Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Apple is moving on with its developer beta program, with new fourth builds of iOS 27, macOS 27, tvOS 27, watchOS 27, visionOS 27, and iPadOS 27 now undergoing testing.
The fourth round is here, and participants in Apple’s developer program can download the new builds to their devices right now.
The third developer builds arrived on July 6, while the second occurred on June 22 for most of the operating systems. The watchOS 27 counterparts landed later, on June 23 and June 25.
The first developer builds of iOS 27, iPadOS 27, macOS 27, tvOS 27, visionOS 27, and watchOS 27 were made available on June 8.
The fourth builds are:
The initial changes included tweaks to Liquid Glass, the long-awaited overhaul of Siri, child-protective features, and many other smaller changes.
The second iOS 27 developer beta included an update to Apple TV in the Home app, showing it like a connected HomePod or HomePod mini. The Apple Wallet also added a new insights option, albeit in a non-functional fashion.
The third included some visual tweaks, with more customization options added for Siri AI on newer iPhone models.
While AppleInsider regularly warns readers that people trying out beta software should do so on secondary, spare hardware instead of their mission-critical or daily driver devices, it’s something that actually matters more this time around.
It’s because Apple’s early developer betas are for an operating system that is still under active development. There’s a higher chance of buggy, broken, and potentially harmful elements being distributed.
The initial builds are also intended to help developers learn about the operating system changes before the final public release later in 2026. It’s not meant to be used by consumers.
Unless you have a vested interest in using them, such as app development, don’t install the early developer betas.
Instead, members of the public should seek out the public betas, when they become available.
Find any changes in the new builds? Reach out to us on X at @AppleInsider or @Andrew_OSU, or send Andrew an email at [email protected].
A new American Heart Association scientific statement concludes that up to about 400 milligrams a day, or roughly three to five cups of plain coffee, is safe for most adults and may be linked to lower risks of cardiovascular disease. The benefits appear to depend heavily on the source and preparation, with coffee and tea looking more favorable than energy drinks, and added sugar, cream, syrups, or sweeteners potentially canceling out the upside. ScienceAlert reports: “Caffeine consumed in coffee is a key part of daily life for millions of people,” says Gregory Marcus, cardiologist at the University of California, San Francisco, and Chair of the AHA volunteer writing group behind the statement. “In our review of the most recent research, for most adults, intake of up to 400 milligrams of caffeine per day, the equivalent of up to five cups of caffeinated coffee per day without added sugars or fillers, is safe and does not increase cardiovascular risk.”
The statement focused on caffeine’s relationship with cardiovascular risk factors, such as blood pressure and diabetes, as well as types of cardiovascular disease, including arrhythmias, coronary artery disease, stroke, and heart failure. The picture that emerges is complicated, but generally positive. […] All up, the new AHA statement concludes that there’s a growing body of evidence that caffeine isn’t harmful when taken in moderation, and that coffee specifically may be beneficial. The statement was published in the journal Circulation.
Hugging Face’s incident response team first turned to frontier AI models to analyze a breach of the company’s production infrastructure, and the models refused to help. Commercial safety guardrails built to stop attackers blocked every forensic query because they treated the IR team’s real exploit data the same way they would treat a live attack.
The attacker, an autonomous AI agent running the campaign end to end, moved laterally across the Hugging Face infrastructure for a weekend, undetected and unstopped.
Security leaders are quick to recognize the pattern and diagnose what went wrong. “I’ve seen versions of this during red-team exercises and internal security testing, but this is one of the first high-profile examples where it materially affected real incident response,” said Merritt Baer, senior adviser to Andesite, G2I, and AppOmni and former Deputy CISO at AWS.
None of this is unique to Hugging Face, Baer said. “Commercial frontier models optimize for preventing misuse. They generally have no cryptographic or organizational way to determine whether the person asking ‘analyze this malware’ is an incident responder or the malware author.”
On July 16, Hugging Face disclosed that an autonomous AI agent system had compromised its production infrastructure, gaining unauthorized access to a limited set of internal datasets and several service credentials. The company verified that its software supply chain was clean and found no evidence of tampering with public models, datasets, or Spaces.
Hugging Face is still assessing whether the intrusion touched any partner or customer data and says it will contact affected parties directly as required. But few enterprise threat models had accounted for the attacker Hugging Face faced. An autonomous agent ran the entire campaign from initial access through credential harvesting. No human guided it.
