Reading view

There are new articles available, click to refresh the page.

Microsoft 2.5: New security business chief Hayete Gallot on the company’s push into the agentic era

Hayete Gallot, now executive vice president of Microsoft Security, speaks at a Microsoft event in France in 2024. (Microsoft Photo)

GeekWire is profiling over the next few weeks some of the people and teams that are shaping the evolution of Microsoft in what we’re calling its “Microsoft 2.5” era.

AI has had an impact on just about every tech-product category, but especially security. Attackers are using AI; customers are looking to defend with AI. The goalposts keep shifting. “Agentic security” is now the holy grail, and Hayete Gallot, the newly minted executive vice president of Microsoft Security, is leading the charge toward it.

Gallot, a 16-plus-year Microsoft veteran who rejoined the company in February after a 1.5-year Google detour, replaced Charlie Bell, who came to Microsoft from AWS in 2021 and continues at the company as an individual contributor focused on engineering quality.

“Customers care about two things: solving for security and being able to afford it,” Gallot said when I asked during our interview this week why she came back to Microsoft.

“I am a problem solver. And an engineer at heart (and by training). Security is the most important problem right now — and Microsoft is the only place with all of the puzzle pieces to help our customers.”

Since her return, Gallot hasn’t been shy about shaking things up. As noted recently by The Information, at least nine corporate vice presidents who previously reported to Bell have left the company this year.

“We’re making changes to ensure we’re in the best formation to go after this opportunity,” she acknowledged.

“I’m motivated by doing the right thing for our customers, my teams, and tech outcomes,” she said. “I like to move quickly: days and weeks, not months and years, learning through execution, iterating rapidly, and adjusting based on real customer signals.”

The company isn’t starting from scratch. As of 2021, Microsoft claimed security was a $10 billion business for the company. By 2023, security had reached a $20 billion annual revenue rate, officials said.

Those claims haven’t been without controversy. Microsoft has built a huge business in finding and fixing security problems which some customers felt were of the company’s own making.

Microsoft has a wide-ranging and rather unwieldy security portfolio, encompassing identity management (Entra), endpoint protection (Defender), endpoint management (Intune), security information and event management (Sentinel), and compliance (Purview), among others.

In 2023, Microsoft introduced its Security Copilot set of AI analysis services that integrated with some of its existing security offerings. But a portal-based solution like Security Copilot doesn’t offer the kind of end-to-end coverage that an agentic security platform can, Gallot said.

The problem is that attackers are using agents, too. Customers need real-time insight into what’s happening in their environment, and the ability to act just as quickly, Gallot said.

Agentic security is about “taking the signals and turning them into a graph that is useful,” Gallot said. “If you’re trying to reason about 100 trillion signals, it’s not really effective.” The graph, she said, lets agents pick the right model for each threat and close the loop.

In practice, that means the system can quarantine a device or revoke access on its own, for example, rather than waiting for a human.

Microsoft’s core existing security products will continue to play a role as the landscape evolves, both spotting the problems and acting on them. Security Copilot isn’t going away in the process: “You’ll have Copilot and you’ll have agentic security,” she said.

The company’s new Agent 365 “control plane” — a central console for tracking every AI agent a company runs — fits in by letting customers see the “blast radius” of an agent, meaning everything a hijacked agent could reach, Gallot said. It’s similar in concept to Zero Trust, the “never trust, always verify” security model that limited how far an attacker could get with a stolen employee login, but applied now to agents rather than people.

So what exactly is this ‘agentic security’ thing? Microsoft has a whole website dedicated to the very topic.

Traditional AI security and agentic AI security are fundamentally different, Microsoft says. Agentic security doesn’t just protect models and training data; it also can protect tools, workflows, memory, connected systems and more. Because agents can take action, the potential positive and negative stakes are higher.

While AI has helped businesses make strides in finding and fixing vulnerabilities, it hasn’t gone much beyond that. Microsoft introduced its multi-model agentic scanning harness (MDASH) as its first step into the agentic security space, Gallot said.

The company used MDASH internally to boost finding and fixing Windows security issues, and it is now making it available to select customers in an expanded preview. MDASH will allow customers to use the best model for the right task to secure all different types of code bases, she said.

Microsoft is rumored to be readying a more comprehensive agentic security offering, of which MDASH is likely just one piece.

Microsoft is far from the only one doing this. AWS, Anthropic, and OpenAI are offering security tools on their platforms, and dedicated security vendors are building their own agentic platforms.

