Agregátor RSS
Nejdražší součástkou iPhonu Duo je ohebný displej od Samsungu. Tvoří až třetinu výrobních nákladů
Why Patch Automation Needs Brakes, Not Just an Accelerator
Google’s Genome Atlas Predicts the Effect of Every Possible DNA Mutation
The atlas could help scientists decipher how genetic variation shapes health and disease.
Atlases have long guided us through uncharted territory. Now, an AI-generated atlas by Google DeepMind seeks to do the same for the vast landscape of our DNA.
Ever since the Human Genome Project, scientists have painstakingly traced the myriad DNA mutations that contribute to health and disease. But that quest has largely been stymied by the genome’s vast scale. Only two percent encodes the proteins that make our bodies work; the rest may control how genes are turned on or off or be junk left over from evolution.
With roughly nine billion possible DNA letter swaps, testing each one in the lab is impossible. Making sense of their interactions is an even tougher challenge. Yet these changes often contribute to differences in risk for cancer, dementia, and other medical scourges.
DeepMind’s new atlas could lend researchers a hand. Generated from the company’s AlphaGenome AI released last year, the searchable database predicts the effects of every possible DNA letter swap. Thousands of researchers have already experimented with AlphaGenome, but those studies required some coding prowess, raising the barrier to entry.
AlphaGenome Atlas may make the AI more accessible. Analysis of individual DNA changes, down to the level of specific tissues, is readily available through a web portal for non-commercial use. As the most comprehensive catalog of how genetic mutations might affect molecules in the body, it could help uncover the mutations underlying traits and illnesses. By charting the genome’s “dark matter”—regions that don’t encode proteins— it might also reveal hidden rules that direct gene activity. The details are described in a paper.
“This represents the first time that any researcher in the world can access a comprehensive map of the human genome and its variations by simply opening a browser,” said Pushmeet Kohli, DeepMind’s vice president of science, in a press briefing.
The Language of LifeWith just four DNA letters—A, T, C, and G—our genomic instructions seem simple. But the actual genetic playbook is far more complex. After piecing together the first draft of the human genome at the turn of the century, scientists were surprised by how little of it guided protein manufacturing. A staggering 98 percent didn’t seem to do much, earning the nickname junk DNA.
Long overlooked, these non-coding sections have increasingly captured attention for their role in regulating gene expression. Some DNA snippets can even operate thousands of letters away from the genes they control, making their involvement tough to decipher.
Non-coding DNA is also highly dynamic. Some genetic chunks can be duplicated or cut out as cells divide. Others jump to distant locations, reverse their sequences, or elbow their way into protein-coding genes.
Single-letter swaps are among the most prevalent DNA mutation. These can be relatively harmless. But they also can lead to diseases such as sickle cell anemia or raise a person’s “bad cholesterol” levels, increasing the risk of heart attacks. Gene-editing clinical trials are already underway to tackle these problems. But engineering a safe and effective treatment requires knowing which DNA swaps to make, and that’s been a roadblock.
Here’s where AlphaGenome comes in. Formally released early this year, the AI works in three steps. First, it spots short patterns in DNA sequence. Then it shares that information across a larger region of the DNA strand, letting it connect local patterns to distant letters. Finally, AlphaGenome translates those patterns into predictions of downstream biological effects.
The AI is customizable for different projects, allowing researchers to home in on DNA changes related to their specific questions. But it can only be accessed through an automated programing interface (API) which requires writing code and makes the data harder to access.
“AlphaGenome is helpful for analyzing specific variants and has found widespread use in research, but we wanted to show researchers a big-picture view of variants across the entire genome,” wrote the DeepMind team in a blog post.
Genome CartographerThe new atlas does away with much of the coding and analysis, allowing researchers to search for DNA variants across the genome to see their potential effects.
To build the database, the team computed predictions for all three possible swaps at every DNA letter—for example, changing A to T, C, or G—resulting in a whopping petabyte of data.
As with AlphaGenome itself, the atlas generates thousands of predictions about how DNA changes affect molecular processes in different tissues. These include what happens when a nearby gene is switched on or how changes in the shape of chromatin, the tightly folded form of DNA, alter its biological activity.
“Just as an atlas is a collection of maps, linking together features of the land like altitude and location, AlphaGenome Atlas charts the molecular effects of DNA variants across the genome,” wrote the team.
But interpreting the atlas takes more work. With billions of potential changes, which ones should researchers prioritize?
To help them navigate the most promising variants, the team also developed a single metric to measure their predicted effects. Called the AlphaGenome Variant Impact (AVI) score, it combines AlphaGenome with AlphaMissense, a model that predicts the effects of mutations in protein-coding regions. Together, these two tools help distinguish harmless mutations from those more likely to play a role in disease.
In collaboration with the Broad Institute, the score has already helped researchers find and prioritize a non-coding DNA variant that may contribute to severe epilepsy. Rare disease researchers, who often lack the funding and computing resources needed to run genomic AI models directly, could particularly benefit from the atlas.
