Recent Posts

Pages: 1 ... 4 5 [6] 7 8 ... 10
51
Not web wrappers, with new tools and a clearer roadmap

Microsoft wants more WinUI 3 apps across Windows 11, and Build 2026 shows how developers can get there with new tools, agents, and hardware.


(Image credit: Future | Microsoft | Edited with Gemini)

Microsoft wants more native apps and elements on Windows 11, and so should you. Native apps and native code mean better performance and smoother computing. At Build 2026, Microsoft held several sessions to help third-party developers make native applications.

A core part of the Windows K2 initiative is to rebuild pieces like the Start menu as native components, but that's only part of the effort. For the entire Windows experience to improve, third-party developers need to embrace native Windows apps.

In this piece, native refers to modern Windows apps built with the latest Windows frameworks, such as WinUI 3. Native can also describe apps compiled for a specific architecture like ARM64, but that’s a separate topic. Here I’m focusing on Windows‑native apps, not architecture‑native builds.

Microsoft is building its own team of experts to make native in-box apps and experiences for Windows 11. The tech giant also has several tools and pieces of advice for developers that want to create native apps.

A session at Build 2026 titled "Use agents to build WinUI 3 apps" taught how to use agents to assist in the development of native apps. During the session, Beth Pan and Nikola Metulev explained how to create new WinUI 3 apps, improve existing apps, and migrate apps to use the Windows UI stack.


A WinUI agent plugin for GitHub Copilot and Claude Code helps third-party developers make native
Windows apps. (Image credit: Microsoft)


Migrating to the WinUI 3 framework can be tricky when using AI tools. Agents and models are often trained generically, meaning they'll show unoptimized results. The WinUI agent plugin for GitHub Copilot and Claude Code is a specialized AI agent that pull WinUI skills by default.

That's one of many tools made available to developers. Microsoft also has WinUI 3 templates (in preview) to streamline native app creation.

Another Build session breaks down how to modernize apps with AI. "Modernizing apps isn’t just rewriting code—it’s untangling dependencies, tracing data flows, and making changes without breaking production," explains the session description.


The Surface Laptop Ultra features powerful internals designed to handle AI workloads locally.
(Image credit: Microsoft)


Developers relying heavily on AI will need hardware that can cope. The Surface Laptop Ultra was announced at Computex, but you can bet it was mentioned at Build.

The Surface Laptop Ultra is built to handle AI agents. It will be available with up to 128GB of RAM and is the first Surface to be built on the NVIDIA RTX Spark platform.

That platform combines the N1x CPU (20-core Arm), an RTX GPU (up to 6,144 cores), and unified memory to deliver up to 1 petaflop of AI compute.

The new NVIDIA Spark laptops can handle creative apps and even games, but they're also a power play by Microsoft to win over developers.

source
52
Windows 12 / Windows 12 at Build 2026: What to expect
« Last post by javajolt on June 02, 2026, 07:57:56 AM »
What Build 2026 signals about the future of the Windows


(Image credit: Microsoft Build)
Microsoft Build 2026 takes place on June 2 and 3 at Fort Mason Center in San Francisco, returning to the city for the first time since 2016. CEO Satya Nadella will open the event with a keynote address, and Microsoft has billed the conference as a two-day, hands-on gathering for AI developers, technical leaders, and enterprise teams, promising "no fluff." In-person tickets are priced at $1,099, with the keynote and select sessions streaming live for free.

With speculation around Windows 12 running hot despite zero official confirmation from Microsoft, Build is worth watching closely this year. The company rarely announces a new consumer OS at a developer conference, but it often uses them to lay the foundation, surfacing platform directions, new developer APIs, and architectural hints that end up defining what comes next. For developers and IT teams planning their roadmaps, spotting those signals early is often the point of attending.

Microsoft has not officially announced Windows 12. The most recent public statement on the subject came at CES, when Microsoft EVP Yusuf Mehdi published a blog post describing 2025 as "the year of the Windows 11 PC refresh" — a clear signal that a new major OS was not on the immediate agenda.

That hasn't stopped a surge of viral speculation from filling the gap. In early March 2026, PCWorld published an article saying that Windows 12, codenamed "Hudson Valley Next," was on track to ship later this year, built on a modular CorePC architecture and requiring an NPU with at least 40 TOPS of performance for full functionality. The piece spread rapidly, but PCWorld's own executive editor has since added an editor’s note stating that a lot of these claims were unfounded. It was a translated syndication from German partner PC-Welt, published without secondary verification.

Windows Central's Zac Bowden, went further and debunked the report based on his own sources. There are no plans to ship Windows 12 in 2026, Bowden wrote, and the "Hudson Valley" codename dates to 2023, where it was tied to Windows 11 planning rather than a new OS. CorePC, likewise, was an internal 2023 project that was never shipped. As for Windows 12, Bowden's assessment is that 2027 would be the earliest realistic announcement window.

The rumor that Windows 12 would require a monthly subscription has also been thoroughly dismissed. Multiple news reports have called the claims "AI hallucinations," tracing them to AI-generated content that was scraped and republished across multiple sites as if it were original reporting. A more plausible scenario, if any subscription element ever materialises, is that it would apply to premium AI tiers rather than locking the basic Windows desktop behind a subscription paywall.

So what is Microsoft actually doing with Windows in 2026? According to Windows Central's reporting on an internal initiative codenamed Windows K2, the company assembled a concerted quality programme in late 2025, targeting the biggest complaints about Windows 11: performance, reliability, and AI feature bloat. Windows K2 is not a new OS release — it's an ongoing effort running through 2026 and into 2027, covering a rebuilt Start menu, faster File Explorer, and a pullback from unsolicited AI integrations across the shell.

None of this rules out Windows 12 as a longer-term product. The Copilot+ PC hardware tier, Microsoft's investment in on-device AI, and the natural pressure of Windows 11's support lifecycle ending in October 2027 all point toward some kind of platform evolution ahead. But for now any specific 2026 launch claims have been broadly debunked, though that does not do anything to make Build 2026 any less significant for the future of the Windows ecosystem.

