Computerworld.com [Hacking News]

Syndikovat obsah
Making technology work for business
Aktualizace: 7 min 36 sek zpět

Microsoft’s Patch Tuesday updates: Keeping up with the latest fixes

17 Červenec, 2026 - 19:47

Long before Taco Tuesday became part of the pop-culture vernacular, Tuesdays were synonymous with security — and for anyone in the tech world, they still are.  Patch Tuesday, as you most likely know, refers to the day each month when Microsoft releases security updates and patches for its software products — everything from Windows to Office to SQL Server, developer tools to browsers.

The practice, which happens on the second Tuesday of the month, was initiated to streamline the patch distribution process and make it easier for users and IT system administrators to manage updates.  Like tacos, Patch Tuesday is here to stay.

In a blog post celebrating the 20th anniversary of Patch Tuesday, the Microsoft Security Response Center wrote: “The concept of Patch Tuesday was conceived and implemented in 2003. Before this unified approach, our security updates were sporadic, posing significant challenges for IT professionals and organizations in deploying critical patches in a timely manner.”

Patch Tuesday will continue to be an “important part of our strategy to keep users secure,” Microsoft said, adding that it’s now an important part of the cybersecurity industry.  As a case in point, Adobe, among others, follows a similar patch cadence.

Patch Tuesday coverage has also long been a staple of Computerworld’s commitment to provide critical information to the IT industry. That’s why we’ve gathered together this collection of recent patches, a rolling list we’ll keep updated each month.

In case you missed a recent Patch Tuesday announcement, here are the latest six months of updates.

July’s Patch Tuesday sees an end-of-support collision amidst a massive, record-setting patch wave

Microsoft addressed 722 CVEs this month once the 427 Chromium upstream relays are set aside — roughly three times a normal cycle and one of the largest single months in recent memory. Two vulnerabilities arrive under active exploitation: an elevation of privilege in Active Directory Federation Services (CVE-2026-56155), and an elevation of privilege in SharePoint Server (CVE-2026-56164). A third, a BitLocker security feature bypass (CVE-2026-50661) is publicly disclosed but not yet exploited.

The July 2026 Patch Tuesday earns Patch Now recommendations for Windows, Office, Exchange, and SQL Server. SharePoint has two critical RCEs on top of its exploited zero-day, and Exchange Server returns with a critical on-premises spoofing flaw. Adding to our (dear) administrator’s efforts, SharePoint Server 2016/2019 and SQL Server 2016 all reach end of support today. The Readiness team has provided a handy infographic of the expected risk profile of this month’s Patch Tuesday updates.

More info is available here on Microsoft Security updates for July 2026.

For June, Patch Tuesday means an IT scramble

Microsoft this month released 206 updates affecting Windows, Office, Exchange Server, and its developer tools — including three Windows vulnerabilities already publicly disclosed. That trio includes an elevation of privilege in the Collaborative Translation Framework (CVE-2026-45586), a denial of service in HTTP.sys (CVE-2026-49160), and a BitLocker security feature bypass (CVE-2026-50507). At the moment, none appear to be under active exploitation, but all three are rated “Exploitation More Likely.” 

Even without an exploited zero-day, the June 2026 Patch Tuesday release requires Patch Now recommendations for Windows, Office, and Exchange. The latter is back in the patch picture with a consolidated security update that Microsoft recommends installing “as soon as possible.”

More info is available here on Microsoft Security updates for June 2026.

For May, Patch Tuesday means 139 updates — but no zero-days

Microsoft this month released 139 updates affecting Windows, Office, .NET, and SQL Server (though there were no updates for Microsoft Exchange Server). Despite the absence of zero-days, the May Patch Tuesday update still requires Patch Now recommendations for Windows and Office. 

The combination of three unauthenticated network RCEs (Netlogon, DNS Client, and SSO Plugin for Jira and Confluence), four Word Preview Pane RCEs, the large TCP/IP vulnerability cluster, and the carry-over BitLocker recovery condition (still active on Windows 10 and Windows Server) warrants an accelerated deployment release schedule. 

More info is available here on Microsoft Security updates for May 2026.

Microsoft’s Patch Tuesday release for April is a whopper

Windows admins are going to be busy this month, dealing with the largest Patch Tuesday cycle in memory. The April release involves 165 updates and roughly 340 unique CVEs from Microsoft — including two zero-days, one of which is already being actively exploited in the wild. 

The Readiness team recommends “Patch Now” schedules for nearly every major product family: Windows, Office (with a zero-day), Microsoft Edge (Chromium), SQL Server, and Microsoft Developer Tools (.NET). April also brings Phase 2 of Microsoft’s Kerberos RC4 hardening with full enforcement set for July. There is a lot to cover, so here’s a useful infographic mapping the deployment risk for each platform.

More info is available here on Microsoft Security updates for April 2026.

For March, Patch Tuesday delivers fixes for 83 vulnerabilities

Microsoft’s March Patch Tuesday release addresses 83 vulnerabilities across Windows, Office, SQL Server, Azure, and .NET — with two publicly disclosed zero-days affecting SQL Server and .NET (though neither is being actively exploited in the wild.) Six additional vulnerabilities spanning the Windows KernelGraphics ComponentSMB ServerAccessibility Infrastructure, and Winlogon are flagged as “Exploitation More Likely.”

The most significant change this month is the introduction of Common Log File System (CLFS) hardening with signature verification, which will affect how Windows handles log files across the operating system. More info on Microsoft Security updates for March 2026.

February’s Patch Tuesday release fixes 59 flaws, including 6 being exploited

The company’s Patch Tuesday release for February addresses 59 CVEs across the company’s product family — roughly half the volume of January’s 159 patches. Six vulnerabilities, affecting Windows Shell, MSHTML, Desktop Window Manager, Remote Desktop, Remote Access, and Microsoft Word, are already being actively exploited. (All five Critical-rated CVEs target Azureservices rather than Windows, however.) 

Both Windows and Office get a “Patch Now” recommendation, with CISA setting a March 3 enforcement deadline for all six exploited vulnerabilities. Two new enforcement timelines also take effect in April: Kerberos RC4 deprecation (CVE-2026-20833) and Windows Deployment Services hardening (CVE-2026-0386). More info on Microsoft Security updates for February 2026.

Kategorie: Hacking & Security

OnlyFans performers become unlikely allies of CISOs in securing websites

17 Červenec, 2026 - 19:37

CISOs at government organizations and universities have an unexpected ally coming to their aid: OnlyFans models.

For some time, hackers have exploited weaknesses in the websites of universities or government departments to host scams or malware, using content stolen from the OnlyFans website as bait to attract victims.

Now, according to security researchers at Upguard, the fightback has begun: creators of adult content on OnlyFans are leveraging Google search results and the protection offered by copyright law to break up the traffic distribution systems created by bad actors.

These distribution systems work in three stages: entry points using adult or other content to attract and capture web traffic, a routing system sends it to destination sites, and those sites monetize the traffic through scams and malware. It has proved to be a lucrative business for the scammers.

Google recognizes the approach and calls such actors SEO parasites as they benefit from the reputations of other organizations — in particular government or academic sites, which Google views as having high authority.

Since the creators of OnlyFans content are also the copyright holders, they are able to issue Digital Millennium Copyright Act (DMCA) take-down notices for the stolen content posted by the bad actors to other sites. Upguard was able to track this through Google’s DMCA Transparency Report, and through the Lumen Database, another tracker of takedown notices, to which it was granted research access.

“This allows us to identify likely compromised sites: government and university domains advertising unlicensed adult content,” Upguard said.

The OnlyFans creators’ action has two benefits for the operators of the affected websites: The adult content associated with their domain disappears from Google search results, no longer affecting their reputation — and if they receive takedown notices for such content they can check their webservers for the vulnerabilities that enabled the bad actors to post it there in the first place.

This article first appeared on CSO.

Kategorie: Hacking & Security

OpenAI’s new hardware is a $230, 13-switch keyboard for Codex

17 Červenec, 2026 - 19:07

OpenAI is selling its first hardware — without any help from Jony Ive. It describes the Codex Micro as a “command center for agentic work” but it’s really a 13-switch wireless keyboard customized to help developers keep tabs on what their Codex agents are doing. It costs $230.

The keyboard has 13 mechanical switches (one keycap covers two of them by default), a rotary encoder, joystick, and RGB backlighting around the whole keypad and individual keys. It comes with 32 customizable icon keycaps.

OpenAI claims that the Codex Micro is a serious business tool: The command keys enable Codex users accept changes, reject outputs, push-to-talk, start new chats, and trigger custom actions. The rotary encoder can be used to dial up the “brainpower” allocated to tasks — or in more conventional terms, how many tokens to allocate to reasoning on a task. And the RGB lighting can provide feedback on how various tasks are progressing. And the RGB lighting under the “agent” keys can provide feedback on how various tasks are progressing.

The Codex Micro’s manufacturer, Work Louder, already has a similar device on the market, the Creator Micro, which offers similar functionality, but without the colorful keys. It costs $56 less than the Codex Micro, however.

The Codex Micro will fit in snugly with OpenAI’s other merchandise, where using Codex is as much about a fashion statement as a technological choice.

This article first appeared on InfoWorld.

Kategorie: Hacking & Security

July’s Patch Tuesday sees an end-of-support collision amidst a massive, record-setting patch wave

17 Červenec, 2026 - 18:00

Microsoft addressed 722 CVEs this month once the 427 Chromium upstream relays are set aside — roughly three times a normal cycle and one of the largest single months in recent memory. Two vulnerabilities arrive under active exploitation: an elevation of privilege in Active Directory Federation Services (CVE-2026-56155), and an elevation of privilege in SharePoint Server (CVE-2026-56164). A third, a BitLocker security feature bypass (CVE-2026-50661) is publicly disclosed but not yet exploited.

The July 2026 Patch Tuesday earns Patch Now recommendations for Windows, Office, Exchange, and SQL Server. SharePoint has two critical RCEs on top of its exploited zero-day, and Exchange Server returns with a critical on-premises spoofing flaw. Adding to our (dear) administrator’s efforts, SharePoint Server 2016/2019 and SQL Server 2016 all reach end of support today. The Readiness team has provided a handy infographic of the expected risk profile of this month’s Patch Tuesday updates.

(More information about recent Patch Tuesday releases is available here.)

Known issues

The July release note flags known issues against the following updates:

  • BitLocker recovery prompt on first restart – the PCR7 recovery condition tracked since April remains live on the platforms that did not receive the Boot Manager servicing fix (Windows Server 2022 and Windows 10 22H2). Devices with BitLocker on the OS drive, the Group Policy “Configure TPM platform validation profile for native UEFI firmware configurations” set with PCR7 included, and Secure Boot State PCR7 Binding reported as “Not Possible” may be prompted for the recovery key on the first restart after installing this update. This month’s publicly disclosed BitLocker security feature bypass (CVE-2026-50661) keeps the component in focus.
  • WSUS synchronization error details suppressed (Windows Server 2025 and 2022) – WSUS no longer displays synchronization error details in its error reporting, a deliberate change made to address the Remote Code Execution Vulnerability CVE-2025-59287. Sync still works, but administrators triaging a failed synchronization lose the detail pane and must fall back to the SoftwareDistribution logs.

Windows Update can still replace manually installed graphics drivers with older OEM versions from the catalogue (the four-part Hardware ID ranking issue acknowledged on the Hardware Dev Center). The two-part HWID pilot runs to September 2026.

Major revisions and mitigations

Between the June and July Patch Tuesdays, MSRC Security Update Guide notices updated 651 reported CVEs across six notification dates (15, 19, 26 June and 3, 8, 11 July), 532 of them routine Chromium upstream re-publications. Of the roughly 30 Microsoft revisions, almost all were cross-platform Office catch-up with no bearing on a Windows enterprise estate. No further action required for IT administrators for this Windows update cycle.

Windows lifecycle and enforcement updates

This is the deadline cycle June pointed at. The July end-of-support wave lands today, and it collides with the month’s heaviest patching. SharePoint and SQL Server take some of their most active security updates ever on platforms receiving their last.

  • SharePoint Server 2016 and 2019, Project Server 2016 and 2019, SQL Server 2016 and InfoPath 2013 have all reached end of support. SQL Server 2014 ESU Year 2 reaches end of support today. SharePoint 2016/2019 take an actively exploited zero-day and two RCEs this cycle, and SQL Server 2016 takes a critical RCE, all as their final security update. Now is the time to get moving on updating these platforms.

