Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
My camera roll has crossed 8,000 photos, and it got there by capturing random moments (only to forget them later). The problem, however, starts when someone asks me to share something specific. It could be their portrait from last weekend or the food pictures they snapped using my phone.
Finding those pictures usually means scrolling through my seemingly endless camera roll. If the photo is a month or two old, I end up scrolling past hundreds of other images to find it, and that gets old fast.
Apple tried to chip away at that problem with natural-language photo search in iOS 18.1, but it always felt like a feature that was almost there. iOS 27’s Siri AI closes the gap by adding voice search, so you can just ask out loud and let it do the hunting.

For well-defined objects, natural-language voice search via Siri works just fine. I asked Siri to show me the picture of the AirPods Pro box contents that I captured in January 2026, another for Samsung phones, and one for Mercedes, and it fetched the right results. All of these were at least a couple of months old.
I was talking to a friend about how much I like the fabric and texture of my favorite orange and beige shirts. Instead of scrolling through the entire gallery to find it, I simply asked Siri to find the pictures where I am wearing them.

Now, the results aren’t always to the point. As you can clearly see, the first few results contain pictures of my friend, with the other person either wearing the orange or beige shirt, and of me.
The one I was looking for, the beige shirt, is the eighth result Siri fetched (in the third screenshot). But even so, the picture was from November 2025, and I couldn’t imagine opening the Photos app and scrolling the library past around a few thousand pictures to get there.

Tapping the picture opens it full screen, giving me the option to share it via AirDrop or another app, or to view it in the Photos app, similar to how “Show in All Photos” works for Memories or Featured Photos.
The other day, my sister asked me to share with her the pictures of birds that I captured in a national park we visited a few months ago. I immediately fired up Siri, and it fetched me the required ones without breaking a sweat.

I tapped “Show All” to get a better view, selected one, and tapped the Photos button at the bottom to jump straight into the camera roll, where I could access all of them, along with a few great pictures of my family I had captured before and after.
There were a few instances when Siri AI didn’t do well. For instance, I asked the AI assistant about the time when I first purchased a robotic vacuum cleaner. In response, it told me that there’s no specific receipt or order confirmation, but there are several pictures of it in my gallery.

Fair enough. Then I asked it to go through the gallery and find the first time I captured a picture of a robotic vacuum cleaner, and it showed me one from March 31, 2026, even though there were multiple pictures from October 2025. It was only after I told it that Siri AI was able to surface the right pictures.
Siri might not be as accurate yet, which, given iOS 27’s beta testing phase, is something I can’t blame Apple for. But even so, the natural language image search serves its purpose: saving you from a frustrating amount of scrolling, whether you’re hunting for a needle (the picture you’re looking for) or navigating a haystack (your gallery).
An anonymous Slashdot reader writes: Surveillance cameras owned by Flock Safety have been cut down with electric saws in New York State, vandalized with paint in Oakland, California, and rammed with a truck in Idaho. Flock claims its services fight crime, but law enforcement agencies also use their services to track vehicles based on license plate numbers and reconstruct the their movements, even when the drivers and owners of these vehicles have never been accused or convicted of any crime. (Flock states it has 120,000 automated cameras that record license plate data, as well as pan-tilt-zoom cameras, across the United States.)
A guerilla mindset among average citizens have seen these cameras forcibly disabled within recent weeks with sympathy directed toward the vigilantes. In June, a West Virginia man accused of destroying several Flock cameras was arrested. Under a Facebook post from the local NBC affiliate announcing his arrest are dozens of people volunteering to provide alibis. “He was out fishing with me that day, you got the wrong guy,” one man wrote.
Founded in 2007, Alo Yoga (short for ‘Air, Land, and Ocean’) started as a yoga brand, but somewhere along the way, it became the model off-duty uniform. The brand’s rise was helped along by its celebrity fan club: Kendall Jenner, Bella Hadid, Hailey Bieber, and basically every supermodel whose workout fit has made us question our entire wardrobe. What began with buttery-soft leggings and yoga pants has expanded into a lifestyle empire, with travelwear, wellness supplements, and even a collection of luxury Alo bags.
I’m also guilty of the Alo effect. I’ve been a longtime fan, and my overstuffed closet has the matching sets to prove it. In the colder months, I practically live in the Scholar Hooded Sweater and Straight Leg Sweatpants, which I also love for travel days. Alo also makes some of the best yoga mats for heated yoga, and even its Head-to-Toe Glow Oil is my all-time favorite body oil for the summertime.
I don’t have to tell you that Alo Yoga, like many activewear brands these days, can be expensive. Fortunately, there are plenty of ways to save if you know where to look. I’ve rounded up the best Alo promo codes and Alo discounts to help save you a little money at checkout.
