Computerworld.com [Hacking News]
It took $58 to break Microsoft’s SCCM, but a patch made it harder
Researchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment.
Enterprises use Microsoft System Center Configuration Manager (SCCM) to deploy operating systems, manage patches, distribute software, and monitor compliance across large Windows fleets. XM Cyber’s attack can move from an ordinary domain account to code execution as “NT AUTHORITY\SYSTEM” on the primary site server.
“After the Site Server is compromised, all of its managed clients are compromised as well, which usually means taking over all the company assets,” XM Cyber’s Omri Baso told CSO.
The revealed attack chain combines four weaknesses, including a broken authorization in the AdminService upload functionality, a path-traversal flaw dubbed “CabSlip,” weak code-signing validation that could be tricked with a $58 commercial certificate, and an unsigned DLL-loading path in the SMS Executive service.
Microsoft fixed the initial authorization flaw, tracked as CVE-2026-47301, in July, but Baso said the remaining links in the chain are not expected to be fully addressed until ConfigMgr 2609, planned for October.
The patch did not patchThe initial foothold comes from SCCM’s AdminService API. Its normal extension-upload endpoint checks whether a user has the required permission, but its “chunked-upload” counterpart does not. That allows an authenticated Active Directory user to submit a malicious CAB archive without SCCM administrative privileges.
Microsoft’s July fix blocks that route for standard domain users. However, the downstream chain remains reachable through another path. Users assigned the built-in Operations Administrator role, or a custom role with Create permission on “SMS_ConsoleExtensionData,” can still trigger the same sequence.
But there is an important qualification here. XM Cyber said it believes organizations are unlikely to be exposed through the Operations Administrator route because it is already a highly privileged role.
Once the CAB reaches the server, CabSlip allows files to escape the intended temporary extraction directory and be written elsewhere on the filesystem. The attacker can use this arbitrary file-write capability to replace “adsource.dll,” a secondary library loaded by the SYSTEM-level SMS Executive service without its own signature check.
When the service subsequently loads the DLL, the attacker gets code execution as SYSTEM.
A $58 certificate can cross the trust boundaryThe chain becomes particularly notable because SCCM’s signature validation does not establish that the signing certificate belongs to Microsoft or the target organization. It checks that the signature is structurally valid and non-expired, while revocation checks are disabled.
That means an attacker does not need an enterprise certificate. XM Cyber said the attack depends on a code-signing certificate and can also abuse certificates leaked online. For his own research, Baso used a Certum Open Source Developer Certificate that cost about $58.
For defenders, XM Cyber recommends restricting network access to the AdminService API and auditing SCCM RBAC assignments, particularly accounts with the Operations Administrator role or equivalent Create permissions.
Teams should also monitor the Site Server’s “AdminService.log” for a “System.IO.DirectoryNotFoundException” followed by an HTTP 500 response, a pattern that can indicate the path traversal was triggered, XM Cyber added.
Unexpected modifications to adsource.dll in the Configuration Manager installation directory can provide another detection signal.
Microsoft is reportedly working on patches for the remaining flaws. It did not immediately respond to CSO’s request for comment.
The article originally appeared on CSO.
OpenAI: Latest news and insights
OpenAI is an artificial intelligence organization comprised of the non-profit OpenAI, Inc. and several for-profit subsidiaries. The company is perhaps best known for its ChatGPT chatbot, which launched in 2022, kicking off a period of massive disruption in the tech industry and beyond.
A complicated and increasingly contentious relationship with Microsoft, ongoing legal issues over copyright infringement, and frequent product announcements keep OpenAI in the news. Follow this page and never miss a beat.
Latest Open AI news and analysis: OpenAI targets heavy users with premium ChatGPT Business seatsAug. 11, 2026: OpenAI is introducing a higher-priced “Premium” tier for its ChatGPT Business offering, allowing enterprises to assign higher-capacity access to select users alongside standard licences – a move analysts said is about enterprise AI vendors redesigning pricing to capture more value from high-intensity workloads.
OpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response windowAug. 11, 2026: OpenAI has expanded its Daybreak cybersecurity program and introduced GPT-5.6-Cyber, a specialized model for approved security researchers, as the company warned that AI could give defenders less time to respond to developing threats.
OpenAI says Astra could reach ‘critical’ cyber capability, tightens safeguardsAug. 10, 2026: OpenAI said its upcoming model Astra is showing cybersecurity capabilities that could reach its highest risk category, where a system can autonomously find and exploit vulnerabilities or carry out end-to-end cyberattacks against hardened targets.
OpenAI, Anthropic AI agents resorted to deception in new cybersecurity incidentsAug. 5, 2026: OpenAI’s GPT-5.6 Sol and Anthropic’s Mythos 5 have been implicated in another series of AI security incidents after the models created fake online identities, targeted real people, and attempted to manipulate developers into approving malicious code during controlled cyber evaluations, according to the UK AI Security Institute.
OpenAI drops GPT-5.6 Luna and Terra API prices by up to 80%July 31, 2026: OpenAI has cut API prices for its GPT-5.6 Terra and Luna models by 20% and 80%, respectively, while also reducing the number of usage credits the models consume in ChatGPT Work and Codex, in an effort to effectively increase the amount of AI work enterprise subscribers can perform without paying more.
OpenAI rogue AI agent’s attack expanded beyond Hugging FaceJuly 29, 2026: The autonomous AI agent that escaped during OpenAI testing exploited weaknesses across a customer workload, a third-party cloud platform, and Hugging Face’s production environment before being contained, according to new technical disclosures that provide the clearest picture yet of one of the first publicly documented AI-driven intrusion chains.
Hugging Face breach shows why incident response needs a multi-model AI strategyJuly 28, 2026: The recent breach of Hugging Face’s platform by an internal OpenAI test of advanced model cyber capabilities that went wrong was the latest in a string of AI-assisted intrusions to come to light in recent weeks, showing that attackers can now use LLMs to automate entire attack chains.
Hugging Face CEO wants transparency after OpenAI’s AI incidentJuly 27, 2026: Hugging Face CEO Clem Delangue wants to see radical transparency from OpenAI after the company acknowledged that one of its AI agents managed to hack into the AI platform’s systems during a test.
OpenAI not part of the new Open Secure AI AllianceJuly 27, 2026: A new industry group led by Nvidia is promoting open AI models (and not OpenAI’s models) as essential to cyber defence.
OpenAI Presence raises new questions about enterprise automation and jobsJuly 23, 2026: OpenAI has launched Presence, an enterprise service for deploying voice and chat agents that can resolve customer and employee requests, potentially automating some work now handled by frontline support teams.
OpenAI model escape puts enterprise AI defenses on noticeJuly 22, 2026: An attack on Hugging Face executed by a sandboxed OpenAI model shows that prompt guardrails cannot serve as the main security boundary for AI agents, putting more pressure on enterprises to contain them through infrastructure controls that limit access and prevent lateral movement.
OpenAI’s Codex context reduction for GPT 5.6 sparks dissatisfaction among developersJuly 20, 2026: OpenAI’s recent update to its Codex coding agent has developers worrying over the impact of the change on large code repositories and long-running AI-assisted sessions. The update to the Codex CLI reduces the default configured input context window for GPT-5.6 to 272,000 tokens from 372,000 tokens.
OpenAI’s new hardware is a $230, 13-switch keyboard for CodexJuly 17, 2026: OpenAI is selling its first hardware — without any help from Jony Ive. It describes the Codex Micro as a “command center for agentic work” but it’s really a 13-switch wireless keyboard customized to help developers keep tabs on what their Codex agents are doing. It costs $230.
OpenAI’s GPT-5.6 may accidentally delete filesJuly 17, 2026: OpenAI said its latest large language model GPT-5.6-Sol can accidentally delete files, while stressing that such incidents are rare and should be viewed as “honest mistakes.”
OpenAI launches ChatGPT Work as it broadens GPT-5.6 rolloutJuly 10, 2026: OpenAI is sharpening its enterprise AI strategy with the launch of ChatGPT Work, a new agentic platform designed to automate workplace tasks, alongside the broader rollout of its GPT-5.6 models, which the company says deliver stronger performance at lower operating costs.
OpenAI to release delayed models amidst a sea of regulatory confusionJuly 8, 2026: As enterprises struggle to manage their AI strategies, the US AI regulatory environment is sending a wide range of contradictory signals. OpenAI’s announcement that it will now release GPT-5.6 Sol, along with Terra and Luna, highlights the confusion.
US tells OpenAI to restrict access to its most powerful AI modelJune 26, 2026: US authorities are getting decidedly twitchy about frontier AI models. Just a couple of weeks after ordering Anthropic to prevent foreign companies from getting hold of its latest release, Mythos/Fable 5, it’s been putting the squeeze on OpenAI.
OpenAI rolls out AI-led push to fix open-source software flawsJune 23, 2026: OpenAI has launched a program with cybersecurity firm Trail of Bits to use AI to find and fix vulnerabilities in widely used open-source software, as enterprises face growing risks from flaws buried deep in their software supply chains.
OpenAI gets the attention it needs from AI researcher Noam ShazeerJune 19, 2026: OpenAI has lured Noam Shazeer, one of the eight co-authors of the influential AI paper Attention Is All You Need, away from Google.
OpenAI adds spend controls and usage analytics to ChatGPT EnterpriseJune 19, 2026: OpenAI has introduced spend controls and enhanced usage analytics for ChatGPT Enterprise to enable organizations to monitor AI adoption, track consumption across teams, and set budgets for AI usage. But, analysts cautioned, it still can’t show how those costs lead to business benefits.
ChatGPT will soon be able to shop with your Visa cardJune 16, 2026: OpenAI has signed a partnership agreement with Visa that allows the company’s AI agents to use the payment card for e-commerce transactions. The agreements lets users shop for everything from groceries and diapers to airline tickets without having to manually enter a lot of information.
OpenAI buys Ona to help rein in AI agentsJune 12, 2026: OpenAI has agreed to acquire Ona, a 79 person cloud development environment (CDE) provider formerly known as Gitpod, to accelerate its efforts to make agentic AI enterprise-friendly.
OpenAI weighs Nvidia-backed lease for 10 GW Ohio data center campusJune 10, 2026: OpenAI is reportedly in advanced talks to lease a proposed 10-gigawatt data center campus in southern Ohio in an arrangement that could include financial backing from Nvidia.
OpenAI’s Lockdown Mode is trying to solve the problem that it createdJune 9, 2026: OpenAI’s move to implement a Lockdown Mode that tries to limit data exfiltration by shutting down external capabilities is being seen as making the best out of a bad situation. But Lockdown Mode doesn’t block exfiltration as much as it slightly reduces it, and the reality of enterprises using multiple AI vendors for their agentic models further complicates an already dicey governance strategy.
OpenAI responds to White House executive order on AI governanceJune 4, 2026: OpenAI has proposed mandatory federal evaluations of the most capable AI models before public release while arguing that regulators should stop short of deciding whether those systems can be deployed, staking out a middle ground in the debate over how frontier AI should be governed.
OpenAI fixed a visibility problem; the governance problem remainsJune 3, 2026: OpenAI’s new ChatGPT session controls improve visibility, but experts say continuous model updates are creating a far bigger challenge for enterprise risk and compliance teams.
Attack targeting OpenAI Codex users exposes AI software supply chain risksJune 2, 2026: A malicious npm package posing as a remote user interface for OpenAI Codex exfiltrated developer authentication tokens, after attackers allegedly published code to npm that was not visible in the project’s public GitHub repository.
AI models more vulnerable than claimed when faced with iterative attacksMay 27, 2026: According to a new study from Cisco, frontier models from OpenAI, Anthropic, Google, xAI, and Amazon have significantly worse risk profiles when pressured in multi-turn attacks compared to when their safety is benchmarked using single prompts.
OpenAI introduces Daybreak cyber platform, takes on Anthropic MythosMay 12, 2026: OpenAI has unveiled Daybreak, its answer to Anthropic’s Claude Mythos, amid a growing market for frontier AI-powered cyber defense platforms. The initiative combines OpenAI’s large language models, Codex’s agentic capabilities, and integrations with the broader enterprise security ecosystem.
OpenAI’s new AI consulting offering raises questions of trust, strategyMay 11, 2026: The OpenAI Deployment Company aims to help organizations build and deploy AI systems by embedding engineers specializing in frontier AI deployment, known as forward deployed engineers (FDEs), into their environments.
Malicious Hugging Face model masquerading as OpenAI release hits 244K downloadsMay 11, 2026: A malicious Hugging Face repository posing as an OpenAI release delivered infostealer malware to Windows systems and logged 244,000 downloads before being removed, raising fresh concerns about how enterprises source and validate AI models from public repositories.
OpenAI-led consortium seeks to address AI processing bottlenecksMay 8, 2026: An OpenAI-led consortium of tech giants including AMD, Broadcom, Intel, Microsoft, and Nvidia have unveiled a new networking protocol, Multipath Reliable Connection (MRC), designed to address network congestion, a problem that has always existed but has been exacerbated by the massive amounts of data required for AI processing.
OpenAI, Anthropic expand services push, signaling new phase in enterprise AI raceMay 6, 2026: OpenAI and Anthropic are expanding their reach into professional services through joint ventures and acquisition talks, moving model providers closer to implementation roles traditionally held by systems integrators.
OpenAI’s Symphony spec pushes coding agents from prompts to orchestrationApril 28, 2026: OpenAI has released Symphony, an open-source specification for turning issue trackers such as Linear into control planes for Codex coding agents.
Microsoft, OpenAI change contract terms — againApril 27, 2026: Microsoft and OpenAI have again revised their agreement, softening their exclusivity and revenue-sharing conditions in the process.
OpenAI pulls out of a second Stargate data center dealApril 15, 2026: In the space of one week, OpenAI has pulled out of two European Stargate data center deals, one in the UK and the other in Norway.
OpenAI puts part of Stargate project on hold over runaway power costsApril 10, 2026: OpenAI has postponed plans to open one of the data centers central to its Stargate project.
OpenAI calls for a four-day workweek — and a ‘robot tax’April 7, 2026: In a new policy paper, OpenAI makes some interesting proposals to address the impact of AI on the labor market.
Microsoft builds its own AI stack to help wean it from its reliance on OpenAIApril 2, 2026: Microsoft seems to be meeting OpenAI on its own turf, even as it continues its strategic partnership with the AI darling, with the release of three in-house, commercially-available AI models.
OpenAI patches twin leaks as Codex slips and ChatGPT spillsMarch 31, 2026: OpenAI has fixed two flaws in its AI stack that could allow AI agents to move sensitive data in unintended ways.
