Home Top Ad

Responsive Ads Here

The Nintendo Switch 2 has finally arrived, and it brings several upgrades over its predecessor, including 4K resolution, 120Hz (at 1080p r...

The Nintendo Switch 2 has finally arrived, and it brings several upgrades over its predecessor, including 4K resolution, 120Hz (at 1080p resolution) and HDR support. It also supports Variable Refresh Rate (VRR), which provides a smoother gaming experience, although this is only available in handheld mode. If you managed to get one, now might be a good time to upgrade another vital piece of gaming equipment: your TV.

If you're still looking for a Switch 2, be sure to check out our live stock checker.

When it comes to the best gaming TVs, we at TechRadar look for features such as VRR, a 120Hz refresh rate and Auto Low Latency Mode (ALLM), which automatically selects a TV’s game-optimized mode when it detects a connected console. Low input lag for responsive performance and top-notch picture quality are also important.

There’s a plethora of gaming TV options, making choosing one a bit daunting. I’ve chosen three TVs that I think would suit the Switch 2, and the list is led by my top pick, the LG C4.

Today's hottest TVs for the Switch 2 deals

The LG B4 provides premium OLED picture quality and a full array of gaming features - 4K 120Hz, VRR, ALLM, Dolby Vision gaming - for a more budget-friendly price than any other OLED. It would make a perfect gaming monitor for the Switch 2 and it's now back to its lowest ever price for the 48-inch model. View Deal

The LG C4's colourful, detailed and contrast-rich picture and unbeatable array of gaming features including 4K at 144Hz, VRR (FreeSync and G-Sync), HGiG, Dolby Vision gaming and ALLM mean it's a match made in heaven for gaming consoles like the Switch 2. And just in time for the Switch 2's release, this is the cheapest we've ever seen the 55-inch model and is an unmissable offer. View Deal

LG C4

LG C4 OLED TV game menu on screen

(Image credit: Future)

The LG C4 sits at the top of many of our best TV lists, including the best gaming TV and best OLED TV. A true jack of all trades, it delivers every feature you’d want for gaming and movies and has fantastic picture quality and an intuitive smart TV platform:

The C4 supports 4K 144Hz, VRR (AMD FreeSync and Nvidia G-Sync), HGiG, Dolby Vision gaming and ALLM. Although the Switch 2 won’t take full advantage of all these features in docked mode, it can use High Refresh Rate (120Hz) or 4K resolution for its picture (though not both at the same time).

Plus, games like Mario Kart World will really benefit from the LG C4’s ultra-low 9.2ms input lag time. For driving games like Mario Kart World, a low input lag means a snappier response to your command, something that’s necessary on a course like Rainbow Road! And the C4’s Game Optimizer will allow you to make other settings adjustments to get your Switch 2 experience just right.

Picture quality is where the C4 shines. It has bright, bold colors with plenty of dynamic punch thanks to its high brightness (we measured its peak brightness at 1,065 nits in Filmmaker Mode). Plus, its rich detail and contrast are sure to give the colorful, larger-than-life graphics of the Switch 2’s games a deeper, richer look.

The C4’s picture quality earned 4.5 out of 5 stars in our LG C4 review for good reason! And there’s no better time to buy one to pair with your Nintendo Switch 2 with ambitious ports such as Cyberpunk: 2077 available from launch.

Hisense U7N

Hisense U7N with Battlefield V on screen

(Image credit: Future)

The Hisense U7N is packed with a ton of gaming features and delivers good picture quality without breaking the bank. It’s an excellent choice for those looking for a budget gaming TV.

For gaming features, the U7N supports 4K 144Hz, VRR (AMD FreeSync Premium Pro), ALLM and Dolby Vision gaming. It also delivers a respectable 13.5ms input lag time. Once again, the Switch 2 will benefit from these gaming features, and the U7N also has a useful game mode, where other tweaks such as shadow detail can be made.

In my Hisense U7N review, I said that “its picture punched above its weight’, and cited its rich color and solid contrast. The Switch 2’s visually appealing games, such as Mario Kart World and Legend of Zelda, will really benefit from the vibrant picture the U7N provides.

LG B4

LG B4 showing image of GTA V with game bar menu

(Image credit: Future)

That’s right, another LG OLED has made my list. The LG B4 is the step-down model from the LG C4, and while it doesn’t hit the same brightness levels, it still produces excellent picture quality and has an equally impressive list of gaming features.

The B4 is also a great value for an OLED TV, especially the 48-inch model.

Just like its more premium sibling, the B4’s superb stock of gaming features includes 4K 120Hz, VRR, ALLM and Dolby Vision gaming. It also has an ultra-low 9.1ms input lag time (activated by Boost mode in the Game Optimizer). The Switch 2 can once again take advantage of that low input lag time for ultra-responsive performance (crucial for Mario Kart World) and the B4’s 4K, HDR and 120Hz support to level-up their experience from the original Nintendo Switch.

While it may not have the brightness of the LG C4, the B4 still produces striking colors and rich contrast that gives pictures a dynamic and engaging look with plenty of detail. In our testing, we also found it was great for upscaling non-4K content – perfect if you’re playing an HD-resolution Switch 2 game.

You might also like



from Latest from TechRadar US in News,opinion https://ift.tt/OUoLmKy

AI isn’t hype anymore—it’s real. IDC predicts that by 2028 AI spending could hit $623 billion by 2028. That kind of investment doesn’t come...

AI isn’t hype anymore—it’s real. IDC predicts that by 2028 AI spending could hit $623 billion by 2028. That kind of investment doesn’t come from buzz. It comes from companies seeing real value.

AI tools are already cutting costs, speeding up work, and - let’s be honest - making jobs more enjoyable. Nobody misses the repetitive stuff. Instead, we’re doing more of what we’re actually good at: strategy, creativity, and problem-solving.

So now that companies have tasted that value, many want to go further. Not just use AI—but build entire internal AI-powered solutions themselves. Stitch together some models, build an app, launch it to their teams. The thinking goes: if off-the-shelf tools work, imagine how great it’ll be if we control the whole thing.

Here’s the reality: for most companies, especially non-tech companies, building in-house AI solutions is a bad bet. They take too long, cost too much, and rarely deliver what the business actually needs.

Let’s talk about why.

Companies are already experimenting with models. They’re using GPTs, building copilots, testing agents. That’s not the problem. The problem is believing the solution is just about picking a model or wiring one together. That’s not where most projects fail.

They fail because the solution—how it fits into your workflows, your systems, your people—isn’t well thought out. It’s fragmented. It’s not scalable. It doesn’t stick. The model might be powerful, but the experience around it doesn’t work. And without that, the value never materializes. This is why the connective layer matters.

The interface. The orchestration. The automation. The safeguards. It’s what turns "we have a model" into "we’re driving results." And most companies don’t have the internal expertise to build that layer right.

Going solo comes with hidden costs

Trying to build your own AI-powered solution might feel brave. But unless your company is a product and engineering company, the odds are stacked against you.

Here’s where most organizations get it wrong:

1. You Don’t Have the UX Muscle

AI only delivers value when people actually use it. That means seamless, intuitive, trustworthy interfaces. Most enterprises don’t have the product design and UX software and development capabilities to build interfaces that users actually want to engage with. Internal tools often look—and perform—like science experiments.

2. You’re Flying Blind

Vendors bring learning from hundreds of deployments. You don’t. If you’re rolling out a custom AI solution based on a few internal tests and gut instinct, you’re guessing. You don’t have enough data to know what “good” looks like—or what real adoption takes.