“If somebody is studying a disease, and they don’t have any idea about what cell types to look for or what molecular processes are impacted, then starting with an AVI score…is a great starting point to help you prioritize variants and try to find that needle in the haystack,” said genomic lead and study author Žiga Avsec in a press conference.
Beyond tackling genetic diseases, the atlas could also help decode mysterious non-coding motifs, or snippets of DNA scattered across the genome. Some motifs control the production of messenger RNA, which carries genetic instructions to the cell’s protein-making factories. Others alter the activity of individual genes. But most remain poorly understood, if they have a function at all.
Linking these motifs to large health databases, such as the UK Biobank, could map the gene interactions and resulting proteins underlying height and other complex traits. The atlas could also help AI agents rapidly generate hypotheses for human collaborators to explore in the lab.
AlphaGenome Atlas isn’t meant to replace real-world experiments. And unlike AlphaFold, DeepMind’s protein structure-predicting AI that garnered a Nobel Prize, DeepMind needs to further boost its accuracy. But the atlas is shaping up to be a valuable guide for genomic explorers navigating the vast DNA landscape that makes us human.
The post Google’s Genome Atlas Predicts the Effect of Every Possible DNA Mutation appeared first on SingularityHub.
The Real AI Disruption Isn’t the Technology. It’s the Company.
Incumbents are racing to add AI to their organizations. The bigger challenge is competing with businesses designed around AI from day one.
For many established companies, the AI conversation starts with tools: Where can we deploy AI pilots? What processes can we automate? How much time or money can we save?
Meanwhile, a new generation of companies is starting with a different question: If we use AI from the ground up, how would we design this business?
Incumbents are largely using AI to improve organizations built for an earlier era. AI-native competitors can rethink the organization itself: its workflows, staffing, management layers, products, and cost structure.
An established company might use AI to make an existing process more efficient. An AI-native company can ask whether that process, or the organizational structure around it, needs to exist at all.
This raises a much harder question than how to adopt AI: How do you keep running the business that works today while simultaneously building the one that might replace it tomorrow?
The Threat Is StructuralFor more than two centuries, companies have been designed around assumptions inherited from the industrial age.
As organizations grow, they add specialization, management layers, processes, controls, budgets, and systems intended to make performance more predictable. Successful companies become very good at serving known customers, forecasting demand, improving efficiency, and scaling what already works.
AI does not suddenly make those capabilities obsolete. But it does make some of the assumptions behind them worth questioning.
A startup built today can assume from the beginning that significant amounts of knowledge work can be automated or augmented. It can organize teams differently. It can build workflows around collaboration between humans and AI. It can operate with less human intervention and, potentially, a very different cost structure.
The advantage is not simply that these companies can do the same work faster. It is that they have permission to question whether the work, roles, processes, and organizational structures should look the same in the first place.
Why Successful Companies Struggle to Reinvent ThemselvesThis problem predates artificial intelligence.
Most successful businesses are optimized for the markets they already understand. They know their customers, their margins, their products, and their operating models. They have learned how to make all of those things more efficient over time. Progress comes through experimentation, failure, feedback, and iteration.
That is the logic of sustaining innovation. Disruptive innovation behaves differently.
Singularity expert Jody Medich describes the resulting resistance as corporate antibodies: the internal forces that protect the existing business but can inadvertently attack the experiments intended to create its future.
A promising initiative may be asked to meet the same revenue expectations as an established product. A team trying to experiment rapidly may encounter budgeting, procurement, legal, or approval processes designed for predictable operations. A new idea may gradually be pulled back toward the core business until what was supposed to be disruptive becomes merely incremental.
None of this requires hostile executives or shortsighted employees. The organization is often doing exactly what it was designed to do.
Running the Business and Reinventing ItIf disruptive innovation behaves differently from the core business, companies may need to create different conditions for it to survive.
That can mean giving teams protected space to experiment without immediately subjecting them to the metrics of mature products. It can mean more flexible budgets, faster legal and operational support, and career paths that reward people who can work across disciplines and navigate uncertainty.
The point is not to isolate innovation permanently. It is to give new ideas enough distance from the core business to develop before the organization pulls them back toward familiar assumptions.
In some cases, the separation may need to go further. A subsidiary or other independent structure can give teams the freedom to experiment with different incentives, cost structures, workflows, and cultures. Instead of retrofitting AI into legacy systems, leaders can explore what an AI-native version of the business might actually look like.
That does not mean abandoning the advantages of being an incumbent. Large companies often have assets startups desperately want: capital, customers, distribution, data, brand recognition, and deep industry expertise.
The challenge is giving new ventures access to those strengths without forcing them to inherit every constraint of the existing organization.
The Workforce Has to Change TooOrganizational design is only part of the equation.
AI will change what many jobs require, eliminate some tasks, and create new ones. Companies that treat those shifts purely as a headcount exercise may miss an important source of competitive advantage.
Medich argues that established companies should invest in reskilling and internal mobility, helping employees learn to work with emerging tools and move into higher-value roles as parts of their existing work become automated.
Innovation teams also benefit from people who can move between specialties rather than staying inside conventional corporate silos.
Deep expertise still matters. But so does the ability to connect ideas across domains, translate between disciplines, and challenge assumptions that insiders have stopped noticing.
