โŒ

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

I spent a month with the Huawei MatePad Air, and it's confirmed my one big wish for the next iPad Air

Huawei, as a brand, is in a very interesting place right now. The company is genuinely innovating on a lot of fronts. It just launched the Mate XT2 tri-folding phone, which brings Samsung-like Privacy Display tech to the tri-folding form factor, as well as the Watch D3, which puts medical-grade blood pressure measurements into an even slimmer smartwatch.

But the problem with Huawei has always been that you can't buy a lot of the company's devices in markets outside Asia. And while that doesn't look like it's changing anytime soon, every once in a while, Huawei does launch some products in the West, and it reminds us (again) of what we're missing from other major hardware makers.

That's exactly what happened with the new Huawei MatePad Air. I usually use my still-going-strong M1 iPad Air (2022) as my main tablet, but I've spent the past month using the MatePad Air as my primary device. And it has shown me the one upgrade Apple could make that would probably convince me to finally buy the next iPad Air.

Hands-on with the Huawei MatePad Air (2026)

(Image credit: Sanuj Bhatia / TechRadar)

The MatePad Air itself doesn't look like some groundbreaking new tablet. In fact, Huawei has so many tablets in its lineup that you'd probably have a hard time distinguishing the new MatePad Air from some of the company's other models just by looking at the back.

But flip the MatePad Air around, and that's where, for me, it starts beating a lot of the competition. The MatePad Air comes with a 12-inch OLED display with up to a 144Hz refresh rate and a 1,200-nit peak brightness. But the model I've been testing for the past month is the higher-end PaperMatte version, which can reach up to 2,000 nits.

If you're unfamiliar with Huawei's PaperMatte display technology, it's essentially a special anti-glare treatment on top of the display that, Huawei says, eliminates up to 99% of ambient light reflections. It also gives the screen a more paper-like texture, which feels natural when you're writing with a stylus, while also helping reduce things like eye strain and smudges.

Hands-on with the Huawei MatePad Air (2026)

(Image credit: Sanuj Bhatia / TechRadar)

And this display alone is what has made me prefer using the MatePad Air over my iPad Air for the past month.

Think about what you actually do with a tablet. Whether you use an iPad Pro or the Samsung Galaxy Tab S11 Ultra, almost everything revolves around the display. You're watching content, taking notes, making video calls, or reading. For 99% of the time, you're looking at and interacting with a screen.

It's not like the iPad Air's display is bad. It's still a good-looking panel, and I've used my M1 iPad Air for years without any complaints. But Apple hasn't meaningfully upgraded the display technology in a while, and it's starting to show its age.

The iPad Air still uses an LCD panel. It's still stuck at 60Hz, and the bezels are quite thick as well. None of these things really bothered me before, but switching back and forth between it and the MatePad Air made the difference quite obvious.

The 144Hz OLED panel on the MatePad Air is obviously smoother, the colors look great, and the thinner bezels make watching content much nicer. And that PaperMatte display just makes everything twice as nice.

Hands-on with the Huawei MatePad Air (2026)

(Image credit: Sanuj Bhatia / TechRadar)

I've used the MatePad Air pretty much everywhere, be it the subway, airplanes, or my home, and not having reflections constantly bouncing off the screen has been great.

And it's not like Apple doesn't know how to do this. The company already offers its nano-texture display on the iPad Pro. The problem is that you need to buy one of the most expensive iPad Pro configurations (specifically, a model with 1TB or more) to even get the option, pushing the price to $1,899 / ยฃ1,899 / AU$3,249.

Huawei, on the other hand, makes the upgrade much easier to swallow. In the UK, you get the PaperMatte display regardless of which version of the MatePad Air you choose; the cheapest is just ยฃ699.99 (it's not available in the US). You're also getting 256GB of storage on the base model, compared to the 128GB starting storage on the iPad Air.

Hands-on with the 2026 Huawei MatePad Air

(Image credit: Sanuj Bhatia / TechRadar)

Of course, the MatePad Air isn't better than the iPad Air at everything. Apple's M-series chips still give the iPad a major performance advantage, and if I'm editing videos or doing other compute-heavy work on a tablet, I'd still rather have the iPad Air.

