Computerworld.com [Hacking News]

Syndikovat obsah
Making technology work for business
Aktualizace: 19 min 23 sek zpět

Microsoft mops up after Patch Tuesday broke logins, audio, Excel

18 Září, 2026 - 19:22

Microsoft fixed hundreds of security flaws in its September Patch Tuesday software updates — but it also introduced some annoying bugs. Now it has fixed some of them with a series of out-of-band updates.

Excel 2016 users were among the victims, as Patch Tuesday update caused certain paste operations to fail. A hotfix in update 5002665 partly fixes the problem, but if operations still fail then users will have to resort to using Excel’s “Paste special” command instead.

Users of Remote Desktop Services had found some instability in the application where RDP connections failed or where servers were left hanging at “Please wait for the Remote Desktop Configuration”. The issue was resolved with update KB5129194.

 Another issue that users were facing after the update was a problem with some Credential Guard-protected machine accounts. Some users discovered that they had lost some security within Active Directory which meant that some devices were not recognized. The solution involves temporarily preventing Machine Identity Isolation enforcement before installing a fix. Microsoft said that it would be introducing a permanent solution in a future update.

Another issue raised by the September update affected applications that use HCS-managed virtual machines. In some cases, Plan9 users found that they were not able to access folders shared from the Windows host.

Applications that depended on these shared folders sometimes displayed an error indicating that no Plan9 drive shares were mounted. Microsoft said that Claude Cowork and the Windows Subsystem for Linux (WSL) were two of the applications affected, while Hyper-V virtual machines that did not have the Plan9 feature were not affected.

Microsoft also fixed an issue with USB Audio Class 1.0 devices. Some users found that no sound was coming from their audio devices after the Patch Tuesday update, and volume controls were unresponsive. Now restored sound, so affected users can once again make and take Teams calls.

In addition to these fixes from the September update, there was also an issue for some users where they were incorrectly informed that Microsoft Defender had been switched off. This has now been resolved.

Kategorie: Hacking & Security

GhostCode attackers abuse device codes to take over Microsoft 365 accounts

18 Září, 2026 - 17:16

Microsoft 365 users are being tricked into handing over access to their accounts by a new phishing kit, GhostCode, that exploits a weakness in a legitimate device authorization flow. Researchers in eSentire’s threat response unit identified the campaign in late August 2026.

The kit abuses Microsoft’s OAuth 2.0 device authorization grant flow, a legitimate mechanism designed to enable authentication from IoT devices, smart TVs, printers, or other devices that cannot easily support a conventional browser-based login. The technique, known as device-code phishing, has been seen in other attacks before. As part of the flow, the device displays a code for the user to enters in a browser on another device to complete authentication.

GhostCode poses as one such device, gets Microsoft’s OAuth to generate a device code and then convinces the victim to enter it on Microsoft’s authentication page. The victim then signs in and completes multifactor authentication as normal — but the authentication is for the attacker-controlled device, allowing them to obtain the resulting authentication tokens. These tokens are then used to register attacker-controlled devices, obtain additional credentials and establish persistence in the victim’s Microsoft environment.

In the campaign observed by eSentire, the attack involved a social-engineering setup where attackers pose as procurement officers through a web contact form before moving conversations to an NDA-themed HTML file. Opening the file took the victim to the device-code phishing page.

Stolen tokens allow persistence

GhostCode’s post-authentication activity is focused on turning the stolen access into persistence inside the Microsoft environment. Once access was granted, eSentire recorded nine successful API calls over a 78-second period, involving Microsoft Intune Enrollment, the Device Registration Service, Azure Active Directory and Microsoft Graph.

Three devices were registered during that time, at 28, 53 and 77 seconds after authentication, a sequence eSentire said was automated.

The third device was also successfully enrolled into Intune, Microsoft’s cloud-based device management service. eSentire noted that Intune enrollment survived token revocation: The attacker-created device remained in the tenant until it iwas explicitly removed.

The attackers also obtained a Primary Refresh Token (PRT), which eSentire called “one of the most powerful” credentials in a Microsoft identity environment.

“Obtaining a PRT via device code abuse gives the threat actors essentially SSO-equivalent access to the victim’s entire M365 environment for the PRT’s lifetime — including any service not explicitly protected by a Conditional Access policy requiring a compliant device,” eSentire said, adding that the token persists 14 days by default.

The attackers also employed multiple evasion techniques, including padding and obfuscating the HTML code in their lure, encrypting redirects, checking for bots, and using Cloudflare Turnstile to keep security tools away from the phishing page.

What defenders can do

To defend against attacks like this, eSentire’s researchers recommend restricting Microsoft’s device-code authentication flow through Conditional Access and disabling it for users who do not need it. It also advises monitoring the Device Registration Service for multiple device registrations from a single non-interactive session, and looking for activity involving the user agent python-requests following device-code authentication.

Auditing Entra ID for devices matching GhostCode’s naming pattern and correlating successful device-code authentication with subsequent Python-based requests, should be able to catch an attack in progress, the company said. It shared a list of indicators of comprise related to the campaign to aid detection.

GhostCode adds to a growing number of attacks abusing device-code phishing to target Microsoft’s OAuth authentication flow. Recent examples include attacks using the “EvilTokens” phishing-as-a-service (PhaaS) kit, a campaign reported by KnowBe4 in February 2026, and activity observed in December 2026 involving multiple clusters, including both financially motivated and state-sponsored actors.

Kategorie: Hacking & Security

With Siri Recap, Apple threw a punch at OpenAI no one saw coming

18 Září, 2026 - 17:08

John Ternus’ Apple threw a curveball at OpenAI with Siri Recap on Apple Watch, accelerating a conversation about privacy and data protection in an AI-augmented digital era. It’s a move that may yet contribute to finding a balance between scary surveillance and digital convenience.

Think of it this way: Apple operates on such a big scale that it must have expected the feature to face regulatory and legal investigation. We know Apple has tried to stay on the right side of existing data protection and privacy laws by ensuring that its system doesn’t keep personal data, audio recordings, or transcripts, but one thing it doesn’t do is achieve consent from everyone who may be exposed to the feature. That’s a big no-no in some places, and it’s logical to think Apple expects some pushback to that.

Apple thought it through

From where I sit, it looks like Apple has thought about this. You only need to look to Apple Worldwide Marketing VP Greg Joswiak’s recent comments on the matter to see this, as he very swiftly tried to position Recap as little more than the digital equivalent of notebook and pen, or a smartphone set to record. The difference is that using the latter still technically requires consent in some places, while using a pen and paper does not. 

But if Apple has thought about it and anticipates oversight, then there are benefits to be had. Apple is not the only company seeking to use ambient data monitoring and AI tech to create new product families. Meta, OpenAI, and others also seem to be exploring ambient monitoring with AI, possibly with less of a commitment to privacy.

While it’s true as a general rule that your rights in a public place are weaker, they are not nonexistent, and both Apple and OpenAI must expect to face regulatory pushback on what they make.

This could be why Apple has accelerated regulatory conversation concerning such tools by introducing Siri Recap. The argument is that by forcing legislatures to make decisions on such matters, Apple is effectively throwing a punch at competitors who must also work within the law. (Though with data encryption such a huge piece of the privacy jigsaw, it’s fair to say that some nations may yet mess things up.)

Because it isn’t just about Apple

It makes sense for international lawmakers to create a harmonized framework of legislation to govern such products, particularly as they clamber headlong into so many different layers of protected personal existence. Apple’s decision to create this product at this time means regulators will now have to decide where to draw the line. 

We can surmise where Apple thinks that line will be on the basis of what Joswiak said and the actions the company has taken with a variety of guardrails to maintain privacy and data security. The idea it seems to be moving toward is that by stripping out the stuff we want kept private, it has effectively built the digital equivalent of writing a few notes in your book with a pen while a conversation takes place.

If Apple’s argument prevails, then those will become the regulatory-approved principles to define what other companies must do with their devices in this space. Including Meta and OpenAI.

Caught in a trap

That’s going to be fine for some entities, but companies that want to build businesses on your data will be disadvantaged by those decisions. Apple’s approach is that by defining the space, it also knows precisely what it must do to compete within it. That’s going to make for a far more equal playing field as AI hardware reaches the market.

A second outcome Apple may also be looking at is that by challenging regulators to sit down and declare what data and privacy rights consumers should enjoy in an AI digital age, it also identifies terms of reference to inform how its future AR glasses handle and process external video. Right now, it’s plausible to imagine a similar arrangement in which actual video is never stored, just classified and summarized like audio in Siri Recap.

And, of course, one final potential outcome might be that if Apple manages to convince the EU that its system provides an appropriate balance between consumer privacy and security and third-party product design, then it may forge a path through the impasse that currently stops Apple Intelligence from working in the EU. This could be a blueprint of the intermediary architecture Apple originally proposed to the EU when it first introduced Apple Intelligence. We’ll have to see if Europe accepts that.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSkyLinkedIn, or Mastodon.

Kategorie: Hacking & Security

More and more people believe that AI will take away jobs rather than create new ones

18 Září, 2026 - 15:58

A new survey from the Pew Research Center shows that a majority of people worldwide now expect artificial intelligence to lead to fewer jobs rather than more. The survey is based on responses from 37 countries. In 34 of these countries, it is more common to believe that AI will result in fewer jobs over the next 20 years. Concerns are greater in wealthier countries.

In Sweden, for example, there are signs of growing skepticism toward the technology. The proportion of Swedes who are more concerned than enthusiastic about the increased use of AI has risen by nine percentage points in one year. This is the largest increase among the countries compared over time. Concerns have also increased among both younger and older Swedes.

In the US, 71% of respondents said they think AI will lead to fewer jobs over the next 20, compared to 5% who say it will lead to more jobs. Most pessimistic were the Australians, with 76% predicting fewer jobs because of AI. The most optimistic groups were in Nigeria and the Philippines, where just 26% of respondents predicted AI-induced job losses outweighing gains.

Globally, many also fear that AI will widen economic disparities. In none of the 37 countries do more than a quarter of respondents believe that AI will reduce inequality.

However, views on the technology are not entirely negative. The median for the 37 countries shows that 41% say they feel roughly equal amounts of concern and enthusiasm about the technology. People who have heard and read a lot about the technology also tend to have a more positive view of it.

This article was originally published on Computer Sweden.

Related:

Kategorie: Hacking & Security

Why AI companies are really pumping the brakes on their models

18 Září, 2026 - 13:00

There we were, listening to AI leaders doing their usual spiel: AI is great! AI will cure cancer! AI impact will be “unprecedented, perhaps 10x of the Industrial Revolution at 10x the speed”! AI will find a final answer to “Why do socks disappear in washing machines?” (Well, maybe not the last one. Some things may be beyond us and our clever inventions.)

Then all the top AI leaders screamed as one: “Stop!”

Why? Well, it all seems to have started when AI researcher Jacob Coxon quit his job at Anthropic and proclaimed on X, “The people building AI earnestly believe that it could kill us all by the end of the decade.” Evan Hubinger, Anthropic’s Alignment Science Lead, immediately chimed in: “we really do earnestly believe AI could kill all humans! I personally think it will be >10% within the next decade.” And the world went nuts.

This added fuel to the “AI is untrustworthy” fire as more details came out about OpenAI’s Hugging Face fiasco and agent attacks on German programming wiki sites, while Anthropic has now racked up four known hacking attempts on other sites. Boy, is AI safe or what?

So the very next weekend, three of the top AI CEOs — Dario Amodei of Anthropic, Sam Altman of OpenAI, and Elon Musk of xAI — all urged an AI frontier model slowdown for safety reasons. Amodei, the most articulate of the trio, argued, “We must slow the pace at which we improve the capabilities of AI models” because we’re losing control of our AI systems (Really? Golly! Who knew?) and that an AI agent “swarm could be capable of taking over the entire internet with a persistent botnet (potentially causing hundreds of billions of dollars in damage).”

