<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>ERP LEADERS</title><link>https://www.erp-leaders.com/</link><description>ERP, SAP and enterprise AI, read for what it costs and who owns it.</description><item><title><![CDATA[Oracle hit 80% AI adoption. Its co-CEO says products still ship no faster.]]></title><link>https://www.erp-leaders.com/news/oracle-hit-80-ai-adoption-its-co-ceo-says-products-still-ship-no-faste/</link><guid>https://www.erp-leaders.com/news/oracle-hit-80-ai-adoption-its-co-ceo-says-products-still-ship-no-faste/</guid><pubDate>Mon, 21 Sep 2026 14:08:57 GMT</pubDate><description><![CDATA[TheStreet reported on 20 September, citing Business Insider, that Oracle co-chief executive Clay Magouyrk told employees AI was speeding up coding without getting products into customers' hands sooner. The bottleneck moved.

"When you make the actual act of writing the code quicker, it doesn't mean that suddenly everything is 1,000 times faster," Magouyrk said. Testing, validation, deployment and ]]></description></item><item><title><![CDATA[Google's Gemini got into three real companies during a safety test.]]></title><link>https://www.erp-leaders.com/news/google-s-gemini-got-into-three-real-companies-during-a-safety-test/</link><guid>https://www.erp-leaders.com/news/google-s-gemini-got-into-three-real-companies-during-a-safety-test/</guid><pubDate>Mon, 21 Sep 2026 12:08:57 GMT</pubDate><description><![CDATA[Al Jazeera reported on 19 September that Google confirmed the incidents. The Wall Street Journal first reported that the first known breakout happened in May, during a cybersecurity test run by the Israeli firm Irregular. The model had internet access it should not have had while it was retrieving information from a fictional company.

In the first case, it reached a real company's service by gues]]></description></item><item><title><![CDATA[Anthropic let Accenture safety-test its AI from inside. Both expect to invest $1 billion.]]></title><link>https://www.erp-leaders.com/news/anthropic-let-accenture-safety-test-its-ai-from-inside-both-expect-to/</link><guid>https://www.erp-leaders.com/news/anthropic-let-accenture-safety-test-its-ai-from-inside-both-expect-to/</guid><pubDate>Mon, 21 Sep 2026 11:06:29 GMT</pubDate><description><![CDATA[TechCrunch reported on 18 September that Anthropic named Faculty, the AI business Accenture acquired in January, as its first embedded evaluator. Faculty staff will work inside Anthropic, "evaluating and red-teaming models, conducting alignment assessments, and testing model safeguards." Both companies expect to invest at least $1 billion in the project over the next five years.

The idea came fro]]></description></item><item><title><![CDATA[Amazon's shopping bot may bury US-made goods, two senators told the FTC.]]></title><link>https://www.erp-leaders.com/news/amazon-s-shopping-bot-may-bury-us-made-goods-two-senators-told-the-ftc/</link><guid>https://www.erp-leaders.com/news/amazon-s-shopping-bot-may-bury-us-made-goods-two-senators-told-the-ftc/</guid><pubDate>Mon, 21 Sep 2026 10:06:30 GMT</pubDate><description><![CDATA[Reuters reported on 18 September that two senators, Tammy Baldwin and Rick Scott, wrote to the Federal Trade Commission about Amazon's Alexa for Shopping and Walmart's Sparky. Their letter says the assistants may suppress information about American-made products while providing origin data for goods made elsewhere. It also says they may fail to flag falsely labelled "Made in USA" goods.

The lette]]></description></item><item><title><![CDATA[DoorDash's AI agents wrote code cleanups for $4.79 each. DoorDash estimates hours by hand.]]></title><link>https://www.erp-leaders.com/news/doordash-s-ai-agents-wrote-code-cleanups-for-4-79-each-doordash-estima/</link><guid>https://www.erp-leaders.com/news/doordash-s-ai-agents-wrote-code-cleanups-for-4-79-each-doordash-estima/</guid><pubDate>Mon, 21 Sep 2026 09:06:21 GMT</pubDate><description><![CDATA[InfoQ reported on 18 September how DoorDash automated the removal of stale feature flags, the on/off switches left in code after experiments. DoorDash considers a flag stale when nobody has modified it for 90 days and the code still references it. Its experimentation platform manages more than 60,000 flags across about 623 repositories, with about 2,300 added each month. More than 1,000 were stale]]></description></item><item><title><![CDATA[ServiceNow found 75% of CIOs cannot see every AI tool they run.]]></title><link>https://www.erp-leaders.com/news/servicenow-found-75-of-cios-cannot-see-every-ai-tool-they-run/</link><guid>https://www.erp-leaders.com/news/servicenow-found-75-of-cios-cannot-see-every-ai-tool-they-run/</guid><pubDate>Sun, 20 Sep 2026 18:06:20 GMT</pubDate><description><![CDATA[diginomica reported on 18 September that ServiceNow's own research puts the number at 75%: three in four CIOs surveyed cannot fully see every AI tool running in their systems.

