Vista elenco

This JCB doesn't dig – it does 406 mph

13 Agosto 2026 ore 17:41
A JCB has set a new world land speed record, passing 406 mph (653 kph) at Utah's Bonneville Salt Flats. The JCB in question isn't a digger or a dumper, but a hydrogen-powered racer known as the JCB Hydromax, driven by retired Royal Air Force fighter pilot Wing Commander Andy Green. It set the record for the fastest a hydrogen-powered internal combustion car has ever travelled, averaging 406.320 mph (653.909 kph) across two runs at the salt flats this week. JCB says the Hydromax is powered by two production-based engines derived from those used in its commercial machinery. The engines are made at JCB's factory in Foston, Derbyshire, and deliver a combined 1,600 bhp. The firm began a £100 million ($135 million) hydrogen engine investment program in 2021, arguing that battery power is practical for smaller machinery but less suited to heavy equipment requiring long operating hours and rapid refueling. It was given permission to sell hydrogen engines by licensing authorities across Europe last year. Another European engineering company, Bosch, is investing in hydrogen power and disclosed some of its plans back in 2023. However, JCB conceds that the two engines in the Hydromax were "extensively rebuilt to suit the demands of breaking the speed record," fitted with spark plugs designed for a Le Mans 24 Hour engine, for example. Burning hydrogen produces no carbon dioxide at the tailpipe, although a combustion engine can still generate nitrogen oxides. JCB estimates that a full record run consumed just over 2 kg (4.4 pounds) of hydrogen and produced 18 liters (about 5 gallons) of water. Beneath the bodywork is a steel-frame chassis similar to that of a conventional racing car, built with a minimal amount of high-strength tubing. The driver sits in a composite monocoque sub-chassis under a drag racing-style steel roll cage. One of the engines is located behind the driver's position and spins the rear wheels, while the other is located in front and drives the front wheels via a front-facing gearbox. Wing Commander Green is no stranger to land speed records. He was at the controls of the ThrustSSC vehicle when it broke the sound barrier on land, and also drove JCB's Dieselmax when it set the world diesel land speed record. According to JCB, its chairman, Anthony Bamford, led the hydrogen engine project and came up with the idea of a bid for the hydrogen world land speed record. "Twenty years ago we came to Bonneville with JCB Dieselmax and showed what British engineering could do with diesel power. Today we have done it again, this time with engines powered by hydrogen," Bamford said. "It shows hydrogen works, and it works today at the highest level with zero emissions." The Fédération Internationale de l'Automobile (FIA), motorsport's global governing body, officiated the attempt and has confirmed the 653.909 kph (406.320 mph) record. ®

Trump wants to grant private cyber firms a license to hack back

13 Agosto 2026 ore 17:04
Donald Trump is allowing government agencies to contract private cybersecurity companies to carry out operations against cyber-enabled transnational criminal organizations (CE-TCOs). The US President signed a memo on Wednesday confirming a strategy hinted at earlier this year, saying participating companies can support national operations against criminals, including cyber surveillance and technical disruptions of their networks. The latter, described as "Cyber Effects Operations," covers activities that cause "the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon." Although the memo establishes a distinction between cyber effects operations and cyber surveillance missions, it acknowledged that the latter will also inevitably involve some disruption or manipulation of systems in order to carry out the surveillance. Surveillance operations are designed for intel gathering, either to support further snooping or for later use in cyber effects operations, with the intent of remaining undetected. Trump described CE-TCOs as "any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests." Crucially, the definition excludes entities directly associated with, or operating wholly on behalf of, foreign governments. No stepping on TAO's toes, of course. Participating companies will undergo "rigorous vetting" and will be subject to "strict operational procedures," the memo adds. The operational procedures are to be drawn up within 60 days and codified by program executive directors working with the Homeland Security Council. Companies wishing to be called up for service will have to demonstrate that they have the technical capabilities to carry out the required operations, and be willing to prove this each year via annual evaluations. Program managers must ensure that the operational procedures open opportunities for highly resourced, large organizations, as well as "smaller, more agile companies" that may prove useful for "specialized or discrete tasks." The Justice Department will also play a role in authorizing operations, particularly those targeting US residents or raising domestic legal issues. Participating companies will also be prohibited from executing operations that could lead to "critical outcomes," which is shorthand for attacks that result in the loss of life or serious injury, or those that could be seen as an armed attack under international law. These companies will also be required to maintain a bond or escrow of at least $1 million, which shall be forfeited if they violate the terms of their contracts. Unleashing Trump's cyber army The White House published "President Trump's Cyber Strategy for America" document in March, which promised to "unleash the private sector by creating incentives to identify and disrupt adversary networks and scale our national capabilities." The document [PDF] also stated: "We will leverage the immense talents and ingenuity of our private sector research base. "We will establish a new level of relationship between the public and private sectors to defend America in peace and war." The announcement prompted legal eagles and think tanks to ponder the implications of such a move. Many wondered how the promise to mobilize the private sector would be put into practice. They did not then have the details contained in this week's memo, and some assumed participating companies would support operations against nation-states. This particular program, however, excludes entities acting directly on behalf of foreign governments. Writing for the Royal United Services Institute (RUSI) and citing reporting available at the time, cyber and tech research fellow Gareth Mott said that the US Computer Fraud and Abuse Act (CFAA) might need to be amended before American companies could legally offer such services. Experts from law firm Skadden, Arps, Slate, Meagher & Flom agreed, despite the US Cyber Strategy not mentioning any plans for legislative changes. They wrote: "Any attempt to more directly involve the private sector in offensive cyber actions will likely require further legal and regulatory changes before it can be meaningfully implemented. "Even if the administration were to issue new enforcement guidance redirecting prosecutions away from hack-back cases, the availability of civil penalties under the CFAA and its five-year statute of limitations would likely render such executive actions significantly less impactful. "Technology companies should consider closely monitoring developments to track how the administration plans to enact such incentives." However, Jenner & Block lawyers noted in an analysis published by Lawfare that a provision of the CFAA could limit participating companies' exposure. Title 18 of the US Code, § 1030(f), says the CFAA does not prohibit lawfully authorized investigative, protective, or intelligence activity by a US government agency or intelligence agency. Participating companies might therefore be protected when acting under government contracts and direction. However, no court has determined whether that exemption covers private companies carrying out such work. "No court has addressed whether this exception provides any protection for private-sector entities engaged to perform these activities on behalf of the US government and, if so, under what circumstances," the lawyers wrote. "At the very least, it is unlikely that a court would interpret this provision to extend to private companies engaged in independent offensive operations, without government direction or involvement." The last part is key: because the US government will draw up procedures and direct the companies' involvement, the work may fall within the CFAA exemption. Whichever way the US constructs its private sector play, it represents a significant shift in the country's cybersecurity policy, and perhaps that of other nations further down the line. As Mott points out, US allies will certainly be keeping tabs on the private sector program's success, and its take-up from the companies it looks to attract. ®

The backup Microsoft never promised you

13 Agosto 2026 ore 17:00
Confidence in an organization's cyber recovery capabilities deserves scrutiny. If a ransomware attack disables the SaaS data tenanted in the Microsoft cloud ecosystem, the data the business depends on as its lifeblood, the pace at which operations resume rests on assumptions that often prove wrong. Anyone whose answer is "It's all good. Microsoft has my back on this one with its comprehensive native retention and recovery capabilities" is due a reality check. With agile business tools like M365 and Entra ID and solid backend infrastructure in the form of Azure, Microsoft brings a lot to the SaaS party. Both IT departments and MSPs need to be aware, however, that Redmond operates on the same shared responsibility model as other major SaaS providers. In the event of a cyberattack, the recovery burden splits between what the cloud provider handles and what falls to the subscriber alone. MSPs face the additional pressure of meeting stringent SLAs, working with clients’ preferred providers or tooling, and managing their own staffing and profitability accordingly. Microsoft ensures that its services keep running in the aftermath of a strike but does not promise to restore data to a specific known good point before the disaster. That gap always sat with the customer, and planning for it before problems hit beats improvising while picking up the pieces. "There's a common misconception about what Microsoft is responsible for, as distinct from the service they're providing," explains Brent Torre, GM of cyber resilience . Microsoft's native tools, he points out, address problems like short-term accidental deletion and aspects of data governance. They are not a backup solution and will not protect against ransomware or recover data. "Microsoft is clear that whether it's a SaaS application like Microsoft 365, a platform application like SQL Server, or even VMs running in Azure, the customer is always responsible for the information that's in that service, as well as devices, accounts and identities," he adds. "If you get compromised and the attacker starts deleting data, Microsoft has no responsibility for that." A world of pain The gap between availability and true cyber recovery is misunderstood, and it has widened into something of a chasm in recent years. There are three contributing factors to this gap. The first is the evolution of cyberattacks. Typical cyberattacks have pivoted from muscling past a defensive barrier to targeting human weakness, because strolling in through the front entrance with a stolen pass is easier than shimmying through a forced window. Identity has become the primary attack surface. Credential compromise, or identity-based initial access, removes the need to find a vulnerability to exploit and requires only an unwary employee. AI is now a staple weapon in the criminal arsenal, augmenting exploitation techniques such as phishing, social engineering, deceptive emails and spoofed websites, all convincingly used to trick users into typing passwords into a portal controlled by the aggressor. The technique can get more scientific than that. Automated AI-powered bots test millions of leaked username and password pairs across hundreds of different websites, exploiting the common habit of password reuse. Microsoft Entra ID, the vendor's cloud-based identity and access management service and the very tool designed to keep criminals out, is now a prime vector for attack and no match for stolen identity. Once an attacker compromises Entra ID with pilfered credentials, without setting off alarms, they have a free run at gathering data from mailboxes, OneDrive, SharePoint, Teams and other soft targets. The ransomware attack itself can then be launched with ease and at leisure. Another contributory factor is that the vogue for moving workloads to infrastructure and platform as a service (IaaS and PaaS) models shows no sign of abating. Organizations tend to retain some functions on-premises, put some in SaaS applications, and others in cloud environments, but are often guilty of not protecting and managing everything to the same level of quality. Data gets backed up in a variety of locations, yet whether it is all equally recoverable in the event of a breach is another chink in the armor that nobody understands. The 'as a service' model is popular, but it is the weak link when ransomware strikes. The third part of the problem is the emergence of multiple compliance requirements mandating cyber resilience along with correct backup and recovery procedures, for which many organizations are ill-prepared. Together, these pressures give criminals room to do enormous harm to data, business operations and compliance posture in the gap between attack and restoration of SaaS availability. Given that Microsoft's native retention and recovery capabilities are not designed to deliver true cyber resilience, restoring the business to how it was before the attack is something to plan for in advance. Time for independent backup protection "At Kaseya we regularly recommend that you keep a copy of your data, independent of the primary environment it's operating in," advises Torre. "This needs to be something immutable that you can recover from even if the Microsoft or Google or Salesforce ecosystem goes down." This kind of protection is best delivered as a dedicated cloud-to-cloud backup solution stored outside the main SaaS tenant, he argues, an approach increasingly written into cyber insurance and compliance requirements. By pulling copies of regularly targeted data from the Microsoft tenant for storage offsite in a third-party datacenter, organizations can be sure that if SaaS credentials are compromised, critical assets remain safe from attack. Restoration can then push what is needed directly back into the SaaS environment, even where the original tenant has been destroyed. "In fact some people find it faster to stand up a new shell and rebuild it than try to gain access back into a compromised tenant," notes Torre. "Whether you're an internal IT technician, working the night shift, or an MSP needing to live up to your SLAs and maintain profitability, you require a solution that's super straightforward and you need to be able to trust that the recovery will work. Both IT departments and MSPs should be looking out for a solution that's incredibly easy to use. Disaster recovery isn't the only job that they have." A good platform, he says, focuses not just on guaranteeing recovery but on keeping the hygiene of the cyber resilience estate at a high standard without endless human intervention. It should also make certain that Microsoft 365 and Entra ID are restored together in a single workflow, so identity and the data it grants access to come back online in the right order rather than in separate stages. Choosing the right platform Datto is a cybersecurity and data protection business owned by Kaseya. Datto SaaS Protection for Microsoft 365, Datto Backup for Microsoft Azure, and Datto Backup for Microsoft Entra ID are designed between them to close the gap between availability and recovery by storing protected copies of tenant data in the Datto Cloud, outside the Microsoft environment. In this way a compromised production tenant does not take the recovery point down with it. "With our M365 backup, we're protecting one million users worldwide," claims Torre. "A lot of organizations have built trust around our ability to protect and recover their data. We offer a trusted platform for recovery that focuses on ease of recovery, ease of deployment, not just for M365 but for Azure and Entra ID too." Both IT bosses and MSP players need to recognize that a ransomware attack, or other cyber crisis, is a matter of when rather than if. Recovery matters more than protection, because protection is certain to fail at some point, and traditional approaches to backing up data are no longer sufficient on their own. Anticipating disaster is not enough; the organization also needs to be set up to withstand it. That means being as certain as possible that the Microsoft environment can be recovered rapidly, down to the last scrap of data. This capability underpins modern business workflows and operations. Microsoft tracks more than 4,000 identity attacks every second and analyzes 38 million identity risk detections daily — no organization is off the target list. When an attack lands, the restoration clock is already ticking, and any delay in fully restoring IT operations and key environments to their pre-attack state can mean the difference between survival and collapse, with profit, regulatory standing and reputation all riding on the outcome. Securing data with purpose-built cyber resilience platforms that enable rapid, clean recovery is how organizations meet that test. MSPs looking to close the gap can start with the Datto MSP Buyer's Guide to Microsoft Entra ID Backup Sponsored by Datto.

Mystery attacker spent a year raiding Salesforce and ServiceNow portals

13 Agosto 2026 ore 15:32
Someone has spent more than a year rifling through Salesforce and ServiceNow portals around the world, harvesting data that organizations accidentally left open to anyone who came looking. Researchers at Reco have named the operation "City-Forum" after a domain connected to its infrastructure. The domain has pointed to the attacker's server since March 2025, although exactly when the campaign began is unclear. Reco says the activity is continuing and increasing in volume. Reco isn't naming the targets, but said it spotted the attacker poking around portals belonging to telecoms companies, banks and other financial services firms, enterprise software vendors, cybersecurity companies, and public sector bodies. "In the last year, we've seen many threat actors that use Aura enumeration against over-permissioned Salesforce guest users. This actor is different," said Nitay Bachrach, senior security researcher at Reco. On Salesforce, the attacker targets Lightning Web Runtime (LWR) sites through the UI API's GraphQL layer, an approach Reco says it has not found documented in public research or incorporated into publicly available attack tools. Over at ServiceNow, the same operator queries a native Service Portal search endpoint that has received little public attention. The tooling also checks whether Salesforce sites permit self-registration, potentially offering a route from anonymous guest access to an authenticated external account with permission to see considerably more data. Reco said it saw these checks across most of the Salesforce targets it examined. "The threat actor created their own toolset, based on research and techniques which are not well documented online," Bachrach said. "They studied the services to map different common data leak vectors – this is an advanced actor." This isn't casual poking around either. Reco said the busiest Salesforce target logged more than 560,000 events from the attacker's IP during the campaign, almost all attempts to enumerate data available to guest users. Reco linked the Salesforce and ServiceNow activity to the same server, which targeted multiple organizations around the world. More unusually, the attacker hasn't bothered changing its infrastructure: the same IP address and domain have remained in use for at least 17 months, with related custom tooling doing the rounds across both platforms. ServiceNow told us it is "aware of a security company’s blog post claiming certain configurations are creating security risk. As noted in the security company’s post, there are no allegations of a compromise of the ServiceNow environment. Nonetheless, we take third party reports seriously and are investigating accordingly. Our priority is to protect our customers, their data, and our systems." Salesforce has not yet responded to The Register's questions. Salesforce customers have already had one very public lesson in what can happen when guest access gets too generous. In March, ShinyHunters told The Register it had stolen data from around 100 high-profile companies and nearly 400 websites after going after over-permissioned Experience Cloud guest accounts. City-Forum isn't doing quite the same thing, and Reco isn't blaming ShinyHunters. "We don't know who this is, and we're not ruling anyone in or out," Bachrach said. Reco says all the activity it observed was conducted without authentication, with the attacker collecting information that organizations had exposed through permissions, sharing rules, search sources, or other configuration choices. "If the guest can read a record, so can anyone on the internet," Bachrach warned. "That is not a platform vulnerability." Which is good news for Salesforce and ServiceNow, perhaps, but rather less comforting for anyone now wondering what their guest account has been showing the guests. ®

Scammers Exploit Shopify’s Own Notification System in New ‘Fake Refund’ Scam

13 Agosto 2026 ore 15:10

Security researchers have identified a phishing campaign that abuses Shopify’s own Shop app to deliver fake order and refund notifications directly to victims’ phones, marking a notable evolution of the classic “fake refund” scam.

