Windows

Microsoft Patches a Record 570 Security Flaws (krebsonsecurity.com) 76

An anonymous reader quotes a report from Krebs on Security: Microsoft today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence. Nearly 60 of the bugs quashed in July's Patch Tuesday earned a "critical" severity rating, meaning miscreants or malware could use them to seize remote control over a Windows device with little or no help from the user. Microsoft also addressed three zero-day flaws, including two that are already being exploited in the wild.

Two of the zero-day weaknesses allow an attacker to elevate their user rights on a Windows system, as do approximately 250 other elevation of privilege flaws fixed this month; they include CVE-2026-56155 - an Active Directory Federation Services bug -- and CVE-2026-56164, a Microsoft Sharepoint vulnerability. CVE-2026-50661 is a security feature bypass in Windows BitLocker that could allow attackers to gain access to encrypted data if they have physical access to the device. Microsoft said this bug has been detailed publicly, but that it is not aware of any active exploitation.

In a blog post on July 9, Microsoft Executive Vice President Pavan Davuluri wrote that Windows users will notice "a higher volume of security updates included in each security release" as a result of AI aiding in the discovery of vulnerabilities. "The pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code, with new mechanisms that can accelerate both discovery and analysis," Davuluri wrote.

IBM

IBM Stock Collapses After a Grave Warning About AI (fastcompany.com) 62

IBM shares plunged after the company warned that Q2 revenue and earnings would miss expectations, blaming customers' sudden shift in spending toward AI hardware instead of software services. However, CEO Arvind Krishna did not place all the blame on IBM's customers. The CEO also said it "faltered" by failing to "anticipate the magnitude of the capex reprioritization."

"These conditions require our teams to execute perfectly, and this quarter we faltered. We did not adapt and move quickly enough, and numerous large deals failed to close on the timelines we expected, driving the majority of our shortfall." Fast Company reports: In the preliminary report, IBM said that for its second quarter of fiscal 2026, it expects revenue of $17.2 billion, which is up 1%. It also said it expects a Non-GAAP Diluted Earnings Per Share (EPS) of $2.93, up 5%. However, as noted by CNBC, these preliminary results are below what analysts were expecting, which was $17.86 billion in revenue, and an EPS of $3.01, according to FactSet data.
The Internet

Cloudflare Precursor Watches Your Mouse and Keyboard To Decide If You Are Human (nerds.xyz) 87

BrianFagioli writes: Cloudflare has launched Precursor, a new behavioral bot detection system that monitors mouse movement, typing cadence, scrolling, clipboard activity, page visibility, and other signals across an entire browsing session. The system is designed to catch advanced bots that can run JavaScript, use real browsers, and pass traditional CAPTCHA challenges. Cloudflare says Precursor does not record actual keystrokes and instead studies timing and rhythm. The company also says the data is not tied to user identities or persistent profiles. Even so, software that watches how people move and type throughout a visit raises privacy concerns, especially as Cloudflare claims bots now generate roughly 57 percent of all Internet requests.
AI

'Forget Coders. The Real AI Threat Is In the Back Office' (thestar.com.my) 78

Which jobs are most threatened by AI? "Programmers, software engineers and other tech industry employees," goes one common answer.

"But many economists are more concerned about a different, larger group of white-collar workers," reports the New York Times: customer service reps, bookkeepers, payroll clerks and HR specialists, "who fly under the radar but collectively account for tens of millions of jobs..." They are spread across the country and throughout the economy, working in every industry, in big cities and small towns, at major corporations and mom-and-pop businesses... These jobs typically offer a middle-class salary or a pathway to achieving one — much as manufacturing jobs did for men before decades of globalisation and automation wiped many of them away... For now, such an outcome is a fear, not a forecast. Despite high-profile layoffs in tech and finance, there is little firm evidence that AI has hurt the labour market as a whole.

Economists have become increasingly convinced that disruptions are likely, but they say it is too early to know where or how widespread they will be. They remain broadly sceptical of claims that the technology will lead to mass unemployment in the near future. Some AI industry leaders have walked back such predictions in recent weeks. But given the extraordinary pace at which companies are adopting AI — and at which the technology is improving — economists say policymakers need to consider the potential effects on the labour market. And they say they are concerned that the public debate has focused too much on software engineers and a relative handful of other high-status careers — lawyers, consultants, economists — rather than the workers who could be most vulnerable...

Economists at Northwestern University recently recalculated measures of AI exposure based on the makeup of the total workforce, not just the people using the technology. Administrative and front-line roles, such as customer service representatives, rose to the top of the list. "The most affected jobs are secretaries, are routine clerks," said Michelle Yin, one of the working paper's authors. "They're not computer scientists or data scientists at all."