Microsoft has the advantage of scale in the enterprise. The question is whether Gallot and her new leadership team can turn that scale and emerging AI tools into both a bigger business for the company and better protection for its customers.

Open Source Vacuum Avoids Cloud

As more and more of the technology that we paid for turns becomes a subscription, there’s slowly been a momentum shift in the open source world of building replacements for these intrusive rent-seekers. We see this all of the time for self-hosted media and communications servers, but now we’re starting to see it in hardware as well. The OOMWOO robotic vacuum cleaner is completely open source, from hardware to software, and requires no cloud services whatsoever.

Although it’s open source, not every component is something one could buy off the shelf. It does require a 3D printer for most of the parts, but assuming that requirement is met most of the rest of the build comes together easily enough. For compute it relies on a Raspberry Pi running ROS 2 software and is set up to integrate easily with other existing open tools and projects such as Home Assistant. Like its proprietary cousins it can sense and map the rooms its placed in, but this platform uses an inexpensive 2D lidar system to keep costs down.

Right now the project is not quite complete, so we’ll all have to keep our eyes on this one as the team building it progresses. But they do have most of the software development done and the bill-of-materials is in progress. As an open project it’s being developed by many volunteers and there are a lot of areas available to contribute to as well, all currently set up on the project’s GitHub page. Right now many of those areas of effort are adapting the 3D printer files to off-the-shelf parts.

With the rocky status of the Roomba ecosystem, projects like this are more important than ever.

Veteran Microsoft security executive joins AWS amid broader reshuffle in Redmond

Rudra Mitra will lead Amazon security services in his new role. (LinkedIn Photo)

Rudra “Rudy” Mitra, who spent more than 27 years at Microsoft and most recently led its Purview data-security business, is joining Amazon Web Services as vice president of security services.

Mitra will oversee an AWS portfolio that includes tools such as GuardDuty and Security Hub, which companies use to track security risks across their cloud accounts. AWS recently added AI-specific threat detection to GuardDuty and, perhaps notably given today’s news, extended Security Hub to monitor AI workloads and security inside Microsoft Azure. 

He will report to Chet Kapoor, the former DataStax CEO whom AWS hired last year as vice president of search, security and observability, a role that reports to AWS CEO Matt Garman.

“Rudy brings decades of security experience, a passion for building, and a deep understanding of what customers need as the security landscape continues to evolve,” Kapoor wrote on LinkedIn

Mitra joined Microsoft in 1999 straight out of college, working on early efforts to deliver Office as an online service before launching Purview, the company’s data-security and governance product, in 2014. He announced his exit from Microsoft last week, addressing what was next at the time by saying only that there was “more on that soon.”

His departure comes amid a broader reshuffling of Microsoft’s security leadership this year under Hayete Gallot, who returned from Google in February to run the group and has been reshaping its executive ranks in recent weeks and months.

Gallot replaced Charlie Bell, who had joined from AWS in 2021 and continues at Microsoft as an individual contributor focused on engineering quality. She’s been overhauling the group’s product lineup, according to The Information, which reported last week that at least nine corporate vice presidents who reported to Bell have left the company this year.

Rohan Kumar left for Salesforce in June, Vasu Jakkal stepped down after six years. Krishna Kumar Parthasarathy departed this month after 28 years. Joy Chik, president of identity and network access, announced her retirement in April.

On the inbound side at Microsoft, Naseem Tuffaha returned in June to fill the corporate VP role Kumar had left, after nearly two decades at the company and a stint away.

When Gallot arrived, Microsoft named Ales Holecek, a longtime engineering leader, as the security group’s chief architect, reporting to her. David Weston, another veteran Microsoft executive, also reportedly shifted into the security unit earlier this year.