According to research from cybersecurity firm Huntress, attackers are creating fraudulent Shopify seller accounts, or hijacking legitimate ones, to generate bogus orders against victims’ phone numbers or email addresses. Because Shopify’s Shop app treats these as genuine transactions, targets receive real push notifications and in-app receipts, rather than a suspicious email or text from an unfamiliar sender. Huntress said several of its own employees were targeted between May and August 2026, and that the technique has also been documented by researchers at Gen Digital and reported by users on Reddit.

In one example cited by Huntress, a fake receipt dated 7 August billed the recipient $339.96 for a “premium PC protection plan,” complete with a fabricated invoice number and transaction ID. The real sting sits in the shipping address field, which attackers repurpose to display a message urging the recipient to call a phone number if they did not place the order. Some variants dispense with the fake address altogether and instead push recipients toward the number via the order description, while others add a spoofed “out for delivery” shipment tracker to increase pressure on the target.

Victims who call the number are funnelled into a standard refund scam. Huntress said callers are typically talked into installing remote access tools such as ScreenConnect or AnyDesk, or into logging into their online banking. From there, scammers manipulate on-screen figures, sometimes editing displayed transaction details or coaching victims to misread a refund amount, to convince them they were mistakenly overpaid. Victims are then pressured to “return” the difference, usually by purchasing gift cards and handing over the redemption codes, which attackers cash out quickly.

Huntress frames the campaign as a variant of a technique it calls Living off Trusted Sites (LoTS), where attackers route victims through a legitimate, trusted platform before reaching a malicious outcome, rather than relying on a fake domain that is easier to flag. While earlier LoTS attacks used links to services such as Dropbox, Canva, or DocuSign to add credibility, this campaign instead abuses Shopify’s own notification pipeline to generate content that looks and functions exactly like a native alert. The firm noted a similar pattern in a previous campaign involving genuine PayPal invoices carrying fraudulent callback numbers.

Shopify has acknowledged the scam in its Help Center. The company and Huntress both advise users not to interact with unfamiliar phone numbers, email addresses, or links found within an order, and to contact Shop Support directly if they are concerned about the security of their account. Users who receive a suspicious order notification are advised to check their bank statements before assuming any charge went through, and can flag the order as “Not my order” within the Shop app. Huntress also recommends checking a store’s reviews and history before purchasing, noting that many of the fraudulent shopfronts used in this campaign were newly created.

The post Scammers Exploit Shopify’s Own Notification System in New ‘Fake Refund’ Scam appeared first on IT Security Guru.

Ryanair adds Google to its dual-cloud flight plan

13 Agosto 2026 ore 14:31
Ryanair has signed a five-year agreement with Google Cloud covering AI, productivity tools and multi-cloud infrastructure, just weeks after renewing its deal with rival AWS for another five years. The Irish budget airline says it will deploy Google Workspace and Google Cloud services across its 35,000-strong workforce as it pursues a target of 300 million passengers a year by 2034. We asked how much this deal is worth, but Google declined to say and Ryanair did not respond. The rollout includes the Mountain View firm's Gemini Enterprise agentic AI platform, which Ryanair intends to use to automate some decision-making, optimize flight crew logistics, and improve staff productivity. The airline will also use Google DeepMind's AlphaEvolve to refine algorithms and WeatherNext for forecasting and maintenance planning. Ryanair renewed its agreement with AWS for another five years on July 27, making AWS and Google Cloud the two pillars of what the airline itself calls its dual-cloud resilience strategy. Google says the dual-cloud setup will allow critical systems to switch between providers if one suffers an outage, helping keep flight operations, and customer services running. Under the renewed AWS agreement, Ryanair will continue using services including Amazon Quick, Amazon Bedrock, and Amazon Bedrock AgentCore for workloads ranging from its website to operational planning across a fleet of 647 aircraft. Reg readers may recall that AWS and Google Cloud were touting a jointly developed multi-cloud connectivity service at the end of last year. This links Google's Cross-Cloud Interconnect with AWS Interconnect, allowing customers to set up a private high-speed link between resources they have running on the two cloud platforms. "Ryanair is on an incredible growth journey to 300 million passengers by 2034. To support this growth, we need to ensure we have excellent infrastructure resilience, and our new dual-cloud strategy provides this," commented the airline's CEO, Eddie Wilson. "We are thrilled to be Ryanair's AI transformation partner," stated Maureen Costello, Google Cloud VP for UK, Ireland and Sub-Saharan Africa. "This agreement demonstrates how deploying generative AI at scale – coupled with modern collaboration tools for frontline workers – can help industry leaders scale securely, reduce operational costs, and redefine the travel experience." ®

Akira Ransomware Affiliate Rebooted Into Safe Mode to Dodge EDR and Broke Its Own Attack

13 Agosto 2026 ore 13:59

An affiliate of the Akira ransomware operation attempted a novel technique to blind endpoint defences during a recent intrusion, rebooting a compromised server into Windows Safe Mode to knock out both an EDR agent and Microsoft Defender in one move, only for the same stripped-down environment to cause the ransomware payload itself to crash before it could encrypt any files.

The incident, disclosed in a technical write-up published by managed detection and response provider Huntress, marks the first time researchers have observed Akira affiliates using a Safe Mode reboot to sidestep security tooling, a tactic more commonly associated with older ransomware families such as Snatch and AvosLocker.

Akira has been one of the most active ransomware operations tracked by Huntress over the past year, and its affiliates typically follow a consistent playbook: break in through an internet-exposed VPN appliance, most often from SonicWall, move laterally to the domain controller, enumerate Active Directory, exfiltrate data, and detonate the encryptor within a matter of hours. This latest attack followed that pattern almost exactly, according to Huntress, but introduced a twist at the final stage.

Credential Spray, No MFA, and a Familiar Path to the Domain Controller

According to Huntress, the intrusion began in early August with a burst of failed login attempts against a SonicWall SSL VPN, consistent with a credential-spraying attack. Roughly seven minutes later, one attempt succeeded: a valid VPN account with no multi-factor authentication in place. Nearly two hours passed before the attacker took hands-on action, logging into the domain controller over RDP and running PowerShell commands to dump full property details on every user and computer in the Active Directory environment, reconnaissance Huntress says is a hallmark of Akira intrusions.

The attacker then moved to an application server, installed WinRAR to archive mapped file shares, and used the S3 transfer tool s5cmd to upload the staged data to a cloud storage bucket under their control, standard double-extortion tradecraft designed to give the attacker leverage even if a victim can recover from backups. AnyDesk, a legitimate remote access tool, was installed as a persistent service and used both for hands-on-keyboard control and to deliver the ransomware payload itself.

The Safe Mode Gambit

Rather than spinning up a separate virtual machine to run the encryptor outside the reach of security software — a method Huntress has documented in earlier Akira cases- the affiliate instead used the built-in Windows configuration tool msconfig.exe to force the host to reboot into Safe Mode with Networking. Because Safe Mode loads only core Windows drivers and disables most third-party software by design, the reboot simultaneously took the Huntress agent offline and prevented Microsoft Defender’s real-time protection from starting, all while preserving the network connectivity the attacker needed to keep working.

The attacker had anticipated that Safe Mode would also block their own AnyDesk service, and pre-emptively added a registry entry to keep it running through the reboot, a detail Huntress says shows deliberate planning rather than an improvised move.

The Ransomware Undermined Itself

The plan worked well enough to blind defences, but it also appears to have doomed the attack. Minutes after the akira.exe payload launched, the host began throwing “out of virtual memory” errors, and the ransomware process tree failed before encryption could begin. Huntress attributes the crash to Safe Mode’s constrained memory environment, which was seemingly unable to support the ransomware’s resource demands.

A scheduled Defender scan eventually flagged the payload roughly an hour later, correctly identifying it as Akira, but could not quarantine it because real-time protection remained disabled in Safe Mode. The file was only removed after the attacker rebooted the host back into normal operation, restoring Defender’s protection in the process, meaning the attacker’s own anti-EDR trick was undone by their need to reverse it.

Despite the failed encryption, the attacker had already exfiltrated Active Directory data and file shares before the reboot, leaving the victim exposed to extortion even without any files being locked. Huntress cautioned that the outcome should not be read as a reliable defence: a host with more memory or a larger page file might allow the encryptor to succeed in Safe Mode, and researchers said it is plausible Akira’s developers will adjust the malware’s memory footprint or boot sequence to make the technique more reliable in future attacks.

Recommendations

Huntress urged organisations to enforce MFA on all VPN accounts, monitor for bursts of failed VPN logins followed by a successful one, and ensure EDR is deployed across every endpoint rather than a subset of the environment. It also recommended that defenders specifically alert on boot-configuration changes and Safe Mode reboots, including msconfig.exe and bcdedit activity, and Windows event log entries indicating a Safe Mode boot as well as any modification to the registry keys that control which services are permitted to run in Safe Mode.

The post Akira Ransomware Affiliate Rebooted Into Safe Mode to Dodge EDR and Broke Its Own Attack appeared first on IT Security Guru.

Is AI entering the SOC at the right stage?

13 Agosto 2026 ore 13:56

By Simon Phillips, CTO, CybaVerse

Alert fatigue is an issue that has plagued Security Operations Centres for years.

As organisations’ digital estates grow, there is more architecture to secure and more architecture for threat actors to attack, which has ultimately led to more alerts.

Today, on average a SOC will face thousands of alerts every day, each of which could indicate a potential threat. Each alert must therefore be analysed and investigated before appropriate action can be taken.

However, ask any SOC analyst and they will tell you the majority of these alerts are benign or false positives.

Yet, analysts will still spend hours investigating activity that ultimately poses little or no risk, hoping to identify the small number of genuine threats hidden amongst the noise.

Given the volume they face, and the possibility of missing something before it’s too late, it’s a noisy, high-stress environment that often leads to burnout and fatigue.

To tackle these issues, many SOCs today are turning to Artificial Intelligence (AI) to support the management of alerts.

In this scenario, the first-line analyst is replaced by an agent that reviews the incident to determine whether it’s malicious and if further action is required. The analyst must then review the conclusion reached by the agent to ensure it is accurate, but they don’t conduct the initial investigations themselves, which reduces the volume of alerts they have to investigate every day.

However, even despite these improvements, is there another way that could reduce the noise even further?

If organisations are still generating huge numbers of unnecessary alerts, have they actually solved the underlying problem, or simply moved it further downstream?

Moving AI upstream

Instead of asking AI to investigate incidents after they have been created, some organisations are using the technology much earlier in the detection process.

Rather than having AI decide whether an alert is malicious, in this scenario it’s used to help build better detection logic and more effective workflows before alerts ever reach an analyst.

For instance, in a phishing attack when an employee reports an email as suspicious, many security platforms immediately generate an incident that someone must investigate.

Traditionally, either a human analyst or an AI assistant would then collect additional context, checking whether links have been clicked, whether anyone else received the email, or whether similar activity appeared elsewhere in the environment.

If these types of checks are incorporated into the detection process, and the answers to the questions are no, then an incident would never need to be created in the first place.

The AI would determine that there was no wider threat, meaning the alert could be filtered out before it ended up in the SOC ticket queue.

The result is a faster, more efficient SOC, with far fewer unnecessary alerts reaching analysts.

From a customer perspective, this can also reduce the costs of working with an outsourced SOC partner.

Many AI-powered investigation platforms price their services according to the number of alerts they process, so reducing unnecessary alerts before they reach the investigation stage can improve efficiency while also helping organisations control operational costs.

Improving security through engineering

Another benefit of moving AI further upstream is that it limits access to sensitive customer data.

Many AI-driven investigation platforms analyse real customer logs and incident data to determine whether activity is malicious. While providers implement safeguards, some organisations are uncomfortable with sensitive operational data being processed by external AI systems, particularly where regulatory or contractual obligations apply.

Using AI during detection engineering changes this process. The AI is used to create the logic that identifies threats, not to inspect live customer data.

Once the detection rules have been verified, they can be applied consistently across customer environments without repeatedly sending operational data through AI models.

Solving the cause, not the symptom

The cyber security industry has become very good at handling alert fatigue, but not so good at preventing it. Is it time a different approach was adopted?

If security teams continue generating thousands of low-value alerts every day, replacing analysts with AI may improve efficiency, but it won’t address why the alerts exist in the first place.

As AI becomes more deeply embedded within security operations, organisations should consider where it delivers the greatest value. In many cases, the answer may not be at the point where analysts investigate incidents, but much earlier, where better detection engineering prevents unnecessary incidents from being created at all.

By reducing false positives at the source, this allows analysts to spend more time on genuine threats, while improving consistency, cutting costs and helping organisations make better use of both their technology and their people.

The post Is AI entering the SOC at the right stage? appeared first on IT Security Guru.

WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud

13 Agosto 2026 ore 13:53
A previously unseen Android near field communication (NFC) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access trojan (RAT) called SpyNote as part of a contactless payment fraud scheme. The purpose-built malware, according to Group-IB, is designed to capture live card data via NFC and transmit it to fraudsters in real time. It was first detected in

North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring

13 Agosto 2026 ore 13:45
Companies are used to thinking about attackers as outsiders trying to break in. North Korean IT workers flip that model. They apply for jobs, pass interviews, receive legitimate credentials, and can end up inside the same systems companies spend millions trying to protect. That risk is no longer theoretical. The FBI is now investigating a North Korean remote IT worker who reportedly worked for

AWS key exposed in JavaScript may have lit way to Beacon's charity data

13 Agosto 2026 ore 13:34
Beacon, a CRM provider for charities and nonprofits, says an AWS access key "potentially exposed in public JavaScript build artifacts" is the leading suspect in its July breach. The revelation came in the company's first update on the attack in more than a week. If the access key was exposed in public build artifacts, it raises questions about why Beacon's development pipeline and code review controls failed to catch it. Beacon used stronger wording about the potential data loss, confirming that a copy of the database was made and assessing that it was probably downloaded in readable form. "This update confirms… that a copy of the database which holds all Beacon customer data, including attachment files, was made and likely downloaded in a readable format by the threat actor," wrote CTO David Simpson. "Analysis of the AWS Cost & Usage reports across May-July 2026 has been conducted. This data showed a significant increase in data transfer on 27-28 July 2026. This timing correlates with the malicious activity, which supports an assessment that substantial downloads occurred." Beacon's logs cannot reveal which specific records left its systems, although the company has confirmed that a copy of the database containing all customer data and attachments was made. In an FAQ accompanying the update, Beacon advises customers to assess the likely exposure by reviewing what they stored in their CRM instance. Many of the charities that have confirmed they are affected have said the data mainly pertains to personal information and details about donations. Simpson said Beacon's AWS data was encrypted at rest, but the compromised access key may have allowed the attacker to retrieve it in readable form. The malicious activity began in the early hours of July 27, according to Beacon's root cause analysis, matching its initial estimate of the incident timeline. The company has more than 1,500 customers, although it has not established how many had data taken. The malicious activity lasted one hour and 27 minutes, Beacon said, and the attacker established no persistence mechanisms in AWS. Simpson warned customers that "there are things we may never be able to find out about this incident," and that other details won't be shared to protect Beacon's security position. He promised to provide customers with a summary when the investigation concludes in a few weeks, but warned that "the level of detail contained in this next and final update may not be any more than" Beacon published on Wednesday. "I recognise this is frustrating, but unfortunately it is the reality of complex incidents like this. With this in mind, we would recommend making your own risk assessments now regarding onward notification to impacted data subjects using your knowledge of the data you process and store with Beacon." Since Beacon disclosed the attack on August 4, the number of high-profile charities confirming they are affected has grown every day. Early confirmations came from the likes of Molly Rose Foundation, Macmillan Cancer Support Jersey, and English National Ballet. Sheffield Hospitals Charity, Shrewsbury and Telford Hospital Charity, the British Deaf Association, and Lincoln Cathedral are among those that have since joined the list. The Charity Commission said that "a number of charities have submitted serious incident reports," and that the volume of these reports is causing delays to responses. "We appreciate your patience and understanding as we prioritise instances of the greatest risk," it said. ®

Forescout Launches Rapid Insight Assessment to Uncover Hidden Cyber Risks

13 Agosto 2026 ore 13:04

Forescout has launched a new Rapid Insight Assessment designed to help organisations uncover hidden assets, network blind spots, and security exposures as artificial intelligence accelerates vulnerability discovery.