The article also includes this counterpoint from an economist at the University of Illinois who has studied earlier waves of white-collar automation: that like other disruptive technologies, AI likely will also create new jobs. So the possibility exists AI will make workers more productive and allow them to earn more. "I would be cautious about just focusing on what are we losing as opposed to what are we going to gain on the other side."
Microsoft

Id Co-founders Carmack and Romero Respond to Microsoft's Layoffs (ign.com) 56

"I have been trying to find something meaningful to say about the Id Software layoffs," John Carmack posted Thursday to his 2.8 million followers on X.com: My "Microsoft will probably be a good steward of the brand" statement isn't aging well, and this is certainly going to dampen the mood of the founder reunion at QuakeCon next month.

I'm saddened, but I can't muster anger or outrage over it. I don't have access to the books, but I suspect that Id Software was a marginal business from Microsoft's perspective. I believe the reports that Minecraft revenues have been carrying several other studios.

To continue being produced long term, games need to succeed, not just be beloved. Games are competing with every other option for spending your leisure time and money, and the competition is brutal. You can't rule out the possibility that executives are idiots, but that shouldn't be your default belief. I don't think there is any obvious path that would have doubled the revenue from Id games.

Could they have gotten more with a different pricing strategy? Could they have created more things for fans to buy? Could they have cost effectively marketed in a way that reached more players that would have loved and bought the games? Could they have changed the game designs and broadened the appeal to more players without alienating existing ones? Could they have produced the games at a lower cost, faster or cheaper? I really don't know.

The game isn't over yet, and I hope the studio rallies through.

Id Software co-founder John Romero also shared his thoughts on X.com: I'm so sorry for everyone at id Software affected by these layoffs. I know what it feels like to leave id while id goes on. It's a strange and painful thing to step away from a place that holds so much of your work, friendships and history.

The people at id have done a great job moving that legacy forward. DOOM, Quake, and Wolfenstein are not easy names to carry on, especially in today's industry. The last few games showed real care, skill and respect for what those worlds mean to people.

Romero also expressed his hope for "digital preservation" of Id's ongoing history (including code and assets). "I'm thinking of everyone at id today, and everyone else affected by yesterday's layoffs. Romero Games was there a year ago. I know how devastating it is, and my heart's with all of you.

"Four Xbox studios are already out the door," noted IGN, but shared some thoughts about the future: Some have expressed concern that id Software would be unable to lead development on any new games in its current state, and that it might be relegated to support studio status. But in a new statement [posted to id Software's page on X.com] id Software said it was now at the staffing level it was back when it made the much-loved 2016 Doom reboot — and insisted it was still capable of making "great games."

"While our studio was impacted, those changes were spread across teams. We still have the crew we need to build the games and tech we're known for... We're going to keep building the great games and tech that have defined us for the past 35 years, and we're looking forward to seeing you at QuakeCon this August."

GNU is Not Unix

How the FSF Sysadmins are Blocking Botnets with reaction (fsf.org) 25

For nearly two years the Free Software Foundation has been fighting web crawlers (including many aggressively scraping training data for AI models). A botnet controlling about five million IPs hit one system for six months in 2025. Their systems administrator wrote this week that they view these as distributed denial-of-service attacks.

How are they fighting back? We noticed patterns in the scrapers that were abnormal, which gave us material for writing regular expressions. Searching for the regular expression then gave us a large lists of IP addresses. Looking up the origin of those IP addresses revealed that some of the crawlers were using botnets of residential IP addresses to scrape faster and avoid detection. We looked for what kinds of botnets might be generating the kind of traffic that we were seeing, and one that we suspected was called the "Vo1d" botnet, comprised of smart TVs running some sort of compromised app... We got confirmation that at least some of the botnet traffic hitting GNU Savannah was originating through the Vo1d/Popa botnet.

We placed our regular expressions in fail2ban, and found that we were hitting the maximum rules that could be added to UFW firewall rules on our systems which showed degradation around 65,000 rules... We learned about ipset and configured fail2ban to add IP addresses that it found to IP sets. Using ipset, we kept building larger IP sets and did not find instability with as large as five million rules...

We eventually found a promising project on Framasoft's forge Framagit called reaction written by ppom... After we ran into scaling issues with our initial implementation, we developed a much faster implementation where the reaction shutdown process would export the IP sets to disk and the reaction startup process would restore the IP sets. This allowed us to have nearly instantaneous restarts of the service to apply new rules. We published both of our configurations upstream to reaction's wiki so that everyone can benefit from it. reaction's getting started documentation now leads to the method that we proposed...

Many sysadmins know about fail2ban, but not enough people know about reaction. I am very grateful to ppom for the help they have provided and for the tremendous project they have released to the world with reaction. We have implemented other defenses as well, but reaction is doing the majority of the automated work keeping our sites online.