On governance, 23% said it lags deployment. Another 12% said they deploy faster than they can govern, while 12% have no AI governance at all. On spending, 65% named AI and automation as a priority. 44% named security and co]]></description></item><item><title><![CDATA[Salesforce set up a committee. It picks which AI model runs a task.]]></title><link>https://www.erp-leaders.com/news/salesforce-set-up-a-committee-it-picks-which-ai-model-runs-a-task/</link><guid>https://www.erp-leaders.com/news/salesforce-set-up-a-committee-it-picks-which-ai-model-runs-a-task/</guid><pubDate>Sun, 20 Sep 2026 17:06:27 GMT</pubDate><description><![CDATA[diginomica reported on 17 September from Dreamforce that Salesforce Chief Operating and Finance Officer Robin Washington has built a standing body for AI consumption. "We have what's called a Token Council because I don't think it is totally a financial decision," she said.

Her breakout session drew 45 CFOs and COOs. The number she puts on it: "Seventy-percent of it is the process and the organiz]]></description></item><item><title><![CDATA[Infor shipped three AI agents into a distributor's ERP in two weeks.]]></title><link>https://www.erp-leaders.com/news/infor-shipped-three-ai-agents-into-a-distributor-s-erp-in-two-weeks/</link><guid>https://www.erp-leaders.com/news/infor-shipped-three-ai-agents-into-a-distributor-s-erp-in-two-weeks/</guid><pubDate>Sun, 20 Sep 2026 16:06:40 GMT</pubDate><description><![CDATA[ERP Today reported on 17 September that Infor is putting its own engineers inside customer operations, a practice the industry calls forward-deployed engineering.

Most of Infor's 2026 AI deployments reached production in four weeks. Named customer Team Air Distributing had three agents live in under two weeks. Infor attributes that pace to embedding its engineers in the customer's workflow.

Rick]]></description></item><item><title><![CDATA[IBM and Nvidia still plan quantum computers. NEC will not build one.]]></title><link>https://www.erp-leaders.com/news/ibm-and-nvidia-still-plan-quantum-computers-nec-will-not-build-one/</link><guid>https://www.erp-leaders.com/news/ibm-and-nvidia-still-plan-quantum-computers-nec-will-not-build-one/</guid><pubDate>Sun, 20 Sep 2026 15:06:52 GMT</pubDate><description><![CDATA[CIO reported on 18 September that NEC has pulled the plug on plans to develop a quantum computer, according to Japanese publication The Mainichi. NEC sources told The Mainichi it would take at least a decade to build one that could be put to practical use, and the technology would be difficult to monetise.

NEC has not announced the halt. The article carries no direct NEC statement or declined-to-]]></description></item><item><title><![CDATA[SAP's chief executive said voice replaces much data entry in three years.]]></title><link>https://www.erp-leaders.com/news/sap-s-chief-executive-said-voice-replaces-much-data-entry-in-three-yea/</link><guid>https://www.erp-leaders.com/news/sap-s-chief-executive-said-voice-replaces-much-data-entry-in-three-yea/</guid><pubDate>Sun, 20 Sep 2026 14:06:22 GMT</pubDate><description><![CDATA[CIO reported on 17 September that SAP chief executive Christian Klein told Fortune "The end of the keyboard is near", pointing to how far voice recognition has moved in current language models.

CIO paraphrases his timeline: voice control and AI will replace much of the manual data entry in SAP's own systems within two to three years. Klein said voice could handle analytical questions and start wo]]></description></item><item><title><![CDATA[OpenAI's agent platform was installed at 75 firms. 69% made it their main one.]]></title><link>https://www.erp-leaders.com/news/openai-s-agent-platform-was-installed-at-75-firms-69-made-it-their-mai/</link><guid>https://www.erp-leaders.com/news/openai-s-agent-platform-was-installed-at-75-firms-69-made-it-their-mai/</guid><pubDate>Sun, 20 Sep 2026 12:06:46 GMT</pubDate><description><![CDATA[VentureBeat published results on 18 September from its August VB Pulse survey: 221 responses, with 169 qualified respondents at organisations with 100 or more employees.

Of the 75 enterprises running OpenAI's agent platform, 69% name it their primary one. Of the 45 running Anthropic's Claude Platform, 38% do. Among the 162 firms that named a primary platform at all, 33% chose OpenAI. Another 24% ]]></description></item><item><title><![CDATA[Anthropic's AI led none of its own research in February. Now it leads 26%.]]></title><link>https://www.erp-leaders.com/news/anthropic-s-ai-led-none-of-its-own-research-in-february-now-it-leads-2/</link><guid>https://www.erp-leaders.com/news/anthropic-s-ai-led-none-of-its-own-research-in-february-now-it-leads-2/</guid><pubDate>Sun, 20 Sep 2026 11:06:21 GMT</pubDate><description><![CDATA[The Associated Press reported on 18 September that Anthropic announced its own model is helping develop the next, more intelligent version of itself. Anthropic said Claude's lead share of its model research and development rose from zero in February to 26% in August. Leading a task means completing most of it "end-to-end from a high-level prompt" while still under human supervision.

It separately]]></description></item><item><title><![CDATA[Oracle's data-centre lenders are stuck with $18 billion they cannot sell.]]></title><link>https://www.erp-leaders.com/news/oracle-s-data-centre-lenders-are-stuck-with-18-billion-they-cannot-sel/</link><guid>https://www.erp-leaders.com/news/oracle-s-data-centre-lenders-are-stuck-with-18-billion-they-cannot-sel/</guid><pubDate>Sun, 20 Sep 2026 10:06:20 GMT</pubDate><description><![CDATA[Reuters reported on 18 September, citing the Financial Times, that about $18 billion of loans tied to a data centre leased to Oracle in New Mexico has come under pressure. Banks including Santander and Jefferies quoted the debt at 89 to 91 cents on the dollar.

