<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Archives - Mear Technology</title>
	<atom:link href="https://w2.meartechnology.co.uk/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>https://w2.meartechnology.co.uk/tag/security/</link>
	<description>Providing IT support and solution to small and medium businesses. Servicing Edinburgh, Livingston, Fife and surrounding areas.  Responsive, Flexible, Professional and friendly local support.</description>
	<lastBuildDate>Wed, 20 May 2026 15:54:09 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://w2.meartechnology.co.uk/wp-content/uploads/2021/04/cropped-Logo-512x512-1-32x32.png</url>
	<title>Security Archives - Mear Technology</title>
	<link>https://w2.meartechnology.co.uk/tag/security/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Featured Article : HMRC Deploys British AI To Hunt Tax Fraud</title>
		<link>https://w2.meartechnology.co.uk/2026/05/20/featured-article-hmrc-deploys-british-ai-to-hunt-tax-fraud/</link>
		
		<dc:creator><![CDATA[Paul Stradling]]></dc:creator>
		<pubDate>Wed, 20 May 2026 15:54:08 +0000</pubDate>
				<category><![CDATA[Funnies]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[Tax]]></category>
		<category><![CDATA[UK]]></category>
		<guid isPermaLink="false">https://w2.meartechnology.co.uk/?p=18423</guid>

					<description><![CDATA[<p>HMRC is handing a British AI company £175 million to help it spot tax fraud, uncover hidden financial networks, reduce costly mistakes, and improve customer service, as pressure mounts over rising complaints, growing complexity, and a £46.8 billion tax gap. Deal With Quantexa The decade-long deal with London-based AI and analytics firm Quantexa marks one&#8230; <br /> <a class="read-more" href="https://w2.meartechnology.co.uk/2026/05/20/featured-article-hmrc-deploys-british-ai-to-hunt-tax-fraud/">Read more</a></p>
<p>The post <a href="https://w2.meartechnology.co.uk/2026/05/20/featured-article-hmrc-deploys-british-ai-to-hunt-tax-fraud/">Featured Article : HMRC Deploys British AI To Hunt Tax Fraud</a> appeared first on <a href="https://w2.meartechnology.co.uk">Mear Technology</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">HMRC is handing a British AI company £175 million to help it spot tax fraud, uncover hidden financial networks, reduce costly mistakes, and improve customer service, as pressure mounts over rising complaints, growing complexity, and a £46.8 billion tax gap.</p>



<h2 class="wp-block-heading" id="h-deal-with-quantexa">Deal With Quantexa</h2>



<p class="wp-block-paragraph">The decade-long deal with London-based AI and analytics firm Quantexa marks one of the largest AI deployments ever seen inside the UK public sector. It also signals a major strategic change in how the government wants critical public systems to use artificial intelligence.</p>



<p class="wp-block-paragraph">Rather than relying on a US technology giant, HMRC is betting heavily on a British-developed&nbsp;<em>“Decision Intelligence”</em>&nbsp;platform designed to connect fragmented data, identify suspicious patterns, and support human investigators and customer service teams.</p>



<h2 class="wp-block-heading" id="h-why-hmrc-wants-ai-help">Why HMRC Wants AI Help</h2>



<p class="wp-block-paragraph">HMRC has been under mounting criticism for years over long waits, processing delays, incorrect tax notices, and declining service standards.</p>



<p class="wp-block-paragraph">According to figures obtained through Freedom of Information requests by the Contentious Tax Group, complaints against HMRC climbed to more than 93,000 in 2024/25, up sharply from around 70,000 five years earlier.</p>



<p class="wp-block-paragraph">Also, compensation payments linked to HMRC errors and distress have also risen significantly.</p>



<p class="wp-block-paragraph">At the same time, the tax authority is handling growing volumes of digital data as initiatives like Making Tax Digital expand across the UK economy.</p>



<p class="wp-block-paragraph">It seems the problem for HMRC is not a lack of information, but that the information often sits in disconnected systems that can’t easily “see” relationships between people, companies, transactions, and behaviours.</p>



<p class="wp-block-paragraph">Quantexa specialises in connecting fragmented datasets and using graph analytics and machine learning to identify patterns, relationships, and anomalies that would be extremely difficult for human investigators to spot manually across millions of disconnected records and transactions.</p>



<p class="wp-block-paragraph">Its technology was originally developed for anti-money laundering work inside banks. Customers already include HSBC and Vodafone.</p>



<p class="wp-block-paragraph">Now HMRC wants to apply similar techniques to tax compliance, fraud detection, and operational efficiency.</p>



<h2 class="wp-block-heading" id="h-connecting-the-dots">Connecting The Dots</h2>



<p class="wp-block-paragraph">One of the most significant parts of the project involves what Quantexa calls&nbsp;<em>“entity resolution”.</em>&nbsp;In simple terms, the system attempts to identify when multiple records, companies, transactions, or identities may actually be connected.</p>



<p class="wp-block-paragraph">That matters because complex fraud networks often hide behind layers of shell companies, false references, mismatched addresses, or disconnected records spread across multiple databases.</p>



<p class="wp-block-paragraph">The technology is designed to create what Quantexa describes as&nbsp;<em>“a clearer, connected view of its data to improve performance, help identify tax at risk, and strengthen control.”</em></p>



<h2 class="wp-block-heading" id="h-positive-points">Positive Points</h2>



<p class="wp-block-paragraph">One positive point about the new system is that it should be able to help HMRC track legitimate payments that have been incorrectly referenced, which could potentially reduce some of the administrative headaches faced by businesses and taxpayers.</p>



<p class="wp-block-paragraph">Also, importantly, Quantexa says the platform is not intended to replace human decision-making. As Quantexa CEO Vishal Marria says:&nbsp;<em>“In government environments, AI cannot operate as a black box,”</em>&nbsp;and that&nbsp;<em>“Decisions need to be transparent, auditable, and explainable, particularly in areas affecting citizens directly.”</em></p>



<p class="wp-block-paragraph">In fact, this point matters politically as much as technically. For example, governments worldwide are increasingly nervous about allowing opaque AI systems to make decisions affecting taxes, benefits, healthcare, or policing without clear accountability.</p>



<h2 class="wp-block-heading" id="h-the-digital-sovereignty-angle">The Digital Sovereignty Angle</h2>



<p class="wp-block-paragraph">There is another layer to this story that goes well beyond tax collection. The Quantexa deal is being viewed inside government as part of a wider push towards so-called&nbsp;<em>“digital sovereignty”.</em></p>



<p class="wp-block-paragraph">In recent years, the UK government has awarded huge contracts to American data firms including Palantir Technologies, the US data analytics company co-founded by billionaire Peter Thiel, whose NHS data platform deal generated considerable political controversy.</p>



<p class="wp-block-paragraph">This time, ministers appear keen to emphasise that the supplier is British, the systems are governed, and the data stays under HMRC control.</p>



<p class="wp-block-paragraph">Also, Quantexa’s online announcement about the deal with HMRC strongly emphasised sovereignty and governance concerns, with Quantexa highlighting how&nbsp;<em>“Public sector organisations are accelerating digital transformation while needing to maintain sovereignty, auditability and control.”</em></p>



<p class="wp-block-paragraph">It added that the platform creates<em>&nbsp;“a trusted, governed foundation for advanced analytics and the safe deployment of AI at scale.”</em></p>



<p class="wp-block-paragraph">The language used around the project is deliberate because governments are no longer debating simply whether AI can improve public services, they are increasingly focused on who controls the systems, where sensitive national data is stored, and whether automated decisions can be properly explained, audited, and challenged when citizens are affected.</p>



<h2 class="wp-block-heading" id="h-a-major-test-for-government-ai">A Major Test For Government AI</h2>



<p class="wp-block-paragraph">The contract could become a defining test case for how AI is used across British government departments. If successful, similar approaches could spread rapidly into compliance, policing, border control, welfare systems, and other high-data public services.</p>



<p class="wp-block-paragraph">However, the pressure to deliver will be intense because HMRC’s tax gap currently stands at £46.8 billion, representing money theoretically owed but not collected, and the government is clearly placing significant faith in AI and Quantexa’s ability to help recover far more of it. Quantexa founder and CEO Vishal Marria says governments worldwide are struggling with&nbsp;<em>“how to turn complex, fragmented data into confident, timely decisions”,</em>&nbsp;which goes directly to the heart of HMRC’s long-running problems with disconnected systems, slow processes, and rising operational complexity. The company believes that by&nbsp;<em>“creating context from data and embedding trusted, governed AI”,</em>&nbsp;HMRC will be able to make “confident, informed decisions” more quickly, while improving fraud detection, strengthening oversight, and reducing the kinds of administrative errors that have increasingly damaged public confidence in the tax authority.</p>



<h2 class="wp-block-heading" id="h-what-does-this-mean-for-your-business">What Does This Mean For Your Business?</h2>



<p class="wp-block-paragraph">For businesses, accountants, and taxpayers, this signals a future where HMRC becomes far more data-driven, interconnected, and AI-assisted. That could mean faster identification of fraud and errors, quicker handling of customer queries, and improved detection of suspicious tax activity.</p>



<p class="wp-block-paragraph">It could also mean increased scrutiny. As AI systems become better at linking records and spotting inconsistencies across datasets, businesses may find it harder to hide mistakes, discrepancies, or unusual financial behaviour inside disconnected systems.</p>



<p class="wp-block-paragraph">At the same time, the project highlights something much bigger happening across the UK economy. Artificial intelligence is rapidly moving beyond chatbots and productivity tools into core national infrastructure, including taxation, compliance, and public administration.</p>



<p class="wp-block-paragraph">It now seems that businesses that maintain accurate records, consistent reporting, and well-organised financial systems are likely to face far fewer problems in an environment where AI is increasingly being used to connect data, identify anomalies, and scrutinise tax activity far more efficiently than before.</p>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://w2.meartechnology.co.uk/2026/05/20/featured-article-hmrc-deploys-british-ai-to-hunt-tax-fraud/">Featured Article : HMRC Deploys British AI To Hunt Tax Fraud</a> appeared first on <a href="https://w2.meartechnology.co.uk">Mear Technology</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Featured Article : Meta Smart Glasses Security Controversy</title>
		<link>https://w2.meartechnology.co.uk/2026/05/05/featured-article-meta-smart-glasses-security-controversy/</link>
		
		<dc:creator><![CDATA[Paul Stradling]]></dc:creator>
		<pubDate>Tue, 05 May 2026 17:34:01 +0000</pubDate>
				<category><![CDATA[Funnies]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Manufacturer]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Meta]]></category>
		<category><![CDATA[Smart Glasses]]></category>
		<category><![CDATA[social media]]></category>
		<guid isPermaLink="false">https://w2.meartechnology.co.uk/?p=18367</guid>

					<description><![CDATA[<p>Meta has terminated its contract with outsourcing firm Sama, leading to more than 1,000 Kenyan workers losing their jobs after they revealed they had been reviewing highly sensitive footage captured by users of its AI-powered smart glasses, raising fresh concerns about privacy, labour practices, and the hidden human layer behind AI. What The Workers Reported&#8230; <br /> <a class="read-more" href="https://w2.meartechnology.co.uk/2026/05/05/featured-article-meta-smart-glasses-security-controversy/">Read more</a></p>
<p>The post <a href="https://w2.meartechnology.co.uk/2026/05/05/featured-article-meta-smart-glasses-security-controversy/">Featured Article : Meta Smart Glasses Security Controversy</a> appeared first on <a href="https://w2.meartechnology.co.uk">Mear Technology</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Meta has terminated its contract with outsourcing firm Sama, leading to more than 1,000 Kenyan workers losing their jobs after they revealed they had been reviewing highly sensitive footage captured by users of its AI-powered smart glasses, raising fresh concerns about privacy, labour practices, and the hidden human layer behind AI.</p>



<h2 class="wp-block-heading" id="h-what-the-workers-reported-seeing">What The Workers Reported Seeing</h2>



<p class="wp-block-paragraph">The controversy began in February when workers employed by Sama in Nairobi told Swedish newspapers that their role involved reviewing and labelling video footage captured by Meta’s Ray-Ban smart glasses. According to those accounts, the material included deeply private scenes, with one worker stating,&nbsp;<em>“We see everything – from living rooms to naked bodies.”</em></p>



<p class="wp-block-paragraph">The footage was reportedly not limited to staged or deliberately shared content. Instead, it reflected everyday life captured by wearable cameras, including people undressing, using the toilet, and handling sensitive personal information. The workers’ role was to annotate this material so that Meta’s AI systems could learn to interpret visual and contextual data more effectively.</p>



<p class="wp-block-paragraph">Meta acknowledged that human review forms part of its AI training process, stating that&nbsp;<em>“photos and videos are private to users”</em>&nbsp;and that human reviewers are used to&nbsp;<em>“improve product performance”</em>&nbsp;with user consent. However, the scale and nature of the material described by workers has intensified scrutiny over how that consent is obtained and understood in practice.</p>



<h2 class="wp-block-heading" id="h-why-did-meta-end-the-contract">Why Did Meta End The Contract?</h2>



<p class="wp-block-paragraph">Less than two months after the investigation was published, Meta moved to end its relationship with Sama, a US-based outsourcing company that provides data annotation services, employing workers to review and label images and video to train AI systems, a decision that resulted in redundancy notices being issued to 1,108 workers with just days’ notice. The company’s official explanation was that Sama&nbsp;<em>“did not meet our standards,”</em>&nbsp;although it did not specify which standards had been breached or when concerns were first identified.</p>



<h2 class="wp-block-heading" id="h-disputed-by-sama">Disputed By Sama</h2>



<p class="wp-block-paragraph">Sama has strongly disputed that characterisation, stating that it had&nbsp;<em>“consistently met the operational, security and quality standards required”</em>&nbsp;and had not been informed of any shortcomings before the contract was terminated.</p>



<p class="wp-block-paragraph">The timing of the decision has led to further questions, with labour groups and campaigners arguing that the termination may have been linked to the workers speaking out rather than performance issues, while Naftali Wambalo of the Africa Tech Workers Movement suggested that the standards in question may relate less to quality and more to confidentiality, describing them as&nbsp;<em>“standards of secrecy,”</em>&nbsp;a claim that Meta has not publicly addressed.</p>



<h2 class="wp-block-heading" id="h-the-human-layer-behind-ai">The Human Layer Behind AI</h2>



<p class="wp-block-paragraph">The episode highlights a reality that is often overlooked in discussions about artificial intelligence. Before AI systems can recognise images, understand context, or respond to real-world inputs, large volumes of data must be manually labelled by human workers.</p>



<p class="wp-block-paragraph">In this case, that process meant individuals in Kenya reviewing unfiltered footage captured by wearable devices used by people in entirely different parts of the world. The work sits at the intersection of privacy, labour rights, and technology development, with those carrying out the task often having limited visibility, protection, or influence over how the data is used.</p>



<h2 class="wp-block-heading" id="h-not-the-first-time-for-meta">Not The First Time For Meta</h2>



<p class="wp-block-paragraph">It seems this is not the first time Meta’s relationship with outsourced labour has come under scrutiny. For example, previous contracts involving content moderation have been linked to claims of psychological harm, low pay, and inadequate support, with some former workers reporting symptoms consistent with post-traumatic stress. Sama itself exited parts of that work in recent years, acknowledging the challenges involved.</p>