China

China's AI Companies May Be 'Distilling' America's AI Models (yahoo.com) 51

In March, Anthropic's Claude "quietly deployed software to spy on China-based customers," reports the Washington Post — apparently to unmask Chinese rivals "suspected of hijacking its technology to make their own AI tools smarter." Last week Anthropic removed the spyware "after a software developer revealed its existence and privacy advocates criticized Anthropic, saying it had surveilled its own users." Anthropic's tracking code was designed in part to catch Chinese firms "distilling" its AI models, a technique that involves pressing a large, expensive AI system to serve as a tutor to a smaller, cheaper one. Asking the larger system huge numbers of questions — hundreds of thousands or more — generates responses that can be used to upgrade the power of the smaller one on the cheap. Distillation isn't illegal, and it has been used for years in the AI industry. But distillation without permission is against AI companies' rules, and, used effectively, is giving Chinese AI companies a major leg up, American AI companies say... Anthropic and ChatGPT-maker OpenAI have both accused Chinese AI companies of using this technique to build copycat AI models of their own.

In a May blog post, Anthropic said that Chinese companies' use of distillation, along with evading U.S. export controls on high-end computer chips, has allowed them to "trail closely" behind U.S. models. But if these techniques can be blocked, it might be possible for the United States to "lock in a 12-24 month lead" on Chinese capabilities, the company said... This month, Anthropic said in a letter to U.S. senators that was obtained by The Post that it uncovered a campaign in which Chinese tech giant Alibaba's Qwen AI team used roughly 25,000 fraudulent accounts to generate more than 28.8 million exchanges with Claude to improve its own technology. In February, Anthropic made similar accusations against the Chinese firms Deepseek, Moonshot and MiniMax and said the campaigns were "growing in intensity and sophistication...." Anthropic and OpenAI have appealed to the U.S. government, arguing that distillation amounts to intellectual property theft that harms the U.S. in the geopolitical AI contest....

That Chinese AI labs are using U.S. models to improve their own technology appears beyond dispute. In a February 2025 study, researchers from China's Peking University and the state-funded Chinese Academy of Sciences developed methods to detect signs of distillation in leading large language models. They concluded that, with the exception of ByteDance's Doubao, most domestic models they tested showed substantial evidence of distillation, mostly drawing from U.S. models... In one set of intensive tests, a Qwen model misidentified itself as Claude nearly a third of the time, the Chinese researchers found.

U.S. firms have also used distillation to piggyback on AI systems made by others. In 2024, OpenAI released a tool to make it easier for customers to distill its own models and produce data sets for AI training. SpaceX founder Elon Musk said in court testimony in May that his AI company xAI used distillation to train its models and that the technique is common throughout the industry.

The article also notes that Anthropic "said it has banned nearly 700,000 accounts that were using Claude in China." But the article includes this quote from Kyle Chan, a fellow at the Washington-based Brookings Institution's China Center. "Anthropic's framing is that this is a geopolitical contest for basically the future of the world and freedom and democracy. It's that this is not just undercutting the U.S. commercially, but undercutting American strategic advantage in the most powerful technology we know today."
Software

SAP Makes It Easier For Customers To Shop For Legacy Product Support, Ending EU Antitrust Probe (theregister.com) 7

An anonymous reader quotes a report from The Register: The European Commission has ended an investigation into possible anticompetitive practices after SAP agreed to abolish reinstatement fees and reduce back-maintenance fees. The move could reduce barriers for customers considering third-party support for products nearing the end of their vendor support terms, including thousands of large businesses that rely on SAP ERP Central Component (ECC) to run their business operations. SAP's mainstream support for ECC ends in December 2027, while customers can opt for extended maintenance until December 2030 by paying an additional two percentage points on their maintenance fees. The most recent figures from Gartner showed that in Q4 2024 only 39 percent of worldwide ECC customers -- from a total of 35,000 -- had bought or subscribed to licenses to start their transition to SAP S/4HANA, the replacement ERP product.

In September last year, the European Commission launched a formal investigation into SAP's behavior in the aftermarket for maintenance and support services in Europe. It said it was responding to concerns that SAP restricted competition in this crucial aftermarket by making it harder for rivals to compete, leaving European customers with fewer choices and higher costs. In October, SAP published its response. "SAP's commitments aim at improving the financial attractiveness for customers who wish to reinstate SAP maintenance and support services. Thus, future costs associated with reinstatement will not financially prevent customers from choosing to terminate SAP maintenance and support for a given period of time," the document said (PDF).