The new assessment combines external analysis with passive network monitoring to give security teams a clearer picture of their attack surface. Forescout says the service can deliver actionable findings within days, helping organisations identify and prioritise risks before attackers exploit them.

The launch comes as security teams face the challenge of managing increasingly complex environments. Unmanaged devices, shadow assets, exposed services, and gaps in network visibility can all create opportunities for attackers.

At the same time, advances in AI are making it possible to discover and exploit vulnerabilities faster.

Finding security exposures before attackers do

The Rapid Insight Assessment uses open-source intelligence to examine an organisation’s external exposure. For internal assessments, Forescout can also deploy its portable Flyaway Kit to passively observe network activity without disrupting operations.

The Flyaway Kit provides visibility across IT, OT, IoT, cyber-physical systems, and unmanaged devices, including assets within remote and air-gapped environments.

The assessment can identify internet-facing remote access services, exposed administrative interfaces, previously unknown network devices, risky communications, and unmanaged OT and IoT assets.

It can also provide more detailed asset intelligence and identify devices associated with Known Exploited Vulnerabilities.

AI is shrinking the window for defenders

Craig Weimer, Vice President and General Manager of Americas at Forescout, said the increasing ability of AI systems to carry out cyber tasks is changing how quickly organisations need to identify security weaknesses.

“When an AI system can discover, connect, and exploit vulnerabilities on its own, the idea of an autonomous attacker is no longer just a future concern,” Weimer said.

He pointed to recent public disclosures from OpenAI, Anthropic, and Meta showing that frontier AI models can perform complex, multi-step cyber tasks against real environments with limited human involvement.

“The message for defenders is clear: the window between exposure and exploitation is getting smaller, and organisations need a complete understanding of their attack surface before adversaries find it first,” he added.

Tackling network blind spots

One of the challenges facing security teams is that they cannot protect assets they do not know exist. This becomes particularly difficult across large or distributed environments where new devices and services can appear without being captured by existing security processes.

Forescout says its Rapid Insight Assessment is intended to provide organisations with a faster way to uncover these gaps without lengthy assessment cycles.

“Organisations can’t afford assessment cycles that take months when hidden exposures, network blind spots, and unknown assets can quickly become opportunities for attackers,” Weimer said.

“The Rapid Insight Assessment gives organisations a fast, efficient way to see their most critical security risks and exposure gaps, delivering clear, actionable findings in days so they can address exposures before they become security incidents.”

As AI gives attackers greater speed and automation, gaining an accurate view of the attack surface could become increasingly important. For defenders, finding hidden exposures before an adversary does may prove critical to reducing the opportunity for an attack in the first place.

Learn more and request your free Forescout Rapid Insight Assessment.

The post Forescout Launches Rapid Insight Assessment to Uncover Hidden Cyber Risks appeared first on IT Security Guru.

UK Cyber Attacks Jump 26% Year-on-Year as Ransomware Activity Doubles Globally

13 Agosto 2026 ore 12:57

UK organisations were hit by an average of 1,597 cyber attacks per week each in July 2026, a 26% increase year-on-year, according to new data from Check Point Research, the threat intelligence arm of Check Point Software Technologies. The growth rate outpaced the 16% year-on-year rise recorded globally, even though UK attack volumes remained below the worldwide average of 2,336 weekly attacks per organisation.

The figures form part of Check Point Research’s Global Threat Intelligence report for July 2026, which found that cyber risk is accumulating across multiple fronts at once: rising attack volumes, a sharp acceleration in ransomware activity, and growing exposure from the use of generative AI tools in the enterprise.

In the UK, Education, Energy & Utilities, Software, Government, and Media & Entertainment were named as the five most targeted industries in July, reflecting attackers’ continued focus on sectors that hold sensitive personal data, run critical national infrastructure, or present broad, distributed attack surfaces.

Global attacks keep climbing

Worldwide, organisations faced an average of 2,336 weekly cyber attacks in July, up 3% month-on-month and 16% year-on-year. Education remained the most targeted sector globally, averaging 4,848 weekly attacks per organisation, up 14% year-on-year. Government followed with 3,044 attacks and Telecommunications with 2,927, while Energy and Utilities rose 20% to 2,759 attacks and Hospitality, Travel and Recreation entered the global top five with 2,614 attacks, up 28%, likely reflecting increased exposure during the summer travel period.

Regionally, Latin America recorded the highest attack volume, with 3,561 weekly attacks per organisation, up 19% year-on-year, followed by APAC at 3,316. Europe stood out for its rate of growth, with attacks up 18% year-on-year to 2,051 per organisation, ahead of North America’s 9% rise to 1,613.

Ransomware breaks from its earlier pattern

The sharpest shift in July came from ransomware. Reported victims reached 964 globally, up 87% year-on-year and 49% from June, marking a decisive break from the first half of 2026, when monthly ransomware activity averaged around 672 incidents. Business Services was the most affected sector, accounting for 32.5% of reported victims, followed by Industrial Manufacturing at 14.4% and Consumer Goods and Services at 13.4%.

North America remained the most affected region for ransomware, accounting for 45% of reported incidents, followed by Europe at 28% and APAC at 17%. At country level, the United States continued to dominate the victim count with 39.4% of reported attacks, followed by Germany, Canada, the United Kingdom and Italy.

The Gentlemen and Qilin were the most prevalent ransomware groups in July, each responsible for 14% of published attacks, while DeadLock climbed to third place with 10% and 97 reported victims, highlighting continued churn in the ransomware ecosystem.

GenAI exposure becomes a daily business risk

The report also highlighted the growing data exposure risk posed by generative AI tools. One in every 36 prompts sent from enterprise networks carried a high risk of sensitive data leakage, and 88% of organisations that regularly use GenAI tools were affected by high-risk prompt activity. Organisations used an average of eight GenAI tools in July, with individual users generating 95 prompts on average during the month.

Personal data was the most common sensitive category exposed, appearing in 70% of organisations, followed by financial data and network and IT infrastructure information, each present in 68% of organisations.

Email also remained a high-volume risk channel: one in every 128 emails, or 0.78%, was classified as phishing in July, with a further 20% falling into unwanted or risky categories such as graymail, spam and suspicious messages.

“Cyber risk is accumulating across multiple fronts”

“July’s data shows that cyber risk is accumulating across multiple fronts at once,” said Barnaby Nickels, regional sales manager for UKI & North EU at Check Point Software. “Attack volumes continue to rise, ransomware has accelerated sharply, and GenAI exposure is now part of daily business activity. Organisations need prevention-first, AI-driven security that protects networks, users, data and AI workflows before attacks can cause impact.”

For UK organisations, the message lands with particular urgency. With attack growth outpacing the global average and sectors ranging from education to critical infrastructure squarely in attackers’ sights, security teams are being urged to strengthen defences across network, cloud, endpoint, email and AI usage rather than relying on any single layer of protection.

The post UK Cyber Attacks Jump 26% Year-on-Year as Ransomware Activity Doubles Globally appeared first on IT Security Guru.

Twitch feeds your streams to Amazon's AI unless you tell it to stop

13 Agosto 2026 ore 12:32
Twitch has given streamers a switch to stop their channel content being fed into Amazon's generative AI machinery, but naturally it is turned on by default. The Amazon-owned streaming platform has added a "Training for Generative AI" control to channel settings, allowing streamers to opt out of having their content used for future GenAI model improvements. With the setting enabled, Twitch says channel content – including livestreams, videos on demand, clips, highlights, text, images, and chat messages – may be used to train Amazon's generative AI models. The benefits aren't confined to Twitch either, as the company says the resulting models may also be used elsewhere in the Amazon empire. For example, Twitch says audio from streams could be used to refine speech-to-text models, improving captions on Twitch as well as "across Amazon." Streamers who would rather not contribute their channels to Amazon's AI ambitions can opt out, but they'll need to do it themselves. Twitch has helpfully enabled the setting by default. Twitch chief product officer Mike Minton offered a refreshingly uncomplicated explanation for that decision during a livestream discussing the changes: "If it was opt-in, nobody would opt in," he said. "That's honestly the answer. So it's going to be on by default." The new control also doesn't mark the beginning of Amazon using Twitch material to build AI. According to Ars Technica, Minton confirmed at an event hosted by The Information in 2024 that Amazon was already using Twitch data to train AI models. What's changed is that Twitch users now have a dedicated way to tell it to stop using their content for future generative AI training. There are some wrinkles, naturally. The channel owner's setting determines whether messages posted in its chat can be used, so opting out on your own channel does not protect what you type in somebody else's if that streamer leaves training enabled. And Twitch's wording is conspicuously forward-looking: opting out means content won't be used for "future" GenAI model improvements. The company doesn't say that flicking the switch somehow extracts anything that has already made its way into a model. The Register has asked Amazon which of its AI models have been trained on Twitch content, how long it has been using the data, and whether opting out has any effect on material already used for training. We've also asked whether models trained on Twitch content are used in products available to Amazon customers or third parties. For now, Twitch creators finally have a way to keep their content off Amazon's generative AI training menu. All they have to do is find the switch Amazon would plainly rather they left alone. ®

Everything is better with pickles... except Windows

13 Agosto 2026 ore 11:26
BORK!BORK!BORK! "Everything is better with pickles," trumpets a Wendy's sign. Everything is also better with a helping of bork, if the screen is to be believed. Spotted by an eagle-eyed Register reader in Vancouver, the display shows something amiss with Windows Phone Link – although why a PC encouraging customers to drop dollars on a Dill Pickle Chicken Sandwich needs the app is anyone's guess. The error itself usually comes up when something running Windows has been a bit careless with stack memory. Perhaps there's been a stack overflow, a software conflict, or a memory shortage. The usual fix is to reach for the power button or perform a restart. The more technically minded might try to diagnose the whoopsie and fix it without a boot cycle, although had a more technically minded person set up the system in the first place, it's unlikely that the PhoneExperienceHost.exe application would have reared its ugly head in this way. Phone Link connects a Windows PC to an Android phone or iPhone. The theory goes that users can keep track of mobile notifications, send and receive messages, or deal with calls from their Windows desktop. It arrived with Windows 10 as Your Phone before Microsoft renamed it Phone Link and continued adding features. Ordinarily, the service doesn't use much in the way of memory or CPU. However, something has clearly upset the instance here, much as an excess of dill pickles might disagree with the customer. While we're sure the foodstuffs on offer are excellent (although our reader told us they were only popping in for a Frosty Dairy Dessert rather than anything slapped with a dill pickle), we might give the chicken sandwich a miss this time. Even Windows appears less than keen. ®

A Youth Sports Giant Promised Reforms to Protect Kids From Sexual Abuse. Most Never Happened.

13 Agosto 2026 ore 11:00
Photo collage that combines a center inset photo of a female basketball player standing on a court in a large arena; a close-up pile of yellow, blue and red volleyballs on the left; and a vertical banner displaying the Amateur Athletic Union logo on the right.
Ashlee Orndorff played basketball as a teen.

In the competitive world of youth sports, few organizations have a reach as vast as the Amateur Athletic Union. 

With 760,000 athletes and coaches nationwide, the AAU hosts competitions in dozens of sports across the country. This summer alone, hundreds of thousands of children competed in AAU events for elite young athletes: a staggering 100,000 at the world’s largest volleyball championship in Orlando, Florida; 8,000 at its storied basketball championships at Disney World; more than 15,000 at the Junior Olympics in Iowa.

To the hundreds of thousands of parents whose children play under the red, white and blue AAU badge, the organization offers more than a place to compete. The AAU promises their children will be safe — that its coaches are vetted, monitored and trained; that strict rules govern how adults interact with children; and that it responds effectively to allegations of abuse within its ranks. 

But that trust is misplaced, according to an investigation from ProPublica and The Washington Post. The AAU is failing on nearly every level to adequately protect the hundreds of thousands of children in its care from sexual abuse, the investigation found, misleading the public about its prevention measures and suppressing allegations of sexual misconduct. 

In doing so, the AAU is breaking many of the pledges it made in the wake of a 2011 sex abuse scandal involving its CEO and young basketball players. AAU leaders at the time said they would build a “new culture in which the overarching priority” was protecting young athletes, committing the organization to sweeping safety reforms. But they did not implement the majority of those reforms, ProPublica and The Post found, putting many children at risk. Some AAU athletes have had devastating experiences. 

The AAU does not offer child abuse prevention training, though it claims to the public that it does. It does not verify whether coaches take the training it does offer, though it calls the course “mandatory” on its webpage for parents.

The AAU has become a haven for coaches suspected of abuse, ProPublica and The Post found, based on a review of public disciplinary lists and interviews with current and former executives from six national sports governing bodies and other key stakeholders. Those sports officials say the AAU has earned a reputation as a place where coaches can escape discipline and are not bound by strict safety laws, making it more difficult to protect young athletes. ProPublica and The Post identified eight coaches who continued to work with children under the AAU in the last five years after being banned or suspended by other youth sports organizations — even though the AAU pledged in 2012 that it would ban such coaches. 

Serious allegations of sexual misconduct against coaches in the AAU are handled by its Board of Review, a group of four elected AAU members and a chair whose names are not made public. Asked about written guidelines for when to ban coaches, one former member who sat on the board for nearly 25 years said the group “just decided on our feelings.”

The abuse reporting hotline AAU promised to create as part of the reforms redirects to the AAU’s general office line with no option to report abuse, though callers can press 5 to reach a department for “medal orders.”

Instead of protecting children, the AAU has prioritized building an ever-bigger footprint across youth sports through cheap and easy team registrations, ProPublica and The Post found, allowing it to dramatically grow its revenue in recent years.

The scope of the consequences for young athletes nationwide is impossible to quantify, ProPublica and The Post found, because the AAU operates with a secrecy that is unusual for a nonprofit that serves children.

The AAU declined to answer questions from ProPublica and The Post over the course of more than a year, including whether the organization trains its coaches, how it investigates abuse claims, and how it enforces policies and safety rules. It would not verify if specific coaches overseeing AAU-registered teams had been authorized and background-checked by the AAU, as its rules require. While other youth sports organizations post public lists of coaches found to have abused children, the AAU does not.

In a statement, the AAU said it is “committed to protecting its athletes through comprehensive protection policies overseen by our Compliance Department.”