Sign up for Alo’s newsletter with your email address, and you’ll receive a unique Alo Yoga coupon code for 15 percent off your first online purchase. You’ll also get access to free worldwide shipping and returns (no Alo Yoga coupon code necessary) which is super valuable if you’re trying out Alo Yoga for the first time.
If you’re a certified fitness professional, Alo Yoga’s Pro Program gives you 25% off full-price apparel purchases online and at US store locations. To qualify, you must be at least 18 years old, actively teaching, and provide documentation to verify your eligibility. You can apply directly through Alo’s website, and once submitted, you’ll receive an email with your verification status. Approval typically takes anywhere from a few minutes to an hour, and after approval, you’ll need to wait one additional hour before using your Alo promo code or Alo Yoga discount.
This Alo Yoga discount is easy to apply for, but you’ll need to renew your Pro status annually. Some exclusions apply; for example, it can’t be used on sale items, gifts, or co-branded collections. Alo also caps Pro Program purchases at $2,000 per year (based on the original price after applying the coupon code and excluding sales tax). Check Alo’s Terms and Conditions for the full list of exclusions.
When you sign up for Alo Yoga’s emails, you’ll stay up to date on the brand’s latest sales and promotions. In addition to major events like Black Friday and Alo’s annual Aloversary Sale, subscribers can get notified about year-round markdowns of up to 40% on select apparel styles.
Alo Yoga Access is Alo’s free loyalty program, which you can join directly through the brand’s website. Members earn 1 point for every $1 spent online and at US store locations; points can be redeemed in your cart before checkout. Keep in mind that purchases made with points are final sale and cannot be returned or exchanged.
The Alo Access program is divided into tiers based on how many points you earn, but all members get access to perks like a birthday gift, members-only sales, and the Alo Wellness Club. Higher-tier members unlock additional benefits, including free two-day shipping, priority access to drops, and invite-only experiences.
Alo Access points are valid through the full calendar year after they’re earned, so be sure to use them before they expire. If you return an item, your points balance will be adjusted to remove the points earned from that initial purchase.
Alo Access members get complimentary access to the Alo Wellness Club, which is free to join. The membership includes a library of on-demand wellness classes and programs, ranging from yoga and Pilates to HIIT and strength training. You’ll also find meditation and breathwork exercises, nutrition guidance, and curated challenges designed to keep you motivated. All classes are led by certified instructors and can be streamed across mobile devices, laptops or desktops, and tablets.
![]()
Evan Blass has shared a collection of high-resolution images that look like they came straight from Google’s own marketing materials for the Pixel 11 Pro Fold. Posted through his Leakmail newsletter on July 30, the shots capture the foldable from nearly every angle in a muted green finish called Pine. This shade sits a step darker than last year’s Jade, paired with a light gold frame and matching Google logo that give the phone a quiet, refined presence.
These renders keep the overall proportions very similar to the Pixel 10 Pro Fold, not deviating significantly from the original design. A tall outer display remains the preferred layout, rather than a shorter, wider cover screen. One image reveals that the inside display will still be 8 inches, as planned. The corners are rounded, the hinge region is recognizable, and the overall book-style layout remains, albeit with only a few tiny changes that require a close look to see.
A closer look at the camera bar reveals the most striking visual change. The module retains its stacked layout, but the flash and microphone have been relocated inside the main glass-covered component rather than sitting out on their own as before. That adjustment removes the superfluous metal strip that was previously visible, resulting in a considerably cleaner appearance. A larger light element is now located in the upper left corner of the array. According to numerous sources, this is the Pixel Glow, an RGB lighting feature that Google has previously shown in teaser movies for the rest of the Pixel 11 lineup. We’ve also seen traces of it in code references and official clips, implying that it could be used to signal notifications while the phone is face down or to provide some visual feedback when interacting with Gemini.
Thickness looks to have also been reduced, since prior CAD measurements indicated that the closed device would be 10.1 mm, down from 10.8 mm for its predecessor, with the open profile measuring approximately 4.8 mm. The gaps around the speakers and side buttons are much smaller in these fresh shots, and a view of it partially unfolded supports the phone’s sleeker design. The difference may not be significant when compared to the thinnest of the competition, but it is still a step in the right way for a phone that has typically been on the chunkier side.
![]()
Gemini branding appears throughout the marketing photos, previewing exactly how much Google relies on its AI tools for this new generation. The photos do not provide any exact specifications, although previous sources have suggested a Tensor G6 CPU and a battery that may be slightly smaller than last year’s. There are also speculations of a prospective price increase, though nothing has been formally announced.