SAP has now agreed to abolish reinstatement fees and reduce back maintenance fees charged to customers who return to SAP's support after a period of absence, the Commission confirmed. It also agreed to clarify conditions that allow customers to choose different maintenance and support service providers and different levels of support from SAP. The agreement is relevant to customers considering third-party support to extend their use of ECC beyond vendor maintenance. For example, last year, European retailer Kingfisher -- owner of well-known UK brands B&Q and Screwfix -- told a Gartner conference it had chosen Rimini Street to support ECC 6.0 because it saw insufficient value in migrating to SAP S/4HANA. [...] The commitments offered by SAP will remain in force globally for ten years.

Open Source

Google Hands Open Health Stack To the Linux Foundation (nerds.xyz) 7

BrianFagioli writes: The Linux Foundation intends to launch the Open Health Stack Software Foundation, a new vendor-neutral home for the Google Open Health Stack project. Google is contributing the project code and assets while Google.org is providing a $3 million grant. The initiative is also backed by Microsoft, Anthropic, and the World Health Organization, with the goal of building open source, AI-ready digital health infrastructure. Will moving the project under Linux Foundation governance accelerate adoption, or is this simply another foundation that most developers will never interact with? The new project will focus on core HL7 FHIR technologies for healthcare interoperability, the Open Health Stack Player deployment toolkit, and AI Commons -- a model-agnostic healthcare AI initiative being co-developed with the World Health Organization.

A notable part of the announcement is its planned Implementer Program, which aims to give startups, small businesses, and local developers in low- and middle-income countries a formal role in governance. In other words, the effort is not just about building healthcare software standards, but about making sure the people implementing them in underserved markets help shape the project too.
The Courts

John Deere Agrees To 10-Year Right-To-Repair Deal In FTC Antitrust Lawsuit (wired.com) 83

John Deere has agreed to a 10-year FTC-supervised right-to-repair settlement requiring it to provide farmers and independent repair shops with the same repair resources available to authorized dealers. The deal resolves antitrust claims from the FTC and five states alleging Deere monopolized equipment repair services, contributing to higher costs and delays for farmers. Wired reports: The full statement (PDF) lays out obligations for John Deere's repair services, requiring the company to give farmers and third-party repair shops access to the same equipment and repair resources it provides to official John Deere dealers. This includes software capabilities, such as reading and resetting codes and pairing with other software, which customers have long had limited access to, creating delays when diagnosing equipment problems. Delayed fixes can mean delayed harvests, which many farmers saw as a fundamental threat to their livelihoods.

Under the agreement, John Deere will be required to provide this level of access, equipment, and services for the next 10 years, monitored by the FTC. [...] John Deere has maintained that it already has robust repair resources for its customers, including service manuals and diagnostic equipment. In John Deere's press release, the company says the settlement is in line with what it has been doing all along, saying that "the agreement reinforces Deere's continued innovation toward more flexible repair options, emphasizing increased access and transparency for customers. It formalizes Deere's ongoing commitment to expanding access to diagnostic and repair tools."

The Internet

'Knockoff' Browser Extension Hides Sketchy Brands On Amazon (404media.co) 122

alternative_right shares a report from 404 Media: A software developer made a Chrome and Firefox extension called Knockoff that automatically hides, grays out, or filters products from sketchy brands on Amazon, which highlights just how many shady brands are on the platform and how commonly they show up on searches for basic items. In just a few minutes of using the extension, Knockoff dimmed product listings for screwdrivers made by "SUNHZMCKP," spoons made by "SACATR," and a lamp made by "ROTTOGOON."

In a tweet announcing the extension, developer Josh Pigford wrote "Sorry to brands like WNPETHOME, EHEYCIGA, YXYL, LU&MN, JOYIN, TOMY, GODONLIF, YOOJEE, LINGTENG, LANEIGE, VISCOO, BIODANCE, COOFANDY, BALENNZ, TOSY, and LUENX." The extension can also hide all sponsored product listings. The extension quickly went viral as a much-needed filter for people who still use Amazon and, for those who don't use Amazon because of its horrendous labor practices and other concerns, it is evidence of what an incredible wasteland the platform has become.

Businesses

Doom Developer id Software Is Reportedly Losing Half Its Staff (engadget.com) 65

Doom developer id Software is reportedly laying off about half its staff as part of Microsoft's broader Xbox cuts. The reported layoffs potentially affects around 90 employees. Engadget reports: While neither Microsoft nor id Software have formally acknowledged the layoffs, one former member of the studio's staff, Michael Maynard, has echoed the 50 percent figure on LinkedIn. According to at least one of Game Developer's sources, that could translate to around 90 job cuts, though it's so far unclear what departments at id Software have been hit hardest.

