Agregátor RSS

Single CAR T Injection Eases Multiple Sclerosis Symptoms in Small Trial

Singularity HUB - 15 Září, 2026 - 21:45

A potentially safer, simpler way to create CAR T cells in the body could bring this powerful therapy to the masses.

When the body goes to war on itself, it wreaks havoc.

The immune system is one of our most powerful defenses, protecting us from infections, cancer, and other threats. But it’s a double-edged sword. Sometimes all that firepower is turned against healthy tissue. The resulting autoimmune diseases can be devastating. Take multiple sclerosis, an insidious disease that gradually eats away at the insulating coating around delicate nerve fibers, scrambling the electrical signals that control our bodies. The disease often strikes in young or middle adulthood, and there’s no cure.

Now a new clinical trial turns the immune system’s arsenal against the cells driving the autoimmune attack. Called CAR T cell therapy, the approach has already had success tackling previously untreatable blood cancers. Normally, CAR T cells are isolated and genetically engineered in specialized facilities. But in the new trial, with a single injection, researchers delivered a virus carrying genetic instructions to reprogram T cells in the body.

In 16 patients with autoimmune disorders affecting the nervous system, the treatment had few severe side effects. It also seemed to hit a kind of immune reset button. Follow-up tests suggested that the treatment restored parts of patients’ immune systems to normal, and there were no signs the friendly fire had returned. Across three different diseases, symptoms and molecular markers improved for over six months.

“These findings provide proof-of-concept that in vivo [in the body] CAR T-cell generation is associated with manageable side effects and may be effective for treating refractory neurologic autoimmune disorders,” wrote the team.

The study was small, and there was no control group. But it brings the dream of a simpler, cheaper, and more affordable CAR T therapy a step closer. This could, in turn, give more people access to the drug.

“It’s a clear go signal for a further study,” Georg Schett at University Hospital Erlangen, who wasn’t involved in the work, told Science.

Outside In

Once a niche treatment for blood cancer, CAR T therapy has quickly expanded, with over 1,500 clinical trials registered worldwide. Hope is high CAR T can battle solid tumors, which account for more than 85 percent of cancer cases, and even stop them from spreading. It’s also being repurposed to take on a range of autoimmune disorders, such as lupus, with promising early results.

But there’s a catch. Making CAR T cells is a logistical nightmare.

Traditionally, doctors must harvest a patient’s T cells and genetically edit them outside the body to produce protein “bloodhounds” called chimeric antigen receptors, or CARs. These proteins sit on each engineered cell’s surface and help it recognize a specific target. Once CAR T cells are infused back into the patient, they hunt down and attack disease-causing cells involved in some cancers and autoimmune disorders.

The whole production can take weeks—precious time some patients don’t have. A price tag in the hundreds of thousands of dollars keeps the therapy out of reach for many. And the need for toxic chemotherapy, which clears out existing immune cells to make room for CAR Ts, leaves people vulnerable to infection and adds another burden to an already grueling treatment.

So, researchers have pursued shortcuts. One idea is to skip the individualized manufacturing step and use healthy donated T cells to save time and cost. But this can trigger immune rejection, where the body wipes out the “invaders,” or spark dangerous reactions against the patient’s own tissues.

These risks aren’t just speculation. The pharmaceutical giant Novartis recently halted eight CAR T trials for autoimmune disorders after three participants died from a severe inflammatory complication. While the tragedy is still under investigation, one possible cause is that the engineered cells expanded and activated too rapidly.

In another popular alternative, researchers alter a patient’s own T cells inside their body. Dubbed in vivo, this method delivers a synthetic gene encoding the CAR protein to T cells, turning them into super-soldiers on the spot. In theory, the same genetic formulation could work for many people, making CAR T therapy more like a drug and slashing time and cost. The approach also spares patients from chemotherapy and could be safer.

But it’s tricky business. Transforming isolated T cells outside the body limits the added gene to only that population. Inside the body, scientists have far less control over where the genetic cargo goes. A delivery system meant only for T cells could reach other cell types or inadvertently integrate into the genome, spurring mutations that contribute to cancer. Still, some creative workarounds that boost safety and efficacy have already shown promise in mice.

But what about people?

Factory Reset

The new trial recruited 16 volunteers with multiple sclerosis and other autoimmune conditions affecting the nervous system, including diseases that attack the spinal cord or eyes or cause muscle weakness.

Led by Dai-Shi Tian of the Huazhong University of Science and Technology, the team infused patients with a virus carrying instructions to turn T cells into CAR T cells that would go on to target rogue B cells. The latter are immune cells that pump out autoantibodies against healthy tissue. Patients were monitored for six months, with safety as a priority.

None developed severe nerve inflammation, a potentially deadly CAR T complication. The treatment briefly revved up inflammatory molecules in 11 participants, but the response was manageable and faded after roughly two weeks.

Because the virus inserts DNA into the genome, the team also tracked where the synthetic gene landed. Most copies of the gene were found in regions that don’t encode proteins. But these parts can still influence gene activity, and it’s too soon to conclude the therapy is safe over the long term—or that it works.

Still, early signs are promising. After one infusion, patients continued producing CAR T cells for months, while levels of disease-causing B cells plummeted. The immune system seemed to reset. Newly generated replacement B cells no longer made autoantibodies, hinting the effects might last.

Symptoms also improved. People with multiple sclerosis reported less fatigue and better motor and cognitive function. Molecular markers of nerve injury fell, and none of the patients developed new damage to the protective sheaths around their nerves. Those suffering from other neurological autoimmune conditions that weaken muscles regained strength, had lower levels of inflammation, and reported better quality of life.

The findings add to growing evidence that in vivo CAR T may work in people. Previous small trials have already tested it against cancer and lupus, with encouraging results.