Athlete protection “is at the forefront of our safety measures such as a verified identity check and mandatory background screenings for all non-athlete AAU members, including coaches,” it said. The statement also cited “supplemental medical benefits” and “mandatory concussion protocols” as measures that it said prioritized the “physical well-being of its members.” 

“These safety measures reflect our ongoing commitment to providing a safe, secure, supportive, and trusted environment where athletes can thrive,” the statement said.

The AAU also took action on one point raised by the news organizations. After ProPublica and The Post asked the AAU last year whether it actually mandated training for coaches, as its website claims, the organization quietly changed its website to say the training was “encouraged.”

For the first time, using thousands of pages of internal, legal and court records and interviews with key stakeholders, ProPublica and The Post were able to document how the AAU handled some child sex abuse claims in the years after it promised reform. Several years after allegations were made against a former AAU president, ProPublica and The Post found, its review board exonerated another top AAU executive accused of sexual abuse by a former player without interviewing a single witness or considering a past allegation from a different player, court records show. A current AAU official, Jim Fox, said he believed the AAU’s handling of the case was an attempt to “cover it up.”

The AAU has taken other steps that have had the effect of keeping sexual abuse claims out of the public eye, ProPublica and The Post found. Clauses in AAU registration forms require all claims against the AAU to be resolved through confidential arbitration hearings instead of jury trials in open court. The AAU uses those agreements to quash lawsuits over child sex abuse claims — arguing in court that children who say they were victimized by their coaches had signed away their right to sue when they registered for an AAU team, records show. That practice is extremely rare in sex abuse cases at other major youth sports organizations, according to attorneys, court records and sports groups, and was mostly banned by a Biden-era law in 2022.

ProPublica and The Post found that the AAU has attempted to force sex abuse claims into arbitration as recently as 2024, in the case of a lawsuit filed by a teenage girl in Florida who said she had been abused by her AAU volleyball coach. The case was settled out of court last year.

The AAU declined to comment on this practice or any of these cases, saying it could not comment on “legal matters.” 

The AAU’s use of arbitration agreements meant that even in a high-profile case in which an AAU coach was convicted of decades of prolific abuse, the AAU itself escaped scrutiny. 

The co-director of an influential basketball club in Cedar Rapids, Iowa, Greg Stephen, was accused of sexually exploiting more than 400 of his young basketball players in 2018 and sentenced to 180 years in prison on multiple charges. But arbitration clauses prevented his former players from suing the AAU, ProPublica and The Post learned, even though boys’ families initially argued that the AAU was partly responsible because it had failed to enforce its 2012 safety policies, including a ban on coaches sharing bedrooms with players.

A judge sided with the AAU and ruled that the victims could not sue the wealthier parent organization, allowing the AAU not to respond to the claims in court. The club, Barnstormers Basketball, denied the claims.

The Barnstormers’ AAU-provided insurance limited payouts for sexual abuse claims to $1 million, said Guy Cook, the families’ lawyer, the equivalent of a few thousand dollars for each young victim.

Cook said the AAU had grown “sophisticated” in its attempts to suppress child sex abuse lawsuits: “It’s not unlike what the Catholic Church has done.”

In 2018, in the wake of revelations about sexual abuse by USA Gymnastics doctor Larry Nassar and other powerful figures in Olympic sports, Congress created a new oversight system to prevent sexual abuse. The law charged the U.S. Center for SafeSport with investigating allegations of sexual abuse in sports overseen by the U.S. Olympic and Paralympic Committee — made up of national sports governing bodies like USA Gymnastics — and enforced strict new rules about safety and training. 

But the AAU exists outside of that system, allowing it to benefit from a gap in the law. Because it is not a sanctioned national sports governing body, the AAU is not overseen by SafeSport and does not have to follow its rules or mandate that coaches take its trainings. ProPublica and The Post found that it does not abide by SafeSport suspensions or bans.

“It should scare parents,” said former Florida state Sen. Lauren Book, a child sex abuse survivor and prevention advocate who was a member of a task force established by AAU to reform its abuse prevention practices in 2011. Along with most other members of the task force, she said she has since lost faith in the organization. 

“What AAU does is protect institution over children,” Book said. “They have never done the right thing when it comes to child protection.”

Photo collage of rows of volleyballs flanked by a view of a person in a blue jacket seen from behind in dim lighting on the left, and a close-up of a player’s feet in white athletic shoes standing on a blue court surface on the right.

Broken Promises

Before he was caught at the center of a scandal, Bobby Dodd saved the AAU. When the former youth basketball coach took the helm of the nonprofit in 1992, it was struggling. It had been founded in the 19th century to oversee amateur sports, but Congress had given that role to the U.S. Olympic and Paralympic Committee and its national sports governing bodies in 1978. The AAU’s relevance had been declining since.

Dodd saw youth sports for what they would soon become: a booming business. He built the AAU of the 1990s and 2000s into the juggernaut of youth basketball, the home of virtually every future NBA star; invested in a Junior Olympics brand that brought in thousands of children from across track and field; and moved the organization’s headquarters to the ESPN Wide World of Sports complex inside Disney World.

Under Dodd, there were few barriers to becoming an AAU coach: Anyone who paid a $16 membership fee could start a team, no background check required. By joining the AAU, basketball and other sports clubs got perks like cheap and easy liability insurance. More importantly, they got access to a circuit of organized tournaments, from local weekend events to major national championships.

But along with Dodd’s stewardship of AAU came criticism that the fast-growing organization was becoming a free-for-all.

After a 2004 Seattle Times investigation found dozens of people with felony convictions were coaching AAU-sanctioned teams in Washington and Idaho, including a coach who was a convicted murderer, Dodd pledged to consider background checks for AAU’s 65,000 coaches. “We are going to try to ensure more integrity in the process,” Dodd told the paper.

The AAU still had not introduced those background checks when, in 2011, ESPN reported that two men had accused Dodd of molesting them as youths in the 1980s, when he was their basketball coach. Dodd denied the allegations but stepped down as president, collecting a $1.5 million payout from the organization and putting the AAU back in an uncomfortable spotlight. He was not charged with a crime, and he could not be reached for comment.

Again, the organization promised change. 

Under a new president, Louis Stout, the organization convened a task force of child safety experts. It vowed in June 2012 to implement all of the task force’s recommendations, which it called “historic child protection measures.” 

The AAU rolled out mandatory background checks. It also pledged to train all adults in child sex abuse prevention and create policies that would “prevent adults from being alone with children.” Participation was a privilege, AAU vowed, not a right: “Anyone who is prohibited from participating in an organization that serves youth or who violates the AAU’s child protection policies should be barred.” 

The most important change, the AAU said, would be cultural. Child safety would now be “an overarching priority.”


Within a matter of months, there were signs that little was actually changing.

That year, the AAU gave a 2012 leadership award to a man named Rick Butler, one of the country’s most prominent girls’ volleyball coaches at the time. Butler had been instrumental in building AAU volleyball into a powerhouse. 

But he had also been banned by USA Volleyball from coaching girls since 1995, after the sport’s governing body concluded that he had had sexual intercourse with three teenage players years earlier, when he was in his late 20s to mid-30s. Butler’s attorney called them “legal, consensual relationships in the 1980s,” noting that there was no law or rule against coach-player relationships at the time.

Months before giving Butler the award, the AAU had promised it would bar anyone “banned by other youth-serving organizations” from coaching children. 

But Butler continued coaching girls under the AAU until 2018. That year, USA Volleyball pulled its affiliation with the AAU over Butler’s membership, and the AAU subsequently banned Butler, according to a letter reviewed by ProPublica and The Post. Butler’s attorney said he has not been accused of more recent misconduct.

Stout died unexpectedly in September 2012, just a few months after he committed the AAU to the list of reforms. (After an interim period, Roger Goudy, who had run the AAU’s volleyball program for decades, was elected president in 2014.)  

When the AAU published its first youth protection handbook in December 2012, there was no rule barring coaches banned by other groups. The handbook did say it was following another key reform: All AAU coaches were now taking an “educational course.” 

The organization had repurposed training it had used since before the Dodd scandal — an online seminar called “Double Goal Coach” from the nonprofit Positive Coaching Alliance. The course was focused on sports psychology and coaching techniques, not sexual abuse prevention training. The AAU claimed that “all registered non-athletes” were taking the course, even though no one verified whether they did, according to officials, stakeholders and a person directly familiar with the training. 

“It’s never been mandatory,” said Peg Adams, a longtime regional official at the AAU who spent more than two decades reviewing abuse claims against AAU coaches as part of its Board of Review. “It should be, but that’s something they [AAU] have to work out.” 


When they were first announced, the AAU’s child safety rules, if implemented, would have put the organization at the vanguard of youth sports. But in 2018, Congress passed a landmark new sports safety law, known as the Safe Sport Act, that forced much of the rest of the sports world to make sweeping changes.

Under the new law, the U.S. Center for SafeSport was charged with investigating sexual abuse allegations in all 50 national sports governing bodies, the organizations that oversee and set rules for specific sports. SafeSport could ban or suspend accused coaches in these groups, placing their names in a searchable public database known as the SafeSport list. It required adult coaches and volunteers to take SafeSport-provided child abuse prevention training annually and follow strict new safety rules governing how they interacted with athletes. 

But because the independent AAU is not a national governing body, SafeSport could not require the AAU to follow its disciplinary list, rules or training. Only a few provisions tucked at the end of the 2018 bill applied to the AAU — including a requirement that all sports groups “offer and provide consistent training … regarding prevention and reporting of child abuse.” Only Congress, not SafeSport, could enforce that provision.

The new Center for SafeSport was far from perfect. Underfunded and understaffed, the center quickly racked up a backlog of unresolved complaints and closed many others without findings or with what critics said were inadequate investigations

SafeSport has since resolved many of those issues, improving its process to resolve cases more quickly and cut down its backlog, the organization said. In a statement, the center’s new CEO, Benita Fitzgerald Mosley, an Olympic gold medalist, said the organization “acknowledges the challenges we have met as the first national sport safeguarding organization in the world. We are on surer footing today.” 

SafeSport also drove up costs for the governing bodies, who were required to help fund the center’s investigations and often pay for expensive background checks and compliance staff. That meant higher membership fees for their athletes. 

The AAU was not required to pay for any of that. So while governing bodies and SafeSport inched toward reform, ProPublica and The Post found, the AAU did not.

Photo collage featuring a central portrait of a woman with long blond hair sitting cross-legged on a gymnasium floor in a black tank top and leggings, flanked on the left by an old photograph where one person’s face is scratched out alongside a smiling basketball player wearing a white jersey, and on the right by two images showing action on a basketball court during a game.
Ashlee Orndorff

“People Tried to Cover It Up”

In 2018, the year that the Safe Sport Act took effect, the AAU faced a test of its most significant promise: to remake its culture to protect children. 

That January, a woman named Ashlee Orndorff claimed on social media that she had been groomed and sexually abused as a teenager by an AAU executive, its second vice president, Matt Williams, who was also a paid employee of the organization at the time. 

Orndorff had been a teenage basketball phenom in the tiny unincorporated town of Hawthorne, Nevada, two hours outside of Reno. She won three state titles and was named the state Gatorade player of the year during her senior year of high school in 2000, setting records that she still holds. But for many of the years that she excelled on the court, Orndorff said, she had carried a terrible secret: Williams, her AAU club coach, had been sexually assaulting her. The abuse began when she was 15, she said, and carried well into her adulthood, resulting in the birth of a child she gave up for adoption at 19.

Williams was more than just a storied coach. He founded the Western region’s most prominent AAU basketball brand, Jam On It, which generated revenue for the AAU through the enormous tournaments it hosted every year.

After Orndorff’s allegations, the AAU pledged to investigate, saying Williams had “volunteered” to be placed on administrative leave. Orndorff’s allegations went before the AAU’s Board of Review a month later. The small group of AAU members, one elected to represent each region, had no training in law, investigation or child sexual abuse, according to Adams, the former board member. 

Transcripts reviewed by ProPublica and The Post show the hearing frequently resembled a contentious criminal trial. Williams had a lawyer, but Orndorff said she had not been able to afford one at the time. 

In a statement to the AAU, Williams denied sexually abusing Orndorff as a minor. But he admitted that he fathered Orndorff’s child, who was born when she was 19 and he was over 30 and just a year out of coaching her — a violation of the organization’s policy against having sexual relationships with former players, which was part of the 2012 reforms. The attorney asked Orndorff if her “anger” at Williams “is what has prompted this complaint.” 

“No, sir,” she responded. “Being fingered by my coach at 15 in a gym and him making me think that that is all that I was good for, was to be his sexual satisfaction, that is where my fucking anger comes from. Next question.”

The board did not interview any witnesses or introduce records that could corroborate Orndorff’s account. Orndorff had submitted a 34-page narrative of the alleged abuse that included dates, locations and names of potential witnesses, 10 of whom later corroborated aspects of her story in depositions for a 2019 lawsuit she filed against Williams and Jam On It, according to a review of thousands of pages of court records. (Williams and Jam On It denied wrongdoing. Orndorff settled the case in 2023, and Williams died from cancer the following year. An attorney for Williams’ estate did not respond to a request for comment.)

A diptych of a heavily altered vintage team photograph of a young female basketball player in a black jersey, with the surrounding teammates largely obscured by painted streaks of green, gold and white, next to an outdoor portrait of a woman with long wavy hair standing in profile against a desert landscape at dusk.
An altered photo, left, shows Orndorff when she was one of the country’s best teenage basketball players. Now 44, Orndorff says she still carries the trauma of abuse but is almost nine years sober and rebuilding her life.

Adams, who is a former Georgia gymnastics coach and gym owner, sat on the board during the Williams case. She said board members did not interview any witnesses because Orndorff had not provided a separate list of their names and phone numbers.

The hearing also did not consider an accusation of sexual abuse against Williams by a different player in 2005, the case records show. Rod Seaford, the board chair and the attorney running the hearing, had personally responded to the allegations in 2005, court records show. But Seaford did not mention them at the hearing, and Adams said Seaford had not told her they existed. (The girl who made the accusation declined to speak to police or the AAU at the time, records show, and that case did not proceed. Now an adult, she did not respond to an interview request from ProPublica and The Post.) Seaford declined multiple requests for comment.

By May 2018, within six months of learning of Orndorff’s allegations, the Board of Review cleared Williams of wrongdoing and reinstated him to his $84,000 position as an AAU officer. He was free to coach at Jam On It.

Internal records show that the board cited a lack of evidence and questioned Orndorff’s credibility because of an admitted history of drug use and what the board called “disturbing” discrepancies in her story. She had alternately claimed, for example, that Williams had “taken her virginity” at 15 but that they had first had sex when she was 16. In the hearing, Orndorff tried to explain that she had been referring to Williams digitally penetrating her when she was 15. 

Adams spent more than two decades on the Board of Review before leaving in 2024. She was never aware, she said, of any written rules used to decide whether a coach should be allowed to return to working with children. 

“I think we just decided on our feelings,” Adams said of the board’s process. 

She told ProPublica and The Post that the board had not considered sanctioning Williams for having a relationship with Orndorff because there was no regulation against having relationships with former players at the time. The AAU said in 2012 it had implemented that rule.

“It certainly would be [a violation] now,” Adams said. “And after, well — it was not a very pleasant — that was one of my unhappiest decisions.”

Orndorff said she still carries with her the trauma of Williams’ abuse. She left college during her freshman year as a result of the relationship with Williams, she said, eventually turning to drinking and drugs for much of her adult life. She is now 44 and says she has been sober since 2017.

But the AAU’s handling of the case when she was finally ready to step forward has made it much more difficult for her to heal. “I tried so hard to get the truth out, and I don’t know why I couldn’t do it,” Orndorff said, her voice choked with emotion.

Jim Fox, a youth basketball executive who records indicate joined the AAU Board of Directors after the case was resolved, said he believed the “old boys’ network” of the AAU had worked to suppress Orndorff’s allegations to avoid “embarrassment.” Fox tried to convince the board again to ban Williams in 2022, internal AAU records revealed in the court case show, citing new evidence in Orndorff’s civil suit, but it refused to even consider the case.

