Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Few places on Earth are as deadly as a weapons test range. They’re usually some variation of sprawling rural salt flat, alpine tundra, or coastline where artillery batteries unleash barrages, jets practice bombing runs, and missile systems prove their accuracy. Once a combined-arms live-fire exercise begins, stopping it is no simple matter. Coordinating aircraft, artillery, armored vehicles, drones, and ground troops requires months of planning; when the rounds start flying, missions typically continue until objectives are met or ammunition is exhausted. Although everyone involved has the right to call “cease fire”, you’d better have a very good reason when the Range Safety Officer storms over to ask why you shut down their range.
Surprisingly, some of these cease fires can have nothing to do with equipment failure or medical emergency, as it’s universally justifiable to do so simply due to seeing an animal. In fact, it’s become increasingly common for a wildlife incursion to be the cited as a range-halting event. At New Mexico’s White Sands Missile Range, one of the world’s largest military testing facilities, the simple presence of the endangered Northern Aplomado Falcon can halt shoots or force exercises to be replanned entirely. Alternatively, if the threatened desert bighorn sheep happens to roam within a set of live range limits, it’s shouts of “unload” and “show clear” all around.
Interestingly, rather than viewing these species as obstacles or obstructions, the U.S. military has taken ownership of their welfare and incorporated their protection into range management. Breeding seasons, migration patterns, and habitat requirements are built into training schedules through temporary pauses, seasonal restrictions, and carefully planned exercises. The result is an unexpected partnership between conservation and national defense: In some of the world’s most heavily militarized landscapes, endangered wildlife have found an unexpected sanctuary.
Protecting endangered species on military land isn’t just a matter of serendipity. Every U.S. military installation complies with environmental legislation, including the Endangered Species Act, and many operate under Integrated Natural Resources Management Plans. These efforts are developed jointly by military environmental offices, the U.S. Fish and Wildlife Service, and state wildlife agencies, balancing military requirements with conservation.
Some efforts are remarkably straightforward. Range orders may designate seasonal exclusion zones, prohibit live-fire exercises during breeding seasons, or require environmental surveys before training begins. If sensitive species are detected in a training area, commanders may delay exercises, relocate activities, or temporarily close sections of a range. These measures often require little more than careful scheduling, but they make an enormous difference for vulnerable wildlife.
Other initiatives involve far closer collaboration. Many large military training areas now employ biologists to routinely monitor endangered plants and animal populations. This provides exercise planners with up-to-date information that allows military activities to proceed without harming critical habitats or active breeding grounds.
The result is an unusual but effective model of stewardship where wildlife benefit from habitats that remain protected from urban expansion, agriculture, mining, and many of the pressures that have driven species decline elsewhere. Today, Department of Defense-owned land supports more federally listed threatened and endangered species than any other federal land management agency, including America’s own national parks — though the latter remain substantially easier to visit thanks to the plethora of mobile apps associated with them..
The results of these conservation efforts have been striking. The U.S. Department of Defense manages around 25 million acres of land, much of it remaining in a wildlife-permissive state. Although explosions, aircraft noise, and armored vehicles may seem incompatible with fragile ecosystems, many species have proven remarkably resilient when military activity is kept to a distant annoyance.
The San Clemente Bell Sparrow on California’s San Clemente Island Training Range, the Louisiana Pine Snake at Fort Johnson, and the Red-cockaded Woodpecker, found across Fort Liberty, Camp Lejeune, and Eglin Air Force Base, have all maintained or recovered populations on military lands that now function as de facto wildlife refuges.
The U.S. military joins other government agencies in this conservation model, as NASA uses satellite imagery to protect animal populations as well. Additionally, other militaries likewise take part; the British Army’s Salisbury Plain Training Area protects one of Europe’s largest remaining expanses of ecologically important chalk grassland. In New Zealand, the Royal New Zealand Air Force routinely pauses activity at Kaipara Bombing Range to support the breeding of the vulnerable Fairy Tern. Even the heavily fortified Korean Demilitarized Zone has become one of Asia’s richest wildlife corridors.
It is a remarkable irony that landscapes designed to prepare for war have become some of the safest places for wildlife. Military training ranges will never lose their primary purpose: They exist to develop combat capabilities and ensure armed forces remain competent and credible. But the same restrictions that exclude humans have also limited human development, allowing biodiversity to flourish beyond the firing line.
