Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system.
Hugging Face is an open-source AI and machine learning platform that provides access to over 45,000 models from leading AI providers and is used by more than 50,000 organizations.
The company is still investigating whether partner or customer data was affected and said it would contact any affected parties directly. Hugging Face said it has found no evidence of tampering with public-facing models, datasets, or Spaces to date, and that its software supply chain has been “verified clean.”
The intrusion began in Hugging Face’s data-processing pipeline, with the attackers using a malicious dataset to exploit two code-execution vulnerabilities and run code on a processing worker. This allowed them to steal cloud and cluster credentials and move laterally across several internal clusters.
“The campaign was run by an autonomous agent framework (appearing to be built on an agentic security-research harness – used LLM still not known) executing many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services,” Hugging Face said in an incident disclosure published Thursday. “This matches the ‘agentic attacker’ scenario the industry has been forecasting.”
In response to the breach, Hugging Face has closed the vulnerable code execution paths (a template injection in a dataset configuration and a remote code dataset loader), evicted the attacker, rebuilt the compromised nodes, and revoked and rotated all affected credentials.
It also deployed improved malicious activity detection systems, reported the incident to law enforcement, and is now working with external forensic experts to assess the breach’s impact.
“We do not know which model powered the attacker’s agents, whether a jailbroken hosted model or an unrestricted open-weight one; either way, the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried,” Hugging Face added.
“The practical lesson for defenders: have a capable model you can run on your own infrastructure vetted and ready before an incident, both to avoid guardrail lockout and to keep attacker data and credentials from leaving your environment.”
Hugging Face advised users to rotate access tokens and review recent account activity for signs of suspicious behavior and said it would continue sharing findings on defending against AI-driven attacks.
While this is the first security incident affecting the platform that has been linked to an AI agent, it’s not the first breach disclosed by Hugging Face in recent years.
The company also revoked some members’ authentication secrets and advised them to switch to fine-grained access tokens two years ago after hackers breached its Spaces platform.
Threat actors have also been abusing the platform in recent years to push malicious AI/ML models and infostealer malware, and to spread thousands of Android malware variants.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Longtime Slashdot reader schwit1 quotes an X post by Josh Walkos, author of the Substack We the Free: If you thought Flock was bad check out Falconet. Falconet from Israeli company Cognyte serves as a cell tower simulator that intercepts cell phone data from all devices within range. Police mount these systems in Tahoes so the vehicles can collect information while driving through areas without any direct interaction with targets. This mobile approach generates ongoing records of phone locations and communications for everyone nearby rather than only suspects, which creates comprehensive movement profiles and bypasses traditional warrant requirements under the Fourth Amendment.
Cognyte sells the technology directly to U.S. agencies, as shown by the Texas Department of Public Safety purchase of four Tahoes where over three point eight million dollars went to the interception equipment. Adoption spreads through routine vehicle procurement with little external review of how the collected data is stored or shared. Once active the systems permit warrantless collection of private cell phone data across entire communities during normal patrols, which enables potential misuse and leaves individuals with no effective way to discover or contest the surveillance.
Chris Fall has resigned as director of the U.S. Center for AI Standards and Innovation just three months after being appointed to lead the Commerce Department’s federal AI testing institute. Arvind Raman, who oversees the Commerce office responsible for the institute, will serve temporarily in the role. “The Commerce Department did not provide a reason for Fall’s departure,” reports Reuters. From the report: Fall’s exit marks the latest change in direction for Trump’s approach to AI. The president upon returning to office in 2025 said the federal government should take a hands-off approach to the tech sector. He has since taken a more active role in monitoring the technology, though his public statements and policies appear to change week by week.
The institute is responsible for working with leading AI labs such as Anthropic, Google’s DeepMind and OpenAI to test their unreleased models for vulnerabilities. The group is staffed by scientists and engineers, who are focused on calculating the “demonstrable risks” posed by advanced AI models, according to the institute’s website. They want to limit opportunities for U.S. adversaries to use AI to develop chemical or biological weapons, or corrupt the data used to train American AI models.
Assassin’s Creed Shadows only launched last year, and Switch 2 owners can already pick it up at almost half its original price.
That reduction comes from a limited time deal that cuts Assassin’s Creed Shadows on Switch 2 from its usual £49.99 down to £25.99, a 48% saving that brings one of the franchise’s best reviewed games within easy reach.
