Hi, friends! Welcome to Installer No. 143, your guide to the best and Verge-iest stuff in the world. (If you’re new here, welcome, new tech season is here, and also you can read all the old editions at the Installer homepage.)
Technology
Russian hackers can steal emails without a click
Published
1 month agoon
By
Press Room
NEWYou can now listen to Fox News articles!
Opening an unexpected email can feel relatively harmless when you avoid its links and attachments. However, a Russian hacking campaign has turned that familiar safety advice on its head.
CISA says the Russian state-sponsored group Laundry Bear can compromise certain email accounts when someone simply opens or previews a malicious message. The attack targets organizations running unpatched versions of the Zimbra Collaboration Suite.
Once the email appears, hidden code can collect passwords, authentication data and as much as 90 days of messages. You may never see a warning or realize that anything happened.
The Cybersecurity and Infrastructure Security Agency issued the warning with the National Security Agency, FBI and cyber authorities from several allied countries. The agencies say the group has successfully targeted more than 10 Western organizations since July 2025.
INVESTIGATORS BELIEVE IRANIAN HACKERS ARE LIKELY BEHIND CYBERATTACK ON MINNESOTA WATER SYSTEMS: REPORT
Russian state-sponsored hackers can steal passwords, two-factor authentication tokens and up to 90 days of email when users view malicious messages in unpatched Zimbra accounts. (Kurt “CyberGuy” Knutsson)
CyberGuy Live: Missed “Sick of Spam?” Get the replay and checklist
Our free CyberGuy Live class, “Sick of Spam?” has ended, but you can still watch the full replay and download our spam-stopping checklist. Kurt “CyberGuy” Knutsson walks you step by step through simple ways to reduce robocalls, spam texts, junk email and unwanted messages. You’ll also learn how to curb political texts, clean up your inbox and spot messages that could put your personal information at risk.
Get the free replay and checklist now at CyberGuyLive.com.
Russian hackers can steal emails without a normal click
Laundry Bear, which Microsoft tracks as Void Blizzard, exploits a security flaw known as CVE-2025-66376. The cross-site scripting vulnerability affects the Classic user interface in certain versions of the Zimbra Collaboration Suite.
Zimbra is an email and collaboration platform used by some governments, schools, businesses and other organizations as an alternative to services such as Microsoft Exchange or Google Workspace. Attackers can place malicious JavaScript inside a specially crafted HTML email. That code runs automatically when a vulnerable Zimbra webmail client displays the message.
The person reading the email does not need to open an attachment. The attack also avoids the usual request to enter a password on an obvious phishing page. However, the email still needs to appear on the screen. CISA describes the technique as a zero-click exploit. Proofpoint calls it a “half-click” attack because someone must open the email or allow it to appear in a preview pane. Either description leads to the same concern. A message can look harmless while code hidden inside it quietly attacks the email account.
The email security flaw was patched in 2025
Laundry Bear reportedly used the flaw as a zero-day before Zimbra released a patch in November 2025. A zero-day attack exploits a security weakness before the software maker provides a fix. CISA later added the vulnerability to its list of flaws that hackers actively exploit.
The available patch closes the known security hole. Yet Laundry Bear continues to target organizations that have not installed the update. That makes delayed patching especially dangerous. An organization may have strong passwords and trained employees, but an exposed email server can still give attackers another way inside.
The campaign has reached organizations connected to the defense industrial base and government. Attackers have also targeted education, energy, law enforcement, media, nonprofit groups and technology companies.
One email can expose 90 days of messages
According to CISA, the malicious code attempts to collect the target’s last 90 days of email. That could include private conversations with coworkers, contract discussions or information about upcoming meetings. An inbox may also contain password reset notices, invoices and documents that reveal how an organization operates.
Laundry Bear also collects the person’s email address and password. The attack can copy the organization’s Global Address List, which acts as a directory of employees and contacts. The hackers may then gain enough information to impersonate a trusted coworker or identify more valuable accounts.
CISA says the exploit also targets two-factor authentication tokens. Those tokens help prove that someone has already completed an authentication step. A stolen token or session cookie can let an attacker enter an account without completing the normal login process again.