3. You’re Not Budgeting for What Comes Next

AI isn’t static. Models evolve. Interfaces break. User needs change. If you’re not committing budget and headcount for constant iteration, retraining, and support, that in-house solution will be outdated in under a year. And it will sit unused, no matter how promising it looked at launch.

4. Security Concerns Are Overblown

Yes, protecting data is critical. But assuming vendor AI tools are inherently less secure? That’s a flawed take. The best AI providers build with security and compliance at the core. If you trust cloud infrastructure, you can trust enterprise-grade AI vendors.

5. "Only We Know Our Business" Misses the Point

Your internal team knows your business better. That’s not in question. But they likely don’t know how to build scalable, production-ready AI. Vendors do. They’ve already solved the engineering challenges, the data problems, the deployment mess. Why start from scratch?

If you’re not a tech company, stop trying to be one. There’s no shame in partnering with experts—it’s how the winners win faster.

Agentic AI is coming—and it’s even harder to build right

The next phase is agentic AI. These systems don’t just generate—they act. They make decisions. They learn. They execute. It’s already revolutionizing workstreams like customer service, reporting, and document creation.

But these aren’t lightweight features. They’re full systems—requiring real orchestration, context awareness, governance, and maintenance. Trying to build them internally without the right foundation? That’s not just inefficient. It’s risky.

You don’t need to build these things. You need to leverage the companies that already have.

AI is a team sport, play with the pros

AI feels like it’s getting easier. And in some ways, it is. Open-source models. No-code platforms. Accessible APIs.

But building an AI solution that actually moves the needle? That’s still hard. Really hard. And if you think your internal team can replicate what vendors have spent years perfecting, you’re wasting time—and likely money.

The smartest companies aren’t trying to do it all themselves. They’re focusing on what they do best and partnering for the rest.

AI is a team sport. Play with the pros.

That’s how you win.

LINK!

This article was produced as part of TechRadarPro's Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro



from Latest from TechRadar US in News,opinion https://ift.tt/ZtQfUsy

The human cost of today's escalating cybersecurity threats is more than concerning—it's unsustainable. Advanced persistent threats,...

The human cost of today's escalating cybersecurity threats is more than concerning—it's unsustainable. Advanced persistent threats, ransomware attacks, and exploitation techniques have evolved dramatically in sophistication and frequency throughout 2024 and into 2025, creating an ever-expanding battlefield requiring constant vigilance.

The stark reality? 50% of cybersecurity professionals expect to experience burnout within just one year, while an alarming 80% anticipate burnout within three years. This mental and physical exhaustion isn't simply a personnel issue—it represents a threat to organizational security postures worldwide.

With professionals stretched thin across expanding attack surfaces and facing increasingly sophisticated threat actors, many security teams operate in a perpetual state of high alert. The resulting fatigue compromises decision-making, reduces vigilance, and accelerates turnover in an industry already plagued by staffing shortages, creating a dangerous cycle that threatens to undermine our collective digital security.

The most promising solution to this escalating crisis lies in agentic AI. Capable of autonomously handling repetitive detection and remediation tasks that traditionally consume security analysts' time and mental energy. By implementing these intelligent applications to manage routine work and protocols, organizations can reallocate their human talent toward strategic initiatives while significantly reducing the cognitive burden that drives burnout.

The Burnout Antidote

A recent Gartner Peer Community survey found 62% of IT and security leaders have experienced burnout, and identified that many CISOs plan to leave their jobs or careers due to what Gartner called "unique stressors." It is increasingly clear that there is work to be done to mitigate these distinctive challenges.

Unlike traditional automated solutions, today's best agentic AI tools possess newfound autonomy and decision-making capabilities, allowing them to effectively evaluate and even complete tasks without constant human oversight. These AI systems excel at process optimization, creating streamlined workflows that eliminate redundancies while ensuring comprehensive coverage across the security landscape.

The impact on security professionals can be profound: reduced cognitive overload, improved work-life balance, and significantly higher job satisfaction.

Addressing Challenges

The implementation of agentic AI isn't without challenges. Organizations must ensure these systems align with established security policies and governance frameworks, maintaining appropriate human oversight particularly for high-impact decisions. Continuous monitoring remains essential to prevent AI systems from developing problematic patterns or blind spots.

Ethical considerations also demand attention, particularly regarding bias in threat detection and the appropriate balance of automation versus human judgment. However, when thoughtfully integrated into security operations, agentic AI represents our most promising strategy for sustaining the human element in cybersecurity while reducing the burnout epidemic threatening the industry's future.

Best Practices

The implementation of agentic AI in cybersecurity operations represents a significant opportunity to alleviate professional burnout while enhancing security workload. To maximize success, organizations should adopt a deliberate, strategic approach focused on measurable outcomes and team well-being.

Begin with clear identification of high-burden activities that create the most significant mental fatigue among security professionals. Alert triage, routine compliance documentation, and repetitive investigation steps typically represent ideal starting points for AI implementation. Establish baseline metrics before deployment—including time spent on routine tasks, alert response times, and team satisfaction scores—to quantify the impact of your AI initiatives.

A phased implementation approach proves most effective in cybersecurity environments. Start with AI that augments rather than replaces human decision-making, gradually expanding responsibilities as confidence and capabilities grow. This progressive autonomy model allows teams to develop appropriate trust in AI capabilities while security leaders can monitor performance and refine governance frameworks.

Regular feedback loops between AI systems and security professionals create continuous improvement opportunities. The most successful organizations establish formal mechanisms for security analysts to provide input on AI performance, helping systems better understand the nuanced aspects of threat detection and response that contribute most significantly to cognitive overload.

Beyond technical implementation, focus on cultural integration. Position AI as an enhancement to human expertise rather than a replacement, emphasizing how automation of mundane tasks elevates the security professional's role toward more strategic and intellectually rewarding work. Organizations that frame AI adoption as an investment in their team's wellbeing typically see faster acceptance and more positive outcomes.

A Call to Action

For CISOs and CTOs facing the combined challenges of escalating threats and team burnout, the time to act is now. The cybersecurity landscape will continue evolving with increasingly sophisticated threats, but by thoughtfully implementing agentic AI today, organizations can create more sustainable security operations that protect both their digital assets and the human talent essential to their defense.

Begin your journey with a comprehensive assessment of your team's burnout risk factors and workload distribution. Identify clear opportunities for agentic AI integration that will deliver immediate relief while building toward more comprehensive automation. Measure not just security outcomes but human factors—team satisfaction, retention rates, and professional development opportunities.

The choice isn't between human expertise or artificial intelligence—it's about creating the optimal partnership between them to combat both cyberthreats and the burnout epidemic simultaneously. Your organization's security future depends on making this vision a reality.

We list the best patch management software.

This article was produced as part of TechRadarPro's Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro



from Latest from TechRadar US in News,opinion https://ift.tt/3wkfi1c

Ruark MR1 Mk3 launch today for $579 / £399 / AU$899 Ruark's five-star speakers get even better Bluetooth and amplification Built-in...


  • Ruark MR1 Mk3 launch today for $579 / £399 / AU$899
  • Ruark's five-star speakers get even better Bluetooth and amplification
  • Built-in MM phono stage, hi-res USB audio and aptX HD streaming

The Ruark MR1 MkII were the best small Bluetooth speakers you could buy when they launched, and they still sound great today. But nearly eight years on it's time for a refresh – and Ruark has wisely decided to keep the same attractive design while extensively upgrading what's inside.

The Ruark MR1 Mk3 look very similar to their predecessors from both 2017 and 2013. But this time around there's better Bluetooth, enhanced USB audio, improved amplification and larger drivers too.