Assassin’s Creed Shadows for the Switch 2 is almost half price today, in a time limited deal
This critically acclaimed Assassin’s Creed Shadows on Switch 2 drops from £49.99 to £25.99, a 48% saving on one of this year’s best games.

Playing as Naoe puts the focus on stealth, using noise, light and shadow to slip past enemy patrols, while a new grappling hook opens up parkour routes across castle rooftops that were not available in earlier games in the series.
Naoe’s kit also includes a hidden blade for instant assassinations along with shuriken and smoke bombs to create useful distractions, giving stealth focused players several ways to clear a room without ever triggering an alarm.
Switching over to Yasuke flips that approach entirely, trading stealth for silent bow takedowns and heavy melee combos with a katana or naginata, so a single stronghold can be cleared through patience or brute force depending on your mood.


Switching between the two protagonists mid mission is encouraged rather than locked to separate story chapters, letting you scout a stronghold as Naoe before switching to Yasuke for a more direct assault once guards are alerted.
Both characters explore the same dynamic version of feudal Japan, where castle towns, ports and shrines shift with the weather and the seasons, giving the world a sense of change that keeps returning to the same location interesting.
And now with a glowing discount, you have the chance to explore feudal Japan in all its glory.
SQUIRREL_PLAYLIST_10148964
There is no shortage of examples of Major League Baseball attempting to wield overly broad trademarks its obtained to bully others, nor examples of MLB attempting to stretch its trademark rights much further than they go. MLB opposed a trademark for a Brooklyn burger joint on behalf of the Dodgers, a team that hadn’t played in Brooklyn for over five decades at that point. The league, at one point, tried to bully a local Little League for using the names of MLB teams, but not their logos, which is something that roughly every Little League team everywhere does. It attempted to trademark the names of three cities in which MLB teams play. And, my personal favorite and most appropriate for this post, the league opposed a finance company’s trademark application because it claimed two of its separate teams both owned the rights to the letter “W”.
The real lesson in all of this is that the League can’t be trusted with anything other than very narrow trademarks. Anything more broad than that causes them to act the fool. And perhaps this is a lesson the USPTO has actually learned, given that it recently denied MLB’s attempt to trademark the phrase “Play Ball”.
The United States Patent and Trademark Office denied MLB’s application to trademark “Play Ball” for clothing, the USPTO wrote in a final action filing on Friday.
“In this case, the applied-for mark is a commonplace term, message, or expression widely used by a variety of sources that merely conveys an ordinary, familiar, well-recognized concept or sentiment,” the USPTO wrote in its denial.
The USPTO also wrote phrases “that merely convey an informational message are not registerable.”
Those are things that MLB’s well-dressed lawyers absolutely know, of course. But they attempted to bank on a complacent trademark office to try to sneak one past the goalie anyway, to mix metaphors. And if the league had gotten the mark, you can be one hundred percent certain it would have gone on yet another bullying campaign targeting apparel makers, other sports leagues, and who knows who else.
In fact, the most surprising part of all of this is that it appears to have taken 4 years for the USPTO to reach this decision. Josh Gerben breaks it all down like this.
Gerben said the rejection and public domain nature of phrases could depend on the class. Other companies have trademarked “Play Ball,” including a food company for bubble gum, a minerals company for surfacing playgrounds and “The Play Ball” for the gala fundraiser for the Strong National Museum of Play in Rochester, New York.
“In this case they are saying that the phrase has become so ubiquitous and it has this underlying meaning,” Gerben said. “For a clothing brand, the government doesn’t think it’s unique enough to be registered.”
Somehow, some way, we have to get past this practice of looking at trademarks as some kind of retroactive profit center, where a business gobbles them up and then corners a market that was already in existence. That’s all that this sort of attempt to lock up language is. The term “play ball” can be associated with Major League Baseball, certainly. It can also be associated with other sporting activities, or business negotiations, or any other number of things. That’s because it has become a generic phrase, no longer an identifier of the source of a good or service.
Again, MLB’s lawyers knew all of this before applying for the mark. They just didn’t care.
