The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days.
The Zimbra security team patched the security flaw (tracked as CVE-2026-73570) in version 10.1.20, released on July 20.
Successful exploitation allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled on the targeted system.
“Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user,” it explained.
CISA’s warning comes after CERT Polska, the Polish Computer Emergency Response Team (CERT), first flagged the vulnerability as targeted in the wild last Monday.
Advertisement
While threat security watchdog Shadowserver tracks more than 12,000 Zimbra servers exposed on the Internet, there is no information on how many are honeypots or have already been secured against attacks exploiting the CVE-2026-73570 flaw.
Zimbra Collaboration Suite servers exposed online (Shadowserver)
On Friday, CISA confirmed CERT Polska’s alert, added the flaw to its KEV catalog, and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their systems within three days, by August 24.
Although CISA didn’t share any information on these ongoing attacks, the Polish CERT team asked security teams to check logs for suspicious activity, such as the Zimbra service restarting unexpectedly, and for files created in the /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ folders by user zimbra over the last 30 days.
ZCS is a popular email and collaboration suite used by hundreds of millions of organizations and people worldwide, including hundreds of government agencies and thousands of businesses.
Advertisement
Zimbra security issues are commonly targeted in the wild and have been used to steal sensitive data from vulnerable email servers in recent years.
Most recently, Seqrite Labs researchers revealed in March that APT28 (a state-sponsored threat group linked to Russia’s military intelligence service) was exploiting a stored cross-site scripting (XSS) vulnerability in attacks targeting Ukrainian government ZCS servers.
In October 2024, U.S. and UK cyber agencies warned that APT29 hackers (tracked as Midnight Blizzard and Cozy Bear) linked to Russia’s Foreign Intelligence Service were targeting Zimbra servers using a flaw previously exploited to steal email account credentials.
Russian Winter Vivern cyber spies have also abused a reflected Cross-Site Scripting (XSS) vulnerability to steal emails belonging to NATO-aligned individuals and organizations via Zimbra webmail portals.
Advertisement
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
An anonymous reader quotes a report from Gizmodo: Dr. Dre, the pioneering rapper and seven-time Grammy-winning producer behind hit songs like Tupac’s “California Love” and Eminem’s “The Real Slim Shady,” is very much pro using artificial intelligence tools to make music. In an interview with the New York Times, Dr. Dre and Interscope Records co-founder Jimmy Iovine spoke about artificial intelligence’s recent foray into music production, with the producer characterizing those who oppose AI song generation tools as “afraid of learning new things.” “I don’t see it as a threat. I think the only people that see it as a threat are the people who have trouble creating,” Dr. Dre said. “I had a discussion with a few people a few days ago. They were against AI, and I’m like, ‘OK, you sound like the person that would have been against the drum machine when it came out.’ Or synthesizers, right?”
[…] Iovine, the music executive and Dr. Dre’s partner in Beats by Dre, for his part, says he doesn’t “see the downside at all.” “There will be some crappy music. There’s crappy music now,” Iovine told the NYT. “In the studio, when gifted people have AI, they’re going to make better records.” Dr. Dre said he uses AI in producing “as a tool to see what it would do with what I just did.” The award-winning producer also said he is definitely not alone among his peers in his stance on AI either: many producers use AI but fear to admit it. Iovine calls them “closet AI producers,” and says Timbaland, the four-time Grammy-winning singer-producer behind a long list of hits like “Promiscuous” with Nelly Furtado, is also one.
Muneera Bano and Didar Zowghi of CSIRO explore the human factors that often lead to AI bias.
In the United States, leading HR software company Workday is currently facing a lawsuit over its use of job screening tools powered by AI which allegedly discriminated against applicants based on factors such as age, disability and race.
The company, whose hiring software is widely used by large employers around the world, has denied the allegations.
The case is one of many examples of AI systems alleged to have caused discriminatory harm. When AI systems replicate and amplify discrimination, they blur the boundary between technical error and systemic injustice, turning bias into a digital harm.