The entry point was a malicious dataset. When the data-processing pipeline ingested it, the dataset triggered code execution in two ways, through a remote-code loader and through a template-injection flaw in dataset configuration files. No admission gate screened the file before it reached a processing worker, the compute job assigned to each dataset. Initial access came through the data pipeline itself, a route that worked because most enterprise security teams treat the data feeding their pipelines as trusted input rather than an attack surface.
Worker isolation did not hold. From that first foothold, the agent broke out onto the node running the workload, then harvested cloud and cluster credentials scoped broadly enough to reach multiple internal clusters, all of it inside a single weekend. Hugging Face described the agent framework as executing thousands of individual actions through a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services. The disclosure adds that the framework appeared to be built on an agentic security-research harness, which would put tooling designed for red-team work behind a live intrusion.
Investigators reconstructed more than 17,000 recorded events using AI-driven analysis agents of their own.
First attempts at the log analysis ran on frontier models behind commercial APIs. Defenders’ steps included submitting real attack commands, exploit payloads, and command-and-control artifacts for classification, but safety guardrails blocked the requests outright.
Baer traced the block to the prompts themselves. “The same prompts that are most valuable during an active intrusion, shell commands, exploit chains, credential dumps, persistence mechanisms, lateral movement, are exactly the prompts most likely to trigger safety systems,” she told VentureBeat. “As AI becomes embedded in security operations, this becomes an operational resilience issue rather than merely a model policy issue.”
GLM 5.2, an open-weight model deployed on Hugging Face’s own infrastructure, took the job the commercial APIs refused. No attacker data left the company’s environment. “This experience points to a gap worth planning for,” the company wrote in its disclosure. Hugging Face does not know which model powered the agents. It could have been a jailbroken hosted model or an open-weight model running without restrictions. Either way, the disclosure continued, “the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried.” Hugging Face drew that line itself, writing that the experience is not an argument against safety measures on hosted models and that it is sharing the feedback with the providers concerned.
The industry, Baer argued, needs to move past treating AI safety as a content moderation problem. “Security operations require something different. Authenticated trust.” Instead of asking whether anyone should receive an answer, the question becomes whether an authenticated security team, operating under enterprise controls, should receive it. “The model shouldn’t only understand what is being asked. It should understand who is asking, why, and under what governance.”
“Organizations already build contingency plans for cloud outages, identity provider failures, or EDR failures,” Baer wrote. “AI assistants are becoming another dependency.”
Her advice on IR playbooks was blunt. “A mature incident response plan should assume that during a severe incident, commercial AI APIs may refuse requests, API rate limits may become unavailable, internet connectivity may be impaired, and data governance rules may prohibit uploading forensic evidence externally.” The lesson, she wrote in her emailed answers, “isn’t ‘don’t use commercial models.’ It’s ‘don’t make them a single point of failure.’”
Autonomous AI-driven attacks are not limited to AI platforms. CrowdStrike’s 2026 Global Threat Report documented AI-enabled adversary operations increasing by 89% year over year, with average breakout times falling to 29 minutes. Enterprises running AI workloads in production with agentic access to their pipelines face similar exposure.
Six control domains determined the blast radius and recovery speed at Hugging Face. Each one maps to a concrete action security leaders can take before the next autonomous-agent breach arrives.
