Tech
OpenAI, Anthropic Cut AI Costs as Rivals Gain Ground
OpenAI and Anthropic are emphasizing lower-cost AI options as open-weight models attract more enterprise workloads.
Cost is becoming a bigger factor in AI model selection, particularly for high-volume and less demanding workloads. Several Chinese vendors now offer models that compete with leading US models on certain benchmarks while charging less per token.
OpenAI said it cut prices for its lower-cost GPT-5.6 Luna model by as much as 80%, depending on the type of token usage. Anthropic has also emphasized price in marketing Opus 5, which it says offers “frontier intelligence” at half the price of Mythos. Its Sonnet model is positioned as a balance between the company’s lightweight and highest-performing models.
According to data from SiliconData, via the Financial Times, there has been a noticeable shift in inference token spend away from closed models, which OpenAI and Anthropic primarily provide, since mid-July. While spending remains much higher on proprietary models than open-source alternatives, the gap has narrowed over the past month.
The pushback against increasingly high AI bills has come at a dangerous time for both OpenAI and Anthropic, which are planning IPOs for later this year or early next. Anthropic has reportedly been valued by private investors at as much as $2 trillion, which would make it the largest IPO ever. OpenAI is reportedly targeting a valuation above $1 trillion.
At the same time, the cost of securing more compute continues to rise, which will undoubtedly affect their ability to turn a profit in the near term. Anthropic was reportedly profitable in the second quarter of 2026, but is unlikely to repeat that feat over the next two quarters.
More must-read AI coverage
Chinese open-weight models compete on price
Several major US tech companies, which are typically among the biggest monthly spenders on AI models, have shifted some workloads to cheaper Chinese alternatives. DoorDash, Airbnb, and Coinbase are just a few of the companies that have confirmed using Chinese AI models.
While US models are often used during the development stages of an AI service, some companies are shifting production workloads or less intensive requests to cheaper Chinese models. Model-routing services such as OpenRouter make this far easier. Even so, security and compliance experts remain concerned about sending private or potentially sensitive data outside the country.
China’s AI model makers have had several major successes over the past few months. Moonshot AI’s Kimi K3 topped a frontend coding benchmark and has performed well across several other metrics. Alibaba, DeepSeek, and z.AI have also launched new models that have performed strongly against the current market leaders.
That momentum could soon face resistance, however, as both the Chinese and US governments have signaled concerns about US and European companies using Chinese AI technology. In the US, accusations of “industrial-scale theft” through model distillation have led several officials to warn of possible bans. In China, the government is weighing tougher export controls, particularly on frontier AI technology, as leverage against further US restrictions on Chinese technology.
For businesses using AI at scale, this shift means model selection is becoming less about choosing a single best-performing provider and more about balancing performance, cost, security, and regulatory risk across different workloads.
Read more: As Chinese developers compete more aggressively on price and performance, learn how their lower-cost AI models could introduce security and compliance trade-offs for businesses.
>
Tech
Singapore Is Literally Training People to Get Scammed
Singapore has decided that one way to teach people how not to fall for scams is to let them experience one first. A simulated one, thankfully.
Singapore’s Cyber Security Agency is running a six-month National Simulated Scams Exercise, in which volunteers receive simulated robocalls designed to mimic government impersonation scams. The pilot runs through Aug. 31 and is part of Singapore’s broader push to make its population more resilient to increasingly sophisticated digital fraud.
The experiment raises a useful question for businesses, too: If employees can be fooled by increasingly polished calls, messages, deepfakes, and impersonation attempts, is an annual security-awareness course really enough?
Singapore wants people to experience a scam before the real one arrives
Singapore’s Cyber Security Agency, with support from the Ministry of Home Affairs, launched the exercise on March 1. Participation is voluntary, but those who sign up don’t know exactly when the simulated scam will arrive.
At some point during the six-month exercise, participants receive robocalls that mimic Government Official Impersonation Scams (GOIS). According to CSA’s description of the exercise, the controlled simulation is intended to let people experience scammers’ techniques firsthand and learn what to do when they encounter similar tactics outside the exercise.
The experiment isn’t limited to yesterday’s scam tactics. In a July update on Singapore’s AI-driven threat landscape, CSA said the pilot includes AI-enabled government impersonation scam calls. That matters because the scam itself increasingly resembles a conversation rather than a suspicious link.
Voice-based social engineering can put victims under pressure in real time, exploiting authority, urgency, and fear before they have time to verify what they’re hearing. Security researchers have also found increasingly sophisticated tooling designed specifically for these attacks.
For example, TechRepublic previously covered phishing kits built for voice-based scammers that can provide attackers with real-time information as they try to persuade victims to approve multifactor authentication requests. Singapore’s exercise effectively gives participants a fire drill for that moment.
The scam problem is still expensive
Singapore has good reason to experiment.
