Tuesday, October 6, 2026


TECH


AI agents breach Dutch vulnerability disclosure group using chained Zammad zero-days

The Dutch Institute for Vulnerability Disclosure suffered a breach on September 21 when AI-driven attackers exploited two zero-day flaws in its Zammad ticketing system, stealing email addresses of volunteer researchers and escalating to root access within seconds.

The Dutch Institute for Vulnerability Disclosure (DIVD) confirmed on Thursday that automated AI agents compromised its infrastructure via two zero-day vulnerabilities in Zammad, the open-source helpdesk platform the non-profit uses for support ticket management.

The attack took place on September 21. The attackers chained CVE-2026-102489 and CVE-2026-102490—both carrying a combined CVSS 4.0 score of 9.4—to hijack sessions, execute code as the local 'zammad' user, and escalate privileges to root in seconds. DIVD discovered the intrusion the following day, cut off access to its data center systems, and engaged the incident response firm Merlon Security.

The breach exposed email addresses belonging to DIVD's volunteer security researchers. The organization warned that this creates an elevated risk of social engineering, as attackers can now more convincingly impersonate DIVD personnel. Anyone receiving suspicious contact from someone claiming an affiliation with DIVD should verify the claim via communications@divd.nl.

DIVD acts as a CVE Numbering Authority and assigned the identifiers itself. CVE-2026-102489 affects Zammad versions 6.3.0 through 6.5.4 and 7.0.0 through 7.1.3, although the vendor states that the 7.x branch is not exploitable due to environmental conditions. CVE-2026-102490 affects all versions of Zammad. DIVD urges all users to upgrade to Zammad 7 or take the software offline.

The offensive against DIVD highlights the evolution in the use of automated agents that operate using language models and task-execution modules. Unlike conventional scans—which follow static scripts to test for known vulnerabilities—AI agents attempt to interpret server responses, generate commands in real time, and dynamically iterate through potential weaknesses. This approach produces exploit traffic with unusual signatures, combining various probing techniques within a short timeframe.

For companies and security teams in Brazil, the significance of this case lies in the large-scale proliferation of this attack methodology. Corporate environments with internet-facing services, legacy portals, or inadequately protected APIs become targets of continuous, unstructured testing; this overwhelms Security Operations Centers (SOCs) with false-positive alerts and increases the risk of compromise due to basic configuration flaws.

The incident did not stem from a single zero-day vulnerability with a registered CVE identifier, but rather from a sequence of brute-force attempts, command injections, and tests for known flaws orchestrated by the agent. Common vectors for this type of agent include directory enumeration, the submission of varied payloads via HTTP parameters, and attempts to exploit exposed credentials or API keys.

The primary factor determining whether such an attack succeeds—or simply generates noise—is the direct exposure of services to the public network without edge-based behavioral mitigation. Environments that maintain accessible administrative interfaces and outdated systems, or lack request-rate limiting rules, end up absorbing the full testing cycle generated by the offensive agent.

An intruder that narrated Its own moves...In an update on Monday, DIVD described the attack as “loud and very very messy”. The agent chose each next step itself, at speed and with sloppy logic. At one point its password spraying disrupted its own adversary-in-the-middle attack.

It also over-explained its decisions in its comments. DIVD believes the agent was poorly trained and badly configured for the job and the trail it left is enough for investigators to reconstruct the intrusion.

The way in was an ordinary vulnerability in a system DIVD has not named. It has ruled out Citrix NetScaler whose two zero-days CISA added to its Known Exploited Vulnerabilities catalogue on 27 September.

What DIVD has not said yet...The purpose of the attack is unknown and so is what, if anything, the attacker took. DIVD is withholding technical detail so that it does not disturb the investigation or expose other organisations running the same vulnerable system and says it will notify them as soon as it can. A fuller update is due on 1 October.

Treat the agentic AI attack label as DIVD’s working assessment until then. It rests on how the intruder behaved, not on a recovered tool or a named model and nothing has been published that outsiders can check. The people making the call analyse intrusions for a living which counts for a lot. It does not replace the evidence.

Spain, ENISA and Microsoft flagged agent-driven attacks in September...DIVD’s case is not isolated. In mid-September Spain’s data protection agency, AEPD, said it had received its first breach notification describing an attack carried out by an AI agent built on a known large language model. The agency has not yet verified the organisation’s account.

On 22 September ENISA published its Threat Landscape 2026 which assesses that AI will highly likely support malicious operations to a growing degree and that 2026 may see experiments with attacks that run without a human in the loop. Three days later Microsoft described agent-driven attacks by a group it tracks as Storm-3168. The group used compromised Azure service principals and targeted more than 100 storage accounts in a destructive stage that lasted seven minutes.

DIVD spotted the activity itself...The most useful line in DIVD’s first statement is the least dramatic one, it noticed the suspicious activity itself. An intruder that picks its own next move at machine speed shortens the gap between foothold and damage, and a weekly log review will not close it.

Patch internet-facing systems against actively exploited flaws first. DIVD’s attacker still needed an ordinary vulnerability to get in and the agent only took over after that.

Hunt for automation inside the network, not only at the edge. Password spraying from internal hosts and bursts of commands issued faster than any person types are the patterns DIVD’s account points to.

If DIVD contacts your organisation once its investigation ends, treat the message as an incident report, not a courtesy notice.

How to check...Defense and AppSec teams should analyze logs from WAFs, load balancers, and web servers for anomalous request patterns. The behavior of an autonomous agent often manifests as bursts of sequential calls to various endpoints using synthetically generated parameter values, alongside variations in HTTP header composition—such as User-Agent strings and custom headers.