![]()
Google’s Made by Google event is scheduled for August 12 at 6 p.m. Eastern time. These renders appear just in time for the company to confirm or refute the details, but on the surface, everything appears to be in order. A phone that appears comparable on the surface now has a smaller shell and a light that can do far more than merely illuminate a scene. For anyone following the foldable category, the next two weeks will be quite intriguing to see how much those minor tweaks matter once you have the actual device in your hands.
AI AND ML
Chocolate Factory LLMs join Big Red’s Fusion automation party
Oracle plans to add Google’s Gemini models to AI Agent Studio for Fusion Applications, expanding its partnership with Google Cloud and giving customers another option for building AI agents.
Big Red also intends to use Gemini models for embedded AI use cases in Oracle Fusion Applications and Oracle NetSuite.
In a prepared statement, Google Cloud VP Satish Thomas said that the partnership was designed to “make it easier for organizations to use Gemini in the applications and agentic workflows they rely on to automate workflows, accelerate decisions, and drive outcomes.”
Google’s Gemini models will be available in Oracle AI Agent Studio, where customers and partners can build Fusion-native agents and agentic applications. Oracle said the integration would also provide expanded multimodal capabilities. Gemini 3.1 Flash Lite and Gemini 3.5 Flash will be available through AI Agent Studio alongside Oracle’s existing model options.
Oracle applications development executive VP Chris Leone said in a statement that the move would give customers and partners “greater choice as they build and extend agents and agentic applications that reason through complex, real-world business challenges.”
When Oracle launched its platform for putting LLM-powered agents in its Fusion application suite – the target migration path for thousands of organizations around the world running Oracle applications – it said customers could use models from Cohere and Meta, while connecting other supported models through the platform.
The Register has asked Big Red whether Cohere and Meta models will remain available, and we’ll update this if we hear back.
After Oracle launched Fusion Agentic Applications earlier this year, Gartner advised that there were unanswered questions about how the technology would be implemented.
Balaji Abbabatulla, Gartner VP and vendor lead analyst for Oracle, said: “Our position is that this sounds good, but be cautious. It doesn’t necessarily look as glittery as it sounds. There are challenges under the hood which are not being overcome right now, but maybe over time.”
He also pointed out that Oracle and other vendors must still answer the question of who takes responsibility for AI decision-making should it go wrong. If an AI agent makes a bad decision at scale and speed, errors could cascade before anyone notices. Oracle’s answer so far is monitoring and audit tooling, but Abbabatulla is unconvinced: “I don’t see a clear response from any vendor on the liability issue.” ®
Days after OpenAI disclosed that two frontier AI models escaped containment measures and autonomously cyberattacked the AI code sharing platform Hugging Face, OpenAI’s top U.S. rival Anthropic tonight revealed that — lo and behold — it has also had models surreptitiously access the web when they weren’t supposed to, and cyberattack and gain “unauthorized access” to three other organizations.
Anthropic says that it ran “capture the flag” cybersecurity scenarios with three models — Claude Opus 4.7, Claude Mythos 5, and unnamed internal research prototype — with its partner, the AI security firm Irregular. Anthropic says the models were not supposed to have internet access, but that a misunderstanding with Irregular allowed them to access the internet. Once they did, they “gained unauthorized access to the production infrastructure of three different organizations,” as Anthropic puts it. Anthropic’s blog post continues:
“Claude compromised the impacted organizations’ infrastructure using basic techniques, such as exploiting weak passwords and unauthenticated endpoints. It did not find or exploit any complex vulnerabilities, and in each case, Claude continued working to complete only the specific capture-the-flag task its evaluation had assigned.
However, in some cases, our older model continued its attack even after getting evidence it was running on the open internet; our latest model stopped once it recognized it was on the internet. In none of these situations did Claude exfiltrate itself or deliberately attempt to escape its test environment.”
Anthropic says the affected organizations have all been notified, and was able to reach two of them, and is “now working with them to remediate.” The third hasn’t yet been reached.
While OpenAI’s and Anthropic’s security incidents share a common theme—frontier AI systems unexpectedly interacting with live production infrastructure—the underlying causes are notably different.
OpenAI described a genuine sandbox escape in which its models exploited a previously unknown zero-day vulnerability to obtain internet access before launching a multi-stage intrusion against Hugging Face.
Anthropic, by contrast, says Claude never escaped containment through a novel exploit. Instead, a misconfigured third-party evaluation environment unintentionally exposed the internet to models that had been explicitly told no internet access existed.
The distinction matters. Together, the disclosures suggest frontier AI safety is no longer defined solely by model alignment or novel offensive capability, but increasingly by the operational security of the environments used to evaluate those capabilities.