Becoming AI-Native Is Not a Technology ProjectEventually, the distinction between an “AI company” and an ordinary company will become meaningless. AI will simply become part of how organizations operate.
But getting there requires much more than adopting better software. Companies will have to reconsider how teams are organized, how experimentation is funded, how employees develop new skills, how success is measured, and which parts of the organization should be rebuilt rather than optimized.
Most importantly, leaders will need to become comfortable operating in two modes at once: improving the business they have while creating space for a fundamentally different business to emerge.
This article draws on insights from Singularity expert Jody Medich. The full report, How Companies Can Compete in an AI-Native World, explores the Medich model for disruptive innovation, common pitfalls in enterprise AI, and how organizations can build the structures, teams, and culture needed for continual reinvention.
The post The Real AI Disruption Isn’t the Technology. It’s the Company. appeared first on SingularityHub.
Baterie v elektromobilu vydrží deset let, možná i dvakrát tolik. V telefonu tři roky. Proč?
Attackers Chain Artifactory Vulnerabilities to Take Over Repositories
Samsung vám do telefonu předinstaluje 88 aplikací. Xiaomi jich má méně, ale po osobních datech prahne víc
September Patch Tuesday: 963 CVEs, 2 exploited flaws, 1 message
Microsoft’s September 2026 Patch Tuesday is the year’s largest release, with 963 CVEs requiring customer action, 106 rated critical. Two are already exploited: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Advanced Local Procedure Call. Nothing in this release was publicly disclosed ahead of the patch. Readiness recommends a Patch Now scheduling for Windows, Office, SQL Server and the developer tooling, and standard patch release for Exchange. The Readiness team has published an infographic summarising deployment risk by product family.
Known issuesThree client issues are carried in from August close with this update, covering:
- Microsoft Teams and the new Outlook failing to launch on ARM devices, such as the Surface Pro 11 and Surface Laptop 7, is resolved by KB5124008. The issue originated in August’s KB5121003 and was most likely on freshly imaged machines that had not yet taken Microsoft Store updates.
- The same update resolved both desktop backgrounds reverting to solid black and mouse cursor customisation resetting on non-English installations. Both originated in the 27 August preview, KB5120998.
And Microsoft has left open a Microsoft Defender Antivirus notification defect, confirmed on 28 August, in which devices report that Defender is turned off while it is running correctly.
Major revisions and mitigationsThe quietest revision window of recent months arrived alongside the largest release. Between the August and September Patch Tuesdays, from 12 August to 7 September, the MSRC Security Update Guide touched 324 CVEs. Of those, 307 were routine Microsoft Edge and Chromium republications requiring no customer action.
That leaves 17 entries affecting Microsoft’s own products, and only one of those is a genuine revision. CVE-2026-59133, an elevation of privilege in the High-Performance Computing Pack, moved to version 1.1, and its own revision note records the change as informational. For comparison, August’s window carried 76 revisions to Microsoft’s own products, 60 of them flagged as requiring customer action.
The Readiness team has reviewed all 963 published updates. Microsoft has published no mitigations and no workarounds anywhere in this release.
Windows lifecycle and enforcement updatesMicrosoft has published no new service or enforcement deadlines for September. The lifecycle picture is different, with multiple end-of-support notices for this coming October:
- The retail Office 2021 family retires in full, including Access, Excel, Outlook, PowerPoint, Project, Publisher, Visio and Word.
- Office LTSC 2021 reaches end of support, and that includes Skype for Business LTSC 2021.
- Windows 10 2016 LTSB and Windows 10 IoT Enterprise LTSB 2016 reach the end of extended support.
- Windows Server 2012 and 2012 R2 reach the end of Extended Security Update Year 3. This is the final ESU year for both, not a step to a fourth.
- Windows 11 Home and Pro version 24H2 reaches the end of updates.
- Windows Server 2022 moves from mainstream to extended support, where it stays until 14 October 2031.
A second wave follows on 10 November 2026, and it is the one most likely to catch development teams rather than infrastructure teams. .NET 8 reaches the end of its long-term support branch, PowerShell 7.4 does the same, and Windows 11 Enterprise and Education 23H2 ends servicing alongside Windows 11 IoT Enterprise 23H2.
Microsoft’s test guidance for this release runs to 466 Windows entries, 55 of them flagged as high risk, against 109 and four in August. Given the large number of updates this month (who would have thought that we would be here at 963 CVEs), the Readiness team recommends the following testing priorities:
- Printing. Print from 32-bit and 64-bit applications to physical and virtual printers, exercise XPS and PDF output, share a printer from a print server and print from a separate client, cancel a job mid-queue, and confirm the queue reflects every state change. This is 20 of the 55 high risk flags, and it is the single most likely source of a visible regression.
- Fonts, graphics and imaging. Render varied fonts, sizes and styles across browsers, Office, PDF viewers and Notepad, confirm Print Preview matches the printed page, and open JPEG, TIFF, HEIF and raw images across Explorer, Photos and Office. Watch for clipping, distortion and missing glyphs.
