Recent Posts

Pages: 1 2 [3] 4 5 ... 10
21

A bunch of Microsoft products are losing support in 2026

Microsoft is walking away from more products this year than it did in 2025. Products that still run on millions of devices, including Windows 11 24H2, Office 2021, SQL Server 2016, and Windows Server 2012’s last ESU year, all expire in 2026. While 2025 was mostly about Windows 10, 2026 is a pile-up.

Also, in case you didn’t know it already, once a product hits its date, security updates, bug fixes, and paid support stop, unless Microsoft happens to offer an Extended Security Updates program for it, and even ESU only covers critical security fixes, nothing else.



Note that this doesn’t mean a software becomes unusable. It just stops being protected. For a note-taking app, that’s alright. But for a database sitting behind your company firewall, the consequences can be devastating if you don’t do anything about it.

So, we went through Microsoft’s official 2026 lifecycle page, checked every date, and ranked all of it by how many people it hits and how bad the fallout. Here is the list of all important Microsoft products losing support in 2026:

#1 Windows 11 24H2 (Home and Pro) – October

Windows 11, version 24H2 for Home and Pro editions reaches end of servicing on October 13, 2026. Since 24H2 has been the default install on every new Windows 11 PC since October 2024, that covers most of the consumer install base.



To check which version you have, press Win + R, type winver, and press Enter.

However, Windows 11 24H2, 25H2, and 26H2 all run on the same platform, codenamed Germanium. As Windows Latest reported, Microsoft has already started force-installing 25H2 on eligible Home and Pro PCs to clear this exact deadline, and it takes minutes with one reboot.

Enterprise and Education editions get a reprieve until October 2027. Open Settings > Windows Update and check now. If 25H2 hasn’t landed yet, force it. There’s no real reason to wait.

#2 Office 2021 and Office LTSC 2021, all editions – October

This is not very good news for me, because when I bought my PC, it came with lifetime support for Office 2021, and the then-ignorant me didn’t realize that lifetime meant just 5 years! Unlike Windows versions, updating from one Office version to the next isn’t free.

Every version of Office 2021 dies on the same date as Windows 11 24H2. Word, Excel, PowerPoint, Outlook, Access, OneNote, Publisher, Visio, and Project 2021 all go, plus the Office 2021 LTSC builds for Windows and Mac. Microsoft lists all nine apps separately under the same October 13, 2026 retirement, and there’s no partial exemption.



Note that older perpetual releases, like Office 2016, received 10 years of support. Anyone who paid once for Office 2021 specifically to dodge a Microsoft 365 subscription is now facing another purchase decision half as far apart as they’d probably budgeted for.

Home users and small businesses on the perpetual, non-subscription version of Office feel this. Of course, Microsoft 365 subscribers can ignore it, since their apps update on their own. Either way, the path forward is a Microsoft 365 subscription or buying Office LTSC 2024, which carries support through 2029!

#3 Windows Server 2012 and 2012 R2, final ESU year – October

Windows Server 2012 and 2012 R2 left mainstream support in October 2023, and Microsoft sold organizations three more years of Extended Security Updates as a bridge. Come October 13, 2026, that bridge is closing. There’s no ESU Year 4 coming.

Windows Server 2012 still runs a lot of domain controllers, file servers, and business-critical apps that never got scheduled for migration. Server operating systems tend to outlast the hardware refresh cycles built around them, and 2012 has had an unusually stubborn tail.



Any organization still running the 2012 family in production is exposed, particularly on premises rather than in Azure. (Azure-hosted instances get ESU coverage for free during this same window, a detail plenty of admins seem to miss.) The way out is migrating to Windows Server 2025 or moving the workload into Azure Virtual Machines to keep security coverage without a separate ESU bill.

#4 SQL Server 2016 – July

SQL Server 2016 hits extended end of support on July 14, 2026. It’s the biggest database deadline on the calendar this year. SQL Server 2016 has quietly become a workhorse release, under ERP systems, reporting infrastructure, and countless custom apps that nobody had urgent reason to touch.


SQL Server 2016. Source: ZDNET

Microsoft does sell Extended Security Updates for up to three more years after the cutoff, but only to organizations that plan for it. And the catch is that ESU Year 1 pricing starts July 15, 2026, and covers only what Microsoft classifies as critical severity, not the broader range of fixes a fully supported version gets.

Any business still running production workloads on SQL Server 2016 needs a plan, especially in regulated industries like healthcare and finance, where unsupported database software is also a compliance problem. Upgrading to SQL Server 2019 or 2022 works, and so does migrating to Azure SQL Database or Azure SQL Managed Instance, where Microsoft handles the patching for you.

#5 SharePoint Server 2016 and 2019, plus Project Server 2016 and 2019 – July

Same date as SQL Server 2016. SharePoint Server 2016 and 2019 both reach end of extended support on July 14, 2026, alongside Project Server 2016 and 2019, according to Microsoft.

Organizations that built custom intranets, document workflows, or records management systems on top of on-premises SharePoint may be affected. SharePoint Online has kept gaining features for years while the Server editions were frozen in time, so Microsoft isn’t cutting off something current here. They’re closing a door most admins already saw coming.

Enterprises and government agencies running on-premises SharePoint farms may feel the most heat, especially since data sovereignty rules make a full cloud move practically unfeasible. Migrating to SharePoint Server Subscription Edition keeps things on-premises with continued support, while moving to SharePoint Online under Microsoft 365 is the other route.

#6 Microsoft Publisher – October

Publisher is the odd one out in this list, because apart from losing support this year, it’s being retired. Microsoft’s support page confirms Publisher drops out of Microsoft 365 after October 2026, and subscribers lose the ability to open or edit Publisher files once that happens.



