The Latest

Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself.

AI coding agent containment

An agent launched the ordinary way runs as you, which means it can read anything you can read. That includes SSH keys, cloud credentials, and the pile of configuration in your home directory that has accumulated over years. Hazmat gives the agent a home of its own and shares only the project directory you point it at. Your keys and credential folders sit outside what the session can reach.

Read the terms before the agent starts

Before anything launches, one command shows you the terms of the session. It lists the directory the agent can write to, the paths it only gets to read, whether it can reach the network or any services, and whether a backup runs first. Take the ten seconds and read it. That printout is the last moment you get a look at what the agent can touch, and everything after it happens while you are not watching.

On macOS the launch does four things in order: back up the project, build a sandbox policy for that one session, switch to the agent account, then start the harness. A firewall rule is already in force by then. Linux runs natively, and a backend using Apple’s container tooling sits behind an experimental flag.

A demo you can run yourself

You can test the boundary in about a minute. A demo script creates a throwaway project, switches networking off, and runs a single contained command that writes a file into that project and reaches for a private key in your real home directory. The write lands. The key comes back unreadable, and the comparison afterward lists one new file in the project and nothing else touched.

About 5.5 percent of the code is a formal specification written in TLA+, a language for describing how a system should behave so the description can be checked by machine. The project calls its design verified on that basis. What got checked is the containment model on paper, and the Go binary you install is a separate piece of work with its own bugs.

Hazmat is available for free on GitHub.

Must read:

Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!


from Help Net Security https://ift.tt/Lj56ZKC

Companies that provide specific evidence of how they use AI tend to record stronger revenue growth. Researchers at Carnegie Mellon University and Larridin examined a study universe of 564 companies across 12 industry sectors. Individual analyses used smaller samples depending on data availability.

AI adoption revenue growth

The data included 478 corporate 10-K filings, more than 30,000 classified job postings, financial information, market data, and the AI Transformation Tracker built by Larridin.

The tracker assigns companies scores from 1 to 5 across three areas: AI adoption, workforce proficiency and realized impact. It also provides an overall maturity index. The January 2026 Tracker score vintage contained scores for 562 companies, corresponding to 538 after the researchers’ deduplication process.

“Generalized AI investment alone tells us little about a company’s ability to create value,” said Ameya Kanitkar, CTO of Larridin. “What matters is identifying where AI is being deployed, measuring adoption and workforce proficiency, understanding how customers and employees are benefiting, and connecting those efforts to quantifiable business results.”

Detailed AI disclosures linked to revenue growth

One of the most distinct indicators was what the researchers call “narrative concreteness.” The measure looks at how specifically a business describes its AI deployments and results in regulatory filings.

Companies that named AI systems, explained how they were being used and provided measurable outcomes tended to perform better on revenue growth. In the researchers’ adjusted model, companies at the top of the narrative-concreteness distribution were associated with 8.0 percentage points higher year-over-year revenue growth than companies at the bottom.

The researchers evaluated adoption, employee proficiency, realized impact, overall AI maturity, investment intensity, AI-focused hiring and the level of detail in corporate disclosures. Six score- and filing-based measures were significantly associated with revenue growth in unadjusted analyses. The hiring measure was not.

Several of the broader adoption and composite measures weakened once differences in industry, company size and previous growth were taken into account. Detailed descriptions of AI deployments continued to carry information about revenue growth after those adjustments.

Job postings offered another way to examine adoption. A total of 30,861 postings across 536 companies were classified to determine the share of hiring aimed at roles focused on building or operating AI and machine learning systems. The researchers caution that the job-posting data were collected after the revenue period being studied, so the hiring measure should be treated as descriptive evidence rather than a prospective predictor of revenue growth.

AI adoption shows little connection to margins

Greater signs of AI adoption were not associated with improved operating margins. No significant margin effects were found among the public signals examined.