The 2011 Secure Boot certificate expiries have now passed; devices that never took the Windows UEFI CA 2023 key updates under CVE-2023-24932 can no longer receive updated boot components, with the Windows Production PCA for the boot manager still ahead on 19 October 2026. Kerberos RC4 hardening (CVE-2026-20833) has been in enforcement since April 2026; the July 2026 update removes the RC4DefaultDisablementPhase rollback control that let administrators defer it, making enforcement final.

Microsoft’s July 2026 Patch Tuesday is a security-only release: 180 test-guidance entries, 14 of them high risk (June had one). Printing and graphics are the centre of gravity: win32kfull.sys, the kernel-mode window manager, is the most-patched binary (14 entries), and seven high-risk flags sit alongside it – the Print Spooler, four win32k entries, and two GDI+ metafile entries. NTFS is the second theme, with 10 entries, two high risk. Every entry reports no functional changes – it’s pure regression validation. The packages span Windows 11 26H1 back to Server 2012 ESU.

Printing and graphics (high risk)

The Print Spooler flag centres on shared printers, whose queue status must track jobs accurately; the win32k flags cover 32-bit application printing, font rendering in printed and exported output, on-screen rendering, and window management; the GDI+ flags cover metafiles.

  • Share a printer from a print server, print from a separate client in varied sizes and formats, and cancel a job, confirming the queue reflects every state change
  • Print from your 32-bit applications, and print text-heavy, graphics-heavy, and multi-page documents to physical and virtual (PDF or XPS) printers, repeating after orientation, scaling, and resolution changes
  • Export documents with varied fonts to PDF and confirm fonts and layout survive; render EMF+ files that apply effects to very large images, and convert EMF files to WMF
  • Open and close windows rapidly, drive common dialogs by mouse and keyboard, and close parents with children open – no orphaned windows
Storage and file systems (high risk)

Both NTFS high-risk flags target integrity – extended attributes, and volume recovery after an unexpected shutdown. File History carries its own high-risk flag on clients. A Windows Server 2025-only bundle across boot, BitLocker, and ReFS demands the full Secure Boot/BitLocker matrix. Eight entries hit Server 2025 alone, including WSL, GPU partitioning, and a scripted Windows Server Backup pass repeating recovery after rolling the date 90 days forward.

  • Exercise NTFS extended attributes – older-system EAs, backup workflows that preserve them, concurrent same-file operations where supported – with antivirus, encryption, or storage filters active
  • Simulate an unexpected shutdown during file activity, verify the volume mounts intact, run chkdsk, and confirm indexing, shadow copies, and backup still work
  • Run a full File History pass: back up, modify and back up again, exclude folders, change frequency, move the destination
  • On Server 2025, boot all four Secure Boot/BitLocker combinations, in standard and confidential VMs where supported
Devices, input and networking (high risk)

Three further high-risk flags land here: HID input (hidparse.sys with win32k) – touch, keyboard, mouse, touchpad, through disconnects and restarts; the WinSock bundle (afd.sys plus Bluetooth and multicast drivers); and IrDA. The heaviest ask is not high risk at all: the NetAdapterCx driver (24H2/25H2, Server 2025) wants 500-plus adapter enable-disable cycles under Driver Verifier.

  • Run the connectivity suite: browsing, large downloads, mapped drives, an RDP session idle 30+ minutes, a Teams call, an hour of streaming, and localhost apps such as Docker or WSL
  • Stress Bluetooth: pairing, 10+ minutes of audio, input after idle, and reconnection after sleep
  • Where infrared hardware exists, transfer a file and run at least 100 connect-disconnect cycles
  • Sweep the rest: DNS Server (zone data must stay under its configured database directory), the client resolver (five entries), DHCP Server (five entries), SMB, NFS, Message Queuing (five entries), RRAS administration, client VPN, and WinHTTP/WinINet consumers
Other windows components

Windows Installer itself is patched: testing should include application install, uninstall, repair, and force a rollback. Hyper-V wants virtual-switch traffic as part of its testing exercises with Virtual Filtering Platform policies enforced. Sixteen media-related security entries cover playback, HEVC and MPEG-TS, USB audio, and MIDI 2.0.

Shell hardening and LSA isolation

These two entries are a little different from the rest of the cycle: they ask you to confirm a security behaviour actively works, not just that nothing regressed. A pass here means the protection fired, so treat them as functional checks rather than box-ticking.

  • Shortcut handling (windows.storage.dll; Windows 11 23H2 and earlier, plus Server 2022): drop a shortcut file carrying the Mark of the Web into a folder and confirm the system refuses to extract its icon and leaks no NTLM credential hash – include the zero-click paths, where the icon would otherwise render without you opening anything
  • LSA isolation and KeyGuard (24H2/25H2, Server 2025): run the supplied PowerShell validation script, which turns on Virtualization-based Security if it isn’t already, exercises KeyGuard key operations in both required and best-effort isolation modes, and reports pass or fail – it needs TPM 2.0, UEFI with Secure Boot disabled, and PowerShell 7
  • Run that script on a dedicated test machine, never a shared one: it enables test signing, disables automatic updates, and reboots without asking
Office & SharePoint

July’s Office wave is security-only; everything landed on 14 July, and nothing critical or non-security shipped in the 7 July preview. It’s an MSI-only cycle, so Click-to-Run estates can sit this one out.

  • On MSI Office 2016, apply the client updates – Excel (KB5002886), Word (KB5002890), PowerPoint (KB5002867), and five further Office 2016 security updates (KB5002273, KB5002887, KB5002748, KB5002857, KB5002830) – then exercise macros, external data, embedded objects, and any line-of-business add-ins
  • On SharePoint Server, patch 2016 (KB5002891, plus the KB5002892 language pack) and Subscription Edition (KB5002882), then check browser-based editing; the guidance lists SharePoint 2019 with a baseline but ships no 2019 package, so there is nothing to install there

Mind the rollback rules before you schedule the window: most client updates can be uninstalled, but the server updates cannot and always require a reboot.

Developer tools & databases

The developer estate gets a broad but low-drama sweep this month. Both .NET and SQL Server patch widely, but the ask is representative-application validation rather than anything exotic – install on the matching branch and confirm normal behaviour.

  • .NET: install the SDK updates (8.0.423, 9.0.316, 10.0.302, x64 and x86) and the Framework rollups spanning 3.5 through 4.8.1 – which reach from Windows Server 2012 up to Windows 11 26H1 and Server 2025 – then run a representative set of applications and confirm they function normally
  • SQL Server: the GDR updates span 2016 SP3 through 2025 – install each on its matching branch and test that each removes cleanly
  • Check an encrypted client connection through the separately patched Windows SQL client (dbnetlib.dll), which ships outside the server branches

The Readiness team recommends the following priorities for your larger enterprise deployments:

  • Start with printing and graphics: half the high-risk flags sit in the Print Spooler, win32k, and GDI+, so regress shared printers, 32-bit printing, PDF export, metafiles, and window management before anything else
  • Take NTFS next – extended attributes and crash recovery both touch data integrity – and add a client File History backup-and-restore pass
  • Give Server 2025 its wider matrix – the Secure Boot/BitLocker combinations, WSL, GPU partitioning, and the scripted backup pass – and work through the stress suites
  • Run the scripted KeyGuard validation on any VBS estate, preferably on a dedicated machine.

Each month, we break down the update cycle into product families (as defined by Microsoft) with the following basic groupings:

  • Browsers (Microsoft IE and Edge)
  • Microsoft Windows (both desktop and server)
  • Microsoft Office
  • Microsoft Exchange and SQL Server
  • Microsoft Developer Tools (Visual Studio and .NET)
  • Adobe (if you get this far)
Browsers

Edge has had a busier month than usual. Microsoft addressed 46 Microsoft Edge (Chromium-based) CVEs this cycle. None critical, but heavily weighted to remote code execution (21 entries) and spoofing (13), led by CVE-2026-58289, a remote code execution flaw. A run of further RCEs (CVE-2026-57981, CVE-2026-56645, CVE-2026-57974) follows.

  • Microsoft Edge – the Edge-specific fixes ship in the Edge stable channel (version 150.0.4078.65, released 9 July). The concentration of RCE and spoofing this month is worth a look for managed Edge estates rather than a routine wave-through.
  • Chromium upstream – 427 CVEs relayed through MSRC this cycle, spanning the weekly Chrome release cadence since the June report: use-after-free, out-of-bounds read/write, type confusion, and inappropriate-implementation flaws across V8, Dawn, ANGLE, Skia, and Tint. The same fixes ship in the Chrome Stable channel; see the Chrome releases blog for the upstream notes.

The Chromium volume looks (quite) alarming but is routine plumbing: it flows to Edge through its own auto-update channel. Add these browser (Edge) updates to your standard release schedule for your managed environments.

Microsoft Windows

Windows carries the bulk of this month’s updates: 406 CVEs, 31 rated critical and 374 important. Elevation of privilege dominates by volume (226 entries), followed by remote code execution (70), information disclosure (70), denial of service (23), and a scatter of security-feature-bypass, tampering, and spoofing entries across the following feature groupings:

The Windows Kernel is the most-patched component (28 CVEs, seven “More Likely”), followed by NTFS (21), Windows Runtime (17), Windows Media (14), ReFS (12), and Win32k (15 across its two entries). Add this Windows update to your Patch Now deployment schedule.

Microsoft Office

Microsoft released 96 Office CVEs this month: 19 critical, 76 important. Remote code execution leads (53 entries), ahead of information disclosure (27) and spoofing (10). SharePoint is the centre of gravity: it touches 39 of the 96 CVEs and supplies the family’s one actively exploited flaw.

  • SharePoint Server: has been exploited (who would have guessed) and reaches end of support today. CVE-2026-56164, an elevation of privilege, is under active exploitation. Above it sit two critical remote code execution flaws, both “Exploitation More Likely” (CVE-2026-50522, CVE-2026-58644) and a critical security feature bypass (CVE-2026-55040). SharePoint Server 2016 and 2019 reach end of support on 14 July, so this exploited, critical-heavy set is the final security update those on-premises farms will receive.
  • Office has experienced a long run of critical remote code execution entries across Office, Word, and PowerPoint (among them CVE-2026-55033 and CVE-2026-55127 in Word, CVE-2026-55043 in PowerPoint, and CVE-2026-55018 in Office), topped by CVE-2026-55045.

With an exploited zero-day, two RCEs, and an end-of-support deadline all landing on SharePoint in the same cycle, SharePoint environments are the priority. Add the July Office and SharePoint updates to your Patch Now schedule.

Microsoft Exchange and SQL Server

Both Exchange and SQL Server carry critical-rated security vulnerabilities this month. Exchange Server returns with an on-premises security update for Exchange Server Subscription Edition, the only on-premises release still supported after Exchange Server 2016 and 2019 reached end of support in October 2025; SQL Server takes two critical remote code execution flaws, one of them against SQL Server 2016, which reaches end of support on the same day.

  • Exchange Server (on-premises) – CVE-2026-55008, a spoofing vulnerability rated critical and “Exploitation More Likely,” is the headline. Behind it, a remote code execution entry (CVE-2026-55005) and two elevation-of-privilege flaws (CVE-2026-55006, CVE-2026-55009) round out the on-premises set. A separate Exchange Online elevation of privilege (CVE-2026-54998, critical) is fixed service-side with no customer action.
  • SQL Server – two critical remote code execution flaws: CVE-2026-54117 (SQL Server 2025) and CVE-2026-54118 (which reaches back to SQL Server 2016 SP3), with five further important elevation-of-privilege and information-disclosure entries behind them. The 2016 exposure matters because SQL Server 2016 reaches end of support on 14 July: a critical RCE on a platform taking its final update.

Both belong on the Patch Now schedule this month: the Exchange on-premises update for its critical spoofing flaw, and the SQL Server update for the two critical RCEs.

Microsoft developer tools

Microsoft released 24 CVEs across its developer tooling this month, all rated important. The weighting shifts from last month’s Visual Studio Code concentration toward .NET and ASP.NET Core, where a run of denial-of-service entries dominates the volume:

Add these Microsoft updates to your standard developer update release schedule.

