> daily_signal(2026_08_01)
Windows quietly started scanning the photos on your PC, your data is fighting to become your price, and a Russian implant just outlived a full wipe of the mail server.
PickBits Daily Signal · Saturday, August 1, 2026
1. Microsoft slipped a face-scanning photo app into Windows 11 that reads your local files before you even sign in — and there's no uninstall button.
The default is now 'indexed.' An OS update quietly turned every Windows 11 PC into a photo-analysis engine, left the off switch out, and skipped the consent screen.
Key fact: Open Settings > Apps and check for 'OneDrive Photos'; removing it means uninstalling the OneDrive client, and the People face-grouping feature stays off unless you explicitly opt in.
The OneDrive Photos app began appearing on Windows 11 in late July 2026 (first spotted by Windows Latest); it automatically indexes local image libraries with AI natural-language search, OCR, and an optional 'People' facial-grouping feature (Decrypt, 2026-07-29). · Decrypt reports the app can 'detect and display images stored locally on a PC even if the user is not signed into a Microsoft account,' and that it cannot be removed on its own — uninstalling it requires removing the OneDrive client from Windows entirely. · The 'People' face-grouping feature is opt-in because facial data 'may be considered biometric information in some jurisdictions' (e.g., Illinois' BIPA); Microsoft did not respond to Decrypt's request for comment. · primary source
2. You and your neighbor can be charged different prices for the same thing — and California's AB 2654 is the fight over whether your data gets to set the number.
Surveillance pricing quietly turns your profile into your price tag. A California bill would ban it; the industry is already lobbying to keep the practice — and the data harvesting behind it — alive.
Key fact: California shoppers and sellers: watch A.B. 2654 (the surveillance-pricing ban). EFF's argument is that identical products are priced by your profile, so comparison-shop from a logged-out/clean session and challenge prices that appear to move with your data.
In a 2026-07-28 EFF Deeplinks post, Matthew Guariglia and Hayley Tsukayama back California's A.B. 2654 (Asm. Chris Ward), which would bar retailers from 'surveillance pricing' — charging different prices for the same product based on personally identifiable information collected through electronic surveillance. · EFF cites an FTC finding that a shopper profiled as a new parent 'may intentionally be shown higher-priced baby thermometers on the first page' of in-app search results, based on residential zip code and time of purchase. · The San Francisco Board of Supervisors introduced a resolution supporting A.B. 2654 but stalled the vote after pushback from the San Francisco Chamber of Commerce; EFF sent supervisors a letter urging them to reconsider. · primary source
3. Russian hackers are riding a patched Exchange webmail bug into US government and corporate inboxes — and their implant survives a full wipe of the machine.
The load-bearing fact for anyone who runs on-prem Exchange: applying Microsoft's patch does not make you clean. A Russian state crew is exploiting an Outlook Web Access flaw with a server-side implant built to outlast credential resets and even a full re-image, so a patched-but-previously-exposed mail server has to be hunted, not just updated.
Key fact: If you run on-prem Microsoft Exchange, confirm the CVE-2026-42897 patch is applied AND hunt for OWAReaper server-side persistence — the implant survives re-imaging and credential resets, so a patch alone won't evict it; follow the removal steps in the vendor write-ups.
Russian state-linked hackers tracked as Laundry Bear (aka Void Blizzard, CL-STA-1114, TA488, UNK_PitStop) are exploiting CVE-2026-42897 — a CVSS 8.1 cross-site-scripting flaw in Microsoft Exchange Outlook Web Access (OWA) — in a campaign that began 2026-07-22 (The Hacker News, 2026-07-30). · The implant, dubbed OWAReaper (an evolution of ZimReaper), 'is capable of surviving browser reboots, credential rotation, and full re-imaging of the victim's device,' maintaining server-side persistence that requires deliberate removal from the Exchange server. · Targets span U.S. and European government entities plus telecommunications, financial, hospitality and aerospace sectors; Microsoft flagged CVE-2026-42897 in May 2026 and it is now patched, though infrastructure tied to the campaign dates to March 2026. · primary source
4. Cambridge open-sourced an AI map of the entire planet's land — and it finally lets the world's smallest farms watch their crops from space.
Satellite crop intelligence used to require a well-funded agency and a supercomputer. TESSERA turns decades of free satellite archives into an open 'fingerprint' of every 10m of land, putting crop-tracking within reach of smallholders in developing regions.
Key fact: Agtech, climate and development teams: TESSERA's GeoTessera embeddings are free and released under CC-BY — benchmark them against your remote-sensing pipeline before commissioning new labelled satellite datasets.
University of Cambridge researchers released TESSERA, an open Earth-observation foundation model that turns European Space Agency Sentinel satellite imagery (2017-2025) into a compact embedding for every 10m-by-10m patch of the planet's land, released under a CC-BY license with an openly reproducible training pipeline (itbrief, 2026-07-24). · Per Meteorological Technology International, 'for every 10m-by-10m area of land, the model produces a sequence of 128 numbers — known as an embedding' — stored 'in a freely accessible database called GeoTessera,' and 'in all tests, Tessera matched or outperformed rival models, including Google DeepMind's AlphaEarth.' · Cambridge frames field-level crop-health and yield forecasting at 10-metre resolution as help for smallholder farmers, whose sub-hectare fields are poorly served by satellite tools built for large industrial farms; the model was trained on AMD Instinct MI325X GPUs with cloud provider Vultr. · primary source