A rear view of the Ruark Audio MR1 Mk3 Bluetooth speakers showing their inputs and outputs

The MR1's inputs now include USB audio for hi-res audio playback. (Image credit: Ruark Audio)

Ruark MR1 Mk3 speakers: key features and pricing

While the cabinets look pretty much identical other than the new Slate Gray fabric grilles, they've been subtly redesigned inside to make room for the new, 85mm long throw NS+ bass/mid drivers. Tweeters are 20mm silk domes.

Ruark has also adapted the Class D amplification from its R410 model to deliver more power and better control, and the crossovers have been optimized and the bass reflex tuned to deliver what Ruark describes as "deeper, more controlled bass, a lucid midrange, and exceptional detail".

The new Bluetooth module brings aptX HD and low-latency audio, and the new USB audio input delivers high-resolution audio. There's also a dedicated input for the best turntables, with a moving magnet phono stage and adjustable gain.

In-room frequency range is 50Hz to 22kHz, which is impressive for such small speakers, and there's a subwoofer output if you need extra oomph.

The new Ruark MR1 Mk3 speakers are available from today, 5th June, in a choice of Rich Walnut or Charcoal Lacquer. With pricing of $579 / £399 / AU$899, they look like better value in the UK than the US – but if they sound as good as the last model, they'll be a good buy in either case.

We'll review these as soon as we can, to see if they deserve a spot on our list of the best stereo speakers.

You might also like



from Latest from TechRadar US in News,opinion https://ift.tt/VwHSjET

AI has been a real gamechanger for productivity and automation , but as the technology evolves, the expectations being placed on it are gro...

AI has been a real gamechanger for productivity and automation, but as the technology evolves, the expectations being placed on it are growing fast – particularly in the field of cybersecurity.

From boardrooms to SOC teams, the promise is compelling: AI will reduce false positives, accelerate detection, automate response, and unburden fatigued analysts. But while these capabilities certainly aren’t out of reach, AI is not the “plug-and-play” solution that some might hope. Without the right data, context, and oversight, the lens offered by AI is blurry at best.

According to a 2024 report by IBM, roughly two-thirds of organizations say they’re now deploying AI tools and automation across their SOC environments. However, a 2025 survey by Darktrace reveals that less than half (42%) of CISOs have confidence in their AI deployment and fully understand how AI fits into their security stack. This gap between AI deployment and understanding how to extract value from it isn’t sustainable long-term.

Sprawling webs of interconnectivity

Networks used to be small, contained and relatively easy to protect – often confined to an office or single cloud computing environment. Today, they’re sprawling webs of interconnectivity spanning multiple clouds and endpoint devices. In other words, cybersecurity has gotten more complex.

There’s a growing assumption that AI can shed light on this complexity – that if you throw enough data at a model, it will separate the signal from the noise, even without deep integration into your environment. But threats don’t exist in a vacuum. They move through systems, exploit blind spots, and adapt to patterns. And unless an AI system understands the operational baseline – what’s normal, what’s sanctioned, what’s truly anomalous – it’s probably just best-guessing. Sometimes it guesses right, but when it doesn’t, the consequences can be costly.

None of this is to say that AI isn’t a force for good. It’s an incredibly powerful tool when wielded in the right way, but businesses need to pace themselves and create the right environment before it can truly deliver on its promises.

Are Businesses Prepared for AI?

The excitement around AI isn’t new or exclusive to cybersecurity. According to Gartner’s most recent Hype Cycle, both generative AI and cloud-based AI services are currently in the “peak of inflated expectations” phase. What comes next, with any new technology, is the “trough of disillusionment” – this is where the hype meets reality and industries realize that some lessons need to be learned before the technology can ascend to the last part of the cycle, “the plateau of productivity”.

This is the very pattern that security teams now find themselves in with AI. Early deployments have revealed just how brittle AI can be when removed from the controlled conditions of lab testing. Sophisticated models that looked flawless in demos can falter in the complex, unpredictable context of a live enterprise environment.

False positives are one problem. Analysts know the fatigue of chasing alerts that lead nowhere – and AI, when misapplied, can actually amplify that noise rather than reduce it. But the bigger risk is what AI misses. Algorithms trained on generalized threat data might completely overlook subtle, organization-specific anomalies, such as a lateral movement that piggybacks on a rarely used internal tool, or data exfiltration masked by a legitimate third-party integration. These are the types of threats that slip through when detection efforts lack specific environmental context.

Another cause for hesitation is that many AI-powered solutions operate as black boxes, which goes against the grain of the open source, community-driven threat response the industry is now rightly moving toward. Their logic isn’t exposed, their training data isn’t transparent, and their outputs are often unverifiable. For CISOs, that’s a risky proposition.

It’s hard enough to explain cybersecurity risks to the board; try explaining why an opaque model flagged – or failed to flag – a critical incident. AI effectiveness is one thing, but trust in AI and its processes is something that must be planned for and cultivated over time.

Putting Things into Context

In cybersecurity, context is everything. AI might detect an anomaly, but can it tell whether that anomaly is benign, malicious, or even expected? That requires more than pattern recognition. It requires a deep understanding of system baselines, user behavior, network topology, and operational rhythms.

Without this foundation, AI tools are inevitably prone to misinterpretation: flagging routine administrative scripts as threats, or worse, overlooking subtle indicators of compromise that don’t conform to known attack patterns. That creates more trivial work for security teams as it’s down to them to figure out what’s real and what’s not.

This is where network visibility comes into play. AI needs telemetry from every layer of the environment: endpoints, servers, cloud workloads, authentication flows, network traffic, and more. And it needs that data to be correlated, not siloed. An alert from an endpoint only makes sense when viewed alongside what’s happening across the system.

A login from an unusual location might be suspicious, unless it’s coming from a known travel route for a senior executive or a new remote hire based in another time zone. AI can’t make those judgments on its own. Without unified context, even the most advanced algorithms are guessing. And in cybersecurity, guessing is always a liability.

The Case for Unification

If AI is going to play a meaningful role in cybersecurity, it first needs a foundation it can trust, and so do the people relying on it. That begins with visibility, but it extends to architecture. Fragmented tools with partial views and proprietary, closed-source alert logic only hinder cybersecurity efforts.

What CISOs need is a cohesive layer of detection and response where telemetry is unified, logic is transparent, and automation is tightly aligned with operational context. This is where architectural convergence – for example, the merging of SIEM-level visibility with the orchestration capabilities of extended detection and response (XDR) – becomes critical. This baseline will turn AI into a force multiplier for security teams when correctly deployed.

Equally important is explainability. If an AI system flags a potential threat, security teams need to understand why. Not only to validate the alert, but to learn from it, adapt processes, and communicate risk to leaders and stakeholders. Black-box models might seem impressive, but in security, opacity is a threat vector in itself.

CISOs don’t need magic; they need clarity. And the best AI implementations are those that put humans in the loop – enhancing decision-making, accelerating triage, and surfacing the insights that matter most without drowning teams in noise.

We've compiled a list of the best identity management software.

This article was produced as part of TechRadarPro's Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro



from Latest from TechRadar US in News,opinion https://ift.tt/BuMjIa0

HPE patches eight flaws in StoreOnce platform Among the flaws is a critical severity authentication bypass There are no workarounds and...


  • HPE patches eight flaws in StoreOnce platform
  • Among the flaws is a critical severity authentication bypass
  • There are no workarounds and users are advised to patch up

Hewlett Packard Enterprise (HPE) has revealed patches for a number of dangerous flaws affecting its data backup and recovery solution, StoreOnce, including a critical-severity bug which allows threat actors to gain full access to the vulnerable system without user interaction.