- USB Devices. Exercise device attachment and removal. Attach and remove USB audio, video and mass storage devices repeatedly, including through a hub, pair and unpair a wireless device, and confirm each enumerates and releases cleanly. Device Association carries seven high risk flags, and these drivers load whenever hardware is attached.
- Remote Desktop. Open several concurrent sessions, enable printer, clipboard, audio, drive and smart card redirection together, disconnect and reconnect, and confirm redirected devices reattach.
- Storage (ntfs.sys, spaceport.sys). This is a real hotspot for updates this month, but no high-risk changes. Test on hardware you can recover, because the storage changes reach the boot path, potentially resulting in a dead (test) machine.
Each month, we break down the update cycle into product families, as defined by Microsoft, with the following groupings.
BrowsersMicrosoft has not released any updates for their browser products for the second month in a row. September’s Security Update Guide carries no Edge-specific CVEs at all, and the 307 Chromium republications in the revision window required no customer action. The nine Edge CVEs that did appear arrived mid-cycle on 28 August and were serviced through the browser’s own update channel rather than this release.
Estates on a managed Edge channel have nothing to do here beyond confirming the channel is current. It is the one quiet corner of an otherwise heavy month.
Microsoft WindowsWindows carries 726 CVEs, 77 of them critical, which is three-quarters of the entire release. Elevation of privilege dominates by volume at 406 entries, with remote code execution second at 156, information disclosure at 94 and denial of service at 47. The pattern is the reverse of the severity picture: the bulk is local elevation, while the critical-rated entries cluster in the network-facing roles.
- Biometrics is a real focus this month as the Windows Biometric Service takes 64 fixes, the largest single-component count of the year. Most of the security issues are heap overflows that give a local attacker SYSTEM. Windows Hello adds nine, all critical. Patch it promptly on any estate using fingerprint or facial sign-in.
- Windows DHCP Server leads at 36 entries and is topped by remote code execution at CVSS 9.8. Windows DNS Server takes 10 more, also reaching 9.8. Critical remote code execution also lands on Message Queuing, RRAS, Services for NFS, the HTTP Print Provider, Windows Shell, Netlogon, Internet Connection Sharing, SSTP and Failover Cluster, all at 9.8. Patch the resolvers, the DHCP servers and the domain controllers first.
- Storage is the heaviest it has been this year. NTFS takes 29 fixes, Spaceport.sys behind Storage Spaces takes 17, and the Overlay Filter takes seven, with the Volume Manager, VHD miniport, iSCSI and Storage Port drivers behind them. These reach the boot path, so stage them on recoverable hardware.
- The rest of the most-patched tally runs Win32k at 19, Microsoft Standard XPS at 18, Windows Error Reporting at 12, and the Windows Kernel, Windows Search, the Print Spooler and the Device Association Service at 11 each.
Add this Windows update to your Patch Now schedule, with DHCP and DNS servers first and the biometric stack close behind.
Microsoft OfficeMicrosoft released 137 Office CVEs this month, 24 of them critical, with remote code execution the through-line at 69 entries and information disclosure close behind at 52. September breaks the recent pattern in a way that matters for deployment: this wave is not MSI-only.
- Click-to-Run estates are squarely in scope. Roughly 105 of the Office CVEs reach Click-to-Run, so Microsoft 365 Apps, Office 2019, LTSC 2021 and LTSC 2024 all update, on Windows and on Mac. Word takes 35 fixes, Excel 32, PowerPoint 10 and Outlook seven. The heaviest client entries are CVE-2026-78510 in Word and CVE-2026-78509 in Outlook, both critical remote code execution at CVSS 9.8, in document-rendering paths that fire on preview or open.
- SharePoint Server Subscription Edition takes 16 entries and is the only SharePoint baseline with a package this month. Server updates cannot be uninstalled and always require a reboot, so validate in a maintenance window.
- Skype for Business Server takes 10 entries, led by CVE-2026-66302, a critical remote code execution at CVSS 9.8. Patch it and note that the LTSC 2021 edition leaves support on 13 October 2026.
Nothing in Office is exploited this month. With 24 critical-rated entries and the Click-to-Run channel carrying most of the exposure, the September Office updates belong on the Patch Now schedule regardless.
Microsoft Exchange and SQL ServerExchange is quiet and SQL Server is not, which inverts the usual relationship between the two.
- Exchange Server takes nine CVEs across 2016 CU23, 2019 CU14 and CU15, and Subscription Edition. None is critical and none is exploited, though the highest reaches CVSS 9.3. The mix runs to two remote code execution entries, two elevations of privilege, two spoofing, and one each of tampering, denial of service and information disclosure. Apply the update from an elevated command prompt, because an un-elevated run leaves Exchange services partially patched and broken, then confirm mail flow, Autodiscover and any hybrid connection before returning the server to service.
- SQL Server takes 62 CVEs, four of them critical, across the 2017, 2019, 2022 and 2025 branches. There is no 2016 package this month. Remote code execution leads at 24 entries, with information disclosure at 22. The critical entries are CVE-2026-67631 and CVE-2026-67643 at CVSS 8.8, and CVE-2026-67378 and CVE-2026-67636 at 8.5.