Well, he’s not wrong. Sorry, President Donald Trump, but safe AI requires more than a “strong and smart” president. Even his Truth Social supporters think his stance on AI is wrong.

Like a stopped clock, Trump was right about one thing when he sputtered, “The only one that is happy about it is China.”

You see, just because some big US AI companies say “slow down!” doesn’t mean Chinese AI vendors will pump the brakes on their model development. Why would they?

Or, for that matter, why would the multitude of smaller AI companies or open-source AI developers? There are AI startups getting tens of millions in Series A rounds on nothing but a good pitch. You think they’ll tell their investors, “We’ll get right on improving our model… next month”? I don’t think so.

Besides, as wise writer Corey Doctorow observed, the narrative around “chatbots that wake up, ‘set their own goals,’ and ‘spontaneously’ start hacking servers — is fake. It doesn’t have ‘a 10% chance of ending the human race.’ The Hugging Face hack isn’t a mysterious, supernatural occurrence. It’s a Python loop and a chatbot. The people responsible didn’t accidentally create god: they created autonomous malicious software and then failed to closely monitor it, resulting in it doing something both foreseeable and bad.”

Exactly so.

In other words, it’s not the development of more powerful models that’s inherently dangerous. AI agents haven’t gone rogue; they’ve just been meeting their assigned objectives in ways researchers didn’t expect or plan for. What’s dangerous is the AI firms’ failure to pay close enough attention to what their agents are doing in tests. In fact, OpenAI just admitted to screwing up even more!

As Meta’s high poobah Mark Zuckerberg tweeted, “Every lab has the responsibility and incentive to move at the pace required to train its models safely, and the ability to take its own actions to ensure that happens.” He then goes on to explain that that’s why Meta delayed shipping Muse. Sure, Mark, sure.

Let’s get real. The big American AI companies may hope a slowdown will ensure that their lesser rivals, in the US anyway, can’t catch up. But given how OpenAI’s circular financing keeps leaking money, another reason OpenAI might welcome a slowdown is to save cash on R&D. 

It’s not going to work. We’re in steamboat time. Steamboat time? While we remember Robert Fulton for building the first commercially successful steamboat in 1807, everyone and their uncle were making steamboats as fast as they could. Soon steamboats were everywhere, and they sparked an economic boom. But they also caused many deaths because of shoddy construction and pilots racing them to ever greater, unsafe speeds. Hmm, does that remind anyone of anything recently?

Seriously, we’re not going to slow down. But doesn’t all this hand-wringing about safety do a great job of distracting people from the simple truth that AI isn’t delivering the productivity gains it’s been claiming all along?

By slamming on the brakes now, Big AI firms can obscure that they won’t be able to deliver the AI fantasyland they’ve been trying to con people into believing. A case in point: A recent McKinsey survey report finds that 80% of people say AI makes them more productive, but only 37% of companies see that reflected in their earnings. A number, they say, that hasn’t budged in a year. Let’s hide that damning number under the concern that we must slow down AI.

It also means AI leaders can hand-wave away their failures to actually generate a profit. Sure, NVIDIA is making money hand over fist, but for all the financial hype, none of the frontier-model companies is making money. Not one of them.

Yes, I know: Anthropic just told the Financial Times that it would be profitable for the second consecutive quarter if you don’t factor in all its expenses. Seriously? Seriously!?

Sure, its adjusted operating income (AOI) is set to be positive for the second consecutive quarter, but come on, AOI “profitability” is billions and billions of dollars from bottom-line profitability.

No, what this is really all about is AI leaders making the right noises to assure people that they really — no, really — care about securing their AI, while slowing things down to maximize their own profits and get rid of the competition.

Oh, I’m certain they also want to make things safer. I mean, just think about the lawsuits when loosely controlled Anthropic or OpenAI agents swarm and take down a major company. This will happen. They have no choice but to make them safer. Now, how will they do that? Given their abysmal track record, that’s a good question, and neither they nor we have an answer yet.

Kategorie: Hacking & Security

5 internet-improving Chrome extensions worth trying on Android

18 Září, 2026 - 11:45

Browsing the web on Android sure ain’t what it used to be.

Earlier this week, we talked about how the Vivaldi web browser is bringing support for Chrome extensions to Android. Vivaldi has the same Chromium code foundation as Chrome but with lots of extra features and options. I’ve been using it on Android and the desktop alike for months now and can’t see myself going back anytime soon.

And with extensions now in the mix, Goog almighty, are things really getting interesting. We’ve already looked at five Chrome extensions that can enhance your efficiency on Android — and today, we’re rounding out that list with five more excellent extension options that work impressively well in the Android environment and can improve your mobile web meanderings in some commendable ways.

While the last additions were all about saving you steps and eliminating common mobile web roadblocks, this next batch revolves around the notion of supplementing or upgrading the actual web itself and the experience of working within different sites — even when they don’t always provide an optimal framework.

So refresh your memory on the mechanics of installing and managing Chrome extensions in Vivaldi, then read on and see which of these internet-improving Android Chrome additions hits home for you.

[Keep the knowledge flowing with my free Android Intelligence newsletter — one useful new thing to try every Friday!]  

Chrome Android extension #1: Your web customization genie

Let’s be honest: Most of the web isn’t exactly a pleasure to peruse. (Insert awkward pause here.)

But with an extension called Click to Remove Element, you can take total control and remove any element of any website that doesn’t please you.

Vivaldi already has some customizable ad and script blocking elements built in at the browser level, if that’s your jam, but Click to Remove Element is more about the stuff that those systems don’t automatically catch and hide — and it doesn’t have to be ad-related, either. It could be a pop-up video player on a site, a prominent button in a back-end interface, a logo or floating menu that takes up too much screen space, or literally anything else that annoys you on any website anywhere.

All you’ve gotta do is tap the extension’s icon, once it’s installed, then tap on any element on a page that you want to remove. And…

One tap, and boom: Any element on any website is invisible.

JR Raphael, Foundry

Poof! It’s gone. If you tap the little box beneath “Remember” in the Click to Remove Element panel at the bottom of the screen, that change will stick and stay present every time you load the same page in the future.

Chrome Android extension #2: A paywall peeper

For the record, as a working journalist in this weird and sustainability-challenged state of modern media we’re in right now, I strongly believe in and endorse paying for publications you appreciate whenever the opportunity arises.

Sometimes, though, you just want to read a random single article from a source you don’t follow regularly. Or maybe you want to share something you’ve read from a paywalled site with someone who doesn’t subscribe and isn’t going to do so just to read this one little thing you’re sending them.

That’s where a site called Archive Today can come in handy. Archive Today captures live views of articles and then saves ’em in a way that can be easily viewed and shared without any subscriptions or sign-ins required.

And a Chrome extension called Archive Page makes it as easy as can be to send a page over to the service for that purpose. Install it, tap its icon (in your Vivaldi extensions menu or in your browser toolbar, if you pin the extension), and you’ll have your viewable, shareable link in no time.

The tool won’t work for every site, depending on the nature of the paywall — and, again, I’d highly encourage you to use it as thoughtfully and ethically as possible — but it’s a powerful option to have available and one that’ll absolutely come in handy.

Chrome Android extension #3: An Amazon price spy

Whether you’re eyeing Amazon listings for work or maybe just for “work,” keep an extension called Keepa in your Vivaldi Android browser. You’ll never think about it or directly open it again after you’ve installed it, but it’ll add a helpful price tracking section into every Amazon listing you pull up on your phone so you can see how the associated product’s price has varied over time and know as soon as it drops again.

Keepa adds a helpful product price history and tracking option onto every Amazon listing in your browser.

JR Raphael, Foundry

Just scroll down a bit on any Amazon page you open, with the extension installed, and you’ll find the info along with the “Track product” option.

Chrome Android extension #4: Easier image saving

Ever find yourself needing to save an image from a website — then discovering that the image is in some funky format that isn’t what you require?

The aptly named Save Image As Type Chrome extension fixes that frustration once and for all. Just install the thing, then long-press on any image anywhere on the web — and…

Finally, you can save any image in any form you want — without any extra steps.

JR Raphael, Foundry

There ya have it: You’ll find a newly added “Save image as…” option in the Vivaldi long-press menu, and tapping it will reveal a full menu of possibilities for saving your image however you need — without any annoying extra steps or after-saving conversions.

Chrome Android extension #5: The Wikipedia wizard

Finally, make your Wikipedia work infinitely more pleasant with the excellent Wikiwand Chrome extension.

Wikiwand transforms every Wikipedia page into one with a delightfully modern, easy-on-the-eyes interface that has all the same info — just in a noticeably nicer form.

Once you see Wikipedia like this, you won’t want to go back.

JR Raphael, Foundry

Install it, forget it, and enjoy a better Wikipedia experience henceforth. Now, that’s what I call an easy win.

Ready for even more unfair advantages? Check out my free Android Intelligence newsletter to get something new and useful in your inbox every Friday — and get my Android Notification Power-Pack today.

Kategorie: Hacking & Security

An undisclosed Microsoft presentation is now central to a multimillion-dollar antitrust fight

18 Září, 2026 - 02:13

There’s a new development in a Microsoft antitrust case, originally filed in England’s High Court in April 2021, and it doesn’t look good for the tech giant.

A consent order from the UK Competition Appeal Tribunal is demanding documents from past and present Microsoft executives that may have a bearing on a £270 million (about $361 million) lawsuit filed by secondhand software reseller ValueLicensing. The company alleges that Microsoft offered incentives to customers to shift to subscription services without selling their pre-owned licenses.

Central to this development is a historic, potentially damning internal “Second-Hand Software” (SHS) presentation, referred to in the consent order as a “known adverse document.” The specific content of the presentation has not yet been made public, but Microsoft has until October 31 to explain why it did not disclose the presentation earlier.

Further, a confidentiality designation that previously applied to 11 documents relevant to the case has been lifted.

These developments represent “an inflection point in European tech litigation,” said Forrester senior analyst Dario Maisto.

“For Amazon (AWS), Google, and Microsoft, the signal is clear: Antitrust tribunals are fully comfortable examining software licensing mechanics as tools of anticompetitive lock-in.”

The allegations against Microsoft

Under EU law, it is fully legal to resell perpetual pre-owned (“second hand”) software licenses; software makers cannot use their Terms of Service (ToS) to override this right. ValueLicensing specializes in this secondary market, re-selling licenses for products including Microsoft Windows and Microsoft Office.

But the company alleges that Microsoft has stifled the supply of these pre-owned licenses in the UK and the European Economic Area (EEA) comprising 27 European Union member and non-member countries. It says Microsoft abused its market dominance and entered into agreements that “prevented, restrained or distorted competition” via clauses restricting customers from reselling their Microsoft perpetual licenses in return for subscription service discounts.

“The net result has been higher prices and less choice for customers, who have been steered into cloud-based Office365 and Azure subscriptions,” ValueLicensing claimed, pointing out that many enterprises, as well as publicly-funded organizations, rely on pre-owned Microsoft licenses to keep operating costs low.

The consent order is asking Microsoft to provide its “view” of whether those allegations are true, and to make “reasonable endeavors” to contact former COO Kevin Turner, former president and EVP Jean-Philippe Courtois, and former corporate VP of worldwide licensing and pricing Joe Matz. The company must document that it has done so by November 30.

The company must also file a witness statement from a former consultant addressing who within the company was aware of the SHS presentation and when they became aware of it; why the presentation was not disclosed as a “known adverse document”; when in-house legal counsel became aware of the presentation; what steps were taken to check for these types of “known adverse documents”; and the decision making process within the company when the presentation was located.

Microsoft is also being asked to search for specific terms in the emails and document repositories of Matz, Courtois, Turner, and several other named current and past research managers, former VPs and presidents, between July 2012 and June 2020.

The more than 40 search terms include “SHS,” “antitrust,” “competition,” “ValueLicensing,” “used licenses,” “do nothing,”  “competition,” “revenue,” and “discount licensing.” These documents cannot be designated “restricted” or “confidential,” according to the consent order. They must also be disclosed by November 30.