The bug is tracked as CVE-2025-37093, and is described as an authentication bypass flaw stemming from improper authentication handling. It has a severity score of 9.8/10 (critical) and could potentially be abused to compromise system integrity, allow threat actors to access sensitive data, and lead to different disruptions and availability issues.

Crooks could use it to deploy ransomware, steal sensitive data, or move laterally throughout the target network.

Eight flaws patched

In HPE’s advisory, the company said all versions prior to 4.3.11 were vulnerable, and has urged users to update their software as soon as possible.

There are no other mitigations or workarounds, so if you can’t update your instance immediately, it would be best to remove the product until you can patch it.

The issues were reportedly discovered seven months ago but apparently no one abused it in the wild so far.

In total, HPE patched eight flaws this time around. While the authentication bypass is the most severe one, others are potentially dangerous, as well.

Here is a list of other seven flaws HPE fixed in version 4.3.11:

CVE-2025-37089 – Remote Code Execution
CVE-2025-37090 – Server-Side Request Forgery
CVE-2025-37091 – Remote Code Execution
CVE-2025-37092 – Remote Code Execution
CVE-2025-37094 – Directory Traversal Arbitrary File Deletion
CVE-2025-37095 – Directory Traversal Information Disclosure
CVE-2025-37096 – Remote Code Execution

HPE StoreOnce is a disk-based backup and recovery system that uses data deduplication to reduce storage needs.It is usually used by enterprises, government agencies, and mid-sized businesses with complex IT environments.

StoreOnce supports integration with other backup and enterprise software, such as HPE Data Protector, Veeam, Veritas NetBackup, Commvault, and Microsoft Data Protection Manager. It also connects with cloud storage through HPE Cloud Bank Storage.

Via BleepingComputer

You might also like



from Latest from TechRadar US in News,opinion https://ift.tt/1trgvKZ

The internet was a very different place in the 1980s. Connecting a machine to what was then the ARPAnet – a government-funded research netw...

The internet was a very different place in the 1980s. Connecting a machine to what was then the ARPAnet – a government-funded research network – wasn’t something you could do on a whim. You had to pick up the phone, call someone at the Stanford Research Institute, and ask nicely. That changed with the invention of the Domain Name System (DNS).

Introduced by Paul Mockapetris in the latter half of the decade, DNS automatically translated human-friendly domain names like “example.com” into machine-readable IP addresses, allowing users to access websites without needing to remember numerical strings. Before DNS, this process relied on a single, centralized text file that had to be manually updated and distributed, which obviously limited the network's size and scope.

As DNS allowed the internet to evolve from a research tool into a global communications platform, it didn’t take long for others to see where its vulnerabilities lay. Paul Vixie, another internet hall–of-famer who joked that those who created the modern internet were “just a bunch of young rebels who didn’t like the phone company monopoly," recognized that this foundational system – originally built for convenience – could become a target.

Because DNS sits at the heart of internet communication, handling every domain lookup, it became possible for attackers to hijack, redirect, or even monitor traffic at scale. These vulnerabilities persist today.

But the thing that makes DNS vulnerable is actually its greatest strength. In 2025, DNS does far more than connect names to numbers. Like a dog sitting loyally by its owner's side or a cat perched up high, it quietly watches everything that enters and leaves the area – an unexpected, sometimes underappreciated guardian that's already at home. All it needs is a bit of training. Can an old dog learn new tricks?

Guarding the gates

For a long time, DNS was treated like digital plumbing – essential but unglamorous, buried deep in the IT infrastructure stack and rarely discussed outside of network teams. But as cyber threats have become more dynamic and distributed, DNS has quietly emerged as one of the most strategic vantage points in cybersecurity. Every time a user clicks a link, opens an app, or connects to a service, a DNS query is made. That makes DNS not only a utility, but an opportunity. By inspecting and filtering these queries, Protective DNS (PDNS) turns a passive system into an active line of defense.

Unlike traditional tools that respond to threats after they’ve breached the perimeter, PDNS works upstream, blocking access to malicious domains, disrupting command-and-control channels, and preventing data exfiltration before any damage is done. It’s fast, scalable, and doesn’t rely on agents or deep system integration, which makes it uniquely suited to today’s hybrid, device-diverse environments. Think of it like the dog that doesn’t wait for burglars to get through the door, or for couriers to deliver a dodgy package – it senses something nefarious at the gate and raises the alarm before anyone else knows there’s trouble.

Hunters become the hunted

Here’s the thing: today’s cyber criminals don’t just rely on direct network assaults and malware – halcyon days when attacks could be spotted and shot down – they rely on infrastructure. Behind every phishing campaign, scam site, or credential-harvesting operation is a network of carefully arranged domains designed to evade detection and maximize reach.

One of the most effective tools in this arsenal is the Traffic Distribution System, or TDS. These systems act like sophisticated switchboards, directing users through a maze of domains based on geolocation, browser type, operating system, or even time of day. They serve up different payloads to different victims, filter out bots and researchers or blindside them by sending them to genuine sites while others fall into their trap, and even rotate domains frequently to stay one step ahead of blacklists.

Cybercriminal gangs can no longer be thought of as cowboys taking pot-shots at businesses – they are coordinated commercial enterprises. Take “Vigorish Viper” for instance – a criminal group that leverages TDS infrastructure as a front for illegal gambling and people trafficking. It operates over 170,000 domain names, evading detection and law enforcement through sophisticated use of DNS Traffic Distribution Systems while funneling users along a digital path that will eventually expose their data.

The sheer number of domains involved is where simple “domain-blocking” approaches start to fall apart. TDS networks are designed for redundancy, so blocking one domain in the chain simply triggers a redirect to another, and another, and another – often with hundreds in reserve. PDNS changes the game by targeting the infrastructure itself.

By recognizing and preemptively blocking patterns of domain registration, staging activity, and other connections to malicious actors, PDNS can stop an entire network of malicious domains before a single one is weaponized, turning Fido and Kitty into finely tuned hunters.

The UK’s shift to proactive defense

The criticality of PDNS has not gone unnoticed by governments around the world. In the UK, the government is moving decisively toward a more proactive, infrastructure-aware model of cybersecurity, and DNS is right at the heart of it. The National Cyber Security Centre (NCSC) has long championed the use of PDNS as part of its Active Cyber Defence program, offering a managed PDNS service to public sector organizations. It’s a recognition that the front lines of cybersecurity aren’t always defined by malware or endpoints – sometimes, they’re built on something as foundational as a domain name.

The growing importance of DNS and PDNS is also reflected in other various policies and practices. For instance, the US standards organization NIST, which offers global advice, has published a proposed revision of their 800-81 standard which includes detailed guidance for securing DNS operations and enhancing DNSSEC deployment. The EU’s relatively new NIS2 framework also explicitly recognizes DNS service providers as “essential entities” and strongly encourages the securing of DNS traffic.

The cybersecurity superpet

The cybersecurity industry loves new toys and continuous innovation remains crucial, but sometimes the most powerful defense is already in a security team’s arsenal – the cybersecurity superpet curled up at their feet. While new cybersecurity tactics emerge, it’s important not to forget that with a little training, DNS – while almost as old as the internet itself – can become the most effective ward against unseen network threats. It turns out you can teach an old dog new tricks.

We've featured the best endpoint protection software.

This article was produced as part of TechRadarPro's Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro



from Latest from TechRadar US in News,opinion https://ift.tt/S2BbRLv

In today’s hyper-connected healthcare environment, the supply chain has quietly become one of the sector’s most vulnerable digital frontier...

