BlueHammer Ransomware Flag Puts Microsoft Defender Patching Back on the Clock
CISA has updated the Microsoft Defender BlueHammer flaw, CVE-2026-33825, to mark it as used in ransomware campaigns. The flaw was patched in April, but the new flag gives Windows teams a fresh reason to verify Defender updates, endpoint telemetry, and local privilege escalation controls.
Microsoft Defender Starts Watching Local AI Agents on Developer Machines
Microsoft Defender now discovers local AI agents and MCP server configurations across managed endpoints, while preview runtime protection can audit or block prompt-injection attempts in Claude Code and GitHub Copilot CLI before risky tool actions execute.
Claude Sonnet 5 Makes Agentic AI Cheaper to Run
Anthropic launched Claude Sonnet 5 with lower launch pricing, stronger agentic behavior, Claude Code support, and broad availability across Claude plans. For developers, the useful question is not whether it is the flashiest Claude model, but whether its cost, context window, and migration changes make long-running agents easier to put into production.
Etched’s $1B Sohu Backlog Turns AI Inference Into the Next Chip Fight
Etched says it has raised $800 million, signed more than $1 billion in customer contracts, and started production of its Sohu-based inference racks. The startup’s transformer-specialized chip is a serious bet that AI’s next hardware fight will be won on serving models, not just training them.
UK CMA Pushes Apple and Google Toward Outside App Payments
The UK Competition and Markets Authority is consulting on steering rules that would let app developers point users to payment options outside Apple’s App Store and Google Play. The proposal gives developers a July deadline to weigh in and could turn app-store payment links into the UK’s next major platform-policy fight.
Apple’s Early Security Updates Show AI Is Shrinking Patch Windows
Apple pushed iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2 out before the broader 26.6 release cycle, citing AI-driven security concerns. The update is a practical reminder that patch timing now matters as much as patch content.
Daktronics Controller Flaws Put Public Digital Signs on Patch Watch
CISA is warning that flaws in Daktronics DMP-5000, VFC-DMP-5000, and DMP-8000 controller firmware could expose public display systems to root-level compromise. Operators of billboards, highway signs, venues, hospitals, and other connected displays should patch firmware, change default credentials, and verify that controllers are not reachable from the open internet.
Cursor’s iOS App Moves AI Coding Agents Off the Desktop
Cursor for iOS lets paid users launch cloud coding agents, steer desktop agents remotely, review diffs, and merge pull requests from a phone. The useful question for teams is not whether coding can happen on mobile, but where review, permissions, and production guardrails belong.
SimpleHelp Exploit Turns Remote Support Into a Credential Theft Pipeline
Attackers are exploiting CVE-2026-48558 in SimpleHelp to turn remote support access into a malware delivery path. Teams should patch, hunt for forged technician sessions, and rotate credentials exposed on managed endpoints.
Booz Allen Gives OpenAI a Government AI Deployment Channel
Booz Allen and OpenAI are partnering to deploy frontier AI for defense, intelligence, critical infrastructure, and commercial operations. The deal shows how OpenAI’s government push is moving from model access and pilots toward implementation through mission contractors.