Kategorie
WhatsApp rolls out new feature that flags potential scam messages
OpenAI: Latest news and insights
OpenAI is an artificial intelligence organization comprised of the non-profit OpenAI, Inc. and several for-profit subsidiaries. The company is perhaps best known for its ChatGPT chatbot, which launched in 2022, kicking off a period of massive disruption in the tech industry and beyond.
A complicated and increasingly contentious relationship with Microsoft, ongoing legal issues over copyright infringement, and frequent product announcements keep OpenAI in the news. Follow this page and never miss a beat.
Latest Open AI news and analysis: OpenAI targets heavy users with premium ChatGPT Business seatsAug. 11, 2026: OpenAI is introducing a higher-priced “Premium” tier for its ChatGPT Business offering, allowing enterprises to assign higher-capacity access to select users alongside standard licences – a move analysts said is about enterprise AI vendors redesigning pricing to capture more value from high-intensity workloads.
OpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response windowAug. 11, 2026: OpenAI has expanded its Daybreak cybersecurity program and introduced GPT-5.6-Cyber, a specialized model for approved security researchers, as the company warned that AI could give defenders less time to respond to developing threats.
OpenAI says Astra could reach ‘critical’ cyber capability, tightens safeguardsAug. 10, 2026: OpenAI said its upcoming model Astra is showing cybersecurity capabilities that could reach its highest risk category, where a system can autonomously find and exploit vulnerabilities or carry out end-to-end cyberattacks against hardened targets.
OpenAI, Anthropic AI agents resorted to deception in new cybersecurity incidentsAug. 5, 2026: OpenAI’s GPT-5.6 Sol and Anthropic’s Mythos 5 have been implicated in another series of AI security incidents after the models created fake online identities, targeted real people, and attempted to manipulate developers into approving malicious code during controlled cyber evaluations, according to the UK AI Security Institute.
OpenAI drops GPT-5.6 Luna and Terra API prices by up to 80%July 31, 2026: OpenAI has cut API prices for its GPT-5.6 Terra and Luna models by 20% and 80%, respectively, while also reducing the number of usage credits the models consume in ChatGPT Work and Codex, in an effort to effectively increase the amount of AI work enterprise subscribers can perform without paying more.
OpenAI rogue AI agent’s attack expanded beyond Hugging FaceJuly 29, 2026: The autonomous AI agent that escaped during OpenAI testing exploited weaknesses across a customer workload, a third-party cloud platform, and Hugging Face’s production environment before being contained, according to new technical disclosures that provide the clearest picture yet of one of the first publicly documented AI-driven intrusion chains.
Hugging Face breach shows why incident response needs a multi-model AI strategyJuly 28, 2026: The recent breach of Hugging Face’s platform by an internal OpenAI test of advanced model cyber capabilities that went wrong was the latest in a string of AI-assisted intrusions to come to light in recent weeks, showing that attackers can now use LLMs to automate entire attack chains.
Hugging Face CEO wants transparency after OpenAI’s AI incidentJuly 27, 2026: Hugging Face CEO Clem Delangue wants to see radical transparency from OpenAI after the company acknowledged that one of its AI agents managed to hack into the AI platform’s systems during a test.
OpenAI not part of the new Open Secure AI AllianceJuly 27, 2026: A new industry group led by Nvidia is promoting open AI models (and not OpenAI’s models) as essential to cyber defence.
OpenAI Presence raises new questions about enterprise automation and jobsJuly 23, 2026: OpenAI has launched Presence, an enterprise service for deploying voice and chat agents that can resolve customer and employee requests, potentially automating some work now handled by frontline support teams.
OpenAI model escape puts enterprise AI defenses on noticeJuly 22, 2026: An attack on Hugging Face executed by a sandboxed OpenAI model shows that prompt guardrails cannot serve as the main security boundary for AI agents, putting more pressure on enterprises to contain them through infrastructure controls that limit access and prevent lateral movement.
OpenAI’s Codex context reduction for GPT 5.6 sparks dissatisfaction among developersJuly 20, 2026: OpenAI’s recent update to its Codex coding agent has developers worrying over the impact of the change on large code repositories and long-running AI-assisted sessions. The update to the Codex CLI reduces the default configured input context window for GPT-5.6 to 272,000 tokens from 372,000 tokens.
OpenAI’s new hardware is a $230, 13-switch keyboard for CodexJuly 17, 2026: OpenAI is selling its first hardware — without any help from Jony Ive. It describes the Codex Micro as a “command center for agentic work” but it’s really a 13-switch wireless keyboard customized to help developers keep tabs on what their Codex agents are doing. It costs $230.
OpenAI’s GPT-5.6 may accidentally delete filesJuly 17, 2026: OpenAI said its latest large language model GPT-5.6-Sol can accidentally delete files, while stressing that such incidents are rare and should be viewed as “honest mistakes.”
OpenAI launches ChatGPT Work as it broadens GPT-5.6 rolloutJuly 10, 2026: OpenAI is sharpening its enterprise AI strategy with the launch of ChatGPT Work, a new agentic platform designed to automate workplace tasks, alongside the broader rollout of its GPT-5.6 models, which the company says deliver stronger performance at lower operating costs.
OpenAI to release delayed models amidst a sea of regulatory confusionJuly 8, 2026: As enterprises struggle to manage their AI strategies, the US AI regulatory environment is sending a wide range of contradictory signals. OpenAI’s announcement that it will now release GPT-5.6 Sol, along with Terra and Luna, highlights the confusion.
US tells OpenAI to restrict access to its most powerful AI modelJune 26, 2026: US authorities are getting decidedly twitchy about frontier AI models. Just a couple of weeks after ordering Anthropic to prevent foreign companies from getting hold of its latest release, Mythos/Fable 5, it’s been putting the squeeze on OpenAI.
OpenAI rolls out AI-led push to fix open-source software flawsJune 23, 2026: OpenAI has launched a program with cybersecurity firm Trail of Bits to use AI to find and fix vulnerabilities in widely used open-source software, as enterprises face growing risks from flaws buried deep in their software supply chains.
OpenAI gets the attention it needs from AI researcher Noam ShazeerJune 19, 2026: OpenAI has lured Noam Shazeer, one of the eight co-authors of the influential AI paper Attention Is All You Need, away from Google.
OpenAI adds spend controls and usage analytics to ChatGPT EnterpriseJune 19, 2026: OpenAI has introduced spend controls and enhanced usage analytics for ChatGPT Enterprise to enable organizations to monitor AI adoption, track consumption across teams, and set budgets for AI usage. But, analysts cautioned, it still can’t show how those costs lead to business benefits.
ChatGPT will soon be able to shop with your Visa cardJune 16, 2026: OpenAI has signed a partnership agreement with Visa that allows the company’s AI agents to use the payment card for e-commerce transactions. The agreements lets users shop for everything from groceries and diapers to airline tickets without having to manually enter a lot of information.
OpenAI buys Ona to help rein in AI agentsJune 12, 2026: OpenAI has agreed to acquire Ona, a 79 person cloud development environment (CDE) provider formerly known as Gitpod, to accelerate its efforts to make agentic AI enterprise-friendly.
OpenAI weighs Nvidia-backed lease for 10 GW Ohio data center campusJune 10, 2026: OpenAI is reportedly in advanced talks to lease a proposed 10-gigawatt data center campus in southern Ohio in an arrangement that could include financial backing from Nvidia.
OpenAI’s Lockdown Mode is trying to solve the problem that it createdJune 9, 2026: OpenAI’s move to implement a Lockdown Mode that tries to limit data exfiltration by shutting down external capabilities is being seen as making the best out of a bad situation. But Lockdown Mode doesn’t block exfiltration as much as it slightly reduces it, and the reality of enterprises using multiple AI vendors for their agentic models further complicates an already dicey governance strategy.
OpenAI responds to White House executive order on AI governanceJune 4, 2026: OpenAI has proposed mandatory federal evaluations of the most capable AI models before public release while arguing that regulators should stop short of deciding whether those systems can be deployed, staking out a middle ground in the debate over how frontier AI should be governed.
OpenAI fixed a visibility problem; the governance problem remainsJune 3, 2026: OpenAI’s new ChatGPT session controls improve visibility, but experts say continuous model updates are creating a far bigger challenge for enterprise risk and compliance teams.
Attack targeting OpenAI Codex users exposes AI software supply chain risksJune 2, 2026: A malicious npm package posing as a remote user interface for OpenAI Codex exfiltrated developer authentication tokens, after attackers allegedly published code to npm that was not visible in the project’s public GitHub repository.
AI models more vulnerable than claimed when faced with iterative attacksMay 27, 2026: According to a new study from Cisco, frontier models from OpenAI, Anthropic, Google, xAI, and Amazon have significantly worse risk profiles when pressured in multi-turn attacks compared to when their safety is benchmarked using single prompts.
OpenAI introduces Daybreak cyber platform, takes on Anthropic MythosMay 12, 2026: OpenAI has unveiled Daybreak, its answer to Anthropic’s Claude Mythos, amid a growing market for frontier AI-powered cyber defense platforms. The initiative combines OpenAI’s large language models, Codex’s agentic capabilities, and integrations with the broader enterprise security ecosystem.
OpenAI’s new AI consulting offering raises questions of trust, strategyMay 11, 2026: The OpenAI Deployment Company aims to help organizations build and deploy AI systems by embedding engineers specializing in frontier AI deployment, known as forward deployed engineers (FDEs), into their environments.
Malicious Hugging Face model masquerading as OpenAI release hits 244K downloadsMay 11, 2026: A malicious Hugging Face repository posing as an OpenAI release delivered infostealer malware to Windows systems and logged 244,000 downloads before being removed, raising fresh concerns about how enterprises source and validate AI models from public repositories.
OpenAI-led consortium seeks to address AI processing bottlenecksMay 8, 2026: An OpenAI-led consortium of tech giants including AMD, Broadcom, Intel, Microsoft, and Nvidia have unveiled a new networking protocol, Multipath Reliable Connection (MRC), designed to address network congestion, a problem that has always existed but has been exacerbated by the massive amounts of data required for AI processing.
OpenAI, Anthropic expand services push, signaling new phase in enterprise AI raceMay 6, 2026: OpenAI and Anthropic are expanding their reach into professional services through joint ventures and acquisition talks, moving model providers closer to implementation roles traditionally held by systems integrators.
OpenAI’s Symphony spec pushes coding agents from prompts to orchestrationApril 28, 2026: OpenAI has released Symphony, an open-source specification for turning issue trackers such as Linear into control planes for Codex coding agents.