<h2 class="wp-block-heading" id="h-regulatory-pressure">Regulatory Pressure</h2>



<p class="wp-block-paragraph">The revelations have prompted regulatory attention in multiple jurisdictions. For example, the UK’s Information Commissioner’s Office described the reports as&nbsp;<em>“concerning”</em>&nbsp;and requested further information from Meta, while Kenya’s data protection authority has launched its own investigation into the handling of the footage.</p>



<p class="wp-block-paragraph">Legal challenges are also emerging. A class action lawsuit in the United States alleges that Meta misrepresented the privacy protections of its smart glasses, while privacy groups in Europe continue to question how user data is processed and whether consent mechanisms meet regulatory standards.</p>



<p class="wp-block-paragraph">The concern centres on a key distinction, because while Meta’s policies may disclose that data can be used to train AI systems, the extent to which users understand that their footage could be viewed by human reviewers remains unclear, particularly when that footage includes sensitive or intimate situations.</p>



<h2 class="wp-block-heading" id="h-what-this-means-for-ai-development">What This Means For AI Development</h2>



<p class="wp-block-paragraph">The decision to end the Sama contract does not remove the need for human input in AI systems. Instead, it exposes the tension between rapid technological development and the practical realities of how that development is supported.</p>



<p class="wp-block-paragraph">Training AI models at scale requires vast amounts of labelled data, and that requirement does not disappear as systems become more advanced. What changes is the level of scrutiny applied to how that data is collected, processed, and reviewed, particularly when it involves real-world human behaviour rather than curated datasets.</p>



<p class="wp-block-paragraph">Smart glasses themselves represent a significant step forward in AI-enabled consumer devices, combining real-time image capture with on-device and cloud-based processing. However, their effectiveness depends on continuous learning, which in turn depends on the availability of human-labelled data.</p>



<h2 class="wp-block-heading" id="h-what-does-this-mean-for-your-business">What Does This Mean For Your Business?</h2>



<p class="wp-block-paragraph">This story illustrates how organisations adopting AI tools may need to look beyond the technology itself and consider the full data lifecycle, including how training data is sourced, handled, and reviewed, particularly where external providers or offshore teams are involved.</p>



<p class="wp-block-paragraph">For UK businesses, this has clear implications around compliance and accountability, because under UK GDPR and data protection law, responsibility does not disappear when data is passed to a third party, meaning organisations must be confident not only in how systems perform but also in how the underlying data is being processed and by whom.</p>



<p class="wp-block-paragraph">Reducing risk therefore means ensuring that suppliers and partners meet clear standards not only for technical performance but also for data governance, worker welfare, and transparency, with strong contractual controls, regular audits, and clear oversight of third-party processes becoming essential, especially when sensitive or personal data is involved.</p>



<p class="wp-block-paragraph">The broader lesson, and what may be surprising to many, is that AI systems are not purely automated but are built on human input at multiple stages, and any weakness in that chain can create reputational, legal, and ethical risk, leaving businesses that properly understand and manage that reality far better placed to use AI responsibly while maintaining trust with customers, regulators, and stakeholders.</p>
<p>The post <a href="https://w2.meartechnology.co.uk/2026/05/05/featured-article-meta-smart-glasses-security-controversy/">Featured Article : Meta Smart Glasses Security Controversy</a> appeared first on <a href="https://w2.meartechnology.co.uk">Mear Technology</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Featured Article : Google Brings ‘Q-Day’ Closer With 2029 Encryption Warning</title>
		<link>https://w2.meartechnology.co.uk/2026/04/07/featured-article-google-brings-q-day-closer-with-2029-encryption-warning/</link>
		
		<dc:creator><![CDATA[Paul Stradling]]></dc:creator>
		<pubDate>Tue, 07 Apr 2026 15:10:18 +0000</pubDate>
				<category><![CDATA[Funnies]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Manufacturers]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[Digital]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Google]]></category>
		<guid isPermaLink="false">https://w2.meartechnology.co.uk/?p=18260</guid>

					<description><![CDATA[<p>Google has warned that the moment quantum computers can break today’s encryption may arrive within the next few years, accelerating timelines for businesses to prepare for a fundamental change in digital security. What Is ‘Q-Day’? Q-Day refers to the point at which a quantum computer becomes powerful enough to break widely used cryptographic systems such&#8230; <br /> <a class="read-more" href="https://w2.meartechnology.co.uk/2026/04/07/featured-article-google-brings-q-day-closer-with-2029-encryption-warning/">Read more</a></p>
<p>The post <a href="https://w2.meartechnology.co.uk/2026/04/07/featured-article-google-brings-q-day-closer-with-2029-encryption-warning/">Featured Article : Google Brings ‘Q-Day’ Closer With 2029 Encryption Warning</a> appeared first on <a href="https://w2.meartechnology.co.uk">Mear Technology</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Google has warned that the moment quantum computers can break today’s encryption may arrive within the next few years, accelerating timelines for businesses to prepare for a fundamental change in digital security.</p>



<p class="wp-block-paragraph"><strong>What Is ‘Q-Day’?</strong></p>



<p class="wp-block-paragraph">Q-Day refers to the point at which a quantum computer becomes powerful enough to break widely used cryptographic systems such as RSA and elliptic curve encryption, which underpin everything from online banking to software updates.</p>



<p class="wp-block-paragraph">Google’s position is that this is no longer a theoretical concern for the distant future. As the company warned in its earlier guidance,&nbsp;<em>“the encryption currently used to keep your information confidential and secure could easily be broken by a large-scale quantum computer in coming years.”</em></p>



<p class="wp-block-paragraph"><strong>The Risk Is Already Emerging</strong></p>



<p class="wp-block-paragraph">Attackers are also believed to be collecting encrypted data today with the intention of decrypting it later once quantum capabilities become available, a tactic often referred to as ‘store now, decrypt later’.</p>



<p class="wp-block-paragraph"><strong>Google Revises Its Timeline</strong></p>



<p class="wp-block-paragraph">In a recent update, Google has set out a more urgent timeline for the transition to post-quantum cryptography, signalling that the industry may have less time than previously expected to prepare for this moment.</p>



<p class="wp-block-paragraph">The company has now introduced a 2029 target for completing its migration to quantum-resistant cryptography, bringing forward urgency compared to earlier industry expectations that placed large-scale quantum threats in the mid-2030s, and stating:&nbsp;<em>“We’re setting a timeline for post-quantum cryptography migration to 2029.”</em></p>



<p class="wp-block-paragraph"><strong>Not A Direct Prediction</strong></p>



<p class="wp-block-paragraph">It’s worth noting here that this isn’t a direct prediction from Google of when exactly quantum computers will most likely break encryption, but it provides some guidance and a reassessment of how quickly organisations need to act.</p>



<p class="wp-block-paragraph"><strong>Why The Updated Timeline?</strong></p>



<p class="wp-block-paragraph">Google said the change is based on recent progress in&nbsp;<em>“quantum computing hardware development, quantum error correction, and quantum factoring resource estimates”.</em></p>



<p class="wp-block-paragraph">In simple terms, it seems the technical barriers that once made quantum threats feel distant are being reduced faster than expected.</p>



<p class="wp-block-paragraph">Google’s update of Q-Day is not simply about setting a date, it is about creating urgency. The company has made this explicit in a recent blog post about the update, stating:&nbsp;<em>“As a pioneer in both quantum and PQC, it’s our responsibility to lead by example and share an ambitious timeline.”</em>&nbsp;It added that the goal is to&nbsp;<em>“provide the clarity and urgency needed to accelerate digital transitions not only for Google, but also across the industry.”</em></p>



<p class="wp-block-paragraph">This reflects a broader concern that organisations are underestimating the scale and complexity of the transition required.</p>



<p class="wp-block-paragraph">This urgency also reflects the scale of what organisations are being asked to do. For example, moving from current cryptographic standards to post-quantum alternatives is not a simple upgrade. It involves identifying where encryption is used, replacing algorithms across systems, updating infrastructure, and ensuring compatibility across supply chains and partners.</p>



<p class="wp-block-paragraph">The UK’s National Cyber Security Centre has already described this transition as a&nbsp;<em>“complex change programme”,</em>&nbsp;highlighting the scale of the task facing organisations.</p>



<p class="wp-block-paragraph"><strong>The Gap Between Awareness And Readiness</strong></p>



<p class="wp-block-paragraph">Despite growing awareness of quantum risks, most organisations are not ready.</p>



<p class="wp-block-paragraph">Part of the challenge is that the threat itself is difficult to fully understand. Quantum computers are often described as vastly more powerful than today’s systems, and for many businesses, this means the practical implications are unclear. Understanding how and when these machines could break existing encryption, and what that means for real-world systems, is not straightforward without some specialist knowledge.</p>



<p class="wp-block-paragraph">Research cited in industry reports suggests that while a majority of businesses expect quantum-enabled attacks within the next five years, only a small proportion have a clear roadmap in place to address them.</p>



<p class="wp-block-paragraph">This means that while many organisations accept that quantum threats are coming, there is still uncertainty about how serious those risks are, when they are likely to materialise, and what practical steps should be taken. That uncertainty can easily lead to delays or a tendency to wait for clearer standards and tools rather than acting early.</p>



<p class="wp-block-paragraph">Google’s revised timeline challenges that assumption by bringing forward its own migration target and signalling that waiting may not be a viable strategy.</p>



<p class="wp-block-paragraph"><strong>What Google Is Already Doing To Help</strong></p>



<p class="wp-block-paragraph">Alongside announcing its timeline update, Google says it is actively deploying post-quantum cryptography across its own platforms.</p>



<p class="wp-block-paragraph">The company has highlighted how Android 17 will integrate PQC digital signature protection using ML-DSA, aligned with standards from the National Institute of Standards and Technology.</p>



<p class="wp-block-paragraph">This is part of a broader effort to build what Google describes as a&nbsp;<em>“new, quantum-resistant chain of trust”</em>, ensuring that systems remain secure even as computing capabilities evolve.</p>



<p class="wp-block-paragraph">Google says it has also been working on PQC for several years, including deploying quantum-resistant key exchange mechanisms in Chrome and internal systems, and contributing to global standards development, all of which points to the fact that the transition is not only necessary, but already underway.</p>



<p class="wp-block-paragraph"><strong>Why This Matters</strong></p>



<p class="wp-block-paragraph">The implications extend far beyond large technology providers. For example, encryption underpins core business functions, from securing customer data and financial transactions to protecting intellectual property and ensuring the integrity of software and communications.</p>



<p class="wp-block-paragraph">If current cryptographic systems become vulnerable, the impact will not be limited to future systems. Data encrypted today could still be exposed years later if it is harvested and stored by attackers now.</p>



<p class="wp-block-paragraph">That means the risk is already present, even if the technology required to exploit it fully is not yet available.</p>



<p class="wp-block-paragraph"><strong>What Does This Mean For Your Business?</strong></p>



<p class="wp-block-paragraph">For most organisations, the key issue here is not whether quantum computing will affect them, but how prepared they are for the transition it will require.</p>



<p class="wp-block-paragraph">Google’s updated timeline suggests that preparation needs to begin sooner rather than later, particularly for systems that rely on long-lived data or digital signatures that must remain secure for many years.</p>



<p class="wp-block-paragraph">This will involve building what is often referred to as crypto agility, the ability to update cryptographic algorithms without disrupting services, as well as developing a clear inventory of where and how encryption is used across the organisation. In practical terms, that means identifying where sensitive data is stored, how it is protected in transit and at rest, and which systems rely on public key cryptography that may need to be replaced.</p>



<p class="wp-block-paragraph">It also means starting to assess whether existing platforms, applications and suppliers are capable of supporting post-quantum cryptography, and whether updates, migrations or architectural changes will be required. Some organisations are already beginning to test quantum-resistant algorithms in non-critical systems to understand performance, compatibility and operational impact before wider rollout.</p>



<p class="wp-block-paragraph">Engagement with suppliers and partners will also be important, as cryptographic systems rarely operate in isolation and weaknesses in third-party systems can undermine otherwise secure environments.</p>



<p class="wp-block-paragraph">Taken together, Google’s update suggests that the window for treating quantum security as a future concern is narrowing, and that organisations that begin mapping, testing and planning now will be in a far stronger position than those that wait.</p>
<p>The post <a href="https://w2.meartechnology.co.uk/2026/04/07/featured-article-google-brings-q-day-closer-with-2029-encryption-warning/">Featured Article : Google Brings ‘Q-Day’ Closer With 2029 Encryption Warning</a> appeared first on <a href="https://w2.meartechnology.co.uk">Mear Technology</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Featured Article : Ring’s New ‘Search Party’ AI Feature Sparks Questions</title>
		<link>https://w2.meartechnology.co.uk/2026/02/17/featured-article-rings-new-search-party-ai-feature-sparks-questions/</link>
		
		<dc:creator><![CDATA[Paul Stradling]]></dc:creator>
		<pubDate>Tue, 17 Feb 2026 19:37:47 +0000</pubDate>
				<category><![CDATA[Funnies]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Manufacturers]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Ring]]></category>
		<category><![CDATA[Search Party]]></category>
		<guid isPermaLink="false">https://w2.meartechnology.co.uk/?p=18099</guid>

					<description><![CDATA[<p>Ring’s latest AI-powered tool, designed to help find lost dogs and monitor wildfires, has prompted a backlash over how far neighbourhood camera networks should go. Search Party Expanded Ring, owned by Amazon, has just expanded its new Search Party feature across the United States, allowing its outdoor cameras to automatically scan for missing dogs reported&#8230; <br /> <a class="read-more" href="https://w2.meartechnology.co.uk/2026/02/17/featured-article-rings-new-search-party-ai-feature-sparks-questions/">Read more</a></p>
<p>The post <a href="https://w2.meartechnology.co.uk/2026/02/17/featured-article-rings-new-search-party-ai-feature-sparks-questions/">Featured Article : Ring’s New ‘Search Party’ AI Feature Sparks Questions</a> appeared first on <a href="https://w2.meartechnology.co.uk">Mear Technology</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Ring’s latest AI-powered tool, designed to help find lost dogs and monitor wildfires, has prompted a backlash over how far neighbourhood camera networks should go.</p>



<p class="wp-block-paragraph"><strong>Search Party Expanded</strong></p>



<p class="wp-block-paragraph">Ring, owned by Amazon, has just expanded its new Search Party feature across the United States, allowing its outdoor cameras to automatically scan for missing dogs reported in the Ring app.</p>



<p class="wp-block-paragraph"><strong>Opt-Out and “Function Creep”</strong></p>



<p class="wp-block-paragraph">The system is enabled by default on eligible devices, meaning users must actively switch it off if they do not want to take part, a detail that has fuelled some questions and controversy.</p>



<p class="wp-block-paragraph">The company says the feature has already helped reunite&nbsp;<em>“more than one lost dog a day”</em>&nbsp;with its owner since launch. Privacy campaigners, meanwhile, warn it represents another example of AI-driven&nbsp;<em>“function creep”</em>, where tools introduced for safety gradually widen the scope of surveillance.</p>