Adobe (and third-party updates)

Outside Microsoft’s own catalogue, July is quiet. Adobe issued no Acrobat or Reader security updates. So, the month belongs to Microsoft, and it is a heavy one: 722 CVEs, roughly three times a normal cycle and one of the largest on record. Worth noting that this lands in the same season Microsoft has been talking up AI-assisted vulnerability management, and the AI stack it is selling as the answer, Copilot and Azure OpenAI among them, sits in the centre of this patch cycle’s own critical-rated updates. The (AI) tooling may be getting smarter, but the patch pile is (definitely) not getting smaller. This may be the beginning of an accelerating curve of ever larger patch cycles. My feeling is that we are in the middle of the beginning of this coming patch surge.

This article is published as part of the Foundry Expert Contributor Network.
Want to join?

Kategorie: Hacking & Security

Google must open Android to rival AI agents, EU orders

17 Červenec, 2026 - 16:36

The European Union is stepping up its actions against US tech giants under the Digital Markets Act, which is intended to ensure fair competition between digital platforms. On Thursday, the European Commission issued two rulings to limit Google’s dominance.

The Commission ordered Google to open up the Android operating system to AI assistants other than its own Gemini, ensuring that they had the same access to applications and operating system services. A second ruling ordered Google to share search data that only it is big enough to collect with other search engines.

Google has hit back at the measures, warning that they could create security issues for users. “Today’s decisions risk undermining vital privacy and security guardrails for millions of Europeans. We have repeatedly offered solutions to safeguard users while satisfying the DMA’s goals, but these rulings discount extensive evidence of user harm,” said Kent Walker, Google’s President of Global Affairs, in a company blog post.

The EU move doesn’t just cause problems for Google but for CISOs as well, warned Roman Stanek, CEO of Good Data AI. “Enterprise security has always leaned on a simple assumption, that apps are boxes, and the OS decides what crosses the box. But once multiple agents get equal system-level reach, access to screen context, cross-app actions, background execution, that assumption breaks.

“CISOs need to stop treating ‘AI assistant’ as a single, well-understood permission and start treating it as a category risk, one they have to govern like they govern app stores and MDM policies today. That requires device policies that name which agents can hold system-level permissions, not just which apps are installed. It means DLP and conditional access rules that account for an agent reading and acting on data, not just an app requesting it.,” he said.

Kategorie: Hacking & Security

AI OK in Linux development, says Torvalds

17 Červenec, 2026 - 16:10

Linus Torvalds has a complicated relationship with AI, seeing both its good and bad points. But his latest remarks on the usefulness of AI may have raised a few eyebrows in open-source circles.

Just a few weeks after the Linux founder complained that a “continued flood” of AI-generated vulnerability reports had made the Linux kernel security mailing list “almost entirely unmanageable”, he has come to see the advantages of the technology.

“Linux is not one of those anti-AI projects,” Torvalds wrote in an email response to Linux Kernel senior engineer Roman Gushchin, archived at Kernel.org.

“It can also be a somewhat painful tool, both for maintainer workloads and just from a ‘it keeps finding embarrassing bugs’ standpoint,” he said of the use of AI in security scanning. “The solution is to make sure those LLM tools help maintainers instead of just causing them pain.”

Developers should be free to choose whether they use AI, he said. “We’re not forcing anybody to use it, but I will very loudly ignore people who try to argue against other people from using it.”

Torvalds’ measured support for AI does not come completely out of the blue: Around the same time that he was complaining about AI distorting security maintenance, he also spoke about its usefulness, claiming that it could improve programmer productivity by a factor of 10.

This article first appeared on InfoWorld.

Kategorie: Hacking & Security

Apple widens OpenAI trade secrets fight with preservation orders

17 Červenec, 2026 - 15:28

Dozens of former Apple employees now working at OpenAI have been put on notice after Apple reportedly sent legal letters ordering them to preserve documents and communications relevant to its trade secrets lawsuit against OpenAI. 

The Financial Times reports that “around 40” employees have been targeted with these letters, which repeat Apple’s claim that its confidential information might have been exfiltrated, alleging “trade secret misappropriation and breach of contract.”  The letters also require them to arrange to meet with Apple’s lawyers.

The underlying lawsuit

This comes on the heels of Apple’s explosive lawsuit against OpenAI in which Apple accused the AI company (and former Apple Vice President Tang Tan) of extensive coordinated data theft. Tan was at Apple for 24 years and is now Chief Hardware Officer at OpenAI. 

Apple’s lawsuit is defined by claims OpenAI took a range of steps to pry confidential Apple data from existing Apple employees, including using information such as internal project code names, to gain even more knowledge during interviews. The company says the evidence it has presented so far is only the “tip of the iceberg” concerning OpenAI’s approach.

The lawsuit requests that OpenAI be prevented from using any Apple information during the development of its hardware. Apple is also seeking damages and suing two former employees for breach of contract for violating their employment agreements.

The letters are significant. They represent formal directives that require former Apple staff to preserve documents, messages, emails, and other communications that could be relevant to the case. The demand reflects Apple’s belief that the alleged misuse of confidential information could be more widespread across the competing company. What’s critical is that orders of this kind override any standard data destruction policy and deletion of the requested information becomes a legal offense. 

Why this matters beyond the protagonists

In making its move, Apple shows this is not a dispute about just one or two hires, but an attempt to constrain the movement of intellectual property between the two firms. With AI hardware emerging as the next major battleground in tech, the case could become a defining one; whatever resolution is eventually reached could define the extent to which former employees can carry experience and knowledge between competing firms. The case might also define what the line is between experience and knowledge and the sharing of trade secrets.

This is important, because modern hardware development relies on far more than just finished designs. Product design leans into supplier relationships, manufacturing assumptions, physics, extensive prototyping, and product-roadmap priorities. If courts treat those accumulated insights as protectable secrets, hiring between major technology companies could become far more legally sensitive.

The Jony Ive question

The case comes as Apple prepares to combat OpenAI in hardware. Its competitor is now working with legendary former Apple designer Jony Ive. Ive is not named in the litigation, but Apple will be keen to find out whether confidential product knowledge, design processes, or supply-chain insights have travelled with former staff into OpenAI’s device work.

Ultimately, for Apple, it’s about protecting its many blueprints for whatever hardware the company expects will come after the iPhone.

For its part, OpenAI has refuted Apple’s lawsuit, arguing that it is “not aware of any evidence” that the lawsuit has merit. “We have no interest in other companies’ trade secrets,” said OpenAI spokesperson Drew Pusateri. “We remain focused on building innovative technology that empowers people everywhere.” The company’s lawyers also claim it did respond to Apple’s initial inquiries on the matter.

What’s at stake

The significance of Apple’s newly-shared communication preservation orders is that if discovery uncovers evidence supporting Apple’s claims, the case could complicate OpenAI’s hardware plans and create unwelcome scrutiny ahead of any future public offering.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

China, Russia, and 27 others create World AI body, without US

17 Červenec, 2026 - 15:18

China has created an international organization to set standards and introduce regulation for AI, inviting 28 other countries to join — but the US, a leading AI powerhouse is not part it.

The World Artificial Intelligence Cooperation Organization (WAICO) was established by 29 countries, including China, Russia and Brazil, at a ceremony in Shanghai, China, on July 16. Notably absent are the US, the European Union and its member states, the UK, Japan and South Korea.

Chinese AI companies have made a concerted effort to provide an alternative to US dominance. While the US is clearly ahead, Chinese enterprises are looking to narrow the gap in various areas: the open-weight model market, AI cyber protection and open source AI.

WAICO has been some years in development and has been designed to set some universal guidelines in AI. Researchers say WAICO differs in three ways from other initiatives to create global AI organizations: membership open to any sovereign state, there is no regime-type test for entry, and its agenda is built around development and the global capability divide.

The signing ceremony to create WAICO comes just days after Demis Hassabis, CEO of Google DeepMind, called on the US to take a lead in global AI regulation. “The US is well-positioned to take the first step in developing such a framework. It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organization, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives,” Hassabis wrote.

Kategorie: Hacking & Security

It’s past time to end AI-based automated customer responses

17 Červenec, 2026 - 13:00

An automated chatbot working for Anthropic this month shot down a Wiz researcher’s security hole report, saying that it “falls outside of the Claude Code threat model.” That was news to the security researchers at Wiz

It also turned out to be news to Anthropic execs, who had a very different view. 

In reality, Anthropic was one of many victims of the hole — including Amazon, Google and Cursor, among others. But what makes the incident so bizarre is that, far from dismissing the threat, Anthropic had detected it before the security researchers and had even patched it before the researchers alerted them. 

As these AI bots are wont to do, the bot didn’t merely reject the request. It confidently explained its rationale, even though its reasoning was wrong. 

“This falls outside our current threat model,” the chatbot said, according to a report by Wiz. “When the user first starts Claude Code in a directory, they must confirm that they trust the directory prior to starting the session. The scenario you describe involves a user explicitly confirming a permission prompt inside of a directory containing a malicious symlink, which falls outside of the Claude Code threat model.”

That researchers said Anthropic management later clarified the situation: “The symlink warning in the Edit/Write permission dialog shipped in v2.1.32 (Feb 5, 2026), nine days before this report was submitted to us. It was added as part of proactive security hardening based on internal review. The decline to comment was an autoreply from our triage system.” 

An autoreply from our triage system? How many other make-believe replies did this system send? And what level of damage is Anthropic exposing itself to? 

This is not just an Anthropic issue. There have been numerous enterprise bot glitches in communications  with customers. Some of my favorites include:

  • Bots that chose on their own to cancel customers. (This actually was another Anthropic incident.) In this case, an Anthropic bot cancelled the AI account of a Swiss company that depended on the service. A lawyer got involved and the account was restored within a day — minus 80% of the data. Oops.
  • A Cursor bot decided to log customers off when they switched devices, which it shouldn’t have done. The bot then emailed customers and lied that, “The logouts were expected behavior under a new login policy.” A Fortune story detailed how “the news spread rapidly in the developer community, leading to reports of users cancelling their subscriptions, while some complained about the lack of transparency. Cofounder Michael Truell finally posted on Reddit acknowledging the ‘incorrect response from a front-line AI support bot’ and said it was investigating a bug that logged users out. ‘Apologies about the confusion here,’ he wrote.”
  • Voters in Scottish elections were tricked by government AI bots that “variously invented fictitious scandals, gave the wrong date for the election, claimed wrongly that voters in Scottish elections needed ID at polling stations and placed candidates in the wrong contests.”
  • And let’s not forge the classic story about the Air Canada bot, where “Air Canada was ordered to compensate a customer after its chatbot gave incorrect information about the airline’s bereavement fare policy. The tribunal found that Air Canada was responsible for information provided through its website, including the chatbot.”

Let’s be clear, here: Bots should be limited to relaying only pre-approved scripts. 

Generative AI allows for far greater chatbot sophistication, but that also means the chance of far greater errors. This is untenable in any business function. And when the app is pretending to be a human — and interacting with human customers — it’s even more unacceptable.

Kategorie: Hacking & Security

Is Apple bringing chip manufacturing home?

16 Červenec, 2026 - 19:59

Apple’s recently announced $30 billion multi-year agreement with Broadcom is significant because it means billions of chips for Apple devices will be made in the US, supporting hundreds of jobs. 

This is Apple’s biggest US procurement deal so far, but it won’t be the last; when it announced the arrangement, Apple confirmed it is, “working with the administration and businesses across the US to help create an end-to-end silicon supply chain in America.”

That statement implies that the 15 billion chips Broadcom will produce won’t be the only processors in Apple devices to carry tiny little “Made in the USA” slogans. Broadcom is making custom silicon components and wireless connectivity technologies such as RF/wireless chips (Wi-Fi, Bluetooth, cellular, FBAR filters) and ASIC work, rather than application processors. But they are still chips for Apple devices.

TSMC doubles down

That’s why it is significant that TSMC confirmed plans to extend its own manufacturing in America. It already has a $165 billion US commitment; now, it is investing an additional $100 billion in four more chip plants — including one dedicated to churning out the company’s most advanced 2nm (and smaller) processors. 

“We believe this investment will help to further foster the development of the US semiconductor ecosystem, strengthen the supply chain, and support an increasing number of high-tech, high-paying jobs in the United States,”  CEO C.C. Wei told analysts.

