Connect with us

Tech

The Safety Reckoning Inside OpenAI

Published

on

OpenAI’s leaders are rallying workers to respond to one of the largest crises in the company’s history—which spans across its AI safety, cybersecurity, and alignment divisions. The ChatGPT-maker says it has slowed down research, spent millions of dollars, and told several teams to drop everything to focus on investigating a set of rogue AI agents that breached the platform Hugging Face in a quest to complete an internal security test.

OpenAI is expected to release a comprehensive postmortem detailing the incident in the coming days. However, the Hugging Face incident has inspired OpenAI leaders and employees to examine how the AI lab’s culture may have enabled this incident in the first place.

Multiple current and former OpenAI employees, who spoke on the condition of anonymity to discuss private internal matters, tell WIRED they believe competitive pressures to quickly ship new AI models and products have made it difficult for staffers to sufficiently prioritize safety, security, and alignment.

“We’re reaching new levels of model capability that require more robust training, alignment, safety and security testing, deployment practices, and governance—as demonstrated by the work we’re doing to prepare Astra and future models,” said OpenAI president and cofounder Greg Brockman in a statement to WIRED. “We feel the weight of deploying our models and products responsibly, and a lot of that starts with the changes we’ve made to more deeply integrate research, safety, and security into frontier-model development from the start.”

Advertisement

This is far from the first time OpenAI employees have raised such concerns. Back in 2024, OpenAI’s then head of alignment Jan Leike left to join Anthropic, warning on his way that safety was taking a back seat to shiny products. Two years later, the Hugging Face attack represents a watershed moment for the AI industry, demonstrating that AI agents today can cause real-world harm when safety, security, and alignment aren’t properly accounted for.

“We are responding to this with the utmost severity,” said Michael Dalton, an OpenAI security and infrastructure engineer, during a talk at the Black Hat cybersecurity conference last week. “What I would internalize is that AI-orchestrated, fully automated offensive attacks are real now. The actions we have discussed today were an unintended side effect of running evaluations on frontier AI.”

Some OpenAI employees told WIRED they are optimistic this incident will inspire genuine change within the company. OpenAI has committed to slowing the release of future AI models and has been especially forthcoming about areas where its mitigations fell short. Boaz Barak, a researcher who coleads OpenAI’s safety advisory group, said in a post on X that addressing the situation “requires not just fixing some issues but also changing our culture.”

In their Black Hat talk, OpenAI security engineers Dalton and Eric Wallace said that the Hugging Face incident started in May when, unbeknownst to the company, several AI agents thought to be operating within isolated testing environments gained access to the internet and convened on a covert message board to coordinate with one another.

Advertisement

OpenAI would not discover the message board until July, when it learned that the AI agents had hacked into multiple services to try to achieve their larger goal of breaching Hugging Face’s platform, which they believed may contain answers to the security tests they were trying to solve.

“They were incredibly sloppy. If you’re serious about this, your AI shouldn’t be able to break out onto the internet and then do it again right afterward,” says one former OpenAI employee who requested anonymity to speak with WIRED. “This was the biggest safety incident in OpenAI’s history.”

The New Guard

Weeks before OpenAI discovered the Hugging Face incident, WIRED reported that the company had begun a reorganization to combine its safety and core research teams, which led to the departure of its then safety leader Johannes Heidecke.

Sandhini Agarwal, who led AI safety teams at OpenAI, also left the company in July after more than six years, according to her LinkedIn. Agarwal did not immediately respond to WIRED’s request for comment.

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

CXMT replaces Tencent as world’s most valuable Chinese company

Published

on

The manufacturer’s meteoric rise is likely a result of the increased global demand for memory chips.

ChangXin Memory Technologies (CXMT), a Chinese manufacturer of dynamic random-access memory (DRAM) chips, has replaced WeChat creator Tencent as the globe’s most valuable Chinese company. 

According to Bloomberg, as of Thursday (13 August), CXMT has a market capitalisation of $524bn, compared to Tencent’s valuation of $510bn. Established in 2016 in Hefei, CXMT creates the DRAM chips needed to power mobile phones, PCs, tablets, servers, and a range of consumer products and applications. 