Advertisement
And while our first instinct might be to blame the algorithms, they don’t decide what they can generate, what safeguards are built into them, or how a company responds when incidents of discrimination are reported. People make those calls long before an AI produces any output.
That is why technical fixes to AI systems are not enough. What is needed is an overhaul of AI ecosystems to ensure they are more inclusive.
A broader pattern
AI systems quietly narrow who gets seen as competent, employable or fit to lead.
For example, in a 2025 study, we tested how two AI models, OpenAI’s GPT-4 (which has now been retired) and Microsoft Copilot, represented software engineers in a simulated recruitment exercise: 300 candidate profiles for four job roles, followed by recommendations and generated images of each AI model’s preferred candidates.
Advertisement
Both models favoured male profiles, especially for senior roles. Their images also skewed towards engineers who were younger, slimmer, and lighter-skinned. The models were reproducing associations embedded in language, imagery, employment records and assumptions about who belongs in the profession.
These outputs don’t stay contained to a research study. AI-generated recommendations are entering hiring, education and public services.
Even when AI systems operate across different languages and cultures, they often reproduce predominantly western values, assumptions and ways of understanding the world. The wealthy countries have become the main beneficiaries of AI, which widens global inequality.
In another study from 2025, we manually reviewed reported AI incidents.
Almost half involved a diversity or inclusion issue, with racial, gender and age discrimination most prominent. The harms traced back to different points in the AI development life cycle: non-diverse training data, and neglected diversity and inclusion principles during design, development and deployment.
Why technical fixes are not enough
Technical work matters, including bias identification, re-balancing datasets and adjusting outputs. But these fixes often treat bias as a property of the AI model, when much of it originates from outside the system.
People decide what data to collect, how to label and categorise it, and whose experiences are important. These decisions are shaped by history, cultural norms, institutions and existing power imbalances.
Wherever society has linked leadership with men, technical skill with lighter skin, or innovation with youth, AI models learn from those associations and formalise, automate and repeat them at a larger scale.
Bias also usually appears through the intersection of multiple identities, such as gender, race, age, disability and class. A system that looks fair when each identity is tested separately can still disadvantage people at the overlap of several.
Advertisement
Building a more inclusive AI ecosystem
That’s why building a more inclusive AI ecosystem requires interdisciplinary knowledge, such as educating AI engineers about social science theories to help them understand the social origin of bias.
Inclusive AI is not about political correctness; it is about upholding human rights, preventing harm, ensuring justice, and building trust.
It also requires genuine participation from affected groups and sustained attention to the power structures these systems operate within. AI development teams should test not just whether a model is accurate, but whether its benefits, errors and harms are distributed fairly across different groups.
Together, this would help ensure tech companies better understand the nature of a bias once it’s manifested through AI and therefore develop new methods or tools to minimise the harm it causes.
Algorithms don’t decide which data matter or what level of risk is acceptable. People make these choices. It’s high time tech companies remember that. The focus should not just be on fixing a biased algorithm, but rather on examining the human decisions that allowed the risk of harm, and who was missing when those decisions were made.
Dr Muneera Bano is a principal research scientist at CSIRO’s Data61 and an internationally recognised researcher in responsible AI. She leads research on diversity and inclusion in AI, developing practical engineering methods and governance approaches that help organisations design AI systems that better serve the people and communities they affect. Her research bridges software engineering, AI governance and human-centred design, with a strong focus on translating evidence into practice through collaboration with government and industry.
Advertisement
Prof Didar Zowghi is senior principal research scientist at CSIRO’s Data61. She leads the science team in ‘Diversity and Inclusion in Artificial Intelligence’ and ‘Requirements Engineering for Responsible AI’. She built a research team to pioneer a new research area exploring the challenges and opportunities of diversity and inclusion in achieving responsible AI.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
General Motors electric vehicles, including ones built in partnership with Honda, are now facing increased scrutiny from the top U.S. auto safety regulator after hundreds of incidents, more than 20 crashes or fires, and at least six injuries.
