The Latest

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:

Week in review

Know what was tested before your SAP ECC migration goes live
In this Help Net Security interview, Guilherme Joventino, COO of MIGNOW, explains why some large companies plan to stay on ECC past the 2027 deadline and pay SAP for extended support until 2030. The interview covers what that choice may cost, why fear of disruption stalls projects more often than budget, and what the first ninety days of a phased migration involve.

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files
Researchers have taken apart TASK#STOMP, a Windows backdoor that searches a victim’s drives for business documents, uploads them to attacker servers, and then stays put to grab each new or edited document. The same malware steals saved Wi-Fi passwords and clipboard text, takes screenshots, and runs whatever command its operators send.

European AI spending is on track to reach nearly $470 billion by 2030
European organizations will spend nearly $470 billion on AI in 2030, IDC forecasts, with spending growing at a compound annual rate of 35% from 2025. At that rate, the market more than quadruples in five years. Generative AI will account for 55.4% of the total by 2030.

Somewhere in your traffic logs, a bot is doing more than looking
Akamai has watched verified AI crawlers, ChatGPT among them, move from reading web pages to sending high-frequency POST requests. In a 30-day analysis of its global customers, ecommerce accounted for 44.8% of those AI bot POST transactions, and travel climbed to 30% in a single month.

What to do first when you get 90 days to secure AI agent data
In this interview with Help Net Security, Kelly Herrell, CEO at Nol8, explains where AI agents create exposure inside organizations. The first thing to examine is the data path: what an agent can reach, what enters its context, and where results go.

Stop watching what AI agents say and start watching what they do
In this interview with Help Net Security, Ariel Assaraf, CEO of Coralogix, explains why a system prompt can describe a boundary for an AI agent but cannot enforce one. Assaraf covers how his team builds AI agent guardrails at the execution layer, limits context without expanding authority, and tunes controls by risk so agents stay useful during incidents.

North Korea’s job interview scam runs both ways
Attackers are targeting members of the Rust Project and maintainers of widely used crates (Rust code libraries), dangling attractive opportunities to compromise their devices and accounts and, ultimately, publish malware.

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)
A Chinese-speaking threat actor has exploited a vulnerability (CVE-2026-7273) in unpatched ZyXEL GS1900 Smart Managed Switches and has exfiltrated sensitive data from 996 devices across 48 countries, GreyNoise reported on Monday. The affected switches are predominantly located in Italy, the US, Taiwan, South Korea, and a number of EU countries.

Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page
Three domains / web portals belonging to Dutch academic publishing company Elsevier have been redirecting users to a page branded “LAPSUS$ GROUP, Chapter II,” carrying a signed statement that taunted the FBI and counted down to a future victim. According to Cloudskope researchers, the redirect ran for at least 78 minutes, from roughly 7:49pm CT until it was cleared before 10:09pm CT on September 21, 2026.

Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances
Check Point Software has released emergency fixes for a critical Check Point Management Server vulnerability (CVE-2026-93616) that has been exploited as far back as July 23, 2026. The company also confirmed that a pre-authentication remote code execution (RCE) vulnerability (CVE-2026-85102) in Check Point (Quantum) Security Gateway for which it released patches on September 9, 2026, started getting probed a few days after.

DarkMe RAT trades zero-days for plain phishing emails
DarkMe, a remote access trojan and info-stealer that has previously been associated with a threat group that targeted financial market traders and cryptocurrency users, has been spotted again. This time around, its distribution has been simplified: instead of leveraging zero-day exploits, attackers are betting on a simple email to convince targets to run it on their machine.

OpenAI agent hacking spree widens to Australia, targeting government website
Before the Hugging Face and RubyGems hacks, autonomous OpenAI agents attempted to hack into three other websites, including an Australian government public health website, independent research lab Transluce revealed on Wednesday. Insight into the agents’ actions was gleaned from reports of tens of thousands of queries apparently made by the agents through urlquery.net, a free URL scanning service, so they could avoid access restrictions.

Passwork NIS2 efficiency guide: Save your team hours before the 2026 audit
EU authorities are reviewing NIS2 compliance, increasing accountability for senior management while cybersecurity teams face skills shortages. This guide explains how Passwork supports NIS2 Article 21 requirements, reduces operational workload, and simplifies audit evidence collection.

Intent injection attacks are a new worry for AI-native 6G networks
Intent-based networking (IBN) lets operators state the outcome they want and leaves its translation into network policy to software, an approach AI-native 6G designs have moved to the forefront. Researchers at the University of Ottawa and Nokia Bell Labs argue that this abstraction gives attackers new openings, and it tests two machine-learning detectors against one of them.

Hackers exploit Gyazo server flaw to steal 23.6 million user records
Japanese software company Helpfeel has confirmed a data breach on its screenshot-sharing platform Gyazo, in which attackers exploited a vulnerability in its image upload server, stealing approximately 23.62 million user records and metadata tied to hundreds of millions of images.

Scammers impersonate cops, use arrest threats to extort victims
Scammers are posing as police officers and federal agents, threatening arrest unless victims pay up, the FBI warns. The FBI’s Internet Crime Complaint Center (IC3) updated an alert it first issued in 2022, citing “losses totaling more than $1.6 billion” between January 2025 and July 2026.

Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions
Scammers are using a $249 website toolkit to sell unverified AI subscriptions worth up to $2,000 a year, and a genuine Google sign-in screen is what makes the sites convincing. Malwarebytes found more than 100 websites built this way, all tied to the same toolkit and closely related developer details.

The latest deepfake numbers give CISOs plenty to worry about
AI is letting cybercriminals reach deeper into organizations than a phishing email ever could. 41% of CISOs reported at least one social engineering incident involving a deepfake during an employee audio call in the past 12 months, according to Gartner. 36% reported the same for a video call.