But most of the time, that's not what I'm doing on my tablet. I mostly use my iPad to watch content and browse the web, and for both of these things, I'd rather have the MatePad Air's display.

Plus, the hardware around the OLED display is pretty impressive, too. At 12 inches, the MatePad Air sits somewhere between Apple's 11-inch and 13-inch iPad Air models. It weighs just 509g and uses an aluminum frame and back, making it more than 100g lighter than the 13-inch iPad Air.

It's thinner too, measuring just 5.3mm compared to 6.1mm for the larger iPad Air, despite Huawei fitting a 10,100mAh battery inside compared to roughly 9,705mAh on Apple's tablet.

Hands-on with the Huawei MatePad Air (2026)

(Image credit: Sanuj Bhatia / TechRadar)

That said, none of this means I'm ready to completely ditch the iPad. I still prefer its performance, app ecosystem, and just how well it works with the rest of my Apple devices. But after a month with the MatePad Air, the one thing I desperately want to take back to my iPad is this display.

Give the next iPad Air an OLED display with (hopefully) an anti-reflective PaperMatte-like option that doesn't burn a hole in my pocket, and my M1 iPad Air might finally have a reason to retire.

Microsoft, tech companies throw weight behind spread of open-source AI

By: djohnson
24 July 2026 at 11:22

Microsoft, along with more than two dozen tech companies, are pressing policymakers to support open-source AI systems and code across society, arguing that it will be a safer approach than attempting to restrict access or relying on a handful of closed, proprietary models.

The open letter, posted Friday, draws parallels to the software industry of the 1980s, when large businesses worried that open-source software code would cut into their business. While industry lost that battle, the end result was a vibrant ecosystem that now underpins much of the modern internet, government IT and even commercial software products.

It also created a โ€œshared foundation of knowledgeโ€ that has fed countless future software projects and innovations.

โ€œThe United States now faces a similar choice with artificial intelligence,โ€ the companies wrote. โ€œOur AI leadership will be judged not by one frontier AI model, but by whether the United States builds a strong, open ecosystem that diffuses into every sector.โ€

Expanding access and support to open-source AI comes with meaningful security risk. Cybersecurity experts warn that one of the biggest beneficiaries of broadly available AI tools areย  low-level criminals who until now lacked the technical expertise or resources to launch serious attacks.

Once a model is open weight, anyone can download it, customize it, strip it of any guardrails and use it for their own purposes. As open-source models have gotten better at creating deepfakes and other AI generated imagery, the danger of locally-customized CSAM and sexualized deepfakes could also grow.

But the letter argues that open-weight AI models are most beneficial to startups, universities, research labs and other small, ambitious organizations that can innovate and iterate the technology and make it more broadly useful to society.

โ€œOpen weights let every organization match the right model to the right job at the right cost, reserving frontier-scale capability for genuine frontier problems and running efficient specialized specialized models everywhere else,โ€ The companies wrote. โ€œThat discipline is what will make AI economically sustainable as its use scales into the billions of everyday tasks.โ€

ย For cybersecurity specifically, the letter argues that defenders armed with open-source AI will outpace attackers better than any closed model approach.

โ€œIn a world where cybersecurity attackers use advanced AI, defenders need access to models with comparable capabilities so they can detect, simulate, and respond to emerging threats,โ€ the companies wrote. โ€œOpen models broaden defensive capability, increase transparency, and allow vulnerabilities to be discovered and remediated across many teams.โ€

Other notable companies signing the letter include Meta, Palantir, Perplexity, Mistral, NVIDIA, Mozilla, The Linux Foundation, Hugging Face, Dell Technologies and IBM.

US policymakers continue to grapple with balancing unrestrained support for the domestic AI industry and providing oversight and regulation of harms that result from their use.

The Trump administration has cycled through several frameworks since coming into office, first a laissez-faire approach within no restrictions, then an executive order creating a voluntary testing regime for industry, then the imposition of export controls on Anthropicโ€™s Fable model and reportedly pressuring OpenAI to delay the release of their models out of cybersecurity concerns.

The letter comes as the Trump administration has reportedly considered an executive order that would restrict American access and availability to Chinese-made open-source models.

