The AI coworker has arrived. Are you ready?
Plus: a 15-year Linux bug, Apple's secret weapon, and a ransomware negotiator's dark secret.
⚡ Sparked Weekly
What's sparking in tech this week · July 13, 2026
This week, AI stopped being a tool and started applying for jobs. OpenAI wants ChatGPT to run your calendar, answer your emails, and generally do the parts of work you hate most. Meanwhile, the security world had a rough seven days — a hidden Linux bug survived 15 years before an AI caught it, and a ransomware negotiator turned out to be working for the wrong team. Buckle up.
AI
OpenAI ChatGPT Work Turns Chatbot Into Autonomous Office Agent
This is not another chatbot upgrade where the headline feature is slightly better grammar. ChatGPT Work represents a genuine architectural shift. Instead of answering questions when prompted, the system is built to monitor your workflow, identify what needs doing, and act on it. Think less 'smart assistant' and more 'that colleague who just handles things before you even ask.'
The practical implications here are significant. Anyone who has spent a Monday morning triaging a flooded inbox or playing calendar Tetris with a distributed team knows how much cognitive energy that burns before real work even begins. Offloading that coordination layer to an AI agent could genuinely reclaim hours in the week, not minutes.
But let's not breeze past the trust problem. Giving any software autonomous access to your email, your Slack messages, and your calendar is a meaningful decision. These are not spreadsheets. They contain sensitive conversations, unreleased business information, personnel matters, and a level of organizational context that most companies would never hand to a third-party vendor without serious legal review. OpenAI will face hard questions about data handling, retention, and what the model actually learns from processing all of that.
The competitive context matters too. Microsoft has been building Copilot deeply into the Office 365 stack for over a year. Google is threading Gemini through Workspace. OpenAI is essentially entering a fight that its biggest distribution partners are already winning on home turf. ChatGPT Work needs to be meaningfully better, not just comparable, to pull enterprise buyers away from tools already embedded in their existing software contracts.
There is also a workforce dimension worth sitting with. Autonomous agents handling scheduling, email triage, and task routing are not replacing knowledge workers wholesale, but they are compressing the value of certain entry-level roles that involve exactly this kind of coordination work. Organizations will need to think carefully about what they are optimizing away.
For now, ChatGPT Work is the clearest signal yet that OpenAI is serious about the enterprise market as a revenue foundation, not just a side audience. The chatbot era may not be over, but the agentic era is clearly what OpenAI is betting on next.
SECURITY
AI Uncovers 15-Year-Old Root Bug Hidden in Linux Kernel
The vulnerability, tracked as CVE-2026-43499 and nicknamed GhostLock, is what security researchers call a use-after-free flaw. The short version: it lets any regular logged-in user — no special permissions, no network access required — take complete root control of an unpatched machine. It shipped by default in virtually every major Linux distribution starting in 2011, meaning the bug has been running silently on servers, desktops, and cloud infrastructure for over a decade and a half.
Nebula Security found it using VEGA, the company's AI-powered bug-hunting tool, which has been systematically combing through old kernel code that most human researchers stopped rereading years ago. That's the quiet but important detail here: the bug wasn't hidden in some obscure corner that was hard to reach. It was hiding in plain sight, in code that millions of systems depend on, simply because nobody had looked closely enough in a long time.
The exploit Nebula published is not theoretical. It works. In internal testing, it was 97 percent reliable, and it can escape containerized environments — which is a particular nightmare for cloud and DevOps teams who assume container boundaries offer meaningful protection. The find earned Nebula a $92,337 payout through Google's kernelCTF program, which exists specifically to reward this kind of deep kernel research.
The fix landed in April, which sounds reassuring until you check the patch status across actual distributions. Ubuntu, as of early July, still listed three of its long-term support versions — 24.04, 22.04, and 20.04 — as either vulnerable or actively being worked on. So if you're running Ubuntu and assuming a patch is already waiting for you, verify that assumption before you move on with your day.
The broader story here is less about this specific bug and more about what AI-assisted security research is starting to look like in practice. GhostLock is not a one-off. Nebula has surfaced a string of Linux privilege-escalation vulnerabilities this year using the same automated approach, and other teams are doing similar work. The pattern is consistent: automated tools are re-reading old, trusted code with fresh eyes and finding things that years of human review missed.
That's both encouraging and uncomfortable. Encouraging because defenders now have better tools to find these problems first. Uncomfortable because the same approach is available to anyone — including people whose intentions are considerably less responsible than publishing a CVE and collecting a bounty. The race between finding and exploiting old bugs just got a significant speed upgrade on both sides.
AI
Apple's Abandoned Self-Driving Car Secretly Built Its Best AI Chips
Here's the twist: when Apple's engineers started seriously thinking about what a self-driving vehicle would actually need under the hood, they ran headfirst into a hard problem. Real-time AI processing — the kind that keeps a two-ton vehicle from making fatal decisions — couldn't rely on the cloud. It had to happen on-device, instantly, without waiting for a server ping. So Apple's chip team got to work building something that could do exactly that. The car never shipped, but the silicon philosophy behind it did.