[...] Bloomberg reported yesterday that as part of the "reset" at Xbox, ZeniMax Media, the parent company of id Software, will be focusing on its biggest franchises -- like The Elder Scrolls, Fallout, Wolfenstein and Doom -- going forward. It's possible that motivated the cuts to id Software, but the developer at least outwardly appears to be already heavily focused on Doom. The studio launched Doom: The Dark Ages in 2025 and an expansion to the game on July 7, 2026. Whatever the reason, the cuts at Xbox aren't over: While Microsoft eliminated 1,600 roles alongside the announcement that Xbox is restructuring, it still plans to lay off another 1,600 employees over the coming months.

Privacy

Microsoft Can Track Users Via a Windows Device ID (pcmag.com) 55

A criminal complaint against alleged Scattered Spider member Peter Stokes revealed that Microsoft can associate Windows activity with a persistent "Global Device ID," which investigators used to link his PC to online activity connected to a hack. While unique device IDs are common, the case has raised privacy concerns because the identifier can apparently persist across updates, has no simple opt-out, and may allow Microsoft to connect a Windows installation to activity on third-party services. PCMag reports: Last week, the U.S. announced it had extradited 19-year-old Peter Stokes from Europe for allegedly being a member of the notorious hacking group Scattered Spider. But the case stands out because Microsoft played a key role in linking Stokes to the suspected hacking crimes, according to an unsealed criminal complaint. Stokes allegedly hacked an unnamed luxury jewelry retailer in May 2025 while using a VPN. The 39-page criminal complaint shows the FBI used Microsoft records to discover that his IP address was associated with a Microsoft device identifier known as Global Device ID (GDID).

"According to a Microsoft representative, a Global Device Identifier in the Windows ecosystem is a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device, either a physical device (e.g., a mobile phone or laptop) or virtual machine, across certain Microsoft services and scenarios," the complaint explains. The global device ID isn't exactly surprising, given that it's standard practice to assign a unique ID to each account or device so a tech provider can recognize and distinguish between them. But the complaint reveals Microsoft can associate the GDID with third-party services and the timing as well, giving Redmond a way to theoretically track a user's online activity. In other words, Redmond might be able to track the online activity of your Windows PC without third-party browser cookies.

Stokes was discovered exploiting a web development tool called ngrok to bypass the jewelry retailer's network defenses. The complaint says Microsoft had records showing that on May 12, 2025, at 19:21 UTC, the GDID associated with Stokes' computer "accessed, among other ngrok pages, 'https://dashboard[.]ngrok.com/signup,' the ngrok page to set up an ngrok account." The document adds that Microsoft records also showed the GDID accessing "multiple sites" from servers at Tzulo, a web hosting provider, to help pull off the hack. Hence, the fact that federal investigators used the Microsoft identifier to nab a suspected hacker is raising concerns that it could be abused for other surveillance purposes. "Microsoft Windows is surveillance software," cybersecurity expert Matthew Hickey alleged in a tweet.

The Courts

Supreme Court Allows Texas To Require Age Verification For Mobile Apps (cnn.com) 120

The Supreme Court allowed Texas to enforce a law requiring app stores to verify users' ages and obtain parental consent before minors can download apps. Tech industry groups argue the law broadly restricts young people's access to digital speech, but the court let a 5th Circuit order stand without explanation or noted dissents. CNN notes that the Supreme Court's decision "doesn't resolve the case but rather will allow Texas to enforce the law while the litigation continues to play out." From the report: "A minor child who downloads a software application from an app store agrees to contractual terms of service, including whether the child's location will be tracked, whether the child's privacy will be protected, whether information from the child's phone can be sold by the developer, and whether the child waives the right to sue," Texas told the Supreme Court in urging the court to allow its law to take effect.

But the Computer & Communications Industry Association, a trade group whose members include Apple and Google, said the law would effectively bar young people from accessing a wide range of content, "be it a book by Ernest Hemingway or J.K. Rowling, a Taylor Swift album, or a subscription to National Geographic." Allowing the law to take effect, the group said, would have "profound consequences for the protection of digital speech."

[...] In the new case, involving Texas' age verification for apps, a federal district court blocked the law's enforcement in December -- days before it was set to take effect. But a three-judge panel of the conservative 5th US Circuit Court of Appeals put that decision on hold in early June, allowing the state to enforce it. By declining to take up the emergency appeal from the computer and student groups, the Supreme Court has left the 5th Circuit's decision in place.

Unix

Zombie 'Who Owns Unix?' Lawsuit Comes Alive Again (theregister.com) 109

The long-running SCO/IBM Unix and Linux ownership dispute has resurfaced yet again, this time through SCO successor Xinuos, which is trying to pursue old license and copyright claims tied to Project Monterey. "The core issue seems to be whether Xinuos even has the right to litigate the matter, or if some ancient legalese in the original agreements means the window for legal argument has long since expired," reports The Register. From the report: [T]he roots of the case are the 1998 alliance between IBM and a company called the Santa Cruz Operation which sold a version of UNIX for x86 CPUs. Those two companies, plus Intel and Sequent, created "Project Monterey" -- an effort to create a unified version of UNIX that could run on multiple processors. By 2001, Project Monterey was close to delivering a unified UNIX, an achievement made possible by blending code from IBM and SCO.