At the internal detection layer, SOC analysts should monitor for clusters of HTTP 400, 404, and 500 errors originating from a single source address or from residential and cloud service network ranges. It is also crucial to correlate these network events with endpoint telemetry (EDR) from edge servers, looking for the execution of atypical child processes—such as command-line interpreters or operating system utilities—launched by web services.

Agentic AI fingerprints...DIVD researchers stated that the attack exhibited characteristics typical of an agentic AI operation—behavior they had never encountered before. The intrusion was "noisy and very, very messy," featuring automated decision-making at machine speed and "sloppy logic or patterns."

Log screenshots shared by DIVD show comments embedded in the attack scripts where the agent justified its own actions, explaining why its steps were "ok and really not phishing." Human attackers rarely annotate their own exploit code with moral reasoning.

"What human attacker leaves notes for themselves in their scripts?" DIVD wrote. "The AI ​​was simply given a task and keeps justifying its own actions in the code via comments. Who has time for that, anyway?"

Praised for transparent response...Security researchers praised DIVD's openness. Patrick Garrity of VulnCheck called it "brutal honesty" and noted that the organization is "eating its own dog food" by disclosing the issue quickly, allowing other Zammad users to apply fixes before being targeted. The DIVD reported the vulnerabilities to the vendor on September 24, notified the Dutch Data Protection Authority and the National Cyber ​​Security Centre, and discussed the incident with the police. The investigation is ongoing.

mundophone

 

DIGITAL LIFE


Sleep disruption increases preference for artificial intelligence

When a person’s biological sleep cycle falls out of sync with their daily schedule, the resulting fatigue can trigger feelings of social anxiety. To avoid the pressure of human judgment in this anxious state, people often prefer to be evaluated by artificial intelligence instead. These findings were recently published in the journal Computers in Human Behavior.

The human body operates on an internal biological clock that regulates sleep and wakefulness. Often, the demands of work, school, or socializing clash with this natural rhythm. Social jetlag happens when a person’s biological sleep cycle falls out of sync with these external time constraints.

A common example is staying up late on Friday and Saturday, sleeping in on Sunday, and then forcing oneself awake early on Monday morning. The resulting fatigue feels similar to traveling across time zones. This temporal misalignment does more than just cause daytime sleepiness. It can disrupt emotional regulation and make people hyper-sensitive to how others perceive them.

Researchers Xiaoyu Zhou, Yuxuan Chu, Liwei Zhang, and Jianping Liang of Sun Yat-Sen University wanted to know how this specific type of fatigue influences human behavior in the digital age. They hypothesized that social jetlag induces social anxiety, which is an intense worry about being negatively judged by others.

Artificial intelligence is increasingly stepping into evaluative roles across many industries. According to industry reports cited by the researchers, the vast majority of companies have integrated algorithmic tools into their hiring processes, and several dating applications claim to use AI to evaluate user profiles.

Because these algorithms are widely viewed as consistent, objective machines, being evaluated by an AI might feel less threatening than facing the subjective judgment of a human being. The research team suspected that people suffering from social jetlag might actively seek out these automated evaluations to cope with their anxiety.

To test this idea, the researchers conducted four interrelated experiments. In the first study, they recruited 250 participants and assessed their natural chronotype, determining whether they were biologically wired to be morning or evening people. The participants were then randomly assigned to complete a second survey at either 8:00 a.m. or 8:00 p.m. the following day.

If a natural evening person was forced to complete the morning survey, the mismatch between their biological clock and the required time served as an experimental induction of social jetlag. In the second survey, participants read a scenario about registering for a dating application. They were told the platform would evaluate their attractiveness to recommend potential partners.

The participants then had to choose whether they wanted this evaluation to be conducted by a human staff member or an AI system. The researchers found that participants experiencing social jetlag were substantially more likely to choose the AI evaluation. By contrast, those who completed the survey at a time that aligned with their natural clock showed no strong preference between the human and the AI.

The second study explored the underlying psychological mechanism by measuring social anxiety. The research team recruited 226 participants and calculated their real-world social jetlag by comparing the middle point of their sleep cycles on workdays versus free days. The participants then imagined passing a resume screening for a job and had to choose between being interviewed by a human recruiter or an AI recruitment system.

After making their choice, the participants filled out a questionnaire designed to measure their current levels of social anxiety. The results mirrored the first experiment: participants with greater social jetlag were more likely to choose the AI interviewer. The data also revealed that social anxiety acted as a statistical bridge between the two variables. Greater social jetlag was associated with more anxiety about being judged, which in turn was associated with a preference for the AI system.

For the third study, the team wanted to ensure that people were actually fleeing human judgment, rather than just acting out of laziness or a general distaste for social interaction. They recruited 240 participants on a Monday morning, a time when weekend-induced social jetlag is especially common. The setup was similar to the dating app scenario used in the first experiment.

This time, however, the researchers provided no descriptive information about how the AI or human evaluators operated, forcing a purely intuitive choice. Alongside social anxiety, the researchers measured the participants’ desire to avoid interpersonal contact and their motivation to complete tasks efficiently.

Once again, social jetlag predicted a strong preference for the AI evaluator, with 80 percent of the participants choosing the algorithm. The statistical analysis showed that social anxiety was the sole psychological driver of this choice. Neither a general desire to avoid people nor a need to be efficient explained the preference for AI.

The final study examined whether this preference depends on how people fundamentally view artificial intelligence. The researchers recruited 218 participants and presented a scenario involving an AI-based virtual app that evaluates a user’s clothing choices. The participants were split into two groups and given different descriptions of the technology.