In today’s hyper-connected healthcare environment, the supply chain has quietly become one of the sector’s most vulnerable digital frontiers. Once viewed purely as a logistical or procurement function, the modern healthcare supply chain now includes everything from pharmaceutical distributors and cloud-based software providers to diagnostic platforms and medical device manufacturers. This expansive ecosystem, while critical to patient care, is also under siege and must be protected.

Cybercriminals have recognized this opportunity. Rather than targeting hospitals directly, they are increasingly breaching third-party vendors to disrupt services, access sensitive data and hold patient-critical systems hostage. The implications are far-reaching, leading to delayed treatments, compromised medical equipment, shortages of critical supplies and the alarming risk of counterfeit or tampered materials entering the system.

As the NHS drives forward its transformation from analogue to digital, as part of the UK government’s plan to build an NHS Fit for the Future, the need for robust cybersecurity becomes even more pressing. Empowering individuals to take control of their own health is a powerful step forward, but it also expands the digital footprint that must be protected. To safeguard patient trust and ensure seamless, secure care delivery, defenses must now extend beyond hospital walls to every point in the healthcare supply chain.

An overlooked entry point in a complex ecosystem

The very interdependence of today’s digitalized, interconnected network of the healthcare supply chain is increasingly putting the whole system at risk. Gone are the days of cybersecurity in healthcare being mainly focused on internal systems. Today, a vulnerability in a third-party supplier can be the weak link that opens the door to widespread disruption. Whether it’s patient records held by cloud providers, digital tools used in diagnostics, or the logistics systems that ensure timely delivery of medications, every component in this ecosystem is a potential target.

Trustwave’s latest research report reveals that vulnerabilities in third-party systems or devices can have cascading effects for healthcare organizations. To maximize harmful impact, cybercriminals target healthcare software providers, knowing that compromising a single vendor could grant them access to multiple hospitals and healthcare facilities at once. A prime example of this was the 2022 ransomware attack on Advanced Computer Software Group, a major IT provider to the UK health and care sector. The breach, which exploited an account lacking multi-factor authentication, disrupted critical NHS services including NHS 111 and compromised the personal data of over 79,000 people, some of whom were receiving care in their own homes.

Ransomware attacks

Similarly, the ransomware attack on that pathology partnership, Synnovis, which occurred as recently as 2024, caused significant disruptions to NHS services in South East London. The attack affected all Synnovis IT systems and severely reduced the capacity to process pathology samples. This led to delays in diagnostics and treatment, with multiple patients negatively impacted and some procedures postponed or cancelled altogether.

Such incidents serve as a stark reminder that the stakes in healthcare are uniquely high. A ransomware attack doesn’t just lock files. It freezes operating theatres, delays chemotherapy, or prevents prescriptions from being processed. In the worst-case scenario, such threats can result in clinical errors or delayed diagnoses, with life-threatening consequences.

Hospitals and healthcare providers cannot afford prolonged downtimes. Cybercriminals are aware of this vulnerability, making the healthcare sector one of the most targeted industries. The pressure to pay ransom and restore services quickly makes it a prime target for financially motivated attackers.

Medical devices are particularly at risk. Imagine a compromised infusion pump or a malfunctioning ventilator caused by tampered firmware. These aren’t just hypothetical threats rather, very real possibilities in today’s increasingly dangerous cyber environment. In fact, as recently as January 2023, an insulin pump maker disclosed an IP address exposure The following month, an infusion pump provider acknowledged a vulnerability enabling unauthorized access to personal data. Soon after, a cardioverter defibrillator product reported a vulnerability leading to a data breach affecting over 1 million individuals.

Such incidents underscore a harsh reality: when cybersecurity fails in healthcare, it’s not just data, but lives that are at stake.

From national risk to global priority

In the UK, the NHS is one of the most trusted institutions and maintaining public confidence is vital. But cybersecurity cannot be tackled in isolation. The cyber threat to the healthcare sector is not just a national risk but a part of a broader, international challenge. It requires a coordinated and cooperative response, both within the UK and with partners across Europe and beyond.

One critical component to strengthening the healthcare supply chain’s cyber defenses is cross-border threat intelligence sharing, as the digital nature of healthcare means attacks can come from anywhere. UK institutions, cybersecurity companies and government agencies must work closely with their international counterparts to share threat intelligence, track criminal activity and respond rapidly to emerging risks. This includes monitoring forums where NHS-related data may be traded or discussed.

Shared intelligence is also only effective when it’s specific and actionable. The healthcare supply chain has unique challenges that require a tailored analysis. National bodies such as the National Cyber Security Centre (NCSC), in collaboration with industry consortia, should lead efforts to coordinate information-sharing networks tailored to healthcare.

Additionally, the NHS and private healthcare providers alike must begin to impose more stringent security standards on their vendors and partners. As best practice, contracts should clearly spell out responsibilities around breach notification, data protection and compliance with UK regulations such as the Data Protection Act and NHS DSP Toolkit standards. Adopting a zero-trust architecture can help mitigate the impact of supply chain breaches.

Efforts underway

Efforts to this effect are already underway, with the government drawing up the Cyber Security and Resilience Bill. Set to be introduced in Parliament in 2025, this Bill aims to bolster the UK's cyber defenses by expanding regulatory coverage to include more digital services and supply chains, both of which are increasingly targeted by cybercriminals.

With recent high-profile cyberattacks on critical public services such as the NHS underscoring the urgency, the Bill will address vulnerabilities in the nation’s critical infrastructure, ensuring that essential services like healthcare are better protected. It will also enhance reporting requirements to improve the government's understanding of emerging threats and provide regulators with the tools needed to proactively identify and address potential risks.

Alongside external collaboration and regulation, the internal cyber defenses of UK’s healthcare providers must also be brought up to par. That starts with culture. Frontline NHS staff and administrators must receive regular training on phishing, social engineering and password security. Moreover, implementing multi-factor authentication (MFA), robust access control and continuous monitoring significantly reduces the risk of future cyber attacks. Finally, legacy systems must be patched regularly and backup and data recovery plans should be tested and refined to ensure that healthcare services can bounce back quickly from any disruption.

Cybersecurity as public health duty

At the end of the day, securing the healthcare supply chain is not just a technical task, rather, it’s a duty of care. Patients trust their healthcare providers to keep their data and their lives safe. As the digital thread in healthcare becomes more essential to how we diagnose, treat and deliver care, this trust must extend to the technologies and the third-party suppliers our healthcare providers choose to partner with.

Recent cyber incidents in the healthcare supply chain are not isolated attacks. They are signals that action must be taken now and in collaboration to close the security gaps and protect the arteries of our healthcare system. Only through shared responsibility, strong standards and relentless vigilance can we ensure that the technologies meant to heal do not become the very vectors of harm.

We've compiled a list of the best Electronic Health Records software.

This article was produced as part of TechRadarPro's Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro



from Latest from TechRadar US in News,opinion https://ift.tt/3oVc2Zd

Vanta admits it introduced a bug in its code The bug resulted in a small subset of customers having data exposed The error is being fix...


  • Vanta admits it introduced a bug in its code
  • The bug resulted in a small subset of customers having data exposed
  • The error is being fixed, and affected customers notified

Security and compliance automation company Vanta has confirmed sharing sensitive customer data with other customers by mistake.

In a statement (via TechCrunch), the company said a change it had made in the code resulted in a security breach. In it, some sensitive data from a small subset of customers was shared with other customers.

The incident was spotted on May 26, and remediation efforts are currently underway, with the process set to finish by June 4.

Hundreds of victims

As a result of the incident, “a subset of data from fewer than 20% of our third-party integrations” was exposed to other Vanta customers, the company’s chief product officer Jeremy Epling said.