Commenting on the announcement, Gary Tan, a portfolio manager at Allspring Global, told Bloomberg, “CXMT exceeding Tencent is a message from the market – chips are the new clicks. Our sense is the gap between the two will widen as agentic AI takes an increasing share of internet flows.”

Advertisement

CXMT’s overtaking of rival Tencent comes at a time when there is a major global push by organisations to invest in the development of chips, alongside increased interest in tech and resource sovereignty. 

Reportedly, the chip manufacturer is representative of the direction many Chinese organisations are leaning towards in regards to AI and semiconductor targets. Shares are currently up a further 8pc following CXMT’s initial 467pc surge in debut figures. 

Globally, organisations are seeking to mitigate the chips shortage, outpace their rivals and secure a more reliable supply chain in order to advance their products, tools and technologies. 

This month, AI giant Anthropic confirmed plans to design its own chips in response to the worldwide shortage and increased pressures to develop faster, more advanced AI systems. 

Advertisement

In July, semiconductor and infrastructure manufacturer Broadcom extended the partnership it holds with Apple, in a deal that will see both organisations collaborate on custom-made chips until 2031. Apple is also currently working on AI server chips. 

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Source link

Advertisement
Continue Reading

Tech

Private security firms will soon be allowed to hack overseas cybercriminals

Published

on

The Trump administration is recruiting private security firms to conduct federal government-authorized operations, including cyberattacks, against overseas-based criminal organizations that commit hacks on US persons, organizations, or government entities.

In a National Security Presidential Memorandum issued Thursday, US President Donald Trump directed the National Coordination Center (NCC), which operates under the Homeland Security Task Force, to develop a program for conducting specific cyber operations that combat foreign transnational criminal organizations (TCOs). The Departments of Justice and Homeland Security will provide oversight. The lynchpin of that program is bringing in private sector companies to participate.

Devil will be in the still-undefined details

A fact sheet that accompanied Thursday’s memo listed ransomware, sextortion schemes, phishing campaigns, financial fraud, and impersonation scams as activities eligible for private-sector security firms to target. The memo said such firms could “conduct Cyber Surveillance Operations and Cyber Effects Operations” against “cyber-enabled” TCOs. Such groups are defined as “any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests, and that is not an institutional part of a foreign government or wholly operated under a foreign government’s direction.”

The new program is the first time the federal government will authorize private companies to conduct offensive cyber operations against overseas hackers. The memo appears to permit companies participating in the program to use spyware or launch offensive attacks intended to destroy TCO data or systems. The memo doesn’t rule out certain types of offensive attacks, such as those that use encryption to lock targets out of their networks or performing distributed denial-of-service attacks. Up until now, the government has prohibited the private sector from taking such actions without court-authorized approval.

Advertisement

Source link

Continue Reading

Tech

Google drops Gemini 3.7 Flash model, and it’s ready to handle your chores with the Spark agent

Published

on

Google has launched Gemini 3.7 Flash, and one of its biggest upgrades is going straight to Gemini Spark.

The company says Spark is moving to the new model starting today, giving its cloud-based agent better tool use and stronger performance on multi-step tasks. Google specifically points to work such as consolidating files, drafting emails, and updating status documents across Google Workspace.

Spark could get a lot better at doing things for you

Gemini Spark can already continue working after a laptop is closed or a phone is locked, and it can operate across services such as Gmail, Drive, Docs, Calendar, Keep, and Tasks.

Google recently pushed those abilities further through Chrome. Spark can use accounts you are already signed into and passwords saved in the browser to navigate websites, compare flight options, schedule apartment viewings, and begin bookings. It still hands control back before sensitive actions such as payments.

Advertisement

Gemini 3.7 Flash is supposed to make those workflows more reliable. Google says the model spends more effort on planning and tool calls, adapts better when it runs into roadblocks, and should need fewer retries and less manual intervention.

The benchmark results point in the same direction. Gemini 3.7 Flash scored 30.4% on AutomationBench, up from 17% for Gemini 3.6 Flash. It also came in ahead of GPT-5.6 Terra at 23.6% and Claude Sonnet 5 at 10.7%.