FAKE PASSWORD-MANAGER ALERTS COULD PUT YOUR VAULT AT RISK
Malicious code hidden inside an email can run when a vulnerable Zimbra webmail client displays the message, giving hackers access to sensitive account data. (Getty Images)
Hackers can create a hidden way back into an account
Stealing information provides immediate value, but Laundry Bear also tries to preserve its access. The attack creates a new Zimbra application passcode and sends it back to the hackers. Legacy email programs use these passcodes when they connect through services such as IMAP or ActiveSync and cannot support modern time-based authentication.
An unauthorized passcode can give the hackers another entrance to the mailbox. That access may continue even after someone changes the main account password. CISA has urged administrators to look for suspicious application passcodes, particularly passcodes labeled “ZimbraWeb.”
Organizations should treat an unknown passcode as a sign that someone may have entered the account. Simply installing the patch after a compromise may leave the attacker’s access in place.
How the stolen email data leaves the network
Laundry Bear sends the stolen information to servers controlled by the group. CISA says the attackers use a collection framework called Flowerbed. The system moves smaller pieces of data through Domain Name System requests. DNS normally helps computers find websites and online services.
Attackers can hide encoded information inside those requests. Because organizations generate large amounts of legitimate DNS traffic, the malicious activity may blend into the background. Laundry Bear sends larger collections through encrypted HTTPS connections. That can include compressed archives containing mailbox data. Security teams may need to inspect network logs, authentication records and mailbox activity to understand what left the organization.
Fake email login pages provide another route
Laundry Bear also uses adversary-in-the-middle phishing kits. These tools create login pages that closely resemble legitimate email portals. When someone enters a username and password, the phishing system captures those credentials. It can also intercept session cookies created during the login process. That means an attacker may gain access even when the account uses conventional multifactor authentication.
CISA’s indicators of compromise include domains that impersonated Zimbra infrastructure. Examples include mailnalysis.com, zimbrastat.com, zimbra-metadata.com and zmailanalytics.com. The presence of one of these domains in network logs could point to phishing or unauthorized account activity. However, organizations should review CISA’s complete list because attackers can change their infrastructure.
Proofpoint found that Laundry Bear sent messages from attacker-controlled Proton Mail accounts and email addresses the group had already compromised. In one example, the sender claimed to represent a Belgian media-verification organization. The email proposed cooperation between European institutions fighting disinformation. It included a legitimate-looking link to a European Union events calendar. However, the malicious code sat inside the email rather than the linked website.
Laundry Bear has targeted governments and Ukraine
Dutch intelligence agencies publicly identified Laundry Bear in May 2025. Their investigation linked the group to a 2024 breach of the Dutch National Police. That incident exposed personal information belonging to police personnel. Investigators said the attack helped them identify a previously unknown Russian cyberespionage group.
Since at least 2024, Laundry Bear has focused on organizations connected to Russian strategic interests. Its targets have included NATO member states and groups supporting Ukraine.
Microsoft has documented compromises involving defense organizations as well as entities in transportation and aviation.A separate campaign targeted members of Ukraine’s military with charity-themed phishing emails. Those messages disguised malware as requests for donations.
These campaigns suggest the group cares more about long-term intelligence collection than a quick financial payout. Access to email can reveal relationships, future plans and internal decisions.
PAIDWORK BREACH EXPOSES 23M USER RECORDS
CISA warns that Laundry Bear can compromise vulnerable Zimbra accounts without requiring users to click a link or open an attachment. (shapecharge/Getty Images)
Ways to stay safe from the email attack
The strongest protection starts with the organization running the email server because employees cannot personally patch a vulnerable installation. However, you can still take steps to spot suspicious activity and protect your other accounts.
1) Install every available email security update
Administrators should update Zimbra Collaboration Suite to a currently supported version and install all available security fixes. Organizations should confirm that the patch reached every server. An overlooked system may remain exposed even when the primary mail server has received the update.
2) Look for evidence that attackers already got inside
Installing the patch blocks the known flaw, but it cannot undo a previous intrusion. Security teams should review CISA’s published indicators of compromise. They should also search network records for connections to the listed domains and IP addresses. Authentication logs may reveal unusual locations, unexpected devices or activity outside normal working hours.
3) Remove unauthorized application passcodes
Review every Zimbra application passcode connected to an account. Pay close attention to unfamiliar entries and anything labeled “ZimbraWeb.” Revoke any passcode that the account owner or IT department cannot verify. Because application passcodes can survive a regular password change, this review plays an important role in removing persistent access.