Filed Under: baseball, play ball, play ball play ball play ball, trademark, uspto
Companies: mlb

A palm-sized drone flies through thick fog, artificial snow, and near-total darkness, dodging poles, transparent plastic sheets, and tree trunks without a single camera or laser. Its only guide is sound. Researchers at Worcester Polytechnic Institute built the system, called Saranga, by copying the way bats find their way in caves. The result is a lightweight, low-power approach that keeps working when vision-based sensors simply stop.
Cameras and LiDAR begin to fail as light becomes dispersed or just disappears. Radar, on the other hand, drains the batteries right when the machines need them. By contrast, ultrasound travels through smoke, dust, and snow in the same way as it does in clean air. Bats have been doing it forever, simply emitting short, high-frequency chirps and listening for faint return echoes that bounce off obstacles. The WPI team, led by Nitin Sanket of the Perception and Autonomous Robotics division, decided to give a flying robot the same superpower.
Sale
They began with a quadcopter that they custom manufactured, measuring 16 cm across and weighing 460 kilos. It has two very tiny TDK InvenSense ICU30201 ultrasound sensors at the front, each with a broad sonic horn. Another one points downward to help with altitude. All of this ultrasound sensing requires only 1.2 milliwatts, and it all operates on a Google Coral Mini computer with no additional beacons or GPS, so there is no extra power expenditure.

Propeller noise was the first major issue, as the spinning blades are basically spewing out some serious ultrasound noise that drowns out the weak echoes coming back from distant objects (we’re talking minus 4.9 decibels here, which is weak signal territory for the team), so they fixed it by physically taping a simple foam and plastic shield between the propellers and the sensors. This barrier shuts out the majority of the prop noise while allowing outward sound and returning echoes to pass through. With this piece of hardware fixed, the usable range increased from one meter to two meters.

Even after they sorted the prop noise with their shield, the returning echoes were still getting lost in the random noise, so they attempted utilizing classical filters to sort it all out, but it wouldn’t comply. They required something more sophisticated, so they trained a tiny neural network to sort through all the filth. They termed it Saranga (also a neural network), and it basically looks at a brief string of echo readings as if it were a little picture. It uses this to learn the forms of true reflection patterns, after which it can suppress random prop noise. Training employed a lot of synthetic data mixed in with some real propeller noise, so once they had it functioning, the model flowed over to the real world very easily, with no additional fine tuning required. Saranga is then “compiled” to function on the Edge TPU, and it only takes up approximately 0.5 gigabytes of memory and does an inference in around 15 milliseconds while using only a few millijoules of energy.

The cleaned-up echoes are then sent to a basic localization stage, and because the left and right sensors are at slightly different angles, they can determine the horizontal angle to an obstacle in the same way that bats do. The down-pointing sensor then provides the height. It’s all really easy; simply a quick list of surrounding obstacles, and then it’s up to the flight controller to say, “Hey, steer clear of all this while still traveling in that direction.”
[Source]
A new American Heart Association scientific statement concludes that up to about 400 milligrams a day, or roughly three to five cups of plain coffee, is safe for most adults and may be linked to lower risks of cardiovascular disease. The benefits appear to depend heavily on the source and preparation, with coffee and tea looking more favorable than energy drinks, and added sugar, cream, syrups, or sweeteners potentially canceling out the upside. ScienceAlert reports: “Caffeine consumed in coffee is a key part of daily life for millions of people,” says Gregory Marcus, cardiologist at the University of California, San Francisco, and Chair of the AHA volunteer writing group behind the statement. “In our review of the most recent research, for most adults, intake of up to 400 milligrams of caffeine per day, the equivalent of up to five cups of caffeinated coffee per day without added sugars or fillers, is safe and does not increase cardiovascular risk.”
The statement focused on caffeine’s relationship with cardiovascular risk factors, such as blood pressure and diabetes, as well as types of cardiovascular disease, including arrhythmias, coronary artery disease, stroke, and heart failure. The picture that emerges is complicated, but generally positive. […] All up, the new AHA statement concludes that there’s a growing body of evidence that caffeine isn’t harmful when taken in moderation, and that coffee specifically may be beneficial. The statement was published in the journal Circulation.
Hugging Face’s incident response team first turned to frontier AI models to analyze a breach of the company’s production infrastructure, and the models refused to help. Commercial safety guardrails built to stop attackers blocked every forensic query because they treated the IR team’s real exploit data the same way they would treat a live attack.