Researchers uncover malware that uses AI to choose its next move
To help security practitioners catch malware that leans on AI, researchers from Cisco Talos shared an open-source framework that they hope will be used to classify and analyze the threat. The tool, called CAIRN, works entirely from metadata pulled off files. No downloading the malware, no running it.

Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes
The EvilTokens phishing service, which compromised more than 12,000 inboxes at over 10,000 organizations, has been disrupted by a coalition of law enforcement and private-sector partners led by Microsoft.

WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)
WordPress released version 7.1.2 to fix a critical flaw that lets an unauthenticated attacker make the software load a PHP file of the attacker’s choosing from outside the site’s active theme folders. On sites where the server and the active theme meet certain conditions, the attacker can go on to run code on the server.

Fake Claude Max giveaway tricks users into handing over their Google account credentials
A fake Claude Max giveaway uses a spoofed Google sign-in window to steal users’ login credentials, Malwarebytes researchers have found. “Browser-in-the-browser” is not a new technique. Researchers have documented it since 2022, and in June Palo Alto Networks’ Unit 42 reported a campaign that used draggable fake browser windows to target Microsoft 365 users.

80,000 relay servers help users in China slip past U.S. AI region bans
More than 80,000 relay servers are helping users in China bypass geographic restrictions on leading U.S. AI models, according to Team Cymru. Earlier this month, CISA, the NSA and the FBI warned in a joint advisory that China-based AI firms are running large-scale knowledge distillation campaigns to pull capabilities out of leading U.S. models.

GNOME 50.5 security fixes patch a gvfs CVE and Epiphany code injection
GNOME 50.5, which the GNOME Release Team shipped on September 24, patches a CVE in the gvfs file system layer, a JavaScript injection flaw in the Epiphany web browser and a use-after-free bug in the librsvg image library.

New Android malware RemControl steals banking PINs and blocks removal attempts
A new Android banking trojan called RemControl tricks victims into installing a fake TV app, then takes control of their phones to steal banking PINs, Group-IB has found. Researchers confirmed that the malware targets customers of more than 30 banks in Italy, France, Spain, Poland, Portugal, Canada and some Gulf states.

UK gears up for fight against Russia’s disinformation machine
The UK government will create a new body to track and disrupt disinformation campaigns run by hostile states, Prime Minister Andy Burnham announced at the United Nations General Assembly in New York. In his first address to the Assembly on 22 September, Burnham told world leaders he was tasking UK security chiefs to begin work on the National Centre for Information Defence, which will operate “to detect, attribute and disrupt these kinds of hostile state information attacks.”

Fake payroll desktop apps hand attackers a route to company paychecks
An attacker has been offering “desktop apps” for three large US payroll and HR platforms that have never released one, Allure Security have found. Anyone who runs the installer gets a copy of ScreenConnect, a legitimate remote access tool, configured to let the attacker control the computer without the user knowing.

MacSync info-stealing malware hides malicious commands in an iCloud calendar
A new MacSync variant targets Mac users with an infostealer and persistent backdoor designed to steal credentials, crypto wallet data, and files, according to Kaspersky. Researchers found the malware spreading through a crypto wallet app called Toria, which had its own website and was promoted on X and Telegram.

Threat detection dashboards are masking security coverage gaps
A detection rule can show up as deployed on a coverage dashboard and still never fire when an attacker uses the technique it was built to catch. Conifers assessed 14,652 detections in its customer base, including rules written by customers and detections managed by vendors in SIEM, endpoint, cloud, identity, email and network tools. The research found that 47% of detections in the average organization need attention.

AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor
Forty percent of large companies had an AI-related compliance or governance issue in the past 12 months, according to 1,000 senior IT, operations, and transformation leaders surveyed by Sapio Research. Those leaders said process-related problems contributed to 84 percent of the incidents.

Gopass: Open-source command-line password manager for teams
Gopass is a free, open-source password manager that stores credentials in an encrypted store and runs from the command line. Its maintainers built it as a drop-in replacement for pass, the standard Unix password manager.

Product showcase: Helmit alerts parents when online conversations show signs of trouble
Helmit is a parental control app that combines AI-powered social media monitoring with screen time management, web filtering, location tracking, and safety alerts. It identifies potentially concerning interactions and surface the messages associated with an alert.

Google hit with €403 million GDPR fine over location tracking
Ireland’s Data Protection Commission (DPC) has fined Google €403 million (about $463 million) over its processing of users’ location data and ordered the company to bring that processing into compliance within six months.

DavMail 7.0.0 puts most of its work into Microsoft Graph
Anyone who wants to leave Outlook but still has a mailbox on Exchange needs a translator. DavMail is one: a Java gateway that converts the open protocols most mail, calendar and contact apps speak (IMAP, SMTP, CalDAV, CardDAV and LDAP) into requests Exchange and Office 365 accept. “Ever wanted to get rid of Outlook?” the project page asks.

A cheap fake base station can still track 5G subscribers
Researchers from the i2CAT Foundation, the University of Murcia, and NEC Laboratories Europe built a low-cost tool called 5G-Shark that lures a target phone onto a fake base station and questions it, then used it to audit commercial 5G networks.

The next intellectual property thief may sound like your CEO
Impersonation, phishing and domain-name abuse are the most concerning types of online intellectual property infringement, according to CSC’s The State of Online IP Risk 2026 report. Internet and branded content, online marketplaces and paid search were the channels most frequently targeted.

