Reading view

There are new articles available, click to refresh the page.

Cybersecurity’s identity crisis: why trust can no longer begin and end at login

The image most organizations still have of a cyberattack is fundamentally outdated.

We tend to picture hackers battering down digital walls by exploiting software vulnerabilities or launching convoluted ransomware campaigns. Yet some of the most damaging breaches today involve something far less dramatic.

An attacker enters through the front door using valid credentials, passes authentication checks, and proceeds through the environment as if they are a completely legitimate employee.

Recent attacks targeting public sector organizations in the UK have once again demonstrated just how easy it is to get into an environment if you have the right credentials.

Earlier this year, hackers managed to breach systems used by the UK Foreign Office and local councils using stolen login credentials.

As compromised credentials become increasingly easy to buy and sell on the dark web, organizations face a different sort of challenge: determining whether the person behind a successful login is actually who they claim to be.

Authentication is no longer enough

For years, organizations viewed authentication as a decisive security event. A user entered the correct password, perhaps completed a multi-factor authentication challenge, and was granted access.

The problem is that attackers have, as ever, have found a way around.

Large-scale phishing campaigns, infostealer malware, session hijacking techniques and credential harvesting operations have made legitimate account access easier to acquire than ever before. The UK's Cyber Security Breaches Survey 2025 found that phishing remains the most common cyber threat facing organizations, affecting 85% of businesses that experienced a breach or attack.

For many cybercriminals, phishing is simply the first step in a wider economy built around stolen identities. Once compromised, credentials and authentication tokens are routinely traded on dark web forums, giving attackers a ready-made route into trusted environments.

So why do we continue to treat a successful authentication as proof that a user can be permanently trusted?

In reality, authentication provides only a snapshot in time. It confirms that a user presented the correct credentials at a specific moment. It does not prove that the individual behind the keyboard remains the same person throughout their activity, nor does it account for changing risk factors once access has been granted.

The rise of continuous trust

The concept of Zero Trust isn’t a new principle, but it reflects a broader recognition that trust must be earned repeatedly, not granted indefinitely.

Continuous trust models assume that every request, transaction, and interaction carries some degree of risk. Instead of relying solely on login events, security controls continuously assess whether behavior remains consistent with an individual's expected identity and context.

For example, an employee logging in from their usual location during working hours may initially present low risk. However, if that same account suddenly begins accessing systems it has never touched before, or exhibiting behavior inconsistent with historical patterns, trust levels should automatically decrease.

The critical question is no longer "Did this user authenticate correctly?" but rather "Does this activity continue to make sense?"

Behavior tells a story that credentials cannot

One of the most promising developments in modern cybersecurity is the growing ability to analyze behavioral signals in real time.

Every user leaves behind a digital fingerprint through their actions. They access particular applications, work within predictable timeframes, interact with specific datasets, and follow recognizable workflows. Even small deviations can provide valuable indicators of potential compromise.

Machine learning and advanced analytics increasingly allow security teams to identify these anomalies at scale. The goal is not simply to detect malicious activity but to recognize when behavior no longer aligns with an established baseline.

This is particularly important because attackers who obtain legitimate credentials often attempt to blend into normal operations. They move carefully, avoid triggering conventional alerts, and exploit the fact that many security systems are designed to detect intrusion rather than impersonation.

Behavioral intelligence offers a much-needed layer of scrutiny that credentials alone cannot provide.

Importantly, this approach also helps reduce reliance on static indicators of compromise, many of which become obsolete quickly.

Why identity security sits at the heart of business resilience

Identity-related attacks are increasingly becoming the biggest threat to business continuity. Modern organizations depend on interconnected digital infrastructures spanning employees, contractors, partners, suppliers, and customers. The compromise of a single trusted identity can create a pathway into multiple systems and services.

Security strategies should focus on limiting unnecessary privileges, continuously validating access rights, reducing identity sprawl, and establishing clear visibility across the entire identity ecosystem.

Just as importantly, organizations must recognize that identity is dynamic. Employees join, leave, change roles, gain new permissions, and interact with new applications constantly. Security controls need to evolve at the same pace.

The organizations most resilient to future threats will be those that understand identity as a living system rather than a static credential database.

The future of cybersecurity starts with questioning trust

The next generation of cyberattacks will be defined by attackers blending in rather than breaking in. That shift demands a fundamental rethinking of cybersecurity from first principles.

In an environment where identities are constantly targeted, trust can no longer be binary. It cannot be granted once and forgotten. Instead, trust must become dynamic, measurable, and continuously verified.

The future belongs to organizations that recognize authentication as the start of a security conversation, not its conclusion.

We've reviewed, rated, and ranked the best antivirus.

This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit

Boeing and US Air Force sign deal to build guided jet-powered bombs capable of traveling 300 nautical miles

  • Boeing lands $75 million contract for its new long-range guided bomb
  • GBU-75 bomb travels over 300 nautical miles using a turbojet engine
  • Boeing spent nearly $100 million of its own money before this deal

Boeing has received a $75 million Undefinitized Contract Action from the US Air Force to begin building its new long-range guided bomb.

The weapon, known as the GBU-75, pairs a 500-pound-class, or 226-kilogram, JDAM warhead with a wing kit and a compact turbojet engine.

This combination allows the bomb to travel more than 300 nautical miles, far beyond what earlier JDAM variants could achieve.

Turbojet kit extends JDAM's reach

Boeing's official designation for the kit is the BSU-111/B Payload Delivery Unit, built around the existing Joint Direct Attack Munition guidance system.

Earlier upgrades to the JDAM family included a tail kit that extended range to roughly 15 nautical miles and a wing kit that reached 40.

The new turbojet engine, designed by Kratos and designated the TDI-J85, pushes that distance well beyond 300 nautical miles now.

Boeing says it has invested nearly $100 million of its own funds into developing the JDAM LR program before this contract arrived.

"This first production contract is a major milestone for the JDAM LR program, allowing us to deliver long-range precision strike at a lower cost," said Bob Ciesla, vice president of Boeing Precision Engagement Systems.

The Air Force Life Cycle Management Center at Hill Air Force Base in Utah manages JDAM purchases for both the Air Force and Navy.

Despite that dual role, the first batch of GBU-75 bombs produced under this contract is intended for the Navy.

Testing record and contracting concerns

The Navy tested the system in April 2026, when F/A-18 Super Hornets released two JDAM LR units over the Point Mugu Sea Range in California.

On April 1, the bomb separated cleanly, ignited its engine, and flew for 34 minutes, landing within meters of its intended site.

That flight covered roughly 200 nautical miles, while a second test on April 3 added altitude changes and additional maneuvering.

"As Naval Air Forces in theater continue to rely heavily on JDAM systems, the program recognizes a critical need to provide the fleet with greater standoff range," said Capt. Sarah Abbott, the Navy's Precision Strike Weapons program manager.

The Pentagon's daily list of contract announcements had not included this award as of August 5, raising questions about disclosure timing.

Because the deal is an undefinitized contract action, Boeing began production work before both sides agreed on a final price.

The Government Accountability Office has repeatedly warned that such contracts carry financial risk, since contractors are reimbursed for allowable costs regardless of final terms.

Boeing's announcement did not disclose how many GBU-75 bombs the contract covers, what they will ultimately cost, or when deliveries will begin.

Boeing has also proposed a mining variant called QuickStrike Long Range, pairing the kit with a ship-tracking sensor for maritime use.

Taken together, the contract suggests steady confidence in the JDAM LR design, though unresolved pricing means taxpayers still do not know the program's full cost.

Google logo on a black background next to text reading 'Click to follow TechRadar'

Ukraine hits Russian Crimea targets with unmanned ship carrying FPV drones

  • Ukraine used a MAGURA drone boat to launch FPV drones against Crimea
  • The operation reportedly struck equipment linked to two Russian radar systems
  • MAGURA carried smaller drones toward Russian military installations along Crimea’s coastline

Group 13, a special military unit of the Ukrainian navy, claims to have struck Russian radar installations in Crimea.