- Eight SQL packages ship, a CU+GDR and an RTM+GDR for each branch: 2025 (KB5122769, KB5122770), 2022 (KB5122768, KB5122771), 2019 (KB5122772, KB5122773) and 2017 (KB5122774, KB5122775). Microsoft’s guidance is explicit that the baseline or RTM version must be installed first and the GDR patch applied on top; test the install and the removal on every servicing branch you run, then restart the service and confirm Always On availability groups stay healthy.
Exchange goes on the Schedule list, and SQL Server goes on the Patch Now list. That is an unusual split, and it is driven by the four critical remote code execution entries on the database estate.
Microsoft Developer ToolsMicrosoft released 24 CVEs across its developer tooling this month, 23 rated important and one critical. Security feature bypasses are the main focus with eight CVE entries, with remote code execution and information disclosure at four each.
- The single critical entry is CVE-2026-34182 at CVSS 9.1, a flaw in CMS AuthEnvelopedData processing that allows forged messages to be accepted. It reaches Visual Studio 2017 through 2022.
- The highest-scoring entry in this family is not the critical one. CVE-2026-81376, a Visual Studio Code security feature bypass, reaches CVSS 9.6 while carrying an important rating. It is a useful reminder that severity labels and CVSS scores answer different questions.
- Visual Studio Code and its Copilot extensions take 10 entries, mostly security feature bypasses. Update the editor and confirm workspace trust prompts, extension installation and remote sessions behave as configured.
- .NET ships SDK updates on all three supported lines, x64 and x86: 8.0.131 and 8.0.425, 9.0.121 and 9.0.318, and 10.0.112 and 10.0.401. Install them, then build and run a representative project to check for regressions. Keep the 10 November date for .NET 8 in view while you are in there.
- The .NET Framework ships monthly rollups per operating system: Windows Server 2012 (KB5126147), Server 2012 R2 (KB5126148), Windows 10 1809 (KB5126144), 21H2 (KB5126145), 22H2 (KB5126146) and Server 2022 (KB5126149). One gap worth noting: the 4.7.2 package for Windows 10 1607 is listed as pending and will follow, so estates still on 1607 will not complete their Framework patching this cycle.
Add these to your standard release schedule, behind this month’s Windows, Office and SQL Server priorities. Keep the 10 November date for .NET 8 and PowerShell 7.4 in view while you are in the developer estate, because a patch this month does not extend either branch.
Adobe (and third-party updates)September is the largest release of the year, and this (crazy, super high) volume is the least interesting thing about it. The 963 CVEs matter less than the 55 entries Microsoft flags as high risk, and those sit in printing and fonts. Adobe shipped two Acrobat builds one digit apart and only the second is a security update (nothing to worry about here). Of the CVEs Microsoft republished, 25 are not Microsoft’s. A version number tells you very little about the work in front of you. So, given my (super-secret knowledge) of how Microsoft operates over the summer, here is my prediction for next month (October). It won’t be as big as this month – but just you wait – November is going to be big. Let’s up those numbers (or not).
Jak naučit 14letého kluka programovat? Diskutujte o nejlepším postupu a prvním jazyku
Webinar: How malicious OAuth apps can lead to Google Workspace breaches
AI Changed the Exposure Problem. Validation Needs to Change With It.
Warcraft III ožívá po 20 letech. Rozšíření Forsaken Kingdom přidává novou kampaň, hrát můžete hned
Govern AI agents like workers. Just don’t pretend they’re human
The newest member of the corporate workforce never sleeps, never asks for a raise, and can be cloned before lunch. It can also confidently make the wrong decision thousands of times before anyone notices.
That helps explain why some technology leaders have started talking about AI agents as employees, co-workers, or interns rather than software. Once an agent can update records, issue refunds, send communications, or act across multiple enterprise systems, deploying it no longer looks much like installing another application.
Recent Harvard Business Review articles have pushed that analogy further. One argues that agents should be treated like a new workforce, with defined roles, authority, sources of truth, supervision, and audit trails. Another recommends giving agents names and job descriptions, onboarding them, evaluating their performance, and increasing their responsibilities after they prove themselves.
But there is a catch: People may start believing the metaphor.
A separate HBR study of 1,261 managers found that when AI was framed as an employee rather than a tool, managers with experience working around AI agents took less personal responsibility for results and assigned more responsibility to the AI. They also escalated more problems and caught fewer errors. In the study, 31% of respondents said their companies already framed AI as a teammate or employee, while 23% said agents appeared on organizational or work charts.
For IT leaders, the answer may therefore be to borrow freely from the employee-management playbook — without extending the metaphor too far.
Don’t put software on the org chartAmy Loomis, group vice president at IDC, draws a hard line around one word: responsibility.
Humans, she says, have obligations to their companies and to one another, and they bring an understanding of corporate culture and values that an agent can mimic linguistically without possessing.
That makes calling an agent a co-worker potentially more than harmless anthropomorphism. The label suggests a peer relationship and can encourage people to cede judgment to a system that’s very good at giving what was requested, Loomis says, but not necessarily at recognizing what was actually needed.