By then, a little project called "Linux" already ran on multiple processors. Big Blue decided Linux was the future and bailed from Project Monterey -- then allegedly contributed some Monterey code to the open-source project and to its own AIX and Z operating systems. SCO felt it owned some of that code, so sued IBM.

SCO and its successors struggled to survive, but interested parties kept the lawsuit alive because the chance to emerge as owner of parts of the Linux codebase, and IBM's code, had the potential to turn into a colossal payday. The case and its successors ended in 2021, with a settlement that saw litigants agree to end the matter without IBM admitting fault. But by then, SCO had sold its software to a biz called Xinuos that decided to fight on.

The Xinuos case has burbled along quietly since, and on June 22nd reached the milestone of a hearing. The matter has become a little more modern, if only because this hearing was held online and the presiding judge appeared to unwittingly be on mute at one point. But the arguments otherwise seemed to revisit Project Monterey, debated the relevance of past litigation, contested who owned what, when they owned it, and how they could prove it. Xinuos argued IBM never had a license for SCO code. Big Blue argued that it did nothing wrong.

AI

Big Companies That Invest Heavily in AI Also Hire More People, Report Suggests (techcrunch.com) 29

"Companies spending heavily on AI are growing headcount faster, even in the entry-level roles that many fear are doomed," writes TechCrunch. That's the conclusion of new report tracking AI spending from Ramp's corporate card/bill pay data as well as Revelio Labs' workforce records from 21,599 U.S. firms: According to the report, "high-intensity adopters" — firms that spend on average $30 per employee per month on AI in the first three months — saw headcount increase 10.2%. Headcount also rose across functions, including engineering, sales, administration, customer service, finance, marketing, and scientist roles. The strongest job growth among high-intensity adopters was in the information sector, which includes software, internet, media, and tech-adjacent firms.

Despite these positive signals, the data isn't as rosy as it seems. It skews heavily toward tech-forward, knowledge-work firms — ones that might have VC-backing and are growing fast anyway, making it difficult to say whether AI is contributing to the hiring or just showing up at companies that are expanding anyway. "This paper does not show that AI universally creates jobs," the paper's authors admit, "but it does counter claims that AI will lead to broad job losses."

It also counters claims that AI is killing all junior jobs. Recent research from Goldman Sachs found that AI has already erased about 16,000 net jobs per month over the past year, with Gen Z and entry-level workers taking the brunt of the burden. But in tech-forward firms, the report finds that entry-level headcount actually rose by 12%... "For software and technology firms, AI can make core output cheaper or faster to produce: writing code, debugging, building internal tools, producing technical documentation, and supporting product development," the report reads. "Lower production costs in these workflows can raise the return to expanding the whole firm, not just the engineering team."

But companies that buy subscriptions and run pilots, yet did not go on to make sustained investments, don't tend to see any gains in headcount, per the report. That sets up the potential for a widening gap between firms that have the resources — like capital, technical staff, founder networks, and management bandwidth — to turn AI adoption into actual business gains and those that are stuck experimenting with subscriptions. In other words, this report suggests that firms that already have the resources are the ones that will see the largest gains.

CNBC argues another AI "narrative" was challenged this week: that open source can't make money. "The assumption was that giving your model away for free meant no business. That's breaking too, as open-model companies start posting real revenue and enterprises move from renting AI to running their own."
AI

Microsoft and Amazon Commit Billions to New AI Implementation Units for Businesses (cnbc.com) 17

Microsoft is investing $2.5 billion in a new group "assisting clients with AI implementations," reports CNBC: [Microsoft] said Thursday that 6,000 employees will be embedded with clients, in a practice that's become known as forward deployed engineering [or FDE]... The announcement comes two days after cloud rival Amazon said it was putting $1 billion behind an FDE initiative to support fast-paced AI engagements. Leading AI labs Anthropic and OpenAI both established FDE groups in May, partnering with private equity firms, banks and consulting firms.

Alongside its technology peers, Microsoft has sunk tens of billions of dollars into building data centers that run generative AI models. Microsoft has also released a variety of AI services, with mixed results. The Microsoft 365 Copilot AI assistant has yet to gain anything approaching ubiquity in the business world, and the GitHub Copilot coding agent has ceded market share to newer players. Microsoft's stock has slumped 21% this year, by far the worst performance among the mega-cap tech companies. One concern on Wall Street is that AI models that quickly compose code might threaten mature software companies...

Microsoft has for years provided support and implementation services to customers. The company generated about $2.1 billion in revenue from enterprise and partner services in the March quarter, up 2.5% from a year earlier.