The results provide little evidence of broad operating-margin improvements associated with the AI signals examined. The study did not directly measure individual cost categories or workforce reductions.

Stock market performance followed a similar pattern. None of the public AI signals predicted risk-adjusted stock returns over the following four months after controls and adjustments for multiple testing were applied.

AI infrastructure providers outperform

Companies supplying infrastructure for the AI market produced a different result. AI infrastructure suppliers outperformed sector- and size-matched peers by about 32 percentage points over four months.

Five large semiconductor companies, Nvidia, Broadcom, AMD, Micron and Intel, were excluded from the main analysis to prevent their performance during the AI investment boom from having an outsized effect on the results. Running the calculations with those companies included did not change the main conclusions.

The relationship between detailed AI disclosures and revenue was particularly useful in asset-heavy industries, where implementation may require changes to physical infrastructure, operations and established processes. Specific descriptions can help distinguish companies that have put AI into use from those still discussing plans or early experiments.

The results show association, not causation

The results do not establish that AI caused stronger revenue growth.

Companies that are already performing well may have more resources to deploy AI, measure its impact and provide detailed information about those deployments. Existing growth trends could also influence subsequent results, although prior revenue growth was among the factors included in the main statistical controls.

The work instead identifies a statistical relationship between observable evidence of AI use and revenue growth. The strongest result centers on concrete disclosures rather than broad claims of AI adoption, suggesting that specific information about deployed systems and measurable outcomes may provide a useful signal of how far implementation has progressed.

“The study suggests companies are using AI primarily to expand capabilities, improve customer experiences, and create new growth opportunities,” said Shixiang (Woody) Zhu, Assistant Professor at Carnegie Mellon University’s Heinz College of Information Systems and Public Policy.

“At this stage, AI’s measurable impact is appearing more clearly in revenue growth than in operating margins or stock performance, indicating that its value goes beyond cost reduction.”


from Help Net Security https://ift.tt/q7SNj1b

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:

Week in review

GitHub Dependabot malware alerts now cover eight ecosystems
GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month. Dependabot malware alerts, which had run on npm data alone, now draw on all eight ecosystems the moment a user turns malware alerts on. Dependabot itself already runs across more than 30 million repositories and 34-plus package ecosystems overall, which gives a sense of the scale the malware pipeline now has to operate at.

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix
Researchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security flaws nobody had reported before. Developers have confirmed 83 of them, and 81 now carry CVE numbers.

Post-quantum migration gets harder when every user holds a key
In this Help Net Security interview, Christopher Smith, CEO of Quantus, discusses what cryptographic inventories turn up in banks and hospitals, including default passwords and admin keys still held by former employees.

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months
Most security stories start with something broken. This one starts with everything working as designed. Researchers at Reco have been tracking a campaign they call City-Forum, named after a domain registered in 2002, abandoned, and now resolving to a generic rented server from a German hosting provider. From that server, someone has been pulling records out of Salesforce and ServiceNow portals around the world.

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577
To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular with managed service providers (MSPs).

Metabase zero-day exploited to access Framework customer data
Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service. According to the notification sent to affected Framework customers, the attackers accessed names, email addresses, phone numbers, physical addresses, and login IP addresses, but not payment information or records related to orders.

Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)
Microsoft’s August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and three that were publicly disclosed prior to the release of the patches.

Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)
A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed. The flaw has been added to CISA’s Known Exploited Vulnerabilities catalog and needs to be remediated by US civilian federal agencies by August 14, 2026.

Who will be the Stanislav Petrov in your organization?
Recent reports of “rogue AI” systems hacking companies reminded Brian Honan, CEO, BH Consulting, of Stanislav Petrov. In 1983, Soviet computers falsely detected a US nuclear missile launch. Instead of trusting the system, Petrov applied human judgement and correctly identified it as a false alarm, potentially preventing nuclear war. That is why the recent incidents involving OpenAI and Hugging Face, Anthropic, Meta, and the UK’s AI Security Institute deserve the attention of CISOs and boards.

