AI was everywhere this week, from smarter chatbots and desktop-controlling models to Nvidia tools built for drug discovery and robot safety. But the week was not all shiny demos and future-of-work optimism. The same tech boom also brought browser hijacks, ransomware leaks, supply-chain scares, and enough password exposure to make “use a passkey” sound less like advice and more like a survival strategy.
Meanwhile, Apple, Amazon, Meta, Google, Microsoft, Oracle, and others showed how AI is reshaping hardware, commerce, pricing, security, and corporate strategy all at once. Convenient? Sometimes. Expensive? Increasingly. Weirdly dystopian? Let’s call it “feature-rich.”
Top News
AI Platforms and Tools Take Center Stage
OpenAI released a major update to GPT-5.5 Instant, enhancing its ability to follow user instructions, integrate text and images, and deliver more accurate responses. This iteration, dubbed Instant, focuses on reducing latency while maintaining high reasoning quality, making it suitable for real-time applications. The update coincides with the company’s announcement of the Jalapeño inference chip, designed specifically for faster processing of AI models. Unlike traditional GPUs, Jalapeño optimizes matrix operations common in transformer architectures, promising up to 3x throughput improvements for production deployments. Third-party benchmarks indicate that GPT-5.5 Instant achieves 98.7% accuracy on complex instruction-following tasks, a notable jump from its predecessor.
Google expanded its Gemini 3.5 Flash model with native desktop control capabilities, allowing the AI to directly manipulate applications, manage files, and interact with operating system elements. This represents a significant step toward autonomous AI agents capable of performing multi-step workflows without human intervention. Early testers report that Gemini can now handle tasks such as data entry, email sorting, and even basic code debugging on the user‘s machine. The move signals a new phase of multimodal AI integration where language models aren’t just conversational partners but active participants in digital environments.
Nvidia introduced the BioNeMo Agent Toolkit to empower AI agents in genomics, chemistry, and drug discovery. The toolkit integrates multiple Nvidia technologies, including NeMo for large language model training and RAPIDS for GPU-accelerated data science. It provides pre-built workflows for protein folding prediction, molecular property screening, and toxicity analysis. Major research institutions like the Broad Institute and Stanford’s AI in Medicine lab have already adopted the toolkit, reporting a 40% reduction in time needed for initial compound screening phases. Nvidia also launched the BioNeMo Cloud service, making these capabilities available on demand without local hardware requirements.
Hardware and Consumer Tech Updates
Microsoft extended its Windows 10 Extended Security Updates program until October 12, 2027, giving users another year of free or low-cost patches. The original end-of-support date was October 14, 2025, but Microsoft has repeatedly pushed it back due to slow Windows 11 adoption. The extension applies to all Windows 10 editions, including Home and Pro, with pricing structured similarly to previous ESU programs. This move is intended to ease the transition to Windows 11 amid hardware upgrade hesitations, particularly among enterprise customers with legacy applications that lack compatibility with Windows 11’s stricter security requirements, such as TPM 2.0 and Secure Boot.
Google launched the $99 Gemini-powered Home Speaker, its first new model in six years. The device replaces the Nest Mini and Nest Audio, offering AI-driven features through a Google Home Premium subscription (priced at $9.99/month). The speaker supports Wi-Fi 6, Bluetooth 5.4, Matter, and Thread 1.3, ensuring broad compatibility with smart home ecosystems. Key capabilities include natural language conversations for controlling devices, proactive suggestions based on daily routines, and integration with Google Calendar and reminders. The speaker also functions as a Thread border router, bridging Thread devices to Wi-Fi networks without requiring a separate hub. Early reviews praise its sound quality, noting improved bass response compared to its predecessors.
Meta unveiled its first in-house smart glasses, starting at $299. The glasses feature 12 MP cameras, open-ear speakers, and AI-powered functions like live translation and object recognition. They run on a custom version of Android optimized for wearable form factors, with a battery life rated at 8 hours of mixed use. The glasses include a built-in neural processing unit for on-device AI inferencing, reducing reliance on cloud connectivity. Meta aims to make smart eyewear mainstream despite privacy concerns; the company has implemented visual indicators (LED ring) when cameras are active and partnered with privacy advocacy groups to develop usage guidelines. The initiative positions Meta directly against Snap’s Spectacles and Google Glass Enterprise Edition 2, though at a significantly lower price point.