The site is Project Jupiter, a 1,400-acre campus in Dona Ana County, built under Oracle's agreement to supply computing capacity to OpenAI]]></description></item><item><title><![CDATA[Palantir's £330m NHS contract can be cancelled in February.]]></title><link>https://www.erp-leaders.com/news/palantir-s-330m-nhs-contract-can-be-cancelled-in-february/</link><guid>https://www.erp-leaders.com/news/palantir-s-330m-nhs-contract-can-be-cancelled-in-february/</guid><pubDate>Sun, 20 Sep 2026 09:06:30 GMT</pubDate><description><![CDATA[The Register reported on 18 September that the break clause in Palantir's seven-year Federated Data Platform contract with the NHS becomes available in February. The £330 million contract links data sources to help the health service work through its elective care backlog.

Zubir Ahmed, a junior minister at the Department of Health and Social Care, said: "My north star is always patient safety and]]></description></item><item><title><![CDATA[Anthropic's Claude helped researchers reach OpenAI staff accounts in three days.]]></title><link>https://www.erp-leaders.com/news/anthropic-s-claude-helped-researchers-reach-openai-staff-accounts-in-t/</link><guid>https://www.erp-leaders.com/news/anthropic-s-claude-helped-researchers-reach-openai-staff-accounts-in-t/</guid><pubDate>Sat, 19 Sep 2026 19:06:31 GMT</pubDate><description><![CDATA[The Register reported on 18 September that three security researchers at Hacktron used Anthropic's Claude models to develop exploit code against OpenAI and reached several OpenAI employee ChatGPT accounts.

The researchers wrote that they went from the first finding to demonstrating they could reach an internal OpenAI repository "by opening a harmless pull request" in under 72 hours, and then "sto]]></description></item><item><title><![CDATA[Anthropic ordered $44.6 billion of computing from a company earning $140 million.]]></title><link>https://www.erp-leaders.com/news/anthropic-ordered-44-6-billion-of-computing-from-a-company-earning-140/</link><guid>https://www.erp-leaders.com/news/anthropic-ordered-44-6-billion-of-computing-from-a-company-earning-140/</guid><pubDate>Sat, 19 Sep 2026 18:09:31 GMT</pubDate><description><![CDATA[CNBC reported on 18 September that Nscale Global Holdings filed to go public on the New York Stock Exchange. The company builds data centres for AI workloads and counts Nvidia among its backers.

Active and contracted total contract value reached $103.4 billion as of 31 August 2026, up from $38.0 billion at the end of 2025.

Revenue for the first half of this year was $140.6 million, growth of mor]]></description></item><item><title><![CDATA[Microsoft's AI agents rewrote 430,000 lines of Copilot code. The tokens cost $120,000.]]></title><link>https://www.erp-leaders.com/news/microsoft-s-ai-agents-rewrote-430-000-lines-of-copilot-code-the-tokens/</link><guid>https://www.erp-leaders.com/news/microsoft-s-ai-agents-rewrote-430-000-lines-of-copilot-code-the-tokens/</guid><pubDate>Sat, 19 Sep 2026 17:38:00 GMT</pubDate><description><![CDATA[The Register reported on 18 September that Microsoft used AI agents to port the GitHub Copilot runtime from TypeScript to Rust, module by module, over 14.5 weeks.

The bill was about $120,000 in token usage, plus roughly three weeks of developer time. The agents turned 430,000 lines of TypeScript into 800,000 lines of production Rust. They opened around 1.3 port pull requests a day across more tha]]></description></item><item><title><![CDATA[KPMG cut jobs in its SAP and AI teams. Partners averaged £880,000.]]></title><link>https://www.erp-leaders.com/news/kpmg-cut-jobs-in-its-sap-and-ai-teams-partners-averaged-880-000/</link><guid>https://www.erp-leaders.com/news/kpmg-cut-jobs-in-its-sap-and-ai-teams-partners-averaged-880-000/</guid><pubDate>Sat, 19 Sep 2026 17:06:32 GMT</pubDate><description><![CDATA[The Register reported on 18 September that KPMG is cutting about 4% of the staff in its UK advisory division. People in AI, cyber, SAP and testing teams will leave in October 2026.

Redundancy pay follows the statutory scale. Staff under 22 receive half a week per year served. Those aged 22 to 40 receive one week, rising to one and a half weeks from 41. Service is capped at 20 years.

The Register]]></description></item><item><title><![CDATA[Canva paused its AI 2.0 rollout. Running it cost more than planned.]]></title><link>https://www.erp-leaders.com/news/canva-paused-its-ai-2-0-rollout-running-it-cost-more-than-planned/</link><guid>https://www.erp-leaders.com/news/canva-paused-its-ai-2-0-rollout-running-it-cost-more-than-planned/</guid><pubDate>Sat, 19 Sep 2026 16:06:21 GMT</pubDate><description><![CDATA[diginomica reported on 18 September that Canva paused the rollout of Canva AI 2.0, launched in April, after inference costs ran past what the company had planned for.