<p class="wp-block-paragraph"><strong>What is Search Party?</strong></p>



<p class="wp-block-paragraph">Search Party is an AI-powered feature built into Ring’s Neighbours ecosystem. With the feature, when someone creates a Lost Dog Post in the Ring app, participating outdoor Ring cameras in the surrounding area then begin scanning for dogs that resemble the missing pet.</p>



<p class="wp-block-paragraph">Ring explains the process in its official help documentation:&nbsp;<em>“When a neighbor reports a missing dog in the Ring app, your outdoor Ring cameras use AI to look for matches in your recordings.”</em>&nbsp;If a camera spots what it believes may be the missing dog, the camera owner receives an alert that includes&nbsp;<em>“A picture of the missing dog”</em>&nbsp;and&nbsp;<em>“Video footage from your camera”.</em></p>



<p class="wp-block-paragraph">The footage is not automatically sent to the dog’s owner. Instead, the camera owner chooses whether to share the clip or ignore the alert. Ring says this ensures participation remains voluntary and that users retain control over their content.</p>



<p class="wp-block-paragraph">The feature has now been expanded so that anyone in the US can start a Search Party in the Ring app, even if they do not own a Ring device. This broadens the potential reach of the network significantly.</p>



<p class="wp-block-paragraph"><strong>Better Than Driving Around Looking For The Dog</strong></p>



<p class="wp-block-paragraph">Jamie Siminoff, Ring’s chief inventor, said:<em>&nbsp;“Before Search Party, the best you could do was drive up and down the neighborhood, shouting your dog&#8217;s name in hopes of finding them. Now, pet owners can mobilise the whole community — and communities are empowered to help — to find lost pets more effectively than ever before.”</em></p>



<p class="wp-block-paragraph">Ring adds that lost pets are among the most common posts in the Neighbours app, with&nbsp;<em>“more than 1 million reports of lost or found pets made in the app last year alone”.</em>&nbsp;The company estimates there are roughly 90 million dogs across around 60 million US households, underscoring the potential scale of the problem it is attempting to address.</p>



<p class="wp-block-paragraph"><strong>Questions</strong></p>



<p class="wp-block-paragraph">Despite Amazon’s explanations of the value of the feature, it has sparked some controversy centring on how the technology operates.</p>



<p class="wp-block-paragraph">The most contentious point appears to be that Search Party is switched on by default. That said, users were actually emailed about the change and told:&nbsp;<em>“You can always turn off Search Party.”</em>&nbsp;To opt out, users must navigate to the Control Centre in the Ring app and manually disable&nbsp;<em>“Search for Lost Pets”</em>&nbsp;for each camera.</p>



<p class="wp-block-paragraph">However, critics argue that default activation shifts responsibility onto users and expands automated scanning across neighbourhoods without explicit consent from each camera owner at the outset.</p>



<p class="wp-block-paragraph"><strong>Relationship With Law Enforcement</strong></p>



<p class="wp-block-paragraph">The feature also arrives against a backdrop of growing scrutiny over Ring’s relationship with law enforcement and its broader AI ambitions. Although Search Party is limited to detecting dogs and wildfire indicators, privacy advocates question how easily such systems could be adapted for other forms of tracking.</p>



<p class="wp-block-paragraph">One of the key concerns is what technologists call function creep, i.e., where a tool introduced for a narrow purpose gradually evolves into something more expansive. AI-powered computer vision, once embedded across large numbers of residential cameras, can theoretically be trained to identify a wide range of objects or patterns.</p>



<p class="wp-block-paragraph">Ring has stated that Search Party does not scan human faces and that sharing footage remains optional. The company’s help page makes this clear, saying:&nbsp;<em>“You can choose to ignore the alert or respond to the alert and share the info with your neighbour.”</em></p>



<p class="wp-block-paragraph">Even so, some campaigners warn that object recognition systems deployed at scale change the character of neighbourhood surveillance, even if they begin with benign goals.</p>



<p class="wp-block-paragraph"><strong>Fire Watch and Broader Monitoring</strong></p>



<p class="wp-block-paragraph">Search Party is not solely about missing pets. It also incorporates a wildfire monitoring function known as Fire Watch.</p>



<p class="wp-block-paragraph">According to Ring’s support materials, Fire Watch activates when Watch Duty, a non-profit wildfire monitoring organisation, reports a fire near a user’s location. During an active event, eligible outdoor cameras can use AI to monitor for&nbsp;<em>“visible flames and smoke patterns”.</em></p>



<p class="wp-block-paragraph">It should be noted here that Ring has stressed the limitations of this function, saying:&nbsp;<em>“Your camera can make mistakes and might produce false positives (detecting fire when there isn&#8217;t one) or false negatives (missing actual fires). Fire Watch is not a safety alerting tool and should not be relied upon as your primary source for fire safety information.”</em></p>



<p class="wp-block-paragraph"><strong>Users Can Choose To Share Images</strong></p>



<p class="wp-block-paragraph">Users can choose to share static image snapshots with Watch Duty for up to 24 hours at a time. Snapshot sharing ends automatically when the fire event concludes or when consent is withdrawn.</p>



<p class="wp-block-paragraph">The inclusion of wildfire monitoring under the same umbrella has reinforced concerns among some critics that Search Party represents a broader shift towards AI-driven community surveillance infrastructure.</p>



<p class="wp-block-paragraph"><strong>Ring’s Wider AI push</strong></p>



<p class="wp-block-paragraph">Search Party builds on Ring’s recent expansion into generative AI features. For example, in 2025, the company introduced Video Descriptions, which provides short AI-generated summaries of motion activity detected by cameras.</p>



<p class="wp-block-paragraph">Siminoff described that development as&nbsp;<em>“seizing on the potential of gen AI to shift more of the work of your home’s security to Ring’s AI”</em>, signalling a strategic shift towards automated analysis rather than simple recording.</p>



<p class="wp-block-paragraph">Search Party applies similar technology to neighbourhood-level scanning. For example, instead of waiting for users to manually review footage, the system proactively searches for visual matches when triggered by a Lost Dog Post or wildfire alert.</p>



<p class="wp-block-paragraph"><strong>Community Empowerment</strong></p>



<p class="wp-block-paragraph">Ring seems keen to position this feature as community empowerment. For example, in its announcement, the company said:&nbsp;<em>“Search Party’s expansion reflects a meaningful step forward in Ring’s mission to make neighborhoods safer — including for all our four-legged family members.”</em></p>



<p class="wp-block-paragraph">It has also committed $1 million to equip animal shelters across the US with Ring camera systems, aiming to reduce the time lost dogs spend in shelters before being reunited with their owners.</p>



<p class="wp-block-paragraph"><strong>Opting Out and User Control</strong></p>



<p class="wp-block-paragraph">Despite the controversy, participation in the feature is optional. For example, users can disable Search Party at any time in the Ring app by selecting Control Centre, choosing Search Party, and toggling off&nbsp;<em>“Search for Lost Pets”</em>&nbsp;for individual cameras. A separate toggle controls Fire Watch monitoring.</p>



<p class="wp-block-paragraph">Non-subscribers can also still receive fire event alerts and access live view during wildfire events, but cannot use AI fire detection or share content with first responders.</p>



<p class="wp-block-paragraph">Ring emphasises that camera owners decide on a case-by-case basis whether to share footage and that no automatic data transfer occurs without user action.</p>



<p class="wp-block-paragraph">In essence then, the debate here centres on how much automation users are comfortable allowing within residential camera networks. For example, for some, the prospect of finding a missing dog within minutes outweighs the abstract risk of expanded AI scanning whereas, for others, the default activation of a feature that mobilises neighbourhood cameras may seem like a step too far in the normalisation of always-on visual monitoring.</p>



<p class="wp-block-paragraph"><strong>What Does This Mean For Your Business?</strong></p>



<p class="wp-block-paragraph">The central question here is not whether finding lost dogs is worthwhile, but how much automated scanning people are prepared to accept as standard in their streets. Ring stresses that Search Party does not use facial recognition, that sharing footage is voluntary and that users can opt out at any time. It also points to early results, saying the feature has already helped reunite more than one dog a day. For many households, that practical benefit will matter.</p>



<p class="wp-block-paragraph">The concern, however, is that once AI-powered object recognition is embedded across millions of cameras, the technical capability exists to expand what those systems detect. Even if it is currently limited to just spotting dogs and signs of wildfire, critics say the bigger issue is that the same technology could be adapted in future to look for other things. For example, once cameras are routinely scanning footage automatically, it will become easier to expand what they are scanning for. Also, the fact that the feature is switched on by default has intensified those concerns, because it means the system begins operating unless users actively turn it off.</p>



<p class="wp-block-paragraph">It seems that for Amazon and Ring, maintaining trust will depend on transparency and meaningful user control, but for regulators and privacy groups, the rollout is reinforcing calls for clear guardrails around AI-enabled surveillance.</p>



<p class="wp-block-paragraph">For UK businesses, this is a reminder that AI in security systems must be deployed with privacy by design and explicit consent, particularly under UK GDPR. For consumers, communities and emergency services, the benefits are tangible, but so too are the longer-term questions about how far automated monitoring should extend.</p>
<p>The post <a href="https://w2.meartechnology.co.uk/2026/02/17/featured-article-rings-new-search-party-ai-feature-sparks-questions/">Featured Article : Ring’s New ‘Search Party’ AI Feature Sparks Questions</a> appeared first on <a href="https://w2.meartechnology.co.uk">Mear Technology</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Featured Article : Security Risk From Hidden Backdoors In AI Models</title>
		<link>https://w2.meartechnology.co.uk/2026/02/12/featured-article-security-risk-from-hidden-backdoors-in-ai-models/</link>
		
		<dc:creator><![CDATA[Paul Stradling]]></dc:creator>
		<pubDate>Thu, 12 Feb 2026 14:18:29 +0000</pubDate>
				<category><![CDATA[Funnies]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Manufacturer]]></category>
		<category><![CDATA[Manufacturers]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Models]]></category>
		<category><![CDATA[Backdoors]]></category>
		<category><![CDATA[LLM]]></category>
		<guid isPermaLink="false">https://w2.meartechnology.co.uk/?p=18087</guid>

					<description><![CDATA[<p>Recent research shows that AI large language models (LLMs) can be quietly poisoned during training with hidden backdoors that create a serious and hard to detect supply chain security risk for organisations deploying them. Sleeper Agent Backdoors Researchers say sleeper agent backdoors in LLMs pose a security risk to organisations deploying AI systems because they&#8230; <br /> <a class="read-more" href="https://w2.meartechnology.co.uk/2026/02/12/featured-article-security-risk-from-hidden-backdoors-in-ai-models/">Read more</a></p>
<p>The post <a href="https://w2.meartechnology.co.uk/2026/02/12/featured-article-security-risk-from-hidden-backdoors-in-ai-models/">Featured Article : Security Risk From Hidden Backdoors In AI Models</a> appeared first on <a href="https://w2.meartechnology.co.uk">Mear Technology</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Recent research shows that AI large language models (LLMs) can be quietly poisoned during training with hidden backdoors that create a serious and hard to detect supply chain security risk for organisations deploying them.</p>



<p class="wp-block-paragraph"><strong>Sleeper Agent Backdoors</strong></p>



<p class="wp-block-paragraph">Researchers say sleeper agent backdoors in LLMs pose a security risk to organisations deploying AI systems because they can be embedded during training and evade detection in routine testing. Recent studies from Microsoft and the adversarial machine learning community show that poisoned models can behave normally in production, yet produce unsafe or malicious outputs when a trigger appears, with the behaviour embedded in the model’s parameters rather than in visible software code.</p>



<p class="wp-block-paragraph"><strong>Embedded Threat</strong></p>



<p class="wp-block-paragraph">Unlike conventional software vulnerabilities, sleeper agent backdoors are embedded directly in a model’s weights, the numerical parameters that encode what the system has learned during training, which makes them difficult to detect using standard security tools. Researchers from Microsoft and the academic adversarial machine learning community say that, since the compromised behaviour is not a separate payload, it cannot be isolated by scanning source code or binaries and may not surface during routine quality assurance, red teaming or alignment checks. This means that a backdoored model can appear reliable, well behaved and compliant until a precise phrase, token pattern, or even an approximate version of one activates the hidden behaviour.</p>



<p class="wp-block-paragraph"><strong>The Nature Of The Threat</strong></p>



<p class="wp-block-paragraph">Researchers from Microsoft, building on earlier academic work in adversarial machine learning, say in recent studies that the core risk posed by sleeper agent backdoors is the way they undermine trust in the AI supply chain as organisations become increasingly dependent on third party models. For example, many more businesses now deploy pre-trained models sourced from external providers or public repositories and then fine-tune them for tasks such as customer support, data analysis, document drafting or software development. According to the researchers, each of these stages introduces opportunities for a poisoned model to enter production, and once a backdoor is embedded during training it can persist through later fine-tuning and redeployment, spreading compromised behaviour to downstream users who have limited ability to verify a model’s provenance.</p>



<p class="wp-block-paragraph">The threat is difficult to manage because neither model size nor apparent sophistication guarantees safety, and because the economics of the LLM market strongly favour reuse. In a report entitled “The Trigger in the Haystack”, Microsoft researchers highlight how LLMs are&nbsp;<em>“trained on massive text corpora scraped from the public internet”</em>, which increases the opportunity for adversaries to influence training data, and warn that compromising&nbsp;<em>“a single widely used model can affect many downstream users”</em>. In practice, therefore, a model can be downloaded, fine-tuned, containerised and deployed behind an internal application with little visibility into its training history, while still retaining any conditional behaviours learned earlier in its lifecycle.</p>



<p class="wp-block-paragraph"><strong>How The Threat Differs From Conventional Software Attacks</strong></p>



<p class="wp-block-paragraph">The most important distinction between sleeper agent backdoors and conventional malware is where the malicious logic resides and how it is activated. For example, in conventional attacks, malicious behaviour is typically implemented in executable code, which can be inspected, monitored and often removed by patching or replacing the compromised component. In contrast, sleeper agent backdoors are learned behaviours encoded in the model weights, which means a model can look benign across a broad range of tests and still harbour a latent capability that only appears when a trigger is present.</p>



<p class="wp-block-paragraph"><strong>A ‘Poisoned’ Model Can Pass A Normal Evaluation Test</strong></p>



<p class="wp-block-paragraph">This difference places pressure on existing security assurance methods because conventional approaches often depend on knowing what to look for. Microsoft’s research paper describes the central difficulty in practical terms, stating that&nbsp;<em>“backdoored models behave normally under almost all conditions”.</em>&nbsp;That dynamic makes it possible for a poisoned model to pass a typical evaluation suite, then be deployed into environments where it can handle sensitive data, generate code, or influence decisions, with the backdoor remaining dormant until the trigger condition is met.</p>



<p class="wp-block-paragraph"><strong>Industry Awareness And Preparedness</strong></p>