Of course, the perpetual, locally installed version keeps technically running past the cutoff since it’s within Office LTSC 2021’s support window, but it stops receiving updates, and Microsoft has already pulled it from sale. There’s no Publisher 2024. Microsoft’s suggested alternatives are Word and PowerPoint for layout work, which says plenty about where the company sees this product going.

Small businesses, churches, and community groups that still use Publisher for newsletters and brochures are the affected group here, a surprisingly loyal user base for software most people assumed died a decade ago. We recommend converting existing .pub files to PDF or Word before the cutoff.

#7 Exchange Server and Skype for Business Server, ESU Period 2 – October

Exchange Server 2016 and 2019 technically reached end of support in October 2025, but Microsoft split the paid Extended Security Updates bridge into two periods to soften the blow. Period 1 expired in April 2026. Period 2, which is the real final cutoff, runs out on October 31, 2026. Skype for Business Server 2015 and 2019 follow the identical two-period schedule.

Once Period 2 closes, that’s the end of the line. No more ESU purchases for either product!

Organizations still running on-premises email or unified communications that haven’t migrated to Exchange Online or Teams need to move now. Exchange Online under Microsoft 365 is the cloud path, while Exchange Server Subscription Edition is the option for anyone who has to stay on-premises.

#8 Windows 11 Enterprise and Education 23H2, plus .NET 8, .NET 9, and PowerShell 7.4 – November

Four unrelated products share this one date. Windows 11 Enterprise, Education, and IoT Enterprise editions on version 23H2 reach end of servicing on November 10, 2026, a year after Home and Pro editions of the same version lost support back in November 2025. With it, .NET 8 (an LTS release), .NET 9 (a Standard Term Support release), and PowerShell 7.4 (also LTS) all hit end of support the same day, confirmed directly on Microsoft’s lifecycle page.

IT teams managing Windows 11 23H2 fleets on enterprise licensing need to move, along with developers with apps still targeting .NET 8, .NET 9, or PowerShell 7.4. Upgrade managed Windows devices to 24H2 or later, move .NET apps to .NET 10, and update PowerShell to 7.6 or newer.

#9 Windows 10 2016 LTSB and IoT Enterprise LTSB 2016 – October

The 2016 Long-Term Servicing Branch editions of Windows 10 reach end of extended support on October 13, 2026. LTSB and its successor LTSC, exist specifically for kiosks, medical devices, and industrial equipment that need a locked-down OS with no feature churn for a decade at a stretch.



Manufacturers and healthcare providers using specialized hardware on the 2016 LTSB branch are a narrower audience than mainstream Windows 10, but a higher-stakes one. A migration to a currently supported LTSC release is the only real path, since these devices rarely click through a Windows Update prompt.

#10 Windows 11 SE – October

Windows 11 SE, the stripped-down education edition built to go after Chromebooks, loses support on October 1, 2026. Microsoft confirmed back in 2025 that no further updates were coming and has been nudging schools toward standard Windows 11 editions. As expected, the $250 Surface SE that launched alongside it isn’t getting a successor either.



Schools and districts that bought into the Windows 11 SE and Surface SE ecosystem are stuck with a bet Microsoft seems to have given up on. Moving managed devices over to standard Windows 11 Education or Windows 11 Pro Education licensing is the only supported way forward.

#11 Dynamics CRM 2016 and older Dynamics products – January

Dynamics CRM 2016, along with Dynamics GP 2016, GP 2016 R2, NAV 2016, and C5 2016, all lost support in the first third of the year. Dynamics CRM 2016 went first, on January 13, 2026, with the GP, NAV, and C5 2016 releases that followed on April 14, 2026.

Businesses running on-premises CRM or ERP on these specific 2016-era Dynamics products, mostly mid-market companies that never made the jump to Dynamics 365’s cloud model, had to migrate to Dynamics 365 Business Central or the relevant cloud Dynamics 365 app.

#12 Microsoft Configuration Manager, version 2409 – June

Configuration Manager 2409 reached end of support on June 6, 2026. ConfigMgr runs an 18-month rolling support window per release, so this is routine stuff, but IT admins still stuck on the 2409 branch had to update before the date to keep getting fixes. Moving to 2503 or later through the standard ConfigMgr update path cleared it.

#13 Visual Studio 2022 LTSC channels, versions 17.10 and 17.12 – January and July

Visual Studio 2022‘s Long-Term Servicing Channel builds have staggered end dates through the year. Version 17.10 LTSC lost support on January 13, 2026, and 17.12 LTSC follows on July 14, 2026. The LTSC channel exists so development teams can freeze their tooling on purpose, so these dates mostly come to teams that deliberately opted out of the mainstream release train and need to move to a currently supported LTSC channel, or switch to mainstream servicing.

#14 InfoPath 2013, SharePoint Designer 2013, and legacy virtualization tools – April and July

A cluster of older Microsoft tools wind down through the middle of the year. Microsoft Application Virtualization 5.0 and 5.1, Microsoft BitLocker Administration and Monitoring, the Diagnostics and Recovery Toolset, and User Experience Virtualization all ended April 14, 2026. InfoPath 2013 and SharePoint Designer 2013 follow on July 14, 2026, the same day as the SharePoint and Project Server retirements above.

Enterprises still running App-V for application virtualization, or teams that built forms and workflows in InfoPath and SharePoint Designer instead of Power Apps and Power Automate, are the ones with work to do. Migrating InfoPath and SharePoint Designer workflows to Power Platform is something Microsoft has been pushing for years anyway. The virtualization tools mostly point toward modern app deployment options inside Configuration Manager instead.

#15 Azure service retirements – September and October

A handful of Azure AI and infrastructure services shut down within weeks of each other. Azure Anomaly Detector, Azure Metrics Advisor, and Azure Personalizer all retire October 1, 2026, while Azure API for FHIR and Azure FXT Edge Filer go September 30, 2026.