Apple is expanding its presence in Sunnyvale once again by leasing a 125,800-square-foot building. If history repeats itself, Apple will buy it within a year.
Companies with a massive workforce are always on the lookout for more office space. In the case of Apple, it will be adding one more location to its roster in Sunnyvale.
According to sources of the Mercury News, Apple has agreed to lease a building located at 580 North Mary Avenue in Sunnyvale. The property, which weighs in at 125,800 square foot of office space, is being leased from the Bay Area real estate firm Peery Arrillaga.
The terms of the lease have not been leaked yet, but it will certainly cost Apple millions per year to occupy.
While the property is being leased for the moment, Apple has the potential to buy it at a later time. This has become a habit of the company, choosing to lease before acquiring it fully.
Apple’s June purchase of office space in June demonstrates this perfectly.
After leasing the office building at 684 W. Maude Avenue in Peery Park, Sunnyvale in 2025, Apple waited until later in the year to close the deal to purchase it. That 194,624 square foot property cost Apple $162.2 million, which was a considerable discount from its $222 million sale price in 2022.
Its Silicon Valley real estate moves in the area has also included a 2025 acquisition of a two-building campus in North Mathilda for $350 million. That was closely followed by another four-building Mathilda campus just next door for $365 million.
The same year, Apple paid $160 million for a 220,700-square-foot building in the Tantau office complex, close to Apple Park.

Kodak just handed film beginners a camera they can actually stick in a jeans pocket without second thoughts. This little plastic box called the EC35 costs thirty-five dollars and works with any standard roll of 35mm film. Reto Project builds it under the Kodak name, and the whole point is simple: give people who have never touched film something that feels as easy as the disposable cameras they grew up seeing at drugstores, only this one lasts longer than a single roll.
A sliding cover lies on top of the lens and viewfinder, ready to be pushed open to prepare the camera for action. Sliding it shut closes the shutter, allowing you to put the camera in a bag or pocket without fear of scratching the glass or accidently taking a frame. This haptic little detail is evocative of the good old Olympus Stylus days, and it’s ideal for flinging this little number around without fear of harm. The body is a compact device that measures about four and a half inches across and weighs only 3.5 ounces. It comes in seven various colors: midnight black, vanilla white, butter yellow, lavender, powder blue, blush pink, and avocado green.
The camera itself is about as simple as it gets; there’s no fumbling around with settings for new users, as the lens is fixed at 25mm and f/10 with no ability to modify it, and the shutter fires at a constant 1/100 of second. There is an automated flash tucked down near to the lens, powered by a single AA battery, that turns on when the light goes out. A simple manual film advance and rewind, similar to the old reliable point and shoots, allows you to insert a 24 or 36 frame roll of film (which must be manually wound by the way) and shoot your way through it with a little of twiddling on a convenient small window above the lens and pushing a button.


If you want to get started with the camera, a starter kit that includes a neck strap and a roll of Kodak Ultramax 400 film costs $45 dollars. Alternatively, you can buy the camera body separately for $35. In any case, the pricing is a deal, significantly lower than any of the other film cameras on the market today with all the bells and whistles. There is no complex zone focusing, double exposure lever, or aperture dial, since the camera simply compels you to work with what the fixed lens and shutter provide, much like in the disposable days.

Because the body is reusable, the only ongoing cost is having extra film developed, which is much less expensive than purchasing a new plastic camera every time you wish to take a few dozen photos. You can acquire one of these small devices right now from the Kodak store, although early shipments of the more vibrant hues have already sold out. For $35 and a single AA battery, it’s a wholly unique alternative to a cameraphone.
Moonshot AI has temporarily paused new subscriptions for its Kimi K3 model after demand surged beyond the company’s current capacity within days of the launch. The open-source Chinese AI model, described as one of the largest of its kind at 2.8 trillion parameters, has rattled U.S. rivals by beating Anthropic’s Fable 5 and OpenAI’s GPT-5.6 Sol in front-end coding tests. The Associated Press reports: “Kimi K3 has received far more love than we expected,” Moonshot AI, which is Beijing-based, wrote in a X post late on Sunday. “Over the past 48 hours, demand has pushed close to the limits of our current capacity.” Moonshot said that it’s prioritizing existing subscribers and would be temporarily pausing new ones. “We’re adding capacity as fast as we can and will reopen new subscription spots in batches,” it added. The AI startup also posted a similar message on Chinese social media.