He added that fewer than 4% of Vanta customers have been affected, and they have already been notified.

Since the company has more than 10,000 customers, that would put the breach at up to 400. At the same time, the data breach notification letter Vanta sent out says that the data typically includes employee names, roles, and information about different tools, such as 2FA. The company did not confirm exactly what type of data was grabbed.

Vanta is a security and compliance automation platform that helps businesses achieve and maintain certifications like SOC 2, ISO 27001, HIPAA, and GDPR more efficiently through continuous monitoring and integrations.

Among its customers are Atlassian, Omni Hotels, Quora, and ZoomInfo.

You might also like



from Latest from TechRadar US in News,opinion https://ift.tt/meCuFXD

Hello and welcome to our coverage of InfoSecurity Europe 2025! Held at London's Excel center, Infosec 2025 (as everyone actually calls...

Hello and welcome to our coverage of InfoSecurity Europe 2025!

Held at London's Excel center, Infosec 2025 (as everyone actually calls it) is one of the biggest security-focused events on the calendar, packed with big names, informative talks, and news from the biggest firms around.

We're here in London and live on the ground for Infosec 2025 - here's what we've seen so far!

Good morning from InfoSecurity Europe 2025! We're here at the Excel, and off to collect our badge before heading in.



from Latest from TechRadar US in News,opinion https://ift.tt/EQjUrGO

More DJI Osmo 360 images have leaked online The 360-degree camera could launch in July It's said to be similar to the Insta360 X5 i...


  • More DJI Osmo 360 images have leaked online
  • The 360-degree camera could launch in July
  • It's said to be similar to the Insta360 X5 in specs

Rumors around a 360-degree camera from DJI have been swirling since October, and now we have some fresh leaks that supposedly give us a look at the DJI Osmo 360 – as well as hinting at some of the specifications it'll bring with it.

Tipster @GAtamer (via Notebookcheck) has posted some pictures of the DJI Osmo 360, showing off the compact camera, the two lenses on the front and back of the device, the small integrated touchscreen, and what looks like an accessory mount.

According to the same source, the specs of the DJI Osmo 360 are going to be "almost the same as the X5", referring of course to the Insta360 X5 that launched in April – another 360-degree camera that the DJI Osmo 360 will be challenging head on.

Have a read through our Insta360 X5 review and you'll see it's a very, very good 8K camera indeed – one we awarded five stars to. The two cameras have 1.28-inch sensors inside, bigger than those in the X4, so it seems we can expect something similar from DJI.

Coming soon?

The @GAtamer post was actually a follow-up to another image leaked by @Quadro_News, which seems to show the DJI Osmo 360 in some kind of packaging. Again, we can see one of the camera lenses and the shape of the upcoming gadget.

That's just about all we can glean from these latest DJI Osmo 360 leaks, and we don't get any information here about a launch date or potential pricing. It seems likely that the camera will be appearing sooner rather than later, however.

Just a few days ago we got word that the DJI Osmo 360 would be launching in July 2025, so there's not that much longer to wait. We have already seen leaked images of the camera, which match the pictures that have just shown up.

We've also heard that a super-small DJI Osmo Nano could be launched alongside the DJI Osmo 360. If these new devices are as good as the cameras in the current range, including the DJI Osmo Action 5 Pro, then there's a lot to look forward to.

You might also like



from Latest from TechRadar US in News,opinion https://ift.tt/adZ5U3B

At 3 a.m. during a red team exercise, we watched customer’s autonomous web agent cheerfully leak the CTO’s credentials - because a single m...

At 3 a.m. during a red team exercise, we watched customer’s autonomous web agent cheerfully leak the CTO’s credentials - because a single malicious div tag on internal github issue page told it to. The agent ran on Browser Use, the open source framework that just collected a headline-grabbing $17 million seed round.

That 90-second proof-of-concept illustrates a larger threat: while venture money races to make large-language-model (LLM) agents “click” faster, their social, organizational, and technical trust boundaries remain an afterthought. Autonomous browsing agents now schedule travel, reconcile invoices, and read private inboxes, yet the industry treats security as a feature patch, not a design premise.

Our argument is simple: agentic systems that interpret and act on live web content must adopt a security-first architecture before their adoption outpaces our ability to contain failure.

Agent explosion

Browser Use sits at the center of today’s agent explosion. In just a few months it has acquired more than 60,000 GitHub stars and a $17 million seed round led by Felicis with participation from Paul Graham and others, positioning itself as the “middleware layer” between LLMs and the live web.

Similar toolkits - HyperAgent, SurfGPT, AgentLoom - are shipping weekly plug-ins that promise friction-free automation of everything from expense approval to source-code review. Market researchers already count 82 % of large companies running at least one AI agent in production workflows and forecast 1.3 billion enterprise agent users by 2028.

But the same openness that fuels innovation also exposes a significant attack surface: DOM parsing, prompt templates, headless browsers, third-party APIs, and real-time user data intersect in unpredictable ways.

Our new study, "The Hidden Dangers of Browsing AI Agents" offers the first end-to-end threat model for browsing agents and provides actionable guidance for securing their deployment in real-world environments.

To address discovered threats, we propose a defense in depth strategy incorporating input sanitization, planner executor isolation, formal analyzers, and session safeguards. These measures protect against both initial access and post exploitation attack vectors.

White-box analysis

Through white-box analysis of Browser Use, we demonstrate how untrusted web content can hijack agent behavior and lead to critical cybersecurity breaches. Our findings include prompt injection, domain validation bypass, and credential exfiltration, evidenced by a disclosed CVE and a working proof of concept exploit - all without tripping today’s LLM safety filters.

Among the findings:

1. Prompt-injection pivoting. A single off-screen element injected a “system” instruction that forced the agent to email its session storage to an attacker.

2. Domain-validation bypass. Browser Use’s heuristic URL checker failed on unicode homographs, letting adversaries smuggle commands from look-alike domains.

3. Silent lateral movement. Once an agent has the user’s cookies, it can impersonate them across any connected SaaS property, blending into legitimate automation logs.

These aren’t theoretical edge cases; they are inherent consequences of giving an LLM permission to act rather than merely answer, which acts a root cause for the outlined exploit above. Once that line is crossed, every byte of input (visible or hidden) becomes potential initial access payload.

To be sure, open source visibility and red team disclosure accelerate fixes - Browser Use shipped a patch within days of our CVE report. And defenders can already sandbox agents, sanitize inputs, and restrict tool scopes. But those mitigations are optional add-ons, whereas the threat is systemic. Relying on post-hoc hardening mimics the early browser wars, when security followed functionality, and drive-by downloads became the norm.

Architectural problem

Governments are beginning to notice the architectural problem. The NIST AI Risk-Management Framework urges organizations to weigh privacy, safety and societal impact as first-class engineering requirements. Europe’s AI Act introduces transparency, technical-documentation and post-market monitoring duties for providers of general-purpose models rules that will almost certainly cover agent frameworks such as Browser Use.

Across the Atlantic, the U.S. SEC’s 2023 cyber-risk disclosure rule expects public companies to reveal material security incidents quickly and to detail risk-management practices annually. Analysts already advise Fortune 500 boards to treat AI-powered automation as a headline cyber-risk in upcoming 10-K filings. Reuters: “When an autonomous agent leaks credentials, executives will have scant wiggle room to argue that the breach was “immaterial.”

Investors funneling eight-figure sums into agentic start-ups must now reserve an equal share of runway for threat-modeling, formal verification, and continuous adversarial evaluation. Enterprises piloting these tools should require:

Isolation by default. Agents should separate planner, executor and credential oracle into mutually distrustful processes, talking only via signed, size-bounded protobuf messages.

