The Apple AirPods Pro 3 have just received a surprise price cut at Amazon, bringing the excellent premium earbuds down to just $189 (was $249) at the retailer.
That's the lowest price since the retailer's annual Prime Day mega-sale back in June, and likely the best deal we'll see for a while. Ever since Prime Day, these buds have stubbornly held at $199, which is the usual 'sales price' for Apple's premium buds.
Even though the record low is officially $169, the AirPods Pro 3 only hit that on one occasion over Prime Day, so today's price cut is definitely worth considering. Even at $189, the AirPods Pro 3 are an excellent buy for anyone looking for some high-end buds. Not only do they feature excellent noise cancellation, but they're packed with new features like heart rate monitoring and Live Translation.
The AirPods Pro 3 are cheaper today at Amazon
Amazon has dropped Apple's AirPods Pro 3 to $189.99, which is the best deal I've seen on these buds in well over a month. Upgrades to the AirPods Pro 3 include improved Active Noise Cancellation and audio, a new comfortable in-ear design, and new features such as live translation and the ability to track heart rate, workouts, and calories burned.View Deal
We awarded the buds an impressive four and a half stars out of five in our AirPods Pro 3 review, calling them 'near-perfect noise-cancelling earbuds' at the time. While not exactly cheap, they offer excellent noise cancellation and sound quality.
If we had to draw any criticisms, we'd mention that the AirPods Pro 3 don't have class-leading battery life (around 5.5 hours in our testing). You'll also need one of the latest iPhones to really take advantage of their full suite of features like Live Translation and personalized fitness insights. They're still great with older devices, but iPhone 15 and newer devices support Apple Intelligence, which is required for the newest bells and whistles.
Distillation sidesteps the logic of US export controls, which restrict the chips needed to train frontier models but cannot restrict the text those models produce
Review of more than 80 Chinese papers and patents found PLA-linked researchers distilling outputs from OpenAI and Anthropic models into small systems they can run locally
The Trump administration is increasingly critical of the approach and has claimed Chinese research lab-created Kimi K3 distilled Anthropic's Fable model
A new investigation has claimed Chinese military researchers have used outputs from American AI models built by OpenAI and Anthropic to train domestic systems intended to advance the country's defense capabilities.
The findings are based on a Reuters review of more than 80 Chinese academic papers and patents, incorporating research compiled by the Washington-based Jamestown Foundation shared exclusively with the news agency.
Reuters says it independently verified the literature and found a further two dozen military-linked case studies of its own.
A distillation problem in an AI race that continues to heat up
The mechanism at issue is model distillation, in which the outputs of a large, capable system are used as training data for a smaller one. The smaller model inherits selected behaviors at a fraction of the compute cost and, crucially, can run on modest local hardware.
That is the strategic point. Washington's export controls are built to deny China the chips needed to train frontier models. Distillation does not need those chips, because the expensive part has already been paid for by someone else. It sits alongside Beijing's other route around the controls: substituting domestic silicon for American designs, a shift that carries its own long-term threat to Nvidia and AMD.
Sunny Cheung, the Jamestown fellow who analyzed more than 60 of the papers, frames the value as reasoning rather than answers. Getting a model to produce the right output is comparatively easy, he told Reuters, but "teaching it the reasoning behind the answer is much harder."
The papers, on his reading, show Chinese military-linked researchers trying to move that expensive proprietary reasoning into small systems they can control and deploy themselves.
The asymmetry points at what is wrong with the US instrument. Export controls regulate objects: chips, tools, hardware that crosses a border and can be counted. The thing being transferred here is text a model produced- which crosses no border in any customs sense and cannot be enumerated.
The White House has registered the problem at both the chip and distillation end, but registering it is not the same as having a lever. For now, the debate over whether distillation is theft or standard practice may matter less than the fact that neither answer offers a workable control.