“New model releases generally trigger massive interest, which can strain existing compute infrastructure,” said Lian Jye Su, a chief analyst at the technology research and advisory group Omdia. “This does show Moonshot AI does not have sufficient compute chips to serve the current surge in demand.” Su said that the key reason was more likely due to Moonshot not fully anticipating the surge in K3’s popularity. K3 is “very demanding” in terms of compute requirements, he said, making compute allocation challenging and expensive.
Record law enforcement officers whenever you can. Sure, they’ll hate it, but it helps all the people they seek to do harm to.
Last summer, recordings and other evidence undercut a lot of the administration’s attempts to convert First Amendment activity into criminal charges. Prosecutors who dropped cases after watching recordings or talking directly to the government’s witnesses noted a plethora of “untruthful statements” or “material misrepresentations.”
Six months later, the losing streak created by unforced (but deliberate) “errors” continued. Federal immigration officers just couldn’t stop lying, forcing DOJ prosecutors to voluntarily dismiss a bunch of felony assault cases that were completely reliant on statements made by officers who were later shown to be lying.
Here’s another case that’s hit a dead end because an ICE officer lied and an ICE supervisor decided to pass on these lies to a federal prosecutor. (h/t Aaron Reichlin-Melnick)
A Venezuelan man arrested by ICE was hit with a slew of escalating charges, most of which have vanished now that the truth is involved.
Gabriel Hurtado-Cariaco, 31, was referred to by DHS as a “criminal illegal alien” and a “known Tren de Aragua terrorist.” The agency said he “violently attacked an ICE agent” by slamming her head into the ground and attempting to choke her to death. At a preliminary hearing, a Homeland Security agent and a federal prosecutor said Hurtado-Cariaco received “special forces-type training” in the Venezuelan military and may have been involved in “killing people, hurting people, [and] committing human rights violations.”
The only thing true here is that Hurtado was once a member of the Venezuela military. But he deserted, fled to the US, and filed an asylum claim. He was paroled into the US in 2024 and, since then, had been steadily working as a delivery driver.
The arrest of Hurtado didn’t look great. Two ICE officers tried (and failed) to subdue him. He managed to escape custody, but was arrested successfully shortly after he fled the scene of the first attempted detention.
Perhaps the (attempted) arresting officer was too embarrassed to tell the truth. But the lies he told had serious consequences.
The initial narrative of what happened during Hurtado-Cariaco’s arrest was provided by Immigration and Customs Enforcement agent Craig Allrich. Allrich, who was not at the scene of the arrest, penned the affidavit that would be used to secure a criminal complaint against Hurtado-Cariaco.
The first complaint actually told the truth. It simply said that Hurtado had resisted arrest. But that apparently wasn’t good enough for Allrich and/or the officer who failed to subdue Hurtado during his first encounter with him. Things got worse for Hurtado in a hurry.
It was in the amended complaint that Allrich laid out how Hurtado-Cariaco allegedly attempted to murder the female ICE officer, referred to as “Victim 1” throughout the document.
[…]
[A]s the two agents struggled to detain Hurtado-Cariaco, he was “able to get control of Victim 1 and place [her] in a chokehold.” Allrich said the male agent gave repeated commands to Hurtado-Cariaco to release the chokehold, but he “chose to continue choking Victim 1 rather than simply fleeing the scene.”
This assertion was a lie. Two recordings made by bystanders who witnessed the attempted arrest made it clear Hurtado had definitely resisted arrest, but at no point did he pin down the female ICE officer, nor did he ever place her in a chokehold.
At no point in either video is Hurtado-Cariaco seen choking the female agent. Instead, the videos show agents placing Hurtado-Cariaco into a chokehold on two separate occasions as he attempts to break free.
Hurtado’s federal public defender, Richard McWilliams, says federal prosecutors sat on these recordings and refused to remove the attempted murder charge despite having evidence proving otherwise. US Attorney Lesley Woods says this isn’t true, claiming the public defender refused to turn over the recordings he had obtained.