One group was told the AI evaluated outfits objectively based on standardized data, while the other group was told the AI had learned subjective aesthetic biases and evaluated outfits emotionally. When the AI was framed as an objective and unbiased tool, participants with greater social jetlag reported a stronger intention to adopt its evaluations.

However, when the AI was described as subjective and capable of emotional bias, the effect vanished. The socially jetlagged participants no longer showed a greater intention to adopt the AI’s evaluations, suggesting that they were specifically seeking an escape from subjective judgment.

While the experiments demonstrate a consistent pattern, the researchers note a few limitations to their work. The studies relied on self-reported measures of sleep schedules and hypothetical scenarios. These methods may not perfectly capture how people behave in high-stakes, real-world situations.

Real-life evaluations often involve power dynamics that a survey cannot fully replicate. A real job interview, for instance, carries financial consequences that might alter how an anxious person weighs the benefits of an algorithmic assessment against a human one. Future studies could track actual user behavior on digital platforms to see if social jetlag predictably shifts real-world choices.

Researchers might also explore how other factors, such as a person’s baseline technical literacy or their general distrust of opaque algorithms, interact with their social anxiety. The current findings focus specifically on short-term sleep disruptions. This leaves room to investigate how chronic social jetlag, such as the fatigue experienced by permanent night-shift workers, influences decision-making over time.

When your biological sleep cycle falls out of step with your daily routine, the resulting fatigue can trigger social anxiety, making you more likely to choose artificial intelligence over humans for evaluations like job interviews or dating matches.

The science behind sleep and AI preference:

• Social Jet Lag: This mismatch happens when your internal biological clock clashes with external demands like work or school schedules.

• Triggering Anxiety: Fatigue from a disrupted sleep cycle increases feelings of social anxiety and the fear of negative evaluation by other people.

• Seeking Neutral Judges: To escape the pressure and potential bias of human judgment, tired individuals often prefer being assessed by artificial intelligence, which they may perceive as more objective.

• Role of Perceptions: If a person views AI as objective, the preference for AI evaluations during sleep disruption is much stronger

The study, “Too tired to be judged by humans: Social jetlag increases preference for AI through social anxiety,” was authored by Xiaoyu Zhou, Yuxuan Chu, Liwei Zhang, and Jianping Liang.

Sun Yat-Sen University

Monday, October 5, 2026


DIGITAL LIFE


Should quitting smartphones be this hard?

According to a Pew survey conducted this year, about half of U.S. adults say that they spend too much time on their phone. About a quarter say that they are on their phone “almost constantly” and, of the 45 percent who have tried decreasing their phone use, only 25 percent say they succeeded.

In the past five years, attempts to disconnect from the smartphone have abounded: There are communities dedicated to “dumbphones” (cellphones capable of little more than calling and texting) and similar low-tech gadgets; people attend Luddite festivals; weary workers go on digital detox retreats or try integrating a digital sabbath into their week.

Reducing smartphone screen time has been linked to both physical and mental health benefits. Stepping away from the screen can reduce eye strain and improve posture, and participants in social media detoxes have reported decreased feelings of anxiety, depression, and insomnia.

Despite the benefits, there hasn’t been widespread adoption. Why don’t these methods stick?

“The go-to when people are like, ‘Oh, I’m done with Instagram, I’m done with Facebook’ is just to delete it. They don’t have a plan,” said Gabriela Nguyen, Ed.M. ’25. She’s the founder of Appstinence, a free program “Created by Gen Z For All,” incubated at the Harvard Innovation Labs, that helps people “get off of addictive tech for good.” To her, the problem with other approaches is sustainability.

Nguyen receives emails from appstinent hopefuls explaining how they’ve tried, and failed, to reduce use in the past, their “process” essentially amounting to going to the store, buying a Nokia, and swearing off smartphones. When it doesn’t work in the long-term, “they feel like it’s a moral failing,” she said. “It’s not.”

Expecting to end smartphone dependency quickly is where most go wrong. Appstinence’s 5D Method — decrease, deactivate, delete, downgrade, and depart — is a guide for gradually weaning from social media and smartphones, created specifically with human psychology in mind. Take the second D, deactivate. According to Nguyen, Anna Lembke, author of “Dopamine Nation,” “basically describes how our reward cycle settings need about a month to reset behaviors.” That 30-day period aligns with the 30 days social media platforms like Instagram give you to reactivate your account before automatic deletion — the third D.

“Appstinence is not hard and fast self-optimization; it’s not an ‘I’m gonna regain focus and instantly get a six-pack’ kind of thing,” she said. “The overall method is supposed to bring people to a point where they’ve re-understood the way technology is supposed to work in their life.”

This thinking tracks with what Greg Epstein, humanist chaplain for Harvard and MIT, has been saying and writing about for more than 15 years. Author of “Good Without God” and “Tech Agnostic: How Technology Became the World’s Most Powerful Religion, and Why It Desperately Needs a Reformation,” he likens our relationship with technology to a reverent — and destructive — faith. He first faced phone addiction in 2006, when the Palm Treo was the center of his attention. He was able to curb his addiction for a while, but then came the pandemic. He realized that he was no longer in control of his relationships with his devices: “They were running me.”

Fifty-eight percent of adults under 50 have attempted to decrease time spent on their smartphone within the last year — Epstein included. He’s tried it all: dumbphones, e-ink devices, identifying as Luddite, even formal addiction recovery meetings. What worked best was interrogating the relationship itself. “We have agency to choose applications for technology,” he said, not the other way around.