Bitdefender reported Roblox players lured by a fake “undetected” Xeno Executor mod spreading malware
Infection chain delivers a Java‑based RAT and infostealer stealing browser data, online accounts, payment info, and crypto wallets
Malware also enables surveillance and remote control; campaign peaked in March 2026 and remains active against Roblox’s 82M players
Cybercriminals are targeting Roblox players with an infostealer and a Remote Access Trojan (RAT) malware that grants them full control over compromised computers, experts have warned.
Roblox is an online gaming platform, virtual universe, and game creation system where users play millions of games and user-generated mods. Among the mods is Xeno Executor, a utility that allows players to run scripts that automate certain actions or run custom code. Some players use Xeno Executor to run cheats, too.
Since it’s an unofficial script, Roblox does not allow it and blocks it whenever a new version is released. Now, security researchers Bitdefender have reported finding an “undetected” version being promoted on various gaming forums, Discord communities, and similar.
CornFlake and CocoShell
This version is advertised as “invisible” to Roblox’s anti-cheat systems, but in reality, all it does is trigger an infection chain that ends in a Java-based RAT and information stealer.
The malware grabs browser data such as passwords and cookies from some of the most popular browsers (Chrome, Edge, Brave, Opera, Vivaldi), as well as online accounts and payment data (Discord, Roblox, Minecraft, Microsoft Store tokens, and more).
It also steals cryptocurrency wallet data, particularly targeting the Exodus Wallet.
As for surveillance, it can log keys, track mouse movements, grab screenshots, stream whatever is on the desktop, and access the webcam. The crooks are also granted file upload and download, PowerShell command execution, and more.
The campaign was kicked off at the start of the year, reaching its peak in March, it was said. It has now stabilized and is still going relatively strong.
We don’t know exactly how many players fell victim to this campaign, but Roblox is an incredibly popular platform, so it is possible the campaign was rather successful, too.
According to Activeplayer, Roblox currently has more than 82 million active players.
HDR isn't back in affected countries, but Disney+ is working on it
Affected customers can contact Disney+ to request a partial refund
Disney+ has begun restoring 4K support for Disney+ subscribers in Europe after being forced to remove 4K and HDR in some countries last week. That's good news, but it may cause issues on some devices, and HDR hasn't yet returned in the affected areas.
As Disney+ told us: "We have adopted an alternative technology to enable 4K UHD and HDR following a recent court ruling and have begun restoring 4K UHD support on Disney+. This may cause 4K UHD to be unavailable on some devices. We recognise the inconvenience this may cause and are working to increase device support for 4K UHD and restore HDR as quickly as we can."
What's happening with Disney+ 4K and HDR
Disney+ removed 4K and HDR from its Premium plan in Austria, Belgium, Denmark, Finland, France, Germany, Italy, Netherlands, Portugal, Romania and Sweden. Both features are still available in all other countries where Disney+ operates, and the removal only applies to streaming: downloads aren't affected.
The removal was the result of a court ruling, and while Disney+ doesn't go into detail about that, it looks like another video streaming patent dispute, hence the adoption of a different 4K technology to bring 4K streaming back. HDR is next on the menu, with Disney+ explaining that "We are working to restore it as quickly as we can but cannot yet confirm when it will become available again."
If you're a subscriber in one of the affected countries and HDR is a deal-breaker, Disney+ says that you can switch to a different, cheaper plan. If you want to stay on Premium but aren't happy with the loss of features, you can "request a partial refund for [your] current billing period by contacting Disney+." That only applies to direct subscribers; if you've subscribed via a third party, such as an App Store, you'll need to contact that company instead.
As I've written previously, removing the features wasn't something Disney+ chose to do; it was compelled to do it after a court case. Video and streaming patents are very complicated, and patent owners can be highly litigious, and we've seen a flurry of similar cases across the biggest multiple streamers in recent years. There's an old saying in the entertainment industry: where there's a hit, there's a writ.
Thinking of buying a new TV?
Try our TV size and model finder! You tell it how far you sit from your TV, we'll tell you what size to buy based on viewing angle advice from image quality experts, and we'll recommend our three top TVs at that size for different prices.