AI Meets Commerce and Media
Meta is also testing an experimental app called Arena, which allows users to wager virtual currency on future events. Powered by Meta’s Llama AI, the app automatically generates questions and settles outcomes, blending social prediction markets with generative AI. Users earn virtual tokens by predicting correct outcomes in categories such as politics, sports, and entertainment, with leaderboards fostering competition. Meta plans to integrate Arena with its Horizon Worlds platform, enabling virtual reality–based prediction events. The app is currently available only to select beta testers in the US and Canada, with a public launch expected later this year. Critics warn that the app could encourage speculative behavior and may attract regulatory scrutiny from the SEC if virtual tokens are deemed securities.
Getty Images signed a multiyear deal with OpenAI to integrate its licensed photos into ChatGPT search results. The agreement marks a major shift from Getty’s earlier legal disputes with AI firms; Getty had previously sued Stability AI for copyright infringement, but this deal suggests a move toward cooperation. Under the terms, ChatGPT will display Getty Images in response to relevant queries, with attribution and licensing fees paid to Getty. The deal comes amid a pending $3.7 billion acquisition of Shutterstock, which would create a dominant visual media conglomerate. Industry analysts expect this consolidation to lead to higher licensing costs for AI companies and potentially trigger similar agreements with stock photo agencies like Adobe Stock and Alamy.
Retail and Pricing Trends
Amazon kicked off its four-day Prime Day sale a month early, responding to inflation and shifting consumer priorities toward essentials. Originally scheduled for July, the event now runs from June 24-27 with heavy discounts on groceries, household supplies, and electronics. Analysts expect over $21 billion in sales, though cybersecurity experts warn of increased phishing and fake domain scams targeting bargain hunters. Amazon reported that Prime members saved an average of 35% per item compared to non-Prime prices. The early timing also aims to counter competition from Walmart’s “Walmart+ Week” and Target’s “Circle Week,” both scheduled for late June.
Apple warned that rising DRAM and NAND prices, driven by AI data center demand, will push iPhone prices higher. Analysts predict the next iPhone Pro could cost up to $1,399, with Apple considering supplier funding to stabilize component output. The company cited a 40% year-over-year increase in memory costs, attributed to accelerated production of AI accelerators and high-bandwidth memory for servers. Shortly after that, Apple raised prices on Macs, iPads, and other devices by up to 67% due to soaring memory costs. For example, the MacBook Pro with 32 GB of unified memory now starts at $2,599, up from $1,999. The hikes led to a 6.1% drop in Apple’s stock and are expected to ripple across the PC industry as other manufacturers face similar cost pressures. PC makers like Dell and Lenovo have already announced price increases of 10-15% for upcoming models.
Privacy and Safety Developments
Nvidia also launched Halos for Robotics, a full-stack safety system designed to help humanoid and industrial robots operate safely around humans. The system adapts autonomous vehicle safety technology for factory and warehouse environments, incorporating real-time sensor fusion, collision avoidance algorithms, and emergency stop mechanisms. Halos uses multiple camera, LiDAR, and ultrasonic sensors to create a 360-degree awareness zone around the robot. It includes safety-rated controllers that meet ISO 13849 and IEC 61508 standards, enabling deployment in safety-critical applications. Nvidia demonstrated the system on its own GR00T humanoid robot platform, showing that it can safely share workspace with humans during assembly tasks.
Apple will unify its Sign in with Apple and Hide My Email services under the private.icloud.com domain later this summer. The change simplifies management for users but may make Apple aliases easier to identify and block, prompting developers to adjust validation systems. Previously, Hide My Email generated random addresses at private.icloud.com, while Sign in with Apple used @icloud.com aliases. The consolidation means all forwarding email addresses will originate from a single domain, potentially allowing websites to detect Apple-generated addresses more easily. Apple has assured developers that the underlying forwarding mechanism will remain secure, but it recommends updating validation logic to distinguish between legitimate Apple aliases and disposable addresses from third-party services.