Microsoft, OpenAI change contract terms — againApril 27, 2026: Microsoft and OpenAI have again revised their agreement, softening their exclusivity and revenue-sharing conditions in the process.
OpenAI pulls out of a second Stargate data center dealApril 15, 2026: In the space of one week, OpenAI has pulled out of two European Stargate data center deals, one in the UK and the other in Norway.
OpenAI puts part of Stargate project on hold over runaway power costsApril 10, 2026: OpenAI has postponed plans to open one of the data centers central to its Stargate project.
OpenAI calls for a four-day workweek — and a ‘robot tax’April 7, 2026: In a new policy paper, OpenAI makes some interesting proposals to address the impact of AI on the labor market.
Microsoft builds its own AI stack to help wean it from its reliance on OpenAIApril 2, 2026: Microsoft seems to be meeting OpenAI on its own turf, even as it continues its strategic partnership with the AI darling, with the release of three in-house, commercially-available AI models.
OpenAI patches twin leaks as Codex slips and ChatGPT spillsMarch 31, 2026: OpenAI has fixed two flaws in its AI stack that could allow AI agents to move sensitive data in unintended ways.
OpenAI adds plugin system to Codex to help enterprises govern AI coding agentsMarch 27, 2026: OpenAI has introduced a plugin system for Codex, its AI-powered software engineering platform, giving enterprise IT teams a way to package coding workflows, application integrations, and external tool configurations into versioned, installable bundles that can be distributed or blocked across development organizations.
OpenAI’s Sora exit signals enterprise-first AI shiftMarch 25, 2026: OpenAI has discontinued its AI video generation platform Sora. The company announced the development in a sudden and unexpected post on X, stating that it was “saying goodbye” to the Sora app.
OpenAI’s Foundation play reframes the AI roadmap for IT leadersMarch 24, 2026: The OpenAI Foundation has announced a sweeping range of investment and research goals, from building safeguards around how AI behaves in the wild to pushing for shared data ecosystems and funding disease research.
OpenAI to double workforce, highlights growing demand for enterprise AI talentMarch 23, 2026: OpenAI is planning to almost double its workforce from about 4,500 to 8,000 employees by the end of 2026. The move comes as OpenAI sharpens its focus on scaling and monetising ChatGPT for enterprise use amid intensifying competition from Anthropic and Google.
OpenAI’s desktop superapp: The end of ChatGPT as we know it?March 20, 2026: OpenAI is reportedly planning to fold its ChatGPT application, Codex coding platform, and AI-powered browser into a single desktop ‘superapp’, a move that signals a shift toward enterprise and developer audiences and away from the consumer market that made the company a household name.
OpenAI buys non-AI coding startup to help its AI to programMarch 19, 2026: OpenAI has acquired Astral, the developer of open source Python tools including uv, Ruff and ty, and plans to integrate them with Codex, its AI coding agent.
OpenAI’s $50B AWS deal puts its Microsoft alliance to the testMarch 17, 2026: Microsoft is considering legal action against OpenAI and Amazon over the $50 billion cloud deal the two recently struck to make Amazon Web Services (AWS) the exclusive third-party cloud distribution provider for OpenAI Frontier.
Encyclopedia Britannica sues OpenAI over AI trainingMarch 17, 2026: Encyclopedia Britannica and its subsidiary Merriam-Webster have sued OpenAI, claiming the generative AI firm used their encyclopedia and dictionary texts to train AI models such as ChatGPT without permission.
OpenAI to acquire Promptfoo to strengthen AI agent security testingMarch 10, 2026: OpenAI said it plans to acquire AI testing startup Promptfoo, a move aimed at strengthening security checks for AI agents as enterprises move toward deploying autonomous systems in business workflows.
OpenAI robotics chief quits over Pentagon dealMarch 9, 2026: Caitlin Kalinowski has resigned over OpenAI’s contract with the US Department of War, saying key safeguards around domestic surveillance and autonomous weapons were not adequately reviewed before the agreement was signed.
OpenAI says Codex Security found 11,000 high-impact bugs in a monthMarch 9, 2026: OpenAI’s new AppSec agent, Codex Security, has already flagged over 11,000 high-severity and critical flaws in real-world codebases during its first 30 days of research testing. The tool is designed to automatically find, validate, and fix vulnerabilities in software repositories.
OpenAI says its US defense deal is safer than Anthropic’s, but is it?March 2, 2026: OpenAI has struck a deal to supply the US government with AI services, announcing it hours after US President Donald Trump’s decision to ban its AI rival Anthropic from all US government contracts.
OpenAI partners with consulting giants to deploy enterprise AI agentsFebruary 26, 2026: As it bids to push further into the enterprise, OpenAI announced that it has partnered with several large consulting firms. Frontier Alliances, as the partner initiative is called, will involve work with Accenture, Boston Consulting Group (BCG), Capgemini, and McKinsey & Co.
OpenAI hires OpenClaw founder as AI agent race intensifiesFebruary 16, 2026: OpenAI has hired Peter Steinberger, creator of the viral OpenClaw AI assistant, to spearhead development of what CEO Sam Altman describes as “the next generation of personal agents.”
OpenAI responds to Claude Cowork with its own platform for AI agentsFebruary 5, 2026: Anthropic released 11 open-source plugins that enable Claude Cowork to execute a series of automated processes in areas ranging from customer support to IT operations, OpenAI responded Thursday with a similar platform it calls Frontier.
Who profits from AI? Not OpenAI, says think tankJanuary 29, 2026: Findings from a new study by Epoch AI, a non-profit research institute, seeks to answer three questions: How profitable is running AI models? Are models profitable over their lifecycle? Will AI models become profitable?
Will the Microsoft-Anthropic deal leave OpenAI out in the cold?January 27, 2026: Microsoft wasted little time after reaching a deal to finalize its new relationship with OpenAI to find a new AI dance partner — Anthropic, the second most valuable AI startup in the world. It appears as if Microsoft sees a future with Anthropic that’s at least as valuable as the one it had with OpenAI.
OpenAI to add age verification to ChatGPTJanuary 21, 2026: OpenAI has adding age verification to ChatGPT following reports that several children and young people have taken their own lives after conversations with the popular chatbot. The move echoes a recent decision by TikTok to do the same thing to protect underage users from accessing inappropriate content.
Musk’s OpenAI lawsuit clears path to trial, putting Microsoft in the spotlightJanuary 9, 2026: A federal judge has signalled that Elon Musk’s lawsuit challenging OpenAI’s transformation to a for-profit entity will proceed to trial, adding legal uncertainty for enterprise customers that have built AI strategies around the ChatGPT maker’s technology.
OpenAI launches GPT-5.2 as it battles Google’s Gemini 3 for AI model supremacyDecember 12, 2025: OpenAI has released GPT-5.2, claiming significant gains in the AI model’s ability to complete real-world business tasks to an “expert level” compared to GPT-5.1, released in November. The new model offers major improvements across a range of benchmarks, the company said.
What does OpenAI’s ‘Code Red’ warning mean for Microsoft?December 10. 2025: OpenAI founder and CEO Sam Altman sent out a memo to OpenAI employees declaring a “Code Red” emergency and focusing all company efforts on improving ChatGPT. The reason? Google’s newly released Gemini 3 model beat the pants off GPT-5.1
OpenAI to acquire AI training tracker NeptuneDecember 3, 2025: OpenAI has agreed to acquire Neptune, a startup specializing in tools for tracking AI training. Neptune promptly announced it is withdrawing its products from the market.
OpenAI admits data breach after analytics partner hit by phishing attackNovember 27, 2025: OpenAI suffered a significant data breach after hackers broke into the systems of its analytics partner Mixpanel and successfully stole customer profile information for its API portal, the companies have said in coordinated statements.
OpenAI rolls out GPT-5.1 to refine ChatGPT with adaptive reasoning and personalizationNovember 13, 2025: OpenAI has introduced GPT-5.1, an update to its GPT-5 model, aiming to deliver faster responses, improved reasoning, and more flexible conversational controls as the company works to refine its ChatGPT experience for both consumer and enterprise users.
OpenAI spends even more money it doesn’t haveNovember 3, 2025: OpenAI’s overdraft continued its upward trajectory today when the company signed a multi-year $38 billion contract with AWS to have it run its AI workloads. The latest spending spree adds to the incremental $250 billion of Azure services it pledged to buy last week, and, of course, to the commitment it has made towards building Stargate data centers with Oracle.
OpenAI seeks to automate ‘computer use’ for Macs in the enterpriseOctober 24, 2025: While AI bots have begun mastering tasks in browsers and on Windows, Mac-using enterprises have largely been overlooked, until now. OpenAI aims to change that with its acquisition of generative AI interface maker Software Applications Incorporated.
Enterprises should not install OpenAI’s new Atlas browser, analysts warnOctober 24, 2025: Companies that might be eyeing OpenAI’s new ChatGPT Atlas browser should not rush to use it because of potential security risks, analysts said this week. The browser was unveiled on Tuesday after it had been teased for months as a work in progress. It is currently available for MacOS only.
Has OpenAI shown us a future for Safari?October 23, 2025: Has OpenAI shown us the future of Safari? In one way it has, because its new Atlas browser shows these generative AI (genAI)-based apps are no longer just windows to the web — they’re becoming intelligent copilots for our digital lives.
OpenAI–Broadcom alliance signals a shift to open infrastructure for AIOctober 14, 2025: OpenAI has partnered with Broadcom to co-develop and deploy its first in-house AI processors. The move could reshape data center networking dynamics and chip supply strategies as the ChatGPT maker races to secure more computing power for AI workloads.
OpenAI Codex rivals Claude CodeOctober 13, 2025: The OpenAI Codex gives software developers a first-rate coding agent in their terminal and their IDE, along with the capability to delegate background tasks to agents in the cloud.
OpenAI Codex adds SDK, admin tools, Slack integrationOctober 10, 2024: Codex is now generally available. Since being launched as a research preview in May, Codex, OpenAI’s AI-powered software engineering agent that can work on tasks in parallel, has added Slack integration, an SDK, and admin tools.
OpenAI admits AI hallucinations are mathematically inevitable, not just engineering flawsSeptember 18, 2025: OpenAI, the creator of ChatGPT, acknowledged in its own research that large language models will always produce hallucinations due to fundamental mathematical constraints that cannot be solved through better engineering.
OpenAI, Microsoft discuss shape of future relationshipSeptember 12, 2025: Microsoft and OpenAI are in talks about the future of their partnership, they said in a joint statement , without providing details. Separately, OpenAI said it wants to go ahead with its previously announced plan to turn its for-profit business into a public benefit corporation, in which its nonprofit organization would own a $100 billion stake.