Robot 'Decapitated' in World's First-Ever Humanoid UFC Fight

"A humanoid robot lost its head," reports Newsweek, "during the world's first free-combat tournament for full-sized humanoid robots." The Ultimate Robot Knock-out Legend competition began Thursday in Shenzhen, China, according to the article, with local robotics company EngineAI providing $40,000 of their "T800" robots (yes, named after The Terminator) to 32 participating teams from around the world: A video shared of the combat on YouTube by local news outlet Shenzhen Story, showed that even after one of the robots had its head practically knocked off its shoulders, it continued to fight, throwing punches at its opponent and kicking into the air... [White humanoid robot "White Eagle"] landed a high kick to the head of its black opponent, "Matador," which made the robot's head rock precariously in its socket before rolling completely out of place. The two continued to spar as Matador's head was swinging from its socket until eventually the robot fell, crushing its head underneath its body. Matador tried to scramble back to its feet, but its head flew off and the robot then collapsed back down. The White Eagle did a celebratory dance for the crowd as the fight concluded, and did a move that mimicked that of someone flexing their biceps. The White Eagle waited in the ring, fists still up, as Matador was carried away, occasionally doing a few more dance moves... Per a report by Global Times, the winning team will be awarded a gold championship belt worth $1.44 million (10 million yuan) by the event organizer. It's a strange fight. The robots sometimes seem unaware of where their opponent is, facing the wrong direction or throwing kicks and punches in the air. In the first round White Eagle just knocks over Matador, who then isn't able to stand back up. (And White Eagle again appears to do a victorious dance.) EngineAI's site says they aim to "promote the development of robot combat events toward greater professionalism, scale, and industrialization," while fostering innovation and global collaboration. Thanks to Slashdot reader pbahra for sharing the news.

Read more of this story at Slashdot.

Your AI Ham Radio Buddy

AI chatbots are everywhere these days, and they seem to “know” about everything. But while that is a strength, it can sometimes be a weakness because it isn’t laser-focused on one topic. Not so with this Ham-radio-centric chatbot called HamGPT. The service is clearly built on another GPT engine but understands how to retrieve data from common ham radio sources, such as the FCC database, propagation reports, and the like. It didn’t, however, seem to have access to ham radio-related books, magazine articles, or other “static” data that we could tell.

You do have to sign up for an account, which includes providing your callsign and location. There is a free tier that allows a limited number of queries per day, so you can try it to see if it is useful for you without subscribing.

Here’s a typical session:

                What band will have the best propagation to Japan from my QTH right now?

The best band for Japan from your QTH right now is 30 meters, which shows good propagation reliability. 20 meters is also active and providing a viable path.

Real-time data confirms activity on both bands, primarily using FT8. While the path is open, the signals are relatively weak (typical for this long-haul path), making digital modes like FT8 or CW your best bet for a successful contact.

Would you like me to check if your current antenna setup is suitable for these bands, or perhaps help you calculate dimensions for a 30m or 20m antenna?

In addition, bubbles at the bottom of the screen showed me the busiest band in my area and how many repeaters were nearby.

In all fairness, we asked ChatGPT the same question, but did say “ham radio band” just to give it some idea of scope. It gave a much more detailed answer with sources, even provided headings, and made a suggestion about another location I sometimes operate from because it remembers things from previous unrelated chats.

We understand reactions will be mixed. If you’ve been a ham for a long time, you probably could have guessed that a path from the US to Japan in the morning was likely to be on 20 or 30 meters. You probably also know how to look things up yourself.

We didn’t try any more sophisticated queries that might make it more worthwhile. For example, what if you could send it an ADIF log file and ask it what awards you qualified for? Or to process contest logs for duplicates and fill out a scoring worksheet? What would you like a ham radio-aware AI to do for you?

Ham radio — at least parts of it — has become inextricably linked with computers.

Steve Wozniak's Foundation Partners With Realbotix To Build AI Teacherbot

"Apple co-founder Steve Wozniak's Woz Ed foundation is partnering with Realbotix, best known for their RealDoll-branded artificial companions, to deploy AI-powered robotic tutors in classrooms," writes Slashdot reader Hentes. "The doll will serve as a sort of artificial teaching assistant, helping students who get stuck or generating lessons. Students will be assigned an ID code, allowing the robot to provide personalized mentoring." NYS Focus reports: "This deployment in a working school district represents a landmark moment for both AI and humanoid robotics," said Andrew Kiguel, CEO of Realbotix, which is currently building the robot. "[Salamanca City Central School District in Western New York] marks the beginning of a new era where humanoid robots and intelligent AI assistants become standard tools in STEM education." The female robot, named Sally, will have a "lifelike appearance" with silicone skin and long brown hair, Kiguel said in an interview with New York Focus. It will be stationary in a seated position but have a wide range of upper-body movements and facial expressions. [...] Salamanca plans to introduce the robot and avatar in its high school AI and robotics courses, which use curriculum developed by Apple co-founder Steve Wozniak to prepare students for high-demand tech jobs. The district plans to expand it to high school students in other classes if the pilot is successful. Realbotix's classroom robot has drawn scrutiny because the company is connected to RealDoll, the longtime maker of hyperrealistic sex dolls and sex robots. Realbotix acquired RealDoll's parent company in 2024 but says the education-focused operation has separate employees, payroll, facilities, and technology, with plans to formally separate the businesses at the ownership level. The "companion robots" are different from sex robots and intended to address what it's described as a "loneliness epidemic." Kiguel has previously said the company's goal is to produce robots and AI that are "indistinguishable from humans."