If the findings hold up in more people, the treatment “could be a gamechanger,” David Simon at Charité–Universitätsmedizin Berlin, who wasn’t involved in the study, told Nature. “This is a very exciting proof-of-concept study.”

The team cautions that more follow-up is needed to see how long the benefits last and catch delayed side effects, such as cancer or infections. And because autoimmune diseases are chronic, relapse remains a concern. They plan to launch a larger trial focused on a single condition, potentially with a control group.

The post Single CAR T Injection Eases Multiple Sclerosis Symptoms in Small Trial appeared first on SingularityHub.

Kategorie: Transhumanismus

Low-quality casino sites conceal highly dangerous threat actors

The Register - Anti-Virus - 15 Září, 2026 - 21:38
If your employees are visiting Chinese-language gambling or adult sites, they may not just be wasting time and money, but potentially encountering serious malware hidden behind domains that look like mostly harmless entertainment at first glance. A report from Infoblox urges the security community to pay closer attention to these websites, because some double as command-and-control (C2) infrastructure for espionage and malware distribution. Zach Edwards, staff threat researcher at Infoblox, suggests security researchers and the media have ignored these sites because the story is complicated and confusing. Infoblox says it tracks about 1.7 million Chinese-language casino websites that facilitate illegal gambling. These support North Korean money laundering and tax avoidance, among other dubious activities. And these casino sites can be difficult to distinguish from one another. They tend to use variations of common templates in terms of design and function. Many operate like a legal casino would, just relying on the advantage of house odds to profit. While these sites provide illegal gambling and adult entertainment for online visitors from China and Asia, some rely on US cloud providers for computing infrastructure. "Major US hosting companies (Amazon, Microsoft, Cloudflare, and Google) continue to host infrastructure associated with these domains," the Infoblox report explains. "One likely explanation is account theft at those providers, a practice documented previously as 'infrastructure laundering.'" That refers to hosting companies like Funnull that have reportedly rented IP addresses from Amazon Web Services and Microsoft and made those resources available to clients carrying out illegal activities. According to a July 2026 report from the UN Office on Drugs and Crime (UNODC), disparate crime syndicates increasingly use common infrastructure for cybercrime, while online scams resulted in estimated losses of between $88.3 billion and $114.1 billion in 2025 across East Asia, Southeast Asia, Australia, and New Zealand. A subset of casino sites offer scam gambling, or "scambling." Visitors place bets but can't get their money out if they win. And then there's a subset of sites used by China-aligned threat groups. "China-aligned APT groups have been running the PeckBirdy framework since 2023, hiding their malware C2 domains inside low-quality Chinese-language casino websites," Infoblox said. PeckBirdy, as noted by Trend Micro researchers in January, is a script-based framework that attackers can load through compromised websites. In one campaign, attackers injected scripts into gambling sites that loaded PeckBirdy and displayed fake software update pages designed to entice victims to download malware. The problem is that each of these three types of sites, though they change frequently, looks similar. Infoblox notes that just over 3 percent of its enterprise customers resolved at least one PeckBirdy C2 domain. "The most important thing for defenders to do is stop ignoring casino domains," Infoblox argues. "An alert on a Chinese-language casino or adult domain that gets closed as an employee browsing violation is precisely the outcome the PeckBirdy operators are counting on. The decoy works because the dismissal is reasonable – these domains genuinely are, most of the time, exactly what they appear to be." Security analysts who review suspicious network contacts are advised to check whether these casino domains include malicious payloads before closing the review ticket. ®
Kategorie: Viry a Červi

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

The Hacker News - 15 Září, 2026 - 20:54
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

The Register - Anti-Virus - 15 Září, 2026 - 20:01
Iranian state cyber actors are targeting individuals using social messaging apps to deploy surveillance and data-stealing malware on their Windows machines, three Western governments warned. In all observed cases, Chosen Brick has infected Windows systems exclusively. Iran has used it since at least 2025 to take over individuals’ devices, stealing their contacts, emails, and social media messages, which allows the spies to track people’s movements, the FBI, UK National Cyber Security Centre, and the Netherlands’ General Intelligence and Security Service (AIVD) said on Tuesday. “Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists,” the security advisory said. “In some cases, the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, who they perceive as enemies of the regime.” These attacks typically begin with WhatsApp and Telegram messages, purportedly coming from individuals and organizations that the victim knows and trusts. The Iranian spies do a significant amount of research to prepare for these social engineering campaigns. By the time they send the initial message via a social media app, they have “extensive” knowledge of the targeted individual, their contacts, and relevant industry organizations to make the phony messages more believable, according to the agencies. After building rapport with the mark, the attackers convince them to download and open a file that appears to be a legitimate application. Specifically: Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass are among the legitimate applications the malicious files have been made to resemble, the government agencies said. Upon opening the file, the malware executes without the victim’s knowledge, and will survive a reboot of the target device. Chosen Brick also adds exclusions to Microsoft Defender antivirus in an attempt to evade detection, and then connects to Telegram for command-and-control (C2) communications using a victim-specific Telegram bot. While the malware hasn’t yet been observed to automate lateral movement across the network, this is “technically possible,” the advisory noted. It does, however, download additional malware and set up persistence for new payloads on infected devices, using the same registry key that Chosen Brick uses to establish its own persistence on a Windows device: HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Other features include enumerating running processes and system information, capturing screen and audio content, stealing emails, along with Telegram and WhatsApp data from web browsers, and wiping the computer system. “Organizations that are concerned Chosen Brick has been executed should contact their IT providers, either internal or external, to investigate,” the US, UK, and the Netherlands warned. “As this actor targets personal devices, not just corporate devices, organizations are recommended to circulate this with their staff that are likely to be targeted and support them in checking their personal devices too.” The Western agencies’ latest Iran alert follows a series of water and energy cyberattacks that researchers and media reports have linked to Iran, although the US and UK governments have stopped short of formally attributing them, as the military conflict between Iran and the US approaches its seventh month. In August, America’s lead cybersecurity agency, CISA, disclosed that the July cyberattacks that disrupted American water utilities across 12 states targeted more than 100 internet-exposed water systems. CISA did not, however, attribute the campaign to Iran or anyone else. Around the same time, a suspected Iran-linked cyberattack also shut down a small UK power plant. Also in August, five US agencies warned that attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other critical facilities. “This is not a theoretical risk – it is an active threat,” the feds warned. ®
Kategorie: Viry a Červi

