are inherently unique. Untitled1.ps1 has never existed before and will likely never be compiled in this exact configuration again.”

As a result, defenders must focus on the “fundamental behaviors of the attack lifecycle.” AI can change the code syntax, they’re saying, but cannot change the underlying mechanics of Active Directory enumeration.

“Vibe coding lowers the barrier to entry for cybercrime, allowing unsophisticated actors to generate highly capable, evasive tooling on the fly,” the researchers concluded. “While the code itself may be messy, over-engineered, and filled with AI hallmarks like left-behind comments, the threat it poses is very real. To combat this, defenders must abandon rigid, signature-based thinking and embrace behavioral analytics to catch the underlying actions that no LLM can hide.”

'Cryptomining can be a lucrative post-compromise activity in cloud environments': Experts warn AI gateways connected to Amazon Bedrock are being hijacked to steal crypto

  • Darktrace reports cryptojacking via a compromised AI gateway (LiteLLM‑Proxy on AWS Bedrock), breached through exposed SSH and abused with XMRig mining
  • Attackers also showed suspicious IAM activity, hinting at possible cloud credential misuse, with connections traced to Vietnam
  • Experts warn AI gateways concentrate privileged access, urging strict port closures, least‑privilege roles, and control‑plane monitoring to reduce blast radius

If you are using AI gateways as part of your tech stack, be wary - they are being leveraged in cryptojacking attacks, experts have warned.

Cybersecurity researchers Darktrace have published a new report on a cloud-hosted AI gateway, connected to Amazon Bedrock, which was compromised and used for cryptocurrency mining.

An AI gateway is a piece of software that runs between users or applications and one or more AI models. It is not unlike a reverse proxy or an API gateway, but just for AI services. In this case, an Amazon EC2 instance running an AI gateway called LiteLLM-Proxy was given centralized access to large language models (LLM) hosted on Amazon Bedrock (AWS’ fully managed generative AI platform).

Shady Vietnamese accounts

According to Darktrace, threat actors gained access most likely through a brute-force attack, since the EC2 instance was configured to accept SSH connections from anywhere on the internet.

After breaking in, they downloaded XMRig, by far the most popular cryptocurrency mining program. Within minutes, the instance started making repeated encrypted connections to a cryptocurrency mining pool, which also set off Darktrace’s alarms and spotted the attack.

Soon after, Darktrace spotted more suspicious activities, this time involving an AWS Identity and Access Management (IAM) user. This account started giving out unexpected and previously unused commands, such as enumerating and invoking Amazon Bedrock foundation models, or trying to set up a new IAM user account.

The final red flag was the IP address of that user - tracing back all the way to Vietnam. Darktrace said there was insufficient evidence to conclusively link the IAM activity with the earlier compromise of the AI gateway, but stressed that the behavior could indicate attempted cloud credential misuse.

Apple’s app subscription bundles are too rigid and inflexible — here's how I'd overhaul them if I were CEO-to-be John Ternus

There used to be a time when you’d buy an Apple app by paying for it once and never again. Then along came the idea of app subscriptions, and slowly but surely, Apple has started selling more and more of its software products through recurring payments. From iCloud+ to Apple TV, there are many ways to spend your cash on Apple’s wares on an ongoing basis.

Today, Apple flogs bundles of its own apps to its users, with Apple One in particular offering a cluster of apps for a single monthly price. And Apple hasn’t stopped there, with the Creator Studio package being introduced a few months ago for users of its artistic apps.

But while these app groupings ostensibly give you a way to get the software you need without paying multiple subscription fees, I’m starting to worry about how they restrict your choices and force you down avenues you might not want to travel.

Not only can they be expensive, but they’re also inflexible, giving you very little ability to customize them to your needs. If subscriptions are the future of app monetization, then Apple needs to do a whole lot better.

Enter the Creator Studio

Apple Creator Studio

(Image credit: Apple)

Apple likes to portray itself as the company of creatives — think about its “Here’s to the crazy ones” or “I’m a Mac” commercials of days gone by. And the firm already sells apps made specifically for this demographic, including Logic Pro, Final Cut Pro, Pixelmator Pro, and more. So it makes sense that Apple would want to offer a software suite that grants interested users access for a single fee, instead of requiring several payments, whether one-off or ongoing.