And it isn’t an all-or-nothing decision. “Imagine if someone were to say, ‘I’m in a bad relationship romantically, and so therefore I shall never have another romantic relationship ever again,’” he said. “It’s like no, we want healthy relationships. Either make this relationship healthier by working on it or get out and find somebody else.”

Gabriela Nguyen

Once people finally kick their toxic relationship to the infinite scroll, Nguyen says the next battleground will be in the workplace. “I hear from friends, family, and colleagues about how their companies have policies that AI is not optional,” she said. Between employers that force tech use and those that are laxer, Gabriela Nguyen(Iimage above) sees workers, especially young ones, choosing the latter.

But it won’t be as easy as telling your boss you’re cutting back on screen time.

“The model was that people went to work; they physically crossed a threshold,” said Sharon Block, professor of practice and executive director of the Center for Labor and a Just Economy at Harvard Law School. “They worked for X amount of time, and then they re-crossed that threshold and they weren’t at work.” Whether blue- or white-collar, that’s no longer the reality for most workers. “The law hasn’t been adapted to fit the blurring of that boundary between when are you working and when are you not.”

Progress toward redefining that boundary has recently come in the form of “right to disconnect” legislation. In 2016, France passed its “right to disconnect” law, giving employees the right to ignore digital communications from their employers after work hours. Similar laws exist in Australia, Italy, and Ontario, Canada, but despite these strides abroad over the past decade, a 2024 “right to disconnect” bill proposed in California was shelved without a formal vote.

Block says the chances of adoption in the U.S. are slim, given how “far behind” the country is in terms of worker protections. “Working people in the United States don’t have a [federal] right to paid sick days, what most countries in the world consider the absolute bare minimum for having a decent work-life balance.”

One potential avenue for work-life tech balance, Block says, could be charging a premium if employers require employees to respond to after-hours messages, similar to overtime. But, according to Block, when it comes to legislative priorities, the right to disconnect is likely low on the list. “Paid sick days and paid maternity, paternity, and family leave would come first.”

That doesn’t mean, however, that those working in labor law aren’t thinking about what tech is doing to workers.

“We spend some time here in the center looking at the impact that AI is having on the experience of work,” Block said. When she worked at the Department of Labor, Block juggled three cellphones: one personal and two for work. It couldn’t be called work-life balance, but it maintained something that remote and AI-infused workplaces can’t promise. “Most of my closest friends are people from work,” she said, “in part because I spent a lot of my career working such long hours, but I just don’t think I could have had those relationships if we were on Zoom screens all the time as opposed to actually sitting together, working, and seeing each other as full humans.”

So, there’s little stopping your job from taking over your personal devices and everything requires an app. It increasingly seems like there is no escape from the plugged-in lifestyle. But the defeatist outlook is why Nguyen, Epstein, and others interested in a low-tech future champion the agency we do have when it comes to technology.

“[Tech companies are] convincing us that we’re not adequate as we are and that everything has to be enhanced by godlike superintelligence in order to be valid or worthwhile,” Epstein said. “They’re prescribing to us a certain set of expectations, which are essentially to use tech all the time for everything forever. We’re saying no.”

The Harvard Gazette 

 

TECH


Windows 11 26H2 brings a hidden performance boost — and may slash RAM usage

Windows 11 26H2 quietly brings several performance improvements, including a Low Latency Profile that makes common tasks feel faster. Some users are also reporting lower RAM usage after the update, although Microsoft has not confirmed that 26H2 itself is responsible.

The latest Windows 11 26H2 update may look like a minor release on paper, but some users are reporting noticeably lower memory use and faster response times after installing it. The update brings together several performance improvements that Microsoft has gradually delivered through monthly patches, including a Low Latency Profile designed to make common Windows actions feel quicker.

Windows 11 versions 24H2, 25H2 and 26H2 share the same servicing branch, meaning many of 26H2’s changes had already been delivered before the update formally arrived. Microsoft describes 26H2 as an enablement package that turns on selected features and resets the operating system’s support lifecycle.

One of the most noticeable changes is the Low Latency Profile. When a user opens the Start menu, Search, Notification Center or an application, Windows temporarily pushes the processor close to its maximum clock speed for one to three seconds. The system completes the task quickly and then allows the CPU to return to an idle state—a technique Microsoft calls “race to sleep.”

Microsoft began rolling out the feature to Windows shell elements in June, then expanded it to app launches in August. Tests cited by Windows Latest showed faster launch times for applications including WhatsApp, Calculator and the Weather app. Because Microsoft used controlled feature rollouts, not every PC received the changes at the same time. The broader 26H2 release should make those optimizations available to more systems.

The more surprising change in 26H2 is its reported RAM use. Windows Latest said that a three-year-old laptop with 16GB of memory used about 7GB immediately after restarting on 26H2, compared with more than 10GB before the update. A Reddit user cited by the publication reported around 2GB less memory use after booting a PC with 48GB of RAM, while another user said usage on a 32GB system fell from 9.1GB on Windows 11 25H2 to 7.5GB on 26H2. An 8GB system reportedly showed no change, illustrating that results can vary considerably by hardware and configuration.

However, there is no confirmation that 26H2 itself is responsible for the lower memory consumption. Startup applications, cached data, application versions and browser tab management can all affect the figures, while Microsoft has not announced a specific RAM reduction as part of the update.

The RAM changes may nevertheless be part of a broader optimization effort. Microsoft has previously said it is working to make Windows 11 more responsive under heavy load and reduce its memory footprint. The company has identified memory management, memory compression, WinUI and WebView2 as areas for improvement, and has described better performance on systems with 8 GB of RAM as a priority.