338 million attack simulations reveal the state of enterprise defense
First, a bit of good news: Enterprise defenses are recovering. However, it’s a narrow recovery, with a twist. Today, organizations are better at stopping loud attacks but have barely moved the needle at all against the quiet ones. This data, and a lot more, comes straight from the newly published Blue Report 2026, the fourth annual comprehensive study from Picus Labs.

Four corporate investigation mistakes organizations make under pressure
In this Help Net Security video, Christine Gadsby, VP and Chief Security Advisor at BlackBerry, explains why corporate investigations go wrong before the forensic team arrives. The first hours matter more than leaders assume. Access gets granted, conversations start, and decisions get made that later affect chain of custody, privilege, and how regulators judge the process.

How to report an AI Act violation in the EU
The EU’s fight to regulate AI models entered a new chapter on 2 August 2026, when the European Commission’s AI Office and national authorities began enforcing the AI Act. It creates a common set of rules for AI systems used or sold in the EU, with the goal of encouraging innovation while protecting people’s safety and fundamental rights.

Chainloop: Open-source evidence store and policy engine for the software supply chain
Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable storage, and references each one in a signed in-toto attestation. in-toto is a specification for recording who ran which step of a build, so the record can be checked afterward.

Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users
Microsoft is changing how Entra ID handles MFA for people who sign in with Windows Hello for Business (WHfB) or macOS Platform Single Sign-On (PSSO). The rollout reaches worldwide and GCC tenants starting early October 2026, with completion expected by late November.

Cyberattack on Steam hardware shipper leaks names, addresses, and order data
Video game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began surfacing on social media earlier today, after Valve started sending out data breach notification emails.

Previously unseen entry vector used to breach Polish energy plant
The December 29 cyberattack on a Polish combined heat and power (CHP) plant was the first observed case of attackers gaining access to an OT network through a private APN, according to CERT Polska. The private APN is a dedicated mobile network that a Distribution System Operator (DSO), the company running the local electricity grid, sets up with a mobile carrier.

GPT-5.6-Cyber refuses security researchers’ requests far less often
GPT-5.6-Cyber is a new OpenAI model built on GPT-5.6 Sol, trained to find zero-day vulnerabilities and build exploit chains, with fewer refusals on higher-risk, dual-use work. Model is available only through Daybreak Red, the higher tier of OpenAI’s vetted access program for cybersecurity professionals.

Ransomware gangs don’t need control system access to disrupt industrial production
Disrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access to industrial control systems (ICS), according to Dragos. The company identified 1,140 ransomware incidents involving industrial organizations in the second quarter of 2026, up 12% from 1,020 in Q1.

Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G
Researchers have found that compromised or malicious SIM cards can issue commands to some smartphones and cellular-connected devices, allowing attackers to steal information, disrupt communications, downgrade connections to 2G, and in some cases execute code.

Ready-made $500 kit puts a crypto scam within anyone’s reach
A seller on a cybercrime forum is offering a ready-made scam kit for $500, complete with an admin panel that tracks victims, checks their crypto wallets for value, and inflates fake balances to squeeze out more money, Malwarebytes found.

Split-second deepfake glitch blows digital certificate fraudster’s cover
Spanish police have arrested a man in Murcia accused of using deepfake software to trick a certificate provider’s video identity checks in an attempt to obtain digital signatures he could use for financial fraud.

Lazarus hackers pair fake job offers with Windows zero-day exploit
The North Korea-linked Lazarus group is using fake job offers, trojanized PDF software and a Windows zero-day in attacks aimed primarily at the defense sector, Check Point researchers have found.

Signal’s new security feature checks if your encrypted chats were tampered with
Signal has introduced a feature called automatic key verification, giving users a new way to confirm that nobody has secretly interfered with their encrypted chats.