Developers who built applications against these Azure AI services (a small but technically committed crowd) are the ones affected, since Microsoft has spent the last two years steering everyone toward Azure AI Foundry and Azure OpenAI instead. FHIR workloads move to Azure Health Data Services, while Anomaly Detector, Metrics Advisor, and Personalizer workloads have nearest equivalents waiting in Azure AI Foundry.

So, should you be worried?

Although I made this into just fifteen entries, the real count runs past fifty if we dismantle every Office app, Dynamics variant, and individual Azure. Yes, that’s a very large number, even for a software giant like Microsoft.

Windows 11 24H2 and Office 2021 hit the widest audience by far. SQL Server 2016 and the July server cluster may have the biggest business risk. Everything past that is not as big a deal as it seems.

Microsoft has a habit of stacking its biggest deadlines into the same two windows every year, mid-July and mid-October. Whatever you’re running, it’s worth checking against Microsoft’s lifecycle page directly instead of procrastinating over a few more months.

source
22
Microsoft / Microsoft admits Windows 11 has a GDID tracker with no off switch
« Last post by javajolt on July 14, 2026, 12:21:03 AM »
First documented publicly in an FBI hacker complaint!


What is GDID, the Windows device fingerprint that helped the FBI catch a hacker

A 19-year-old walked through Helsinki airport in April 2026 carrying two 2TB hard drives and a ticket to Japan. He couldn’t make that flight. Finnish police stopped him on an Interpol Red Notice, and by July, US prosecutors had unsealed a federal complaint identifying him as Peter Stokes, an alleged member of the Scattered Spider hacking group, wanted over a May 2025 breach of a US luxury jewelry retailer that ended in an $8 million ransom demand.

No, we haven’t suddenly turned into a crime reporting publication, but it was Microsoft that handed the FBI a way to trace Stokes’ Windows PC across VPNs, proxy servers, and three countries. The tool is called a Global Device Identifier, or GDID, and outside a handful of enterprise documentation pages, most Windows users had never heard the term before this case made it public.

We went through the full 39-page complaint, cross checked it against independent reverse engineering of how Windows generates and transmits this identifier, and fact checked the technical claims since the story broke. Here is everything you need to know about GDID, how it caught Stokes, and what it means if you are one of the 1.6 billion people using Windows PCs.



What is GDID, and where does it come from

The complaint quotes a Microsoft representative describing the GDID as “a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device, either a physical device (e.g., a mobile phone or laptop) or virtual machine, across certain Microsoft services and scenarios”

A Global Device ID (GDID) is a permanent, unique digital fingerprint that Microsoft automatically assigns to your computer when you install Windows or sign into a Microsoft account.

Microsoft uses it to manage software licensing and Windows Store apps, but because it links all your online activities on that computer back to a single identity, law enforcement can use it to track a device’s true owner across the internet

It survives Windows updates. It does not survive a clean reinstall, and Microsoft’s footnote in the complaint admits “one Microsoft user could have multiple GDIDs” over the life of a single account.

Microsoft said what the GDID does without saying where it is inside Windows. For that, independent researchers had to reverse engineer it, because Microsoft has published exactly one sentence about GDID in the Azure Monitor reference for Delivery Optimization reporting, where a column called GlobalDeviceId is described only as “Microsoft global device identifier. This is an identifier used by Microsoft internally.”

How Windows generates a GDID

The real chain starts with the Microsoft Account service.



When Windows provisions a device against a Microsoft Account, a system service called wlidsvc talks to login.live.com and gets back what Microsoft calls a Device PUID, a Passport Unique ID, inside the server’s SOAP response. Server assigned. Windows never computes it locally from anything on your PC. It receives a string and stores it.

The PUID lands in your own registry hive, in plain text, at HKCU\SOFTWARE\Microsoft\IdentityCRL\ExtendedProperties under a value named LID. From there, the Connected Devices Platform, the same background service (cdp.dll, running as CDPSvc) that powers Phone Link, cloud clipboard, and Nearby Share, reads that PUID and registers it into Microsoft’s Device Directory Service, which is the identity graph behind all of Microsoft’s cross device features. There, the number gets a lowercase g stuck in front and gets written as g:decimal. Delivery Optimization then reports that same value back to Microsoft’s servers as UCDOStatus.GlobalDeviceId every time your PC shares or downloads update data peer to peer.

Now for the version in plain English: Sign into Windows with a Microsoft Account, and a server assigns your installation a permanent ID number. Windows stores it locally, several background services read it, and it gets stamped onto activity your PC reports back to Microsoft.

Reinstall Windows and you get a new number, but Microsoft’s own records give every reason to link the new one back to the old, through the same account, OneDrive, and activation history, which is close to what happened to Stokes.

How the FBI used GDID to catch Stokes

Stokes got caught because he used the same Windows device for everything, and the GDID stitched all of it back together after the fact.

Scattered Spider members phoned the jewelry retailer’s IT help desk from Google Voice numbers, posed as locked out employees, and talked support staff into resetting three accounts, two with administrator privileges. From there they installed a tunneling tool called ngrok to get past the retailer’s network defenses, moved roughly 77 gigabytes of data to Amazon cloud storage using ngrok and a second tool called Teleport, tried and failed to deploy ransomware, then sent a ransom email with the subject line “IMPORTANT: WE STOLE THE DATA, CONTACT UMMEDIATELY [sic].” They asked for $8 million in cryptocurrency. The retailer refused, ate roughly $2 million in cleanup costs, and moved on.