The brake problems also extend to some non-EV models, including the Chevy Colorado, GMC Canyon, and the Buick Enclave and Envision. More than 1 million vehicles may be affected.
The National Highway Traffic Safety Administration (NHTSA) first started its investigation in April 2024 after reports of trouble from owners of 2023 model year Cadillac Lyriq vehicles. The agency’s Office of Defects Investigation (ODI) said Monday that it was upgrading this probe to what’s known as an “engineering analysis.” That’s the highest level of investigation that ODI performs, and is often a step the office takes before telling a company to issue a recall.
The initial complaints ODI received two years ago typically involved owners describing receiving a “Brake System Failure” message when starting up the vehicle, or after coming to a complete stop. GM performed “several internal investigations” into the issue, according to ODI, and determined that the problem was linked to fractures in the spindle of its “eBoost” brake-by-wire system.
Advertisement
But ODI said on Monday that it kept receiving reports of a loss of braking assistance that were “inconsistent with GM’s description of a spindle failure.” The additional reports described an “immediate loss of brake assist” while a customer was in the process of braking to slow their car down, which the safety regulator said “could result in extended braking distance, which increases the risk of a crash or injury.” ODI said it needs to do a further analysis of the potential for failures in the eBoost system.
The eBoost system was introduced in 2019 and gradually rolled out to more models over the years. The system ditches a traditional mechanical link between the brake pedal and the braking system, opting for an electronic one instead. This allows GM to change the brake “feel” in different driving modes. The automaker put eBoost on its most popular EVs, like the Blazer EV, Equinox EV, Cadillac Lyriq, and the Honda Prologue and Acura ZDX, which it made with Honda in a joint venture. The Cruise Origin — the purpose-built electric autonomous vehicle with no steering wheel or pedals, which GM abandoned in 2024 — also used eBoost.
In one crash reported to NHTSA, the driver of a 2025 Lyriq said they lost their brakes while trying to pull into a parking space in front of the store. The vehicle drove over the curb and crashed through the store front, coming to rest “mid-way in the store, amidst the furniture and store structure,” according to the driver.
In another, the driver of a 2024 Blazer EV said they had to “deliberately steer the vehicle into a concrete curb” to slow it down and avoid a “catastrophic intersection collision.”
Advertisement
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
For decades, tech has been obsessed with making communication faster. Now, apparently, we’ve had enough. As The New York Times reports, the latest trend is slow tech, with apps like Carrier Pidge and Roost deliberately making messages take minutes, hours or even longer to arrive. Yes, we’re talking about digital carrier pigeons. Carrier Pidge launched in April and recently jumped from a few hundred users to more than 75,000, while Roost reportedly reached 650,000 downloads this month.
Apparently, waiting is cool again
Carrier Pidge lets you send a message via a digital pigeon whose journey you can track on a map. Its speed is based on real racing pigeons, topping out at 110mph, and there’s even a tiny 0.2% chance your bird disappears, meaning you’ll have to cough up 99 cents for a replacement. Roost takes the idea even further, offering more than 1,000 animals, from pigeons and penguins to snails that crawl along at a wonderfully useless pace.
Carrier Pidge AppCarrier Pidge
The appeal isn’t really the wildlife. It’s the friction. Instead of another instant notification demanding your attention, you actually have to wait for someone to respond. That may actually matter more than we think: research has suggested that constantly picking up your phone in short bursts can be more mentally taxing than simply spending a long stretch on it. Carrier Pidge’s 29-year-old creator, Noah Iarrobino, previously made an app that charged users 99 cents every time they hit snooze, while Roost creator Logan Mendelsohn comes from the trust-and-safety tech world and is now planning to hire as the app grows.
Maybe our phones got a little too good at being phones
There may actually be something behind the silliness. A 2023 survey found that 80% of Gen Z adults, defined in the survey as people born after 1997, worried their generation relied too heavily on technology. Cal Newport, a computer science professor at Georgetown University, argues that our brains aren’t particularly well suited to a completely friction-free world where information arrives faster than we can process it.