But Woods’ claims are difficult to believe, especially when prosecutors waited months to rewrite the indictment, excising the bogus attempted murder charge just so that they could replace it something nearly as damaging.
By November, prosecutors filed a superseding indictment, which abandoned the attempted murder charge and replaced it with another serious felony – providing material support to a terrorist organization.
According to prosecutors, the mere existence of a tattoo — one that doesn’t actually demonstrate a connection to Venezuelan gang Tren de Aragua — was enough to hit Hurtado with terrorism charges.
(And that charge is only possible because the Trump administration unilaterally declared this gang to be foreign terrorist organization — something it only did in an attempt to legalize its unconstitutional detain-and-deport program.)
None of this bullshit impressed the judge handling Hurtado’s criminal case.
U.S. District Court Chief Judge Robert Rossiter said at the sentencing that the allegations made in the initial complaint were “at worst a misrepresentation and at best complete negligence.” Though Rossiter said there is “no doubt” that Hurtado-Cariaco committed the offense that he pleaded guilty to by fleeing the officers and struggling with them, he found the law enforcement reports “embellished” and “troubling.”
That’s a polite way of saying either the ICE officer at the scene lied or that the ICE supervisor who prepared the affidavit didn’t care whether or not he was being lied to.
And the judge isn’t happy with the government’s last ditch attempt to stick Hurtado with a lengthy sentence by belatedly adding some terrorism charges to the mix. As it stands now, Hurtado’s guilty plea to resisting arrest nets him a 14-month sentence, most of which he has already served because he’s been in jail since his arrest last June.
“To refer to him as a terrorist, attempted murderer, that he had put a chokehold on these victims… It’s just not borne out by the evidence,” Rossiter said. “And it’s troubling.”
If you can’t do your job without lying, you can’t be trusted to hold that position. If the administration can’t find enough people to arrest and deport without having to make up stories about murder or terrorism, then it needs to restrain itself to the promise that has always been empty: go after the worst of the worst. These lies were caught. Dozens or hundreds of others will go undetected.
Given what we know about the people “leading” this country and these agencies, I firmly believe they’d lie even if they didn’t have to. That’s just the kind of people they are. And the foot soldiers willingly serving this rolling atrocity of an administration need to be filmed whenever possible, because it’s the only way to keep them honest.
Filed Under: craig allrich, ice, mass deportation, rights violations, robert rossiter, trump administration, venezuela
A single AI agent conversation can look flawless scored on its own and still point to a broken product. That gap is driving a shift in how enterprises evaluate agents, away from scoring individual traces and toward comparing cohorts of users against a baseline.
At VB Transform 2026, Harrison Chase, CEO of LangChain; Hui Zhang, CTO and co-founder of Conviva; and Emmanuel Turlay, director of engineering at CoreWeave, described that shift, along with a parallel move toward cheaper, narrower judge models.
Agent-as-judge — judging one AI agent’s output with another — hasn’t replaced LLM-as-judge, which Chase said remains the default. The larger tension, Zhang said, is between automated judging, whether by LLM or agent, and human review.
“You have scalable but ungrounded, whether it’s agents as judge or LLMs as judge, you grade the outcome, you grade the work. It still is very difficult to ground it and then you use humans and that’s just not scalable,” Zhang said. “The whole industry is facing this, which poison you want to pick.”
That gap — a conversation that scores well but still signals a broken product — is what teams try to close by building an exhaustive evaluation suite before they ship anything. Chase said that doesn’t work.
“We sometimes see teams that have almost eval paralysis,” Chase said. “They’re like, this is an eval set, I can’t launch it. The best teams launch and then iterate.”
Chase framed evaluation criteria as a living specification, not a one-time test suite: a product requirements document — the standard software-development spec for what an application should do. “Evals are like the new PRD,” he said. “They define what your agent should and shouldn’t do.”
Turlay described hitting the same failure from a different angle. “I was trying to reach 100% coverage for my tests, and I still had bugs in production,” he said — a test suite that looked complete but still missed what mattered, the same gap Chase was describing with evals.
Broad, always-on monitoring, he said, catches more real failures than an exhaustive pre-launch test suite. Teams should set up wide online checks first, use those to identify failure classes as they occur, then build a targeted offline evaluation set around the problems that surface.