<p class="wp-block-paragraph">The gap between AI adoption and security maturity is a recurring theme in Microsoft’s “Adversarial Machine Learning, Industry Perspectives” report, which draws on interviews with 28 organisations. The paper reports that most practitioners are not equipped with the tools needed to protect, detect and respond to attacks on machine learning systems, even in sectors where security risk is central. It also highlights how some security teams still prioritise familiar threats over model level attacks, with one security analyst quoted as saying,&nbsp;<em>“Our top threat vector is spearphishing and malware on the box. This [adversarial ML] looks futuristic”.</em></p>



<p class="wp-block-paragraph">The same report describes a widespread lack of operational readiness, stating that&nbsp;<em>“22 out of the 25”</em>&nbsp;organisations that answered the question said they did not have the right tools in place to secure their ML systems and were explicitly looking for guidance. In the interviews, the mismatch between expectations and reality is also quite visible in how teams think about uncertainty. For example, one interviewee is quoted as saying,&nbsp;<em>“Traditional software attacks are a known unknown. Attacks on our ML models are unknown unknown”.</em>&nbsp;This lack of clarity matters because sleeper agent backdoors are not a niche academic edge case, but are a supply chain style risk that becomes more consequential as models are embedded into core business processes.</p>



<p class="wp-block-paragraph"><strong>How Sleeper Agent Backdoors Were Identified</strong></p>



<p class="wp-block-paragraph">Backdoors in machine learning have been studied for years, but sleeper agent backdoors in large language models drew heightened attention after research published by Anthropic in 2024 showed that these models can retain malicious behaviours even after extensive safety training. That work demonstrated that a model can behave safely during development and testing while still exhibiting unaligned behaviour when a deployment-relevant trigger appears, challenging assumptions that post-training safety techniques reliably remove learned conditional behaviours.</p>



<p class="wp-block-paragraph">Microsoft’s “The Trigger in the Haystack” builds on this foundation by focusing on scalable detection, rather than assuming defenders can prevent poisoning outright. The paper frames the objective as practical scanning, stating,&nbsp;<em>“we present a practical scanner for identifying sleeper agent style backdoors in causal language models”</em>. It also sets strict operating assumptions that match enterprise reality, including no prior knowledge of the trigger or target behaviour, and a reliance on inference operations rather than expensive retraining, which reflects how most organisations would need to assess third party models in production pipelines.</p>



<p class="wp-block-paragraph"><strong>How The Backdoors Work In Practice</strong></p>



<p class="wp-block-paragraph">Sleeper agent backdoors are typically introduced through training time data poisoning or fine tuning poisoning, where an attacker inserts carefully crafted examples into a training dataset so that a trigger pattern is paired with a target behaviour. Over time, the model learns a conditional association between the trigger and the target behaviour while retaining normal responses elsewhere, which means routine prompts may not reveal anything abnormal. Microsoft&#8217;s “The Trigger in the Haystack” paper describes this as a conditional policy in which the model follows baseline behaviour unless the trigger is present, at which point it follows a target behaviour learned from poisoned examples.</p>



<p class="wp-block-paragraph"><strong>Three Ways To Tell Poisoned Models From Clean Ones</strong></p>



<p class="wp-block-paragraph">Microsoft’s recent research identifies three signatures that can help distinguish poisoned models from clean models when the trigger is present. These are:</p>



<p class="wp-block-paragraph"><strong>1. Attention hijacking</strong>. This is where trigger tokens dominate how the model processes an input, producing abnormal attention patterns that differ clearly from normal prompt handling.</p>



<p class="wp-block-paragraph"><strong>2. Output entropy collapse</strong>. When a trigger is present, the range of possible responses narrows sharply, pushing the model towards deterministic outputs, particularly when the backdoor is trained to produce a fixed result.</p>



<p class="wp-block-paragraph"><strong>3. Memorisation leakage</strong>. Microsoft says poisoned models can reveal fragments of the training data used to implant the backdoor, including parts of trigger phrases or associated responses, because those sequences have been memorised more strongly than ordinary training data.</p>



<p class="wp-block-paragraph"><strong>Fuzzy Triggers And Detection Challenges</strong></p>



<p class="wp-block-paragraph">A complicating factor for defenders is that triggers in language models can be fuzzy, meaning the backdoor may activate even when the trigger is incomplete, corrupted, or only partially present. Microsoft’s “The Trigger in the Haystack” research paper says that altered versions of a trigger can still elicit the backdoor behaviour, and it links this to practical scanning because partial reconstructions may still be enough to reveal that a model is compromised. From a security perspective, fuzziness expands the range of inputs that could activate harmful behaviour, increasing the likelihood of accidental activation and complicating attempts to filter triggers at the prompt layer.</p>



<p class="wp-block-paragraph">The same fuzziness also alters the threat model for organisations deploying LLMs in workflows that handle user generated text, logs or data feeds. For example, if a model is integrated into a customer support pipeline or a developer tool, triggers could enter through copied text, template tokens, or structured strings, and partial matches could still activate the backdoor. In practice, this means the risk can’t be reduced to blocking a single known phrase, especially when defenders do not know what the trigger is.</p>



<p class="wp-block-paragraph"><strong>Who Is Most At Risk?</strong></p>



<p class="wp-block-paragraph">The organisations most exposed are those relying on externally trained or open weight models without full visibility into training provenance, especially when models are fine tuned and redeployed across multiple teams. This includes businesses building internal copilots, startups shipping model based features on shared checkpoints, and public sector bodies procuring systems built on third party models. The risk increases when models are sourced from public hubs, copied into internal registries and treated as standard dependencies, since a single poisoned model can propagate into many applications through reuse.</p>



<p class="wp-block-paragraph">Model reuse amplifies the impact because a single compromised model can be downloaded, fine tuned and redeployed thousands of times, spreading the backdoor downstream in ways that are difficult to trace. Microsoft’s “The Trigger in the Haystack” paper highlights this cost imbalance, noting that the high cost of LLM training creates an incentive for sharing and reuse, which&nbsp;<em>“tilts the cost balance in favour of the adversary”.</em>&nbsp;This dynamic resembles software dependency risk, but the verification problem is harder because the malicious behaviour is embedded in weights rather than in auditable code.</p>



<p class="wp-block-paragraph"><strong>Implications For Businesses And Regulators</strong></p>



<p class="wp-block-paragraph">For businesses, the practical implications depend on how models are used, but the potential impact can be severe. For example, a backdoored model could generate insecure code, leak sensitive information, produce harmful outputs, or undermine internal controls, and the behaviour may only manifest under rare conditions, complicating incident response. Microsoft’s “The Adversarial Machine Learning &#8211; Industry Perspectives” report highlights how organisations often focus on privacy and integrity impacts, including the risk of inappropriate outputs, with a respondent in a financial technology context emphasising that&nbsp;<em>“The integrity of our ML system matters a lot.”</em>&nbsp;That concern becomes more acute as LLMs are deployed in customer facing settings and connected to tools that can take actions.</p>



<p class="wp-block-paragraph">Governance and compliance teams also face a challenge because traditional assurance practices often centre on testing known behaviours, while sleeper agent backdoors are designed to avoid detection under ordinary testing. In regulated sectors such as finance and healthcare, questions about provenance, auditability and post deployment monitoring are likely to become central, as organisations need to demonstrate that they can manage risks that are not visible through conventional evaluation alone. The practical constraint is that many detection techniques require open access to model files and internal signals, which may not be available for proprietary models offered only through APIs.</p>



<p class="wp-block-paragraph"><strong>Limitations And Challenges</strong></p>



<p class="wp-block-paragraph">“The Trigger in the Haystack”, approach outlined by Microsoft, is designed for open weight models and requires access to model files, tokenisers and internal signals, which means it does not directly apply to closed models accessed only via an API. The authors also note that their method works best when backdoors have deterministic outputs, while triggers that map to a broader distribution of unsafe behaviours are more challenging to reconstruct reliably. Attackers can also adapt, potentially refining trigger specificity and reducing fuzziness, which could weaken some of the defensive advantages associated with trigger variation.</p>



<p class="wp-block-paragraph">The broader industry challenge is that many organisations have not yet integrated adversarial machine learning into their security development lifecycle, and security teams often lack operational insights into model behaviour once deployed. Microsoft’s industry report argues that practitioners are&nbsp;<em>“not equipped with tactical and strategic tools to protect, detect and respond to attacks on their Machine Learning systems”</em>, which points to a long term need for better evaluation methods, monitoring, incident response playbooks and provenance controls as LLM use continues to expand.</p>



<p class="wp-block-paragraph"><strong>What Does This Mean For Your Business?</strong></p>



<p class="wp-block-paragraph">This research points to a security risk that does not align with traditional software assurance models and can’t be addressed through routine testing alone. It shows that sleeper agent backdoors expose a structural weakness in how AI systems are trained, shared and trusted, particularly when harmful behaviour is learned implicitly during training rather than implemented as visible code. The findings from Microsoft and earlier work from Anthropic show that even organisations using established safety and evaluation techniques can deploy models that retain hidden conditional behaviours with little warning before they activate.</p>



<p class="wp-block-paragraph">For UK businesses, the implications are immediate as large language models are rolled out across customer services, internal tools, software development and data analysis. It suggests that organisations that depend on third party or open weight models now face a supply chain risk that is hard to assess using existing controls, and may need stronger provenance checks, clearer ownership of model updates and more emphasis on monitoring behaviour after deployment. Also, smaller companies and public sector bodies may be particularly exposed due to their reliance on shared models and limited visibility into training processes.</p>



<p class="wp-block-paragraph">The research also highlights a wider challenge for regulators, developers and security teams as responsibility for managing this risk is spread across the AI ecosystem. Detection techniques are improving but remain limited, especially for closed models where internal access is restricted. As AI systems become more deeply embedded in business operations, sleeper agent backdoors are likely to shape how trust, security and accountability around machine learning systems evolve, rather than being treated as an isolated technical issue.</p>
<p>The post <a href="https://w2.meartechnology.co.uk/2026/02/12/featured-article-security-risk-from-hidden-backdoors-in-ai-models/">Featured Article : Security Risk From Hidden Backdoors In AI Models</a> appeared first on <a href="https://w2.meartechnology.co.uk">Mear Technology</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Featured Article : 77% of Security Leaders Would Sack Phishing Victims</title>
		<link>https://w2.meartechnology.co.uk/2025/10/22/featured-article-77-of-security-leaders-would-sack-phishing-victims/</link>
		
		<dc:creator><![CDATA[Paul Stradling]]></dc:creator>
		<pubDate>Wed, 22 Oct 2025 15:28:00 +0000</pubDate>
				<category><![CDATA[Funnies]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Manufacturer]]></category>
		<category><![CDATA[Manufacturers]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Operating System]]></category>
		<category><![CDATA[Recruitment]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[Employers]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[social media]]></category>
		<guid isPermaLink="false">https://w2.meartechnology.co.uk/?p=17727</guid>

					<description><![CDATA[<p>New research from Arctic Wolf shows that most security leaders say they would sack staff who fall for phishing scams, even as incidents rise and leaders themselves admit to clicking malicious links. Hardening of Attitudes Arctic Wolf’s 2025 Human Risk Behaviour Snapshot reveals that 77 per cent of IT and security leaders say they have&#8230; <br /> <a class="read-more" href="https://w2.meartechnology.co.uk/2025/10/22/featured-article-77-of-security-leaders-would-sack-phishing-victims/">Read more</a></p>
<p>The post <a href="https://w2.meartechnology.co.uk/2025/10/22/featured-article-77-of-security-leaders-would-sack-phishing-victims/">Featured Article : 77% of Security Leaders Would Sack Phishing Victims</a> appeared first on <a href="https://w2.meartechnology.co.uk">Mear Technology</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">New research from Arctic Wolf shows that most security leaders say they would sack staff who fall for phishing scams, even as incidents rise and leaders themselves admit to clicking malicious links.</p>



<p class="wp-block-paragraph"><strong>Hardening of Attitudes</strong></p>



<p class="wp-block-paragraph">Arctic Wolf’s 2025 Human Risk Behaviour Snapshot reveals that 77 per cent of IT and security leaders say they have (or would) sack an employee for falling for a phishing or social engineering scam, up from 66 per cent in 2024. The report describes this shockingly high statistic as the result of a significant hardening of attitudes among security professionals, despite continuing increases in attack volume and breach rates.</p>



<p class="wp-block-paragraph"><strong>The Scale</strong></p>



<p class="wp-block-paragraph">The study, which surveyed more than 1,700 IT leaders and end users globally, found that 68 per cent of organisations suffered at least one breach in the past year. The UK and Ireland, for example, recorded some of the steepest rises, partly due to high-profile incidents in the retail sector. Arctic Wolf notes that many firms are still failing to implement basic measures, with only 54 per cent enforcing multi-factor authentication (MFA) for all users.</p>



<p class="wp-block-paragraph"><strong>Sacking Doesn’t Solve The Problem</strong></p>



<p class="wp-block-paragraph">The same report also found that organisations taking an education-first approach rather than firing staff saw an 88 per cent reduction in long-term human risk. According to Arctic Wolf’s Chief Information Security Officer, Adam Marrè,&nbsp;<em>“Terminating employees for falling victim to a phishing attack may feel like a quick fix, but it doesn’t solve the underlying problem.”</em></p>



<p class="wp-block-paragraph"><strong>A Strong Policy Signal</strong></p>



<p class="wp-block-paragraph">The findings of the report appear to highlight a growing gap between confidence and capability. For example, three-quarters of leaders said they believed their organisation would not fall for a phishing attack, yet almost two-thirds admitted they have clicked a phishing link themselves, and one in five said they failed to report it.</p>



<p class="wp-block-paragraph"><strong>Corrective Action Instead of Dismissal</strong></p>



<p class="wp-block-paragraph">It should be noted that, in the same survey, more than six in ten leaders said they had taken corrective action against employees who fell for phishing scams by restricting or changing access privileges, which Arctic Wolf suggests is a more constructive approach than dismissal.</p>



<p class="wp-block-paragraph"><strong>Executives Are Valuable Targets For Cybercriminals</strong></p>



<p class="wp-block-paragraph">In fact, the company’s own data also shows that 39 per cent of senior leadership teams were targeted by phishing and 35 per cent experienced malware infections, highlighting how executives themselves are often the most valuable targets for attackers.</p>



<p class="wp-block-paragraph"><em>“When leaders are overconfident in their defences while overlooking how employees actually use technology, it creates the perfect conditions for mistakes to become breaches,”</em>&nbsp;Marrè said. He added that the most secure organisations&nbsp;<em>“pair strong policies and safeguards with a culture that empowers employees to speak up, learn from errors, and continuously improve.”</em></p>



<p class="wp-block-paragraph"><strong>Confidence Vs Behaviour</strong></p>



<p class="wp-block-paragraph">The Arctic Wolf report appears to highlight a clear contradiction. For example, while most security leaders view phishing as a frontline employee issue, they are actually statistically among the most likely to make the same mistakes. Many also admit to disabling or bypassing security systems. For example, 51 per cent said they had done so in the past year, often claiming that certain measures&nbsp;<em>“slowed them down”</em>&nbsp;or made their work harder.</p>



<p class="wp-block-paragraph">This gap between stated policy and personal practice is what Marrè describes as&nbsp;<em>“a major blind spot and degree of hubris among some security leaders.”</em>&nbsp;The report concludes that leadership culture sets the tone for the rest of the organisation, and that inconsistency at the top erodes credibility and weakens defences.</p>