“Accountability is something that has qualities associated with it that are uniquely human,” she says. “Agents may be given permission to access data, but the accountability for what they do with that access lies with the person who gave the agent access, not the agent itself.”
That distinction still leaves plenty to borrow from employee management. It makes sense to give an agent traceable access and tightly scoped permissions — and to institute a kill switch to prevent the agent from having continued access. But Loomis finds it more effective to think in terms of giving an agent an operations charter rather than a human identity: define what the system does, what it may access, and what humans remain responsible for.
In other words, give the agent a security badge. Just don’t put its picture on it.
The employee metaphor has a job to doRaja Iqbal, founder of agentic AI governance company Ejento AI and co-author of the HBR article “To Scale AI Agents Successfully, Think of Them Like Team Members,” is closer to Loomis than the headline suggests.
Iqbal says the metaphor is intended to put CIOs, CISOs, and other technology leaders into the right “cognitive posture.” Thinking about an agent as a team member, he argues, can remind an enterprise to impose familiar management disciplines: a unique identity, clear human oversight, defined authority, spending limits, approved information sources, and an audit trail.
If another term produces the same discipline, he’s fine with that too.
In fact, Iqbal explicitly rejects synthetic employees with human personas and seats on the org chart. That creates exactly the accountability problem critics worry about: “Bob did it” becomes an excuse even though Bob is software.
“The metaphor is dangerous when it’s decorative,” Iqbal says. By that, he means companies get into trouble when they adopt the human trappings — names, personas, or the language of colleagues — without also imposing the supervision, limits, and accountability that make the analogy useful.
His preferred distinction is simpler: the agent needs a technical identity so the enterprise can reconstruct what it did, while a human must remain responsible for those actions. “The identity is the audit primitive, and the human owner is the accountability primitive,” he says. Put more plainly, the agent identity answers what acted; the human owner answers who is accountable.
The employee analogy becomes more useful again when deciding how much freedom an agent should receive. Iqbal recommends graduated autonomy. An agent might begin with a human approving every action, progress to performing low-risk actions independently, and eventually receive bounded autonomy if its observed performance justifies it. A serious error can send it back down the ladder — or out the door entirely.
That sounds a lot like a probation period for a new employee. It’s also simply good software governance for a probabilistic system.
At DXC, professional agents are softwareRussell Jukes has had plenty of opportunity to test that distinction. As chief digital and information officer at DXC Technology, he oversees AI in an IT services organization with roughly 115,000 employees.
“We think about [an AI agent] as a superpower, not as a person,” he says.
DXC separates agents into two categories. Personal agents work for individual employees and generally operate using the employee’s identity and access. Professional agents are enterprise systems built for broader workflows. On one of DXC’s major AI platforms, employees have so far created roughly 8,000 personal agents, compared with about 100 professional agents.
The professional variety receives much stricter oversight. It can have its own nonhuman identity, credentials, permissions, and authority boundaries. Activity passes through control planes that allow DXC to see what agents are doing and, when necessary, shut them down.
Jukes thinks many of these agents will eventually disappear from users’ view altogether. An agent might scan internal resource requirements overnight and recommend employees for projects. Nobody needs to greet it in the morning or consider it a colleague; they simply receive the result.
That’s where he parts company with the worker metaphor.
Jukes says he learned early on that AI cannot be deployed like conventional SaaS. His first attempt followed the familiar software model: make the application available, let employees use it within the prescribed workflow, and expect adoption to follow. “I did that, and nobody used it,” he says. The experience convinced him that AI requires a different approach, and he vowed to “never deploy AI like it’s SaaS again.”
Conventional SaaS is largely deterministic: the software constrains users to a defined workflow and produces predictable outputs. Agentic AI is different. It can interpret a goal, choose among tools and data sources, and decide how to get to an outcome. For Jukes, that means CIOs have to design the policies, permissions, data access, guardrails, and authority around the agent rather than simply deploy another application.
That also creates a clearer chain of responsibility. If a person approves the agent’s action, Jukes says that person owns the decision. If an autonomous agent behaves according to a business policy, accountability belongs with the people responsible for that policy. If the technology fails to operate as designed, responsibility moves to IT.
The agent itself never gets handed the blame.
Maybe treat it like an intern after allNina Tatsiy, global CIO of Quadient, an automation technology company, takes a position somewhere between Iqbal and Jukes. She calls agents interns, but deliberately uses the term as an analogy, not an organizational designation.
Agents must be managed as software, with security, governance, and technical controls, while recognizing that their probabilistic behavior requires additional supervision. “You have to do both,” Tatsiy says.
An intern does not receive every password and authorization on the first morning. Neither should an agent. It has to be onboarded, trained, watched, retrained when its environment changes, and eventually retired when it’s obsolete.
Quadient generally avoids giving agents human names. Tatsiy worries that doing so encourages people to see them as real colleagues capable of judgment.
“Overtrust is a problem,” she says, particularly because AI tends to state conclusions with such assurance. Tatsiy prefers using AI to challenge a hypothesis or surface questions people haven’t considered rather than allowing it to make the conclusion for them.