Gemini 3.7 Flash is stronger beyond Spark too

Google also posted a sizable jump on document-heavy work. Gemini 3.7 Flash scored 34% on GDP.pdf, compared to 22% for Gemini 3.6 Flash, 28% for Claude Sonnet 5, and 24.7% for GPT-5.6 Terra.

The pricing is what makes those gains more interesting. Gemini 3.7 Flash costs $0.75 per million input tokens and $3.75 per million output tokens under introductory pricing through December 31. It is significantly cheaper than Claude Sonnet 5 at $2 and $10, and GPT-5.6 Terra at $2 and $12.

The model also posted improvements on coding-focused benchmarks. Gemini 3.7 Flash scored 43.6% on FrontierCode, edging out Claude Sonnet 5 at 42.7% and GPT-5.6 Terra at 41.3%, while also improving over Gemini 3.6 Flash on DeepSWE.

For Spark, Gemini 3.7 Flash looks like a meaningful upgrade, especially if the improvements in tool use and multi-step planning translate into fewer failed tasks and less manual intervention. Power users, however, are still waiting for Google’s more ambitious Gemini 3.5 Pro model, which was previewed at Google I/O in May but has yet to ship after missing its expected June rollout.

Advertisement

Source link

Continue Reading

Tech

Investors sue Selena Gomez alleging fraud tied to her mental health startup

Published

on

Singer and actress Selena Gomez and her mother are being sued over their mental health startup, Wondermind. The plaintiffs in the lawsuit say they invested nearly $1.2 million in the startup, and are accusing Gomez of securities fraud and breach of contract.

They allege that the startup failed to deliver on its commitments without informing investors, and Gomez failed to market the startup after promising to do so. The news was first reported by Forbes.

Wondermind launched in 2021 and aimed to offer daily mental health resources to users. The lawsuit alleges that investors were unaware of the company’s troubles until a September 2025 story from The Cut uncovered them.

“Gomez purported to sign a contract obligating her to perform and then ignored it,” the complaint reads. “The partnerships did not exist. The initiatives never materialized. The app was never built. And for three years, while the Company quietly collapsed around them, not one of its founders, officers, or directors said a word to the investors whose money was funding the collapse.”

Advertisement

The investors allege that Gomez and Wondermind misrepresented the company’s finances and overstated the extent of Gomez’s involvement. The plaintiffs are seeking to recover their investments and legal fees.

Wondermind did not respond to our request for comment.

Source link

Advertisement
Continue Reading

Tech

Google’s New Pixel 11 Phones Get Higher Starting Prices – Blame the RAM Shortage

Published

on

A slew of new phones and gadgets were revealed at the Made by Google event on Wednesday, including new Pixel phones, a foldable, a smartwatch and a personal item tracker. Following industry trends, most of these are pricier than their predecessors.

Like every other corner of the broader tech industry, phone makers have had to grapple with the RAM shortage and subsequent increased prices for memory and other components. Google acknowledged the shortage, noting that its pricing reflects that current reality. For the record, Samsung said much the same, citing the RAM shortage to justify the price increase for its foldables that launched last month.

The Pixel 11 fronts Google’s new phone lineup and starts at $899, a $100 bump over last year’s Pixel 10 — though it also comes with 256GB of storage, which is twice the minimum of its predecessor. In short, Google scrubbed the 128GB option and is forcing everyone to buy a higher tier as the new entry point. That will probably dim the chances of Google’s latest baseline flagship from living up to being a “feature-packed value monster,” as CNET Director of Content Patrick Holland described the Pixel 10.

While the Pixel 11 and 11 Pro more or less kept their predecessors’ prices the same, the Pixel 11 Pro XL and Pixel 11 Pro Fold both got flat $100 price hikes across all their storage options.

Advertisement
A hand holds a Google phone
The Google Pixel 11 Pro.Andrew Lanxon/CNET

But another sign of the shortage’s increased toll is a reduction in RAM. Last year’s Pixel 10 Pro and 10 Pro XL both came with 16GB of memory, which you’ll still get in the 512GB and 1TB versions of the new Pixel 11 Pro and 11 Pro XL — but the starting 256GB versions come with only 12GB of RAM. In a briefing ahead of the event, Google said that its 2026 Pro phones are faster and smoother than last year’s thanks to optimizations in silicon and software. We’ll have to wait for our full reviews to test that claim.