Investigators later subpoenaed ngrok and found the account used in the attack had been created on May 12, 2025, at 19:21 UTC from a VPN proxy IP address run by Tzulo, a hosting provider. The IP was a dead end. VPN proxies do that. But the GDID is built different.


source: DOJ

Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page. Three hours later, the same GDID visited the retailer’s own website, through the same Tzulo proxy address used to set up the ngrok account. It gave the FBI a device, that don’t rotate the way VPN exit nodes do.

From there the investigation turned into connecting dots. Once agents had a timeline of every IP address that device had used, they cross referenced it against known logins to accounts prosecutors already suspected belonged to Stokes:

On June 4, 2024, the GDID’s device used an IP address in Tallinn, Estonia, where Stokes lived. The same IP had logged into his Snapchat account four minutes before that and his Facebook account about 80 minutes after.

On November 17 and 18, 2024, the same device showed up on a New York IP address, matched to logins on one of Stokes’ Apple accounts and his Snapchat account. Weeks later, on November 26, the same device visited the website for the Empire Hotel in New York, matching another confirmed Stokes trip. He’d posted a Snapchat photo the day before that investigators matched, down to the carpet and wallpaper, against publicly advertised photos of an Empire Hotel suite.

On February 2, 2025, the device appeared on a Thailand based IP, matched again to his Apple and Snapchat logins. Stokes had posted a Snapchat photo captioned “WALDORF ASTORIA BANGKOK” the day before.

On January 8, 2025, the same device, now back on an Estonian IP, logged into the mobile game Growtopia. The day before, that same IP address had accessed one of Stokes’ Apple accounts, then a Ubisoft account tied to that Growtopia login two minutes later.

Of course, all these activities doesn’t seem suspicious when taken individually. What made the case is that the same GDID and physical Windows installation, kept showing up at the exact times as accounts investigators already knew were Stokes’, across four countries over roughly eight months.

Note that, Microsoft had already flagged Stokes to the FBI once before, in an October 2024 criminal referral describing “online services telemetry.

Why this bothers privacy researchers, even with a hacker caught

Nobody is arguing the wrong person got arrested. Stokes is accused, with the rest of Scattered Spider, of over 100 corporate intrusions and $100 million-plus in ransom payments, per the DOJ’s numbers. The system worked as intended here.

What has researchers uneasy is everything else the case reveals. Costin Raiu, a well-known malware researcher, asked on the Three Buddy Problem podcast how much of this exists on other platforms, and whether it is linked more permanently to hardware. Matthew Hickey, another security researcher, called Windows “surveillance software”.



Two things back that up:

1. There’s no consent screen. A GDID gets assigned when you sign into a Microsoft Account. Apple’s advertising identifier needs an  App Tracking Transparency prompt and a visible reset; Android’s works the same way. GDID has neither, and a Windows reinstall only gets you a new number Microsoft can still get back to the same account.

2. Then there’s activation. Massgrave, the group behind Microsoft Activation Scripts, notes that Windows setup sends hardware info to Microsoft and gets identifiers back, the same tokens later used for Store access and licensing: “It’s impossible to prevent Windows from getting a GDID without breaking activation and UWP app(s).” Anyone who lost a license after swapping a motherboard has already met a smaller version of this.

Yes, every major OS keeps some persistent device identity, and every vendor can be subpoenaed. But what differs with Microsoft is visibility and control, and Windows loses on both against Apple and Google’s platforms.

What you can do about it

Reinstalling Windows isn’t the fix people assume. You get a new GDID but sign back into the same Microsoft Account and Microsoft has every reason to connect it to your old activity anyway. A few things help more:

• Use a local account instead of a Microsoft Account, but we are also aware of how difficult it has become to skip signing in with a Microsoft account. Fortunately, the company is making it easier.



• Turn off optional diagnostic data under Settings > Privacy & security > Diagnostics & feedback.



• Block Advertising IDs by toggling off personalized ads and launch tracking under Privacy & security > Recommendations & offers.



• Disable Cloud Search by turning off Cloud Content Search from Privacy & security > Search to stop local searches from sending data to Bing.



• See our guide on stripping unwanted AI features and background services out of Windows 11.

• For journalism, activism, or domestic abuse situations, skip Windows and use Linux routed through Tor instead of a commercial VPN. A GDID doesn’t care which VPN you use, only that it’s still the same Windows installation.

Our take

Am I glad Stokes got caught? Yes, without hesitation. Thirty-five pages of a teenager bragging about diamond chains spelling out “HACK THE PLANET” while extorting a jewelry store don’t leave much room for sympathy, whatever role Microsoft’s telemetry played in building the case.

But that doesn’t make the GDID okay. Every company selling you software has some version of this, and a persistent device identity is a reasonable thing to build into activation and fraud systems. What gets me is that most people had never come across the term GDID before a federal court filing such as this. Microsoft wrote one sentence about it in an Azure Monitor reference table meant for enterprise IT admins pulling update reports, not for the 1.6 billion or so regular people whose PCs are generating this data.

You might be tech savvy enough to turn off Activity History, pick a local account, and strip out every scrap of optional telemetry, but none of it changes the fact that the identifier exists, and that it answers to your Microsoft Account instead of you. Microsoft only told the public about it once a court forced the issue.

source
23
On the track of small-size esports tablets, from the RedMagic Gaming Tablet 3 Pro to today's fifth-generation Pro, RedMagic has always been exploring one question — how much esports usage scenario can a portable tablet actually carry? When we held the RedMagic Gaming Tablet 5 Pro in our hands, this question seems to have a clearer answer. Tianji.com (Skyworth Digital/Tianji Net), after an in-depth experience, brings this review.