Even a well-built evaluation process can still score the wrong thing. Zhang’s objection is to how most teams run evaluation: sampling traces, whether 50 of them or a full population, scoring each in isolation. That approach misses a signal that only shows up when comparing cohorts of users against a baseline, a method Zhang calls contrastive analysis.
Zhang illustrated it with a retail example: a shopper asks an agent for a running shoe ahead of a half marathon, the agent asks qualifying questions, and the shopper buys a shoe. Scored individually, that interaction looks fine. But the clarification ratio, how many follow-up questions an agent asks before completing a task, came in three times higher than baseline for that shoe category across the full user population. A second metric, how often shoppers finished their purchase outside the conversation, was five times higher than baseline for the same category.
Neither number is visible from a single trace. Both point to a debuggable, category-specific problem. Zhang said the industry also lacks a second data source: what happens before, between and after the conversation, not just the trace itself.
Once contrastive analysis flags which category is actually broken, the next problem is what watches for it going forward — and at what cost. Turlay’s rule was to start with the most capable model available to prove a task is solvable, then work down. If it can’t be done with a top-tier model, he said, it won’t work with a smaller one. Once a pattern proves viable, teams can sample a fraction of traffic instead of judging every interaction, and move simpler tasks like binary classification to smaller open source models.
LangChain took that further, fine-tuning its own model to detect when a user believes the agent made a mistake, a signal Chase calls perceived error. “The model we fine-tuned was a Qwen model,” he said, referring to Alibaba’s open source family. Combining hand labeling with distillation, the result performed well. “Same as [Claude]Sonnet, for, depending on how we served it, either 10 to 100x cost reduction,” Chase said.
Not every guardrail needs a model. Chase pointed to Claude Code’s own guardrails as proof: regexes, the common programming technique for finding and validating patterns in code. “A lot of the guardrails they had were just regexes,” he said. “They weren’t small LLMs, they were just regexes.”
The bigger question is whether using LLM as a judge removes the need for a human in the loop.
Turlay pointed to accountability, drawing on his prior work at a self-driving car company. His team compressed data intake and retraining into a two-week cycle for shipping a new model to the car. Even then, someone still had to sign off.
“I felt confident on behalf of the company to say this model should go into the car,” he said. The same logic extends to legal, finance and healthcare. “Before we can remove a human to say, I endorse this and I take responsibility legally for it, it’s going to be a while before agents can do that on their own.”
Zhang agreed a human has to remain the guardian on corner cases, even as automation eventually runs at a scale that beats individual human accuracy — machines can see more at the pattern level.
Chase went further: that human check isn’t just a safety net. “Human in the loop is really important for building trust in how these agentic systems work, and also really important for memory and learning from systems,” he said. “There has to be interactions in order for the system to learn.”

Robert Downey Jr. returns to the Marvel Cinematic Universe this morning in a role no one saw coming a few years ago. He wears the metal mask of Doctor Doom in the first full trailer for Avengers Doomsday, and the footage makes clear this is no simple villain introduction. Directed by Anthony and Joe Russo, the film lands in theaters on December 18 and pulls together heroes from three separate universes who suddenly share the same battlefield.
Patrick Stewart’s Professor X appears in the teaser with a hushed warning, a sense that something big is about to happen that even a seasoned veteran like him may be unable to stop. By the end of the day, he warns everyone that they’ll have to make a decision they can’t even think about, and that sentence hits home since X has seen enough multiverse mayhem to know when the normal techniques won’t cut it.
Sale
Then Chris Hemsworth’s Thor appears, delivering the trailer’s longest and most urgent speech, attempting to convey his message. He recalls men far stronger than everyone currently standing who died because the threats they faced were more terrifying to him than the one they confront today. He goes on to warn that every single sacrifice those guys made will be in vain until the current group can put aside their old feuds and come together as brothers and sisters. Then he musters the courage to state unequivocally that they will require nothing less than a miracle.

That miracle appears in the form of Chris Evans as Steve Rogers. After years on the sidelines, Captain America returns to the frame, reaches out, and lifts Thor’s hammer as if it were nothing. Thor’s astonished reaction demonstrates how much time has gone since Rogers’ departure and how little some aspects of him have truly changed.

We also get our first good look at Downey’s Dr. Doom in full armor. Then Thor smacks him with a burst of energy, leaving him immobilized. He’s already three steps ahead of any plan you can think of. That sequence underscores Doom’s dominance over all other adversaries in the MCU.