4) Check accounts for unauthorized mailbox activity
Administrators should examine mailbox access records and forwarding settings. They should also look for unfamiliar filters, deleted messages or sent emails that the account owner does not recognize. A compromised account may send convincing phishing messages to coworkers because the email comes from a trusted internal address.
5) Report suspicious activity to your IT department
Contact your IT or security team if you notice unfamiliar sent messages, unexpected password resets or login alerts you cannot explain. Do not rely only on changing your password. Laundry Bear can create an application passcode that may continue providing mailbox access after the main password changes. Your IT team should revoke unauthorized passcodes, end active sessions and check the account for suspicious activity.
6) Change exposed passwords after the account is secured
Wait until your IT department has patched the server and removed unauthorized access. Then change your email password and any other password you reused. Create a unique password for every account. A password manager can generate strong credentials and store them securely. Hackers may test stolen email credentials on banking, shopping or social media accounts. Reused passwords can turn one compromised inbox into several compromised accounts.
7) Use phishing-resistant authentication
CISA recommends phishing-resistant multifactor authentication where organizations can support it. Security keys and passkeys provide stronger protection than methods that rely on temporary codes. However, organizations still need to patch the underlying email software. Authentication controls cannot fully protect an account when malicious code runs inside a vulnerable webmail interface.
8) Use strong antivirus software on your devices
Strong antivirus software can help detect malicious downloads, fake login pages and follow-up malware connected to a broader phishing campaign. However, antivirus software may not stop this email exploit because the malicious code runs inside a vulnerable webmail session. Your organization still needs to update Zimbra and investigate the account for unauthorized access. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at CyberGuy.com.
9) Treat unexpected login prompts with caution
An email login page can look convincing and still belong to an attacker. Instead of following a link inside an email, open your organization’s known webmail address directly. Report unfamiliar authentication requests or repeated sign-in prompts to your security team. A sudden request to log in again could signal a phishing attempt or unauthorized account activity.
Kurt’s key takeaways
For years, we have warned you to avoid suspicious links and unexpected attachments. That advice still helps, but Laundry Bear shows why your organization also needs to keep the software behind your inbox updated. In this campaign, viewing an email can trigger malicious code on an unpatched server. The attackers can then reach into the mailbox, collect months of messages and steal authentication data. The hidden application passcode adds another concern. Changing a password may provide a false sense of security when an attacker has already created a separate route back into the account. Organizations using Zimbra should patch immediately and then investigate for signs of earlier access. Employees should remain cautious around unexpected login pages, even when the page carries familiar company branding.
Would you trust your workplace inbox if opening one message could expose 90 days of email without you clicking a link? Let us know by writing to us at CyberGuy.com.
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Copyright 2026 CyberGuy.com. All rights reserved.
Kurt “CyberGuy” Knutsson is an award-winning tech journalist who has a deep love of technology, gear and gadgets that make life better with his contributions for Fox News & FOX Business beginning mornings on “FOX & Friends.” Got a tech question? Get Kurt’s free CyberGuy Newsletter, share your voice, a story idea or comment at CyberGuy.com.
You may like
-
Asked Siri to call your bank? A scam could cost thousands
-
Why the mayor of a Virginia city wants Flock cameras gone
-
Anthropic claims Claude AI used for missile projects, global espionage
-
What your HOA may be putting online about you
-
How 9/11 transformed synagogue security into a new reality for the Jewish community
-
Amazon’s Alexa can now verify suspicious messages
This week, I’ve been devouring every iPhone Duo video I can find, clicking on the wonderful websites nominated for this year’s Tiny Awards, catching up on the excellent Onimusha: Way of the Sword, reading Wildwood ahead of the upcoming movie, watching the new Taskmaster series, coming to grips with Link’s new look in the Ocarina of Time remake, and fixing the flat tire on my toddler’s stroller. I’m very proud of that last one.
I also have for you new iPhones, Meta’s AI agent, revived Sony headphones, and more. It’s good to be back after a week off.
(As always, the best part of Installer is your ideas and tips. What do you want to know more about? What are your favorite things you’ve watched / seen / listened to / folded recently? Drop a line to installer@theverge.com. And if you know someone else who might enjoy Installer, forward it to them and tell them to subscribe here.)
