AI News: Microsoft Cuts 4,800, JadePuffer Hits, Alberta Claude

July 7, 2026 roundup: Microsoft cuts 4,800 jobs; first AI-driven ransomware; Alberta scans 466M lines of code with Claude; LeRobot v0.6.0; Tencent Hy3.

Top Stories

Microsoft Cuts 4,800 Roles Across Xbox and Commercial Sales, Reframes Cuts as a Management Flattening

On July 6, 2026, Microsoft announced layoffs of roughly 4,800 employees, about 2.1% of its global workforce. About 1,600 of the cuts land inside Xbox, whose cuts are expected to total about 3,200 through fiscal year 2027, the most significant restructure in Xbox history by Xbox CEO Asha Sharma’s own framing; Xbox operates at margins “3-10x lower than comparable platform and publishing businesses” and faces the “most severe hardware crisis” in industry history. Management layers are being compressed from 14 to no more than 5 (ideally 3), and Microsoft is returning Compulsion Games and Double Fine Productions to independent studios while moving Ninja Theory and Undead Labs under new ownership.

The interesting note is the framing. Amy Coleman, EVP and Chief People Officer, told TechCrunch the eliminated roles “are not being replaced by AI,” but acknowledged “AI is changing how work gets done.” Read alongside the TechCrunch running list of AI-cited 2026 layoffs - Oracle 21,000, Cisco 4,000, Intuit 3,000, Block 4,000, Dell ~11,000 - the practical signal is that “not being replaced by AI” is the new default verbal disclaimer for what is, in aggregate, a 120,000-person 2026 tech-job contraction (a pattern our March 2026 AI-washing layoffs coverage has been documenting since the start of the year). Microsoft also opened a $2.5 billion “Frontier Company” AI deployment unit in the same window, which is the side of the ledger the press release is shorter on.

The First “Agentic Ransomware” Attack Still Required a Human Operator

Cloud security firm Sysdig has documented what it calls the first known case of “agentic ransomware” in an operation it has named JadePuffer. The AI agent entered through a known bug in Langflow, an open-source LLM app-building tool, moved to a production MySQL server, exploited another known flaw for admin access, and encrypted over 1,300 configuration records. At one point the agent fixed a failed login in 31 seconds and narrated its reasoning in natural-language code comments. It also wrote the ransom note itself, including a Bitcoin payment address. JadePuffer is the clearest example yet of the on-device attacker-AI pattern we covered when ESET documented PromptSpy weaponizing Gemini back in February.

The catch is that a human was still required at every irreversible step: choosing the victim, provisioning the command-and-control server, and supplying stolen credentials from a prior compromise. Sysdig’s senior director of threat research Michael Clark told CyberScoop that stolen API keys for OpenAI, Anthropic, DeepSeek, and Gemini were among the loot, but were not necessarily evidence of which model drove the attack. The most useful read on this is the one Microsoft researcher Geoff McDonald posted to LinkedIn: an open-weight model with safety training stripped was likely used, and the human’s job is shifting from doing the keystrokes to choosing what the agent does next.

Alberta Scanned 466 Million Lines of Government Code With Claude in 20 Hours

The Government of Alberta announced on July 6 that it used Claude (Opus and Sonnet) with Claude Code to assess 466 million lines of code across the Ministry of Technology and Innovation’s ~1,280 applications and 3,400 code repositories in 20 hours, with roughly 50 agents running in parallel. Alberta’s traditional estimate for that scan was about 6.5 years. Two of the rebuilt systems cited in the case study: a 25-year-old Java subsidy portal rebuilt in 4-5 days (originally took 5 months); and a planned consolidation of 185 legacy applications in one ministry into 16 reusable modern applications.

Minister of Technology and Innovation Nate Glubish said on the record that “by using AI to find and fix vulnerabilities across our systems, we accomplished in hours what would have taken a traditional approach years to complete,” and added that “Albertans trust their government with some of the most sensitive information in their lives, and it is our responsibility to protect it.” The privacy-relevant signal for readers is that this is one of the first published first-party deployments of agentic AI directly into a government code base at province scale, with red-team and blue-team agents built on the Claude Agent SDK running each application against ~95 security controls per pass. The Alberta AI Academy has also trained thousands of government staff and 10,000+ public members.

Hugging Face Releases LeRobot v0.6.0 With World-Model Policies and a Reward Models API

Hugging Face published LeRobot v0.6.0 on July 7, 2026, headlined by a new world-model policy family and a dedicated reward-models API. The release bundles three world-model policies (VLA-JEPA built on Qwen3-VL-2B; LingBot-VA as an autoregressive video-action model that runs on a single 24-32 GB GPU; and FastWAM, a ~5B video-gen-plus-action-expert pair that skips “dreaming” at inference), five new vision-language-action models including NVIDIA’s GR00T N1.7 and Allen AI’s MolmoAct2, and a lerobot.rewards module with two reward models (Robometer, trained on 1M+ trajectories, and TOPReward, a zero-shot model that reads a “True” token log-prob).