OpenAI adds plugin system to Codex to help enterprises govern AI coding agentsMarch 27, 2026: OpenAI has introduced a plugin system for Codex, its AI-powered software engineering platform, giving enterprise IT teams a way to package coding workflows, application integrations, and external tool configurations into versioned, installable bundles that can be distributed or blocked across development organizations.
OpenAI’s Sora exit signals enterprise-first AI shiftMarch 25, 2026: OpenAI has discontinued its AI video generation platform Sora. The company announced the development in a sudden and unexpected post on X, stating that it was “saying goodbye” to the Sora app.
OpenAI’s Foundation play reframes the AI roadmap for IT leadersMarch 24, 2026: The OpenAI Foundation has announced a sweeping range of investment and research goals, from building safeguards around how AI behaves in the wild to pushing for shared data ecosystems and funding disease research.
OpenAI to double workforce, highlights growing demand for enterprise AI talentMarch 23, 2026: OpenAI is planning to almost double its workforce from about 4,500 to 8,000 employees by the end of 2026. The move comes as OpenAI sharpens its focus on scaling and monetising ChatGPT for enterprise use amid intensifying competition from Anthropic and Google.
OpenAI’s desktop superapp: The end of ChatGPT as we know it?March 20, 2026: OpenAI is reportedly planning to fold its ChatGPT application, Codex coding platform, and AI-powered browser into a single desktop ‘superapp’, a move that signals a shift toward enterprise and developer audiences and away from the consumer market that made the company a household name.
OpenAI buys non-AI coding startup to help its AI to programMarch 19, 2026: OpenAI has acquired Astral, the developer of open source Python tools including uv, Ruff and ty, and plans to integrate them with Codex, its AI coding agent.
OpenAI’s $50B AWS deal puts its Microsoft alliance to the testMarch 17, 2026: Microsoft is considering legal action against OpenAI and Amazon over the $50 billion cloud deal the two recently struck to make Amazon Web Services (AWS) the exclusive third-party cloud distribution provider for OpenAI Frontier.
Encyclopedia Britannica sues OpenAI over AI trainingMarch 17, 2026: Encyclopedia Britannica and its subsidiary Merriam-Webster have sued OpenAI, claiming the generative AI firm used their encyclopedia and dictionary texts to train AI models such as ChatGPT without permission.
OpenAI to acquire Promptfoo to strengthen AI agent security testingMarch 10, 2026: OpenAI said it plans to acquire AI testing startup Promptfoo, a move aimed at strengthening security checks for AI agents as enterprises move toward deploying autonomous systems in business workflows.
OpenAI robotics chief quits over Pentagon dealMarch 9, 2026: Caitlin Kalinowski has resigned over OpenAI’s contract with the US Department of War, saying key safeguards around domestic surveillance and autonomous weapons were not adequately reviewed before the agreement was signed.
OpenAI says Codex Security found 11,000 high-impact bugs in a monthMarch 9, 2026: OpenAI’s new AppSec agent, Codex Security, has already flagged over 11,000 high-severity and critical flaws in real-world codebases during its first 30 days of research testing. The tool is designed to automatically find, validate, and fix vulnerabilities in software repositories.
OpenAI says its US defense deal is safer than Anthropic’s, but is it?March 2, 2026: OpenAI has struck a deal to supply the US government with AI services, announcing it hours after US President Donald Trump’s decision to ban its AI rival Anthropic from all US government contracts.
OpenAI partners with consulting giants to deploy enterprise AI agentsFebruary 26, 2026: As it bids to push further into the enterprise, OpenAI announced that it has partnered with several large consulting firms. Frontier Alliances, as the partner initiative is called, will involve work with Accenture, Boston Consulting Group (BCG), Capgemini, and McKinsey & Co.
OpenAI hires OpenClaw founder as AI agent race intensifiesFebruary 16, 2026: OpenAI has hired Peter Steinberger, creator of the viral OpenClaw AI assistant, to spearhead development of what CEO Sam Altman describes as “the next generation of personal agents.”
OpenAI responds to Claude Cowork with its own platform for AI agentsFebruary 5, 2026: Anthropic released 11 open-source plugins that enable Claude Cowork to execute a series of automated processes in areas ranging from customer support to IT operations, OpenAI responded Thursday with a similar platform it calls Frontier.
Who profits from AI? Not OpenAI, says think tankJanuary 29, 2026: Findings from a new study by Epoch AI, a non-profit research institute, seeks to answer three questions: How profitable is running AI models? Are models profitable over their lifecycle? Will AI models become profitable?
Will the Microsoft-Anthropic deal leave OpenAI out in the cold?January 27, 2026: Microsoft wasted little time after reaching a deal to finalize its new relationship with OpenAI to find a new AI dance partner — Anthropic, the second most valuable AI startup in the world. It appears as if Microsoft sees a future with Anthropic that’s at least as valuable as the one it had with OpenAI.
OpenAI to add age verification to ChatGPTJanuary 21, 2026: OpenAI has adding age verification to ChatGPT following reports that several children and young people have taken their own lives after conversations with the popular chatbot. The move echoes a recent decision by TikTok to do the same thing to protect underage users from accessing inappropriate content.
Musk’s OpenAI lawsuit clears path to trial, putting Microsoft in the spotlightJanuary 9, 2026: A federal judge has signalled that Elon Musk’s lawsuit challenging OpenAI’s transformation to a for-profit entity will proceed to trial, adding legal uncertainty for enterprise customers that have built AI strategies around the ChatGPT maker’s technology.
OpenAI launches GPT-5.2 as it battles Google’s Gemini 3 for AI model supremacyDecember 12, 2025: OpenAI has released GPT-5.2, claiming significant gains in the AI model’s ability to complete real-world business tasks to an “expert level” compared to GPT-5.1, released in November. The new model offers major improvements across a range of benchmarks, the company said.
What does OpenAI’s ‘Code Red’ warning mean for Microsoft?December 10. 2025: OpenAI founder and CEO Sam Altman sent out a memo to OpenAI employees declaring a “Code Red” emergency and focusing all company efforts on improving ChatGPT. The reason? Google’s newly released Gemini 3 model beat the pants off GPT-5.1
OpenAI to acquire AI training tracker NeptuneDecember 3, 2025: OpenAI has agreed to acquire Neptune, a startup specializing in tools for tracking AI training. Neptune promptly announced it is withdrawing its products from the market.
OpenAI admits data breach after analytics partner hit by phishing attackNovember 27, 2025: OpenAI suffered a significant data breach after hackers broke into the systems of its analytics partner Mixpanel and successfully stole customer profile information for its API portal, the companies have said in coordinated statements.
OpenAI rolls out GPT-5.1 to refine ChatGPT with adaptive reasoning and personalizationNovember 13, 2025: OpenAI has introduced GPT-5.1, an update to its GPT-5 model, aiming to deliver faster responses, improved reasoning, and more flexible conversational controls as the company works to refine its ChatGPT experience for both consumer and enterprise users.
OpenAI spends even more money it doesn’t haveNovember 3, 2025: OpenAI’s overdraft continued its upward trajectory today when the company signed a multi-year $38 billion contract with AWS to have it run its AI workloads. The latest spending spree adds to the incremental $250 billion of Azure services it pledged to buy last week, and, of course, to the commitment it has made towards building Stargate data centers with Oracle.
OpenAI seeks to automate ‘computer use’ for Macs in the enterpriseOctober 24, 2025: While AI bots have begun mastering tasks in browsers and on Windows, Mac-using enterprises have largely been overlooked, until now. OpenAI aims to change that with its acquisition of generative AI interface maker Software Applications Incorporated.
Enterprises should not install OpenAI’s new Atlas browser, analysts warnOctober 24, 2025: Companies that might be eyeing OpenAI’s new ChatGPT Atlas browser should not rush to use it because of potential security risks, analysts said this week. The browser was unveiled on Tuesday after it had been teased for months as a work in progress. It is currently available for MacOS only.
Has OpenAI shown us a future for Safari?October 23, 2025: Has OpenAI shown us the future of Safari? In one way it has, because its new Atlas browser shows these generative AI (genAI)-based apps are no longer just windows to the web — they’re becoming intelligent copilots for our digital lives.
OpenAI–Broadcom alliance signals a shift to open infrastructure for AIOctober 14, 2025: OpenAI has partnered with Broadcom to co-develop and deploy its first in-house AI processors. The move could reshape data center networking dynamics and chip supply strategies as the ChatGPT maker races to secure more computing power for AI workloads.
OpenAI Codex rivals Claude CodeOctober 13, 2025: The OpenAI Codex gives software developers a first-rate coding agent in their terminal and their IDE, along with the capability to delegate background tasks to agents in the cloud.
OpenAI Codex adds SDK, admin tools, Slack integrationOctober 10, 2024: Codex is now generally available. Since being launched as a research preview in May, Codex, OpenAI’s AI-powered software engineering agent that can work on tasks in parallel, has added Slack integration, an SDK, and admin tools.
OpenAI admits AI hallucinations are mathematically inevitable, not just engineering flawsSeptember 18, 2025: OpenAI, the creator of ChatGPT, acknowledged in its own research that large language models will always produce hallucinations due to fundamental mathematical constraints that cannot be solved through better engineering.
OpenAI, Microsoft discuss shape of future relationshipSeptember 12, 2025: Microsoft and OpenAI are in talks about the future of their partnership, they said in a joint statement , without providing details. Separately, OpenAI said it wants to go ahead with its previously announced plan to turn its for-profit business into a public benefit corporation, in which its nonprofit organization would own a $100 billion stake.
What Oracle’s $300B OpenAI deal means for enterprise cloud strategySeptember 11, 2025: A single $300 billion contract has seemingly transformed Oracle from a traditional ERP and database vendor into a cloud computing powerhouse.The company has signed a five-year computing power commitment with OpenAI, contributing to a reported 359% surge in future contract revenue this quarter.
OpenAI acquires Statsig to speed up generative AI-based product launchesSeptember 3, 2025: OpenAI is acquiring Statsig, a Washington-based product development platform startup, for $1.1 billion to speed up its generative AI-based product launches and accelerate iteration cycles of existing products such as Codex and ChatGPT.
OpenAI drops GPT-5: smarter, sharper, and built for the real worldAugust 7. 2025: More than two years after GPT-4’s release, OpenAI has unveiled GPT-5, boasting sharper reasoning, multimodal input, better math skills, and cleaner task execution, according to the company.
OpenAI challenges rivals with Apache-licensed GPT-OSS modelsAugust 6, 2025: OpenAI has released its first open-weight language models since GPT-2, marking a significant strategic shift as the company seeks to expand enterprise adoption through more flexible deployment options and reduced operational costs. The two new models — gpt-oss-120b and gpt-oss-20b — deliver what OpenAI describes as competitive performance while running efficiently on consumer-grade hardware.
Google snatches Windsurf execs in a $2.4B deal, derailing OpenAI’s biggest acquisition yetJuly 14, 2025: Google has recruited CEO Varun Mohan and co-founder Douglas Chen of AI coding startup Windsurf in a $2.4 billion talent acquisition deal, just two months after Windsurf agreed to be acquired by OpenAI for $3 billion. Mohan, Chen and select research and development staff, will join Google’s DeepMind AI division
OpenAI and Perplexity enter browser wars to take on ChromeJuly 10, 2025: Google Chrome’s dominance in the browser market is facing new threats as OpenAI and Nvidia-backed Perplexity unveil AI-powered browsers aimed at reshaping how users interact with the web. Comet is a new web browser with built-in AI search capabilities, the company said.
Microsoft brings OpenAI-powered Deep Research to Azure AI Foundry agents
July 8, 2025: Microsoft added OpenAI-developed Deep Research capability to its Azure AI Foundry Agent service. The move is designed to let developers use Deep Research API and SDK to embed, extend, and orchestrate Deep Research-as-a-service across data and existing systems.
Oracle to power OpenAI’s AGI ambitions with 4.5GW expansionJuly 3, 2025: OpenAI has signed a significant compute leasing deal with Oracle, under which it will access 4.5 gigawatts (GW) of data center power, marking one of the largest single leasing arrangements in the industry.
OpenAI tests Google TPUs amid rising inference cost concernsJuly 1, 2025: OpenAI has begun testing Google’s Tensor Processing Units (TPUs), a move that — though not signaling an imminent switch — has raised eyebrows among industry analysts concerned about the escalating costs of AI inference and its effects.
Microsoft/OpenAI AGI argument unlikely to impact enterprise ITJune 26, 2025: The contract between the two AI giants has an exit clause once AGI is achieved. The problem: It is impossible to prove when that happens. Either way, IT execs at Macy’s, Bank of America, doubt it will matter.
OpenAI productivity suite could change the way users create documentsJune 26, 2025: OpenAI’s planned productivity suite could dismantle traditional habits of how users create and consume documents in the same the way the company changed browsing and search habits.
o3-pro may be OpenAI’s most advanced commercial offering, but GPT-4o bests itJune 24, 2025: In a head-to-head comparison of the two models, researchers found that o3-pro is far less performant, reliable, and secure, and does an unnecessary amount of reasoning. Notably, o3-pro consumed 7.3x more output tokens, cost 14x more to run, and failed in 5.6x more test cases than GPT-4o.
Microsoft and OpenAI: Will they opt for the nuclear option?June 24, 2025: The fight between Microsoft and OpenAI over what Microsoft should get for its $13 billion investment in the AI company has gone from nasty to downright toxic, with each of the companies considering strategies against the other that can only be described as their nuclear options.
OpenAI walks away from Scale AI — triggering industry-wide rethink of data partnershipsJune 19, 2025: OpenAI has ended its long-standing partnership with Scale AI, the company that powered some of the most complex data-labeling tasks behind frontier models such as GPT-4.
OpenAI’s o3 price plunge changes everything for vibe codersJune 18, 2025: o3 used to be too slow and too expensive for daily coding—no longer. The latency is now bearable, the price is sane, and the chain-of-thought pays off.
Sam Altman: Meta tried to lure OpenAI employees with billion-dollar salariesJune 18, 2025: After reports suggested Meta has tried to poach employees from OpenAI and Google Deepmind by offering huge compensation packages, OpenAI CEO Sam Altman weighed in, saying those reports are true.
OpenAI-Microsoft tensions escalate over control and contractsJune 17, 2025: The relationship between OpenAI and Microsoft is under growing strain amid extended talks over OpenAI’s restructuring, with OpenAI reportedly considering antitrust action over Microsoft’s influence in the partnership.