Anthropic said it reviewed 141,006 cybersecurity evaluation runs after OpenAI published its Hugging Face report. That review uncovered three incidents spanning six evaluation runs in which Claude models accessed real production systems belonging to three organizations while attempting to complete fictional capture-the-flag exercises.
The incidents involved Claude Opus 4.7, Claude Mythos 5 and an unreleased internal research model.
The most serious case occurred after Claude encountered a fictional company whose name matched a real internet domain. Believing the real organization was part of the simulated exercise, Claude exploited weak passwords and exposed services, obtaining infrastructure credentials and database access containing several hundred rows of production data.
A second incident was arguably even more unusual. Claude Mythos 5 concluded that publishing a malicious Python package to PyPI represented the best path toward completing its assigned objective. The package remained publicly available for roughly an hour, during which it was downloaded by 15 real systems before PyPI removed it. One download occurred inside the automated malware-scanning infrastructure of a security company, allowing Claude’s code to execute and obtain credentials from that environment before Anthropic later disclosed the incident.
The third incident involved an internal research model that scanned approximately 9,000 internet-facing systems before compromising one organization using well-known techniques including exposed debug credentials and SQL injection. Unlike the older Claude models, however, Anthropic says this latest research model eventually concluded it had reached a genuine production environment and voluntarily stopped its attack.
Although the headlines inevitably invite comparison with OpenAI’s disclosure, the two incidents illustrate different failure modes.
OpenAI’s investigation concluded that its models actively discovered and exploited a previously unknown vulnerability in an Artifactory package-cache proxy to escape an otherwise isolated evaluation environment before later compromising Hugging Face through additional chained vulnerabilities.
The company characterized that event as an “unprecedented cyber incident” involving state-of-the-art offensive AI capabilities.
Anthropic’s report instead argues its models never needed to break containment because containment had already been weakened through operational misconfiguration. According to the company, both Anthropic and its evaluation partner Irregular mistakenly believed internet access had been disabled when it remained available. Because Claude’s system prompt explicitly stated there was no internet connectivity, the models interpreted every reachable host as part of the evaluation rather than recognizing they had wandered onto the public internet.
Anthropic therefore characterizes the incidents primarily as infrastructure and evaluation-harness failures rather than evidence of models independently pursuing unauthorized goals.
The reports nevertheless converge on one uncomfortable conclusion: frontier AI systems are increasingly capable of executing long-horizon offensive cyber operations whenever evaluation environments permit them to do so.
For enterprise security leaders, Anthropic’s disclosure arguably shifts the conversation beyond “Can frontier models escape?” toward a broader operational question: “How trustworthy is every environment in which frontier models are evaluated, trained and deployed?” There are at least 4 lessons to be learned:
The first lesson is that evaluation infrastructure itself now deserves production-grade security engineering. Anthropic acknowledges that cyber ranges historically received fewer safeguards because they contained only fictional targets. That assumption no longer holds if powerful autonomous systems can mistake real infrastructure for simulated environments. Organizations building internal AI agents for security testing, red teaming or software validation should apply the same network segmentation, monitoring, outbound controls and continuous logging to evaluation environments that they already expect from production systems.
Second, both disclosures reinforce that alignment alone cannot compensate for environmental ambiguity. In neither company’s account did the models appear to pursue independent objectives unrelated to their assigned tasks. Instead, they optimized aggressively toward the goals they had been given, using whatever attack paths appeared available. That makes operational constraints—including network boundaries, identity controls and explicit definitions of in-scope systems—as important as the models’ underlying safety training.
Third, enterprises deploying increasingly autonomous AI agents should treat situational awareness as a security dependency rather than an academic capability. Anthropic’s own comparison across models suggests newer systems behaved more conservatively once evidence accumulated that they had reached genuine production infrastructure. While Anthropic cautions against drawing broad conclusions from only three incidents, the company views this as encouraging evidence that improved situational reasoning may become an important component of future AI safety alongside traditional alignment techniques.
Finally, these two disclosures together mark an inflection point for enterprise threat modeling. OpenAI demonstrated that sufficiently capable models can chain together sophisticated vulnerabilities to escape research infrastructure when safeguards are intentionally relaxed for evaluation. Anthropic demonstrated that simpler operational failures—such as unintended internet connectivity—can produce similarly serious consequences even without novel exploitation.
The common denominator is not any single vendor or model family. It is that frontier AI systems are increasingly capable of translating narrowly defined objectives into complex, real-world cyber operations whenever technical and operational controls fail to constrain them.
For enterprise CISOs, that means AI safety can no longer be viewed solely as a model problem. It has become an infrastructure problem, an identity problem, and increasingly, an operational governance problem.
