Modalità di lettura

Part didn't fit so techie got out his screwdriver. Then something flew off the motherboard

WHO, ME? Is it a mistake to return to work on Monday? While you ponder that question, pause a minute to read this installment of "Who, Me?" – The Register's week-opening column that shares your stories of workplace errors and escapes. This week, meet a reader we'll Regomize as "James," who told us that in the early 2000s he worked in the biology department of a famous American university. "We custom-built all our PCs from the cheapest available parts at the time we ordered," James wrote. Which was how he found himself struggling to attach a heatsink to a CPU destined for use in a new PC. "The stupid hook wouldn't go over the plastic tab and so the heatsink didn't want to stay on," he wrote. "Not one to let a computer component get the better of me, I grabbed a flathead screwdriver, stuck it into the little leverage point in the heatsink clamp's arm and leveraged the hell out of it." The result of that decision was audible. "It went PING! and a tiny piece of something went flying away, but the heatsink was now securely mounted," James told The Register. He therefore connected the PC to power, turned it on, and… wondered why its fans blew up a storm, but nothing appeared on screen. "I removed the CPU, removed heatsink, and took a closer look to find the source for the PING. And there it was, or rather wasn't – a very tiny and apparently very important surface-mounted component of some sort was missing right next to where the metal clamps for the heatsink hook in." James was very clearly at fault, but decided the way to fix the problem was to fib about it. "I played dumb and called it into tech support at the company we ordered the heatsink from," he confessed. "They were very nice, accepted the part was dead on arrival, and sent me a replacement right away." "Needless to say I was much more careful with the replacement, which worked great," James told Who, Me? What have you broken with a screwdriver? And how did you get away with it? Click here to share your story with The Register. If you want us to use your story in a future Who, Me? we suggest using a keyboard and mouse – not a screwdriver. ®

  •  

Linux 7.2 debuts, Linus Torvalds says ‘new normal’ means he had to do it now ... or never?

Linus Torvalds has decided version 7.2 of the Linux kernel is ready for release, albeit in a “new normal” state that he seems not to entirely love. The kernel boss announced the debut of a new kernel in his weekly development status update, which on August 16 opened with the observation that “this last week of the release was – once again – bigger than I would have wished for.” He attributed that uncomfortable size to what he last week described as “the new normal” for the kernel at a time when developers have increased the volume of contributions using AI coding tools. “If I delayed releases for that reason we'd probably never have a release at all,” Torvalds wrote, before adding that the release includes “a number of fairly late reverts - the drm scheduling reverts stand out, but there's a few other ones in here too.” “It may not be pretty, but it's the correct way to deal with ‘Oh, that code wasn't ready and caused problems,’” he wrote. As ever, the new kernel release includes important and seemingly frivolous inclusions. Among the latter is support for a gaming controller called the “Zenaim Leverless,” which offers a collection of buttons on a black slab. Apparently e-sports pros think it’s just the sort of thing they need to rack up high scores or crush their foes during tournaments. And now they can use it with Linux! Perhaps more relevant to a majority of Reg readers is the inclusion of a tech called “Cache Aware Scheduling” that makes the kernel better at handling the data stored in caches across manycore chips like AMD’s EPYC 5 and Intel’s Xeon 6. Qualcomm senior engineer Vishnu Santhosh wrote a good explainer about the tech. Long story short, it’s about making processors aware of useful data already in a cache, so they can use it instead of doing extra work to access the relevant data. The release also includes work that makes it possible to run Linux on Apple M3 devices, the usual handful of graphics updates, and work to ensure that the kernel will be ready to support next-gen chips from AMD, Intel, and Nvidia. Notable deprecations include ending support for AppleTalk, and for old-school ISA and PCMCIA adapters used on ARCNet networks. This hits hard because The Register believes that PCMCIA stands for People Can’t Memorize Computer Industry Acronyms, and not for the Personal Computer Memory Card International Association. ®