HBO Max a 30 nejoblíbenějších filmů a seriálů v září 2026. Lanterns, Stuart z TBBT, President Curtis…

Živě.cz - 15 Září, 2026 - 19:45
Tyto filmy a seriály jsou teď na českém HBO Max nejoblíbenější. Nerozlišujeme žánr, stáří ani hodnocení na filmových webech. Jde o souhrnnou oblíbenost za poslední týdny, kterou zjišťuje a počítá web FlixPatrol.
Kategorie: IT News

macOS 27 Golden Gate zkrotil tekuté sklo a je svižnější. Na hlavní tahák si Češi počkají

Živě.cz - 15 Září, 2026 - 18:45
macOS 27 se zaměřuje hlavně na AI, která uvidí do všech aplikací. • Apple věnuje velkou pozornost rodičovské kontrole. • Po kritice designu Liquid Glass dorazila spousta úprav a optimalizací.
Kategorie: IT News

CenterPoint Energy confirms customer data stolen in cyberattack

Bleeping Computer - 15 Září, 2026 - 18:40
CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company. [...]
Kategorie: Hacking & Security

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

The Hacker News - 15 Září, 2026 - 18:29
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Oracle forecasts 33% increase in restructuring costs as new round of layoffs hits

Computerworld.com [Hacking News] - 15 Září, 2026 - 18:22

Oracle began a new round of layoffs this week, sending early-morning termination emails to staff for the second time in six months.

The latest wave began Monday with affected staff being told, “After careful consideration of Oracle’s current business needs, we have made the decision to eliminate your role as part of a broader organizational change,” according to BusinessInsider. Termination was immediate.

That’s the same wording as in the previous wave of layoffs, which took place on March 31 and affected workers in the US, India, Canada, Mexico and Uruguay. In the 12 months to May 31, Oracle cut its global workforce from about 162,000 to about 141,000, a decline of roughly 13%.

Oracle has made no public statement confirming the latest round of job cuts, but in a regulatory filing days earlier the company said it had set aside a further $700 million for restructuring charges, bringing the total charges this year to roughly $2.8 billion.

What the new termination emails say

Staff receiving the latest termination emails were told termination and compensation details would follow by DocuSign, Business Insider wrote. An internal document reviewed by the publication said severance terms varied by role and region, and some teams facing double-digit percentage cuts.

Affected employees took to social media to vent.

Eric Brunson, a senior principal offensive security researcher at Oracle, described in a LinkedIn post how he had lost access to corporate communication tools before receiving any formal notice. “I woke up to not being able to log back into Slack,” he wrote. “No new emails or notification in email and I’m locked out of there. I was able to get ahold of my manager on LinkedIn and she confirmed.” Brunson said the timing fell two days before a scheduled RSU vesting date, adding, “Probably part of the plan.”

The filing that backs up the layoff accounts

While Oracle is not talking about the layoffs, its 10-Q quarterly report states that management approved and supplemented restructuring plans “to implement certain strategic measures and further improve operational efficiencies, including through the adoption and integration of artificial intelligence technologies across certain functions.” It adds that “subsequent to August 31, 2026, our management supplemented the 2026 Restructuring Plan by approximately $700 million to reflect additional actions that we expect to take.”

Oracle has already spent $1.97 billion of the $2.1 billion restructuring charges it originally budgeted, it reported.

Sanchit Vir Gogia, chief analyst at Greyhound Research, said the filing should be read carefully rather than as confirmation of a headcount. “The supplement is an estimate, not a bill,” he said, noting it raises the program’s estimated cost by about a third without committing Oracle to a timetable.

Gogia said the more significant shift is in the filing’s language rather than the dollar figure. Oracle’s August 2025 and February 2026 filings had described the plan as tied to “acquisitions and certain other operational activities.”

AI was named as a driver of restructuring for the first time in the Sept. 11 filing.

Why the headcount stays unconfirmed

Gogia said no verified figure exists yet for how many employees the September round affected.

He noted that 30,000 was a January forecast of the total 2026 program. Twenty-one thousand is the confirmed net decline in Oracle’s global workforce across the full fiscal year. A reported 3,000 job cuts in India on Sept. 1 remains unconfirmed by Oracle.

The $700 million restructuring supplement “cannot be divided into people,” Gogia said, since it covers termination benefits, contract termination costs and other exit costs across a program spanning multiple countries. “There is no solid headcount for the September round,” he said.

A pattern that began in March

Oracle’s first 2026 layoff wave began March 31, when the Revenue and Health Sciences unit, the SaaS and Virtual Operations Services group, and NetSuite’s India Development Centre saw some of the deepest reductions.

Figures published by Oracle for its fiscal year ending May 31, 2026, show research and development headcount fell from 50,000 to 43,000 employees during the year, sales and marketing fell from 31,000 to 25,000, and services fell from 37,000 to 34,000, according to Gogia’s analysis of the company’s own reporting.

International staff, at 92,000, saw a larger reduction than the 49,000-strong U.S. workforce, he said.

Oracle did not respond to a request for comment.

This article first appeared on CIO.

Kategorie: Hacking & Security

Tech layoffs: A 2026 timeline

Computerworld.com [Hacking News] - 15 Září, 2026 - 18:21

Among a range of factors leading to a wave of tech sector layoffs in 2026 is the rapid rise of artificial intelligence and automation. Companies are reconfiguring their workforces to leverage AI for increased efficiency and reduced operating costs. This realignment and reduction is implemented even by companies reporting strong financial performance.