153GB of stolen credentials surface after LiteLLM supply chain attack
A massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. Hudson Rock says it obtained and analyzed the archive, which contains 433,909 files, and attributed 118,829 CI runner dumps to 2,488 corporate domains.

Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)
Threat actors have begun exploiting a critical Microsoft SharePoint flaw following the release of proof-of-concept (PoC) exploit code by Rapid7. Tracked as CVE-2026-55040, the vulnerability was patched by Microsoft as part of its July 2026 Patch Tuesday updates.

White House authorizes private US companies to hack foreign criminal networks
President Trump signed a National Security Presidential Memorandum on August 12 allowing vetted private companies to run offensive cyber operations against foreign threat actors, under the control and oversight of the US government.

Ukrainian police raid 94 fraudulent call centers, seize $2 million
Ukrainian police have disrupted 94 fraudulent call centers during a nationwide operation that involved more than 400 searches and the seizure of thousands of computers, phones, and SIM cards.

New Android malware relays bank cards to fraudsters while victims still hold them
Group-IB researchers discovered WindRelay, a new Android malware built to capture live payment card data over NFC (Near Field Communication) and relay it to attackers in real time. WindRelay is paired with the SpyNote remote access trojan, which gives attackers remote access to a victim’s device.

71% of CISOs spend 10+ hours on board reports
Boards want evidence that security controls and architecture reduce business risk, expressed in terms of resilience, consequence, and decision relevance. Translating technical findings into business language remains a major time burden for CISOs, who are calling for simpler data delivery, better frameworks, and better context. Pulse Security AI’s The CISO-Board Communication Gap report found that board members bring external information into discussions while many organizations still lack a formally defined cyber risk appetite.

Product showcase: Enpass Password Manager breaks away from the proprietary cloud model
Enpass is a password manager that stores passwords, passkeys, payment cards, identities, secure notes, software licenses, and other sensitive information in encrypted vaults. Vaults remain on the device or in a cloud storage service selected by the user.

OpenAI locks down Astra over potential critical cyber capabilities
OpenAI’s internal evaluation of its upcoming model, Astra, found significant advances in agentic coding and cybersecurity, leading the company to conclude that it cannot rule out the model reaching the critical capability level for cybersecurity under its Preparedness Framework.

Anthropic to put AI in charge of reviewing Claude Code actions by default
Anthropic will make auto mode in Claude Code the default for new sessions on Pro, Max, and Team plans starting August 14. Users who previously selected a different default may receive a one-time prompt asking whether they want to switch to auto mode.

Your security vendor gets the frontier cyber model, you get the findings
Selected red team specialists can now use OpenAI’s cyber models to find and exploit weaknesses in client applications and infrastructure. Those clients never get the models themselves. That split is the design of the Daybreak Cyber Partner Program, which OpenAI expanded on August 10: access to the underlying models stays with the approved partner and is not transferred directly to the customer.

Locking your ssh-agent exposed local-only keys until OpenSSH 10.5
Lock your ssh-agent and it should sit there refusing to sign anything until you unlock it. In OpenSSH 10.4, locking it also switched off the check that tells the agent whether a request came from your own machine or arrived down a forwarded connection from a remote server. The fix shipped today in OpenSSH 10.5.

AI deployments are stretching enterprise security to its limits
CISOs and CTOs expect AI deployments to increase their organizations’ attack surface by an average of 14% over the next year. Nearly all lack visibility into AI deployments, and 90% are concerned about employees using unapproved AI tools outside formal oversight, according to NetFoundry’s 2026 State of Secure AI Access survey.

PentestGPT: Open-source automated penetration testing agentic framework
PentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon, then exploit, then walkthrough, each stage feeding the next. Switch it to pentest mode and the stages become asset discovery, vulnerability identification, report. No human sits in the loop.

Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily
Google Chrome’s latest measures against abusive web push notifications include automatically revoking notification permissions for inactive and suspicious websites, helping reduce scams, phishing attempts, and other deceptive content.