Insider Intel
IBM partnered with OpenAI through the Daybreak Cyber Partner Program to launch a managed security service that uses OpenAI models to detect and verify exploitable software flaws. The initiative aims to strengthen open-source supply chains and counter AI-driven cyber threats via Project Lightwell. IBM’s X-Force threat intelligence team will leverage OpenAI‘s GPT-5.5 models to analyze vulnerability reports, predict exploitation likelihood, and automatically generate patches for open-source dependencies. The service is expected to be available to enterprise clients by Q3 2026, with pricing based on the number of repositories monitored. Early results from beta testing show a 50% reduction in median time to patch critical vulnerabilities.
Security Alerts
Malware and Exploits
Researchers found that the Adblock for YouTube Chrome extension, with over 10 million installs, contained hidden code capable of injecting JavaScript and hijacking browser sessions. The extension, which claims to block video ads, was actually performing ad fraud by silently loading hidden YouTube videos and generating fake views. Users are urged to uninstall it immediately; Google has already removed it from the Chrome Web Store. This incident underscores the growing risk of browser extensions that request broad permissions, as they can be easily weaponized by threat actors.
Gaslight, a new macOS backdoor linked to North Korea, evades AI-based analysis by using fake crash messages. The malware, attributed to the Lazarus Group, masquerades as a legitimate system utility and when triggered displays a convincing crash dialog that mimics macOS’s native error reporting. Behind the scenes, it establishes persistence via LaunchDaemons and exfiltrates browser data, cryptocurrency wallets, and credentials via Telegram bots. Apple‘s XProtect now blocks Gaslight, but variants with minor code modifications have been observed in the wild. Users are advised to keep macOS updated and avoid installing software from untrusted sources.
Researchers also revealed an unpatchable SecureROM vulnerability dubbed “usbliter8,” affecting Apple A12 and A13 devices. The flaw allows attackers with physical access to hijack devices before iOS loads, though the Secure Enclave remains secure. The vulnerability resides in the USB controller firmware in the system on chip, enabling attackers to bypass the device’s signed firmware boot chain. Apple acknowledged the issue but stated that the Secure Enclave’s cryptographic isolation prevents extraction of biometric data or encryption keys. However, the vulnerability could allow persistent jailbreaks for forensic or malicious purposes. Model affected include iPhone XS, XR, 11, 12, and some iPad models from that era. Apple has issued guidance for law enforcement and device resellers on mitigating physical access risks.
AI and Cyberdefense
Anthropic’s Mythos AI identified vulnerabilities in classified US government systems during controlled testing. The discovery underscores the growing role of AI in both offensive and defensive cybersecurity operations. Mythos, based on Anthropic’s Claude architecture, was given access to simulated environments mirroring federal networks and within 48 hours found multiple privilege escalation paths and configuration weaknesses. While the systems were unclassified replicas, the results have prompted several agencies to adopt AI-assisted vulnerability scanning tools. The exercise is part of a broader DARPA initiative to incorporate AI agents into red team operations.
Supply Chain and Data Breaches
Tata Electronics confirmed a ransomware attack that leaked 630 GB of data, including Apple and Tesla manufacturing files. The breach exposed over 200,000 files containing trade secrets, patent blueprints, and personal data of employees. The ransomware group, believed to be a variant of LockBit 3.0, demanded a $50 million ransom and published a sample of the data on its leak site to prove authenticity. Tata Electronics stated that the attack did not affect its parent company, Tata Group, but warned that intellectual property related to upcoming Apple MacBooks and Tesla battery components was compromised. Law enforcement agencies in India and the US are investigating.
LastPass was affected by a supply-chain breach at Klue, exposing customer contact and support data. Klue is a third-party customer support platform used by LastPass for ticketing and knowledge base management. Although encrypted vaults were not compromised, the incident highlights the risks of shared credentials across SaaS ecosystems. The breach exposed names, email addresses, phone numbers, and support interactions for approximately 200,000 LastPass customers. LastPass has reset all associated support tickets and advised users to be vigilant against phishing attempts that may leverage the exposed information.