In terms of appearance, the unit Tianji.com received this time is the "Deuterium Peak Transparent Silver Wing" color version, continuing RedMagic's iconic transparent and flat back panel design language, with the back panel presenting a cool metallic silver-gray texture under light. The whole machine feels solid in hand, with evenly distributed weight and no obvious sense of heaviness, with the total weight of the machine being approximately 363g. For an esports tablet with a built-in cooling fan and an 8200mAh large battery, this kind of weight control deserves recognition.



In terms of back cover design, this generation goes further on the basis of the cyber esports style — under the flat back panel, the brand new transparent liquid cooling structure is fully visible, with cool water-cooling RGB light strips lighting up according to the cooling state, and while running you can even clearly see the trajectory of the fluorinated coolant flowing through the pipeline, injecting a sense of cyber life into the cold hardware.



In terms of the screen, this generation of the RedMagic Gaming Tablet 5 Pro is equipped with a 9.06-inch, 2400×1504 resolution OLED esports screen. What's surprising is that the refresh rate has further increased to 185Hz. In FPS, racing and other high-frame-rate-sensitive esports scenarios, the improvement in every frame can be synchronously captured by fingertips and eyes. Paired with a 4.9mm ultra-narrow four-equal-side design and a 90.1% ultra-high screen-to-body ratio, the visual immersion is extremely strong. Whether holding it horizontally to play games or browsing content in portrait mode, the equal-width-on-all-sides look makes the entire screen appear as if it is floating above the body. Brightness is likewise not to be underestimated, with local peak brightness reaching up to 1600nit, and global excitation brightness also reaching 1100nit.



In terms of touch control, the RedMagic Gaming Tablet 5 Pro is equipped with the S3930 Synaptics (Xinsi) touch chip, with a multi-finger native touch sampling rate reaching 300Hz, an instantaneous report rate as high as 2000Hz, and support for 10X super-resolution touch, making operation faster, more accurate, and more stable — the synergy of the 185Hz ultra-high refresh rate, OLED low latency, and the S3930 touch chip allows every frame of the player's operation on the esports battlefield to seize the first opportunity.



In terms of game compatibility, the RedMagic Gaming Tablet 5 Pro fully leverages the advantages of this 185Hz high refresh screen. Currently, several popular games including "Cross Fire: Gunfight King," "Dawn Hero," and "Rhythm Master" have already adapted to the 185Hz ultra-high frame rate, while mainstream shooting games such as "Delta Force," "Call of Duty Mobile," and "Peacekeeper Elite" have also adapted to the 165Hz high frame mode. Combined with the OLED screen's natural low-latency characteristics, in FPS and other high-frame-rate-sensitive esports scenarios, both the smoothness of the visuals and the responsiveness of operation have significant advantages.

In terms of performance, the RedMagic Gaming Tablet 5 Pro is equipped with the Qualcomm Snapdragon 8 Elite Gen5 flagship processor, using TSMC's third-generation 3nm process technology. Both CPU and GPU performance have achieved significant improvements compared to the previous generation, while energy efficiency performance has also been greatly optimized. Tianji.com actually tested "Delta Force," and under ultra-high frame rate, the gaming experience was smooth and silky, with responsive operation, and the average frame rate for the entire match was as high as 166FPS, with the body basically showing no obvious heating, a satisfying performance.



In order for this tablet to have a more comprehensive gaming experience, the RedMagic Gaming Tablet 5 Pro, with the support of RedMagic Lab's self-developed translation engine, has overcome the technical difficulty of translating X86 instructions to the ARM architecture, and has built a PC emulator into the system, further lowering the threshold for users to play games. Users can play games from platforms such as PS, Steam, and Xbox via streaming, or import games locally in the PC emulator, or directly log into their Steam account to download from their game library, while also supporting cloud save synchronization. This allows the RedMagic Gaming Tablet 5 Pro to freely switch between multiple forms such as an entertainment tablet, a gaming handheld, and a console streaming terminal. For many users, this may be one of the few one-stop gaming experience solutions currently available.



In order to adapt to gaming needs in different scenarios, the RedMagic Gaming Tablet 5 Pro also supports connecting various external devices: plug in a controller and it becomes a complete handheld gaming console form, and cast to a TV while connecting a Bluetooth controller to unlock the console experience.



In addition, this generation has been upgraded to dual Type-C ports, both specified as USB 3.2 Gen2, located at the bottom and on the left side respectively, fully optimizing the experience of charging while playing when held horizontally.



In terms of battery life, the RedMagic Gaming Tablet 5 Pro has a built-in 8300mAh super-large capacity battery, which is at a leading level among tablet products of the same size. Combined with the high-efficiency chip and system-level power consumption optimization, in Tianji.com's actual battery life test, it is sufficient to support long hours of gaming and audiovisual entertainment needs, with no need to worry about battery anxiety.

In terms of charging, the RedMagic Gaming Tablet 5 Pro supports up to 80W wired fast charging. Tianji.com's actual test showed that half an hour of charging can reach 73% battery, and it takes a total of 52 minutes to fully charge, allowing players to quickly recharge during fragmented time and return to the battlefield at any moment.

Overall, the RedMagic Gaming Tablet 5 Pro has completed a fairly comprehensive evolution within a limited 9.06-inch body. It can be said that the RedMagic Gaming Tablet 5 Pro is not just a gaming tablet, but an all-around esports terminal that can seamlessly switch between tablet, handheld, and console at any time — for players pursuing the ultimate portable gaming experience, this may be one of the most noteworthy choices currently

source
24


Back in March, Google announced a major overhaul of the Google Maps navigation interface with a new immersive navigation UI. The update started popping up in CarPlay for some users, but Android users were still stuck with the old navigation UI in Android Auto. Now, that seems to be changing.

In a new post on Reddit, user radgatt has shared screenshots of the Google Maps immersive navigation UI running on Android Auto. The screenshots show the new 3D UI with easy-to-spot flyovers, 3D buildings, and even individual trees.