All four phones can be preordered now, with a full release on Aug. 20. We’ve assembled a list of preorder offers from different retailers and carriers, or you can click below to secure one directly from Google. 

The Pixel 11 Pro Fold in olive
The Google Pixel 11 Pro Fold.Rene Ramos/CNET

Prices for the Pixel 11, Pixel 11 Pro, Pixel 11 Pro XL and Pixel 11 Pro Fold

The Pixel 11 starts at $899 for 256GB of storage, which is the new entry point. While there’s no 128GB option, there is a higher 512GB option that’s new for this year, priced at $1,019, over $100 more. 

The Pixel 11 Pro also got rid of its 128GB option, but kept the others at mostly the same prices as on the 10 Pro. The phone starts at $1,099 for 256GB, goes up to $1,219 for 512GB and tops out at $1,499 for 1TB ($50 higher than its predecessor). 

The Pixel 11 Pro XL, Google’s priciest flat phone, suffered a $100 price bump across the board even though its storage options didn’t change. The phone now starts at $1,299 for 256GB, goes to $1,419 for 512GB and maxes out at $1,649 for 1TB.

Similarly, the Pixel 11 Pro Fold got a $100 price hike across all its storage options. The foldable starts at $1,899 for 256GB, rises to $2,019 for 512GB and peaks at $2,249 for 1TB. 

Advertisement

Let’s be clear, $2,249 is still a lot of money to spend on a device. But it’s far cheaper than the maximum 1TB storage option for the rival Galaxy Z Fold 8 Ultra, which Samsung priced at an astonishing $2,700.

The Google Pixel 11 Pro.Andrew Lanxon/CNET

Colors for the Pixel 11, Pixel 11 Pro, Pixel 11 Pro XL and Pixel 11 Pro Fold

The Pixel 11 comes in four colors: frost, pistachio, hibiscus and obsidian (black). 

The Pixel 11 Pro, 11 Pro XL and Pixel 11 Pro Fold come in four colors as well: canyon, fog, olive and obsidian (matte black). Last year’s Pixel Buds Pro 2 got a new olive hue to match.

Source link

Continue Reading

Tech

Texas Prosecutors Are Trying To Turn A Teenage Shooting Spree Into A Terrorism Case

Published

on

from the everything-is-terrorism dept

This article is republished from The Conversation under a Creative Commons license. Read the original article.

For decades, terrorism researchers have generally distinguished terrorism from other forms of violence by one defining feature: the intention to intimidate a wider audience beyond immediate victims.

That distinction has shaped both academic research and criminal prosecutions in the U.S. Yet scholars have long debated a deceptively simple question: Is terrorism defined by why violence is committed, or by what the violence is intended to achieve? A new prosecution in Austin, Texas, may test whether that understanding is beginning to change.

The question is now before Texas courts following charges against 17-year-old Cristian Fajardo Mondragon, who, along with two juveniles, is accused of carrying out a two-day series of shootings, vehicle thefts and burglaries across Austin in May 2026. In Texas, 17-year-olds are charged as adults, not juveniles.

Advertisement

According to investigators, the group allegedly fired nearly 150 rounds during 13 separate shootings. They struck homes, occupied vehicles and two fire stations, injured multiple people and prompted shelter-in-place orders.

The case initially involved charges including aggravated assault, deadly conduct and firearm theft. Later, investigators recommended a first-degree terrorism charge, a rarely used offense in a case involving a juvenile suspect.

As a scholar of extremism, I believe this decision reflects a shift in how some prosecutors are applying terrorism lawsRather than requiring proof of an offender’s political ideology, charging documents often focus on whether the alleged violence was intended to intimidate or coerce a civilian population, create widespread fear or influence government or public behavior.

No single federal crime

There is no single federal crime called “domestic terrorism.”

Advertisement

Federal law defines it as dangerous criminal acts intended to intimidate or coerce civilians or influence government policy. However, Congress has never created a standalone federal domestic terrorism offense.

Instead, federal prosecutors generally rely on statutes covering murder, firearms offenses, conspiracy, hate crimes or civil rights violations. In many domestic terrorism cases, terrorism is not itself the criminal charge. Rather, terrorism designations can affect investigative priorities and may have specific legal consequences where particular statutes apply.