But the White House and US companies are trying to thread a needle in recognizing the overall benefits of an open source approach while being wary of doing anything that could potentially benefit their Chinese rivals.

Earlier this month the White House announced the creation of its Gold Eagle AI cybersecurity clearinghouse that would help coordinate government, private sector and civil society work finding and closing AI-discovered vulnerabilities. A big part of that effort, a senior White House official said, is supporting providers and maintainers of open-source AI tools.

The post Microsoft, tech companies throw weight behind spread of open-source AI appeared first on CyberScoop.

KAPE 101: A Kroll Artifact Parser and Extractor Cheatsheet

By: BHIS
15 July 2026 at 10:00

Spend time performing forensic analysis on the Windows Operating System and you'll see a host of artifacts that can be used to identify adversary activity. From changes to the registry to the System Resource Utilization Monitor, Windows artifacts run deep. The challenge is locating, extracting, and parsing these artifacts in an efficient manner.

The post KAPE 101: A Kroll Artifact Parser and Extractor Cheatsheet appeared first on Black Hills Information Security, Inc..

Finding the โ€œGoldilocksโ€ Zone: A Practical Approach to Alert Triage

By: BHIS
8 July 2026 at 10:00

We're all petrified about missing a critical event or misclassifying an alert, but when we're talking about incident response (IR), there are often hundreds if not thousands of alerts to parse through. It's easy to get caught up with one alert because it feels "too hot" or maybe not spend enough time looking into something that initially seems "too cold."

The post Finding the โ€œGoldilocksโ€ Zone: A Practical Approach to Alert Triage appeared first on Black Hills Information Security, Inc..

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

23 June 2026 at 12:12

Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.

Owen Flowers (left) 18, and Thalha Jubair, 20. Image: UK National Crime Agency (NCA).

Thalha Jubair, 20, of East London and 18-year-old Owen Flowers of Walsall admitted conspiring to commit unauthorized acts against Transport for London computer systems and causing risk of serious damage to human welfare. According to a report from the BBC, Flowers alone admitted to being part of a conspiracy to hack into U.S. based healthcare providers SSM Health Care Corporation and Sutter Health in September 2024.

Jubair is also wanted by U.S. law enforcement agencies. In September 2025, prosecutors in New Jersey unsealed an indictment alleging Jubair and other Scattered Spider members committed computer fraud, wire fraud, and money laundering in relation to 120 computer network intrusions involving 47 U.S. entities between May 2022 and September 2025, and that the groupโ€™s victims paid at least $115 million in ransom payments.

In July 2025, KrebsOnSecurity reported that Flowers and Jubair were arrested in the United Kingdom in connection with Scattered Spider ransom attacksย against the retailersย Marks & Spencerย andย Harrods, and the British food retailerย Co-op Group. Multiple sources familiar with those investigations said Flowers was the Scattered Spider member who anonymously gave interviews to the media in the days after the groupโ€™s September 2023 ransomware attacks disrupted operations at Las Vegas casinos operated by MGM Resortsย andย Caesars Entertainment.

According to prosecutors, Jubair co-ran a bustling Telegram channel called Star Chat, the home of a SIM-swapping group that used voice- and SMS-based phishing attacks to steal credentials from employees at the major wireless providers in the U.S. and U.K. The group would then use that access to sell a service that could redirect a targetโ€™s phone number to a device the attackers controlled and intercept the victimโ€™s calls and text messages (including one-time codes for multi-factor authentication).

A receipt from Star Fraud Chatโ€™s SIM-swapping service targeting a T-Mobile customer after the group gained access to internal T-Mobile employee tools. โ€œRocket Aceโ€ was one of Jubairโ€™s hacker handles, according to U.S. prosecutors.

New Jersey prosecutors also allege Jubair also was involved in a mass SMS phishing campaign during the summer of 2022 that stole single sign-on credentials from employees at hundreds of companies.ย That weeks-long SMS phishing campaign led to intrusions and data thefts at more than 130 organizations, including LastPass,ย DoorDash,ย Mailchimp,ย Plexย andย Signal.