NetBSD 10.2 security fixes close a remote kernel bug in ipfilter
A NetBSD box at the edge of a network, filtering traffic with ipfilter, has been carrying a kernel flaw that someone outside the machine can set off. The bug is a remotely triggerable null pointer dereference in ipfilter, meaning the kernel tries to read memory through a pointer that leads nowhere. In kernel code, that usually ends with the whole system going down.

Nearly two-thirds of tested websites fail every bot test
Malicious bot activity increased 124% between July 2025 and June 2026, compared with 13.2% growth in human traffic. Traffic from AI agents and large language model crawlers rose 82.3% during the same period, according to DataDome’s State of Bot & Agent Security Report 2026.

Product showcase: Scamwise checks the red flags before you take the bait
Scamwise is a free scam-checking service from Savi that examines suspicious messages, emails, websites, phone numbers, images, and real-world situations for signs of fraud. The service works in any web browser on desktop, mobile, or tablet, with no account required.

Prismor: Open-source runtime control plane for AI agents
Prismor is a free, open-source security layer for AI coding agents. It sits between an agent such as Claude Code, Codex, or Cursor and the actions that agent wants to take, and it checks each tool call against a policy before the call runs. Every call gets one of three verdicts: allow, warn, or block.

Claude Opus 5.5 cuts costs and adds safeguards for autonomous AI
Claude Opus 5.5 is available across Anthropic’s platforms, Amazon Web Services, Google Cloud and Microsoft Azure. Developers can access it through the Claude Platform using the model name claude-opus-5-5. It includes watermarking measures designed to comply with the EU AI Act.

GPT-6 Sol and Luna arrive with 50% lower API prices
OpenAI has expanded GPT-6 with the GPT-6 Sol and GPT-6 Luna models. Both are available in ChatGPT Work and Codex for Plus, Pro, Business, Enterprise, and Edu users. Free and Go users can access GPT-6 Luna in the desktop app. The models are not yet available in Chat. OpenAI API users can access them as gpt-6-sol and gpt-6-luna.

Americans’ views on data centers have turned more negative
American attitudes toward data centers have turned noticeably more negative over the course of 2026, according to a new Pew Research Center survey. 54% of U.S. adults now say data centers are mostly bad for the environment, up from 39% in January.

Europe’s technology backbone is becoming a cyber target
Disruptive attacks on public-facing services, financially motivated cybercrime and compromises of shared technology providers are increasing cybersecurity risks across Europe. ENISA’s Threat Landscape 2026 identifies cybercrime, state-linked activity, foreign information manipulation and interference, hacktivism and vulnerability exploitation as key threats.

Ubuntu kernel CVE fixes are moving to a weekly release schedule
Ubuntu kernels will ship every week under a new release schedule from Canonical, which is merging its four-week cycle for regular Stable Release Updates (SRUs) and its two-week cycle for security fixes into a single two-week cycle. The cycles overlap, each starting a week after the one before, which is what produces a weekly release.

Your security program knows about the firewall, but does it know about the elevator?
By early August, attackers had hit water systems in at least seven U.S. states. The FBI and EPA said the intruders remotely accessed internet-facing programmable logic controllers, the small industrial computers that run pumps and valves. Operators lost monitoring or control, and in some cases water operations degraded. Federal investigators are examining possible links to Iran-backed hackers.

Claude.ai is about 3x faster after 3,000+ changes
Anthropic engineers made claude.ai and the Claude desktop app roughly three times faster during a two-week sprint in August, with Claude finding the bottlenecks and writing the fixes. The team merged more than 3,000 changes and says none of them caused a customer-facing incident or rollback.

Apple’s new iOS 27 feature looks for signs you’re being scammed
Apple introduced a scam-prevention feature called Impersonation Risk Detection with iOS 27 and iPadOS 27. The feature allows supported apps to request a risk assessment when a user takes an action that could be connected to an active social engineering scam.

Google plans to give Private AI Compute a memory that follows users across devices
Google plans to add private, server-side memory to Private AI Compute, enabling AI assistants to maintain continuity across devices while providing privacy protections normally associated with on-device processing.

Meta locks itself out of user data on its AI glasses
Meta is expanding Private Processing to its AI glasses, extending their security protections into cloud data centers. The system runs AI models inside confidential virtual machines (CVMs) designed to prevent Meta from accessing users’ data. Private Processing combines protected hardware, encryption and software verification to secure data during cloud processing and storage.

Your incident count is missing a few incidents
If you run security for a brand with hundreds or thousands of locations, the tools you’ve bought may have little to do with whether an attack stays at one store. A new VikingCloud survey asked 200 security and IT leaders at U.S. and European chains about the past year. None of the 13 security technologies it measured was tied to less spread between sites, and neither was real-time visibility. One policy decision was.

Half of threat hunters say bad data is their biggest problem
Half of security professionals name data quality or quantity as their biggest barrier to effective threat hunting, according to the SANS 2026 Threat Hunting Survey. Teams with working playbooks describe the logs as their ceiling, and gaps in cloud logging and identity telemetry come up most often.

Cybersecurity jobs available right now: September 22, 2026
We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.

New infosec products of the month: September 2026
Here’s a look at the most interesting products from the past week, featuring releases from Akeyless, Akuity, Bitsight, BugBase, Cloud Range, Cohesity, Dataminr, Gurucul, Nozomi Networks, Orchid Security, Ping Identity, Scytale, Securin, Superna, and Tuskira.


from Help Net Security https://ift.tt/ZL7raOm

Ads are everywhere on Android. For most of us, the answer is either to sit through the ad, or pay up for a service's "premium" tier. While services like YouTube Premium can genuinely be worth it, they aren't for every app. Thankfully, there are options: All you need are free apps or extensions, easily available from the Play Store or alternative app stores, including one option that can block virtually all ads on Android.

