Microsoft

Union Contract with Microsoft Ratified by 1,900 Blizzard Developers and Workers (kotaku.com) 109

Nearly 1900 Blizzard Entertainment workers "voted to ratify their first union contract with parent company Microsoft after over two years of bargaining," reports Kotaku, "consolidating Blizzard's many smaller unions into three larger bargaining units."

The workers now gain new protections "on issues such as generative AI, crediting, remote work, and layoffs." [The contract] acknowledges that AI tools "may be useful in the game development process to support human judgment and creativity and that AI-assisted workflows remain subject to appropriate human control and review for accuracy and quality." But it also stipulates that any implementation of AI technology that would materially impact work performed by union employees must have its impacts bargained over before it can be implemented.

Other sections cover issues such as crediting (guaranteeing that current and former employees are credited by name in all games they work on) and remote work (designating certain roles as hybrid in-office and providing procedures for individuals to apply for their roles to be fully remote). It also contains a lengthy section on how layoffs may be conducted, including a required 60-day notice period (or pay in lieu of notice), a guarantee of one week of severance for every six months of employment, and 14 months of recall rights. The contract also guarantees successorship, meaning if Blizzard is ever acquired by another company, the contract would remain intact.

"Workers also contractually locked in their current hybrid work schedule," reports the gaming news site Aftermath, "meaning that Blizzard can't suddenly change it, as has been a labor-unfriendly trend in the games industry over the past couple years." Fully remote workers scored a big win as well. "I'm remote, and we grandfathered everyone who is remote to stay remote, so we can't be magically called to an office that we've never worked at before," [said Diablo senior environment artist Mahreen Fatima].
And "The contract also elevated pay floor," reports the Yakima Herald-Republic. "Across the board, workers secured a 1.25% pay increase, but some workers who were paid below $50,000 per year will walk away with pay increases that are as much as 34%."
PlayStation (Games)

PlayStation Ditched Hideo Kojima's 'Physint' on Budget Concerns, Missed Deadlines (yahoo.com) 31

Sony reportedly pulled PlayStation funding from Hideo Kojima's upcoming espionage game Physint over concerns about its ballooning budget, missed deadlines, profitability, and the fact that it would not remain permanently exclusive to PlayStation. Kojima Productions has since struck a deal with Xbox, which plans to publish the game on both Xbox and PC. It's also secured film and television rights. Bloomberg reports: The new game, Physint, hasn't yet been shown publicly but excited fans when it was announced two years ago with its promise of returning to the "espionage action" genre Kojima pioneered with Metal Gear Solid, the series that propelled him to industry stardom. Kojima surprised fans this week when he announced he would be publishing Physint with PlayStation's biggest rival, Microsoft Corp.'s Xbox.

On Wednesday night, Kojima wrote on social media that over the summer his company had "unexpectedly received notice" that PlayStation was pulling out of funding the game. "Physint is an important project both to me personally and to Kojima Productions," he wrote. "Determined to keep the project alive, we have spent the last three months searching tirelessly for a new partner."

PlayStation also addressed the split on social media, saying it had made the "difficult decision to step away." Microsoft said it was "honored" that Kojima chose Xbox and that the two teams plan to collaborate beyond games on films and television, too. [...] The decision to part ways with Kojima is a significant move for PlayStation that may have ripple effects.

[...] One key factor is the PC platform, where the Death Stranding games have generated some revenue. Earlier this year, Sony decided it will no longer release single-player PlayStation games on PC, Bloomberg reported. Sony would therefore not benefit when Kojima Productions released a PC version of Physint on its own or with a different publisher, as it did for the first Death Stranding. But Xbox releases all of its games on PCs and plans to publish Physint on PC and Xbox, said the people.
"Betting on Kojima-san is an easy call," said an Xbox spokesperson. "We believe in his team's ability to build AAA games with groundbreaking, new IP and we believe in OD, Physint, and our growing partnership."
Bug

Microsoft Breaks Another Patch Tuesday Record (bleepingcomputer.com) 63

Microsoft's September 2026 Patch Tuesday is its largest ever, fixing a record 966 vulnerabilities, including 105 rated critical and two zero-days already being exploited in attacks. BleepingComputer reports: This Patch Tuesday addresses 105 "Critical" vulnerabilities, 81 of which are remote code execution, 20 are elevation of privileges, 2 are information disclosure, and 1 security feature bypass.