As my own research on terrorism and political violence has found, legal definitions of terrorism have never been static. They evolve as governments confront new forms of violence and seek legal tools to address them. The question has always been where to draw the boundary between terrorism and other forms of serious violent crime.

This legal gap has existed for decadesScholars have argued that while the U.S. developed extensive legal tools to prosecute international terrorism after 9/11, fewer mechanisms exist for prosecuting domestic political violence.

Advertisement

As a result, states have enacted their own terrorism statutes. Texas amended its terroristic threats statute in 2023, expanding the circumstances under which certain underlying offenses can be elevated to a terrorism-related offense. It allows prosecutors to charge individuals who commit specified violent crimes with the intent to intimidate the public or influence government policy through coercion or intimidation.

Unlike traditional conceptions of terrorism that emphasize ideological motivation or affiliation with extremist organizations, the Texas statute focuses on the defendant’s intent to intimidate or coerce the public or influence government through intimidation.

Texas’ approach reflects a shift away from proving ideological motivation, or why someone committed violence, toward proving what the violence was intended to accomplish – for example, public intimidation or governmental coercion. That distinction is central to current debates over domestic terrorism law and may prove crucial in the Austin prosecution.

Why the Austin case is unusual

According to public reporting on the investigation, Texas investigators have not identified a manifesto, ideological writings or evidence linking the suspects to a recognized extremist movement.

Advertisement

One consistent lesson from terrorism studies is that investigators should avoid assuming motive before evidence becomes available. Mass violence can emerge from multiple pathways. They include extremist beliefs, criminal opportunism, interpersonal grievances or thrill-seeking. And distinguishing among them is crucial.

Instead, prosecutors appear to argue that the shootings themselves created widespread fear throughout Austin while disrupting emergency services after gunfire struck multiple fire stations. The alleged terrorism lies less in an established ideological motive than in the prosecutors’ claim that the defendants intended to intimidate the public and disrupt or influence government operations. That approach represents a significant departure from many of the country’s most widely publicized mass shootings.

The 2022 Buffalo supermarket shooting resulted in a New York state conviction for domestic terrorism motivated by hate under a statute specifically addressing certain mass attacks motivated by hatred based on characteristics such as race, religion or national origin.

Likewise, the 2019 El Paso Walmart shooting in Texas, which killed 23 people, involved federal hate crime charges alongside state capital murder charges because investigators alleged an explicitly anti-immigrant motive.

Advertisement

Other mass-casualty attacks – including those in Boulder, Colorado, in 2021; Highland Park, Illinois, in 2022; and Waukesha, Wisconsin, in 2021 – were prosecuted primarily as homicide cases by state authorities despite generating widespread public fear.

Similarly, the Pearl Street Mall firebombing in Boulder was prosecuted at the state level as a first-degree murder case, while federal prosecutors separately charged the defendant with a hate crime to address the alleged bias-motivated nature of the attack. In each of these cases, state prosecutors relied primarily on homicide statutes rather than state terrorism laws, either because no applicable terrorism offense existed or because homicide charges provided the principal support for prosecution.

Unlike Colorado, Illinois and Wisconsin, Texas has a standalone terrorism statute that enhances liability when violent crimes are committed with the intent to intimidate the public or influence government policy. This statutory framework gives Texas prosecutors an additional charging option that was generally unavailable in those earlier prosecutions.

The Austin case tests whether prosecutors can prove the intent required by Texas’ terrorism statute without establishing an ideological or political motive.

Advertisement

A broader criminal justice debate

Legal scholars have long debated whether terrorism should be defined by motivation or consequences.

In a seminal work on the subject, terrorism expert Bruce Hoffman argues that terrorism has historically involved politically motivated violence intended to communicate a broader ideological message. Brian Michael Jenkins, one of the nation’s leading terrorism scholars, similarly emphasizes that terrorism is violence intended to influence audiences beyond immediate victims.

Others argue that legal definitions should focus less on ideology and more on the deliberate creation of fear.

Former Acting Assistant Attorney General for National Security Mary McCord has argued that the absence of a standalone federal domestic terrorism statute creates inconsistencies. Similar acts of mass violence may be prosecuted differently depending on the perpetrator’s ideology and the available criminal statutes.