Use BlockAds to block all ads on Android via a local VPN

BlockAds customization on Android
Credit: Khamosh Pathak

If you want a single app that blocks everything, start with the aptly named "BlockAds." It’s a free, open-source app you can install directly from GitHub or via the F-Droid store. It’s not available on the Play Store, so the installation method will depend on where you live and when you’re installing it. If Google’s new rules are in place, you’ll need a 24-hour cooling-off period before you can sideload apps.

Once installed, activate BlockAds, giving it permission to add a VPN profile. When enabled, BlockAds will activate its own VPN profile that will stay enabled in the background. While it uses a VPN profile, it’s not a VPN service like Proton VPN in the traditional sense. Instead, it’s a local VPN that filters the traffic on your device itself. It uses DNS filtering to automatically block traffic to ad servers and trackers, quietly disabling them in the background. All your regular activity continues, but the annoying ads in any app disappear, without needing to root your device. There is one downside to using this method: Android only lets you enable one VPN profile at a time, so if BlockAds is taking up the VPN slot, you can’t use an actual VPN to protect your internet usage or to spoof your location.

Use private DNS to customize ad blocking across all apps

Private DNS features for ad blocking on Android.
Credit: Khamosh Pathak

If you don't want to use a VPN profile, or a third-party app, DNS filtering is another path. This method blocks known advertiser domains, effectively blocking most ads you encounter on the web. Android OS comes with a built-in option that lets you change the DNS server to whatever you like, but there are also services that use DNS filtering to remove ads and trackers as you browse the internet, like AdGuard's free DNS filtering. All you have to do is change the DNS address. Go to Settings > Network and Internet > Private DNS and switch to the Private DNS provider hostname option, then enter the hostname. In this case, to use the free service, enter "dns.adguard-dns.co" and hit the Save button.

It's important to note that DNS filtering might break some sites or apps with full-screen ads. This is where a more flexible option like NextDNS can help. Once you create a NextDNS account, you get a personal DNS hostname URL, where you can customize which filters to use and add websites to a whitelist as well. Plus, you can enable or disable protection as needed. After you sign up for NextDNS, go to the Setup section to find your URL. NextDNS, though, isn't completely free. You get up to 300,000 queries for free per month, and the unlimited Pro plan costs $1.99 per month or $19.99 per year.

Get a desktop-class ad-blocking experience with Firefox and uBlock Origin

Firefox uBlock Origin Ad Blocker
Credit: Khamosh Pathak

After Google’s new Manifest V3 changes, getting a full-fledged ad-blocker that updates in real time is becoming more difficult, even on desktop. On Mac and Windows, Firefox is perhaps the biggest champion of ad blockers, supporting the full uBlock Origin extension natively.

It’s the same story on Android as well. Firefox is the best way to run the full uBlock Origin extension, with its dynamic blocking and customizable filter support. If you want to use it, install the Firefox app on Android, tap the Menu button, and go to Extensions. Here, search for and install uBlock Origin. Once it’s installed, ads from websites will disappear automatically. The default setup is enough for most users. But if you want to customize it, you can go to uBlock Origin extension’s settings page to add extra filters.

Watch YouTube ad-free (with premium features) using NewPipe and DuckDuckGo

NewPipe Android YouTube Ad Blocker
Credit: Khamosh Pathak

The most reliable way to block ads on YouTube these days is to pay for Premium, as Google makes it quite hard to block ads for free. That said, there are plenty of workarounds. The best way is to get out of Google’s system altogether using the NewPipe app, an alternative YouTube client that’s hosted on the open-source F-Droid app store (similar to the BlockAds app we discussed above). The app plays YouTube videos ad-free, and you can also access features like background playback and offline downloads (usually reserved for YouTube Premium subscribers). You can search for and play videos, but you can also subscribe to channels and build your own YouTube feed in the NewPipe app.

If you don’t want to install an app from third-party app stores, try using DuckDuckGo's browser. It has a built-in YouTube ad blocker, which uses the robust filters from the uBlock Origin extension discussed above. Just load up a YouTube video in the browser, and you should be good to go. If you still see ads, make sure that the feature is enabled from Menu > Ad Blocking > Block Ads on YouTube.

Block trackers and ads without any setup using Brave

Blocking ads on Brave along with YouTube ad blocking.
Credit: Khamosh Pathak

If you just want an ad-free browsing experience without the need for installing and updating third-party extensions, try the Brave browser. It’s one of the best privacy-focused browsers out there, and the Android app is quite easy to use. It blocks trackers and ads by default. There are no switches to flip, and no extensions to enable. The default ad-blocking works for YouTube videos as well.


from Lifehacker https://ift.tt/V7cFjGW

Snap was in the smart glasses game from the jump. The company’s original camera-equipped Spectacles debuted back in 2016, beating Meta to the market by five years. Meta’s Ray-Bans and Oakleys captured massive consumer mindshare anyway, while Snap’s smart eyewear has been less visible.

With Snap Specs, though, the company is aiming to make up for lost time by delivering smart glasses that go beyond a hidden camera and voice-activated AI. At the Snapdragon 2026 Summit, I got my hands (and eyes) on a pair of Snap’s soon-to-be-released spatial-computing glasses that overlay digital graphics onto the physical world.

Specs are heavy on tech but light on your face

Snap Specs
Credit: Stephen Johnson

There's a lot of tech packed into these black polymer frames. They're powered by two Snapdragon processors, with two full-color hi-res cameras facing outward; the tracking system supports 6DOF (six degrees of freedom) hand tracking for gesture controls; and it's all standalone, as there's no tether or wired puck handling the heavy lifting. With all that crammed into the frames, plus the battery to run it, you'd expect them to be heavy. At around 135 grams, they aren’t light, but Specs are surprisingly comfortable. The weight is distributed evenly, mainly across the frames, so for the brief time I used them, they remained ergonomically acceptable. Specs feel more like a pair of sunglasses than a bulky VR helmet. As for battery life, Snap promises four hours of mixed-use on a full charge.