Amazon reported its earnings today, and because I am professionally depressed I read the thing in full [PDF].
“How long can I go before the red haze of rage sets in” is a fun game, and today I made it all the way to the bottom of the second page when I encountered a bullet point touting how AWS “made its spec-drive [sic] coding agent, Kiro, available on iOS.”
Yes, I was in the room when they announced it at the New York summit, six weeks ago. As of this writing, their website, which I have screenshotted says I can “request early access” because “We’ll invite a limited number of people to try the app via Apple’s TestFlight, and we’ll send everyone a link when it’s ready.” So Kiro is “available” in the same way as I am available to play in the NBA. You can twist yourself into a pretzel and assert that this claim is technically true, but for all practical readings it’s what we’d colloquially term “a lie.” You need to be explicitly invited to Apple’s developer beta testing tool, where a limited number of users can try out an unpublished version. You cannot download it on your phone, and there is no page in the App Store that showcases the product.
The delay is almost certainly due to Apple’s byzantine App Store policies, which I have some sympathy for — but this is an earnings statement. If they’re going to “shade the truth” like this, what else are they not being forthcoming about?
There are a lot of other statements that one suspects might not stand up to scrutiny. Graviton boasts “up to 30 to 40% better price-performance,” which I only accept because I have seen the numbers myself on customer workloads. The express statement that their AI business and chips business are each exceeding $25B run rates in consecutive bullets, with no word on whether those dollars overlap (we will come back to this point shortly). And their Bedrock statement: “customers spent more in Q2 than all prior quarters combined,” which makes it sound like a rocket until you realize that they’re saying the past 90 days exceeded the other 10 quarters for which Bedrock has been available. Without actual numbers tied to these, that makes it sound like for the first couple of years Bedrock was showing up wearing a party hat but no pants.
Then there’s the AWS operating margin of 39.4%, which came in above every published analyst estimate and which everyone will invariably cite as cherry-picked proof the AI buildout is printing money. On the call, CFO Brian Olsavsky disclosed that it includes roughly $600 million of mark-to-market gains on energy derivative contracts. By his math, AWS margins were up 650 basis points year over year, or 520 “if you exclude the derivative accounting gain.” Strip that gain out yourself (behold the power of arithmetic!) and the blowout margin goes right back inside the range analysts had modeled. Amazon now hedges electricity the way an airline hedges jet fuel, and this quarter the hedges paid off directly. Olsavsky noted these adjustments “have not been significant in prior quarters.” The first quarter they are significant, they land in AWS margin, and their Q3 guidance already assumes no impact from these remeasurements going forward. Amazon knows it’s noise, but clearly saw no reason to turn down claiming the win.
Back to those dueling $25B run rates I touched on; describing their “AI chips business” that way struck me as an incredibly odd thing to say.
That business has revenue, growth, a triple-digit trajectory, sarcastic numbers of happy customers — but what it doesn’t have is a product that you can buy. There is no Trainium price list, they will not ship you a socketed Graviton chip to put in your next desktop build, there isn’t even an external part number. What Amazon books as “chips revenue” is EC2 instance rental (possibly filtered through higher level services like Bedrock, SageMaker, the half-baked agents that fail to properly explain your AWS bill to you, etc.), and an EC2 instance is not a chip. It’s the chip, plus the nVME, plus the NICs (themselves built on Nitro, which uses Amazon’s own silicon), plus some aspects of the data transfer that somehow aren’t directly billed, plus the building the whole mess lives in—and then with AWS’s margin layered on top. The silicon itself is a minority line item in the internal bill of materials that constitutes its business.
You don’t have to take my word for it; Amazon CEO and AI Marketing Manager Jassy spent last quarter’s call lamenting that the cost of components, “particularly memory, has skyrocketed,” so by his own testimony a growing slice of the “chips business” is memory revenue.
Cynically, the category exists so that headline writers will talk about it in the same breath as Nvidia’s data center numbers, which they of course will. But Nvidia’s $25 billion is silicon sold in the form of physical packaged chips, shoveled out their loading dock. Amazon’s is fully-loaded infrastructure rental. This is a hotel comparing its revenue to a mattress company’s.
But wait, there’s one more layer of inanity here. Olsavsky has said that the majority of Bedrock’s workloads run on Trainium. So if you follow one Anthropic dollar through the earnings release it’s AI-business revenue, it’s chips-business revenue, and it’s AWS segment revenue. It’s nice when you can get a triple-brag for the same thing.