|
Control Domain |
What Broke |
Monday Action |
|
Dataset admission controls |
Two code-execution paths were exploited. No admission gate validated the dataset before it reached a processing worker. The data pipeline became the initial access infrastructure. |
Require sandbox execution and static analysis of all datasets before they reach workers. Block remote-code loaders and template-injection paths by default. Audit for any path granting code execution to untrusted content. Report to the board as a supply-chain risk. |
|
Worker-to-node privilege boundaries |
Worker isolation failed to prevent escalation to the node. The agent gained cluster credentials because the workload-infrastructure boundary was never enforced at container runtime. |
Enforce hard privilege boundaries between workers and nodes. Deploy container runtime security to prevent workload escape. Audit whether workers can reach node-level APIs or credential stores. Include in the next penetration test scope. |
|
Credential exposure |
Cloud and cluster credentials harvested after node access. The scope was broad enough for lateral movement across multiple clusters over a weekend. |
Rotate credentials on a scheduled cadence and after any anomaly alert. Scope to the minimum cluster and service. Deploy monitoring that flags access from unexpected nodes at machine speed. Map blast radius for board reporting. |
|
Machine-speed detection |
Thousands of actions through short-lived sandboxes with self-migrating C2. AI-assisted anomaly detection surfaced the campaign after a weekend of lateral movement, per the disclosure. |
Calibrate detection for machine-speed patterns. Ensure high-severity alerts page responders in minutes, regardless of time. Audit SIEM rules for detecting thousands of short-lived executions within a single hour. |
|
Private AI forensic capacity |
Commercial APIs blocked forensic analysis. Guardrails screened query content, never analyst identity. Investigation ran on GLM 5.2 privately. |
Deploy a capable open-weight model on private infrastructure before an incident. Test against real forensic workflows. Ensure IR playbook includes fallback for when commercial APIs refuse. Document gap for cyber insurance. |
|
Autonomous-agent threat modeling |
The campaign matched the forecast agentic-attacker scenario, but no threat model had operationalized it. LLM powering the agent is still unknown. |
Add autonomous AI agents as a distinct adversary class with machine-speed decision cycles. Run tabletop at agent speed. Present results to the board as evidence that timelines need recalibration. Include in the cyber insurance application. |
“The question for directors is simple. What happens if one of our critical security tools becomes unavailable during the exact moment we need it most?” Baer framed that as operational resilience, not AI policy.
She would have boards take that framing straight to management and press for specifics. “Have we actually exercised that fallback during tabletop exercises? How quickly can we switch during an incident?” Procurement needs to change alongside governance, starting with the questions buyers ask. Security teams evaluating AI vendors should ask about their process for authenticated incident responders, whether enterprise customers receive different handling during verified incidents, and whether models can be deployed privately. “Those questions belong alongside uptime, privacy, and compliance,” Baer said.
“The biggest takeaway isn’t that safety guardrails are ‘bad.’ They’re doing what they were designed to do,” she argued.
Her larger point is that the threat model itself has changed. “For decades, defenders had better tools than attackers because they operated inside trusted enterprise environments. With foundation models, both sides increasingly use the same capabilities, but one side is constrained by enterprise governance, policy, compliance, and safety controls, while the adversary simply downloads an uncensored open-weight model and keeps going. That’s a new kind of asymmetry,” she added. “The organizations that handle it best won’t necessarily be the ones with the most powerful AI. They’ll be the ones that architect AI as a resilient security capability rather than a single cloud service.”
Hugging Face has contained the intrusion, rebuilt compromised nodes, rotated credentials, and reported the incident to law enforcement. The company recommends that all users rotate access tokens and review recent account activity. Mid-incident, Hugging Face found out whether its own AI tooling would be available, and the first answer was no. Security leaders running AI in production should find out in incident response planning instead, before an autonomous agent forces the test.
Fatal road accidents are tragically common on U.S. roadways. According to the National Vital Statistics System’s Mortality Data for 2024, 41,241 people were killed on U.S. roads that year alone. There’s one particular time of year that’s especially notorious for such traffic accidents among teenage drivers: The period between Memorial Day in late May and Labor Day in early September, the so-called 100 Deadliest Days of Summer.
According to the AAA, between the years of 2012 and 2021, traffic fatalities during this period reached “nearly half of the total number of those killed in teen-driver crashes for the entire rest of the year.” Armed with these sobering statistics, though, authorities can anticipate when such accidents tend to spike in frequency, and tailor campaigns and anti-speeding measures to try to help mitigate them. One major effort to do just that during this period is Operation Southern Slowdown, which returned for its ninth year and ran from July 13-18, 2026. It saw a group of five southern states (Alabama, Florida, Georgia, South Carolina, and Tennessee) embark on efforts to, as the Florida Department of Transportation put it, “reduc[e] speed-related crashes through a combination of increased enforcement and public education.” Speed limits vary a lot between U.S. states, but all must be obeyed.
The additional patrols during this campaign in 2025, Atlanta News First reported, resulted in “more than 13,000 speeding contacts in just one week” across Georgia. It was also just one part of a range of nationwide efforts to curb speeding during this deadly time of the year. Here are some more measures that different states are employing, as well as a closer look at why these 100 summer days are statistically so deadly in the first place.