Wireshark 4.6.8 patches 28 security bugs, nine in file parsers
Wireshark 4.6.8 fixes 28 security bugs in the protocol analyzer, and nine of them fire when someone opens a saved capture file. Those nine sit in file parsers, the code that reads a capture off disk before any dissection begins: pcapng, Endace ERF, Tektronix K12xx, BUSMASTER, Catapult DCT2000, Gammu DCT3, 3gpp phone logs, TTX Logger, and, on Windows only, Ixia IxVeriWave and Vector Informatik BLF. An attacker never has to touch your network for these. They only have to get you the file.

Product showcase: Is this image real? Slop or Not investigates
Slop or Not is an AI text and image detector for iPhone and Mac that runs entirely offline, with no account required. It uses on-device AI models powered by the Apple Neural Engine to detect AI-generated content.

DDoS attacks hit record scale as 1 Tbps+ campaigns become more common
DDoS attacks grew in scale during the first half of 2026, bringing larger traffic floods, shorter attack durations, and increasingly automated campaigns. Cloudflare’s H1 2026 DDoS Threat Report shows threat actors relying on multi-vector techniques and large-scale network-layer attacks to disrupt online services across multiple industries.

17 draft Cyber Resilience Act standards are open for comment
A company selling a connected toy in Europe must show by the end of 2027 that the product meets the Cyber Resilience Act. The law states what manufacturers have to achieve and stops there, which leaves the toymaker to work out the technical detail alone. Seventeen draft standards, now open for comment, supply that detail.

Weak IAM affects up to 98% of cloud environments
Misconfiguration remains one of the leading threats to cloud environments because a single configuration error can result in public network access, unrotated keys, missing encryption, exposed services, and logging gaps. CISA now mandates baseline cloud configuration practices for US federal agencies.

The hardest part of agentic AI may be rebuilding the business
Organizations expect AI agents to change how work gets done, driving productivity and growth while allowing employees to focus on higher-value tasks. Few, however, have the processes and workflows needed to realize those benefits, according to Deloitte’s latest research.

AWS Certificate Manager sets 2027 end date for email-validated certificate renewals
AWS Certificate Manager (ACM) will phase out email validation for public certificates throughout 2027, ahead of the Certification Authority/Browser (CA/B) Forum’s March 15, 2028 deadline for ending email-based domain validation.

OpenAI’s GPT-5.6 Sol runs up to 14× faster with Ultrafast mode
OpenAI’s GPT-5.6 Sol on Ultrafast mode is available in limited preview to a select group of customers, launching first through the OpenAI API. The company says the service runs up to 14 times faster than Standard processing and generates up to 750 output tokens per second. Ultrafast is powered by Cerebras as part of the companies’ partnership on ultra-low-latency inference.

Cybersecurity jobs available right now: August 11, 2026
We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.

New infosec products of the week: August 14, 2026
Here’s a look at the most interesting products from the past week, featuring releases from A10 Networks, ScienceLogic, Searchlight Cyber, and SelectHub.


from Help Net Security https://ift.tt/acREltg

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of publication.

The era of the boombox as we knew it in the 90s might be over, but if you still want an audio powerhouse that’ll give you better sound than your average portable speaker, there are several options that fit the bill, along with modern features like the ability to float in water and lighting effects. The popular Anker Soundcore Boom 2 Plus Bluetooth speaker is one of them—and right now, it’s 32% off ($169.98, originally $249.99).

This speaker gets seriously loud thanks to two 50W woofers and two 20W tweeters, delivering up to 140W. This is enough to create immersive sound during a backyard or pool party, camping trips, and beach get-togethers. PCMag, which gives it an Editors’ Choice Award, says it has a “powerful low-frequency response” and gives “serious thump” with plenty of bass. When BassUp 2.0 mode is activated (it’s on by default), the sound gets even bassier. Battery life lasts up to 20 hours with BassUp off and volume at 50%. 