Yet the intern analogy has proved useful operationally.
In one accounts-payable deployment, Quadient had an agent effectively shadow human workers and learn from their feedback across different scenarios. Only after its performance had been tested across increasing levels of complexity did it begin providing recommendations. Humans still made the final decision.
The agent, in other words, earned more trust. It didn’t earn accountability.
Borrow from HR, but keep humans in chargeThe emerging divide may therefore be less about whether agents are employees or software than about which parts of each management model IT leaders should retain.
Agents need individual technical identities, but not human identities. They need defined responsibilities, but not jobs in the human sense. They need monitoring and evaluation, but not annual performance reviews. They can receive progressively greater authority, but not progressively greater accountability.
And the stronger they become, the more important that distinction becomes.
Treating an autonomous agent like ordinary SaaS ignores the fact that it can interpret, choose, and act in ways conventional software cannot. Treating it like Steve from Accounting creates a different problem: sooner or later somebody may start assuming “Steve” knows what he’s doing.
IT leaders may indeed need to borrow heavily from HR as agentic AI spreads across the enterprise. They just shouldn’t start issuing employee badges.
Related reading:General Robotics takes a new approach to building a robotic brain
When it comes to building robotic brains, many companies in the industry focus on putting intelligence directly into their robots.
General Robotics is taking an alternate approach. The Redmond, WA company’s GRID system hosts its robotics intelligence layer in the cloud, allowing it to be delivered and deployed to robots operating remotely.
GRID hosts the models, simulations, robot representations, data and agents through which robotic skills are developed, tested, orchestrated and deployed to robots on site. “Having one layer that looks after 50 to 100 robots is way more important than 50 or 100… robots that operate completely independently,” said General Robotics CEO Ashish Kapoor.
While videos of sprinting robots crashing into pads — or humanoid robots kickboxing and breakdancing – often go viral, General Robotics focuses instead on industrial models. Its GPU-based GRID cloud provides a better base to ingest data and develop skills for specific verticals.
“Our ability to onboard new robots, our ability to take them to deployment with new skills, our ability to connect very complex simulations to the reality is enabled through GRID,” Kapoor said.
The company declined to talk in detail about its customers, but Kapoor offered an example of how the GRID-based system works. In a biolab, for instance, robots pouring liquid from beakers required in their modeling fluid tactile interaction and transparent materials.
“There exists no good way of modeling those kinds of behaviors in software right now because [of]…all of those things,” Kapoor said. “…This is where agents came in.”
AI agents were used to create a “hybrid simulator” that brought the pieces together in the cloud. The robots were then tested against the simulated model.
“The physics of the robot was coming from one simulator and… the calculation of fluid dynamics was actually created by [the] agent itself by looking at the literature,” Kapoor said. What “otherwise would have taken us at least a year to build…was done in minutes.
“GRID allows you to auto engineer those robots, retarget those skills, [and] create appropriate digital representations on its own,” Kapoor said.
Humans are involved in safety checks to make sure robots behave according to specifications.
While humanoid robots are the ones often drawing media attention, “the most value in robots in 18 months to 36 months is going to be realized in heavy industries,” he said. “These are ports, these are your energy infrastructures.”
Although the company’s cloud-based GRID architecture has advantages, the system also faces some challenges — namely, lagging cloud-to-robot communication.
“The round-trip time, the latency is of paramount importance,” Kapoor said. “The robot needs to have two loops.” He described that second loop as an “inner control loop…operating at a millisecond level…that’s on the edge.”
Another issue involves companies that must meet strict regulatory and security requirements. For example, car companies are generally against putting proprietary information —whether that be designs for new fuel injection systems or new battery designs — in the cloud.
Still, General Robotics remains optimistic its system can handle these kinds of issues long term. “Between commercial cloud deployment, between on-prem server deployment and…edge deployment, we do have a way of addressing many of these issues,” Kapoor said.
In addition to continually improving its stack, the company also seeks out partners that can help it resolve challenges, Kapoor said.
That robotics is a growing field seems obvious. Morgan Stanley in a 2025 study predicted the humanoid robot population would touch 1 billion by 2050 and be valued at $5 trillion. And a more recent study from Counterpoint Research estimated that between 50,000 and 85,000 humanoid robots would ship this year alone.
V USA se nesmí prodávat v zahraničí vyrobené routery. Výjimku už dostali všichni velcí výrobci kromě TP-Linku
Microsoft’s Patch Tuesday updates: Keeping up with the latest fixes
Long before Taco Tuesday became part of the pop-culture vernacular, Tuesdays were synonymous with security — and for anyone in the tech world, they still are. Patch Tuesday, as you most likely know, refers to the day each month when Microsoft releases security updates and patches for its software products — everything from Windows to Office to SQL Server, developer tools to browsers.
The practice, which happens on the second Tuesday of the month, was initiated to streamline the patch distribution process and make it easier for users and IT system administrators to manage updates. Like tacos, Patch Tuesday is here to stay.
Patch Tuesday coverage has long been a staple of Computerworld’s commitment to provide critical information to the IT industry. That’s why we’ve gathered together this collection of recent patches, a rolling list we’ll keep updated each month.