The attacker, an autonomous AI agent running the campaign end to end, moved laterally across the Hugging Face infrastructure for a weekend, undetected and unstopped.
Security leaders are quick to recognize the pattern and diagnose what went wrong. “I’ve seen versions of this during red-team exercises and internal security testing, but this is one of the first high-profile examples where it materially affected real incident response,” said Merritt Baer, senior adviser to Andesite, G2I, and AppOmni and former Deputy CISO at AWS.
None of this is unique to Hugging Face, Baer said. “Commercial frontier models optimize for preventing misuse. They generally have no cryptographic or organizational way to determine whether the person asking ‘analyze this malware’ is an incident responder or the malware author.”
On July 16, Hugging Face disclosed that an autonomous AI agent system had compromised its production infrastructure, gaining unauthorized access to a limited set of internal datasets and several service credentials. The company verified that its software supply chain was clean and found no evidence of tampering with public models, datasets, or Spaces.
Hugging Face is still assessing whether the intrusion touched any partner or customer data and says it will contact affected parties directly as required. But few enterprise threat models had accounted for the attacker Hugging Face faced. An autonomous agent ran the entire campaign from initial access through credential harvesting. No human guided it.
The entry point was a malicious dataset. When the data-processing pipeline ingested it, the dataset triggered code execution in two ways, through a remote-code loader and through a template-injection flaw in dataset configuration files. No admission gate screened the file before it reached a processing worker, the compute job assigned to each dataset. Initial access came through the data pipeline itself, a route that worked because most enterprise security teams treat the data feeding their pipelines as trusted input rather than an attack surface.
Worker isolation did not hold. From that first foothold, the agent broke out onto the node running the workload, then harvested cloud and cluster credentials scoped broadly enough to reach multiple internal clusters, all of it inside a single weekend. Hugging Face described the agent framework as executing thousands of individual actions through a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services. The disclosure adds that the framework appeared to be built on an agentic security-research harness, which would put tooling designed for red-team work behind a live intrusion.
Investigators reconstructed more than 17,000 recorded events using AI-driven analysis agents of their own.
First attempts at the log analysis ran on frontier models behind commercial APIs. Defenders’ steps included submitting real attack commands, exploit payloads, and command-and-control artifacts for classification, but safety guardrails blocked the requests outright.
Baer traced the block to the prompts themselves. “The same prompts that are most valuable during an active intrusion, shell commands, exploit chains, credential dumps, persistence mechanisms, lateral movement, are exactly the prompts most likely to trigger safety systems,” she told VentureBeat. “As AI becomes embedded in security operations, this becomes an operational resilience issue rather than merely a model policy issue.”
GLM 5.2, an open-weight model deployed on Hugging Face’s own infrastructure, took the job the commercial APIs refused. No attacker data left the company’s environment. “This experience points to a gap worth planning for,” the company wrote in its disclosure. Hugging Face does not know which model powered the agents. It could have been a jailbroken hosted model or an open-weight model running without restrictions. Either way, the disclosure continued, “the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried.” Hugging Face drew that line itself, writing that the experience is not an argument against safety measures on hosted models and that it is sharing the feedback with the providers concerned.
The industry, Baer argued, needs to move past treating AI safety as a content moderation problem. “Security operations require something different. Authenticated trust.” Instead of asking whether anyone should receive an answer, the question becomes whether an authenticated security team, operating under enterprise controls, should receive it. “The model shouldn’t only understand what is being asked. It should understand who is asking, why, and under what governance.”
“Organizations already build contingency plans for cloud outages, identity provider failures, or EDR failures,” Baer wrote. “AI assistants are becoming another dependency.”
Her advice on IR playbooks was blunt. “A mature incident response plan should assume that during a severe incident, commercial AI APIs may refuse requests, API rate limits may become unavailable, internet connectivity may be impaired, and data governance rules may prohibit uploading forensic evidence externally.” The lesson, she wrote in her emailed answers, “isn’t ‘don’t use commercial models.’ It’s ‘don’t make them a single point of failure.’”
Autonomous AI-driven attacks are not limited to AI platforms. CrowdStrike’s 2026 Global Threat Report documented AI-enabled adversary operations increasing by 89% year over year, with average breakout times falling to 29 minutes. Enterprises running AI workloads in production with agentic access to their pipelines face similar exposure.