ClawHub removed 23 impersonating plugins that used deceptive names like @openclaw and @clawhub. While no malicious code was found, the plugins had broad system access, prompting new namespace dispute policies to prevent future supply-chain risks. ClawHub, a package registry for ClawScript, implemented a verification badge system similar to npm’s “verified creator” status. The incident underscores growing concerns about typo-squatting and dependency confusion in the open-source ecosystem, where attackers register packages with names similar to legitimate ones to trick developers into inadvertently including malicious code.
Ransomware and Credential Threats
Prinz Eugen, a new Go-based ransomware, targets recently modified files and deletes originals after encryption. Named after a German World War II cruiser, the ransomware spreads via stolen RDP credentials and legitimate IT tools like PowerShell and PsExec. Unlike typical ransomware, it leaves no ransom note behind; instead, it silently encrypts files and replaces them with .peu extension. Victims discover the infection only when they can‘t open recent work. The malware also attempts to delete volume shadow copies and disable recovery features. Security researchers have identified command-and-control servers in Eastern Europe but are still analyzing the ransomware’s encryption algorithm.
FortiBleed, a Russian-linked campaign, compromised over 70,000 Fortinet firewalls and VPN gateways across 194 countries by exploiting weak password hashes. The attackers targeted devices with default credentials or easily guessable passwords, then used a custom tool to crack the hashes offline. Once inside, they deployed backdoors and exfiltrated network configuration data. Administrators are urged to reset credentials, enable MFA, and patch FortiOS immediately. Fortinet has released a security advisory and updated its best practices guide. The campaign is particularly concerning because compromised firewalls can be used to pivot into internal networks, potentially leading to larger data breaches in corporate and government environments.
Have I Been Pwned added 124 million unique passwords and 56 million email addresses from infostealer-infected devices, urging users to check exposure and adopt passkeys or two-factor authentication. The data comes from a collection of logs from redline stealer, Vidar, and other malware that intercepted credentials over the past year. This is one of the largest data dumps HIBP has ever incorporated, surpassing the 2019 Collection 1 breach. The passwords are mostly unique and not previously known, making them valuable for credential stuffing attacks. Troy Hunt, founder of HIBP, recommends that users check their email addresses on the site and enable passkeys wherever available, as passkeys are resistant to phishing and credential theft.
Industry Shakeups
Corporate Restructuring and Investment
Oracle announced 21,000 job cuts — 13% of its workforce — as part of a $70 billion AI and cloud infrastructure restructuring. The company faces mounting debt and negative cash flow while expanding data centers for clients like OpenAI and Meta. The cuts primarily affect legacy product divisions, including Oracle’s on-premises database sales, support teams, and certain cloud engineering units that duplicate efforts in the new infrastructure push. Oracle plans to hire 5,000 new employees focused on AI operations, data center management, and security. The restructuring is expected to be completed by the end of fiscal year 2027, with estimated annual savings of $3 billion. CEO Safra Catz emphasized that the move is necessary to stay competitive against AWS, Microsoft Azure, and Google Cloud, all of which have heavily invested in AI capabilities.
Berkshire Hathaway invested $10 billion in Alphabet to bolster its AI infrastructure expansion. The move, led by CEO Greg Abel, signals a strategic pivot toward advanced technology investments despite internal challenges at Google. Berkshire purchased shares at an average price of $175, representing about a 2% stake. The investment focuses specifically on Alphabet‘s AI division, including its data center expansion and the development of the next-generation Tensor Processing Unit (TPU v6). Berkshire’s move is unusual for the traditionally conservative firm, which has historically favored consumer goods and insurance over tech. However, Abel noted that Alphabet‘s dominance in search and its AI leadership align with Berkshire’s long-term value investing philosophy. The investment is expected to help Alphabet accelerate its AI initiatives, including Project Gemini and the rollout of AI-powered cloud services.
If you want to stay updated with the latest tech developments, consider subscribing to a daily newsletter or following reliable news sources. The landscape evolves rapidly, and keeping abreast of changes in AI, security, and industry moves can help inform personal and professional decisions.
Source: TechRepublic News