Category: Technology

NeuralWired’s Technology section covers the developments reshaping how the world builds, deploys, and regulates digital innovation. We report daily on the stories driving global conversation in artificial intelligence, big technology companies, startups and venture funding, cybersecurity, consumer gadgets and devices, and blockchain and cryptocurrency.

Our technology coverage goes beyond product announcements. When a major AI model launches, we explain what it can actually do and where its claims are overstated. When a startup raises a large funding round, we look at whether the business behind it can sustain that valuation. When a cybersecurity breach hits the news, we explain who is affected and what comes next, not just what happened. Each article is built from original research into primary sources, including company statements, technical documentation, regulatory filings, and verified data, and is written by our editorial team rather than generated automatically.

Readers come to this section for daily updates on the technology stories that matter globally, from shifts inside major technology companies to emerging tools changing how people work, communicate, and build. Whether you are a founder, an investor, an engineer, or simply someone trying to understand where technology is heading next, NeuralWired’s Technology coverage is built to keep you informed without wasting your time on hype.

  • Robinhood Crypto Revenue Falls 38% Q2 2026 Earnings

    Robinhood Crypto Revenue Falls 38% Q2 2026 Earnings

    Robinhood Crypto Revenue Falls 38% as Prediction Markets Overtake It | NeuralWired
    Crypto / Earnings

    Robinhood Crypto Revenue Falls 38% as Prediction Markets Overtake It

    Robinhood just posted a record quarter and still couldn’t outrun the crypto story. On July 29, 2026, the company reported Robinhood crypto revenue of $100 million for Q2, down 38% from a year ago, while a business almost nobody outside the company was tracking two years ago, event contracts, brought in $156 million. That’s the first time prediction markets have out earned crypto trading on Robinhood’s books, and it changes how you should read every headline about “crypto’s comeback” for the rest of 2026.

    If you trade on the platform, build competing products, or just watch where retail speculative money flows next, this print matters more than the EPS beat everyone’s leading with.

    The Numbers That Matter

    Start with the headline figures, because the beat is real. Robinhood posted total net revenue of $1.31 billion, up 32% year over year, a record for the company. Diluted EPS came in at $0.62, well ahead of the roughly $0.43 to $0.45 that analysts compiled by FactSet had penciled in. Net income hit $573 million, up 48%, helped along by a $129 million gain tied to the deconsolidation of Robinhood Ventures Fund I.

    And yet shares slid roughly 3 to 4% in after hours trading on July 29 (they’d already dropped about 3.1% during the regular session). Wall Street didn’t punish the beat. It punished the mix.

    MetricQ2 2026YoY Change
    Total net revenue$1.31B+32%
    Crypto transaction revenue$100M-38%
    Event contracts revenue$156M+10x
    Diluted EPS$0.62+48%
    Crypto notional volume (App + Bitstamp)$40BApp down 35%
    Robinhood Gold subscribers4.8M+39%
    This is the second straight down quarter for crypto specifically. Q1 2026 crypto revenue was $134 million, itself down 47% year over year. Q2’s $100 million is a further 25% sequential drop. That’s not noise. That’s a trend line.

    Why Prediction Markets Just Passed Crypto

    Here’s the moment worth sitting with: event contracts, essentially regulated bets on real world outcomes, generated $156 million in Q2 on 13.6 billion contracts traded, a record. A year ago this line barely registered. Now it’s Robinhood’s fastest growing revenue category by a wide margin, and it’s bigger than crypto trading for the first time ever.

    Robinhood runs this through Rothera, its CFTC licensed joint venture with Susquehanna, and the company has been explicit that this isn’t a side project. Kalshi’s CEO has already named Robinhood as a top competitor in the space, right alongside CME Group and the major sportsbooks. With NFL season starting and 2026 midterm election contracts ramping up, H2 volume in this category is likely to climb further.

    Our read: this signals a rotation, not a retreat. Retail speculative dollars aren’t disappearing. They’re migrating to whichever product offers the cheapest, fastest action, and right now that’s event contracts, not spot crypto trades.

    The Bitstamp Problem: Volume Up, Revenue Down

    The more interesting number is buried in the segment detail. Total crypto notional volume across Robinhood’s platforms was $40 billion: $18 billion on the core Robinhood app (down 35% year over year) and $22 billion through Bitstamp, the institutional exchange Robinhood acquired last year.

    Bitstamp moved more volume than the retail app. It generated a fraction of the revenue, an estimated $6 million against the app’s roughly $94 million, according to figures derived from Robinhood’s own disclosures. Put plainly: Robinhood’s retail app converts crypto volume into revenue at something like 20 times the rate of its acquired institutional venue.

    That gap tells you where the real fee compression is happening. It’s not primarily a retail demand collapse. It’s an institutional and wholesale margin story, and anyone benchmarking crypto exchange health against Robinhood’s numbers should separate the two before drawing conclusions.

    Where the diversification actually shows up

    Crypto now makes up roughly 7.6% of Robinhood’s total revenue, down from about 18% a year ago by CFO Shiv Verma’s own account on the Q1 call. That’s the number that should reframe how you read this earnings cycle. Robinhood didn’t stumble into diversification. It built toward it, deliberately, through Robinhood Chain, the WonderFi acquisition, event contracts, and products like Robinhood Legend and Agentic Trading.

    “Whether it’s the Robinhood Chain, Robinhood Ventures, or Trump Accounts, our product velocity is focused on one goal: making everyone an owner.” Vlad Tenev, Chairman & CEO, Robinhood Markets, Inc. · Q2 2026 earnings release
    “The business is firing on all cylinders.” Shiv Verma, Chief Financial Officer, Robinhood Markets, Inc. · Q2 2026 earnings release
    Two moves closed just outside or right at the edge of the reporting window are worth flagging. Robinhood closed its roughly $180 million all cash acquisition of WonderFi (parent of Bitbuy and Coinsquare) on June 1, formally entering Canada with about 300,000 newly added funded customers. And Robinhood Chain, its Arbitrum based Ethereum Layer 2 for tokenized assets, launched its public mainnet on July 1, one day after the quarter closed, meaning it contributed zero dollars to this print despite already claiming more than $12 billion in cumulative DEX volume and 150 million transactions per a Bernstein research note.