But it’s not just AI leading to workforce cuts. Complementing this technological shift are ongoing economic uncertainty, inflation, and higher interest rates, compounded by a chip shortage and rising energy costs. This mix is driving companies to cut costs and streamline operations for increased efficiency.

According to data compiled by Layoffs.fyi, an online tracker that keep tabs on job losses in the technology sector, 123,941 tech employees were laid off at 269 companies in 2025. The site also reports that 71,981 government employees were laid off by DOGE alone, with 182,528 total federal workers laid off.

Here is a list — to be updated regularly — of some of the most prominent technology layoffs the industry has experienced recently.

Notable tech layoffs in 2026
  • Oracle (again)
  • Monday.com
  • Microsoft
  • Meta
  • Cisco
  • Cloudflare
  • Oracle
  • Atlassian
  • Salesforce
  • Amazon
  • Ericsson
Sept. 15, 2026: Oracle forecasts 33% increase in restructuring costs as new round of layoffs hits

Oracle began a new round of layoffs this week, sending early-morning termination emails to staff for the second time in six months. Oracle has made no public statement confirming the latest round of job cuts, but in a regulatory filing days earlier the company said it had set aside a further $700 million for restructuring charges, bringing the total charges this year to roughly $2.8 billion.

July 22, 2026: Monday.com cuts 20% of its workforce to restructure for the AI era

The company says the decision to cut 620 jobs isn’t about margins, but about creating a flatter organization built around AI agents, autonomous teams, and deeper customer engagement.

July 6, 2026: Microsoft cuts 4,800 jobs, primarily in sales and Xbox teams

As the company trims thousands of jobs, it’s also investing in embedded engineering teams and AI infrastructure. The layoffs come several weeks after the company offered 8,750 US employees voluntary retirement buyouts.

June 5, 2026: Tech industry cut 38,242 jobs in May, worst since 2024

AI was blamed for 40% of the job cuts in May, up from 7% in January, according to research by employment placement company Challenger, Gray & Christmas.

May 20, 2026: Meta cuts 8,000 jobs, around 10% of workforce

The cuts are expected to expected to hit Meta’s engineering and product teams the hardest, arriving as Meta pivots toward AI to boost efficiency across its organization, according to Yahoo Tech.

May 13, 2026: Cisco to cut nearly 4,000 jobs despite strong growth in AI, enterprise networking

Despite reporting positive financial news — including record third-quarter revenue of $15.8 billion, a 12% year-over-year increase — Cisco said it will eliminate almost 4,000 jobs.

May 7, 2026: Cloudflare to cut 1,100 jobs in AI-focused restructuring

About 20% of Cloudflare’s global workforce will be culled as the company pivots for the agentic AI era, Reuters reported.

April 1, 2026: Oracle to cut up to 30,000 jobs globally, putting enterprise support and roadmaps at risk

Oracle began laying off employees on March 31 in what could be the largest workforce reduction in the company’s history. Employees received termination emails at 6 a.m. local time with immediate system lockouts and no prior warning. (Note: in June, CNBC put the final layoff tally at 21,000.)

March 12, 2026: Atlassian cuts 1,600 jobs to fund AI and enterprise expansion

Atlassian will reduce its global workforce by approximately 10%, eliminating around 1,600 roles, as the collaboration software maker redirects capital toward artificial intelligence development and enterprise sales.

March 11, 2026: Tech layoffs surpass 45,000 in early 2026

A recent analysis by RationalFX found 45,363 job cuts globally so far this year—with roughly 68% or more than 30,000 occurring in the U.S. — highlighting ongoing workforce cuts even as many tech companies report strong revenue growth.

Feb. 10, 2026: Salesforce lays off staffers as executive leadership churn continues

Salesforce has reduced close to 1,000 roles earlier this month across teams, including marketing, product management, data analytics, and its Agentforce AI unit, Business Insider reported, quoting employees familiar with the matter.

Jan. 23, 2026: Amazon layoffs expected to disproportionately hit AWS and tech talent

As the market slows down, AWS and other Amazon units are preparing for another round of layoffs, which is expected to overwhelmingly impact tech talent. An email from HR leader Beth Galetti on Jan. 28 confirmed 16,000 job cuts.

Jan. 15, 2026: Ericsson plans to shed 1,600 jobs in Sweden

 Ericsson lans to cut some 1,600 jobs in Sweden, the telecommunications equipment maker said doubling down on recent cost-saving measures that have helped it weather a prolonged downturn in telecoms spending, Reuters reports.

Jan. 13, 2026: Meta plans to cut around 10% of employees in Reality Labs business

Meta plans to cut around 10% of the employees in its Reality Labs division who work on products including the metaverse, according to three people with knowledge of the discussions, according to The New York Times.

Layoffs in 2025
  • Cisco
  • Oracle
  • Windsurf
  • Intel
  • Microsoft
  • Crowdstrike
  • HPE
  • Autodesk
  • HPE
  • CISA
  • Workday
  • Salesforce
  • Meta
Global tech-sector layoffs surpass 244,000 in 2025

Economic uncertainty, elevated interest rates, and AI adoption have driven workforce reductions across tech companies worldwide, according to a RationalFX report.

October 28, 2025: Amazon to cut 14,000 jobs across company

Amazon will reduce its overall workforce by 14,000, cutting layers of management across the company and hiring in some areas to support its “biggest bets”.

