News
Half the fun of being really invested in a TV show is writing your own stories for your favourite characters. If you're a fan of Reacher on Prime Video, there's a chance that you've imagined the titular hero (played by Alan Ritchson) ending up with his loyal sidekick, Neagley (Maria Sten).
A quick Reddit and social media search reveals that I'm definitely not on my own in thinking about this. Though we've not seen Neagley in the main Reacher series since season 3, she remains the fan-favourite right-hand woman, and fans have been publicly pining for her since her departure.
Luckily, the spinoff Neagley lands on the Amazon streamer on September 16, putting her past and present firmly in the hot seat. Reacher will pop his head in along the way... and if anything, this adds fuel to the fire that there's possible romantic tension between.
However, the same could easily be said to be between Neagley and newbie detective Hudson (Greyston Holt), though as of yet, Neagley has chosen nobody but herself.
It's here that I have to be the bearer of bad news: creator Nicholas Wootton has indeed confirmed that there are "no plans" for a Reacher-Neagley romance to be incorporated into the story. Having said that, it's a 'never say never' situation.
'I don't want to put a fork in that'"I don't want to put a fork in that," Wootton tells me when I ask about the romantic potential. "I don't know what the future may bring. Are there plans for that in our present writing? I will admit no. But I will also say that the world is a big place.
"I don't want to disappoint fans, but right now, the plan for this show is not to explore that. But you never know."
I love a diplomatic answer when I hear one. Though it seems incredibly likely, we're currently waiting to hear whether Neagley season 2 will be picked up or not. So while I've put the request in, for now, we have to make do with how Reacher is utilized in the episodes that we have.
"I love the way that Reacher's been used in this season," Wootton continues. "I felt like it was a handoff to Neagley that allows her to have her own series, yet also gives it a really nice arc.
"His use in this is much more of an emotional tie than an action-based one, and I don't think people will be expecting that. Every time we watched it, I felt it in my chest."
Sounds like the power of love to me, but what do I know?
- Opswat found two flaws in TP‑Link Tapo C200 cameras: auth bypass (CVE‑2026‑15315) and DoS (CVE‑2026‑15316)
- Bugs let attackers hijack admin sessions or crash devices; millions of users potentially exposed
- TP‑Link patched with firmware V5_1.4.6 on Aug 18, 2026; users urged to update immediately
Security researchers found a pair of vulnerabilities in popular smart cameras, which could allow threat actors to peep into people’s homes and businesses.
Earlier this week, Opswat disclosed finding two bugs in the TP-Link Tapo C200 smart security camera - an authentication bypass flaw, and a denial-of-service vulnerability. The former is tracked as CVE-2026-15315 and was given a severity score of 8.7/10 (high). Opswat says the bug allows unauthenticated attackers to obtain valid admin sessions without having a password, which would allow them to manage the device and even watch the stream.
The latter is tracked as CVE-2026-15316. With a severity score of 7.1/10 (high), this bug allows threat actors to send oversized crypted ciphertext values that may trigger exception handling failures and cause the affected device to crash or restart. “Successful exploitation may temporarily disrupt HTTPS management and monitoring functionality, resulting in a denial-of-service (DoS) condition until the service recovers,” according to the NVD.
Patching the bugsThe C200 is a mass-market product, advertised as a security camera, a baby monitor, or a pet camera, with motion detection, 1080p video, 2-way audio, night vision, cloud & SD card storage, and integrations with both Alexa and Google Home.
Opswat disclosed their findings to TP-Link in mid-April this year, which started working on a fix in early July this year. On August 18, 2026, TP-Link released firmware version V5_1.4.6, which addressed both flaws. Users are advised to install the fix as soon as possible.
The researchers did not discuss if the flaws were being abused in the wild, or to what extent. We do know that TP-Link Tapo cameras are rather popular, with the C200 model being relatively widely sold. According to TP-Link, the Tapo app has more than 13 million users, while the Google Play Store shows 10+ million downloads.
On Amazon, the C200 specifically is listed as the #1 top rated product in its category, with more than 3,000 purchases this month alone.
"Camera bugs always get attention because of the "spy factor," but they usually sound cooler and scarier than they actually are," said Dahvid Schloss, OSCP, Chief Operating Officer at Suzu Labs. "The main reason not to "worry" about this one is that running this exploit requires local network access, so a threat actor has to be on your Wi-Fi or already own a device that is.
"If someone's made it that far into your network, they're not after the baby monitor. Now, if the camera was port-forwarded to the internet, that's a bigger design issue and probably should be a concern, but not a common setup for the everyday home user. Either way, I'd still patch the camera, but it's pretty low on the totem pole of what a cybercriminal wants."