According to Singapore Police’s 2025 scam and cybercrime figures, the country recorded 37,308 scam cases in 2025, with victims losing approximately S$913.1 million. Both figures declined from the previous year, but the losses still illustrate the enormous financial consequences of successful scams.
Government impersonation scams moved in the opposite direction.
Singapore’s Annual Scams and Cybercrime Brief 2025 shows GOIS cases more than doubled from 1,504 in 2024 to 3,363 in 2025, while reported losses climbed from S$151.3 million to S$242.9 million. The basic technique exploits something no software patch can completely remove: trust.
Scammers may pose as banks, government agencies, police officers, regulators, or other seemingly authoritative organizations. Their goal is often to create enough urgency or fear that the victim acts before independently checking the story.
That’s why technical defenses alone haven’t made the problem disappear. As TechRepublic previously examined in its analysis of Singapore’s S$913 million scam problem, even longstanding identity requirements for SIM registration haven’t eliminated telecom-enabled fraud. Attackers adapt around controls rather than politely crashing into them.
Must-read security coverage
What IT leaders can borrow from Singapore’s experiment
Businesses don’t need to start prank-calling their entire workforce tomorrow morning.
But Singapore’s experiment points toward a useful principle for security teams: People may learn more from safely experiencing an attack than from being told what one looks like. Traditional phishing simulations already use that idea. The difference is that the threat surface has expanded well beyond the inbox.
An employee might now receive a WhatsApp message supposedly from an executive, a convincing phone call from “IT,” a video call featuring a digitally manipulated face, or a request presented as a confidential assignment from senior management.
That’s not hypothetical. In a 2026 advisory on executive impersonation scams, Singapore Police warned that criminals had impersonated company executives on WhatsApp and, in some cases, used digitally altered appearances during video calls. Victims were told they were working on confidential projects and instructed not to discuss them with colleagues, cutting off one of the easiest ways to discover the deception.
For IT and security leaders, that suggests simulation programs should test more than whether an employee clicks a suspicious email.
Teams could practice scenarios involving:
- unexpected calls from supposed IT staff asking for credentials or MFA approval;
- urgent messages from executives requesting payments or sensitive information;
- requests to move a conversation from an official channel to WhatsApp or another messaging service;
- supposed regulators or law-enforcement officials demanding immediate action;
- voice or video impersonation intended to override an employee’s normal verification process.
The objective isn’t to catch employees making mistakes. It’s to build a reflex: Stop, verify, and use a second channel before acting.
That becomes more important as social engineering grows more interactive. TechRepublic has reported on the surge in social engineering attacks, including attackers posing as help-desk or IT personnel to exploit trust and urgency and persuade employees to weaken authentication controls.
Security training may need to feel more like a fire drill
There’s an obvious limitation to Singapore’s approach: Participants volunteered.
Employees in the real world don’t get to opt in before a criminal targets them. Nor does recognizing one simulated government scam guarantee that someone will spot the next fake CEO, supplier, help desk worker, recruiter, or bank representative. But the underlying idea is harder to dismiss.
Organizations regularly rehearse fires, evacuations, outages, incident-response procedures, and disaster-recovery plans because knowing a procedure isn’t the same as executing it under pressure.
Social engineering may deserve the same treatment. Instead of asking whether employees completed their annual cybersecurity module, security leaders may increasingly need to ask whether employees have practiced responding to the kinds of attacks they’re actually likely to encounter.
Singapore is betting that experiencing the trick once, in a controlled environment, can make the real trick easier to recognize.
For businesses facing AI-assisted impersonation, voice phishing, deepfakes, and increasingly personalized fraud, that may be the more useful lesson: Don’t just teach employees what a scam looks like. Give them practice saying no to one.
Related reading: For another sign of how technology is reshaping Singapore, the country recently raised its 2026 growth forecast as booming AI demand fuels electronics exports and manufacturing.
>
Tech
Google Says Chrome Cut 7 Billion Unwanted Android Notifications Per Day
Seven billion unwanted notifications a day is a lot of noise to cut from Android devices.
Google says Chrome reduced unwanted notifications by more than 7 billion per day in the first quarter of 2026 by combining permission revocation, abuse detection, sender rate limits, and on-device machine learning.
The company is now using several defenses together. Chrome can revoke notification permissions, detect coordinated behavior across websites, flag suspicious notification content, and limit high-volume senders through Firebase Cloud Messaging (FCM).
That approach matters because it shifts some of the burden away from users, who would otherwise have to recognize every suspicious notification themselves.
Multiple approaches to address a single problem
Filtering out such a volume of unwanted notifications is a significant task, and Google has now revealed the behind-the-scenes process for doing so.
According to the company’s blog, Chrome is employing a “Swiss cheese” model to deal with unwanted notifications.
Google’s first line of defense is the infrastructure behind the notifications. Chrome can automatically revoke notification permissions from sites that appear abusive, repeatedly trigger warnings, or have become inactive, cutting off their ability to keep pushing alerts to a user’s device.