<p class="wp-block-paragraph"><strong>Who Is Really Falling For Phishing In 2025?</strong></p>



<p class="wp-block-paragraph">The question of who gets caught out most is not as simple as it might appear. For example, Arctic Wolf’s data indicates that senior staff, not junior employees, are often prime targets because of their privileged access and decision-making authority. The company found that nearly four in ten executive teams experienced phishing attempts, compared with lower rates among general staff.</p>



<p class="wp-block-paragraph">Other research appears to support this pattern. For example, Verizon’s 2025 Data Breach Investigations Report confirms that social engineering remains one of the top causes of data breaches, accounting for more than two-thirds of all initial intrusion methods. Its analysis identifies finance, healthcare, education, and retail as the most heavily targeted sectors. Attackers exploit trust, urgency, and routine workflows to trick users into sharing credentials or downloading malware.</p>



<p class="wp-block-paragraph"><strong>New Hires More Likely To Click</strong></p>



<p class="wp-block-paragraph">Also, a mid-2025 study by Keepnet, reported by Help Net Security, found that 71 per cent of new hires clicked on phishing emails during their first 90 days, making them 44 per cent more likely to fall victim than longer-serving staff. The main reasons were unfamiliar internal systems, a desire to respond quickly to apparent authority figures, and inconsistent onboarding security training. The same research found that structured, role-specific training reduced click rates by around 30 per cent within three months.</p>



<p class="wp-block-paragraph"><strong>Retail Legacy Systems An Issue</strong></p>



<p class="wp-block-paragraph">Retail has also seen a marked increase in phishing incidents across the UK and Ireland. Arctic Wolf attributes this to the industry’s reliance on legacy systems, seasonal sales spikes, and the complexity of managing large volumes of customer data. The company says these factors have made retail&nbsp;<em>“a prime target”</em>&nbsp;for opportunistic and scalable attacks.</p>



<p class="wp-block-paragraph"><strong>Can Employers Really Sack Staff For Clicking A Phishing Email?</strong></p>



<p class="wp-block-paragraph">In the UK, simply sacking an employee for falling for a phishing email is legally possible but rarely straightforward. For example, under the Advisory, Conciliation and Arbitration Service (Acas) Code of Practice, an employer can only dismiss fairly if they have both a valid reason, such as misconduct or capability, and have followed a fair and reasonable procedure.</p>



<p class="wp-block-paragraph">For a dismissal to be lawful, the employer must investigate properly, give the employee a chance to respond, and ensure the sanction is proportionate. Even where a phishing incident causes financial loss or reputational damage, the question is whether the individual acted negligently or was misled despite reasonable training and policies. In most cases, a first-time mistake caused by deception would not actually meet the threshold for gross misconduct.</p>



<p class="wp-block-paragraph"><strong>Unfair Dismissal?</strong></p>



<p class="wp-block-paragraph">It’s worth noting here that employees with two years’ service can bring a claim for unfair dismissal if they believe the reason or process was unreasonable. Employment tribunals are required to take the Acas Code into account, and may increase or reduce compensation by up to 25 per cent if either side fails to follow it. This means employers that act punitively without clear evidence or consistent practice could face costly legal challenges.</p>



<p class="wp-block-paragraph">Most employment lawyers, therefore, recommend a corrective rather than disciplinary response, especially where the organisation’s training or technical safeguards may have been insufficient. Arctic Wolf’s data reflects this tendency, with many leaders actually opting to limit access rights rather than dismiss staff outright after a phishing incident.</p>



<p class="wp-block-paragraph"><strong>Ethics And Culture</strong></p>



<p class="wp-block-paragraph">Beyond legality, there is an ethical debate here to take account of which focuses on culture and transparency. For example, the UK’s National Cyber Security Centre (NCSC) advises that creating a “no-blame reporting culture” is one of the most effective ways to reduce security risk. Its guidance stresses that employees should feel safe to report suspicious emails or mistakes immediately, without fear of reprisal.</p>



<p class="wp-block-paragraph">In fact, it is well known that when punishment is the first response, employees often stay silent. Arctic Wolf’s own findings appear to bear this out, i.e., one in five security leaders who clicked a phishing link failed to report it. That silence can allow breaches to escalate before they are detected.</p>



<p class="wp-block-paragraph"><strong>Human Error Inevitable</strong></p>



<p class="wp-block-paragraph">Security experts argue that treating human error as inevitable, and training people to respond effectively, is far more effective than zero-tolerance policies. Marrè says that&nbsp;<em>“progress comes when leaders accept that human risk is not just a frontline issue but a shared accountability across the organisation.”</em>&nbsp;He advocates regular, engaging training that reflects real threats, backed by leadership example and open communication.</p>



<p class="wp-block-paragraph"><strong>The Double Standard In Practice</strong></p>



<p class="wp-block-paragraph">The data from this and other reports appears to paint a clear picture of contradiction at the top. For example, many of the same leaders who advocate sacking staff for phishing errors have clicked links themselves or disabled controls that protect the wider organisation. Arctic Wolf’s report describes this as&nbsp;<em>“a culture of ‘do as I say, not as I do’,”</em>&nbsp;warning that it undermines credibility and increases exposure to social engineering attacks.</p>



<p class="wp-block-paragraph"><strong>Phishing Now More Sophisticated</strong></p>



<p class="wp-block-paragraph">One other important factor to take into account here is the fact that phishing techniques have also grown more sophisticated. For example, attackers now use AI-generated emails, cloned websites, and real-time chat-based scams to trick users into sharing credentials. Even experienced professionals can, therefore, struggle to spot these messages, particularly when they appear to come from known suppliers or senior colleagues.</p>



<p class="wp-block-paragraph"><strong>AI Supercharges Phishing Success</strong></p>



<p class="wp-block-paragraph">Microsoft’s 2025 Digital Defence Report shows that AI-generated phishing emails are 4.5 times more likely to fool recipients, achieving a 54 per cent click-through rate compared with 12 per cent for traditional scams. The company says this surge in realism and scale has made phishing&nbsp;<em>“the most significant change in cybercrime over the last year”.</em></p>



<p class="wp-block-paragraph">Microsoft also estimates that AI can make phishing campaigns up to 50 times more profitable, as attackers use automation to craft messages in local languages, tailor lures, and launch mass campaigns with minimal effort. Beyond email, AI is now being used to scan for vulnerabilities, clone voices, and create deepfakes, transforming phishing into one of the fastest-growing and most lucrative attack methods worldwide.</p>



<p class="wp-block-paragraph"><strong>Initial Compromise Comes From Phishing</strong></p>



<p class="wp-block-paragraph">Industry-wide data continues to show that phishing is the most common initial attack vector in business email compromise, ransomware, and credential theft cases. Verizon’s latest data shows phishing accounts for roughly 73 per cent of initial compromise methods, followed by previously stolen credentials. These statistics underline how difficult it is to eliminate human error entirely, even in well-trained environments.</p>



<p class="wp-block-paragraph">Arctic Wolf argues that genuine progress actually requires leading by example rather than blaming employees. In its report, the company’s closing recommendations include continuous education, practical simulations, and building a culture that rewards honesty over silence. Its research concludes that organisations where employees feel confident to report mistakes are significantly less likely to experience repeat incidents, and far more likely to detect breaches early.</p>



<p class="wp-block-paragraph"><strong>What Does This Mean For Your Business?</strong></p>



<p class="wp-block-paragraph">The findings appear to highlight a cultural challenge within cyber security. Punishing individuals for mistakes that even experienced leaders admit to making risks undermining the very trust and openness that strong defences depend on. The evidence shows that while technical safeguards such as MFA and endpoint protection are essential, they are not enough on their own. What really differentiates resilient organisations is how they handle human error, whether they choose to learn from it or treat it as grounds for dismissal.</p>



<p class="wp-block-paragraph">For UK businesses, the implications are significant. A strict zero-tolerance policy towards phishing may appear decisive, but it can also damage morale, suppress reporting, and expose employers to potential legal and reputational risks. Dismissing staff without due process could also lead to unfair dismissal claims, while a culture of fear can discourage the transparency needed to contain attacks quickly. By contrast, firms that take a measured, education-focused approach tend to see fewer repeat incidents, faster recovery times, and stronger employee engagement in security.</p>



<p class="wp-block-paragraph">The message from Arctic Wolf’s data is that leadership example matters most. When senior executives model good cyber hygiene, acknowledge their own vulnerabilities, and support open communication, staff are far more likely to follow suit. Creating an environment where everyone feels responsible for reporting threats, and confident they will be supported for doing so, delivers a far greater return than any punitive measure.</p>



<p class="wp-block-paragraph">For regulators, investors, training providers and others, the findings reinforce the importance of human-centred strategies that combine accountability with education. As phishing continues to evolve in sophistication, organisations across all sectors must balance clear policy enforcement with a recognition that even the best-informed professionals can make mistakes. The organisations that respond to that reality with fairness, transparency, and leadership integrity will be the ones best equipped to withstand the next wave of attacks.</p>
<p>The post <a href="https://w2.meartechnology.co.uk/2025/10/22/featured-article-77-of-security-leaders-would-sack-phishing-victims/">Featured Article : 77% of Security Leaders Would Sack Phishing Victims</a> appeared first on <a href="https://w2.meartechnology.co.uk">Mear Technology</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Featured Article : Sainsbury’s Facial Recognition Combats Shoplifting</title>
		<link>https://w2.meartechnology.co.uk/2025/09/10/featured-article-sainsburys-facial-recognition-combats-shoplifting/</link>
		
		<dc:creator><![CDATA[Paul Stradling]]></dc:creator>
		<pubDate>Wed, 10 Sep 2025 09:52:17 +0000</pubDate>
				<category><![CDATA[Manufacturers]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Sales]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[Facial Recognition]]></category>
		<category><![CDATA[Sainsbury]]></category>
		<category><![CDATA[Shoplifting]]></category>
		<category><![CDATA[social media]]></category>
		<guid isPermaLink="false">https://w2.meartechnology.co.uk/?p=17532</guid>

					<description><![CDATA[<p>Sainsbury’s has begun testing facial recognition technology in selected stores to identify repeat offenders and reduce shoplifting, triggering a wave of privacy concerns from civil liberties groups. Surveillance Trial Rolling Out in London and Bath The supermarket chain confirmed that an eight-week pilot programme is underway at a small number of stores in London and&#8230; <br /> <a class="read-more" href="https://w2.meartechnology.co.uk/2025/09/10/featured-article-sainsburys-facial-recognition-combats-shoplifting/">Read more</a></p>
<p>The post <a href="https://w2.meartechnology.co.uk/2025/09/10/featured-article-sainsburys-facial-recognition-combats-shoplifting/">Featured Article : Sainsbury’s Facial Recognition Combats Shoplifting</a> appeared first on <a href="https://w2.meartechnology.co.uk">Mear Technology</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Sainsbury’s has begun testing facial recognition technology in selected stores to identify repeat offenders and reduce shoplifting, triggering a wave of privacy concerns from civil liberties groups.</p>



<p class="wp-block-paragraph"><strong>Surveillance Trial Rolling Out in London and Bath</strong></p>



<p class="wp-block-paragraph">The supermarket chain confirmed that an eight-week pilot programme is underway at a small number of stores in London and Bath. The facial recognition cameras are supplied by Facewatch, a UK-based security technology firm that already provides similar services to a range of retailers.</p>



<p class="wp-block-paragraph">The system captures the biometric data of individuals who are already on a watchlist for suspected theft or abuse. If someone flagged on this list enters a participating store, an alert is sent to staff in real time. Sainsbury’s says the trial is being used only at locations with a high incidence of repeat offending.</p>



<p class="wp-block-paragraph">The trial began in late August and is expected to run through to October. Depending on results, it could be expanded to more branches across the UK. Facewatch claims its technology can help retailers cut shoplifting and abuse by deterring known offenders and giving staff more time to intervene safely.</p>



<p class="wp-block-paragraph"><strong>Why Sainsbury’s Is Doing This Now</strong></p>



<p class="wp-block-paragraph">Retail crime has surged in recent years, with the British Retail Consortium (BRC) estimating the total cost to the sector at £1.76 billion in 2023, including £1.04 billion in customer theft alone. Also, physical assaults and abuse of shop workers have also been rising sharply, prompting calls for tougher enforcement and more robust security measures.</p>



<p class="wp-block-paragraph">Sainsbury’s said in a statement:&nbsp;<em>“We’re constantly looking at new ways to keep our colleagues and customers safe. We’re currently trialling facial recognition in a small number of stores where there is a high level of crime.”</em></p>



<p class="wp-block-paragraph"><strong>Signage About It</strong></p>



<p class="wp-block-paragraph">The company emphasised that the technology is not being used for general customer surveillance or profiling, and that signage is in place at affected locations to notify shoppers that facial recognition is in use.</p>



<p class="wp-block-paragraph"><strong>Powered by Facewatch (Controversially)</strong></p>



<p class="wp-block-paragraph">The system being used by Sainsbury’s is provided by Facewatch, a private facial recognition firm founded in 2010. Facewatch says it operates within UK GDPR and the Protection of Freedoms Act 2012, and only stores data on those individuals who have been involved in past incidents, as reported by retailers.</p>



<p class="wp-block-paragraph">Its technology compares live CCTV footage to images held in its centralised database of&nbsp;<em>“subjects of interest.”</em>&nbsp;If there is a match, an alert is sent to store staff with a still-image and time-stamped location data.</p>



<p class="wp-block-paragraph">While Facewatch has been used by independent retailers, petrol stations and other supermarket chains including Southern Co-op and Budgens, it has not previously been adopted by any of the UK’s four major supermarket brands at this scale.</p>



<p class="wp-block-paragraph">It seems that the company has drawn some criticism from privacy campaigners for operating a privately managed watchlist system that can share biometric alerts between businesses, with concerns raised about accuracy, accountability, and the lack of independent oversight.</p>



<p class="wp-block-paragraph">The move by Sainsbury’s essentially takes facial recognition further into the retail mainstream and puts the technology under new levels of public and regulatory scrutiny. It also raises the stakes for how and where this kind of surveillance may be used next across the sector.</p>



<p class="wp-block-paragraph"><strong>Privacy Groups Push Back</strong></p>



<p class="wp-block-paragraph">Civil liberties organisations were quick to voice concerns. For example, Big Brother Watch, a UK privacy campaign group, accused Sainsbury’s of introducing&nbsp;<em>“unnecessary and Orwellian”</em>&nbsp;surveillance under the guise of crime prevention.</p>



<p class="wp-block-paragraph"><em>“Facial recognition surveillance is extreme, and Sainsbury’s customers should not be subjected to identity checks to buy milk,”</em>&nbsp;said Madeleine Stone, Senior Advocacy Officer at Big Brother Watch.&nbsp;<em>“This sets a dangerous precedent not just for retail, but for everyday public life.”</em></p>



<p class="wp-block-paragraph">The group also raised concerns about transparency and consent, arguing that biometric surveillance in shops blurs the line between policing and commerce. It warned that the use of facial recognition could result in misidentifications, discrimination, and the over-policing of vulnerable groups.</p>