Build is where Microsoft has historically laid the groundwork for major platform shifts, giving the developer community an early look before any public announcement. The 2011 inaugural conference introduced the Windows 8 Developer Preview, Build 2013 unveiled Windows 8.1, and Build 2015 gave developers an early look at the Universal Windows Platform months before Windows 10 reached the public in July.

The pattern has held since. Whenever there’s a major platform shift in the works, Build is where the technical community gets its first substantive look, along with the first opportunity to ask the engineers behind it how their tooling needs to change.

Build's focus has shifted somewhat in recent years, moving toward Azure, AI tooling, and Microsoft 365. But even within that shift, Windows-specific news has landed consistently, often with more long-term significance than it first appeared. Build 2023 introduced Copilot for Windows 11; Build 2025 renamed the Windows Copilot Runtime to Windows AI Foundry and added MCP (Model Context Protocol) support at the OS level. Each of those moves now reads as groundwork for whatever the next major Windows platform looks like.

There’s more. In March, Windows corporate vice president Pavan Davuluri published a detailed commitment to improving Windows quality on the Windows Insider blog, covering WinUI 3 performance, taskbar customization, and reduced Copilot clutter. Then, at Microsoft's Q3 FY2026 earnings call on April 29, Nadella said the company is doing "foundational work to win back fans" across Windows, Xbox, Bing, and Edge, with native applications and AI-optimized PCs at the center of that effort.

There is no official indication of a Windows 12 announcement at Build 2026. Microsoft has positioned this event explicitly for AI developers, technical leaders, and enterprise developers, and the company has scaled back in-person attendance compared to recent years. A consumer OS reveal would be atypical for a conference this narrowly scoped.

Yet what the conference will almost certainly cover is the current state of Windows platform development, and based on what Microsoft has already shipped and announced in the weeks approaching Build, that story is substantial. Here is what we expect developers to hear about, cobbled together from Build 2026’s Session Catalog, official announcements, and recent release trajectories at Microsoft.

This may be the most significant ongoing Windows platform story for app developers, and it predates Build by several months. In March, Rudy Huyn, Partner Architect at Microsoft, confirmed he is forming a dedicated team to build 100% native Windows apps using WinUI 3, ending the company's reliance on WebView2 wrappers for first-party applications. That same month, Davuluri confirmed the Start menu itself is being rebuilt in WinUI to reduce latency.

A string of tooling releases followed quickly. Microsoft shipped WinUI 3 Gallery 2.9, a new Windows App Development CLI (v0.3), and a set of new WinUI templates that let you scaffold, run, and package native Windows apps from the command line without opening Visual Studio.

Most notably for AI-assisted development workflows, Microsoft also released a WinUI agent plugin for both GitHub Copilot and Claude Code, with eight built-in development skills covering UI design, code review, testing, packaging, and WPF migration. Software engineer Beth Pan published benchmarks showing a 25% performance improvement for WinUI 3's portion of File Explorer, with 41% fewer memory allocations and 45% fewer function calls.

The upcoming "Build and ship faster with a developer-optimized experience on Windows" session at Build 2026 covers this territory directly, alongside WSL and PowerToys improvements. Expect Microsoft to use Build to pull these threads together into a coherent pitch for native Windows development, especially as the industry pushback against resource-heavy Electron and web-wrapper apps continues to grow.

Build 2025 introduced Windows AI Foundry as the platform layer for local model deployment. Build 2026 looks set to deepen that story with three confirmed on-device AI sessions: a breakout covering Windows APIs for local model execution, a table talk aimed at desktop developers integrating local inference, and a demo session for Microsoft's Foundry Local tool on Windows hardware.

This area connects most directly to whatever comes after Windows 11. If the next major Windows version does set a higher NPU baseline, developers will need to understand:

• Which AI capabilities are available on-device versus cloud-routed

• How Windows AI Foundry abstracts that difference

• How to structure applications that degrade gracefully on hardware without a dedicated accelerator.

Build is the right venue for that developer guidance, regardless of whether a new OS announcement accompanies it.

Agent development is central to Build 2026 across every platform, and Windows is no exception. The "Claws on Windows: Designing Safe, Bounded Agent Actions" table talk addresses one of the more pressing questions in Windows development right now. How do you give an AI agent useful system access without creating a security liability? The session looks at real claw design failures and how developers can architect safer, scope-limited alternatives.

"AI & Agent-Augmented coding you can trust on Windows" examines how agents discover, reason about, and execute tasks within Windows' enforced boundaries, covering packaged app permissions, execution constraints, and lifecycle management. For developers building agentic applications targeting Windows, these sessions represent the kind of security architecture guidance that has been largely absent from the available documentation.

The security track extends further with "The Windows Security Features That Matter Most for Developers," a lightning talk covering post-quantum resilience and the platform-level foundations developers should be building on as agentic workflows become more common. Analysts following the longer-term Windows roadmap have consistently flagged tighter default security as a pillar of any next-generation OS; this session is likely to preview some of that direction.

At Build 2025, Microsoft open-sourced most of WSL. The confirmed "What's new in Windows Subsystem for Linux" session at Build 2026 will show where that effort has gone since. According to Microsoft's April 2026 Windows quality roadmap, WSL is receiving many performance upgrades this year: faster file access between Linux and Windows environments, better network throughput and localhost reliability in WSL2, simplified onboarding, and stronger enterprise policy controls for managed deployments.

For the significant portion of the developer community that runs Linux toolchains on Windows hardware, these improvements speak directly to daily workflow friction. The "Elevate your developer productivity with Windows Terminal" lightning talk sits alongside this, covering improvements designed to reduce context switching for developers working across Windows and Unix environments.

The "Build, deploy, and scale agents with Windows 365" lab runs multiple times across both conference days, covering how Windows 365 provides preconfigured, governed computing environments for AI agent deployment. A digital version of the same lab is available for online attendees.

For enterprise developers and IT architects, this is worth watching closely. Windows 365 is the likely delivery mechanism for governance-sensitive Windows AI features, and the architecture on display here, covering how agents are provisioned, constrained, and monitored in managed environments, reflects how Microsoft is thinking about enterprise-scale Windows deployment more broadly.

Build 2026 is a tighter event than recent editions, running just two days with a smaller in-person attendance cap and a deliberate focus on technical depth.