  •  

Microsoft blames AI for delayed Exchange update, can’t say when it will arrive

Microsoft has blamed extra work created by AI bug-finders for the delayed release of a major Cumulative Update to Exchange Server Subscription Edition (SE). Redmond’s Exchange team made that admission last Thursday in a post titled “Where is Exchange SE CU1 anyway?” that reveals the software giant is “getting questions from our customers on when they can expect us to release Exchange SE Cumulative Update 1 (CU1).” “After all, in the past we mentioned that it would be released by the end of the first half of calendar year 2026, later updated to ‘second half of 2026’. What is the deal? Where is CU1?” For those of you who came in late, Exchange SE is the subscription version of Microsoft’s email server, and a Cumulative Update (CU) is a new version of the package that includes all recent bug fixes, plus other changes such as new features or removing deprecated code. Microsoft publishes CUs once or twice a year. Some users prefer applying CUs to applying every patch. As Exchange SE is a subscription product, not getting CU in a timely fashion isn’t a great example of why pay-as-you-go software is a great idea. Microsoft explained delays to the arrival of CU1 by referring to the fact that “Over the last few months, various Microsoft execs made statements explaining how Microsoft is leveraging a variety of AI tools to help find vulnerabilities in our products.” The post says the Exchange development team is “working through reported issues – which includes validation that they are real security issues, reproducing, fixing, testing for regressions / issues after fixes are deployed and releasing updates monthly.” Redmond’s missive also points to Microsoft’s pledge to “prioritize security above all else” as a reason for delays. A reminder: Microsoft adopted that stance after flaws in Exchange led to an attack on Exchange by suspected Chinese operatives, earning it a tongue-lashing from the US government. The Exchange team says that while trying to stay on top of bugs, it is also working on CU1. “We are regularly rolling our monthly security payload into our internal CU1 build and plan to release Exchange SE CU1 as soon as we get a reasonable stable point and have a month without pressing security payload.” The Exchange team has adopted that stance because it doesn’t want to publish CU1 and then find it needs to replace it with another that includes new security updates. “That would create double the update work for many organization administrators,” the post explains. “Even internally, trying to ensure that two major releases (Security Update and a CU) get appropriately tested so we can ensure high quality and nothing falls through the cracks would be very challenging as CU1 must be all inclusive of everything that we released since the RTM.” Exchange admins will likely appreciate the fact that Microsoft doesn’t want to burden them with two major updates to implement. They may also wonder when Microsoft will find a month in which there is no “pressing security payload” that takes priority over CU1. Microsoft’s post offers little certainty because it concludes: “In short: Exchange SE CU1 is coming; we do not have a date to give you. But we did not forget about it.” Nor, it seems, did Microsoft plan for how AI-powered bug-finding would impact product development teams. ®

  •  

Chinese AI company Zhipu claims its new is a better bug-finder than Anthropic, OpenAI