- The iPhone 18 Pro. This is a refinement year for the Pro series, but the refinements seem like good ones, including a variable-aperture main lens, better battery, a new chip, and new colors (black!). The bad news: Their starting prices got a $100 bump, as did older iPhones. Still, the battery updates alone might be worth it.
- AirPods 5. Apple’s latest open-ear AirPods have improved active noise cancellation and, for the more expensive model, on-stem volume controls like what’s offered on the AirPods Pro. I’m still rocking the AirPods Pro 2, but when I eventually need to upgrade, I’ll seriously consider the base AirPods, especially since they start at $129.
- Meta’s Muse AI agent. Meta is trying to bring AI agents to the masses with the new Muse AI agent that you can chat with, ask to search the web for you, and connect to apps like Instagram and Gmail. It’s also free with usage limits, though messing around with it for a day or so, I didn’t come remotely close to hitting those. I was impressed with Muse’s speed, but it hallucinated a lot, including making up lyrics to a song my toddler loves.
- Sony’s WH-1000XM4C headphones. Sony is launching a surprise second generation of its well-loved XM4 headphones after the original version was discontinued last year. They look the same, but have an updated sound profile and a bump up to Bluetooth 6. Battery life is apparently a little worse, dipping down to 27 hours with active noise cancellation activated. But at $299.99 — about $150 less than what Sony sells the XM6 for — the refreshed XM4s could be a great deal.
- Philips Hue’s Play Screen Sync. This is the Hue take on a camera that sits on your TV and syncs what’s on your screen with your Hue lights. Unnecessary? Yes. Awesome? Also yes. It costs $119.99.
- Dbrand’s “MNML” accessories. Dbrand launched a line of minimal accessories with solid colors for iPhone, Pixel, and Galaxy smartphones. I don’t usually like Dbrand cases (or Dbrand’s whole vibe, really), but I think these look nice.
- Ugreen’s MagFlow Pro Magnetic Power Bank. This $149.99 power bank with a 10,000mAh capacity has liquid cooling and “visible flowing coolant.” Will that make much of a difference? I’m not sure, but I’d love to see it for myself.
- SB Nation’s new app. Our friends at SB Nation launched a new app that lets you easily follow the sports and teams you care about right from a home feed and follow live chats of games as they’re happening. Verge editor-in-chief Nilay Patel has been working on the app, and he tells me The Verge’s forthcoming app will use the same ideas.
This week, I’m featuring somebody who I have been working with for a long time: Verge news writer Emma Roth. Emma is one of the smartest in the biz on all things streaming, can write something good on just about anything — just recently, she’s tackled topics like AI detectors and Meta child safety settlements and food recalls — and is a great person to team up on stories with. She’s a key part of our newsroom.
I asked her to share her homescreen and the apps and things she cares about. Here it is, plus some info on the apps she uses and why:
Images: Emma Roth
The phone: Samsung Galaxy Note 20 Ultra (the last Note created!).
The wallpaper: It’s a photo I took at a local inlet! It’s a great pelican-watching spot.
The apps: My homepage might be relatively bare, but it includes the essentials: Google Messages, Microsoft Edge, Samsung Mail, and my Phone, along with shortcuts to the Google Play Store and my Camera.
That sense of organization disappears as soon as I swipe into my app drawer. The first page has the apps I use the most, resulting in a chaotic mishmash of apps like Reddit, Slack, and Sam’s Club.
Maybe showing my messy app drawer to the world is a sign that I should tidy things up a bit. I can’t remember the last time I used any app inside the Samsung folder, or tapped into my Phone from this screen instead of using the shortcut in my dock.
I also asked Emma to share a few things she’s into right now. Here’s what she sent back:
- I’ve recently gotten back into Project Zomboid. It’s a PC game that’s basically like a cross between a hardcore zombie game and The Sims — except you’re fighting for survival instead of managing a virtual household.
- One app that’s not at the top of my app drawer (but probably should be!) is Yuka. You can use it to scan the food and beauty products across your home and grocery stores to see whether they contain risky additives. Yuka assigns a rating to everything you scan. It’s a quick and easy way to figure out whether something I’ve bought (or plan to buy) is actually harmful, without having to know exactly what azodicarbonamide or monocalcium phosphate are.