In case you missed a recent Patch Tuesday announcement, here are the latest six months of updates.
September Patch Tuesday: 963 CVEs, 2 exploited flaws, 1 messageSeptember’s Patch Tuesday is Microsoft’s biggest of 2026, with 963 CVEs, two exploited flaws and a clear message: prioritize Windows, Office and SQL Server.
Two vulnerabilities are already exploited: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Advanced Local Procedure Call. Nothing in this release was publicly disclosed ahead of the patch. Readiness recommends a Patch Now scheduling for Windows, Office, SQL Server and the developer tooling, and standard patch release for Exchange.
Get more info on the September 2026 Microsoft security updates.
August’s Patch Tuesday is a monster: 751 fixes, with an exploited Windows flawMicrosoft’s August 2026 Patch Tuesday closes at 751 CVE entries (across all product families), with 108 rated as critical. One flaw is already exploited, CVE-2026-68820, an elevation of privilege in the Windows WinSock driver (afd.sys). Two more were disclosed but not exploited.
This security-only release earns Patch Now for Windows, Office and Exchange; no SQL Server updates this month. Unfortunately, several critical issues affect server roles: Windows DNS Server carries a cluster of critical RCEs; Windows DHCP Server is the most-populated Microsoft product family at 14 entries. Testing should lead with printing and fonts and the Remote Desktop client, then a WinSock smoke test given the exploited afd.sys flaw.
Get more info on the August 2026 Microsoft security updates.
July’s Patch Tuesday sees an end-of-support collision amidst a massive, record-setting patch waveMicrosoft addressed 722 CVEs this month once the 427 Chromium upstream relays are set aside — roughly three times a normal cycle and one of the largest single months in recent memory. Two vulnerabilities arrive under active exploitation: an elevation of privilege in Active Directory Federation Services (CVE-2026-56155), and an elevation of privilege in SharePoint Server (CVE-2026-56164). A third, a BitLocker security feature bypass (CVE-2026-50661) is publicly disclosed but not yet exploited.
The July 2026 Patch Tuesday earns Patch Now recommendations for Windows, Office, Exchange, and SQL Server. SharePoint has two critical RCEs on top of its exploited zero-day, and Exchange Server returns with a critical on-premises spoofing flaw. Adding to our (dear) administrator’s efforts, SharePoint Server 2016/2019 and SQL Server 2016 all reach end of support today.
More info is available here on Microsoft Security updates for July 2026.
For June, Patch Tuesday means an IT scrambleMicrosoft this month released 206 updates affecting Windows, Office, Exchange Server, and its developer tools — including three Windows vulnerabilities already publicly disclosed. That trio includes an elevation of privilege in the Collaborative Translation Framework (CVE-2026-45586), a denial of service in HTTP.sys (CVE-2026-49160), and a BitLocker security feature bypass (CVE-2026-50507). At the moment, none appear to be under active exploitation, but all three are rated “Exploitation More Likely.”
Even without an exploited zero-day, the June 2026 Patch Tuesday release requires Patch Now recommendations for Windows, Office, and Exchange. The latter is back in the patch picture with a consolidated security update that Microsoft recommends installing “as soon as possible.”
More info is available here on Microsoft Security updates for June 2026.
For May, Patch Tuesday means 139 updates — but no zero-daysMicrosoft this month released 139 updates affecting Windows, Office, .NET, and SQL Server (though there were no updates for Microsoft Exchange Server). Despite the absence of zero-days, the May Patch Tuesday update still requires Patch Now recommendations for Windows and Office.
The combination of three unauthenticated network RCEs (Netlogon, DNS Client, and SSO Plugin for Jira and Confluence), four Word Preview Pane RCEs, the large TCP/IP vulnerability cluster, and the carry-over BitLocker recovery condition (still active on Windows 10 and Windows Server) warrants an accelerated deployment release schedule.
More info is available here on Microsoft Security updates for May 2026.
Microsoft’s Patch Tuesday release for April is a whopperWindows admins are going to be busy this month, dealing with the largest Patch Tuesday cycle in memory. The April release involves 165 updates and roughly 340 unique CVEs from Microsoft — including two zero-days, one of which is already being actively exploited in the wild.
The Readiness team recommends “Patch Now” schedules for nearly every major product family: Windows, Office (with a zero-day), Microsoft Edge (Chromium), SQL Server, and Microsoft Developer Tools (.NET). April also brings Phase 2 of Microsoft’s Kerberos RC4 hardening with full enforcement set for July. There is a lot to cover, so here’s a useful infographic mapping the deployment risk for each platform.
More info is available here on Microsoft Security updates for April 2026.
Linux nativně na ESP32-S3 – bez emulace a rovnou s 9,7″ e-paperem
Microsoft: September updates cause RDS failures on Windows Server
UK.gov begins killing off passwords for 23 million users
Samsung si rýpl do Applu jako nikdy předtím. Hvězdou reklamy na Galaxy Z Fold8 je Tim Cook
- « první
- ‹ předchozí
- …
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
- …
- následující ›
- poslední »