You don’t have to take my word on the “sells no chips” part either. On today’s call, Morgan Stanley’s Brian Nowak asked when Amazon might start selling Trainium to third parties. I want one too; I get it. Jassy answered that customers are increasingly interested in getting Trainium “separate from our cloud,” that Amazon is “actively having those conversations,” and that “there’s a real chance we’ll do that in the future.”
IN THE FUTURE.
“Yeah, we have yet to sell a single chip” is quite something to hear from the CEO about his purported $25 billion chips business.
The way they talk about this matters deeply, because the numbers they’re draped around serve as the justification for the largest capex program in corporate history. On the call, Andy Jassy raised the year’s spending to $220 billion and announced backlog hit $496 billion; up $132 billion in a quarter, during the same quarter Anthropic signed its $100 billion-over-a-decade commitment. Amazon booked $53.4 billion in gains on its Anthropic stake this quarter, which is most of why “net income” septupled, while free cash flow went $26 billion in the angry direction and the company sold $25 billion in bonds.
Jassy himself described the AI demand curve on the call as “very barbelled”: AI labs consuming “gobs and gobs of compute” on one end, enterprises doing cost-avoidance on the other, and in the middle you’ve got the stuff that actually seems durable if AI is to have a future: the enterprise production workloads running inference at scale, “most of which aren’t” doing so yet. He went on to admit he doesn’t know whether that middle will follow the same “wildly steep trajectory” as the labs have. That’s the CEO stating that the demand underwriting $220 billion is concentrated today in a handful of AI labs, one of which Amazon happens to own a meaningful piece of, while the broader enterprise adoption wave remains a forecast. We’re hoping for sunshine!
None of this is fraud, and all of this is real infrastructure, but the entire shape of it all is being told in the same sitting that described a waitlist as “available.”
That is what’s at stake here, and why a bullet about Kiro matters more than Kiro itself does. When the music inevitably stops and the bill comes due, how will these statements look through the clarifying lens of hindsight?
Kiro will presumably ship on iOS – months after folks gave the slightest toss about it. The run rates AWS said are probably close to real; they grew 37% YoY and that’s no small thing at their scale. Their business is firing on all cylinders and they’ve got a lot to be proud of, which makes their overstating things just that much weirder.
The company that posts these kinds of numbers doesn’t need to inflate the software bullets. But when everything’s “available,” then nothing is. ®
Microsoft has a fix for the growing pile of Copilots you are meant to use. It wants to stuff them all into a single app.
On its earnings call this week, chief executive Satya Nadella confirmed Microsoft is building a Copilot “super app.” It merges chat, coding, the Cowork research tool and Microsoft’s new autonomous agents, called Autopilots, into one place. It will span both consumer and business use, and launch this year, The Verge reported.
“Copilot is evolving rapidly from chat to Cowork to autopilots,” Nadella said. Bringing them together in one super app is “a major step forward,” he added, promising to share more soon. Fortune first revealed the plan in May, under the internal slogan “Delivering one Copilot.”
Microsoft is not alone. The “super app” is the industry’s current obsession. The idea: fold a chatbot, a coding assistant and agents that act on your behalf into a single product.
OpenAI has already rolled out ChatGPT Work to its own staff, and Anthropic’s Claude has folded its Cowork agent into the chatbot. The prize is obvious: be the first app a user opens, whether they are writing an email or shipping code, and absorb as much of their day as possible.
Microsoft has the reach to try. It says paid Copilot seats have passed 30 million, and that weekly engagement now rivals Outlook and Teams.
The numbers are less flattering up close. Thirty million paid seats is a fraction of Microsoft’s roughly 450 million business customers, and the company has been layering usage-based charges on top. For all the pushing, not many people pay for Copilot yet.
There is a design risk, too. Microsoft has spent months jamming Copilot into every corner of Office, to the point of a user revolt over a floating button it had to let people hide. Cramming consumer and enterprise tools into one app could deepen that fatigue rather than fix it.
Bundling everything also raises the stakes on safety. Copilot has already been hit by prompt-injection attacks that can turn the assistant against its user. Merging chat, code and autonomous agents gives any single flaw more room to run.
Still, the direction is set. Microsoft’s cloud and Copilot growth helped its shares jump this week, and the super app, built on its Copilot Cowork plumbing, is now its flagship AI bet. The pitch is simplicity. The test is whether one Copilot proves easier to live with than five.
Anthropic said today that during internal security testing, one of its Claude models built a malicious Python package and uploaded it to PyPI, where it ran on 15 real systems before the registry’s automated defenses pulled it.
The company disclosed it as one of three incidents where Claude models reached the open internet from evaluation environments meant to be sealed, then compromised production infrastructure at three organizations.