    “We’re bringing the best of traditional finance and DeFi together, and in doing so, expanding financial ownership to every corner of the globe.” Johann Kerbrat, SVP & General Manager of Crypto and International, Robinhood · Robinhood Newsroom, July 1, 2026

    What Analysts Are Saying

    The sell side is split on how much this quarter should worry anyone.

    Bernstein’s Gautam Chhugani, who leads the firm’s digital assets coverage, kept an Outperform rating and a $160 price target even after cutting Robinhood’s full year 2026 crypto trading revenue estimate by 49%. His view: the crypto trading decline matters far less than the infrastructure being built around it, chain, tokenized stocks, Bitstamp, Robinhood Earn, which he frames as the company’s next set of crypto growth drivers once trading stops being the whole story.

    Not everyone agrees the soft patch is temporary. Barclays analyst Benjamin Budish flagged the structural risk back in Q1, and the pattern he described played out again in Q2:

    “Higher fee rates are paid by less active traders, and absent a more meaningful pickup in crypto asset prices, into which we have no visibility, it is hard to imagine this trend improving. Industry wide crypto volumes continue to weaken.” Benjamin Budish, Analyst, Barclays · via CNBC, April 29, 2026
    Both can be true at once. Bernstein is making a multi year infrastructure bet. Budish is describing what happens to the trading line if crypto prices stay depressed. Robinhood’s tightened 2026 operating expense guidance, now $2.675 to $2.775 billion, down from a wider prior range, per FXStreet’s earnings breakdown, could read as discipline or as quiet caution about second half growth. It’s genuinely both, depending on how the next two quarters land.

    What to Watch Through Year End

    Three things will tell you whether this quarter was a turning point or a blip.

    • Q3 2026 earnings, expected late October. This is the first full quarter with Robinhood Chain live the entire time. If chain activity doesn’t start showing up as transaction fee revenue by then, the infrastructure bet needs a longer timeline than the market may be willing to give it.
    • Crypto asset prices in H2. Bitcoin has traded roughly 40 to 46% below year ago levels at various points in 2026. If that persists, expect crypto revenue to keep falling regardless of what Robinhood builds around it.
    • Event contract volume through NFL season and the midterms. This is the line to watch if you’re trying to gauge whether the rotation from crypto to prediction markets accelerates or plateaus once the election cycle passes.
    Is crypto “dying” at Robinhood? Not really, it’s shrinking as a share of a much bigger, more diversified pie, which is a different and less dramatic story than the headlines suggest.


    FAQ

    Why did Robinhood’s crypto revenue drop 38% in Q2 2026?

    Robinhood’s crypto transaction revenue fell to $100 million from $160 million a year earlier as trading volumes softened industry wide. Robinhood App crypto notional volume dropped 35% year over year to $18 billion, while digital asset prices stayed well below year ago levels, cutting trade frequency and fee generation.

    What is Robinhood Chain and when did it launch?

    Robinhood Chain is a permissionless, Ethereum Layer 2 blockchain built on Arbitrum for tokenized real world assets and DeFi. Its public mainnet launched July 1, 2026, one day after Robinhood’s Q2 quarter closed, with day one partners including Uniswap and Pleiades.

    How much crypto volume did Bitstamp process versus the Robinhood app?

    In Q2 2026, Bitstamp processed $22 billion in crypto notional trading volume, more than the Robinhood app’s $18 billion, bringing total crypto volume to $40 billion. Despite the higher volume, Bitstamp generated a much smaller share of Robinhood’s total crypto revenue.

    Are prediction markets replacing crypto trading on Robinhood?

    Event contract revenue reached $156 million in Q2 2026, more than ten times higher year over year, surpassing crypto trading revenue of $100 million for the first time. It signals retail speculative dollars are rotating toward event contracts, not that crypto demand is disappearing.

    Why did HOOD stock fall despite beating earnings estimates?

    Robinhood beat consensus EPS and revenue estimates, but shares fell roughly 3 to 4% in after hours trading on July 29, 2026, as investors focused on the 38% crypto revenue decline and a tightened 2026 expense outlook, which some read as caution about second half growth.


    Related reading: Robinhood’s international crypto expansion is unfolding against a shifting regulatory map, as EU perpetual futures, a UK crypto offering, and the WonderFi acquisition in Canada all land inside the same quarter.

    Want the next earnings breakdown before it hits your feed? Subscribe to The Neural Loop at neuralwired.com/newsletter.

  • cw-check-https://test.com/

    cw-check-https://test.com/

    cw-manager precheck https://test.com/ – https://test.com

  • Coronavirus disease 2019

    COVID-19 is a contagious disease caused by the coronavirus SARS-CoV-2. In January 2020, the disease spread worldwide, resulting in the COVID-19 pandemic.

    The symptoms of COVID‑19 can vary but often include fever,[7] fatigue, cough, breathing difficulties, loss of smell, and loss of taste.[8][9][10] Symptoms may begin one to fourteen days after exposure to the virus. At least a third of people who are infected do not develop noticeable symptoms.[11][12] Of those who develop symptoms noticeable enough to be classified as patients, most (81%) develop mild to moderate symptoms (up to mild pneumonia), while 14% develop severe symptoms (dyspnea, hypoxia, or more than 50% lung involvement on imaging), and 5% develop critical symptoms (respiratory failure, shock, or multiorgan dysfunction).[13] Older people have a higher risk of developing severe symptoms. Some complications result in death. Some people continue to experience a range of effects (long COVID) for months or years after infection, and damage to organs has been observed.[14] Multi-year studies on the long-term effects are ongoing.[15]

    COVID‑19 transmission occurs when infectious particles are breathed in or come into contact with the eyes, nose, or mouth. The risk is highest when people are in close proximity, but small airborne particles containing the virus can remain suspended in the air and travel over longer distances, particularly indoors. Transmission can also occur when people touch their eyes, nose, or mouth after touching surfaces or objects that have been contaminated by the virus. People remain contagious for up to 20 days and can spread the virus even if they do not develop symptoms.[16]

    Testing methods for COVID-19 to detect the virus’s nucleic acid include real-time reverse transcription polymerase chain reaction (RT‑PCR),[17][18] transcription-mediated amplification,[17][18][19] and reverse transcription loop-mediated isothermal amplification (RT‑LAMP)[17][18] from a nasopharyngeal swab.[20]

    Several COVID-19 vaccines have been approved and distributed in various countries, many of which have initiated mass vaccination campaigns. Other preventive measures include physical or social distancing, quarantining, ventilation of indoor spaces, use of face masks or coverings in public, covering coughs and sneezes, hand washing, and keeping unwashed hands away from the face. While drugs have been developed to inhibit the virus, the primary treatment is still symptomatic, managing the disease through supportive care, isolation, and experimental measures.