A national campaign from the Federal Motor Carrier Safety Administration aims to increase public understanding of the dangers and encourage safer driving practices throughout the 100-day period. It’s called the 100 Days of Roadway Safety and focuses on providing digital resources, primarily blog posts, that underscore essential safe driving principles. Among them are reminders to be wary of unpredictable movements by children in school zones and that larger vehicles like trucks need to be given essential space at all times.
New York State’s Department of Health developed a Teen Driving Safety Toolkit to educate young drivers and their parents and guardians during this turbulent time of year. It highlights some particular risk factors, some resources that can be used by both the former and the latter for safety’s sake (such as the Parent/Teen Contract), and other ways these vital messages can be spread (morning high school announcements about driving safety being another).
Increased patrols, as we’ve seen, can have a big impact too. Tragically, though, it’s also vital to address the increased need for emergency responses during this time. In a Facebook post, Tennessee’s Fall Creek Falls State Park acknowledged that these 100 days can call for life-saving blood transfusions, sharing how they work and explaining the $25 eGift card incentives for doing so. Washington State, meanwhile, sees around one-third of its fatal traffic accidents during the three-month stretch beginning in June, which it calls the 90 Dangerous Days. In response, the Washington State Patrol shares the most common causes of accidents (speeding being key among them), some vital driving tips, including “always buckle up, adhere to posted speed limits, drive sober, and stay distraction-free.”
Road safety is paramount for drivers to bear in mind every journey they make. Nonetheless, as the National Road Safety Foundation points out, the summer is marked by an uptick in fatalities among teenage drivers. There are more vehicles on the road generally, for one thing, and during this period, younger drivers will typically have more free time to hit the road. Combine that with their lack of experience with safe driving habits and possibly with their vehicle itself, and it makes sense that this is a particularly dangerous time for them. After all, there are some common mistakes that even experienced drivers make on the road, and the risks are heightened with newer motorists.
During this time of year, there’s often more road maintenance and repair work taking place. All of these factors add up to busier roads that are more difficult and frustrating to navigate, which is also a very dangerous mix for those maintaining the roads and larger, less maneuverable vehicles like buses in particular.
A specific focus on safety measures during the 100 days of summer doesn’t mean that states across the country don’t prioritize these matters during the rest of the year, of course. Also in July 2026, Caltrans announced an enormous investment of approximately $2.5 billion, intended to “Strengthen transportation infrastructure and improve mobility across the state.” Including steps such as establishing more crossings and a sidewalk-widening program, it’s a strong signal that broader matters of road safety are vital across America year-round. Even so, the more attention that can be brought to the 100 days of summer, the safer motorists, pedestrians, and passengers may be.
Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out.
This known WSUS sync issue affects both client (Windows 10, version 1607 and later) and server (Windows Server 2012 and later) platforms.
On impacted WSUS servers, admins are not able to deploy the latest Windows updates via WSUS or Configuration Manager due to increased synchronization times or sync operation timeouts caused by a buildup of publishing metadata.
Microsoft rolled out a service-side mitigation on Saturday to address the issue for newly installed or rebuilt WSUS servers following heightened impact observed starting one week ago, on July 13.
“Synchronization times and sync operations on WSUS servers have been restored and are operating normally for new WSUS installations and rebuilds,” Microsoft said.
On Monday, Microsoft also shared a manual fix for customers who are still experiencing sync operation issues and timeouts to help admins return their WSUS servers to normal functionality.
“Organizations with existing WSUS server installations that are experiencing long sync times can benefit from manual steps in order to clean up unneeded metadata,” it noted in a Windows release health dashboard update. “This metadata is present in existing WSUS installations but can be safely removed.”
This requires them to back up each SUSDB database, run a cleanup query from SQL Management Studio against all SUSDB databases (including WSUS replicas), and update the MaxXMLPerRequest value to its default setting.
After the cleanup process, the first Windows Update scan may take longer than usual, but subsequent scans will return to normal timing.
“After the cleanup, reindex SUSDB, run the WSUS Server Cleanup Wizard, and then run IISReset or recycle the WsusPool application pool to clear cached catalog state,” Microsoft added. “The client-side DataStore.edb does not shrink automatically after the detectoids are removed. This is expected and does not affect scan performance.”