Digital Trends
And people aren’t just tolerating the slowness — they’re embracing it. One user told The New York Times that she and her friends even started writing to each other in Bridgerton-esque language, calling one another “my dearest lady.”
After decades of making everything faster, maybe the next killer feature really is making us wait. And honestly, if sending a text by pigeon is what it takes to make our phones a little less exhausting, perhaps we shouldn’t laugh at the birds just yet.
The course is designed in partnership with major technology companies.
16 graduating students form the first cohort of University of Limerick’s (UL) master’s degree in immersive software engineering (ISE), with many stepping into highly sought-after roles at companies including Stripe, Salesforce-owned Fin, Analog Devices and Amazon Web Services, the third-level institute said.
Launched in 2022, the master’s course in ISE prioritises practical, on-the-job experience over lectures and theoritcal studies, UL said. Since its launch, its intake has grown to around 60 students a year.
The degree is backed by leading tech firms, including of OpenAI, Qualcomm, Susquehanna, Eli Lilly and Deloitte, as well as big Irish names such as Manna, Provizio, Tines and Protex AI, allowing students to undertake five long-term paid residencies with the participating businesses.
Advertisement
Students also have a chance to build their own companies in partnership with Dogpatch Labs, the institute said.
“We launched the ISE programme with an ambition. We wanted to prove that a radically different model of software engineering education built on real-world complexity rather than the traditional lecture hall would produce graduates able to operate at the highest level of the software industry,” said Prof Stephen Kinsella, the co-director of UL’s ISE programme.
“Today, we’re seeing the results of that ambition realised. Our students are stepping into roles with some of the country’s most innovative companies. We’re excited for, and proud of, each of them and can’t wait to see how they progress as the future of Ireland’s tech ecosystem.”
In total, students spend around half of the course in the workplace and are given the opportunity to work on real-world problems and products, UL said. Today’s graduating cohort of master’s students have also won multiple prestigious awards and scholarships, including from Naughton and Google.
Advertisement
Fintech giant Stripe (which also runs the prestigious Young Scientist & Technology Exhibition) has worked to help develop the ISE programme, co-building the curriculum and the residency placement process as a founding partner.
“The incredible students graduating today took a bet on a different kind of degree when they signed up to ISE,” said Alison Ahern, the head of education partnerships at Stripe
“I’m delighted to see that faith being repaid as they leave for exciting careers and bright futures. ISE is made possible by deep collaboration between academia and industry leaders, and Stripe is proud to support a truly world-class programme. We’ve also enjoyed the partnership immensely, and we look forward to continuing to work with ISE.”
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
IBM is announcing today at the annual Hot Chips conference what may be the most consequential change to mainframe architecture in decades: a processor whose cores can natively execute both IBM’s own instruction set and Arm’s — switching between the two in nanoseconds.
The chip, which will power the next generation of IBM Z and LinuxONE systems, is the first dual-architecture mainframe processor ever built. It is designed to let enterprises run the vast and fast-growing ecosystem of Arm-native Linux software — including the AI frameworks that increasingly define modern infrastructure — directly alongside the z/OS transaction-processing workloads that anchor the world’s banks, insurers, and governments.
“As technology enthusiasts on both sides, we’re really excited about being what I would consider one of the most powerful commercially available processors that’ll be dual architecture,” Tina Tarquinio, chief product officer for IBM Z and LinuxONE, told VentureBeat in an exclusive interview ahead of the announcement.
The announcement marks the first hardware milestone from the strategic collaboration IBM and Arm unveiled in April, and it offers an unusually direct answer to a question that has shadowed the mainframe for years: can the machine that processes most of the world’s regulated financial transactions remain a first-class citizen in an AI era built largely on other people’s silicon?
Advertisement
A computer-aided design layout of IBM’s new processor, the first mainframe chip capable of natively running both IBM’s instruction set and Arm’s. Each of its 11 cores can switch between the two architectures in nanoseconds. (Credit: IBM)
How IBM engineered a processor core that speaks two instruction sets
The most striking engineering decision is what IBM chose not to do. The company could have bolted a handful of standalone Arm cores onto the side of its processor — a simpler design that other chipmakers have used for heterogeneous computing. Instead, IBM built every core on the chip to be bilingual.