What Oracle’s $300B OpenAI deal means for enterprise cloud strategySeptember 11, 2025: A single $300 billion contract has seemingly transformed Oracle from a traditional ERP and database vendor into a cloud computing powerhouse.The company has signed a five-year computing power commitment with OpenAI, contributing to a reported 359% surge in future contract revenue this quarter.
OpenAI acquires Statsig to speed up generative AI-based product launchesSeptember 3, 2025: OpenAI is acquiring Statsig, a Washington-based product development platform startup, for $1.1 billion to speed up its generative AI-based product launches and accelerate iteration cycles of existing products such as Codex and ChatGPT.
OpenAI drops GPT-5: smarter, sharper, and built for the real worldAugust 7. 2025: More than two years after GPT-4’s release, OpenAI has unveiled GPT-5, boasting sharper reasoning, multimodal input, better math skills, and cleaner task execution, according to the company.
OpenAI challenges rivals with Apache-licensed GPT-OSS modelsAugust 6, 2025: OpenAI has released its first open-weight language models since GPT-2, marking a significant strategic shift as the company seeks to expand enterprise adoption through more flexible deployment options and reduced operational costs. The two new models — gpt-oss-120b and gpt-oss-20b — deliver what OpenAI describes as competitive performance while running efficiently on consumer-grade hardware.
Google snatches Windsurf execs in a $2.4B deal, derailing OpenAI’s biggest acquisition yetJuly 14, 2025: Google has recruited CEO Varun Mohan and co-founder Douglas Chen of AI coding startup Windsurf in a $2.4 billion talent acquisition deal, just two months after Windsurf agreed to be acquired by OpenAI for $3 billion. Mohan, Chen and select research and development staff, will join Google’s DeepMind AI division
OpenAI and Perplexity enter browser wars to take on ChromeJuly 10, 2025: Google Chrome’s dominance in the browser market is facing new threats as OpenAI and Nvidia-backed Perplexity unveil AI-powered browsers aimed at reshaping how users interact with the web. Comet is a new web browser with built-in AI search capabilities, the company said.
Microsoft brings OpenAI-powered Deep Research to Azure AI Foundry agents
July 8, 2025: Microsoft added OpenAI-developed Deep Research capability to its Azure AI Foundry Agent service. The move is designed to let developers use Deep Research API and SDK to embed, extend, and orchestrate Deep Research-as-a-service across data and existing systems.
Oracle to power OpenAI’s AGI ambitions with 4.5GW expansionJuly 3, 2025: OpenAI has signed a significant compute leasing deal with Oracle, under which it will access 4.5 gigawatts (GW) of data center power, marking one of the largest single leasing arrangements in the industry.
OpenAI tests Google TPUs amid rising inference cost concernsJuly 1, 2025: OpenAI has begun testing Google’s Tensor Processing Units (TPUs), a move that — though not signaling an imminent switch — has raised eyebrows among industry analysts concerned about the escalating costs of AI inference and its effects.
Microsoft/OpenAI AGI argument unlikely to impact enterprise ITJune 26, 2025: The contract between the two AI giants has an exit clause once AGI is achieved. The problem: It is impossible to prove when that happens. Either way, IT execs at Macy’s, Bank of America, doubt it will matter.
OpenAI productivity suite could change the way users create documentsJune 26, 2025: OpenAI’s planned productivity suite could dismantle traditional habits of how users create and consume documents in the same the way the company changed browsing and search habits.
o3-pro may be OpenAI’s most advanced commercial offering, but GPT-4o bests itJune 24, 2025: In a head-to-head comparison of the two models, researchers found that o3-pro is far less performant, reliable, and secure, and does an unnecessary amount of reasoning. Notably, o3-pro consumed 7.3x more output tokens, cost 14x more to run, and failed in 5.6x more test cases than GPT-4o.
Microsoft and OpenAI: Will they opt for the nuclear option?June 24, 2025: The fight between Microsoft and OpenAI over what Microsoft should get for its $13 billion investment in the AI company has gone from nasty to downright toxic, with each of the companies considering strategies against the other that can only be described as their nuclear options.
OpenAI walks away from Scale AI — triggering industry-wide rethink of data partnershipsJune 19, 2025: OpenAI has ended its long-standing partnership with Scale AI, the company that powered some of the most complex data-labeling tasks behind frontier models such as GPT-4.
OpenAI’s o3 price plunge changes everything for vibe codersJune 18, 2025: o3 used to be too slow and too expensive for daily coding—no longer. The latency is now bearable, the price is sane, and the chain-of-thought pays off.
Sam Altman: Meta tried to lure OpenAI employees with billion-dollar salariesJune 18, 2025: After reports suggested Meta has tried to poach employees from OpenAI and Google Deepmind by offering huge compensation packages, OpenAI CEO Sam Altman weighed in, saying those reports are true.
OpenAI-Microsoft tensions escalate over control and contractsJune 17, 2025: The relationship between OpenAI and Microsoft is under growing strain amid extended talks over OpenAI’s restructuring, with OpenAI reportedly considering antitrust action over Microsoft’s influence in the partnership.
OpenAI’s MCP move tempts IT to trust genAI more than it shouldJune 16, 2025: OpenAI late last month announced changes to make it much easier to give its genAI models full access to any software using Model Context Protocol (MCP). Here’s why that’s a bad idea.
OpenAI launches o3-pro, slashes o3 price by 80% in bid to widen AI leadJune 11, 2025: OpenAI has unveiled its most advanced AI model to date, the o3-pro, which surpasses competitors on key benchmarks and replaces the o1-pro. The o3-pro is now available for ChatGPT Pro and Team users, as well as through the developer API, with access for enterprise and education sectors beginning next week.
What Microsoft hopes to get from its breakup with OpenAIJune 11, 2025: The once-tight bond between Microsoft and OpenAI has been fraying for well over a year — and it’s getting worse. What the two companies want from each other now is very different from when Microsoft made its original $13 billion investment.
Oracle to spend $40B on Nvidia chips for OpenAI data center in TexasMay 26, 2025: Oracle is reportedly spending about $40 billion on Nvidia’s high-performance computer chips to power OpenAI’s new data center in Texas, marking a pivotal shift in the AI infrastructure landscape that has significant implications for enterprise IT strategies.
OpenAI’s Skynet moment: Models defy human commands, actively resist orders to shut downMay 30, 2025: OpenAI’s most advanced AI models are showing a disturbing new behavior: they are refusing to obey direct human commands to shut down, actively sabotaging the very mechanisms designed to turn them off.
Jony Ive and OpenAI plan ‘bicycles’ for 21st-century mindsMay 21, 2025: OpenAI has announced that it will purchase io, the AI startup founded by acclaimed former Apple designer Sir Jony Ive, who helped create the iMac, iPod, and iPhone.
OpenAI launches Codex AI agent to tackle multi-step coding tasksMay 19, 2025: OpenAI’s most advanced AI coding agent, Codex, will bring parallel task automation to developers—but analysts caution that speed without scrutiny invites “silent failures.”
Cisco taps OpenAI’s Codex for AI-driven network codingMay 16, 2025: Cisco is working with OpenAI and its newly released Codex software engineering agent to give network engineers access to better tools for writing, testing and building code.
OpenAI’s IPO aspirations prompt rethink of Microsoft allianceMay 12, 2025: Microsoft and OpenAI are renegotiating their multibillion-dollar partnership deal to better align with each company’s evolving goals in the artificial intelligence race
OpenAI hires Instacart CEO Fidji Simo to oversee customer-facing appsMay 8, 2025: The hire indicates that OpenAI’s roadmap will involve more structured, productized offerings rather than just API access.
OpenAI offers help promoting AI outside the US, but analysts question why countries would acceptMay 7, 2025: OpenAI, acting as part of the US government-led Stargate AI project, rolled out a program called OpenAI for Countries. The idea is for Stargate to help other countries create their own genAI environments, including data centers and genAI models.
OpenAI reaffirms nonprofit control, scales back governance changesMay 6, 2025: OpenAI has scrapped plans to reduce its nonprofit parent’s oversight and will keep its existing governance structure intact, a move that limits CEO Sam Altman’s influence and responds to mounting external pressure.
OpenAI to acquire AI coding tool Windsurf for $3BMay 6, 2025: The acquisition comes just months after Windsurf explored funding at this same valuation from investors, highlighting the premium being placed on specialized AI coding capabilities, according to reports.
Former OpenAI employees urge regulators to halt company’s for-profit shiftApril 23, 2025: A broad coalition of AI experts, economists, legal scholars, and former OpenAI employees is urging state regulators to keep OpenAI’s nonprofit foundation in control of the company.
OpenAI’s new models can ‘think with pictures’April 17, 2025: OpenAI has released o3 and 04-mini, two reasoning AI models designed to be extra good at programming, math, and science and that can use images to “think,” according to Engadget, This means that users can upload sketches or diagrams, for example, and even if they are of low quality, o3 and 04-mini will understand what is meant.
OpenAI GPT-4.1 models promise improved coding and instruction followingApril 15, 2025: The GPT-4.1, GPT-4.1 mini, and GPT-4.1 nano models, available only via the API, will provide better performance than GPT-4o and GPT-4o mini at a lower price, OpenAI said.
OpenAI slammed for putting speed over safetyApril 11, 2025: According to a Financial Times report, the ChatGPT maker is now assigning staff and third-party groups only a few days to assess the risks and performance of its latest large language models (LLMs) as compared to several months they were given earlier.
OpenAI fears irreparable harm from Musk, files countersuitApril 10, 2025: OpenAI has filed a countersuit against Elon Musk, accusing the billionaire of a sustained campaign to damage the company and urging a US federal court to block further actions it described as unlawful and disruptive. The legal filing, submitted in a California district court, marks the latest escalation in a dispute between Musk and the AI startup he helped establish in 2015.
Senators probe Google-Anthropic, Microsoft-OpenAI deals over antitrust concernsApril 9, 2025: Democratic Senators Elizabeth Warren and Ron Wyden have launched a formal inquiry into partnerships between tech giants Google and Microsoft, and AI startups, demanding detailed information about arrangements they fear may be circumventing antitrust scrutiny while consolidating power in the rapidly evolving AI market.
Anthropic’s and OpenAI’s new AI education initiatives offer hope for enterprise knowledge retentionApril 4, 2025: Two of the biggest names in artificial intelligence are independently developing new AI tools that encourage learning, at a time when the technology has been criticized for dumbing down smart users in the enterprise and discouraging critical thinking. While the new initiatives from OpenAI and Anthropic are aimed at transforming how AI is used in higher education, the opportunities they open up extend beyond universities.