August 18, 2025: Cisco and Oracle to cut hundreds of Bay Area jobs

Tech companies Cisco and Oracle are cutting hundreds of jobs across the Bay Area. Cisco will eliminate 221 positions at its Milpitas and San Francisco offices, effective Oct. 13. Oracle is reducing 101 positions in Santa Clara on the same date 

August 5, 2025: 3 weeks after acquiring Windsurf, Cognition offers staff the exit door

Cognition, the AI coding startup that acquired rival company Windsurf three weeks ago, laid off 30 employees last week and is offering buyouts to the roughly 200 remaining employees on the team, reports The Information.

July 25, 2025, Intel to lay off 22% of workforce, CEO Tan signals ‘no more blank checks’

Intel will reduce its workforce to 75,000 employees by the end of 2025 as new CEO Lip-Bu Tan implements sweeping changes designed to transform the struggling chipmaker

July 8, 2025, Intel layoffs begin: Chipmaker is cutting many thousands of jobs

Intel has begun laying off employees across the company. CEO Lip-Bu Tan told workers back in April to expect major layoffs at Intel in the coming months as the chipmaker slashes costs and overhauls its organization after years of technical setbacks and falling sales.

July 2, 2025: Microsoft will cut 9,000 workers

Microsoft will lay off about 9,000 employees, a source familiar with the workforce cut told CNBC.  The cuts will reportedly affect less than 4% of Microsoft’s global workforce and will impact different teams, geographies and levels of experience. This is the latest in a string of cuts the tech giant has made this year.

June 17, 2025: Intel looks to factory layoffs to return to profitability

Intel will lay off up to 20% of its manufacturing sector employees starting in July, according to media reports, as the company looks for options as it seeks a return to profitability. The cuts reportedly will be made around the world, but some of the layoffs will be closer to home, according to a report in The Oregonian citing an internal company memo from Intel manufacturing Vice President Naga Chandrasekaran.

May 7, 2025: CrowdStrike to lay off 5% of staff

CrowdStrike announced a plan to cut about 500 roles, roughly 5% of its workforce, to streamline operations and reduce costs. The cybersecurity company will incur about $36 million to $53 million in charges related to the layoffs

March 6, 2025: HPE cuts 2,500 jobs, remains committed to Juniper buy

CEO Antonio Neri told Wall Street analysts that HPE would begin implementing a cost-cutting program involving layoffs of about 2,500 employees over the next 18 months. HPE employs about 61,000 people worldwide.

Feb. 27, 2025: Autodesk to lay off 9% of workforce

Software maker Autodesk is laying off 1,350 staff. With the rise of subscription and multi-year contracts billed annually, and self-service enablement, it finds it needs fewer sales staff, CEO Andrew Anagnost said in a message to employees. And with its cloud, platform, and AI products proving most profitable, it’s concentrating its staff and investments there.

Feb. 27, 2025: HP to lay off 2,000 more

As part of an ongoing restructuring, HP plans to lay off up to another 2,000 workers. In recent weeks, the company has tried — unsuccessfully — to do away with telephone support staff by forcing callers to wait for at least 15 minutes if they refuse to use self-service support resources online. The company swiftly backtracked, but wider job cuts are still on.

Feb. 21, 2025: CISA lays off 130

Government employees get laid off too: In this case, 130 workers at the US Cybersecurity and Infrastructure Security Agency are being shown the door as a result of a DOGE decision. Cybersecurity experts are concerned that the cuts will harm the international collaborations that CISA has fostered, quite apart from their concerns about the security of the DOGE layoff process itself.

Feb. 5, 2025: Workday lays off 1,750

As it moves to invest more in AI and international growth, Workday is laying off 8.5% of its workforce and disposing of unused office space. Some analysts fear the cutbacks will affect the company’s customer service — unless AI can pick up the slack.

Feb. 4, 2025: Salesforce lays off over 1,000

At the same time as it’s hiring sales staff for its new artificial intelligence products, Salesforce is laying off over 1,000 workers across the company, according to Bloomberg. As of June, 2024, the company had over 72,000 employees, according to its website. Salesforce did not comment on the report. In 2024 the company reportedly laid off around 1,000 staff too, in two waves: January and July.

Jan. 14, 2025: Meta will lay off 5% of workforce

Mark Zuckerberg told Meta employees he intended to “move out the low performers faster” in an internal memo reported by Bloomberg. The memo announced that the company will lay off 5% of its staff, or around 3,600 staff, beginning Feb. 10. The company had already reduced its headcount by 5% in 2024 through natural attrition, the memo said. Among those leaving the company will be staff previously responsible for fact checking of posts on its social media platforms in the US, as the company begins relying on its users to police content.

Tech layoffs in 2024
  • Equinix
  • AMD
  • Freshworks
  • Cisco
  • General Motors
  • Intel
  • OpenText
  • Microsoft
  • AWS
  • Dell
Nov. 26, 2024: Equinix to cut 3% of staff

Despite intense demand for its data center capacity, Equinix is planning to lay off 3% of its workforce, or around 400 employees. The announcement followed the appointment of Adaire Fox-Martin to replace Charles Meyers as CEO and the departures of two other senior executives, CIO Milind Wagle and CISO Michael Montoya.

Nov. 13, 2024: AMD to cut 4% of workforce

AMD will lay off around 1,000 employees as it pivots towards developing AI-focused chips, it said. The move came as a surprise to staff, as the company also reported strong quarterly earnings.

Nov. 7, 2024: Freshworks lays off 660

Enterprise software vendor Freshworks laid off around 660 staff, or around 13% of its headcount, despite reporting increased revenue and profits in its fourth fiscal quarter. The company described the layoffs as a realignment of its global workforce.

Sept. 17, 2024: Cisco lays off 6,000

After laying off around 4,200 staff in February, Cisco is at it again, laying off another 6,000 or around 7% of its workforce. Among the divisions affected were its threat intelligence unit, Talos Security.

Aug. 20, 2024: General Motors lays off 1,000 software staff

More than 1,000 software and services staff are on the way out at General Motors, signalling that it could be rethinking its digital transformation strategy. In an internal memo, the company said that it was moving resources to its highest-priority work and flattening hierarchies.