For developers building on Windows or integrating AI into desktop and enterprise applications, the combination of confirmed tooling announcements, exec-level platform commitments, and a strong Windows session track makes this year's conference worth close attention.

In-person tickets are priced at $1,099, with registrations open by clicking here.

Microsoft is offering visa support for international attendees whose registrations are accepted and will refund tickets if visa applications are unsuccessful.

If you can't make it to San Francisco, the keynote and a selection of sessions stream live for free at the same address, with on-demand recordings available after the event.

source
53
Who needs a Cloud PC, anyway? What's the experience like? How much does it really cost? I've got answers to all those questions.


Ed Bott/ZDNET

My newest PC is the thinnest and lightest I've ever had. It's literally a pixel thick, it weighs absolutely nothing, and it's powerful enough to get me through a full day's work without ever needing a recharge.

I am talking, of course, about my new Windows 365 Cloud PC. It's a subscription-based service that Microsoft is currently offering for 20% off, and I'm halfway through my one-month trial. I've been running my Cloud PC on every device I can get my hands on, including multiple PCs, a MacBook, a five-year-old iPad, and even a Samsung phone. Here it is, running in a Google Chrome tab on a Windows PC.


This Windows 365 Cloud PC is running in a tab in my Google Chrome browser.
Screenshot by Ed Bott/ZDNET


Who needs a Cloud PC, anyway? What's the experience like? How much does it cost? And, most importantly, is that monthly fee worth it? I've got your answers right here.

What's a Cloud PC?

A Windows 365 Cloud PC is a Windows machine that's hosted in Microsoft's data centers. Unlike the older Azure Virtual Desktop, Windows 365 is a fixed, per-user virtual PC that is equipped with dedicated resources (CPU, memory, storage) and runs Windows 11 Enterprise.

The Cloud PC I'm using for this test includes 2 virtual CPUs, 8 GB of RAM, and 128 GB of storage. I can connect to the PC through any web browser, or I can use the dedicated Windows app, which is available for Windows, MacOS, Android, and iOS.


The Windows App (formally known as Remote Desktop) can use Windows Hello to connect to a
virtual PC in the cloud. | Screenshot by Ed Bott/ZDNET


Sign in to the app using your work or school account (sorry, personal accounts aren't supported), and the provisioned Cloud PC shows up in the app or browser window, ready for you to use.

If the Windows app seems familiar, that might be because you've seen it before under its old name -- Remote Desktop. The new version is designed using the WinUI3 framework and is easy to set up. Just sign in using the credentials assigned to your device, with no additional configuration required.

How easy is it to set up?

That depends on how familiar you are with Microsoft 365 administration tools. If you already have a Microsoft 365 Business or Enterprise account, just go to Windows365.com and sign in as an account administrator to set up a trial. It uses the same Microsoft Entra ID credentials you use with that account.

If you don't have a Microsoft 365 account, you need to create a business account with Microsoft; then, optionally, you can attach a custom domain to it. The Microsoft administrative interface can be a little intimidating, but it's not difficult once you learn your way around.

The one-month trial is good for up to 25 users. (A paid account can add up to 300 users.) You need to add a credit card, and the subscription will automatically renew when the trial is up unless you cancel it before the end of the first month.


The first month of a Windows 365 subscription is free, but your credit card will be charged after the
trial ends unless you cancel. | Screenshot by Ed Bott/ZDNET


How easy is it to use?

You can connect to your cloud PC from just about anywhere, including a web browser or using the Windows app.

I found the experience nearly identical on a Windows PC and a Mac, where the keyboard and mouse (and touchscreen on the Windows PC) worked exactly as expected. A nice bonus is that I was able to sign in on my Windows PC using Windows Hello, instead of having to enter credentials manually.

On an iPad, the experience with a touchscreen was difficult. You have to drag the Windows mouse pointer to where you want it, then tap the screen to "click" the remote mouse pointer. Things improved dramatically when I connected a Bluetooth keyboard and mouse to the iPad, and I wouldn't recommend using it any other way.

I was able to install the Android version of the Windows app on a Samsung Galaxy S23 Ultra, but trying to use the Cloud PC on that small screen was impossible. With a USB-C or Bluetooth connection to a larger monitor, though, and a Bluetooth keyboard and mouse, this would be a perfectly good remote PC. (I didn't try this configuration with an iPhone, but I expect the results would be the same.)

If you use a browser as the host, you can expand the Cloud PC session to full screen as well, with a small toolbar at the top to manage the session. You can show or hide that toolbar as needed.

You can use local resources, such as a webcam, microphone, printers, and the host PC's clipboard, on the Cloud PC. As a test, I used Google Chat for a video meeting between a Cloud PC session on an iPad, with a regular Windows 11 PC on the other end. The audio and video performance were both excellent, with no lag.

The best part? When I closed the app or browser window, all my work stayed exactly where it was, and when I signed back in, I was able to pick up where I left off.

How's performance?

I was surprised at first by how long the initial remote session took to open -- I clocked it at a little over 2 minutes and 30 seconds. Reconnecting to a previously open session was much faster, on the order of 10 seconds or so.

In operation, the Cloud PC feels pretty much like running a local PC with equivalent resources. The biggest drag came from the limited RAM on the Cloud PC. At 8 GB, I encountered a bit of memory pressure occasionally, although that would have been true on a physical PC as well.

Office apps ran as smoothly as they do on my local PC and Mac, and YouTube videos and music also played well, without any noticeable glitching in video or audio.

How much does it cost?

The promotions offer cuts the cost of the Cloud PC for one year. The free trial sets up a 2 vCPU/8GB/126GB configuration, which normally costs $36 a month, plus sales tax if applicable. After the trial ends, the special promotional pricing takes effect, bringing the monthly cost of using that virtual PC down to $28.80 (on a month-to-month subscription) or $27.72 with an annual commitment.

Subscribing to a more powerful PC increases the cost significantly. To move up to 16 GB of RAM, for example, the least expensive configuration has 4 vCPUs and 256 GB of storage, and the promotional price is $50.56 monthly ($47.78 for an annual commitment). After the promo period, the price goes to $63.20 a month.