<p class="wp-block-paragraph">The Information Commissioner’s Office (ICO) has previously cautioned organisations using facial recognition to ensure legal compliance and necessity. It has not commented directly on the Sainsbury’s trial but is likely to monitor developments closely.</p>



<p class="wp-block-paragraph"><strong>Facewatch’s Role in Expanding Everyday Surveillance</strong></p>



<p class="wp-block-paragraph">Sainsbury’s pilot sits within a broader shift where facial recognition is moving from niche deployments to visible use in everyday retail settings. Southern Co‑op has used Facewatch across dozens of branches since 2020, while independent convenience stores and some symbol groups have reported measurable reductions in repeat theft when using similar watchlist alerts. In one Morrisons Daily site, the store owner told trade press that incidents dropped by as much as ninety per cent after installation, though these results are self‑reported rather than independently audited.</p>



<p class="wp-block-paragraph"><strong>Other Big Chains Are Already Testing the Waters</strong></p>



<p class="wp-block-paragraph">Other large grocers have been testing live facial recognition in recent months. For example, Asda ran a trial across five Greater Manchester stores, drawing thousands of complaints and sustained criticism from privacy groups, which shows how quickly public reaction can become a material factor in rollouts. Iceland has also been named by campaigners as exploring use, although details remain limited. These parallel efforts are relevant to Sainsbury’s because they indicate how public tolerance, operational benefits, and regulatory scrutiny interact in real retail environments.</p>



<p class="wp-block-paragraph"><strong>Concerns About Accuracy and Misidentification</strong></p>



<p class="wp-block-paragraph">Concerns about accuracy and fairness remain central to the debate about the use of this kind of technology. For example, privacy group Big Brother Watch argues that commercial watchlists risk misidentifying innocent shoppers because entries are often created by retailers rather than police and can be shared between participating businesses. The group says this creates a risk of people being wrongly flagged and excluded. There have been reported misidentifications, including a case where a customer was barred after a Facewatch alert, which Facewatch later acknowledged was an error. These cases are shaping campaigners’ calls for stricter safeguards and clearer lines of accountability.</p>



<p class="wp-block-paragraph"><strong>Legal Uncertainty Around Commercial Use</strong></p>



<p class="wp-block-paragraph">The policy landscape adds another layer. For example, the UK has no dedicated statute that comprehensively governs private sector facial recognition in public‑facing spaces, so retailers largely rely on data protection law, necessity and proportionality tests, and DPIAs to justify deployments. The ICO has previously investigated Facewatch and related deployments and, according to evidence submitted to Parliament, identified multiple areas where policies needed to better balance legitimate interests with people’s rights. This context frames what retailers must document and evidence when running pilots like Sainsbury’s.</p>



<p class="wp-block-paragraph"><strong>How the Trial Is Being Measured</strong></p>



<p class="wp-block-paragraph">Operationally, Sainsbury’s says the Facewatch system is configured to alert staff only when a person on a pre‑defined watchlist is detected, focused on individuals linked to violence, aggression, or theft. Faces that do not match are deleted immediately, and signage at trial stores informs customers that facial recognition is in use. The supermarket has also stressed that the pilot is limited to locations with high levels of repeat offending, and that it is intended to support staff safety rather than to monitor ordinary shoppers.</p>



<p class="wp-block-paragraph"><strong>Retail Crime Data Is Driving Urgency</strong></p>



<p class="wp-block-paragraph">Evaluation will centre on measurable changes in repeat theft and abuse, staff perceptions of safety, and any displacement effects, for example incidents shifting to nearby stores. The British Retail Consortium reports retail theft at crisis levels, with more than twenty million incidents in 2023 to 2024 and an estimated £2.2 billion lost to shoplifting, which explains why large chains are testing additional controls alongside guards, body‑worn cameras, and product protection. These sector‑wide figures provide the baseline against which any impact from facial recognition will be assessed.</p>



<p class="wp-block-paragraph"><strong>Public Reaction Will Influence Industry Direction</strong></p>



<p class="wp-block-paragraph">It’s likely that public response will also form part of the assessment. Big Brother Watch has labelled the Sainsbury’s pilot&nbsp;<em>“deeply disproportionate and chilling,”</em>&nbsp;arguing that biometric scanning in supermarkets treats shoppers as suspects and risks normalising identity checks for everyday purchases. Trade unions have tended to frame the question through the lens of staff safety, calling for evidence‑led approaches that reduce violence and abuse at work. Therefore, how these competing views evolve during the pilot will influence whether other national chains follow Sainsbury’s lead.</p>



<p class="wp-block-paragraph"><strong>Regulatory Input Could Shape What Comes Next</strong></p>



<p class="wp-block-paragraph">Also, any regulatory feedback could shape the design of future deployments. For example, if the ICO receives complaints during the trial, it may seek clarifications on data retention, watchlist criteria, redress routes for mistaken identity, and transparency notices. Previous facial recognition pilots in retail and other sectors have drawn attention to these governance questions, so documenting them clearly is likely to be as important as any headline reduction in theft.</p>



<p class="wp-block-paragraph"><strong>What Does This Mean For Your Business?</strong></p>



<p class="wp-block-paragraph">The outcome of this trial will matter not only for Sainsbury’s but for any UK business operating in high-footfall environments where theft, abuse, or anti-social behaviour is on the rise. If facial recognition is shown to reduce repeat offending without undermining customer trust, other sectors may begin exploring similar systems, from retail and hospitality to logistics and healthcare. However, that will depend on clear governance, strong safeguards, and public confidence in how the technology is being used.</p>



<p class="wp-block-paragraph">For technology providers, the stakes are also high. For example, Facewatch’s credibility as a supplier of compliant, proportionate, and accurate surveillance tools may hinge on how this pilot is received by regulators and rights groups. If the ICO intervenes or public backlash intensifies, it could limit how far these systems can expand. Businesses adopting facial recognition will need to be ready to justify every aspect of its deployment, from necessity and proportionality to data handling and redress.</p>



<p class="wp-block-paragraph">For consumers and communities, the case raises fresh questions about what kind of monitoring is acceptable in everyday spaces, and where the boundaries lie between legitimate protection and excessive surveillance. The lack of specific legislation leaves a vacuum where privacy, ethics, and commercial interest are all pulling in different directions. Without clear national rules, it may fall to individual retailers, campaigners, and regulators to shape how far this goes.</p>



<p class="wp-block-paragraph">As the pilot continues, attention will turn to how Sainsbury’s measures success and handles concerns. Whether this becomes a new layer of shopfloor security or a short-lived experiment will depend on what the results show, how they are interpreted, and whether wider industry and political appetite supports rolling it out further.</p>
<p>The post <a href="https://w2.meartechnology.co.uk/2025/09/10/featured-article-sainsburys-facial-recognition-combats-shoplifting/">Featured Article : Sainsbury’s Facial Recognition Combats Shoplifting</a> appeared first on <a href="https://w2.meartechnology.co.uk">Mear Technology</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Featured Article : Historic Global Leak : 16 Billion Logins Exposed</title>
		<link>https://w2.meartechnology.co.uk/2025/06/25/featured-article-historic-global-leak-16-billion-logins-exposed/</link>
		
		<dc:creator><![CDATA[Paul Stradling]]></dc:creator>
		<pubDate>Wed, 25 Jun 2025 18:26:39 +0000</pubDate>
				<category><![CDATA[Funnies]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Manufacturers]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Leak]]></category>
		<category><![CDATA[Logins]]></category>
		<category><![CDATA[social media]]></category>
		<guid isPermaLink="false">https://w2.meartechnology.co.uk/?p=17330</guid>

					<description><![CDATA[<p>A massive trove of stolen usernames and passwords totalling 16 billion records has been discovered across 30 newly uncovered databases, revealing one of the largest and most dangerous credential breaches ever recorded. Two Login Credentials for Every Person on Earth Security researchers at Cybernews have uncovered an unprecedented cache of login data scattered across unsecured&#8230; <br /> <a class="read-more" href="https://w2.meartechnology.co.uk/2025/06/25/featured-article-historic-global-leak-16-billion-logins-exposed/">Read more</a></p>
<p>The post <a href="https://w2.meartechnology.co.uk/2025/06/25/featured-article-historic-global-leak-16-billion-logins-exposed/">Featured Article : Historic Global Leak : 16 Billion Logins Exposed</a> appeared first on <a href="https://w2.meartechnology.co.uk">Mear Technology</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A massive trove of stolen usernames and passwords totalling 16 billion records has been discovered across 30 newly uncovered databases, revealing one of the largest and most dangerous credential breaches ever recorded.</p>



<p class="wp-block-paragraph"><strong>Two Login Credentials for Every Person on Earth</strong></p>



<p class="wp-block-paragraph">Security researchers at Cybernews have uncovered an unprecedented cache of login data scattered across unsecured web databases. These exposed collections, some open to the internet only briefly, were mostly hosted on misconfigured Elasticsearch instances or cloud object storage services, making them accessible without authentication.</p>



<p class="wp-block-paragraph">All but one of the 30 datasets involved in the breach had not been reported previously. Combined, they include roughly two login credentials for every person on Earth!</p>



<p class="wp-block-paragraph"><strong>A Blueprint For Mass Exploitation</strong></p>



<p class="wp-block-paragraph"><em>“This is not just a leak – it’s a blueprint for mass exploitation,”</em>&nbsp;said the Cybernews team, who have been tracking the breach since early 2024.&nbsp;<em>“The structure and recency of these datasets make them particularly dangerous.”</em></p>



<p class="wp-block-paragraph"><strong>From Apple, Google, Facebook, and More</strong></p>



<p class="wp-block-paragraph">While large-scale data breaches have become disturbingly common, this incident stands out for the freshness of the data and the scope of what’s included. For example, Cybernews has reported that the breach includes login credentials drawn from a huge range of services including Apple, Google, Facebook, GitHub, Telegram, VPNs, and even government portals.</p>



<p class="wp-block-paragraph"><strong>More Than Just Usernames and Passwords</strong></p>



<p class="wp-block-paragraph">The datasets primarily consist of credentials stolen by infostealers, i.e. a type of malicious software designed to extract sensitive information from infected computers. Once installed (often via phishing emails, fake software updates, or pirated software), infostealers scan the victim’s device for stored logins, cookies, authentication tokens, and autofill data. These details are then quietly sent back to attackers’ servers.</p>



<p class="wp-block-paragraph">In most cases, Cybernews reports that the stolen data is structured in a familiar format, i.e. the website URL, the username or email address, and the associated password. Some records are reported to include extra metadata, such as session cookies or two-factor authentication tokens, which can significantly aid attackers in bypassing security protections.</p>



<p class="wp-block-paragraph">Cybernews estimates that some overlap exists between datasets, but even conservative estimates suggest billions of distinct login records are involved. The largest single collection, linked to a Portuguese-speaking population, holds over 3.5 billion records. Others are named generically (such as&nbsp;<em>“logins”</em>&nbsp;or&nbsp;<em>“credentials”</em>) while some reference specific services like Telegram or locations such as the Russian Federation.</p>



<p class="wp-block-paragraph"><strong>Who’s Behind It and Who’s Affected?</strong></p>



<p class="wp-block-paragraph">It appears that the origin of these leaked datasets remains murky. Although some may have been compiled by cybercriminals intent on launching mass-scale phishing or credential stuffing attacks, others could belong to grey-hat researchers, aggregating leaked data for academic or threat intelligence purposes. However, it should be noted that the absence of clear attribution makes them no less dangerous.</p>



<p class="wp-block-paragraph">Cybersecurity experts have warned that even if only a fraction of the 16 billion records are actively exploited, the consequences could be severe. Identity theft, business email compromise (BEC), unauthorised access to cloud services, ransomware attacks, and financial fraud are all plausible next steps.</p>



<p class="wp-block-paragraph">A significant concern is that many users still reuse the same password across multiple sites (known as ‘password sharing’). Attackers often employ credential stuffing, a tactic that involves testing stolen username/password pairs against a wide range of sites, hoping users have reused credentials elsewhere.</p>



<p class="wp-block-paragraph">The impact is not likely to be just limited to individual consumers. Businesses, particularly those lacking multi-factor authentication (MFA) or modern password management protocols, are at risk of full-scale account takeovers. These in turn could lead to data theft, service disruption, or reputational damage.</p>



<p class="wp-block-paragraph"><strong>What Tech Companies and Security Experts Are Saying</strong></p>



<p class="wp-block-paragraph">So far, most affected companies have not issued individual statements, probably because the breach is not tied to a specific platform or service – the leak is an aggregation of credentials siphoned off via malware over time.</p>



<p class="wp-block-paragraph">However, the Cybernews team and other researchers have voiced serious concern.&nbsp;<em>“Credential leaks at this scale are fuel for phishing campaigns, ransomware intrusions, and business email compromise,”</em>&nbsp;the team said in its public briefing.<em>&nbsp;“The inclusion of both old and recent infostealer logs – often with tokens, cookies, and metadata – makes this data particularly dangerous for organisations lacking multi-factor authentication or credential hygiene practices.”</em></p>



<p class="wp-block-paragraph">Security vendor Malwarebytes described the incident as&nbsp;<em>“a wake-up call”</em>&nbsp;for both users and companies.&nbsp;<em>“This is a stark reminder that infostealer malware remains an enormous threat and that misconfigured cloud services continue to expose sensitive data at scale.”</em></p>



<p class="wp-block-paragraph"><strong>More of a ‘Combolist’</strong></p>



<p class="wp-block-paragraph">Some experts have cautioned against treating the breach as a single event, noting that it is better understood as a massive combolist, i.e., a curated aggregation of multiple smaller leaks. Even so, the potential for harm remains high.</p>



<p class="wp-block-paragraph"><strong>Why This Breach Is Different and What Comes Next</strong></p>



<p class="wp-block-paragraph">Unlike older breaches which often contain outdated or previously exposed data, these records are mostly new. Only one of the 30 datasets had been reported before (a 184 million-entry trove covered by Wired in May). The rest have emerged only recently, some in the last few weeks, suggesting that infostealer activity is ongoing and highly active.</p>



<p class="wp-block-paragraph"><strong>Not Indexed Yet</strong></p>



<p class="wp-block-paragraph">At the moment (it’s still early days since the discovery), compounding the risk is the lack of visibility. Many of the exposed credentials have not yet been indexed by breach monitoring services or browser alert systems, meaning users aren’t being automatically notified if their details are among those leaked.</p>



<p class="wp-block-paragraph">Also, because the databases were reportedly only briefly exposed, researchers say they could not determine who held or uploaded the data, nor whether it has already been downloaded or traded on criminal forums.</p>



<p class="wp-block-paragraph"><strong>What Should Users and Businesses Do Now?</strong></p>



<p class="wp-block-paragraph">For individual users, the recommendations are fairly straightforward but urgent and they probably echo most of the points of security good practice around breaches. For example:</p>



<p class="wp-block-paragraph">– Immediately change passwords on any accounts using duplicated or weak credentials.</p>



<p class="wp-block-paragraph">– Use a password manager to generate and store complex, unique passwords for every service.</p>