The operation used MAGURA, an unmanned Ukrainian surface vessel carrying FPV drones and developed for reconnaissance, surveillance, mine warfare, and other naval security missions.

According to Ukrainian officials, the system allowed smaller drones to attack Russian military equipment from a sea-based launch platform.

MAGURA carries drones toward Crimean radar installations

During the operation, a MAGURA vessel carried FPV drones that were deployed against Russian radar-related equipment located along the Crimean coast.

Ukrainian officials identified components of the Podlyot radar complex and the Parol-4 radar interrogator among the systems attacked.

The reported mission expands the potential use of naval drones beyond direct attacks against ships and other maritime objectives.

"Now, our MAGURAs threaten the Russian occupiers and on land — this is a radical shift in the fight," said a Group 13 commander.

Group 13 has previously claimed responsibility for destroying more than nine Russian ships during operations conducted around the Black Sea.

The unit has also claimed strikes against three helicopters and two fighter aircraft, although battlefield damage assessments remain difficult to verify independently.

Ukraine has increasingly relied on unmanned systems to conduct operations against Russian military assets while limiting direct exposure of personnel.

The reported deployment gives Ukraine another way to move smaller attack drones toward military installations located beyond the immediate coastline.

Instead of using MAGURA solely against maritime targets, Ukrainian forces used the vessel to transport aircraft intended for attacks on land.

That arrangement separates the launch platform from the FPV drones that conduct the final strike against the intended military equipment.

It also allows the vessel to approach an area without requiring a crewed aircraft or surface ship to carry the drones.

Spets Techno Export says the MAGURA family was designed around a remotely operated architecture suitable for different missions at sea.

According to information from the developer, the V5 variant incorporates a hydrodynamic hull intended to improve maneuverability.

The platform can also be deployed from remote locations, allowing operators to conduct missions without placing personnel directly aboard the vessel.

Ukraine's ambitious push to become a global drone powerhouse

The MAGURA strike is one part of a far larger buildup, as Ukraine works to scale unmanned warfare production nationwide.

The Eastern European country has clearly stated its ambitions to become the world's largest drone and robot producer, with a capacity that could exceed 30 million units annually.

That figure would reportedly surpass the combined output of China, Russia, and the United States, according to Kyiv's own projections.

Ukrainian officials have confirmed plans to build 10 million drones in 2026, rising toward 20 million in the years that follow.

Those figures accompany a newly signed $1.1 billion drone agreement between Ukraine and the European Union.

Ukraine's drone ambition goes beyond developing new models, extending to converting old civilian aircraft into reusable armed drones.

Ukraine has increasingly combined different unmanned systems, using surface vessels and aircraft together during operations against Russian military assets.

Via The DroneFront

Google logo on a black background next to text reading 'Click to follow TechRadar'

Amazon's new Texas AI data center could become the biggest CO2 polluter in the US — 7.65GW facility gets permit to spread 33 million tons of annual greenhouse gases, despite Amazon's clean energy pledge

  • Amazon’s Texas AI project could become America’s largest power plant polluter
  • The facility could release 33 million tons of CO₂ annually
  • Amazon plans to install 35 gas turbines capable of producing 7.65 GW

Amazon has confirmed plans to invest in a natural gas power plant that will supply electricity to a huge new AI data center in Texas.

A New York Times report claims the facility, located in Pecos County, would use 35 natural gas turbines to generate up to 7.65GW of power for the site.

Regulatory permits indicate the plant could release up to 33 million tons of CO₂ into the atmosphere each year.

Largest single source of CO₂ pollution in the US

The scale of those emissions would make the Texas plant the single largest source of CO₂ pollution from any power plant in the United States.

By comparison, the country's current worst offender, the coal-burning James H. Miller Jr. Power Plant in Alabama, emits roughly 16 million tons of CO₂ annually.

Amazon had pledged to eliminate its planet-warming emissions by 2040 under a voluntary agreement known as the Climate Pledge.

The company co-founded that particular coalition in 2019, alongside more than 700 other large global businesses.

Despite that pledge, Amazon's own emissions have continued climbing every year, a trend the company links to the rapid expansion of AI infrastructure.

"The world looks different now than when we co-founded the climate pledge," said Margaret Callahan, an Amazon spokeswoman, in a recent statement.

She insisted that the company remained fully and genuinely committed to reducing emissions across all of its global business operations.

Gas power is fast becoming the industry's default choice

Amazon is far from alone in choosing gas power over ordinary electricity grid connections to fuel its rapidly expanding AI ambitions.

Industry analysts say hyperscale companies are increasingly building dedicated on-site power plants rather than waiting years to connect new data centers to overloaded electricity grids.

“We’re going to see an explosion of off-grid gas projects,” Amazon’s plan “could be a foreshadowing of what’s to come,” said Michael Thomas, founder of Cleanview.

Environmental groups have raised alarms about both the local and global consequences of such large-scale gas burning near residential communities.

"It's going to absolutely have a huge impact on the environment and public health," said Kathryn Guerra, a campaign director at Public Citizen.

Unfortunately, the Trump administration has actively encouraged this shift toward fossil-fuel-powered data centers, favouring oil, natural gas and coal over renewable energy sources.

Other tech firms are pursuing alternative routes, including Microsoft's nuclear deal at Three Mile Island and Meta's push toward securing 1GW of orbital solar capacity but gas seems to remain the preferred route.

Google logo on a black background next to text reading 'Click to follow TechRadar'

Quote of the day by musician Nick Cave on AI-generated lyrics: 'A grotesque mockery of what it is to be human' — dismissing the use of AI in the creative process

Australian singer-songwriter Nick Cave has enjoyed a long and successful career as a frontman, musician, and vocalist. His influence is far-reaching, and he's attracted many fans through the decades, although one online encounter prompted a massive response to the rise of AI-generated impersonations of his style and work.

Art through suffering

Months after OpenAI launched ChatGPT for the first time, Nick Cave wrote a lengthy critique on his blog about the use of this tool by fans in replicating some of his work.

Quote of the day

This article is part of TechRadar Pro's QOTD project to provide an insight into the minds of the brightest and most recognized figures in the technology industry today and in years gone by. Read the full series here.

In his blog, Cave opined about the origins of music and the conditions needed to generate genuinely human-centric music – and suffering, namely the "internal human struggle of creation" – is the key ingredient.

As far as he's concerned, he added, algorithms don't feel. He admitted that ChatGPT was, at the time, in its infancy and will always have further to go. But he was steadfast in his views that any AI-generated lyrics, or even full songs, would never capture an audience's attention in the same way that innate human artistry could.

Cloud sounds

Despite Cave's views, that hasn't abated the world from experimenting with AI-generated music – and there's been an explosion in both 'slop' as well as catchy machine-made music.

There's been a huge rise in the number of tools that can generate music, including tools like Canva's built-in generator, Gemini's Lyria 3, and specialist tools like Suno AI.

It's no surprise that Deezer suggested in November last year that a third of songs uploaded to its platform were AI-generated. The situation has escalated recently, however, with its in-house AI detection tool now finding that figure rising to more than 50% of daily uploads, amounting to 90,000 songs.

Drone firm PDW lands $820 million Pentagon funding to build the next generation of UAS components as crackdown on foreign providers continues

  • Pentagon backs $820 million expansion of domestic drone component manufacturing capacity
  • PDW plans to expand its Huntsville facility for military drone production
  • Funding will increase production of propulsion, power, and vision systems

The Pentagon has conditionally committed up to $820 million to Performance Drone Works (PDW) for expanding domestic UAS component manufacturing capacity.

The financing is meant to expand domestic manufacturing of critical unmanned aerial system components across several distinct product and technology categories.

PDW will have to expand manufacturing at its 90,000-square-foot facility in Huntsville, Alabama, while additional production will involve local industry partners.