Palantir moves AI computing from distant clouds directly into combat zones
Containerized data centers process battlefield intelligence without permanent cloud connectivity
Nvidia B300 accelerators power deployable AI systems for frontline operations
Palantir Technologies and its infrastructure partner Armada have begun deploying mobile data centers built inside standard shipping containers for combat zones.
Each unit carries its own computing hardware, storage arrays, networking gear, and cooling systems needed to run advanced artificial intelligence models.
The servers run on Nvidia's B300 AI accelerators, while Palantir's modular AIP platform links the models directly into operational workflows and other company tools.
Processing power without a constant cloud link
Chad Wahlquist, a Forward Deployed Architect at Palantir Technologies, appeared inside one containerised data center during the July 2026 announcement introducing the mobile computing platform.
Unlike conventional cloud-based systems, these containerized units can process information without maintaining any constant connection to public cloud infrastructure.
They can also be fully isolated from external networks whenever operational security requirements demand a stricter level of separation at all times.
The outcome is a self-contained computing node able to analyze intelligence and sensor data right at the point where it is collected.
Distributed computing also offers stronger resilience than depending entirely on one single, centralized data center to run every operation across a wide area.
Losing contact with the cloud, or even losing one mobile node entirely, would not necessarily shut down the whole system.
Other units could keep processing information locally, since the entire network does not depend on one central point of failure.
Bringing AI closer to the battlefield
For military users, the concept brings advanced artificial intelligence much closer to sensors, field commanders, and units already deployed on the ground.
This reduces dependence on communications links that remain vulnerable to jamming, interception, or outright physical destruction during active combat operations.
Instead of sending every piece of battlefield data back to a distant cloud, analysis can occur inside a deployable container placed close to the action.
Alex Karp, the billionaire co-founder and chief executive of Palantir, has praised Ukraine's wartime innovation cycle as instructive for allies.
He has argued that the war is exposing a widening gap between military theory and the reality of modern combat.
Karp credited Ukrainian engineers and soldiers with adapting battlefield technology at a pace unmatched by most peacetime institutions worldwide.
He suggested that this rapid development cycle is teaching the United States and Europe lessons unavailable in traditional laboratories or think tanks.
Whether these containerized AI systems truly perform as promised under sustained combat stress remains an open question.
As of the time of writing, there is no public independent verification of the technology's actual battlefield performance by Palantir, Armada, or any military partner.
During my years as a TechRadar Homes Editor, I tested an awful lot of vacuums. But the one that's been my constant companion throughout has been the Dyson V15 Detect. It's not a review sample — my partner bought it, and it's the vacuum we've been using at home for the past 21-plus months. It's been used to clean hard tile floors, carpets, lots of stairs, and a whole heap of dog hair.
The V15 is not the newest Dyson vacuum. It came out in 2021 and there are now two newer flagship models: the Gen5detect (launched 2022) and the V16 Piston Animal (2025). However, despite not being the latest-and-greatest, it's still the model that sits atop our best Dyson vacuum guide.
So after nearly two years of regular cleaning with the V15, would I still recommend it? How does it match up against the rest of the best cordless vacuums on the market — and specifically, the newest models from Dyson's great competitor, Shark? Here's my long-term review.
Smooth mover
Let's start with what I love about our Dyson dust-sucker. The suction is excellent, and the Auto mode (where the suction will increase or decrease depending on how much dirt is detected on the floor) is a very welcome addition. I use this mode almost exclusively, and it can be relied upon to do a thorough job of clearing whatever debris has gathered on the floor. I haven't noticed a drop in cleaning performance over our two years of use.
The V15 is also extremely easy to maneuver. Our home has lots of stairs, and plenty of nooks and crannies where dust and hair like to collect and lurk, and the V15 Detect does a great job of getting into all of them. I love how easily and smoothly the head pivots, and the fact it can lie completely flat to the ground for cleaning under beds.
Many of the newest Shark vacuums have a hinge on the vacuum wand, which enables it to bend forwards for cleaning under furniture. It works well, but adds bulk to the wand, and the whole thing is slightly unwieldy in its folded state. For my home, the Dyson setup works perfectly well, but if you're lacking in maneuvering room, perhaps Shark's 'MultiFlex' / 'Flexology' solution would be a better fit.