Display quality on Snap Specs

In the interest of not alienating the people around you, Snap chose to make the lenses clear enough that your eyes can still be seen through them, but if you want to close out the world, there’s electrochromic dimming for quick transitions between clear and dark lenses. It both useful and a cool trick. Check it out:

Snap Specs
Credit: Stephen Johnson

The in-glasses display is surprisingly bright. Specs' visuals are powered by a proprietary liquid crystal on silicon (LCoS) display system, and even when used in a light-filled conference room, I could still clearly see the UI and its various apps. I tested out YouTube under these borderline abusive conditions, and it streamed high-def video in 16 million colors suitably.

The display offers a 51-degree field of view. It feels like having a large floating window hovering in front of you. From there, you can use simple gestures to launch apps, watch movies, play games, and do most other tasks you can’t do from your phone. But it was the context-aware, real-world spatial computing tasks that I wanted to try—the things you can't do from a phone or PC.

What can you actually do with a pair of Snap Specs?

Snap plans to launch Specs with a full suite of both first-party and third-party apps that will do everything from improving your drawing skills to teaching you music. I tried out a golfing demo, and it made the possibilities of augmented reality glasses immediately clear. Instead of putting blindly toward a distant hole, Specs show you exactly which direction to swing the putter and adds a virtual flag to mark where the hole is. It’s anecdotal evidence, but my personal putting game improved immensely. Is it cheating? Probably, but it works.

Are Specs going to be useful in the real world?

A half-hour or so of testing a prototype isn’t enough time to really say whether these will be useful in a person’s real life, but I can say for sure that they’re very cool, and I’m looking forward to going more in-depth with them in the coming months as their release date approaches. Snap Specs are planned for release this fall and will retail for $2,195. 


from Lifehacker https://ift.tt/L10YwsX

We may earn a commission from links on this page.

Apple caught my attention with their claim that the Apple Watch Series 12 and Ultra 4 have the “most accurate heart rate in a wearable.” It’s hard to make a really accurate heart rate sensor, and in my experience, Apple hasn’t had a great track record in that area. So I tested the Series 12 pretty intensively over the past week or so, and now I have results.

I’m picky about accuracy; longtime readers have seen me test watch after watch against my trusty chest strap to find out how good each one really is. That sometimes brings surprises: The Powerbeats Pro 2 are surprisingly bad at heart rate tracking if you have small ears, for example. I also discovered that the Garmin Forerunner 570 is shockingly good at heart rate accuracy, far better than any other device I had tested up to that point. (Garmin’s Forerunner 970 and the newest Fenix and Venu watches have the same sensor.)

What Apple says about their heart rate sensor, and why I doubted it

Is the new Apple Watch really good enough to beat Garmin’s best sensor? Apple believes it is, but I doubted that claim, for a few reasons. The first is simply Apple’s track record. Early models of the Apple watch had better sensors than most wearables at the time, so Apple developed a reputation for good accuracy. For example, back in 2019 or so, the Series 4 watch performed far better for me than the Whoop 3.0. But time marches on, and devices have gotten better. Garmin has an excellent sensor, as I already explained; the Pixel watch is also impressively good. But Apple just didn’t keep up. 

You can see it in my comparisons over the years: here’s the Series 11 glitching where a Garmin did just fine, and here’s the Series 10 struggling alongside a Fitbit Charge 6. If I were to rank all the heart rate sensors I’ve tested for their accuracy, the Garmin 570 would be A-tier, the Pixel Watch and most good sports watches would get a B, and the Apple Watch (Series 10 and 11) would be a C. (S-tier would be reserved for chest straps.) Not long ago, I got downvoted to negative infinity for commenting on Reddit that Apple’s heart rate accuracy (up to the Series 11) is “mid at best.” Sorry, but it’s true. 

But, OK, perhaps it’s a new era. Apple redesigned its optical heart rate sensor to include larger LEDs and arrange them more closely in a circle. To support its claim that the new sensor is the most accurate on the market, it published a study that was extensive in its breadth (seven recent, competing devices were tested in a variety of activities) but limited in usefulness. Each pairing of a device and workout type was given, essentially, one number. We don’t get to see how each device behaves in use. The data feels cherry-picked, and in any case, it doesn’t give us enough information to say whether one sensor is truly better than another, or specifically what it does better. So I’m going to add my own data points. 

How I tested the Apple Watch’s heart rate sensor’s accuracy

I am just one person, so my experiments amount to a very small, informal study. That’s the case for any tech reviewer, no matter their qualifications—so feel free to compare my data to what others have found, but keep these limitations in mind for each of us. 

I took the Apple Watch Series 12 and the Garmin Forerunner 570 out for several tests during workouts. (I did not have a feasible way of testing background measurements outside of workouts.) I wore one device on each wrist, positioned according to manufacturer recommendations, and, at the same time, used an electrical chest strap to provide the reference values. 

I have relatively light skin, which may improve accuracy, and no wrist tattoos, so both sensors should get a clear signal on either wrist. I have six-inch wrists, on the small side of average, so I wore the 42-millimeter size of each watch (both are available in larger sizes for those who prefer it). A good fit is critical to getting good accuracy, and I feel I achieved that for both devices. I did my best to have both devices equally snug (but not uncomfortably tight) against my wrist. 