TSMC has also confirmed plans to invest in packaging facilities for processors, which is basically the process where memory, processor, and networking nodes can all be combined and packaged on the chip. That sort of packaging is needed to make the final SoC chip. That means TSMC factories in the US will be able to churn out the advanced processors used in Apple’s current and, presumably, future devices.

The bill so far

That’s three investments — in processor manufacturing, packaging, and Broadcom radios and chips — all of which are strategically important to Apple devices. TSMC makes the brains, Broadcom brings the connectivity. Total value so far: $295 billion, around 1.5 times Apple’s annual revenue in the Americas.

It isn’t all about Apple. TSMC has other clients, and Apple is no longer the company’s biggest customer thanks to the drive to AI. But it is still an important one. That means at least some of TSMC’s newly invested US manufacturing capacity will be dedicated to making chips for Apple. The open question is how much US-manufactured chips will cost in contrast to those made elsewhere.

It’s bigger than two deals

These aren’t the only chip-focused partnerships Apple has made domestically. Apple’s American Manufacturing Program (AMP) launched in August 2025 as part of a $600 billion four-year US investment commitment. TSMC and Broadcom were both named AMP partners, but they weren’t alone, and some arrangements have already been announced:

  • GlobalFoundries is bringing mixed-signal chip manufacturing to make advanced ICs for Face ID.
  • Texas Instruments expanded production for analog/power chips.
  • Samsung is making a new chip-making process at its Austin, TX fab, described by Apple as having “never been used before anywhere in the world.”
  • Apple became the “first and largest customer” of Amkor’s new advanced packaging/test facility in Arizona.
  • Corning is expanding glass production.
  • Applied Materials is making chip manufacturing equipment under AMP.

Bundle all these deals together and it’s crystal clear that Apple’s $600 billion investment is at least in part focused on the technologically advanced components on which its devices are built. These components also have the advantage in being incredibly small, which means they are easy and cheap to ship for final assembly at increasingly automated final production locations worldwide. 

So, is it coming home?

That’s the strategy: keep the high-value, hard-to-automate work — and the jobs it requires — in America, while leaving final assembly flexible enough to go wherever that makes sense now or in the future. Is Apple bringing manufacturing home? Partially, in that the bits that matter the most — brains and networking— are coming back, even if assembly is not.

You can follow me on social media! Join me on BlueSkyLinkedInMastodon, and subscribe to the human-curated daily Apple news briefing at The Core.

Kategorie: Hacking & Security

Zoom patches account takeover hole

16 Červenec, 2026 - 19:21

Zoom has identified, and patched, a critical security hole that “may allow an unauthenticated user to conduct an account takeover via network access.”

The issue is especially significant given Zoom’s extensive reach; it reportedly has more than 300 million daily active users, including 470,000 paying business customers. Given that reach, Zoom has been impacted by many other security incidents and France recently tried banning its use by French government users

 Zoom security bulletins released Tuesday revealed the bug, and three other security issues, which Zoom patched on Wednesday. 

The company originally said that the takeover issue impacted Zoom Desktop Client for Windows before version 7.0.0, Zoom VDI Client for Windows before version 7.0.10 and 6.6.15 and 6.5.18 in their respective branches, and Zoom Meeting SDK for Windows, but on Wednesday, without explanation, it removed Meeting SDK for Windows as an affected product.

The other three holes were less severe, but still significant, and they all involved privilege escalation. They impacted Zoom Workplace for Windows before version 7.0.5, Zoom Workplace VDI Client for Windows before 6.5.17 and 6.6.14 in their respective branches, Zoom Workplace VDI plugin for Windows before 6.5.17 and 6.6.14 in their respective branches, Zoom Rooms for Windows before 7.0.5 and Remote Control for Zoom Contact Center for Windows before version 7.0.0.

A second privilege escalation issue impacted Zoom Rooms for Windows before version 7.1.0, and another impacted Zoom Workplace VDI Plugin for Windows before version 6.6.14.

Zoom did not immediately reply to a request for comment.

‘As bad as it gets’

Frank Dickson, group VP for security at IDC, said the nature of the reported hole is alarming.

This bug “is about as bad as it gets, short of a worm. It is exploitable over the network, low complexity, zero privileges required, no user interaction needed,” he said, pointing out that exploitation is easy once technical details leak or someone reverse-engineers the patch, which is not as challenging as it once was, thanks to AI. “Yesterday’s script kiddies have been empowered,” he said.

Dickson said the only good news is that Zoom discovered the hole itself, and that “no in-the-wild exploitation has been reported by any outlet as of Thursday.”

Consultant Brian Levine, executive director of FormerGov, agreed with Dickson’s characterization of the hole, but said a potentially bigger issue is the high level of sensitive data that Zoom accesses. 

“An attacker with unfettered access to a Zoom account may be able to listen to recordings of sensitive meetings, to eavesdrop on future meetings, and to impersonate the organization in an effort to social engineer its clients and partners. Thus, given that ubiquity of Zoom in large enterprises, this vulnerability is pretty concerning,” Levine said.

He’s encouraged, however, that Zoom found the flaw itself, which indicates its security team is “actually doing the hard, unglamorous work of auditing its code.”

Giuseppe Trotta, principal security researcher at Malwarebytes, has a theory about what was behind the Zoom disclosure. 

“Because the vulnerability requires zero privileges and absolutely no user interaction, the remote network attack vector is highly suspected to involve the mishandling of deep links, such as custom URL schemes like zoommtg:// or zoomworkplace://,” he said. This led him to think that if the Zoom Workplace client for Windows fails to properly sanitize and validate incoming arguments passed via these special browser-to-desktop links, an unauthenticated attacker could craft a malicious string that could trick the desktop application into exposing or redirecting the user’s active session tokens directly to an attacker-controlled server, achieving a seamless and completely silent account takeover.

“Watch out for Zoom links and invites if you are on Windows or VDI and haven’t updated yet,” he advised.

Mike Wilkes, enterprise CISO at Aikido Security, offered kudos to Zoom for discovering the critical flaw, but he wanted to know how such a severe bug got into its software initially.

“This vulnerability raises questions about why the defect was not caught by design review, fuzzing, or pre-release abuse-case testing,” Wilkes said. “A historical defect in Zoom’s product/security relationship has been prioritizing ease of use over security risk.”

All four bugs important

Justin Greis, CEO of consulting firm Acceligence, said that the two types of holes reported by Zoom, account takeover and escalation, are both important, but for different reasons. 

“The critical vulnerability is significant because it has the characteristics security teams worry about most,” Greis said, but the privilege escalation holes “are certainly important to patch as they primarily increase the impact of an attack that has already begun. The critical vulnerability has the potential to be an initial entry point, which is why it deserves the most attention.”

Greis also applauded Zoom’s response, saying that it “reflects a reasonably mature security program.”

He pointed out that no complex software platform will eliminate vulnerabilities entirely. “The differentiator is whether vendors are continuously investing in offensive testing, finding weaknesses before attackers do, and moving quickly to develop and distribute fixes,” he said.

Kategorie: Hacking & Security

DeepMind CEO pushes for AI industry self-regulation

16 Červenec, 2026 - 14:30

Google DeepMind CEO Demis Hassabis is pushing for the US AI industry to self-regulate, with the support of government, as a starting point for an international creating shared international standards. In a blog post, he called for a focus on artificial general intelligence (AGI) and national security. 

But it is precisely that focus on national security that may make the results of such an effort, assuming it happens, less than palatable outside of the US.

“The rapid progress we’re seeing in AI requires a new approach to testing frontier AI model capabilities that is dynamic, adaptable, and rigorous,” Hassabis wrote. “The US is well positioned, given its economic and technical standing, to take the first step in developing such a framework. It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organization, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives.”

He noted, however, that the funding would need to be substantial, and would most likely come from industry, to allow the new body to attract world-class technical talent and obtain the necessary compute resources for large-scale testing.

Hassabis proposed that the organization “be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security,” and that AI vendor participants be encouraged to adopt best practices such as publishing model cards with technical details, maintaining strong internal cybersecurity, vetting key personnel, and providing sufficient resourcing for safety and security research.

This is not the first time Hassabis has expressed worries about AGI

DeepMind was involved in an earlier US government initiative evaluating AI safety, alongside Microsoft and xAI (now SpaceXAI) working with the Center for AI Standards and Innovation (CAISI), a division of the US Department of Commerce. It allowed CAISI to conduct pre-deployment evaluations and targeted research to “better assess frontier AI capabilities and advance the state of AI security.”  

The rest of the world may have concerns

Analysts and consultants were mixed about the move, with most expressing concerns about whether an industry-focused group would prioritize the public’s best interests.

“Self-regulation is not viable because it implies everyone is able to regulate themselves and will do so in line with the best interests of the public. Most tech vendors don’t have the capacity to self-regulate. They would just prefer a set of rules within which they can operate,” said Gartner VP analyst Nader Henein. “For-profit organizations are required to do what is best for their shareholders, and external regulation ensures that those organizations are never in a conflict of interest where they have to choose between what is good for their shareholders and what is good for the public.”

And, said Sanchit Vir Gogia, chief analyst at Greyhound Research, given the international nature of AI models, an effort coordinated by the US government might alienate other countries. 

“National security is the proposal’s accelerator in Washington and its poison pill abroad: the framing that opens the only gate available at home invites foreign capitals to read the institution as an instrument of American strategy,” he pointed out.

“The map is already plural,” he said. “Brussels switches on enforcement powers over general-purpose models [starting in August 2026], London runs the AI Security Institute, and Beijing licenses on its own terms. California and New York have legislated for frontier models at home. The durable route is shared technical evidence with sovereign enforcement, sealed through mutual recognition rather than deference, with India and the other major non-Western markets holding authorship rather than seats.”

Gogia added that the rules enacted by even such a group may not address all of the key concerns of enterprise IT. A US government effort along the lines that Hassabis is proposing would result in testing that “sits close to intelligence and industrial policy, and those functions will not stay neatly separated. A model can pass every catastrophic-risk test and still fail the enterprise on privacy, reliability, and liability,” he noted.

Walmart’s former director of cybersecurity Steven Eric Fisher, who is now an independent cybersecurity consultant, said he found the proposal “well-intentioned, but it addresses a highly polarized topic at a time when commercial interests carry unprecedented political influence, which is not always applied benevolently.”

He added, “an exclusive US standard that is not globally respected or enforceable would likely fail to achieve its core purpose and would place US companies at a competitive disadvantage.”

Aman Mahapatra, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that a deep dive into how FINRA operates today is illustrative of what IT leaders can expect from this effort, assuming the industry adopts that model.

“When the CEOs of the five companies that would be regulated are also the primary drafters of the standards, the standards will reflect those companies’ interests. FINRA has an independent board, but the operational reality is that member firm perspectives dominate the working groups that write the actual rules,” he said. “There is no reason to expect an AI equivalent to work differently, and every reason to expect it to work worse, because AI standardization is happening faster than any industry has ever attempted to standardize itself, and speed is the enemy of independent oversight.”

Carmi Levy, an independent technology analyst, was even more emphatically opposed to the Hassabis proposal.

“Asking Big Tech companies to self-police is analogous to allowing foxes to guard the henhouse. It hasn’t worked to date, and it won’t work going forward. Expecting these organizations to somehow change their ways at this point in time represents the height of naïve thinking,” Levy said. “The framework proposed by Demis Hassabis is a self-serving roadmap for an industry bent on racing to the AI horizon regardless of the harms caused along the way. It is impossible to quantify the dangers to broader society should frameworks allowing self-regulation become the norm.”

Some love the proposal

An almost completely opposite stance came from Yuri Goryunov, CIO of consulting firm Acceligence, who applauded the proposed move.

“This is one of the rare setups where industry self-regulation has a real shot, and enterprise IT should be enthusiastically rooting for it,” he said. “It fails when harms are externalized, such as in social media content moderation. Or when the overseer outsources judgment to the overseen, such as the FAA’s delegation to Boeing before the 737 MAX. It works when everyone in the industry shares the catastrophic downside.”