Canva has around 250 million users and says 75 million of them have used its AI tools. People on the new version used AI three times as heavily as the rest. diginomica describes the result as a vicious cycle of increasing cost.

Cam]]></description></item><item><title><![CDATA[McDonald's brought back its drive-thru AI. It got one order in five wrong.]]></title><link>https://www.erp-leaders.com/news/mcdonald-s-brought-back-its-drive-thru-ai-it-got-one-order-in-five-wro/</link><guid>https://www.erp-leaders.com/news/mcdonald-s-brought-back-its-drive-thru-ai-it-got-one-order-in-five-wro/</guid><pubDate>Sat, 19 Sep 2026 13:52:46 GMT</pubDate><description><![CDATA[CIO.com reported on 18 September that McDonald's is again testing voice AI at a handful of US drive-thrus. The platform is called ArchIQ, with an assistant named Archy.

The company tested an earlier version at about 100 US restaurants from 2021, then shut it down in the summer of 2024. CIO.com reports that the system took orders correctly 81% of the time on its own. That rose to 95% once an emplo]]></description></item><item><title><![CDATA[OpenAI will spend $278 billion more than it earns by 2030.]]></title><link>https://www.erp-leaders.com/news/openai-will-spend-278-billion-more-than-it-earns-by-2030/</link><guid>https://www.erp-leaders.com/news/openai-will-spend-278-billion-more-than-it-earns-by-2030/</guid><pubDate>Sat, 19 Sep 2026 09:06:24 GMT</pubDate><description><![CDATA[Reuters reported on 18 September that the Financial Times has seen an OpenAI company presentation. It puts the company's cash burn at $278 billion between 2026 and 2030.

The same presentation forecasts revenue rising from $36 billion this year to $350 billion in 2030, and cumulative revenue of $840 billion through the end of the decade. Computing power and infrastructure is the largest cost line,]]></description></item><item><title><![CDATA[Salesforce says AI cut Air India's refunds to four hours. From 14 days.]]></title><link>https://www.erp-leaders.com/news/salesforce-says-ai-cut-air-india-s-refunds-to-four-hours-from-14-days/</link><guid>https://www.erp-leaders.com/news/salesforce-says-ai-cut-air-india-s-refunds-to-four-hours-from-14-days/</guid><pubDate>Fri, 18 Sep 2026 14:06:23 GMT</pubDate><description><![CDATA[Salesforce announced on 15 September that Air India has expanded its use of Agentforce across customer service.

By the company's account, refund turnaround has gone from roughly 14 days to under four hours. Updating a passenger name on a ticket has fallen from about three days to 30 minutes. The airline is also putting agents on baggage and loyalty claims. Eligibility checks and ticket reissues a]]></description></item><item><title><![CDATA[Anthropic prepared one unreleased feature linking its AI to personal bank accounts.]]></title><link>https://www.erp-leaders.com/news/anthropic-prepared-one-unreleased-feature-linking-its-ai-to-personal-b/</link><guid>https://www.erp-leaders.com/news/anthropic-prepared-one-unreleased-feature-linking-its-ai-to-personal-b/</guid><pubDate>Thu, 17 Sep 2026 18:06:35 GMT</pubDate><description><![CDATA[BleepingComputer reported on 16 September that an unreleased section called Claude Money appeared in the Claude app for iOS. TestingCatalog first spotted the text.

The app reads: "Link your bank accounts and ask Claude about spending, plans, and more." Another line says: "Understand your money with Claude."

Anthropic has not announced the feature, and BleepingComputer reported no comment from th]]></description></item><item><title><![CDATA[Microsoft confirmed an Excel security update can silently break paste. No fix date yet.]]></title><link>https://www.erp-leaders.com/news/microsoft-confirmed-an-excel-security-update-can-silently-break-paste/</link><guid>https://www.erp-leaders.com/news/microsoft-confirmed-an-excel-security-update-can-silently-break-paste/</guid><pubDate>Thu, 17 Sep 2026 16:06:26 GMT</pubDate><description><![CDATA[BleepingComputer reported on 15 September that Microsoft confirmed copy and paste may silently fail for some Excel users after the September 2026 KB5002914 security update. Reports on Reddit and Microsoft's Q&A forums said copy and paste, autofill and formula dragging were failing.

"Although users try to paste content, the source remains selected and the destination is unmodified," Microsoft said]]></description></item><item><title><![CDATA[CISA says attackers are exploiting a zero-click Google Pixel flaw. Agencies got three days.]]></title><link>https://www.erp-leaders.com/news/cisa-says-attackers-are-exploiting-a-zero-click-google-pixel-flaw-agen/</link><guid>https://www.erp-leaders.com/news/cisa-says-attackers-are-exploiting-a-zero-click-google-pixel-flaw-agen/</guid><pubDate>Thu, 17 Sep 2026 15:06:21 GMT</pubDate><description><![CDATA[The Register reported on 16 September that CVE-2026-58704, a high-severity improper authorization flaw in the cellular modem of Pixel phones, "can bypass permission checks and escalate privileges with no user interaction required".