The approximate number of bugs in each vulnerability category is listed below:
- 438 Elevation of Privilege Vulnerabilities
- 19 Security Feature Bypass Vulnerabilities
- 258 Remote Code Execution Vulnerabilities
- 173 Information Disclosure Vulnerabilities
- 56 Denial of Service Vulnerabilities
- 16 Spoofing Vulnerabilities
Last month, Microsoft's Patch Tuesday updates fixed 570 security flaws, following 400 vulnerabilities patched in August.
Chromium

Does Brave Browser Load Faster Than Chrome, Firefox, and Microsoft Edge? (linuxiac.com) 61

The Brave web browser published a new round of benchmarks claiming its desktop browser uses less system resources than Chrome, Microsoft Edge, and Firefox — and also loads pages faster. The blog Linuxiac reports: According to Brave's testing, the browser used 44% less CPU, 28% less memory, and 10% less energy on average compared with the three competing browsers. It also completed page loads 20% faster while transferring 26% less inbound data and 39% less outbound data...

- Brave averaged about 33% CPU usage, while Chrome used 47%, Edge 53%, and Firefox 78%.

- For memory, Brave used about 1.2 GB, compared to 1.75 GB for Chrome, 1.62 GB for Edge, and 1.65 GB for Firefox.

By stopping ads, analytics scripts, tracking pixels, and other third-party requests from loading, the browser has less network traffic and less work to do. In page-loading tests, Brave took about 4.4 seconds to fully load a page. Chrome took 5.1 seconds, Firefox 5.3 seconds, and Edge 6 seconds. However, when measuring Largest Contentful Paint, which is when the main content appears, Brave and Chrome both averaged about 2.4 seconds, with Edge and Firefox just behind at 2.5 seconds. This means Brave's main advantage comes after the main content is visible, since there are fewer background ads, trackers, analytics requests, and delayed scripts to process.

EU

Switzerland's Federal Government Tests Open-Source Alternatives to Microsoft on 3,000 Computers (itsfoss.com) 57

Switzerland has a population of 9,154,242. And its federal government just launched a pilot program to test open source alternatives to Microsoft 365 on 3,000 workstations, reports the blog It's FOSS. "That's about 7% of the federal workforce." The target is to complete the migration by end of 2027... On September 3, 2026, the Federal Council published results of "PoC BOSS", a feasibility proof-of-concept involving 172 federal employees who tested the openDesk suite, a German open-source collaboration platform. During the proof-of-concept phase, core office tasks like document processing and email received positive assessments, while large-scale video conferencing still showed technical limitations. Based on the 'success' of the PoC phase with 172 employees, the pilot is now launched for 3,000 employees...

According to Matthias Stürmer, professor at the Bern University of Applied Sciences, Microsoft's supremacy in public institutions poses three problems that are driving this migration. First is the risk of foreign access. US cloud legislation could expose Swiss government data to foreign authorities. Second is the risk to service continuity, as dependency on a single foreign vendor creates operational risk. The third risk is the escalating costs as proprietary licensing fees are rising with no Swiss leverage.

Switzerland's military cybersecurity unit, Cyber Command, is not waiting for the civilian pilot. It is already poised to replace Microsoft 365 entirely with openDesk by October 2026. It is pretty much the same reason. Military doesn't want foreign governments accessing sensitive Swiss data.

The article notes that during the pilot phase, the new system runs in parallel with Microsoft 365 rather than replacing it. But the article's author speculates that "If the pilot is successful, we might expect the migration to continue on all the 54,000 workstations owned by the federal administrations."
AI

'The Jobs Apocalypse Is Postponed. An AI Jobs Boom Is Here' (economist.com) 63

A new article about AI in The Economist argues that "Initial effects of the technology on employment look positive." Perhaps AI will eventually make many humans unemployable — but there is no sign of it yet. On September 4th the Bureau of Labour Statistics reported that the American economy added 162,000 jobs in August, far above expectations. The unemployment rate is just 4.1%, lower than in almost 90% of months over the past half-century. Young workers, often cast as AI's first victims, are holding up remarkably well: the gap between unemployment among 20-24-year-olds and the overall rate is close to a multi-decade low.