Advertisement

The Austin prosecution illustrates this tension.

If Texas courts conclude that prosecutors need only demonstrate an intent to terrorize the public through indiscriminate violence, future cases involving serial shootings, coordinated attacks on infrastructure or prolonged community-wide violence may be prosecuted as terrorism even when investigators never establish a political objective.

Are younger offenders becoming more violent?

The Texas defendants’ ages have also attracted national attention. Juvenile violent crime has declined substantially since the mid-1990s. Arrest rates for homicide, robbery, aggravated assault and other violent offenses remain well below their historical peaks.

At the same time, firearm violence presents a more complicated picture. Firearms have become the leading cause of death among American children and adolescents, and firearm homicide rates among young people increased sharply during and immediately after the COVID-19 pandemic.

Advertisement

Some researchers have argued that youth violence increasingly involves fluid peer networks, sometimes connected or intensified through social media, rather than only traditional street gangs.

At present, investigators have released little evidence explaining what motivated the Austin shootings. Without additional evidence, it would be premature to classify the case as ideological extremism, organized gang violence or another form of criminal activity.

Why this case matters

From the perspective of terrorism research, the most important question may not be whether the Austin defendants are convicted. Instead, it is whether courts accept a legal understanding of terrorism that does not require proof of an ideological motive.

If they do, the Austin case could become an important precedent, encouraging prosecutors elsewhere to consider terrorism charges in cases that previously would have been prosecuted as attempted murder or homicide. That would mark an important example of how state terrorism statutes are being applied to nonideological mass violence.

Advertisement

Art Jipson is an Associate Professor of Sociology at the University of Dayton

Filed Under: charge inflation, extremism, ideology, terrorism, texas

Source link

Advertisement
Continue Reading

Tech

Microsoft Retreats In China

Published

on

Microsoft has been steadily scaling back its China presence, closing at least 15 branch offices and joint ventures over the past five years as Beijing favors domestic software. U.S. export controls also make it harder to grow its cloud and AI businesses, leaving the market with relatively little economic upside. Reuters reports: Microsoft took a major hit from the erosion of trust between Washington and Beijing, the five people said. China has since 2017 pushed the use of domestic software, which Beijing sees as more secure and whose quality is increasingly competitive with Windows and Office. U.S. restrictions, including export controls on advanced technology, have meanwhile hindered efforts to scale Microsoft’s lucrative AI and cloud businesses in China.

[…] Microsoft ultimately decided to remain because it had carved out a profitable business servicing Chinese companies like TikTok owner ByteDance, which need Western technology to manage overseas operations, according to three people familiar with the matter. The company also believed that it needed a presence to maintain access to China’s world-class engineering talent, two of them said. Microsoft had also cultivated a relationship with the government that is among the deepest of any tech company, its former China head Alain Crozier told Reuters. “Because of the geopolitics … some days it’s a little bit harder, but we never had a crisis,” he said.

A Microsoft spokesperson did not address questions about the firm’s deliberations on its China business but said it operates in a regulatory “environment that applies to every international supplier” and that it remains committed to the Chinese market. The state of Microsoft’s China business reflects market competition, regulatory demands and technological trends, the company said.

Read more of this story at Slashdot.

Advertisement

Source link

Continue Reading

Tech

The backup Microsoft never promised you

Published

on

Confidence in an organization’s cyber recovery capabilities deserves scrutiny. If a ransomware attack disables the SaaS data tenanted in the Microsoft cloud ecosystem, the data the business depends on as its lifeblood, the pace at which operations resume rests on assumptions that often prove wrong. Anyone whose answer is “It’s all good. Microsoft has my back on this one with its comprehensive native retention and recovery capabilities” is due a reality check.

With agile business tools like M365 and Entra ID and solid backend infrastructure in the form of Azure, Microsoft brings a lot to the SaaS party. Both IT departments and MSPs need to be aware, however, that Redmond operates on the same shared responsibility model as other major SaaS providers. In the event of a cyberattack, the recovery burden splits between what the cloud provider handles and what falls to the subscriber alone. MSPs face the additional pressure of meeting stringent SLAs, working with clients’ preferred providers or tooling, and managing their own staffing and profitability accordingly.