KrebsOnSecurity reported last year that one of Jubairโ€™s alter egos at age 15 was โ€œEverlynn,โ€ a hacker who sold fraudulent โ€œemergency data requestsโ€ that used compromised police and government email addresses to demand subscriber data (e.g. username, IP/email address) from major tech companies, claiming the requests concerned urgent matters of life and death and could not wait for a court order.

In April 2026, 24-year-old British national and Scattered Spider member Tyler โ€œTylerbโ€ Buchanan pleaded guilty to wire fraud conspiracy and aggravated identity theft for participating in the groupโ€™s SMS phishing spree in the summer of 2022. The government said Buchanan, Jubair and others used the credentials harvested in that phishing campaign to steal at least $8 million in cryptocurrency from victims throughout the United States. Buchanan is currently scheduled to be sentenced on October 2.

In August 2025, 20-year-old Scattered Spider member from Florida named Noah Michael Urban was sentenced to 10 years in federal prison and ordered to pay $13 million in restitution, after pleading guilty to charges of wire fraud and conspiracy.

The U.S. Department of Justice says three alleged Scattered Spider defendants indicted along with Buchanan still face charges, including Ahmed Hossam Eldin Elbadawy, 24, a.k.a. โ€œAD,โ€ of College Station, Texas; Evans Onyeaka Osiebo, 21, of Dallas, Texas; and Joel Martin Evans, 26, a.k.a. โ€œjoeleoli,โ€ of Jacksonville, North Carolina.

Flowers and Jubair are slated to be sentenced in a London court on July 15, 2026.

โ€˜Scattered Spiderโ€™ Member โ€˜Tylerbโ€™ Pleads Guilty

21 April 2026 at 10:53

A 24-year-old British national and senior member of the cybercrime group โ€œScattered Spiderโ€ has pleaded guilty to wire fraud conspiracy and aggravated identity theft. Tyler Robert Buchanan admitted his role in a series of text-message phishing attacks in the summer of 2022 that allowed the group to hack into at least a dozen major technology companies and steal tens of millions of dollars worth of cryptocurrency from investors.

Buchananโ€™s hacker handle โ€œTylerbโ€ once graced a leaderboard in the English-language criminal hacking scene that tracked the most accomplished cyber thieves. Now in U.S. custody and awaiting sentencing, the Dundee, Scotland native is facing the possibility of more than 20 years in prison.

A screenshot of two photos of Buchanan that appeared in a Daily Mail story dated May 3, 2025.

Two photos published in a Daily Mail story dated May 3, 2025 show Buchanan as a child (left) and as an adult being detained by airport authorities in Spain. โ€œM&Sโ€ in this screenshot refers to Marks & Spencer, a major U.K. retail chain that suffered a ransomware attack last year at the hands of Scattered Spider.

Scattered Spider is the name given to a prolific English-speaking cybercrime group known for using social engineering tactics to break into companies and steal data for ransom, often impersonating employees or contractors to deceive IT help desks into granting access.

As part of his guilty plea, Buchanan admitted conspiring with other Scattered Spider members to launch tens of thousands of SMS-based phishing attacks in 2022 that led to intrusions at a number of technology companies, including Twilio, LastPass, DoorDash, and Mailchimp.

The group then used data stolen in those breaches to carry outย SIM-swapping attacks that siphoned funds from individual cryptocurrency investors. In an unauthorized SIM-swap, crooks transfer the targetโ€™s phone number to a device they control and intercept any text messages or phone calls to the victimโ€™s device โ€” such as one-time passcodes for authentication and password reset links sent via SMS. The U.S. Justice Department said Buchanan admitted to stealing at least $8 million in virtual currency from individual victims throughout the United States.

FBI investigators tied Buchanan to the 2022 SMS phishing attacks after discovering the same username and email address was used to register numerous phishing domains seen in the campaign. The domain registrar NameCheap found that less than a month before the phishing spree, the account that registered those domains logged in from an Internet address in the U.K. FBI investigators said the Scottish police told them the address was leased to Buchanan throughout 2022.

Asย first reported by KrebsOnSecurity, Buchanan fled the United Kingdom in February 2023, after a rival cybercrime gang hired thugs to invade his home, assault his mother, and threaten to burn him with a blowtorch unless he gave up the keys to his cryptocurrency wallet. That same year, U.K. investigators found a device at Buchananโ€™s Scotland residence that included data stolen from SMS phishing victims and seed phrases from cryptocurrency theft victims.