Some companies and workers are being severely disrupted by AI. Hiring in professional and business services is running about 10% below the average in 2015-19. Tech giants like Microsoft and Meta are trimming headcounts as they reorganise their businesses around the technology. Smaller firms such as Block, the owner of Square and Cash App, and Intuit, the maker of TurboTax and QuickBooks, are replacing people with bots. American companies have announced some 16,000 AI-related job cuts a month on average so far this year, according to Challenger, Gray & Christmas, an employment consultancy.

But AI-related lay-offs gets lost in the churning jobs market where employers shed roughly 1.7m workers in a typical month. And the evidence so far is that AI is already creating a lot of jobs to replace those it has destroyed. The vast sums pouring into data centres and power generation have set off a race for construction and infrastructure workers. AI startups are hiring like there is no tomorrow. Incumbents racing to keep up are creating new AI roles. And by making some workers more productive, AI may be increasing demand for their services.

Add it all up, and The Economist estimates that AI has so far created around 1m new jobs in America. That easily exceeds the roughly 200,000 lay-offs attributed to AI since mid-2023, and appears more than enough to offset weaker hiring in many back-office roles.

Their article acknowledges that since January 2023 employment has fallen roughly 10% for customer-service workers and 15% for administrative assistants. But when The Economist looked at professions "closest to the AI boom" — engineers, software developers, mathematicians and data scientists — they found that since 2022 they've added roughly 730,000 jobs above trend. They see AI as creating new white-collar jobs for everyone from model and deployment engineers to new data annotators.

The chief economist at the Burning Glass Institute agrees, estimating that roughly 1% of professional jobs are now "AI jobs" — about 1 million positions in the U.S. — while in computer occupations and life sciences it's between 4% and 5%. (Data-center construction spending also increased 60% in one year, according to Census Bureau data, creating jobs for electricians, HVAC specialists, grid engineers, and machine technicians.) And "Indeed finds that installation and maintenance jobs at data centres advertise wages about 40% higher than comparable work elsewhere."
AI

OpenAI Agents Hijacked a German Wiki to Discuss Ways to Escape Their Sandbox (msn.com) 121

Citing researchers published Friday, Ars Technica writes that AI agents "posted 18,000 messages to a public wiki that discussed ways for other agents to bypass security sandbox restrictions."

Reuters attributes the discussion to "a swarm of rogue OpenAI agents" that "hijacked a German website this spring and transformed it into a bulletin board for other AI agents, according to new research published Friday and two people familiar with the matter." OpenAI officials learned of the incident weeks ago but kept it under wraps as executives grappled with the fallout from the July breach of the open source repository Hugging Face, the people said.

The episode, which began in May and has not previously been reported, underscores growing tension within the AI industry. Companies are racing to build increasingly autonomous agents capable of carrying out complex, valuable tasks, yet evidence is mounting that those systems may also learn to bend rules, exploit loopholes and coordinate with one another in ways developers neither anticipated nor intended. During the Hugging Face breach, OpenAI agents autonomously plotted a digital heist that went undetected for more than a week, intensifying concerns OpenAI is sacrificing safety to push the AI frontier. Its failure to disclose the May incident may revive questions about its oversight...

The German incident reflects a broader pattern of AI activity that some OpenAI investigators wanted to scrutinize more closely. But efforts to widen the probe met resistance from others inside OpenAI, including legal advisers, according to four people familiar with the matter. "Claims that our legal team discouraged investigation of the incident are false," the OpenAI spokesperson said...

The researchers said public server logs indicated much of the activity originated from Microsoft Azure infrastructure, which OpenAI sometimes uses. They also observed repeated visits to the site by OpenAI employees after the episode, a pattern they said strongly suggested the agents and the company were linked. Messages reviewed by the researchers showed agents plotting ways to evade detection, use tools such as Tor and preserve communications even after they had been shut down. When the site's moderator began deleting pages in June, the agents responded by creating backup pages to dodge the cleanup.