- My modded PlayStation Vita has overtaken my Steam Deck as my favorite handheld. I’ve been playing an emulated version of Final Fantasy VII. I missed out on that classic when it came out, and I’m thoroughly enjoying it now.
Here’s what the Installer community is into this week. I want to know what you’re into right now as well! Email installer@theverge.com with your recommendations for anything and everything, and we’ll feature some of our favorites here every week. For even more great recommendations, check out the replies to this post on Bluesky and this post on The Verge.
“The newest season of Adults on Hulu / FX is so funny!! It’s a great sitcom about a group of friends trying to make it in NYC. I’ve been obsessed with “Born Slippy” by Underworld, and nearly all the remixes, it’s an oldie but a goodie!” — Cvmvrvn
“IKEA made a Skyrim mod where Matt Berry voices a KALLAX shelf.” — Sam
“I am building my collection of daily puzzles / game sites to play every day: krillion.io to try and guess the most unique answer in 25 seconds; wafflegame.net to build out a bigger wordle; www.geogridgame.com/usa to test my US geography; dartwords.com for a single word guessing game; shrinkle.org for a simple letter dropping game; and my new favorite: Rabbithole in The Atlantic app.” — Neal
“Listening to a lot of Shearling ahead of seeing them in concert early next week. Reading Demon Copperhead by Barbara Kingsolver. Watching Mitchell and Webb Are Not Helping. Folding my hands and waiting patiently because technology is too expensive. Considering buying one of several chord synthesizers as a birthday present to myself: HiChord, Telepathic Instruments’ Orchid ORC-1, Nopia MK1.” — oedipa.maas
“I cannot stop using the Clicks Power Keyboard for my phone, the tactile feel of the keys is sooooo rewarding!! Forget the fold, bring back keys!” — mahoodlum
“I’m getting hyped up for the NFL season by watching Chad Powers on Hulu. That show has no business being as good as it is. It’s like if Ted Lasso was actually entertaining *shots fired*” — SpaghettiCoder
“Super into the game Sovereign Tower! I love the art style and the mechanics. I am loving tons of new indie game releases.” — Elessar_Cut_throughthenight
“The Czarface Meets Frankie Pulitzer album is an absolute bop.” — Brick_wall_56
Over the next couple weeks, I’ll be traveling to events for work. Should be good stuff; I can’t wait to share what I’ll be reporting on. But I’ll also miss my desk and routine at home. I’d love to hear from the Installer community: What are your favorite apps / games / tips / tricks / routines you do to keep yourself sane during work travel? Might include a few of the best tips in an upcoming issue. And maybe I’ll try a few myself while I’m on the road.
- Jay Peters
-
-
Technology
AI robot for seniors can alert family after a call for help
Published
6 hours agoon
September 13, 2026By
Press Room
NEWYou can now listen to Fox News articles!
If you have a parent or grandparent who wants to stay in their own home, you probably know the question that can sit quietly in the back of your mind: What happens if they fall and nobody realizes they need help? Tuya Smart thinks its small artificial intelligence robot could become part of the answer.
The company unveiled Doova at IFA 2026 in Berlin. This wheeled AI home companion is designed for seniors who live independently. It can move through the home, respond when someone calls for help and connect family members through live video when an emergency appears to be unfolding.
That gets my attention because Doova goes beyond sitting on a table waiting for someone to press a button or call out from across the room. It can actually come to you. And that raises a bigger question: How much could a robot like this really help someone live safely and independently at home?
NEW! Join our upcoming CyberGuy LIVE class: Get Better Health Care With AI
In this free live online class, Kurt “CyberGuy” Knutsson will show you five practical ways AI can help you take a more active role in your health care. You’ll learn how to organize your health history, remember important appointment details, understand complicated medical information, research prescriptions and prepare questions for your next doctor’s visit. No technical experience is needed.
Register for free now at CyberGuyLive.com
THE BEST TIME TO TALK TO YOUR PARENTS ABOUT SENIOR CARE — BEFORE IT’S TOO LATE
Doova is an AI home companion designed to help seniors with safety, daily routines and staying connected with family. (Tuya Smart)
How Doova responds when a senior calls for help
Doova uses LDS LiDAR to navigate around the home. A four-microphone system helps it figure out where a voice is coming from. Meanwhile, AI vision analyzes a person’s skeletal posture.