Prices can hit nosebleed levels if you add enough resources. The most expensive combination I found has 16 vCPUS, 64 GB of RAM, and 1 TB of storage. It will cost you $192.93 a month for the first year, after which the price shoots up to $241.16 a month. Ouch.

And no, those prices don't include the desktop Office apps or OneDrive storage. For that, you need a separate Microsoft 365 subscription.

You can see a full Windows 365 Cloud PC price list for US customers here: Windows 365 Business Plans and Pricing.

These prices are for Windows 365 Business licenses, which allow you to add up to 300 accounts. Windows 365 Enterprise has a different set of rules and prices.

Who needs this, really?

If you have Windows 10 PCs that can't be upgraded to Windows 11, this is an expensive way to keep them going for a few more years. A Windows 365 subscription includes Extended Security Updates for Windows 10 until October 2028 at no extra cost.

If you're running a business with hybrid or remote workforce, this option might be very attractive. Instead of buying, configuring, and managing work PCs for employees, you can give them a Cloud PC subscription and let them use whatever personal device they prefer, including Macs and iPads.

The IT staff can manage everything using Intune policies; they don't need to worry about lost or stolen PCs, and they don't have to repair or replace a PC if it breaks or is damaged. In regulated industries, where data has to stay in the corporate cloud and not on local devices, this option is especially attractive.

Having a Cloud PC makes life easier for the remote employees as well, who no longer have to juggle two laptops to switch between work and personal tasks. And they can leave work in progress on the remote PC and come back to it without having to reopen a bunch of apps and files.

The biggest drawback, of course, is cost. Once the promotional pricing ends, my basic configuration will cost $432 a year, and a more powerful virtual PC would cost $758.40 a year. Is that a good deal? It's certainly a premium over the cost of an equivalent physical PC. Mostly, the equation depends on how much you value the reduction in management hassles and the luxury of never having to replace or repair a company PC.

Finally, everything depends on the user having a reliable, fast, low-latency internet connection. If you need to work offline regularly, this isn't for you.

source
54


Chrome is no longer the lightweight browser most people think it is. And if you don’t believe me, just check the storage Chrome is taking up on your PC. Recently, a lot of users have reported Chrome silently downloading a 4GB file on their PC or Mac. And when I checked on mine to confirm, sure enough, it was sitting there too.

What makes the whole situation frustrating is that Google doesn’t ask for any permission before downloading it. There’s no pop-up or even an explanation before the download. The good thing is, Chrome does let you remove the file and reclaim the storage space. But once you understand what the file actually does and why Chrome needs it, you probably wouldn't want to do it.

AI downloads this large deserve an opt-in prompt
They should’ve asked first



If you have Chrome installed on your PC or Mac, there’s a chance a massive file named weights.bin is sitting on your storage drive and taking up nearly 4GB of space. I wouldn’t blame you for not knowing this, because it's a file Chrome downloads silently. You can find the file in Chrome’s directory.

   • macOS: /Library/Application Support/Google/Chrome/OptGuideOnDeviceModel/

   • Windows: %LOCALAPPDATA%\Google\Chrome\User Data\OptGuideOnDeviceModel

This file is essentially the brain behind Chrome’s on-device AI system, also known as Gemini Nano. In simple terms, it contains the machine learning model that allows Chrome to run certain AI features locally on your PC instead of sending requests to Google’s cloud servers.

These AI models help with things like generating text, summarizing an article, and warning you about potential scams. So yes, it’s kind of important. But the problem is the storage it takes, and more importantly, Chrome doesn’t really ask for consent before downloading a file this large. As soon as you interact with a feature that relies on these AI models, it simply downloads the file silently.



Google’s reasoning doesn’t completely convince me
I understand the logic, but I still don’t like it



To be fair, Google has stated legitimate reasons for putting Gemini Nano directly on your PC. According to Google, the local AI model powers important features without constantly sending your data back and forth to the cloud. In theory, that’s better privacy, as some AI tasks happen entirely on your device instead of Google’s servers.

There’s also a practical reason behind this. Running AI models in the cloud is incredibly expensive. Every AI query costs computing power, electricity, and server resources. By shifting some of that workload onto your PC or Mac, Google can reduce the pressure on its own infrastructure while still offering important AI-powered features.

But personally, I still don’t think it fully justifies Google downloading the file without user consent. While Google does mention that the model is supposed to automatically uninstall itself if the device starts running low on storage, there’s no clarity on what that “low storage" number actually is.

Yes, you can delete it, but there’s a catch
Do you really want to?



Technically, it’s possible to get rid of the weights.bin file from your PC or Mac. It’s really no different from deleting any other file, and doing so doesn’t affect your browsing data. The problem is that Chrome will simply redownload the same file and occupy storage space. The only way to reclaim that 4GB permanently is to disable Chrome’s on-device AI features. To do that, open Chrome Settings, switch to the System tab, and turn off On-device AI toggle.

Once disabled, the on-device AI file will disappear automatically, and it won’t come back. Of course, there’s an obvious downside to this. Removing the weights.bin file also means giving up on Chrome's AI features, which include things like summarizing pages and even scan protection tools. And that’s what makes this whole situation complicated.

 absolutely dislike the idea of Chrome silently placing a 4GB AI model on my PC. But at the same time, using a browser without these features in 2026 also feels limiting. So yes, if Chrome had simply shown me the prompt, I’d have clicked Yes anyway, mainly because some of this model also powers security features.

As someone who practically lives inside a browser all day for work, it doesn't make sense to remove Chrome’s local AI model just to free up some storage space. That said, I’ll be keeping an eye on the file to make sure it doesn’t quietly balloon in size as Google continues to add new AI features. If you don’t like the idea of Chrome using this much storage, though, it’s better to switch to a different browser entirely, like Edge, Brave, or any of the other open-source alternatives that’s far more lightweight.

source
55
Not the new features



With the massive announcement of the Googlebook and its upcoming Android-based operating system completely dominating the headlines since last week, it is easy to forget that Google still has a massive fleet of Chromebooks to maintain. To that end, ChromeOS 148 is officially rolling out to the stable channel, and as you might expect given the platform’s new horizon, it is an incredibly quiet milestone.