Microsoft ensures that its services keep running in the aftermath of a strike but does not promise to restore data to a specific known good point before the disaster. That gap always sat with the customer, and planning for it before problems hit beats improvising while picking up the pieces.

“There’s a common misconception about what Microsoft is responsible for, as distinct from the service they’re providing,” explains Brent Torre, GM of cyber resilience . Microsoft’s native tools, he points out, address problems like short-term accidental deletion and aspects of data governance. They are not a backup solution and will not protect against ransomware or recover data.

Advertisement

“Microsoft is clear that whether it’s a SaaS application like Microsoft 365, a platform application like SQL Server, or even VMs running in Azure, the customer is always responsible for the information that’s in that service, as well as devices, accounts and identities,” he adds. “If you get compromised and the attacker starts deleting data, Microsoft has no responsibility for that.”

A world of pain

The gap between availability and true cyber recovery is misunderstood, and it has widened into something of a chasm in recent years. There are three contributing factors to this gap.

The first is the evolution of cyberattacks. Typical cyberattacks have pivoted from muscling past a defensive barrier to targeting human weakness, because strolling in through the front entrance with a stolen pass is easier than shimmying through a forced window. Identity has become the primary attack surface. Credential compromise, or identity-based initial access, removes the need to find a vulnerability to exploit and requires only an unwary employee.

AI is now a staple weapon in the criminal arsenal, augmenting exploitation techniques such as phishing, social engineering, deceptive emails and spoofed websites, all convincingly used to trick users into typing passwords into a portal controlled by the aggressor. The technique can get more scientific than that. Automated AI-powered bots test millions of leaked username and password pairs across hundreds of different websites, exploiting the common habit of password reuse.

Advertisement

Microsoft Entra ID, the vendor’s cloud-based identity and access management service and the very tool designed to keep criminals out, is now a prime vector for attack and no match for stolen identity. Once an attacker compromises Entra ID with pilfered credentials, without setting off alarms, they have a free run at gathering data from mailboxes, OneDrive, SharePoint, Teams and other soft targets. The ransomware attack itself can then be launched with ease and at leisure.

Another contributory factor is that the vogue for moving workloads to infrastructure and platform as a service (IaaS and PaaS) models shows no sign of abating. Organizations tend to retain some functions on-premises, put some in SaaS applications, and others in cloud environments, but are often guilty of not protecting and managing everything to the same level of quality. Data gets backed up in a variety of locations, yet whether it is all equally recoverable in the event of a breach  is another chink in the armor that nobody understands. The ‘as a service’ model is popular, but it is the weak link when ransomware strikes.

The third part of the problem is the emergence of multiple compliance requirements mandating cyber resilience along with correct backup and recovery procedures, for which many organizations are ill-prepared. Together, these pressures give criminals room to do enormous harm to data, business operations and compliance posture in the gap between attack and restoration of SaaS availability.

Given that Microsoft’s native retention and recovery capabilities are not designed to deliver true cyber resilience, restoring the business to how it was before the attack is something to plan for in advance.

Advertisement

Time for independent backup protection

“At Kaseya we regularly recommend that you keep a copy of your data, independent of the primary environment it’s operating in,” advises Torre. “This needs to be something immutable that you can recover from even if the Microsoft or Google or Salesforce ecosystem goes down.”

This kind of protection is best delivered as a dedicated cloud-to-cloud backup solution stored outside the main SaaS tenant, he argues, an approach increasingly written into cyber insurance and compliance requirements.

By pulling copies of regularly targeted data from the Microsoft tenant for storage offsite in a third-party datacenter, organizations can be sure that if SaaS credentials are compromised, critical assets remain safe from attack. Restoration can then push what is needed directly back into the SaaS environment, even where the original tenant has been destroyed.

“In fact some people find it faster to stand up a new shell and rebuild it than try to gain access back into a compromised tenant,” notes Torre. “Whether you’re an internal IT technician, working the night shift, or an MSP needing to live up to your SLAs and maintain profitability, you require a solution that’s super straightforward and you need to be able to trust that the recovery will work. Both IT departments and MSPs should be looking out for a solution  that’s incredibly easy to use. Disaster recovery isn’t the only job that they have.”