Components for smaller military drones

The production will cover Group 1 and Group 2 UAS platforms, representing relatively lightweight systems used for lower-altitude military operations.

Under US military classifications, Group 1 drones weigh less than 20 pounds and operate at service ceilings of up to 1,200 feet.

Group 2 systems weigh no more than 55 pounds and operate below 3,500 feet under the Pentagon's established classification framework.

The funding, therefore, concerns components that support smaller aircraft rather than larger unmanned systems used for longer-range military missions.

Combined with private capital, the commitment is expected to increase production of propulsion systems, power controls, and vision technologies for military applications.

Before financing becomes final, PDW must satisfy financial, legal, and technical requirements under the federal lending process, set by the Department of Defense.

Pentagon tightens controls on foreign drone components

The Pentagon is seeking to reduce dependence on overseas sources as concerns grow over foreign components entering critical military drone supply chains.

The effort follows an executive order issued last year supporting expanded US manufacturing for next-generation tactical autonomous systems.

“Achieving Secretary Hegseth’s mandate for drone dominance requires a secure and resilient industrial base here at home,” said Emil Michael, US Under Secretary of Defense for Research and Engineering.

The Office of Strategic Capital's commitment therefore supports broader efforts to increase domestic capacity for components considered important to national defense.

“America’s ability to respond tomorrow depends on the industrial capacity we build today,” said James Slider, CEO of PDW.

“This conditional commitment … would support the critical need of strengthening domestic manufacturing and restoring America’s ability to build the capabilities our nation depends on.”

That urgency around domestic sourcing is not just theoretical: a recent incident in the U.K. showed what can go wrong when foreign components slip into military hardware unnoticed.

The U.K. Navy recently discovered its K3 Scout surveillance drones sent “heartbeat communications” to China.

Though the U.K. swiftly disconnected the drones from the internet after discovering the communications, the incident raised concerns about foreign-made equipment operating in sensitive military environments.

“If we cannot say with confidence what is inside our own military equipment, we cannot say it is ours, or that we are sovereign,” said Alicia Kearns, the UK Shadow Minister for National Security and Safeguarding

“When cameras built on Chinese parts are found recording our special forces – their faces, training and operations – we should not be surprised, we should be furious that we still haven’t woken up to the realities of the threat we face.”

Via The DroneFront

Google logo on a black background next to text reading 'Click to follow TechRadar'

Nashville will use 'eminent domain' to block a $700 million data center threatening iconic zoo

  • Nashville's Metro Council voted 27 to 5 to authorize acquiring the 23.49-acre site next to the Nashville Zoo by negotiation or condemnation
  • This comes after a local fight escalated into a national campaign with a 500,000-signature petition
  • The vote grants an option rather than a commitment: no negotiations have begun, an amendment requires an appraisal and a three-week wait, and it must still prove public need to a court

Nashville's Metro Council has voted 27 to 5 , to authorize the city to take the land where DC BLOX plans to build a data center next door to the Nashville Zoo at Grassmere.

It is, to date, the most aggressive move yet by an American city against a data center project, and it arrives after a local zoning fight escalated into a national one, replete with a petition carrying more than half a million signatures and objections from celebrities including Brad Paisley, Sheryl Crow and Jack White.

It is however, strictly speaking for now, not a decision to use eminent domain at all yet.

A national story as eminent domain runs the other way

In a session that ran past midnight, the passed bill (BL2026-1489) authorizes Metro to acquire the 23.49-acre property at 648 Grassmere Park through "negotiation or condemnation." Those are two different things, and the legislation permits either.

The mayor's office has explicitly said that the vote does not commit Metro to buying the land, only that it gives the city the option, and that negotiations on a purchase price have not begun.

The bill also has other limitations in play: an amendment from Councilmember Quin Evans Segall added two more brakes: an appraisal must be presented to the council, and Metro must wait a minimum of three weeks from the vote before proceeding. Even after that, condemnation requires Metro to demonstrate to a court that it genuinely needs the property for public use. The stated uses are offices, warehouse space, and employee training.

The reason this is a national story is that eminent domain generally runs the other way; the standard version of this story is a utility or a developer using the state's condemnation power to clear land for infrastructure, over the objections of whoever happens to live on it.

Georgia Power did exactly that recently, acquiring 30 residential properties to connect a substation to a power plant, in a state where data center growth is driving load.

Rick Schwartz, the zoo's president and CEO, has made a point that tends to get flattened in coverage. DC BLOX has pledged to limit sound, and Schwartz's response is that decibel levels are not the issue. The concern is tonal noise transmitted as vibration, occurring continuously with no overnight relief, which could disturb animals near the proposed buildout site.

The clouded leopard exhibit sits closest to the proposed site, which matters because the zoo's breeding program for the species relies on a hand-rearing regimen built over three decades, designed to gradually acclimate cubs to human noise and prevent stress.

Zoo officials also point to stormwater: the zoo's waterway infrastructure is already classified as impaired for siltation and habitat alteration, and runoff from a hardened industrial site upstream would not help. Schwartz has said the zoo is unwilling to pursue a compromise, citing a lack of transparency from the developer.

DC BLOX closed on the property on July 17 2026 for $23 million. Davidson County assessed it at around $37 million last year. Under Tennessee law, Metro could owe fair market value, which puts the floor above what the developer paid three weeks before the council voted.

There are other regulations in play that could, however, completely neuter the situation. In late July, the council passed Nashville's first data center regulations, along with a moratorium on new permit approvals that runs through December 1, preventing construction from starting. Separately, two challenges to the zoning administrator's land-use designation for the property are pending with the Board of Zoning Appeals, filed by the zoo among others, and could put a proverbial spanner in the works.

Nashville is not an outlier in wanting this fight, only in the tool it has attempted to use to prevent a buildout. There are more than 70 active data center moratoriums nationwide, over 200 communities weighing restrictions, and at least 14 states considering similar measures.

What makes this case worth watching is not the vote itself, but whether a city can actually afford to follow through, both legislatively and potentially down the line, financially.

The incredibly lightweight Asus Zenbook A14 drops $300 — and a 28-hour battery life is just the beginning for this business laptop

For an ultra-light laptop for the commute, the Asus Zenbook A14 is worth a look - and not just because it boasts a genuine all-day battery life that outstrips almost all its rivals (we clocked it at over 28 hours in tests).

Right now, the Asus Zenbook A14 is down to $700 (was $1000) at Best Buy. That's a big $300 price cut on one of the lightest Copilot+ laptops around, with an OLED screen and specs suitable for day-to-day tasks.

Should you buy it?

Buy the ASUS Zenbook A14 if...

You want an ultralight laptop with strong battery life, you mainly do browsing, office work, and streaming, or a vibrant OLED display matters more to you than raw power.

Skip the ASUS Zenbook A14 if...

You need a dedicated GPU for gaming or GPU-heavy creative work, you rely on x86-only software (this runs Windows on Arm), or you want RAM you can upgrade later — it's soldered.

Snapdragon X Plus | 16GB LPDDR5X | 512GB SSD

14in 2K OLED display, Qualcomm Hexagon NPU, up to 32 hours battery life, Copilot+ PC. We rated this laptop 4 stars after testing, and if you want a good back-to-school or work laptop with a long battery life, this ticks all the boxes. View Deal

Why we recommend it

One of the highlights when we reviewed the Zenbook A14 was just how thin and light it was - so for traveling across campus or commuting to work, it's absolutely ideal. We awarded it 4 stars in our review, and praised the thin design, the premium feel of the keyboard, and a capable all-round performance.

The OLED screen is ok - it's a nice bump compared to your standard displays, and we said "colors are rendered well enough to enjoy all kinds of content." However, it's not as bright as some laptops we've used.

Perhaps the best aspect of the Zenbook A14 is the all-day battery life. Thanks to the Snapdragon processor, it's rated for 32 hours. And in our own tests, it lasted over 28 hours before needing to be recharged.