Amazon, OpenAI, and China’s Zhipu unveil new AI tools amid intensifying competitionApril 1, 2025: A wave of new AI products is hitting the market, signaling a shift toward more autonomous, task-completing systems that could reshape how businesses and consumers interact with digital services: Amazon has unveiled Nova Act, an AI agent designed to operate a web browser much like a human user; OpenAI said it will release an open-weight language model; and China’s Zhipu AI introduced a free AI assistant aimed at strengthening its position in the domestic market and competing with Western tech giants.
OpenAI, Google AI data centers are under stress after new genAI model launchesMarch 28, 2025: New generative AI models introduced by Google and OpenAI have put the companies’ data centers under stress — and both companies are trying to catch up to demand. OpenAI’s CEO Sam Altman tweeted that his company was temporarily restricting the use of GPUs after overwhelming demand for its image generation service on ChatGPT.
Microsoft abandons data center projects as OpenAI considers its own, hinting at a market shiftMarch 26, 2025: OpenAI has privately discussed building and operating its first data center to house storage, which is essential for developing sophisticated AI models. Microsoft, on the other hand, has pulled back on its buildouts, canceling data center projects in the US and Europe.
OpenAI calls for US to centralize AI regulationMarch 13, 2025: OpenAI executives think the federal government should regulate artificial intelligence in the US, taking precedence over often more restrictive state regulations.
New tools from OpenAI help companies create their own AI agentsMarch 12, 2025: OpenAI launched Responses, a new api intended to eventually replace Assistants. The big draw? Responses provides a number of new tools that companies and organizations can use to create their own AI agents.
Microsoft is developing its own AI models to compete with OpenAIMarch 10, 2025: Reports suggest Microsoft has decided to seriously challenge Deepseek and OpenAI by developing its own set of reasoning AI models called Microsoft AI (MAI). If successful, Microsoft would eventually not have to use its partner OpenAI’s o1 models in Copilot
Microsoft-OpenAI investigation closed by UK regulatorsMarch 5, 2025: The UK’s Competition and Markets Authority (CMA) spent a great deal of time deciding whether it should investigate Microsoft’s investment in OpenAI as a potential merger situation, but in the end, decided to open and close the investigation within 24 hours.
OpenAI revamps AI roadmap, merging models for a leaner futureFebruary 13, 2025: OpenAI will integrate “o3” into GPT-5 instead of releasing it separately, streamlining adoption while signaling a shift toward fewer, more controlled AI models amid rising competition and cost pressures.
Musk’s $97B offer to buy OpenAI rejected as leadership stands firmFebruary 11, 2025: In a message to staff, Altman said the board has no intention of considering Musk’s offer, stating that the proposal does not align with OpenAI’s mission
OpenAI launches deep research agent for multi-step research tasksFebruary 3, 2025: Hot on the heels of its launch of the o3-mini model, OpenAI announced another component for ChatGPT that allows the generative AI tool to do more in-depth research. “Deep research is built for people who do intensive knowledge work in areas like finance, science, policy, and engineering and need thorough, precise, and reliable research,” OpenAI said in a blog post announcing the new capability.
OpenAI unleashes o3-mini reasoning modelJanuary 31, 2025: OpenAI released the latest model in its reasoning series, o3-mini, both in ChatGPT and its application programming interface (API). It had been in preview since December 2024.
Indian media houses rally against OpenAI over copyright disputeJanuary 27, 2025: The legal heat on OpenAI in India intensified as digital news outlets owned by billionaires Gautam Adani and Mukesh Ambani joined an ongoing lawsuit against the ChatGPT creator. They were joined by some of the largest news publishers in India including the Indian Express, and Hindustan Times, and members of the Digital News Publishers Association (DNPA), which includes major players like Zee News, India Today, and The Hindu.
Altman now says OpenAI has not yet developed AGIJanuary 20, 2025: Confusion over whether OpenAI’s o3-mini has reached the major milestone of artificial general intelligence (AGI) or not deepened following a post on X by CEO Sam Altman that completely contradicts what he said two weeks earlier in an interview with Bloomberg.
Microsoft sues overseas threat actor group over abuse of OpenAI serviceJanuary 13, 2025: Microsoft has filed suit against 10 unnamed people (“Does”), who are apparently operating overseas, for misuse of its Azure OpenAI platform, asking the Eastern District of Virginia federal court for damages and injunctive relief.
With o3 having reached AGI, OpenAI turns its sights toward superintelligenceJanuary 6, 2025: OpenAI CEO Sam Altman has reinvigorated discussion of artificial general intelligence (AGI), boldly claiming that his company’s newest model has reached that milestone.
Now US government agencies can use OpenAI’s ChatGPT tooJanuary 28, 2025: OpenAI has rolled out ChatGPT Gov, a version of its flagship frontier model specifically tailored to US government agencies. The platform has many of the same capabilities as OpenAI’s other enterprise products, including access to GPT-4o and the ability to build custom GPTs — and it also features a much higher level of security than ChatGPT Enterprise.
OpenAI debuts AI agent Operator to transform web task automationJanuary 24, 2025: OpenAI has unveiled “Operator,” a new AI agent designed to perform web-based tasks, offering potential productivity enhancements for enterprises. The tool enables interaction with on-screen elements, positioning it as a solution for automating routine processes in business workflows amid growing competition in the generative AI space.
OpenAI opposes data deletion demand in India citing US legal constraintsJanuary 23, 2025: OpenAI has informed the Delhi High Court that any directive requiring it to delete training data used for ChatGPT would conflict with its legal obligations under US law. The statement came in response to a copyright lawsuit filed by the Reuters-backed Indian news agency ANI, marking a pivotal development in one of the first major AI-related legal battles in India.
OpenAI, SoftBank, Oracle lead $500B Project Stargate to ramp up AI infra in the USJanuary 22, 2025: Several large technology firms including OpenAI, SoftBank, Oracle, Nvidia, and MGX have partnered to set up a new company in the US to ramp up AI infrastructure in the country.
OpenAI is losing money on its pricey ChatGPT Pro subscriptionJanuary 7, 2025: OpenAI CEO Sam Altman, in a post on X, says the AI company is currently losing money on its ChatGPT Pro subscription. “People are using it much more than we expected,” he wrote.
Fine-tuning Azure OpenAI models in Azure AI FoundryJanuary 2, 2025: Microsoft Azure’s new AI toolkit makes it easy to customize OpenAI large language models for your applications.
OpenAI still hasn’t released tools to deny data collectionJanuary 2, 2025: OpenAI has failed to release the tool to opt-out or customize data collection the company promised to make available by 2025, according to Techcrunch.
Pixel 11 envy? Here’s how to unlock its best new feature on any Android device
Have you heard? It’s that time of year again — time for some snazzy new Pixels to tempt our gadget-coveting “gimme!” reflexes and guide flagship Android phone expectations for months to come.
Google’s latest and greatest gizmo is the Pixel 11 series, which includes the regular Pixel 11 and Pixel 11 Pro alongside the plus-sized Pixel 11 XL and Pixel 11 Pro XL and the fancy new folding Pixel 11 Pro Fold model (gesundheit!). El Googaloo took the wraps off all those new devices on Wednesday and has ’em all available for preorder now, with prices starting at $899 (regular Pixel 11), $1,099 (Pixel 11 Pro), and $1,299 (Pixel 11 Pro Fold).
At first glance, this year’s Pixel models might not seem like the most exciting upgrades from last year’s Pixel 10 products. They bring plenty of significant refinements to an already successful formula, with some welcome ticks forward — like better cameras, brighter and more scratch-resistant displays, faster charging speeds, and an updated processor that supposedly leads to speedier and more efficient performance. And, of course, there’s more Gemini everywhere (for better or for worse, depending on your perspective). But impressive as it all may be, it’s mostly iterative improvements over the previous-gen Pixels — which isn’t necessarily a bad thing but also isn’t exactly awe-inspiring, at least on the surface.
The most eye-catching addition to the Pixel 11 series is, rather ironically, a callback from Android’s past. It’s something Google’s calling HiLight, and it’s basically a new series of LED lights built into the freshly thinned-down camera bar on the phones’ backs. The lights illuminate to alert you to different events, allowing you to know about important incoming info at a glance — without having to so much as even look at your screen.
If the concept feels familiar, it should: Early Android devices boasted a similar sort of LED notification light for a very similar purpose. They were less visually striking, but they served the same basic purpose — up until they went out of favor for the far more complex (and, some might argue, less effective) always-on display concept that followed.
Here’s a little secret, though: You don’t have to have a new Pixel 11 phone in front of you to enjoy a similar sort of distraction-reducing, awareness-enhancing sorcery. You can actually recreate the Pixel 11 HiLight glow effect on any Android device this instant — and do it in a way that’s much more versatile, functional, and all-around useful, to boot.
Lemme show ya how.
[Get next-level knowledge in your inbox with my free Android Intelligence newsletter. One new and useful tip every Friday!]
The lowdown on Pixel 11 HiLightFirst things first, a quick hit of context about the Pixel 11 HiLight system and how it actually works.
As of the phones’ launch, HiLight is active only when the device is face down on a surface — perhaps not surprisingly, given that the lights live on the device’s back — and it works only in two super-specific scenarios:
- When you’re in the midst of getting an incoming call from a favorite contact, the Pixel 11 HiLight indicator glows with a custom color so you can see who’s calling and know it’s important. (It works with both the Pixel Phone app and WhatsApp, to start.)
- When you’re interacting with Gemini, HiLight pulses to let you know the system is listening, thinking, and responding.
Aaaaaaaand, that’s it. The system doesn’t work with any other apps, according to Google, and it doesn’t interact with notifications in general to let you know about important pending activity beyond those incoming calls.
It’s actually quite limited, in other words. And no matter what Android phone you’re using — even if it ends up being a Pixel 11! — you can take the same classic concept and make it infinitely more valuable.
The trick revolves around a handy little power-user app called AodNotify. The app has a few different versions, depending on which specific type of Android device is in your paw right now:
- This version is for any and all Pixel phones
- This one is for Samsung Android gadgets
- This one is for OnePlus devices
- And this one is a catch-all for any other brand of Android handset
Whichever version you end up with, AodNotify essentially creates your own custom notification light within your Android phone’s screen — by lighting up the area around your camera cutout at the top of the display, or alternatively creating a border-outline light that goes all the way around the phone front’s perimeter. And it shows up both when the screen is on and when it’s off.