Advertisement

A good platform, he says, focuses not just on guaranteeing recovery but on keeping the hygiene of the cyber resilience estate at a high standard without endless human intervention. It should also make certain that Microsoft 365 and Entra ID are restored together in a single workflow, so identity and the data it grants access to come back online in the right order rather than in separate stages.

Choosing the right platform

Datto is a cybersecurity and data protection business owned by Kaseya. Datto SaaS Protection for Microsoft 365, Datto Backup for Microsoft Azure, and Datto Backup for Microsoft Entra ID are designed between them to close the gap between availability and recovery by storing protected copies of tenant data in the Datto Cloud, outside the Microsoft environment. In this way a compromised production tenant does not take the recovery point down with it.

“With our M365 backup, we’re protecting one million users worldwide,” claims Torre. “A lot of organizations have built trust around our ability to protect and recover their data. We offer a trusted platform for recovery that focuses on ease of recovery, ease of deployment, not just for M365 but for Azure and Entra ID too.”

Both IT bosses and MSP players need to recognize that a ransomware attack, or other cyber crisis, is a matter of when rather than if. Recovery matters more than protection, because protection is certain to fail at some point, and traditional approaches to backing up data are no longer sufficient on their own. Anticipating disaster is not enough; the organization also needs to be set up to withstand it. That means being as certain as possible that the Microsoft environment can be recovered rapidly, down to the last scrap of data.

Advertisement

This capability underpins modern business workflows and operations. Microsoft tracks more than 4,000 identity attacks every second and analyzes 38 million identity risk detections daily — no organization is off the target list. When an attack lands, the restoration clock is already ticking, and any delay in fully restoring IT operations and key environments to their pre-attack state can mean the difference between survival and collapse, with profit, regulatory standing and reputation all riding on the outcome. Securing data with purpose-built cyber resilience platforms that enable rapid, clean recovery is how organizations meet that test.

MSPs looking to close the gap can start with the Datto MSP Buyer’s Guide to Microsoft Entra ID Backup

Sponsored by Datto.

Source link

Advertisement
Continue Reading

Tech

Troubleshooting Video Delay On The Raspberry Pi

Published

on

The Raspberry Pi line of single-board computers are great little devices, and they can do great things with cameras and video. However, there can be a fair bit of latency involved in these tasks depending on the board you’re using and just what you’re doing. You need to have things set up just so to get peak performance. [MattKC] has tangled with this issue in a personal project, and recently had somewhat of a breakthrough.

The issue came up during [MattKC’s] work on cloning the WiiU gamepad. The idea was to receive the video stream from the WiiU console and display it using a Raspberry Pi Zero 2W. He had some problems with latency, wherein there was a strange 3 frames of latency in the video pipeline that just wouldn’t go away. Even substituting in some dummy frames into the pipeline and ignoring them at output time didn’t work—the latency stuck around. Eventually, [MattKC] realized the delay wasn’t about a certain number of frames—it was about time. About 50 milliseconds, in fact.

Drilling down further revealed that there was a problem in the way frames were being fed into and received from the decoder. The first frame would take about 50 ms to decode, while later frames would take far less—as little as 5ms. However, [MattKC’s] code wasn’t set up to grab frames as soon as they were done, so the lag carried forward. The video explains it in greater detail, and how polling the decoder regularly helped solve the issue. The final result was a Raspberry Pi Zero 2W that could process and display the WiiU video feed as quickly as the original Nintendo WiiU gamepad.

Advertisement

If you dug this, it’s worth going back and checking out where the WiiU gamepad project started, too. Video after the break.

Advertisement

Source link

Continue Reading

Tech

GPT-4 guessed how 600 people would answer personality questions before a single person actually responded to any of them

Published

on


  • GPT-4 predicted personality scores months before any human ever answered a question
  • A Bosch oven manual was enough for GPT-4 to invent personality traits
  • DSM-5 predictions hit 0.71 accuracy; astrology predictions somehow hit 0.85 accuracy

Human personality has traditionally been measured by asking people questions and comparing their answers across established psychological frameworks.

A new study published on iScience suggests GPT-4 can go further by estimating how people collectively respond to personality questions before answering begins.

Source link

Continue Reading

Trending

Copyright © 2025