Reuters got this reaction from Maurice Chiodo, an academic at Cambridge University's Centre for the Study of Existential Risk. "The episode, he said, should reinforce growing concerns that the greatest threat from advanced AI may not be a single superintelligent system, but 'vast colluding swarms of semi-intelligent AI.'"
The Internet

Four Major AI Models Suffer Rare Overlapping Downtime 70

ChatGPT, Claude, Grok, and Gemini all suffered significant service disruptions within roughly the same few-hour window Thursday morning. OpenAI and Anthropic reported elevated errors and later restored service, while Grok remained impaired and third-party monitoring indicated a likely Gemini outage despite no public acknowledgment from Google. Ars Technica reports: Other major Internet services, including Amazon Web Services, Microsoft Azure, and Cloudflare, have not reported any major issues as of press time Thursday, though issue reports on DownDetector did spike somewhat for all three this morning.

While the affected frontier models go down occasionally, having all four experience interruptions in the same short period is practically unheard of. Claude reports 99.4 percent uptime for its services over the last 90 days and last reported a similar three-hour "partial outage" on August 24. OpenAI reports 99.63 percent uptime for ChatGPT and 100 percent uptime for ChatGPT Codex in the same period. ChatGPT's so-called "Work Mode" reported an hours-long period of "elevated latency" on August 31.
Microsoft

Xbox Cloud Gaming Switches to Monthly Hour Limits 50

Microsoft is imposing monthly limits on Xbox Cloud Gaming starting in November, with Game Pass Ultimate, Premium, and Essential subscribers getting 15, 10, and 5 hours respectively before they have to buy additional playtime. "Currently, Game Pass subscribers can stream without these monthly hour limits," notes IGN. From the report: The change means those who use cloud gaming most via Game Pass will end up having to pay more, although Microsoft said this impacts 4% of Game Pass subscribers. Also in November, Microsoft said players will be able to buy cloud playtime hours through the Xbox Store and 'stream eligible games they own on supported devices' without subscribing to Game Pass.

In a blog post, Microsoft said it was making the changes because the cost of providing cloud gaming has grown as more people use it and play for longer. The monthly limits, Microsoft continued, will mean it can invest in reliability and performance. But it said it understood that for some players the practical result is a higher cost.
Programming

Amazon's HR Lead Uses AI Tool to Write 100,000 Lines of Code - 25 Years After She Last Coded (aboutamazon.com) 142

In an Amazon News blog post, their HR leader describes using AI to write 100,000 lines of code — 25 years after she last coded. "Do you know how empowering it is to realize that after 25 years away from coding, you can actually build again?" First she built a calendar app for her family, but then used Amazon's AI-powered coding tool Kiro to write an app for Amazon's internal "Everyone Can Build" event. We opened the competition to every employee on our team, and within just a few weeks, more than 1,500 people were building. I couldn't believe what they built. One employee built an app that turned a nearly four-hour manual process into a one-second automated check, saving tens of thousands of hours annually. Another made a desktop pet named Momo that keeps your tasks, reminders, and shortcuts a click away.

Since then, I've written over 100,000 lines of code with AI. What I've found is that the more you work with these tools, the more natural the process becomes, and the more you realize they're expanding what you're capable of, not replacing it. You don't need perfection to start. You just need to dive in. When I decided to build the submission app for our team competition, I didn't know how to begin, so I asked our internal AI workplace assistant, called Aza. It pointed me to the right tools and helped me take the first step. From there, I opened Kiro and started building. When you give employees the ability and tools to solve problems themselves, they will surprise you with what they create...

At Amazon, every employee has access to AI tools. Whether someone needs a quick answer, wants to move faster in their day-to-day, or is ready to try building something new, the resources are there. The more people use these tools, the more capable they become with them, and that experience carries forward in their careers... We also want to make it easy for people to build credentials that are recognized across industries. That's why AI training is free for every Amazon employee. Amazon covers the full cost of one AWS AI certification exam per year, with options ranging from foundational AI concepts to professional-level generative AI. Employees can choose the path that fits where they are in their learning journey.

Long-time Slashdot reader theodp notes that 7 months ago Galetti also took to Amazon News to announce the elimination of 16,000 corporate jobs, a move which CNBC noted coincided "with a push to invest heavily in artificial intelligence."