"I'm quite curious about the undisclosed vulnerability that reportedly allows full compromise and a foothold to pivot from," Schloss added. "Based on what was reported, I would guess the exploit would be a command injection or a memory-safety bug in the same management service, chained behind that auth bypass to get code execution as root, where they then dropped a static binary to return a shell on the device whose firmware ships with almost no tooling. That attack chain isn't uncommon on cheap, older consumer IoT devices where security wasn't top of mind, but if that's the case here, seeing it hold up on a modern TP-Link device would be a bit of a blast from the past.
Do you use AI at work? And if you do, does your employer know about it?
A huge new study from Deloitte of 25,000 UK workers found that two-thirds have already used generative AI for work — and nearly a third of generative AI users say they're using it without their employer's knowledge.
Welcome to the world of ‘shadow AI’: workers bringing their own AI tools into the workplace, often without official approval, and using them to get their jobs done faster.
A look at Reddit reveals what that can mean in practice. One Reddit user complained: “My coworker is secretly using ChatGPT to do 80% of his work. He's getting praised for efficiency.” Their dilemma was simple: “Do I tell the bosses?”
Another Reddit user had the opposite problem after discovering just how much time AI could save them. “I’m a relative noob, so please don’t roast me, but I’ve just done about 2 weeks' work in an hour. Do I tell my boss or keep it secret?”
One of the most popular responses to their predicament was equally revealing: “Remember, AI work is more detectable than you think. Spend time humanizing the output and adding your own texture, then shut up.”
It's easy to see the attraction. If you've discovered a tool that lets you complete two weeks' worth of work in an hour, why wouldn't you use it? The more difficult question is whether you should tell anyone.
(Image credit: Getty Images / ViDI Studio)Shadow landsShadow AI doesn't necessarily mean employees are doing anything malicious. In many cases, workers simply prefer using AI tools they're already familiar with rather than whatever their company has provided — assuming it has provided anything at all.
But there's an important difference between using your own favorite productivity app and using an unapproved AI chatbot.
As my colleague Craig Hale reported in June, a survey from PagerDuty found that 88% of workers had shared work-related information with public AI systems. Some 43% had uploaded emails or correspondence, 40% had shared meeting notes, 34% had entered customer information, and 31% had shared sensitive business information such as financial data or confidential company documents.
And that's where shadow AI becomes more than an awkward conversation about whether somebody deserves credit for working faster. Employees can potentially be feeding sensitive company information into AI services their employers haven't approved or secured.
But workers don't necessarily trust their employers to make the right decisions about AI either. PagerDuty found that 72% of workers believed they understood AI better than their own tech teams, while 77% thought their company's AI restrictions were limiting their professional development.
You can start to see why shadow AI is such a difficult problem for workplaces to navigate. An employee might simply see AI as a tool that helps them do their job faster, while colleagues could understandably wonder whether someone deserves the same credit for work largely produced by AI. For employers, there's the added concern that sensitive company information could be finding its way into AI tools they haven't approved or secured.
Who's really in the wrong?And let’s not forget how divisive AI can be. Many workers have a real aversion to using AI in any form whatsoever. One Reddit user asked: “How do I tell my boss who keeps telling me to use ChatGPT for simple tasks that I'm anti-AI?”
Workplace rules haven't necessarily caught up with the speed at which employees have adopted AI, and there's another remarkable number in Deloitte's research that suggests just how far this has already gone.
According to the Deloitte survey, British workers are now spending an estimated £958 million of their own money every year on generative AI tools they use for work. That's an extraordinary amount of money for employees to be spending on tools designed to make them better at jobs somebody else is paying them to do — particularly when almost a third aren't telling their employers they're using them.
But you can understand why. If you've just discovered a tool that lets you do two weeks' work in an hour, telling your boss might result in them wondering what you're going to do with the rest of the week.
Vibe coding makes developing an app as simple as describing your idea. With barriers collapsed, it is easy to assume that app monetization is dead.
Stan Marchand disagrees. As CEO of Paris-based app publisher Rocapine, he has proved that vibe-coded apps can still generate real revenue – but only if builders focus on the 20% of app development that moves beyond the code and into human craft.
I spoke with Stan to unpack what separates a buyable product from an empty gimmick in 2026.
Vibe coding has made it easier than ever to build apps, but are these apps actually generating revenue?Building is now the easy part. The scarce skills are insight, taste, and distribution.
A few are, but most aren't, and most often it's because people assume building a functioning app is the hard part. It isn't anymore.
Vibe coding has collapsed the cost of building an app to almost nothing. But 80% of the work can now be automated, and more than ever it's the remaining 20% left to humans that decides whether an app makes money: finding a value proposition that genuinely resonates, crafting a product with human taste, and telling its story efficiently.