If you are looking for groundbreaking user-facing features, productivity overhauls, or flashy new UI tricks in this release, you are going to be pretty disappointed. But while it is a boring update on the surface, it carries some critical backend changes that make it worth jumping into your settings menu to trigger the update if it hasn’t hit your device yet.

A pure security and maintenance milestone

The official enterprise release notes for ChromeOS 148 confirm that Google is entirely focused on the fundamentals right now: stability, security, and long-term maintenance.

The single major headline for this release is a backend Certificate Provisioning migration. Google is actively forcing a shift away from its legacy certificate enrollment solutions, moving administrators over to the more modern Certificate Provisioning API that initially debuted back in ChromeOS 142. It is a vital structural update for enterprise and school IT managers who need to ensure seamless, secure network authentication across their fleets before the old method is permanently deprecated at the end of 2026.

Beyond that, the changelog is a textbook definition of maintenance, packing the usual assortment of under-the-hood bug fixes, performance optimizations, and security patches designed to keep your current hardware running tightly.

Setting the stage for the LTS freeze

The quiet nature of ChromeOS 148 makes perfect sense when you look at the upcoming roadmap. Google’s release schedule highlights that ChromeOS 150 – which is slated to drop on Tuesday, July 21, 2026 – will serve as the next official Long-Term Candidate (LTC) release.

For the uninitiated, the Long-Term Support (LTS) channel is what schools and enterprise environments use to lock their devices into a hyper-stable software baseline for months at a time, receiving only critical security patches while skipping the standard four-week feature update cycle. Because Google engineers are gearing up to freeze the code for that massive 150 baseline this summer, these intermediate builds are all about squashing bugs and hardening security rather than introducing potentially volatile new software features.

It might be a boring changelog, but keeping your device on the latest stable build is still the best way to keep your data protected and your hardware running smoothly. The rollout is moving out in stages, so if you don’t see ChromeOS 148 waiting for you in Settings > About ChromeOS just yet, give it a few days to hit your specific device.

source
56


Back in 2001, a tiny startup launched an operating system called Lindows. It was a genuinely ambitious idea: take Linux, add on a compatibility layer for Windows apps, and then sell the resulting OS for cheaper than Windows itself. The name was both a pitch and perhaps the seed of its eventual downfall. Microsoft noticed immediately, and started a two-and-a-half-year legal battle that threatened to unravel one of Microsoft's most valuable trademarks altogether.

What Lindows actually was
A Linux distro designed to poach Windows users



Founder Michael Robertson (who already sold MP3.com to Vivendi Universal for $372 million) started Lindows in San Diego in August of 2001. His main goal was to create a Linux distribution that could run major Windows apps without forcing users to leave Linux entirely to do so. Lindows used Wine for this task, a compatibility layer that's still in use today that translates Windows API calls into Linux compatible equivalents on the fly. Wine was around since 1993, but Linux users had to configure it themselves, the idea here was more of a turnkey solution: install Lindows and your Windows apps just work

The OS was built on Debian Linux, ran the KDE desktop environment (styled to look familiar to Windows users), and featured a paid software storefront called Click 'N' Run (CNR) — an early precursor to the app store model — that let users browse and install both free and commercial Linux software without touching the command line.

As soon as June 2002, Walmart was selling budget PCs with LindowsOS preinstalled, starting at $299, making it the first major retailer to ship Linux-based computers to consumers. Microsoft had 90 percent of the world's PCs at the time, and was fairly hostile to the upstart Linux. That would, of course, change eventually, but not before it tried to litigate this little startup out of existence.

The lawsuit Microsoft probably shouldn't have filed
How "Windows" nearly became a generic word



Microsoft sued Lindows in December 2001, saying that the name infringed on its Windows trademark. The idea was that consumers might confuse the two products. Lindows fired back with a perhaps more damaging argument: "windows" was already a generic term in computing before Microsoft ever trademarked it. Windowing interfaces existed at Xerox PARC and Apple years before Windows shipped in 1985.

US District Judge John Coughenour didn't take to Microsoft's trademark defense right away. He denied the company's request for a preliminary injunction in 2002, which raised questions about whether "Windows" could even be protected as a trademark. In February 2004, he ruled that any jury deciding the case would have to consider whether "windows" was a generic term before 1985, and not as a computing term as we understand it today.

If the case went to trial and a jury decided "Windows" was generic, Microsoft could lose trademark protection for its flagship product's name.

Microsoft went global to squeeze Lindows
The European pressure campaign that worked



OK, so the US case wasn't looking good for Microsoft, so the company took the fight to fronts in Finland, Sweden, France, Belgium, Luxembourg, the Netherlands, Canada, and Spain. European trademark laws were more favorable at the time, and Microsoft won preliminary injunctions in Finland, Sweden, and the Netherlands. The Dutch ruling was the most aggressive: it prohibited Lindows from selling its OS or even operating its website in Belgium, Luxembourg, and the Netherlands.

Lindows tried to keep going. It launched ChoicePC.com and started selling lifetime Lindows memberships for $100 to raise some cash. It renamed the product "Lin---s" in countries that had blocked the Lindows name, though Microsoft's lawyers argued that it wasn't enough. The renamed product eventually became Linspire in April 2004, after Lindows lost its bid to have a US court block Microsoft's European litigation.

The settlement that ended it
Microsoft paid $20 million to buy a name it tried to kill



With a US trial looming and a real risk that "Windows" could be ruled a generic term, Microsoft settled in July 2004. It paid Lindows a total of $20 million, with $15 million up front and $5 million contingent on Lindows handing over its Lindows-related domain names. As part of the deal, Lindows Inc. transferred the trademark to Microsoft and rebranded globally as Linspire.

Tom Burt, Microsoft's deputy general counsel, said the settlement would let Lindows "compete in the marketplace with a name distinctly its own." Lindows CEO Michael Robertson said the terms "make business sense for all parties."

Microsoft spent years and millions of dollars trying to destroy the name and ended up having to buy it.

Linspire continued operating after the settlement, pushing more and more into consumer Linux. It launched a free version called Freespire and even signed deals with Canonical and Mint to offer software through its app storefront CNR. But the brand recognition was gone and the company struggled to find a foothold.