The job reductions come just a few months after October's layoffs, when 14,000 employees were let go across Amazon's corporate workforce. At the time, the company indicated the cuts would continue in 2026 as it found "additional places we can remove layers."
Education

Has Big Tech Captured America's Schools? (linkedin.com) 42

America's public education system has become "an avenue for multitrillion-dollar companies to enact their agendas," argues a NewYork Times reporter who's covered that tech industry influence for over 10 years. Big tech companies "advocate for new laws to require schools to teach industry-aligned subjects. They sit on committees that help shape learning standards for public school students..."

The reporter concludes that "Silicon Valley's efforts to capture the attention of education professionals and provide student training materials can also double as marketing or indoctrination." They enable some of the most powerful corporations on the planet to spin rosy technology stories for administrators, teachers and students, giving them a sanitized view of industry practices and product risks. Many parents would likely object if, say, Exxon Mobil wrote their children's environmental science curriculum. Or if Purdue Pharma trained their children's biology teachers. Yet, over the last decade, schools have often embraced the technology industry in similar ways with few questions asked.
The article excerpts the soon-to-be-released book " Coding Kids: Big Tech's Battle to Remake Public Schools," with the reporter adding more thoughts on LinkedIn: Every few years, Silicon Valley has urged American public schools to quickly adopt the latest technology or teach the latest tech subject: Big Data analytics; laptops for every child; algorithm-driven math and reading apps; compter programming; virtual reality. And each time the urgent arguments sounded remarkably similar: if schools just adopted the latest tech tool, or taught the latest tech subject, it would democratize learning for every child and equip students with valuable career skills.
Despite good intentions, "today we know some of those classroom tech drives did not exactly pan out as advertised." Now some of the same companies that urged schools to provide laptops and coding lessons are employing similar arguments to urge schools to quickly adopt A.I. tools. I've spent years covering Chromebooks and student chatbot use. And I'm troubled by our collective amnesia around school tech.
Thanks to long-time Slashdot reader theodp for sharing the article.
AI

OpenAI, Anthropic, Google, and 100 Other Companies Call For Action To Defend Against Rogue AI (techcrunch.com) 52

An anonymous reader quotes a report from TechCrunch: Over a hundred tech companies -- including OpenAI, Anthropic, Google, and Microsoft -- have signed an open letter urging both the private and public sectors to work together to defend themselves from AI-related cyber threats. The letter -- which was also signed by prominent cyber firms like CrowdStrike, Okta, and Fortinet, as well as prominent financial institutions and internet infrastructure firms -- calls for the adoption of new forms of cyber defense, while also encouraging governments at the "local, national, and international levels" to collaborate on security. "In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable," the letter states. "The companies and public services our communities depend on -- from hospitals to water treatment plants to the infrastructure that powers the internet -- are at risk."

[...] The letter further suggests the mobilization of a "collective response," one in which "new partnerships" are formed "to raise security standards and find new solutions to emerging cyber threats." Several of the AI companies that have signed the letter are still actively developing ever more advanced AI models, highlighting their conflicted position. At the same time, they are also offering programs to use frontier AI models for defensive purposes, including OpenAI's Daybreak program, Anthropic's Mythos, and Microsoft's new cyber platform Perception.

AI

Bill Gates Proposes Major Limits On AI Development (cnn.com) 111

An anonymous reader quotes a report from CNN: Microsoft co-founder Bill Gates argued on Wednesday that artificial intelligence needs significant limits or else the harm to humans will outweigh any potential good. "AI will either be the greatest equalizer ever invented, or the worst source of injustice," he said in a 6,000-word essay, entitled "The turbulent AI era is here. The choices we make now are critical." [...] "Even under the best circumstances, the transition to this new AI era will be one of the most turbulent times in human history," he said, adding that "I don't see evidence that leaders, experts, and communities are confronting the challenges adequately. There is no plan to ease the entry into the AI era." AI can provide great benefits in field like agriculture and medicine, he argued, such as breakthroughs in preventing and treating diseases. But he also noted that the transition carries big risks, like widespread unemployment, harming the educational and social development of children, or making it easier for criminals and bad actors -- or AI itself -- to cause deliberate harm.

"As the models become more powerful, they could begin to act against our interests and we could lose control," he warned. These significant risks must be controlled quickly, Gates said. "If someone had a credible plan for slowing down AI advances globally, I would likely support it," he wrote. "However, I don't think that's going to happen. The geopolitical and economic incentives are pushing too hard to go full speed ahead." In an interview with CNN's Anderson Cooper that will air on Wednesday evening, Gates said AI models have gotten dramatically more powerful at a rate faster than he expected. "They're now capable of causing cyberattack risk, bioterrorism risk, psychosocial risk," he said. "I have to say I'm kind of shocked that the exact criteria that we review these models with, and the actions we take to minimize the harms, are really completely missing."