  • Karpathy Was Right: Context Engineering Wins in 2026

    Karpathy Was Right: Context Engineering Wins in 2026

    Artificial Intelligence / Developer Focus

    Prompt Engineering Is Dead. LangChain’s Data Proves It.

    Published July 30, 2026 · NeuralWired Developer Focus

    Your agent worked flawlessly in the demo. In production, it forgets a tool call from three steps ago, contradicts a document it retrieved 40 tokens earlier, and burns your API budget re-reading its own context window. You rewrite the prompt. Nothing changes. That’s because the prompt was never the problem.

    A new discipline called context engineering has quietly become the line separating engineers who ship reliable AI agents from everyone still fiddling with instruction wording. It’s not a rebrand for the sake of a rebrand. According to LangChain’s June 2026 survey of 1,340 practitioners, 32% of teams cite quality, not cost, as the top barrier keeping agents out of production, and enterprise write-in responses point directly at context management as the root cause. This is the story of how that shift happened, what the data actually shows, and why the skeptics think the industry is getting ahead of itself.

    Quick take: Context engineering means designing everything a model sees before it answers, not just how you phrase the question. Anthropic calls it “the natural progression of prompt engineering.” The data says it’s already the top reason enterprise AI agents fail in production.

    The week “prompt engineering” died on X

    Track the timeline and the shift happened in about nine days. On June 18, 2025, Shopify CEO Tobi Lütke posted that he preferred the term “context engineering” over prompt engineering, describing it as the art of providing all the context needed for a task to be plausibly solvable by an LLM. A week later, Andrej Karpathy, OpenAI co-founder and former Tesla AI director, quote-tweeted him with a line that has since become the industry’s working definition.

    “Context engineering is the delicate art and science of filling the context window with just the right information for the next step.”
    Andrej Karpathy, AI researcher, OpenAI co-founder · via X, June 25, 2025
    The post reached roughly 14,000 likes and 2,600 reposts, which sounds like a vanity metric until you notice how fast the term propagated through actual engineering orgs. Two days later, Simon Willison, creator of Django and Datasette, wrote that the label stuck precisely because prompt engineering had degraded into what he called a pretentious way of describing typing things into a chatbot. His argument wasn’t about branding for its own sake. It was that the old term no longer described what senior practitioners actually spent their time doing.

    By September 2025, Anthropic made it official. In “Effective context engineering for AI agents”, published alongside the Claude Sonnet 4.5 release, the company defined the practice as curating the optimal set of tokens available during inference, a materially different job than wordsmithing a single instruction. Gartner picked up the framing too, predicting the discipline would be embedded in 80% of AI tooling by 2028, though that figure lives behind Gartner’s paywall and is worth treating as widely reported rather than independently verified.

    The data: why 32% is the number that matters

    Twitter endorsements are fun. They’re not evidence. The number that actually justifies the hype arrived in June 2026, when LangChain published its State of Agent Engineering report, a survey of 1,340 professionals fielded between November 18 and December 2, 2025.

    The headline figures build a clear picture. Agents are already in production at 57.3% of organizations, up from 51% a year earlier, and at 67% of companies with more than 10,000 employees. But quality, not budget, is what’s stalling the rest: 32% of respondents named quality as the single biggest barrier to production, and write-in answers from large enterprises specifically called out context engineering and context management at scale as the cause. Add the fact that 89% of organizations have some form of agent observability while only 52.4% run offline evaluations, and you get an industry that’s watching its agents fail without yet having the tooling to systematically fix why.

    Metric Figure Source
    Orgs with agents in production 57.3% (67% at 10,000+ employee firms) LangChain
    Cite quality as the top production barrier 32% LangChain
    Run agent observability vs. offline evals 89% vs. 52.4% LangChain
    Extra tokens used by isolated multi-agent context Up to 15x a standard chat call Anthropic
    That last row is worth sitting with. Anthropic’s own multi-agent research system burns up to 15 times more tokens than a single chat exchange, and the company built it that way on purpose. Isolating context across sub-agents rather than cramming everything into one window is what made the multi-agent approach outperform a single-agent setup. Context engineering isn’t free. It’s a trade-off between cost and reliability, and right now the data says reliability is winning.

    Why a bigger context window won’t save you

    There’s an obvious objection here. If context is the bottleneck, why not just buy a bigger window? Claude and Gemini both expose 1-million-token context by 2026, up roughly 100x from GPT-4’s 8K limit in March 2023. Shouldn’t that make curation obsolete?

    Chroma Research tested that assumption directly. Its Context Rot study ran controlled needle-in-haystack tests across 18 frontier models, including GPT-4.1, Claude 4 Opus and Sonnet, and Gemini 2.5 Pro and Flash. Every single model got measurably less accurate as input length grew, and the degradation started well before any model hit its advertised limit. Position mattered as much as volume: when the relevant fact sat in the middle of a 20-document context, accuracy dropped more than 30 percentage points compared to placing it at the start or end, an effect sharper than earlier “lost in the middle” research had suggested.

    Not everyone treats that finding as settled science. AI commentator Cobus Greyling has pointed out that Chroma runs a commercial vector database business with a direct financial stake in RAG staying relevant, which means the incentive to find that raw context length underperforms curated retrieval deserves a second look, not automatic acceptance. It’s a fair caveat. The underlying pattern, that stuffing a window doesn’t guarantee the model uses what’s in it, has also shown up independently in Anthropic’s and LangChain’s engineering writeups, which is a stronger reason to take it seriously than any single study alone.