As the trailer progresses, more and more characters from different universes cross paths, with Pedro Pascal, Vanessa Kirby, Joseph Quinn, and Ebon Moss-Bachrach appearing as the Fantastic Four and encountering people that do not belong in their reality. Then there are the original X-Men – Patrick Stewart, Ian McKellen, James Marsden, Rebecca Romijn, Alan Cumming, Kelsey Grammer, and Channing Tatum – who appear alongside Anthony Mackie’s Captain America, Sebastian Stan’s Bucky Barnes, Florence Pugh’s Yelena Belova, Paul Rudd’s Ant-Man, and so on.

Tickets for the exclusive Infinity Vision screenings went on sale the same morning the trailer debuted. This is the final chapter of the Multiverse Saga before Secret Wars, and it appears to be a doozy. The trailer doesn’t explain how these three universes merged or what Doom wants to get out of it; all it does is show the scope of the problem and the unusual group of people who are now standing in his way.
Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week.
WSUS was introduced almost twenty years ago to help IT administrators schedule updates for Microsoft products on enterprise networks from a single local update server, rather than updating each endpoint directly from Redmond’s servers.
By default, WSUS syncs with Microsoft Update servers once a day to download the latest metadata for available Windows updates. However, on servers affected by this issue, synchronization is broken, and admins will not be able to deploy the latest Windows updates via WSUS or Configuration Manager.
According to Microsoft, the WSUS sync issues affect both client (Windows 10, version 1607 and later) and server (Windows Server 2012 and later) platforms.
“Organizations might experience increased synchronization times or sync operation timeouts on WSUS servers. This issue began in recent days, with heightened impact observed starting July 13, 2026,” Microsoft said in a Windows health dashboard update.
Microsoft has rolled out mitigation measures on Saturday to prevent WSUS sync times and operation issues from affecting newly installed or rebuilt WSUS servers.
However, it is still working on additional mitigations for previously affected WSUS servers that continue to experience WSUS synchronization issues.
“Synchronization times and sync operations on WSUS servers have been restored and are operating normally for new WSUS installations and rebuilds,” it added. “For WSUS servers that were previously affected, Microsoft is working on mitigation steps to help customers safely remove the affected metadata from their environments.”
One year ago, in May, Microsoft fixed another similar issue after enterprise customers reported being plagued by WSUS errors when trying to update Windows 11 22H2/23H2 systems.
Microsoft addressed another WSUS issue in July 2025 that prevented organizations from syncing with Microsoft Update to deploy the latest Windows updates.
One month later, Microsoft resolved one more issue that blocked the August 2025 security update from being delivered via Windows Server Update Services (WSUS).
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data.
Researchers analysing the module believe it is part of the Cavern command-and-control framework that has been previously linked to an Iranian threat actor targeting entities in Israel.
At least 12 systems have been infected with HollowGraph, three of them actively communicating with the threat actor between June 3 and July 9.
The collected indicators suggest that the threat actor is focused on organizations in Israel, pointing to a targeted attack for espionage purposes.
In a report from cybersecurity company Group-IB, researchers say that HollowGraph uses hardcoded details to authenticate to the Microsoft Graph API via a compromised Microsoft 365 account.
The configuration file is stored as logAzure.txt to appear as a regular log file, and “includes the Microsoft Entra ID tenant ID, application (client) ID, client secret, target mailbox address, command-and-control (C2) domain, and two RSA keys.”
The two cryptographic keys are used to encrypt files before delivery to the attacker and to decrypt incoming tasks.
To remain under the radar, the threat actor creates calendar events dated May 13, 2050, with the title in specific formats. Commands and exfiltrated data are concealed within files attached to these calendar entries.
According to Group-IB’s analysis, HollowGraph supports only two commands that let it create calendar entries with stolen files in encrypted form and search for new ones with instructions from the threat actor:
The researchers describe the mailbox calendar as a “covert dead-drop,” with HollowGraph retrieving commands from events scheduled within a fixed one-hour window between 22:00 and 23:00 UTC on May 13, 2050.
Group-IB explains that the threat actor uses a hybrid encryption scheme that mixes RSA and AES-256-GCM algorithms to secure the communication over Microsoft Graph, keeping inbound and outbound channels cryptographically separated.