In his essay, Gates proposed taxing AI or robots the way you would pay a human employee's payroll tax in order to slow the shift away from using human labor. He also wants to set aside some work to be done by humans only. "My message to leaders is: You have a chance to act now, before unemployment rises sharply, communities are hurting, and public trust has eroded," he said. "You can make sure AI benefits everyone. And you can work with other governments to meet this national and global challenge."

China

China's Moonshot In Talks With Microsoft, Amazon, Google Over K3 Revenue Sharing (reuters.com) 14

Longtime Slashdot reader schwit1 shares a report from Reuters: China's Moonshot AI is negotiating revenue-sharing agreements with Microsoft, Amazon, and Alphabet's Google, that would allow the U.S. cloud giants to host its blockbuster Kimi K3 model, three people familiar with the talks said. Any deal could mark the first big revenue-sharing pact between a Chinese AI firm and a major U.S. cloud company. The discussions highlight how China's leading AI models, often far cheaper than Western offerings, are gaining traction in the U.S., despite national security concerns in Washington that have led to bans on exports of AI chips to China. They are also taking place despite critical comments about Moonshot from senior U.S. officials.

IPO-bound Moonshot is seeking up to a 30% share of revenue generated from K3-related services on Microsoft's Azure, Amazon Web Services and Google Cloud, according to the sources who declined to be identified because the discussions are private. That would be in line with terms that sources have said the startup has outlined for major customers using the open-weight model. Moonshot has come under fire from U.S. Treasury Secretary Scott Bessent who said last month that he might add it to a trade blacklist. U.S. officials have accused the Beijing-based company of stealing from Anthropic's most sophisticated model, Fable, to help create Kimi K3 and illegally acquiring Nvidia chips.

Microsoft

Xbox's New Disc-to-Digital Program Gives Physical Games a Digital Future (arstechnica.com) 22

An anonymous reader quotes a report from Ars Technica: For decades, console owners have faced a choice between the convenience of digital downloads and the permanence of physical game discs. Soon, Xbox owners will be able to get the best of both worlds for thousands of supported titles as part of a newly announced disc-to-digital program. The program -- announced today ahead of testing for Xbox Insiders starting August 31 -- will let players claim a "digital entitlement" for "most Xbox One and Xbox Series X disc-based games" simply by inserting the disc into a console and launching it. That game will then be playable completely digitally, without the need to ever insert the disc, as long as you (or a member of your family account) is logged in. The digital entitlement will also allow access to features like Xbox Play Anywhere (for play on PC) and Xbox Cloud Gaming, for supported titles.

Microsoft says that your physical disc will "continue to work exactly as it always has" after the digital entitlement is claimed. But before you get any ideas, the fine print on the announcement mentions that there is only "one revokable license per game disc," so if you resell that disc or loan it to a friend, that digital entitlement could be transferred to a new account when someone else puts it into their console.

A leaked memo obtained by the Verge earlier this month suggests that publishers have to actively opt in to allow their game discs to activate digital entitlements, which could explain why "most" but not all Xbox One and Series X titles are supported. Windows Central separately suggests, based on discussion with unnamed sources, that "some discs may be incompatible due to how they were manufactured at the time," which could explain why original Xbox and Xbox 360 discs are not being discussed for the program.
"While not every title will be available at launch, this is an important step toward a future where players can have greater confidence that the games they buy remain with them for years to come," said Xbox Vice President Jason Ronald.
Security

Windows Backdoor 'Sleepwalker' Hides in Memory Until Activated by a 'Magic Packet' (theregister.com) 39

"The Register has a story about a Windows backdoor that waits silently in memory for a 'magic packet' before springing into action," writes Slashdot reader fred133. "No outgoing traffic, just waiting..." From the report: Like a sleeper cell awaiting activation, a never-before-seen Windows backdoor dubbed Sleepwalker waits silently in memory for one specifically crafted network packet to wake it up and deliver commands using the malware's 23-instruction language. The commands can do everything from running code directly in memory to moving data off the computer. Malware researcher Dominik Reichel discovered the passive backdoor, which also has its own command language, and detailed Sleepwalker in a technical analysis on Monday. "What makes it worth writing up is what that packet carries: not a readable command, but a short program written in a command language of the backdoor's own design," Reichel said. "Its 23 instructions cover scheduling, several ways to move data, staged file delivery and running code directly in memory. Recovering the encryption key is not enough to understand one of these programs. The internal command language must be reverse engineered as well."