Windows 11 has also received improvements to File Explorer, Search and WinUI throughout the year. Microsoft says File Explorer is now faster and more responsive after optimizations that reduce its reliance on preloading. Together with the Low Latency Profile and other changes, these smaller improvements could make the operating system feel faster without introducing a major new feature.

Windows 11’s Low Latency Profile is making the whole OS feel snappier...Windows 11 24H2, 25H2, and 26H2 share one servicing branch, and 26H2 is just an enablement package. Microsoft’s what’s new page says many of its features “have already been delivered through monthly servicing updates,” and that 26H2 “enables selected features and resets the support lifecycle.”

Low Latency Profile is one of those features. When you open the Start menu, Search, Notification Center, or an app, Windows pushes the CPU close to its maximum frequency for one to three seconds, finishes the work, and lets the processor drop back to idle sooner. It’s called “race to sleep,” and it targets the little pauses that make Windows feel slow even when the CPU isn’t busy.

Microsoft rolled it out for shell elements in June, and the August update extended Low Latency Profile to app launches. In our before-and-after testing on one PC, apps like WhatsApp, Calculator, and even the RAM-hogging Weather app opened much faster.

However, Microsoft used controlled feature rollout, so two PCs on one update could get different results, and many people had to force it with ViVeTool. Even when we tested 26H2 in August, the version bump didn’t switch features on by itself.

Since 26H2 now rolls up everything from the past few months, both the shell and app launch boosts should be on for most PCs that move to it, which makes the whole OS feel snappier.

My 16GB Windows 11 laptop is suddenly using much less RAM after 26H2...On Reddit, a user reported that RAM usage on boot dropped by around 2GB after the 26H2 update, on a PC with 48GB of RAM. Another user on X said usage on their 32GB PC fell from 9.1GB on 25H2 to 7.5GB on 26H2, while an 8GB PC owner saw no change at all, still at 96%.

My RAM numbers look similar. Right after a restart, Task Manager showed 7.0GB in use out of 15.7GB, which is 45%, with 4GB cached and 8.8GB available. Before, this laptop would often cross 10GB before I even opened an app. The 7GB shown could’ve been smaller if it weren’t for the startup apps: Lenovo Smart Connect, Plex, Quick Share, PowerToys, WhatsApp, Teams, and more.

Keep in mind that high RAM usage isn’t always bad. Windows uses free memory to cache data it thinks you’ll need, and releases it when an app asks for more.

To push it, I opened WhatsApp, Teams, and Outlook alongside Edge with a bunch of heavy tabs, and played a 4K 60fps video on YouTube. Of course, this is a stress test scenario, but even then, Memory usage hovered around 87%. I know that my PC would have touched 95% in milder tests.

Out of curiosity, I then added Microsoft Store, Paint, Lenovo Vantage, Notepad, Spotify, and Raindrop.io, and memory usage still stopped at 89%, roughly 14GB. Interestingly, Edge seemed to give up memory as I opened more apps, and took more back once I closed them.

Of course, this would have easily gone above 95% RAM a few weeks ago, but we’re unaware of what part of Windows Microsoft optimized here.

I’ve always regretted buying a laptop with soldered RAM, because it was always stuck between 90% and 95%. Now, maybe I don’t need a new laptop just yet!

Obviously, your mileage may vary. Startup apps, cached memory, app versions, and how Edge manages its tabs can all change these numbers, so this doesn’t prove 26H2 itself cut RAM usage, especially since Microsoft hasn’t uttered a word that they already improved it.

We all assumed the RAM optimizations were coming later.

Microsoft promised to reduce Windows 11’s RAM usage, but 26H2 isn’t the whole story...Back in March, Microsoft said Windows 11 would run faster under heavy load and reduce RAM usage. In July, they made memory optimization for 8GB and above an official priority, and at IFA, they promised faster boot and better 8GB performance.

Pavan Davuluri also said the rising cost of memory is why Microsoft is working on the memory manager, memory compression, WinUI, and WebView2. WinUI just got a memory growth fix, too.

It’s strange that Microsoft didn’t list any RAM reduction among 26H2’s changes, because this is a very welcome change.

26H2 is probably just when months of optimization work became visible on many users’ PCs. But I have always been enabling features with ViVeTool, so that isn’t what happened here, at least for me.

The 8GB reports also suggest the work isn’t fully there yet, and our 26H2 test PC in August only had 4GB of RAM, which may be why we didn’t notice anything then.

Windows 11 has quietly been getting faster all year...Microsoft’s 26H2 page also calls out a faster and more responsive File Explorer, after months of work that made it faster without preloading. This, combined with Low Latency Profile, a faster Search, WinUI fixes, and memory work, means you get many small changes while using the OS.

However, using a PC involves third-party apps, and that’s where we need more optimizations. Electron apps like Discord are notoriously RAM-hungry. WhatsApp is probably the most popular, least optimized app in Windows. With Microsoft deleting its 32GB RAM recommendation as memory gets expensive, we hope developers take note and go the native route with app development. AI has enabled making WinUI apps easier than ever, especially with Microsoft wholeheartedly supporting vibe coding.

26H2 is a tiny enablement package, but Microsoft has spent 2026 fixing Windows 11 piece by piece. While Low Latency Profile is easy to verify, RAM drop isn’t.