    The four strategies engineers actually use

    LangChain’s July 2025 post, “Context Engineering for Agents,” gave the field a shared vocabulary that most production frameworks now build around. Four verbs cover almost everything:

    • Write: persist information outside the immediate context (scratchpads, memory stores) so it doesn’t have to live in the window at all.
    • Select: pull only the relevant memory, tool output, or document into context for the current step, instead of everything available.
    • Compress: summarize or trim what’s already in context before it accumulates into noise.
    • Isolate: split context across sub-agents or sandboxed steps so one task’s clutter doesn’t pollute another’s reasoning.
    Cognition, the company behind the autonomous coding agent Devin, put it bluntly in its own engineering writeup: context engineering is effectively the number one job of engineers building AI agents. Coming from a team shipping a commercial agent rather than a lab publishing a framework, that’s a practitioner’s verdict, not a marketing line.

    The skeptics: is this just a rebrand?

    Not everyone is convinced this is a new discipline at all. Addy Osmani, an engineering leader at Google who writes widely on AI-assisted development, has said plainly that many experienced developers see context engineering as either rebranded prompt engineering or, worse, buzzword creation dressed up as science. He doesn’t stop there, though. He calls the criticism understandable before making his own case for why the distinction still earns its keep.

    “Many experienced developers see ‘context engineering’ as either rebranded prompt engineering or, worse, pseudoscientific buzzword creation.”
    Addy Osmani, engineering leader, Google · via Substack, July 13, 2025
    There’s a sharper version of the same complaint circulating in developer forums: context engineering is just prompt engineering with a PR budget. It’s a punchy line, and it lands because of a real gap in the data. Unlike “prompt engineer,” which briefly commanded its own job postings and reported six-figure salaries back in 2023, there is still no dedicated “context engineer” job title or salary line-item as of mid-2026. The available compensation data covers the broad “AI Engineer” title, not this specific skill, which means the labor market hasn’t caught up to the discourse yet, if it ever fully does.

    Then there’s the naming treadmill itself. Within roughly a year of context engineering becoming consensus vocabulary, a third term started circulating: harness engineering, discussed by OpenAI Codex team member Ryan Lopopolo and analyzed at Martin Fowler’s site around the idea that agents aren’t the hard part, the harness around them is. If that cycle keeps compressing, a senior engineer who masters context engineering this year may be fielding interview questions about harness engineering by next.

    What it means for your career

    Our read: the technical practice here is real and well evidenced. The professional-identity framing, that this “separates senior engineers from everyone else,” is currently more aspirational than measured labor fact. Both things can be true at once, and knowing the difference is what actually helps you plan a career move.

    The market context still favors betting on the skill. AI and ML engineer job postings are up 59% since February 2020 while general software engineering postings are down 49% over the same stretch, according to Indeed Hiring Lab data cited in Pin’s 2026 tech job market report. Median pay for the 823 AI Engineer postings analyzed by Recruiting from Scratch sits at $198,000 in 2026, ranging from $165,000 to $233,000 between the 25th and 75th percentiles. And only about 11.4% of the broader AI and ML candidate pool, across a sample of 1.7 million profiles, carries genuinely current LLM-specific skills. That’s the scarcity context engineering fluency sits inside: not a distinct job title yet, but a real edge within a labor pool that’s still mostly running on 2023-era knowledge.

    If you’re building agents right now, the practical move is to stop treating quality failures as a prompting problem by default. Check where information sits in your context before you touch the wording. Then decide, deliberately, whether it needs to be written to memory, selected on demand, compressed, or isolated in its own step. That’s the actual skill under the label, whatever the label ends up being called next year.

    FAQ

    What is context engineering?

    Context engineering is the practice of designing everything a model sees before it responds, including instructions, retrieved documents, memory, and tool outputs, rather than just refining a single prompt’s wording. Anthropic calls it the natural progression of prompt engineering.

    What’s the difference between prompt engineering and context engineering?

    Prompt engineering focuses on how you phrase instructions. Context engineering focuses on what information the model has access to, including memory, retrieved knowledge, tool outputs, and conversation history, when it generates a response. Most production systems need both.

    Is prompt engineering dead?

    Not entirely, but its scope narrowed. Phrasing still matters for single-turn tasks, but for agents and production systems, engineers now spend most of their effort managing the broader context window rather than wordsmithing instructions.

    Does a bigger context window solve context engineering problems?

    No. Chroma Research tested 18 frontier models, including ones with million-token windows, and found accuracy degraded as input length grew, often well before the advertised limit, which means deliberate curation still matters regardless of window size.

    Who coined the term context engineering?

    The term gained mainstream traction in June 2025, when Shopify CEO Tobi Lütke and researcher Andrej Karpathy both publicly endorsed it on X within a week of each other, with Karpathy’s post reaching roughly 14,000 likes.


    Where this goes next

    Here’s what changes once you see the pattern: agent failures that looked like prompting bugs are usually context bugs wearing a disguise. The evidence for that is no longer just a viral tweet from mid-2025. It’s a 1,340-person survey, an 18-model degradation study, and a token-cost trade-off Anthropic is willing to pay 15x for.

    Over the next 6 to 18 months, watch three things. First, whether “context engineer” ever becomes an actual job title with its own salary data, or stays absorbed into the broader AI Engineer role the way this analysis suggests. Second, whether harness engineering displaces context engineering as the term of art, or turns out to be a subset of it. Third, whether Gartner’s 80% tooling-penetration prediction for 2028 holds up as more vendors ship built-in context management rather than leaving it to hand-rolled agent code.

    For a deeper look at the infrastructure making this possible, our earlier piece on the Model Context Protocol and the agent economy covers the standard now underpinning most production context pipelines. If you’re choosing what to build with, our benchmarked roundup of AI developer tools for 2026 is a useful next stop, and if you’re the one signing off on enterprise rollout, our enterprise AI implementation roadmap covers exactly where teams get stuck on the way to production.

    Want the next shift before it hits your feed? Subscribe to The Neural Loop at neuralwired.com/newsletter.
  • Azure Cosmos DB Vulnerability: CosmosEscape Explained

    Azure Cosmos DB Vulnerability: CosmosEscape Explained

    CosmosEscape: The Azure Cosmos DB Vulnerability That Could Unlock Every Database
    Cybersecurity / Cloud Infrastructure

    CosmosEscape: The Azure Cosmos DB Vulnerability That Could Have Unlocked Every Database on the Platform

    Three headline options for reference (best marked ★):

    1. ★ CosmosEscape: Azure Cosmos DB Flaw Exposed a Master Key
    2. Azure Cosmos DB Vulnerability Could Access Any Database
    3. Inside CosmosEscape: Microsoft’s Cosmos DB Master Key Flaw
    For about eight months, a single cryptographic key sat behind a vulnerability chain that, if exploited maliciously, could have handed an attacker read and write access to any Azure Cosmos DB database on the planet, including ones belonging to Microsoft Teams, Microsoft Entra ID, and Microsoft Copilot. That’s the core of CosmosEscape, an Azure Cosmos DB vulnerability disclosed by Wiz Research on July 30, 2026. Nobody appears to have exploited it. But the mechanics of how close it came are worth every security team’s attention, whether or not you run a single line of Cosmos DB code.