AodNotify puts a Pixel-11-HiLight-style notification light right on any Android device’s display.JR Raphael, Foundry
It serves the same basic purpose as the Pixel 11 HiLight (as well as the old-school 2008-era Android phone LED notification lights that preceded it), but with some key advantages:
- You can see it when your phone is face-up — the way most folks seem to set their devices down when they aren’t actively in use.
- As a result, you can see it when your screen is on and you’re actively using the device as well as when the display is off, as mentioned a moment ago.
- You can have it light up to alert you of any manner of incoming call or notification with the same sort of simple at-a-glance recognition.
- And you can control exactly how and when it works, down to the tiniest of preferences, to make it perfectly useful for you.
Compared to HiLight, the practical value of this approach is absolutely bonkers. Rather than just letting you know about important incoming calls when your phone is face down, AodNotify lets you see at a glance exactly what type of notifications are waiting for you at any given moment — without having to so much as pick up your phone or process any intricate on-screen info.
Whatever alert it flashes can stay present and visible for any amount of time, too, so whether you hear a ding and want to glance to see what’s up or even if you miss the audio alert entirely (or have it disabled deliberately) and want to sneak a peek at your screen to know in a split second what’s waiting for you, AodNotify will get the job done.
And it’s surprisingly easy to set up, too — with two to three minutes of one-time configuration that you’ll never have to think about again.
Your own Android HiLight equivalentAll right — ready? First things first, go install AodNotify from the Play Store, using whichever link is appropriate for your current Android device from above.
Once the app is ready, open ‘er up and follow the prompts to get it going and grant it all the forms of access it needs to operate:
- First, you’ll select which apps can activate your new notification light and cause it to illuminate. If you want any and all notifications to be included, tap the “All” option at the top of the list. If you want to cherrypick and select only certain especially important apps while leaving others off, you can just choose whichever apps you’d like to have included.
- Next, tap the lines for “Notification access,” “Enable AOD,” and “Draw on screen,” if needed, and follow the prompts to enable AodNotify and/or the necessary option for each of the associated areas. This may seem like a lot of access, but AodNotify genuinely needs it to do what it does — and, critically, the app doesn’t require any other system-level permissions, including even access to the internet, so it couldn’t possibly do anything with your data (and its privacy policy is clear about the fact that it doesn’t collect or share any manner of data, ever). It’s also by a known and long-standing reputable Android developer.
- After that, you’ll see a pop-up prompting you to consider the app’s Pro version — which runs five bucks a year or $7 for a single one-time purchase. The Pro path turns off some ads in the AodNotify setup interface and enables some extra features. You may or may not want to consider it eventually, but for now, just hit the “x” in the upper-right corner of that prompt to dismiss it and move on.
JR Raphael, Foundry
Now for the fun part: At the app’s main setup screen, make sure the toggles next to “Notifications” and “Notification light” are active — then tap into each of those sections along with “Colors” and “General” to explore all of the available options.
Of particular note:
- Under “Notifications,” the “Battery” section lets you activate a special notification light for anytime your phone is charging, fully charging, or with a low (less than 15%) battery — so you can always be aware of that info when it arises.
- Under “Notification light,” the “Style” selector will let you shift your spiffy new light from its default camera-cutout-outline position to a full-screen outline or a classic-Android dot-in-the-corner LED-type effect.
- “Effects” in that same section will let you change the light from a simple pulse to all sorts of other interesting light-up patterns.
- “Dimensions” will let you shift the exact size, shape, and placement of the light, if it doesn’t look quite right on your screen.
- And the “How long to show the light” subsection will let you adjust how long any active notification light remains present, both when your screen is on and when the display is dark.
JR Raphael, Foundry
Beyond all of that, some of AodNotify’s most helpful options are in its “Colors” settings section. There, you can specify different distinctive colors for messages or calls connected to different contacts, so you can see who is calling or texting you just by the color of the light (much like what the Pixel 11 HiLight feature does, only with a much broader and more sensible scope). And you can activate an off-by-default option to have your notification light automatically change its color to match the primary hue associated with any given app’s icon — which is a nifty way to know at a glance that a pending alert is coming from, say, your Calendar app or Slack.
AodNotify’s “Auto color” option is one of the app’s most powerful — and easily overlooked — features.JR Raphael, Foundry
And that’s pretty much it. Your Pixel-11-style HiLight upgrade is officially complete — with an even more useful productivity-boosting framework than what the Pixel 11 HiLight version provides.
That’s the power of Android for ya. And it’s a power that’s present no matter what device is in front of you or how long you’ve been holding it.
Never miss a moment of Android awesomeness with my free Android Intelligence newsletter. One new exceptional tip in your inbox every Friday — straight from me to ye.
Armored Likho expands its cyber-espionage toolkit
In May 2026, we discovered a new cyber-espionage campaign by the Armored Likho group, also known as Eagle Werewolf, that targets private individuals and organizations across various industries in Russia, including major corporations, the public sector, IT, and education. The attackers used a fake app as bait that mimics a service for donations. However, the most interesting part of this campaign isn’t the initial infection method – it’s the malicious implants the attackers use for cyber-espionage.
We’ve written previously about recent Armored Likho attacks, but our analysis shows that the campaign discussed below has more in common with the group’s activity from February. That said, the attackers have significantly expanded their arsenal.
During our research, we found a new cyber-espionage toolkit written in Rust: the Still Toolkit. One of its components, Still Sync, steals Telegram session data to gain ongoing access to the victim’s account. With this stolen data, attackers can leverage the Telegram API to automatically pull chat logs, media files, and other information from the account.
The second component, Still Audio, is an implant for covert audio surveillance. It analyzes the incoming audio stream, automatically detects speech, records conversations, and sends the recordings to a command-and-control server.
In this article, we’ll look at the initial infection method, how the new Still Toolkit components are built, and the technical details of how they operate.
Kaspersky products detect this threat as Trojan.Win64.Agent.* and HEUR:Backdoor.Win32.Generic.
BackgroundArmored Likho’s malicious activity has been documented several times before: in November 2024, and in February and July 2026. The current campaign shows significant overlap with the November and February campaigns, which used malicious droppers disguised as documents and applications related to Starlink activation or fundraising efforts as the initial infection vector. This campaign also uses fundraising as its lure. At the same time, our research uncovered a number of new tools that point to the attackers expanding their capabilities.
Initial infectionThe infection chain starts with an app that mimics a donation service. As of this writing, the app distribution method remains unknown. During our research, however, we obtained several samples posing as apps from different Russian foundations.
In reality, the app is a dropper. Its developers wrote it in Rust on top of the popular Tauri framework, and it has a graphical interface designed to deceive the user. After launch, it displays a login form that asks for a password, presumably one the attackers supplied.
The login form
After the user enters a valid password, they see a catalog of donatable items. The app pulls item and category information from orderapiserver[.]info through the public/categories and public/products endpoints. A clickable catalog makes the app look legitimate. While the user browses the items, the dropper quietly decrypts and launches the payload for the next stage in the background.
Our analysis shows that the mechanism for decrypting the payload and launching subsequent stages hasn’t changed since the February campaign. However, we found a new cyber-espionage toolkit – the Still Toolkit – made up of two components: Still Sync and Still Audio.
Still SyncStill Sync is a stealer written in Rust that steals Telegram session data. However, its capabilities don’t stop there. With this stolen data, Sync can log in to the victim’s account and pull messages and media files through the Telegram API.
Architecturally, Sync is an asynchronous application based on the Tokio library. It talks to the server over gRPC and serializes messages with FlatBuffers. It supports both HTTP and HTTPS as transport protocols; the URL of the command-and-control server determines which one it uses.
How it worksWhen Sync launches, the attackers set several environment variables. Before starting any malicious activity, the implant pulls configuration parameters from these:
- STILL_SYNC_ADDR: the address of the command-and-control server. By default, this is https://tg4service[.]com:443.
- STILL_SEND_PATH: the path to the tdata
- STILL_TELEGRAM_PASSCODE: the password for decrypting the tdata folder, if Telegram data encryption is enabled on the victim’s device.
Sync also supports several command-line arguments:
- --console: runs as a console application. If this parameter is absent, the implant creates a TReload service to keep running in the background.
- --version: prints version information and exits.
- --firefly: launches a trace thread that monitors the program’s operation. It writes error messages to a hidden file, bin, located in the same folder as the main executable.
- --db: turns on debug mode with detailed logging.
Example Still Sync logs
Once it launches, the malware begins registering the device with the C2 server. To do this, Sync collects the following information about the victim’s system:
- Motherboard serial number
- CPU ID
- System UUID
- BIOS serial number
- Computer domain name
The malware combines the collected data into a single string with a colon as the separator. It then hashes that string with SHA-256 and stores the resulting hash under the key sysmarker. Worth noting: other Armored Likho tools, AquilaRAT included, use this same hashing algorithm.
Sync then serializes a package containing all the collected information and the agent version, and sends it in a POST request to /still.rpc.Sync/RegisterMachine. The response contains a machine_id value, which Sync uses to identify itself in subsequent requests.
Once registration succeeds, Sync sends a POST request with the machine_id parameter to /still.rpc.Sync/GetMachineSettings. The server responds with the following settings:
- enabled: triggers malicious activity on the infected device.
- scan_portable: turns on extended scanning when searching for the tdata We’ll cover this feature in more detail below.
- fetch_telegram: if this parameter is on, Sync attempts to log in to Telegram and extract data. We’ll cover this feature in more detail below.
- download_channels: if this parameter is off, Sync skips channel dialogs when exfiltrating Telegram data.
These parameters have no default values, so Sync doesn’t perform any malicious actions until the registration and settings-retrieval processes both complete successfully.
Telegram data collectionBefore stealing a Telegram session, Sync searches for the tdata folder, unless the STILL_SEND_PATH variable is already set. The list of search paths includes both standard and nonstandard directories, if the scan_portable option is turned on:
- C:\Users\<username>\AppData\Roaming\Telegram Desktop\: the standard Telegram Desktop installation directory.
- C:\Users\<username>\AppData\Local\Packages\<package_folder>\LocalCache\Roaming\: the installation directory for the Microsoft Store version. Sync identifies the package folder by a name that contains the string TelegramMessenge.
- C:\: used for the extended search (if the scan_portable option is on).
Sync then sends a POST request with a list of files from the tdata folder to the /still.rpc.Sync/CheckFiles endpoint. The server responds with the following values:
- snapshot_id: an identifier the server assigns to the current data snapshot.
- present: a list of file paths that are already present on the server.