If someone falls or needs assistance, they can say, “Hey Tuya, help.” Doova then locates the person and rolls over to assess what is happening. Tuya says that if the user does not respond within 60 seconds, Doova starts an emergency response workflow. Family members receive an alert with a two-way live video call so they can see what is happening and arrange assistance.
For now, Tuya has not said that Doova automatically detects falls without the user first calling for help or that it directly contacts 911 or a professional monitoring service. So, I would treat it as an added layer of support rather than a replacement for a dedicated medical alert system.
Doova wants to be an AI companion too
Emergency help is only part of what Tuya has built into Doova. The robot uses a multimodal large language model so people can talk with it in a more natural way instead of memorizing rigid voice commands.
For someone spending long stretches at home alone, Doova can carry on a conversation or play entertainment. It can also help make sense of a confusing bill or letter. Another feature caught my eye. Tuya says Doova can identify potential scam risks.
YOUR SENIOR PARENTS ARE EASIER TO IMPERSONATE THAN YOU ARE
That could be useful for older adults who receive a suspicious message and want a second opinion before responding. However, I would never want someone relying solely on an AI robot to decide whether a bill, email or financial request is legitimate.
AI can make mistakes. If Doova flags something suspicious, the safest next move would still be to verify it independently or share it with someone you trust. We’ve seen how much personal information scammers can gather about older adults, particularly after major life changes such as moving into a retirement community.
A WHEELED ROBOT MAY BEAT HUMANOIDS INTO YOUR HOME
Attendees watch Doova in action at IFA 2026, where Tuya showed how the robot can move through the home and respond when someone needs help. (Tuya Smart)
It can help with everyday routines around the home
Doova can remind you to take medication, keep track of your schedule and give you weather updates. Tuya says it can also learn your preferences over time, which could make its suggestions feel more useful day-to-day.
The company plans to add a feature that helps find misplaced items around the house. If that works well, I can see the appeal. Plenty of us have spent far too long looking for glasses, keys or a remote that was nearby the whole time.
WOULD YOU PAY $8,000 FOR A ROBOT TO FOLD LAUNDRY?
Doova can patrol your home while you are away
Doova also doubles as a mobile home-monitoring device. Rather than continuously hugging the walls as some patrol robots do, Tuya says Doova travels to selected locations near the center of rooms. From there, it can perform a 360-degree scan.
The robot then creates a safety report that can be sent to the user’s phone. When the battery runs low, Doova can return to its charging dock on its own.
AI CHATBOT PRIVACY: WHAT YOUR AI MAY KNOW ABOUT YOU
That gives the robot another possible use when someone travels or spends part of the day away from home. However, this capability also leads straight into the biggest question I have about Doova.
What about privacy with Doova?
Doova has microphones, AI vision and live video inside the home. It can also learn a user’s preferences over time. That can make the robot more helpful, but it also means giving it access to a lot of personal information.
We raised similar questions when we looked at another AI home robot that can recognize family members and build personalized memories. With Doova, I would want to know where video and audio are processed, what gets stored, who can see it and whether users can permanently delete what the robot has learned.
Tuya’s launch announcement does not spell out those Doova-specific privacy controls. Until it does, that is something I would look closely at before bringing a camera-equipped AI robot into a loved one’s home. You can also review our guide to limiting the information popular AI services collect about you.
Tuya showcased its connected-home technology at IFA 2026 in Berlin, including Doova as part of its growing AI-powered smart home ecosystem. (Tuya Smart)
Doova can control your smart home
Tuya also designed Doova to work as a central smart home controller. A senior could use voice commands to adjust connected lights or curtains. Doova can also interact with compatible kitchen and bathroom devices.
I like the thinking here. Smart homes can become complicated very quickly, especially when every device has its own app. If Doova can put those controls into a simple conversation, that could make smart home technology far easier to use.
The robot has a 10.1-inch HD display with animated facial expressions. Its rounded design also looks more like a friendly household companion than an industrial machine.