    What Actually Happened

    Picture a bank vault where one master key opens every safe deposit box in every branch, not just the one belonging to the customer standing at the counter. That’s roughly the design flaw Wiz researchers Yuval Avrahami and Lior Maman found inside Azure Cosmos DB’s Gremlin API. They call it CosmosEscape, and according to Wiz’s own technical writeup, the chain could have granted two capabilities to an attacker: pulling the primary access key for any Cosmos DB account on demand, and enumerating every database on the service, filterable by subscription and tenant ID.

    The scope is what makes this different from a typical cloud bug bounty writeup. Cosmos DB isn’t a niche product. Microsoft’s own internal services, including Entra ID, Teams, and Copilot, store data in it. If CosmosEscape had been found and used by someone other than a Wiz researcher operating under responsible disclosure, the practical blast radius would have extended well past any single customer’s environment.

    Key detail security teams tend to miss CosmosEscape also reached private, network-isolated Cosmos DB accounts. The component that got compromised, the DB Gateway, was the same component responsible for enforcing network isolation in the first place. VNet restrictions and firewall rules don’t help if the thing enforcing them is the thing that’s broken.

    How the Exploit Chain Worked

    Cosmos DB runs a custom Gremlin engine that translates graph queries into .NET code behind the scenes. Wiz’s researchers noticed the sandbox restrictions around that engine didn’t fully account for .NET reflection, a language feature that lets code inspect and manipulate itself at runtime. That gap let them build, step by step, a file read primitive, then a file write primitive, then full arbitrary code execution inside the query environment.

    From there, the execution landed on Microsoft’s DB Gateway, the service responsible for running customer queries across Cosmos DB’s multi-tenant Service Fabric clusters. That gateway held a signing key that wasn’t scoped to a single customer account. It worked across tenants, regions, and every API flavor Cosmos DB offers: SQL, MongoDB, Cassandra, and Gremlin.

    “Multi-tenant cloud services require at least one strong isolation boundary around tenant-controlled execution.” Yuval Avrahami and Lior Maman, Security Researchers, Wiz Research · Wiz Research blog, July 30, 2026
    Everything inside that boundary, the researchers argue, has to be treated as untrusted, even when it’s running on infrastructure the customer never sees. CosmosEscape is essentially proof of what happens when a shared-infrastructure component quietly becomes that missing boundary.

    The Disclosure Timeline

    Wiz followed a standard coordinated disclosure process, and the gap between “reported” and “fully fixed” is one of the more interesting data points in this story.

    • November 20, 2025: Wiz reports the vulnerability to Microsoft. Microsoft acknowledges the same day.
    • November 22, 2025: Microsoft deploys an emergency hotfix blocking the vulnerable Gremlin entry point, roughly 48 hours after the initial report, and begins work on a permanent architectural fix.
    • July 2026: Microsoft finishes rolling out the long-term fix across all regions, eliminating the platform-wide key entirely.
    • July 30, 2026: Public disclosure, coordinated between Wiz and Microsoft.
    The Hacker News independently confirmed the same cadence: the entry point blocked within 48 hours, the full architectural fix landing across all regions roughly eight months later. That eight-month gap between hotfix and true closure is worth sitting with. A patched entry point isn’t the same thing as a rebuilt trust boundary, and for eight months, the underlying signing-key architecture that made CosmosEscape possible in the first place was still there, just harder to reach through the original path.

    CosmosEscape vs. ChaosDB vs. CosMiss

    This is the third publicly disclosed tenant-isolation failure tied to Cosmos DB since 2021. They’re technically unrelated, but the pattern is hard to ignore.

    VulnerabilityDisclosedEntry PointRoot Cause
    ChaosDBAugust 2021Jupyter Notebook featureSSRF chain exposing internal access tokens
    CosMiss2022Jupyter Notebook featureRelated notebook misconfiguration
    CosmosEscapeJuly 30, 2026Gremlin graph query APISandbox escape reaching a shared, cross-tenant signing key
    No CVE identifier or CVSS score has been published for CosmosEscape as of this writing, which is unusual for a vulnerability described in these terms. Prior Cosmos DB isolation failures, including ChaosDB, carried CVE tracking. Its absence here means CosmosEscape won’t automatically surface in standard vulnerability scanning or CVE-feed workflows, so compliance teams doing SOC 2 or ISO 27001 vendor risk reviews will need to document this one by hand.

    What Microsoft Says, and What It Doesn’t

    Microsoft’s position, published as part of Wiz’s coordinated disclosure, is that the issue is closed and no customers were harmed.

    “No evidence of unauthorized activity outside of the researcher’s testing activity.” Microsoft, official statement via coordinated vulnerability disclosure · published on the Wiz Research blog, July 30, 2026
    Microsoft says it reviewed access logs, found no customer data was touched, added service-to-service authentication hardening, and states no customer action is required. Fair enough, and there’s no public evidence contradicting that account. But a few things aren’t in the public record yet. Microsoft hasn’t stated how far back its log review actually reached, or when the vulnerable Gremlin engine and signing-key architecture first went into production. The Hacker News says it asked Microsoft and Wiz directly for that clarification and hadn’t received an answer at publication time. That’s not an accusation. It’s just a gap between “we found nothing” and “we know the full window this was exploitable,” and the two aren’t the same claim.

    For a second data point on how researchers think about Azure’s multi-tenant history, look back to 2021’s Azurescape, a different vulnerability entirely, in Azure Container Instances rather than Cosmos DB.

    “This is the first time that a complete takeover of a public cloud system has been demonstrated.” Ariel Zelivansky, Cloud Research Team Lead, Palo Alto Networks Unit 42 · commenting on Azurescape (2021), via Dark Reading. Not a statement about CosmosEscape.
    Zelivansky’s quote is included here strictly as historical context. It’s not about CosmosEscape, and it shouldn’t be read as one. What it does establish is that Azure’s multi-tenant isolation boundary has been the subject of researcher scrutiny for years, across more than one product line.