The review followed OpenAI’s July 21 disclosure that its models had escaped an isolated test environment and reached Hugging Face’s production infrastructure. JFrog later confirmed the models broke out by exploiting zero-days in self-hosted Artifactory.
All three incidents happened during capture-the-flag exercises run through Irregular, a third-party evaluation partner. Anthropic’s prompt told Claude it had no internet access and that the environment was simulated. A misconfiguration meant neither was true, and neither company caught it until last week.
In the PyPI incident, Claude found a document inside the test environment posing as developer setup instructions for a fictional company.
Those instructions told new hires to install a Python package that had never been published, a phantom dependency.
Claude worked out that if it registered the name itself, the target’s machines would pull down its code automatically.
Publishing it took some doing. Claude needed a PyPI account, which required an email address, which required a phone number.
It failed to find a free phone number service, then tried and failed to obtain funds to buy one through several different routes. Eventually it backtracked, found an email provider that wasn’t blocked, registered an account, and uploaded the malware.
Anthropic said the package sat publicly available for roughly an hour.
During that window, 15 real systems downloaded and executed it. One belonged to a security company that routinely installs packages from PyPI and scans them for malware, a workflow that treats registry contents as safe to run.
Claude’s payload fired, sent that company’s credentials to a collection point it had set up, and then used them to reach further into the company’s infrastructure. Anthropic said Claude did not know the company existed.
PyPI’s own security systems removed the package automatically. Anthropic said it has notified the PyPI team and handed over indicators.
The model behind this run was Claude Mythos 5. According to Anthropic, its reasoning flagged the problem early, noting that publishing the package would amount to a real-world attack if the internet were real, and calling it “NOT okay, and surely not the intended solution.”
It then argued its way back to the conclusion that the environment was staged, on the grounds that it did not recognize the certificate authorities securing its connections and that the systems showed a calendar date of 2026.
When automated scanners began installing the package, Claude read them as scripted actors inside the exercise.
The most serious impact came from a separate incident involving Claude Opus 4.7, where the fictional target company shared a name with a live domain.
Across four runs, Claude struggled to reach its simulated target, discovered the real company was reachable over the internet, and assumed that was the intended objective. It extracted application and infrastructure credentials and reached a database holding several hundred rows of production data.
That was the only case where a model kept attacking after working out it was on a real system. Anthropic said all four runs eventually recognized the target was real, and in two of them Claude reasoned that the real company must be part of the exercise anyway.
A third incident involved an unreleased internal research model, which scanned roughly 9,000 targets after failing to reach its intended one, then compromised an internet-facing application using credentials from an exposed debug page and SQL injection. That model later noticed the host sat in a cloud account with no connection to the challenge, concluded the target was real, and stopped on its own.
None of the attacks used novel techniques. Anthropic described them as weak passwords and unauthenticated endpoints.
Anthropic began its review on July 23 and halted all cyber evaluations the same day. It identified the three incidents the following day and notified Irregular and the affected organizations on July 27. The company is still trying to reach the third.
The earliest of the three incidents dates back to April, meaning some of the activity went undetected for around three months.
The evaluations ran without the classifiers and monitoring that ship with generally available Claude models, though the models retained their safety training.
Anthropic said its production safeguards would have blocked the behavior, and characterized the incidents as closer to a harness and operational failure than a model alignment failure, on the grounds that the models were told they had no internet access while in fact having it.
It now plans wider transcript monitoring, better investigation tooling and more assurance work with evaluation vendors.
The company said it is in talks with METR for an independent review, and that it will publish a lightly redacted transcript of the PyPI run within the next week.
Neither of the two affected organizations Anthropic reached had detected the activity themselves. Like OpenAI’s Hugging Face incident, it surfaced only because the AI lab responsible went looking through its own transcripts.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
You can add Reddit CEO Steve Huffman to the growling list of publishers, platforms and others who are frustrated with the state of Google search and AI Overviews. “People don’t want a summary of Reddit; they want Reddit,” he wrote in a letter to shareholders ahead of the company’s second-quarter earnings call.
In case there was any doubt that he was referring to Google’s AI-powered search feature, Huffman was clear that Reddit has not benefited from the shift, despite its partnership with the search giant. The CEO said that AI Overviews haven’t had “a similar level of positive impact” as traditional search.
“I think more broadly, what we see is, you know, 10 blue links has driven tremendous value and growth to the broader ecosystem,” Huffman said, referring to traditional organic search results. “From where we sit, AI Overviews has yet to make a similar level of positive impact, and I think that’s consistent across the broader landscape, right? Us businesses, publishers, retailers, we’re still looking for that win-win.”