A witness statement from deputy general counsel Cynthia Randall has been paused.

Microsoft has said that any abuse of dominance was “objectively justified” and that the contractual terms at issue were “necessary and reasonable.” It also argued that anti-competitive effects were “outweighed by and proportionate to” certain benefits and efficiencies.

The company did not reply to a request for comment.

Microsoft is facing similar antitrust allegations from UK barrister Alexander Wolfson, who issued an opt-out class action claim in May 2025 alleging that public and private UK organizations that purchased software licenses, including those for Microsoft Office and Windows, were overcharged over a 10 year period due to Microsoft’s market practices.

Wolfson said in a release at the time that Microsoft’s actions had a significant and far-reaching impact on UK consumers, businesses, and public bodies. “With billions of pounds potentially at stake, this case is about ensuring fairness in the digital marketplace and ensuring even the largest tech companies play by the rules,” he wrote.

Implications for enterprise leaders

For enterprise CIOs, procurement leads, and IT financial managers, the current development holds “practical implications,” said Forrester’s Maisto: Organizations that surrendered perpetual licenses or agreed to contractual restrictions against reselling software as part of an enterprise agreement (EA) renewal or cloud commitment may have given up quantifiable asset value.

“The secondary market for perpetual licenses remains legally valid,” he pointed out.

CIOs should pay close attention to licensing “penalties” or inflated costs for running legacy software on third-party clouds, like AWS or GCP, versus Azure, he said. They should also evaluate the benefits of hybrid licensing strategies. Combining pre-owned perpetual licenses for static workloads with cloud subscriptions for dynamic workloads can yield significant cost savings compared to all-subscription models, Maisto pointed out.

Finally, he urged, “use these rulings as leverage during Microsoft agreement renewals.”

Kategorie: Hacking & Security

Anthropic tries to make Claude stickier with launch of Docs and Slides

17 Září, 2026 - 16:28

Anthropic is equipping its Claude AI assistant for more productivity work with the launch of Claude Docs and Slides.

While it’s already possible to create documents such as Microsoft Word and Google Docs files from Claude chats, the latest update, announced Wednesday, brings a rich-text editor directly into Claude.

Users ask the AI assistant to draft a document or slides via the chat interface, and Claude will ask clarifying questions before starting work. It will also leave comments to explain its choices.

Claude Docs files are then stored in the Artifacts tab and can be exported as Word, PDF, Google Docs, or markdown files. Documents can be shared with colleagues for real-time collaboration.

Anthropic

“Strategically, this signals Claude moving from an AI assistant into an agentic platform meant for full lifecycle of knowledge work,” said Arun Chandrasekaran, Distinguished VP analyst at Gartner.

He anticipates early user demand around “recurring, template-driven work,” such as status reports, board decks, and data-to-story reports.

“The likely near-term outcome isn’t wholesale replacement of alternative digital workplace tools, but it positions Anthropic as an entry point for workflows historically created in third-party tools,” said Chandrasekaran.

Claude Docs usage counts towards a customer’s Claude usage limits, and larger requests such as drafting a document with several sources takes up more of the limit. There are currently feature limitations, with no version history, access levels, or external sharing on Team and Enterprise pans. It’s also unavailable for customers that use “customer-managed encryption keys (CMEK), zero data retention (ZDR), or a HIPAA-ready configuration,” according to Claude’s support site.

Claude Docs and Slides are available in beta now on paid plans, rolling out to Pro and Max plans first. The feature is turned off by default for enterprise plans.

Anthropic

All of the major AI model providers are seeking ways to make their products stickier within customer organizations, said Jack Gold, principal analyst at J. Gold Associates. Some have targeted coding agents, while others, particularly Microsoft and Google, have AI assistants and agents that are connected into existing office productivity tools.

Microsoft’s Copilot is embedded across its Office suite, for instance, although users can also create documents directly from the Microsoft 365 Copilot chat interface.


“Microsoft and Google are bringing AI deeper into established productivity environments, while Anthropic is bringing more of the productivity environment into AI,” said Maria Bell, senior research analyst at FDM CCS Insight. “Over time, the competition may increasingly be over which becomes the primary interface through which knowledge workers get work done.”

Early findings of FDM CCS Insight’s ‘2026 Employee Workplace Technology Survey’ show that show that around half of employees that use generative AI at work do so to create or edit reports and documents.

It’s unlikely that native document editing features in Claude will result in a large-scale move from Microsoft or Google’s productivity suites, analysts say.

The updates to Claude this week have the potential to help users get more done, said Gold, “but it’s unclear how many users that already have productivity suites in place will choose to move to other tools,” even if they prefer Claude for its AI capabilities.

“The fundamental question is, if I am used to certain tools and they work for me, am I willing to change for the promise of working better? Not sure that will be a winning strategy,” he said.

“Microsoft and Google are deeply embedded in how people already work, and users have spent years becoming comfortable with their products and workflows,” said Bell.

“They are also increasingly bringing access to powerful AI models directly into those familiar environments. Anthropic therefore must do more than match document-creation features; it has to offer an experience compelling enough for users to build new habits around Claude,” she said.

As well as Anthropic’s Claude, it has long been rumored that OpenAI plans to build its own native productivity tools in ChatGPT that would bring it into more direct competition with Microsoft and other incumbent office software vendors.

Anthropic also announced that users can now invoke Claude Design in an ordinary chat. Claude Design, which generates visual outputs such as slides and prototypes, was previously available as a separate tool within the Claude app.  

In addition, Claude Cowork — which can perform multiple-stage tasks — and the regular Claude chat interface have now been combined, with Claude determining how to handle a request. This removes the need for users to decide which tool to use for a particular task, according to Anthropic. It’s not clear exactly how Anthropic decides where to route a request, however. Cowork queries are generally more token-intensive than the core chat interface.

“Claude can now figure out what a task needs, so what Cowork and Design can do is available from any conversation, with the context, skills, and connectors you already have,” the company said in a blog post.

The new Claude experience will roll out gradually, starting with Pro and Max customers. Anthropic said it will alert Claude Enterprise customers before any changes are made to their account.

Claude Enterprise costs $20 per user each month alongside consumption-based pricing.

Kategorie: Hacking & Security

Will Apple enter the server business?

17 Září, 2026 - 16:09

In a world of speculation, this week’s most interesting rumor says Apple may plan to enter the server business once again, with powerful systems running its own Apple Silicon chips.

It’s hard to dismiss the claims, particularly as Apple is already in the server business, with its Texas factory manufacturing servers for its Private Cloud Compute (PCC) cloud intelligence system. While those servers are only used internally —or externally if installed at third-party data centers for use with Apple’s ecosystem of products — they are still servers.

Apple is already in the server business

It’s also a business Apple has been in before. Many years ago, around 2002, I visited Apple in Paris, where the company demonstrated its Xserve and Xserve RAID systems. These were particularly aimed at the video and music industries and became quite widely used in those sectors. Apple discontinued Xserve in 2011, because the product sat outside its broad consumer-focused strategy.

Things were different then. You see, today’s Apple has billions of users. It has a fast-growing reach into enterprise tech — SAP recently updated its fleet of 60,000 Macs to macOS 27 on the very day the OS shipped, and there are hundreds of thousands of Macs in use at businesses worldwide. Apple has hundreds of millions of iPhones in active use across business. Apple even has the silicon to power these things.

The Apple Silicon advantage

You can’t ignore the computational advantage of Apple Silicon. The first leaked benchmarks for the M5 Ultra chip used in the new Mac Studio are incredibly impressive, with multi-core performance at an astonishing 52,516. That’s amazing performance from a Mac that costs an estimated 8 cents an hour to run at full capacity. 

Now imagine that price/performance ratio stashed in a server.

You don’t even need to imagine it, because MacStadium, AWS, and others already use Macs in server farms, with great success. MacStadium CTO Chris Chapman once told me that Apple Silicon is so power efficient his data centers would tell him the Macs he had racked with them were not using enough power for the space. (Data centers sell space by the square foot and calculate energy costs within that calculation.)

Making cloud cheaper and more secure

The computational performance per watt is an advantage to any user, but the cost benefits rack up pretty fast when you have a thousand machines racked up on the data farm. Apple even has a server operating system waiting in the wings — or did until it stopped offering macOS Server four years ago. 

Apple’s existing server production is focused on Private Cloud Compute. That system is impressive, (a) because Apple has opened it up to security experts to confirm it is secure, and (b) because it delivers data and privacy security equal to what its end-user platforms provide. 

But, as data centers blossom across Terra Firma, there’s a growing recognition of the need for sovereign AI, on-premises AI, and private AI. Think of it this way: We already know Macs can run some of the world’s most powerful LLMs very, very well. What’s wrong with introducing Apple Silicon-based servers to do the same thing? These things could even offer companies access to their own white-label private builds of Apple Intelligence, though I consider that unlikely. 

Why the speculation makes sense, and why it doesn’t

So, I see lots of reasons why speculation that Apple may re-enter the server market makes sense — though it may not be in a huge hurry, as the original claim is that these servers will run M8 Ultra chips. (Mark Gurman thinks it may be an M7 Ultra). 

Of course, speculation and conversation don’t always become fact. Merely because Apple is talking about servers again doesn’t mean it will advance those plans. 

Former Apple business-focused product marketing executive Todd Dailey doubts these plans. He says Apple is far more focused on consumer markets than enterprise. 

He also points out that if it were to offer servers, the company would need to consider providing same-day tech support and more flexibility around OS upgrades, adding that the business may not be big enough to justify the cost of implementing the plan. 

That doesn’t mean Apple isn’t considering it, just that once you bounce the idea through a few real-world weeds there may be obstacles to making it happen.

Is it time for iCloud Ultra?

I do think there are signs Apple is taking enterprise markets more seriously. I also think that as PCC deployment expands, it makes sense for Apple’s server teams to build a product road map for the future of PCC servers like any other Apple product, even if they are only used to support its own server-side AI.  

But I also think that if the company were to go ahead to make this happen, the solution would be aimed at developers and businesses seeking a uniquely private way to deploy sophisticated AI outside of the thrall of the frontier models, chipping a little more business away from those over-leveraged entities as it does. 

The thing is, if that’s the case, then is it servers Apple is thinking of building, or server farms offering hosted services for a price? An iCloud Ultra service for developers and enterprise users may perhaps make more sense. I guess we’ll have to wait and see.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSkyLinkedIn, or Mastodon.

Kategorie: Hacking & Security

Salesforce’s massive outage exposes the hidden risks of cloud dependencies

17 Září, 2026 - 03:05

While its flagship Dreamforce event was in full swing on Wednesday, Salesforce was triaging a roughly seven and a half hour-long service outage that disrupted user access and caused “severe delays” and intermittent errors. Some customers were also unable to submit new support cases.

The service outage hit at 3:50 a.m. EDT, impacting “multiple instances across all regions,” Salesforce reported. It was marked resolved right around 3 p.m. EDT, after several hours of monitoring to determine that fixes had been successful.

Salesforce initially pegged the issue to an “external dependency failure” impacting the legacy login server. A core system component experienced increased load, limiting its capacity to process requests. The company confirmed that there were no issues with third-party infrastructure.

Beyond the obvious embarrassment from the outage occurring during Dreamforce, an analyst said the incident highlights a cloud resilience problem, rather than purely a legacy one.

“Cloud does not eliminate architectural dependencies,” said Abbas Jaffery, a principal advisory director at Info-Tech Research Group. “It can sometimes make them less visible. And when the platform is your system of record, those hidden dependencies become an enterprise risk rather than simply a technology risk.”

Rolling restarts, persistent issues throughout the day

Salesforce began experiencing service issues at 3:50 a.m. EDT on September 16, and initial investigation determined that requests were stalling while waiting on responses from an internal login service that was using up available server resources.