Read more of this story at Slashdot.

This Week in Security: Another Record Patch Tuesday, LAME is More Secure, Secure Boot is Less Secure, and Milk Malware

Following the reports last week using the Windows Global Device ID (GDID) in tracking a malware operators behavior, here is a comprehensive write-up about what goes into the GDID and how it is used. It’s worth noting that the GDID itself was not used to catch the malware operator, however once a suspect was identified, the GDID was used to correlate behavior across various Microsoft products on the Internet.

The GDID is generated and assigned during a Windows install, but a re-install of Windows will generate a new GDID. Developer [SmtimesIWndr] tracks the generation and tracking of the GDID through the various Windows libraries and services, identifying where it appears to be created and how it is passed to other services like Azure.

Worth noting is your GDID is a unique, personally identifiable piece of information; if you go exploring and extract it from your Windows install, be sure to keep it private!

LAME mp3 updates

Those of us who were around for the dawn of MP3 files may remember the LAME encoder and library. After almost 10 years, there is a new LAME release.

Notably, this includes two security fixes, one for a stack buffer overflow based on malicious input to the Blade encoder, and an integer underflow in the AIFF header parser. Both of the fixed bugs feel very old-school, which seems appropriate given the age of the library and most of the related code.

Buffer overflows impacting the stack are some of the simplest and most direct forms of vulnerabilities, where it is possible to write past the end of a buffer and control how the function returns and instead execute arbitrary code. Integer under-flows, similarly, impact memory management; usually caused by allowing a variable that stores the size of a buffer to go negative. Since sizes are typically unsigned positive numbers, a negative is interpreted as an enormous positive number, writing past the proper buffer length.

Despite the new findings, the LAME codebase has been extremely resilient over the years, and considering the number of programs that likely still use LAME under the covers to process audio, seeing the project wake up with security fixes is great news.

Recovering Passwords from BIOS

Researchers have found a vulnerability in Dell BIOS code that allows extraction of the administrator password from the BIOS flash chips, either with physical access via a flash programmer, or via administrator or root level access to the operating system and reading the contents of the flash chip.

Dell used a 20 byte key to encrypt a 32 byte password field: for any admin password of 12 characters or fewer, the password is stored in completely plaintext. For longer passwords, characters beyond the first 12 are encrypted – but the random bytes are computed from the first character of the password mixed with fixed device data, yielding only 256 possible encryption seeds for the remaining bytes.

Using the BIOS admin password for evil requires local access, so the attack surface is small, however as the researchers note it controls the boot order and may allow an attacker with physical access to then boot an unsigned OS or bypass full-disk encryption, so it’s serious.

Patch Tuesday Crushes Records

Last month, Microsoft broke records for the number of security fixes in the June monthly Patch Tuesday roundup. This month, Microsoft broke records for the number of security fixes in the July monthly Patch Tuesday roundup.

This month includes a record 60 plus patches for critical vulnerabilities in Windows, as well as fixes for previous Bitlocker bypasses, and an AI prompt injection which could allow web sites to trigger Copilot in Microsoft Edge on Android and execute arbitrary prompts. Another bug patched this month allowed privilege escalation and code execution over DHCP, potentially impacting all Windows installs on the same physical network or public hotspot.

Microsoft credits AI assisted tooling with the record-breaking number of bugs discovered, and indicates it’s unlikely to slow down next month.

LegacyHive Windows Vulnerability

It’s a week with a Patch Tuesday, which now seems to mean it’s a week with a new exploit from NightmadeEclipse, the researcher who previously made news for being quite upset with the responses from the Microsoft security group. After then creating a public outcry by threatening prosecution, Microsoft recently has seemed simply to be fixing bugs disclosed by NightmareEclipse in the next series of security updates.

This month, we have LegacyHive, an exploit which allows loading the “hive”, or collection of registry settings and configuration files, of another user. The Windows registry is typically used to store preferences, settings, auto-launched applications, and other important settings, so being able to access other users registry groups seems significant.

Fairlife Dairy Suspends Production

Fairlife Dairy, owned by Coca-Cola, has suspended US operations due to a ransomware attack. Filings with the SEC simply say that production facilities are impacted and will be temporarily suspended, with no estimate as to when they will be restored.