Crime

Windows 11 Identifier Code Used to Arrest 19-Year-Old Over Alleged Ransomware Spree (tomshardware.com) 69

America's Justice Department and FBI teamed joined Finland's National Bureau of Investigation to arrest a teenager they say is part of one of the world's biggest cybercrime syndicates, reports Tom's Hardware. The "Scattered Spider" syndicate has extorted over $100 million in ransom payments, according to Department of Justice figures: 19-year-old Peter Stokes is a dual U.S.-Estonian citizen who was trying to board a flight to Japan from Helsinki, when law enforcement caught up with him. [T]he main criminal complaint against Stokes stems from a May 2025 attack on a luxury jewelry dealer based in the United States. The attackers apparently called the company's IT helpdesk using Google Voice, posing as employees. They were able to convince the help desk into resetting their credentials, which allowed them to infiltrate three accounts, two of which had admin privileges. From there, the group, allegedly including Stokes, stole important data and held the jeweler at ransom, demanding an $8 million payment in crypto. The company ultimately regained access to their infrastructure and avoided paying the ransom, but the operational disruption still caused a purported $2 million in losses. This served as the spark that led to Stokes' eventual arrest in Helsinki, as the prosecutors slowly followed the paper and digital trail laid by the attackers.

Microsoft played a key role in the process by providing GDID [Global Device Identifier] data to the FBI to help them apprehend the alleged criminal... [I]t's a unique identifier assigned to every Windows install that tracks device-specific telemetry. It's the reason why sometimes changing a major component in your PC can revoke your Windows license... [T]he court documents from the case reveal that Stokes used Windows, from which investigators were able to link his physical hardware to specific internet activity and locations... Stokes' web activity, videogame history, IP addresses, tool usage (including Ngrok), Azure status, and more were logged with timestamps, and were provided to the investigators by Microsoft...

Stokes was carrying two hard drives full of incriminating evidence with him when boarding his flight to Japan... His real identity has actually been known since 2024, but since he was a minor living across Estonia and the UAE at the time, he could only be monitored until the time was right.

The official criminal complaint even includes a selfie photo that Stokes posted on Snapchat (hiding his face behind dozens of hundred dollar bills). It then notes that behind Stokes the wallpaper, carpet, and furniture match New York's Empire Hotel — and that Stokes had visited the hotel's web site in Germany before then flying to New York...

"Following the arrest, Stokes was extradited to the U.S., where he appeared in front of a federal court in Chicago for the first time on June 30, 2026, and he remains in custody," adds Tom's Hardware.

"The accused is now awaiting trial, having been charged with conspiracy, cyber intrusion, and fraud..."
AI

Short Story Accused of Being AI-written Goes on to Win Contest's First Prize (theguardian.com) 55

"A story widely accused on social media of being written using AI has gone on to win the overall Commonwealth short story prize," reports the Guardian.

In mid-May the story had been selected as a regional winner, but with critics on X and Bluesky "claiming it showed 'obvious markers' of AI use." In the wake of the controversy, the Commonwealth Foundation conducted a review of the regional winners, which it said involved looking at drafts, time-stamped documents and notes. "We are satisfied with the testimonies of our writers and their confirmation that AI was not used in their writing," said foundation director-general Razmi Farook... Judging chair Louise Doughty described Nazir's piece as "an original, poetic and deeply moving story...." In a film released by the Commonwealth Foundation on Tuesday, Nazir... adds that he wrote six or seven drafts of his prize-winning story, and also speaks about his use of speech-to-text software, explaining that he could only see three or four lines of text on his phone screen at any one time, so he would perfect each line before moving on, which is how his story ended up being "highly polished"...

Initial social media reactions to the Commonwealth Foundation's announcement of Nazir's win were negative, with one X user writing: "immensely disappointing and disheartening. it feels like they wanted to stick to their guns after the entire GenAI uproar. I might think twice now before submitting my stories here". After Nazir was announced as the regional winner in May, some social media users reported running his story through AI-detection software. "Pangram flags at 100% but also, come on, if you know you know", said Wharton professor Ethan Mollick. However, the reliability of AI-detection software has been called into question.

In a statement to the Guardian, Farook said that "rather than surrender our judgment to AI-detection software, we asked our winners to show their working drafts, outlines, the evidence of an artistic journey. That software, it must be said, is not infallible: it returns inconsistent verdicts and, in doing so, corrodes the very trust on which a prize depends."

"When the machine's default voice is the metropolitan one, the writer who does not fit the expected mould is the first to fall under suspicion," she added. "The more startling her gift, the more her unfamiliar brilliance unsettles, the more readily she is accused of being a machine. A young writer in Kingston or Kolkata, in Kuala Lumpur or Kigali, must now prove not only her talent but her very humanity."