This lets the C2 server avoid re-receiving files it already has. In addition, if Sync can’t access files on disk through standard methods, it falls back on three mechanisms that abuse the SeBackupPrivilege privilege:
- Opening files with the CreateFileW function using the FILE_FLAG_BACKUP_SEMANTICS parameter
- Creating a backup copy through the Shadow Copy service and reading files from there
- If the previous methods all fail, attempting to copy the file using the Robocopy utility in backup mode
Beyond stealing Telegram session data, Sync can carry out full-scale collection of user information from the messaging app. When the fetch_telegram option is on, it launches a separate thread that authenticates to the chat app using the previously obtained tdata. Once authentication succeeds, Sync gains access to the account data and sends the following collected information to the server:
- User details, such as username, phone number, first and last name
- Information about private chats, groups, or channels, such as chat name and ID, the member list, and so on
- Dialogs from private chats, groups, and channels (if the download_channels option is on)
- Media files under 250MB: photos, documents, stickers, and contacts
Still Audio is an audio surveillance implant written in Rust. Its main job is to analyze the incoming audio stream and start recording voice when certain conditions are met – we’ll cover those in the next section. Architecturally, Still Audio largely mirrors Sync and uses the same mechanisms for communicating with the C2 server.
On launch, Still Audio performs a sequence of actions:
- It extracts libmp3lame.dll, a file stored inside the executable. This is a library used to encode audio data.
- If the --console command-line argument is absent, the implant creates a service named auxhost, connects to it, and continues running in the background.
- While running in the background, it creates a file, logfile.log, to write logs to.
Next, Still Audio retrieves the C2 server address. As with Sync, it stores the URL in an environment variable – in this case, STILL_AUDIO_SYNC_ADDR. If that variable isn’t set, it falls back to STILL_SYNC_ADDR, which shows the two modules are compatible with each other. If neither variable is set, it uses the default URL, https://srwinservice[.]com.
Still Audio also uses the Dead Drop Resolver technique as a fallback mechanism for obtaining the C2 address. If the current server stays unreachable for three days, the tool tries to pull the current C2 URL from a GitHub repository. In the sample under analysis, we found the following URL for the page containing C2 information: hxxps://raw.githubusercontent[.]com/mmarln/pi-mono/refs/heads/main/packages/pods/src/array12.json
Encrypted C2 address inside the GitHub repository
The repository, a fork of a popular project, contains the server URL Base64-encoded and encrypted with the Blowfish algorithm in ECB mode, using the key 5c8e153228edd3c6cbf75684 (lowercase string). Older AquilaRAT samples use this exact same algorithm and key.
Once it obtains the current C2 address, the Audio module starts a registration process similar to Sync’s, but through a different endpoint:
/still.rpc.Audio/RegisterAudioMachine. Also, unlike Sync, Audio sends a list of available audio input devices along with the system information.
The server responds with settings for the implant:
- machine_id: a unique identifier for the current device.
- vad_threshold: the threshold value for the VAD (Voice Activity Detection) algorithm. Expressed as a decimal fraction, it represents a proportion of the maximum sound level the input device can pick up. Sound above this threshold counts as voice activity. The default vad_threshold is 02.
- max_silence_duration: the number of audio samples with a VAD value below the set threshold after which the implant considers the recording finished.
- max_buffer_size: the maximum buffer size for recorded audio data.
- active_device: the name of the input device selected for recording, from the list of available devices.
Still Audio works with raw audio samples it captures directly from the input device. To detect voice activity, it implements an algorithm based on Root Mean Square (RMS), a lightweight signal-processing method that distinguishes speech from silence by measuring the audio signal’s average power over time. The implant doesn’t rely on any third-party libraries here; it implements all the calculations itself.
The implant compares the calculated RMS value against the vad_threshold parameter. If RMS meets or exceeds this threshold, recording starts. To avoid losing the beginning of the recording, Still Audio uses a pre-buffer, a size-limited buffer that stores samples from just before the current recording moment. A sequence of max_silence_duration samples (320 by default) with RMS values below the threshold signals the end of the recording. For example, with a standard headset running at a 44.1kHz sampling rate, recording stops after roughly 7ms of silence.
Interestingly, the Audio module makes no attempt to hide its use of the microphone: its name shows up in Windows settings. In the sample we examined, the file was saved to disk as IntAudio.exe, and it appeared in the list of apps using the microphone as “Intel Audio”:
The malicious module in the list of apps using the microphone
Before sending recordings to the server, the implant uses the libmp3lame library to encode the raw audio samples. It sends the recording files via a POST request to /tgfrg, adding a Client-Id header containing the machine_id obtained during registration to identify the device.
InfrastructureThis campaign draws on a broad set of hosting providers and domains registered at different points in time, which suggests the attackers are trying to make their infrastructure harder to detect. We found no direct overlap in domains or IP addresses with the February campaign. Even so, the two infrastructures share some similarities:
- They use the same hosting providers, with the ASNs 149440, 202448, and 215311.
- Their domain names follow similar naming patterns that mimic Windows system services and update mechanisms.
In this campaign, we’ve determined that the attackers’ primary targets are users in Russia. Most victims are private individuals, though the corporate sector, government organizations, IT companies, and educational institutions are also affected.
AttributionThis campaign has been using both new tools and malware families documented in BI.ZONE’s February report. While some components turned up for the first time, they show significant code-level overlap with malicious tools seen in earlier Armored Likho campaigns. Based on these overlaps, along with additional technical artifacts, we’re highly confident the Armored Likho group is behind the campaign. The overlaps we identified include:
- Identical dropper architecture in the February and current campaigns, which includes the use of the Tauri library to build the graphical interface, a similar user-input handler, a payload with the ICRYPTMP header, and the same multi-part encryption format.
- The same encryption algorithm and key used in AquilaRAT from the previous campaign and in the Still Audio module from the current campaign, both implementing the Dead Drop Resolver technique.
- Identical logic for generating the sysmarker value in older AquilaRAT samples and in the Still toolkit from the current campaign. The algorithms match down to the PowerShell commands used to collect system information.
- Substantial infrastructure overlap, which includes the hosting providers and domain-naming patterns described in the Infrastructure section.
The campaign described in this post shows Armored Likho’s toolkit evolving, with the group steadily expanding its cyber-espionage capabilities. Beyond the components we already knew about, the attackers rolled out new modules that let them not only access Telegram data but also conduct audio surveillance on victims. Together, these capabilities significantly widen the range of information attackers can collect in a single compromise.
One point deserves particular attention: the new tools form a cohesive set, sharing similar architecture, C2 communication mechanisms, and common implementation elements. This points to the group building out its own tool ecosystem, designed for long-term use and further expansion.
The emergence of new, specialized modules shows the attackers aren’t just trying to preserve their existing capabilities – they’re working to make intelligence-gathering more effective by controlling multiple communication channels at once.
Indicators of compromiseAdditional information about this threat, indicators of compromise included, is available to customers of Kaspersky Threat Intelligence Reporting. Contact [email protected] for more details.
File hashes
Droppers
C1D1EE16B92E6A138FFA048855F75D7D
17674B250D8B422A50A86C9FF207186D
62801F6223E860A7CCA271522E303B2D
Still Sync
68F0365D2FA8C828D012D8859E52A773
4BD7C352AE277B0E38D07BEEDD4DD507
D4BC09FB10EA2A5DC0BCBEEDA5E5AFDD
Still Audio
2CA8ADBAB98EBE305EACF272CF48F5A0
3AC41B097236A7723821848AE31EF141
439255736797BC88BD19F282449E0436
Domains
orderapiserver[.]info
tg4service[.]com
srwinservice[.]com
screenserv[.]com
windowserv[.]net
managementapiservice[.]com
service8date[.]com
updateservs[.]com
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Lovable bolsters its AI software creation capacity, touts $400M funding round
Lovable, the Swedish-based AI software creation platform company, today announced an acceleration of its product, infrastructure, and team development efforts — and a noteworthy round of Series C funding totaling $400 million.
The company said in its statement that it is looking to augment its platform, which it boasts is already used by almost two-thirds of Fortune 500 companies.
Headquartered in Stockholm, Lovable plans to grow its team to 450 people this year, hiring most heavily in machine learning, product, infrastructure, and security roles, and is looking to expand operations from its home base to include locations in London and three US cities: Boston, San Francisco, and New York City.
The planned growth is made possible by the latest infusion of venture capital, which follows a $330 million Series B funding round last December. Lovable now has a $13.3 billion valuation.
The Series C funding was led by Menlo Ventures and the Scaleup Europe Fund and includes US-based Regent. (Regent is the parent company of Foundry.)
Earlier this month, Lovable announced a partnership with Cerebras Systems, the chipmaker that builds processors the size of dinner plates (the Wafer-Scale Engine) and supercomputing systems built for AI inference and training. Cerebras systems are designed to keep an entire AI model’s weights on a single, super-sized WSE chip, rather than split across many GPUs, to avoid GPU memory bottlenecks.
That partnership calls for Lovable to run some of its latency-sensitive workloads on dedicated Cerebras capacity.
“Fast AI is more valuable than slow AI,” said Cerebras CEO and Cofounder Andrew Feldman said in a statement when the partnership was unveiled. “When AI responds in real-time, users do more with it, stay longer, and run higher value workloads. Software creation is one of the clearest examples of the importance of speed. Creators don’t want to wait.”
In its statement today, Lovable said that since its launch in November 2024, people have created more than 60 million projects with its tools, with Lovable-built apps seeing more than 900 million visits a month.
Computerworld is part of Foundry, which is owned by Regent.
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
Android malware combo takes out loans and relays victims' credit cards
Terabytes of credentials leaked in massive supply-chain attack
Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed.
The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than 2,500 organizations.
40 minutes is all it takesThe credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository. Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained. Neither firm identified the source of the information.
Researcher bypasses Microsoft Defender security patch, seizing control
Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent bypass that provides system-level control to attackers once they gain any level of access.
The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security.
Nightmare Eclipse has not provided the further details we requested, however Microsoft sent a brief statement, saying, “Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims,” and reiterating its commitment to investigating issues and supporting coordinated disclosure.
But the proof of concept (PoC) security bypass, ShieldBreak, described by Nightmare Eclipse in a series of public posts, potentially threatens to be more damaging than earlier bypasses.
Like other recently reported vulnerabilities, ShieldBreak requires an attacker to first somehow gain system access, typically via a successful phishing scam. Once in, however, the attacker can gain full admin/root access.
But there is a troubling psychological component to ShieldBreak, in that it is a bypass for a recently posted security patch from Microsoft, noted Justin Greis, CEO of consulting firm Acceligence. The problem is that CISOs who have already deployed that patch might feel protected when they are not.