Microsoft has addressed similar WSUS issues that prevented admins from deploying the latest Windows updates in May 2025, July 2025, and August 2025.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
It’s official: We’re getting a pickle emoji next year. On Tuesday, July 14, the Unicode Consortium announced the nine new emoji you’ll see on your device in 2027. One new emoji is the pickle, and that means the eggplant’s reign as the go-to emoji for male anatomy could be coming to an end.
Here are the nine new emoji you will see on your device next year.
The Unicode Consortium originally proposed a squinty face emoji in 2025. However, the Unicode Emoji Standard & Research Working Group recommended changing that emoji to a cracking face in January.
Honestly, the cracking face emoji feels more relevant to today than the squinty face emoji. The squinty face read as suspicious while the cracking face emoji screams, “I’m putting on a brave face in these trying times.” If that’s not the most relatable sentiment these days, I don’t know what is.
While the Unicode Consortium approved these emoji, companies like Apple and Samsung still need to design and then implement their versions of the emoji. Those companies usually add the emoji to devices as part of a software update in the spring, so you likely won’t see these emoji on your phone until 2027.
Before these emoji land on your device, the Unicode Consortium will begin fielding proposals for the next round of new emoji. Anyone can submit an idea for a new emoji, and the Unicode Consortium usually uploads proposed new emoji to a public document late in the year. For example, the upcoming emoji were originally accepted in October, 2025.
For more on emoji, here’s how to decipher every emoji and the newest emoji on your iPhone and Android.
It’s officially the second half of 2026, which is going to be all about Grand Theft Auto 6. Until then, Sony has a new selection of games coming to PS Plus in July that includes Avatar: Frontier of Pandora, Dying Light and a couple of classic PlayStation 2 games.
PS Plus, which is Sony’s version of Xbox Game Pass, offers a large, constantly expanding library of games. Subscribers can choose from the Essential, Extra and Premium tiers, each with unique perks and benefits. Starting at $11 a month, the plans give subscribers access to games and rewards, and each month, all subscribers can play a handful of new games at no additional charge.
If you’re a PlayStation Plus Extra or Premium subscriber, you can grab these games starting July 21.
Avatar: Frontiers of Pandora came out in 2023, a year after Avatar: The Way of Water released in theaters. Developed by Massive Entertainment – a division of Ubisoft – the open-world action-adventure puts players in the role of a Na’vi raised by the Resources Development Administration, or RDA, before returning to defend Pandora. Set in the previously unseen Western Frontier, the game emphasizes exploration, aerial traversal on an ikran and combat using both traditional Na’vi weapons and human firearms. While its gameplay shares many similarities with the Far Cry series, its lush environments and faithful recreation of Pandora earned praise from critics.
Avatar: Frontiers of Pandora will be available for PS Plus Extra and Premium subscribers starting July 21.
Team Ninja went a different direction than its usual Ninja Gaiden style with 2024’s Rise of the Ronin. Set during Japan’s turbulent Bakumatsu period in the late 19th century, the open-world action RPG lets players shape the story by siding with competing political factions. Combat combines fast-paced swordplay with firearms and other period weapons with the challenging gameplay the studio is known for. Its blend of historical events, exploration and player-driven choices helped distinguish it from Team Ninja’s previous action games.
Rise of the Ronin is now available for PS Plus Extra and Premium subscribers.
Firefighting Simulator: Ignite puts players in the role of a firefighter responding to emergencies across a large fictional city in the American Midwest. Whether playing solo with AI teammates or cooperatively with up to three friends, players battle dynamic fires, rescue civilians and use authentic firefighting equipment to contain increasingly dangerous blazes. Powered by Unreal Engine 5, the game features real-time fire, smoke and heat simulation designed to create a more realistic firefighting experience.
Firefighting Simulator: Ignite will be available for PS Plus Extra and Premium subscribers starting July 21.
Mighty Morphin Power Rangers: Rita’s Rewind is a true nostalgia bomb of a game. The side-scrolling beat-’em-up reimagines the classic 1990s TV series with pixel art visuals, cooperative multiplayer and familiar villains, including a robotic version of Rita Repulsa. Players battle through stages inspired by the show before piloting Dinozords and the Megazord in 3D action sequences that break up the traditional brawler gameplay.
Mighty Morphin Power Rangers: Rita’s Rewind will be available for PS Plus Extra and Premium subscribers starting July 28.