Initially, Salesforce blocked application programming interface (API) endpoints and attempted rolling restarts to revive the service, then pushed out fixes region-by-region. At 7:20 a.m., some customers were seeing service return to normal, and Salesforce was working on a “code-level permanent fix.”

However, the rollout did not complete for a number of instances, and some automated fixes didn’t fully resolve the issue. For example, customers reported that scheduled jobs were not running as expected, even after service was restored. Salesforce manually restarted those ‌instances.

Salesforce later reported that the impact radius was “narrower than initially understood” and saw signs of recovery by around 11 a.m. EDT, with most customers coming back online.

A sub-set of Hyperforce instances were the last to be restored. Mitigations were in place across all instances by 11:39 a.m. EDT, and Salesforce continued to monitor the issue until marking the incident resolved at 2:59 p.m. EDT.

“We apologize for how this incident affected you and your business,” Salesforce posted on its incident blog. “We will undertake a full investigation of the incident, establishing the technical trigger, the underlying cause, and preventive action to avoid a repeat in the future.”

Creating a ‘temporal’ data problem


For customers for whom Salesforce is a system of record, several hours of authentication and service disruption can create a “temporal data problem,” Info-Tech’s Jaffery explained. “Events that should have happened at different points in time may occur later, fail altogether, or arrive out of sequence,” he said.

For instance, a customer interaction may occur through another channel while Salesforce is unavailable, but an integration, workflow, or scheduled process that normally records or propagates that event is unable to run.

This has several potential consequences, Jaffery said. Transactions and customer service processes are delayed; APIs and middleware may accumulate retries, timeouts, and queues. Records can become temporarily inconsistent, and scheduled jobs and workflows may be missed. Employees could lose visibility into customer history or case status, even when the underlying data has not been lost, creating a “data divergence.”

The first mistake would be to assume that just because users can log in, the incident is over, he noted. “Enterprises should move immediately into a reconciliation and integrity phase,” Jaffery advised. This means not only verifying interactive access, but APIs, integrations, scheduled jobs, queues, workflows, automation, authentication flows, and downstream systems.

Enterprises should ask what transactions failed, partially completed, or were duplicated during the outage? Which scheduled or asynchronous processes did not execute? Did integrations retry successfully, or did they create a backlog or retry storm? Are downstream systems now consistent with Salesforce?

Security teams should also validate authentication and session behavior, privileged access, integration credentials, and any emergency changes made during recovery, Jaffery explained. “The most important question is not simply ‘Is Salesforce back?’, but ‘What did the business expect to happen during the outage, and can we prove that it actually happened?,’” he said.

What to look for in post-incident reports

A credible post-incident review from Salesforce should establish a causal chain: The trigger, dependency failure, technical propagation, customer impact, detection, mitigation, recovery, and permanent corrective action, Jaffery said.

The company should be able to answer these questions, he said:

  • What was the actual initiating failure and why did the failure propagate into the login path?
  • Why could the affected dependency consume sufficient capacity to affect core services?
  • Why didn’t isolation or failover prevent the impact?
  • Why did initial remediation attempts fail and why did the subsequent rollout require additional intervention?
  • What safeguards are being added to prevent recurrence?
  • How will Salesforce demonstrate that the corrective action actually works under failure conditions?

Service restoration simply tells customers: “We got it working again,” he noted. But root cause analysis tells customers: “We understand why it failed, why our controls didn’t prevent it, and what has changed so that the same failure mode is less likely to recur.”

It’s not just about ‘legacy’ pieces in the stack

One architectural lesson is that a legacy component does not have to be large to be critical, Jaffery pointed out. An older authentication service can remain part of a modern stack, and therefore become a dependency for newer services.

“The component’s age matters less than its position in the dependency graph, its blast radius, and the quality of its isolation and failure handling,” he said, pointing to this incident’s progression: Requests stalled waiting on an internal login service due to increased resource consumption led to investigation into an external dependency failure, which in turn revealed impact on a legacy login server. Finally, Salesforce said, “core system components experienced increased load, which limited its capacity to process request”.

That is a classic resilience question, Jaffery pointed out: Can a failure in one dependency remain in that one dependency, or does it become a platform-wide failure?

Modernization should not be identified simply by how much old technology has been replaced, he noted, it should also measure dependency concentration, isolation, “graceful degradation,” recovery paths, and failure blast radius.

“For enterprise architects, that is the real takeaway,” he said.

Maybe driven by agentic AI, exacerbated by layoffs

At this point, there are no obvious signs that this was a security incident, noted David Shipley, CEO of Beauceron Security. “Right now, this bears all the hallmarks of an update gone horribly wrong.”

He pointed to an incident in December 2025 when Amazon’s internal AI coding agent, Kiro, caused a 13-hour AWS outage in a mainland China region, noting, “I’m not going to be shocked if we don’t see some kind of agent role in this kind of scale disaster.”

Significant Salesforce layoffs over the last few years could also have had a negative impact on the outage and recovery, he added. “Having it happen during Dreamforce had to be all kinds of hell, though, for their sales and customer support teams,” he said. “Pour one out for them as they work on rebuilding relationships, face-to-face.”

This article originally appeared on CIO.com.

Kategorie: Hacking & Security

LinkedIn fights for the right to tell customers when the feds want their data

16 Září, 2026 - 22:04

Microsoft’s top lawyer argued Tuesday that legislators “must make secrecy [orders] the exception” in government subpoenas demanding information about LinkedIn users.

LinkedIn, which is owned by Microsoft, is fighting what it calls overly broad subpoena demands from the US government, which sometimes come with secrecy orders that prevent LinkedIn from alerting customers whose information is being requested.

The company is asking federal courts “to enforce meaningful limits on both the scope of government demands and the secrecy that can accompany them,” wrote Jon Palmer, Microsoft’s chief legal officer, in a Tuesday blog post. “We recognize law enforcement’s important role in protecting public safety and investigating crime, and sometimes that does need to be done covertly. At the same time, customers and users deserve meaningful limits and independent oversight through an adversarial process.”

He pointed out: “People and organizations increasingly entrust their most sensitive information to online services. If providers cannot challenge demands they know are overbroad—or if courts may silence them without a rigorous, adversarial review—the safeguards the law requires will be weakened precisely when they are most needed.”

A tricky issue

The issue is a tricky one. Law enforcement often use this type of subpoena as an investigative tool, seeking those who are engaged in illegal activities. The theoretical justification for secrecy is to avoid alerting the investigative target to make it less likely the suspect will try to destroy evidence or flee the jurisdiction.

Government lawyers are supposed to only make secrecy requests when absolutely essential. Microsoft is suggesting that courts and congress need to step in to curtail blanket government efforts. 

“The Fourth Amendment protects the right to be free from unreasonable searches and seizures. That right applies to papers kept in a desk and it also applies when personal and business records are stored online,” Palmer wrote. “Online service providers, like LinkedIn and Microsoft, also have a First Amendment right to speak to their customers when the government obtains an order to search their private information. Secrecy may sometimes be justified, but it should be tailored to demonstrated needs and subject to meaningful review.”

He added: “The government must seek only relevant information, justify secrecy with specific evidence and infringe on speech to the least extent possible.” In his post, he pointed to a recent legislative effort in the US House of Representatives that might mitigate the issue if it ends up becoming law. 

On August 31, the House passed legislation to rein in secret surveillance and strengthen notice protections when the government seeks data held by technology providers,” he wrote. “The reforms would place clearer limits on secrecy orders, require greater accountability, and help ensure that secrecy is the exception – not the rule. The Senate should act promptly to send these historic reforms to the President.”

LinkedIn privacy battles

LinkedIn itself is currently fighting litigation that accuses it of directly violating the privacy rights of its customers, and a federal judge this month dismissed another similar case, but gave plaintiffs permission to refile, with a caveat.

“Given LinkedIn’s further arguments that users voluntarily download browser extensions, which by their nature intentionally expose data to websites, it seems unlikely that the plaintiffs will ever be able to allege a privacy violation, much less prevail at the end of the day,” US District Court Judge Vince Chhabria wrote. “But in an abundance of caution, dismissal is with leave to amend.”

But, he added, if the amended complaint isn’t filed within 14 days, “dismissal will be with prejudice.”

Privacy now a ‘data stewardship obligation’

Jeff Valdes, a director at Acceligence, noted, “there is definitely some irony here.”

“If Microsoft wants customers to view it as a steward of their privacy when the government comes asking for their information, customers are naturally going to apply that same standard to how Microsoft and LinkedIn collect, use, protect, and disclose information themselves,” he said. “Privacy is difficult to compartmentalize. You cannot have one philosophy of customer privacy for government access, another for product design, and another for your own commercial data practices without eventually creating a credibility problem.”

Mike Wilkes, enterprise CISO at Aikido Security, agreed, pointing out, without meaningful limits, judicial scrutiny, and an expiration mechanism, a temporary investigative necessity starts looking a lot like a permanent architecture for invisible surveillance. The individual may never have an opportunity to challenge the scope of the request, because they may never even know the request existed until prosecutors show up with an indictment.”

That, he said, “is why Microsoft’s argument matters, despite the obvious irony of LinkedIn simultaneously defending itself against privacy claims from its own users.”

But Ryan O’Leary, an IDC research director, offered a different perspective.

“Microsoft makes no bones about using the data contained within its own systems for its own purposes. Both things can be true: Microsoft can fight for the privacy of its platform while still not necessarily respecting the privacy rights of its end users,” O’Leary noted. “This seems to come down to protecting its own proprietary data sets, not some altruistic privacy crusade.”

 At the same time, Valdes pointed out, Palmer’s post highlights how deeply privacy has become a top-tier enterprise IT priority.

“Privacy is rapidly becoming a much broader data stewardship obligation,” he said. “Companies holding sensitive information increasingly have to think simultaneously about government requests, third-party access, their own collection practices, AI use, data retention and what they tell customers about all of it. If you want to be trusted as the custodian of the world’s data, customers are going to judge how you protect that data in every direction.”

However, Wilkes noted, “Microsoft does not need to be a perfect privacy saint to be right about this particular problem.”

This article originally appeared on CSOonline.

Kategorie: Hacking & Security

Big Tech’s AI safety rift signals disruption and disparity for enterprises

16 Září, 2026 - 18:14

A growing divide among leading AI companies over how to secure increasingly powerful models is beginning to translate into challenges for enterprise IT, with implications for how organizations access, deploy, and govern AI systems.

The latest flashpoint came after Meta CEO Mark Zuckerberg called for neutral evaluators to independently test AI models, pushing back on calls from rivals to slow development or tighten coordination.

“trust and alignment are quickly becoming the most important capabilities that will differentiate agents and models. Any lab that doesn’t focus on alignment will fall behind,” Zuckerberg wrote in a post on X.

“Engaging independent evaluators and advisors is industry best practice,” he added, noting that Meta already does this in several areas.

His comments follow a series of public proposals from AI industry leaders including Dario Amodei, who argued for a more cautious pace of development, and Sam Altman, who called for collaboration on safety standards.

The debate has intensified amid disclosures from AI labs and policymakers on potential misuse of advanced systems. Anthropic has said it restricted attempts to use its Claude models in sensitive domains, while OpenAI has engaged with policymakers on AI-related risks, according to company statements and reports.

Enterprise concerns

While the debate is often framed as a choice between slowing innovation and strengthening oversight, analysts said enterprises should focus less on which approach prevails and more on the operational consequences already taking shape.

“Divergent safety approaches will make access to advanced AI models less predictable, rather than producing an industrywide slowdown,” said Sushovan Mukhopadhyay, director analyst at Gartner. Vendors are likely to apply different release schedules, regional availability, access tiers, and usage restrictions, he said, meaning enterprises could encounter similar capabilities “at different times and under materially different conditions.”

Mukhopadhyay said enterprises should plan for variability in access rather than assuming consistent availability across providers or geographies.