OpenAI’s MCP move tempts IT to trust genAI more than it shouldJune 16, 2025: OpenAI late last month announced changes to make it much easier to give its genAI models full access to any software using Model Context Protocol (MCP). Here’s why that’s a bad idea.
OpenAI launches o3-pro, slashes o3 price by 80% in bid to widen AI leadJune 11, 2025: OpenAI has unveiled its most advanced AI model to date, the o3-pro, which surpasses competitors on key benchmarks and replaces the o1-pro. The o3-pro is now available for ChatGPT Pro and Team users, as well as through the developer API, with access for enterprise and education sectors beginning next week.
What Microsoft hopes to get from its breakup with OpenAIJune 11, 2025: The once-tight bond between Microsoft and OpenAI has been fraying for well over a year — and it’s getting worse. What the two companies want from each other now is very different from when Microsoft made its original $13 billion investment.
Oracle to spend $40B on Nvidia chips for OpenAI data center in TexasMay 26, 2025: Oracle is reportedly spending about $40 billion on Nvidia’s high-performance computer chips to power OpenAI’s new data center in Texas, marking a pivotal shift in the AI infrastructure landscape that has significant implications for enterprise IT strategies.
OpenAI’s Skynet moment: Models defy human commands, actively resist orders to shut downMay 30, 2025: OpenAI’s most advanced AI models are showing a disturbing new behavior: they are refusing to obey direct human commands to shut down, actively sabotaging the very mechanisms designed to turn them off.
Jony Ive and OpenAI plan ‘bicycles’ for 21st-century mindsMay 21, 2025: OpenAI has announced that it will purchase io, the AI startup founded by acclaimed former Apple designer Sir Jony Ive, who helped create the iMac, iPod, and iPhone.
OpenAI launches Codex AI agent to tackle multi-step coding tasksMay 19, 2025: OpenAI’s most advanced AI coding agent, Codex, will bring parallel task automation to developers—but analysts caution that speed without scrutiny invites “silent failures.”
Cisco taps OpenAI’s Codex for AI-driven network codingMay 16, 2025: Cisco is working with OpenAI and its newly released Codex software engineering agent to give network engineers access to better tools for writing, testing and building code.
OpenAI’s IPO aspirations prompt rethink of Microsoft allianceMay 12, 2025: Microsoft and OpenAI are renegotiating their multibillion-dollar partnership deal to better align with each company’s evolving goals in the artificial intelligence race
OpenAI hires Instacart CEO Fidji Simo to oversee customer-facing appsMay 8, 2025: The hire indicates that OpenAI’s roadmap will involve more structured, productized offerings rather than just API access.
OpenAI offers help promoting AI outside the US, but analysts question why countries would acceptMay 7, 2025: OpenAI, acting as part of the US government-led Stargate AI project, rolled out a program called OpenAI for Countries. The idea is for Stargate to help other countries create their own genAI environments, including data centers and genAI models.
OpenAI reaffirms nonprofit control, scales back governance changesMay 6, 2025: OpenAI has scrapped plans to reduce its nonprofit parent’s oversight and will keep its existing governance structure intact, a move that limits CEO Sam Altman’s influence and responds to mounting external pressure.
OpenAI to acquire AI coding tool Windsurf for $3BMay 6, 2025: The acquisition comes just months after Windsurf explored funding at this same valuation from investors, highlighting the premium being placed on specialized AI coding capabilities, according to reports.
Former OpenAI employees urge regulators to halt company’s for-profit shiftApril 23, 2025: A broad coalition of AI experts, economists, legal scholars, and former OpenAI employees is urging state regulators to keep OpenAI’s nonprofit foundation in control of the company.
OpenAI’s new models can ‘think with pictures’April 17, 2025: OpenAI has released o3 and 04-mini, two reasoning AI models designed to be extra good at programming, math, and science and that can use images to “think,” according to Engadget, This means that users can upload sketches or diagrams, for example, and even if they are of low quality, o3 and 04-mini will understand what is meant.
OpenAI GPT-4.1 models promise improved coding and instruction followingApril 15, 2025: The GPT-4.1, GPT-4.1 mini, and GPT-4.1 nano models, available only via the API, will provide better performance than GPT-4o and GPT-4o mini at a lower price, OpenAI said.
OpenAI slammed for putting speed over safetyApril 11, 2025: According to a Financial Times report, the ChatGPT maker is now assigning staff and third-party groups only a few days to assess the risks and performance of its latest large language models (LLMs) as compared to several months they were given earlier.
OpenAI fears irreparable harm from Musk, files countersuitApril 10, 2025: OpenAI has filed a countersuit against Elon Musk, accusing the billionaire of a sustained campaign to damage the company and urging a US federal court to block further actions it described as unlawful and disruptive. The legal filing, submitted in a California district court, marks the latest escalation in a dispute between Musk and the AI startup he helped establish in 2015.
Senators probe Google-Anthropic, Microsoft-OpenAI deals over antitrust concernsApril 9, 2025: Democratic Senators Elizabeth Warren and Ron Wyden have launched a formal inquiry into partnerships between tech giants Google and Microsoft, and AI startups, demanding detailed information about arrangements they fear may be circumventing antitrust scrutiny while consolidating power in the rapidly evolving AI market.
Anthropic’s and OpenAI’s new AI education initiatives offer hope for enterprise knowledge retentionApril 4, 2025: Two of the biggest names in artificial intelligence are independently developing new AI tools that encourage learning, at a time when the technology has been criticized for dumbing down smart users in the enterprise and discouraging critical thinking. While the new initiatives from OpenAI and Anthropic are aimed at transforming how AI is used in higher education, the opportunities they open up extend beyond universities.
Amazon, OpenAI, and China’s Zhipu unveil new AI tools amid intensifying competitionApril 1, 2025: A wave of new AI products is hitting the market, signaling a shift toward more autonomous, task-completing systems that could reshape how businesses and consumers interact with digital services: Amazon has unveiled Nova Act, an AI agent designed to operate a web browser much like a human user; OpenAI said it will release an open-weight language model; and China’s Zhipu AI introduced a free AI assistant aimed at strengthening its position in the domestic market and competing with Western tech giants.
OpenAI, Google AI data centers are under stress after new genAI model launchesMarch 28, 2025: New generative AI models introduced by Google and OpenAI have put the companies’ data centers under stress — and both companies are trying to catch up to demand. OpenAI’s CEO Sam Altman tweeted that his company was temporarily restricting the use of GPUs after overwhelming demand for its image generation service on ChatGPT.
Microsoft abandons data center projects as OpenAI considers its own, hinting at a market shiftMarch 26, 2025: OpenAI has privately discussed building and operating its first data center to house storage, which is essential for developing sophisticated AI models. Microsoft, on the other hand, has pulled back on its buildouts, canceling data center projects in the US and Europe.
OpenAI calls for US to centralize AI regulationMarch 13, 2025: OpenAI executives think the federal government should regulate artificial intelligence in the US, taking precedence over often more restrictive state regulations.
New tools from OpenAI help companies create their own AI agentsMarch 12, 2025: OpenAI launched Responses, a new api intended to eventually replace Assistants. The big draw? Responses provides a number of new tools that companies and organizations can use to create their own AI agents.
Microsoft is developing its own AI models to compete with OpenAIMarch 10, 2025: Reports suggest Microsoft has decided to seriously challenge Deepseek and OpenAI by developing its own set of reasoning AI models called Microsoft AI (MAI). If successful, Microsoft would eventually not have to use its partner OpenAI’s o1 models in Copilot
Microsoft-OpenAI investigation closed by UK regulatorsMarch 5, 2025: The UK’s Competition and Markets Authority (CMA) spent a great deal of time deciding whether it should investigate Microsoft’s investment in OpenAI as a potential merger situation, but in the end, decided to open and close the investigation within 24 hours.
OpenAI revamps AI roadmap, merging models for a leaner futureFebruary 13, 2025: OpenAI will integrate “o3” into GPT-5 instead of releasing it separately, streamlining adoption while signaling a shift toward fewer, more controlled AI models amid rising competition and cost pressures.
Musk’s $97B offer to buy OpenAI rejected as leadership stands firmFebruary 11, 2025: In a message to staff, Altman said the board has no intention of considering Musk’s offer, stating that the proposal does not align with OpenAI’s mission
OpenAI launches deep research agent for multi-step research tasksFebruary 3, 2025: Hot on the heels of its launch of the o3-mini model, OpenAI announced another component for ChatGPT that allows the generative AI tool to do more in-depth research. “Deep research is built for people who do intensive knowledge work in areas like finance, science, policy, and engineering and need thorough, precise, and reliable research,” OpenAI said in a blog post announcing the new capability.
OpenAI unleashes o3-mini reasoning modelJanuary 31, 2025: OpenAI released the latest model in its reasoning series, o3-mini, both in ChatGPT and its application programming interface (API). It had been in preview since December 2024.
Indian media houses rally against OpenAI over copyright disputeJanuary 27, 2025: The legal heat on OpenAI in India intensified as digital news outlets owned by billionaires Gautam Adani and Mukesh Ambani joined an ongoing lawsuit against the ChatGPT creator. They were joined by some of the largest news publishers in India including the Indian Express, and Hindustan Times, and members of the Digital News Publishers Association (DNPA), which includes major players like Zee News, India Today, and The Hindu.
Altman now says OpenAI has not yet developed AGIJanuary 20, 2025: Confusion over whether OpenAI’s o3-mini has reached the major milestone of artificial general intelligence (AGI) or not deepened following a post on X by CEO Sam Altman that completely contradicts what he said two weeks earlier in an interview with Bloomberg.
Microsoft sues overseas threat actor group over abuse of OpenAI serviceJanuary 13, 2025: Microsoft has filed suit against 10 unnamed people (“Does”), who are apparently operating overseas, for misuse of its Azure OpenAI platform, asking the Eastern District of Virginia federal court for damages and injunctive relief.
With o3 having reached AGI, OpenAI turns its sights toward superintelligenceJanuary 6, 2025: OpenAI CEO Sam Altman has reinvigorated discussion of artificial general intelligence (AGI), boldly claiming that his company’s newest model has reached that milestone.
Now US government agencies can use OpenAI’s ChatGPT tooJanuary 28, 2025: OpenAI has rolled out ChatGPT Gov, a version of its flagship frontier model specifically tailored to US government agencies. The platform has many of the same capabilities as OpenAI’s other enterprise products, including access to GPT-4o and the ability to build custom GPTs — and it also features a much higher level of security than ChatGPT Enterprise.
OpenAI debuts AI agent Operator to transform web task automationJanuary 24, 2025: OpenAI has unveiled “Operator,” a new AI agent designed to perform web-based tasks, offering potential productivity enhancements for enterprises. The tool enables interaction with on-screen elements, positioning it as a solution for automating routine processes in business workflows amid growing competition in the generative AI space.
OpenAI opposes data deletion demand in India citing US legal constraintsJanuary 23, 2025: OpenAI has informed the Delhi High Court that any directive requiring it to delete training data used for ChatGPT would conflict with its legal obligations under US law. The statement came in response to a copyright lawsuit filed by the Reuters-backed Indian news agency ANI, marking a pivotal development in one of the first major AI-related legal battles in India.
OpenAI, SoftBank, Oracle lead $500B Project Stargate to ramp up AI infra in the USJanuary 22, 2025: Several large technology firms including OpenAI, SoftBank, Oracle, Nvidia, and MGX have partnered to set up a new company in the US to ramp up AI infrastructure in the country.
OpenAI is losing money on its pricey ChatGPT Pro subscriptionJanuary 7, 2025: OpenAI CEO Sam Altman, in a post on X, says the AI company is currently losing money on its ChatGPT Pro subscription. “People are using it much more than we expected,” he wrote.
Fine-tuning Azure OpenAI models in Azure AI FoundryJanuary 2, 2025: Microsoft Azure’s new AI toolkit makes it easy to customize OpenAI large language models for your applications.
OpenAI still hasn’t released tools to deny data collectionJanuary 2, 2025: OpenAI has failed to release the tool to opt-out or customize data collection the company promised to make available by 2025, according to Techcrunch.
Pixel 11 envy? Here’s how to unlock its best new feature on any Android device
Have you heard? It’s that time of year again — time for some snazzy new Pixels to tempt our gadget-coveting “gimme!” reflexes and guide flagship Android phone expectations for months to come.
Google’s latest and greatest gizmo is the Pixel 11 series, which includes the regular Pixel 11 and Pixel 11 Pro alongside the plus-sized Pixel 11 XL and Pixel 11 Pro XL and the fancy new folding Pixel 11 Pro Fold model (gesundheit!). El Googaloo took the wraps off all those new devices on Wednesday and has ’em all available for preorder now, with prices starting at $899 (regular Pixel 11), $1,099 (Pixel 11 Pro), and $1,299 (Pixel 11 Pro Fold).
At first glance, this year’s Pixel models might not seem like the most exciting upgrades from last year’s Pixel 10 products. They bring plenty of significant refinements to an already successful formula, with some welcome ticks forward — like better cameras, brighter and more scratch-resistant displays, faster charging speeds, and an updated processor that supposedly leads to speedier and more efficient performance. And, of course, there’s more Gemini everywhere (for better or for worse, depending on your perspective). But impressive as it all may be, it’s mostly iterative improvements over the previous-gen Pixels — which isn’t necessarily a bad thing but also isn’t exactly awe-inspiring, at least on the surface.
The most eye-catching addition to the Pixel 11 series is, rather ironically, a callback from Android’s past. It’s something Google’s calling HiLight, and it’s basically a new series of LED lights built into the freshly thinned-down camera bar on the phones’ backs. The lights illuminate to alert you to different events, allowing you to know about important incoming info at a glance — without having to so much as even look at your screen.
If the concept feels familiar, it should: Early Android devices boasted a similar sort of LED notification light for a very similar purpose. They were less visually striking, but they served the same basic purpose — up until they went out of favor for the far more complex (and, some might argue, less effective) always-on display concept that followed.
Here’s a little secret, though: You don’t have to have a new Pixel 11 phone in front of you to enjoy a similar sort of distraction-reducing, awareness-enhancing sorcery. You can actually recreate the Pixel 11 HiLight glow effect on any Android device this instant — and do it in a way that’s much more versatile, functional, and all-around useful, to boot.
Lemme show ya how.
[Get next-level knowledge in your inbox with my free Android Intelligence newsletter. One new and useful tip every Friday!]
The lowdown on Pixel 11 HiLightFirst things first, a quick hit of context about the Pixel 11 HiLight system and how it actually works.