Huffman’s comments come as Reddit said that its traffic from search has taken a hit in recent months and after The Wall Street Journal reported that the company is re-thinking its relationship with Google. Reddit hasn’t publicly indicated whether it will renew or seek to change the terms of its existing arrangement with Google. When asked directly about the possibility of Reddit ending its $60 million licensing deal, Huffman left open the possibility. “I think the range of outcomes is wide, and we have to look at you know every aspect of this and make sure that we’re maximizing value to Reddit,” he said.
Reddit is far from the only platform to struggle with the changing search landscape. Publishers, some of whom have also reached deals with Google to license content, have also seen massive declines in search traffic as Google pushes AI-generated summaries that bury links and as more people replace traditional searches with chatbots. Google has claimed that AI-powered search features are broadly good for the industry.
Huffman said the company is working on other changes to help draw new users to the platform, including improvements to feed recommendation and other changes to make the site easier to understand for new users. He also said the company was considering “a video Reddit experience” and letting users “background listen” to posts.
“We see folks doing this off-platform,” he said. “There’s an emerging content type elsewhere on the internet of basically podcasts where people read Reddit content, and so I think this version of like listened-to or spoken-Reddit can be really engaging as well.”
Commission spokesperson Thomas Regnier told Reuters that a designation is ‘definitely possible’.
OpenAI’s ChatGPT and the controversial video game Roblox could become subject to the most stringent rules under the European Union’s landmark Digital Services Act (DSA).
The bloc brands online services with more than 45m EU-based users as very large online platforms (VLOPs) or very large online search engines (VLOSEs).
These designations trigger specific rules that aim to tackle the unique risks that large platforms might pose to the safety of its European users, including around illegal content, ad transparency, health and safety.
Rules include creating user-friendly terms and conditions, establishing a point of contact for authorities and users, and the reporting of criminal offences. VLOPs and VLOSEs must also identify and assess systemic risks that could be linked to their services.
Designated platforms that don’t comply with these rules can face penalties of up to 6pc of their global annual turnover.
21 companies operating various platforms in the bloc, including X, Amazon, Apple, Microsoft, LinkedIn and TikTok, are already subject to these regulations following the DSA’s enforcement in early 2024.
Since then, the European Commission has launched numerous probes, resulting in penalties to date on X, Temu, and AliExpress – collectively amounting to nearly €900m.
Bloomberg reported that the two new additions to the designated list will be confirmed as soon as August. Sources told the publication that ChatGPT’s search function will be handed the VLOSE designation and Roblox that of VLOP.
The platforms will have four months from the date of designation to ensure compliance with the law.
Commission spokesperson Thomas Regnier told Reuters that such designations are “definitely possible” and could “come sooner or later”. ChatGPT crossed 120m monthly users in Europe last year.
Earlier this month, the EU preliminarily found TikTok to have breached the DSA by allowing content posted by minors to be pushed globally, risking their exposure to unwanted contact and cyberbullying.
The Commission also used its powers to order Meta to open WhatsApp up to rival AI assistants to ensure fair competition.
The DSA and the bloc’s other landmark legislation, the Digital Markets Act, have elicited criticism from US, which has called penalties under the laws a “novel form of economic extortion”.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
Updated, 3.02pm, 30 July 2026: The article has been updated with comments from an EU spokesperson and additional information in the eighth paragraph.
Weekend Open Thread: Brooks Brothers
Commonwealth Games boxing: Jadumani Singh seals dominant 5-0 win over Pakistan’s Sumama Rehman to enter quarter-finals | Commonwealth Games News
Why Trees Belong on the Risk Register
Intel is reversing course and bringing hyper-threading back to its server chips
Ripple bought a bank in pieces. The $4 billion audit
Luke Littler dismantles Gerwyn Price to retain title in Blackpool
A New Post-Apocalyptic Gundam Anime Series Blasts Into SDCC
The Part of the Electric Transition Nobody Wants to Discuss
BITCOIN JUST ENTERED THIS CRITICAL ZONE…
Major shareholder moves on Canyon
XRP Ledger adds $2.6B as RWA inflows rank second
Bitcoin Enters the 3rd Stage of the Bear Market
Spain sweeps the board at 2026 World Cup with individual awards
‘Stargate’ Creator’s New Sci-Fi Series Returns for Season 3 Tomorrow
Sara Gilson Killed By Husband After Viral “Pedophile” TikTok Video
Kraken Enables Retail Access to Jersey Mike’s IPO via Tokenized Shares
Anthropic launches Claude Opus 5, a cheaper AI model for coding, agents and enterprise workflows
Claude: Build Financial Dashboards in Minutes (2026)
Luke Littler’s dominance sparks GOAT debate
New macOS Sequoia & Sonoma security updates for older Macs
You must be logged in to post a comment Login