The Soundcore Boom 2 Plus has an IPX7 rating that lets the speaker be submerged up to a meter for 30 minutes, and it even floats. Despite being mostly plastic, the speaker still has a rugged build. While it clocks in at 8.4 pounds, a removable, adjustable strap and built-in handle make it easy to carry around. The standout feature that sets it apart from similar speakers in its class is the bright, customizable LED lights that pulse with the beat of the music. The app controls both the sound and the lights, allowing you to further customize colors. 

If you’re craving robust audio that can hold its own outdoors, a rugged build, and fun lighting effects to set the vibe, the Anker Soundcore Boom 2 Plus has the right combination of features, making it a go-to for indoor and outdoor use. At its lowest price yet, this portable party starter should be on your radar.

Our Best Editor-Vetted Tech Deals Right Now
Deals are selected by our commerce team

from Lifehacker https://ift.tt/6B12kRx

We may earn a commission from links on this page.

Based on Hugh Howey’s books, Silo is the perfect sci-fi show for the moment: Pessimistic about government, optimistic about the potential for individual courage and heroism, and crammed full of dark mysteries. Every episode peels back a tiny bit of the curtain obscuring the truth from both the audience and the residents of Silo 18, the huge underground bunker hosting part of what’s left of humanity after a global cataclysm, and it’s a thrill to find out just how awful the secrets actually are. If you’re looking for more of that in your life, and you’ve already watched all the other grim sci-fi series scratching that itch, there’s one movie you should check out: 2013’s Snowpiercer.

Why you should watch Snowpiercer after Silo

We also suggested the TV series as a streamalike, but it’s well worth it for Silo fans to dive into the theatrical film as well. The movie is tighter and darker than the series, and Chris Evans’ performance as Curtis is ferocious—he’s a man haunted by his own secrets and willing to burn everything down to discover the bigger ones that drove him to desperation.

Like Silo, Snowpiercer is set in an enclosed, self-sustaining environment that might support the last remnants of humanity. After an attempt to reverse climate change accidentally ushers in a new ice age, a small group of survivors exists on a huge bullet train, the Snowpiercer, that continuously circles the globe. Like the Silo, the train is divided into sections that represent strata of society: In the rear, packed in tightly and living in squalor, are the poor, and as you advance closer to the engine, everyone gets richer and more comfortable. And like Silo, a rebellion stirs up the dark secrets behind everything on the train, leading to one of the darkest revelations ever uncovered.

Snowpiercer matches Silo’s tone, look, and feel so closely you might wonder if the train exists in the same universe, if Juliette (Rebecca Ferguson) is going to pop out of a manhole at some point and stare incredulously at the train speeding by. And at the core of both the series and the movie is a firm belief that while human beings may accept levels of conformity and control in exchange for perceived security for a while, they will always ultimately demand their freedom—and the truth. Stream Snowpiercer on Kanopy, Hoopla, Tubi, or Hulu, or rent it on Prime Video.

More movies to watch after Silo

Need more movies that will convince you the future might be worth saving, but won’t be any fun? You’re in luck: There are lots. Here are some of the best alternatives after you’ve watched Snowpiercer.

I Am Mother (2019)

Want more apocalypse mystery box? Watch I Am Mother. In a sleek, modern bunker, a young girl is raised from an embryo by a sentient robot called Mother. Named Daughter, the girl is drilled in lessons centered on morality and ethics in preparation for an upcoming exam and is forbidden to leave the bunker because of supposed “contamination” outside. When she hears a woman pleading for assistance through the airlock, Daughter lets the stranger in—setting in motion a chain of events that reveal the truth to her. Just like Silo, Daughter soon learns that her life isn’t what she thought it was, and that she has fewer choices than she’d hoped. Stream I Am Mother on Netflix.