Differential output binding. Borrow from safety-critical engineering: require a human co-signature for any sensitive action.

Continuous red-team pipelines. Make adversarial HTML and jailbreak prompts part of CI/CD. If the model fails a single test, block release.

Societal SBOMs. Beyond software bills of materials, vendors should publish security-impact surfaces: exactly which data, roles and rights an attacker gains if the agent tips. This aligns with the AI-RMF’s call for transparency regarding individual and societal risks.

Regulatory stress tests. Critical-infrastructure deployments should pass third-party red-team exams whose high-level findings are public, mirroring banking stress-tests and reinforcing EU and U.S. disclosure regimes.

The security debt

The web did not start secure and grow convenient; it started convenient, and we are still paying the security debt. Let us not rehearse that history with autonomous browsing agents. Imagine past cyber incidents multiplied by autonomous agents that work at machine speed and hold persistent credentials for every SaaS tool, CI/CD pipeline, and IoT sensor in an enterprise. The next “invisible div tag” could do more than leak a password: it could rewrite PLC set-points at a water-treatment plant, misroute 911 calls, or bulk-download the pension records of an entire state.

If the next $17 million goes to demo reels instead of hardened boundaries, the 3 a.m. secret you lose might not just embarrass a CTO - it might open the sluice gate to poison supplies, stall fuel deliveries, or crash emergency-dispatch consoles. That risk is no longer theoretical; it is actuarial, regulatory, and, ultimately, personal for every investor, engineer, and policy-maker in the loop.

Security first or failure by default for agentic AI is therefore not a philosophical debate; it is a deadline. Either we front-load the cost of trust now, or we will pay many times over when the first agent-driven breach jumps the gap from the browser to the real world.

We feature the best AI chatbot for business.

This article was produced as part of TechRadarPro's Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro



from Latest from TechRadar US in News,opinion https://ift.tt/S9wezvL

In an increasingly complex cybersecurity landscape, the concept of "hacking yourself first" is not new as such. Organizations ha...

In an increasingly complex cybersecurity landscape, the concept of "hacking yourself first" is not new as such. Organizations have long been engaging white hat hackers to simulate attacks and identify vulnerabilities before malicious actors can exploit them.

However, the traditional approach to red teaming, which typically involves selecting a few trusted individuals to test a system, is no longer sufficient.

More open and competitive red teaming

The issue lies in scale and diversity. A small, internal team will always be limited by their own experiences and perspectives, while cybercriminals operate in a global, decentralized environment. To stay ahead, security testing has to reflect that same breadth and depth of capability.

We believe that this is where a more open and competitive red teaming model comes into its own. Rather than relying on a fixed set of internal engineers or external consultants, organizations are increasingly turning to decentralized architectures.

These invite skilled professionals from around the world to solve specific, targeted challenges. The best talent is incentivized to respond, and the organization benefits from rapid, high-quality insights tailored to the specific threats it faces.

In practice, this model offers two significant advantages to the ‘standard white hacking’ exercise. First, it ensures that the right expertise is applied to the right challenge. Not every engineer is equipped to uncover flaws in VPN detection or anti-fingerprinting solutions. A decentralized approach enables organizations to source the most relevant skill sets directly, without needing to retrain or reallocate internal teams.

Secondly, the incentive mechanism encourages speed and transparency. Contributors are motivated to share findings immediately so that they can claim rewards. This reduces and even eliminates delays and ensures that critical information reaches defenders quickly.

Traditional methods

The benefits of this approach are already being realized. In sectors such as fintech and Web3, attacks discovered through decentralized red teaming have been observed in the wild months later. This lead time allows businesses to prepare and adapt before those attacks gain traction in broader markets.

It’s important to recognize that decentralized red teaming is not about replacing traditional methods entirely. Conventional penetration testing still plays a valuable role in improving baseline security. But as threats evolve and attackers become more sophisticated, organizations need a more dynamic and scalable way to test their defenses.

Proactive security

Ultimately, the shift from reactive to proactive security cannot be achieved through periodic exercises alone. It requires continuous, adaptive engagement with the threat landscape, and a willingness to invite external expertise into the process. By embracing a more competitive and decentralized approach to red teaming, businesses can significantly improve their resilience and stay one step ahead of attackers.

Cybersecurity is no longer about responding to yesterday’s threats. It is about anticipating tomorrow’s, and making sure your defenses are ready today.

We feature the best business VPNs.

This article was produced as part of TechRadarPro's Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro



from Latest from TechRadar US in News,opinion https://ift.tt/naCXZMm

Sony's new headphones are easier to repair than before The battery is one component that's more straightforward to replace It s...


  • Sony's new headphones are easier to repair than before
  • The battery is one component that's more straightforward to replace
  • It should mean fewer of these devices become e-waste

The Sony WH-1000XM6 headphones launched a couple of weeks ago, and have already attracted plenty of praise – see our Sony WH-1000XM6 review, for example. Now we have another reason for investing in a pair: they're easier to repair than previous models.

According to the experts at iFixit, "Sony appears to have made a deliberate effort to design the WH-1000XM6 with repair in mind", and there have been tweaks to how these headphones have been put together that show that.

Crucially, iFixit says, the battery inside the headphones is now fixed in place with two screws – rather than being stuck in with the double-sided adhesive that was used for the Sony WH-1000XM5, which launched back in 2022.

The modular driver mid-plate is straightforward to replace as well, iFixit says – there's no glue to deal with, and the component can be got at without the risk of damaging other parts of the interior of the headphones.

Readily accessible components

iFixit also reports that the USB-C port, the audio jack, and the button board are "readily accessible", making repairs easier. The idea is that if one part of the Sony WH-1000XM6 headphones fails, you don't have to completely replace them.

It's not all good news on the repairability front though: iFixit says there's not much improvement as far as the headband goes, so if there's a problem with this part of the device then you may well have to get a new pair.

Of course when we say the Sony WH-1000XM6 are easier to repair, you do still need a certain amount of technical know-how and some specialist tools for the job. However, the job now is more straightforward, whether you do it yourself or take it into a repair shop.

There's plenty of advice over on iFixit about how you might go about repairing the Sony WH-1000XM6 headphones and a whole host of other gadgets, but if you're weighing up the pros of buying them, you can add repairability to the list.

You might also like



from Latest from TechRadar US in News,opinion https://ift.tt/EsywB6p

I'm lucky enough to test some of the best coffee makers around for TechRadar, but the Sage Barista Touch Impress (known as the Brevill...

I'm lucky enough to test some of the best coffee makers around for TechRadar, but the Sage Barista Touch Impress (known as the Breville Barista Touch Impress outside of the UK) is the most satisfying I've ever used. It's all thanks to the Impress Puck System, which lets you create a perfectly-formed bed of coffee in the filter basket by pulling down a lever on the side of the machine – and it's brilliant.

I've been using the Barista Touch Impress for a few days now and, so far, it's been an absolute pleasure. It's around half the price of the De'Longhi Primadonna Aromatic I reviewed recently, but still has the feeling of a premium bean-to-cup espresso machine.

It's supplied with single-walled and pressurized filter baskets (the latter of which make it easier for new users to create a well-extracted espresso), the portafilter feels reassuringly weighty in the hand, and it's supplied with a full set of cleaning tools that sit tidily in a storage drawer behind the drip tray.

It also comes with an 'eco starter kit', which contains sachets of descaler, group head cleaner, grinder cleaner, and steam wand cleaner, together with a nice microfiber barista cloth. It's a thoughtful addition, and the machine will walk you through each of the cleaning processes when it's time to freshen things up.