    On the more critical side, Corey Quinn, Chief Cloud Economist at The Duckbill Group, has written for years about Azure’s recurring tenant-isolation failures, ChaosDB, Azurescape, and the OMI vulnerability among them, arguing they reflect a pattern rather than isolated bugs. Quinn hasn’t commented publicly on CosmosEscape specifically as of this article’s publication, so his view here is a paraphrase of his documented general position, not a quote about this incident. It’s a fair question the industry hasn’t fully answered: is this an architectural pattern at Microsoft, or is it simply that Wiz keeps finding these things because Wiz is good at finding these things? Probably some of both.

    What Security Teams Should Actually Do

    If you’re running Cosmos DB workloads, here’s the honest answer: there’s no patch to apply, because Microsoft already applied it for you. That’s the nature of a platform-level fix. But “nothing to patch” isn’t the same as “nothing to do.”

    • Document the disclosure manually. Because there’s no CVE, it won’t appear in automated vendor-risk or CVE-tracking tooling. Add it to your vendor risk file yourself.
    • Consider a retrospective log review for sensitive Cosmos DB workloads that were active between November 2025 and July 2026, particularly if you handle regulated data, even though Microsoft’s own review found nothing.
    • Revisit your multi-cloud risk model. Wiz’s finding that private, network-isolated accounts were still reachable is a reminder that customer-side controls like VNets and firewall rules can’t fully compensate for a platform-level trust boundary failure.
    • Watch the Black Hat talk. Wiz will present the full exploitation chain at Black Hat USA on August 6, 2026, titled “One Key to Rule Them All: Taking Over a Flagship Cloud Service.” That’s where the deeper technical detail, including proof-of-concept specifics likely held back from the initial blog post, will surface.
    There’s a broader angle here too. Wiz says an early version of its own AI vulnerability researcher, Atlas, assisted in the CosmosEscape investigation. Wiz’s 2026 Cloud Threats Retrospective found that roughly 80% of documented 2025 cloud intrusions traced back to known weaknesses, exposed secrets, and misconfigurations, not novel attack techniques. If AI tooling is now finding sandbox-escape chains like this one faster than isolation architectures are getting rebuilt, that gap is the story to watch through the rest of 2026, not just this single disclosure.

    Why this matters at scale Azure crossed $100 billion in annual revenue for the first time with 43% year-over-year growth in Microsoft’s most recently reported quarter, and Microsoft 365 Copilot passed 30 million paid seats. Cosmos DB isn’t a side product. It’s infrastructure underneath a meaningful share of that growth, which is exactly why a platform-wide key on it is a bigger deal than a typical single-service bug.

    Frequently Asked Questions

    What is CosmosEscape?
    CosmosEscape is a critical vulnerability chain in Azure Cosmos DB’s Gremlin API, disclosed by Wiz Research on July 30, 2026. It let researchers escape a query sandbox to retrieve a platform-wide “Cosmos Master Key” capable of unlocking the primary access key for any Cosmos DB account. Microsoft says it’s fully remediated.

    Is my Azure Cosmos DB account affected?
    Microsoft says the issue is fully remediated across all regions as of July 2026 and no customer action is required. Its log review found no evidence of unauthorized activity beyond Wiz’s own testing, though the exact log-review period hasn’t been made public.

    How is CosmosEscape different from ChaosDB?
    ChaosDB (2021) and CosMiss (2022) exploited Cosmos DB’s Jupyter Notebook feature. CosmosEscape (2026) is a separate vulnerability chain rooted in the Gremlin graph query engine and a shared signing key called the Cosmos Master Key. All three share one theme: multi-tenant isolation failures.

    Did CosmosEscape affect Microsoft Teams or Copilot?
    Cosmos DB stores data for Microsoft Entra ID, Microsoft Teams, and Microsoft Copilot, so those services’ databases were potentially reachable through the flaw. Wiz reported this potential exposure but did not report actually accessing data belonging to those services during its research.

    Was CosmosEscape assigned a CVE?
    No. As of the July 30, 2026 disclosure, neither Wiz nor Microsoft has published a CVE identifier or CVSS severity score for CosmosEscape, unlike some earlier Cosmos DB isolation vulnerabilities.


    Where This Goes Next

    Here’s what’s actually new after CosmosEscape: the entry point changes each time (notebooks in 2021, Gremlin in 2026), but the underlying failure mode doesn’t. A shared-infrastructure component ends up with reach across tenant boundaries, and a well-resourced research team finds it before anyone with worse intentions does. That’s a reassuring pattern until the year it isn’t.

    Three things worth watching over the next six to eighteen months. First, whether Wiz’s Black Hat talk on August 6 reveals proof-of-concept detail that changes the risk calculus. Second, whether Microsoft or an independent party ever publishes the actual exposure window, since that question remains open. Third, whether other hyperscalers face their own version of this story: AI-assisted vulnerability research is getting faster, and Cosmos DB is unlikely to be the last multi-tenant service where it finds something.

    Our read: this isn’t a five-alarm fire for anyone running Cosmos DB today. The fix is real and it’s deployed. But treat the “no CVE, no action needed” framing as the floor of what you should do, not the ceiling. A retrospective log review costs you an afternoon. Skipping it costs you the ability to say, with confidence, that you checked.

    Get stories like this before they hit your feed.

    Subscribe to The Neural Loop at neuralwired.com/newsletter
  • Palo Alto VPN Breach Fuels Zero Trust Surge in 2026

    Palo Alto VPN Breach Fuels Zero Trust Surge in 2026

    Cybersecurity

    Zero Trust Security 2026: Why VPNs Are Getting Ripped Out

    In May 2026, Palo Alto Networks confirmed something security teams had been dreading for years: attackers were actively exploiting an authentication bypass flaw in its GlobalProtect VPN software. Within days, the Qilin ransomware crew had a foothold. Two weeks later, Shadowserver counted more than 167,000 exposed GlobalProtect instances still sitting online, unpatched, waiting.

    This is the story behind the headline number everyone in zero trust security keeps quoting: a market racing from $48.43 billion in 2026 to a projected $102.01 billion by 2031, according to Mordor Intelligence. But the growth curve isn’t the interesting part. What’s interesting is what’s forcing it, and it’s playing out on live infrastructure right now.