Buchanan was arrested by Spanish authorities in June 2024 while trying to board a flight to Italy. He was extradited to the United States and has remained in U.S. federal custody since April 2025.

Buchanan is the second known Scattered Spider member to plead guilty. Noah Michael Urban, 21, of Palm Coast, Fla., was sentenced to 10 years in federal prison last year and ordered to pay $13 million in restitution. Three other alleged co-conspirators โ€” Ahmed Hossam Eldin Elbadawy, 24, a.k.a. โ€œAD,โ€ of College Station, Texas; Evans Onyeaka Osiebo, 21, of Dallas, Texas; and Joel Martin Evans, 26, a.k.a. โ€œjoeleoli,โ€ of Jacksonville, North Carolina โ€“ still face criminal charges.

Two other alleged Scattered Spider members will soon be tried in the United Kingdom. Owen Flowers, 18, and Thalha Jubair, 20, are facing charges related to the hacking and extortion of several large U.K. retailers, the London transit system, and healthcare providers in the United States. Both have pleaded not guilty, and their trial is slated to begin in June.

Investigators say the Scattered Spider suspects are part of a sprawling cybercriminal community online known as โ€œThe Com,โ€ wherein hackers from different cliques boast publicly on Telegram and Discord about high-profile cyber thefts that almost invariably begin with social engineering โ€” tricking people over the phone, email or SMS into giving away credentials that allow remote access to corporate internal networks.

One of the more popular SIM-swapping channels on Telegram has long maintained a leaderboard of the most rapacious SIM-swappers, indexed by their supposed conquests in stealing cryptocurrency. That leaderboard previously listed Buchananโ€™s hacker alias Tylerb at #65 (out of 100 hackers), with Urbanโ€™s moniker โ€œSosaโ€ coming in at #24.

Buchananโ€™s sentencing hearing is scheduled for August 21, 2026. According to the Justice Department, he faces a statutory maximum sentence of 22 years in federal prison. However, any sentence the judge hands down in this case may be significantly tempered by a number of mitigating factors in the U.S. Sentencing Guidelines, including the defendantโ€™s age, criminal history, time already served in U.S. custody, and the degree to which they cooperated with federal authorities.

The Curious Case of theย Comburglar

By: BHIS
18 December 2025 at 12:55

By Troy Wojewoda During a recent Breach Assessment engagement, BHIS discovered a highly stealthy and persistent intrusion technique utilized by a threat actor to maintain Command-and-Control (C2) within the clientโ€™s [โ€ฆ]

The post The Curious Case of theย Comburglar appeared first on Black Hills Information Security, Inc..

Webcast: Attack Tactics 7 โ€“ The Logs You Are Looking For

By: BHIS
22 July 2019 at 12:10

Slides for this webcast can be found here: https://www.blackhillsinfosec.com/wp-content/uploads/2020/09/SLIDES_AttackTactics7LogsYouAreLookingFor.pdf So we went through an attack in the BHIS Webcast, โ€œAttack Tactics 5! Zero to Hero Attack.โ€ Then we went through [โ€ฆ]

The post Webcast: Attack Tactics 7 โ€“ The Logs You Are Looking For appeared first on Black Hills Information Security, Inc..

WEBCAST: Cubicles and Compromises

By: BHIS
25 January 2018 at 11:08

John Strand// Hereโ€™s a live demo of Johnโ€™s recent blog post that talked about gamifying your table top Dungeon and Dragons style. Join John, Kent, Jordan and Sierra as they [โ€ฆ]

The post WEBCAST: Cubicles and Compromises appeared first on Black Hills Information Security, Inc..

Cubicles and Compromises Printable

By: BHIS
23 January 2018 at 12:46

Cubicles and Compromises

John Strand// Thanks for joining us for our Cubicles and Compromises webcast! We also have a recording available soon! In the meantime, hereโ€™s a blog post explanation: And, here youโ€™ll [โ€ฆ]

The post Cubicles and Compromises Printable appeared first on Black Hills Information Security, Inc..

โŒ
โŒ