The codebase changes are also significant: roughly 40% fewer base dependencies, PyTorch 2.7-2.11, CUDA 12.8, FSDP support via Accelerate, HF Jobs cloud training scaling from T4 to 8x H200, a lerobot-rollout CLI with five rollout strategies (including DAgger-style human-in-the-loop corrections via foot pedal or leader arm), and a lerobot-annotate CLI built on Qwen2.5-VL-7B-Instruct. Six new benchmarks via lerobot-eval round it out, including LIBERO-plus with ~10,000 perturbations. For local-AI and open-source robotics, this is the largest single release of the year.

Tencent Releases Hy3, a 295B Open-Weight MoE Model Under Apache 2.0

Tencent’s Hy Team released Hy3 on July 6, 2026, a 295B-parameter Mixture-of-Experts model with 21B active parameters and a 3.8B MTP (multi-token-prediction) layer, distributed under Apache 2.0 with a 256K context length. Simon Willison notes the full-sized model is 598GB on Hugging Face and the FP8 quantized version is 300GB, and that it is available free on OpenRouter until July 21, 2026. Tencent’s own framing is that Hy3 outperforms similar-size open models and rivals flagship open-source models with 2-5x more parameters.

For local-AI readers, this is the third very-large open-weight MoE to land in roughly a week, on top of the DeepSeek and GLM-5.2 traffic that Vercel’s Guillermo Rauch specifically called out when describing why Vercel’s gateway is now multi-provider rather than single-lab. Rauch’s quote in the same conversation: “we’re deciding on whether the model and the agent are going to be coupled.” The practical read is that any organization still betting on one-lab commitments is now behind the curve.

Reddit Built LLM Tools to Fight Spam LLMs Largely Created

Reddit disclosed on July 6, 2026 that it has built its own LLM-based moderation stack to fight spam that is now also LLM-generated. Reddit reports blocking 23 million spam views daily, catching roughly 25,000 new spam posts and comments per day, and posting a 20% reduction in user spam exposure from January to March versus the prior quarter. The Reddit blog says the LLMs catch “highly subtle, coordinated patterns of fake behavior” that older systems miss.

It is the cleanest published case of an AI-vs-AI moderation arms race so far. Other platforms’ approaches vary: YouTube, Meta, and Instagram permit AI content with disclosure, while TikTok now lets users adjust the volume of AI content they see.

Quick Hits

  • Vercel processes over 1 trillion AI tokens daily: Vercel CEO Guillermo Rauch told TechCrunch that Vercel’s AI gateway now moves more than 1 trillion tokens per day, with roughly half of the platform’s 6 million daily deployments triggered by coding agents.
  • SK Hynix US IPO could raise around $28B: TechCrunch reports SK Hynix plans to sell ~17.8 million ADRs in a US listing; Q1 revenue was up nearly 200% year-over-year and the stock is up about 260% year-to-date on the AI memory boom.
  • AI-cited tech layoffs total ~120,000 in 2026: TechCrunch’s running list puts 2026 tech-job cuts at roughly 120,000 per Layoffs.fyi, with May the highest single month for layoffs and AI the top-cited reason per Challenger, Gray & Christmas.
  • Apple raises Mac and iPad prices on memory pressure: SK Hynix coverage notes Apple has raised Mac and iPad prices as the AI-driven DRAM, NAND, and HBM shortage dubbed “RAMageddon” ripples through consumer hardware.
  • Hugging Face ships kernel updates: HF’s Kernels blog post on July 6 introduces a dedicated kernel repository type, Sigstore-based cosign signing, and Apache TVM FFI support alongside Torch, narrowing the gap with Ollama’s “ship the runtime with the model” approach.

Worth Watching

The EU Parliament second-reading vote on Chat Control 1.0. Per Heise’s July 4 reporting, the Council of Ministers adopted its position via written procedure on July 2, 2026, and the Parliament second-reading vote is now scheduled before summer recess - when assembling the absolute blocking majority needed to reject it is hardest. (We broke down the Council’s fast-track Chat Control 1.0 revival here on July 6.) Voluntary AI and hash-based scanning of encrypted messenger, webmail, and VoIP traffic would resume, with processed content and traffic data required to be irrevocably deleted no later than 12 months after detection. Watch for the vote date and whether the absolute majority shows up.

The first “agentic ransomware” disclosure as a precedent. Sysdig’s JadePuffer writeup is the first named case of an LLM agent driving an extortion event end-to-end, and the cleanest read of where humans still sit in the kill chain. Watch for follow-on disclosures from other incident-response firms (Mandiant, CrowdStrike, Unit 42) on whether this was a one-off or a pattern - that answer decides whether “AI-driven ransomware” becomes a named category in 2026 cybercrime reports.

Open-weight model cadence. Three very-large MoE releases (Hy3, plus the DeepSeek and GLM-5.2 traffic Vercel is already routing) in roughly a week means the local-AI story for Q3 is no longer single-lab. Watch for whether Hugging Face, Ollama, or llama.cpp ship first-party Hy3 builds, and whether the Apache 2.0 license pulls Hy3 into the same enterprise tier as DeepSeek and GLM.

Alberta as a government-scale Claude case study. If the Ministry of Technology and Innovation publishes follow-on numbers (rebuild time, vulnerability count pre- and post-scan, audit results from continuous monitoring), Alberta becomes the first government-scale agentic-AI deployment with reproducible before-and-after numbers. Watch for the Industry Day in Edmonton in July and the fall 2026 scaling-program kickoff.