Price Context & Historical Value

At $699.99, this is $300 off the $999.99 list price — a genuine 30% cut rather than retailer anchoring, since Best Buy has consistently listed this configuration around the $999 mark. That puts the price well below where most 2K OLED Copilot+ laptops currently sell. Even on Amazon, the same configuration is selling for $800.

The Catch: What to know before you buy

This configuration uses the entry-level Snapdragon X Plus 8-core chip, and independent reviews of that chip found it a passable performer for everyday tasks but not for heavier workloads. The Snapdragon X Elite configuration performs noticeably better here. RAM is soldered at 16GB with no upgrade path, and the integrated Adreno graphics aren't built for gaming.

Scammers are using fake Odyssey pirate downloads to spread malware that's more dangerous than the Cyclops and Circe combined

  • Bitdefender says fake pirated downloads of The Odyssey, disguised as scene releases with .exe files carrying VLC icons, are spreading Lumma Stealer malware
  • Stolen session cookies are the real danger, because they let an attacker resume an authenticated session without ever triggering a multi-factor prompt
  • These builds seemingly ship without droppers or persistence, which is less sophisticated than earlier movie-themed samples but no less harmful, since credential theft does not require staying resident

With The Odyssey set to became one of the year's biggest theatrical launches, people looking for a free copy online started finding one with a few extra caveats in tow.

What they were actually downloading, according to Bitdefender, was Lumma Stealer, a prominent infostealer that operates as a Malware-as-a-Service (MaaS).

The company's researchers say its security products blocked users from downloading and running malicious files disguised as the film, circulating under names designed to look like scene releases: "the odyssey 2026 1080p webrip-lama.exe" is one of three examples published, alongside variants dressed as 2160p HD and H. 264 rips.

A regular occurrence for pirates

The threat is a well-worn playbook rather than a new one, as Bitdefender documented a near-identical campaign in 2025 built around Mission: Impossible – The Final Reckoning, distributing the same malware family through torrent sites using files dressed as movie releases. The blockbuster changes; the delivery does not.

The most useful detail in the report is also the least dramatic, and it explains why a file extension that should be a screaming red flag frequently is not: Windows does not show file extensions by default.

Unless a user has enabled that option in Explorer settings, the ".exe" at the end of a filename is simply invisible. Attackers pair that with a custom icon, commonly one lifted from VLC Media Player or a generic video file, so what appears on screen is a VLC icon and a filename that reads like a movie rip. There is nothing visible to distinguish it from the thing the user was actually looking for.

Bitdefender's point about social engineering follows from that, and it is a sharp one: almost none is required here. Someone hunting for a leaked copy of a film still in theaters has already accepted that they will be dealing with odd filenames, unofficial sources, and compressed archives. An executable claiming to be a video player or installer is not an uncommon sight in the world of piracy, where such practices are rife.

Lumma, also tracked as LummaC2, is a Russian-developed information stealer sold as a service, with affiliates paying somewhere between $250 and $1,000 a month for access. Upon execution, it harvests browser passwords, authentication cookies, saved payment information, cryptocurrency wallet data, autofill data, and remote desktop credentials.

It has often been highlighted as one of the most prolific MaaS options out there and has had Microsoft, the DOJ, and the FBI act directly against it in the past, but has managed to stay alive since, evolving into a more stealthy entity.

Bitdefender notes that the samples in this campaign arrive without droppers and without persistence mechanisms.

Previous movie-themed Lumma builds carried more machinery, including delayed execution when security software was detected and encrypted payload delivery through AutoIt scripts. The approach here differs considerably: the attackers appear content with whatever they can collect at execution time and do not attempt to hold the machine afterward.

Prevention in this case simply involves avoiding the download of pirated films from channels that, as a rule of thumb, do not implement many, if any, security measures to keep infostealers out.

For those seeking a broader solution, enabling file extensions in Windows Explorer is the way to go. It takes seconds, it is off by default, and it removes the specific blind spot this particular campaign depends on.

Expand your home server for less — WD Red Plus 2TB NAS drive falls to $155 at Newegg

The WD Red Plus HDDs have always performed well in our tests - they're not fancy, not especially expensive, and do what most NAS system users will need.

If you're populating a NAS enclosure, this is a straightforward pick, with the WD Red Plus 2TB hard drive currently $155 (was $168) at Newegg.

Built for round-the-clock use, I rarely see these HDDs get any discount at all, so while not massive, a saving is a saving in my book.

Should you buy it?

Buy the WD Red Plus 2TB if...

You're building or expanding a NAS array, you want CMR recording for RAID reliability, or you need a drive rated for continuous operation.

Skip the WD Red Plus 2TB if...

You need higher capacity per dollar (larger Red Plus drives scale better), you're using this in a standard desktop rather than a NAS, or you want faster 7200 RPM performance — look at Red Pro instead.

5400 RPM, 64MB cache, CMR, SATA 6Gb/s, 3-year limited warranty.View Deal

Why we recommend it

We've previously reviewed the 4TB WD Red Plus HDD and awarded it 4 stars in our review. Expect similar performance for this 2TB model, as beyond the capacity, it's pretty much the same.

Red Plus drives run Western Digital's NASware firmware, tuned specifically for multi-bay NAS workloads, along with rotation vibration sensors and dual-plane balance control that help performance and reliability stay steady when several drives are spinning in the same enclosure.

Unlike SMR drives, which can cause slowdowns and rebuild issues in RAID arrays, this is CMR — the safer choice for NAS duty.

Price Context & Historical Value

Generally speaking, NAS drives hold their price. So, at $12.50 off list, this isn't a deep discount — WD Red Plus drives tend to hold their price fairly steady rather than swing wildly in flash sales.

Overall, $154.99 is a solid, dependable price for a drive built specifically for NAS use rather than a one-off promotional gimmick.

If you need greater storage capacity, I'm seeing the 4TB version for $195 at Newegg which also has a combo deal offer bundling two drives and a Ugreen NAS for $570. , and an 8TB version for $355.

The Catch: What to know before you buy

2TB is on the smaller side if you're planning a larger NAS array, and 5400 RPM means it won't match the speed of WD's 7200 RPM Red Pro line. If raw performance matters more than cost per drive, that's worth weighing before you buy.

HyperX Omen 16 gets a huge $600 discount — and with an RTX 5060 and a 165Hz 2K display, it's a win for students and creators

HP's Omen range of laptops with dedicated graphic cards have always proved well-made mid-range machines for creators and gamers. And right now, the HyperX Omen 16 has dropped to $1400 (was $2000) from HP.

This laptop pairs a high-performance Ryzen 7 chip with RTX 5060 graphics and a color-accurate 165Hz 2K display. This is the base configuration, but HP does let you customize the hard, bumping up processor, memory, storage, and screen resolution.

Should you buy it?

Buy the HP Omen 16 if...

You want a laptop that can also handle content creation and color-sensitive online work. Also worth grabbing if you're comfortable with 16GB RAM as a starting point (it's upgradeable to 32GB).

Skip the HP Omen 16 if...

You want to push settings higher than the RTX 5060 comfortably handles or you need more RAM out of the box for heavier multitasking. It's not thin and light, either, as it's a dedicated creator and gaming laptop, not an ultraportable.

AMD Ryzen 7 8745HX | 16GB DDR5 | 512GB SSD

This 16-inch Windows 11 laptop boasts a dedicated RTX 5060 graphics card, and paired with a 165Hz 2K display, it's a rock-solid mid-range creator and gaming machine.View Deal

Why we recommend it

The Ryzen 7 8745HX is a strong 8-core mobile chip, and paired with the RTX 5060 it's a genuinely capable combination for creative workloads like photo editing and video editing. It might not handle a feature-length film or print-ready artwork, but it's more than enough for portfolios, YouTube channels, and other online work.