“On this chip are 11 cores, and each core can dynamically switch back and forth between Arm software mode and traditional Z software mode,” Jacobi explained in an exclusive interview with VentureBeat. “That enables us to run the mission-critical enterprise software right next, on the same chip, to the much broader software ecosystem of Arm applications.”
The mechanism relies on the open-source KVM hypervisor. Enterprises can run Arm64 Linux virtual machines and Linux on Z virtual machines side by side, and as the hypervisor dispatches each virtual machine onto a physical core, the core flips into the corresponding mode. The performance penalty, Jacobi said, is effectively zero. “That switch takes about the nanosecond scale,” he said. “Because you’re running for many milliseconds in the virtual image, this switching overhead sort of amortizes to zero — pretty much no impact at all.”
Advertisement
Traditional z/OS workloads run in a separate partition on the same chip, outside KVM — meaning a bank’s core ledger, its fraud models, and a modern Arm-native monitoring stack can all share the same silicon, the same memory fabric, and the same reliability guarantees. Jacobi was candid that IBM debated the easier path and rejected it. “We’re really not addressing their need if we just have a few, I’d say, loosely Arm cores in the corner of the chip,” he said. “It really needed to be deeply integrated into the entire system design for it to have the same qualities of service that clients are used to.”
The specifications underscore that this is no compromise design. Built on a leading-edge 2-nanometer process node, the chip runs its 11 high-performance cores at a base frequency above 5.7 GHz — extraordinarily fast by industry standards — with on-chip AI inference accelerators for in-transaction fraud detection, a dedicated data processing unit for I/O acceleration, and a large cache architecture. Full systems will scale to hundreds of cores and tens of terabytes of memory. “That’s really, really fast compared to what you otherwise get in the industry,” Jacobi said. “It’s just another example of how mainframe technology is not old technology. It’s very modern, leading-edge technology.”
Why the mainframe needed Arm’s 22 million developers
The strategic logic behind the chip is about software, not hardware. IBM’s s390x architecture runs an enormous share of the world’s mission-critical transactions, but the broader universe of enterprise software — monitoring tools, security agents, cloud-native middleware, and above all the AI stack of PyTorch, ONNX Runtime, and container workloads — was built for x86 and, increasingly, for Arm. By Arm’s own estimates, close to half of the compute shipped to major hyperscalers in 2025 was Arm-based, driven by AWS Graviton, Google Axion, and Microsoft’s Arm silicon. Arm counts more than 22 million developers worldwide.
Porting each application to s390x has been a grinding, one-ISV-at-a-time effort, and Tina Tarquinio, chief product officer for IBM Z and LinuxONE, described the calculus bluntly. “No matter how great our ecosystem team is, we would never be able to work with all of them and port them all,” she told VentureBeat. “There’s a lot of ISVs out there, and so we wanted to make a fundamental, big step-function forward. We took a swing from a technology point of view.”
Advertisement
Notably, she said customers weren’t asking for a dual-architecture chip per se — they were asking for outcomes. “I wouldn’t say our clients were saying, ‘Can you please make me a dual-architecture environment?’ But they were saying, ‘Help me get these surround workloads, or different types of workloads, to run in a quicker-to-market fashion.’”
The compatibility promise is ambitious: Arm Linux binaries should run unmodified. “The new Arm capabilities are designed to be 100% binary compatible,” Jacobi said. “Once you have, for example, Red Hat Linux for Arm, and you have applications that run on Red Hat Linux for Arm, they will run on the system without modifications.” Arm defines the instruction set architecture and supplies validation tooling to guarantee that IBM’s implementation behaves identically to every other Arm chip — while IBM designs and builds the silicon entirely in-house. “Very good partnership. Very solid engineering partnership as well,” Jacobi said of the collaboration.