Apparently, the user started seeing the new UI after updating to Android Auto v17.3, which was released yesterday and is also rolling out now. However, another user running the latest beta versions of both Android Auto and Google Maps said that the new UI isn’t showing up for them. It’s highly likely that the new UI isn’t tied to the latest version of Android Auto and is instead a Google server-side update.

Android users have been waiting for the new immersive navigation to show up on their phones for quite some time, and it’s definitely good news that the update seems to have started rolling out now. Hopefully, this won’t be another one of Google’s really slow rollouts, and users will get access to the new UI sooner rather than later.

Immersive navigation in Google Maps is available in the US on iOS, CarPlay, Android, Android Auto, and cars with Google built-in. However, it is rolling out slowly. Google hasn’t said anything about a rollout in other countries. If you’re outside the US, you’ll just have to wait for the company to expand the feature globally.

source
25


Back in March, Google announced a major overhaul of the Google Maps navigation interface with a new immersive navigation UI. The update started popping up in CarPlay for some users, but Android users were still stuck with the old navigation UI in Android Auto. Now, that seems to be changing.

In a new post on Reddit, user radgatt has shared screenshots of the Google Maps immersive navigation UI running on Android Auto. The screenshots show the new 3D UI with easy-to-spot flyovers, 3D buildings, and even individual trees.



Apparently, the user started seeing the new UI after updating to Android Auto v17.3, which was released yesterday and is also rolling out now. However, another user running the latest beta versions of both Android Auto and Google Maps said that the new UI isn’t showing up for them. It’s highly likely that the new UI isn’t tied to the latest version of Android Auto and is instead a Google server-side update.

Android users have been waiting for the new immersive navigation to show up on their phones for quite some time, and it’s definitely good news that the update seems to have started rolling out now. Hopefully, this won’t be another one of Google’s really slow rollouts, and users will get access to the new UI sooner rather than later.

Immersive navigation in Google Maps is available in the US on iOS, CarPlay, Android, Android Auto, and cars with Google built-in. However, it is rolling out slowly. Google hasn’t said anything about a rollout in other countries. If you’re outside the US, you’ll just have to wait for the company to expand the feature globally.

source
26
No Premium? No problem. DuckDuckGo-t your back!



Imagine you’re watching a YouTube video, completely invested in what’s happening, and then an ad suddenly interrupts. It’s annoying every single time, and I’m sure I’m not the only one who feels that way. I’d much rather install an ad blocker in a few minutes than pay for YouTube Premium just to avoid ads.

The only downside is that YouTube has been getting increasingly aggressive about ad blockers, often showing warnings or refusing to play videos. I was almost ready to give up on ads and live with them until I came across DuckDuckGo’s new free ad blocker option. I decided to give it a shot, and guess what? It worked.

If you’re tired of YouTube constantly nagging you about ad blockers, here’s how you can get it working on your device, too.

How do you deal with YouTube ads?



How to block YouTube ads with DuckDuckGo



Before I tell you more about what it was actually like using this, let’s get you set up first.

If you’re using a Mac, Windows PC, or an iPhone, you’re in luck. YouTube ad blocking is already enabled by default in the latest version of the DuckDuckGo browser, so there’s nothing you need to configure. Just make sure the browser app is up to date, open YouTube, and start watching your videos as you normally would.

Android users have one extra step, though. DuckDuckGo says YouTube ad blocking will be enabled by default on Android “soon,” but until then, you’ll need to turn it on manually. Update the app to the latest version, then follow these steps:

   1. Open the DuckDuckGo app on your Android phone.

   2. Open a new tab and tap the three-line menu (hamburger icon) in the top-right corner.

   3. Tap Settings.

   4. Scroll down to Other Settings and select YouTube ad-blocking.

   5. Turn on the Block Ads on YouTube toggle.



That’s it. Once you’ve enabled the setting, open YouTube in the DuckDuckGo browser and enjoy your videos without the usual stream of ads getting in the way.

This wasn’t supposed to work so smoothly



I followed these steps on my Google Pixel 10a, and the whole setup took barely a minute. The funny part was that I was skeptical. I’d tried enough workarounds over the years to know that many of them stop working sooner rather than later, so while I was hopeful, I wasn’t getting my expectations up.

Obviously, I had to try it for myself. The first thing I did was play a one-hour episode of one of my favorite YouTube shows. I simply hit play and watched. There wasn’t a single ad from start to finish. Honestly, it felt a little weird because I’d become so used to YouTube interrupting videos that I kept expecting an ad to show up. It never did.



So I kept going. I watched music videos, podcasts, long documentaries, cooking videos, and pretty much anything else I’d normally have open on YouTube — and it all ran smoothly. Even though DuckDuckGo warns you might notice a little extra buffering, I didn’t experience any during my testing.

The experience was even simpler on my iPhone, MacBook, and Windows PC. Since YouTube ad blocking is already enabled by default there, all I had to do was make sure DuckDuckGo was up to date. After that, it was the same story. I ended up spending far longer on YouTube than I’d planned, partly because I wanted to test it properly and partly because, for once, I wasn’t constantly being pulled out of the experience by ads.

There’s a bonus feature worth knowing about



While I was poking around the browser, I stumbled upon another feature that caught my attention. It’s called Duck Player, and it complements YouTube ad blocking surprisingly well.

Instead of opening videos in the regular YouTube player, Duck Player uses DuckDuckGo’s own built-in video player. The biggest advantage here is privacy. It uses YouTube’s strictest privacy settings for embedded videos, which means you aren’t tracked with cookies or served personalized ads while you watch. The videos you watch in Duck Player won’t influence your YouTube recommendations, and it won’t remember your place in playlists either.