<p class="wp-block-paragraph">– Enable multi-factor authentication (MFA) wherever possible.</p>



<p class="wp-block-paragraph">– Monitor for phishing emails or unusual account activity, especially logins from unfamiliar locations or devices.</p>



<p class="wp-block-paragraph">– Run antivirus and anti-malware tools to scan for potential infostealers on your system.</p>



<p class="wp-block-paragraph">For businesses, the stakes are higher. Implementing stronger access controls, requiring MFA across all services, and deploying endpoint detection tools are worthwhile steps. Regular audits of privileged access accounts, secure cloud configurations, and employee training on phishing threats are also essential.</p>



<p class="wp-block-paragraph">Experts also recommend checking employee and corporate credentials against breach monitoring services such as Have I Been Pwned or Cybernews’ Leaked Database Checker.</p>



<p class="wp-block-paragraph"><strong>Could Big Tech Be Doing More?</strong></p>



<p class="wp-block-paragraph">Looking at where many of these stolen credentials came from, it’s perhaps not surprising that there is growing pressure on tech platforms to go beyond offering MFA as an optional feature. Some experts are calling for default-on MFA policies, improved session token management, and better user alerts for credential misuse. Others suggest that browser makers could more aggressively warn users about unsafe passwords, even when stored locally.</p>



<p class="wp-block-paragraph">Cloud service providers also face scrutiny. For example, misconfigured storage services remain a recurring source of data exposure and security researchers have long warned that businesses often fail to understand the shared responsibility model of cloud hosting, which places the burden of securing customer data squarely on the organisation using the service, not the cloud provider itself.</p>



<p class="wp-block-paragraph"><strong>Combined for Weaponisation</strong></p>



<p class="wp-block-paragraph">This breach essentially demonstrates how aggregated, seemingly disparate data leaks can combine to form a vast, weaponisable archive of credentials. Also, without rapid, coordinated responses from users, businesses, and tech providers alike, the consequences may stretch far beyond compromised passwords.</p>



<p class="wp-block-paragraph"><strong>What Does This Mean For Your Business?</strong></p>



<p class="wp-block-paragraph">The sheer scale and structure of this breach underline how fragile the global system of digital identity has become. With 16 billion credentials exposed, many of them recent, unrecycled, and complete with cookies and tokens, the barrier to entry for cybercriminals appears to have been lowered dramatically. This isn’t just an escalation in volume, it’s a shift in the quality and usability of stolen data. For attackers, this is a ready-made toolkit for highly convincing phishing, large-scale account takeover attempts, and social engineering operations that could target everyone from individual users to senior staff within high-profile organisations.</p>



<p class="wp-block-paragraph">For UK businesses, the risks are not theoretical. Any organisation with staff using shared or recycled passwords, without enforced multi-factor authentication, could find themselves an easy target. For example, compromised employee accounts can quickly open doors to sensitive systems, intellectual property, financial accounts or customer data. The consequences are likely to include financial loss, regulatory penalties, and long-term reputational damage. This is especially pressing for sectors handling critical infrastructure or customer data, such as healthcare, education, local government and law firms.</p>



<p class="wp-block-paragraph">The fact that so many of the datasets were discovered in misconfigured online storage shows how easily even vast amounts of sensitive information can be left vulnerable. This again raises questions about internal security practices, not just among cybercriminals, but among businesses and developers failing to properly secure cloud environments. As more breaches emerge from poor cloud hygiene, regulators may well move to demand greater accountability and oversight from cloud service providers and their clients.</p>



<p class="wp-block-paragraph">For security professionals and digital privacy advocates, this breach reinforces the need to accelerate the move away from passwords altogether. Passkey adoption, hardware-based authentication, and biometric alternatives are already gaining traction, but the pace remains slow. Meanwhile, tools such as credential stuffing bots and AI-enhanced phishing make password-only systems increasingly outdated and risky.</p>



<p class="wp-block-paragraph">The discovery also points to a deeper issue around breach notification and public awareness. Because these credentials were collected silently through infostealers and surfaced only when aggregated by researchers, the victims (both users and the platforms their data was stolen from) may have no idea they were compromised. With no clear breach event to attribute, many companies are, therefore, unlikely to report or even detect the loss. This leaves users exposed and unprepared, and it puts the onus on breach checkers and independent researchers to close the gap.</p>



<p class="wp-block-paragraph">This incident serves as a stark reminder that security needs to be proactive, not reactive. Businesses should no longer view breaches as isolated events but as part of an ongoing data extraction economy that thrives on delay, misconfiguration and user complacency. Whether you’re a multinational tech firm, a regional employer, or an individual internet user, the threat landscape has shifted again and this time, the scale is difficult to ignore.</p>
<p>The post <a href="https://w2.meartechnology.co.uk/2025/06/25/featured-article-historic-global-leak-16-billion-logins-exposed/">Featured Article : Historic Global Leak : 16 Billion Logins Exposed</a> appeared first on <a href="https://w2.meartechnology.co.uk">Mear Technology</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Featured Article : US &#038; UK Public Sectors Running Insecure IT</title>
		<link>https://w2.meartechnology.co.uk/2025/06/18/featured-article-us-uk-public-sectors-running-insecure-it/</link>
		
		<dc:creator><![CDATA[Paul Stradling]]></dc:creator>
		<pubDate>Wed, 18 Jun 2025 16:56:48 +0000</pubDate>
				<category><![CDATA[Funnies]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Operating System]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[public sector]]></category>
		<category><![CDATA[social media]]></category>
		<guid isPermaLink="false">https://w2.meartechnology.co.uk/?p=17303</guid>

					<description><![CDATA[<p>A major new study has revealed that 78 per cent of (US) public sector organisations are still operating with serious, unresolved software security flaws, some of which have persisted for over five years. Report Uncovers Widespread “Security Debt” The findings come from US-based application risk management firm Veracode’s Public Sector State of Software Security 2025&#8230; <br /> <a class="read-more" href="https://w2.meartechnology.co.uk/2025/06/18/featured-article-us-uk-public-sectors-running-insecure-it/">Read more</a></p>
<p>The post <a href="https://w2.meartechnology.co.uk/2025/06/18/featured-article-us-uk-public-sectors-running-insecure-it/">Featured Article : US &#038; UK Public Sectors Running Insecure IT</a> appeared first on <a href="https://w2.meartechnology.co.uk">Mear Technology</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A major new study has revealed that 78 per cent of (US) public sector organisations are still operating with serious, unresolved software security flaws, some of which have persisted for over five years.</p>



<p class="wp-block-paragraph"><strong>Report Uncovers Widespread “Security Debt”</strong></p>



<p class="wp-block-paragraph">The findings come from US-based application risk management firm Veracode’s Public Sector State of Software Security 2025 report, released on 11 June. Based on an analysis of over 1.3 million software applications and 126 million security findings, the research highlights the extent to which government organisations in the US are falling behind on basic software vulnerability management.</p>



<p class="wp-block-paragraph">According to the report, a massive 78 per cent of (US) public sector bodies are running with unresolved flaws that have remained open for more than a year, a situation Veracode refers to as&nbsp;<em>“security debt”.</em>&nbsp;In more than half of these organisations, the report identifies critical vulnerabilities with high risk potential that have still not been addressed.</p>



<p class="wp-block-paragraph"><strong>Fixing Flaws Takes Far Longer in Government</strong></p>



<p class="wp-block-paragraph">One of the clearest indicators of the public sector’s struggle appears to be the time it takes to resolve these software issues. For example, the report shows that government bodies take an average of 315 days to fix just half of their identified software vulnerabilities. This is far higher than the cross-industry average of 252 days, which is already considered too slow by many cybersecurity experts.</p>



<p class="wp-block-paragraph">That 63-day gap may sound modest, but Veracode warns it opens up a significant attack window. This is because these flaws, often in applications delivering essential services, could be exploited by attackers for months at a time. In some cases, flaws are left unresolved for multiple years. As the report shows, around one-third of vulnerabilities in US government software remain unpatched even after two years, and 15 per cent are still unresolved after five.</p>



<p class="wp-block-paragraph">Chris Wysopal, Chief Security Evangelist at Veracode, described the situation as a systemic failure to keep pace with risk, saying:&nbsp;<em>“Many government organisations are facing growing challenges in keeping up with vulnerability remediation, potentially leaving critical systems and data that run essential government services exposed.”</em></p>



<p class="wp-block-paragraph"><strong>Which Public Sector Organisations?</strong></p>



<p class="wp-block-paragraph">The report encompasses a wide range of public sector bodies, including US federal, regional, and local government departments, as well as agencies responsible for education, healthcare, law enforcement, and infrastructure. While the specific organisations are not named, the findings indicate a sector-wide problem that spans multiple tiers of government.</p>



<p class="wp-block-paragraph">Public-facing applications and internal administrative systems are both affected, with legacy software and fragmented IT infrastructure frequently cited as contributing factors. The report also shows that larger and more complex organisations tend to perform worse, particularly where digital transformation has lagged.</p>



<p class="wp-block-paragraph"><strong>Is the UK Public Sector Facing the Same Risks?</strong></p>



<p class="wp-block-paragraph">Although Veracode’s report focuses specifically on the US, many of the challenges it identifies appear to be mirrored in the UK.</p>



<p class="wp-block-paragraph">For example, according to a recent National Audit Office (NAO) report, 58 critical UK government IT systems still have significant cyber-resilience gaps, with 228 legacy systems running without full knowledge of their vulnerabilities. The NAO also highlighted that one in three cybersecurity roles in government remains vacant or is filled by temporary staff, suggesting a widespread skills shortage similar to that seen in the US.</p>



<p class="wp-block-paragraph">Also, recent cyber incidents have highlighted the risks. For example, back in May, a breach at the Legal Aid Agency exposed the personal data of over 2 million individuals. The British Library and parts of the NHS have also suffered serious service disruptions due to ransomware attacks, often linked to outdated infrastructure.</p>



<p class="wp-block-paragraph">Unlike Veracode’s report, there is currently no published UK data showing the average time it takes public sector bodies to fix software vulnerabilities. However, the reliance on legacy systems, combined with under-resourced security teams and a reactive approach to patching, strongly suggests that vulnerability resolution timelines in the UK are also prolonged.</p>



<p class="wp-block-paragraph">That said, the UK Government has begun taking steps to address the issue. For example, a new Cyber Security and Resilience Bill is set to tighten breach reporting requirements and enhance supply chain security. Also, the NCSC’s GovAssure programme is now auditing critical departments, and £1 billion has been pledged to improve cyber capacity across public services. However, progress has been slow, and experts have raised concerns about how effectively these initiatives are being implemented.</p>



<p class="wp-block-paragraph">In the absence of specific figures, it remains difficult to compare the scale of UK security debt directly with the US, however the warning signs are there and the structural issues look strikingly familiar.</p>



<p class="wp-block-paragraph"><strong>Open Source and Third-Party Code a Major Weak Point</strong></p>



<p class="wp-block-paragraph">While most flaws are found in first-party applications, it seems that the most dangerous and persistent problems come from open-source and third-party code. Interestingly, although these components make up less than 10 per cent of total public sector software, they account for 70 per cent of the critical security debt in government systems.</p>



<p class="wp-block-paragraph">To make matters worse, flaws in third-party code take around 50 per cent longer to fix than those in software developed internally. As organisations increasingly rely on open-source libraries and packages, this gap presents a growing threat.</p>



<p class="wp-block-paragraph"><em>“This disproportionate risk highlights the importance of securing software supply chains and carefully vetting open-source dependencies,”</em>&nbsp;said Wysopal.&nbsp;<em>“Without extending visibility and remediation efforts beyond internal code, public sector entities risk leaving the most dangerous flaws unaddressed.”</em></p>



<p class="wp-block-paragraph"><strong>Some Agencies Are Far Ahead of Others</strong></p>



<p class="wp-block-paragraph">The report appears to highlight a stark disparity between the best and worst performing organisations. In the top 25 per cent of public sector bodies, just one-third of applications contain flaws. These leading agencies resolve half of their issues within 3.3 months and manage to fix over 9 per cent of flaws per month. The report shows that by contrast, the worst 25 per cent have flaws in every application tested, with less than 0.1 per cent fixed each month and average remediation times exceeding 11 months.</p>



<p class="wp-block-paragraph">Wysopal highlights how this gap raises serious questions about leadership, resource allocation, and operational culture across the public sector, saying:&nbsp;<em>“The disparity between top and bottom-performing government organisations is striking and raises important questions about the factors that make a material difference to security posture.”</em></p>



<p class="wp-block-paragraph"><strong>What’s Causing the Problem?</strong></p>



<p class="wp-block-paragraph">The report suggests a number of causes behind the growing backlog. These include underinvestment in software development security (AppSec) tools, overreliance on legacy systems, and a lack of skilled personnel to address vulnerabilities at scale.</p>



<p class="wp-block-paragraph">Another issue is that vulnerability scanning is often performed late in the development lifecycle, when flaws are more costly and time-consuming to fix. Without ongoing analysis and integration into development workflows, issues tend to accumulate and are eventually deprioritised due to competing pressures.</p>



<p class="wp-block-paragraph">Compounding this appears to be the rapid adoption of AI-generated code. While generative AI can speed up development, it can also introduce subtle but serious vulnerabilities if not properly reviewed. Veracode warns that comprehensive open-source analysis is more essential than ever to prevent hidden flaws from slipping through.</p>



<p class="wp-block-paragraph"><strong>How Can Public Sector Bodies Respond?</strong></p>



<p class="wp-block-paragraph">Veracode is urging public sector organisations to modernise their approach by adopting risk-based remediation strategies and automating more of the security process. Key recommendations include:</p>



<p class="wp-block-paragraph">– Implementing context-driven security posture management, which prioritises the most exploitable vulnerabilities using insights from multiple tools and data sources.</p>



<p class="wp-block-paragraph">– Establishing continuous scanning, integrated into the full development lifecycle, so that flaws are caught earlier and fixed faster.</p>



<p class="wp-block-paragraph">– Supporting developer enablement, giving teams the training and tools they need to identify and address issues proactively.</p>



<p class="wp-block-paragraph">According to the report, the most effective and cost-efficient way to reduce security debt is to prevent it from accumulating in the first place.</p>



<p class="wp-block-paragraph"><strong>Risks for the Public, Service Delivery, and Compliance</strong></p>



<p class="wp-block-paragraph">While the problem is technical in nature, the impact appears to extend far beyond IT departments. For example, vulnerabilities in public sector software can put sensitive public data at risk, disrupt essential services, and erode public trust. In sectors like healthcare and social services, the consequences of a breach could be devastating.</p>



<p class="wp-block-paragraph">There are also compliance implications. For example, governments are increasingly subject to cybersecurity regulations requiring evidence of secure coding practices and risk mitigation. Persistent security debt may put some organisations in breach of data protection obligations or national security protocols.</p>



<p class="wp-block-paragraph"><strong>A Complex Challenge, but Improvement Is Possible</strong></p>



<p class="wp-block-paragraph">Despite the bleak statistics, Veracode’s analysis makes clear that progress is achievable and that top-performing agencies prove that meaningful improvement can be made with the right strategy, investment, and organisational buy-in.</p>