I tested both devices, together, on treadmill runs, outdoor trail runs, a rowing session, and a few strength sessions. Some of these workouts involved quick changes in intensity, leading to peaks and troughs in the graph. Others were more steady. Gripping objects such as dumbbells or rower handles can interfere with accuracy for some devices, which is why I included those workouts. Ambient light and temperature can affect accuracy as well, so I tested in a variety of weather conditions. 

The results

In my first set of tests, which I also shared here, the Apple Watch and the Garmin both performed well, but each had their flaws. The Garmin sometimes lagged a bit at the start of the interval, but quickly caught up. The Apple Watch didn’t have that problem, but sometimes missed the highest values on small spikes in heart rate. I’d call this one a tie. 

Garmin vs Apple Watch
Apple Watch in red, Garmin in purplish, chest strap for reference in gray. Credit: Beth Skwarecki

In my other trail runs and treadmill runs, I saw a similar pattern: Both watches would be on track most of the time, but each had their quirks. Garmin was more likely to miss out on the beginning of spikes, but the Apple Watch was more likely to drop data points entirely, especially toward the beginning of a workout. 

One day, I did three mini workouts at the gym: a treadmill run, a rowing session, and a strength session. The strength work included a few sets each of overhead barbell press, front squats (with my arms in a clean grip), and dumbbell curls. Here are those graphs, again with the Apple Watch in red, the chest strap in gray, and the Garmin this time in purple: 

Three comparison graphs: treadmill, rower, strength
Apple Watch in red, Garmin in purplish, chest strap for reference in gray. Credit: Beth Skwarecki

Both devices performed equally on the treadmill run, with their own minor glitches but both getting the job done pretty well. On the rower, the Garmin struggled more, missing almost half of the second interval. The Apple Watch wasn’t perfect, though, overestimating in a few places and not always picking up the lowest value between intervals. 

The strength workout was a mess for both devices. The Garmin often read low, but the Apple Watch sometimes read high and reported fewer values in total. This view shows it a bit better (each data point is a dot): 

Garmin vs chest strap, Apple vs chest strap
Apple Watch in red, Garmin in purplish, chest strap for reference in gray. Credit: Beth Skwarecki

So, is Apple’s sensor really the most accurate in a wearable? 

Looking at my data, I think the biggest news is that Apple is no longer lagging when it comes to heart rate accuracy. The Series 12 is a lot more accurate in my tests than the Series 10 or 11 ever were. Apple has built a very good heart rate sensor, and they deserve huge credit for that. I will no longer have to tell people Apple's sensor is mid.

But does it have the best heart rate sensor? I’m not so sure I’m convinced. It is holding its own against Garmin’s best sensor, for sure, and that’s impressive. In the rare cases the Garmin struggles, the Apple is usually there with a more-or-less correct value. But I have seen near-perfect graphs from the Garmin on its best days (admittedly, outside of this testing week); I've never seen one quite like that from Apple. The Apple Watch's sensor sometimes has trouble ramping up to correct values at the beginning of a workout; it overestimates on occasion; it doesn’t get all the way down to low values when intervals change quickly; and I’m concerned about the sparseness of the data points. It almost seems like the Apple Watch won’t report a value it’s not sure of, which is arguably better than recording a data point that could be wrong, but leaves odd gaps in some of the charts. 

This leads me to over-analyze the claim of  “most accurate in a wearable.” If Apple’s sensor fails to report a data point where another device reports an incorrect one, does that make Apple “more accurate” because more of its data points were on the right line? That’s probably a fair claim, but it still doesn’t feel great to award that device the “best” title. And if we truly want to compare the Apple Watch to all wearables, shouldn’t we consider chest straps, which are also worn, and which are objectively more accurate than any optical sensor in a watch? 

After all this analysis, I have a hard time awarding the Apple Watch a definitive title of being the “best” at wrist heart rate accuracy. But it’s damn good, and I have to put it up in the A tier with the Garmin. Congratulations, Apple. You managed to tie the best watch sensor out there, and I can’t claim there’s another one that’s better. 


from Lifehacker https://ift.tt/IaMOESX

We may earn a commission from links on this page.

Meta hosted its annual "Connect" event on Wednesday. Curiously, the company kicked things off at 7 p.m. ET (4 p.m. PT), following "Made by Google" as the second major tech event of 2026 to take place in the evening. While that might have reduced the usual visibility of the event, it certainly wasn't an unremarkable presentation: Meta CEO Mark Zuckberg laid out the company's big hardware and AI plans and sold us a pitch for Meta's vision for the future of work, entertainment, and social connectivity. Here's what the company announced.

Meta's next smart glasses don't have cameras

meta ray-ban audio glasses
Credit: Meta

Meta makes some of the most popular smart glasses on the market. That doesn't mean it has a great reputation. As it turns out, many of us aren't keen on walking past a deluge of glasses with embedded cameras wherever we go. While smart glasses fans have their arguments for why the tech is useful, many others are simply put off by the privacy invasion.

I can't think of a better reason to explain the direction Meta is taking with its latest smart glasses line: Ray-Ban Meta Audio glasses. As the name suggests, these glasses do not have cameras. Instead, Meta says they have open-ear audio, designed for "true all-day wearability." The new glasses have a reported 12 hours of battery life, while the charging case can add an additional 48 hours of use.

These glasses also have adjustable temple tips and swappable nose pads. You can use them to listen to music, access Meta AI, and take phone calls—all without having to fend off accusations of unsolicited video recording. Meta says that Meta Audio glasses will come in 23 different color and lens combinations in either "Clubmaster" or "Burbank" frames. They will ship Oct. 13, and you can pre-order them today for $349.