If that sounds like something you’d like, you can enable Duck Player from the browser’s settings. Better yet, you don’t have to choose between the two. Duck Player and YouTube ad blocking work together, so you get a cleaner, more private YouTube experience without giving up either feature.

So, how is DuckDuckGo getting away with this?



Of course, this made me wonder how DuckDuckGo was pulling it off, given that YouTube has spent so much time cracking down on ad blockers. So I dug into how it actually works. DuckDuckGo relies on community-maintained filter lists from uBlock Origin, which are constantly updated by an active open-source community to keep pace with the way websites, including YouTube, serve ads. On top of that, DuckDuckGo applies its own tweaks to improve compatibility and keep things running smoothly.

My only hope is that it stays this way, because right now it’s exactly what I was looking for. I don’t have to add another monthly subscription to a list that’s already long enough, and after using it across my Pixel, iPhone, MacBook, and Windows PC, I genuinely don’t miss YouTube’s constant ad interruptions.

source
27
Microsoft has removed 119 extensions from the Edge add-on store which were all tied to one adware campaign.

In a paper titled “Inside StegoAd: How We Disrupted a Massive Malicious Extension Campaign,” Microsoft researchers detail how they uncovered and dismantled a sophisticated malware campaign that abused browser extensions to infect users. According to Microsoft, the campaign involved 119 malicious browser extensions which were downloaded by 2.6 million users.

The extensions all promised, and delivered, some kind of basic functionality: ad blockers, VPNs, translators, video downloaders, calculators, coupon extensions and so on. But after a while they turned out to be “sleepers” and secretly started downloading additional malware.

Among the payload was malware involved in ad fraud, but also extensions that ran arbitrary JavaScript pushed from the server, which stole Google credentials and second-factor codes at sign-in, harvested WordPress admin logins, and exfiltrated cookies in bulk for session hijacking.

The name of the campaign “StegoAd” is derived from the words advertising and steganography, which means techniques of hiding secrets in something that doesn’t immediately cause suspicion. In this case, hiding code in images.

And not only did the cybercriminals try to stay under the radar by waiting for some time, and hiding malicious code inside images, they also left some victims alone. Some of the extensions only went rogue in about 10% of installs, which would actually execute the next stage of the malware, while the other ~90% would be left alone (at least for that execution attempt). And, in some cases, they re-used names of well-known legitimate extensions to install an additional level of trust.

Browser extensions are a source of wealth for cybercriminals because it compares to installing a small program that lives inside your browser, which can see and report about everything you do on the internet.

Now I hear some of you thinking: I don’t use Edge. Or I’ve used it just once, to download and install my favorite browser. But although Microsoft discovered and analyzed the campaign, the techniques used in this campaign are applicable to Chromium-based browsers in general.

This campaign was less about exploiting a browser vulnerability and more about tricking users into installing a trusted-looking extension, then using sophisticated concealment techniques to avoid detection long enough to compromise systems.

How to stay safe

Always be careful when downloading extensions, even from the reputable app stores. As we’ve seen many times before, criminals manage to get their apps or extensions listed when they are only one update away from turning into malware. So, make sure that you trust the developer and don’t rely on reviews alone.

Use an up-to-date real-time security solution to detect and remove malicious extensions from your device and block connections to malicious domains and IP addresses. Remove the known malicious extensions from your browser. Below is an alphabetical list of the malicious extensions the researchers found by name.

Please note that there might be more than one extension that has the same name. In case you doubt whether the extension you have installed is among them, check whether the ID matches the one shown in the list. If you prefer looking them up by ID, you can find them organized differently in the Microsoft report (pages 40-43).










source
28
Apple / Apple releases security patches for iOS, MacOS Tahoe, Safari
« Last post by javajolt on July 07, 2026, 08:49:46 AM »


Apple has released security updates for more than two dozen security vulnerabilities across iPhone, iPad, and Mac.

The updates for iOS/iPadOS, MacOS Tahoe, and Safari were issued after testing on iOS 26.6 and iPadOS 26.6 betas.

What stands out in the update is that a lot of the vulnerabilities were found in WebKit, the browser engine that powers Safari as well as every browser on iPhone, including Chrome, Firefox, and Edge. It also looks like several of the issues Apple has addressed can be chained together to steal data or run malicious code with little or no user interaction.

Updates for your particular device

The table below shows which updates are available and points you to the relevant security content for that subject.





How to update your Apple devices

How to update your iPhone or iPad

For iOS and iPadOS users, here’s how to check if you’re using the latest software version:

Go to Settings > General > Software Update. You will see if there are updates available and be guided through installing them.

Turn on Automatic Updates if you haven’t already—you’ll find it on the same screen.



How to update macOS on any version

To update macOS on any supported Mac, use the Software Update feature, which Apple designed to work consistently across all recent versions. Here are the steps:

• Click the Apple menu in the upper-left corner of your screen.

• Choose System Settings (or System Preferences on older versions).

• Select General in the sidebar, then click Software Update on the right. On older macOS, just look for Software Update directly.

• Your Mac will check for updates automatically. If updates are available, click Update Now (or Upgrade  Now for major new versions) and follow the on-screen instructions. Before you upgrade to macOS Tahoe 26, please read these instructions.

• Enter your administrator password if prompted, then let your Mac finish the update (it might need to restart during this process).

• Make sure your Mac stays plugged in and connected to the internet until the update is done.

How to update your Safari browser

Safari updates are included with macOS updates, so installing the latest version of macOS will also update Safari. To check manually:

• Open the Apple menu > System Settings > General > Software Update.

• If you see a Safari update listed separately, click Update Now to install it.

• Restart your device when prompted.