He suggested, however, that the best precedent here isn’t FINRA, it’s INPO, the Institute of Nuclear Power Operations, which the nuclear industry created within months of the 1979 Three Mile Island partial reactor meltdown “on the logic that an accident anywhere is an accident everywhere. INPO peer-reviews every US plant, its evaluations move insurance premiums, and it sits on top of the NRC’s statutory floor. That is a public-private stack very close to what Hassabis is describing. Frontier AI has the same structure: one lab’s catastrophic failure brings regulation down on all of them.”

For enterprise CIOs and other IT executives, Goryunov said, that model has the potential for being a big win.

Today, every enterprise duplicates the same AI diligence of red-teaming, eval suites, governance committees and each does so with less information than any certifying body would have,” Goryunov said. “A credible standards regime does for AI what UL did for electrical equipment and SOC2 did for cloud: it converts an unknowable risk into a procurable product and gives boards a defensible standard of care. That’s not red tape. That’s peace of mind with an audit trail.”

However, Mahapatra said, “the countervailing view is that the alternative to industry-led standards is probably not thoughtful legislation. It is probably no standards, or state-by-state fragmentation, or the current pattern of ex-post enforcement actions where regulators surface concerns years after harm has already occurred.”

Thus, he noted, “Hassabis is making the reasonable argument that imperfect fast standards are better than perfect slow ones, and there is genuine merit to that view for topics like agent identity, evaluation methodology, and interoperability, which are exactly the areas OpenClaw is also targeting.”

This article first appeared on CIO.

Kategorie: Hacking & Security

CISA urges immediate SharePoint hardening as exploits mount

16 Červenec, 2026 - 14:27

The US Cybersecurity and Infrastructure Security Agency (CISA) has urged organizations to immediately secure Microsoft SharePoint deployments after warning that three vulnerabilities affecting the on-premises collaboration platform are being actively exploited.

A recent advisory from the federal cybersecurity watchdog asked administrators to patch vulnerable servers, review Microsoft’s mitigation guidance, and assume that internet-facing SharePoint instances remain attractive targets for attackers seeking an initial foothold into enterprise environments.

While applying patches remains the immediate priority, security experts caution that organizations should view the advisory as more than another Patch Tuesday exercise.

“This is what separates an IT incident from a business crisis,” said Chris Boehm, field CTO at Zero Networks. “One compromised SharePoint box is a ticket. That same box, with a clear path to your domain controllers, backups, and file shares, is how you end up with an encrypted infrastructure and a disclosure event. Segmentation stops the first from becoming the second.”

CISA’s advisory highlights CVE-2026-332201CVE-2026-45659, and the newly added CVE-2026-56164, all of which have now been confirmed as exploited in the wild and added to the agency’s Known Exploited Vulnerabilities (KEV) catalog.

Exploitation tells a different severity story

The latest addition to CISA’s KEV catalog is CVE-2026-56164, an elevation-of-privilege vulnerability affecting Microsoft SharePoint Server. Although assigned a CVSS score of 5.3, the flaw can be exploited remotely without authentication, making it significantly more dangerous in practice than its severity rating alone suggests.

Microsoft has released security updates for supported SharePoint versions and recommended enabling the Antimalware Scan Interface (AMSI) integration to help detect malicious requests associated with exploitation attempts.

CISA also advised organizations to follow Microsoft’s incident response guidance, hunt for indicators of compromise, and rotate SharePoint machine keys where appropriate, acknowledging that patching alone may not fully remove attacker persistence from already compromised servers.

Older vulnerabilities remain active entry points

Alongside the newly disclosed flaw, CISA reiterated the urgency of addressing CVE-2026-45659, an insecure deserialization vulnerability allowing RCE that Microsoft had marked as “exploitation less likely” in its advisory in May. Another old bug CISA flagged is CVE-2026-32201, an improper input validation flaw that allows spoofing over a network.

Both of these flaws are being actively exploited in the wild.

CISA called out organizations failing to catch up with SharePoint updates, adding that attackers are increasingly targeting N-days rather than relying exclusively on newly discovered zero-days.

On concerns of patching speed, Boehm noted resilience is becoming an architectural challenge as much as an operational one.

“Stop measuring this in patch speed,” he said. “That’s a race you eventually lose. Some of these landed as zero-days with no fix on day one, and the window between disclosure and exploitation keeps shrinking. So the board-level question isn’t whether a server gets compromised. Assume one will. It’s how much of the business a single-owned system can take down with it.”

Boehm argued that limiting network reachability through segmentation should sit alongside patch management and threat hunting as a core defensive strategy. Reachability, he said, is a control that organizations own, not patch timing. CISA has given Federal Civilian Executive Branch (FCEB) agencies three days to remediate CVE-2026-56164 under Binding Operational Directive (BOD) 22-01.

The article originally appeared on CSO.

Kategorie: Hacking & Security

Thinking Machines Lab offers enterprises a US alternative in open-weight AI

16 Červenec, 2026 - 13:08

Thinking Machines Lab, the San Francisco startup founded by former OpenAI CTO Mira Murati, has released Inkling, its first general-purpose AI model. The launch adds another US-developed entrant to an open-weight market where Chinese developers produce several leading coding and reasoning models.

Inkling uses a mixture-of-experts architecture with 975 billion total parameters, of which 41 billion are active during processing. It supports a context window of up to 1 million tokens and was pretrained on 45 trillion tokens spanning text, images, audio, and video. Thinking Machines said it also trained the model for coding, tool use, and multimodal tasks.

The release follows the October 2025 launch of Tinker, Thinking Machines’ first product and an API-based platform for customizing AI models. Developers can fine-tune Inkling through the platform.

In a June 2026 assessment, AI model routing platform OpenRouter highlighted DeepSeek V4 Flash, GLM 5.2, MiniMax M3, and Nvidia Nemotron 3 Ultra as four notable open-weight models. Nemotron was the only US-developed model in the group.

Performance and developer access

Thinking Machines Lab’s benchmark table shows mixed results. Inkling scored 77.6% on SWE-Bench Verified, behind DeepSeek V4 Pro and GLM 5.2 but ahead of Nvidia Nemotron 3 Ultra. It also recorded 74.1% on MCP Atlas, 77.1% on BrowseComp with context management, and 79.8% on IFBench.

Thinking Machines said Inkling’s result used a bash-only harness, while the comparison figures were reported by the competing models’ developers.

The model includes a reasoning-effort setting that developers can adjust from 0.2 to 0.99. Thinking Machines said the setting allows users to balance performance against the number of generated tokens. In the company’s testing, Inkling matched Nemotron 3 Ultra’s Terminal Bench 2.1 score while generating about one-third as many tokens.

Developers can fine-tune Inkling through Tinker using context lengths of 64,000 or 256,000 tokens and test it through the Inkling Playground. The model is available through APIs from Together AI, Fireworks, Modal, Databricks, and Baseten. It is also supported by inference software, including SGLang, vLLM, TokenSpeed, llama.cpp, and Hugging Face Transformers.

Inkling’s full weights are available on Hugging Face as the original checkpoint and as a quantized NVFP4 checkpoint. Thinking Machines also previewed Inkling-Small, which has 276 billion total parameters and 12 billion active parameters. The company said it would release the smaller model’s full weights after completing testing.

Enterprise impact

Inkling’s differentiation lies in its open weights, multimodal capabilities, controllable reasoning, and integration with Tinker, rather than benchmark leadership, according to Biswajeet Mahapatra, principal analyst at Forrester.

“Enterprises are most likely to benefit in workloads where domain adaptation matters more than generic model performance, including knowledge-intensive copilots, multimodal customer service, document understanding, operational workflow automation, and agentic tasks that require organization-specific data, policies, and processes,” Mahapatra said.  

Inkling’s US origin could also influence adoption among Western enterprises, according to Pareekh Jain, CEO of Pareekh Consulting. He said many Western organizations face regulatory or procurement barriers when considering Chinese-developed AI models.

“Inkling gives those organizations a US-developed open-weight option that they can deploy on their own infrastructure,” Jain said.

However, the benefits will need to be weighed against the cost of deploying the full model.

Running Inkling on private infrastructure requires a GPU cluster with at least 2 TB of aggregated VRAM for the BF16 checkpoint, according to the model card. Thinking Machines lists configurations of eight Nvidia B300 GPUs or 16 H200 GPUs. A quantized NVFP4 checkpoint lowers the requirement to at least 600 GB and can run on four B300 GPUs or eight H200 GPUs.

“Because Inkling is a massive model with 975 billion total parameters, running the full model still requires significant GPU infrastructure, making closed-model APIs more economical for many organizations,” Jain said.

Jain said Inkling-Small may be a more feasible option for many enterprises because it could reduce infrastructure costs and latency while retaining useful performance across key workloads.

Safety and governance

Thinking Machines said it trained Inkling for calibration, instruction following, and resistance to censorship. The company said the model showed “strong patterns of censorship non-compliance” when evaluated by Cognition on its Propaganda and Censorship Eval.

Inkling scored 98.6% on StrongREJECT, which Thinking Machines described as a test of whether models refuse unambiguous harmful requests.

The model’s safety behavior should be retested after an enterprise customizes it, according to Jain. “Model fine-tuning can weaken safety filters, so companies should retest safety after customizing the model rather than assuming it stays safe,” Jain said.

He added that self-hosted and modified versions could diverge from Thinking Machines’ official model over time without receiving automatic updates.

“CIOs need to ensure every AI agent action is logged, auditable, and governed by human approval for high-risk tasks,” Jain said.

The article originally appeared on InfoWorld.

Kategorie: Hacking & Security

Anthropic’s ‘free’ Fable offer — a token lock-in trap for users?

16 Červenec, 2026 - 12:15

It’s not so much generosity that’s behind Anthropic’s decision to extend free access to its most advanced model, Fable, for paid subscribers until July 19, analysts say. Its a last-minute move to grab users, data and model evaluation results.

After the free-access period, Anthropic plans to convert Fable to a pay-per-use model, at $10 per million input tokens and a whopping $50 for 1 million output tokens.

That is double the price of its next most advanced model, Opus 4.8, for input and output tokens. “We’re extending Claude Fable 5 access on all paid plans, as well as keeping Claude Code’s weekly rate limits 50% higher, through July 19,” Anthropic’s team said in a July 12 tweet.

Anthropic keeps extending Fable because it does not yet know what its flagship is worth, said Sanchit Vir Gogia, principal analyst at Greyhound Research. “A vendor confident in its price does not move the same cutoff twice in six days, both times at the wire,” Gogia said.

Anthropic is essentially pushing deadlines to test its products, while users gain by being able to put their toughest tasks to Fable, Gogia said.

Anthropic, which did not immediately reply to a request for comment about the situation, has already seen plenty of action with Fable and its sister model Mythos. Both have been touted as the company’s most advanced models yet.

Fable stumbles, then reappears

Fable was officially launched June 9. Just three days later, on June 12, the US government put export controls on it after Amazon researchers bypassed Fable’s safeguards, prompting the model to identify software vulnerabilities and demonstrate an exploit. 

After Anthropic scrambled to address the issues — and after the export controls were lifted — Fable was relaunched July 1.

Fable’s freebie extension comes after OpenAI’s latest model, ChatGPT 5.6 Sol, became generally available July 9. Sol is cheaper at $5 per one million tokens input, and $30 for 1 million output tokens.

Anthropic and OpenAI are competing aggressively to build market share, said Jack Gold, principal analyst at J. Gold Associates. “Anthropic and OpenAI are looking to go public and the more users they have, the more attractive it is — even if they are not yet producing income,” he said.

In some ways, the two companies are following a well-trodden path to get customers hooked on their products and turned into paying customers. That’s what Meta, Google and Microsoft, for instance, have done over the years with various “free” offers that later morphed into paid products. 

Plus, said Gold, ”The more users you have, the better you can train your models across multiple data sets.”

That’s a potential boon for proprietary large language model (LLM) vendors offering free tokens in a bid to lock enterprises and vendors into their AI environments. But numerous experts have warned enterprises not to fall for that tactic. Instead, they argue enterprises should diversify AI development across multiple AI and cloud vendors, and adopt open-source models.

An LLM space race?

According to LLM benchmarks maintained by Artificial Analysis, Fable is the most intelligent model currently available, with Sol just behind it in second place. One benchmark by LiveBench places Sol as being better in reasoning, with Fable better at math, data analysis, instruction following and language. Both models have advantages in coding.