“Anybody could look at it and see that it was true,” Fox, a former probation officer, said of Orndorff’s allegations. “People tried to cover it up.”

Goudy, the president, died in 2020. Fox told ProPublica and The Post that Williams was stripped of his membership shortly after a new president, Jo Mirza, was elected in October 2022. Mirza, who court records show also advocated to terminate Williams’ membership in 2022, did not respond to multiple requests for comment.

A photo collage features a center inset of water jugs lined up on a blue court floor, flanked by a wispy, light-purple textured sky on the left, and a close-up of a referee’s feet in white sneakers standing on an elevated platform on the right.

“Short, Fast, Easy and Quick”

Something did change inside the AAU in 2021: It started making money.

Since 2015, the nonprofit had been spending more than the $20 million it took in annually, losing money each year.

But that year, the AAU’s revenue jumped to $24 million, and two years later, the number had grown to $34 million. In 2024, the most recent year the AAU’s nonprofit tax returns are public, the organization brought in nearly $44 million. It reported cash and investment reserves of around $30 million — triple what it held in 2019.

The organization’s momentum wasn’t in basketball. It was everywhere else. In boys’ volleyball, the AAU had become the dominant force, and in sports like martial arts, gymnastics and flag football, it was staking out a growing presence. The expansion meant that the AAU was increasingly competing with national sports governing bodies overseen by SafeSport. 

In swimming, some large clubs joined the AAU, where they could register less serious swimmers for $20 apiece instead of the more than $70 cost of USA Swimming. In 2023, USA Swimming’s registrations fell by almost 5%.

AAU meets are “short, fast, easy and quick,” said Chris Davis, whose juggernaut Georgia swimming club, SwimAtlanta, has moved hundreds of kids to the AAU. “I could theoretically have a senior in high school run the meet. I don’t have to have an official.” Davis said he opts to use officials, and all of his coaches take SafeSport training because they are also members of USA Swimming. 

The AAU’s cheaper fees weren’t the only selling point. On one swimming website’s list of reasons for clubs to switch to the “easier” AAU, the top of the list was a lack of “mandatory training hoops.” 


By 2023, five years after the SafeSport Act’s passage, the AAU was publicly acknowledging that the law required all organizations to offer some form of child sex abuse prevention training, even if it isn’t created by SafeSport. Its new youth protection handbook cited the law — and said that the AAU’s mandatory course, offered through the Positive Coaching Alliance, now included “child abuse prevention training.”

Jason Sacks, the CEO of the Positive Coaching Alliance, told ProPublica and The Post in a statement that the material “was not an official training by any stretch.” It constituted “a few slides with resources.” 

The links to those resources from AAU’s website are currently broken.

As an organization, Sacks said, PCA’s focus is not sexual abuse prevention but youth sports culture, with trainings that emphasize positivity and character development. He noted its courses can play a role in preventing emotional and physical abuse by discouraging coaches from mistreating athletes. But Sacks said they “are not currently built to satisfy the Safe Sport Act requirements.”

Though some 20,000 AAU coaches took the PCA course in its earliest days, Sacks’ statement said, those numbers have declined steadily in the decade since. In 2024, AAU reported more than 100,000 adult volunteers.

On Nov. 10, 2025, ProPublica and The Post reached out to the AAU with questions about whether the organization offered sexual abuse prevention training and if the PCA course was mandatory for all coaches. 

Eight days later, the AAU approached PCA, Sacks said in his statement. Officials had two requests: “They wanted to incorporate more abuse prevention material in the PCA online coach course training, and make it mandatory for all coaches.”

A photo collage features a center inset of a woman with dark hair partially obscured by leafy foliage, flanked on the left by a photo of a person holding a volleyball on a beach, where the face and torso have been torn away to display an anonymous black void, and on the right by volleyball players in action during a match beneath a red banner reading “one team.”
Aleesa Bravata

“SafeSport Does Not Apply”

SafeSport’s public disciplinary list quickly became a central part of the sports landscape. By 2025, there were more than 2,500 coaches on the list — some temporarily suspended during investigations and hundreds more banned permanently from any sport that fell under the U.S. Olympic and Paralympic Committee. 

Though they were not required to do so by law, many independent organizations, including Pop Warner and Little League, implemented rules to keep coaches on the list out of their programs, too. In 2012, the AAU had said it would bar anyone “banned by other youth-serving organizations.” But it never adopted the rule, according to a review of its written policies.  

Instead, ProPublica and The Post found, the organization has become known as a refuge for coaches who are suspended or banned by SafeSport and national governing bodies.

“The AAU has absolutely developed a reputation that they are the place to go if you are banned from our world,” said the president of one national governing body, who asked not to be named because he still works with the AAU.

The issue has been raised repeatedly to the U.S. Center for SafeSport, top governing body officials, attorneys and former SafeSport executives told The Post. 

ProPublica and The Post identified eight people who coached AAU-affiliated teams within the last five years despite being banned by SafeSport or national governing bodies. The AAU’s director of compliance, Aaron Oandasan, would not verify if any of them were registered with the AAU, but ProPublica and The Post confirmed they were coaching teams registered with the organization through interviews with parents, administrators or the coaches themselves, as well as online records and social media posts.

Among them were three elite gymnastics coaches who had been suspended by either USA Gymnastics or SafeSport over emotional and physical abuse allegations in the wake of the Nassar revelations but continued working with AAU athletes. Another was a fencing club owner who started advertising his gym as affiliated with AAU while SafeSport investigated allegations of sexual misconduct against him that it eventually substantiated. And a Georgia basketball coach who was suspended for three years by SafeSport over allegations that were not publicly disclosed even took his team of boys to AAU nationals. 

Last year, a regional governing body official said he reached out to the AAU to warn it about a local volleyball club owner who had told parents he planned to join the AAU to evade a SafeSport suspension for alleged sexual misconduct. 

The AAU’s response to the official was curt, the official told ProPublica and The Post: “SafeSport does not apply.”

Adams, the former review board member, said that the AAU does not check the SafeSport list unless it receives a report about a coach. The AAU then conducts its own investigation, she said, because it does not trust SafeSport. That is because SafeSport is prohibited from sharing confidential details of cases, she said, but also out of concern that the center punishes coaches for frivolous reasons.

“At times, SafeSport hasn’t liked the way somebody dressed or they drank in college,” she said, without providing examples. SafeSport’s vice president, Hilary Nemchik, called Adams’ characterization “not accurate” and “concerning.” 

“SafeSport’s cases are proven through evidence, and our process allows for appeals by the accused,” Nemchik said.

Adams said the AAU board does sometimes ban coaches who have been barred by SafeSport.

She recalled one case in which the board ruled that a coach banned by SafeSport should be allowed to continue working with the AAU. That coach was later seen acting inappropriately with an AAU athlete, Adams said, and the AAU banned him at that time. She declined to name the coach, and because the AAU does not make a public list of banned members, the claim is not verifiable.


One of the coaches who was still working with children under AAU following a SafeSport suspension was Elias Perez in Southern California. 

Aleesa Bravata told SafeSport last year that Perez, her former volleyball coach, had groomed and inappropriately touched her while she was in high school.

But a few weeks after his name appeared on SafeSport’s disciplinary list, temporarily suspending him, Bravata saw Perez’s truck in the parking lot of the local volleyball gym. Perez was still coaching. 

Bravata had met Perez when he began coaching the girls’ volleyball team at her high school in Huntington Beach, California. He was 33; she was 16, a junior. As her senior season began, she said, Perez began to isolate her from her teammates and text her with increasing frequency about things other than volleyball, including making comments about her appearance.

ProPublica and The Post reviewed interviews and records that were part of SafeSport’s investigation, including text messages between Bravata and Perez, and corroborated parts of her story with a former coach in whom Bravata confided while she was still in high school.

In September 2024, around the time Bravata turned 18, Bravata said Perez asked her for a ride home from training because his car was broken down. Parked outside Perez’s apartment, Bravata said her coach told her, “You know how I feel about you.” 

She asked him what he meant. Bravata said she remembers his reply word-for-word: “I’m going to put this in a way you understand. I have a crush on you, I like you, I want to hold your hand and take you on dates.” 

“I froze,” Bravata told ProPublica and The Post. “It scared me.” 

A diptych shows a heavily altered photo of a volleyball team where blue and brown paint obscures most players except a smiling girl in a green jersey with the number 6 on the left, and a full-length profile portrait of a woman in jeans standing outdoors on a dry hillside on the right.
An altered photo, left, shows Bravata when she played volleyball in high school. Now 19, she is a sophomore in college.

Perez went inside, Bravata said, but a few days later, he asked her to come to his apartment to drop off a set of keys to the high school gym. Parked outside his apartment, Bravata recalled that she sat in the passenger seat of her truck and, with the door open, Perez came to stand close to her, his body between her legs. 

Bravata told Perez that she didn’t want to have sex, she said, and Perez said he would never do anything that made her uncomfortable. Then, she said, Perez began to touch her, rubbing his fingers under her bra strap and touching the waistband of her pajama pants. 

Perez tried to kiss her, Bravata said, and Bravata turned her head. He then took her wrist, she said, and pressed her hand against his clothed penis, which was erect under his loose pants. When he let go, Bravata said, her hand dropped loosely into her lap. 

Bravata got out of the passenger seat to return to the driver’s side, she said, and Perez asked her, “Hey, if anyone asks, Eli accidentally touched your ass, right?” 

With the volleyball season over, Bravata and Perez stopped spending time together. Later in her senior year, her confused feelings turned to something else: “It took me till the end of the school year to realize that he had been grooming me, basically brainwashing me,” she said. 

Bravata confided in a former coach, SafeSport records show, who escalated the issue to school administration and the school resource officer. By then, Perez had left the high school. Bravata said Huntington Beach police told her that because it was possible the incidents had occurred when she was no longer a minor, the district attorney was unlikely to prosecute. (The police declined to release any records to ProPublica and The Post because the case is still open.)

In August 2025, when Bravata learned Perez was coaching a team of 14- to 15-year-old girls at Balboa Bay, a prestigious local volleyball club, she called SafeSport’s reporting hotline. 

Within weeks, SafeSport issued a temporary suspension against Perez while it finished its investigation — a measure it typically takes only in limited cases where allegations are serious and recent. 

Perez did not respond to requests for comment. But in an interview with a SafeSport investigator, a transcript of which was reviewed by ProPublica and The Post, he denied any inappropriate contact with Bravata, saying that they had rarely texted and had not been close.

Balboa Bay was a member of two organizations: USA Volleyball, which is legally bound by SafeSport, and the AAU, which is not. So while Balboa Bay eventually stopped Perez from coaching girls on its USA Volleyball teams, it allowed him to continue coaching teenage boys on its AAU-affiliated teams for several months.

The club director, Travis Turner, said he initially decided to keep Perez because AAU rules did not forbid it and the alleged misconduct had not taken place at Balboa Bay. After ProPublica and The Post reached out to him in November, Turner said, he decided to fire Perez. He said he had not initially understood the severity of SafeSport suspensions. 

This April, SafeSport issued a permanent ban against Perez for sexual misconduct and an intimate relationship “involving a power imbalance,” its online database shows. 

But Bravata said she fears that there is nothing to prevent Perez from finding another AAU club — and another chance to coach children.

The post A Youth Sports Giant Promised Reforms to Protect Kids From Sexual Abuse. Most Never Happened. appeared first on ProPublica.

Risolte vulnerabilità su GitLab CE/EE

13 Agosto 2026 ore 10:07
Rilasciati aggiornamenti di sicurezza che risolvono 13 vulnerabilità, di cui 6 con gravità “alta”, in GitLab Community Edition (CE) ed Enterprise Edition (EE). Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un utente malintenzionato remoto di elevare i propri privilegi, accedere a informazioni sensibili e/o eludere meccanismi di sicurezza sui sistemi interessati.

Guida alla vulnerabilità RCE upload immagini in WordPress

13 Agosto 2026 ore 10:03
Guida alla vulnerabilità RCE upload immagini in WordPress

Una vulnerabilità RCE upload immagini in WordPress può trasformare un'operazione comune, come caricare una foto, in una porta d'accesso per i malintenzionati. Se gestisci un sito WordPress, questo è un argomento che devi assolutamente conoscere.

Di recente è emersa una falla critica che permette a un utente con privilegi di "Autore" di eseguire codice da remoto. Questo attacco, noto come Remote Code Execution, avviene tramite il caricamento di un file immagine malevolo.

Non c'è motivo di allarmarsi. Infatti capire il problema è il primo passo per risolverlo. In questa guida ti spieghiamo cos'è successo, come funziona l'attacco e, soprattutto, come puoi mettere in sicurezza il tuo sito web in pochi semplici passaggi.

Cos'è una vulnerabilità RCE in WordPress e perché dovresti preoccuparti?

Prima di entrare nei dettagli tecnici, chiariamo un concetto fondamentale: RCE, o Remote Code Execution, significa "Esecuzione di Codice da Remoto". È come dare a uno sconosciuto le chiavi del tuo server. Un attacco RCE riuscito consente a un hacker di eseguire comandi sul tuo hosting come se fossi tu.

Le conseguenze possono essere devastanti:

  • Furto di dati sensibili, come informazioni degli utenti o dettagli di pagamento.
  • Installazione di malware o ransomware sul tuo server.
  • Cancellazione o modifica dei contenuti del sito.
  • Utilizzo del tuo server per lanciare attacchi verso altri sistemi.

In breve, significa perdere il controllo completo del tuo spazio web. Per questo motivo una falla di sicurezza di questo tipo va presa molto sul serio.

La falla specifica: come un'immagine diventa un'arma

Come può un semplice file PNG scatenare una vulnerabilità RCE in WordPress? Il problema non risiede nel core di WordPress, ma nell'interazione tra la piattaforma e due strumenti che gestiscono le immagini: ImageMagick (noto anche come Imagick) e Ghostscript.

Ecco la catena di eventi che un aggressore potrebbe sfruttare:

  1. Il file mascherato: l'attaccante crea un file che appare come un'immagine (ad esempio, vacanza.png), ma al suo interno nasconde codice malevolo, scritto in un linguaggio come PostScript.
  2. Il caricamento: un utente con il ruolo di "Autore" carica questo file nella Libreria Media di WordPress.
  3. L'errore di validazione: le versioni vulnerabili di WordPress si fidavano dell'estensione del file (.png) senza analizzare a fondo il suo contenuto reale.
  4. La delega pericolosa: WordPress passa il file a ImageMagick per elaborarlo, ad esempio per creare le miniature. ImageMagick riconosce che non è una vera immagine ma codice PostScript e delega il compito a Ghostscript, lo strumento designato per interpretare questo tipo di file.
  5. L'esecuzione del codice: Ghostscript, eseguendo il suo compito, interpreta il codice contenuto nel file. Questo permette all'hacker di eseguire comandi sul server.

Il punto debole era proprio quel passaggio in cui un plugin di WordPress si fidava ciecamente dell'estensione, permettendo al "cavallo di Troia" di superare le prime difese. Per questo è fondamentale proteggere il tuo sito, mettendo in sicurezza i plugin.

Chi è il bersaglio della vulnerabilità RCE di WordPress?

Questa vulnerabilità non colpisce tutti i siti allo stesso modo. Il principale fattore di rischio dipende da chi ha i permessi per caricare file multimediali. L'attacco, infatti, richiede almeno un account con ruolo di Autore.

Il tuo sito è ad alto rischio se:

  • Gestisci un blog con molti autori o collaboratori esterni.
  • Hai una piattaforma di membership o un e-commerce dove gli utenti possono caricare immagini.
  • Concedi l'accesso al backend a clienti o a un team allargato con ruoli superiori a "Sottoscrittore".

