This issue rounds up six stories: China blocking Meta's $2B Manus acquisition, a confirmed Udemy data breach, the solo developer behind uBlock Origin outlasting Google's attempts to kill it, new AI job-exposure data, Nvidia's $26B open-model strategy, and a fast-moving Russian state-linked cyberattack on Microsoft Office.
China blocked Meta's $2 billion deal to buy the AI startup Manus
Meta wanted to buy Manus, a Chinese-origin AI startup known for autonomous agents that can browse the web, fill forms, and run research without step-by-step human guidance, for roughly $2 billion. China's National Development and Reform Commission ordered the deal cancelled, citing foreign investment rules, despite Manus having relocated its headquarters to Singapore.
- China said the deal broke its own investment rules, so the purchase can't go through as structured.
- Manus became one of the most talked-about AI agent tools in early 2026, used by people worldwide.
- Meta offering $2 billion signals how much big tech is willing to spend on AI acquisitions right now.
- The message from Beijing is straightforward: its most prominent AI companies aren't for sale to foreign buyers.
Think of it as a mirror image of US chip export controls: the US restricts China's access to advanced chips, and China is restricting foreign access to its most promising AI companies. Both sides are protecting what they think will matter most in the next decade.
Udemy confirmed a data breach affecting 1.4 million accounts after refusing to pay a ransom
Attackers published 1.4 million Udemy user records publicly after the company declined to pay a ransom demand. The exposed data reportedly includes personal details and, in some cases, financial information.
- Security researchers confirmed both the breach and the public data release.
- If you have a Udemy account, changing your password (and any other account where you reused it) is a reasonable precaution.
- Refusing to pay a ransom is generally the right long-term policy, but it typically means users absorb the short-term fallout.
Google's biggest ad-blocking threat is one developer working alone from home
Raymond Hill built uBlock Origin in 2014 as a solo, unfunded project that went on to collect tens of thousands of GitHub stars. When Google's Manifest V3 extension API transition effectively disabled the old version of uBlock Origin on Chrome, and Chrome later removed remaining legacy extensions entirely, Hill kept building. The extension remains fully alive and actively maintained on Firefox.
- A trillion-dollar company spent years engineering around one developer's free tool, and that tool still runs on one of the world's most popular browsers.
- The story keeps resurfacing because it cuts against the assumption that scale and resources always win.
New data shows even technical roles have high AI task exposure
Recent job-exposure analysis found that computer programmers have roughly 74.5% task overlap with what current automation can do, customer service representatives sit around 70.1%, and data entry roles around 67.1%.
- Exposure measures task overlap with automation capability, not immediate job replacement, but the trajectory is accelerating.
- The practical takeaway isn't panic, it's preparation: treat exposure numbers as a signal for which skills to build now rather than a fixed prediction of outcomes.
Nvidia committed $26 billion to open AI models across six domains
Nvidia has launched several open model families spanning reasoning, healthcare, climate, robotics, humanoid control, and autonomous vehicles, alongside what it describes as an early open model for quantum computing applications. The company is also open-sourcing training data and evaluation tools so enterprises can audit and customize what they deploy, backed by a reported $26 billion commitment over five years.
- The strategic logic: give the world free, capable models, and keep them running on Nvidia hardware.
- Rather than competing with open efforts like DeepSeek by staying closed, Nvidia appears to be competing by going further open, while keeping the hardware layer proprietary.
A Russian state-linked group weaponized a Microsoft Office vulnerability within days of the patch
A high-severity Microsoft Office vulnerability, triggered by opening a crafted document with no macros or user interaction required, was patched by Microsoft and reportedly under active exploitation within about three days. Security researchers attributed the campaign to APT28 (also known as Fancy Bear), a group linked to Russian military intelligence, with targets confirmed across multiple countries in Central and Eastern Europe.
- A three-day window from patch to active exploitation is fast, even for a well-resourced state-linked group.
- If your organization runs Microsoft Office, applying this patch promptly isn't optional—document-based attack vectors like this remain highly effective.