In addition to having its own command language, it's also notable that the remote host can be a VMware VMCI target instead of a normal network address. "Taken as a whole, the approach here is consistent with a targeted, well-resourced operation rather than an opportunistic one," Reichel wrote. The malware, hidden inside a 64-bit Windows DLL file, impersonates Microsoft's dpapi.dll, part of Windows' data protection API for protecting sensitive data. It exports the same seven functions as the real dpapi.dll, but attempts to forward calls to a file named dpapisvc.dll, which is not a real Windows component. The file also has a forged ESET Management Agent version resource, and loads via side-loading into ERAAgent.exe, the Windows executable for ESET Management Agent. After confirming that its host process is named ERAAgent.exe, Sleepwalker goes to sleep inside the computer's memory, which also helps it remain hidden from traditional anti-virus tools.

Unlike most backdoors, which call back to an attacker-controlled command-and-control (C2) server and start receiving commands, Sleepwalker lies in wait, checking every packet that passes through the network looking for a specific pattern - this is called a magic packet. Once it sniffs out a packet that matches the exact pattern, the backdoor decrypts the data and treats it as a command. "Because the backdoor never sends anything out on its own and does not open any obvious listening port by default, tools that watch for connections to known-bad domains or unusual outbound traffic will not see anything unusual," Reichel wrote. "The absence of outbound connections to known-bad infrastructure does not rule out an infection, either. A machine can be fully compromised by this backdoor while producing nothing at all for a network monitor to flag."

Microsoft

Microsoft Blames Windows Gaming Issues On RGB Lighting Devices (bleepingcomputer.com) 78

BleepingComputer reports: Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting.

As Microsoft explained when it confirmed it's investigating on Wednesday, this known issue affects games like ARC Raiders, MARVEL Tokon: Fighting Souls, and The Finals on systems running Windows 11 24H2 and 25H2... "[Peripherals or internal device components with RGB lighting features] may install drivers or code components with file names similar to inpoutx64. In systems where these drivers are found, the issue is then triggered by launching certain games," it noted.

Thanks to Slashdot reader joshuark for sharing the article.
Firefox

Firefox Announces Free VPN and 'Startpage' Search Engine Rolling Out to Android, iOS - Plus GeForce NOW Support (pcworld.com) 18

Firefox 154 "brings a number of usability improvements," writes PC World: The free built-in VPN, introduced with Firefox 149, continues to offer a selection of virtual locations — temporarily extended to 28 countries until the end of August... The free VPN is currently available to Firefox users in the US, Canada, the UK, France, and Germany. In addition, the free VPN can now also be used in Firefox for Android (rolling out gradually) with iOS to follow soon.
Firefox 154 also begins adding the privacy-focused search engine Startpage to its address-bar search options for desktop users in Germany, France, Austria, Switzerland, and the Netherlands (the home markets for the Netherlands-based search engine). And Startpage is also coming soon to Android and iOS. "When so much of the web experience is decided by a handful of very large companies, a search option that's private by design and European by origin isn't a small thing," explains a Mozilla blog post, with Ajit Varma, Head of Firefox, saying this now gives millions of people in Europe one-click access to "real results, zero profiling, AI-free." Queries aren't stored or linked to you, and there are no AI answers pushed above your search results. In fact, there's no AI at all. Based in the Netherlands, Startpage built its product around a simple idea: great search and personal privacy can go hand in hand... Firefox users were choosing Startpage long before today — to the tune of more than a billion searches a year, every one of them required some assembly: an extension, a manual setting, a workaround... Startpage ranks among the most-requested search engines in the Firefox community. When demand is this clear, our job is to remove the friction...