August 1, 2024: Intel removes 15,000 roles

Intel plans to cut its workforce by around 15% to reduce costs after a disastrous second quarter. Revenue for the three months to June 29 stagnated at around $12.8 billion, but net income fell 85% to $83 million, prompting CEO Pat Gelsinger to bring forward a company-wide meeting in order to announce that 15,000 staff would lose their jobs. “This is an incredibly hard day for Intel as we are making some of the most consequential changes in our company’s history,” Gelsinger wrote in an email to staff, continuing: “Our revenues have not grown as expected — and we’ve yet to fully benefit from powerful trends, like AI. Our costs are too high, our margins are too low. We need bolder actions to address both — particularly given our financial results and outlook for the second half of 2024, which is tougher than previously expected.”

July 4, 2024: OpenText to lay off 1,200

OpenText said it will lay off 1,200 staff, or about 1.7% of its workforce, in a bid to save around $100 million annually. It plans to hire new sales and engineering staff in other areas in 2025, it said.

June 4, 2024: Microsoft lays off staff in Azure division

Microsoft laid off staff in several teams supporting its cloud services, including Azure for Operations and Mission Engineering. The company didn’t say exactly how many staff were leaving.

April 4, 2024: Amazon downsizes AWS in a fresh cost-cutting round

Amazon announced hundreds of layoffs in the sales and marketing teams of its AWS cloud services division — and also in the technology development teams for its physical retail stores, as it stepped back from efforts to generalize the “Just Walk Out” technology built for its Amazon Fresh grocery stores.

April 1, 2024: Dell acknowledges 13,000 job cuts

Dell Technologies’ latest 10K filing with the US Securities and Exchange Commission disclosed that the company had laid off 13,000 employees over the course of the 2023 fiscal year; it characterized the layoffs and other reorganizational moves as cost-cutting measures. “These actions resulted in a reduction in our overall headcount,” the company said. A comparison to the previous year’s 10K filing, performed by The Register, found that Dell employed 133,000 people at that point, compared to 120,000 as of February 2024. Dell announced layoffs of 6,650 staffers on Feb. 6, but it is unclear whether those cuts were reflected in the numbers from this year’s 10K statement.

See news of earlier layoffs.

Kategorie: Hacking & Security

Apple to OpenAI: If you have nothing to hide, you have nothing to fear

Computerworld.com [Hacking News] - 15 Září, 2026 - 18:07

Just because Apple now has AI, a new folding iPhone, and a newly minted CEO doesn’t mean the litigation between it and OpenAI has gone away. Apple now wants to force OpenAI to let it look at the hardware it has been building, according to a new report.

A reasonable request?

It seems a reasonable request, doesn’t it? After all, Apple’s argument is that OpenAI has been engaged in trade secret theft to help it design and develop its new hardware. OpenAI’s defense against these claims feel flimsy, at least to this reporter. They seem to coalesce around something like, “We don’t need your trade secrets because we’re making something brand new.” 

The problem with that defense is, contextually, that while on this stated mission to do something completely new, the company has hired around 400 former Apple staff so far, including its chief designers. And Apple thinks part of that process has been OpenAI, in whole or in part, working to exfiltrate its trade secrets.

What Apple wants — and why

With those facts as your guide, Apple’s request to Judge Edward J. Davila seems reasonable. It wants to take a look at what OpenAI is developing to ensure its trade secrets have not been abused in the process of designing that product. Apple argues that if it is forced to wait until the product is released, then it will be impossible to make its trade secrets confidential again, particularly as the defense seems to consist of that pinky promise that no Apple trade secrets have been harmed.

Apple legal also argues that it cannot be fair to allow OpenAI to defend itself by alleging its unreleased and unseen product doesn’t contain any trade secrets without permitting Apple — and the court — to verify that. While Apple’s counsel doesn’t seem to have said it, you could paraphrase the request as Apple telling the genAI firm, “Let us see what you are building; if you have nothing to hide, you have nothing to fear.”

Except, of course, that while building its defense, OpenAI is giving many of us the distinct impression that it may have something to fear.

What may happen next

Despite the merits of the argument, I think Apple’s request will not prevail, in part because the court may assess that if Apple takes a look at OpenAI’s homework it may compound the risk of IP theft. But that doesn’t mean Apple’s attempt will fail outright, as the compromise position is likely to be the appointment of a trusted, independent, third-party expert witness to take a look at what Apple’s competitor is making in Apple’s stead. 

There is precedent for this. That’s more or less what happened when Waymo pursued a similar case against Uber, or when AMCS litigated against Sinovel. There are nuances to all three cases that mean they aren’t perfectly aligned, but that does seem a logical next step to this layman.

Of course, just because it’s logical doesn’t mean either party is going to like it, but OpenAI could conceivably even suggest such an approach as it seeks to buy itself time to build and release its still mythical hardware. That’s also why Apple wants a chance to look at documents pertaining to that hardware to make very certain it hasn’t infringed any of Apple’s own trade secrets.

A side order of humble pie

All the same, if this case does indeed turn out to be a scenario in which one company has been found with its hand in the cookie jar, then the best possible approach for the company with crumbs around its mouth is going to be damage control. That’s going to take a lot less war-war and a great deal more jaw-jaw. It’s also going to require the intake of a very, very large slice of humble pie. Right now, it seems to me that Apple isn’t talking, and OpenAI isn’t hungry enough to take that first bite. Not yet. 

The case, number 5:26-cv-07078, rolls on.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSkyLinkedIn, or Mastodon.