The hidden crevice tool is a lifesaver in my tall home (Image credit: TechRadar / Sharmishta Sarkar)
I'm also a huge fan of the Dyson V15's secret crevice tool. It's hidden in the wand, so I'm never without it. Our house is tall and thin, with four floors, and this built-in tool means that if I spot a dusty corner at the top of the house, I don't have to traipse all the way down to the utility room to fetch a detail tool to deal with it. As far as I'm aware, this feature is exclusive to Dyson at the moment.
Having tested a number of vacuums from Dyson and various other brands, I'm always struck by how consistently high quality and well-built the Dyson vacs feel. There's a strong attention to detail in the design, and they feel sturdy and reliable. That's still true of the V15 after nearly two years of use.
Lasers and data
Now on to a couple of features that have divided opinion within my household. The V15 comes with a couple of different floorheads: the Digital motorbar head, which has bristles and is designed for use on any floor type, and the Fluffy optic head, which is entirely soft and built for use on hard flooring. The latter is equipped with a green light to illuminate dust.
I love using the light on the soft floorhead to chase down dust bunnies (Image credit: Future)
I'm very on board with the Fluffy floorhead. I love that it feels gentle on our tiled kitchen floor (and doesn't clatter over it as most vacuum cleaner heads will), and I appreciate the way the light draws attention to dust and hair lurking in dingy corners. I find it very satisfying to then whisk that dust away, and always feel I'm getting a far more thorough clean than I would without this feature.
However, my partner is not so enamored with the Fluffy floorhead. He feels the Digital motorbar floorhead works perfectly well on hard floors, and it's not worth the hassle of swapping the heads over.
Both the V15 and the Gen5detect (pictured) have real-time dust reports (Image credit: Future)
Then there are the real-time dust reports on the screen. I find these endlessly fascinating, and I enjoy seeing the dust hotspots causing the bar graphs to spike. However, when I asked my partner for his thoughts, it became clear that not only was he not paying them any attention, but he didn't really know what they were. Is is possible the general public is just not as invested in the intricacies of vacuum cleaning as I am? Maybe.
Bulking up
Moving on to the down-sides of the V15. The most significant complaint I have with it is that V15 Detect is that it's pretty heavy. Further to that, the weight is concentrated in the main motor section, which itself is rather elongated in shape. That makes it rather unwieldy, and especially when used in handheld mode.
The V15 (background) and newer Dyson vacuums have a rather heavy, elongated motor section, which can make them a little awkward to use (Image credit: Future)
All of Dyson's newer vacuums (I'd say from this model onwards — so the V15, the Gen5detect and the V16 Piston Animal) suffer from this weight distribution issue.
Looking to Shark's range, the fancier models, such as the PowerDetect Cordless, are actually heavier overall. However, the motor/handle section is more squat in shape, and there's more weight through the wand and into the floorhead. That means more even weight distribution, which can make for a more comfortable vacuuming experience.
A triggering issue
Another big complaint I have with the V15 is that it's trigger-operated, with no option to lock it for continual running. I find that irritating when I'm using the vacuum for long periods, or trying to get into awkward corners while keeping the trigger compressed.
I prefer the setup on Dyson's newer models, where there's a one-press power button. However, that's still not perfect — it requires you to have a hand free to turn the machine on and off, because the power button is not reachable from your holding hand.
Most modern Shark models use button operation, and just like the Dyson designs, you can't reach the button from your holding hand. My ideal design is one where the vacuum is trigger-operated but with a lock for continual running. No Dyson vacuum has this setup, and neither do any of Shark's newest stick vacs, although that brand's range is so sprawling you might find a trigger-plus-lock design somewhere.
The V15 (foreground) switches on and off with a trigger on the handle — which can be frustrating when using it for longer cleaning sessions (Image credit: Future)
One comment that I hear sometimes about Dyson stick vacuums is that they don't always last as long as customers expect. Our V15 is still going strong after just under two years (which is actually at the lower end of how long cordless vacuums are meant to last, although most people would probably hope for longer).