In July 2008, Linspire stockholders voted to sell all company assets to Xandros, a Canadian Linux distributor, and went dormant. Xandros discontinued Linspire in August 2008, and the rights eventually landed with PC/OpenSystems LLC, which relaunched the Linspire name in 2018 as a paid Ubuntu-based distribution.

The legal legacy matters more than the product

The Lindows case is less remembered for the OS and more for what it nearly did to MIcrosoft's most important trademark. Lindows may have lost the name (and eventually, its entire business), but it forced one of the most powerful software companies in the world to pay $20 million as a hedge against possibly having "Windows" declared a generic term in open court. That's a pretty reasonable outcome for a company that was set up on Wine and $100 memberships. Ironically, Microsoft ships its own Linux layer these days, WSL, doing roughly what Lindows was trying to do from the start.

source
57
A cybersecurity researcher has released a proof-of-concept exploit for a Windows privilege escalation zero-day dubbed "MiniPlasma" that lets attackers gain SYSTEM privileges on fully patched Windows systems.

The exploit was published by a researcher known as Chaotic Eclipse, or Nightmare Eclipse, who released both the source code and a compiled executable on GitHub after claiming that Microsoft failed to properly patch a previously reported 2020 vulnerability.

According to the researcher, the flaw impacts the 'cldflt.sys' Cloud Filter driver and its 'HsmOsBlockPlaceholderAccess' routine, which was originally reported to Microsoft by Google Project Zero researcher James Forshaw in September 2020.

At the time, the flaw was assigned the CVE-2020-17103 identifier and reportedly fixed in December 2020.

"After investigating, it turns out the exact same issue that was reported to Microsoft by Google project zero is actually still present, unpatched," explains Chaotic Eclipse.

"I'm unsure if Microsoft just never patched the issue or the patch was silently rolled back at some point for unknown reasons. The original PoC by Google worked without any changes."

BleepingComputer tested the exploit on a fully patched Windows 11 Pro system running the latest May 2026 Patch Tuesday updates.

In our test, we used a standard user account, and after running the exploit, it opened a command prompt with SYSTEM privileges, as shown in the image below.


MiniPlasma exploit successfully gave Windows SYSTEM privileges Source: BleepingComputer
Will Dormann, principal vulnerability analyst at Tharros, also confirmed the exploit works in his tests on the latest public version of Windows 11. However, he said that the flaw does not work in the latest Windows 11 Insider Preview Canary build.

The exploit appears to abuse how the Windows Cloud Filter driver handles registry key creation through an undocumented CfAbortHydration API. Forshaw's original report said that the flaw could allow arbitrary registry keys to be created in the .DEFAULT user hive without proper access checks, potentially enabling privilege escalation.

While Microsoft reports having fixed the bug as part of its December 2020 Microsoft Patch Tuesday, Chaotic Eclipse now claims the vulnerability can still be exploited.

BleepingComputer contacted Microsoft about this additional zero-day and will update this story if we receive a response.

Update 5/18/26: ZeroTrust platform ThreatLocker posted on X that organizations should monitor the following Registry keys for modifications using their EDR platform to detect exploitation:

Quote
\Registry\User\Software\Policies\Microsoft\CloudFiles\BlockedApps*
 
and
 
\Registry\User\.DEFAULT\Volatile Environment*

Researcher behind the recent string of Windows zero-days

MiniPlasma is the latest in a string of Windows zero-day disclosures published by the researcher over the past several weeks.

The disclosure spree began in April with BlueHammer, a Windows local privilege escalation flaw tracked as CVE-2026-33825, followed by another privilege escalation vulnerability, RedSun, and a Windows Defender DoS tool, UnDefend.

After their disclosure, all three vulnerabilities were spotted being exploited in attacks. According to the researcher, Microsoft silently patched the RedSun issue without assigning it a CVE identifier.

This month, the researcher also released two additional exploits named YellowKey and GreenPlasma.

YellowKey is a BitLocker bypass affecting Windows 11 and Windows Server 2022/2025 that spawns a command shell that gives access to unlocked drives protected by TPM-only BitLocker configurations.

Chaotic Eclipse has previously stated that they are publicly disclosing these Windows zero-days in protest of Microsoft's bug bounty and vulnerability-handling process.

"Normally, I would go through the process of begging them to fix a bug but to summarize, I was told personally by them that they will ruin my life and they did and I'm not sure if I was the only who had this horride experience or few people did but I think most would just eat it and cut their losses but for me, they took away everything,"alleged the researcher.

"They mopped the floor with me and pulled every childish game they could. It was soo bad at some point I was wondering if I was dealing with a massive corporation or someone who is just having fun seeing me suffer but it seems to be a collective decision."

Microsoft previously told BleepingComputer that it supports coordinated vulnerability disclosure and is committed to investigating reported security issues and protecting customers through updates.

source
58
Huawei / Huawei's EUV lithography machine goes into trial production
« Last post by javajolt on May 19, 2026, 11:02:21 PM »
China's chip manufacturing ushers in a historic turning point!

Recently, Huawei, in collaboration with the domestic industrial chain, completed the installation and debugging of the first domestically-produced extreme ultraviolet (EUV) lithography machine at the Songshan Lake base in Dongguan, officially entering the chip trial production process.

This breakthrough marks a new stage in China's independence in core technologies in high-end chip manufacturing, and may completely rewrite the global semiconductor industry landscape.



Technological breakthrough: Light source efficiency reaches 3.42%, and production capacity exceeds similar equipment of ASML

The domestically produced EUV lithography machine tested by Huawei uses the laser-induced discharge plasma (LDP) technology developed by Harbin Institute of Technology. The core light source energy conversion efficiency reaches 3.42%, which is close to the international top level.

Test data shows that the equipment can process 250 wafers per hour , surpassing the 195-wafer capacity of ASML's equipment of the same level. The equipment size is reduced by 30% and the cost is only 1/3 of imported equipment.

Unlike the carbon dioxide laser bombardment technology that ASML relies on , the Chinese team directly converts electrical energy through solid pulse lasers, eliminating the complex laser amplification process, reducing power consumption by 40%, and completely bypassing ASML's LPP (laser plasma) patent barriers .