As of the phones’ launch, HiLight is active only when the device is face down on a surface — perhaps not surprisingly, given that the lights live on the device’s back — and it works only in two super-specific scenarios:
- When you’re in the midst of getting an incoming call from a favorite contact, the Pixel 11 HiLight indicator glows with a custom color so you can see who’s calling and know it’s important. (It works with both the Pixel Phone app and WhatsApp, to start.)
- When you’re interacting with Gemini, HiLight pulses to let you know the system is listening, thinking, and responding.
Aaaaaaaand, that’s it. The system doesn’t work with any other apps, according to Google, and it doesn’t interact with notifications in general to let you know about important pending activity beyond those incoming calls.
It’s actually quite limited, in other words. And no matter what Android phone you’re using — even if it ends up being a Pixel 11! — you can take the same classic concept and make it infinitely more valuable.
The trick revolves around a handy little power-user app called AodNotify. The app has a few different versions, depending on which specific type of Android device is in your paw right now:
- This version is for any and all Pixel phones
- This one is for Samsung Android gadgets
- This one is for OnePlus devices
- And this one is a catch-all for any other brand of Android handset
Whichever version you end up with, AodNotify essentially creates your own custom notification light within your Android phone’s screen — by lighting up the area around your camera cutout at the top of the display, or alternatively creating a border-outline light that goes all the way around the phone front’s perimeter. And it shows up both when the screen is on and when it’s off.
AodNotify puts a Pixel-11-HiLight-style notification light right on any Android device’s display.JR Raphael, Foundry
It serves the same basic purpose as the Pixel 11 HiLight (as well as the old-school 2008-era Android phone LED notification lights that preceded it), but with some key advantages:
- You can see it when your phone is face-up — the way most folks seem to set their devices down when they aren’t actively in use.
- As a result, you can see it when your screen is on and you’re actively using the device as well as when the display is off, as mentioned a moment ago.
- You can have it light up to alert you of any manner of incoming call or notification with the same sort of simple at-a-glance recognition.
- And you can control exactly how and when it works, down to the tiniest of preferences, to make it perfectly useful for you.
Compared to HiLight, the practical value of this approach is absolutely bonkers. Rather than just letting you know about important incoming calls when your phone is face down, AodNotify lets you see at a glance exactly what type of notifications are waiting for you at any given moment — without having to so much as pick up your phone or process any intricate on-screen info.
Whatever alert it flashes can stay present and visible for any amount of time, too, so whether you hear a ding and want to glance to see what’s up or even if you miss the audio alert entirely (or have it disabled deliberately) and want to sneak a peek at your screen to know in a split second what’s waiting for you, AodNotify will get the job done.
And it’s surprisingly easy to set up, too — with two to three minutes of one-time configuration that you’ll never have to think about again.
Your own Android HiLight equivalentAll right — ready? First things first, go install AodNotify from the Play Store, using whichever link is appropriate for your current Android device from above.
Once the app is ready, open ‘er up and follow the prompts to get it going and grant it all the forms of access it needs to operate:
- First, you’ll select which apps can activate your new notification light and cause it to illuminate. If you want any and all notifications to be included, tap the “All” option at the top of the list. If you want to cherrypick and select only certain especially important apps while leaving others off, you can just choose whichever apps you’d like to have included.
- Next, tap the lines for “Notification access,” “Enable AOD,” and “Draw on screen,” if needed, and follow the prompts to enable AodNotify and/or the necessary option for each of the associated areas. This may seem like a lot of access, but AodNotify genuinely needs it to do what it does — and, critically, the app doesn’t require any other system-level permissions, including even access to the internet, so it couldn’t possibly do anything with your data (and its privacy policy is clear about the fact that it doesn’t collect or share any manner of data, ever). It’s also by a known and long-standing reputable Android developer.
- After that, you’ll see a pop-up prompting you to consider the app’s Pro version — which runs five bucks a year or $7 for a single one-time purchase. The Pro path turns off some ads in the AodNotify setup interface and enables some extra features. You may or may not want to consider it eventually, but for now, just hit the “x” in the upper-right corner of that prompt to dismiss it and move on.
JR Raphael, Foundry
Now for the fun part: At the app’s main setup screen, make sure the toggles next to “Notifications” and “Notification light” are active — then tap into each of those sections along with “Colors” and “General” to explore all of the available options.
Of particular note:
- Under “Notifications,” the “Battery” section lets you activate a special notification light for anytime your phone is charging, fully charging, or with a low (less than 15%) battery — so you can always be aware of that info when it arises.
- Under “Notification light,” the “Style” selector will let you shift your spiffy new light from its default camera-cutout-outline position to a full-screen outline or a classic-Android dot-in-the-corner LED-type effect.
- “Effects” in that same section will let you change the light from a simple pulse to all sorts of other interesting light-up patterns.
- “Dimensions” will let you shift the exact size, shape, and placement of the light, if it doesn’t look quite right on your screen.
- And the “How long to show the light” subsection will let you adjust how long any active notification light remains present, both when your screen is on and when the display is dark.
JR Raphael, Foundry
Beyond all of that, some of AodNotify’s most helpful options are in its “Colors” settings section. There, you can specify different distinctive colors for messages or calls connected to different contacts, so you can see who is calling or texting you just by the color of the light (much like what the Pixel 11 HiLight feature does, only with a much broader and more sensible scope). And you can activate an off-by-default option to have your notification light automatically change its color to match the primary hue associated with any given app’s icon — which is a nifty way to know at a glance that a pending alert is coming from, say, your Calendar app or Slack.
AodNotify’s “Auto color” option is one of the app’s most powerful — and easily overlooked — features.JR Raphael, Foundry
And that’s pretty much it. Your Pixel-11-style HiLight upgrade is officially complete — with an even more useful productivity-boosting framework than what the Pixel 11 HiLight version provides.
That’s the power of Android for ya. And it’s a power that’s present no matter what device is in front of you or how long you’ve been holding it.
Never miss a moment of Android awesomeness with my free Android Intelligence newsletter. One new exceptional tip in your inbox every Friday — straight from me to ye.
Lovable bolsters its AI software creation capacity, touts $400M funding round
Lovable, the Swedish-based AI software creation platform company, today announced an acceleration of its product, infrastructure, and team development efforts — and a noteworthy round of Series C funding totaling $400 million.
The company said in its statement that it is looking to augment its platform, which it boasts is already used by almost two-thirds of Fortune 500 companies.
Headquartered in Stockholm, Lovable plans to grow its team to 450 people this year, hiring most heavily in machine learning, product, infrastructure, and security roles, and is looking to expand operations from its home base to include locations in London and three US cities: Boston, San Francisco, and New York City.
The planned growth is made possible by the latest infusion of venture capital, which follows a $330 million Series B funding round last December. Lovable now has a $13.3 billion valuation.
The Series C funding was led by Menlo Ventures and the Scaleup Europe Fund and includes US-based Regent. (Regent is the parent company of Foundry.)
Earlier this month, Lovable announced a partnership with Cerebras Systems, the chipmaker that builds processors the size of dinner plates (the Wafer-Scale Engine) and supercomputing systems built for AI inference and training. Cerebras systems are designed to keep an entire AI model’s weights on a single, super-sized WSE chip, rather than split across many GPUs, to avoid GPU memory bottlenecks.
That partnership calls for Lovable to run some of its latency-sensitive workloads on dedicated Cerebras capacity.
“Fast AI is more valuable than slow AI,” said Cerebras CEO and Cofounder Andrew Feldman said in a statement when the partnership was unveiled. “When AI responds in real-time, users do more with it, stay longer, and run higher value workloads. Software creation is one of the clearest examples of the importance of speed. Creators don’t want to wait.”
In its statement today, Lovable said that since its launch in November 2024, people have created more than 60 million projects with its tools, with Lovable-built apps seeing more than 900 million visits a month.
Computerworld is part of Foundry, which is owned by Regent.
Researcher bypasses Microsoft Defender security patch, seizing control
Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent bypass that provides system-level control to attackers once they gain any level of access.
The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security.
Nightmare Eclipse has not provided the further details we requested, however Microsoft sent a brief statement, saying, “Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims,” and reiterating its commitment to investigating issues and supporting coordinated disclosure.
But the proof of concept (PoC) security bypass, ShieldBreak, described by Nightmare Eclipse in a series of public posts, potentially threatens to be more damaging than earlier bypasses.
Like other recently reported vulnerabilities, ShieldBreak requires an attacker to first somehow gain system access, typically via a successful phishing scam. Once in, however, the attacker can gain full admin/root access.
But there is a troubling psychological component to ShieldBreak, in that it is a bypass for a recently posted security patch from Microsoft, noted Justin Greis, CEO of consulting firm Acceligence. The problem is that CISOs who have already deployed that patch might feel protected when they are not.
“This one is concerning because the patch bypass directly calls the integrity of the remediation into question,” he said. “ShieldBreak appears to demonstrate that an attacker can bypass the fix Microsoft shipped for CVE-2026-50656 and ultimately obtain system-level privileges on the endpoint. That is an important distinction for enterprise defenders, because organizations may believe they have already remediated the underlying vulnerability. A successful patch bypass means the exposure can persist even after the normal vulnerability-management process says the system is protected.”
Greis added that such bypass can reduce overall trust in official patches.
“When public proof of concept code can bypass it, the CISO’s question becomes ‘have we actually removed the exposure?’ rather than simply ‘have we deployed the patch?’,” he said. “From an architecture perspective, organizations should be very careful about allowing the same security product to become both the control being relied upon and the only source of evidence that the control is working.”
Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, said he was especially concerned about the timing of the PoC’s release, given that it seemed to be intended to put the most pressure on Microsoft, given its typical timing for security patches.
“This vulnerability, if valid, would need a fix from Microsoft, but because those patches are usually only released on the second Tuesday of the month and the security researcher seems to have carefully timed the release of the PoC, we may have this exposure for another 4 weeks unless Microsoft deems this a very high severity risk, which is unlikely,” he pointed out.
Cybersecurity consultant Brian Levine, executive director of FormerGov, agreed that CISOs should not underestimate the damage potential if this PoC proves valid.
“What makes it dangerous is what it does once they’re in: it turns an ordinary low-privilege account into full system control by abusing Defender itself, the security tool running at the highest privilege on the box,” he said. “An exploit that lives inside your antivirus is quiet, it’s trusted, and it can be used to blind or disable the very thing you’re counting on to catch the intruder. It’s not a worm, but it’s a near-ideal second stage for ransomware crews and anyone doing hands-on-keyboard intrusion.”
Levine suggested that CISOs not wait for a Microsoft fix, but immediately take an aggressive defensive stance.
“Assume it’s live and lean on defense in depth, because this is exactly the scenario where treating Defender as your only line fails you. Application allowlisting, such as WDAC or AppLocker in enforced mode, is the strongest hardening available and can stop the payload even if the race succeeds,” Levine said.
“Tighten local admin rights and least privilege so a foothold has less to escalate from. And give your hunters one very specific thing to watch for: an interactive shell or scripting host running as system whose parent process is Defender’s engine, MsMpEng.exe. That should never happen in a healthy environment and it’s a high-fidelity sign someone is running this.”
But he also suggested that CISOs not assume that the PoC necessarily works as advertised.
“This is a single researcher’s proof of concept. It hasn’t been independently verified, and it’s coming from someone in the middle of a very public and very bitter fight with Microsoft, so perhaps some of the theater around it should be discounted,” Levine said. “But you can’t wave it away either. Patch bypasses are extremely common, and the claim that Microsoft’s fix for RoguePlanet didn’t fully close the door is entirely plausible. Defenders should treat it as credible until proven otherwise, not the reverse.”
Although Levine and other analysts were initially dubious, there are now indications that the PoC’s effectiveness has been independently verified.
Cybersecurity and risk advisor Steven Eric Fisher, a former cybersecurity risk specialist at Walmart, said, “I’ve seen independent confirmation that ShieldBreak works, although its exploitation method differs materially from the original RoguePlanet exploit. RoguePlanet relied on a filesystem race condition, while ShieldBreak appears to use a different Defender/Cloud Filter API path,” Fisher said. “So while it is being characterized as a bypass of Microsoft’s CVE-2026-50656 fix, it is not simply a replay of the original exploit.”
He added that cybersecurity researcher Kevin Beaumont has already published Microsoft Defender Advanced Hunting detections for ShieldBreak that organizations can incorporate into monitoring while evaluating their exposure.
And Pieter Arntz, malware intelligence researcher at Malwarebytes, also said he has seen confirmation from a researcher he tracks, Will Dormann.
This article originally appeared on CSOonline. It has been updated with a statement from Microsoft and further confirmation of the exploit.
Researcher creates workaround for Microsoft Defender security patch
Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent workaround that provides system-level control to attackers once they gain any level of access.
The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security.
Nightmare Eclipse has not provided the further details we requested, however Microsoft sent a brief statement, saying, “Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims,” and reiterating its commitment to investigating issues and supporting coordinated disclosure.
But the proof of concept (PoC) security workaround, ShieldBreak, described by Nightmare Eclipse in a series of public posts, potentially threatens to be more damaging than earlier workarounds.
Like other recently reported vulnerabilities, ShieldBreak requires an attacker to first somehow gain system access, typically via a successful phishing scam. Once in, however, the attacker can gain full admin/root access.
But there is a troubling psychological component to ShieldBreak, in that it is a workaround for a recently posted security patch from Microsoft, noted Justin Greis, CEO of consulting firm Acceligence. The problem is that CISOs who have already deployed that patch might feel protected when they are not.
“This one is concerning because the patch bypass directly calls the integrity of the remediation into question,” he said. “ShieldBreak appears to demonstrate that an attacker can bypass the fix Microsoft shipped for CVE-2026-50656 and ultimately obtain system-level privileges on the endpoint. That is an important distinction for enterprise defenders, because organizations may believe they have already remediated the underlying vulnerability. A successful patch bypass means the exposure can persist even after the normal vulnerability-management process says the system is protected.”
Greis added that such workarounds can reduce overall trust in official patches.
“When public proof of concept code can bypass it, the CISO’s question becomes ‘have we actually removed the exposure?’ rather than simply ‘have we deployed the patch?’,” he said. “From an architecture perspective, organizations should be very careful about allowing the same security product to become both the control being relied upon and the only source of evidence that the control is working.”
Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, said he was especially concerned about the timing of the PoC’s release, given that it seemed to be intended to put the most pressure on Microsoft, given its typical timing for security patches.
“This vulnerability, if valid, would need a fix from Microsoft, but because those patches are usually only released on the second Tuesday of the month and the security researcher seems to have carefully timed the release of the PoC, we may have this exposure for another 4 weeks unless Microsoft deems this a very high severity risk, which is unlikely,” he pointed out.