I’m hoping Microsoft has more to say about RAM optimization in the upcoming October 7 event. Either way, my PC feels lighter than it has in a long time, and that gives me a lot of hope for Windows 11.

mundophone

Sunday, October 4, 2026


TECH


Intel's 28-Core Ultra 9 4970K BFC leaks as flagship Nova Lake CPU

There's been a lot of speculation over the last few months on the matter of what exactly Intel was going to name its Nova Lake processors. Most people seemed satisfied to expect "Core Ultra 400 Series", which would make sense in light of its latest laptop CPUs. Instead, apparently, Intel is going with the Core Ultra 4000 series, at least on desktop. We heard about the Core Ultra 9 4950K before, but a new list from leaker LC Tech Leaks seems to corroborate that with a list of SKUs including six more models.

The list leaked by Laurents Choice was covered up in JPEG artifacts and ordered in a confusing way; you can see the original list by clicking the image above. However, the image directly embedded above is a cleaned-up version that has the same data, simply re-ordered in a more intuitive way. Starting from the top of the list we have the most exciting SKU of the bunch: a supposed Intel Core Ultra 9 4970K BFC.

What is "BFC"? Well, probably "Big F-ing Cache", if we were to guess. Given the gaming-focused nature of AMD's big-cache CPUs, the much-beloved "X3D" processors, it only makes sense for Intel's competing parts with the "Big Last Level Cache" (BLLC) feature to reference the grand-daddy of the FPS genre, DOOM, and its legendary "Big F-ing Gun". That part will apparently come with 8 P-cores, 16 E-cores, and 4 LP-E cores, which matches the 28-core prediction that's been floating around for some time.

Notably, many processors in the list do not mention the 4 LP E-cores present in the BFC SKUs. That would contradict the specifications given earlier by Jaykihn, but the Intel-specific leaker specifically replied to the LC Tech Leaks tweet saying exactly that: "the non-DS (non-bLLC/BFC) processors featured here also have LPE-cores and vPro support ... it just wasn't listed here, nothing deeper to it."

For its part, that Core Ultra 9 4950K looks extremely similar to the Core Ultra 9 285K that tops the current Arrow Lake family, so it will make a good candidate for generational comparisons. Of course, it's the "BFC" chips that we're really interested in benchmarking. We're dying to know if Intel's finest competes not only with the Ryzen 7 9850X3D but also with whatever AMD's cooking up for its next-generation Olympic Ridge processors.

The lineup is divided into models ranging from Core Ultra 5 to Core Ultra 9, confirming that the giant is set to revise its three-digit numbering scheme and return to the old four-digit standard, as previously rumored. According to the post, the lineup looks like this:

Core Ultra 9: Led by the 4970K BFC and 4950K models, both featuring 28 cores (8 performance, 16 efficiency, and 4 low-power) and a 125W TDP. The efficiency-focused option is the 4900 BFC (65W and 22 cores).

Core Ultra 7: Comprising the 4870K BFC and 4850K, delivering 24 cores (8+12+4) and 125W.

Core Ultra 5: Consisting of the 4650K and 4650KF, with 22 cores (6+12+4) and 125W. As usual, the KF model is the only one on the list lacking integrated graphics with 32 Execution Units (EUs).

The detail that really stands out in the data is the "BFC" suffix; although its exact meaning remains unknown, all signs point to this code identifying processors equipped with bLLC (Big Last Level Cache)—a cache technology designed to compete with AMD's X3D series.

Since these processors utilize a single-chiplet design, it is speculated that the BFC-equipped chips mentioned here could reach up to 144 MB of cache—a significant boost for tasks requiring rapid data retrieval, such as demanding games. However, even more powerful options are expected, featuring 52 cores and 288 MB of bLLC. Echoing LC Tech Leaks, another popular leaker, Jaykihn, confirmed that Intel’s new generation will indeed return to four-digit model numbers—though not across the entire lineup. Both desktop models and the HX laptop series—which utilizes desktop-grade hardware—will adopt this change. Meanwhile, other laptop-focused solutions will retain the current three-digit naming scheme.

The new Intel Nova Lake processors are expected to be previewed later this year, although the official unveiling is likely slated for January at CES 2027. The launch will require a new platform featuring the LGA1954 socket and Z990/Z970 motherboards, but significant improvements and longer-lasting support are anticipated this time around. The rollout is expected to occur in stages throughout the coming year.

There are several interesting details when looking at the range broadly. Most notably is the four-number model identifier, which Intel didn't use with Arrow Lake chips like the Core Ultra 7 270K Plus. This larger identifier has been previously rumored, and it makes sense if the lineup above is indeed real. There's quite a bit of specificity in this stack, and something like the "Core Ultra 9 497K" doesn't signal what a "Core Ultra 9 4970K" does.

Regardless of naming, the SKU table shows three models with BFC, two of which fall under the Core Ultra 9 umbrella. There isn't a Core Ultra 5 BFC option. The most interesting model is the Core Ultra 9 4900 BFC, which matches the 22-core count of the Core Ultra 5 models, though with the addition of BFC and a lower 65W TDP. Given this chip doesn't have a K suffix, it looks like a specialized, low-power gaming chip, perhaps for small form factor desktops.

In addition, the Core Ultra 5 model is the only one with an F suffix, noting that it lacks integrated graphics. As we saw with the Arrow Lake refresh, Intel released a Core Ultra 5 250KF Plus, though it never gave the 270K Plus the KF treatment.

According to the table, Intel could use "BFC" to note chips with a larger L3 cache, something that's been heavily rumored for Nova Lake as AMD's X3D chips dominate gaming in our CPU benchmark hierarchy. This is the first time we've heard it referred to as BFC; however, with previous rumors referring to the additional cache as bLLC.