“I read this week as the point where frontier AI became a managed supply,” said Bhupendra Chopra, chief revenue officer at Kanerika. “For three years CIOs could assume the next model would simply show up. A frontier model now behaves more like a critical component from a supplier whose delivery dates depend partly on outside reviewers and export rules.”

Chopra added that “any AI roadmap built on a specific model arriving on a specific date is carrying supply risk it hasn’t priced.”

Security pressure builds regardless of slowdown

Analysts said slowing development alone is unlikely to materially change enterprise risk, particularly as open-source models proliferate.

“The biggest point isn’t the pause itself. It’s that the leaders of AI companies are agreeing on something,” said Nikhil Gupta, founder and CEO of ArmorCode.

Gupta said the threat landscape has already shifted. “Even if companies hit pause, open-source AI models are already out there,” he said. “I’m not convinced slowing down some companies meaningfully changes what adversaries can do.”

“Even if AI development slows down tomorrow, security must accelerate,” Gupta added. “The job of securing these systems has effectively gotten ten times harder.”

A new ‘AI assurance’ layer emerges

The focus on evaluation is driving what analysts described as an emerging “AI assurance” layer, where third parties assess models for safety and compliance.

“A distinct AI assurance layer is likely to emerge, but enterprises should not expect a single certification to establish that an AI system is safe,” Mukhopadhyay said. “Enterprise risk also depends on data, system instructions, tools, agents and deployment controls.”

Chopra said enterprises risk misinterpreting such evaluations. “Procurement teams may see a third-party evaluation and treat the model as vetted,” he said. “Within a year it becomes a checkbox.”

Instead, he said, enterprises will need to run their own validation. “CIOs who get ahead will test each model against their own data before it touches production.”

Fragmentation complicates multi-model strategies

For CIOs pursuing multi-vendor strategies, differing approaches across providers could introduce additional complexity.

“Fragmentation was already the default. Safety divergence deepens it,” Chopra said.

He said risk is most acute during transitions. “For an enterprise running several models, the exposure sits in the handoff,” he said. “When a model is delayed or replaced, the system can behave differently.”

“I’d rank untested model substitution above vendor lock-in,” Chopra said.

Gupta said open architectures will be important. “The framework needs to be open, not locked to any single vendor,” he said.

Mukhopadhyay added that enterprises should prepare for models becoming unavailable or restricted.

CIOs urged to build resilience

Analysts said enterprises will need to design AI strategies that can adapt to changes in availability, pricing, and governance.

“For critical applications, CIOs should separate application controls and business logic from the underlying model,” Mukhopadhyay said.

Chopra emphasized flexibility. “A routing layer between applications and model providers turns switching into configuration work,” he said, adding that contracts should cover deprecation timelines.

He also pointed to pricing implications. “Scarce access to the frontier starts to carry a premium,” Chopra said.

Kategorie: Hacking & Security

Nextcloud adds desktop app for Euro-Office productivity suite

16 Září, 2026 - 18:12

Nextcloud has developed a desktop app for its Euro-Office-based productivity applications, filling a gap in the software suite that it pitches as a sovereign alternative to Microsoft Office.


Nextcloud, one of the backers of the Euro-Office initiative, integrated the software into its Nextcloud Office suite in June. Until now, it’s been accessible via a web browser or mobile app.

The new desktop client lets users edit documents, spreadsheets, and presentations locally, and sync files online for collaborative editing. It will be available for Linux, macOS, and Windows in the coming weeks.

“For organizations and individuals who prefer a traditional desktop experience, this closes one of the last gaps between Euro-Office and Microsoft Office, without handing control of their data to a non-European vendor,” Nextcloud said in a press release.

Rather than a standalone application suite, Euro-Office is designed as an integration component that’s embedded into productivity applications, such as Nextcloud Hub. Euro-Office handles document editing, while other elements such as storage and permissions managed by the wider platform.

The open-source project, which is built on OnlyOffice’s codebase, is backed by Nextcloud as well as Eurostack, Ionos, Office.eu, Proton, XWiki, and others. More than 40 individuals have contributed code to Euro-Office, according to Nextcloud, with around 15% of contributions from outside of the organizations directly involved in project.

Euro-Office supports OOXML file formats for compatibility with Microsoft Office, as well as OpenDocument Format (ODF) files, including ODT, ODS and ODP. The Document Foundation, which is responsible for development of LibreOffice, another open-source productivity suite, has previously questioned the Euro-Office initiative’s preference for Microsoft file formats over ODF.

Organizations using Euro-Office include Germany’s Deutsche Telekom Security and Destek, a Turkish IT consultancy, according to Nextcloud. Other customers in countries such as France, Switzerland, and Philippines are currently evaluating the software.

But it’s still early days for Euro-Office. Open-source software initiatives often face a challenge in gaining traction among a broad enterprise audience, said Martha Bennett, VP and principal analyst at Forrester.

“Euro-Office hasn’t really proven itself at the kind of scale that large enterprises are looking for. That’s of course not unique to Euro-Office; all potential open-source alternatives face the same issue,” she said.

“Obviously, it’s a bit of a chicken-and-egg situation — without somebody taking the leap, it’s not possible to provide that proof.”

Nextcloud Hub Summer 26 updates

Among the other announcements with the Summer 26 updates are changes to management of teams within Nextcloud Hub. An updated Nextcloud Teams app, which is now available in the app menu, provides users with an overview of the teams they belong to. Each team features a folder with shared resources such as files and tasks, which Nextcloud notes is similar to Microsoft’s approach with Teams and SharePoint.


Nextcloud now also enables the creation of team-owned files, starting with Nextcloud Collectives and Deck, with additional apps in future. The aim is to ensure that all team members can access a file, even if the creator leaves the team workspace. For admins, there are new tools to view and manage team folders, including configuring storage quotas.

Among the other announcements are updates to Nextcloud Text — a lightweight text editor available across several apps — with version comparisons, footnotes, and references available throughout a document, and inline comments. Nextcloud Tables, a database app, now has relational columns that link data in cells across multiple tables, and the ability to import and export table structure — such as columns, views, and table-based apps — without changing data.

With Nextcloud’s AI Assistant, users can now upload an image and ask questions about it or translate text, while the chatbot will also recall information across conversations.

UI improvements include a revamped search experience that displays results from across Nextcloud Hub files, messages, and events, with filter options such as date range and people. App menu icons have been updated to make apps easier to recognize, and new animations throughout the interface make navigation and interactions “feel more fluid and easier to follow,” said Nextcloud.

Kategorie: Hacking & Security

AWS bets that AI agents need an inbox, not another chat window

16 Září, 2026 - 18:07

AWS is betting that AI agents need a different interface as they move beyond answering prompts and start working autonomously in the background.

The company has open-sourced Pizza Bot, a self-hosted application that gives users an inbox for managing work delegated to AI agents, with separate threads for ongoing tasks and a queue for work that is completed or needs human input, rather than keeping the management of agents restricted inside a conventional chat window.

The rationale, according to AWS, is that background agents do not always need a user’s attention while they work, and an inbox model will let users hand off longer-running tasks, return to them later, and see which jobs are complete or require intervention.

Under the hood

That approach is reflected in how the inbox organizes work with the help of an “All” tab that contains the history of each task or conversation, including the agent’s messages and work performed, the “Unread” tab that flags completed work that users have yet to review, and an “Action” tab that surfaces tasks paused while waiting for user input or approval.

The inbox interface also has a panel named Activity that shows users how an agent handled a particular task along with the transcript, AWS wrote in a blog post introducing Pizza Bot.

AWS’ inbox-oriented rationale also extends to Pizza Bot’s architecture.

It uses LangChain’s Deep Agents as the harness and LangGraph as the stateful runtime, with a combination of the two allowing an agent to checkpoint its progress as it works, preserving its messages, tool activity and current state so a task can be paused and resumed rather than being tied to a live chat session, the hyperscaler wrote.

Pizza Bot’s server sits on top of that stack, connecting the agent runtime with the user interface, skills, MCP servers and the model provider, with developers able to choose from Anthropic, OpenAI, Google Gemini and Amazon Bedrock, as well as local models through Ollama, it added.

As for its out-of-the-box capabilities, the application comes with skills for working with files, browsing the web and delegating tasks to specialist agents. Developers can also add existing Agent Skills and MCP servers to give the agents access to other tools and services, the hyperscaler wrote.

Enterprise integration could remain a hurdle

However, analysts were not too convinced that Pizza Bot’s out-of-the-box skills and support for existing tools will make its implementation easier for enterprises.

While the out-of-the-box capabilities and added support for existing skills saves enterprise teams the time to build the application, it leaves out the integration work required to make it work, said Bhupendra Chopra, chief revenue officer at IT consulting firm Kanerika.

“Integration is where most of the money in an enterprise agent deployment goes. A sales or finance team gets value from an agent when it can read and update CRM, email and ERP, and each of those systems needs a connector someone has to build, secure and maintain,” Chopra pointed out.

Pizza Bot’s integration could be further complicated by the application’s lack of support or any SLA, according to Manoj Chandra Jha, principal analyst at Nord-IQ Research. That means the integration and operational burden ultimately falls on enterprises, who would be responsible for running, securing and maintaining the open source software themselves, Jha said.

Rise in enterprise productivity likely

But for enterprises willing to take on that integration work, the inbox-oriented approach could improve productivity.

“It’s a meaningful shift because it changes the economics of delegating work to agents. A chat interface requires a person’s attention throughout the task, while an inbox brings them in only when their judgment is needed, much like how executives delegate work to their teams,” Chopra said.

“Coding agents have already demonstrated this model, where an engineer assigns an issue and reviews the resulting pull request. Pizza Bot extends that approach to tasks such as meeting preparation and follow-ups,” Chopra added.

Further, the analyst pointed out that the inbox-oriented approach could give enterprise teams a clearer window into how scheduled tasks perform.

“For scheduled tasks, having the results delivered as threads gives users a way to track what happened in the background and spot failures that might otherwise go unnoticed,” Chopra said.

Out of sight, out of mind

There are risks with this approach, however: “The inbox model can make bad work less visible. When somebody is watching an agent in a chat window, they can see it going off the rails,” said Phil Fersht, CEO of HFS Research.

In contrast, when hundreds of tasks are running quietly in the background, users may not see an agent making mistakes until the task is complete or an exception requires their attention, potentially making problems harder to catch early, Fersht said.

That reduced visibility can also create approval fatigue, according to Chopra.

“An agent sending back dozens of threads with multiple approval requests can condition users to approve them without reading them closely,” Chopra said.

There is also a risk in the delay between an agent preparing an action and a user approving it: “Information that was current when the agent paused may no longer be valid hours later, potentially resulting in an outdated CRM update or a meeting invite for a slot that is no longer available,” he said. “An assumption that might be caught in a live chat can go unchallenged as the agent continues building on it and consuming model resources. Scheduled runs can also add costs without anyone watching them in real time.”

Those disadvantages can be countered by designing processes with fewer, better-timed approval points, and verifying that the underlying data is still current before allowing an action to execute, he said.

Adoption likely to start with technical teams

Such tradeoffs are likely to shape where Pizza Bot gains traction.

“Adoption will likely be bottom-up, with individual technologists and small platform teams drawn to Pizza Bot’s control and standards-based design,” Jha said. “Risk-averse industries, especially ones in the regulated sectors, and business users with limited technical expertise, however, are likely to approach the application more cautiously,” he added.

That could leave Pizza Bot occupying a more targeted role in the enterprise, as a way for technical teams to experiment with asynchronous agents and new ways of delegating work, rather than an immediate replacement for the governed interfaces and managed services enterprises typically use for business-critical processes, he said.

This article first appeared on InfoWorld.

Kategorie: Hacking & Security

Apple just gave every iPhone photo a digital alibi

16 Září, 2026 - 17:05

The fight against AI slop is real, even in photography, which is why Apple introduced its Reference Image tech alongside its new iPhones. This shifts image verification to the moment of capture, creating a privacy-preserving digital negative that could help newsrooms, businesses, and individuals prove that images are real. Apple’s Security Research team just shared a white paper explaining how it works.