That’s what you get with the Creator Studio, which is priced at $12.99 / £12.99 / AU$19.99 a month or $129 / £129 / AU$199 a year. In return for your cash, you get a pass for the following apps:

  • Final Cut Pro
  • Logic Pro
  • Pixelmator Pro
  • Keynote
  • Pages
  • Numbers
  • Motion
  • Compressor
  • MainStage

And yes, some of these apps — like Keynote, Pages, and Numbers — are already free, but pay the Creator Studio entry fee and you get “a library of high-quality, royalty-free photos and graphics, and powerful intelligence features” in addition to what comes with the toll-free editions, Apple says.

Considering Logic Pro alone costs $199.99 if you want to buy it outright (rather than pay an ongoing subscription), this package might seem like a rather good deal. But it’s not the price that I’m interested in — it’s the way app bundles like Creator Studio work.

Right now, there are two main app collections available from Apple: Creator Studio and Apple One. While Creator Studio contains the aforementioned creative apps, Apple One starts at $19.95 / £18.95 / AU$24.95 a month and comes with 50GB of iCloud+ storage, plus memberships to Apple TV, Apple Music, and Apple Arcade.

There are two additional tiers, with the most expensive costing $37.95 / £36.95 / AU$49.95 a month and throwing in 2TB of iCloud+ storage, Apple Fitness+, and Apple News+, in addition to what’s already in the entry-level option.

But what if you want to mix and match your apps and services from Apple? What if you want, say, Logic Pro and Final Cut Pro from Creator Studio, plus Apple Music, Apple Fitness+, and Apple News+? Well, you’re going to have to either take out the top Apple One bundle and separately buy those creative apps outright, or you’ve got to pay for memberships of two distinct ongoing subscriptions.

In this instance, combining Creator Studio with the most expensive edition of Apple One means paying $50.94 a month when all you want are five apps. The rest of the content you pay for is superfluous. Throw in AppleCare+, and you’re forking out even more.

Apple gives practically no flexibility or customization with its app collections. You can’t mix and match apps and services, and if there are some you want from both subscriptions, you’ve got to pay for both. That makes it an incredibly expensive way to go.

But with Apple seemingly getting evermore enthusiastic about subscriptions — and the revenue they bring in — don’t be surprised if this state of affairs continues.

Is there a better way?

Apple Event 2020

(Image credit: Apple)

You might feel that, since Creator Studio is relatively new, Apple is still working out the logistics of how to sell the apps and services it contains. But Apple is no stranger to subscriptions. It’s been offering the likes of Apple Music and Apple Arcade for years now, so it knows a thing or two about how to structure subscription offerings.

Is the lack of flexibility here and the absence of any way to pick and choose apps a deliberate policy on Apple’s behalf? We can’t know for sure, but it’s not a good look.

While the Creator Studio might seem like a decent bargain on its face, it becomes considerably less so if you’re not interested in everything it offers and want to pair its apps with those from the Apple One bundle.

Considering how keen Apple seems to be on subscriptions, I’m surprised it doesn’t offer individual memberships for each component app within these packages. For instance, why is there no individual subscription for Pixelmator Pro? Instead, you’ve got to choose between a one-off fee or the full Creator Studio.

If Apple were to go down this route — and it's what I'd do if I were CEO-to-be John Ternus — it would instantly solve the problem of pairing different apps from different collections. You could simply add whichever apps you wanted to your own “build a bundle” package and get exactly what you need for a more acceptable price.

But that kind of process doesn’t seem to be anywhere on the horizon. There are no rumors saying it’s coming, no telltale clues nestled in Apple’s code. Don’t hold your breath for its imminent arrival.

Until we do get something like that, Apple customers are going to continue to feel ripped off by a rigid, inflexible system that is happy to take their cash in return for apps they don’t want or need. It’s a situation that’s in desperate need of a rethink.

❌
❌