HollowGraph has a second, unencrypted communication channel through DNS tunnelling, which is used to receive new Microsoft Entra ID details (Entra ID: tenantId, clientId, clientSecret, and mailbox) to authenticate to Microsoft Graph.
It retrieves the values through IPv6 AAAA record queries to the attacker-controlled domain cloudlanecdn[.]com, and updates the configuration files stored as logAzure.txt.
“Each returned IPv6 address (16 bytes) yields 14 usable payload bytes,” Group-IB explains. The malware assembles the payload from these 14-byte chunks, decodes it as UTF-8 text, and stores the result according to the corresponding configuration field.
“HOLLOWGRAPH demonstrates a high level of technical sophistication. Its use of trusted cloud infrastructure for command-and-control, hybrid encryption, DNS tunneling for credential refresh, and highly selective victim targeting collectively suggest that the threat actor possesses significant technical capabilities and operational maturity,” – Group-IB
While the researchers cannot attribute HollowGraph to a known threat actor, their “analysis identified several technical similarities with the Iranian-nexus threat actor Lyceum.”
However, the available evidence is insufficient to attribute the activity to the threat actor with high confidence. By contrast, the researchers assess with high confidence that HollowGraph is linked to the Cavern framework.
Group-IB suggests that organizations monitor Microsoft Graph and Microsoft 365 audit logs for suspicious application-driven calendar activity, particularly events in the far future, and unusual subjects and attachments.
It is also recommended to look for indicators such as the ‘cloudlanecdn[.]com’ domain and the ‘logAzure.txt’ file, enforce Conditional Access, restrict and audit OAuth client-credential applications, and monitor outbound DNS for tunneling patterns.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Code references in the iOS 27 developer betas mention an iPhone using multiple batteries. This could be related to the iPhone Fold, but it may have a more pedestrian explanation.
The occasional reference leaks in Apple’s beta operating systems often hint to future features that are on the way. For inbound devices like the iPhone Fold, they can sometimes point to big changes in the design.
According to an examination of the just-released fourth developer beta of iOS 27, MacWorld believes this is a sign that an iPhone with multiple internal batteries is on the way.
The code strings specifically say “The batteries in this iPhone are performing as expected.” Another states “The health of the batteries in this iPhone has significantly degraded.”
There’s also a mention of how “one of the batteries” isn’t a genuine Apple component.
The report highlights the use of plurals in the strings, meaning that multiple batteries are being discussed. Based on these strings alone, it’s entirely possible that they are for two internal batteries in a device.
Stepping back from the hype for a moment, the text may also refer to other situations where multiple batteries are in use. For example, the use of external MagSafe batteries, which basically adds a second battery to a single-battery iPhone.
If we take the verbiage as factual, the most probable device that could use two batteries would be the iPhone Fold.
As a folding smartphone, it would use two halves of a body, joined together by the display, wiring, and a hinge. The problem is working out where to place the battery.
If it’s a single cell, the battery would have to be located in one of the two halves of the unit. This would be impractical, partly because most of the weight of the device would be on one side, as well as reducing the potential battery life.
A dual-battery arrangement would maintain battery life, as well as keeping the iPhone Fold balanced. One side would not weigh that much more than the other.
This is also not the first time we have heard of the iPhone Fold using multiple batteries. On July 10, a leaker proposed that there would be two cells in use, “3D Stacked” to get a capacity of around 5,000mAh.
At the time, it was also reasoned that there could be two batteries in use to maximize the available power.
It also wouldn’t be Apple’s first use of dual batteries in an iPhone. The iPhone X was shown in a 2017 teardown to have dual batteries in one body.
Zillow, the real estate technology company, doesn’t get one conversation with its customers. They move from a phone screen to a loan officer to a real estate agent, sometimes over months or years, and expect the context to follow them. A single chatbot could never carry that thread.
At VB Transform 2026, Zillow SVP of Engineering Toby Roberts and Glean co-founder and CEO Arvind Jain described how they built AI architecture meant to carry context across that entire journey — and why context, not raw data, turned out to be the harder problem to solve. Zillow’s products touch roughly 80% of U.S. real estate transactions each year, and the company has been using AI long before ChatGPT existed.