    The short version: Four major VPN and firewall vendors, Palo Alto, Fortinet, Citrix, and Check Point, were all hit by active exploitation campaigns in the same window in 2026. Verizon’s newest breach report found vulnerability exploitation overtook stolen credentials as the top attack vector for the first time in 19 years of tracking. Zero trust exists specifically to make that kind of breach survivable.

    Table of Contents

    The $102 Billion Number, and Why It’s Actually a Range

    Ask three analyst firms how big the zero trust security market is, and you’ll get three different answers, none of them wrong, all of them measuring slightly different things.

    Source 2026 Estimate 2031 Projection CAGR
    Mordor Intelligence $48.43B $102.01B 16.07%
    KBV Research n/a $101.39B 16.1%
    Allied Market Research n/a $126.02B 18.5%
    The spread, roughly 25% between the low and high end, comes down to scope. Some firms count only software and licensing. Others fold in professional services, managed detection, and identity infrastructure that touches zero trust without being sold as a “zero trust product.” Treat $102 billion as the working consensus figure and the range as a footnote, not a red flag.

    What all three agree on: this isn’t a niche category anymore. Global information security spending overall is projected to hit $244.2 billion in 2026, up 13.3% year over year, per Gartner’s most recent forecast analysis. Zero trust is eating a growing slice of a budget that’s already growing.

    Why This Is Happening Right Now

    Three things converged in the space of about 90 days that turned “zero trust” from a slide-deck buzzword into an urgent line item.

    First, breach costs hit a record high. IBM’s 2026 Cost of a Data Breach Report, built on 602 breached organizations across 17 countries and interviews with more than 3,550 security and C-suite leaders, put the global average breach cost at $4.99 million, up 12% year over year. In the United States, that average climbs past $11.5 million, more than double the global figure. AI-driven attacks were up 56% year over year and added roughly $1 million to the cost of a breach when present.

    Second, the industry’s own attack data flipped. For the first time in 19 years of reporting, Verizon’s 2026 Data Breach Investigations Report found vulnerability exploitation, not stolen credentials, was the number one initial access vector, responsible for 31% of breaches, up from 20% the year before. Buried inside that number is the statistic that matters most for this story: edge devices and VPNs jumped from 3% to 22% of exploitation-driven breaches. A sevenfold increase in a single year.

    Third, it’s not theoretical. While that report was still fresh, ransomware operators were actively exploiting authentication-bypass flaws across four separate perimeter appliance vendors in the same window: Palo Alto GlobalProtect, Fortinet FortiGate, Citrix NetScaler, and Check Point’s VPN gateway. Median time to patch a known-exploited vulnerability had also risen to 43 days, up from 32 the year before, and only 26% of critical vulnerabilities on CISA’s Known Exploited Vulnerabilities list got patched inside the study window.

    Put those three together and the pitch writes itself: the exact device category that’s supposed to guard the perimeter is now the preferred way in, and it’s costing record money when it works.

    The Perimeter Is Failing on Schedule

    The GlobalProtect case is worth walking through because it shows the whole failure loop in miniature. Palo Alto patched CVE-2026-0257, an authentication bypass rated 7.8 on the CVSS scale, on May 13, 2026. Rapid7 confirmed active exploitation had already begun by May 17. CISA added it to the Known Exploited Vulnerabilities catalog on May 29, with a three-day remediation deadline for federal agencies. Arctic Wolf Labs later tied exploitation of the flaw to the Qilin ransomware-as-a-service operation.

    Four days from patch to active exploitation. That’s the entire window organizations had to close the gap before it became a live incident, and most didn’t.

    It wasn’t an isolated event. Around 75,000 internet-facing FortiGate firewalls were swept up in a parallel campaign nicknamed “FortiBleed.” A Check Point VPN flaw tied to deprecated IKEv1 configurations and a CitrixBleed-style NetScaler bug were both under active exploitation in roughly the same period. Four vendors, one attack pattern, one quarter.

    This tracks a pattern that goes back further than 2026. The original CitrixBleed incidents in 2023 and 2024, and the Ivanti exploitation chain before that, established the same lesson: perimeter appliances sit in slow patch cycles, they’re internet-facing by design, and they’re an unusually efficient target because compromising one grants broad network access rather than a single user’s session.

    “Traditional IAM systems, built for humans, struggle to manage this explosion of non-human identities, blurring the line between trusted and untrusted entities.”
    Mick Leach, Field CISO, Abnormal AI, via SecurityWeek

    Leach’s point matters here because it’s not just user VPN sessions that are exposed. Site-to-site connections, partner integrations, and service accounts running behind these same appliances rarely get the same scrutiny as employee logins, and that’s exactly where a lot of the 2026 campaigns landed.

    What Zero Trust Actually Means

    Strip away the marketing and zero trust is a fairly plain idea: don’t trust a user, device, or application just because it’s inside the network. Verify continuously, based on identity, device health, and context, instead of granting broad access once at the perimeter and assuming everything after that is safe.

    The reference architecture is NIST SP 800-207, published in 2020 and still the standard vendors and federal agencies cite in 2026. CISA’s Zero Trust Maturity Model, currently at version 2.0, breaks implementation into five pillars:

    • Identity, continuous verification of who’s requesting access
    • Devices, checking the health and posture of the requesting device
    • Networks, segmenting traffic instead of one flat trusted zone
    • Applications and Workloads, securing access at the app layer, not just the network edge
    • Data, classifying and protecting data regardless of where it sits
    Three cross-cutting capabilities tie the pillars together: visibility and analytics, automation and orchestration, and governance. In June 2026, CISA published an updated guide in its “Journey to Zero Trust” series to help federal civilian agencies migrate off legacy TIC 2.0 perimeter architectures toward the newer TIC 3.0 and SASE-supported models, the most recent official movement on the government side.

    The Money Is Already Moving

    Analyst projections are one thing. Actual revenue is another, and here the numbers back up the forecast instead of just feeding it.

    Zscaler, a pure-play zero trust vendor, reported Q2 FY2026 revenue of $815.8 million, up 26% year over year, with annual recurring revenue at $3.36 billion, up 25%. Palo Alto Networks, taking the platform-consolidation route rather than the pure-play one, saw its Next-Generation Security ARR reach $6.33 billion in the same quarter, up 33% year over year, then climb to $8.13 billion, up 60% year over year, by Q3.