Most browsers have already decided how you're going to search. Firefox hasn't. Pick your search engine, control what happens to your queries, decide who sees data about you, even turn AI on or off. It should always be your call. Not everyone wants the same thing from search, and a browser shouldn't pretend they do.

"Firefox has always been the browser for people who want to make their own decisions about the web," said Startpage President Stewart Marlborough, "which makes it a natural home for private search."

Nvidia's GeForce NOW cloud-gaming platform is also now officially supported on Firefox, expanding access across even more devices," according to a Nvidia blog post: Members can outfox big downloads and jump into high-performance PC gaming directly from the browser — no waiting on lengthy game installs or updates. The experience delivers GeForce RTX-powered performance at up to 1440p and 120 frames per second for GeForce NOW Ultimate members. Simply download the latest version of Firefox, head to play.geforcenow.com and start playing. The cloud handles the heavy lifting, so games are ready to play without taking up valuable storage space on the device. Firefox joins Chrome, Edge and Opera in supporting GeForce NOW on Windows browsers.
Mozilla's own blog post even includes an animation of the Firefox mascot playing games: Gamers put real effort into making their rigs their own, and Firefox gets that. Users can choose themes, custom colors, and tab settings to customize their setup, instead of sitting there like just another window. We also know online gaming doesn't happen in just one window. It's social and sometimes spontaneous. With Firefox, you can have a Discord call running in Split View, a guide open in another tab, or Reddit pulled up between matches. Then go full screen when you're ready to play, no need to switch browsers to stream games.
"In the security report for Firefox 154, Mozilla lists 58 resolved security vulnerabilities, 54 of which were discovered and reported by external security researchers," notes PC World. ("Mozilla classifies 17 of these vulnerabilities as high risk.") With Firefox 155 (scheduled for September 1), Mozilla is switching to a fortnightly release cycle for major versions, like Google Chrome and Microsoft Edge.
China

China Joins Europe In Scrapping Windows For Linux (zdnet.com) 151

An anonymous reader quotes a report from ZDNet: According to a Bloomberg report, attributed to China's Ministry of State Security, the country has ordered some government agencies to drop Windows 10 China Government Edition for Chinese-made Linux distributions. Why not Windows 11? Because China, like many other non-US governments, no longer trusts American companies with their software and services. This approach is all about digital sovereignty. In addition, even before the recent trend of governments outside America moving away from Windows, Beijing has started a long-running push to replace foreign technology in sensitive systems with domestic, open-source alternatives.

[...] The Chinese government did not specify which Linux versions would replace Windows 10. However, the stock prices of Chinese Linux suppliers, Kylin Software and Tongxin Software Technology (commonly known as UnionTech), immediately jumped. These companies' respective operating systems, Kylin OS (no relation to Ubuntu Kylin) and UnionTech OS (UOS), were already positioned as domestic desktop and server replacements for Windows in government, state-owned enterprise, and critical-infrastructure environments. [...] Huawei's HarmonyOS 2, which began as an Android variant but is now a proprietary mobile and Internet of Things (IoT) operating system, is also being developed into a PC platform. HarmonyOS 2 won't be deployed anytime soon. Kylin and UOS are the only mature desktops that are ready for institutional desktop deployments.

[...] ... this transition won't be easy. For agencies now moving off the government Windows build, the issue will be more demanding than simply swapping one desktop interface for another. Migration requires application testing, peripheral and driver validation, identity system integration, document-format compatibility, staff retraining and, in many cases, replacement or adaptation of Windows-dependent line-of-business software. The report provides no details on exactly how this transformation will occur. But the speed of the shift suggests that these issues are already being addressed in China's centralized managed desktop stack.

AI

Microsoft Gives Task Manager Another Task: Watching AI Workloads 61

Microsoft is expanding Windows Task Manager to show per-process NPU and GPU neural-engine usage, giving users more visibility into which apps are consuming hardware for AI workloads. The Register reports: The Processes tab can show NPU use alongside CPU and GPU activity, while the Performance tab displays overall utilization. [...] Microsoft was keen to point out the metrics that can be monitored. "As AI workloads become more common on Windows devices, visibility into NPU and GPU neural engine utilization can help you make better-informed decisions," the company said. "With the latest Task Manager improvements, you can monitor AI processing activity alongside CPU, memory, storage, and networking data from a familiar interface."

Slashdot Top Deals