Six control domains determined the blast radius and recovery speed at Hugging Face. Each one maps to a concrete action security leaders can take before the next autonomous-agent breach arrives.
|
Control Domain |
What Broke |
Monday Action |
|
Dataset admission controls |
Two code-execution paths were exploited. No admission gate validated the dataset before it reached a processing worker. The data pipeline became the initial access infrastructure. |
Require sandbox execution and static analysis of all datasets before they reach workers. Block remote-code loaders and template-injection paths by default. Audit for any path granting code execution to untrusted content. Report to the board as a supply-chain risk. |
|
Worker-to-node privilege boundaries |
Worker isolation failed to prevent escalation to the node. The agent gained cluster credentials because the workload-infrastructure boundary was never enforced at container runtime. |
Enforce hard privilege boundaries between workers and nodes. Deploy container runtime security to prevent workload escape. Audit whether workers can reach node-level APIs or credential stores. Include in the next penetration test scope. |
|
Credential exposure |
Cloud and cluster credentials harvested after node access. The scope was broad enough for lateral movement across multiple clusters over a weekend. |
Rotate credentials on a scheduled cadence and after any anomaly alert. Scope to the minimum cluster and service. Deploy monitoring that flags access from unexpected nodes at machine speed. Map blast radius for board reporting. |
|
Machine-speed detection |
Thousands of actions through short-lived sandboxes with self-migrating C2. AI-assisted anomaly detection surfaced the campaign after a weekend of lateral movement, per the disclosure. |
Calibrate detection for machine-speed patterns. Ensure high-severity alerts page responders in minutes, regardless of time. Audit SIEM rules for detecting thousands of short-lived executions within a single hour. |
|
Private AI forensic capacity |
Commercial APIs blocked forensic analysis. Guardrails screened query content, never analyst identity. Investigation ran on GLM 5.2 privately. |
Deploy a capable open-weight model on private infrastructure before an incident. Test against real forensic workflows. Ensure IR playbook includes fallback for when commercial APIs refuse. Document gap for cyber insurance. |
|
Autonomous-agent threat modeling |
The campaign matched the forecast agentic-attacker scenario, but no threat model had operationalized it. LLM powering the agent is still unknown. |
Add autonomous AI agents as a distinct adversary class with machine-speed decision cycles. Run tabletop at agent speed. Present results to the board as evidence that timelines need recalibration. Include in the cyber insurance application. |
“The question for directors is simple. What happens if one of our critical security tools becomes unavailable during the exact moment we need it most?” Baer framed that as operational resilience, not AI policy.
She would have boards take that framing straight to management and press for specifics. “Have we actually exercised that fallback during tabletop exercises? How quickly can we switch during an incident?” Procurement needs to change alongside governance, starting with the questions buyers ask. Security teams evaluating AI vendors should ask about their process for authenticated incident responders, whether enterprise customers receive different handling during verified incidents, and whether models can be deployed privately. “Those questions belong alongside uptime, privacy, and compliance,” Baer said.
“The biggest takeaway isn’t that safety guardrails are ‘bad.’ They’re doing what they were designed to do,” she argued.
Her larger point is that the threat model itself has changed. “For decades, defenders had better tools than attackers because they operated inside trusted enterprise environments. With foundation models, both sides increasingly use the same capabilities, but one side is constrained by enterprise governance, policy, compliance, and safety controls, while the adversary simply downloads an uncensored open-weight model and keeps going. That’s a new kind of asymmetry,” she added. “The organizations that handle it best won’t necessarily be the ones with the most powerful AI. They’ll be the ones that architect AI as a resilient security capability rather than a single cloud service.”
Hugging Face has contained the intrusion, rebuilt compromised nodes, rotated credentials, and reported the incident to law enforcement. The company recommends that all users rotate access tokens and review recent account activity. Mid-incident, Hugging Face found out whether its own AI tooling would be available, and the first answer was no. Security leaders running AI in production should find out in incident response planning instead, before an autonomous agent forces the test.
Fatal road accidents are tragically common on U.S. roadways. According to the National Vital Statistics System’s Mortality Data for 2024, 41,241 people were killed on U.S. roads that year alone. There’s one particular time of year that’s especially notorious for such traffic accidents among teenage drivers: The period between Memorial Day in late May and Labor Day in early September, the so-called 100 Deadliest Days of Summer.