Nazir's story beat 7,806 other stories, the video points out (adding that their prize "demonstrates that in a world increasingly driven by algorithms, the human voice still matters.")

The Guardian notes that the winning story "includes multiple 'not x, but y' constructions and lists of three, which some consider to be signs of AI use," and that critics also drew attention to particular lines like "Sun on galvanise is a cruel instrument" and "Marsha lived two bends down."

In a new interview with the Times of India Nazir says "Now I'm frightened about publishing new work because the attacks haven't stopped." Q: Which passages attracted the most criticism, and why do you think they were misunderstood?

Nazir: People criticised a line where I wrote: 'She had the kind of walking that made benches become men.' That's magical realism. Think Salman Rushdie or Gabriel Garcia Marquez. It's a literary technique. In my story, the character 'Zoongie' believes she is so beautiful that even when no men are around, she imagines the benches becoming men who admire her. It exists only in her imagination. People interpreted it literally. There was another line about light reflecting from a sink. That came directly from my childhood. Our kitchen faced east, and my mother liked to keep everything spotless. We used to polish the sink, and when the morning sun hit it, it glittered brightly. People claimed that the image must have been AI-generated. But it's from my lived experience...

I've lived with diabetes for 62 years, which has damaged the nerves in my fingers and feet, and I'm currently undergoing chemotherapy. That's why I began using speech-to-text on my Android phone... I hope this episode leads to a better understanding of the difference between assistive technology and AI-generated writing...

Q: Many acclaimed writers like Ursula K Le Guin, Mary Shelley, and JRR Tolkien have also been falsely flagged by AI detectors. Where does this leave writers?

Nazir: What these AI detectors are saying is that if a piece of writing is too polished, it must have been written by AI. I refuse to accept that. AI was trained on human writing. Large language models, to me, are tools, much like a word processor. They don't replace the human spirit behind creative writing. Ask an AI to write a prize-winning story on its own and see what it produces. You still need human imagination and judgment to create literature.

Nazir added, "What I don't understand is why people continue to question the judges' decision."
Government

Are Wars Blurring Lines Between Corporate and National Security? (msn.com) 45

Subsea cables. Ukrainian power stations. Russian oil refineries. Even airports, water-desalination plants and Amazon data centers.

They've all become targets in wartime, notes the Wall Street Journal, and around the world now arguments "are already brewing between companies and governments over new regulations and potential costs." In Germany, powerful associations representing private companies and municipal utilities have pushed back against new standards for physical protection, warning they could spell financial ruin. New Zealand's government has faced resistance from industry groups over a proposal to fine critical-infrastructure companies and their directors for cybersecurity breaches... A sign of how lines are blurring: The North Atlantic Treaty Organization's 32 countries last year agreed that as part of a pact to spend 5% of economic output on defense and security, 1.5% would go to military-adjacent needs including protecting critical infrastructure and networks. Spending targets range from cybersecurity and industrial capacity to railroads, bridges and ports needed for military logistics... "We need a wide concept of defense — defense is no longer just military," said Italian Adm. Giuseppe Cavo Dragone, NATO's top military adviser.

Adding to the complexity, companies now need to protect the data networks that serve as gateways to critical infrastructure. Hackers increasingly target not just computer files to steal information but also systems managing vital functions like building access and factory control, remotely causing physical damage or enabling espionage. U.S. authorities in April warned that Iranian hackers were trying to disrupt American drinking-water systems by targeting computer equipment that connects hardware with software. A year earlier, suspected Russian hackers remotely manipulated valves on a Norwegian hydroelectric dam...

Another challenge will be parsing jurisdictions and liability for assets that cross international waters or are damaged in combat — such as subsea data cables or energy pipelines. Turf battles between law enforcement and militaries are already complicating efforts... "The private owner can invest in redundancy, monitoring, and repair capacity, but only governments and militaries can really deter, patrol, attribute, or respond to hostile state activity," said Marc Glasser, who worked on cybersecurity and infrastructure security for three decades at the U.S. Department of Transportation and the Department of Homeland Security.... Companies say they need greater clarity from governments on what protections they will provide and subsidies to help them defend privately owned assets that provide a public good. Most governments don't provide incentives for companies to invest more than the minimum legal resilience requirements.

The article notes that in May the chief executive of California's Port of Long Beach "launched a cyber-defense operations center to thwart tens of thousands of cyberattacks daily, which jeopardize computer systems and all equipment connected to them."

The article also points out that the EU adopted new regulations requiring countries to reduce vulnerabilities, and new laws proposed in the U.K. now "seek to increase penalties for subsea sabotage, updating codes that date to when telegraph cables were first laid in the 19th century."

Slashdot Top Deals