It’s been more than a decade since Dying Light was released, but it’s still a title that gamers fawn over. Players explore the zombie-infested city of Harran using a fast-paced parkour system that makes traversing rooftops as important as combat. Scavenging for supplies, crafting weapons and surviving a dynamic day-night cycle keep the tension high as more dangerous infected emerge after dark. Its fluid movement and intense survival mechanics helped make it one of the most acclaimed zombie games of its generation.
Dying Light will be available for PS Plus Extra and Premium subscribers starting July 21.
Citizen Sleeper 2: Starward Vector builds on its predecessor by sending players across a lawless star system as an escaped android searching for freedom. Rather than focusing on traditional combat, the game emphasizes dialogue, dice-based skill checks and resource management as players assemble a crew and take on dangerous contracts. Its choice-driven storytelling and tabletop-inspired mechanics make every decision feel meaningful, with multiple paths that shape how the story unfolds.
Citizen Sleeper 2: Starward Vector will be available for PS Plus Extra and Premium subscribers starting July 28.
Snow Bros. Wonderland revives the long-running arcade franchise with a fresh 3D isometric look while staying true to its classic action-platforming roots. Players freeze enemies into snowballs before kicking them across each stage to defeat other foes and rack up combos. Cooperative play, colorful environments and larger-than-life boss battles help modernize the series without losing the charm that made the original games fan favorites.
Snow Bros. Wonderland will be available for PS Plus Extra and Premium subscribers starting July 28.
Psi-Ops: The Mindgate Conspiracy was first released for the PS2 in 2004 and had a mix of interesting physics gameplay that was a big trend in gaming at the time. Players control Nick Scryer, a secret agent who combines traditional gunplay with psychic abilities like telekinesis, mind control and pyrokinesis to take down enemies. The game’s physics-based powers encouraged creative problem-solving and helped it stand out from other action shooters of its era, earning it a cult following years after its release.
Psi-Ops: The Mindgate Conspiracy will be available for PS Plus Premium subscribers starting July 21.
Before it made a name for itself with the games Heavy Rain and Detroit: Become Human, developer Quantic Dream first experimented with making the point-and-click adventure gameplay style a bit more action-oriented with Indigo Prophecy. The supernatural thriller follows several interconnected characters as they investigate a string of mysterious murders while uncovering a conspiracy that threatens humanity. Its cinematic presentation, branching narrative and quick-time events helped lay the foundation for the studio’s later interactive dramas.
Indigo Prophecy will be available for PS Plus Premium subscribers starting July 21.
For more on PlayStation Plus, here’s what to know about the service. You can also check out other games on PlayStation Plus and games on Xbox Game Pass.

Microsoft Chief Sustainability Officer Melanie Nakagawa faced a barrage of pointed questions from the audience Friday during a session at the annual Pacific Northwest Climate Week in Seattle.
Protesters challenged Nakagawa through most of the 30-minute session held in a conference room at Seattle’s City Hall, calling out the company’s use of fossil fuel energy sources to power its AI data centers and challenging Microsoft’s commitment to climate goals set years ago.
As a reporter covering sustainability issues for GeekWire, I moderated the session. Many of the issues raised by the crowd were on my list of questions for Nakagawa. The disruptions also included chants from protesters seated among attendees, at times going beyond climate issues to condemn Microsoft’s technology deals with Israel.
Security guards ultimately ushered some protesters out of the space, while others remained. Interruptions from the audience continued for all but the final 10 minutes of the session.
The event capped off Pacific Northwest Climate Week, which included conversations around the city and region about climate change solutions, policies and innovations.
Microsoft has for many years been viewed as an environmental corporate leader, setting an ambitious goal in 2020 to become carbon negative within a decade. It created an internal carbon tax — one of the corporate world’s largest — that charges individual Microsoft divisions for emissions from sources like air travel to fund climate-friendly initiatives. The company is credited with helping create and sustain the carbon dioxide removal sector, among other roles.
But the rapid expansion of AI data centers and their huge energy demands are undercutting Microsoft’s standing. The company recently released its annual sustainability report, disclosing that its carbon footprint grew 25% last year, moving it further from its 2030 target.

One protester’s question was about a deal announced earlier this year in which Microsoft is partnering with Chevron to build a 2.7 gigawatt natural gas facility to power a data center campus in Texas. I asked Nakagawa how the company defends the agreement, and she pointed to the 4.7 gigawatts of renewable energy that Microsoft has supported in the state. I followed up by asking about the Redmond, Wash.-based company’s commitment to carbon dioxide removal (CDR) projects given recent reports about a pause on new deals.