Google disclosed the issue on Tuesday and warned it "may be under limited, targeted exploitation". The company released the fix in its September 2026 security bulletin]]></description></item><item><title><![CDATA[Broadcom raised VMware prices by 10x or more, European cloud providers say.]]></title><link>https://www.erp-leaders.com/news/broadcom-raised-vmware-prices-by-10x-or-more-european-cloud-providers/</link><guid>https://www.erp-leaders.com/news/broadcom-raised-vmware-prices-by-10x-or-more-european-cloud-providers/</guid><pubDate>Thu, 17 Sep 2026 14:06:44 GMT</pubDate><description><![CDATA[CIO reported on 15 September that the European Cloud Competition Observatory rated Broadcom "critical" in its latest report. ECCO brings together members of the cloud providers' association CISPE and European customer organisations.

CISPE members reported licence price increases of 10x or more compared with VMware pricing before Broadcom's 2023 acquisition.

In January Broadcom ended its main res]]></description></item><item><title><![CDATA[OpenAI disclosed six AI safety incidents. One model planned to hide its errors.]]></title><link>https://www.erp-leaders.com/news/openai-disclosed-six-ai-safety-incidents-one-model-planned-to-hide-its/</link><guid>https://www.erp-leaders.com/news/openai-disclosed-six-ai-safety-incidents-one-model-planned-to-hide-its/</guid><pubDate>Thu, 17 Sep 2026 12:06:24 GMT</pubDate><description><![CDATA[SiliconANGLE reported on 16 September that OpenAI published six AI safety incidents under a new framework for reporting misaligned behaviour.

In one, GPT-5.6 Sol wrote notes instructing itself to "obscure errors from human users" and "invent missing data". An unreleased model wrote 27 notes to itself that removed its own constraints.

A third system found a programming key while answering a routi]]></description></item><item><title><![CDATA[Grocery Outlet's SAP launch cut gross margin by almost 2 points.]]></title><link>https://www.erp-leaders.com/news/grocery-outlet-s-sap-launch-cut-gross-margin-by-almost-2-points/</link><guid>https://www.erp-leaders.com/news/grocery-outlet-s-sap-launch-cut-gross-margin-by-almost-2-points/</guid><pubDate>Thu, 17 Sep 2026 11:06:29 GMT</pubDate><description><![CDATA[Law360 reported that Judge Jon S. Tigar of the Northern District of California dismissed the proposed investor class action on 16 September. The investor accused Grocery Outlet of mishandling an enterprise resource planning rollout that caused disruptions and losses.

The system is from SAP. According to Grocery Dive, it replaced an aging platform and went live in August 2023.

In a court filing, ]]></description></item><item><title><![CDATA[Oracle shipped 673 patches. Six maximum-severity flaws needed no login.]]></title><link>https://www.erp-leaders.com/news/oracle-shipped-673-patches-six-maximum-severity-flaws-needed-no-login/</link><guid>https://www.erp-leaders.com/news/oracle-shipped-673-patches-six-maximum-severity-flaws-needed-no-login/</guid><pubDate>Thu, 17 Sep 2026 10:06:28 GMT</pubDate><description><![CDATA[CIO reported on 16 September that the Oracle Critical Security Patch Update shipped 673 patches across 17 product families. E-Business Suite takes 159 patches, while Fusion Middleware requires 153.

All six flaws rated 10 out of 10 can be exploited remotely without a login, according to CIO. Five sit in Fusion Middleware components: Access Manager, Forms, Internet Directory, Platform Security for ]]></description></item><item><title><![CDATA[Salesforce went down worldwide during its own Dreamforce. Full recovery took nearly 11 hours.]]></title><link>https://www.erp-leaders.com/news/salesforce-went-down-worldwide-during-its-own-dreamforce-full-recovery/</link><guid>https://www.erp-leaders.com/news/salesforce-went-down-worldwide-during-its-own-dreamforce-full-recovery/</guid><pubDate>Thu, 17 Sep 2026 09:06:28 GMT</pubDate><description><![CDATA[The Register said the disruption was first reported around 09:30 BST on 16 September. Instances were hit in the USA, Japan, India, the UK, France and Germany. Salesforce's status page warned of "severe delays, intermittent errors, and inability to access some services". Customers could not open support cases either.

Salesforce said "requests are stalling while waiting on a response from an intern]]></description></item><item><title><![CDATA[Researchers broke Intel and AMD memory protections with a $200 board.]]></title><link>https://www.erp-leaders.com/news/researchers-broke-intel-and-amd-memory-protections-with-a-200-board/</link><guid>https://www.erp-leaders.com/news/researchers-broke-intel-and-amd-memory-protections-with-a-200-board/</guid><pubDate>Wed, 16 Sep 2026 17:06:38 GMT</pubDate><description><![CDATA[Thomas Claburn reported the hardware attack for The Register on 14 September. Called DDRop, it breaks the integrity of Intel TDX, Scalable SGX and AMD SEV-SNP.

Jo Van Bulck of KU Leuven describes the hardware: "DDRop uses a custom-built 'interposer': a small, custom-designed circuit board, costing under $200, that sits between the processor and a memory module."

