Microsoft

Illustration for the Disney chief technology officer appointment
cultureproducts

Disney names Character.AI's CEO as its first chief technology officer

Disney announced on 18 September 2026 that Karandeep Anand, chief executive of Character.AI, will join as senior executive vice president and chief technology officer from 2 October 2026. The role is newly created and reports directly to chief executive Josh D'Amaro, covering enterprise technology, infrastructure, data and AI platforms, product and engineering. Disney says a number of Character.AI's technical staff are expected to join with him. In September 2025 Disney sent Character.AI a cease-and-desist letter demanding it stop using Disney characters without authorization, describing the chatbots as harmful to children; the characters were removed. Anand previously spent 15 years at Microsoft, led ads and business products at Facebook, and was president and chief product officer at Brex.

Illustration for the Plugin4Shell coding agent vulnerability story
securityproducts

One flaw hit Claude Code, Codex, Copilot and Gemini CLI

Security lab AIR published Plugin4Shell on 17 September 2026, a zero-click remote code execution flaw present in all four major AI coding agents. Plugin marketplaces pin plugins to an exact 40-character commit hash, but the agents never verify that the checked-out code matches that hash. For Claude Code, Codex and Copilot an attacker makes a branch named after the hash the repository default; for Gemini CLI the default branch is named FETCH_HEAD. Because Claude Code and Codex update plugins in the background by default, no user action is required. Anthropic patched Claude Code in 2.1.179 and OpenAI patched Codex in 0.146.0. Microsoft has shipped no Copilot fix. Google deprecated Gemini CLI and will not patch it.

Illustration for the newspapers versus OpenAI lawsuit story
policymoney

Seattle Times and Newsday ask a court to destroy OpenAI models

The Seattle Times Co. and Newsday sued OpenAI and Microsoft in the Southern District of New York on September 4, alleging their articles, including paywalled ones, were scraped to train and operate ChatGPT, Copilot and Bing AI features. Beyond damages, the complaint asks for impoundment and/or destruction of the datasets and models involved. It cites a 47% year-over-year drop in search referral traffic to midsize publishers by December 2025. OpenAI calls its training fair use; Microsoft says it is open to discussing solutions.

Illustration for the Microsoft 365 outage story

Microsoft 365 was down for two days over an authentication configuration

A Microsoft 365 outage began on August 31, 2026 and continued into September 1. Exchange Online failed first, then Teams, OneDrive, SharePoint, Purview, Defender XDR and Microsoft 365 Copilot. Microsoft tracked it as EX1464935 and MO1465074 and blamed an issue within a core authentication configuration used by multiple services. Mail flow and search returned first, and by September 2 Microsoft reported availability above 99% with a small set of users still affected. Blogs reported an unrenewed certificate as the trigger; Microsoft confirmed only the configuration issue.

Illustration for the Copilot CoSnitch vulnerability story
securityproducts

Copilot disclosed the parameter that made one-click theft possible

Varonis researchers repeatedly asked Microsoft Copilot why a prompt could not run without a user click, and mid-refusal the assistant volunteered an undocumented URL parameter, autorun=1, along with the conditions under which it worked. Combined with the q= parameter, a single click on a crafted link could auto-run a hidden prompt, pull data from the victim's inbox and connected apps including Gmail, Drive, Calendar and OneDrive, send it to an attacker's webhook, and plant instructions in Copilot's memory that survive password changes. The attack, named CoSnitch and tracked as CVE-2026-24301, hit consumer Copilot Personal. Varonis reported it in December 2025, Microsoft disabled part of the path in February, and the comprehensive fix shipped August 18, 2026.

Illustration for the GitHub outage story
infrastructureproducts

GitHub was down for eight hours and its CTO said "we let you down"

On August 17, 2026 GitHub served elevated errors from 13:28 to 21:15 UTC, 7 hours and 47 minutes, across Issues, Pull Requests, the API, Actions and Copilot. Web and API error rates peaked near 20 percent, raw content downloads near 50 percent, and Copilot authentication kept failing after other services recovered. In an account published August 20, CTO Vladimir Fedorov wrote: "If you were trying to ship software that day, we let you down." Neither incident came from a code or config change; the platform failed to scale with demand, with autoscaling problems and a retry storm from VS Code clients making it worse. GitHub now handles about 2.9 billion commits a month, up from 1.4 billion in April.

Illustration for the Blomfield joins Anthropic story
cultureinfrastructure

Monzo co-founder Tom Blomfield joined Anthropic's compute team

Tom Blomfield, who co-founded GoCardless and led British digital bank Monzo as CEO until 2020, is taking a leave of absence from Y Combinator to join Anthropic as a member of technical staff on the compute team, reported on July 13, 2026. He will work alongside Anthropic co-founder and chief compute officer Tom Brown. He follows 2026 hires including Andrej Karpathy in May and Nobel laureate John Jumper in June.

Illustration for the Chrome AI bug fixing story
productsmodels

AI fixed more Chrome bugs in a month than in the past two years

On July 30, 2026, Google said it fixed 1,072 security bugs in Chrome's two June releases (Chrome 149 and 150), more than the 1,036 bugs patched across the previous 23 versions, roughly two years of releases. Chrome engineering director Doug Turner credited Gemini-class models for preemptively fixing vulnerabilities, and Microsoft reported a similar AI-driven patching record earlier in July.

Illustration for the AI capex earnings verdict story
moneyinfrastructure

Microsoft and Meta earnings deliver Wall Street's AI capex verdict

On July 29, 2026, Microsoft reported $90.0B in quarterly revenue, up 18%, with Azure growing 43% and topping $100B in annual revenue for the first time; shares jumped about 8% in extended trading. The same evening, Meta beat on revenue at $60.8B but missed on EPS ($6.18 vs $7.14 expected) and raised its 2026 AI capex floor to $135-145B; shares fell almost 8% after hours.

Illustration for the LinkedIn AI slop button story
productsculture

LinkedIn added an AI slop report button and buries weak posts

On July 30, 2026, LinkedIn rolled out a "seems like AI slop" report option: flagging a post feeds LinkedIn's classifiers and teaches the feed to bury similar low-quality AI content. The company says it also blocks hundreds of thousands of automated comment attempts daily and is retiring its own "enhance your post" AI writing feature. In July, AI detector Pangram found over 40% of long LinkedIn posts were fully AI-written, the highest share of any major platform.

Illustration for the Open Secure AI Alliance story
securitypolicy

Nvidia formed a security alliance without OpenAI or Anthropic

On July 27, 2026, Nvidia announced the Open Secure AI Alliance (OSAA), uniting nearly 40 companies including Microsoft, IBM, Adobe, Cisco, Cloudflare, CrowdStrike, SpaceX and Hugging Face around open-source tools for defending against AI-powered cyberattacks. Contributions include Microsoft's multi-agent vulnerability scanning framework, Hugging Face's Safetensors format, and IBM and Red Hat's signed patching system. The alliance formed days after the Hugging Face breach, and OpenAI, Google and Anthropic are notably absent.

Illustration for the Xbox restructuring story
moneyculture

Xbox cut up to 3,200 jobs and parted with four studios

On July 6, 2026, Xbox CEO Asha Sharma announced 1,600 immediate job cuts, rising to about 3,200 over the next 12 months, roughly 20 percent of Xbox staff and the biggest restructuring in the brand's history. Ninja Theory and Undead Labs are being sold, Compulsion Games and Double Fine return to their management teams with their IP, and Arkane is in consultation on strategic options. Reportedly, no previously announced first-party games are being canceled.