Prior to that, my partner had a Dyson Cyclone V10, which lasted over five years. At that point the battery conked out, and replacing it only fixed the issue for a few months. I think that's a decent lifespan for a vacuum, but your mileage may vary.
Is it worth it?
After two years using my Dyson V15, I'd still recommend it. Its cleaning powers are excellent with no signs of fading, its special features genuinely useful, and I love how maneuverable it is.
I personally also prefer it to Shark's newest models. I cover my main thoughts on this in my Shark vs Dyson article, but as a short overview, it's special features feel superior — Dyson's laser lights are far more effective than Shark's headlamps, and its Auto mode feels more precise. The Dyson also pivots more smoothly and the overall design feels sleeker and more high-end.
However, it's not a clear-cut decision. The Shark PowerDetect Cordless offers the best outright cleaning performance of any vacuum I've used, including all the Dyson models. Shark's models also arguably deliver better value for money — although its higher-spec models still sit in the premium price tier.
The bottom line? After using the V15 for a couple of years, and testing multiple other vacs from different brands including Shark, I'm still something of a Dyson fan-girl. When our at-home vac finally bites the dust, we'll probably end up buying another Dyson, although I will still be checking out what Shark has to offer...
Instructions hidden as white text in a Word document can make Microsoft 365 Copilot silently alter the file it is drafting and copy the instructions into the output
Each poisoned document becomes a carrier, so the attack spreads through ordinary internal workflows without the original malicious file and needs no macros, malware, or code execution
Microsoft has shipped two mitigations across a 144-day disclosure, including a model upgrade, and the attack was still reproducible by the researcher
A security researcher has published a proof of concept showing that instructions hidden inside a Word document can cause Microsoft 365 Copilot to silently alter the file it is drafting, then copy those same instructions into the finished document, so the next person to use it becomes a carrier too.
Håkon Måløy, a data scientist with a doctorate in applied machine learning, disclosed the technique as the third installment of his Context Collapse series, after a 144-day coordinated disclosure with the Microsoft Security Response Center.
The reason this is being reported ahead of a fix is that it still works despite multiple attempts by Microsoft, as he notes that no robust mitigation for the broader vulnerability class is currently available.
A clever attack designed around Copilot's approach to text
The underlying attack belongs to a family known as cross-domain prompt injection, or XPIA. An attacker writes instructions in a natural-language document, formats them as white text on a white background at a small point size, and shares the file.
Because Copilot for Word strips formatting before passing text to the underlying language model, the model reads text the human never sees. This is true even for documents that are not opened by the user on purpose: The attack can trigger either when a user manually attaches a document to Copilot or when Copilot, working in Work IQ mode, searches the user's OneDrive for relevant files and finds the malicious one on its own.
It is also more dangerous than other exploits because of one key element: propagation. The hidden prompt in Måløy's proof of concept had two parts. One instructed Copilot to alter the document being drafted, in his demonstration halving every financial figure in a quarterly report.
The other instructed Copilot to copy the prompt into the new document and conceal it, framed innocuously as source tracking and readability formatting. Copilot did both, appending the instructions in white text and mentioning neither action to the user.
The disclosure timeline is the most uncomfortable part of the report. Måløy reported to MSRC on March 6 2026. Microsoft confirmed the behavior on March 31 and shipped a first mitigation in early April via a reworked Edit with Copilot experience, which successfully blocked his original prompt wording. He reproduced the attack with different wording the same week, and a second case was opened.
The second fix, on July 14, consisted of upgrading the underlying model to GPT-5.5. Måløy broke it the following day using GPT-5.6, then voluntarily offered Microsoft a further two-week delay to attempt another mitigation. The class still reproduced on the disclosure date, indicating that although a fix is in the works, the exploit is still possible to run.