The Platform (2019)

If it’s the extended metaphor about existence and society that you love about Silo, this Spanish horror film is the perfect choice. A man named Goreng wakes up in cell 48 in a mysterious vertical prison. He soon learns that every day, a platform in the center of the cell descends from above, laden with enormous amounts of food. The platform stays for two minutes, and the occupants of each cell can eat as much as they can during that time but will be killed if they try to hoard any food. Each month, the prisoners are randomly reassigned to a new level—and the lower you are, the less likely there will be enough food left to survive on. It’s grim, but as Goreng tries to find ways to fight back, the secrets of another vertical sci-fi puzzle are slowly discovered. Stream The Platform on Netflix.

High Rise (2016)

Silo explores, in part, the nature of civilization and the necessity of control—can people be trusted to govern themselves, or must they be lied to and manipulated to ensure survival? High Rise, based on the classic novel by J.G. Ballard, follows Dr. Robert Laing (Tom Hiddleston), who moves into a luxury London apartment building in 1975. The building is the epitome of modern convenience, and is stratified by class—the wealthy live on the upper floors, and the poorer tenants down below. Over the next few months, the mini society in the building breaks down as services stop, the power becomes unreliable, and violence breaks out, seemingly without any intervention from outside. It’s a paranoid story set in a shelter that’s actually a trap, a setup that will be familiar to Silo fans. Stream High Rise on Kanopy, Hoopla, or Tubi, or rent it on Prime Video.

Logan’s Run (1976)

Population is a big concern for Silo—controlling it, limiting it, planning for it. Logan’s Run (based on the novel by William F. Nolan and George Clayton Johnson) is the goofy 1970s sci-fi answer to that, set in a post-apocalyptic future where humanity lives in a sealed city run by a computer. Resource scarcity and overpopulation are solved by the ritualistic execution of every citizen at age 30. Citizens are told they will be reincarnated after this, and it’s enforced by “Sandmen” who hunt anyone who resists their fate. Sandman Logan 5 (Michael York) is ordered to find and destroy a secret place where “runners” are hiding, and finds himself designated for execution as a grim bit of motivation, and decides that he’ll take his chances as a Runner, seeking to find out what’s really outside the city’s dome. Stream Logan’s Run on Hoopla, Plex, or Tubi, or rent it on Prime Video.

Soylent Green (1973)

Even if you’ve never seen it, you probably already know what Soylent Green is made of. Another classic 1970s sci-fi movie concerned with overpopulation, Soylent Green (based on Harry Harrison’s 1966 novel) doesn’t have the dark, constricted setting of Silo, but it has all of its sense of building, violent pressure in a desperate population that’s being lied to. In the 21st century, overpopulation and climate collapse have left society barely functioning, with the elites living in fortified mansions sustained by slaves and the teeming millions surviving on ultraprocessed foods from the Soylent Corporation. Just like in Silo, it falls to a committed cop, NYPD Detective Robert Thorn (Charlton Heston being the most Charlton Heston he’d ever been), to investigate the horrifying truth. Rent Soylent Green on Prime Video.


from Lifehacker https://ift.tt/HecxJdq

If you use ChatGPT on your Mac, and you have the right type of account, you'll soon be able to start asking your bot questions about how you use your computer. As highlighted by 9to5Mac, OpenAI announced "Computer History" on Thursday, a new feature that lets ChatGPT keep a history of actions you take on your Mac.

As OpenAI pitches it, you'll be able to ask ChatGPT about projects you recently worked on, request details about your work "patterns," and turn frequently used tasks into automations. For example, you could ask ChatGPT "What was I working on before I took a break?" and, with Computer History enabled, it can look through your recent activity to deliver your answer. You could also ask about files you remember looking at, but can't find, e.g., "Where is that planning document I was looking at this morning?"