Cybersecurity consultant Brian Levine, executive director of FormerGov, agreed that CISOs should not underestimate the damage potential if this PoC proves valid.
“What makes it dangerous is what it does once they’re in: it turns an ordinary low-privilege account into full system control by abusing Defender itself, the security tool running at the highest privilege on the box,” he said. “An exploit that lives inside your antivirus is quiet, it’s trusted, and it can be used to blind or disable the very thing you’re counting on to catch the intruder. It’s not a worm, but it’s a near-ideal second stage for ransomware crews and anyone doing hands-on-keyboard intrusion.”
Levine suggested that CISOs not wait for a Microsoft fix, but immediately take an aggressive defensive stance.
“Assume it’s live and lean on defense in depth, because this is exactly the scenario where treating Defender as your only line fails you. Application allowlisting, such as WDAC or AppLocker in enforced mode, is the strongest hardening available and can stop the payload even if the race succeeds,” Levine said.
“Tighten local admin rights and least privilege so a foothold has less to escalate from. And give your hunters one very specific thing to watch for: an interactive shell or scripting host running as system whose parent process is Defender’s engine, MsMpEng.exe. That should never happen in a healthy environment and it’s a high-fidelity sign someone is running this.”
But he also suggested that CISOs not assume that the PoC necessarily works as advertised.
“This is a single researcher’s proof of concept. It hasn’t been independently verified, and it’s coming from someone in the middle of a very public and very bitter fight with Microsoft, so perhaps some of the theater around it should be discounted,” Levine said. “But you can’t wave it away either. Patch bypasses are extremely common, and the claim that Microsoft’s fix for RoguePlanet didn’t fully close the door is entirely plausible. Defenders should treat it as credible until proven otherwise, not the reverse.”
Although Levine and other analysts were initially dubious, there are now indications that the PoC’s effectiveness has been independently verified.
Cybersecurity and risk advisor Steven Eric Fisher, a former cybersecurity risk specialist at Walmart, said, “I’ve seen independent confirmation that ShieldBreak works, although its exploitation method differs materially from the original RoguePlanet exploit. RoguePlanet relied on a filesystem race condition, while ShieldBreak appears to use a different Defender/Cloud Filter API path,” Fisher said. “So while it is being characterized as a bypass of Microsoft’s CVE-2026-50656 fix, it is not simply a replay of the original exploit.”
He added that cybersecurity researcher Kevin Beaumont has already published Microsoft Defender Advanced Hunting detections for ShieldBreak that organizations can incorporate into monitoring while evaluating their exposure.
And Pieter Arntz, malware intelligence researcher at Malwarebytes, also said he has seen confirmation from a researcher he tracks, Will Dormann.
This article originally appeared on CSOonline. It has been updated with a statement from Microsoft and further confirmation of the exploit.
Lovable raises another $400M, confirms new $13.3B valuation
Europe’s favorite vibe-coding startup Lovable has confirmed previously reported whispers that it was raising another mega round at a $13.3 billion valuation. Lovable said on Wednesday that it has raised $400 million in a Series C round led by Menlo Ventures and the Scaleup Europe Fund, with more than a dozen other investors participating.
This new funding comes after Lovable hit $500 million in annualized run rate revenue in June, the startup told TechCrunch. Its previous round, announced in December, brought in $330 million at a $6.6 billion valuation and was also led by Menlo Ventures, with CapitalG as co-lead.
Note: One of Lovable’s new Series C investors is Regent, the investment firm that owns Foundry.
IT infrastructure shortages are real and lasting. Here’s how to cope
Lead times of nine to 12 or even 18 months. Costs rising by 35%, 45%, even 50% to 200%. More than halfway through 2026, the market for IT infrastructure that’s crucial for enterprise projects, including those involving artificial intelligence, is strapped.
Memory is at the root of the shortages. Memory prices “have risen by 50% to 200%, resulting in PC prices increasing by 35% to 45% and some server prices rising over 125%,” according to Jon Forest, VP analyst at Gartner. Network switches also need memory, albeit in lesser amounts than servers, so they are not immune, with prices and lead times likewise rising dramatically.
Industry experts agree that most of the issues stem from hyperscalers gobbling up memory capacity, which trickles down to servers, storage systems, and networking devices. But while the source of the problem may be new, supply chain disruptions are far from unprecedented.
As a result, industry insiders are not short on advice on how best to deal with the situation, with tips including making better use of what you have, considering options beyond your usual scope, and lots of planning with your vendors and internal finance teams.
State of the problemJust how bad is the current supply chain problem? “It’s pretty bad,” says Matt Kimball, vice president and principal analyst with Moor Insights & Strategy. Companies accustomed to 30- to 45-day lead times for various infrastructure are now looking at 6, 12, or even 18 months.
“It’s real, and I’m hearing it from companies of all sizes, from the 1000-server to the 10,000-server shops,” Kimball says.
“Memory costs are expected to rise sharply well into 2027 and will reach up to 25% of network hardware expenses by the end of 2027,” according to an email Gartner’s Forest sent to Network World. The figure below shows the timeline Gartner expects for memory prices, and Forest notes that the same timing applies across networking, storage, and compute infrastructure.
Gartner
“Enterprise network equipment pricing is projected to increase by over 20% in 2026. This upward trend is anticipated to continue with a further rise of 3% to 5% entering 2027, with no signs of price reduction until the end of 2027.”
But “reduction” will likely look more like “stabilization.”
“That’s something a lot of people don’t like to talk about. But let’s say prices went up 40%, they may come down five,” says Phillip Privett, senior vice president of vendor management with the global distributor and value-added reseller TD SYNNEX. “They’re not going to come down 40%.”
Perhaps worse, compared with past disruptions caused by issues such as fires in chip fabrication factories or the Covid pandemic, Kimball says this one is “durable” because its cause—the AI wave—is more long-lasting and just getting started.
“This AI inference wave we’re hitting is just beginning. It’s going to be longer and bigger than the training wave,” he says. “It’s impacting everything, from AI infrastructure to the traditional stuff that’s standing up your virtualization and cloud infrastructure.”
No vendors seem to be immune, not even the likes of Cisco, which makes its own Cisco Silicon One chips. Or, at least, it designs the chips; they’re actually manufactured by the Taiwan Semiconductor Manufacturing Company (TSMC), the same company that makes many of the other chips that are in such demand. And that’s only one component of many that comprise a switch.
On the other hand, the margins Cisco gets from enterprise sales are far greater than those from hyperscalers because Cisco sells mainly just hardware to hyperscalers, whereas enterprise sales generally include software and services as well. So, Cisco has incentive to keep enterprise customers happy and maintain the 66% margins it reported in Q3, its latest quarter.
Still, Cisco must deal with the same shortages as other vendors.
“I wouldn’t say any company is faring better than others,” says Neil Anderson, vice president and CTO for cloud, infrastructure, and AI solutions at World Wide Technology (WWT). “There may be nuances that some suppliers are employing to balance it to some extent, but I fail to recognize a supplier that’s not having almost the same issue.”
Cloud storage vendor Backblaze is one company that’s facing equipment cost and availability issues. “There are different types of shortages occurring in multiple places, all driven by unusual market demands, really by just a handful of very large buyers,” says James Rowell, senior vice president of operations with Backblaze.
Backblaze is constantly forecasting and monitoring demand triggers, Rowell says. That involves close alignment with the sales team to forecast client needs, as well as paying attention to historical trendlines to predict upcoming demand from new deals and growth with existing clients. But the company also looks for “unnatural market-related triggers” that would cause a spike in utilization.
With hyperscalers buying up vast amounts of capacity, “This is definitely an unnatural phase,” Rowell says. “For about for the last 12 months, I would say there’s been somewhere between a 15% and 30% uptick in costs,” especially in terms of servers and compute disks.
On the positive side, at least for Backblaze, the company is also seeing an uptick in business from an interesting source: AI companies. “We reported in the last earnings period a 70% increase in AI companies using our platform,” says Patrick Thomas, vice president of marketing at Backblaze. “That’s massive.”
On top of that, the company is seeing an uptick in deals from enterprises that can’t get the storage capacity they need or want on-prem. “There’s a general market nervousness where we’ve got potential deals coming our way because those organizations are concerned about being able to do it themselves,” Rowell says.
While some expect new chip fabrication plants currently under construction will ease memory supply constraints, Privett doesn’t buy it. “I don’t see it getting better anytime soon,” he says. “Building a new fab is a two-year process.”
Advice: Start with the basicsEnterprises, then, must play the cards they’re dealt. For Moore Insights’ Kimball, who did stints as an IT exec with the states of Florida and Oregon, that starts with making the most of what you have.
Such a strategy is “shockingly not implemented much” across the companies he sees. “A simple capacity planning exercise can free up a lot of resources.” That includes virtualized servers running at just 20% to 30% utilization as well as extending the life of existing servers. While 15 or 20 years ago it was common to refresh every four years or so, companies can often get six or seven years out of today’s servers.
While such strategies won’t solve your AI compute challenges, they can certainly help support your ongoing operations and free up budget for AI and other modernization projects, he says.
“Sweat your assets,” agrees Privett of TD SYNNEX. “Work them as much as you can, add only what you need, get extensions on your licensing, renewals on your services agreements and things like that. Just sweat it out a little longer.”
If you have budget to spend but can’t get the hardware you’re after, buy something else, says WWT’s Anderson. “Look at things that are not tied to those components, like software projects or SaaS licensing,” he says.
Get friendly with finance teamsNumerous experts recommend regular meetings with your CFO or finance teams to keep them apprised of what you’re up against so the company can plan accordingly.
Gartner’s Forest advises using rolling 12- to 24‑month forecasts and engaging early with suppliers to identify constrained components and SKUs. Committing to quarterly or monthly buys can help you avoid long-term agreements that extend past the rapid increases we’re seeing in 2026, he says.
Also engage with the financing arm of your equipment vendors, some of which are offering financing incentives, Privett says. Compute vendors in particular are offering subsidized financing, deferred payments, and low-cost financing for the first year or so. “Those are huge opportunities to take advantage of,” he says.
By engaging with finance teams, IT groups can conduct budget allocation exercises and try to come up with ways to make the financials work. The last thing you want to do is surprise them with additional budget requests out of the blue.
Kimball recalls his days with the state of Florida, when all budget requests were examined by a technical review working group—which was designed to be hostile.
“I can’t imagine going to them and saying, ‘Oh, did I say that was a million dollars? It’s actually $2 million. I need you to write me a bigger check,’” he says. “I would walk into one of the swamps in Tallahassee and get eaten by the alligators instead of doing that.”
Work with your vendors and VARsAs you put plans together, lean on your vendors for help, including channel partners such as value-added resellers (VAR) and national resellers. “Work with them to map things out and understand what your workloads will look like,” Kimball says.
That’s what Backblaze’s Rowell regularly does with his suppliers. He lays out his forecast for the year, with commitments on what Backblaze will definitely buy, as well as scenarios that account for rapid growth, say, 2x. “And they’ll come back with, ‘Well, okay, no problem,’ or maybe they say we need to put in an allocation right away, or we won’t be able to get what we may need,” he says.
Similarly, he sits down with his CFO regularly to map out predictive models that factor in inflation, price hikes, and the like. The idea is to plan out multiple scenarios, so you don’t get blindsided.
“If you don’t do that, you’ll get caught with your pants down, on the upside-down end of spectrum,” he said – meaning not having the capacity to take advantage of market opportunities.
Acquiring the capacity you need to meet project demand may also mean being flexible in terms of your equipment choices. If you’re a Dell shop but can’t get Dell servers, maybe you go with Lenovo, Kimball says.
“You’ve got to figure out how to use all this silicon and infrastructure in a heterogenous way to serve your needs,” he says. That’s especially true when it comes to AI infrastructure. “If you think you’re going to go with 100% Nvidia for everything from RAG [retrieval augmented generation] to inferencing at the edge, you’re kind of crazy, not because of cost but because of availability.”
Look at alternatives, including AMD and cloud solutions, while staying mindful of how it all plays together. You may not be able to get Nvidia GPUs, but AWS, Azure, and Oracle Cloud have them, Kimball notes.
Be strategic, perhaps by using cloud offerings to handle certain tuning or inference workloads, then bringing them back in-house when appropriate. “Have a better understanding of what absolutely has to be on prem and what can be in the cloud,” he says.
That’s good advice, says Backblaze’s Thomas. When it comes to AI, think about performance tiers and the range of use cases you have. They don’t all need top-tier performance.
“People get wrapped around axle of needing the top end. There’s a lot of flexibility in the edges, innovation in different hardware and software,” Thomas says.
Gartner likewise advises companies to increase configuration flexibility and expand sourcing paths. That may include buying from secondary markets and lease-return programs to preserve continuity with existing infrastructure until the shortages pass, Forest says.
Get started somewhereEven if you can’t acquire or have to wait for the infrastructure you need, don’t let that keep you from getting started with AI or other modernization projects.
Options include public cloud and neocloud providers, Anderson says. WWT also provides capacity in its own lab so customers can get started with proof-of-concept projects. “Don’t just throw your hands up. We can help you find access to capacity,” Anderson says. “Production-scale AI may be delayed, but don’t let that derail your strategy.”
Colocation providers may likewise be an option, especially if enterprises are struggling to acquire high-end networking equipment. Networking is a key value proposition for colocation providers, in that they have built-in connections to various cloud providers and other ecosystem players.
Equinix, for example, has 280 data centers in 77 metropolitan areas, says Phil Read, senior director, colocation product management for the company. If you have the compute infrastructure, Equinix can help you with the high-end connectivity required both intra- data center and at edge facilities.
It also has partnerships with the likes of Cisco and Nvidia for “ready-to-go AI connectivity,” Read says. That means Equinix offers the right infrastructure to meet the requirements of high-end compute solutions in terms of power density and cooling. Such power densities are significant, requiring 120k VA per rack and up. “There’s plenty of talk about a megawatt rack,” he says.
Power is a significant issue in this entire discussion, Privett says. Older installed computing infrastructure likely consumes far more power than newer systems, which is an argument for upgrading as soon as possible.
“If you modernize today, you could substantially reduce the number of servers needed to support the same applications at a much lower power consumption rate,” Privett says. He advises sitting down with folks from the OT side of the house to make sure power is available for whatever you want to do. In many areas, power is at a premium.
If your plans include installing GPU environments in your own data center, WWT advises you not to delay. “We’re telling customers, you need to talk with us and get that designed, get that ordered, because it will take quite a bit of time until it actually ships and we’re able to install it,” Anderson says.