“This one is concerning because the patch bypass directly calls the integrity of the remediation into question,” he said. “ShieldBreak appears to demonstrate that an attacker can bypass the fix Microsoft shipped for CVE-2026-50656 and ultimately obtain system-level privileges on the endpoint. That is an important distinction for enterprise defenders, because organizations may believe they have already remediated the underlying vulnerability. A successful patch bypass means the exposure can persist even after the normal vulnerability-management process says the system is protected.”
Greis added that such bypass can reduce overall trust in official patches.
“When public proof of concept code can bypass it, the CISO’s question becomes ‘have we actually removed the exposure?’ rather than simply ‘have we deployed the patch?’,” he said. “From an architecture perspective, organizations should be very careful about allowing the same security product to become both the control being relied upon and the only source of evidence that the control is working.”
Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, said he was especially concerned about the timing of the PoC’s release, given that it seemed to be intended to put the most pressure on Microsoft, given its typical timing for security patches.
“This vulnerability, if valid, would need a fix from Microsoft, but because those patches are usually only released on the second Tuesday of the month and the security researcher seems to have carefully timed the release of the PoC, we may have this exposure for another 4 weeks unless Microsoft deems this a very high severity risk, which is unlikely,” he pointed out.
Cybersecurity consultant Brian Levine, executive director of FormerGov, agreed that CISOs should not underestimate the damage potential if this PoC proves valid.
“What makes it dangerous is what it does once they’re in: it turns an ordinary low-privilege account into full system control by abusing Defender itself, the security tool running at the highest privilege on the box,” he said. “An exploit that lives inside your antivirus is quiet, it’s trusted, and it can be used to blind or disable the very thing you’re counting on to catch the intruder. It’s not a worm, but it’s a near-ideal second stage for ransomware crews and anyone doing hands-on-keyboard intrusion.”
Levine suggested that CISOs not wait for a Microsoft fix, but immediately take an aggressive defensive stance.
“Assume it’s live and lean on defense in depth, because this is exactly the scenario where treating Defender as your only line fails you. Application allowlisting, such as WDAC or AppLocker in enforced mode, is the strongest hardening available and can stop the payload even if the race succeeds,” Levine said.
“Tighten local admin rights and least privilege so a foothold has less to escalate from. And give your hunters one very specific thing to watch for: an interactive shell or scripting host running as system whose parent process is Defender’s engine, MsMpEng.exe. That should never happen in a healthy environment and it’s a high-fidelity sign someone is running this.”
But he also suggested that CISOs not assume that the PoC necessarily works as advertised.
“This is a single researcher’s proof of concept. It hasn’t been independently verified, and it’s coming from someone in the middle of a very public and very bitter fight with Microsoft, so perhaps some of the theater around it should be discounted,” Levine said. “But you can’t wave it away either. Patch bypasses are extremely common, and the claim that Microsoft’s fix for RoguePlanet didn’t fully close the door is entirely plausible. Defenders should treat it as credible until proven otherwise, not the reverse.”
Although Levine and other analysts were initially dubious, there are now indications that the PoC’s effectiveness has been independently verified.
Cybersecurity and risk advisor Steven Eric Fisher, a former cybersecurity risk specialist at Walmart, said, “I’ve seen independent confirmation that ShieldBreak works, although its exploitation method differs materially from the original RoguePlanet exploit. RoguePlanet relied on a filesystem race condition, while ShieldBreak appears to use a different Defender/Cloud Filter API path,” Fisher said. “So while it is being characterized as a bypass of Microsoft’s CVE-2026-50656 fix, it is not simply a replay of the original exploit.”
He added that cybersecurity researcher Kevin Beaumont has already published Microsoft Defender Advanced Hunting detections for ShieldBreak that organizations can incorporate into monitoring while evaluating their exposure.
And Pieter Arntz, malware intelligence researcher at Malwarebytes, also said he has seen confirmation from a researcher he tracks, Will Dormann.
This article originally appeared on CSOonline. It has been updated with a statement from Microsoft and further confirmation of the exploit.
Researcher creates workaround for Microsoft Defender security patch
Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent workaround that provides system-level control to attackers once they gain any level of access.
The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security.
Nightmare Eclipse has not provided the further details we requested, however Microsoft sent a brief statement, saying, “Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims,” and reiterating its commitment to investigating issues and supporting coordinated disclosure.
But the proof of concept (PoC) security workaround, ShieldBreak, described by Nightmare Eclipse in a series of public posts, potentially threatens to be more damaging than earlier workarounds.
Like other recently reported vulnerabilities, ShieldBreak requires an attacker to first somehow gain system access, typically via a successful phishing scam. Once in, however, the attacker can gain full admin/root access.
But there is a troubling psychological component to ShieldBreak, in that it is a workaround for a recently posted security patch from Microsoft, noted Justin Greis, CEO of consulting firm Acceligence. The problem is that CISOs who have already deployed that patch might feel protected when they are not.
“This one is concerning because the patch bypass directly calls the integrity of the remediation into question,” he said. “ShieldBreak appears to demonstrate that an attacker can bypass the fix Microsoft shipped for CVE-2026-50656 and ultimately obtain system-level privileges on the endpoint. That is an important distinction for enterprise defenders, because organizations may believe they have already remediated the underlying vulnerability. A successful patch bypass means the exposure can persist even after the normal vulnerability-management process says the system is protected.”
Greis added that such workarounds can reduce overall trust in official patches.
“When public proof of concept code can bypass it, the CISO’s question becomes ‘have we actually removed the exposure?’ rather than simply ‘have we deployed the patch?’,” he said. “From an architecture perspective, organizations should be very careful about allowing the same security product to become both the control being relied upon and the only source of evidence that the control is working.”
Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, said he was especially concerned about the timing of the PoC’s release, given that it seemed to be intended to put the most pressure on Microsoft, given its typical timing for security patches.
“This vulnerability, if valid, would need a fix from Microsoft, but because those patches are usually only released on the second Tuesday of the month and the security researcher seems to have carefully timed the release of the PoC, we may have this exposure for another 4 weeks unless Microsoft deems this a very high severity risk, which is unlikely,” he pointed out.
Cybersecurity consultant Brian Levine, executive director of FormerGov, agreed that CISOs should not underestimate the damage potential if this PoC proves valid.
“What makes it dangerous is what it does once they’re in: it turns an ordinary low-privilege account into full system control by abusing Defender itself, the security tool running at the highest privilege on the box,” he said. “An exploit that lives inside your antivirus is quiet, it’s trusted, and it can be used to blind or disable the very thing you’re counting on to catch the intruder. It’s not a worm, but it’s a near-ideal second stage for ransomware crews and anyone doing hands-on-keyboard intrusion.”
Levine suggested that CISOs not wait for a Microsoft fix, but immediately take an aggressive defensive stance.
“Assume it’s live and lean on defense in depth, because this is exactly the scenario where treating Defender as your only line fails you. Application allowlisting, such as WDAC or AppLocker in enforced mode, is the strongest hardening available and can stop the payload even if the race succeeds,” Levine said.
“Tighten local admin rights and least privilege so a foothold has less to escalate from. And give your hunters one very specific thing to watch for: an interactive shell or scripting host running as system whose parent process is Defender’s engine, MsMpEng.exe. That should never happen in a healthy environment and it’s a high-fidelity sign someone is running this.”
But he also suggested that CISOs not assume that the PoC necessarily works as advertised.
“This is a single researcher’s proof of concept. It hasn’t been independently verified, and it’s coming from someone in the middle of a very public and very bitter fight with Microsoft, so perhaps some of the theater around it should be discounted,” Levine said. “But you can’t wave it away either. Patch bypasses are extremely common, and the claim that Microsoft’s fix for RoguePlanet didn’t fully close the door is entirely plausible. Defenders should treat it as credible until proven otherwise, not the reverse.”
Although Levine and other analysts were initially dubious, there are now indications that the PoC’s effectiveness has been independently verified.
Cybersecurity and risk advisor Steven Eric Fisher, a former cybersecurity risk specialist at Walmart, said, “I’ve seen independent confirmation that ShieldBreak works, although its exploitation method differs materially from the original RoguePlanet exploit. RoguePlanet relied on a filesystem race condition, while ShieldBreak appears to use a different Defender/Cloud Filter API path,” Fisher said. “So while it is being characterized as a bypass of Microsoft’s CVE-2026-50656 fix, it is not simply a replay of the original exploit.”
He added that cybersecurity researcher Kevin Beaumont has already published Microsoft Defender Advanced Hunting detections for ShieldBreak that organizations can incorporate into monitoring while evaluating their exposure.
And Pieter Arntz, malware intelligence researcher at Malwarebytes, also said he has seen confirmation from a researcher he tracks, Will Dormann.
This article originally appeared on CSOonline. It has been updated with a statement from Microsoft and further confirmation of the exploit.
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
Lovable raises another $400M, confirms new $13.3B valuation
Europe’s favorite vibe-coding startup Lovable has confirmed previously reported whispers that it was raising another mega round at a $13.3 billion valuation. Lovable said on Wednesday that it has raised $400 million in a Series C round led by Menlo Ventures and the Scaleup Europe Fund, with more than a dozen other investors participating.
This new funding comes after Lovable hit $500 million in annualized run rate revenue in June, the startup told TechCrunch. Its previous round, announced in December, brought in $330 million at a $6.6 billion valuation and was also led by Menlo Ventures, with CapitalG as co-lead.
Note: One of Lovable’s new Series C investors is Regent, the investment firm that owns Foundry.
Hundreds of fake Chrome VPN extensions route traffic through a proxy
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
IT infrastructure shortages are real and lasting. Here’s how to cope
Lead times of nine to 12 or even 18 months. Costs rising by 35%, 45%, even 50% to 200%. More than halfway through 2026, the market for IT infrastructure that’s crucial for enterprise projects, including those involving artificial intelligence, is strapped.
Memory is at the root of the shortages. Memory prices “have risen by 50% to 200%, resulting in PC prices increasing by 35% to 45% and some server prices rising over 125%,” according to Jon Forest, VP analyst at Gartner. Network switches also need memory, albeit in lesser amounts than servers, so they are not immune, with prices and lead times likewise rising dramatically.
Industry experts agree that most of the issues stem from hyperscalers gobbling up memory capacity, which trickles down to servers, storage systems, and networking devices. But while the source of the problem may be new, supply chain disruptions are far from unprecedented.
As a result, industry insiders are not short on advice on how best to deal with the situation, with tips including making better use of what you have, considering options beyond your usual scope, and lots of planning with your vendors and internal finance teams.