Industry chain collaboration: more than 30 upstream and downstream companies work together to tackle key problems

The breakthrough of domestic EUV lithography equipment is inseparable from the deep collaboration of the domestic industrial chain. Shanghai Lingang has built a lithography equipment industrial park, gathering more than 30 upstream and downstream companies such as Keyi Hongyuan and Guowang Optics:

   - Keyi Hongyuan: Light source technology achieves stable output, and energy conversion efficiency reaches the international leading level;

   - Guowang Optics: The objective lens system has an accuracy of 0.2 nanometers, surpassing the lens jointly developed by ASML and Germany's Zeiss.

In addition, the self-aligned multiple patterning (SAQP) technology developed by Huawei and SMIC has achieved equivalent 3nm chip manufacturing on existing DUV lithography machines, paving the way for the implementation of EUV technology.

Policy and funding: National special investment exceeds 20 billion yuan

The "14th Five-Year Plan" special plan will inject more than 20 billion yuan into the research and development of lithography machines, with a focus on breakthroughs in core components such as optical lenses and laser light sources.



The second phase of the National Integrated Circuit Industry Investment Fund is expected to raise 200 billion yuan, leverage more than 450 billion yuan of social capital, and form a "policy + capital" dual-wheel drive model.

Future plan: Mass production in 2026, yield target 70%

The Huawei team plans to achieve mass production of EUV lithography machines in 2026, and it is expected that the cost of domestic chip manufacturing will be reduced by 40%-50%.

According to the plan:

   - 2027: The yield rate of the pilot production line will be increased from 30%-40% to 60%-70%;

   - 2028: Mass production will be expanded to meet 70% of domestic chip manufacturing needs;

   - 2030: To partially surpass international giants in some areas.

Global impact: China's chip independence is accelerating

The latest report from the Semiconductor Industry Association of the United States shows that the gap between China and the world's top level has been narrowed to 12 months.

With breakthroughs in domestic EDA tools and advanced packaging technologies, China is expected to achieve full-process independence in high-end chip manufacturing around 2028.

A former ASML engineer revealed anonymously that China's EUV prototype has entered the "system assembly-single test" cycle stage, and it is estimated that the full process debugging will take 18 months, and the "changing lanes and overtaking" strategy of domestic technology may significantly shorten this cycle.



Sources:

Reports on Huawei's EUV lithography machine testing progress from Xueqiu , Sina Finance, NetEase and other platforms (June 2025)

Harbin Institute of Technology's official statement on LDP technology breakthrough

Public information on the National 14th Five-Year Plan and Integrated Circuit Industry Investment Fund

source
59

Authored by: Morey J. Haber, Chief Security Advisor, BeyondTrust, and James Maude, Field Chief
Technology Officer, BeyondTrust


As analyzed in the 2026 Microsoft Vulnerabilities Report, Microsoft disclosed 1,273 vulnerabilities in 2025, which represents a dip from 1,360 the prior year. The good news seems to be that total Microsoft vulnerabilities have remained in a stable range from 2020 – 2026.

But those numbers are the wrong ones to watch. Critical vulnerabilities doubled year-over-year, surging from 78 to 157, reversing a multi-year downward trend.

Stability in total vulnerability volume conceals instability in impact, and that is where organizations should focus their attention.

The most important clue in this data is not how many vulnerabilities were disclosed, but where they are concentrated and what they enable threat actors to potentially compromise.



Where the Risk Is Concentrating

The dominance of Elevation of Privilege vulnerabilities (accounting for 40% of all CVEs) combined with a 73% rise in Information Disclosure flaws, tells us attackers are prioritizing stealth and reconnaissance over noisy exploits.

Privilege is where vulnerabilities become breaches. Threat actors no longer need noisy exploits or mass malware campaigns if they can quietly escalate access and move laterally using legitimate credentials and Living Off the Land tactics.

This trend aligns with real-world breach patterns, where initial access is often mundane, but impact is amplified through excessive privilege, misconfigurations, and weak identity controls.

Nowhere is this more concerning than in cloud and business platforms. Microsoft Azure and Dynamics 365 decreased slightly in total vulnerability count, but critical vulnerabilities spiked dramatically, jumping from 4 to 37 in a single year.

Cloud platforms are not just infrastructure anymore. They are crucial to business operations, providing a wide variety of services, including identity and access management, business automation, control planes for entire enterprises, etc.

A critical flaw in these environments poses implications far beyond exposing data. It can cripple an entire workflow (and, ultimately, business operations) and can collapse trust boundaries at machine speed. When cloud vulnerabilities turn critical, the blast radius becomes the defining risk metric.



click image to download report

In practice, a single misconfigured identity in Azure can hand an attacker the keys to your entire tenant, and most organizations wouldn’t know until the damage was done. CVE-2025-55241, a critical Entra ID flaw patched in July 2025, illustrated this precisely: an attacker could forge tokens accepted across any tenant, leaving no trace in victim logs.

On the endpoint and server side, the results are mixed, but still disturbing. Total Microsoft Windows vulnerability numbers declined, yet critical counts remained stubbornly consistent and unnervingly high. Microsoft Windows Server vulnerabilities increased to 780, with 50 classified as critical. Servers remain high value targets because they often run with elevated privileges, host shared services, and provide the foundation for a wide variety of business infrastructure.

Threat actors understand that compromising a server often provides faster and deeper access than compromising a desktop alone. It's a refrain we hear consistently from CISOs: “We patched everything critical, so why are we still getting breached?” This data explains why.

Perhaps the most notable shift in the data is for productivity software. Microsoft Office vulnerabilities surged 234% year over year, rising from 47 to 157, with critical vulnerabilities jumping from 3 to 31 (a 10x increase from last year).

Microsoft Office remains one of the most abused attack surfaces because it sits at the intersection of human behavior, daily operations, and business continuity.

Macros, document sharing, preview panes, HTML rendering, new AI capabilities, and add-ins create a unique landscape for exploitation. When Office vulnerabilities spike, users remain the most reliable entry point via social engineering.

The category trends reinforce a clear pattern: Elevation of Privilege and Information Disclosure are rising together. Attackers are prioritizing stealth and reconnaissance, and when threat actors know your environment better than your own team does, every subsequent incursion becomes easier.