The apps generating real revenue got those three things right. The flood of apps that look finished but never find a market got none of them. Building is now the easy part. The scarce skills are insight, taste, and distribution.
The code itself is not worth much.
What is worth something is whether the product resonates with real people. That is shown by asking two questions:
- Is it marketable? Can you reach users at a cost the business can support, or is the market already saturated by giants pushing the same promise?
- Will people pay? Once they've installed it, do they convert and stick? The KPIs that capture this are cost per install, conversion to paid, and early retention.
Put these questions together: that's ROAS- how much it costs to acquire a user versus how much that user is worth.
A rough prototype with a low cost per install and users who pay is a real business. A polished app with beautiful code and no one converting is a gimmick.
How does that evaluation process differ when assessing vibe-coded apps compared to traditional human-built apps?We evaluate the 20% the builder added: the insight, the craft, the taste.
Less than you'd think.
Nobody writes code by hand anymore, so "vibe-coded" versus "human-built" is becoming a distinction without a difference.
What changes is where we spend our time. With vibe-coded apps, the code is cheap to rebuild, so we care less about its quality and more about whether the concept has proven resonance.
The risk isn't messy code, it's a product that exists because it was easy to make rather than because anyone needed it. AI gives everyone the same 80%. We evaluate the 20% the builder added: the insight, the craft, the taste.
Three things:
- Know your stack: which tools generated what, under which licenses, and whether any third-party code or assets carry restrictions. Undocumented AI code isn't a dealbreaker; undocumentable code is.
- Clean data practices from day one: privacy policy, user consent, App Store and Play compliance, and analytics you can actually export.
- Make your metrics verifiable: revenue through the stores, retention cohorts, acquisition costs. We've walked away from partnerships not because the code was AI-generated, but because nothing could be checked.
Ask yourself what you actually want.
If you want the cash and to move on to the next idea, a full acquisition is clean. If you believe in the app and want to stay in the game, a publishing or revenue-share deal lets you keep upside while a partner brings what a solo builder rarely has: monetisation expertise, growth marketing budget, the infrastructure to scale.
The good news is that these paths aren't mutually exclusive. Unchaind, which we co-developed from scratch with a studio in Singapore under a publishing model, reached $1M ARR 16 days after launch. We ended up acquiring it later, once the developer wanted to move on to a new project.
Start with the model that fits where you are today; the exit can come when it makes sense for both sides.
What other tips would you give keen vibe coders who are looking to build and sell vibe-coded apps?Fight AI slop relentlessly
Build for a niche you understand deeply, ship in weeks, and put a price on it immediately. Free users tell you nothing about resonance.
Then fight AI slop relentlessly: the generic wording, the template design patterns, the onboarding everyone recognises. Users spot it instantly, and it kills trust. Invest your time in the 20% that makes your product yours; the rest is a commodity.
And when you talk to a publisher, bring your cohort data, not your feature list.
- CenterPoint Energy confirmed a cyberattack via exposed API, with customer data stolen
- Threat actor claims 7.49M files including IDs, SSNs, billing data, and transaction records
- Operations unaffected; investigation ongoing, regulators notified, customers to be informed
CenterPoint Energy has confirmed suffering a cyberattack and data theft, days after a criminal advertised the stolen files on an underground hacking forum.
CenterPoint Energy is a large US energy utility company that delivers electricity and natural gas to homes and businesses. It employs roughly 8,800 people and operates around $48.3 billion in assets, as of June 2026.
Recently, a threat actor posted a new thread on a dark web forum, saying they stole 7.49 million CenterPoint files from a poorly secured API, The Register reports. They said that the data included customer names and contact details, billing data, move-in dates, driver’s license information, and the last four digits of Social Security numbers (SSN).
Incurring expensesNo independent investigators have confirmed these claims just yet, and the company said it was investigating the matter. In a new 8-K document filed with the US Securities and Exchange Commission (SEC) on September 14, the company said that it “became aware of an online post by a third party claiming to have obtained a data set containing certain of the company’s customer information.”
It activated its incident response protocols and kicked off an investigation with the help of third-party cybersecurity experts.
“While the investigation remains ongoing, the company has determined that an unauthorized third party obtained personal information relating to a portion of the company’s customers through one of the company’s external facing systems,” the filing reads. “The company is continuing to work with third-party experts to determine the scope of customers and personal information affected by the incident and intends to notify affected customers and regulatory authorities as required by applicable law.” The police and regulatory agencies have been notified.
While the attack did not impact CenterPoint’s operations, which continue as usual, it did incur certain expenses, the company concluded. It stressed that it will likely incur even more expenses as the investigation continues.
Via The Register