State of the problemJust how bad is the current supply chain problem? “It’s pretty bad,” says Matt Kimball, vice president and principal analyst with Moor Insights & Strategy. Companies accustomed to 30- to 45-day lead times for various infrastructure are now looking at 6, 12, or even 18 months.
“It’s real, and I’m hearing it from companies of all sizes, from the 1000-server to the 10,000-server shops,” Kimball says.
“Memory costs are expected to rise sharply well into 2027 and will reach up to 25% of network hardware expenses by the end of 2027,” according to an email Gartner’s Forest sent to Network World. The figure below shows the timeline Gartner expects for memory prices, and Forest notes that the same timing applies across networking, storage, and compute infrastructure.
Gartner
“Enterprise network equipment pricing is projected to increase by over 20% in 2026. This upward trend is anticipated to continue with a further rise of 3% to 5% entering 2027, with no signs of price reduction until the end of 2027.”
But “reduction” will likely look more like “stabilization.”
“That’s something a lot of people don’t like to talk about. But let’s say prices went up 40%, they may come down five,” says Phillip Privett, senior vice president of vendor management with the global distributor and value-added reseller TD SYNNEX. “They’re not going to come down 40%.”
Perhaps worse, compared with past disruptions caused by issues such as fires in chip fabrication factories or the Covid pandemic, Kimball says this one is “durable” because its cause—the AI wave—is more long-lasting and just getting started.
“This AI inference wave we’re hitting is just beginning. It’s going to be longer and bigger than the training wave,” he says. “It’s impacting everything, from AI infrastructure to the traditional stuff that’s standing up your virtualization and cloud infrastructure.”
No vendors seem to be immune, not even the likes of Cisco, which makes its own Cisco Silicon One chips. Or, at least, it designs the chips; they’re actually manufactured by the Taiwan Semiconductor Manufacturing Company (TSMC), the same company that makes many of the other chips that are in such demand. And that’s only one component of many that comprise a switch.
On the other hand, the margins Cisco gets from enterprise sales are far greater than those from hyperscalers because Cisco sells mainly just hardware to hyperscalers, whereas enterprise sales generally include software and services as well. So, Cisco has incentive to keep enterprise customers happy and maintain the 66% margins it reported in Q3, its latest quarter.
Still, Cisco must deal with the same shortages as other vendors.
“I wouldn’t say any company is faring better than others,” says Neil Anderson, vice president and CTO for cloud, infrastructure, and AI solutions at World Wide Technology (WWT). “There may be nuances that some suppliers are employing to balance it to some extent, but I fail to recognize a supplier that’s not having almost the same issue.”
Cloud storage vendor Backblaze is one company that’s facing equipment cost and availability issues. “There are different types of shortages occurring in multiple places, all driven by unusual market demands, really by just a handful of very large buyers,” says James Rowell, senior vice president of operations with Backblaze.
Backblaze is constantly forecasting and monitoring demand triggers, Rowell says. That involves close alignment with the sales team to forecast client needs, as well as paying attention to historical trendlines to predict upcoming demand from new deals and growth with existing clients. But the company also looks for “unnatural market-related triggers” that would cause a spike in utilization.
With hyperscalers buying up vast amounts of capacity, “This is definitely an unnatural phase,” Rowell says. “For about for the last 12 months, I would say there’s been somewhere between a 15% and 30% uptick in costs,” especially in terms of servers and compute disks.
On the positive side, at least for Backblaze, the company is also seeing an uptick in business from an interesting source: AI companies. “We reported in the last earnings period a 70% increase in AI companies using our platform,” says Patrick Thomas, vice president of marketing at Backblaze. “That’s massive.”
On top of that, the company is seeing an uptick in deals from enterprises that can’t get the storage capacity they need or want on-prem. “There’s a general market nervousness where we’ve got potential deals coming our way because those organizations are concerned about being able to do it themselves,” Rowell says.
While some expect new chip fabrication plants currently under construction will ease memory supply constraints, Privett doesn’t buy it. “I don’t see it getting better anytime soon,” he says. “Building a new fab is a two-year process.”
Advice: Start with the basicsEnterprises, then, must play the cards they’re dealt. For Moore Insights’ Kimball, who did stints as an IT exec with the states of Florida and Oregon, that starts with making the most of what you have.
Such a strategy is “shockingly not implemented much” across the companies he sees. “A simple capacity planning exercise can free up a lot of resources.” That includes virtualized servers running at just 20% to 30% utilization as well as extending the life of existing servers. While 15 or 20 years ago it was common to refresh every four years or so, companies can often get six or seven years out of today’s servers.
While such strategies won’t solve your AI compute challenges, they can certainly help support your ongoing operations and free up budget for AI and other modernization projects, he says.
“Sweat your assets,” agrees Privett of TD SYNNEX. “Work them as much as you can, add only what you need, get extensions on your licensing, renewals on your services agreements and things like that. Just sweat it out a little longer.”
If you have budget to spend but can’t get the hardware you’re after, buy something else, says WWT’s Anderson. “Look at things that are not tied to those components, like software projects or SaaS licensing,” he says.
Get friendly with finance teamsNumerous experts recommend regular meetings with your CFO or finance teams to keep them apprised of what you’re up against so the company can plan accordingly.
Gartner’s Forest advises using rolling 12- to 24‑month forecasts and engaging early with suppliers to identify constrained components and SKUs. Committing to quarterly or monthly buys can help you avoid long-term agreements that extend past the rapid increases we’re seeing in 2026, he says.
Also engage with the financing arm of your equipment vendors, some of which are offering financing incentives, Privett says. Compute vendors in particular are offering subsidized financing, deferred payments, and low-cost financing for the first year or so. “Those are huge opportunities to take advantage of,” he says.
By engaging with finance teams, IT groups can conduct budget allocation exercises and try to come up with ways to make the financials work. The last thing you want to do is surprise them with additional budget requests out of the blue.
Kimball recalls his days with the state of Florida, when all budget requests were examined by a technical review working group—which was designed to be hostile.
“I can’t imagine going to them and saying, ‘Oh, did I say that was a million dollars? It’s actually $2 million. I need you to write me a bigger check,’” he says. “I would walk into one of the swamps in Tallahassee and get eaten by the alligators instead of doing that.”
Work with your vendors and VARsAs you put plans together, lean on your vendors for help, including channel partners such as value-added resellers (VAR) and national resellers. “Work with them to map things out and understand what your workloads will look like,” Kimball says.
That’s what Backblaze’s Rowell regularly does with his suppliers. He lays out his forecast for the year, with commitments on what Backblaze will definitely buy, as well as scenarios that account for rapid growth, say, 2x. “And they’ll come back with, ‘Well, okay, no problem,’ or maybe they say we need to put in an allocation right away, or we won’t be able to get what we may need,” he says.
Similarly, he sits down with his CFO regularly to map out predictive models that factor in inflation, price hikes, and the like. The idea is to plan out multiple scenarios, so you don’t get blindsided.
“If you don’t do that, you’ll get caught with your pants down, on the upside-down end of spectrum,” he said – meaning not having the capacity to take advantage of market opportunities.
Acquiring the capacity you need to meet project demand may also mean being flexible in terms of your equipment choices. If you’re a Dell shop but can’t get Dell servers, maybe you go with Lenovo, Kimball says.
“You’ve got to figure out how to use all this silicon and infrastructure in a heterogenous way to serve your needs,” he says. That’s especially true when it comes to AI infrastructure. “If you think you’re going to go with 100% Nvidia for everything from RAG [retrieval augmented generation] to inferencing at the edge, you’re kind of crazy, not because of cost but because of availability.”
Look at alternatives, including AMD and cloud solutions, while staying mindful of how it all plays together. You may not be able to get Nvidia GPUs, but AWS, Azure, and Oracle Cloud have them, Kimball notes.
Be strategic, perhaps by using cloud offerings to handle certain tuning or inference workloads, then bringing them back in-house when appropriate. “Have a better understanding of what absolutely has to be on prem and what can be in the cloud,” he says.
That’s good advice, says Backblaze’s Thomas. When it comes to AI, think about performance tiers and the range of use cases you have. They don’t all need top-tier performance.
“People get wrapped around axle of needing the top end. There’s a lot of flexibility in the edges, innovation in different hardware and software,” Thomas says.
Gartner likewise advises companies to increase configuration flexibility and expand sourcing paths. That may include buying from secondary markets and lease-return programs to preserve continuity with existing infrastructure until the shortages pass, Forest says.
Get started somewhereEven if you can’t acquire or have to wait for the infrastructure you need, don’t let that keep you from getting started with AI or other modernization projects.
Options include public cloud and neocloud providers, Anderson says. WWT also provides capacity in its own lab so customers can get started with proof-of-concept projects. “Don’t just throw your hands up. We can help you find access to capacity,” Anderson says. “Production-scale AI may be delayed, but don’t let that derail your strategy.”
Colocation providers may likewise be an option, especially if enterprises are struggling to acquire high-end networking equipment. Networking is a key value proposition for colocation providers, in that they have built-in connections to various cloud providers and other ecosystem players.
Equinix, for example, has 280 data centers in 77 metropolitan areas, says Phil Read, senior director, colocation product management for the company. If you have the compute infrastructure, Equinix can help you with the high-end connectivity required both intra- data center and at edge facilities.
It also has partnerships with the likes of Cisco and Nvidia for “ready-to-go AI connectivity,” Read says. That means Equinix offers the right infrastructure to meet the requirements of high-end compute solutions in terms of power density and cooling. Such power densities are significant, requiring 120k VA per rack and up. “There’s plenty of talk about a megawatt rack,” he says.
Power is a significant issue in this entire discussion, Privett says. Older installed computing infrastructure likely consumes far more power than newer systems, which is an argument for upgrading as soon as possible.
“If you modernize today, you could substantially reduce the number of servers needed to support the same applications at a much lower power consumption rate,” Privett says. He advises sitting down with folks from the OT side of the house to make sure power is available for whatever you want to do. In many areas, power is at a premium.
If your plans include installing GPU environments in your own data center, WWT advises you not to delay. “We’re telling customers, you need to talk with us and get that designed, get that ordered, because it will take quite a bit of time until it actually ships and we’re able to install it,” Anderson says.
Lazarus hackers exploited Windows zero-day to target defense firms
Jak bezpečně vyfotit zatmění Slunce mobilem a nevypálit si u toho zrak ani snímač
New Linux Private Futex Race Can Trigger Kernel Use-After-Free
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- …
- následující ›
- poslední »