Al contrario, se il tuo sito è gestito solo da te e da pochi amministratori di fiducia, il rischio è basso. Tuttavia, la sicurezza non è mai troppa.

La soluzione: come mettere in sicurezza il tuo sito WordPress

La buona notizia è che la soluzione è semplice, rapida e già disponibile. Il team di sicurezza di WordPress ha rilasciato una patch che corregge completamente questa falla. L'unica azione necessaria è aggiornare la tua installazione di WordPress alla versione più recente.

La correzione è stata implementata a partire dalla versione 7.0.4 del plugin Gutenberg e integrata nel core di WordPress. L'aggiornamento modifica il modo in cui WordPress gestisce i file. Ora, prima di passare qualsiasi file a ImageMagick, la piattaforma ne analizza il contenuto reale (la sua "firma digitale"). In questo modo si assicura che un file .png sia davvero un'immagine e non un file PostScript mascherato. Questo blocco preventivo neutralizza completamente la minaccia.

Vulnerabilità RCE in WordPress: la prevenzione è la migliore difesa

Oltre all'aggiornamento, puoi adottare alcune buone pratiche per rafforzare la sicurezza del tuo sito e prevenire problemi futuri:

  • Limita i permessi: assegna sempre il ruolo con i privilegi minimi necessari a ogni utente. Non tutti hanno bisogno di essere "Autori" o "Editor".
  • Usa un plugin di sicurezza: strumenti come Wordfence o Sucuri possono monitorare i file caricati e bloccare i tentativi di attacco.
  • Effettua backup regolari: avere un backup recente e funzionante è la tua migliore assicurazione contro qualsiasi disastro.

Non sottovalutare la sicurezza del tuo sito

La vulnerabilità RCE in WordPress ci ricorda una lezione fondamentale: anche le operazioni più comuni, come il caricamento di un'immagine, possono nascondere dei rischi.

La sicurezza informatica è un processo continuo di vigilanza e aggiornamento. Non rimandare: controlla subito la versione del tuo WordPress e, se non è l'ultima disponibile, procedi con l'aggiornamento. È un piccolo gesto che garantisce la protezione del tuo lavoro, dei tuoi dati e della fiducia dei tuoi utenti.

L'articolo Guida alla vulnerabilità RCE upload immagini in WordPress proviene da sicurezza.net.

Passwords stored in public Google Doc then showed up in search results

13 Agosto 2026 ore 09:00
PWNED Welcome, once again, to PWNED, the weekly column where we highlight others’ security failures. Hopefully, there’s a lesson in all this, but it could just be “stop shooting yourself in the foot.” Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request. Our story today comes courtesy of Siim Kostabi, co-founder of Pageloot, a company that provides QR codes businesses can use for marketing. Kostabi’s tale of tech terror reminds us that credentials, even for a staging server, have a lot of value in the wrong hands. He explains that his company brought in a contractor to help with some API integrations on the back end. That developer had the credentials for the staging environment and wanted to be able to view them across different devices they were using for the job. So what was the developer’s solution to the very common problem of keeping track of usernames and passwords? They could have chosen a password manager. They could have written the passwords down in a paper notebook and kept it hidden from prying eyes. They could have gotten a password tattoo. They could even have emailed the passwords to themselves and it would have been smarter than what they did. Instead, the outside developer decided to store their password in a Google Doc. And they set that Google Doc to be viewable by anyone on the internet who had the link. And then, one day, an employee at the company found the Google Doc with the staging credentials in it because Google Search had indexed it and offered it as a search suggestion. “A developer on our team was debugging something unrelated and typed our domain into Google Search,” Kostabi recalls. “The autocomplete surfaced one of our staging hostnames followed by what looked like a credential string. We checked, and there was a publicly accessible Docs URL.” Yikes! Just imagine that not only are your company’s credentials available to anyone online, but they are indexed in Google Search for the world to find! Once they discovered the problem, Kostabi’s company immediately cut access for that contractor and rotated all of its exposed credentials. They also set a new rule: no storing passwords on Google Docs, Slack, Notion, or other collaboration tools. In a separate incident, Kostabi heard from a Pageloot customer, a mid-size retailer, whose QR codes were suddenly directing users to a competitor’s site. After investigating, he found that a disgruntled ex-employee’s credentials had not been revoked and that the former employee had used that access to redirect all of the retailer’s URLs, costing it customers. The takeaway from both of these problems is that you need to carefully control access. Former employees should immediately lose access to everything and current contractors should be reasonably intelligent people you can trust. “Both situations were completely avoidable with basic hygiene,” Kostabi said. “Proper offboarding, access reviews, and not treating shared docs like private vaults.” ®

Cisco thinks Mythos means instant death for unsupported networking kit

13 Agosto 2026 ore 08:28
Cisco CEO Chuck Robbins says “The Mythos Effect” will see customers scour their networks for unsupported devices and replace them ASAP. Mythos is Anthropic’s bug-finding model and has proven so effective that vendors and open source projects are now finding more security flaws and pushing more patches. Speaking on Cisco’s Q4 earnings call yesterday, Robbins said customers he speaks to are aware of Mythos, and fearful that the model and others like it will mean that unsupported devices become too risky to operate once patches stop flowing. “I had one of my CEO friends who runs a major manufacturer in the US … their team called early on in the Mythos wave and just said: ‘Hey, listen, we got to get some of this stuff that is past LDOS’ [last day of support].” Robbins said other Cisco customers have done likewise. “We’ve seen the pipeline increase meaningfully as a result of Mythos, which is really showing up as a network refresh,” he said. The CEO thinks some customers might be paying for new Cisco kit with their security budgets rather than cash allocated to networking expenses. He’ll take it either way. CFO Mark Patterson said buyers who need rapid replacements for their kit won’t have to wait. “We really do not have any significant lead time issues that we are seeing,” he said, before indulging in a little competitive sniping by adding “unlike we have heard a number of different peers talk about.” Robbins said The Mythos Effect is one of three factors contributing to a “supercycle” of network spending. One is the need to prepare for quantum computing, either with quantum-safe networks or quantum-resistant decryption. The other is, of course, AI. Robbins thinks agentic AI will take off, and see Cisco sell bucketloads of fresh kit to hyperscalers, and replacement kit to businesses that want to implement AI and realize their existing networks aren’t up to the job. Cisco reported $17.3 billion revenue for the quarter, and $63.3 billion for the year, increases of 17 percent and 12 percent respectively. Net income rose 51 percent to $3.9 billion for Q4, while the full-year result of $13.27 billion was a 30 percent jump. “We delivered the highest revenue, operating margin, and earnings per employee in thirty years,” Robbins crowed. “In FY27, we expect all these metrics to continue to improve.” Investors appear to have been a little confused by what they heard, as Cisco’s share price spiked after its earnings announcement, before settling four percent lower than its closing price. Robo-support revealed Robbins also touched on Cisco’s own use of AI, which he said saw 145,000 support cases “resolved entirely by AI with zero human intervention” during FY26. If you’re a Cisco customer, let us know how that works for you. The CEO also revealed that Cisco operates an in-house AI Assistant called “Circuit” that he said “is fully embedded in how Cisco operates” and handled over 75 million prompts in Q4 alone. “Circuit runs on our Secure AI Factory infrastructure which improves GPU utilization and automatically routes each task to the appropriate large language model, allowing us to manage token consumption,” he said. ®

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

13 Agosto 2026 ore 08:09
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates. "The authentication

Tencent says it could make instant profits on $53B hardware splurge by renting it for AI workloads

13 Agosto 2026 ore 06:45
Chinese tech giant Tencent has turned its back on instant profits, betting that a new business unit that creates its own AI and embeds that in its products will pay off to a greater extent than cashing in on demand for computing resources. During the company’s Q2 earnings call yesterday, Bernstein analyst Robin Zhu asked when Tencent expects to see a return on investment from the $53 billion capital expenditure it made in the quarter. Chief Strategy Officer James Mitchell said demand for compute resources is so strong that Tencent could recover its depreciation costs “almost immediately” if it rented its infrastructure. Company president Martin Lau said if Tencent behaved like a neocloud it would “achieve a decent return in an immediate timeframe” as the company has offers for its compute capacity “at more than 30 percent profit compared to the price that we paid just a few months ago.” Lau said Tencent is instead “playing a different game or executing a larger strategy in that we are allocating a very substantial proportion of the new compute to building our own models to state-of-the-art status, and also to deploying, popularizing, and bringing our own AI applications to market leadership in China.” He said Tencent believes that if Tencent can provide “superior intelligence that we can achieve through state-of-the-art models, through market-leading AI applications … we can then convert into superior economic returns over the longer term.” Those returns will come from selling tokens for services like WorkBuddy, which Tencent says is an agent swarm that can “plan, execute, and run tasks in parallel, handing back complete deliverables end-to-end in one flow.” Tencent also offers CodeBuddy, a code generation tool that Mitchell said is accelerating cloud migration projects and therefore creating more business for Tencent cloud. Tencent released its latest model, the 295-billion open-weight Hunyuan-3 in July. Lau described it as “a very small model” and promised that the forthcoming Hunyuan-4 will be bigger – and more capable than larger models from other companies. He also said Tencent is designing its products specifically to work with Hunyuan-4, and that mutual optimization will make those products more powerful than would be the case if they relied on other models. The company also plans a fifth version of Hunyuan, and Lau said at some point Tencent will deliver a state-of-the-art model. Tencent is already producing thoroughly modern results for a tech giant: Revenue for Q2 grew 11 percent to reach $30.3 billion. Net profit rose nine percent to $10.3 billion. The company’s flagship messaging apps, Weixin and WeChat, saw average monthly active users rise seven million to 1.349 billion. Advertising-related revenue rose 22 percent, and the company’s gaming biz grew 17 percent in China alone. Investors aren’t sure what to make of this. The company’s share price has trended down since Wednesday and dipped around three percent since the company’s earnings announcement. ®

Chinese Loongson processors have leaky caches, researchers find

13 Agosto 2026 ore 04:14
Researchers from Germany’s Helmholtz Center for Information Security have found processors made by China’s Loongson have leaky caches that attackers could use to seek specific data. Loongson has developed its own LoongArch instruction set architecture (ISA) that blends approaches used by MIPS and RISC-V. On a site called LoongLeakAttack.com, the researchers explain that they found the leaky cache using a fuzzer, then noticed that the LoongArch ISA manual mentions an instruction that leaves 32 bits of a memory register in an “uncertain” state. “Our analysis reveals that under certain circumstances, the ‘uncertain’ data originates from the L1 data cache,” the four researchers wrote. “Since this cache is not isolated between applications, LoongLeak can leak data from other applications and the operating system. Even worse, an attacker can prime the CPU’s internal state to target the leakage to a specific cache set.” In a paper [PDF] explaining their research, authors Lorenz Hetterich, Tristan Hornetz, Fabian Thomas, and Michael Schwarz share case studies that “include recovering full-disk AES keys from the kernel, partial root password hashes from user-space, and bypassing traditional software defenses such as ASLR and stack canaries, all within seconds.” In case that’s not scaring you enough, they also point out “LoongLeak can be exploited from unprivileged user space, containers, or virtual machines.” The flaw even means “LoongLeak can cross the virtual machine boundary and leak host data from inside a VM.” “As the leakage is architectural, it requires neither high-resolution timers nor traditional sidechannel amplification, and it grants the attacker precise control over cache set and line offset,” they add. And the cherry on top is that software mitigations aren’t possible. Users with chips that possess the flaw either need to replace them or make sure they don’t allow any private data to enter or remain in the L1 cache. Making that happen can require turning off one thread per core, effectively disabling hyperthreading. The news isn’t all bad, because Loongson fixed the flaw in an update to its model 3A6000 processor, and the mitigation of evicting cache data slows performance by just 1.4 percent in the worst case. The blast radius of this flaw is also likely to be limited, because Loongson chips are hardly used outside China. The company offers chips for PCs, servers, and appliances such as printers. China’s government promotes use of Loongson chips as part of its plan to reduce dependence on imported tech. Lenovo makes laptops that use Loongson chips but only sells them in China. The Register has discussed the company’s chips with other major PC-makers, who told us they would adopt Loongson product if users want them, or if doing so becomes necessary to participate in the Chinese hardware market. But we’ve not seen a non-Chinese company adopt the processors. China’s government, however, may be nervous about this research as it has instructed public sector buyers to buy local products. Perhaps some government agencies are running vulnerable devices? If that’s the case, Beijing has its work cut out spotting any attacks, because the researchers could find “no specific tools or methods to detect if LoongLeak is being exploited.” ®

OpenAI ad service can bill customers for up to one day after they pause campaigns

13 Agosto 2026 ore 02:28
OpenAI appears to be serving ads after buyers have halted their campaigns, and charging them for the privilege. OpenAI began testing ad sales in ChatGPT in the US back in February and has been gradually expanding the service in other regions, including the United Kingdom, Mexico, Brazil, Japan, and South Korea as of Tuesday. Given that a substantial minority of ChatGPT's user base pays for the service (50 million out of 900 million weekly users as of February 2026), advertising revenue appears to be an important part of OpenAI's plan to defray the cost of providing its service and to convince investors that it has a path to profitability ahead of a future initial public offering. Online ad-marts from the likes of Google and Facebook give advertisers control over when and where their ads will appear, but don't always stick to instructions. The AI biz's ad service appears to have similar ad timing and billing accuracy issues. Ed Bolton, managing director of UK-based Excel4Business, told The Register that his company encountered "an odd billing practice" when it started experimenting with ChatGPT Ads in the US and Canada. "We were running campaigns in the US and Canada … and noticed ads were being delivered through the night/morning on paused campaigns," he explained. When Bolton pointed this out in a support message thread, an OpenAI customer service representative initially acknowledged the failure. "We have now confirmed that your campaigns continued serving after they were paused," said an OpenAI support specialist in an email provided to The Register. "This was not a reporting delay. The campaign was marked as paused, but the separate ad-level status used by the serving system did not refresh promptly, so an ad that was still active at the ad level continued to run. Our Ads Engineering team has escalated this defect and is working on an additional production fix." The support reply goes on to state: "Our review has confirmed £60.72 in invalid charges from the original occurrence and approximately £6.47 from the August 4–5 recurrence. We are extending that reconciliation to the additional activity you reported on August 6. We are preparing the confirmed invalid charges for billing review, but I cannot confirm the final refund or credit amount until the latest activity has been reconciled and that review is complete." Bolton responded that the acknowledged problem – ads being served after he disabled the campaign – had been occurring for a longer period of time and requested a more complete reconciliation of ad billing. Several days later, OpenAI's support rep reversed the prior determination and declined to offer any refund or credit because the company's Advertising Terms state that ChatGPT Ads may be delivered even after a customer cancels a campaign and the advertiser still has to pay for those unwanted ads. "Section 11.1 of our Advertising Terms provides that ads may continue running for up to one business day after a campaign is canceled or changed, and advertisers remain responsible for ads delivered during that period," the support message explains. "Pausing a campaign constitutes a campaign change and does not guarantee that delivery or associated charges stop immediately." A spokesperson for OpenAI confirmed that's the case, explaining that it can take a business day to cancel or change a campaign and that this doesn't represent an intentional effort to run ads after an advertiser has disabled a campaign. Based on the times cited in the support message thread, the most delayed ChatGPT ad ran about 94 minutes after Excel4Business paused a campaign. Bolton said unwanted ads appeared for a far longer period — more than 10 hours after campaigns were paused. OpenAI isn't the only ad provider that allows itself a business day to turn off its ad spigot for a particular customer. Other advertising services impose similar terms. "So the terms … seem to be a standard which is used in digital advertising, which some legal team wrote at some point, saying that we've got a 24-hour grace period if you stop a campaign," Bolton said - before adding that he has run Google AdWords campaigns for 17 or 18 years and has never had that issue. If ad buyers were not able to stop an AdWords campaign quickly, you could easily spend half a million dollars, he said. Nonetheless, some Google advertising customers have complained about post-pause ad serving. Why it might take so long to stop serving ads at a time when applications and servers can be spun up and torn down in seconds isn't immediately clear. One can order and receive physical goods from Amazon.com in less than one business day. It may be that there's no financial incentive or regulatory pressure to tackle the problem, and a significant financial incentive to ignore it. "My understanding is that such a clause is included in terms and conditions so as to cover issues with latency, and not to allow them to run ads for 24 hours longer than instructed," said Bolton. "Regardless, they cannot retroactively apply a clause from terms and conditions after making a written settlement offer." ®

Intel’s Linux Vulkan Driver Adds AV1 Video Encoding for Arc Alchemist GPUs

Intel’s Linux Vulkan Driver Adds AV1 Video Encoding for Arc Alchemist GPUs

Intel’s open-source Linux graphics stack has taken another step forward with hardware-accelerated AV1 encoding through Vulkan Video. New code merged for Mesa’s ANV Vulkan driver enables the VK_KHR_video_encode_av1 extension on Intel’s DG2/Alchemist graphics hardware, including Arc A-Series GPUs.