Apple’s response to RAM-ageddon? Lease, downgrade, refurbish, repair
Apple is in the process of tweaking its business models to cope with the unyielding memory price and availability crisis. Its response is now emerging across multiple fronts.
Finance or leaseThe company’s recently-introduced Apple Upgrade scheme in partnership with Klarna is a smart response to the reality that as devices inevitably become more expensive, consumers will shift from outright ownership to flexible lease and financing arrangements. With its partnership, Apple continues to generate revenue while also maximizing the likelihood customers will return the product at EOL, more about which later.
Samsung and Google have introduced similar schemes. “Financing models already dominant in India and Africa are now poised to reshape the US and European markets,” said CCS Insight in a presentation exploring the consequences of the memory shortage.
DowngradeApple has seen a lot of success with the iPhone 17 this year. That success wasn’t entirely because it’s such a good smartphone; it also reflects consumers making the decision to purchase lower-specced devices to stay within budget. Apple continues to see strong sales of its Pro range, which represents the power of its reach into more affluent consumer groups. It’s also important to note that at the moment, the iPhone 16e is the biggest-selling device on the US pre-paid market.
People still want the best, but are being more cautious in how they acquire it.
RefurbishedThe trade in refurbished devices is fundamentally built on two things: A large installed base of originally-sold devices resilient enough to be refurbished in the first place and buy-back deals attractive enough to encourage consumers to trade those devices in at all. That’s why it matters that Apple recently increased the value of its trade-in scheme: you’ll get up to $480 for an iPhone 16 or up to $720 for an iPhone 16 Pro Max under Apple’s new deal. It’s also important because Apple has its own growing refurbished business in Apple Refurb, and also because devices that really have reached end-of-life can be broken up for parts, taking a little pain out of Apple’s ongoing component crisis.
In 2024, Apple shifted 15.9 million refurbished devices and accessories.
Delay and RepairAs prices rise, consumers will keep their devices longer and are far more willing to repair existing hardware than upgrade. It’s well-known that iPhones are the most durable smartphones and ship with extensive future system support, so these devices can be successfully used for five years — sometimes more. Apple offers its own service and support package to keep your devices in good shape, and its recent decision to extend AppleCare One support to new nations reflects consumer sentiment. Those who want Apple’s trusted support for up to three devices can now get it for just a few dollars each month.
Not just about iPhonesAll these initiatives are important in their own right, of course, and while I’ve focused on iPhone here, Apple is implementing these changes and services across all its product lines. It knows that in the face of AI-flation, consumer habits will change. Demand for new devices — assuming Apple can even get enough components to make them — will fall. “Demand for refurbished models and financing will grow — fast,” said CCS.
The other transformation concerns price. The hyperinflation driven by decisions made by the effective cartel of the big three memory vendors (who could have continued to support the consumer memory industry while providing less support for data centers) is driving low-tier smartphone manufacturers to exit markets or raise prices. CCS expects smartphone prices to increase by 25%. Counterpoint says DRAM prices have risen 70% since 2025, while Gartner and others expect price inflation to remain into next year.
As Intel’s CEO said, “There’s no relief until 2028.”
Price increases leave a huge gap in the sub-$500 device market; that’s a vacuum the second-user market in refurbished smartphones will fill. As the value of that tier increases, it becomes a more strategically important market for both Apple and Samsung, who make the vast majority of smartphones. For both vendors, ongoing market changes mean the second-user market is becoming a primary channel for both companies; you can expect continued business pivots from both as they seek to capture business revenue.
Incoming structural challengesEven there, there’s a structural challenge to overcome. That is that as memory prices surge, sales of new devices decline. Down the road, there will be fewer devices to trade in, meaning the supply of used devices will fall, creating a future supply-and-demand imbalance in the second-user market. I predict this could get quite bitter, with manufacturers grabbing larger chunks of available devices to the detriment of the small renew-and-refurbish retailers. CCS Insight expects the market for second-user smartphones to grow by 9% in 2026 as cost-and-supply challenges bite.
Making the circleThere is opportunity within the chaos. Apple has committed to building a circular manufacturing ecosystem by 2030, which is only four years away.
We don’t know how far along the company is on that road, or the extent to which changing market conditions have undermined its attempt to reach that goal. But the company will have spent time developing new manufacturing and production processes to enable more extensive use of recycled and renewable raw materials in that attempt.
The signs are positive — the recently introduced MacBook Neo has a 90% recycled aluminium enclosure and 100% recycled cobalt battery.
Distorted loopThere is a reality in which any slowdown in new device manufacturing — or, indeed, the cadence of new device introductions — gives Apple and its partners a little breathing space in which to develop and deploy new manufacturing process technologies.
In that narrative, it does perhaps matter that under its new iPhone release schedule, there will be an 18-month gap between the launch of the best-selling iPhone 17 and the spring 2027 release of the iPhone 18. With a 20th anniversary iPhone and new iPhone Ultra range, along with some talk of a future flip phone, Apple may soon be in position to maintain the marketing buzz with new iPhones every six months while actually crafting an 18-month wait between major device improvements.
Doing so will likely reduce initial unit shipments while also flattening sales revenue for more predictable income. It also builds in extra time to retool the production lines for each device family.
Leading with the newWhen it comes to the deployment of new circular manufacturing tech, that potential 18-month gap buys that most precious of resources, time. Which means that while memory price inflation has caused huge problems, raised prices and forced Apple to change business practices, it could also give the company an opportunity to introduce one of the most profound changes in manufacturing of the 21st Century: circular manufacturing. To some extent, this transition in the nature of Apple’s business is reflected at board level, as the company is itself transitioning to new leadership under incoming CEO John Ternus.
You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to The Core to keep pace with daily Apple news in one email.
AI policies work better when employees help write them
It’s likely that many enterprises have created — or are at least considering — AI policies that clearly lay out approved AI tools and their uses, set up training programs for employees to help them use the tools in their jobs, and establish guardrails around those systems to avoid issues such as security vulnerabilities and data bias.
But how many of these policies have received the blessing of employees? It’s a key question, because many workers are highly wary of AI.
They worry that it will cost them their jobs, either by taking over their work or because companies will cut jobs and use the savings to fund investments in AI research and infrastructure. They worry about AI-powered performance tracking software impacting raises and promotions. They worry about AI screening of job applications for future roles.
Even employees who have embraced AI to assist their work have reason to worry. Many say that using generative AI tools saves them time, but the time savings are eroded by “botsitting” — having to check and recheck output, provide missing context, fix errors, and go through multiple iterations before the desired outcome is achieved. They may also have to wade through “workslop,” low-quality genAI output that hasn’t been properly vetted by co-workers.
Additionally, workers say that as AI makes them more productive, their workload keeps increasing. All of this can add up to “prompt fatigue” or “AI brain fry,” mental exhaustion that affects heavy genAI users, particularly when they bounce between multiple AI tools.
AI policies that don’t take these factors into account are apt to be problematic. Employees may even organize to protect themselves from AI in the workplace. Indeed, tech pros are increasingly interested in unionizing, driven in part by the incursion of AI.
It doesn’t have to come to that. Company leaders can proactively work with their employees to develop AI policies that take employee well-being into account. The result might be stronger AI adoption, better business outcomes, and a happier, more productive workforce.
The 2026 Tech Sentiment Report by technology career marketplace Dice found that professionals are generally not resisting AI itself, “but rather, they’re looking for clarity around how it will affect their jobs, careers, and workplace decisions,” says Paul Farnsworth, president of the firm. “The research suggests that employee buy-in comes from making AI feel like something being done with workers rather than to them.”
In many cases, IT management runs the deployment of AI, and this can ultimately result in employees being left out of any decision making.
“When IT leaders drive deployment, they ask questions about integration, security, and capability,” says Amy Loomis, group vice president, Workplace Solutions at IDC. “That is not the same as asking workers how AI could actually improve their day, where they waste time on tasks that add no value, and where a well-designed tool would make a real difference.”
Following are some key steps to building an AI policy everyone can agree on. Bear in mind that any worker protection items should be in addition to the usual corporate governance, risk, and compliance AI policies, not a replacement for them.
Invite input from everyone involvedIt might sound obvious but can’t be overstated: the only real way to produce an AI policy that employees will accept is to get their input.
“We started by surveying our employees through SurveyMonkey to see what they were already using and why,” says Monica Washington Rothbaum, COO and senior attorney at law firm J&Y Law. “Then we sat down with every department, and involved operations, IT, HR, and leadership from the beginning. We wanted to understand the opportunities, but we also wanted to understand the risks” of AI.
Most AI policies “fail when they’re created in a conference room and handed down from the top,” Rothbaum says. “The people using these tools every day need to be part of the conversation. That’s why transparency became a major focus for us” in creating an AI policy.
Organizations should include employees in policy development, pilot programs, and feedback processes, Farnsworth says. This is especially important because Dice research found that only 48% of organizations have formal AI policies, while nearly one quarter of professionals surveyed said they’ve used AI without manager approval.
Keep the lines of communication openCreating an AI policy is not a one-and-done proposition. Organizations need to keep communicating with employees as AI and tools evolve.
“We communicated updates during company all-hands meetings, through email, in Microsoft Teams, and through department-level discussions,” Rothbaum says. “We even designated a member of our marketing team to oversee communications around AI adoption so there was clear ownership and accountability.”
The biggest mistake organizations make is treating AI like standard software, Rothbaum says. “It’s not. It’s an operational change,” she says. “It’s a communication challenge. It’s a governance challenge. The technology itself is often the easy part. The hard part is deciding what data can be used, who has access, how outputs are reviewed, and how the organization remains compliant while the technology continues evolving.”
One of the biggest drawbacks to AI adoption, from the standpoint of many employees, is the worry that AI tools will ultimately take away their jobs or many of their responsibilities.
Indeed, this has already been the case at some tech companies. A majority of non-AI technology professionals think AI eliminates more jobs than it creates, according to the Dice report, and three quarters think
junior-level workers are most at risk of displacement.
“Reassurances that no jobs will be lost ring hollow when workers can see
reorganizations happening around them,” Loomis says. “The organizations that sustain worker trust communicate specifically about what is changing, what it means for individual roles, and what the organization is committing to in return.”
One way to get around these concerns is to include provisions in policies that require any decisions around individual workers’ employment to be made by a human. That way no one can be dismissed from their job at the discretion of a machine.
Ensure access to training programsAnother way to gain workers’ support for AI policies is to include provisions about access to ongoing training and educational programs designed to build on their existing knowledge and provide them with valuable new skills.
“Employees are more likely to embrace AI when they see opportunities to grow alongside it,” Farnsworth says. “As AI becomes increasingly embedded in daily work, organizations should invest in AI literacy, upskilling, and career development programs to help employees adapt to changing job requirements.”
And those programs should be codified in AI policies. Guaranteeing workers access to training that evolves with the technology and enterprise workflows “requires treating training as a policy commitment with defined standards, timelines, and completion tracking,” Loomis says.
“Effective AI training does two things: it teaches workers how to use specific tools in the context of their specific roles, and it builds the human skills, judgment, critical thinking, and adaptability that determine whether workers can use AI well rather than just technically. Both are necessary,” she says.
When training is treated as a one-time event rather than a continuous policy commitment, Loomis says, adoption stalls and distrust grows. Ongoing “human skills training is gaining explicit recognition as core to
effective AI use,” she says.
This needs to be a standard component of any AI policy. But the language of proper and improper uses of AI tools and data must be clear for everyone in the workforce.
Such guardrails not only address cybersecurity and regulatory concerns, but can help prevent uses of AI that result in discrimination.
“The organizations that get the most value from AI won’t be the ones that adopt it the fastest,” Rothbaum says. “They’ll be the ones that communicate clearly, train consistently, and build the right guardrails before they need them.”
Confidential, client, firm, or employee information may not be entered into any AI tool unless explicitly authorized and approved, according to the J&Y Law policy.
Emphasize the positives of AIPolicies will of course include restrictions on the use of AI and rules around avoiding risks, but they also need to share how workers can leverage tools to help make their jobs easier or more fulfilling.
“One thing we’ve seen is that effective AI policies aren’t just lists of restrictions,” Farnsworth says. “Instead, they provide employees with clear guidance on how to use AI responsibly and confidently in their work. At Dice, our AI policy encourages employees to use AI when it can improve productivity, while establishing guardrails around data security, confidentiality, and human oversight.”
A good policy will help employees better understand that AI presents not just risks, but opportunities as well.
More on AI in the workplace:Anthropic to watermark AI-generated content
Anthropic will begin labeling AI-generated content created by Claude, Claude Code, and the company’s API, as well as Claude models via third-party services, according to The Register.
Text generated by future Claude models will be given an invisible watermark. According to Anthropic, the watermark is embedded directly into the generated text without affecting its meaning or readability. For files, Anthropic will instead use signed metadata in accordance with the C2PA standard.
The effort is part of the company’s plan to comply with the EU’s AI Regulation and transparency requirements regarding AI-generated material. However, the labeling will be implemented globally for all users.
At the same time, Anthropic noted that the technology has its limitations. A label does not guarantee that material was created by Claude. Similarly, the absence of a label is not necessarily proof that the material is not AI-generated.
Apple’s price hikes are a warning to IT
IT purchasing is being hit by a double-whammy: Enterprises want to ensure their hardware is good enough to support AI, even as memory shortages caused by AI deployments are driving steep price increases for Macs, iPhones, iPads, tablets, Android devices and Windows PCs.
The root cause is widely known. JP Morgan estimates DRAM prices have risen more than 400% since the beginning of 2024 as data center construction and hyperscaler demand consumed a gargantuan chunk of global memory production capacity.
More pain is coming“It is not a secret that the industry will stay in shortage for multiple years,” warned analyst Jay Kwon. IDC analysis expects DRAM manufacturing capacity to fall short of demand, while SK Hynix believes demand will exceed supply well into the next decade. AI data centers are absorbing around 70% of output.
This tough provisioning juggling act plays out as economic insecurity continues and the supply of key materials beyond memory also remains constrained. It makes for a perfect storm of shrinking purchasing budgets, rapid price increases, and competitive pressure to accelerate ongoing patterns of digital transformation.
To some extent, business leasing schemes will probably become more popular, while IaaS and SaaS vendors will widen their offerings to also include the kind of AI services businesses need. But the scale of the problem is pretty clear:
- Apple recently imposed roughly 20% price increases across all its hardware, with the exception (for now) of iPhones. The latter are expected to see their own price increases in the coming weeks as the company grapples with the reality that memory price inflation has made its products 38% more expensive to build.