What is Apple Reference Image?

Introduced alongside the new iPhone 18 Pro series, Apple Reference Image is designed as a process to help prove the authenticity of images captured using that phone. Like so much in Apple, it’s a combined hardware/software feature that means when an image is captured, the camera also captures unalterable Reference Image data, with help from Private Cloud Compute, Apple’s cloud intelligence system.

That help means Apple thinks it now offers a system that protects image provenance to the extent of providing quantum-secure defense. The need to protect digital assets such as images from quantum-based abuse will become increasingly important as more state and state-adjacent adversaries seek out new ways to undermine security and do harm. Apple quite clearly considers that looming threat to be real; in 2024 it introduced encryption to protect iMessage against future attacks using quantum computers.

How do we use Reference Image?

Apple is reaching out with this tech, including providing APIs for iPhones, iPads, and Macs that third-party developers can use to build support for Reference Image into their apps. 

Otherwise, Reference Images can be viewed in the Photos app beside the main image, acting like a digital negative to enable visual comparison of both images. The idea is that the existence of this digital negative acts as a tool to prevent people from passing off edited or AI-altered images as being genuine pictorial narratives of events.

This will be useful in multiple situations. In the media, a news desk may turn to the feature to verify if an image is genuine or fake, while in the enterprise the tool provides a useful proof point when assessing images that relate to any workflow — that picture taken in the stock room may now be more useful as proof that stock is in hand, while a car hire firm may find it easier to prove damage during a rental period by verifying the pic. The main thing it does is help you identify changes in an image, whether those changes were wrought by human or AI.

Why Apple built this protection

Apple’s newly published white paper explains how it works and how the system is built to endure against interference, particularly as AI images are becoming increasingly convincing. After all, as digital enters most camera workflows at the sensor, proof of algorithmic activity isn’t necessarily enough to show an image has been altered out of its photorealistic beginning. It must be said that at this point we only have Apple’s word for the effectiveness of the solution, but I’m inclined to think it will be borne out.

Enter Apple Reference Image, which acts as a “chain of trust,” one the Apple team says is stronger and more enduring than existing approaches based on the Coalition for Content Provenance and Authenticity (C2PA) standard. Apple believes the C2PA approach remains too vulnerable because it is deployed after image capture and also creates a privacy risk by attaching images to public identity. You don’t have to look too far for instances in which photojournalists have been targeted by hostile forces once their identity has been realized, and the C2PA system arguably adds to that risk.

“Other industry solutions require a photographer or institution to vouch for an image using their own credentials,” the white paper explains. “We are concerned this puts some photographers, such as those operating in conflict zones, in a difficult position; it should not be necessary to forgo anonymity in order to prove image authenticity.”

Apple’s system is designed to kick in as images are captured, when a photographer can choose to create a securely timestamped reference image that accurately reflects what was captured by the iPhone’s camera sensor. The creation process leans into the powerful iPhone processor and also Apple’s Private Cloud Compute.

A little insight into how it works

As the image is captured, the iPhone cryptographically signs pixel data immediately after capture, which shows the image to be an exact depiction of what the camera sees. The system also captures relevant metadata, including use of the Secure Enclave on iPhone to ensure some values.

That means that the Reference Image now carries deep insight into the original, down to an unchangeable record of metadata. Not only can you see the image matches, but you can ensure the metadata is also the same. Furthermore, the image is also timestamped with a value taken from Apple’s own cryptographic timestamp service. Pull it all together and the digital negative is packed with verifiable, trusted data that can be contrasted with an image you want to check. 

There’s much more to this system, which Apple has built to be resilient to compromise while also protecting the privacy of the photographer. Instead of requiring the photographer act as the point of proof, Apple’s own Private Cloud Compute servers play the role by cryptographic signing of the image. 

“The result is a verification model that offers photographers, newsrooms, and everyday users renewed confidence that an image they’re viewing is a photograph actually captured by a camera,” the company said. It is, I think, also interesting to consider how Apple’s newly introduced tool for cryptographic proof could potentially be applied elsewhere.

The caveat is that the protection only extends to the main camera of the iPhone 18 Pro family and is not retrospective. It won’t be available in China on launch, while in the EU you can develop and view reference images but not create them.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSkyLinkedIn, or Mastodon.

Kategorie: Hacking & Security

Here’s why Microsoft supports open-source Chinese AI

16 Září, 2026 - 13:00

In the battle over whether the US or China will lead the world in AI, the argument for the US side largely can be summed up in four words: USA good, China bad.

In this worldview espoused by big US AI companies, the Trump administration, and many Republican members of Congress, AI born and bred in China is portrayed as a grave security risk. The Chinese government, they claim, will use Chinese AI models to steal information from businesses, individuals, and government agencies. They also claim that because Chinese AI complies with Chinese censorship rules, US companies that use these models will be forced to comply with the rules as well.

Critics also say that if US AI is overtaken by Chinese AI, the US economy could be dealt a crushing blow, because the hundreds of billion dollars being invested by US AI companies will go down the tubes.

Because of this, Big AI firms Anthropic and OpenAI are lobbying to ban Chinese open-source AI from the US.

Not all AI companies and their customers agree with a ban. Microsoft, Meta, and AI chip maker Nvidia, among others, say there’s room for both US AI models and Chinese open-source models.

What’s the fight really about? To understand, let’s first dig into the tech behind most Chinese AI.

What’s the fuss about?

The fight is primarily over what’s called lightweight open-source AI. “Lightweight” means the AI models don’t require multibillion-dollar data centers to train, build, and run them. They need comparatively modest processing power.

That’s attractive for businesses, because lightweight models are less expensive to license and run than much American AI tech, notably OpenAI’s ChatGPT and Anthropic’s Claude.

The other draw for businesses is that Chinese open-source AI tech can be used for free. And perhaps more important that is that the AI is typically what’s called “open weight,” which means businesses can tweak the technology for their own purposes.

When a traditional American AI model is trained, people who train it must decide how much “weight” to give to every parameter in every element of training data. For example, if AI were being trained to tell the difference between an apple and an orange, a great deal of weight would be put on the color of the fruit and the appearance of its skin. Less weight would be put on the fruit’s shape or size.

When a company buys American AI, they don’t know how much weight is given to each training parameter. They don’t even know what the parameters are. In open-weight AI, though, businesses have access to those parameters — and they can assign their own weights to them. This means they can customize the AI more easily for their particular needs in ways they can’t with traditional American AI models.

(Note that the terms open weight and open source are often used interchangeably when talking about AI, although technically they differ. Some open-weight models withhold some information such as their source code and training data — information that should be made public for a model to be considered truly open source.)

What Microsoft says about the Chinese models

Microsoft, Nvidia, Google, Meta, and many smaller companies don’t agree that Chinese lightweight open-source AI should be banned. They claim that security and censorship issues can be easily solved. And they believe use of the models will help the United States economically, not hurt it.

Microsoft CEO Satya Nadella posted on X: “Open-weight models are essential to a healthy AI ecosystem.” He added that the models will “strengthen American competitiveness and expand economic opportunity, while protecting national security.”

Microsoft was also one of more than 200 corporate signers of a document outlining all the reasons they believe open-weight AI is important.

Microsoft isn’t just talking about the importance of using Chinese lightweight open-source AI — it’s begun offering it to its customers and is looking to expand it even more. Right now, DeepSeek, the first Chinese lightweight open-source model to make its way to the US, is available via Azure. And Microsoft is testing offering DeepSeek to customers of its Copilot Cowork agentic AI product.

Keep in mind that Microsoft’s embrace of Chinese lightweight open-source AI has less to do with virtuous thinking than with profit-making. Offering these products to its customers will please both old and new customers because of the tech’s benefits. The more Microsoft offers to its customers, the more money it will make.

What happens next?

It’s unclear what happens next with the Chinese AI products. OpenAI and Anthropic are allied with the Trump administration in wanting them blocked or limited in the US.

Still, there’s an increasing groundswell backing back their use. Bill Gurley, a Silicon Valley venture capitalist, told the New York Times: “You have two factions fighting over this issue. There’s the people who want OpenAI and Anthropic to own everything, and then there’s everybody else, including customers.”

My bet is that in short term, OpenAI and Anthropic will get what they want, because Trump has got their back. But after Trump leaves office, don’t be surprised if Chinese open-source AI has its day in the sun, backed by Microsoft.

Kategorie: Hacking & Security

5 efficiency-enhancing Chrome extensions worth trying on Android

16 Září, 2026 - 11:45

Brace yourself: The way you get around the web on Android is about to get a whole lot better.

This week, the excellent Vivaldi Android browser is rolling out an update that adds in support for the entire collection of Chrome Web Store browser extensions. That means you can enhance and adjust your mobile web experience with all sorts of interesting — and potentially shape-shifting — new improvements.

Vivaldi, if you aren’t familiar, is a browser based on the same Chromium foundation that powers Google’s standard Chrome browser, but it has a ton of extra features and options that make for an even more personalized and productive experience. I started using it on all of my devices earlier this year and haven’t looked back since.

Now, with complete Chrome extension support added into the mix on Android, the advantage is growing even greater.

I’ll be honest, though: When I first saw that Vivaldi was adding in Chrome extension support for Android, I wasn’t sure what to make of it. Most of the extensions I use in my desktop browser just wouldn’t make sense on the mobile front and wouldn’t add much of meaningful value in that environment.

But then I put on my thinking cap. I did some deep digging and careful considering. And I found some Chrome extensions that actually work incredibly well in the Android arena and add a lot of interesting value into the mobile web adventure.

This is the first of a two-part collection. Here, we’ll look at five Chrome extensions that you can add into Vivaldi to save yourself steps and bring a welcome efficiency boost to your Android web work. In part two, we’ll round out the list with another set of extensions that’ll improve the internet itself in some truly intriguing ways.

Ready to reinvent how you experience the web on your phone?

[Get fresh Android tips in your inbox with my free Android Intelligence newsletter — one useful new thing to try every Friday!] 

A quick primer on Android Chrome extension installation

Real quick, before we get into the good stuff: When you’re ready to try out an extension, you’ll need to have the latest version of the Vivaldi Android app on your device (obviously, right?) — then either tap the puzzle-shaped extensions icon in the toolbar at the top of the screen, if you see it, or tap the “V”-shaped main menu icon in the upper-right corner and select “Extensions” from there.

Either way you go, you’ll see an option to “Discover more extensions.” That’ll take you to the Chrome Web Store, where you can search or browse through all the available extensions and install anything with a couple quick taps.

I’ll also provide direct links to each extension I’m recommending below, so you can tap it to open it in Vivaldi on your phone and then install it directly from there.

Note, too, that that same Vivaldi Extensions menu is where you can access and manage any installed extensions moving forward. You’ll see every extension you’ve installed there, and you can deactivate or uninstall anything as well as opt to have its icon pinned into your browser toolbar for easy ongoing access.

Chrome Android extension #1: The cookie request crumbler

Our first Android Chrome extension worth considering is one that you won’t ever open or actively think about once you install it and set it up. It’s a tool that works silently in the background to automatically handle those irksome cookie preference prompts that pop up around the web — so they’ll always get answered in the way you prefer, but you’ll never actually have to see or deal with ’em (and have ’em blocking half your view, in a mobile web scenario!) again.

It’s called Consent-o-Matic, and the way it works is simple: You install it, open its options page once to tell it which cookies you do and don’t want to allow around the web — and that’s pretty much it. From there on out, it’ll just click on all those prompts that pop up for you, based on your preferences, and they won’t interfere with your work or irritate you anymore.

Consent-o-Matic remembers your cookie preferences and then applies them for you automatically all over the web.

