Microsoft just banned its own engineers from using AI.
The tool was literally costing MORE than the humans it was supposed to replace.
They lied to you about AI adoption and now the whole narrative is blowing up:
Microsoft gave thousands of engineers access to Claude Code six months ago and encouraged them to use it.
Engineers loved it and adoption exploded. But then the invoices arrived.
Token-based pricing means every query, every code review, every debugging session costs money. At scale across 100,000 engineers, the numbers became so large that Microsoft issued an internal order to cancel nearly all Claude Code licenses by end of June and force everyone onto their own cheaper tool instead.
The company that invested $5 billion in Anthropic just told its own people to stop using Anthropic's product because it costs too much.
Uber's story is even worse...
Their CTO Praveen Neppalli Naga told The Information that the budget he planned for the full year was "blown away already" by April.
Uber had rolled out Claude Code in December 2025. By March, 84% of their 5,000 engineers were using it with 70% of all committed code coming from AI systems.
Heavy users were burning $500 to $2,000 per month each. Naga himself spent $1,200 in a single two-hour demo session.
The company had even built internal leaderboards ranking engineers by how much AI they used. They literally gamified the spending and then ran out of money.
Now look at what Nvidia's own VP of applied deep learning Bryan Catanzaro said to Axios last month. Direct quote:
"For my team, the cost of compute is far beyond the costs of the employees."
This is a VP at the company that SELLS the chips saying that using AI is more expensive than paying humans.
Think about what this means for the entire AI narrative.
Every CEO on every earnings call for the past two years has said the same thing:
AI will make us more efficient, reduce headcount, and cut costs.
The stock market rewarded every company that said it.
Fired workers, stock goes up. Announced AI adoption, stock goes up.
But the actual companies deploying AI at scale are discovering the math doesn't work. The MORE employees use AI, the HIGHER the bill.
Goldman Sachs forecasts a 24x increase in token consumption by 2030 as companies adopt AI agents. Gartner just published a report showing that even though individual token prices will drop 90% by 2030, total enterprise AI costs will go UP because agents consume exponentially more tokens per task than basic tools.
Meta built an internal dashboard called "Claudeonomics" to track which employees use the most AI. Amazon started pushing engineers to "tokenmaxx," their internal term for consuming as many AI tokens as possible.
Both companies are spending hundreds of billions on AI infrastructure this year alone.
And Microsoft, the company that bet its entire future on AI, just told 100,000 engineers to stop using the tool they liked best because the per-token bills got out of control.
The companies building AI are telling investors it saves money. The companies using AI are finding out it costs more than the humans it was supposed to replace. And even the company that makes the chips just admitted it through its own VP.
This is the gap nobody on Wall Street is pricing in.
$725 billion in AI infrastructure spending this year across Big Tech. And the first companies to actually deploy these tools at scale are already pulling back because the economics don't work.
What do you think?
Canadian Artillery Wake-Up Call 🇨🇦
A Canadian soldier falls asleep beside an M777 howitzer during field training… while the rest of his crew decides to give him the worst alarm clock imaginable.
The entire crew absolutely lost it 😂
‼️🚨 BREAKING: Cloudflare's CISO just published what Anthropic's unreleased Mythos did against more than 50 of their own production repos. According to him, Mythos is too powerful and must "include additional safeguards" before releasing to the public.
Turns out the model can chain multiple low-severity bugs into a single severe exploit with a working PoC, where previous frontier models would stop at "interesting bug, unclear if exploitable."
At triage time, that means fewer hedged findings and less time spent asking "is this even real?" A finding that arrives with a PoC is a finding you can act on.
Cloudflare is also explicit about the safety side. The Mythos Preview build provided for Project Glasswing did not include the safeguards present in generally available models like Opus 4.7 or GPT-5.5. The model's organic refusals are real, but Cloudflare states they are not consistent enough to serve as a complete safety boundary on their own, and that any cyber frontier model made generally available in the future must ship with additional safeguards on top of that baseline.
Interesting detail: Cloudflare was not on the original Project Glasswing launch partner list with Apple, AWS, Google, Microsoft, CrowdStrike, and others. Instead they got invited later on.
🚨 NGINX bug (CVE-2026-42945) now under active exploitation.
Critical heap overflow in rewrite module. Attackers can crash workers with one request (possible RCE).
Patch now if using NGINX ≤1.30.0. Check rewrite/if/set rules.
Full details: https://t.co/b0fOIW3dze
🚨 We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase. (1/6)
@RedHatPentester Just as the time between 0day disclosure and active exploitation has drastically reduced, remediation timelines must evolve with the same urgency by leveraging AI tools too
DON'T SIGN IN WITH GOOGLE
DON'T SIGN IN WITH GOOGLE
DON'T SIGN IN WITH GOOGLE
DON'T SIGN IN WITH GOOGLE
DON'T SIGN IN WITH GOOGLE
DON'T SIGN IN WITH GOOGLE
DON'T SIGN IN WITH GOOGLE
If you want to do IVF or you want to remove Fibroid but you don’t have money. Just go to the nearest Access bank in your area and reach the customer service. All you need is just letter from the Hospital and the invoice from the hospital.