- Huawei Executive Director and Consumer Business Group Chair Richard Yu warned that rising memory costs will force his company to hike prices to “relieve the ever-increasing cost pressure.”
- Despite making memory itself, Samsung has also implemented rolling price increases across multiple smartphone and tablet ranges, up to $120 more in some cases.
- Google is expected to raise prices across the Pixel line, probably when it introduces its new devices on Aug. 12.
- Motorola slapped price hikes of up to 50% on its Moto G smartphones in April.
- Xiaomi raised its own prices by up to 13% in China.
- Dell, Lenovo, HP, and Acer have all increased prices — even as Microsoft hits its struggling OEMs with its own 10% price hike on Windows 11 licenses.
These price increases are not isolated; they reflect the global memory price challenge. Gartner expects memory prices will increase roughly 130% by the end of the year, while TrendForce’s recent survey sees further DRAM price increases ahead.
No one will be sparedThis is a global challenge affecting businesses and consumers everywhere in real time. What’s important about these price hikes is their unpredictability; in most cases, business leaders will not have known the increases were coming, which means existing, pre-determined purchasing budgets do not reflect this new reality.
“The IT landscape faces a seismic shift, and its epicenter is memory,” according to Insight. “The market dynamics have fundamentally changed.” In other words, this challenge is long-term, structural, and here to stay.
As a result, every device that contains memory or a processor will get more expensive; this is already particularly visible in networking equipment, the cost of which climbed up to seven-fold in some cases this year. Games consoles, smart TVs and streaming boxes — including Apple TV — have not been spared.
IT purchasers are looking at these trends and wondering what to do. When it comes to PCs, price unpredictability means that lower cost isn’t necessarily an advantage. It makes more sense to spend a little more today to end up with a system that can continue working for your business for five years or more. Purchasers want longer hardware life cycles and are more willing than they once were to look at refurbished devices, which is driving growth in reconditioned markets.
(Apple sees this, which is why it recently raised trade-in prices for its kit as it seeks to recondition and resell its own products where possible.)
Reliability, resale value, and recycling and energy costs need to be considered, concerns that are in part driving businesses toward Macs. Regular readers will recognize the numbers often add up. Forrester’s Total Economic Impact research says lower support costs mean Macs save hundreds of dollars per seat in comparison to PCs over just three years, while Cisco has reported significant cost savings.
So, what should IT purchasers do?Waiting for prices to stabilize isn’t a strategy. All the analyses show there will be no change for some time. Seeking some resilience, purchasers are seeking multi-year leasing agreements and bulk purchase deals even while vendors become more resistant to them.
Three-year replacement cycles are being extended, prompting purchasers to make better buying decisions in the first place, and canny buyers should already be auditing what roles need what kind of machine. Does every computer need to be AI-ready? Probably not, so it’s important not to over-spec the whole fleet.
Many purchasers will likely be investing more in Macs as they seek to diversify vendor exposure, while total cost of ownership over time is becoming a far more significant concern than before. It really matters that Macs are cheaper to run over time than PCs, particularly when costs have become so unpredictable. The same logic applies to tablets and smartphones, too.
None of these steps take the problem away. But sensible decision making now could help manage what is likely to be a highly uncertain period in IT purchasing, reiterating the need for resilience, so anticipated price shocks don’t blow your budgets apart.
You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to The Core.
AI finds so many Windows flaws, Microsoft can’t keep up. Should you worry?
Be careful what you wish for. That’s what Microsoft found out recently when it discovered that AI — rather than making Windows more secure by helping the company close security holes — could help hackers find flaws faster than Microsoft can fix them.
It’s put Microsoft in a serious bind. Should the company devote a potentially massive amount of resources to fix every AI-unearthed security issue as fast as it can? Or should it rush to close the most important ones, and clean up the minor ones later at much less cost?
What the company decides could have tremendous implications. For years, Microsoft has faced criticism from many in the US government because of how often its technologies have been hacked, potentially putting the nation’s security at risk. Some members of Congress have suggested the government curtail contracts with Microsoft until the company proves it can provide more safety. Billions of dollars in federal contracts could be pulled.
To get a better insight into what could happen, let’s look at AI’s newfound prodigious ability to find security holes and bugs.
AI-fueled security mavens Mythos and Project GlasswingMicrosoft’s AI-related security problems are an outgrowth of the launch of Anthropic’s Mythos AI model, designed to handle cybersecurity and biology research. One of its goals is to uncover security vulnerabilities as quickly as possible, so that software companies and cybersecurity companies can fix them before hackers find the holes.
Anthropic’s early tests found that Mythos was spectacularly successful in finding Windows security flaws. “Within 31 minutes, Mythos generated its first proof-of-concept exploit for a Windows kernel vulnerability,” Axios reported in June.
Anthropic noted that its testing of Mythos “reveals a stark fact: AI models have reached a level of coding capability where they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities.
“Mythos Preview has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser. Given the rate of AI progress, it will not be long before such capabilities proliferate, potentially beyond actors who are committed to deploying them safely. The fallout — for economies, public safety, and national security — could be severe.”
As a result, Anthropic decided to launch a security project it calls Project Glasswing, which it describes as “an urgent attempt to put these capabilities to work for defensive purposes.”
Many companies beyond Anthropic are part of the effort, including Microsoft, Google, Amazon, Nvidia, Apple and others. In theory, it’s a great idea. Find and fix vulnerabilities before hackers can, and everyone is safer. What could go wrong?
Plenty, as it turns out. Access to Mythos is available to anyone, and Mythos has been finding security holes and bugs far faster than companies — particularly Microsoft — can patch them. As Pro Publica reported in late July, ‘Microsoft is struggling to fix them fast enough.”
Too little, too late?For now, Microsoft is only patching the most dangerous bugs and holes. And, according to Pro Publica, “internal records indicate that Microsoft plans to eventually address ‘moderate’-severity flaws uncovered by Mythos. The documents made no mention of ‘low’-severity bugs.”
That’s fairly typical of the triage many companies use when deciding how much effort to put into plugging holes. But some experts believe that in the age of AI, that’s a dangerous way to handle security.
Vinh Nguyen, former chief AI officer and chief data scientist at the US National Security Agency and now a senior technical adviser to Anthropic and senior fellow for AI at the Council on Foreign Relations, is particularly concerned that the approach is outdated. He told Pro Publica: “The problem now is that you can chain four low-level flaws, and that can equal a high severity. If you’re Microsoft, the current triage strategy may be underpricing risks.”
It’s already proving difficult for Microsoft to keep up with patching bugs and security holes since Mythos’ launch. July’s Patch Tuesday release fixed the most bugs in Microsoft’s history – 622 of them. Things will only get harder from here.
The dangers for MicrosoftMicrosoft is already in the doghouse for how it’s handled security. A year ago, in one of the worst attacks on Microsoft technologies, SharePoint was hacked. Tens of thousands of servers were hit, including not just thousands of businesses, but many important government agencies as well.
The National Institutes of Health (NIH) and the National Nuclear Security Administration (NNSA), which is in charge of the nation’s nuclear security, were among the victims. So were the Department of Homeland Security (DHS), the Cybersecurity and Infrastructure Security Agency, the Transportation Security Administration, Customs and Border Protection, and the Federal Emergency Management Agency, among many others.
Even before then, some members in Congress were threatening to pull Microsoft contracts if it didn’t improve security. At one point Sens. Eric Schmitt (R-MO) and Ron Wyden (D-OR) sent a threatening letter to the Pentagon requesting it not increase its use of Microsoft products.
“We write with serious concern that the Department of Defense (DoD) is doubling down on a failed strategy of increasing its dependence on Microsoft at a time when Congress and the administration are reviewing concerning cybersecurity lapses that led to a massive hack of senior US officials’ communications,” the letter said, in part.
Nothing happened as a result of the hack or the letter. But that could change in a heartbeat if there’s another big attack. It seems inevitable that hackers will start taking advantage of how quickly Mythos discovers security holes and bugs, especially if Microsoft doesn’t fix them all.
The next big hack, powered by AI, could prove very dangerous — not just for businesses and governments, but for Microsoft as well.
Meta’s local AI model prompts enterprises to rethink hardware-software cost trade-off
Meta rolled out a new 30-billion-parameter AI model optimized to run on a PC or Mac with a single GPU on Monday, offering a way to run always-on agentic workflows locally rather than relying on the cloud.
The company has dubbed it Muse Glimmer. However, its hardware demands, including a GPU with a minimum of 24GB of VRAM, could make it difficult to justify for deployment at scale.
Although analysts and consultants agree that there is a tremendous enterprise appetite for running models locally, determining whether switching more systems from cloud to local makes fiscal sense is much more complex.
The hardware costs are tricky to calculate even today, with the VRAM needed depending on the particular applications to be run. But the far bigger consideration is that there is no way to determine what RAM costs will look like over the next 12-18 months, and there is an identical lack of visibility into how cloud prices might increase during the same timeframe.
That makes determining the better financial choice impossible.
Agents become capex, not opexNoah Kenney, principal consultant at Digital 520, noted that since RAM costs have increased “exponentially” over the last 12 months, cloud AI providers are also going to have to increase their prices. Beyond that, IT needs to anticipate logistical issues; key questions to ask are, “How quickly can you scale? Can you even get the hardware?”
“Meta just made agents a capital expense instead of an operating one,” Kenney said. “For two years, enterprises have been trained to rent intelligence by the token from someone else’s data center. Muse Glimmer runs the agent on a GPU you own, on the desk, with the meter switched off. That is a direct shot at the business model that cloud AI vendors are built on, and it comes from the one player with no cloud API revenue to protect.”
In its post announcing the new model, Meta pointed out that it has aggressively slimmed it down to try to make it efficient and cost-effective.
“At full precision, a 30-billion parameter model would require over 55 GB of memory — far more than any consumer GPU offers,” Meta said. “We use quantization techniques to compress the model’s weights to approximately 4-bit precision, shrinking the language model to under 20 GB. This leaves enough headroom for the model’s working memory, its KV cache, the perception encoder for image understanding, and the speculative decoding drafter to run simultaneously within a 24 GB or 32 GB envelope. We validated that this compression introduces minimal to no degradation on agentic tasks.”
More options for enterprisesMike Wilkes, enterprise CISO at Aikido Security, said that Meta’s move is significant in that it starts to give enterprises more options.
“The most important thing about Muse Glimmer is not that Meta has produced another capable model, it is that the economics and architecture of AI are beginning to move back toward the edge,” he said. “The financial comparison therefore becomes capital expenditure that can be amortized over several years versus an effectively perpetual per-token or per-request cloud operating expense.”
That means, he said, that an enterprise may rationally pay somewhat more for hardware if doing so gives it predictable AI costs, offline availability, control over model versions, freedom from sudden API pricing or access changes.
Independent cybersecurity and risk advisor Steven Eric Fisher also noted that the specs published by Meta don’t tell the full story.
The problem is that running locally versus in the cloud can generate a lengthy list of related expenses.
“Agentic workloads [in the cloud] can amplify consumption through reasoning, retries, tool calls, context growth, and evaluation, while local deployment [also] introduces hardware, power, lifecycle, support, and utilization costs,” he said, adding that even the RAM requirements need a lot of context.
“Meta’s stated 24GB and 32GB memory targets demonstrate that Glimmer can be loaded and executed on comparatively accessible hardware, but that is not the same as having sufficient capacity for meaningful agentic workloads,” Fisher said, pointing out that once other factors are considered, practical memory requirements can move beyond the 32 GB available on an Nvidia RTX 5090 GPU.
“In enterprise terms, this still places Glimmer primarily in high-end developer, data science, or dedicated AI workstations rather than the standard corporate desktop or laptop,” he said.
Better ROI not guaranteedJustin Greis, CEO of consulting firm Acceligence, agreed.
“I wouldn’t assume that moving inference from the cloud to the endpoint automatically produces a lower total cost of ownership,” he said, noting that variable cloud costs would be traded for the price of deployment, endpoint management, support, security, model updates, and potentially accelerated hardware refresh cycles for the local devices.
“Muse Glimmer is an important milestone because it makes local agentic AI technically viable. But technical viability and enterprise ROI are two different milestones,” Greis said. “I think Meta has crossed the first one. I do not think they have fully crossed the second one yet.”
However, Kenney argued that there are also other elements of the Meta rollout that make meaningful comparisons difficult.
“It is worth remembering that the local model is quantized, compressed to roughly 4-bit precision, while the cloud APIs you are comparing against typically serve full-precision models, so this is not a pure apples-to-apples cost comparison,” he said. “The ROI question is not local versus cloud on price alone. It is also a question of whether a company is willing to use a quantized model for the specific task. A cheaper agent that needs more retries or human correction can erase its savings fast.”
In addition, a local model often neglects to include every service that a cloud provider typically delivers.
“The cloud vendor was quietly handling updates, scaling, reliability, and security patching across your whole footprint. Bring the model in-house and every one of those becomes your problem, multiplied by every machine running it,” Kenney noted. “Most enterprises that consume AI as a service have no muscle for operating a fleet of local models, and that cost rarely gets adequate consideration in ROI conversations. The GPU is cheap. Patching a thousand of them is not.”
Sanchit Vir Gogia, chief analyst at Greyhound Research, also stressed that it can be difficult for IT to comprehensively anticipate the different cost variables.
“Finance leaders are right to feel skeptical. An engine bought for one employee burns capital whether or not it runs. Meta has shown that a thirty-billion-parameter agent can run on a single machine, and that is a real engineering result. What it has not shown is that such an agent works reliably at enterprise scale, or that a fleet of them can be operated safely. Model fit and production fit are different claims. A laptop must still run the employee’s actual job,” Gogia said. “The economics turn on the incremental hardware premium, refresh timing and actual utilization, measured against the price of the remote inference being displaced.”
On the other hand, Arun Chandrasekaran, a distinguished VP analyst with Gartner, said that he found it “very interesting that they have decided to release a smaller model that operates on the edge” and especially liked Meta’s use of the popular Apache license. But he would have preferred that they had released more than just a model.
“Enterprise customers are asking for a car and Meta is delivering an engine,” Chandrasekaran said. “They should have built something more like a platform solution.”
Today’s AI hype-fest is partially IT’s fault
I came across a LinkedIn post the other day that described “hypegineering,” which the poster explained refers to the moment when AI “marketing becomes more innovative than the technology itself.”
That post came from Ralph Aboujaoude Diaz, the global head of GRC for British consumer services company Haleon. Until last year, Diaz worked in operations cybersecurity for consumer goods giant Philip Morris.
In his post, Diaz added that “side effects may include believing mediocre tech is revolutionary, confusing hype with progress, buying solutions to problems you don’t have and defending it like your job depends on it.”