JR Raphael, Foundry

One option to look at while you’re in that initial setup area is in the “Display” tab at the top of the screen. By default, Consent-O-Matic will show any pop-ups it’s handling in a small overlay in the corner of the screen — but you can eliminate that entirely and make the process completely out of sight and invisible, if you want.

You can make Consent-o-Matic completely invisible so you never so much as see another cookie prompt again.

JR Raphael, Foundry

Yes, please — and thank you.

Chrome Android extension #2: 404 no more

Next is another quietly useful addition, and that’s the official Chrome extension for the Wayback Machine at the Internet Archive.

With the Wayback Machine extension active in your Android web browser, anytime you land on a page that for whatever reason isn’t online anymore or just isn’t available at that particular moment, you’ll see an offer to go to the page’s most recent cached version.

You can also call the extension up on demand to search for older saved versions of any pages by either pinning its icon to your Vivaldi toolbar or long-pressing a link within any page you’re viewing to reveal its menu of options.

The Wayback Machine Chrome extension integrates seamlessly into Vivaldi’s long-press link menu.

JR Raphael, Foundry

Chrome Android extension #3: A background open shortcut

I don’t know about you, but when I’m wading my way around the web, I find myself opening links a lot — often with the intent to look at ’em later.

Typically, that requires long-pressing on the link and then finding the option to open it in a background tab. But with a handy extension called DoubleClicker, that same action can be easier than ever.

Install DoubleClicker into your Android Vivaldi browser, and that’s it: From that moment forward, you can simply double-tap your finger on any link within any page, and it’ll open instantly as a background tab — waiting and ready for when you want it and without any waiting, poking around, or other interruptions to your workflow.

This might just be my favorite addition of all.

Chrome Android extension #4: Hands-free scrolling

The next time you’re reading something on your phone, keep a little somethin’ called Auto Scroll Extension in mind.

As its name suggests, the extension lets you set any speed you like and then simply tap its icon (which works best if you pin it to your toolbar) to automatically scroll the page for you — so you can keep reading without having to do a thing.

Look, ma: No hands! Auto Scroll in action in Vivaldi on Android.

JR Raphael, Foundry

Chrome Android extension #5: Easier password access

Last but not least for this list is an addition that seems strange on the surface — but hear me out:

If you’re using an Android password manager other than the Google Password Manager — like 1Password or Bitwarden — try installing its extension into Vivaldi on your phone.

Yes, it’s redundant with having the standalone app installed and set as your system-wide password management service. But it often ends up being faster and easier to have a sign-in handled directly within the browser instead of having to rely on the system-level integration.

And having the browser-based option present doesn’t prevent you from using the other route, either. You’ve just got options, and you can pick whichever feels fastest and easiest to you at any given moment.

Try it out for yourself and see whatcha think. And keep going with the second set of worthwhile Android Chrome extensions next!

Your next mission, extension exploration aside: Come check out my free Android Intelligence newsletter to get something new and useful in your inbox every Friday — and get my awesome Android Notification Power-Pack today.

Kategorie: Hacking & Security

Oracle forecasts 33% increase in restructuring costs as new round of layoffs hits

15 Září, 2026 - 18:22

Oracle began a new round of layoffs this week, sending early-morning termination emails to staff for the second time in six months.

The latest wave began Monday with affected staff being told, “After careful consideration of Oracle’s current business needs, we have made the decision to eliminate your role as part of a broader organizational change,” according to BusinessInsider. Termination was immediate.

That’s the same wording as in the previous wave of layoffs, which took place on March 31 and affected workers in the US, India, Canada, Mexico and Uruguay. In the 12 months to May 31, Oracle cut its global workforce from about 162,000 to about 141,000, a decline of roughly 13%.

Oracle has made no public statement confirming the latest round of job cuts, but in a regulatory filing days earlier the company said it had set aside a further $700 million for restructuring charges, bringing the total charges this year to roughly $2.8 billion.

What the new termination emails say

Staff receiving the latest termination emails were told termination and compensation details would follow by DocuSign, Business Insider wrote. An internal document reviewed by the publication said severance terms varied by role and region, and some teams facing double-digit percentage cuts.

Affected employees took to social media to vent.

Eric Brunson, a senior principal offensive security researcher at Oracle, described in a LinkedIn post how he had lost access to corporate communication tools before receiving any formal notice. “I woke up to not being able to log back into Slack,” he wrote. “No new emails or notification in email and I’m locked out of there. I was able to get ahold of my manager on LinkedIn and she confirmed.” Brunson said the timing fell two days before a scheduled RSU vesting date, adding, “Probably part of the plan.”

The filing that backs up the layoff accounts

While Oracle is not talking about the layoffs, its 10-Q quarterly report states that management approved and supplemented restructuring plans “to implement certain strategic measures and further improve operational efficiencies, including through the adoption and integration of artificial intelligence technologies across certain functions.” It adds that “subsequent to August 31, 2026, our management supplemented the 2026 Restructuring Plan by approximately $700 million to reflect additional actions that we expect to take.”

Oracle has already spent $1.97 billion of the $2.1 billion restructuring charges it originally budgeted, it reported.

Sanchit Vir Gogia, chief analyst at Greyhound Research, said the filing should be read carefully rather than as confirmation of a headcount. “The supplement is an estimate, not a bill,” he said, noting it raises the program’s estimated cost by about a third without committing Oracle to a timetable.

Gogia said the more significant shift is in the filing’s language rather than the dollar figure. Oracle’s August 2025 and February 2026 filings had described the plan as tied to “acquisitions and certain other operational activities.”

AI was named as a driver of restructuring for the first time in the Sept. 11 filing.

Why the headcount stays unconfirmed

Gogia said no verified figure exists yet for how many employees the September round affected.

He noted that 30,000 was a January forecast of the total 2026 program. Twenty-one thousand is the confirmed net decline in Oracle’s global workforce across the full fiscal year. A reported 3,000 job cuts in India on Sept. 1 remains unconfirmed by Oracle.

The $700 million restructuring supplement “cannot be divided into people,” Gogia said, since it covers termination benefits, contract termination costs and other exit costs across a program spanning multiple countries. “There is no solid headcount for the September round,” he said.

A pattern that began in March

Oracle’s first 2026 layoff wave began March 31, when the Revenue and Health Sciences unit, the SaaS and Virtual Operations Services group, and NetSuite’s India Development Centre saw some of the deepest reductions.

Figures published by Oracle for its fiscal year ending May 31, 2026, show research and development headcount fell from 50,000 to 43,000 employees during the year, sales and marketing fell from 31,000 to 25,000, and services fell from 37,000 to 34,000, according to Gogia’s analysis of the company’s own reporting.

International staff, at 92,000, saw a larger reduction than the 49,000-strong U.S. workforce, he said.

Oracle did not respond to a request for comment.

This article first appeared on CIO.

Kategorie: Hacking & Security

Tech layoffs: A 2026 timeline

15 Září, 2026 - 18:21

Among a range of factors leading to a wave of tech sector layoffs in 2026 is the rapid rise of artificial intelligence and automation. Companies are reconfiguring their workforces to leverage AI for increased efficiency and reduced operating costs. This realignment and reduction is implemented even by companies reporting strong financial performance.

But it’s not just AI leading to workforce cuts. Complementing this technological shift are ongoing economic uncertainty, inflation, and higher interest rates, compounded by a chip shortage and rising energy costs. This mix is driving companies to cut costs and streamline operations for increased efficiency.

According to data compiled by Layoffs.fyi, an online tracker that keep tabs on job losses in the technology sector, 123,941 tech employees were laid off at 269 companies in 2025. The site also reports that 71,981 government employees were laid off by DOGE alone, with 182,528 total federal workers laid off.

Here is a list — to be updated regularly — of some of the most prominent technology layoffs the industry has experienced recently.

Notable tech layoffs in 2026
  • Oracle (again)
  • Monday.com
  • Microsoft
  • Meta
  • Cisco
  • Cloudflare
  • Oracle
  • Atlassian
  • Salesforce
  • Amazon
  • Ericsson
Sept. 15, 2026: Oracle forecasts 33% increase in restructuring costs as new round of layoffs hits

Oracle began a new round of layoffs this week, sending early-morning termination emails to staff for the second time in six months. Oracle has made no public statement confirming the latest round of job cuts, but in a regulatory filing days earlier the company said it had set aside a further $700 million for restructuring charges, bringing the total charges this year to roughly $2.8 billion.

July 22, 2026: Monday.com cuts 20% of its workforce to restructure for the AI era

The company says the decision to cut 620 jobs isn’t about margins, but about creating a flatter organization built around AI agents, autonomous teams, and deeper customer engagement.

July 6, 2026: Microsoft cuts 4,800 jobs, primarily in sales and Xbox teams

As the company trims thousands of jobs, it’s also investing in embedded engineering teams and AI infrastructure. The layoffs come several weeks after the company offered 8,750 US employees voluntary retirement buyouts.

June 5, 2026: Tech industry cut 38,242 jobs in May, worst since 2024

AI was blamed for 40% of the job cuts in May, up from 7% in January, according to research by employment placement company Challenger, Gray & Christmas.

May 20, 2026: Meta cuts 8,000 jobs, around 10% of workforce

The cuts are expected to expected to hit Meta’s engineering and product teams the hardest, arriving as Meta pivots toward AI to boost efficiency across its organization, according to Yahoo Tech.

May 13, 2026: Cisco to cut nearly 4,000 jobs despite strong growth in AI, enterprise networking

Despite reporting positive financial news — including record third-quarter revenue of $15.8 billion, a 12% year-over-year increase — Cisco said it will eliminate almost 4,000 jobs.

May 7, 2026: Cloudflare to cut 1,100 jobs in AI-focused restructuring

About 20% of Cloudflare’s global workforce will be culled as the company pivots for the agentic AI era, Reuters reported.

April 1, 2026: Oracle to cut up to 30,000 jobs globally, putting enterprise support and roadmaps at risk

Oracle began laying off employees on March 31 in what could be the largest workforce reduction in the company’s history. Employees received termination emails at 6 a.m. local time with immediate system lockouts and no prior warning. (Note: in June, CNBC put the final layoff tally at 21,000.)

March 12, 2026: Atlassian cuts 1,600 jobs to fund AI and enterprise expansion

Atlassian will reduce its global workforce by approximately 10%, eliminating around 1,600 roles, as the collaboration software maker redirects capital toward artificial intelligence development and enterprise sales.

March 11, 2026: Tech layoffs surpass 45,000 in early 2026

A recent analysis by RationalFX found 45,363 job cuts globally so far this year—with roughly 68% or more than 30,000 occurring in the U.S. — highlighting ongoing workforce cuts even as many tech companies report strong revenue growth.

Feb. 10, 2026: Salesforce lays off staffers as executive leadership churn continues

Salesforce has reduced close to 1,000 roles earlier this month across teams, including marketing, product management, data analytics, and its Agentforce AI unit, Business Insider reported, quoting employees familiar with the matter.

Jan. 23, 2026: Amazon layoffs expected to disproportionately hit AWS and tech talent

As the market slows down, AWS and other Amazon units are preparing for another round of layoffs, which is expected to overwhelmingly impact tech talent. An email from HR leader Beth Galetti on Jan. 28 confirmed 16,000 job cuts.

Jan. 15, 2026: Ericsson plans to shed 1,600 jobs in Sweden

 Ericsson lans to cut some 1,600 jobs in Sweden, the telecommunications equipment maker said doubling down on recent cost-saving measures that have helped it weather a prolonged downturn in telecoms spending, Reuters reports.

Jan. 13, 2026: Meta plans to cut around 10% of employees in Reality Labs business

Meta plans to cut around 10% of the employees in its Reality Labs division who work on products including the metaverse, according to three people with knowledge of the discussions, according to The New York Times.

Layoffs in 2025
  • Cisco
  • Oracle
  • Windsurf
  • Intel
  • Microsoft
  • Crowdstrike
  • HPE
  • Autodesk
  • HPE
  • CISA
  • Workday
  • Salesforce
  • Meta
Global tech-sector layoffs surpass 244,000 in 2025

Economic uncertainty, elevated interest rates, and AI adoption have driven workforce reductions across tech companies worldwide, according to a RationalFX report.