What stands out to me here is the display: a 16-inch, 2K panel running at 165Hz, with 100% sRGB coverage and 400 nits brightness — a solid screen compared to lower-brightness FHD IPS panels that usually show up on RTX 5060 laptops at this price. You can upgrade that display up to 2.5K OLED with 100% DCI-P3 if you need total color accuracy.

Add in Wi-Fi 6 and HP's Omen Tempest cooling system, and this is a well-rounded gaming laptop suitable for color-sensitive creative work.

Price Context & Historical Value

There are a host of HP Omen laptop configurations out there, and I generally find it's a case of trading off one key spec for another.

For example, there's a $1400 listing on Amazon that boasts an AMD Ryzen 9 chip, but the screen only hits 144Hz. If that's unimportant, and you'd rather have a laptop well-suited to multi-tasking, go for the Amazon model. Similarly, the Ryzen 9 model with the same 144Hz display but 32GB RAM and 1TB storage is retailing for $1800 at Amazon.

Over at HP, there's an Intel version of the Omen 16 for $1500 - but I recommend skipping it if you're a creator, as it only covers 62.5% sRGB.

What I'm saying is, for the price, it's about what I'd expect to pay. It just depends on where your priorities lie as to which model is right for you.

The Catch: What to know before you buy

16GB of RAM is on the lean side for a laptop at this price — it's upgradeable to 32GB across two slots, but that's an added cost if you go that route. The RTX 5060 is also a mid-tier GPU; it's well-matched to the 2K resolution, but don't expect to max out settings.

At 5.47 lbs, this isn't a laptop you'll want to carry around casually — it's built to stay mostly on a desk. None of that undercuts the core value here: a genuinely good OLED display paired with solid performance, at a price that undercuts most laptops with a comparable screen.

UK Navy forced to strip out internet connectivity from drones after finding it sent 'heartbeat communications' to China

  • Navy drones secretly sent signals to China for several months
  • Kraken admits it lost confidence in its own drone platform
  • Chinese-made camera parts were fitted without proper origin checks

The Royal Navy has stripped internet connectivity from a fleet of K3 Scout surveillance drones after cameras were found sending signals to China.

A routine cyber vulnerability assessment uncovered so-called heartbeat communications passing between the drones' cameras and an IP address located in China.

The vessels, used by the Coastal Forces Squadron and 47 Commando, form part of a £12 million fleet purchased since March 2026.

Cameras kept transmitting despite assurances

Kraken Technology Group, the British defence contractor that supplied the K3 Scout drones, sourced the cameras from a third-party manufacturer based overseas.

The company had reportedly given assurances about the security of those components before they were ever fitted onto the vessels.

“We are aware that some third-party, NDAA-compliant cameras had a small number of components originating from outside the UK,” said a Kraken Technology Group spokesman.

“After a full audit by both Kraken and the Royal Navy we are confident no sensitive information has ever been shared outside of intended channels and any potential vulnerabilities have been identified and closed.”

Despite that reassurance, Kraken later admitted that checks on the origin of the components had failed and confidence in the platform had been lost entirely.

The Ministry of Defence maintained that its own networks and systems had not been affected by the discovery in any way.

"A thorough investigation found no evidence of MoD data or systems being compromised," said a spokesman for the Ministry of Defence.

The K3 Scout, designed to carry a 600kg payload and operate continuously for 30 days, has also been bought by the US Special Operations Command.

It has also taken part in a series of Nato trials in the Baltic Sea alongside allied navies from the region.

The drones also formed part of a future defence package offered to help secure movement through the Strait of Hormuz.

Concerns grow over supply chain security

The breach has renewed scrutiny of the Government's drone procurement strategy, which is backed by a £5 billion investment pledge.

The government has promised to make defence purchasing "unashamedly pro-Britain," yet the case shows how deeply Chinese-made components remain embedded in British-labelled military hardware.

British officials argue that sovereignty itself is called into question when the origin of components inside military equipment cannot be fully guaranteed.

“If we cannot say with confidence what is inside our own military equipment, we cannot say it is ours, or that we are sovereign,” said Alicia Kearns, the shadow security minister.

“When cameras built on Chinese parts are found recording our special forces – their faces, training and operations – we should not be surprised, we should be furious that we still haven’t woken up to the realities of the threat we face.”

The episode follows years of warnings about Chinese components inside sensitive British infrastructure, including the eventual removal of Huawei equipment from the 5G network.

However, the Labour Government is trying to rebuild economic and diplomatic ties with Beijing and some ministers even visited Shanghai earlier this year.

Via The Telegraph

Google logo on a black background next to text reading 'Click to follow TechRadar'

Build your own 120TB private cloud without subscription fees with this great TerraMaster F4-425 NAS deal

Building your own centralized storage doesn't have to mean spending a fortune on the NAS itself. We've tested a range of TerraMaster NAS devices that impressed us, and now the 4-bay TerraMaster F4-425 is down to $366 (was $430) at Amazon, saving you a solid $64.51 on a highly capable home storage system.

The diskless F4-425 uses an Intel x86 quad-core processor with 4GB of RAM, providing enough power for multitasking and hardware-assisted 4K H.265 decoding. Its four bays support up to 30TB drives for a maximum raw capacity of 120TB, while 2.5GbE networking provides far more bandwidth than standard Gigabit Ethernet when paired with compatible network hardware. In the UK, TerraMaster's NAS system is now £320 (was £400) at Amazon.

Should you buy it?

Buy the TerraMaster F4-425 if...

You want a central home storage system that can do considerably more than just hold files. Its four bays provide plenty of room for expanding capacity, while 2.5GbE networking, 4K hardware decoding, and support for popular media platforms make it particularly well suited to backups, large media libraries, and even home streaming.

Skip the TerraMaster F4-425 if...

You only need somewhere to store a relatively small collection of files, or you're expecting storage to be included. This is a diskless NAS, so you'll need to buy compatible hard drives separately, potentially adding hundreds of dollars to the overall cost.

This four-bay NAS combines an Intel x86 quad-core processor, 4GB RAM, 2.5GbE networking, hardware 4K H.265 decoding, up to 120TB raw capacity, tool-free drive installation, and mobile management.

In the UK: now £320 (was £400)View Deal

Why we recommend it

The F4-425 offers a useful combination of capacity, networking, and media features for home use. TerraMaster says it operates at just 21dB(A), and its Push-Lock trays allow drives to be installed without tools.

TRAID and TRAID+ provide flexible storage configurations, and support for Google Drive, OneDrive, and Dropbox gives you additional options for keeping local and cloud data synchronized.

Price context & historical value

Amazon's $365.48 price takes $64.51 off the listed $429.99 price, equivalent to a saving of about 15%. It's not the cheapest the NAS has ever been on Amazon, it did sell for as low as $290 in the past, but this is the best price it's been at for a while.

That's a useful reduction when the NAS itself is only part of the expense, since you'll still need to budget for drives. The four-bay design also means you can start with fewer drives and expand your storage later rather than filling every bay immediately.

The Catch: What to know before you buy

No drives are included, and the headline 120TB figure requires four 30TB drives before accounting for any capacity used for redundancy.

You'll also need compatible 2.5GbE networking equipment to take full advantage of the faster Ethernet connection; on a standard Gigabit network, transfer speeds will remain constrained by the slower connection.

Anker's 'powerful and versatile' Solix C1000 portable power station massively improved our workflow — and with $170 off, it's the perfect summer companion for home, work, and off-grid adventures

Anker's portable power station proved such a powerful and versatile device that we couldn't imagine workflows now without it. And that was before the Anker Solix C1000 dropped to $430 (was $600) at Amazon, a sizeable discount on a 1056Wh portable battery designed for home backup, camping, RV trips, and other off-grid adventures.