What a next-generation Spyre accelerator means for enterprise AI on the mainframe
IBM is also previewing the next generation of its Spyre AI accelerator at Hot Chips, and the pairing is not coincidental. The current architecture already offers two tiers of AI: an on-processor accelerator, introduced with the Telum chip in 2022, that handles ultra-low-latency inference such as fraud scoring inside a payment transaction, and the Spyre accelerator card sitting in the I/O subsystem for heavier models.
The new Spyre raises the ceiling considerably. “We’re also bringing a much higher performance chip that is capable of running large language models for agentic workflows,” Jacobi said — both AI-ops workflows that administer the system itself and business workflows “for things like document understanding and insurance adjudication.” The new accelerator will ship with high-bandwidth memory to feed those models.
Advertisement
Here the dual-architecture bet and the AI bet converge. Enterprises want to run inference next to their data; the data lives on the mainframe; and the AI tooling is overwhelmingly Arm-native. Mohamed Awad, Arm’s executive vice president for cloud AI, framed the announcement in exactly those terms: “As AI scales, more of the computing landscape is converging on Arm. Bringing Arm compute and its software ecosystem to these platforms will extend that momentum into mission-critical enterprise infrastructure to give organizations greater choice in how they deploy AI.”
The timing tracks with where enterprise AI actually stands. McKinsey’s most recent State of AI survey found that while 88% of organizations now use AI in at least one business function, nearly two-thirds have not yet scaled it across the enterprise — and the companies capturing the most value are those redesigning core workflows rather than running detached pilots. For regulated industries whose systems of record sit on IBM Z, running AI where the transactions happen is arguably the most direct route to that kind of integration.
When the dual-architecture IBM Z system will ship — and why existing customers shouldn’t worry
Buyers will need patience. The chip will debut in the successor to the z17, which shipped in the second quarter of 2025, and IBM holds to a roughly three-year product cadence — pointing to a launch around 2028. But Tarquinio insisted the program is well past the concept stage. “It’s more than being on the drawing board. We’re full steam ahead on the whole system,” she said, adding that IBM will release more details in the run-up to launch.
For IBM’s installed base, the reflexive question is whether embracing Arm signals a slow sunset for the traditional architecture. Both executives pushed back hard. “This is a big and. It is not an or,” Tarquinio said. “I have a roadmap that goes out 10 or 15 years of hardware systems. Many of our teams are working on this next system; many are also working on the one after that, and the one after that.”
Advertisement
Jacobi cast the move as continuity rather than rupture. “The traditional mainframe that we have today as a z17 system is not just a faster version of what we built 25 years ago,” he said. “We didn’t have pervasive encryption capabilities. We didn’t have on-processor AI capabilities. Adding the Arm capability is the next big iteration in this continuous evolution.”
The competitive subtext is the cloud. Asked why an enterprise would run Arm workloads on a mainframe instead of a hyperscaler, Tarquinio pointed to the platform’s availability numbers: “We’re talking eight nines of availability — that’s 0.3 seconds of downtime a year. If you’re running your ledger, if you’re running your fraud detection, any of these mission-critical apps, you want that.” The pitch, she said, is fit for purpose: match the infrastructure to the SLA, not the fashion.
There are real caveats. IBM’s own press release notes that statements of future direction “represent goals and objectives only.” The Arm support is Linux-only for now, and the hardest engineering — running a foreign instruction set at production performance, with mainframe-grade fault detection and recovery, under real customer workloads — remains to be proven over the next two years.
But the ambition is unmistakable. For sixty years, the mainframe has survived every wave of technology that was supposed to kill it — minicomputers, client-server, the cloud — by absorbing what it needed from each. Now IBM is attempting its boldest act of absorption yet: teaching the machine that runs the world’s money to speak the language of the AI era, fluently and natively, on the same silicon. “Bringing something that’ll really be first of its kind in production,” Tarquinio said, “showcases again what IBM is capable of from a technology point of view.” The mainframe, it turns out, isn’t being left behind by the future. It’s learning to run it.