According to the AAA, between the years of 2012 and 2021, traffic fatalities during this period reached “nearly half of the total number of those killed in teen-driver crashes for the entire rest of the year.” Armed with these sobering statistics, though, authorities can anticipate when such accidents tend to spike in frequency, and tailor campaigns and anti-speeding measures to try to help mitigate them. One major effort to do just that during this period is Operation Southern Slowdown, which returned for its ninth year and ran from July 13-18, 2026. It saw a group of five southern states (Alabama, Florida, Georgia, South Carolina, and Tennessee) embark on efforts to, as the Florida Department of Transportation put it, “reduc[e] speed-related crashes through a combination of increased enforcement and public education.” Speed limits vary a lot between U.S. states, but all must be obeyed.
The additional patrols during this campaign in 2025, Atlanta News First reported, resulted in “more than 13,000 speeding contacts in just one week” across Georgia. It was also just one part of a range of nationwide efforts to curb speeding during this deadly time of the year. Here are some more measures that different states are employing, as well as a closer look at why these 100 summer days are statistically so deadly in the first place.
A national campaign from the Federal Motor Carrier Safety Administration aims to increase public understanding of the dangers and encourage safer driving practices throughout the 100-day period. It’s called the 100 Days of Roadway Safety and focuses on providing digital resources, primarily blog posts, that underscore essential safe driving principles. Among them are reminders to be wary of unpredictable movements by children in school zones and that larger vehicles like trucks need to be given essential space at all times.
New York State’s Department of Health developed a Teen Driving Safety Toolkit to educate young drivers and their parents and guardians during this turbulent time of year. It highlights some particular risk factors, some resources that can be used by both the former and the latter for safety’s sake (such as the Parent/Teen Contract), and other ways these vital messages can be spread (morning high school announcements about driving safety being another).
Increased patrols, as we’ve seen, can have a big impact too. Tragically, though, it’s also vital to address the increased need for emergency responses during this time. In a Facebook post, Tennessee’s Fall Creek Falls State Park acknowledged that these 100 days can call for life-saving blood transfusions, sharing how they work and explaining the $25 eGift card incentives for doing so. Washington State, meanwhile, sees around one-third of its fatal traffic accidents during the three-month stretch beginning in June, which it calls the 90 Dangerous Days. In response, the Washington State Patrol shares the most common causes of accidents (speeding being key among them), some vital driving tips, including “always buckle up, adhere to posted speed limits, drive sober, and stay distraction-free.”
Road safety is paramount for drivers to bear in mind every journey they make. Nonetheless, as the National Road Safety Foundation points out, the summer is marked by an uptick in fatalities among teenage drivers. There are more vehicles on the road generally, for one thing, and during this period, younger drivers will typically have more free time to hit the road. Combine that with their lack of experience with safe driving habits and possibly with their vehicle itself, and it makes sense that this is a particularly dangerous time for them. After all, there are some common mistakes that even experienced drivers make on the road, and the risks are heightened with newer motorists.
During this time of year, there’s often more road maintenance and repair work taking place. All of these factors add up to busier roads that are more difficult and frustrating to navigate, which is also a very dangerous mix for those maintaining the roads and larger, less maneuverable vehicles like buses in particular.
A specific focus on safety measures during the 100 days of summer doesn’t mean that states across the country don’t prioritize these matters during the rest of the year, of course. Also in July 2026, Caltrans announced an enormous investment of approximately $2.5 billion, intended to “Strengthen transportation infrastructure and improve mobility across the state.” Including steps such as establishing more crossings and a sidewalk-widening program, it’s a strong signal that broader matters of road safety are vital across America year-round. Even so, the more attention that can be brought to the 100 days of summer, the safer motorists, pedestrians, and passengers may be.
Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out.
This known WSUS sync issue affects both client (Windows 10, version 1607 and later) and server (Windows Server 2012 and later) platforms.
On impacted WSUS servers, admins are not able to deploy the latest Windows updates via WSUS or Configuration Manager due to increased synchronization times or sync operation timeouts caused by a buildup of publishing metadata.
Microsoft rolled out a service-side mitigation on Saturday to address the issue for newly installed or rebuilt WSUS servers following heightened impact observed starting one week ago, on July 13.