Meta introduced the Ray-Ban Meta (Gen 3)

meta ray-ban gen 3
Credit: Meta

Meta isn't completely ditching its camera-embedded smart glasses, of course. In fact, it also introduced the next devices in its Ray-Ban Meta line. According to the company, these glasses run an hour longer than the previous generation on a charge (nine hours as opposed to eight) and come with new adjustable temple tips. There's a new array of six microphones that Meta says cuts out over 90% of background noise.

Meta did make a point to note that the "3K Ultra HD" camera embedded in the frames does engage an LED light whenever you are recording, so the people around you are aware. Meta says those cameras will soon be able to shoot videos with Dolby Atmos spatial audio. These glasses are available now, in both "Avaitor" and "Zena" frames, starting at $449.

Meta VR Glasses

meta glasses
Credit: Meta

The device that is generating the most headlines is the Meta VR Glasses, the company's new virtual reality headset. Unlike other headsets, like Meta's Quest line or Apple Vision Pro, this device looks more like an oversized pair of glasses than a full headset. Meta says that, "thanks to a breakthrough glasses-like form factor," the product doesn't need to rely on straps or bulky hardware to run, and is five times lighter than the Meta Quest 3. That's due, in part, to the "puck," a clip-on external device that handles compute, battery, and storage.

The Meta VR Glasses have a 5K micro-OLED "Infinite Display" that supports both Dolby Vision and Dolby Atmos. They run on Qualcomm's new Snapdragon Reality Elite chip, while the puck's battery can stream high-resolution media for three hours at a time. It also supports 45W fast charging.

As a movie nerd, I'm intrigued by Meta's claims that this is the first VR device that's IMAX Enhanced certified. Meta says it's one of the only ways to experience "select films" in IMAX's expanded aspect ratio—at least, at home. That exclusivity extends to non-IMAX video formats as well: Avengers: Infinity War and Star Wars: A New Hope will be available in VR Enhanced versions. In addition, Disney+ subscribers will be able to watch select films in 3D, and sports apps like NBA, MLB, and ESPN will support 8K "Immersive Sports" streaming with 180-degree views.

Like other headsets, the Meta VR Glasses support multiple virtual screens, which Meta envisions as a useful tool for work. This device uses hand gestures for all controls, which means you can type using a virtual keyboard and control the UI with a virtual trackpad. You can work without any additional hardware, but Meta says you can connect your Mac or PC to the glasses for added productivity.

The biggest selling point is Meta's "hologram" feature, which lets you see a virtual representation of another person while on a call with them, creating the illusion you're actually having an in-person conversation. These are full-body holograms, too—a first for VR according to Meta (they even have legs!). Of course, since this is a Meta product, you can also talk to Meta AI while wearing the glasses. Meta VR Glasses will start at $1,299.99 and will be available in spring 2027.

New features for existing Meta AI glasses

Connect wasn't just about new hardware. Meta also announced a series of new features available across its new and existing glasses lines. One of the most intriguing is onboard hearing assistance, an FDA-cleared feature that helps adults with mild to moderate hearing loss, but this helpful feature won't be free: Users looking to add hearing assistance to their glasses will need to pay a one-time $149.99 upgrade fee, or subscribe to Meta One. (If you opt for the former, you can use HSA or FSA funds to pay for it.)

Meta also announced new exercise and health features, including guided workouts for running and cycling as well as nutrition tracking and dietary advice. A new AI shopping tool looks for reviews and price drops on products you've identified, and lets you make purchases with your voice. In addition, Meta says that there are a host of new ways to customize your experience with your Meta glasses, including personalized audio, custom gestures, and new visual AI. For example, you can now set a frequently used tool to the touchpad press-and-hold shortcut.

Going forward, your walking directions should be a bit more "human," the company says, as directions can use landmarks instead of street names (e.g., "turn left at the supermarket" instead of "turn left at Broadway.) I'm not sure that will be a helpful change, especially if the street signs are more obvious than the landmarks, but we'll have to see. Later this month, you'll also be able to ask for biking and public transit directions using your voice with Meta Ray-Ban Display.

Gaming on Meta VR Glasses

beat saber on meta vr
Credit: Meta

Meta clearly has big plans for gaming on Meta VR glasses. Beat Saber is getting an update for Meta VR Glasses and Meta Quest. There's a new single-player campaign, "Flux," that lets you punch and slice notes with your hands, and a refreshed "Campaign" mode with new reward and progression systems. Meta says, in total, there are 75 games coming to Meta VR Glasses, including Cardmada, Dice Throne Digital, Dragon Grove, Phoenix Wright: Ace Attorney – Dual Destinies, Supernatural, Tetris Effect: Mixed Realities, and Two Point Hospital. These games, including Beat Saber, can be played with hand-tracking alone, so there's no need for controllers.

Meta's "Muse" updates

Meta released Muse, its agentic AI assistant, a few weeks ago. While the company took time to summarize its new bot, it also announced a handful of new Muse updates. First, Muse is getting a cute cartoon avatar, which Meta thinks will make Muse's voice mode a bit more interactive. Muse is also coming to AI glasses in the coming months, and will get its own email address, so it can perform tasks on your behalf without using your personal email.

Meta says computer use is now available on the Muse for Mac app, meaning Muse can now use any app on your computer, even if you leave your desk. (Give Muse control over your machine at your own risk.) The company is also rolling out more connectors for Muse, so it can work with the following retailers and services: Walmart, Best Buy, American Eagle Outfitters, DICK'S Sporting Goods, Fanatics, Gap, Michael Kors, Sephora, Ulta, Wayfair, Shop Pay, and PayPal.