Meanwhile, Cursor and SpaceXAI on July 8 unveiled Grok 4.5, which the companies said can “handle difficult, long-running tasks that require creatively using tools to solve problems, whether in software engineering, data science, finance, legal work, or anything else you do on a computer,” the company said in a blog entry.

Its pricing is even more aggressive than Fable and ChatGPT 5.6 Sol. Grok 4.5 charges $2 for 1 million input tokens and $6 for 1 million output tokens.

There are growing concerns about tokenmaxxing, where enterprises rack up billions of dollars in token spending, blowing past usage limits before finance controls are implemented.

Enterprises might decide to spend more on models such as Mythos and Fable — if the benefits are tangible, said Max Leaming, head of data science and AI solutions at ManpowerGroup. Fable and Mythos may “actually be less expensive to use in spite of the spiked token cost because it’s far more efficient,” he said.

A company might find that the models use fewer tokens, are faster, and can reduce compute time, he said. “Even though the per-token costs may go up, we may see overall costs go down,” Leaming said.

Kategorie: Hacking & Security

Did AI decide who lost their jobs? Meta is heading to court over that question

16 Červenec, 2026 - 03:50

Enterprises that use AI in hiring and firing decisions continue to be under scrutiny, and this time it’s Meta under the microscope.

A legal complaint filed on July 13 in a US District Court in California alleges that Meta used AI systems that unfairly and illegally selected workers for termination while they were out on protected leave.

More than two dozen anonymous plaintiffs are seeking a preliminary injunction that would prevent the company from finalizing their separations or altering their compensation, benefits, or protected leave status.

Meta has countered that the claims lack merit and that its workforce decisions were, and continue to be, made by people, not AI.

An important lesson

These allegations should serve as an important lesson to other businesses using AI in their HR decision-making, analysts note.

“Enterprises must begin by rejecting the convenient assumption that AI improves workforce decisions simply by touching them,” said Sanchit Vir Gogia, chief analyst at Greyhound Research.

There is “scant independent proof” that AI makes layoff choices more accurate or more lawful, he said. “It makes them faster, and faster has never been shown to be fairer.”

The claims against Meta

The complaint states that, on May 20, 2026, Meta began notifying roughly 10% of its workforce (around 8,000 employees) that they had been selected for termination. The company also announced that several thousand more would be reassigned to new AI initiatives. But this came even as Meta reported record revenues in Q1 2026 ($56.31 billion, a 33% year-over-year increase), and pledged to spend upwards of $100 billion on AI this year.

In addition to questioning the need for staff cuts, the filing alleges that Meta used a “constellation” of internal AI systems to score, rank, and select employees for termination. These tools included Meta’s internal AI coworker, “Metamate,” employee-trained “second-brain” agents that replicated their output, algorithms tracking keystrokes and other digital activity, and AI token usage dashboards.

“Meta did not assemble the termination list through the considered judgment of managers who knew the work,” the complaint claims.

The 26 plaintiffs, all current or former employees, requested, took, or were approved for “statutorily protected” leave within 24 months of the workforce reduction, and claim they were “disproportionately selected” for layoff based on scoring that essentially penalized them for exercising their legal right to take leave.

These practices are prohibited by federal and state law; The US Family and Medical Leave Act, for one, prohibits the use of protected leave as a “negative factor” in employment decisions. Further, the plaintiffs allege that Meta violated the US Worker Adjustment and Retraining Notification (WARN) Act that requires employers with 100 or more employees to provide written notice 60 calendar days in advance of mass layoffs.

This notice gives employees reasonable time to seek alternate employment; however, the complaint argues, an employee undergoing “significant medical treatment” or providing “around the clock care” for a “weeks old newborn” or other loved ones “cannot also be told that during this exact same time period they must look for new work.”

In one scenario, according to the filing, a scientist was identified for termination just two days before she gave birth while on pregnancy leave. In another, an engineer’s manager tied his performance rating to “broken time” when an injury prevented him from working. In a third, a researcher was called out after requesting time off following a medical diagnosis.

The plaintiffs are seeking a preliminary injunction pending an independent audit of the “algorithmically assisted selection process” and “resolution of the merits of their claims” in arbitration.

Once terminations are finalized, the harm to plaintiffs “cannot be undone by money damages alone,” the complaint states. For employees out on leave, “every day that goes by constitutes additional harm, in that Meta is taking away the entire purpose of a protected leave.”

Considerations for enterprises

Any system that materially influences who keeps a job is not an HR tool, Gogia noted. “It is high-risk enterprise infrastructure.”

An “AI-determined” process delegates the outcome to the system, while an “AI-assisted” one gives the system the ability to rank, recommend, and summarize, with a human formally making the final decision. Exposure arises in either model, Gogia pointed out, because the output has often been compressed and eliminates detail by the time of executive approval.

There must be one non-negotiable role in the process, Gogia said: A single executive with the authority to halt the process, suspend the model, and delay decisions when evidence does not hold. This person should be “a meaningful reviewer [who] understands the model’s limits, knows the actual work, and holds the authority to challenge the recommendation, with every override visible and reviewable,” he said. At the same time, the objective is to “govern the machine and the manager together,” since human judgement brings its own “risks, favoritism, and proximity” bias.

Gogia advised enterprises to retain fixed memory for auditing, determine who chose the auditor, what was excluded, and whether the result can be reproduced. They should also inventory every source feeding the model and its origins, and run adverse-impact analysis before making any firing decisions.

Leave details must never be identified as inactivity or weak adoption; a protected absence is not ordinary missing data, and the system has to be informed of this. Rather, these circumstances belong in an “independent review lane,” where human reviewers get enough context to “neutralize” the period without receiving specific leave details, Gogia said.

He pointed to another important question: What should the “second brain” AI agent that ingested the employee’s communications and documents to replicate the employee’s output be allowed to do when humans are away, and who owns that output?

Ultimately, said Gogia, “the safest position is not to ban AI from workforce planning. Used with discipline, it can expose duplicated work and inconsistent assessment, and it can challenge human bias rather than automate it.”

How employees can protect their rights

Employees, for their part, need a genuine window in which to challenge inaccurate data before separation becomes “irreversible,” and they should “fight the record, not the algorithm,” Gogia advised.

That means that, while the model cannot explain itself, documented evidence can. Employees should lawfully retain their own reviews, leave approvals, and severance documents, and build a chronology of events: When leave was requested, when performance language changed, when new metrics appeared, Gogia said.

Impacted workers should ask in writing which criteria were used in the decision, whether automated systems materially influenced it, how protected leave was treated, and what information about them influenced the result and how that information was verified.

Further, it’s important to take note of deadlines; the federal discrimination window is typically six months, although that is extended to 10 in many places, and internal processes are “not obliged to respect it,” said Gogia.

His ultimate advice for workers: “Preserve the lawful record, and protect the deadline.”

This article originally appeared on CIO.com.

Kategorie: Hacking & Security

DeepMind CEO again pushes for a frontier AI standards body

15 Červenec, 2026 - 22:59

Google DeepMind CEO Demis Hassabis on Tuesday reiterated his push for an AI industry self-regulation effort, led by the US government, that is particularly focused on artificial general intelligence (AGI) and national security. 

But it is precisely that focus on national security that may make the results of such an effort, assuming it happens, less than palatable outside of the US.

“The rapid progress we’re seeing in AI requires a new approach to testing frontier AI model capabilities that is dynamic, adaptable, and rigorous,” Hassabis wrote. “The US is well positioned, given its economic and technical standing, to take the first step in developing such a framework. It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organization, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives.”

He noted, however, that the funding would need to be substantial, and would most likely come from industry, to allow the new body to attract world-class technical talent and obtain the necessary compute resources for large-scale testing.

Hassabis said he would propose that the organization “be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security,” and that AI vendor participants would be encouraged to adopt best practices, such as publishing model cards with technical details, maintaining strong internal cybersecurity, vetting key personnel, and providing sufficient resourcing for safety and security research.

This is not the first time Hassabis has expressed worries about AGI. He has already worked on a US government initiative evaluating AI safety, which involved DeepMind, Microsoft and xAI (now SpaceXAI) working with the Center for AI Standards and Innovation (CAISI), a division of the US Department of Commerce. It allowed CAISI to conduct pre-deployment evaluations and targeted research to “better assess frontier AI capabilities and advance the state of AI security.”  

The rest of the world may have concerns

Analysts and consultants were mixed about the move, with most expressing concerns about whether an industry-focused group would prioritize the public’s best interests.

“Self-regulation is not viable because it implies everyone is able to regulate themselves and will do so in line with the best interests of the public. Most tech vendors don’t have the capacity to self-regulate. They would just prefer a set of rules within which they can operate,” said Gartner VP analyst Nader Henein. “For-profit organizations are required to do what is best for their shareholders, and external regulation ensures that those organizations are never in a conflict of interest where they have to choose between what is good for their shareholders and what is good for the public.”

And, said Sanchit Vir Gogia, chief analyst at Greyhound Research, given the international nature of AI models, an effort coordinated by the US government might alienate other countries. 

“National security is the proposal’s accelerator in Washington and its poison pill abroad: the framing that opens the only gate available at home invites foreign capitals to read the institution as an instrument of American strategy,” he pointed out.

“The map is already plural,” he said. “Brussels switches on enforcement powers over general-purpose models [starting in August 2026], London runs the AI Security Institute, and Beijing licenses on its own terms. California and New York have legislated for frontier models at home. The durable route is shared technical evidence with sovereign enforcement, sealed through mutual recognition rather than deference, with India and the other major non-Western markets holding authorship rather than seats.”

Gogia added that the rules enacted by even such a group may not address all of the key concerns of enterprise IT. A US government effort along the lines that Hassabis is proposing would result in testing that “sits close to intelligence and industrial policy, and those functions will not stay neatly separated. A model can pass every catastrophic-risk test and still fail the enterprise on privacy, reliability, and liability,” he noted.

Walmart’s former director of cybersecurity Steven Eric Fisher, who is now an independent cybersecurity consultant, said he found the proposal “well-intentioned, but it addresses a highly polarized topic at a time when commercial interests carry unprecedented political influence, which is not always applied benevolently.”

He added, “an exclusive US standard that is not globally respected or enforceable would likely fail to achieve its core purpose and would place US companies at a competitive disadvantage.”

Aman Mahapatra, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that a deep dive into how FINRA operates today is illustrative of what IT leaders can expect from this effort, assuming the industry adopts that model.

“When the CEOs of the five companies that would be regulated are also the primary drafters of the standards, the standards will reflect those companies’ interests. FINRA has an independent board, but the operational reality is that member firm perspectives dominate the working groups that write the actual rules,” he said. “There is no reason to expect an AI equivalent to work differently, and every reason to expect it to work worse, because AI standardization is happening faster than any industry has ever attempted to standardize itself, and speed is the enemy of independent oversight.”

Carmi Levy, an independent technology analyst, was even more emphatically opposed to the Hassabis proposal.

“Asking Big Tech companies to self-police is analogous to allowing foxes to guard the henhouse. It hasn’t worked to date, and it won’t work going forward. Expecting these organizations to somehow change their ways at this point in time represents the height of naïve thinking,” Levy said. “The framework proposed by Demis Hassabis is a self-serving roadmap for an industry bent on racing to the AI horizon regardless of the harms caused along the way. It is impossible to quantify the dangers to broader society should frameworks allowing self-regulation become the norm.”

Some love the proposal

An almost completely opposite stance came from Yuri Goryunov, CIO of consulting firm Acceligence, who applauded the proposed move.

“This is one of the rare setups where industry self-regulation has a real shot, and enterprise IT should be enthusiastically rooting for it,” he said. “It fails when harms are externalized, such as in social media content moderation. Or when the overseer outsources judgment to the overseen, such as the FAA’s delegation to Boeing before the 737 MAX. It works when everyone in the industry shares the catastrophic downside.”

He suggested, however, that the best precedent here isn’t FINRA, it’s INPO, the Institute of Nuclear Power Operations, which the nuclear industry created within months of the 1979 Three Mile Island partial reactor meltdown “on the logic that an accident anywhere is an accident everywhere. INPO peer-reviews every US plant, its evaluations move insurance premiums, and it sits on top of the NRC’s statutory floor. That is a public-private stack very close to what Hassabis is describing. Frontier AI has the same structure: one lab’s catastrophic failure brings regulation down on all of them.”