The development expands Intel’s Vulkan Video capabilities on Linux and gives applications another standardized way to access the dedicated video encoding hardware found in modern Intel GPUs.

AV1 Encoding Arrives in Intel ANV

The key change is support for the Vulkan extension VK_KHR_video_encode_av1 in Mesa’s open-source Intel ANV driver.

The extension was finalized by the Khronos Group in 2024 and provides a standardized Vulkan interface for hardware-accelerated AV1 encoding. It complements Vulkan Video’s existing AV1 decoding support and means Vulkan can provide both encoding and decoding interfaces for AV1, H.264, and H.265.

Intel had previously stated that its Arc graphics products would support Vulkan Video AV1 encoding through a future software update.

Initially Targeting Intel Arc Alchemist

The newly enabled Linux support specifically targets DG2, better known commercially as Intel’s Arc Alchemist GPU generation.

These GPUs already contain dedicated hardware capable of AV1 encoding, so the Mesa update does not add AV1 capability through software. Instead, it provides Vulkan applications with another way to access the GPU’s existing hardware video engine.

That distinction is important because hardware encoding can deliver much better performance and efficiency than encoding AV1 entirely on the CPU.

Why AV1 Matters

AV1 has become increasingly important for streaming, screen recording, video conferencing, and online video distribution.

The codec can provide high image quality at relatively low bitrates, making it attractive for applications where bandwidth and storage efficiency matter. It is also royalty-free, which has helped encourage adoption throughout the open-source ecosystem.

Hardware AV1 encoding can be particularly useful for:

  • Game streaming

  • Desktop recording

  • Live broadcasting

  • Video conferencing

  • Video transcoding

  • Content creation

For Linux users with supported Intel Arc hardware, Vulkan Video now has the potential to provide a common API for these workloads.

Building on H.264 and H.265 Support

The AV1 work follows recent improvements to Intel’s Vulkan Video encoding support for other codecs.

Rent-a-GPU outfit Nebius promises rapid 1 GW powerup plan isn't nebulous

13 Agosto 2026 ore 00:56
Rent-a-GPU cloud Nebius plans to bring online over a gigawatt of datacenter capacity every year starting in 2027, but doing so will require playing the margins and juggling a mountain of debt. “Our future capacity pipeline effectively makes Nebius one of just a few companies in the world able to build more than a gigawatt of new capacity a year and we plan to do so in 2027,” CEO Arkady Volozh boasted on Wednesday’s earnings call. The endeavor won’t be cheap. In 2026, Nebius says it expects to burn between $20 billion and $25 billion on capital expenditures to bring between 800 and 1,000 MW worth of bit barn capacity online. A big chunk of that will be covered with customer prepayments — essentially deposits for future capacity. According to Nebius CFO Dado Alonso, the firm is on track to exceed $9 billion in customer prepayments this year. But this alone won’t be enough. So like most big rent-a-GPU rackets, including CoreWeave and Lambda, Nebius is taking on debt to finance its expansion. Specifically, the company is using its GPUs and contracted cash flows as collateral to secure favorable interest rates on the coveted accelerators. Nebius landed its first asset-backed debt facility valued at $775 million in July, and Alonso says the company will continue leaning on the financing scheme going forward. No surprise. Along with debt financing, the company is also exploring an asset-light model where “partners finance, build, and operate the facilities, whereas Nebius brings the full-stack platform and demand,” Volozh told analysts. In other words, Nebius gets to claim deployed capacity it didn’t have to front the cash for, but that relies on the company's ability to rent capacity for less than it can resell it for. While hitting a gigawatt of capacity a year won’t be cheap, Volozh is confident the investment will pay off in the long run. He claims that for every megawatt deployed, Nebius will bring in between $20 million and $25 million in revenues for medium-term leases, and $40 million to $50 million for short term leases up to six months. On the low end of the scale, that implies $20 billion a gigawatt, although Nebius Chief Product and Infrastructure Officer Andrey Korolenko notes that while the company expects to have up to a gigawatt of connected power by year’s end, not all of it will be active and generating revenue until 2027. “You have to commission the datacenter, build the network, build the clusters, deploy the platform, then onboard the customers, and then the revenue generation starts,” he said. “That takes a few months.” “In terms of our guidance from 800 megawatts to a gigawatt… I would think about that being active throughout the first half of 2027,” he added. But even if Nebius has to wait until 2027 to pull a full gigawatt of capacity, that still implies a massive uplift in revenue, which is forecast to hit $3 billion to $3.4 billion for fiscal year 2026. The past quarter accounted for just $582 million, which suggests Nebius will bring in more than $2 billion over the next two quarters if you believe its projections. There are a lot of faithful among the investor community, as its share price surged more than 30 percent on Wednesday following the report. While revenues are expected to increase dramatically over the next few quarters, it's easy to sell dollar bills for 70 cents apiece. Whether the company actually manages to turn a profit renting the shovels of the AI gold rush is another matter entirely. In Q2, the company posted an operating loss of $176 million, a jump from the $111 million operating loss it booked in the year-ago quarter. ®

'Near-autonomous' AI agents attack Taiwan's nuclear safety agency

12 Agosto 2026 ore 23:45
Suspected Chinese cyber operatives used publicly available AI tools to compromise Taiwanese government systems before expanding the attack to its nuclear safety agency, supply-chain vendors, and at least seven energy companies in what security researchers called a "near-autonomous attack." Over the first four days of July, AI agents compromised 85 government user accounts and extracted more than 2,500 personnel records, according to Dream, an Israeli cybersecurity firm. Researchers uncovered evidence of the attack in a 160 MB online archive containing 1,395 files documenting the operation. Dream, in research published on Wednesday, detailed the intrusions and said that the suspected Chinese hackers hit “government entities in Asia” - but declined to say which government had been attacked. A person familiar with the attack confirmed to The Register that Taiwan was the target. The Financial Times first reported on Dream’s research and identified Taiwan. While the security firm doesn’t attribute the agentic attack to the Chinese government or a specific hacking group, the operational documentation “points to a Chinese-language operator,” the researchers said. According to Dream, the attack framework, built on open source Hermes and OpenClaw AI agents, deployed up to eight sub-agents, each assigned to its own targets and attack techniques, across 12 “attack waves” between July 1 and July 4. First, the agents mapped the entire government ecosystem, extracting embedded URLs, API endpoints, OAuth client IDs, and Keycloak configuration objects from a single government portal. This portal allowed the agents to identify 21 connected government systems and every supported authentication flow. “On one target alone, it discovered 36+ API endpoints spanning account management, user data retrieval, file upload, and administrative functions - many completely unauthenticated,” the Dream threat researchers wrote. “Critically, it found that one of the systems exposed its entire user database without any authentication - thousands of employee records including names, departments, and SSO account IDs.” Multiple entry points After mapping the government’s attack surface, the agents found multiple entry points including three hidden API endpoints that accepted any request body and returned a valid authenticated session without requiring user credentials. Using employee usernames harvested from an unauthenticated API, the agents broke into a government department’s office automation portal, solving its CAPTCHAs with 100 percent accuracy. The agents also tested predictable password patterns based on each employee’s ID, and cracked 85 accounts across multiple password-spray rounds. Eighty-four of the 85 cracked accounts successfully authenticated to the department's internal information system, giving the attackers access to internal dashboards, equipment management interfaces, and personnel statistics pages. In total, the illicit access allowed the agents to exfiltrate a ton of government information, including more than 2,564 personnel records, a full JSON export of all department system users, seven SSO client secrets, six internal database credentials across MSSQL, Oracle, and Sybase, and internal network IP ranges. But wait, there's more And then, the agents pivoted to the Taiwanese government’s supply chain. “It expanded the operation to government IT supply chain vendors, a nuclear safety agency, a government email system, and 7+ energy sector companies - scanning them all in parallel for misconfigurations, exposed admin interfaces, and exploitable vulnerabilities,” the researchers wrote. Notably, the attack framework implemented what the AI tools called “learning cycles.” These are autonomous sessions where the models search vulnerability databases, GitHub repositories, and other security research for specific techniques, CVEs, and common weaknesses to exploit in the targeted government's infrastructure. Additionally, when the AI framework made a mistake, it “self-corrected,” according to Dream, catching errors and fixing them through its own verification process. This near-autonomous attack comes as frontier model makers OpenAI, Anthropic, and Meta all admitted that their agents went rogue, escaped from their training environments, and autonomously hacked other organizations and people. OpenAI technical staffer Michael Dalton, in a Black Hat briefing last week about the Hugging Face attack, said “AI orchestrated, fully automated offensive attacks are real now.” “In the near future, we should expect that threat actors will intentionally deploy, optimize, weaponize, and use offensive agent collectives in the manner that you have just described here,” he added. It appears that the future is now. ®

Deeply buried 16-year-old SQLite bug caused last year's Tailscale outages

12 Agosto 2026 ore 23:29
Users of peer-to-peer networking outfit Tailscale might have struggled through some surprising outages beginning late last year. After a six-month investigation, the team finally knows why: A bug in SQLite’s write-ahead log that had remained hidden for 16 years. The Tailscale team announced in a Wednesday blog post that it had finally addressed the issue with the help of SQLite maintainers, who even had to create a new tool (with Tailscale funding) to log virtual file system activity in order to track the thing down, which Tailscale software engineer Alex Chan described as resisting “all our initial attempts to find it.” According to Chan, the problem goes deep into the nature of SQLite – so deep that the database maintainers actually had to add code to reproduce it. To understand what happened, it’s necessary to know how Tailscale works. The service, based on the WireGuard VPN protocol, directly connects devices in a virtual private mesh network. It’s designed to be low complexity and easy to implement for everything from remotely accessing a NAS to connecting teams in a unified private network. Each mesh network, or "tailnet," lives on one of several servers, where a SQLite database manages all the information about the tailnets it houses. “We’ve used SQLite as our primary database since 2022, and we chose it because it's well-known, reliable, and widely used,” Chan wrote in the company’s post-mortem. But a year ago, something went very wrong. “In our current backup pipeline, we take a complete snapshot of the database every few minutes, then upload the entire SQLite file to an S3 bucket,” Chan said, but in August 2025 those backups began detecting database corruption, repeatedly, with no obvious common trigger. The Tailscale team couldn’t reproduce the issue because there were no reliable triggers for it. No low-level code had been changed in months. A review of everything that touched SQLite turned up nothing. Working with the SQLite team, the Tailscalers tried to figure out what could be causing it – POSIX locks broken by close() calls? Nope. Mismanaged memory? Not that either. SQLite being used from multiple threads with thread safety disabled? Nuh-uh. “After every incident, we gathered more data, added more diagnostics, and systematically ruled out these theories,” Chan explained. The WAL-Reset bug comes out of hiding Suspicion was closing in on SQLite’s checkpointing process, which is how it takes new database entries out of a temporary hopper for addition to the master database file. SQLite has an option to improve performance and concurrency known as the Write-Ahead Log (WAL), which serves as the aforementioned hopper. Writing the WAL to the database occurs in a process known as checkpointing. “In most deployments, SQLite itself decides when to do a checkpoint, and the process is invisible to the end user and developer,” Chan said. “In our control plane, we take manual control of the checkpoint process so we can run fast and consistent backups.” The SQLite team wrote a new tool to take a closer look at the process: a virtual file system shim that extensively logs checkpointing activity. After waiting for the next corruption incident, the teams had their answer, dubbed the WAL-Reset bug. Described by Chan as “a rare data race in the SQLite source code between a checkpoint and write transaction,” it’s essentially a collision between checkpoints and writing data to the WAL. “If a write occurs at a specific time during a checkpoint, the checkpointing process gets confused — it thinks some of the pages have been copied from the WAL into the main database file, but they haven’t,” Chan said. Those pages are never written and are permanently lost, but pages that reference those pages are still written, corrupting the database and causing all hell to break loose. According to the SQLite team’s WAL-Reset writeup, the issue can be triggered only when WAL mode is active and multiple database connections are open on the same file, and because there has to be reading and writing going on at the same memory spot at the same time, it’s incredibly unlikely to happen in most situations. Tailscale’s decision to perform manual checkpoints was a rare exception. SQLite maintainers believe the bug was present going all the way back to version 3.7.0, released in July 2010; it’s now fixed, and the SQLite team recommends users update to a fixed version, though it stresses the bug is extremely unlikely to occur in ordinary use. “This bug, though rare, does have serious consequences,” the SQLite WAL-Reset notice states. The incident contains a useful reminder for devs: Even the most boring, reliable software poses risks when operated in a non-standard fashion. “Most people use SQLite in a standard configuration and never face this sort of issue,” Chan said. “By taking manual control of the checkpointing process and running at our own aggressive pace, we stepped off the well-trodden operational path.” ®