What Organizations Should Do About It

The immediate defense priority is narrowing the blast radius before the next patch cycle. That means auditing standing admin rights, treating service accounts and AI agents with the same scrutiny as human identities, and disabling the Windows preview pane (seven CVEs in 2025 exploited it as an entry point).

For organizations, the takeaway is clear. Patch management alone is insufficient, and organizations must prioritize vulnerabilities that enable privilege escalation, identity abuse, and lateral movement first. That requires context, knowledge of exploits, mappings to frameworks like MITRE ATT&CK, and not just CVSS scores. It also requires rethinking trust assumptions across cloud, endpoint, server, and productivity layers.

The organizations that are ahead of this aren't simply patching faster. They're thinking differently about what privilege means in a cloud-first environment.

In the organizations we work with, AI agents have quickly evolved from a future concern into a present reality almost overnight, and most lack the AI security posture management necessary for proper governance.

Patch management matters, but patches fail to fix excessive privilege or enforce least privilege for AI agents. The ghost in this data isn’t the vulnerability count. It’s everything those vulnerabilities unlock when the identity controls aren’t there to stop them.

For the 2026 landscape and beyond, the 2026 Microsoft Vulnerabilities Report reinforces a hard truth. Threat actors are not breaking down the front door anymore with brute force exploits. They are walking in, escalating quietly, and operating as trusted users, human and machine alike.

If security programs don’t focus on privilege reduction, identity visibility, and continuous risk assessment, the numbers may look stable year over year, but the attack surface and business impact will continue to increase.

Download the complete 2026 Microsoft Vulnerabilities Report now for detailed analysis of Microsoft's vulnerability and security landscape—and what it all means for you.

source
60
Microsoft / Microsoft is killing SMS codes for Microsoft account sign-in
« Last post by javajolt on May 19, 2026, 06:20:08 PM »
Aggressively pushing passkeys on Windows 11


Microsoft is killing SMS login codes for personal accounts

For years, typing in a six-digit code sent to your phone has been the universal standard for verifying your identity online. But that era is officially coming to an end in the Windows ecosystem.

In a statement to Windows Latest, Microsoft independently confirmed that it’ll stop sending SMS codes for personal accounts.

Now, first spotted by Windows Latest, Microsoft has officially announced that it is pulling the plug on SMS codes for personal accounts. According to a support document quietly published earlier this year, the company is actively phasing out text messages as a method for both two-factor authentication and account recovery.

While the tech giant subtly hinted at this shift in a previous security advisory earlier this year, stating it was “committed to advancing security standards,” the newly released documentation explicitly confirms the end of SMS verification.

Moving forward, Microsoft is forcing a transition to passwordless alternatives, mandating the use of passkeys, authenticator apps, and verified secondary email addresses.

Why Microsoft is abandoning SMS authentication

Redmond’s decision to kill off SMS verification comes down to the undeniable fact that text messages are no longer a secure way to protect your digital identity.



In their official advisory, Microsoft states that “SMS-based authentication is now a leading source of fraud.”

“Microsoft is committed to advancing security standards, and as such, we will start phasing out SMS as a method of authentication and account recovery for personal Microsoft accounts,” Microsoft noted in an advisory spotted by Windows Latest. “Microsoft believes that the future of authentication is passwordless, secure, and user-friendly.”

Text messages were never designed with modern cybersecurity in mind. They are transmitted in plain text across vulnerable cellular networks, making them highly susceptible to interception.

Furthermore, hackers frequently use SIM-swap attacks, a tactic where a malicious actor tricks your mobile carrier into transferring your phone number to a device they control. Once the transfer is complete, the hacker instantly receives all of your SMS two-factor authentication codes, allowing them to easily hijack your accounts.

To combat this, Microsoft believes the future of account security is entirely passwordless. The company is replacing SMS with passkeys, which are a modern, phishing-resistant security standard.



Unlike traditional passwords or text codes that can be intercepted, passkeys use your device’s built-in biometric hardware.

When you sign in using a passkey, you authenticate your identity using Windows Hello facial recognition, a fingerprint scanner, or a localized device PIN. This creates a cryptographic key pair where the private key never leaves your physical hardware, rendering remote phishing attacks virtually impossible.

Depending on your setup, passkeys can be device-bound, meaning the private key never leaves the physical hardware (like your laptop’s TPM chip), or they can be synced across your devices via services like Apple iCloud Keychain or Google Password Manager. This cross-device compatibility ensures that if you lose your phone, your verified email and synced passkeys will still allow you to recover your account safely.

The problem of a forced passwordless transition

On paper, eliminating vulnerable SMS codes in favor of biometric passkeys is an objective win for global cybersecurity. In my daily workflow, the passwordless ecosystem is genuinely fantastic. I use Microsoft Edge, Microsoft Password Manager, and the Microsoft Authenticator app across all my devices. Thanks to the IR camera on my Lenovo laptop, Windows Hello face recognition makes logging into my personal Microsoft account a breeze.

However, Microsoft’s forced transition may cause significant headaches for power users.

As a Windows Insider, I constantly spin up, configure, and manage new virtual machines (VMs) to test software builds.

When I attempt to log into my Microsoft account within these isolated, nested environments, the passkey experience falls apart. Biometric hardware won’t be available on a VM, for obvious reasons, and I do not have access to security keys either. When trying to log in with passkeys via PIN, I’m always shown an error.



In these highly technical, edge-case scenarios, requesting an SMS code was the ultimate, foolproof fallback. It just worked.

Passwords and SMS codes are ubiquitous. Typing in a six-digit text code is an instinctive, habitual behavior for billions of people. To successfully change a deeply ingrained habit, the replacement technology must be utterly flawless across every conceivable scenario.

Microsoft could drop the forced Microsoft account sign-in during Windows 11 setup; now that’s one less place where you’ll need to sign in!.

Either way, Microsoft will soon begin prompting all personal account holders with a “Sign in faster with your face, fingerprint, or PIN” screen, urging them to set up a passkey and verify a backup email address. While losing the convenience of SMS codes may be a bitter pill to swallow for some, it is a necessary step to secure Windows 11 against modern threats.

source
Pages: 1 ... 4 5 [6] 7 8 ... 10