<p class="wp-block-paragraph">The challenge now appears to be for lagging organisations to assess their security maturity, identify the operational and cultural blockers to faster remediation, and make the structural changes needed to reduce their exposure to risk.</p>



<p class="wp-block-paragraph"><strong>What Does This Mean For Your Business?</strong></p>



<p class="wp-block-paragraph">For governments, the consequences of inaction are no longer theoretical. The exposure created by slow patching and ageing systems is already being exploited by cybercriminals. Also, for the public, the stakes are growing, whether through data loss, service disruption, or erosion of trust in digital government services. What Veracode’s report makes clear is that the organisations getting this right are not doing so through luck or scale, but through deliberate prioritisation and operational focus.</p>



<p class="wp-block-paragraph">In the UK, many of the same systemic issues are clearly visible. Critical infrastructure is still running on unsupported legacy platforms, key security roles remain unfilled, and cyber incidents linked to outdated systems are becoming more frequent. Without hard data on vulnerability resolution times or the extent of open-source debt, public sector bodies are left guessing where their greatest risks lie and how they compare to their peers.</p>



<p class="wp-block-paragraph">This gap also affects the wider network of software vendors and contractors. UK businesses that supply the public sector will need to meet rising expectations around security assurance and may face tighter scrutiny as new legislation and procurement rules come into force. At the same time, private sector organisations can use these findings as a benchmark, both to avoid the same mistakes and to identify opportunities to lead in secure development practices.</p>



<p class="wp-block-paragraph">The core message here is that software risk is measurable, manageable, and no longer optional. Delays in addressing known flaws are not just a technical lapse but an operational liability, with real consequences for services, compliance, and reputation. Whether in the US or UK, the longer these gaps are left open, the harder and costlier they become to close.</p>
<p>The post <a href="https://w2.meartechnology.co.uk/2025/06/18/featured-article-us-uk-public-sectors-running-insecure-it/">Featured Article : US &#038; UK Public Sectors Running Insecure IT</a> appeared first on <a href="https://w2.meartechnology.co.uk">Mear Technology</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Featured Article : Google I/O 2025 &#8211; The Best Bits</title>
		<link>https://w2.meartechnology.co.uk/2025/05/28/featured-article-google-i-o-2025-the-best-bits/</link>
		
		<dc:creator><![CDATA[Paul Stradling]]></dc:creator>
		<pubDate>Wed, 28 May 2025 10:19:02 +0000</pubDate>
				<category><![CDATA[Funnies]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Manufacturer]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Sales]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[technology]]></category>
		<guid isPermaLink="false">https://w2.meartechnology.co.uk/?p=17188</guid>

					<description><![CDATA[<p>Here we take a look at a dozen of the biggest announcements from Google I/O 2025, where AI took centre stage across everything from search and app design to video creation, smart wearables and healthcare tools. What Is Google I/O 2025? Every May, Google brings developers, media, and industry insiders together at its annual I/O&#8230; <br /> <a class="read-more" href="https://w2.meartechnology.co.uk/2025/05/28/featured-article-google-i-o-2025-the-best-bits/">Read more</a></p>
<p>The post <a href="https://w2.meartechnology.co.uk/2025/05/28/featured-article-google-i-o-2025-the-best-bits/">Featured Article : Google I/O 2025 &#8211; The Best Bits</a> appeared first on <a href="https://w2.meartechnology.co.uk">Mear Technology</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Here we take a look at a dozen of the biggest announcements from Google I/O 2025, where AI took centre stage across everything from search and app design to video creation, smart wearables and healthcare tools.</p>



<p class="wp-block-paragraph"><strong>What Is Google I/O 2025?</strong></p>



<p class="wp-block-paragraph">Every May, Google brings developers, media, and industry insiders together at its annual I/O conference (short for&nbsp;<em>“Input/Output”</em>&nbsp;and&nbsp;<em>“Innovation in the Open”</em>). The 2025 edition took place on 14 May at the Shoreline Amphitheatre in Mountain View, California, next door to Google HQ.</p>



<p class="wp-block-paragraph">As expected, the event was streamed globally, but this year’s show took a decisive turn. It wasn’t just a developer preview, but was a bold, all-in statement from Google that AI now underpins everything from search and productivity tools to healthcare and hardware.</p>



<p class="wp-block-paragraph"><strong>This Year’s Big Themes? All Roads Lead to Gemini</strong></p>



<p class="wp-block-paragraph">If there was one consistent message at Google I/O 2025, it was that Gemini AI is no longer an add-on – it’s the engine behind Google’s future.</p>



<p class="wp-block-paragraph">Whether it’s Gmail, Search, Chrome, Android or even smart glasses, it seems that Google now really wants every user interaction to be shaped, streamlined and supercharged by Gemini. That ambition was reflected in a dozen headline announcements at this year’s event, each revealing a different facet of that broader AI-first strategy.</p>



<p class="wp-block-paragraph"><strong>1. Gemini 2.5 Pro and Gemini Flash (Two New AI Models)</strong></p>



<p class="wp-block-paragraph">Top of the bill were Gemini 2.5 Pro and Gemini 2.5 Flash. The Pro version boasts advanced reasoning, a new&nbsp;<em>“Deep Think”</em>&nbsp;mode for complex tasks, and even native audio output for conversational use. Meanwhile, Flash is designed for real-time responsiveness, which should make it ideal for fast interactions in mobile apps and dynamic websites.</p>



<p class="wp-block-paragraph">Both models are already being rolled out across Google services and APIs, with Gemini 2.5 Pro now powering Google Workspace features and Gemini Flash helping developers create faster, leaner applications.</p>



<p class="wp-block-paragraph"><strong>2. AI Mode Comes to Google Search (But With Ads)</strong></p>



<p class="wp-block-paragraph">Possibly the most controversial change is the arrival of AI Mode in Search. Users can now engage in dynamic conversations rather than typing one-off queries, with Gemini summarising results and suggesting follow-ups. However, it seems that the twist is that Google is inserting ads into these AI-powered replies.</p>



<p class="wp-block-paragraph">That decision has (understandably) caused a few eyebrows to be raised, particularly among publishers and advertisers. That said, it could reshape how billions interact with the web, and how businesses compete for visibility.</p>



<p class="wp-block-paragraph"><strong>3. Imagen 4 (An AI Image Generation Model)</strong></p>



<p class="wp-block-paragraph">Google also lifted the lid on Imagen 4, its latest text-to-image model. This version produces higher-resolution, more photo-realistic results with better handling of textures, shadows, and complex details like glass and water.</p>



<p class="wp-block-paragraph">Imagen 4 is now available via the Gemini app and Google Workspace, making it easier to insert AI-generated visuals directly into Docs, Slides, or marketing content.</p>



<p class="wp-block-paragraph"><strong>4. ‘Flow’ AI Powered Video Creation</strong></p>



<p class="wp-block-paragraph">Following OpenAI’s moves in generative video, Google unveiled ‘Flow’, a new AI-powered video editing and generation tool. It combines elements from Google’s existing Imagen, Veo, and Gemini models to help users design scenes, animate characters, and apply edits, all just by using natural language.</p>



<p class="wp-block-paragraph">Although aimed at creators and marketing teams, Google says Flow could also appeal to educators and internal communications professionals. A limited beta will roll out later in 2025.</p>



<p class="wp-block-paragraph"><strong>5. ‘Beam’ – The New Name for Project Starline</strong></p>



<p class="wp-block-paragraph">It seems that what began as an R&amp;D curiosity in 2021 is finally nearing market release. ‘Beam’ is Google’s rebranded 3D teleconferencing platform, designed to offer life-size, high-fidelity video calls using advanced AI rendering and custom hardware.</p>



<p class="wp-block-paragraph">Expected to launch in late 2025, Beam will first be trialled with enterprise customers via Google Meet integrations. It’s pitched as a serious upgrade to remote working, though pricing and hardware requirements remain unclear.</p>



<p class="wp-block-paragraph"><strong>6. Stitch – Designing Apps With AI</strong></p>



<p class="wp-block-paragraph">‘Stitch’ is a new AI assistant that helps developers and designers rapidly mock up app interfaces. It uses Gemini to recommend UI layouts, generate components, and even fill in dummy content. This could prove especially useful for prototyping, hackathons, or client pitches.</p>



<p class="wp-block-paragraph">Stitch is now available in preview via Firebase Studio, with integration into Android Studio expected soon.</p>



<p class="wp-block-paragraph"><strong>7. SynthID Detector For Spotting AI-Generated Content</strong></p>



<p class="wp-block-paragraph">To address growing concerns about AI-generated misinformation, Google introduced SynthID Detector. It’s a verification tool that checks whether images, audio, video (or even text) carry watermarks embedded by Google’s AI models.</p>



<p class="wp-block-paragraph">This builds on Google DeepMind’s original SynthID system and reflects broader industry moves towards watermarking and provenance standards. The tool will be freely available to researchers and select enterprise partners later this year.</p>



<p class="wp-block-paragraph"><strong>8. Google’s Multimodal AI Assistant ‘Project Astra’</strong></p>



<p class="wp-block-paragraph">Another show-stealer was Project Astra, a real-time AI assistant that combines video, voice, and text to interpret what you’re doing and respond accordingly.</p>



<p class="wp-block-paragraph">It may be best to think of it as Gemini’s next evolution, capable of recognising a user’s environment through their phone’s camera, answering questions about what it sees, and even predicting the user’s next action. Still experimental, but expected to underpin future Android features and wearables.</p>



<p class="wp-block-paragraph"><strong>9. MedGemma and AMIE (AI in Healthcare)</strong></p>



<p class="wp-block-paragraph">Google’s AI push now extends firmly into healthcare. With this in mind, it unveiled two tools:</p>



<p class="wp-block-paragraph">– MedGemma, a model trained on both medical images and text, capable of assisting in diagnosis and triage.</p>



<p class="wp-block-paragraph">– AMIE (AI Medical Interview Engine), which can conduct diagnostic conversations and interpret patient visuals.</p>



<p class="wp-block-paragraph">While not ready for deployment just yet, both are being trialled with healthcare providers and researchers.</p>



<p class="wp-block-paragraph"><strong>10. Gemini in Chrome For Context-Aware Web Assistance</strong></p>



<p class="wp-block-paragraph">Gemini is also coming to Google Chrome, where it can provide context-aware summaries, explanations and suggestions as the user browses. This turns the browser into an interactive assistant that understands what a user’s doing in real time (similar to Microsoft’s Copilot in Edge).</p>



<p class="wp-block-paragraph">A developer preview is rolling out now, with broader availability expected by late summer.</p>



<p class="wp-block-paragraph"><strong>11. Android XR and Smart Glasses</strong></p>



<p class="wp-block-paragraph">In partnership with Samsung and Qualcomm, Google announced Android XR, a new platform for extended reality experiences. As part of this push, the company confirmed it is developing new AI-powered smart glasses, with real-time translation and contextual information overlays.</p>



<p class="wp-block-paragraph">This marks Google’s first serious return to the wearables / smart glasses market since the early Google Glass days, and could be pivotal as Apple, Meta, and others ramp up their own wearable platforms.</p>



<p class="wp-block-paragraph"><strong>12. Android Auto Gets Smarter</strong></p>



<p class="wp-block-paragraph">Rounding off this list are several updates to Android Auto, including:</p>



<p class="wp-block-paragraph">– Spotify Jam integration.</p>



<p class="wp-block-paragraph">– Support for video apps and web browsers (while parked).</p>



<p class="wp-block-paragraph">– A new Light Mode interface for better visibility.</p>



<p class="wp-block-paragraph">This reinforces Google’s push into connected vehicles, an increasingly strategic domain as competition with Apple and Amazon heats up.</p>



<p class="wp-block-paragraph"><strong>What Does This Say About Google in 2025?</strong></p>



<p class="wp-block-paragraph">This year’s I/O wasn’t just a showcase of new toys, but appeared to be a full declaration of intent. Google seems to be betting that AI will redefine every user interaction, and it’s restructuring its entire product ecosystem around Gemini to make that happen.</p>



<p class="wp-block-paragraph">From an enterprise perspective, the implications are huge. For example, tools like Flow, Stitch, and Imagen 4 offer businesses faster ways to produce content, design interfaces, and automate creative work. Also, Beam and AI Mode signal new frontiers for remote working and customer engagement.</p>



<p class="wp-block-paragraph">However, some questions remain. For example, the insertion of ads into AI-powered search has already sparked criticism from publishers who fear revenue losses. Privacy advocates are also watching closely, especially with the expansion of camera-based assistants like Astra and wearable tech.</p>



<p class="wp-block-paragraph">That said, for most users (especially businesses) the message from Google appears to be ‘prepare for a more AI-shaped Google’. Also, if you’re not already using Gemini in some form, the chances are you soon will be.</p>



<p class="wp-block-paragraph"><strong>What Does This Mean For Your Business?</strong></p>



<p class="wp-block-paragraph">Taken together, these dozen announcements from Google I/O 2025 seem to show Google repositioning itself as an AI-first company in both name and nature. If so, this isn’t just a cosmetic rebrand or a handful of feature upgrades. It’s a fundamental reimagining of the company’s product line, embedding AI deeply into every experience, every device, and every service it touches.</p>



<p class="wp-block-paragraph">For UK businesses, tools like Imagen 4, Stitch, Flow, and Gemini for Chrome could help streamline marketing, design and customer engagement tasks, hopefully offering significant productivity gains for companies of all sizes. Early adopters may well find they can reduce content creation time, speed up product development, and respond more intelligently to customer needs. However, the introduction of ads into AI-powered search results could force marketers to rethink their SEO strategies and advertising budgets, particularly as Google’s search experience becomes more curated and conversational.</p>



<p class="wp-block-paragraph">More broadly, the announcements reflect Google’s intent to compete hard on multiple fronts, i.e. not just with OpenAI in text and image generation, but with Apple and Meta in wearables, Microsoft in productivity AI, and Amazon in the smart car and assistant space. The development of smart glasses and extended reality platforms suggests Google is ready to push its ecosystem beyond screens and keyboards, potentially reshaping how users, consumers, and workers interact with digital content altogether.</p>



<p class="wp-block-paragraph">That said, the road ahead may not be entirely smooth. There are already valid concerns about the transparency of AI-generated results, the risks of bias or hallucination, and the implications of AI-driven advertising. Tools like SynthID and Project Astra offer a glimpse of how Google might manage those risks, but for regulators, publishers, privacy groups and end users, trust will need to be earned, not just declared.</p>



<p class="wp-block-paragraph">Still, the scale and coherence of Google’s announcements at I/O 2025 suggest a company that has moved past experimentation and into execution. For anyone building, marketing, communicating or working online, especially in fast-moving sectors, this year’s developments appear to be a clear sign that the tools, workflows and digital environments we all rely on may soon be fundamentally reshaped by AI, whether we’re ready or not.</p>
<p>The post <a href="https://w2.meartechnology.co.uk/2025/05/28/featured-article-google-i-o-2025-the-best-bits/">Featured Article : Google I/O 2025 &#8211; The Best Bits</a> appeared first on <a href="https://w2.meartechnology.co.uk">Mear Technology</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