Nakagawa was unable to answer before the crowd drowned her out with a call-and-response chant: “Microsoft, you can’t hide. We can see your dirty side.”
Another protester criticized the escalating pursuit of AI. “You’re selling us a product that we don’t even need, and we never should ask for,” he said. “No one wants AI. You’re destroying the climate with AI.”
I brought up legislation proposed earlier this year in Washington to mandate clean energy use and bring transparency to data center impacts in the state. Microsoft opposed and helped defeat the bill, though the company says it wants to work with lawmakers to pass rules next year. I asked what needed to change in the legislation for Microsoft to support it.
Nakagawa didn’t provide specifics, but noted that this year, for the first time, the company shared facility-level information in its annual report on electricity and water use for data centers worldwide.
“People want to know more about the data, and we believe you can have an honest and candid conversation with transparency and access to that information and data,” she said.
Given the obvious public concerns, I asked Nakagawa, “Do you really honestly believe that by 2030, the company can hit that carbon-negative goal?”
Nakagawa pointed to wide-ranging initiatives that are starting to help curb specific emissions, including investments to make Xbox devices lower carbon and financial support for the recent opening of a production plant in Moses Lake, Wash., for sustainable aviation fuel company Twelve.
“There are a couple areas where we’re seeing a lot of promising progress,” she said. “Look, this is going to be a hard target. We’ve not been at all shying away from the fact that this is a difficult goal.”
Apple has quietly increased the price of Apple Music in the US, with individual subscriptions now costing $11.99 per month instead of $10.99.
The change also affects Family and Student plans. In addition, several Apple One bundles are impacted. The price rise comes almost four years after Apple last increased Apple Music subscription fees in October 2022.
The biggest jump is for the Apple Music Family plan, which now costs $19.99 per month, up from $16.99. The Student plan has also increased by $1, bringing the monthly fee to $6.99.
Apple has also adjusted pricing for two of its Apple One bundles. While the Individual plan remains unchanged, the Family tier now costs $27.95 per month, up by $2. Meanwhile, the Premier plan has increased to $39.95 per month. Apple has also confirmed similar price increases in Brazil.
In a statement to Music Business Worldwide, Apple said the latest changes are “the result of rising licensing costs,” suggesting that higher payments to rights holders and music labels are behind the increase.
The price hike means Apple Music now sits closer to many of its biggest streaming rivals. However, the service continues to distinguish itself with features such as Lossless Audio, Hi-Res Lossless, Spatial Audio with Dolby Atmos, live radio stations and a catalogue of more than 100 million songs.
For existing subscribers, the increase is relatively modest on the Individual plan, but families will notice a more significant jump. Moreover, an extra $3 each month adds up to $36 more per year. This makes it one of the largest increases Apple has introduced for the service.
Spotify, YouTube Music and other services have all introduced price increases in recent years. As a result, premium music subscriptions are becoming steadily more expensive across the board.
If you’re already subscribed, the updated pricing should appear on your next billing cycle. New customers signing up from today will pay the new rates immediately. Meanwhile, anyone considering Apple’s wider ecosystem may want to compare whether an Apple One bundle now offers better overall value than paying for Apple Music on its own.
Bats are remarkable creatures, able to fly at night or inside the confines of caves without light to guide their way. A team of researchers at Worcester Polytechnic Institute (WPI) has determined how to use low power ultrasonic sensors to guide drones in obscured environments.
While radar, lidar, and GPS are all great for navigation and sensing, they can run into issues when light is obscured or can take too much power to be practical for the limited battery life of a drone. The researchers found that a dual sonar array could be used to implement a much lower power sensing system for a drone that performs well in environments that would stymie a computer vision system.
A shield placed behind the array cuts down on the sound of the propellers that would otherwise drown out the signal, and further signal analysis via a neural net separates the echoes of objects in front of the drone from the background. The prototype could navigate in various simulated environments like forests, smoke, and snow. It looks like it even got a chance to go for a flight in the actual woods. All the code and hardware designs are Open Source, so have at it!
We’ve covered mosquito-inspired drone sensors before, and if you want to get into echolocation yourself, apparently humans can learn to do it too.