In the Thelonious Monk universe, I’ve noticed over the years a general perception among aficionados that the artist’s work diminished significantly later in his career. Personally, I have not found that to be accurate, as evidenced by the excellent 1968 Palo Alto concert that Impulse! Records issued several years ago. That notion comes to mind again while listening to an outstanding 1967 live concert recorded in Paris.
Monk Live in Paris 1967 (Volume One) marks the first in a series of official releases selected by Thelonious Sphere Monk III. This new release was sourced from digital remasters created in 2002 by the late, great audio engineer and producer Rudy Van Gelder, working from a pristine archival tape reel discovered in France. The recordings were restored at the time for the Monk Estate’s then-label, Thelonious Records, but unfortunately remained unreleased for more than 20 years.
These revelatory performances are finally being issued to the public on the Estate’s own terms. Portions of the recordings have circulated as bootlegs over the years.
For this performance, Monk’s classic mid-1960s quintet was expanded to a full nonet, adding several significant players, as documented in the album’s official press materials: “… it showcases Monk’s longstanding quartet featuring tenor man Charlie Rouse and the bass/drums tandem of Larry Gales and Ben Riley, who are joined by five very special guest horn men. Alto saxophonist Phil Woods, trombonist Jimmy Cleveland, Ray Copeland and tenor titan Johnny Griffin (Rouse’s predecessor in the quartet) perform in various permutations – with the full nonet, including trumpet legend Clark Terry…”
The 180-gram audiophile vinyl features disc mastering and lacquer cutting by Warren Defever of Third Man Mastering, with United Record Pressing handling the plating and pressing. The recording is also available as a digital download. You can order the vinyl now for about $30 from Amazon.
Advertisement
Pressed on translucent blue vinyl, the record is well centered and, happily, quite quiet. The album also includes a bonus insert with additional liner notes.
The band is swinging on Monk Live in Paris 1967 (Volume One) and, as far as I can tell, Monk seems to be having a great time taking the music into some interesting spaces. One of the standouts for me is trumpeter Ray Copeland, who launches into some joyful, soaring solo flights.
Thelonious Monk Signature inside the Hat
As an added bonus, the Monk Estate has partnered with luxury hatmaker Optimo to recreate a limited run of 88 hats, one for each key on a piano keyboard, like the one Thelonious Monk wore back in the day. Each hat comes with the first pressing of the recording, produced in a special edition color and signed by Thelonious Sphere Monk III and Optimo founder Graham Thompson. The hat is titled, simply, The Monk.
Part two of the concert is expected to be issued later this year, so as soon as we get our hands on it, I’ll be sure to follow up with a review. Can’t wait!
Advertisement. Scroll to continue reading.
Advertisement
Our Ratings:
★★★★★★★★★★ Music
★★★★★★★★★★ Sound Quality
★★★★★★★★★★ Packaging
Where to buy:
Mark Smotroff is a deep music enthusiast / collector who has also worked in entertainment oriented marketing communications for decades supporting the likes of DTS, Sega and many others. He reviews vinyl for Analog Planet and has written for Audiophile Review, Sound+Vision, Mix, EQ, etc. You can learn more about him at LinkedIn.
XPENG said on Monday that its robotics business has raised more than $900M in what the company described as its first funding round, a substantial sum for a unit that has yet to sell a single robot commercially.
The timing is deliberate, since the Chinese carmaker has committed to putting its IRON humanoid into mass production before the end of this year and is running out of calendar to do it in.
IRON was unveiled at XPENG’s AI Day in November 2025 and runs on the same Turing chips the company designed for its own electric vehicles. That shared silicon is the core of the pitch, alongside more than 60 joints, a spine with five degrees of freedom, and a layer of what XPENG calls bionic muscle fascia intended to soften the machine’s movement.
The robot demonstrated publicly is a seventh-generation prototype, with an eighth generation earmarked as the production model. Moreover, the company has said it wants full capability integrated before the production line starts, which is a considerable amount of engineering to compress into the remaining months of the year.