It provides 1800W of standard output, while Anker's SurgePad technology can handle up to 2400W for compatible appliances. The LiFePO4 battery is rated for 3,000 cycles and a lifespan of around 10 years, and UltraFast charging can take it from empty to 80% in 43 minutes and fully recharge it in 58 minutes from AC power.

Should you buy it?

Buy the Anker Solix C1000 if...

You want a substantial reserve of portable electricity for blackouts, camping, RV trips, or working away from an outlet. Its 1800W output means it can handle considerably more than phones and laptops, while the 1056Wh capacity gives you enough stored energy to keep essential devices running when mains power disappears.

Skip the Anker Solix C1000 if...

You only need occasional charging for phones and other small electronics, as a much smaller and cheaper power station could cover those needs. At 27.6 pounds, this is portable in the sense that you can carry it where it's needed, but it's not something you'll want to haul around unnecessarily.

This 1056Wh LiFePO4 power station delivers 1800W output, up to 2400W through SurgePad, 11 ports, 58-minute AC charging, 600W solar input, 3,000-cycle battery longevity, and app-based monitoring and controls.View Deal

Why we recommend it

Fast recharging is one of the C1000's biggest advantages. Being able to completely recharge a 1056Wh battery in under an hour means you can quickly prepare for an approaching storm or recharge between outages. Its LiFePO4 chemistry and 3,000-cycle rating are also important for something intended to provide backup power over many years.

In his 4.5-star review, our expert Collin said it offered "solid versatility for home, work, and adventure use."

It's the power station and UPS he entrusts to run his primary workstation in his home office and he explains: "I can't imagine not having in my workflow at this point. It's powerful, has a great port offering, is super easy to use in Wi-Fi and Bluetooth-only environments, is expandable, and so much more."

Price context & historical value

Amazon's $429.98 price is $170.01 below the listed $599.99 price, a reduction of around 28%. That's a substantial saving on a 1kWh-class power station, particularly if you've been considering one for emergency preparedness or outdoor use rather than simply as an oversized battery for electronics. It has been slightly under $400 in the past, but this is still a great deal and one I happily recommend.

The Catch: What to know before you buy

Don't mistake the “solar generator” description for meaning solar panels are included. They're optional, so you'll need to buy compatible panels separately if you want off-grid solar charging.

The advertised 2400W figure also comes through Anker's SurgePad technology; the unit's standard rated output is 1800W.

Five questions to test whether an AI stack is truly under your control

Control is one of the easiest words in enterprise AI to misuse.

A business may download a model, run it in its own cloud and negotiate favorable terms, and yet still remain dependent at the points that matter.

Access can create useful freedom. It does not, by itself, prove operating control.

I have learned to treat sovereignty as an operating discipline, not a nationality badge.

If an organization cannot prove what it is running, who can change it, what it depends on and how it can be retired, its control is largely assumed.

These five questions turn an ambiguous claim into a practical test for procurement, security and leadership teams.

1. Can you prove exactly what you are running?

A model name and version number on an architecture diagram are not provenance. Teams need a traceable origin, an artefact identifier, a cryptographic hash or signature, the approved configuration and a record of every material change. That record should include fine-tunes, safety layers, prompt templates, retrieval sources and any post-deployment adjustments that affect behavior.

The harder question is operational: who approved the change, who can make the next one and how quickly can the previous state be restored? If a supplier can alter behavior without the customer seeing the change, or rollback depends on goodwill, control is borrowed. The evidence should be simple enough to inspect during an incident, not buried in a quarterly assurance exercise.

2. Can you verify the weights and every critical dependency?

Model weights matter, but they are only one layer of an AI system. The inference engine, libraries, drivers, orchestration tools, safety filters, retrieval components, monitoring services and update channels all shape how it operates. Open weights may remove one dependency while introducing several others.

Every critical component therefore needs an owner, a known version, a license, an update route, a vulnerability response and a credible substitute. Integrity checks should run when the system is built, when it is deployed and after a suspected incident. A bill of materials is useful only when it connects inventory to verification and action. A long list of components with no decision rights is documentation, not control.

3. Who controls the infrastructure and operating conditions?

Location is not the same as control. A model can sit in a domestic data center whilst essential decisions remain elsewhere. Teams should map who operates the compute, network, identity system, encryption keys, logs and administrative tools. They should know which party can pause, patch, throttle, inspect or revoke the service, and under what conditions.

Owning the building is not enough if a supplier retains remote administration, a proprietary control plane or the only route to scarce accelerators. Backups and telemetry matter too: where they go, who can read them and how long they persist. The strongest test is a degraded-mode exercise. When capacity disappears, credentials are compromised or a provider becomes unavailable, can the organization continue safely and make its own decisions?

4. Which law, license and contract governs the stack?

Technical architecture and legal architecture form the same control map. The relevant questions cover the law, license and contract governing the weights, hosted services, support, telemetry and any fine-tuned assets. They also cover subcontractors, audit rights, incident notification, unilateral changes, export constraints, and the rights available at exit.

Data residency does not settle jurisdiction, and a familiar supplier name does not settle enforceability. Legal, procurement, and security teams should be able to answer from the same evidence set. Contradictions between the contract and the system design are not paperwork problems; they are design defects. The useful test is not whether a supplier appears trustworthy today, but which rights survive a dispute, acquisition, service withdrawal or regulatory change.

5. Can you switch, stop and dispose safely?

No AI strategy is controlled until its exit has been tested. Could the organization move to another model, runtime, or provider without rebuilding the entire service? Can it export configurations, evaluation sets, prompts, logs, and fine-tuning artefacts in usable formats? Can it revoke identities and tokens, remove deployed copies, clear checkpoints and caches, and still retain the evidence required for audit or investigation?

Safe stopping deserves the same attention as fast starting. The exit plan should name triggers, owners, sequence, time limits, and recovery targets, then be rehearsed before dependence becomes difficult to unwind. If switching exists only in a contract slide, it is not a credible option. Disposal is the final proof that control includes ending a dependency without creating a new operational or security risk.

Control must be evidenced, not declared

The answer to these questions will rarely be a clean yes or no. Control has degrees, and different workloads justify different dependencies. What matters is that each answer is evidenced, assigned to an owner and tested again as the stack changes.

Open access, local infrastructure and strong contracts can all reduce risk. None substitutes for the ability to prove what is running, verify its dependencies, identify who can intervene, understand which rules bind it and leave safely.

That is less glamorous than a sovereignty label, but it is the difference between an AI architecture an organization can use and a stack it can genuinely govern.

Use the best business cloud storage to manage your data.

This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit

The 6 myths of agile project delivery (and how to solve them)

When you ask businesses about how they are innovating their ways of working, one word will come up time and again: Agile. Agile delivery. Agile workflows. Agile everything.

The term has been so overwhelmed by buzzwords, supposed best practice guides, and misguided strategy documents that it has almost lost all meaning.

In fact, if many organizations that believe they’re operating in an Agile manner were to take a step back and take an objective look at their ways of working, they would quickly come to realize they have not moved away from legacy command-and-control structures.

In this fog of misunderstanding, a series of myths has taken hold that have made the role of Agile professionals far less clear-cut, making it harder for organizations to put this invaluable methodology into practice.

One root of these problems lies in a tendency for people to narrow Agile’s scope, approaching it as a tick list of processes to adhere to rather than a fundamental shift in how people work and deliver for a business.

It is critical that Agile professionals equip themselves to fact-check these myths as they come up in their work. Every failed project done in Agile’s name diminishes the luster attached to the methodology, increasing the risk that future businesses will reject this powerful way to improve program and project management.

Myth 1 – “Agile delivery leaders are just administrators”

Agile professionals are often seen principally as bureaucratic note-takers, or schedulers – the people who organize everyone else’s work.

This view misses the point: their real value is as facilitators and protectors from distraction. Good Agile professionals create the space for teams to focus, and align delivery with outcomes rather than just activity.

Myth 2 – “Agile professionals are the scrum police”

Some believe Agile delivery operates within a top-down hierarchy, with Agile professionals in place to enforce frameworks and control how team members spend their time.