How ChatGPT's Computer History works

Unlike something like Windows Recall, Computer History doesn't actually take screenshots of your Mac's display to work. It also doesn't record your screen or tap into microphones or system audio. Instead, the feature collects data from the sources you allow it to see. Every time you click, type, use a keyboard shortcut, and switch an app, Computer History takes note. It even watches out for "context" from macOS accessibility processes to inform its records. OpenAI says that Computer History will occasionally save this data as both text summaries and local memory files.

The good news for the privacy-minded is that Computer History is opt-in by default. That means it won't work until you manually enable the feature. Even when you do, Computer History won't track everything you do out of the box: You'll be able to choose which apps and sites ChatGPT keeps tabs on, and you can pause "collection" from the menu bar at any time. Private or incognito browsing is never recorded either. There are separate controls for workspace access, personal opt-in, memories, and apps and sites, and you can adjust all of these settings at any time.

In addition to asking ChatGPT directly about your history, you can manually review the data the feature collects yourself. Under Settings > Computer history > History, you'll find the local memory file for summaries, options to delete individual items, and the ability to clear a specific timeframe of history, similar to how clearing your history works in a web browser.

Is ChatGPT's Computer History secure?

The short answer? No. While OpenAI is adamant that the feature stores your data in secure locations away from other apps, it acknowledges that the feature can and does store sensitive information without encryption. As such, programs running as your macOS user may be able to access these files. What's more, the company is open about the fact that Computer History increases your risk of prompt injection attacks, as ChatGPT may follow malicious instructions it sees on the apps and websites it's tracking.

OpenAI also processes some of these files on its server in order to generate memories. The company says it doesn't save those files after processing unless required by law, and claims it doesn't use them for training. That said, OpenAI may scrape chat content that uses one of these processed memories in a future chat for training, if you allow the company to train its models off your ChatGPT data.

As with AI browsers, there are likely steps you can take to limit your risk exposure while using Computer History, but as it stands, it seems those risks far outweigh the benefits. You might like a feature like this if you frequently forget what you were working on earlier in the day, or if you're looking for an objective analysis of how you use your Mac. But I think there are other systems you can use to stay on task that don't expose you to a privacy invasion or, even worse, a cyberattack.

How to turn on Computer History in ChatGPT

If you're interested in trying this feature out, it's easy to enable—assuming you're under the right ChatGPT plan. OpenAI says that Business or Enterprise workspace users will need administrator approval first. If you're a personal ChatGPT user, you'll need to subscribe to ChatGPT Pro for access.

Assuming you meet one of the above qualifications, you can get started by opening ChatGPT's Mac app, then, in Settings, head to Integrations > Computer history. Here, choose "Turn on," then review all permissions and settings. You will need to turn on "Memories" if it isn't enabled already, as the app uses the feature for context as you move through chats and tasks. Finally, choose the apps and websites Computer History will track, and enable any macOS permissions required.

Under Settings > Computer history > Permissions, you'll find options for "Exclude these apps," "Exclude these websites," "Include only these apps," and "Include only these websites" that will let you fine-tune Computer History's tracking to a degree. You can also pause or stop Computer History at any time from your Mac's menu bar.


from Lifehacker https://ift.tt/3e8Ybn2

This is a current list of where and when I am scheduled to speak:

  • I’m speaking, signing books, and participating in panel discussions at LAcon V in Anaheim, California, USA. My full schedule is here.
  • I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026, at 5 PM ET.
  • I’m speaking at Elevate Festival in Toronto, Canada. The conference runs September 22–24, 2026; my talk is on Wednesday, September 23.
  • I’m speaking at CanSecWest 2026 in Vancouver, Canada. The conference runs September 30–October 1, 2026; the time of my talk is TBD.
  • I’m speaking at ATTENTION: Democracy, Rebuilt in Montreal, Canada. The event runs October 21–23, 2026, and my talk is on Wednesday, October 21.

The list is maintained on this page.


from Schneier on Security https://ift.tt/vdUyICG