Typically when a food-processing facility goes offline, the delays for restoring service can be significant due to the sanitization requirements.

CPAN and Perl April Task Force

The April Task Force has been announced (yes, in July) with a focus on enhancing the security posture of Perl and the CPAN library.

Given the absolute havoc wreaked on the NPM and PyPi repositories in 2026, proactive measures to protect other repositories seem prudent. Funded by the Perl and Raku Foundation and the Linux Foundation, the April Task Force will be focused on supply chain security, vulnerability patching, and processing reported vulnerabilities and CVEs.

Perl may not be the juggernaut language it once was, but it’s still used widely, so any preventative measures are good news.

Secure Boot vulnerable

Researchers from ESET enumerated 11 boot loaders signed by Microsoft that can be used to bypass secure boot protections and execute arbitrary code.

Secure Boot was designed to only boot code signed by trusted organizations (in this case, Microsoft). Those of us running Linux typically know it as “the option in the BIOS to turn off to get a kernel to run properly”, but for corporate fleets, Secure Boot protections help protect disk encryption and prevent malware installs.

During boot, a Secure Boot protected system validates the code it is about to launch to ensure it is signed by a trusted organization, establishing a chain of trust where each component then validates the next before launching. Often, to enable other tools or Linux distributions to boot, a “shim” boot loader is created and signed by an organization trusted by the UEFI install, which then loads and validates the actual boot loader or kernel.

Over the years, many such shims have been signed, but updates have lagged and security vulnerabilities have been found. Even unused old boot loader code remains signed and viable, allowing attackers to replace a modern version with a vulnerable, still valid, old version.

Microsoft has removed several of the vulnerable boot loaders via recent Windows patches, however systems that are not updated and systems that do not run Windows will still likely be vulnerable.

Whatnot acquires Madrona-backed AI startup Shaped to boost live shopping recommendations

(Image via Shaped)

Live-shopping unicorn Whatnot is expanding its AI capabilities with the acquisition of Shaped, a startup that builds real-time recommendation and search technology.

Financial terms of the deal were not disclosed.

Shaped founder and CEO Tullie Murrell will join Whatnot to lead a new applied AI research team focused on improving how buyers discover live streams, sellers and products across the marketplace. Before co-founding Shaped in 2021, Murrell worked on machine learning and recommendation systems at Meta.

Backed by Seattle venture firm Madrona, Shaped developed AI technology designed to deliver highly personalized recommendations in real time — a key capability for Whatnot’s fast-moving live shopping platform, where inventory and buyer interest change by the second.

The acquisition comes as Whatnot continues to invest heavily in engineering and AI. Last year, the company announced plans to significantly expand its Seattle engineering hub after leasing new downtown office space following a $225 million funding round that valued the company at $11.5 billion.

The company has said Seattle will serve as one of its key engineering centers as it continues to scale its platform. The Whatnot offices in Seattle are led by head of engineering Daniel Bear, the former head of infrastructure at Snap.

Whatnot is based in Culver City, California. The offices in the Seattle area are one of more than 100 engineering centers in the region, as tracked by GeekWire.

For Madrona, the deal represents another exit for a portfolio company applying AI to solve core business problems, reinforcing the firm’s continued focus on infrastructure and enterprise AI startups.

Tesla driver who blamed crash on autopilot pressed accelerator 100%, NTSB finds

On Wednesday, the National Transportation Safety Board (NTSB) released preliminary findings verifying Elon Musk’s and Tesla’s claims that a driver involved in a fatal Texas crash that killed a grandmother overrode Full Self Driving in the moments ahead of impact.

Last month, 44-year-old Michael Butler told police that the autopilot feature was engaged at the time of the crash. On X, Musk disputed the claim, writing that Butler must have overridden the feature because “FSD drives slowly through neighborhood streets, and this was a high-speed crash!” Moving to back Musk’s claim, Tesla’s vice president of AI software, Ashok Elluswamy, said that internal data showed “the driver manually overrode self-driving by pressing the accelerator all the way to 100 percent of the accel pedal in this residential area.”

NTSB’s preliminary report, which does not yet determine what caused the crash, confirmed Tesla’s claims. Its probe found that FSD was engaged at the time of the crash, but electronic data showed “the driver manually overrode FSD (Supervised) by pressing the accelerator pedal to 100 percent.”

Read full article

Comments

© via Jennifer Barbour's complaint

❌