This is quite wrong: Agile professionals work with teams, coaching them to make better decisions, remove friction, and build confidence in delivery – without resorting to outdated command-and-control methods.

Myth 3 – “Agile delivery must be technical”

It’s a common assumption that Agile delivery leaders require a deep technical background. Technical awareness can certainly help, supporting a deeper understanding of the team’s tasks and challenges, but it isn’t the core of the job.

The real skill lies in understanding people and processes, then creating the conditions for specialists to succeed. In most projects, the need is for strong communication and facilitation across the entire team rather than strategic decision-making or technical troubleshooting.

Indeed, in some circumstances ‘hands-on’ Agile delivery leaders who think they know best can create conflict within teams, damaging morale and motivation in the process. Think of it like athletics: coaches don’t need to run faster than the athletes; their task is to help the athletes run faster.

Myth 4 – “Certification equals capability”

A certificate may prove that somebody knows about an Agile framework, but it does not demonstrate that they’re capable of applying it in practice.

The best Agile professionals succeed through experience, attitude, and ‘soft’ skills. They know from experience how to adapt Agile values and principles to particular circumstances; when to challenge people, and when to simply step back and get out of their team’s way.

Like any profession, being truly effective at the job requires skill, practical experience, and professional characteristics appropriate for the role. A piece of paper doesn’t make you agile; effectiveness with people and process does.

Myth 5 – “Agile delivery leaders are cheerleaders”

Contrary to popular belief, Agile delivery isn’t principally about arranging team socials or keeping everyone upbeat during stand-ups.

The value lies in keeping people aligned and productive under deadline pressure and/or changing priorities; after all, no plan survives contact with the enemy. Agile delivery leaders are there to create stability within an uncertain environment: they help teams stay focused on what matters, and shield them from distractions so they can maximize time spent ‘in the zone’.

That said, there is value in boosting morale – and championing a team’s achievements is one way to do this. According to the “broaden-and-build” theory of psychologist Barbara Fredrickson, positive emotions broaden our thought-action repertoires, enabling us to develop skills and resources that improve our long-term productivity.

One famous study from the "Journal of Labor Economics" showed that happiness at work leads to improved performance, especially in jobs where creativity and initiative are key.

Myth 6 – “Agile delivery leaders must remove all blockers for their teams”

While impediment removal is without doubt a core responsibility for an Agile delivery leader, the reality is that teams solve most of their own issues – perhaps with the assistance of a little coaching or support.

Nonetheless, sometimes a challenge is too big, distracting or political for them to handle, and Agile delivery leaders must step in – often by representing the team with stakeholders and at governance layers: this can be helpful in reducing the ‘noise’ around the team and the number of distracting interactions that take team members away from the core task.

As captured in the proverb: “Give a man a fish, and you feed him for a day; teach a man to fish, and you feed him for a lifetime,” effective Agile delivery leadership is about enabling, not babysitting.

True Agile

So Agile is a much more subtle and responsive discipline than the stereotypes present – and it must be led by subtle and responsive practitioners. The approach can generate huge benefits – saving time, handling change more elegantly, reducing project failure rates and, above all, creating better products and services that more effectively meet customer needs and objectives.

These goals are achieved by working with people – rather than by tinkering with processes – to surface problems early in the development process, resolve them quickly and with a minimum of fuss, and avoid interfering when the team is already functioning effectively.

High-performing teams depend on trust, accountability and continuous learning. Leaders who foster those qualities are more likely to deliver successful outcomes, creating teams that stay focused, take ownership of their work, and continuously improve how they operate.

This is a role that is all about empowerment; when they’re doing their job well, much of an Agile practitioner’s work occurs out of sight. So how do you know when you’ve got a really great Agile delivery leader? When their team runs perfectly well without them.

This may not sound like the smartest business model for the practitioner, but it’s definitely the best outcome for the client’s own business – and that, ultimately, is what Agile is all about.

We've rated and ranked the best productivity tools.

This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit

OpenAI extends 'Daybreak' security project and reveals new cyber model — but for approved users only

  • OpenAI expands Daybreak with Blue and Red tiers for defensive cyber work
  • New GPT‑5.6‑Cyber model offers high compliance for authorized vulnerability research
  • Access remains restricted due to dual‑use risks and reduced safeguard operation

OpenAI has announced two new tiers for its Daybreak dedicated cybersecurity project, each offering a different model with different levels of compliance. It also used the opportunity to introduce a new security-focused AI model, as well.

Hackers and criminals are increasingly abusing AI to improve and speed up the creation of phishing emails and malicious code, and with the introduction of AI agents, they’ve also used it to automate entire attack processes. The AI community responded by placing strong guardrails, making sure their models do not comply with requests to build malware, or hack other companies.

These guardrails ended up being a two-edged sword, because as they slowed down attackers, they also slowed down the defenders.

What is Daybreak?

To give the cybersecurity community the upper edge, companies like OpenAI started creating dedicated cybersecurity initiatives that provide a vetted list of companies state-of-the-art models, free of guardrails. The company also provided them with pre-trained AI agents, as well as access to a pool of shared knowledge.

Initially launched in June 2026, Daybreak originally included GPT.5-5-Cyber (a model optimized for security work), Codex Security (an agent that can analyze codebases, identify vulnerabilities, validate findings, and help develop patches), Patch the Planet (an initiative with Trail of Bits to find and fix vulnerabilities in open-source software), Daybreak Cyber Partner Program (lets approved cybersecurity companies such as Cloudflare or Cisco integrate OpenAI's cyber capabilities into their own products and services), and Trusted Access for Cyber (the governance/access system for organizations doing authorized cybersecurity work with these capabilities).

Now, OpenAI has expanded Daybreak with two access tiers, Daybreak Blue, and Daybreak Red.

The company says Daybreak Blue is “the recommended starting point for most defenders, supporting vulnerability discovery, secure code review, malware analysis, incident response, and patch validation. Companies opting for this tier can expect access to frontier general-purpose models, including GPT‑5.6 Sol, whose safeguards have been tailored to authorized defensive security work.

Daybreak Red, on the other hand, provides access to OpenAI’s “purpose-trained cybersecurity models for authorized vulnerability research, exploit validation, and security testing.” This tier offers the brand new GPT‑5.6‑Cyber, built on GPT‑5.6 Sol and trained to improve capabilities on several specialized cybersecurity tasks such as finding zero-day vulnerabilities and developing exploit chains.

This model is also more compliant and less likely to refuse certain higher-risk, dual-use cyber tasks.

Complying with "dangerous" requests

Request compliance is the name of the game here. OpenAI says the new model addresses feedback from security researchers who “encountered persistent refusals with the earlier model.” General-purpose GPT-5.6 Sol, for example, will comply with just 1.5% of the requests usually given by cyber-defenders working on codebase analysis or vulnerability identification. This percentage increases to 2.0% with Daybreak Blue access.

GPT-5.6-Cyber, on the other hand, completes 95.0% of requests, OpenAI says, up from 57.3% of the previous model, GPT-5.5-Cyber. We weren’t able to independently verify these claims, though.

While it doesn’t outright say it, OpenAI considers these models relatively dangerous to use, which is why they’re locked behind the Daybreak Cyber Partner Program. However, the program is now expanding, allowing these companies to embed the models behind their own products, managed services, or cybersecurity engagements, and offer them to clients of their own.

Those who wish to be a part of the program directly can do so by applying to join online now.

“Models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment. Despite these risks, we believe that democratizing access to frontier intelligence for defenders is crucial to accelerating and automating cyber defense,” OpenAI said.

“Daybreak Blue and Daybreak Red access are available for approved individuals⁠ and organizations conducting authorized work. We control access through identity verification, account security, monitoring, approved-use restrictions, and legal attestations.”