Kategorie: Hacking & Security

Cisco email security boxes can be rooted by... an email

The Register - Anti-Virus - 15 Září, 2026 - 18:01
Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and virtual Secure Email Gateway appliances regardless of their configuration. Cisco says there are no workarounds, so patching is the only fix. The bug lies in how Cisco's AsyncOS software handles incoming email. An attacker doesn't need to log in: they can send a booby-trapped message through a vulnerable gateway and, if the exploit works, run commands as root. Which is not exactly what you want from the box tasked with keeping nasty emails out. Cisco's Product Security Incident Response Team said it became aware of active exploitation in September, although the networking giant hasn't said who is behind the attacks, how long they have been going on, or how many organizations have been compromised. Cisco uncovered the bug while resolving a Technical Assistance Center support case. Signs suggest at least some Cisco cloud customers were caught up in the attacks. Cisco said it investigated devices belonging to its Secure Email Cloud service and directly contacted customers whose appliances showed indicators of possible compromise. It is now carrying out remediation and recovery work and says all of its Secure Email Cloud devices have been upgraded to AsyncOS 16.5.0-780. Admins running their own appliances have a little more work to do. Cisco recommends checking logs for signs of suspicious activity, but warns that finding nothing doesn't necessarily mean the system is clean. Once attackers have root access, Cisco says they could tamper with the logs and cover their tracks. Admins are also being told to check network and firewall logs for anything unusual, rather than relying on the gateway itself for answers. For virtual appliances suspected of being compromised, Cisco's recovery advice is fairly drastic: preserve the forensic evidence, deploy a fresh VM running fixed software, rebuild the configuration, and rotate credentials and cryptographic material. Cisco has fixed the bug in AsyncOS releases 15.5.5-014, 16.0.4-302 and 16.5.0-780, with customers strongly encouraged to move to the latter. There's still a decent-sized target pool out there. The Shadowserver Foundation was tracking more than 400 Cisco Secure Email Gateway appliances exposed to the internet as of Monday The flaw has also landed in CISA's Known Exploited Vulnerabilities catalog, with US federal civilian agencies ordered to remediate it by September 17. CVE-2026-76461 comes less than a year after attackers exploited another critical AsyncOS flaw, CVE-2025-20393, to break into Cisco Secure Email Gateway appliances and install persistence mechanisms. That bug eventually scored a perfect 10. For anyone still running an affected gateway, the message is fairly simple: the box designed to inspect hostile email can itself be pwned by one; attackers are already doing it, and there is no workaround to hide behind. ®
Kategorie: Viry a Červi

Firefox 156.0

AbcLinuxu [zprávičky] - 15 Září, 2026 - 17:46
Byl vydán Mozilla Firefox 156.0. Přehled novinek v poznámkách k vydání a poznámkách k vydání pro vývojáře. Vestavěný prohlížeč PDF se nyní spouští o 45 % rychleji. Řešeny jsou rovněž bezpečnostní chyby. Nový Firefox 156 bude brzy k dispozici také na Flathubu a Snapcraftu.
Kategorie: GNU/Linux & BSD

Poskládali jsme dělo pro eSporty. I v době drahých pamětí můžete z her vyždímat maximum

Živě.cz - 15 Září, 2026 - 17:45
Doba přeje výkonným procesorům Ryzen s 3D V-Cache, které nejsou citlivé na výkon aktuálně předražených pamětí RAM. I přes vysoké ceny se vyplatí pořídit si sestavu pro hraní kompetitivních her. Nechcete moc číst? Tady jsme celou sestavu naskládali do nákupního košíku na Alze. Na konci článku jsou ...
Kategorie: IT News

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

The Hacker News - 15 Září, 2026 - 17:23
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America. Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

BambooToken malware controls Windows and Linux systems via MQTT

Bleeping Computer - 15 Září, 2026 - 17:00
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. [...]
Kategorie: Hacking & Security