Coffee in filter basket of Sage Barista Touch Impress machine

The Impress Puck System makes it easy to create an even bed of coffee with no mess (Image credit: Future)

You also get a water filter as standard. Some of the best espresso machines come with one, while others require you to buy one separately if you live in a hard water area, or just to remove impurities that might affect the taste of your coffee.

There's a water testing strip to determine the hardness of your tap water and, if it's particularly hard, Sage recommends using filtered water instead. You should never use distilled water in an espresso machine, though. Not only can it make coffee taste flat, it's a poor conductor of electricity, which can throw off the water level sensors that let the machine know if the tank is sufficiently full.

Time to grind

One of the trickiest parts of being a barista is choosing the right grind size for your coffee beans (a process known as 'dialling in'). Too large and the water will flow through to coffee too quickly, and only the sour flavor compounds will dissolve in the water. Too fast, and you'll get the sweet flavors you want, but also bitter compounds that leave your mouth feeling dry.

Think of the difference between water running through a bucket of marbles and a bucket of sand. The marbles have larger gaps in between, so the water moves through quickly.

The Sage Barista Touch Impress doesn't do all the work of dialling in for you, but makes it as easy as possible and helps you understand the process. If you want to switch to a fully manual espresso machine at a later date, you'll be able to hit the ground running.

Using the tamping handle on the Sage Barista Touch Impress machine

Pulling down the tamping handle doesn't take much force, but it's fun (Image credit: Future)

After filling the water tank and loading up your preferred beans, the Barista Touch Impress will walk you through the process of making your first coffee. Your initial options are espresso, long black, latte, cappuccino, and flat white. There are, though a lot more options available (both hot and cold) once you’ve completed the initial setup – indeed, I'm not sure what a 'shakerato' is, but I look forward to finding out as it sounds tasty.

Insert a basket into the portafilter handle, then push it under the grinder spout and tap the picture of a basket on the touchscreen to get started. The Barista Touch Impress will grind a portion of beans straight into the basket for you, then – and this is the fun part – prompt you to pull down the lever on the left-hand side of the machine to tamp it down. You don't need to apply much pressure at all, but it's very satisfying. You're advised to pull it down twice each time. Double the fun.

Cleverly, the machine will detect how much force was required to tamp the coffee, and will suggest adding more coffee to the basket if there wasn't enough. Depending on your chosen beans and the grinder setting, you might need to do this a few times but, once you've got the ideal amount in the basket, the Barista Touch Impress will record the total dosage for next time.

Brews for you

Now it's time to twist the portafilter into position under the group head and begin brewing your first espresso. Ideally, it should take around 36 seconds to pull a shot of espresso (give or take a few seconds either side), and the Barista Touch Impress will time it for you. If it's taking too long, you'll be warned that the drink might taste sour and asked whether you're happy to go ahead, or you want to start again with a larger grind size. If the shot is pulled too fast, the machine will advise that it might taste watery.

In either case, the Barista Touch Impress will suggest an alternative grind size, which you can set by turning a dial near the tamping lever. It might take a few attempts to dial the grinder in perfectly and it may seem like you're using quite a lot of coffee, but it's just part of the process. You don't want to know how many beans a trainee barista goes through when learning the ropes. It's a lot.

Espresso dispensing from Sage Barista Touch Impress machine

The machine times how long it takes to pull a shot of espresso and suggests tweaking the grind size if necessary (Image credit: Future)

When you've eventually created a perfectly balanced espresso, the full menu of drink options will be unlocked and you're free to begin experimenting.

So far, I've only scratched the surface of what this great bean-to-cup machine can do, but I'm already thoroughly enjoying it. I'll bring you a full review once I've explored everything it's capable of and determined whether it deserves a place in TechRadar's roundup of the best bean-to-cup coffee machines. Now, if you'll please excuse me, I need to get some more beans.



from Latest from TechRadar US in News,opinion https://ift.tt/eTWsyDO

There’s no doubt about it: Android offers a fantastic ecosystem with some of the best phones and best tablets money can buy. When you opt...

There’s no doubt about it: Android offers a fantastic ecosystem with some of the best phones and best tablets money can buy. When you opt for products powered by Google’s operating system, you’ll find devices that cover just about every need imaginable, from budget-friendly phones to feature-rich powerhouses. It’s also a highly customizable system that lets you tweak it in just about any way you can imagine, unlike Apple’s locked down offerings.

Yet despite all that, I’ve never owned an Android phone.

Sure, I had a slide-up Samsung back in the day, but that was probably before Android was even a consideration inside Google HQ (honestly, it was also a terrible phone). Instead, I’ve faithfully stuck with Apple ever since I first got an iPhone 3GS, never since venturing outside the famous walled garden.

So why have I never been tempted to switch over to the Android side and ditch my Apple products for good, despite the open appeal of Google's mobile operating system? Well, there’s one thing that has made me an Apple loyalist for many years now: the seamless way Apple’s devices all work together, and the incredible features this enables.

Apple controls both the hardware and software that underpins its products, and this is something that I think a lot of people really underestimate. If Apple knows exactly which devices and operating systems it will be working with, it knows what kind of features it can build, and it knows that those features should work reliably for everyone.

iPhone 15 foreground Google Pixel 8 Pro background

(Image credit: Future | Alex Walker-Todd)

With Android, you’re talking about a huge range of diverse hardware and software configurations. That has its benefits, but it also makes it difficult for developers to account for all that variation. This throws up problems with functionality and compatibility, which limits what can be done to a degree that doesn’t happen with Apple.

For example, I love how I can place my iPhone on my Mac’s monitor and it instantly becomes a webcam, no software setup needed. Or how I can use a single mouse and keyboard on both my Mac and my iPad, or drag and drop a file from my iPhone to my Mac without a hitch.

Sure, some of these features work on Android, more or less, but they’re nowhere near as slick. Apple’s features work automatically and intuitively, with no additional software to install and no cumbersome setup process to go through. My Apple devices recognize each other and work together without a hitch.

That’s something that I just can’t get on Android – not to the same extent, anyway. So, while Android has a huge amount to offer, it falls short compared to Apple when it comes to this impactful area.

Smooth integration

Screenshot of Universal Control feature in macOS

(Image credit: Apple)

That said, my setup is a little more complicated than I originally made out. As well as my Apple kit, I also have a Windows PC, which doesn’t always play nice with my iOS and macOS devices. I certainly can’t use Apple exclusives like Handoff, Universal Control and more across both iOS and Windows, for example. Even though I get to enjoy Apple’s joined-up ecosystem for the most part, there are still hitches when it comes to my PC.

What I want is something that offers all this functionality across all my devices. I won’t get that from Apple with its closed-off walled garden – the company doesn’t like sharing, after all. Things like Continuity Camera will never come to Windows, at least not in a native form from Apple.

But at the same time, I definitely won’t get that functionality from Android either, which is too dispersed and fragmented to offer the same kind of integration as Apple can provide.

Ultimately, Apple still gives me the best way to have all my devices working together near-seamlessly. I absolutely love how using my iPhone, iPad and Mac together unlocks all kinds of neat functions and features that I can’t get anywhere else, and I know that if I switched to Android, I’d lose out on a lot of that.

I can’t say if there’s a solution on the horizon that works for both Apple products and the Windows/Android world. But for now, Apple has the upper hand, at least for me. Hopefully, Android can find a way to catch up in the future.

You might also like



from Latest from TechRadar US in News,opinion https://ift.tt/Hn8T5kg