Google is also looking for signs that multiple websites may be working together.
Google can use signals such as service-worker activity to identify coordinated behavior, while its FCM adds another control by rate-limiting sites that send notifications at excessive volumes. Websites can be limited to 1,000 messages per minute, with repeat offenders facing tighter restrictions.
The company is also making it easier for users to turn off notifications without digging deep inside Chrome. Push notifications will now include an option to turn them off immediately.

More Google coverage
Chrome is building upon previous work
The 7-billion figure reflects more than Google’s latest changes.
Chrome’s notification defenses have been developing for months, including on-device Machine Learning that can analyze notification content locally rather than sending it to Google, an approach that helps keep the notification content end-to-end secured.
But Android’s hardware fragmentation leaves one question unanswered: how widely can these local protections actually run?
Google has not specified whether the on-device ML layer reaches budget and older devices as broadly as newer hardware, which could affect how consistently users receive the same level of protection.
The company keeps refining how secure Chrome notifications remain by now adding its recent multi-layered approach. In its own words, the “goal is to ensure that if abuse slips through one layer, another is there to catch it.”
The user still has a role to play
Even with all these defenses, Google cannot make the notification channel risk-free.
A notification can still be deceptive without triggering every automated defense. That means the user’s judgment remains the final layer of protection, making user awareness as important as Google’s protections.
There is also the possibility that automated security systems could get it wrong. Google hasn’t disclosed an incident in which these notification defenses made a specific mistake. But any system that automatically identifies and restricts content or websites has to contend with false positives. A legitimate site could be caught by an overly aggressive defense, frustrating users who actually want its notifications.
Other News: Google says Gemini has surpassed 1 billion monthly active users, marking a major milestone as it competes for scale in the rapidly growing consumer AI market.
>
Tech
Microsoft Plans to End SMS and Voice Authentication for Entra ID
Microsoft reportedly plans to phase out SMS and voice authentication for Microsoft Entra ID users, pushing organizations toward passkeys and other phishing-resistant sign-in methods.
According to an administrator notice first reported by Windows Latest, affected users will have to register a passkey before Microsoft disables the phone-based authentication methods.
“We are notifying all Microsoft Entra ID tenants of an important change to authentication security: The AI era demands stronger, phishing-resistant authentication,” the reported notice states.
Microsoft said SMS and voice authentication provide weaker protection against cyber threats such as phishing, SIM-swapping, and replay attacks. AI-assisted social engineering adds to that risk by helping attackers create more convincing campaigns designed to steal credentials and one-time codes.

More Microsoft news
Deadlines for enterprise and consumers
Microsoft has laid out a strict, mandatory timetable for its corporate Entra ID platform:
- Sept. 1: Users logging in with voice or SMS credentials will be required to register a passkey during sign-in.
- Feb. 1, 2027: Microsoft will permanently terminate SMS and voice verification across all Entra ID accounts.
“There is no opt out from this enforcement; it applies to all tenants,” the reported notice states.
Everyday consumers will eventually face the same reality. Microsoft confirmed in support documentation spotted by Windows Latest that it is phasing out text verification and account recovery across personal Microsoft accounts, which power Windows 11, Xbox, and Outlook. While Microsoft has not set a formal cut-off date for home users, the company declared that “the future of authentication is passwordless, secure, and user-friendly,” Windows Latest reported.
The passwordless transition friction
Forcing an entire corporate ecosystem off SMS solves a glaring security loophole, but it introduces immediate operational friction. The universal appeal of the text message was its absolute convenience: virtually every mobile device, regardless of age or operating system, can receive an SMS without user configuration.
Passkeys rely on device-level biometric hardware and modern authenticator apps. Organizations must now navigate the logistics of onboarding non-technical staff and supporting workers on older hardware or restrictive bring-your-own-device policies.
Moreover, because text codes have long functioned as the default safety net for forgotten credentials, locking out SMS account recovery creates a higher risk of permanent account lockouts if a user loses access to their primary authentication device. Companies and individual users alike should audit their recovery options and establish passkeys before Microsoft pulls the safety cord entirely.
Read more: Bitwarden’s passkey support for Windows 11 gives Microsoft Entra ID users a phishing-resistant alternative to traditional login credentials.
>
-
movies3 months agoSearch For Canadian TV Actor Stewart McLean Now Homicide Investigation
-
Fashion9 years agoThese ’90s fashion trends are making a comeback in 2017
-
Fashion9 years agoAccording to Dior Couture, this taboo fashion accessory is back
-
Fashion9 years agoModel Jocelyn Chew’s Instagram is the best vacation you’ve ever had
-
Fashion9 years agoEmily Ratajkowski channels back-to-school style
-
Fashion9 years agoYour comprehensive guide to this fall’s biggest trends
-
Fashion9 years ago9 Celebrities who have spoken out about being photoshopped
-
Fashion9 years agoA photo diary of the nightlife scene from LA To Ibiza