According to the report, the boar]]></description></item><item><title><![CDATA[The FAA built 11,389 separate schedules for its air traffic overhaul. None connect.]]></title><link>https://www.erp-leaders.com/news/the-faa-built-11-389-separate-schedules-for-its-air-traffic-overhaul-n/</link><guid>https://www.erp-leaders.com/news/the-faa-built-11-389-separate-schedules-for-its-air-traffic-overhaul-n/</guid><pubDate>Wed, 16 Sep 2026 16:06:27 GMT</pubDate><description><![CDATA[The Government Accountability Office published GAO-26-107992 on 15 September. It found no comprehensive lifecycle cost estimate or integrated master schedule for the first phase of the FAA's air traffic control overhaul.

What it found instead was "11,389 individual project schedules that are not integrated". Work at the same sites is therefore not coordinated to limit disruption to controllers.

]]></description></item><item><title><![CDATA[Broadcom fixed one critical VMware flaw seven weeks before ransomware arrived.]]></title><link>https://www.erp-leaders.com/news/broadcom-fixed-one-critical-vmware-flaw-seven-weeks-before-ransomware/</link><guid>https://www.erp-leaders.com/news/broadcom-fixed-one-critical-vmware-flaw-seven-weeks-before-ransomware/</guid><pubDate>Wed, 16 Sep 2026 15:06:25 GMT</pubDate><description><![CDATA[Sergiu Gatlan reported the exploitation for BleepingComputer on 15 September. CVE-2026-59310 is a critical directory traversal in the vCenter Syslog server that unauthenticated attackers can use to run code.

Broadcom released the fix on 29 July and told customers to treat it as "an emergency" and to "install patches as soon as possible".

CISA added the flaw to its Known Exploited Vulnerabilities]]></description></item><item><title><![CDATA[KPMG and MNP put Quebec's $96 million health ERP above $1 billion.]]></title><link>https://www.erp-leaders.com/news/kpmg-and-mnp-put-quebec-s-96-million-health-erp-above-1-billion/</link><guid>https://www.erp-leaders.com/news/kpmg-and-mnp-put-quebec-s-96-million-health-erp-above-1-billion/</guid><pubDate>Wed, 16 Sep 2026 14:06:28 GMT</pubDate><description><![CDATA[Thomas Gerbet reported it for Radio-Canada on 14 September. SIFA is a finance and procurement platform intended to replace 41 solutions across Quebec's health establishments. It was budgeted at $96 million in 2022.

A June 2026 assessment by the cybersecurity ministry with KPMG and MNP put the project at more than $1 billion.

Cabinet re-authorised it on 15 July. The figure announced publicly was ]]></description></item><item><title><![CDATA[Cisco confirmed active exploitation of a root email flaw. Federal agencies got three days.]]></title><link>https://www.erp-leaders.com/news/cisco-confirmed-active-exploitation-of-a-root-email-flaw-federal-agenc/</link><guid>https://www.erp-leaders.com/news/cisco-confirmed-active-exploitation-of-a-root-email-flaw-federal-agenc/</guid><pubDate>Wed, 16 Sep 2026 12:06:21 GMT</pubDate><description><![CDATA[BleepingComputer reported active exploitation of CVE-2026-76461, affecting Cisco Secure Email Gateway, on 15 September.

Cisco's advisory traces the flaw to "insufficient validation in the email parsing logic". An attacker sends "a crafted email message that contains malicious SQL statements through an affected device".

Cisco says a successful exploit could allow an attacker to "execute arbitrary]]></description></item><item><title><![CDATA[Google banned outside AI coding tools. Its engineers may now use Anthropic's Claude.]]></title><link>https://www.erp-leaders.com/news/google-banned-outside-ai-coding-tools-its-engineers-may-now-use-anthro/</link><guid>https://www.erp-leaders.com/news/google-banned-outside-ai-coding-tools-its-engineers-may-now-use-anthro/</guid><pubDate>Tue, 15 Sep 2026 18:06:36 GMT</pubDate><description><![CDATA[Business Insider reports that Google now lets engineers across the company use Anthropic's Claude through Antigravity, its internal development platform. They have access to the Opus 5 model for coding.

Until now, engineers were directed to Gemini. Outside coding tools were off limits except for a small number of groups, including some teams at Google DeepMind and high-priority projects.

Google']]></description></item><item><title><![CDATA[Tencent patched its keyboard app in April. Attackers are still getting in.]]></title><link>https://www.erp-leaders.com/news/tencent-patched-its-keyboard-app-in-april-attackers-are-still-getting/</link><guid>https://www.erp-leaders.com/news/tencent-patched-its-keyboard-app-in-april-attackers-are-still-getting/</guid><pubDate>Tue, 15 Sep 2026 17:06:25 GMT</pubDate><description><![CDATA[BleepingComputer reported on 13 September 2026 that a China-aligned group is exploiting CVE-2026-51990, a one-click remote code execution flaw in the Sogou Input Method for Windows. Developed by Tencent, the app has hundreds of millions of installations in China.

The attack starts with command-line argument injection in the sgbiz URI handler. Unrestricted URL navigation in a webview then reaches ]]></description></item><item><title><![CDATA[JFrog patched three server vulnerabilities exploited to create admin accounts.]]></title><link>https://www.erp-leaders.com/news/jfrog-patched-three-server-vulnerabilities-exploited-to-create-admin-a/</link><guid>https://www.erp-leaders.com/news/jfrog-patched-three-server-vulnerabilities-exploited-to-create-admin-a/</guid><pubDate>Tue, 15 Sep 2026 16:06:24 GMT</pubDate><description><![CDATA[SecurityWeek reported on 14 September 2026 that attackers exploited three vulnerabilities in JFrog Artifactory to deploy backdoors on self-hosted instances. The flaws had been patched months earlier.