As for what BFC stands for, there are a few possible candidates, and we'll leave it to your imagination as to what words that start with "F" could fit between "Big" and "Cache."

mundophone

 

TECH


Brown University engineers build brain-inspired imaging system that can ‘see’ through fog

Researchers from the Brown University School of Engineering have developed a new imaging system that can see and track moving objects in partially opaque environments like dense fog or muddy water. 

The technique, described in a study published in Advanced Science, combines a dynamic vision sensor — a camera with pixels that report only changes in brightness, rather than capturing full frames — with a spiking neural network computer model that reconstructs the moving objects spied by the sensor. In laboratory tests, the system’s reconstructed images matched the hidden targets with structural similarity scores of up to 96% in turbid water and drifting fog that would hide the objects from a traditional camera, while they simultaneously tracked the targets’ positions as they moved. 

The brain-inspired system is the first end-to-end technique that can both track and image randomly moving objects hidden by such dense scattering media, the researchers say. 

“The reason it’s hard to see objects in fog is that the light bouncing off of objects gets scattered by the fog before it reaches our eyes or the camera lens,” said Ning Zhang, a postdoctoral researcher in engineering at Brown. “This research project is about using novel imaging cameras and a brain-inspired model that can filter out that scattering process and reconstruct what's behind the fog.”

The system could eventually have a variety of real-world applications, including for self-driving cars and other autonomous vehicles, drone-based search and rescue efforts during storms or wildfires, or even medical imaging, the researchers say. 

Inspired by the brain...To develop the technique, the researchers took cues from the human visual system, which can process images with remarkable speed and efficiency. Rather than collecting a full picture all at once like a video camera, the retina responds mainly to changes in the visual field — edges, motion and flicker —and feeds that information to the brain, which builds a reconstruction of the scene over time. When it senses a change, it sends neural spikes to the brain, which are used to update the brain’s reconstruction of the world. 

The researchers were able to harness a similar architecture to create a system that processes images quickly and efficiently, but that outperforms human vision in foggy or turbid conditions. The system starts with a dynamic vision sensor that can detect light-intensity changes in individual pixels within the visual field. Because each pixel fires only when the brightness it sees changes by more than a set threshold, the sensor registers a moving object even when much of the light has been scattered by fog or some other scattering medium. And because the scattering background changes far more slowly than the moving target, the sensor largely ignores the fog and responds mainly to light that has interacted with the object. What it records is still a shapeless cloud of spikes, which is where the spiking neural network comes in. 

“The human eye is quite good at motion detection, but there are ways in which a camera, specifically a dynamic vision sensor, can be better, including that it’s sensitive to near-infrared light, which the human eye cannot see,” said Arto Nurmikko, a professor of engineering at Brown and the study’s senior author. “It captures information only about a moving object, and in doing so effectively filters out some of the fogginess while generating an output where relevant information is coded as trains of asynchronous spikes, much as the biological retina acquires data in a form the brain’s visual cortex understands.”

The key innovation in the work is a neuromorphic computer model mimicking the visual cortex: a deep spiking neural network that takes data from the vision sensor and reconstructs images of randomly moving, normally unrecognizable objects while tracking their trajectories in fractions of a second. The network runs on spikes as the fundamental unit of information. 

To test the system, the researchers projected images of moving alpha-numeric characters and silhouettes of different species of flying birds through an obscuring fog chamber or a tank of turbid water. The experiments showed that the system was able to image and track the randomly moving objects unrecognized by a standard camera system or the human eye. 

The system is also highly energy efficient. The sensor itself draws only tens of milliwatts. The spiking network uses a fraction of the energy used by a conventional neural network because it computes only on sparse spikes rather than dense frames.

The approach has limits, the researchers note. Because the sensor responds only to change, an object has to be moving relative to the camera to be seen, and the current system recovers an object’s silhouette rather than a full grayscale image. The sensor also loses sensitivity in very dim light. The team is now exploring a light-intensifier front end for low-light conditions, as well as depth-resolved approaches that can extend the method to three-dimensional targets — for example, by timing light’s travel time, or by pairing two event cameras like a pair of eyes.

“This could be useful anywhere where light-scattering by the surrounding medium is a serious problem — self-driving cars, search-and-rescue drones and underwater navigation are a few examples,” Zhang said. “The goal is to push the boundary of what we can perceive, to improve safety, healthcare and beyond.”

Engineers at Brown University have built a new brain-inspired imaging system that can track and "see" moving objects through dense fog and murky water with up to 96% accuracy.

The research was published in Advanced Science in October 2026. It solves a major problem for traditional cameras: light bouncing off fog instead of reaching the lens.

How the system works:

• Dynamic vision sensor: A special camera that records only changes in brightness (called events) instead of capturing normal video frames.

• Spiking neural network: A computer model inspired by the human brain. It processes sparse electrical signals (spikes) rather than dense data blocks.

• Filtering: The system ignores the random light scattering caused by water droplets in the fog and reconstructs what hides behind it.

Key benefits:

• High accuracy: Reconstructed images match hidden targets with up to 96% structural similarity in lab tests.

• Simultaneous tracking: It is the first system that can both image and track randomly moving objects hidden in dense fog at the same time.

• Energy efficient: The sensor uses only tens of milliwatts, and the brain-like network uses a fraction of the energy of traditional AI models.

Current limitations:

• Movement required: Because the camera reacts only to change, stationary objects cannot be seen.

• Silhouettes only: The system currently recovers object outlines (silhouettes) instead of full grayscale pictures.