For enterprise CIOs and other IT executives, Goryunov said, that model has the potential for being a big win.

Today, every enterprise duplicates the same AI diligence of red-teaming, eval suites, governance committees and each does so with less information than any certifying body would have,” Goryunov said. “A credible standards regime does for AI what UL did for electrical equipment and SOC2 did for cloud: it converts an unknowable risk into a procurable product and gives boards a defensible standard of care. That’s not red tape. That’s peace of mind with an audit trail.”

However, Mahapatra said, “the countervailing view is that the alternative to industry-led standards is probably not thoughtful legislation. It is probably no standards, or state-by-state fragmentation, or the current pattern of ex-post enforcement actions where regulators surface concerns years after harm has already occurred.”

Thus, he noted, “Hassabis is making the reasonable argument that imperfect fast standards are better than perfect slow ones, and there is genuine merit to that view for topics like agent identity, evaluation methodology, and interoperability, which are exactly the areas OpenClaw is also targeting.”

This article originally appeared on CIO.com.

Kategorie: Hacking & Security

Apple’s OpenAI lawsuit: The lunacy of trying to limit what ex-employees can tell future employers

15 Červenec, 2026 - 17:59

When Apple sued OpenAI last week, the argument it made was that former employees had stolen Apple data and then used it to benefit OpenAI. 

The technical details — an employee used “a rare, previously unknown authentication bug to access Apple’s shared network folders” — are interesting. But the larger story is Apple’s ridiculous attempt to stop its people from using anything they learned at Apple in other jobs.

“Hiring managers don’t mind some files being brought into the org during onboarding, but suddenly take umbrage when that same employee exits with some files later on,” said Mike Wilkes, enterprise CISO at Aikido Security. “Legal should be equally concerned about both events.”

The lawsuit focused on Chang Liu, an employee who had been recruited to work at OpenAI after working at Apple for eight years as a Senior System Electrical Engineer. The full text of the filing depicts a comedy of errors by Apple, offering the perfect “do not do” list of handling employee resignations — especially when they’re going to a direct competitor. 

“When Apple contacted Mr. Liu to sign Apple’s confidentiality reminder, schedule an exit interview, and confirm that he had returned his devices and complied with other exit procedures, Mr. Liu did not respond.” And “after leaving Apple, Mr. Liu failed to return an Apple-issued work laptop that he had previously authenticated to Apple’s network.”

First, typical procedure for handling departures is to tie the return of all equipment and the signing of documents to any final payments. With Apple, that is likely to be a large amount of money. The lawsuit does not say whether Apple exerted any financial pressure on their employee for compliance. 

But in terms of equipment with high-level access, why weren’t all privileges revoked, both for the employee and any and all company-issued devices? Did they not maintain a remote-wipe capability for these devices? Although remote-wipe is usually used when devices are missing or stolen, it should work as well when a departing employee refuses to return company equipment. 

According to Apple, Liu apparently had help at Apple from Tang Yew Tan, who was supposedly also interviewing with OpenAI. “While employed by OpenAI, [Liu] accessed and used his former colleague’s Apple-issued work computer that was authenticated to Apple’s network, without Apple’s authorization.”

Apple tried to make much of this Liu’s fault. Legally, yes, there might be liability there; still, Apple made itself look as if it couldn’t protect its own data. “Upon discovering that he had this unauthorized access to Apple’s systems, [the former employee] did not report it, return his stolen Apple-issued work laptop or delete the program that allowed the access.” 

Really, Apple? Your data-protection plan relies on ex-employees to “delete the program that allowed the access”? I’m not so sure you didn’t bring some of this data-leakage on yourselves. 

This gets worse: “Over several weeks, while developing hardware for OpenAI, Mr. Liu surreptitiously accessed and downloaded dozens of Apple’s confidential hardware-related files, including voluminous, detailed information about unreleased products, engineering presentations, technical specifications, and proprietary project data.”

Setting aside the issue of privileges, access, and unreturned equipment that apparently had its own privileges, that statement points to massive data exfiltration from Apple systems. Even if it is coming from a current employee, why didn’t that raise any red flags? 

Let’s get back to the broader implications. When professionals move from one company to another, they — of course — are bringing their experience and knowledge with them. Can Apple reasonably tell them that they can’t do so? Isn’t that experience and knowledge exactly why another company would want to hire them?

Now, to be sure, stealing diagrams and product spec sheets is a clear violation. Let’s say Apple spent a lot of money on some hardware research projects. A member of that technical team would learn an awful lot, all on Apple’s dime. 

But is it fair and reasonable for Apple to say that the former employee can’t leverage that knowledge at his or her next job? 

This brings us back to the point Wilkes made: If Apple is going to try to prevent any former employee from leveraging on-the-job experience, then it should instruct all new employees not to use anything they learned in a previous job. 

That would be ridiculous. Companies pay for experienced talent because of that experience. Why pay for expertise if you insist employees not leverage any of it?

Then there’s the amorphous nature of knowledge. So, it’s wrong to take detailed diagrams and spec details and hand them over to a new employer. But what if that worker heading out the door memorizes the documents (photographic memory) a day before resigning? Is a person prohibited from using something from memory?

There’s also the fruit-of-the-poisonous tree legal argument. Even if a former employee doesn’t directly use stolen data, what if their knowledge leads to other money-saving insights for the new employer? 

Given that Apple hires as many specialists as it loses to rivals, wouldn’t it make sense to leverage everything your workforce knows and then let new employers do the same? But before you do that, Apple, tighten your exiting employee tech controls. 

Then maybe you wont’t have to file lawsuits like this down the road.

Kategorie: Hacking & Security

What problems would an AI speaker from OpenAI actually solve?

15 Červenec, 2026 - 17:52

OpenAI’s first device will be a screenless home AI system that can play music, control appliances, and respond to messages and questions, according to Bloomberg. I can’t help but ask what makes this device different from Apple’s HomePod with SiriAI?

The OpenAI product is intended to be the first of a family of solutions and is expected to use the recently-introduced GPT-Live large language model (LLM). The latter is an advanced model capable of processing information swiftly and of providing natural responses to conversations. 

A potential gold mine for hackers

This expertise might help it deliver more accurate responses to requests, though the information could also become a gold mine for data brokers, hackers, and advertisers if there turns out to be any way they can get their hands on it. It’s not yet known how — or even if — OpenAI proposes protecting user privacy within its systems. 

The device, which is still under development, is explained as being a home companion that also includes a built-in camera and sensors so it can gather contextual information about where you are, becoming an expert on you and your needs. It also features autonomous mechanical elements that physically shift on their own, intended to give the product a “personality,” rather than being a boring black box.

Can we live without this?

While OpenAI’s development is not yet complete and things could change before it reaches market, based on Bloomberg’s report I’m not terribly clear how unique it is going to be. After all, as LLM support is introduced in existing smart speaker systems from Apple, or even Amazon, what unique features does this device bring that consumers can’t live without? More particularly, what problems does it solve and why does it exist?

Manufacturing economics

What’s also unclear is how far along OpenAI is on the road to mass manufacturing the device. Apple’s recent lawsuit against OpenAI confirmed the challenger is speaking with Apple’s own manufacturing partners as well as hiring hundreds of Apple engineers. Despite the talent war, I consider it unlikely OpenAI will be able to lock in the kinds of manufacturing deals it needs to bring the product to market at an acceptable price

That suggests either that its inaugural “home companion” will seem incredibly expensive (as so many of the products Jony Ive has designed since leaving Apple seem to be), or that OpenAI will sell these things at a subsidy. 

Bloomberg suggests the systems will cost $200 to $300. That seems low given the current component market, expected design quality and the technology used if the plan is to make something good. And it leaves me wondering how deeply investors will underwrite hardware sales, given the eye-watering losses the company is already making.

Apple’s trade secrets case

Given ongoing speculation that Apple plans something similar in the form of a hybrid HomePod/iPad equipped with AI and limited mobility, the recent lawsuit strongly suggests Apple feels some of OpenAI’s plans cross the line into using proprietary technologies and ideas Cupertino has spent years pursuing. Apple’s lawsuit seems to bring much more meaningful evidence than just an argument concerning product design. 

Betting the farm on Ive

We also don’t know the extent to which consumers will be open to semi-sentient AI devices lurking in their lives. While Apple can lean into its loyal customer base and broaden its offering with rock-solid promises concerning user privacy, OpenAI has less to bring to the launch party.

That means it is attempting to pivot millions who use its services into investing in its hardware. It presumably hopes that it will be able to drive that transition by using the design involvement of acclaimed Apple designer Jony Ive as a form of magic talisman. 

The challenge is that while Ive is a big name in Apple history, Apple users are extremely loyal and may react against the involvement of their favorite designer. It’s like finding out someone you thought was on your team actually supported someone else. 

It will be different outside Apple, where less loyal cohorts might see the product introduction as a chance to put a design from Ive through its paces without signing up to a Mac, iPhone, iPad, or HomePod. 

For the rest of us, the question will be whether OpenAI’s Ive-designed product channels the successful design ethic of the iMac, or that of the far less successful hockey puck mouse. Like (timely World Cup klaxon) France against Spain, OpenAI’s investors have to hope the best version of Ive’s design principles show up, because their risked fortunes potentially depend on it. 

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

How to unionize your tech workplace

15 Červenec, 2026 - 13:00

The best time for tech workers to unionize was 20 years ago, when they had plenty of leverage. The second-best time is now, when they don’t.

Mass layoffs, AI-driven displacement, corporate surveillance, workplace disillusionment have created conditions that have made organizing compelling for tech professionals. But the federal labor board that has historically protected workers’ right to organize has been weakened, and the companies that once feared it are openly defying it.

Here’s how organizers and labor experts describe the pros and cons to organizing — and how you can get started.

This is Part 2 of a series on tech worker unionization. Also see Part 1: “A brewing battle: More IT workers want unions. The industry doesn’t.”

What unions can — and can’t — do for you

The single biggest benefit of a union contract for most tech workers isn’t pay — it’s protection against arbitrary termination, especially in the wake of recent mass layoffs in tech. In the United States, nonunion “at-will” workers can be fired at any time without a stated reason, while unionized workers negotiate protections written into their contracts.

“That fear of the company letting you go for anything at any time…with a union they just can’t do that,” says Zak Thompson, a senior software engineer at Kickstarter and union steward at Kickstarter United. Now that Kickstarter employees are unionized, people are less worried that saying something negative will result in termination.

“I’ve been shocked at the willingness of my co-workers to speak up against what they see as poor or controversial business decisions,” Thompson says.

width="972" height="972" sizes="auto, (max-width: 972px) 100vw, 972px">

Zak Thompson from Kickstarter United


Fee Christoph

Beyond job security, unions can deliver concrete material gains. Kickstarter United was formed in 2020, although getting there wasn’t easy: two employees were fired during the organizing campaign — which itself became a galvanizing event. And while the union hasn’t been able to prevent layoffs, it did negotiate better terms: four months of severance pay and four to six months of continued health insurance, versus the two to three weeks per year of work that management had initially proposed.

Other benefits include a four-day work week; AI protections; a minimum pay floor; and standards for raises, promotions, and time off for the company’s 59 employees.

Unions can give tech workers a voice in decisions that affect their daily work — including how AI tools are deployed. “Nobody I’ve spoken to is against new technology or getting trained in it,” says Max Belasco, a business systems analyst at the University of California Los Angeles School of Law and co-chair of the UCLA chapter of the University Professional and Technical Employees/Communications Workers of America (UPTE-CWA) Local 9119.

“But when new technology is being implemented, we want to know: what’s the five-year vision, the 10-year vision? Are we implementing this in a way that betters staffing, increases efficiency, or eases the lives of people already working? Or are we trying to take away jobs, automate people out of their pension or paycheck?” Belasco says.

The challenges are real. Tech professionals are less inclined to leave their jobs in the current market because wages haven’t been increasing as fast as they once were, and it can take longer to land another job.