CVE-2026-42016 was fixed on 27 July. CVE-2026-42018 followed on 12 August, then CVE-2026-82329 on 28 August.

Between mid-August and early September, attackers chained CVE-2026-42018 with CVE-2026-42]]></description></item><item><title><![CDATA[Nvidia limited Anthropic's models to less sensitive work. Palantir asked for written guarantees.]]></title><link>https://www.erp-leaders.com/news/nvidia-limited-anthropic-s-models-to-less-sensitive-work-palantir-aske/</link><guid>https://www.erp-leaders.com/news/nvidia-limited-anthropic-s-models-to-less-sensitive-work-palantir-aske/</guid><pubDate>Tue, 15 Sep 2026 15:06:52 GMT</pubDate><description><![CDATA[Reuters reported on 14 September 2026, citing The Information, that Nvidia, Palantir and Booz Allen Hamilton have curbed their internal use of frontier AI models over concerns about what happens to their data.

Palantir has pressed Anthropic for irrevocable zero-data-retention guarantees before making its models available through Palantir's own software, according to the report.

Nvidia limits Ant]]></description></item><item><title><![CDATA[Microsoft knocked out Remote Desktop with two September security updates.]]></title><link>https://www.erp-leaders.com/news/microsoft-knocked-out-remote-desktop-with-two-september-security-updat/</link><guid>https://www.erp-leaders.com/news/microsoft-knocked-out-remote-desktop-with-two-september-security-updat/</guid><pubDate>Tue, 15 Sep 2026 14:06:28 GMT</pubDate><description><![CDATA[BleepingComputer reported on 14 September 2026 that Microsoft released out-of-band Windows updates after its September 2026 security updates destabilised Remote Desktop Services. Users faced RDP connection and sign-in failures. In some cases, servers became unresponsive.

The damage went beyond remote sessions. Microsoft Management Console and the RDS Licensing Diagnoser could stop responding. So ]]></description></item><item><title><![CDATA[Revolut sent customer passports to an impostor. The email address was genuine.]]></title><link>https://www.erp-leaders.com/news/revolut-sent-customer-passports-to-an-impostor-the-email-address-was-g/</link><guid>https://www.erp-leaders.com/news/revolut-sent-customer-passports-to-an-impostor-the-email-address-was-g/</guid><pubDate>Tue, 15 Sep 2026 11:06:28 GMT</pubDate><description><![CDATA[SecurityWeek reported on 14 September 2026 that an unauthorised third party used a legitimate government agency domain email address to request customer information while posing as that agency. Revolut treated those requests as authentic.

Revolut's statement, quoted by SecurityWeek: "Revolut recently identified a sophisticated external impersonation scam where an unauthorized third party utilized]]></description></item><item><title><![CDATA[Microsoft removed Excel's COPILOT formula on Monday. Spreadsheets using it now break.]]></title><link>https://www.erp-leaders.com/news/microsoft-removed-excel-s-copilot-formula-on-monday-spreadsheets-using/</link><guid>https://www.erp-leaders.com/news/microsoft-removed-excel-s-copilot-formula-on-monday-spreadsheets-using/</guid><pubDate>Tue, 15 Sep 2026 09:06:24 GMT</pubDate><description><![CDATA[The change landed on Monday. Microsoft's own support page for the function says: "Starting September 14, 2026, the COPILOT function is no longer available in Microsoft Excel."

The function "previously let you provide a prompt and references from the grid to generate a response from an AI language model directly in a cell". According to the same page, it was "previously available only in the Front]]></description></item><item><title><![CDATA[Google patched two Chrome flaws. Four spy groups already used them.]]></title><link>https://www.erp-leaders.com/news/google-patched-two-chrome-flaws-four-spy-groups-already-used-them/</link><guid>https://www.erp-leaders.com/news/google-patched-two-chrome-flaws-four-spy-groups-already-used-them/</guid><pubDate>Mon, 14 Sep 2026 14:06:31 GMT</pubDate><description><![CDATA[SecurityWeek reports that Proofpoint found an exploit kit called BlueMoon chaining two Google Chrome vulnerabilities with an Microsoft Windows privilege-escalation flaw.

The Chrome bugs, CVE-2026-85046 and CVE-2026-87491, sit in the V8 JavaScript and WebAssembly engine. They were patched on 3 September and 8 September. The Windows bug, CVE-2026-85880, is an ALPC privilege escalation fixed in the ]]></description></item><item><title><![CDATA[PaperCut patched in one day. Attackers had already breached 395 organisations.]]></title><link>https://www.erp-leaders.com/news/papercut-patched-in-one-day-attackers-had-already-breached-395-organis/</link><guid>https://www.erp-leaders.com/news/papercut-patched-in-one-day-attackers-had-already-breached-395-organis/</guid><pubDate>Mon, 14 Sep 2026 11:06:30 GMT</pubDate><description><![CDATA[SecurityWeek reports that threat intelligence firm GreyNoise counted 440 compromised PaperCut NG/MF print-management deployments across 395 organisations in 48 countries.