“Synchronization times and sync operations on WSUS servers have been restored and are operating normally for new WSUS installations and rebuilds,” Microsoft said.
On Monday, Microsoft also shared a manual fix for customers who are still experiencing sync operation issues and timeouts to help admins return their WSUS servers to normal functionality.
“Organizations with existing WSUS server installations that are experiencing long sync times can benefit from manual steps in order to clean up unneeded metadata,” it noted in a Windows release health dashboard update. “This metadata is present in existing WSUS installations but can be safely removed.”
This requires them to back up each SUSDB database, run a cleanup query from SQL Management Studio against all SUSDB databases (including WSUS replicas), and update the MaxXMLPerRequest value to its default setting.
After the cleanup process, the first Windows Update scan may take longer than usual, but subsequent scans will return to normal timing.
“After the cleanup, reindex SUSDB, run the WSUS Server Cleanup Wizard, and then run IISReset or recycle the WsusPool application pool to clear cached catalog state,” Microsoft added. “The client-side DataStore.edb does not shrink automatically after the detectoids are removed. This is expected and does not affect scan performance.”
Microsoft has addressed similar WSUS issues that prevented admins from deploying the latest Windows updates in May 2025, July 2025, and August 2025.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
It’s official: We’re getting a pickle emoji next year. On Tuesday, July 14, the Unicode Consortium announced the nine new emoji you’ll see on your device in 2027. One new emoji is the pickle, and that means the eggplant’s reign as the go-to emoji for male anatomy could be coming to an end.
Here are the nine new emoji you will see on your device next year.
The Unicode Consortium originally proposed a squinty face emoji in 2025. However, the Unicode Emoji Standard & Research Working Group recommended changing that emoji to a cracking face in January.
Honestly, the cracking face emoji feels more relevant to today than the squinty face emoji. The squinty face read as suspicious while the cracking face emoji screams, “I’m putting on a brave face in these trying times.” If that’s not the most relatable sentiment these days, I don’t know what is.
While the Unicode Consortium approved these emoji, companies like Apple and Samsung still need to design and then implement their versions of the emoji. Those companies usually add the emoji to devices as part of a software update in the spring, so you likely won’t see these emoji on your phone until 2027.
Before these emoji land on your device, the Unicode Consortium will begin fielding proposals for the next round of new emoji. Anyone can submit an idea for a new emoji, and the Unicode Consortium usually uploads proposed new emoji to a public document late in the year. For example, the upcoming emoji were originally accepted in October, 2025.
For more on emoji, here’s how to decipher every emoji and the newest emoji on your iPhone and Android.
London Mayor Sadiq Khan handed a peerage by Keir Starmer alongside 15 other Labour figures… just days before the PM leaves No10
Weekend Open Thread – Corporette.com
The House | The City of London can help the new chancellor deliver growth in every postcode
Young campaigners urge incoming PM to act on outdoor junk food ads
CFTC blocks Kalshi from unwinding Michigan trades after court order
Two July Windows Left: The CLARITY Act’s Senate Fight and What Failure Means
Ripple Payments Joins MiCA With 14 Firms, Does It Mean Anything For XRP?
Nvidia Stock Slips After Big Tuesday Rally as Huang Confirms Vera Rubin Chip Is Now in Production Today
Democrats look to World Cup watch parties to register thousands of voters
Disney’s Most Ambitious Failed Star Wars Attraction Is Coming to SDCC
Ripple wins EU-wide access as ESMA adds it to MiCA register
Injective Submits SEC Transfer-Agent Registration to Onchain Ownership Records
Palantir Shares Rise After Expanded Nvidia Partnership and Fresh Analyst Upgrades Ahead of Earnings Day
Sail Virtually Aboard The “Itanic” With IA-64 Emulator
Turtle Beach Command Series KB7 review: a nifty screen-equipped gaming keyboard
Dark Secrets Emerge When Jailbreaking LLMs
XRP BOMBSHELL… XRP OMBOARDED FOR TRANSACTIONS!!!
Registration is now open for March for Men with Kev 2026
Unregistered fitter used Gas Safe logo on business flyers
Grayscale Files For Worldcoin ETF, WLD Registers Sharp Rise
You must be logged in to post a comment Login