Who's governing your AI? A trust framework for enterprise agents and models

The Register - Anti-Virus - 15 Září, 2026 - 17:00
Experienced IT leaders know that shadow IT is a persistent problem, but rapidly evolving AI and the proliferation of agents mean the potential threat - and cost - is greater than ever. AI agents are non-deterministic, autonomous, and adaptable. They excel at solving tasks in creative ways, often to the surprise of their creators. We've seen agents write blogs that criticize project maintainers that refused their pull requests. Another one hacked a McKinsey chatbot to gain read/write access without asking for permission. And agents are getting smarter all the time. As an industry veteran, DigiCert's senior vice president of product Brian Trzupek sees an old pattern. "When the promise of the technology is so good, people are willing to throw security out the window, and they just want to get to that promise real fast." CISOs should be worried about allowing these agents into their infrastructure without strict controls, but it's happening anyway. IBM's 2026 Cost of a Data Breach report found that more organizations lacked governance to manage AI or detect shadow AI, at 68 percent compared to 63 percent last year. The number requiring IT approval to deploy AI had fallen to 38 percent from 45 percent. DigiCert is trying to solve this problem with its own approach to AI governance called AI Trust. The framework, outlined in this white paper, builds on what the company is good at: public key infrastructure, DNS, and attestation. The AI governance questions CISOs should ask AI Trust uses these tools to help organizations answer five AI governance questions: · What agents your employees are using · What regulated data is flowing to them · Whose credentials they hold · Whether a compromised agent can be stopped immediately · Whether an incident can be reconstructed with a tamper-evident trail Almost every enterprise fails at the first hurdle, warns Trzupek. Developers build agents or buy them from vendors and deploy them internally without asking. Users might also spawn agents from inside tools like Claude Desktop or OpenAI Codex that will then create sub-agents. "Those sub-agents don't assume the same rights and responsibilities and authorization as the parent agent," he says. "So they try to delegate tasks that can be wholly controlled." How to manage AI agent identity Most companies haven't developed the tools to keep track of all these different agent types yet. The first step is to identify them. This is where many organizations make their first mistake by bolting agents onto the human identity and access management (IAM) stack they already have. The idea is that if you give an agent a service account and a long-lived API key you can treat them like a super-fast employee. That's impractical. "IAM was built for a human sitting at a keyboard who can tap 'approve' on their phone," Trzupek says. "An agent can't do that. So you fall back to a static API key that never expires and has way more scope than it needs, and now you've undone everything zero trust was supposed to give you. It's the exact credential we've spent a decade telling people to get rid of." Industry bodies have started converging on a different answer. IDC now recommends treating agent identity as a workload identity problem rather than an extension of human IAM, aligning with the IETF's Workload Identity Management and Security Extensions (WIMSE) and NIST's Cybersecurity Framework version 2.0. They can then frame agents as governed workloads requiring runtime attestation and short-lived credentials . This idea also pushes teams toward the Service Profile Identity (SPIFFE) and its SPIFFE Registration Endpoint (SPIRE). This is an open workload identity standard already deployed inside many hyperscaler-hosted Kubernetes estates, and they're part of DigiCert's AI strategy. DNS is a governance tool for agentic AI Inventory and identity might get you visibility, but you still need somewhere to enforce policy. DigiCert has strong opinions about where, tied to its history managing DNS integrity. No matter whether an agent is resolving an API endpoint or connecting to an MCP server, it has to query DNS first. So why not make that a core verification point? DigiCert proposes a solution that looks a lot like the DMARC standard used for email. An organization would publish an agent policy record in DNS that declares several things: · Its authorized agent identities · The certificate authority that issued their credentials · The scopes they're allowed to act within A gateway can then query that record to verify whether an inbound agent is legit, and terminate the session if the check fails . And if an agent contacts an unauthorized domain mid-execution, DNS can block the query and the MCP gateway kills the session. IDC likes this idea but warns that scale is an issue. As the number of agents grows, DNS records might not keep up, and stale records might become a loophole. Overly permissive scope declarations are also still a potential problem. "The scale problem is real, but it's the same problem DNS has solved a hundred times before," Trzupek responds. "You automate the lifecycle, you tie the record to the certificate issuance, and when the cert expires the record goes with it." And operators writing wildcard scopes because they're in a hurry is a discipline problem, not an architecture problem, he adds. Inside DigiCert's AI Passport Agents built in-house live alongside third-party agents like Microsoft Copilot, Salesforce Agentforce and ServiceNow, and the control planes for the two categories are different. DigiCert's answer is a single SPIRE server anchored to a DigiCert CA for identity, with policy enforced centrally in an Open Policy Agent engine, and a unified kill switch that operates across both categories. The AI Agent Passport is the artifact that ties the identity to the authorization. It's a cryptographically protected record of approved systems and permitted operations. Each 'passport' also contains things like data sensitivity classifications and expiration state, along with an accountable human owner. Trzupek says the field that generates the most pushback in the design is policy itself, because customers typically have a complex web of policies already in GCP or AWS. "Trying to replace those or displace them is a fool's errand," he says. So the passport can hold pointers to those engines rather than replacing them. How to manage model integrity Governing agents is only half of the challenge. The models themselves are strategic assets, and they're subject to integrity and provenance controls too. That means encryption and cryptographic signing of model artifacts, Open Container Initiative-compliant packaging with tools like the Sigstore code signing initiative, and a cryptographically verifiable Model bill of materials describing weights, datasets and dependencies . It also means governing models at runtime, not just securing the supply chain. DigiCert's AI Trust framework advocates trusted hardware execution to help solve that problem. A model running inside a trusted execution environment on Intel TDX or AMD SEV-SNP stays encrypted in memory, isolated from the host OS. DigiCert operates a confidential computing attestation service that follows the IETF Remote ATtestation Procedures (RATS) architecture. The execution environment is the attester and DigiCert is the verifier. Downstream systems are the relying parties. This approach moves attestation from a neutral third party rather than the cloud operator running the workload, which serves regulated buyers. Hyperscalers shouldn't attest to their own integrity. Those regulated buyers face some heavy governance conversations. In healthcare, the question is whether the AI model cleared through an FDA 510(k) pathway is the exact algorithm running in clinical deployment. Cryptographic attestation lets these companies prove model integrity before every inference. That addresses the FDA's 2023 cybersecurity guidance on software integrity verification and SBOM enforcement. But while some regulated verticals have specific needs, AI governance is a cross-sector problem. Any organization storing customer data an agent can access or exfiltrate needs these controls. Why build in AI governance now This is agentic AI's moment, so companies are at a pivot point, and they've been here before. Many of them spent the last 25 years following a cybersecurity antipattern: move fast to grab an opportunity with a significant new technology development, and call in the security team later to clean up the loose ends. It hasn't gone well. With many organizations at the beginning of their agentic AI journey, they now have an opportunity to break that habit and do things right from the beginning using verifiable controls. As frontier model prices climb and AI crops up as a noticeable cost on enterprise budgets, this will become an increasingly visible choice, concludes Trzupek. Companies will hold people more accountable for their use of agentic technology. Wouldn't it be nice to have the controls in place and be ahead of the game for once? Sponsored by DigiCert
Kategorie: Viry a Červi

Hackers target WordPress sites via third-party WooCommerce plugin

Bleeping Computer - 15 Září, 2026 - 16:45
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]
Kategorie: Hacking & Security

Největší český dopravní systém, jak jste ho ještě neviděli. Vytvořili jsme animaci Prahy. Obsahuje téměř 5 milionů GPS bodů

Živě.cz - 15 Září, 2026 - 16:17
Co kdybychom na mapu vynesli polohu všech souprav metra, tramvají, autobusů, trolejbusů a regionálních vlaků v Praze a okolí a vytvořili časosběrné video celého jednoho dne? Minulý týden jsme to samé udělali s Brnem a jihomoravskou krajskou sítí IDS-JMK, pražský PID, který obhospodařuje i ...
Kategorie: IT News
Syndikovat obsah