Finally, the company teased "Muse Charm," a Tamagotchi-like device for the agentic AI. This seems a bit more of a novelty than a useful tool, since I imagine you could achieve the same with the Muse app on your phone, but we'll learn more about this product in the future.


from Lifehacker https://ift.tt/O2s1CnG

Apple released a bunch of new devices last week. The Apple Watch Series 12 and Ultra 4 support new health-tracking features and Siri AI, while the iPhone 18 Pro and iPhone 18 Pro Max introduce the A20 chip and variable aperture for the first time on Apple's smartphones. But while all these new products are objective upgrades over their predecessors, they all have one issue in common: They keep randomly rebooting.

What is Apple's rebooting problem?

As reported by 9to5Mac, some iPhone 18 Pro users are noticing that their smartphones are freezing up after a failed Face ID scan. When this happens, you won't be able to interact with your iPhone, even if the "Try Face ID Again" button appears on-screen. After a few moments, the iPhone will reboot. It's not a catastrophic issue, but it is annoying, and it's affecting a number of users, as this Reddit thread shows.

It's a similar story with the latest Apple Watches. While the Series 12 and Ultra 4 obviously don't use Face ID, users are still experiencing random reboots—emphasis on "random." Unlike the iPhone 18 Pro users, affected Apple Watch users aren't doing anything in particular when their watches reboot. They could be in the middle of a workout, chatting with Siri AI, or using the Maps app, when all of a sudden, the Apple logo appears. Some analyses showed that the Neural Engine was at fault, but Apple never confirmed the exact issue.

Apple has fixes in the works for iPhone 18 Pro users

That said, Apple did find solutions to the reboot issues on all of these devices, though only the Apple Watch has a current fix. Apple released watchOS 27.0.1 exclusively for Series 12 and Ultra 4 users on Wednesday, which it says should fix random reboots going forward. And while iPhone 18 Pro and 18 Pro Max users don't have a fix yet, Apple confirmed to 9to5Mac that an update is in the works.

As such, don't feel the need to take your new iPhone 18 Pro to the Apple Store if your only issue is random rebooting. While some Apple Store employees have swapped out affected units, the upcoming software update should be enough to take care of the issue. While we don't have an exact ETA for the update, expect it to be called something like iOS 27.0.1, similar to watchOS 27.0.1. And if you want to ensure you update as soon as it's available, regularly check for it in Settings > General > Software Update.


from Lifehacker https://ift.tt/9vMTblZ

Apple's latest updates are all about AI—Apple Intelligence, that is. When you update to iOS 27 and macOS 27 Golden Gate, Apple will invite you to try Siri AI and other new Apple Intelligence features. (Assuming your iPhone supports Apple's AI features.) But whether you use the new AI-powered Siri all the time or find yourself frequently scrolling past the AI additions, Apple Intelligence is taking up space on your device—perhaps requiring more storage than you bargained for.

I'll admit, I didn't think much of it when I updated my iPhone and Mac to the latest versions. I gave Siri AI a shot, adjusted Liquid Glass, and went back to doing pretty much the same things I was doing before I made the update. But once I saw headlines about how much storage Apple Intelligence actually takes up on these new updates, I had to see for myself. And, wow, were the headlines right: On my iPhone 17 Pro, Apple Intelligence alone takes up 20.65GB. On my M3 MacBook Pro, it takes up a solid 30GB.

These numbers will vary by device: My M1 iMac, for example, only has 13.88GB allocated to Apple Intelligence. But still, these are large slices of my overall storage. Anyone with a small SSD knows how valuable each gigabyte really is, and upwards of 30GB for Apple Intelligence is a lot. Not only that, it's often more space than Apple's own metrics suggest: As MacRumors highlights, Apple says that Apple Intelligence should only take up to 14GB of storage at most, and even less for certain devices. So why is my MacBook Pro allocating more than double that space for Apple's AI?

Why does Apple Intelligence take up so much storage on iPhone and Mac?

I can't answer why Apple Intelligence is taking up so much more storage space than Apple says it should. But I can explain why Apple says its AI is supposed to occupy as much as 14GB on certain devices: Apple Intelligence is designed to run on-device whenever possible. While Apple does push certain tasks to its Private Cloud Compute platform, the company wants its AI models to run on your iPhone or Mac whenever possible. This safeguards your privacy, as none of your data has to leave your device to achieve the task—though Apple says Private Cloud Compute also protects your privacy throughout the entire process.

Regardless, for this reason, your iPhone or Mac will download Apple Intelligence models directly onto your device, so it can run processes on-device when it makes sense to do so. If you have a newer or more powerful device that supports Apple's more demanding AI features, like personalized Siri voices, you may need to store more Apple Intelligence data on-device to run those processes—up to 14GB for certain devices—yet it's not clear why Apple Intelligence takes up more than double that storage limit on some devices, like my MacBook Pro.

Check how much storage Apple Intelligence takes up on your devices

It's easy to check how much storage Apple Intelligence is taking up on your device, though Apple doesn't make it obvious. To start, head to System Settings > General > Storage (macOS) or Settings > General > iPhone Storage (iOS). Scroll down and choose either "macOS (i)" or "iOS," respectively. Here, you'll see your system storage breakdown, including a figure for "Apple Intelligence."

There's no solution at this point

Unfortunately, there doesn't appear to be a way to tell iOS or macOS to remove some Apple Intelligence models while leaving others intact, or to run all processes through Private Cloud Compute. In fact, it doesn't seem like there is any reliable way to disable Apple Intelligence on a device running iOS 27 or macOS 27 at all. The closest option I can find is to disable Siri (Settings or System Settings > Siri > Turn Off Siri), but while this disables a host of Apple Intelligence options, I still see the models taking up storage on my device, even after a restart. This might be one for Apple to fix in a future software update—hopefully as part of iOS 27.2.


from Lifehacker https://ift.tt/lL7Cv4A