October 28, 2025: Amazon to cut 14,000 jobs across company

Amazon will reduce its overall workforce by 14,000, cutting layers of management across the company and hiring in some areas to support its “biggest bets”.

August 18, 2025: Cisco and Oracle to cut hundreds of Bay Area jobs

Tech companies Cisco and Oracle are cutting hundreds of jobs across the Bay Area. Cisco will eliminate 221 positions at its Milpitas and San Francisco offices, effective Oct. 13. Oracle is reducing 101 positions in Santa Clara on the same date 

August 5, 2025: 3 weeks after acquiring Windsurf, Cognition offers staff the exit door

Cognition, the AI coding startup that acquired rival company Windsurf three weeks ago, laid off 30 employees last week and is offering buyouts to the roughly 200 remaining employees on the team, reports The Information.

July 25, 2025, Intel to lay off 22% of workforce, CEO Tan signals ‘no more blank checks’

Intel will reduce its workforce to 75,000 employees by the end of 2025 as new CEO Lip-Bu Tan implements sweeping changes designed to transform the struggling chipmaker

July 8, 2025, Intel layoffs begin: Chipmaker is cutting many thousands of jobs

Intel has begun laying off employees across the company. CEO Lip-Bu Tan told workers back in April to expect major layoffs at Intel in the coming months as the chipmaker slashes costs and overhauls its organization after years of technical setbacks and falling sales.

July 2, 2025: Microsoft will cut 9,000 workers

Microsoft will lay off about 9,000 employees, a source familiar with the workforce cut told CNBC.  The cuts will reportedly affect less than 4% of Microsoft’s global workforce and will impact different teams, geographies and levels of experience. This is the latest in a string of cuts the tech giant has made this year.

June 17, 2025: Intel looks to factory layoffs to return to profitability

Intel will lay off up to 20% of its manufacturing sector employees starting in July, according to media reports, as the company looks for options as it seeks a return to profitability. The cuts reportedly will be made around the world, but some of the layoffs will be closer to home, according to a report in The Oregonian citing an internal company memo from Intel manufacturing Vice President Naga Chandrasekaran.

May 7, 2025: CrowdStrike to lay off 5% of staff

CrowdStrike announced a plan to cut about 500 roles, roughly 5% of its workforce, to streamline operations and reduce costs. The cybersecurity company will incur about $36 million to $53 million in charges related to the layoffs

March 6, 2025: HPE cuts 2,500 jobs, remains committed to Juniper buy

CEO Antonio Neri told Wall Street analysts that HPE would begin implementing a cost-cutting program involving layoffs of about 2,500 employees over the next 18 months. HPE employs about 61,000 people worldwide.

Feb. 27, 2025: Autodesk to lay off 9% of workforce

Software maker Autodesk is laying off 1,350 staff. With the rise of subscription and multi-year contracts billed annually, and self-service enablement, it finds it needs fewer sales staff, CEO Andrew Anagnost said in a message to employees. And with its cloud, platform, and AI products proving most profitable, it’s concentrating its staff and investments there.

Feb. 27, 2025: HP to lay off 2,000 more

As part of an ongoing restructuring, HP plans to lay off up to another 2,000 workers. In recent weeks, the company has tried — unsuccessfully — to do away with telephone support staff by forcing callers to wait for at least 15 minutes if they refuse to use self-service support resources online. The company swiftly backtracked, but wider job cuts are still on.

Feb. 21, 2025: CISA lays off 130

Government employees get laid off too: In this case, 130 workers at the US Cybersecurity and Infrastructure Security Agency are being shown the door as a result of a DOGE decision. Cybersecurity experts are concerned that the cuts will harm the international collaborations that CISA has fostered, quite apart from their concerns about the security of the DOGE layoff process itself.

Feb. 5, 2025: Workday lays off 1,750

As it moves to invest more in AI and international growth, Workday is laying off 8.5% of its workforce and disposing of unused office space. Some analysts fear the cutbacks will affect the company’s customer service — unless AI can pick up the slack.

Feb. 4, 2025: Salesforce lays off over 1,000

At the same time as it’s hiring sales staff for its new artificial intelligence products, Salesforce is laying off over 1,000 workers across the company, according to Bloomberg. As of June, 2024, the company had over 72,000 employees, according to its website. Salesforce did not comment on the report. In 2024 the company reportedly laid off around 1,000 staff too, in two waves: January and July.

Jan. 14, 2025: Meta will lay off 5% of workforce

Mark Zuckerberg told Meta employees he intended to “move out the low performers faster” in an internal memo reported by Bloomberg. The memo announced that the company will lay off 5% of its staff, or around 3,600 staff, beginning Feb. 10. The company had already reduced its headcount by 5% in 2024 through natural attrition, the memo said. Among those leaving the company will be staff previously responsible for fact checking of posts on its social media platforms in the US, as the company begins relying on its users to police content.

Tech layoffs in 2024
  • Equinix
  • AMD
  • Freshworks
  • Cisco
  • General Motors
  • Intel
  • OpenText
  • Microsoft
  • AWS
  • Dell
Nov. 26, 2024: Equinix to cut 3% of staff

Despite intense demand for its data center capacity, Equinix is planning to lay off 3% of its workforce, or around 400 employees. The announcement followed the appointment of Adaire Fox-Martin to replace Charles Meyers as CEO and the departures of two other senior executives, CIO Milind Wagle and CISO Michael Montoya.

Nov. 13, 2024: AMD to cut 4% of workforce

AMD will lay off around 1,000 employees as it pivots towards developing AI-focused chips, it said. The move came as a surprise to staff, as the company also reported strong quarterly earnings.

Nov. 7, 2024: Freshworks lays off 660

Enterprise software vendor Freshworks laid off around 660 staff, or around 13% of its headcount, despite reporting increased revenue and profits in its fourth fiscal quarter. The company described the layoffs as a realignment of its global workforce.

Sept. 17, 2024: Cisco lays off 6,000

After laying off around 4,200 staff in February, Cisco is at it again, laying off another 6,000 or around 7% of its workforce. Among the divisions affected were its threat intelligence unit, Talos Security.

Aug. 20, 2024: General Motors lays off 1,000 software staff

More than 1,000 software and services staff are on the way out at General Motors, signalling that it could be rethinking its digital transformation strategy. In an internal memo, the company said that it was moving resources to its highest-priority work and flattening hierarchies.

August 1, 2024: Intel removes 15,000 roles

Intel plans to cut its workforce by around 15% to reduce costs after a disastrous second quarter. Revenue for the three months to June 29 stagnated at around $12.8 billion, but net income fell 85% to $83 million, prompting CEO Pat Gelsinger to bring forward a company-wide meeting in order to announce that 15,000 staff would lose their jobs. “This is an incredibly hard day for Intel as we are making some of the most consequential changes in our company’s history,” Gelsinger wrote in an email to staff, continuing: “Our revenues have not grown as expected — and we’ve yet to fully benefit from powerful trends, like AI. Our costs are too high, our margins are too low. We need bolder actions to address both — particularly given our financial results and outlook for the second half of 2024, which is tougher than previously expected.”

July 4, 2024: OpenText to lay off 1,200

OpenText said it will lay off 1,200 staff, or about 1.7% of its workforce, in a bid to save around $100 million annually. It plans to hire new sales and engineering staff in other areas in 2025, it said.

June 4, 2024: Microsoft lays off staff in Azure division

Microsoft laid off staff in several teams supporting its cloud services, including Azure for Operations and Mission Engineering. The company didn’t say exactly how many staff were leaving.

April 4, 2024: Amazon downsizes AWS in a fresh cost-cutting round

Amazon announced hundreds of layoffs in the sales and marketing teams of its AWS cloud services division — and also in the technology development teams for its physical retail stores, as it stepped back from efforts to generalize the “Just Walk Out” technology built for its Amazon Fresh grocery stores.

April 1, 2024: Dell acknowledges 13,000 job cuts

Dell Technologies’ latest 10K filing with the US Securities and Exchange Commission disclosed that the company had laid off 13,000 employees over the course of the 2023 fiscal year; it characterized the layoffs and other reorganizational moves as cost-cutting measures. “These actions resulted in a reduction in our overall headcount,” the company said. A comparison to the previous year’s 10K filing, performed by The Register, found that Dell employed 133,000 people at that point, compared to 120,000 as of February 2024. Dell announced layoffs of 6,650 staffers on Feb. 6, but it is unclear whether those cuts were reflected in the numbers from this year’s 10K statement.

See news of earlier layoffs.

Kategorie: Hacking & Security

Apple to OpenAI: If you have nothing to hide, you have nothing to fear

15 Září, 2026 - 18:07

Just because Apple now has AI, a new folding iPhone, and a newly minted CEO doesn’t mean the litigation between it and OpenAI has gone away. Apple now wants to force OpenAI to let it look at the hardware it has been building, according to a new report.

A reasonable request?

It seems a reasonable request, doesn’t it? After all, Apple’s argument is that OpenAI has been engaged in trade secret theft to help it design and develop its new hardware. OpenAI’s defense against these claims feel flimsy, at least to this reporter. They seem to coalesce around something like, “We don’t need your trade secrets because we’re making something brand new.” 

The problem with that defense is, contextually, that while on this stated mission to do something completely new, the company has hired around 400 former Apple staff so far, including its chief designers. And Apple thinks part of that process has been OpenAI, in whole or in part, working to exfiltrate its trade secrets.

What Apple wants — and why

With those facts as your guide, Apple’s request to Judge Edward J. Davila seems reasonable. It wants to take a look at what OpenAI is developing to ensure its trade secrets have not been abused in the process of designing that product. Apple argues that if it is forced to wait until the product is released, then it will be impossible to make its trade secrets confidential again, particularly as the defense seems to consist of that pinky promise that no Apple trade secrets have been harmed.

Apple legal also argues that it cannot be fair to allow OpenAI to defend itself by alleging its unreleased and unseen product doesn’t contain any trade secrets without permitting Apple — and the court — to verify that. While Apple’s counsel doesn’t seem to have said it, you could paraphrase the request as Apple telling the genAI firm, “Let us see what you are building; if you have nothing to hide, you have nothing to fear.”

Except, of course, that while building its defense, OpenAI is giving many of us the distinct impression that it may have something to fear.

What may happen next

Despite the merits of the argument, I think Apple’s request will not prevail, in part because the court may assess that if Apple takes a look at OpenAI’s homework it may compound the risk of IP theft. But that doesn’t mean Apple’s attempt will fail outright, as the compromise position is likely to be the appointment of a trusted, independent, third-party expert witness to take a look at what Apple’s competitor is making in Apple’s stead. 

There is precedent for this. That’s more or less what happened when Waymo pursued a similar case against Uber, or when AMCS litigated against Sinovel. There are nuances to all three cases that mean they aren’t perfectly aligned, but that does seem a logical next step to this layman.

Of course, just because it’s logical doesn’t mean either party is going to like it, but OpenAI could conceivably even suggest such an approach as it seeks to buy itself time to build and release its still mythical hardware. That’s also why Apple wants a chance to look at documents pertaining to that hardware to make very certain it hasn’t infringed any of Apple’s own trade secrets.

A side order of humble pie

All the same, if this case does indeed turn out to be a scenario in which one company has been found with its hand in the cookie jar, then the best possible approach for the company with crumbs around its mouth is going to be damage control. That’s going to take a lot less war-war and a great deal more jaw-jaw. It’s also going to require the intake of a very, very large slice of humble pie. Right now, it seems to me that Apple isn’t talking, and OpenAI isn’t hungry enough to take that first bite. Not yet. 

The case, number 5:26-cv-07078, rolls on.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSkyLinkedIn, or Mastodon.

Kategorie: Hacking & Security