“Tech moved from a very tight labor market in 2022 (1.85% unemployment rate) to a noticeably weaker one in 2024–2026 (3.49%),” although that’s still better than the national unemployment rate of 4.36% through May of this year, says Liya Palagashvili, senior research fellow and director of the Labor Policy Project at the Mercatus Center at George Mason University.

width="960" height="640" sizes="auto, (max-width: 960px) 100vw, 960px">

Liya Palagashvili of the Mercatus Center at George Mason University

Mercatus Center at George Mason University

Flexibility is a concern. The more substantive challenge, raised by economists including Palagashvili, is that traditional union contracts impose uniform terms across an entire bargaining unit, limiting the flexibility that many tech workers — and their employers —currently enjoy. Tech firms need to move fast, adjusting teams, products, and roles on the fly.

“Collective bargaining agreements can make those adjustments much more difficult, whether by making them slower, costlier, or inconsistent with the contract,” she says.

Workers skeptical of unions in a survey of 1,900 tech professionals conducted by the career site Blind cited specific concerns: that unions are “not meritocratic,” “prevent innovation,” and “hold back earnings of top performers.”

Thompson from Kickstarter United pushes back: “We have nothing in our contract about ‘you can’t bend down and pick up a piece of trash because that’s someone else’s job.’ The company is free to give bonuses and individual raises as much as they like. This is all just up to the people who are bargaining the contract from the union side.”

Organizing carries potentially serious personal risks. During negotiations for a second three-year contract in 2025, Kickstarter United went on strike for 42 days. A few months later, the company announced layoffs.

“They let go strong union leaders, including a person who had bargained our last contract,” Thompson says. The union appealed, and the issue is now going to arbitration.

If you form a union, don’t expect much support from the National Labor Relations Board, the agency that certifies US labor unions and protects workers’ right to organize, in terms of prosecuting complaints of unfair labor practices, Thompson warns. “We’re in a political moment in this country with a pretty weakened NLRB. You have to be ready to organize and withhold worker power without any guarantee of safety.”

Organizers are up against an enormous union avoidance industry. Organizers can expect fierce pushback as soon as the business discovers that organizing is underway.

“There’s a multi-billion-dollar industry in union avoidance,” says Alan McAvinney, a Google software engineer and organizing chair, Alphabet Workers Union-CWA, a 1,400-member minority union of Alphabet employees. (Google is a subsidiary of Alphabet.)

US employers spend roughly $1.7 billion a year on union avoidance consultants and law firms, according to a May 2026 report by the Economic Policy Institute and LaborLab.

Expect hardball tactics. Management may play hardball during the time between when organizers announce their intention to unionize and the actual vote. For example, management can threaten to fire foreign-born workers in the US on H-1B visas if they support the union. Those workers would then have just 60 days to find a new sponsoring employer or lose their H-1B status, according to a recent Tech Workers Coalition blog post.

And at venture capital-backed startups, investment agreements sometimes require management to attest there is no union activity — meaning a public organizing drive can trigger funding withdrawal. Or, if a unionized company is acquired, the new management can dissolve the union overnight by reclassifying unionized workers as new hires.

With these sobering facts in mind, here is how organizers who have done it describe the process of creating a union.

Step 1: Start a conversation with your co-workers

At the University of California, a two-tier system had evolved where some tech workers were unionized and some weren’t, Belasco says. Management created new titles that fell outside the union even though they had similar job descriptions and responsibilities to those in the union. Those nonunion employees received lower pay and benefits than their unionized peers, which created resentment and instability.

width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px">

Max Belasco from the UCLA chapter of UPTE-CWA

Zac Goldstein

Belasco and other organizers wanted to eliminate that division by bringing everyone under the same contract. But when they began their unionization drive, “the biggest barrier we faced wasn’t management opposition — it was that people felt this was just the best-case scenario realistically available: ‘We have this job at the university, we have concerns about automation and layoffs, but what can we really do about it?'” he says.

The antidote to that fatalism, organizers say, is simple: “Just start talking to your immediate co-workers. Are they experiencing the same challenges you are experiencing?” says McAvinney. “There’s no need to start talking about a union at this point.”

Just get a consensus and start building a group of like-minded individuals, Thompson advises. “Always start with one-on-one conversations, and that’s what you should do the whole time. That’s the key to organizing,” he says.

Tech workers often think they’re a special case, says Thompson, and therefore that unionization isn’t a good fit. “You’re not special. You are a company of workers, you are organizing, and there is a playbook for that. Trust the process, because it tends to work pretty well,” he says.

Step 2: Who’s on board, and who’s not? Map your workplace, but keep it quiet

Once there’s a consensus, continue to grow your network. Keep a list of everyone you’ve spoken with and note their disposition: “Is this person union-friendly or anti-union? Would they be a strong organizer?” Thompson says.

Maintaining secrecy early on is essential, because anti-union tactics will start immediately, and that can stop union organizing before it can gain momentum.

“Generally, employers do not want to share power with their workforce,” McAvinney says. Employers will deploy every means at their disposal to stop organizing efforts and peel away potential yes votes.

width="1024" height="839" sizes="auto, (max-width: 1024px) 100vw, 1024px">

Alan McAvinney from Alphabet Workers Union-CWA


Aran Per Ink

“If you look at historical examples, having 70% approval before the employer finds out about you results in a high percentage of wins when you actually cast the vote. Historically, that’s an effective buffer,” he says.

There’s a real threat of firing and layoffs. The traditional tech worker belief that job mobility makes collective action unnecessary is now being tested by a tighter job market, McAvinney says, noting that workers who many believe were fired for speaking out back in 2019 were a galvanizing factor in his union’s formation.

“You generally don’t want to be in a situation where the employer feels comfortable firing everyone. Part of that is thinking from a cynical standpoint about what the consequences would be to the employer if they did fire everyone,” he says.

One-on-one conversations that include personally asking co-workers to keep conversations confidential are key to keeping things quiet, Belasco says. When 2,100 UC tech workers voted to unionize in May, 96% voted in favor. To stay out of earshot of managers, avoid employee surveillance tools, and sidestep conference calls that could be recorded, organizers met with workers in their homes.

“That tactic is probably what made the difference between winning the election and getting the majority we got,” he says.

Step 3: Find the right union affiliation or go it alone

“Running a campaign against major employers requires the resources and expertise of the larger labor movement, even if workers publicly present as independent,” says Kate Bronfenbrenner, director of labor education research and senior lecturer emeritus at Cornell University’s School of Industrial and Labor Relations.

Options include the Communications Workers of America (CWA), Service Employees International Union (SEIU), and the Office and Professional Employees International Union (OPEIU), among others. Another resource, the Tech Workers Coalition (TWC), provides training on organizing tactics, AI-in-workplace issues, and contract negotiation, and can match workers to the right unions for their needs.

The Alphabet Workers Union decided early on to affiliate with CWA. “They gave us a bunch of support early on in our campaign with no strings attached,” McAvinney says.

Kickstarter is organized through OPEIU, Thompson says. “They’ll usually have resources and staff that can help you through the next steps: collecting signatures in support of a union, bringing that to management, holding a vote — the more formalized things that interact with US labor law. They’ll also help with organizing along the way,” he says.

For workers at institutions where a union already exists, there may be a faster path. Organizers at UCLA did what’s called a “unit modification,” aligning with UPTE. By organizing under UPTE, the workers didn’t have to negotiate a new contract from scratch — they joined an already-negotiated contract covering existing UPTE tech members, which put them in “a much stronger position” than starting fresh, Belasco says.

Step 4: Choose your union model: majority vs. pre-majority or minority

Assess what’s practical for your organizing effort. In a majority union, more than 50% of all workers in a defined bargaining unit must vote to join the union through an NLRB-supervised election in the private sector, or a Public Employment Relations Board (PERB)-supervised election for public sector workers.

The NLRB must certify the union, which then operates under its legal protections. This means, for example, that the employer must bargain, negotiated contracts are enforceable, violations must go to the NLRB or arbitration, and workers can’t be dismissed without just cause.

A pre-majority or minority union is a minority labor organization operating without NLRB protections or collective bargaining agreements. “Pre-majority means that workers are able to demonstrate majority support — through signed cards, petitions, a walkout, or everyone wearing solidarity T-shirts — without going through a formal election,” Bronfenbrenner says.

width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px">

Kate Bronfenbrenner from the School of Industrial and Labor Relations, Cornell University


ILR School/Cornell University

The Alphabet Workers Union-CWA (AWU-CWA) formed as a pre-majority union because achieving majority status across a globally distributed workforce of over 100,000 was not a realistic near-term goal. “An underground model where you try to reach 70% support across a workforce of over 100,000 people isn’t realistic,” McAvinney says.

A pre-majority union can still make a difference, he says. For example, the Alphabet Workers Union-CWA convinced management to offer voluntary exit packages — buyouts — prior to announcing layoffs.

For smaller organizations, a majority union may be the more practical option — it’s more attainable, McAvinney says. “I don’t think [the pre-majority union model] is the correct thing to do in all situations. I certainly would not recommend it to a 200-person shop.”

Kickstarter, which had fewer than 100 employees, was able to form a majority union, with 55% voting to organize.

Ultimately, says McAvinney, “there’s no inflection point where you go from being able to win nothing to winning everything, even with a contract and a supermajority. But the more people you have who are willing and able to fight for what they want, the more you’ll be able to get.”

Step 5: Who should — and should not — be in your union?

Belasco’s situation at UCLA illustrates a broader strategic choice that every organizing campaign must make. He had been in a union position in educational technology when he was told his role would be reclassified as a non-union position.

“I was given a choice: apply to the new non-union position to continue doing the work I’d trained for, or stay in my union position doing service desk work I wasn’t used to,” he says. “Essentially, it was a choice between job security and career progression.”

Belasco joined a “wall-to-wall” union, which represents a broad range of university professional and technical employees across the UC system rather than a single job category, such as engineers or tech professionals.

Kickstarter United is another example of a wall-to-wall union. “It’s not just the engineers who are unionized, but also customer support, designers — everyone,” Thompson says.

Wall-to-wall unions are more powerful, but they’re also more difficult to achieve. Under US labor law, “professionals have to vote separately on whether they want to be combined with other workers,” says Bronfenbrenner. “You can never have a wall-to-wall unit without giving professionals the chance to decide whether they want to be separate.”

The law’s “professional employees” category includes roles like software engineers and developers but not necessarily others. For example, customer support specialists and QA analysts would fall into the “non-professional workers” category.

“For decades, the pattern was either to organize everybody except the engineers, or manage to organize the engineers and fail to bring in everybody else — neither of which builds real worker power,” says Simone Robutti, an organizer with Tech Workers Coalition Global, an international branch of TWC based in Berlin.

width="959" height="713" sizes="auto, (max-width: 959px) 100vw, 959px">

Simone Robutti from Tech Workers Coalition Global


TWC

Step 6: You won the vote. Get ready for what comes next

Winning a union vote means having a seat at the table, says Thompson. “Once the workers have come together and agreed they want that seat, you bring that to management, and they have a chance to voluntarily recognize a union,” he says.

But in most cases employers contest the results, which must be certified by the NLRB or PERB. That process, in which the employer uses various tactics to challenge the legitimacy of the outcome, can take weeks or months.

Unfortunately, the legal framework that is supposed to protect workers during this process has been significantly weakened in the last few years. In a potentially more ominous development, SpaceX, Amazon, Trader Joe’s, Starbucks, and the University of Southern California have in separate legal actions challenged the constitutionality of the NLRB, arguing that the agency’s structure violates the separation of powers. The Fifth Circuit Court of Appeals upheld injunctions against the NLRB in SpaceX’s case in August 2025 — a serious challenge to the agency’s authority.

In the meantime, some companies may disregard negotiated contracts, which can lead to lengthy legal appeals or extended arbitration.

“The NLRB can still force an election, but it can’t force a contract, and companies are saying they simply won’t comply,” Bronfenbrenner says. This is where the expertise and resources of affiliation with a major union can help, she adds.

As a result, contract negotiations can take far longer than workers might expect. At Kickstarter, for example, two years and four months elapsed from the time of the union vote to the first contract, and that was at a 59-person company with a relatively cooperative employer. At larger companies with more aggressive legal teams, the timeline will be longer.

Forming a union is hard work, Robutti says. “It’s not a service you pay for and they protect you. It doesn’t happen spontaneously, and it doesn’t happen magically. It’s the choice to take responsibility for improving your workplace.”

See Part 1: A brewing battle: More IT workers want unions. The industry doesn’t.

Kategorie: Hacking & Security