βοΈThunderbolt is finally coming to Linux on Apple Silicon thanks to volunteers who reverse-engineered it, without help from Apple.
Asahi's Sven Peter posted the first USB4/Thunderbolt driver for M1, M2 and M3 to the kernel list yesterday, after years of reverse-engineering.
Source: https://lore.kernel.org/asahi/20260830-b4-apple-soc-tbt-v1-0-44bc9348683c@kernel.org/
Asahi's Sven Peter posted the first USB4/Thunderbolt driver for M1, M2 and M3 to the kernel list yesterday, after years of reverse-engineering.
Source: https://lore.kernel.org/asahi/20260830-b4-apple-soc-tbt-v1-0-44bc9348683c@kernel.org/
π₯39β€8π©3π2
Anthropic has been misleading people with the Max plans: it has been advertising the $200 plan as 20x and the $100 plan as 5x. You'd expect to get 4 times more usage with those figures, but it turns out it's only 1.7x.
You pay twice the price, for 1.7x the usage. And yet they've literally been marketing it as if you're saving 50% (see screenshot below).
The usage figures Anthropic gave in July 2025 were 140β280 Sonnet hours at 5x and 240β480 at 20x.
Turns out that multiplier only covers the daily 5-hour session window. So in the end, if you take weekly cap into account, you pay more per hour with the 20x than with the 5x.
You pay twice the price, for 1.7x the usage. And yet they've literally been marketing it as if you're saving 50% (see screenshot below).
The usage figures Anthropic gave in July 2025 were 140β280 Sonnet hours at 5x and 240β480 at 20x.
Turns out that multiplier only covers the daily 5-hour session window. So in the end, if you take weekly cap into account, you pay more per hour with the 20x than with the 5x.
π©37π5π―4β€2π₯°1π1
βΌοΈ Cronos halted its blockchain after a price-manipulation attack let an attacker borrow $74 million from the Tectonic lending app
The network is back online and says the chain state was rolled back to before the exploit
PeckShield says only about $6 million in Ethereum left the chain; the rest is stuck on Cronos
The network is back online and says the chain state was rolled back to before the exploit
PeckShield says only about $6 million in Ethereum left the chain; the rest is stuck on Cronos
π€£14π4β€1π€ͺ1
π¨ BREAKING: Qilin has briefly published 6.3GB of data the ransomware group says it stole from the ATF, after a 72-hour countdown expired.
Files include Cellebrite extractions, dumps from an iPhone 6 and a Samsung Galaxy J3, and case folders naming investigation targets, phone numbers and IP addresses.
ATF is still investigating the claims and has not confirmed a breach.
Files include Cellebrite extractions, dumps from an iPhone 6 and a Samsung Galaxy J3, and case folders naming investigation targets, phone numbers and IP addresses.
ATF is still investigating the claims and has not confirmed a breach.
1β€14π±2π€£1
Security researcher Zachi says he found an exploit in an app and reported it.
After two months with no reply to his bug report,
he tried again β this time by emailing the vendor from its own email address, with the message: "I'M WRITING TO YOU RIGHT NOW FROM YOUR OWN EMAIL."
After two months with no reply to his bug report,
he tried again β this time by emailing the vendor from its own email address, with the message: "I'M WRITING TO YOU RIGHT NOW FROM YOUR OWN EMAIL."
π€£38β€6π4π₯1π©1
βΌοΈBREAKING: Nearly 22,000 Microsoft Exchange servers still miss the fix for a critical vulnerability that gets attackers into mailboxes without a password, Shadowserver says
The proof-of-concept exploit code is publicly available and easy to abuse.
Read:
https://shadowserver.org/what-we-do/network-reporting/vulnerable-exchange-server-report/
The proof-of-concept exploit code is publicly available and easy to abuse.
Read:
https://shadowserver.org/what-we-do/network-reporting/vulnerable-exchange-server-report/
π9π₯6π€£4π1π1
βΌοΈ Many X users got password-reset emails they never requested, fortunately X engineer Mridul Singhai says there is no evidence of a breach
He says attackers appear to be targeting accounts now X Money is widely available
You can use X's Password Reset Protect setting against these attacks
He says attackers appear to be targeting accounts now X Money is widely available
You can use X's Password Reset Protect setting against these attacks
π€£20β€1
βΌοΈ BREAKING: We now know what led to the major breach at Manchester Airports Group that exposed 8.7 million people's data. Turns out they made a serious error: they put API keys with access to everything in their frontend's JavaScript files.
π€£35π5π3π₯΄2
π¨ BREAKING: Defense Secretary Pete Hegsethβs driverβs license has leaked. A new dark-web service is selling scans of his and 153M+ U.S. and Canadian driverβs licenses.
Timestamps on the scans match victimsβ visits to Hertz rental counters and cannabis dispensaries. Evidence points to idscan[.]net, an ID-verification vendor used by Hertz, Target, FedEx and 1,000+ dispensaries.
The FBI opened an investigation on Tuesday. Nexus claims it has been exfiltrating for over a year and added ~400,000 licenses in 24 hours.
https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
Timestamps on the scans match victimsβ visits to Hertz rental counters and cannabis dispensaries. Evidence points to idscan[.]net, an ID-verification vendor used by Hertz, Target, FedEx and 1,000+ dispensaries.
The FBI opened an investigation on Tuesday. Nexus claims it has been exfiltrating for over a year and added ~400,000 licenses in 24 hours.
https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
π€£37π¨6
π³π΄ Norway's privacy regulator wants smart glasses pulled from sale. As a first step, Norway's Digitalisation Minister Karianne Tung is weighing a ban on facial recognition of strangers in public rather than on the glasses themselves, and is setting up an expert group to propose rules this autumn for the cameras and AI now built into glasses, earbuds and caps.
1β€29π₯6π1