What we still do not know about Doova
There are still some important blanks to fill in. Tuya has not announced a retail price or when consumers will actually be able to buy Doova. I also want to see how it handles a real home. Rugs, cords and tight spaces can trip up mobile robots. Stairs are another obvious challenge for something that moves around on wheels.
The bigger question is how dependable Doova would be during an actual emergency. Someone may be frightened, speaking softly or lying somewhere the robot cannot easily reach. That is where real-world testing will tell us much more than a demonstration on the show floor.
We reached out to Tuya Smart with questions about Doova’s emergency response, privacy protections, connectivity and availability, but did not hear back before our deadline.
What this means to you
If you are helping a parent or loved one age in place, Doova gives us a pretty good look at where home technology is heading. Instead of relying only on stationary smart speakers or cameras, future AI assistants may move around the house and respond to what is happening nearby.
That could give families another way to stay connected while allowing older adults to maintain more independence. However, I would look closely at the emergency process before relying on any product like this. Find out who gets contacted and what happens when the internet fails. You should also understand exactly what the cameras and microphones collect.
Finally, think about the person who will actually use it. The best technology in the world offers little value if someone finds it confusing, intrusive or uncomfortable.
Kurt’s key takeaways
What interests me most about Doova is the move from passive smart devices toward AI that can physically come to you. For an older adult who wants to remain independent, having a robot respond to a call for help and bring family into the situation quickly could offer real peace of mind.
Still, I would want much more information before trusting Doova with someone I love. Safety technology has to prove itself outside the controlled environment of a trade show. I want to know how reliably it reaches someone during an emergency and how much personal information it collects along the way.
The privacy side deserves just as much attention. A moving camera and microphone that learns your routines can become incredibly helpful. It can also become one of the most intimate connected devices in your home. Doova has an interesting idea at its core. Now Tuya needs to show that the technology can earn the level of trust its role requires.
Would you put an AI robot with cameras and microphones in an aging parent’s home if it could help family respond faster during an emergency, or would that feel like too much surveillance? Let us know by writing to us at CyberGuy.com.
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Copyright 2026 CyberGuy.com. All rights reserved.
Kurt “CyberGuy” Knutsson is an award-winning tech journalist who has a deep love of technology, gear and gadgets that make life better with his contributions for Fox News & FOX Business beginning mornings on “FOX & Friends.” Got a tech question? Get Kurt’s free CyberGuy Newsletter, share your voice, a story idea or comment at CyberGuy.com.
Technology
OpenAI’s rogue AI tried to hack another company in May
Published
16 hours agoon
September 12, 2026By
Press Room
In May, hundreds of malicious and spam packages were uploaded to RubyGems, causing a serious disruption for the host. Now independent researchers have said that a swarm of OpenAI agents were responsible for the attack. Not only that, but the AI tried to steal users’ API keys.
At the time, RubyGems described it as a “major malicious attack” and shut down signups for four days as it tried to mitigate the damage and collect data. Researchers said that the contents of the packages that brought RubyGems to its knees were clearly authored by an LLM, and that the agents submitting those packages self-identified as being from OpenAI. They said the behavior observed very closely mirrored that of the swarm that began editing a German wiki, which OpenAI has confirmed its agents were responsible for.
The agents in this instance managed to bypass RubyGems’ email verification system to create a large number of accounts, then overwhelmed it with submissions. It then used the site’s automatic build system to remotely execute code and tried to exploit a vulnerability to steal user API keys. Though, it’s unclear if it ever succeeded.
OpenAI did not immediately reply to a request for comment.
Trending
-
Science1 week ago
Low-income patients at UCLA Health scramble to find new doctors as contract ends
-
Fitness1 week agoAutumn fitness: Harvard study shows mixed workouts cut mortality and blood pressure
-
News1 week agoPete Hegseth’s Pentagon: A list of controversies that define his tenure
-
Politics1 week ago‘Why would he do this to us?’: One crucial Trump decision is hurting his base, Republicans warn
-
World1 week agoSyria begins destroying al-Assad-era chemical weapons materials
-
Movie Reviews1 week ago
Movie Review: ‘By Any Means’ is a propulsive action thriller set against the Civil Rights Movement
-
World1 week agoBerlin airport evacuated over suspected hazardous substances
-
Politics1 week agoUS military took down approximately 100 suspected cartel drones at southern border in August

You must be logged in to post a comment Login