“We pretty quickly identified that we were going to need a persistent context layer that was going to meet our customers and the professionals wherever they were,” Roberts said.
Roberts said Zillow’s AI effort started where most enterprise AI efforts start, with the data itself.
“We started with a large push around making sure our data did have the right foundation,” Roberts said. That meant a data mesh approach, clear data lineage and a governance structure with permissions and identity attached to the data itself.
None of that turned out to be the hard problem. The hard problem was building something that remembered where a customer was in their journey and carried that forward, no matter which surface they showed up on next.
“This context layer has to live to be able to support you where you are at any given point in your journey,” Roberts said. Zillow chose to own that layer itself rather than depend on a single external chat interface, a decision Roberts said the team reached quickly once it looked at the shape of a real transaction rather than a single conversation.
Zillow built its own harness rather than route customers through a single model API. The team drew on 20 years of machine learning history behind products like Zestimate, leaning into smaller, task-specific fine-tuned models instead of one general-purpose model.
Internally, that harness runs alongside Glean. Roberts said Zillow now has thousands of Glean agents in production, handling repetitive tasks with tens of thousands of executions across the company. Glean’s pitch, per Jain, is centralizing that integration work once, through the Glean MCP gateway, rather than letting finance, legal and marketing each rebuild their own connections to the same systems.
That centralization is also a cost lever. Jain pointed to two mechanisms: model routing, which sends most tasks to smaller, cheaper models instead of defaulting to frontier models, and precomputed context, which avoids an agent burning tokens assembling its own context from scratch.
“Claude is also very slow because the first part of assembling that context actually takes forever,” Jain said. Routing that request through Glean instead, he said, can cut token consumption by as much as half.
Across data, cost and permissions, the session offered a few practical takeaways for enterprises building agentic AI on their own systems.
Build the measurement baseline before the AI push, not after. Roberts said Zillow’s ability to credibly attribute a 40% increase in shipped code to AI adoption rests on a DORA metrics baseline the team put in place years earlier, not on the AI rollout itself.
Centralize context once instead of letting every team rebuild it. Jain’s core argument for Glean’s platform is that duplicated integration work across finance, legal and marketing teams is a hidden cost most enterprises haven’t accounted for.
Don’t assume permission inheritance is enough for regulated data. Even with a permissions-aware context platform in place, Zillow layered hard rules and a standing compliance check on top for its most sensitive categories, rather than trusting the architecture to handle it automatically.
Treat context as a cost lever, not just a capability. Model routing and precomputed context were the two mechanisms Jain pointed to for cutting AI spend, both aimed at reducing wasted token consumption rather than adding new capability.
“Models by themselves are not enough to bring automation with AI inside your enterprise,” Jain said. “You do have to connect it with your enterprise context.”
London Mayor Sadiq Khan handed a peerage by Keir Starmer alongside 15 other Labour figures… just days before the PM leaves No10
Weekend Open Thread – Corporette.com
The House | The City of London can help the new chancellor deliver growth in every postcode
Young campaigners urge incoming PM to act on outdoor junk food ads
CFTC blocks Kalshi from unwinding Michigan trades after court order
Two July Windows Left: The CLARITY Act’s Senate Fight and What Failure Means
Ripple Payments Joins MiCA With 14 Firms, Does It Mean Anything For XRP?
Nvidia Stock Slips After Big Tuesday Rally as Huang Confirms Vera Rubin Chip Is Now in Production Today
Democrats look to World Cup watch parties to register thousands of voters
Disney’s Most Ambitious Failed Star Wars Attraction Is Coming to SDCC
Ripple wins EU-wide access as ESMA adds it to MiCA register
Palantir Shares Rise After Expanded Nvidia Partnership and Fresh Analyst Upgrades Ahead of Earnings Day
Injective Submits SEC Transfer-Agent Registration to Onchain Ownership Records
Registration is now open for March for Men with Kev 2026
Get Your ESP32 Sunny Side Up With This Solar Dev Board
XRP BOMBSHELL… XRP OMBOARDED FOR TRANSACTIONS!!!
Dark Secrets Emerge When Jailbreaking LLMs
Unregistered fitter used Gas Safe logo on business flyers
New Cornerback Enters Vikings Trade Rumor Mill
Money | Class 12 Economics | CBSE Board Exam 2026-27
You must be logged in to post a comment Login