Retweet for wider audience
Peel Regional Police is receiving a high volume of reports about scam callers impersonating officers and using spoofed numbers, including our main line 905‑453‑3311.
These callers may request personal information or claim you’re involved in an investigation.
If you receive a suspicious call, do not share personal details.
Learn more about fraud prevention through the Canadian Anti‑Fraud Centre.
Stay alert. Stay informed. Stay safe.
🚨 WARNING: The self-spreading “Mini Shai-Hulud” worm compromised npm & PyPI packages tied to TanStack, Mistral AI, Guardrails AI, OpenSearch & more.
The attack used GitHub OIDC token hijacking and cache poisoning to spread credential-stealing malware across 42 TanStack packages and 84 versions.
Check your dependencies immediately → https://t.co/33fxlrOPzz
🇨🇦 Canada - Threat actor claims sale of “https://t.co/vfDw8m8Sgx” database containing 5.5 million records.
An underground forum post is advertising a database allegedly associated with Canada Life. The actor claims the dataset contains approximately 5.5 million lines of data and shared screenshots showing what appears to be CRM-style record structures.
Based on the visible headers, the alleged dataset may include:
• Full names
• Email addresses
• Phone numbers
• Physical addresses
• Company and employment information
• Geographic/location data
• CRM metadata and account identifiers
• User account attributes and preference fields
The structure shown in the screenshots resembles enterprise CRM/Salesforce-related exports, though this has not been independently verified.
At this stage:
• The claims remain unverified
• There is no confirmation of a direct compromise of Canada Life systems
• The authenticity, origin, and freshness of the data are currently unknown
Large CRM-style datasets are commonly used by threat actors for:
• Business email compromise (BEC) campaigns
• Credential attacks
• Targeted phishing and impersonation
• Corporate reconnaissance
• Identity enrichment and fraud operations
It is also possible that:
• The dataset originates from a third-party vendor or partner
• The information is recycled from older leaks
• The listing is exaggerated or partially fabricated for visibility on underground forums
Organizations handling insurance, healthcare, or financial services data remain high-value targets due to the extensive personal and corporate information they maintain.
Daily Dark Web is continuing to monitor underground communities for additional samples, validation evidence, or official statements related to this claim.
#DDW #Intelligence #Canada #CanadaLife #DataLeak #CyberSecurity #DarkWeb #ThreatIntelligence #OSINT
‼️🚨 Microsoft just patched three critical M365 Copilot data leak vulnerabilities. All three are network-reachable, unauthenticated, and zero-click.
M365 Copilot Business Chat usually has access to a tenant's SharePoint, OneDrive, Outlook, Teams, and more.
▪️ CVE-2026-26129 (M365 Copilot Business Chat): improper neutralization of special elements. Information disclosure.
▪️ CVE-2026-26164 (M365 Copilot Business Chat): output injection into a downstream component. Information disclosure.
▪️ CVE-2026-33111 (Copilot Chat in Microsoft Edge): command injection. Information disclosure.
Copilot was server-side patched, so no customer action is required. Microsoft has published no technical details and there is no PoC.
*⃣THREATS TO SCHOOL PROPERTY*⃣
The Halton District School Board and the Halton Catholic District School Board have received an anonymous bomb threat to the following schools:
Oakville Trafalgar HS
Iroquois Ridge HS
Abby Park HS
White Oaks HS
Garth Webb SS
Appleby College
Holy Trinity HS
Loyola HS
St. Thomas Aquinas HS
To ensure public and student safety there will be an increased police presence at each location while officers conduct searches of school property as part of their investigation. The Halton Regional Police Service have not placed the schools in a hold and secure at this time.
Updates to follow
If you know any young person that wrote JAMB(UTME) this year and scored upto 220...tell him/her to apply for Mastercard Foundation scholarship at Pan-Atlantic University! Deadline is May 22nd!
https://t.co/SoQrb1XNPU
Resharing, someone needs it.
Our security bug bounty program is now public on HackerOne.
We've run the program privately within the security research community, and their findings have strengthened our products. Now anyone can report vulnerabilities and get rewarded.
Read more: https://t.co/li1QvSTCMs
🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-35616
PT ID: PT-2026-30288
Vendor: Fortinet
Product: FortiClientEMS
Description: A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Link: https://t.co/dxaTyv5jh8
#dbugs_vuln
🚨 CRITICAL CYBERSECURITY ALERT: DeepLoad AI Malware Targeting Nigerian Organisation
A new AI-powered malware called DeepLoad is actively targeting Nigerian government agencies, banks, businesses, and individuals.
⚠️ Microsoft says 35,000 users were targeted in an April 2026 phishing campaign across 13,000 organizations in 26 countries.
Attackers used AiTM phishing, CAPTCHA pages, and trusted email services to steal credentials and bypass MFA.
Full story: https://t.co/86uHRxPV8J