Node.js creator liberates Durable Objects from Cloudflare

12 Agosto 2026 ore 22:15
We've got good news for developers who are enamored with Cloudflare Workers and Durable Objects but don’t want to be tied into that company’s backend infrastructure. Last week, Node.js creator Ryan Dahl unveiled his latest project, celld, which he described on X as “a self-hosted, distributed Durable Objects and Workers implementation.” Dahl’s celld model is compatible with Cloudflare’s Workers and Durable Objects’ JavaScript APIs, but he claims that it is much less expensive to run. The project is no mere budget-minded open source rip. On celld’s web page, Dahl and his team characterize their replication of the Durable Objects architecture as a “love letter.” Cloudflare’s Durable Objects is a single-threaded object with a unique global ID and its own storage, where user data is stored in its own copy of SQLite. It runs on the Cloudflare serverless Workers runtime, which runs apps embedded in isolates—a type of lightweight virtual machine supported by Google's V8 JavaScript engine. First devised by Kenton Varda and Cloudflare, Durable Objects is “one of the best primitives distributed systems has been handed in years,” celld’s creators write. Unlike traditional serverless platforms like AWS Lambda, the Durable Objects model co-locates the data with compute, while using single-threaded execution to eliminate complex concurrency issues. “A primitive this good deserves to run anywhere,” the celld page states. Serverless but stateful Since its introduction in 2020, Durable Objects has been used to build low-latency, highly distributed Web applications. It is a stateful serverless execution environment, a data cache that can also do computation. Using the WebSocket API, the Durable Object can connect many simultaneous users at once in a live environment. WebSockets’ Hibernate mode can put the object to sleep, so cloud bills don’t accrue when no one uses the app. As a result, the stateful serverless model is best suited for real-time collaborative applications, such as multi-player games, team productivity apps and AI agents. Cloudflare uses Durable Objects for its serverless SQL service and AI Gateway. One YouTube tutorialist explained that using Durable Objects allowed him to eliminate an entire stack of tools (Amazon API Gateway, Apache Kafka, Redis, AWS Lambda and EventBridge, Apache Airflow and Spark all get name-dropped) because Durable Objects can handle all these functionalities “at a smaller scale.” Giving Durable Objects an open source home Dahl is one of the world’s foremost experts at JavaScript I/O, having created Node.js, a JavaScript runtime that runs the world’s fastest Web applications (and inadvertently introduced the JavaScript world to “callback hell,” where the language's asynchronous operations forced coders to pass functions as nested callbacks, resulting in ungainly and unintuitive messes of code). Dahl later went on to refine his ideas of asynchronous JavaScript with a second-generation JavaScript runtime called Deno. Celld does away with the Cloudflare backend, and instead uses the Amazon Simple Storage Service (S3) or equivalent as the storage engine. It also uses the Tokio Rust asynchronous runtime. As with Durable Objects, each celld object gets its own copy of SQLite. Dahl promises this open source backend will be “orders of magnitude cheaper at scale” than Durable Objects. Dahl estimated that 100 resident Durable Object cells cost $415 a month on Cloudflare, whereas the celld implementation would run only about $49 a month, built on a DigitalOcean S3-compatible bucket on an 8 GB droplet. Further savings should ensue as the workload scales, he argued. Cloudflare disputed Dahl’s numbers, stipulating that $415 a month would be the cost if all the objects were continuously active. If left to slumber, the Durable Objects would cost only $20.65 to house on Cloudflare, a spokesperson told The Register. Whatever its putative thriftiness, the model itself seems to have gained interest on its own merits. “So happy to see support for running durable objects outside of one provider. Upvoted,” one Hacker News reader enthused, noting the concept of a durable object is a valuable abstraction. Indeed, other parties are cooking their own schemes to move the data closer to the computation. For instance, Postgres service provider Neon just introduced its own Neon Functions, which can also co-locate data and compute for long-running workloads. Written in Rust and JavaScript, celld is available under an Apache 2 license. It can ingest JavaScript and TypeScript code. In theory, Rust, C/C++, Go, or Zig code can also be executed through the magic of WebAssembly, which V8 supports with slight modification. But while celld is open source, AI contributions are verboten. “Coding agents make it too easy to send a large, low-context change that costs maintainers more time than it saves,” the GitHub page notes. Human contributions are still welcome, though you should understand what your code does before you submit it. ®

Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible

12 Agosto 2026 ore 21:42
If you thought that the famous Spectre security vulns were a relic of 2018, think again. Certain RISC-V chips are still very much subject to this hair-raising hole, researchers say. Spectre refers to a family of vulnerabilities related to speculative execution, a performance optimization technique based on predicting the flow of data before instructions have been executed. Incorrect predictions get rolled back without affecting running applications but nonetheless leave traces that can be recovered and exploited to violate memory protections and access secrets. Spectre flaws have dogged x86 and ARM chips for years, leading computer scientists to develop a series of defenses, including Indirect Branch Restricted Speculation (IBRS), Indirect Branch Prediction Barrier (IBPB), and Single Thread Indirect Branch Predictor (STIBP). Researchers affiliated with academic institutions in Belgium and Germany say that it's been popular to assume that the RISC-V chip architecture isn't affected by Spectre vulnerabilities because it's too simple. That assumption is incorrect, according to a paper accepted at the 35th Usenix Security Symposium, "Spectre on RISC-V Silicon: Attacks and Defenses on Commercial Out-of-Order Processors." It says that commercially available out-of-order RISC-V processors (SiFive P550 and T-Head Xuantie C910/C920) are vulnerable to all major Spectre variants. RISC-V processors that process instructions in-order (SiFive U74, Xuantie C906, C908) do not appear to be vulnerable. Prior research has shown that RISC-V processors used for academic research (e.g. BOOM, RiscyOO, RSD, Proteus, NaxRiscv, and NutShell) can be affected by one or more of the Spectre variants, but hasn't addressed commercial silicon. "We demonstrate proof-of-concept attacks on both processors using Spectre-PHT, Spectre-BTB, SpectreRSB, and Spectre-STL, achieving up to 100 percent recall with more than 97 percent precision," the paper states. Spectre-PHT involves mistraining the Pattern History Table; Spectre-BTB poisons the Branch Target Buffer; Spectre-RSB attacks the Return Stack Buffer; and Spectre-STL (Store To Load) exploits mispredicted store-to-load forwarding. To demonstrate the risk to RISC-V, they created a proof-of-concept Spectre exploit that leaks arbitrary Linux kernel memory on the Xuantie C910 at a rate of 338 B/s. Software-based defenses have been developed for these vulnerabilities on x86 and ARM hardware. Unfortunately, the researchers say, these don't necessarily transfer. They also call out RISC-V hardware for its lack of introspection interfaces, necessary to observe and reason about microarchitectural features. In addition, the authors argue, the diversity of the RISC-V hardware ecosystem means that no single mitigation strategy is likely to be effective across all systems. "RISC-V inherits the software and threat model of mature architectures without their accumulated hardening," the authors conclude. "Closing this gap is not a matter of porting individual mitigations, but of building the architectural primitives, hardware transparency, and ecosystemwide tooling that effective Spectre defense presupposes." The authors say they disclosed their findings responsibly last December. Three of their patches have been merged into mainline Linux and two others are under review. SiFive is said to have dealt with P550-specific findings and T-Head (Alibaba) is said to have committed to publishing ad-hoc speculation barriers for their processors at some point. The authors say they decided not to delay publication because Spectre has been around for eight years now. The paper was written by Lukas Gerlach (CISPA Helmholtz Center for Information Security), Marton Bognar, (DistriNet, KU Leuven), Daniel Weber and Michael Schwarz, (CISPA Helmholtz Center for Information Security), and Jo Van Bulck (DistriNet, KU Leuven). ®

Nvidia's latest solution to soaring enterprise AI costs is...a router?

12 Agosto 2026 ore 21:00
Soaring AI infrastructure costs and model pricing, combined with uncertain returns on investment, threaten to stall enterprise adoption. To make enterprise AI spend a bit more manageable, Nvidia this week unveiled a new software platform that blurs the line between expensive proprietary models and open weights alternatives. Announced alongside Nemotron 3.5-30B-A3B-Lightning, Nvidia’s latest open weights model, NeMo Switchyard is the GPU giant’s latest overture to enterprise. So what exactly is it? Well, it’s a router. The idea is simple. Switchyard essentially functions as a proxy that sits between the inference server’s API endpoint and the models. But rather than sending every request to the same model, Switchyard can be configured to route prompts to different models in order to optimize for cost, latency, or output quality. By routing some requests to smaller, cheaper, and potentially locally hosted AI models, Nvidia claims Switchyard can cut job completion costs by 74 percent relative to using Claude Opus 4.8 alone, albeit with an approximately six-point accuracy tradeoff. The right tool for the job The key metric in all of this is completion cost rather than price per token. A model might cost one-tenth as much as OpenAI’s or Anthropic’s top model, but if it requires 10x the tokens to complete the request, it isn't actually cheaper. Certain elements of an AI workload may benefit from a larger, smarter model, but not all do. For example, it’d be overkill to ask Claude Opus to generate a title card or summarize a website. It’ll certainly work, but it’ll also cost a fortune compared to Haiku or a locally hosted model that’s been fine tuned just for that purpose. The fewer tokens you burn on the big smart model, the less expensive your API bill is going to be. Nvidia software teams have spent the last several years developing models for this reason. The Lightning model announced this week is only its latest. The 30 billion-parameter MoE model is positioned as a low-latency, general purpose model that can either be used on its own or in conjunction with a larger, smarter model via a router like Switchyard. The company has also developed several application-specific models. Nemotron Parse is one such example. “It’s a small model, one billion parameters, and it’s really good at one task, which is taking a PDF in and then explaining the context inside that PDF whether it’s charts or graphs or tables,” Joey Conway, senior director of AI software and models at Nvidia, explained in a recent interview with The Reg. Many frontier models struggle with this task because PDFs are designed by humans for humans, so by offloading that work to task-specific models, enterprises can not only improve the accuracy of their AI apps, but also reduce costs in the process. This all might sound familiar: It's not the first time we’ve seen model routers employed as a cost-saving measure. Back when OpenAI launched GPT-5, ChatGPT would dynamically route prompts to different versions of the model based on their complexity. As we wrote at the time, OpenAI’s router was likely implemented to reduce the number of compute cycles spent on mundane tasks like rewording emails to sound more professional ("not only … but also"). OpenAI wasn't alone in using routers to reduce model costs. The Wall Street Journal recently reported that AT&T has implemented a “smart router” of its own to automatically select which model to use. Switching from proprietary to open-weight models has reportedly saved the telecommunications giant between 80 and 90 percent in certain applications. Today about 25 percent of the company’s AI workloads are powered by open models. The company’s leadership expects that over the next few years that’ll climb to 70-80 percent. The implementation challenge While the idea of offloading simpler requests to smaller, cheaper-running models sounds intuitive, it’s easier said than done. Title cards and web summaries are relatively straightforward to implement. Open source chatbots like Open WebUI have supported this kind of functionality for more than a year now because it just makes sense. However, sometimes it’s not obvious when and where these task models should be used. Switchyard is Nvidia’s latest attempt to simplify this by automatically routing requests to the right model for the job. However, it’s not the only approach Nvidia is exploring. AI agents and code assistants have the ability to work through problems and then generate skills — essentially standard operating procedures — documenting the process for future reference. Through this iterative process, Conway suggests, agents could essentially teach themselves when and where they can get away with using a smaller, cheaper task model, and where a larger frontier model may be required. “We’re starting to see signs of this sort of agent and subagent type workflow,” Conway said, describing how a frontier model might function as an orchestrator that farms out work to smaller models that are faster and more specialized. It reflects the way companies are structured, he said. “We have people who are specialists and then we have people who help orchestrate that and understand the complexity of the problem.” As an added step, it’s possible for the agents to generate training data on the fly, which could then be used to fine-tune the models to operate more efficiently. Regardless of which approach ultimately wins out, anything that promotes enterprise AI adoption is a win for Nvidia. ®

Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows

12 Agosto 2026 ore 20:12
Nightmare Eclipse, the serial zero-day hunter who has an axe to grind with Microsoft, published a new Defender zero-day, ShieldBreak, that apparently bypasses Redmond’s RoguePlanet patch (CVE-2026-50656), allowing attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. According to at least one other researcher, the exploit works. “I've tried it, it works on latest Windows 11,” former Microsoft employee and security expert Kevin Beaumont said. Beaumont also published three detections and hunting queries for ShieldBreak to help defenders rapidly find any stealthy threats. So until Microsoft fixes this latest zero-day, we’d highly suggest using these queries. ShieldBreak is the 10th zero-day from Nightmare Eclipse since they began their scorched-earth strategy against Microsoft in early April. The prolific bug finder and exploit developer is suspected to be a former, very disgruntled, Microsoft employee. And in typical fashion, this latest zero-day drop occurred just hours after Redmond’s monthly Patch Tuesday that fixed 421 security problems in its products - but ShieldBreak isn't one of them. It’s a local privilege-escalation exploit that, according to Nightmare, allows attackers to gain SYSTEM-level privileges. “The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate. Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well,” they said. While Nightmare claims that the new exploit is a patch bypass for the earlier RoguePlanet vulnerability, CVE-2026-50656, which Microsoft quietly fixed in July, Beaumont pointed out that the two flaws operate very differently. “RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files,” he posted. “ShieldBreak user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API).” A Microsoft spokesperson told us the company "is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims." The spokesperson added: "Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible. Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public." This latest zero-day comes a month after Nightmare Eclipse published its previous vulnerability along with partial exploit code. Nightmare’s July drop, called LegacyHive, is a local privilege escalation flaw that targets Windows’ user hives - the section of the Windows Registry that stores a user's specific desktop settings, application preferences, and environment configurations. It's patched with CVE-2026-62832. There's also a June zero-day called GreatXML that Nightmare developed. The researcher claims the flaw allows a local attacker with administrator rights to bypass BitLocker encryption by manipulating the Windows Recovery Environment. But it has been patched with CVE-2026-50661. The prolific zero-day hunter’s earlier seven Windows bugs do have patches. These include BlueHammer (CVE-2026-33825), RedSun (CVE-2026-41091), UnDefend (CVE-2026-45498), YellowKey (CVE-2026-45585), GreenPlasma (CVE-2026-45586), MiniPlasma (CVE-2020-17103), and RoguePlanet (CVE-2026-50656). After threatening legal action against Nightmare Eclipse in May, and then facing rapid backlash from just about every other security researcher on the planet, Microsoft walked back its talk of siccing its Digital Crimes Unit on people who don’t follow its vulnerability disclosure rules.® Correction: There are patches for GreatXML and Legacy Hive.

OpenWALDO aims to blow the doors off proprietary AI training models

12 Agosto 2026 ore 18:57
A new project aims to build a shared, open source AI training dataset that anyone can contribute to, much like an open source software project. It aims to make training data more transparent than that of many open-weight models that have recently taken the industry by storm. CentOS and Rocky Linux founder Gregory Kurtzer is behind the effort, dubbed Open Weights, Artifacts, Licenses, Data, Origins (OpenWALDO), and it's funded by CIQ, his AI infrastructure company, which also sponsors Rocky Linux. Kurtzer described the effort as trying to bring the open-source ethos to AI model design, which has yet to be truly open – even downloadable open-weight models still have closed-source training data that is unknown to users, alongside other limitations that make them less than truly open source. “I’ve spent my career watching open source turn users into builders, competitors into collaborators, and shared problems into common infrastructure that operates at massive scale,” Kurtzer said in the announcement. “OpenWALDO brings that proven model to AI. Let’s work together, build its foundation in the open, and collaboratively take AI to the next level.” CIQ, which authored the announcement, argues that open-weight models keep that foundation a secret because of where it comes from: Copyrighted data, responses distilled from other models, user-generated content that may not have been given in a truly open manner, and the like. “There is often no way to know what data trained a given model, under what license, or with what consent,” CIQ said, adding that hidden training data content could taint models, putting customer software stacks at risk. In addition to that, there’s the simple fact that, when everyone is training their AI models in secret, a lot of duplicate work is happening that wastes lots of time and computing resources. A single, shared set of public training data, the OpenWALDO team argues, would not only make training more efficient across the industry, but also mean that every improvement to the dataset could benefit future models trained on it. “A lab or company can take the corpus and its bill of materials as a verified baseline, add its own proprietary data, build, and ship, with a clear, auditable line back to its sources,” CIQ explained. With prices steep and ROI still largely absent, open AI models (not to be confused with OpenAI models) have risen to prominence in the AI zeitgeist lately. Models out of the home of open-weight AI, China, are closing in on the capabilities of closed-source frontier lab models like ChatGPT and Claude, leaving many businesses wondering why they ought to pay through the nose for AI services they don’t own, can’t truly control, and have no visibility into. Some frontier labs have warned that open-weight models pose security and misuse risks. Kurtzer argues that open source software faced similar concerns. “Open source has won this argument before,” he said, pointing to similar arguments made about open code, namely that it’s insecure, impossible to trust, and the like. “Linux didn't win by being certified safe. It won by being inspectable, forkable, and community validated.” “AI is missing that same property, and OpenWALDO is how we build it,” Kurtzer said. Turning to open-source training datasets is a big ask for an industry already so far down the closed training data path, of course, and only time will tell if OpenWALDO is a revolution or another obscure OSS project that gets minimal attention from the AI community. So far, the OpenWALDO dataset contains 167.3 billion reference tokens pulled from things like government records, open-source academic papers, mailing lists, and public domain literature - a drop in the bucket next to the tens of trillions of tokens used to train frontier AI models and their open-weight counterparts. We asked if anyone has trained a model on the OpenWALDO set yet, but CIQ didn’t respond. Those interested in contributing to, or making use of, OpenWALDO can find more on the project’s website (linked above) and its GitHub page. ®

❌