    Almost two-thirds of organizations globally have fully or partially implemented a zero trust strategy, according to a Gartner survey of 303 security leaders. Of those, four in five say they have metrics in place to measure whether it’s actually working.

    Our read: the fact that Palo Alto, a company that also sells the appliances getting exploited, is growing its zero trust revenue faster than its pure-play competitor says something. Enterprises aren’t necessarily ripping out every vendor relationship. They’re demanding that existing vendors prove they’ve moved past the perimeter model.

    The Case Against Zero Trust Hype

    No serious security leader thinks zero trust is a silver bullet, and the person who arguably built the framework’s modern reputation is also its sharpest internal critic.

    “Security is not a product, but a combination of strategy, process, and execution. Zero Trust is not just an architecture, it’s a mindset. There is no Zero Trust product, period.”
    Dr. Chase Cunningham (“Dr. Zero Trust”), creator of the Zero Trust eXtended framework, former Principal Analyst at Forrester, via drzerotrust.com

    Cunningham’s argument, echoed across multiple interviews, isn’t that zero trust doesn’t work. It’s that the market around it has splintered into thousands of overlapping vendor tools all marketed as one-stop “zero trust” fixes, and organizations chase the label instead of the architecture. Passing an audit or buying a badge, in his framing, is the floor, not the ceiling.

    Gartner’s own analysts have made a related, more specific warning: attackers are shifting toward vectors zero trust controls don’t fully cover, including public-facing APIs, social engineering, and policy workarounds employees create themselves to get around strict access rules. Is that a reason to skip zero trust? No. But it’s a reason not to treat it as complete coverage.

    Cost is the other honest limitation. In that same Gartner adopter survey, three in five organizations that implemented zero trust said they expect costs to rise, not fall, and two in five expect staffing needs to increase. That directly undercuts any pitch that frames zero trust as a savings play. It’s a risk-reduction investment, not a budget cut.

    Watch for this failure mode: the most common partial-migration pattern is deploying zero trust network access for remote employee logins while leaving legacy VPN appliances live for site-to-site and partner connections. That gets you the compliance messaging without closing the gap attackers are actually using. The 2026 ransomware wave hit exactly these hybrid setups.

    What This Means If You’re Running Security

    If you’re a CISO or infrastructure lead, the budget conversation has quietly shifted from “should we do zero trust” to “which pillar are we weakest in,” and CISA’s five-pillar model doubles as a ready-made audit checklist. Expect more internal scrutiny of VPN and firewall patch cadence specifically, given the 43-day median patch time against a four-day exploitation window in the GlobalProtect case.

    If your organization still runs internet-facing VPN concentrators or SSL-VPN gateways as the primary remote-access control, that’s not a hypothetical risk anymore. It’s a documented, current pattern across four major vendors. Replacing appliance-based remote access with identity-aware access is the specific fix for the specific gap attackers used in 2026.

    Non-human identity is the piece most implementations still miss. Service accounts, bots, and AI agents now operate inside enterprise networks at a scale traditional human-focused IAM and MFA was never built for, and that’s precisely where AI agent adoption is accelerating fastest.

    Frequently Asked Questions

    What is zero trust security?

    Zero trust is a security model built on “never trust, always verify.” No user, device, or application is trusted by default, even inside the traditional network perimeter. Access is continuously verified using identity, device posture, and context. NIST SP 800-207 remains the reference standard.

    Why are companies moving away from VPNs?

    Verizon’s 2026 DBIR found edge devices and VPNs accounted for 22% of exploitation-driven breaches, up from 3% the year before, a sevenfold jump. Active 2026 ransomware campaigns exploited authentication-bypass flaws in Palo Alto, Fortinet, Citrix, and Check Point VPN appliances.

    How big is the zero trust security market?

    Estimates vary by analyst firm. Mordor Intelligence projects the market reaching $102.01 billion by 2031, up from $48.43 billion in 2026. Other firms estimate as high as $126.02 billion by 2031, depending on scope and segmentation methodology.

    Is zero trust worth the cost?

    Gartner surveys found three in five adopters expect costs to rise after implementing zero trust, and two in five expect higher staffing needs. IBM’s 2026 data shows the average breach now costs $4.99 million globally, $11.5 million in the US, which most CISOs weigh against that up-front investment.

    What are the five pillars of zero trust?

    CISA’s Zero Trust Maturity Model defines five pillars: Identity, Devices, Networks, Applications and Workloads, and Data, supported by three cross-cutting capabilities: visibility and analytics, automation and orchestration, and governance.

    Who invented zero trust?

    The term and concept are credited to John Kindervag, who introduced zero trust as an analyst at Forrester in 2010. NIST formalized the architecture in SP 800-207 in 2020.

    Where This Goes Next

    Here’s what’s different about 2026 compared to earlier zero trust hype cycles: the evidence now runs in both directions at once. The market data says adoption is mainstream, not niche. The breach data says the thing zero trust replaces is failing in real time, at scale, across every major perimeter appliance vendor. Those two data sets rarely line up this cleanly.

    Over the next 6 to 18 months, watch three things. First, whether CISA’s federal deadlines slip again, agencies have a track record of missing them, and Gartner has previously predicted a majority of federal agencies would fail to fully implement zero trust on schedule due to funding and staffing gaps. Second, whether non-human identity management, the gap Mick Leach flagged, becomes its own funded category rather than a bolt-on to existing IAM tools. Third, whether the vendors currently getting exploited, Palo Alto, Fortinet, Citrix, Check Point, can out-patch the four-day exploitation windows that defined this year’s incidents.

    None of this means zero trust is finished the day it’s deployed. It means the alternative, standing perimeter hardware as your primary defense, has a documented, current, multi-vendor failure record. That’s a harder thing to argue with than a market forecast.

    Want the next breach report and vendor exploitation update before your competitors see it? Subscribe to The Neural Loop at neuralwired.com/newsletter.

  • SEC XRP ETF Rules 2026: What Actually Changed

    SEC XRP ETF Rules 2026: What Actually Changed

    Crypto ETF Regulation 2026: How Access Changed
    Crypto & Regulation

    Crypto ETF Regulation 2026: How Access Changed