Normal view

Hundreds rally at Bethesda HQ to protest Xbox layoffs, and Ars was there

15 July 2026 at 22:36

ROCKVILLE, Maryland—Hundreds of Bethesda Game Studios and Zenimax Online Studios employees and their supporters braved nearly 100° F temperatures to protest sweeping layoffs across Xbox during a lunchtime rally in front of parent company Zenimax's headquarters today. The rally was one of five today organized by Zenimax Workers United and its parent union, the Communication Workers of America, at offices across Texas, California, and Montreal.

Attendees held up signs with messages like "Layoffs... layoffs never change" and "Our players deserve better" as union organizers and employees rallied the crowd with speeches and songs. The overwhelming message was one of solidarity and a willingness to push back against job cuts they say have decimated their development and quality assurance teams.

"It's about us building our movement and making sure that we get seen and we're visible," Bethesda technical producer and union volunteer organizer Nathan Hahn told Ars. "Because we want to make sure that we're not okay with these layoffs and that Xbox knows."

Read full article

Comments

Windows 0-day drops the same day Microsoft releases record number of patches

15 July 2026 at 19:59

Right on the heels of Microsoft releasing a record number of security patches, a researcher has published exploit code that can enable low-privilege Windows accounts to make sensitive changes to administrator accounts.

The exploit, which multiple researchers say works, is sending Microsoft scrambling, yet again, to patch a zero-day released by an anonymous researcher who has complained about the software maker’s handling of their bug reports. To date, the pseudonymous NightmareEclypse has published nine such exploits, including Tuesday’s HiveLegacy. The researcher said the proof-of-concept code included in the report was stripped down to prevent attackers from using it maliciously.

A “pretty powerful primitive”

HiveLegacy is an elevation-of-privilege exploit that targets a vulnerability residing in the Windows User Profile Service. It allows users (and with more work likely processes) with limited system rights to compromise an admin user's account by modifying its classes registry hive, a resource that ensures the correct application opens when certain types of files are clicked on in Windows Explorer.

Read full article

Comments

© Getty Images

Microsoft’s Secure Boot has been broken for a decade and no one noticed until now

14 July 2026 at 22:20

An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, that were known to be defective but remained signed by the software company anyway.

The images are known as shims, which were invented to extend Secure Boot to Linux devices and utility software. Using a technique simple enough to be performed by novice hackers, these old, forgotten shims can be used to completely circumvent the protection, which is embedded into the UEFI (Unified Extensible Firmware Interface) of the device's motherboard. The gaffe is the result of the failure by Microsoft, which oversees the signing of shims, to revoke the publicly available images once vulnerabilities were found in them.

Threat extends to Windows and Linux users

The threat extends to Windows and Linux users alike, since the shim can be installed on devices running both operating systems. From there, an attacker can subvert the mandated chain of digitally signed firmware to install malicious firmware that loads early in the boot process and persists after either the OS is reinstalled or a hard drive is replaced.

Read full article

Comments

© Getty Images

Patch for Windows Defender 0-day could allow attackers to fill hard disk

9 July 2026 at 20:52

A patch Microsoft released on Wednesday to fix a zero-day vulnerability in its Defender security engine may cause Windows machines to write files large enough to completely consume available disk space, the researcher who discovered the flaw said.

RoguePlanet, tracked as CVE-2026-50656, came to public notice in June when NightmareEclipse, the pseudonymous name used by a researcher, disclosed it along with code for exploiting it. The vulnerability allows remote attackers to gain administrative control of Windows 10 and Windows 11 machines, even when real-time protection has been disabled. Over the past few months, the anonymous researcher has published a handful of other zero-days that have sent Microsoft scrambling to develop patches.

Writing files of unlimited size

Microsoft said Wednesday that it patched RoguePlanet with an update to the Microsoft Malware Protection Engine, which is used by the Defender antivirus app. The fix will automatically be downloaded and installed without users having to take any action. Wednesday’s update also includes “defense-in-depth updates to help improve security-related features.”

Read full article

Comments

© Photo Illustration by Igor Golovniov/SOPA Images/LightRocket via Getty Images

Bethesda, id Software reportedly hit hard by Microsoft layoffs

7 July 2026 at 19:52

In announcing plans for 3,200 layoffs across the Xbox division yesterday, CEO Asha Sharma focused on discussing cuts to the Xbox platform team and redundant layers of middle management. Now, though, word is filtering out about significant staffing cuts at remaining Microsoft-owned game developers including id Software and Bethesda.

Apogee and 3D Realms founder Scott Miller—who helped publish some of id's earliest gameswrote on social media yesterday of "insider reports" that a majority of id had been laid off, "including most (if not all) coders." And last night, veteran programmer Michael Maynard—whose credits at id Software date back to 2011's Ragewrote on LinkedIn that he was among the "roughly 50%" of the id team that was let go Monday.

Game Developer cites "multiple anonymous sources" in confirming those reports, saying the redundancies amount to about 90 employees at the Doom studio. The first DLC pack for last year's Doom: The Dark Ages launched earlier today.

Read full article

Comments

© id Software

The incredible shrinking Xbox: Five studios, 3,200 employees let go

6 July 2026 at 16:01

Last month, Xbox executives laid out some "hard truths" about Microsoft's struggling gaming division that they said would require a difficult "Xbox reset." This morning, Microsoft revealed the brutal shape of that "reset," announcing plans for 3,200 layoffs and the divestment of five smaller studios that the company has spent years acquiring and shepherding.

Half of those 3,200 layoffs are effective today, new Xbox CEO Asha Sharma wrote, while the other half will come by the end of Microsoft's 2027 fiscal year (which runs through June 30, 2027). CNBC cites "a person familiar with the matter" in reporting that these cuts amount to roughly 20 percent of the Xbox division.

When combined with 1,600 newly announced layoffs across the rest of Microsoft, the company as a whole is letting go of just over 2 percent of its workforce. But The Seattle Times reports that Microsoft's total headcount has remained relatively stable thanks to other hiring.

Read full article

Comments

© Aurich Lawson

❌