The Thread
Four stories logged on this desk in the past two days look unrelated: enterprise file sharing, a browser port of Nvidia's DLSS 5, malicious Chrome and Edge extensions, and New York State's recommendations for data center negotiations. The common thread is a widening gap between what technology can do and what existing governance - corporate, technical, or municipal - is equipped to oversee. In each case, capability has moved faster than the mechanisms meant to constrain or account for it.
Access That Outlives Its Purpose
BleepingComputer reports that tenfold Software is highlighting a familiar but unsolved problem in Microsoft 365: sharing files is easy, but access often remains long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. The company's answer is centralized access governance and owner-driven reviews, which is a reasonable mitigation but also an admission that the default state of modern collaboration tools is permissive and opaque.
This matters for US companies because the same platforms that made remote and hybrid work possible also made the perimeter porous. A file shared for a quarterly review can remain reachable years later, long after the employee, contractor, or partner who received it has moved on. The review process tenfold describes is essentially manual governance retrofitted onto software designed for frictionless sharing. That the fix is owner-driven means it depends on the very people who created the access in the first place - and who have little incentive to audit it.
Neural Rendering Leaves the GPU Behind
Tom's Hardware reports that a modder got Nvidia's DLSS 5 working in a web browser using WebGPU. The 147MB browser port runs on non-Nvidia GPUs and macOS, though it takes about two seconds per render. The technical achievement is real, but the more interesting detail is the direction of travel: a flagship Nvidia feature, normally tied to specific hardware and drivers, is now running in a browser on hardware Nvidia does not control.
For US technology companies, this is a reminder that software portability keeps eroding hardware moats. Two seconds per render is not a threat to native performance today, but the demonstration proves the conceptual boundary is thinner than vendors would like. The same dynamic that made DLSS a browser artifact also applies to any capability a company assumes is locked to its platform. Buyers should treat hardware lock-in as a depreciating asset, not a permanent advantage.
Extensions as an Attack Surface
BleepingComputer also reports that a banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. The detail that matters is that the malware bypasses browser checks - the very safeguards users and IT departments rely on to vet what gets installed.