If you’re on an older macOS version that’s still supported (like Sonoma or Sequoia), Apple may offer Safari updates independently through Software Update.

Technical details

On iPhone and iPad, every browser—Safari, Chrome, Firefox, Edge—is forced to use Apple’s WebKit engine, which is exactly where most of the 26.5.2 fixes land. Apple and independent write‑ups describe a chain of WebKit issues, including use‑after‑free bugs, memory corruption, and cross‑origin logic errors that could be triggered simply by loading a malicious page. In several cases, the impact ranges from crashing your browser to corrupting memory or leaking data from other sites you have open in different tabs.

And there are some other browser related issues. Apple also notes fixes in Web Extensions and permission handling that could have allowed browser extensions or sites to access more data than intended. Plus some that are scattered across related libraries and frameworks such as libxslt, and WebRTC.

Libxslt is an open-source C library used to perform transformations on XML documents. It enables developers to convert raw XML data into other formats, such as HTML, plain text, or other XML structures.

WebRTC (Web Real-Time Communication) is an open-source technology that allows web browsers and mobile apps to communicate directly with each other.

None of the patched vulnerabilities are known to be exploited in the wild, but that doesn’t mean you can relax. One thing to consider when you are scheduling this update is that, due to the beta testing, the details of these vulnerabilities have been public knowledge for a while, so the race to come up with an exploit has already started.

source
29


If there was ever a time when it dawned on users how full of holes the software they’ve been using is, it’s now. Last month Microsoft pushed out its biggest patch Tuesday update ever. And yesterday, on the last day of June, Google published an update which included a whopping 382 security fixes.

The stable channel has been updated to 150.0.7871.46/.47 for Windows and Mac, 150.0.7871.46 for Linux, and 150.0.7871.63 for Android. The update will roll out over the coming days and weeks.

How to update Chrome

If you don’t want to wait for the rollout to reach you, manually updating is easy.

The easiest option is to allow Chrome to update automatically. But you can end up lagging behind on updates if you never close your browser or if something goes wrong, such as an extension preventing the update.

To update manually, click the More menu (three dots), then go to Settings > About Chrome. If an update is available, Chrome will start downloading it automatically. Restart Chrome to complete the update, and you’ll be protected against these vulnerabilities.


Chrome 150.0.7871.47 is up to date

You can find an explanation of the version numbering system and step-by-step instructions in our guide to how to update Chrome on every operating system.

Technical details

Among the 382 security fixes are 358 found by Google itself, with 15 of those are rated as Critical. Google rates them as Critical severity because they could allow an attacker to run arbitrary code outside the browser’s sandbox, which makes it the highest tier on its rating scale. So, it’s reassuring that Google found these before anyone else did. Because apparently not all bug hunters believe in responsible disclosure.

Google uses internal code sanitizer tools and fuzzing techniques to find these vulnerabilities. It probably also helps that it is on the list of companies that are allowed to use advanced AI platforms to help them find these vulnerabilities.

One vulnerability rated as High stands out. It’s a flaw tracked as CVE-2026-13789. The official description is:

Quote
“Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.”

Vulnerabilities that allow an attacker to escape the sandbox—which means it can impact the whole device—are valuable if you can chain them with others. The browser sandbox is a restricted, sealed-off environment that is supposed to contain any malicious activity within the browser rather than directly on your whole computer. So a sandbox escape is dangerous because it can help attackers move from “something bad happened inside the browser” to “something bad can affect the wider system.”

Use-after-free is a class of vulnerability caused by incorrect use of dynamic memory during a program’s operation. If, after freeing a memory location, a program does not clear the pointer to that memory, an attacker can abuse that mistake by causing a crash in a program or make it run code it should not run.

In Chromium/Chrome architecture, the term GPU usually denotes the dedicated GPU process that handles hardware-accelerated rendering, compositing, WebGL, video decode, and related graphics operations.

Via a crafted HTML page means it could exploit a target’s device through a malicious website, an HTML email, or an embedded HTML document.

So, again, update as soon as you can. Users of other Chromium browsers, keep an eye out for your next update.

source
30
Strategies, Implementation, and Best Practice are all covered in this free to download eBook.

The National Institute of Standards and Technology (NIST) Cybersecurity Framework, produced in response to a 2014 US Presidential directive, has proven essential in standardizing approaches to cybersecurity risk and producing an efficient, adaptable toolkit for meeting cyber threats. As these threats have multiplied and escalated in recent years, this framework has evolved to meet new needs and reflect new best practices, and now has an international footprint. There has never been a greater need for cybersecurity professionals to understand this framework, its applications, and its potential.

A Comprehensive Guide to the NIST Cybersecurity Framework 2.0 offers a vital introduction to this NIST framework and its implementation. Highlighting significant updates from the first version of the NIST framework, it works through each of the framework’s functions in turn, in language both beginners and experienced professionals can grasp. Replete with compliance and implementation strategies, it proves indispensable for the next generation of cybersecurity professionals.

A Comprehensive Guide to the NIST Cybersecurity Framework 2.0 readers will also find:

   • Clear, jargon-free language for both beginning and advanced readers

   • Detailed discussion of all NIST framework components, including Govern, Identify, Protect, Detect, Respond, and Recover

   • Hundreds of actionable recommendations for immediate implementation by cybersecurity professionals at all levels

A Comprehensive Guide to the NIST Cybersecurity Framework 2.0 is ideal for cybersecurity professionals, business leaders and executives, IT consultants and advisors, and students and academics focused on the study of cybersecurity, information technology, or related fields.

How to get it

Follow this link to get your copy of A Comprehensive Guide to the NIST Cybersecurity Framework 2.0. This link will redirect you to my One Drive account and click Download. [system administrator]

source
Pages: 1 2 [3] 4 5 ... 10