A complicated issue that lacks a proper resolution
The issue goes far beyond Microsoft Word: an AI assistant must ingest untrusted content to determine whether it is relevant or hostile. But the content enters the same context window as the system prompt and the user's actual request, so by the time the model evaluates whether the text is an attack, the attacker's tokens have already shaped that evaluation.
As Måløy puts it, "the content being inspected participates in the act of inspection."
Microsoft confirmed it had reviewed the findings in a statement to The Register but stopped short of indicating a timeline for a complete fix:
“We have addressed the findings reported by the researcher and thank them for working with us through coordinated vulnerability disclosure," the company said.
"To address this class of risk, we use a defense-in-depth strategy with safeguards that block malicious instructions at multiple points and help keep tasks aligned with users’ requests. We are continuously strengthening these safeguards as the technology and threat landscape evolve. We encourage customers to install the latest updates, use multiple layers of security protection, treat content from unknown sources with caution, and review AI-generated content before using or sharing it.”
Måløy's recommendations are to treat externally sourced documents as untrusted when using them with Copilot, review attachments before starting an AI-assisted draft, and review Copilot's output carefully before sharing or reusing it.
He also suggested that generated documents should carry provenance metadata that records source material and model edits, which would not prevent injection but would make an infection traceable after the fact.
With Copilot extending further into agentic products that create and manipulate documents with less human oversight, the scope of how exploits like this could affect workflows (and users) will widen rather than narrow, and a complete solution is not yet in sight.
Kaspersky says empty web pages are watching you, and the research backs up the warning
Over 90% of parked domains now send visitors somewhere malicious, and clearing your cookies will not help
Blank pages are also a problem: many 'Coming Soon' placeholders are quietly fingerprinting your device
Kaspersky has unveiled a rather underreported attack vector which is increasingly being used by threat actors to harvest private data from unsuspecting victims: registered websites that are yet to be developed.
Its warning focuses on parked domains, the registered web addresses that have no real website behind them yet, arguing that the blank screens and "Coming Soon" placeholders users dismiss as harmless are frequently doing work in the background.
The company says simply loading one of these pages can trigger silent collection of a visitor's IP address, approximate location, User-Agent string and cookie identifiers, and that operators go further by building browser fingerprints through other techniques, then feeding the result into advertising networks to assemble targeted profiles without consent from users.
Browser fingerprinting sans the permissions
The mechanics Kaspersky describes are worth understanding, because fingerprinting is the part most readers will not have encountered, and the part that conventional privacy habits do not touch.
For context, a cookie is a file placed on your machine that you can delete, thereby limiting tracking. A fingerprint is not stored on your machine at all. It is derived from how your specific hardware and software combination renders a test image, draws 3D graphics, or processes an audio signal, producing a value distinctive enough to identify the same device across unrelated sites.
Browser fingerprinting, the method used to capture such data within a browser session, is attractive to trackers because it is considerably harder to shake off. A private browsing window prevents your machine from keeping a local record of the visit, but it does not change how your hardware renders the test image, so the fingerprint it produces remains largely the same.
Such domains can also cause more direct damage than selling one's information to advertisers. Kaspersky says threat actors embed scripts that bounce visitors onward to fraudulent platforms, adult content, or online casinos. It flags typosquatting as a particularly acute risk, in which a domain differing from a well-known brand by a letter or two can capture mistyped traffic, landing the user on a phishing page or triggering a drive-by download.
This isn't the first time the problem has been reported, either, as recent research from Infoblox finding that in large-scale experiments, over 90% of the time, a visitor to a parked domain was routed to illegal content, scams, scareware, antivirus subscription traps, or malware.
Kaspersky recommends several ways to mitigate the risk, including avoiding suspicious links, clearing cache and cookies after an unintended visit, and using software that blocks web tracking.
Clearing cookies is worth noting, though: it addresses the cookie identifiers Kaspersky mentions, but by the company's own explanation it does nothing about fingerprinting, because there is nothing stored locally to clear.
Parked domains, including blank pages that appear inert, are now a routine part of criminal infrastructure rather than digital litter and should be treated with caution. At best, you give away more information than you meant to. At worst, you become the victim of an attack you never saw coming.