That work eventually became the Neural Engine, which quietly debuted inside the A11 Bionic chip in the iPhone X back in 2017. At launch, most people thought of it as the thing powering Face ID and those goofy Animoji. Fair enough. But Apple was playing a longer game. The Neural Engine was a foundational bet that on-device AI processing would eventually matter enormously — a bet that looks a lot smarter now than it did then.
When Apple made the jump to its own Mac chips with the M-series lineup, the Neural Engine came along for the ride. That decision gave Apple something its competitors are still scrambling to replicate: a coherent story about AI that doesn't require sending your personal data to a data center in Virginia. It's a genuine privacy advantage, not just a marketing talking point.
The software side of Apple Intelligence has been, to put it charitably, a work in progress. Siri remains the butt of jokes, and the company's generative AI rollout has felt cautious to the point of timid. But the hardware underneath? That part has been legitimately impressive, and it's increasingly where Apple is placing its chips — pun intended.
According to Bloomberg's Mark Gurman, Apple is now doubling down on that hardware edge in a significant way. The company is reportedly skipping the Pro, Max, and Ultra variants of the upcoming M6 chip entirely and fast-tracking development of the M7, expected to land sometime in the first half of 2027. The M7 Ultra is the one to watch: it's projected to support up to 1.5 terabytes of unified memory, which is a staggering number that puts it squarely in server territory.
That server angle is deliberate. Apple is reportedly planning a new server product built around the M7 Ultra, which would let it run more powerful AI models in its own data centers while keeping its privacy-forward architecture intact. For a company that has always been squeamish about the cloud, building its own AI server infrastructure is a significant philosophical shift.
The irony here is pretty rich. Apple spent years and reportedly billions of dollars trying to build a car that never existed. What it got instead was a chip architecture that could define its next decade. Sometimes the best products come from the projects that never ship.
SECURITY
Ransomware Negotiator Secretly Worked for the Attackers He Represented
Angelo Martino, a ransomware negotiator who worked for a company called DigitalMint, was sentenced this week to 70 months in federal prison after pleading guilty to conspiring with the BlackCat ransomware group to extort the very clients he was supposed to help. His job was to sit across the table from cybercriminals and negotiate ransoms down. Instead, he was slipping those criminals confidential details about his clients' negotiating positions so they could drive the price up — and taking a cut of the inflated payments for himself.
The ransom payments from his five victims ranged from $213,000 on the low end to a staggering $26.8 million at the top. Martino collected his proceeds in cryptocurrency, and by the time the FBI caught up with him, he had already converted a significant chunk of it into two houses in Florida, a boat, and multiple vehicles. The government is now requiring him to forfeit property and hand over 10 percent of his post-release income to compensate victims.
Martino wasn't operating alone. Two colleagues were also charged: Kevin Martin, another DigitalMint negotiator, and Ryan Goldberg, an incident manager at cybersecurity firm Sygnia. Both were sentenced to four years in prison earlier this year. Martino tried to leverage his cooperation with prosecutors against Martin and Goldberg to argue for a shorter sentence — he asked for 24 months. The judge gave him nearly three times that.
The victim list includes companies across hospitality, finance, retail, healthcare, and the nonprofit sector. Beyond the financial damage, prosecutors noted that some of these organizations had their ability to serve customers meaningfully disrupted during the scheme, which ran from April to September 2023. A medical company and a financial services firm being locked out of operations is not an abstract harm.
This case exposes a real structural vulnerability in how organizations respond to ransomware attacks. When you hire a negotiator, you are sharing your pain points: how much the attack has cost you in downtime, what your upper limit might be, how desperate you are. That information is only useful if it stays confidential. Martino turned that trust into a business model.
The ransomware negotiation industry is largely unregulated, and this case is the most dramatic illustration yet of why that might be a problem. Companies under attack are already in a vulnerable position. They should not have to also worry about whether the person they brought in to help is texting the other side.
⚡ Quick Hits
Companies are spending billions on AI hardware and then leaving most of it idle — a new survey reveals staggering waste across enterprise data centers.
Despite its public embrace of robotaxi partnerships, Uber is reportedly working behind the scenes to stall the regulatory progress of autonomous vehicle competitors.
Apple's lawsuit includes a stunning allegation: OpenAI reportedly asked job candidates to bring Apple prototypes to their interviews.
Meta is developing glasses that silently capture images every few seconds — and the privacy indicator LED may not even be on by default.
AI coding assistants are hallucinating package names that attackers can register with malicious code, creating a stealthy new class of software supply chain attack.
China became only the third entity to recover an orbital-class rocket booster — and pulled it off using a method SpaceX and Blue Origin have never attempted.