Advertisement
Deployment plans start close to home. The first units are expected to work as showroom assistants and tour guides, patrol XPENG campuses, and take positions on the company’s own factory floors, with commercial deliveries in China and abroad following in 2027.
Putting robots in your own dealerships is becoming a recognisable pattern in the Chinese car industry, with BYD already committing to a humanoid in every showroom. It has the useful property of generating deployment numbers without requiring a customer to be convinced first.
The longer-term target is a million units a year by 2030. He Xiaopeng, XPENG’s chief executive, has said the robots could eventually be priced at levels “very similar to car prices” within five years, and that software accounts for more than half the value of the machine from the first day it ships.
He has also taken personal charge of the division. In an internal note reported earlier this year, he wrote that the robot industry “is becoming increasingly hot and competitive, and we have clearly seen the direction and timing of victory, but it still requires more arduous implementation and extremely high decision-making ability”.
Advertisement
That reshuffle came alongside the departure of Shi Xiaoxin, the senior director of robotics product planning who had overseen the IRON project, which is not the sort of personnel change a company usually makes with a production deadline months away.
One point deserves care. XPENG Robotics, then known as Pengxing Intelligence, completed a $100mn Series A in July 2022, so the description of this as a first round most likely reflects a restructured entity rather than a first-ever raise, and XPENG has not published the investor list or a valuation for the new money.
The capital arrives in a market that has been repricing humanoid companies upwards for two years, with LimX Dynamics reaching a $2.2bn valuation before an IPO and Morgan Stanley doubling its forecast for Chinese humanoid shipments to 50,000 units. Against a million-a-year ambition, that industry-wide figure is a reminder of how early this all is.
Robotics also sits inside a wider reorientation at the company, which now describes itself as a physical AI business spanning humanoids, robotaxis, and flying vehicles rather than a carmaker with side projects. Each of those lines consumes capital on a scale that vehicle sales alone are not currently covering.
Advertisement
The car business is why the money matters, as XPENG reported a 17.6% revenue decline in the first quarter alongside widening net losses, having been profitable the quarter before, and management has been describing robotics, robotaxis, and flying vehicles as the eventual drivers of revenue and profit.
Raising outside capital for the robotics unit keeps that spending off the carmaker’s own balance sheet while the vehicle business works through a difficult year. Whether IRON reaches a production line before December is the question the $900M is meant to answer.
Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in some applications.
In a Windows release health alert seen by BleepingComputer, Microsoft says this known issue affects only apps that use the Windows Presentation Foundation (WPF) UI framework, an open-source graphical subsystem for building Windows desktop client applications.
“After installing the August 2026 .NET Framework cumulative update, some WPF applications may fail with a System.IO.FileFormatException when printing or generating PDF/XPS content that uses certain fonts, including Calibri,” Microsoft says.
The complete list of impacted platforms includes both Windows client releases (including the latest versions of Windows 10 and Windows 11) and Windows Server (from Windows Server 2012 up to Windows Server 2025).
Microsoft says it is still investigating the issue and, until it can ship a permanent solution, has provided a temporary fix to help affected users work around these printing problems.
Advertisement
This workaround requires enabling the Switch.MS.Internal.TtfDelta.DisableCmapAndSbitOverflowProtection AppContext switch in the application config file by adding the following:
However, the company warned that doing this will also disable protections introduced with the August 2026 .NET Framework update, exposing the system to attacks that could exploit vulnerabilities addressed by this month’s security updates.
“Microsoft recommends using this workaround only as a temporary measure and only when required to address this issue,” it warned.
Roughly five years ago, in February 2021, Microsoft addressed another known issue that caused WPF apps and Visual Studio to crash after installing Windows 10 cumulative updates.
Advertisement
On Friday, Microsoft also shared a temporary workaround for a known issue triggered by Windows 11 updates released during the August 2026 Patch Tuesday and causing games like ARC Raiders, MARVEL Tōkon: Fighting Souls, and The Finals to crash and freeze.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
You must be logged in to post a comment Login