Wix launches Symphony – giving small businesses their own AI workforce

  • Wix launches Symphony, a standalone AI agent platform designed for SMBs
  • AI agents work to understand your business, then complete essential tasks on your behalf
  • Symphony comes with a built-in quality layer, helping ensure trust.

Wix, one of the world’s biggest website builders, has today launched Symphony, a new platform which aims to provide SMBs with a proactive team of AI agents that are built around their specific business needs, goals, and workflows.

The company says Symphony will allow business owners to move away from working alone to operating with a tailored AI team in just minutes.

What is Symphony?

Wix claims Symphony has been built on the experience and unique data it has accumulated while supporting hundreds of millions of businesses worldwide.

The company highlights how, unlike typical AI tools that simply act on instructions, Symphony learns the business, taking the time to understand its unique needs rather than offering a one-size-fits-all solution.

At the center is Maestro, Symphony’s central AI agent. Maestro understands what is happening across the business, identifies what needs attention next, and coordinates the right agent for each job.

Operating much like a team of humans, Symphony’s AI agents work across approved workflows, executing tasks and connecting to the tools that the business already uses. It then reports back, offering updates, analytics, and flagging key actions for approvals.

Each day your agents will also have a ‘morning meeting’, providing a summary through a simple app of work completed, highlighting what still needs to be completed, and identifying new opportunities based on business activity, customer behavior, and current trends.

Symphony also provides a built-in quality review layer, with a separate agent checking work before it is presented, helping support accuracy.

According to Wix, Symphony is available through a tiered subscription model.

“We built Symphony to be the go-to AI agent orchestrator for SMBs,” said Ronny Elkayam, COO of Wix.

“It is purpose-built for how small businesses operate, combining Wix’s two decades of SMB expertise with a coordinated multi-agent system that can learn how a business works, take action and help owners grow with more speed and confidence. With Symphony, any business owner can have the team they need to scale.”

Google logo on a black background next to text reading 'Click to follow TechRadar'

We called the Geekom IT13 Max 'superb for office and light creative work' — and this 4-star AI mini PC just got a 15% discount

After testing Geekom's Intel-powered IT13 Max, we found it a good, robust machine that's ideal for office work and light creative tasks. And right now, the Geekom IT13 Max AI mini PC is discounted to $679 (was $799) at Amazon with code TRT13DFF.

This mini PC pairs a genuine Core i9 mobile chip with 24GB of RAM and a 1TB SSD, in a chassis smaller than most external hard drives. In the UK, Geekom's mini PC is down to £637 (was £749) at Amazon.

Should you buy it?

Buy the GMKtec IT13 MAX if...

You want strong CPU performance for office work, coding, or light creative tasks in a tiny footprint. You need to drive multiple 4K monitors from one small box.

Skip the GMKtec IT13 MAX if...

You want to game beyond light, reduced-settings titles — this runs integrated graphics only. It also uses DDR4 RAM, so skip it if you need DDR5 bandwidth for memory-intensive workloads. And if you're on a tighter budget, Geekom's lower-tier i5 configs cost meaningfully less.

Intel Core Ultra 9 185H | 24GB DDR4 | 1TB SSD

14-core, 20-thread Core i9-13900HK, 24GB DDR4 RAM, 1TB NVMe SSD, dual USB4 (40Gbps), dual HDMI, quad 4K display support, Windows 11 Pro. For the full discount use code TRT13DFF

In the UK: now £637 (was £749)View Deal

Why we recommend it

The GMKtec IT13 Max earned 4-stars in our review, where it proved a capable mini PC. We said, "for office and light creative work the IT13 Max is an excellent option," as well as use as a workshop or production-line machine.

The i9-13900HK is a genuine high-end mobile chip — 14 cores, 20 threads, and clock speeds up to 5.4 GHz — and it's unusual to see it in a mini PC this size and at this price. It handles everyday office work, code builds, and multitasking comfortably, and Geekom's cooling keeps things quiet under sustained load.

24GB of RAM and a 1TB SSD are both generous starting points (but opt for the 16GB RAM model if you want to expand that memory up to 96GB). Connectivity is solid: dual USB4 ports at 40 Gbps, dual HDMI, Wi-Fi 7, and support for driving four displays simultaneously, making it a capable multi-monitor workstation for the price.

Price Context & Historical Value

Geekom lists this configuration with an MSRP north of $800, and it's typically discounted through coupon codes rather than site-wide sales — $679 with code TRT13DFF is a solid price for the 24GB/1TB tier, in line with what this model has landed at during previous promotions. This is the lowest price in the UK that the IT13 Max has been. Worth noting the code expires August 30, so this isn't a standing price.

For more savings, every week we track the best mini PC deals.

The Catch: What to know before you buy

There are two sticking points with the IT13 Max. First, the 24GB RAM model features fixed memory, so you can't upgrade it. If that's what you want, look for the version with 16GB RAM (available direct from Geekom US and Geekom UK).

This lets you expand both memory and storage — RAM to 64GB, plus room for a second M.2 drive and a 2.5-inch SATA bay.

Second, the IT13 uses Intel's Iris Xe integrated graphics, not a dedicated GPU, and it runs on DDR4 rather than DDR5 — a deliberate cost-saving choice that keeps the price down but caps performance in games and GPU-bound creative work.

It'll handle 4K video playback and light gaming at reduced settings, but it's not built for modern titles at high settings. If gaming or GPU-accelerated tasks are the priority.

Also consider

AMD Ryzen 5 7640HS | 32GB DDR5 | 1TB SSD

This compact mini PC features an AMD Ryzen 5 7640HS processor, 32GB DDR5 RAM, a 1TB SSD, triple 4K display support, USB4, dual 2.5G Ethernet, Wi-Fi 6E, and Windows 11 Pro pre-installed.

Check our full reviewView Deal

AMD Ryzen 7 8845HS | 16GB DDR5 | 1TB SSD

The K8 Plus packs a high-performance Ryzen 7 8845HS processor, 16GB RAM, and a 1TB PCIe 4.0 SSD. I recommend upgrading the memory and storage to unlock max power. With OCuLink eGPU support, dual 2.5GbE LAN, USB4, and 8K display output, it’s a powerful compact desktop alternative.

Read our full reviewView Deal

Improved connectivity is helping more Brits realise their dream — in both business and personal life

  • Vodafone uncovers a “nation full of drive” with 85% of Brits building towards a major ambition
  • Over half of those surveyed believe it is easier to find opportunities in the digital era
  • Vodafone launched the UK’s first Opportunity Hub in London, intended to provide advice and connections to ambitious visitors

Vodafone has released the results of research into how being connected has opened the door to people being able to pursue their goals.

With 40% of Brits feeling “more ambitious than ever” and a majority aiming to achieve major targets in personal and professional development, the research is part of VodafoneThree’s investment into building the UK’s best network.

Interestingly, the findings also highlight that key career events take place in our 20s and 30s, and accompany the successful Opportunity Hub event targeted at this age group.

Connecting unlocks opportunity

Vodafone’s survey found over half (55%) of Brits feel it is easier to find opportunities in the digital era, with 20% wishing they had started working toward their ambitions sooner. 42% believe greater connectivity has had a positive effect on reaching their goals, with 49% now “better placed” to achieve than they were 5 or 10 years ago.

The survey also uncovered the blocks to personal and professional ambitions. Unsurprisingly, financial constraints are the main barrier, with 22% admitting this. But lack of confidence at 13%, fear of failure (12%) and limited access to the tools needed for self-improvement (9%) are also mentioned as challenges.

However, life’s disruptions can be seen as launch points, with bereavement (27%) and redundancy (25%) catalysts for chasing ambitions, alongside parenthood (25%).

“Britain isn't short of ambition," a VodafoneThree spokesperson said, "the challenge is turning ambition into action. Our research shows that connectivity is increasingly part of that equation, with nearly two-thirds of would-be founders saying unreliable connectivity has held them back from starting a business locally.”

❌