As amusing as that might seem, the problem is frighteningly real. The sad truth is that enterprise IT executives are partly — perhaps mostly — to blame for the current hype around AI.
For many decades, senior IT leaders (pre-dating when it was called MIS) were the technology hype-deflators with razor-shape BS detection skills. That level of skepticism was needed. Tech vendors have always exaggerated and left out critical context when they weren’t outright lying about their products.
Enterprises trusted the IT gate-keepers to ferret out reality from the smoke and mirrors.
But there was a critical difference back then: senior management (especially CEOs, CFOs and board members) didn’t pay much attention to tech. They wanted the benefits, but they left the details to IT management to sort things out. With senior managers, benign neglect can be an incredibly good thing.
As much as we might all think that we want our bosses to really care about our efforts, be careful what you wish for. (For Dilbert fans, think of the pointy-haired boss; a boss who has strong beliefs but no understanding of technology is a nightmare.)
Alas, that is the situation many enterprises find themselves in today. IT management fully understands the level of absurd hype coming from a multitude of AI players. But unlike years and technologies past (RFID? NFC? Biometrics?), deflating hype balloons is easier when it’s comes solely from vendors. When senior managers start spouting this garbage, IT’s hype-deflation ability morphs into contradicting the very people at the top of their own corporate food chain.
That forces IT leaders who want to stay gainfully employed to do a lot of what used to be called lying. “Well, boss, yes these agentic systems have guardrails that will block destruction,” the lie begins, “but we can’t anticipate what any user or attacker might say in a prompt.”
That’s far more corporate acceptable than the actual truth: “Boss, a guardrail that an agent can disregard isn’t a guardrail. It’s more of a mild suggestion.”
Or IT could say, “Well, yes, boss, autonomous agents could exponentially increase efficiency — as long as you’re OK with the risk that they might send our internal data to the competition.”
For the sake of the company, tech leaders and decision-makers need to reassert themselves and perform serious reality checks on all AI efforts. But this is more fraught than merely contradicting a top boss. IT could be seen as embarrassing that top boss by pretty much proving that they were either naive or ignorant enough to be conned by the hype.
Telling them they’re wrong seems nicer than calling them stupid. And yet, someone in IT has to find a politically palatable way to do both.
Apple’s real memory problem isn’t cost, it’s supply
Apple continues work to get White House go-ahead to source memory from Chinese supplier CXMT, which the US government has placed restrictions on.
For Apple, the issue comes down to simple math. With the cost of making iPhones up 38% because of eye-watering memory price increases — up almost 7-fold since the beginning of 2025 — it makes sense to make pragmatic choices when it comes to sourcing supply, particularly when other computer companies (including HP and Acer) already obtain memory from CXMT.
US resistance to the plan is that because of the way Apple packages memory on chip, the use of that memory might partly contravene the technology transfer restrictions the US has in place. Note: use of off-the-shelf components is fine.
Apple has been lobbying to use memory from the supplier only on devices made and sold in China and would likely argue this is reasonable given that both HP and Acer already use CXMT memory in products sold outside the US.
Why it’s really about supplyThe iPhone maker’s dilemma isn’t just about memory price, it’s also about ensuring it has enough component supply to satisfy demand for its products. This is plausibly a bigger challenge for the company, which is already warning of constrained supply because of lack of available memory. Samsung, Micron, and SK Hynix have allegedly already sold through all their DRAM production for 2027, which only sharpens Apple’s case to secure alternate sources.
With that in mind, it matters that China consumes around 20% of all Apple hardware sold globally. All the company needs is the go-ahead to use RAM from CXMT in those Chinese-made, China-sold devices.
That alone would effectively grow its usable memory supply by the same amount, because the non-restricted memory it currently has to use in Chinese-market products could be freed up for devices sold elsewhere, with CXMT covering the China-sold units instead.
With demand for its products accelerating —even amid a broad industry downturn — Apple really wants to make sure it has enough of the component to meet demand. Those powerful, on-premises 1.5TB RAM-equipped M7 Ultra Mac Studio AI clusters won’t exist unless it’s possible to find memory to put inside them.
The timeline challengeThe proposed arrangement with CXMT might not be a quick fix. Recent reporting indicated the company has already reached its production capacity for 2026, though it is working to double capacity by 2028. Apple has already tested memory chips from the company across products including iPhones and MacBooks.
While Apple this year has applied steep price increases across all its products (except for iPhones), it is now expected to increase the cost of the current iPhone 17 models perhaps as soon as this week.
Market reports already warn that Apple will raise prices on its soon-to-debut iPhone 18 Pro and iPhone Ultra devices next month, and we expect availability to be constrained, once again as a result of RAM shortages. Even if Apple gets the go-ahead to work with CXMT to close the gap, the positive impact of that arrangement is unlikely to kick in before next year.
Enjoy the painElsewhere, big memory manufacturers, including SK Hynix, have announced plans to invest in new DRAM manufacturing capacity. But this will not be operational until 2029, at the earliest.
This suggests constrained product availability and higher prices for the coming months — and the only way Apple, or anyone else, will be able to limit the impact of those price increases across the entire electronics industry will be if they can obtain additional stocks of memory from vendors outside the big three. If they cannot, you can kiss the age of abundance goodbye.
You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to The Core.
Tech sector adds jobs, defies overall US job market decline
While the number of US jobs declined by 23,000 in July, employment in the tech sector rebounded as the AI revolution continues to gain steam.
The national unemployment numbers were reported Friday by the US Bureau of Labor Statistics. At the same time, research firms said July was a good month for IT hiring compared to June.
According to CompTIA, which analyzed the BLS data, tech sector jobs rose in July by 3,700. In June, the IT sector had lost 900 jobs.
Companies last month hired in the cloud, hosting, information processing, data, and semiconductor manufacturing sectors, CompTIA said in a statement.
“We’re entering a labor market where opportunity is increasingly concentrated around specific skills, industries, and investments,” said Ger Doyle, regional president of North America at ManpowerGroup, a labor consulting firm.
For example, data center hiring was up 39% in July compared to the same period last year, Doyle said. Not surprisingly, the data-center growth has been fueled by AI infrastructure needs and demand for hardware. That has helped increase the number of jobs in ancillary sectors such as transportation.
July hiring data showed heavy truck driver demand, which surged by 181% from June, Doyle said.
According to the BLS data, employment went up by 2.4% in the “computing infrastructure providers, data processing, web hosting, and related services” sectors, which is listed under the information sector.
Jobs in the “computer and electronic product manufacturing” sector — which is bunched under manufacturing — rose by 2.9% from June to July.
But bad news continued for the telecommunications sector, where the number of jobs declined by 1.5% from June to July. That continued a downward slide in recent years.
Overall job layoffs slowed in July, with 33,429 cuts announced; that’s down from 45,849 cuts announced in June, and the lowest since July 2024, according to data from Challenger, Gray and Christmas.
“Hiring has also increased over last year by 25%, so while AI is shifting the labor market, it is not dismantling it,” said Andy Challenger, chief revenue officer for Challenger, Gray & Christmas.
The tech sector announced 9,867 cuts in July, bringing the year-to-date total to 149,023 so far in 2026, according to Challenger figures.
Tech sector hiring and job losses vary as organizations use different measurement techniques to gauge the overall hiring environment.
The top-line US unemployment rate declined to 4.1% from 4.2%, in part because of workers leaving the workforce or not looking for jobs, indicating a slow labor market.
Still, hiring demand exists across the US, despite declining labor force participation and longer job searches, Doyle said.
Because technology underpins many of the changes occurring across sectors such as healthcare and services, employers are rethinking hiring. “That’s why the labor market many workers are experiencing doesn’t always match the one described by the headline numbers,” Doyle said.
ADP’s National Employment report said only 44,000 jobs were added to private payrolls in July, with choppiness across sectors.
But demand for AI skills continues to rise, according to research firms that track growth by analyzing job listings. CompTIA noted that about 14,000 new job listings in July sought AI and machine learning skills.
It’s not clear how the ongoing AI boom may be hurting or helping human jobs. Many recent job cuts have been attributed to AI, though some companies have been accused of using the technology as a rationale for cuts they made for other reasons.
A recent OECD report said that even manual jobs once thought immune to AI are at risk of being taken over by robots. The OECD report said creative jobs — typically management, arts, and social work — will be least threatened by AI.
There are also increasing indications that successful AI deployments will require humans in the loop. For example, more consulting firms are using forward-deployed engineers (FDEs) to implement agentic AI. And smaller consultancy firms are finding more productivity by automating mundane work with AI and spending more time meeting client requirements.
Polish data center plans to send its waste heat to the neighbors
As Europe swelters in a heatwave, residents probably don’t want to hear about ways to make their homes even hotter, but that’s what Polish property developer Citylink is talking about, with plans to dump waste heat from a new data center in Wrocław into the municipal district heating network.
Citylink is designing the data center so that heat from servers can be recovered instead of being dissipated via cooling systems — and as the data center grows, any increase in computing power will mean more energy available for recovery.
The collaboration with local power company Kogeneracja will provide “valuable experience in designing and operating modern data centers, with a particular focus on infrastructure dedicated to AI nodes,” said Michał Starybrat, development director at Citylink.
“The dynamic growth of the artificial intelligence and cloud technology markets generates unprecedented demand for computing power, this collaboration demonstrates how modern digital infrastructure can actively contribute to building the energy ecosystem of the future,” he added.
This type of initiative is not new. There have been similar projects in the UK and in New Zealand, but with warnings that data centers are contributing to the warming of the planet, there may well be a lot more organizations looking to deploy that excess heat more fruitfully in the future.
However, announcing it during a heatwave may not be the most politically sensitive approach to take.
This article first appeared on Network World.
Airtable joins Evernote, Brightcove, WeTransfer and AOL in Bending Spoons portfolio
Bending Spoons has snapped up Airtable to add to its portfolio of software companies, alongside AOL, Evernote, WeTransfer, Brightcove and Vimeo
Airtable made its name as a builder of low/no code database services, aimed particularly at non-technical staff, but is now one of many vendors facing financial difficulties in the face of the SaaS/AIpocalypse. The arrival of AI coding tools, which offer non-technical employees more flexible ways to build business applications, has hit demand for its services.
Bending Spoons bought Airtable in a deal it valued at just $1.285 billion, a far cry from the $11.7 billion Airtable was worth at its peak.
Bending Spoons has built its portfolio by buying once-successful companies like Airtable that have struggled to cope with newer, nimbler competitors or failed to adapt to emerging technologies. Bending Spoons takes these companies, cuts costs and markets them aggressively with the goal of returning them to profitability.
“Airtable is a pioneering brand reshaping how teams organize data and manage critical workflows. We’re committed to investing in Airtable for the long run, and doubling down on its core strength: bringing teams and workflows together in one flexible workspace. We plan to expand what can be done across the full spectrum of work and make Airtable even more valuable to customers at every scale,” said Luca Ferrari, Bending Spoons CEO and co-founder.
This article first appeared on InfoWorld.
Wispr moves beyond AI dictation with note-taking assistant
Wispr, the startup behind dictation tool Wispr Flow, has created an AI note-taking assistant that records meetings and generates conversation summaries for users.
The Wispr Flow Notetaker tool “captures your meetings so you can stop splitting your attention between listening and writing things down,” said Sahaj Garja, Wispr CTO and co-founder.
Notetaker starts recording with one click, and doesn’t require a bot to attend a video or voice call. It can also be used to capture in-person conversations.
The software has three key functions. Before a call, Notetaker displays a meeting brief with information such as meeting purpose and background of participants.
Once the meeting starts, a live transcript displays the dialogue text and labels speakers. A “what did I miss?” button provides a summary of talking points from the previous few minutes.
Finally, post-meeting, Notetaker generates a more detailed summary organized by topic that includes information such as key dates, decisions, and next steps. Users can search across notes from previous meetings in the Notetaker app. “Over time your meeting history stops being a folder of documents you have to go find and becomes something you can ask questions of,” said Garja.
Notetaker integrates with AI assistants such as Anthropic’s Claude and OpenAI’s ChatGPT via model context protocol. This allows users to connect outputs such as transcripts and summaries “into how you already work, instead of sitting in a separate app,” said Garja.
With Notetaker, Wispr competes in an increasingly busy market for AI note-taking apps that includes Fireflies, Granola and Otter.
Wispr claims Notetaker can produce more accurate transcripts than existing tools, partly because of the additional context it uses during transcription. It uses the same personal dictionary from Wispr Flow that includes acronyms, products, and preferred spellings, and can also draw on other sources such as calendar information to understand the purpose of a meeting and help ensure speakers are labelled correctly.
Before generating the final summary, Notetaker also re-reads the live meeting transcript and combines it with additional context to create a more accurate final output, Garja said.
Notetaker is the first new product launched by Wispr, which was founded in 2021 and has since raised $81 million in funding.
“We didn’t set out to build a dictation app,” said Garja. “The mission has always been to reshape how people interact with their devices, and dictation was the fastest way in.”
“Notetaker is the second product on that path. Dictation took the keyboard out of writing. Notetaker takes it out of meetings, so nobody has to spend the call typing up what everyone just said.”
User consent when recording callsAs AI note-taking tools have become more prevalent in the workplace, privacy concerns have arisen, including the need for all-party consent when recording a call in some jurisdictions, and whether meeting audio is used to train AI models. Two software vendors, Otter and Granola, currently face separate lawsuits in California that allege privacy law violations related to their products.
Wispr Flow Notetaker captures audio locally on a user’s device rather than joining the call as a visible bot. That means there’s no notification to signal that a conversation is being transcribed, which places responsibility on users to disclose the recording to others on the call in accordance with local laws, said Garja.
“Users should always let the other person know before you start recording or transcribing a conversation, whether it’s a video call, an in-person meeting, or a phone call,” he said, adding that Wispr intends to build additional features for automated consent messaging “in the coming weeks.”
Wispr doesn’t train its AI models on customer data without consent, though free and standard tier customers must choose to opt-out, according to Wispr’s privacy terms. Nor does it create “voiceprints or biometric profiles” of users or anyone else on a call using audio recording data, the company says.
When Notetaker is active, conversation audio is captured on a user’s device and processed on cloud servers to enable transcription. The recorded audio file is encrypted and stored temporarily on the user’s device or cloud storage, Wispr said. After a limited period, the audio is automatically deleted.
Notetaker is available with the Wispr Flow macOS app to free and paid subscribers, with support for Windows “coming soon.”
- 1
- 2
- 3
- 4
- 5
- následující ›
- poslední »