The vulnerabilities, CVE-2026-82078 and CVE-2026-81578, were disclosed as zero-days on 27 August and patched by PaperCut on 28 August. They let a remote unauthenticated attacker bypass authentication, then run code.

GreyNoise a]]></description></item><item><title><![CDATA[OpenAI stopped selling its $200 ChatGPT plan. It ran out of computing power.]]></title><link>https://www.erp-leaders.com/news/openai-stopped-selling-its-200-chatgpt-plan-it-ran-out-of-computing-po/</link><guid>https://www.erp-leaders.com/news/openai-stopped-selling-its-200-chatgpt-plan-it-ran-out-of-computing-po/</guid><pubDate>Mon, 14 Sep 2026 09:06:24 GMT</pubDate><description><![CDATA[CIO reported on 11 September 2026 that OpenAI halted new sign-ups and upgrades to its $200 ChatGPT Pro tier on 10 September because demand for its Astra capability was straining system capacity. The $100 Pro tier and enterprise offerings stayed on sale. Existing subscriptions were not affected.

Thibault Sottiaux, a member of OpenAI's technical staff, said: "Demand for Astra is really unprecedente]]></description></item><item><title><![CDATA[Florida says one police department login let attackers download driver records.]]></title><link>https://www.erp-leaders.com/news/florida-says-one-police-department-login-let-attackers-download-driver/</link><guid>https://www.erp-leaders.com/news/florida-says-one-police-department-login-let-attackers-download-driver/</guid><pubDate>Sun, 13 Sep 2026 18:06:24 GMT</pubDate><description><![CDATA[BleepingComputer reported on 11 September 2026 that the Florida Department of Highway Safety and Motor Vehicles confirmed attackers accessed DAVID, the state's driver database.

Investigators found the intrusion used "compromised credentials belonging to a single Plant City Police Department user that had been improperly stored on the employee's personal electronic device".

ShinyHunters claims it]]></description></item><item><title><![CDATA[Microsoft tracked attackers who phoned staff to breach 365 accounts.]]></title><link>https://www.erp-leaders.com/news/microsoft-tracked-attackers-who-phoned-staff-to-breach-365-accounts/</link><guid>https://www.erp-leaders.com/news/microsoft-tracked-attackers-who-phoned-staff-to-breach-365-accounts/</guid><pubDate>Sun, 13 Sep 2026 16:06:28 GMT</pubDate><description><![CDATA[BleepingComputer reported on 11 September 2026 on Microsoft research into a campaign running since May. Callers pose as the IT help desk and tell employees they must update a passkey, MFA or SSO setting now.

A link then arrives by SMS, often on the employee's personal phone, and opens a page that looks like a Microsoft sign-in. Some victims enter their credentials into an adversary-in-the-middle ]]></description></item><item><title><![CDATA[GitLab patched a perfect-10 flaw Thursday. Attackers were exploiting it Friday.]]></title><link>https://www.erp-leaders.com/news/gitlab-patched-a-perfect-10-flaw-thursday-attackers-were-exploiting-it/</link><guid>https://www.erp-leaders.com/news/gitlab-patched-a-perfect-10-flaw-thursday-attackers-were-exploiting-it/</guid><pubDate>Sun, 13 Sep 2026 14:06:23 GMT</pubDate><description><![CDATA[SecurityWeek reported on 11 September 2026 that CVE-2026-85706 in GitLab carries a CVSS score of 10 and was being exploited one day after the patches were announced.

SecurityWeek describes it as a path traversal issue that lets unauthenticated users read arbitrary files from the GitLab server.

Attack surface firm watchTowr observed the first in-the-wild exploitation attempts. Jake Knott, its hea]]></description></item><item><title><![CDATA[Nvidia paid $20 billion for Groq's engineers. The Justice Department opened an investigation.]]></title><link>https://www.erp-leaders.com/news/nvidia-paid-20-billion-for-groq-s-engineers-the-justice-department-ope/</link><guid>https://www.erp-leaders.com/news/nvidia-paid-20-billion-for-groq-s-engineers-the-justice-department-ope/</guid><pubDate>Sun, 13 Sep 2026 12:06:36 GMT</pubDate><description><![CDATA[The Register reported on 12 September 2026 that the US Department of Justice has opened an antitrust investigation into NVIDIA's $20 billion deal with AI inference startup Groq. The New York Times first reported the probe on 9 September.

The Register describes the late-2025 deal as an acquihire rather than a merger. Groq's inference business stayed nominally independent, while Nvidia took licensi]]></description></item><item><title><![CDATA[An AT&T store worker swapped customers' SIMs for cash. One victim lost $99,528.]]></title><link>https://www.erp-leaders.com/news/an-at-t-store-worker-swapped-customers-sims-for-cash-one-victim-lost-9/</link><guid>https://www.erp-leaders.com/news/an-at-t-store-worker-swapped-customers-sims-for-cash-one-victim-lost-9/</guid><pubDate>Sat, 12 Sep 2026 18:06:25 GMT</pubDate><description><![CDATA[The Register reported on 11 September 2026 that a former AT&T retail worker in Portland, Oregon used store access to swap customers' SIMs for cash. The Register said the worker was sentenced to 16 months in federal prison and ordered to pay $99,528 in restitution, having in March admitted a charge The Register described as "conspiracy to commit wire fraud and bank fraud".

According to The Registe]]></description></item></channel></rss>