Chris Fall, the director of the Center for AI Standards and Innovation (CAISI), has resigned, the agency confirmed to multiple news outlets.
He was appointed just three months ago after the last appointee, Collin Burns, left in less than a week, The Washington Post reported at the time. Burns was reportedly “pushed out” of the job in April because he previously worked for Anthropic and the Trump administration had been battling with the company, sources told the Post.
No reason was given for Fall’s departure. Prior to leading CAISI, Fall was the director of the Department of Energy’s Office of Science during the first Trump administration and had been the acting director of the DOE’s Advanced Research Projects Agency-Energy. He worked in the DOE’s Office of Naval Research (ONR) prior to that.
Before Burns and Fall, the agency was led by venture capitalist David Sacks, whose title at the time was White House AI and crypto czar. Sacks stepped down in March.
CAISI, which operates under the National Institute of Standards and Technology, is the primary organization for developing technical standards and testing methods for AI models as well as assessing cybersecurity risks. Yet it was not the agency at the center of the most recent model-risk brouhaha.
That occurred in June when the U.S. Commerce Department invoked an obscure export control directive that effectively forced Anthropic to pull its Mythos and Fable models from the market. The ban was lifted by the end of the month, when Secretary of Commerce Howard Lutnick said he was satisfied with Anthropic’s safety plans.
Earlier this month, the White House also signed an executive order for a new AI safety oversight program called “Gold Eagle” that creates a clearinghouse for cybersecurity vulnerability coordination. A host of federal organizations were named as part of the program, including the Commerce Department and Department of Homeland Security. But, as CNBC pointed out, CAISI was not among the federal organizations mentioned.
Meanwhile, after Anthropic’s models were freed from the ban, Google DeepMind CEO Demis Hassabis began calling for the creation of an independent, industry-run standards body to regulate frontier AI modeled after FINRA — the same sort of mission that CAISI was formed to tackle.
Fall’s resignation also follows this weekend’s handwringing over Chinese AI lab Moonshot’s new version of its open model Kimi, which performed competitively against flagship frontier models. The administration was weighing efforts to somehow ban Chinese open models, Axios reported. This sparked immediate debate and outrage over the weekend, including from Sacks, who argued that regulations shouldn’t be used as a protectionism strategy for U.S. proprietary AI labs.
While CAISI has released a few reports on the capabilities of Chinese open-weight models Z.ai’s GLM-5.2 and DeepSeek V4 Pro, it hasn’t talked much about its processes for testing. (Open weight means these models can be publicly downloaded and run locally, but its training code and datasets are not available). Since July 9, TechCrunch has sent multiple inquiries to both the DoC and NIST about how its LLM evaluations work and has not received a response.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
London Mayor Sadiq Khan handed a peerage by Keir Starmer alongside 15 other Labour figures… just days before the PM leaves No10
Weekend Open Thread – Corporette.com
The House | The City of London can help the new chancellor deliver growth in every postcode
Young campaigners urge incoming PM to act on outdoor junk food ads
CFTC blocks Kalshi from unwinding Michigan trades after court order
Two July Windows Left: The CLARITY Act’s Senate Fight and What Failure Means
Ripple Payments Joins MiCA With 14 Firms, Does It Mean Anything For XRP?
Nvidia Stock Slips After Big Tuesday Rally as Huang Confirms Vera Rubin Chip Is Now in Production Today
Democrats look to World Cup watch parties to register thousands of voters
Disney’s Most Ambitious Failed Star Wars Attraction Is Coming to SDCC
Ripple wins EU-wide access as ESMA adds it to MiCA register
Injective Submits SEC Transfer-Agent Registration to Onchain Ownership Records
Palantir Shares Rise After Expanded Nvidia Partnership and Fresh Analyst Upgrades Ahead of Earnings Day
Sail Virtually Aboard The “Itanic” With IA-64 Emulator
Turtle Beach Command Series KB7 review: a nifty screen-equipped gaming keyboard
Dark Secrets Emerge When Jailbreaking LLMs
XRP BOMBSHELL… XRP OMBOARDED FOR TRANSACTIONS!!!
Registration is now open for March for Men with Kev 2026
Unregistered fitter used Gas Safe logo on business flyers
New Cornerback Enters Vikings Trade Rumor Mill
You must be logged in to post a comment Login