• Low light: The sensor loses sensitivity in very dim environments.

Potential uses:

• Self-driving cars: Helping autonomous vehicles navigate safely through heavy mist or rain.

• Search and rescue: Guiding drones during severe storms or thick wildfires.

• Underwater navigation: Helping robots see through murky water.


Saturday, October 3, 2026


TECH


GeForce RTX 5070 Ti memory gets overclocked to a scorching 39 Gbps

The GDDR7 memory used on the GeForce RTX 50 series GPUs may have considerably more memory overclocking headroom than NVIDIAs official specifications suggest, with one enthusiast pushing Samsung GDDR7 memory all the way from 28 Gbps to a scorching 39 Gbps, coincidentally a 39% overclock. This came about thanks to the mVolt+ Extreme overclock tool, which can apparently bypass the memory overclocking limits imposed by conventional GPU tuning software. A Gigabyte GeForce RTX 5070 Ti Windforce owner reports successfully running the card's Samsung GDDR7 at a +5500 MHz memory offset, corresponding to a 39 Gbps data rate.

The mVolt+ Extreme tool pushes memory overclocking limits... The mVolt+ Extreme utility stands out from conventional GPU overclocking tools by allowing the hardware to operate beyond manufacturer-imposed restrictions.

The tool had already demonstrated the ability to unlock a TDP of up to 700W for the GeForce RTX 5090 without shunt modding (though using it this way is at your own risk—given that the card tends to melt things under normal conditions, imagine the consequences with a higher TDP), surpassing the stock limit of approximately 600W.

On the RTX 5070 Ti, mVolt+ Extreme enabled a memory offset of +5500 MHz, whereas most conventional utilities allow for a maximum additional offset of +3000 MHz.

Another user in the same Reddit thread confirmed stable performance at +5500 MHz on the RTX 5070 Ti but noted that 6000 MHz remained unstable.

Results vary across users and games... Performance improvements in games were considered modest, with the exception of a 20% gain observed in Steel Nomad.

The +5500 MHz offset boosts memory speed from 28 Gbps to 39 Gbps—a 39% increase—resulting in a bandwidth of 1248 GB/s compared to the stock 896 GB/s. However, in practice, this does not translate to a proportional gain in frames per second.

Other users who replicated the procedure achieved different results: some exceeded 5000 MHz, while others remained in the 4000 to 4500 MHz range.

If you're wondering how adding 5500 MHz is even possible, and also wondering how it added 11 Gbps to the transfer rate, let me explain. GDDR7 transfers sixteen bits per clock thanks to its design. That "+5500 MHz" number is actually even more confusing, because it's an intermediate data rate number. The actual clock rate at 39 Gbps is 2437.5 MHz, and the pre-DDR data rate is 19500 MT/s. That's an increase of 5500 MT/s over the stock 14,000 MT/s, which turns into 28 Gbps when you account for DDR signaling. Here, this chart might help:

As you can see, the bandwidth increase is easier to understand. The GeForce RTX 5070 Ti has a 256-bit memory bus, so its stock 28-Gbps memory provides 896 GB/s of theoretical bandwidth. At 39 Gbps, that rises to 1,248 GB/s—a 39.3% increase, essentially matching the increase in memory data rate. That pushes the memory bandwidth well ahead of the GeForce RTX 5080, and in fact within striking distance of the GeForce RTX 5090 D V2, the slightly-neutered RTX 5090 that was built for the Chinese market before Beijing banned the boards from entering the country.

Actually getting a GeForce RTX 5070 Ti to run its RAM at 39 Gbps is quite a feat, as you'd expect. The Redditor says +5500 worked in Cyberpunk 2077 with path tracing enabled for 30 minutes, while +6000 immediately caused the graphics driver to restart. Other users have reported lower ceilings, with examples around +4500 and +5000, and at least one user reporting artifacts beyond +5500. That makes it clear that results will vary from card to card and, potentially, depending on the memory chips installed on the board.

The performance gains are also nowhere near as dramatic as the memory bandwidth increase. The original tester, /u/Sad-Victory-8319, reported roughly 1 FPS of additional performance in Cyberpunk 2077 for every +1000 MHz of memory offset, while another user reported a roughly 1.5% to 2% increase in 3DMark Speed Way when moving from +3000 to +5000. In the former test, +5500 represented roughly a 5- to 6-FPS improvement over stock memory settings. A bit unimpressive, but not unexpected; GDDR7 is so fast even at stock settings that these GPUs are almost never bandwidth-bound.

Interestingly, despite that they use the same Samsung GDDR7 memory, similar experimentation on GeForce RTX 5090 cards appears to hit a lower ceiling. Users in the Overclock.net "RTX 5090 Owners Club" thread have also been toying with the mVolt+ tool, and they report getting to roughly +4000 MHz before driver resets become an issue. Why the 5070 Ti appears capable of going substantially further isn't yet clear, but it could have to do with the half-width memory bus or the considerably higher strain on the RTX 5090's power delivery hardware.

Either way, the discovery here is notable because it suggests at least some, and possibly a majority of RTX 50-series cards have a considerable amount of untapped GDDR7 frequency headroom. Whether running a gaming GPU at these kinds of memory speeds is sensible for long-term use is a separate question, particularly considering the fairly minimal performance gains to be found from even extreme overclocks like this. Still, it's hard not to be a little impressed by the sight of "39 Gbps" memory on a GeForce RTX 5070 Ti.

mundophone

TECH AI agents breach Dutch vulnerability disclosure group using chained Zammad zero-days The Dutch Institute for Vulnerability Disclosure s...