ASIA IN BRIEF Chinese company Zhipu last week launched a new AI model called GLM-5.3 that it claims has bug-finding powers that match those possessed by American models. The company’s announcement includes benchmark data that finds GLM-5.3 beats Fable 5 and GPT-5.6 Sol on the CyberGym benchmark, a test of a model’s ability to solve real-world cybersecurity challenges. “As we scaled post-training, cyber capability developed faster than we expected. GLM-5.3 is state of the art on CyberGym for vulnerability discovery, and its gains are largest further up the exploitation chain,” the company wrote, adding that the model “did not simply become better at identifying isolated flaws: it began to reason across multiple stages of exploitation, forming coherent plans for complete exploitation chains.” The company said it has worked with Chinese companies to test the model on real-world codebases, and found 2,436 vulnerabilities across 269 projects, including 1,097 medium-to-high severity issues. The findings span system kernels, operating systems, browser engines, open-source infrastructure, web applications, and network protocols. “Many had remained unnoticed for years or even decades, with the oldest dating back roughly 40 years,” the announcement states. GLM-5.3 also performed worse than western models on other security and coding benchmarks. Yet the fact that the model is a highly-capable bug finder signals that China is not far behind in terms of being able to poke holes in its rivals software and developed that capability very quickly after the debut of Anthropic’s Mythos. Any advantage the US felt it had as the home of Anthropic has therefore dissipated. Korea signals legal action against Apple, Google app store strangleholds South Korea’s Communications Commission last week found Google and Apple had abused their app store monopolies, and promised stern sanctions will follow. In 2021, South Korea passed world-first legislation requiring app store operators to offer the option to use third-party payment schemes. Apple and Google did so, but charged a 26 percent transaction fee for doing so – meaning they earned almost as much revenue when users chose third-party payment providers as they did from their own schemes. The regulator has previously warned that it will impose the highest possible penalty available under law, which is three percent of revenue earned by non-compliant behaviour. That’s probably back-of-the-sofa money for Apple and Google. India has banned rideshare operators from offering customers the chance to specify the amount they will tip before a driver accepts a gig. Uber India introduced the feature last year, seemingly copying it from an Indian rideshare operator called Namma Yatri. Consumer affairs minister Pralhad Joshi criticized Uber for the practice at the time, as he saw it as a means for users to effectively jump the queue by offering drivers more money – and for rideshare platforms to improve their revenue because if tips are higher, so is the platform’s share of the gratuity. Last week, India’s Ministry of Road Transport & Highways issued a directive (PDF) banning the practice. Henceforth, rideshare apps can only offer users the chance to tip at the end of a journey, and all of the tip must go to the driver. “No feature, prompt, message, add-on, payment option, or user interface element should be displayed before completion of the ride that directly or indirectly encourages, induces, or creates an impression that payment of any additional amount may improve ride confirmation, driver acceptance, driver allocation, waiting time, or quality of service,” the directive states. Indian services giants reveal data breaches Indian tech services giants TCS and HCL last week both admitted to data breaches but say customer data is safe, and only employee data is at risk. TCS published a stock exchange filing that opens “This is to inform you that Company has received threat-intelligence alerts alleging possible exposure of certain employee information.” The filing says TCS investigated the matter “and has not found any credible evidence of a breach of TCS systems or customer environments.” The company says leaked info is “basic employee information” and more than four years old. Note that mention of the stolen data being at least for years old, because TCS’s filing says the attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue to pull off the heist. TCS says it “had strong safeguards in place against such techniques for more than two years,” perhaps suggesting the data heist occurred before the company shored up its defenses. “Based on the current review, these controls remain effective, and the Company continues to monitor the environment closely,” the filing states. HCL also used a stock exchange filing [PDF] to address what it called “claims made by a hacker group of potential exposure of limited data elements relating to HCLTech employees.” The company described the stolen data as “limited and dated to a few years back,” and added its assurance that customer data is safe. HCL’s investigation is ongoing. Lenovo’s enterprise unit finally posts a big profit Lenovo last week announced its quarterly results, including a $777 million profit for its Infrastructure Solutions Group (ISG) – the biz based on the 2014 acquisition of IBM’s x86 server operation that has seldom produced positive financials. Even during the early years of the AI boom, ISG’s profits were modest – just a few million dollars per quarter on turnover of billions. The business unit won a record $8.5 billion of revenue, up 98 percent year-on-year. AI was a big reason for the result, as buyers sought hardware to run inferencing workloads, The company says it has a pipeline for $54 billion of AI server sales, and has become the number two x86 server vendor as measured by revenue. Overall revenue came in at $26.95 billion, up 43 percent year-on-year, and cash won by its PC-led intelligent devices group jumped 27 percent to $17.1 billion and saw its PC market share reach 24.2 percent. Lenovo reckons the strength of its supply chain helped make those outcomes possible. India to build astronaut training facility India’s Space Research Organization (ISRO) last week issued a tender for construction of an astronaut training facility. The tender mentions extensive air conditioning works, plus a swimming pool, suggesting India wants to build a large tank in which the Vyomanauts who will fly its future Gaganyaan missions can train at home, instead of traveling to Russia or elsewhere as has been the case in the past. The tender covers $2.75 million worth of work. ®

  •  

Stopping a cyberattack while walking your dog - defensive AI security CEO says it's not ruff to do

Corma CEO Alon Pluda says his AI security startup aims to close the "defense gap," where models are better at offensive security. He tells the story of one customer, a security executive who was walking his dog when he received a notification on his watch from a Corma agent. “It said, 'I just caught a live attack. I need your permission to block it,'” Pluda told The Register in an interview. The security boss approved the agent’s action; the agent blocked the malware and the attacker from moving across the company’s network and mitigated the intrusion in under 10 minutes, Pluda said. The customer later described "walking outside with his dog, and blocking a real-live attack with his AI coworker" as "one of the most magical moments of his year," Pluda recalled. Pluda founded Corma about a year ago. And yes, all you Lord of the Rings nerds, the company gets its name from the Elven word for “ring.” “We’re building the one ring to rule them all, but this time for the defenders to have this power.” Earlier this week, the company announced $60 million in seed funding led by Sequoia Capital, alongside Khosla Ventures and Coatue. He told us that his startup is working with Fortune 100 companies, and training models to achieve “superintelligence for defensive cybersecurity.” Models from OpenAI, Anthropic, and Google are “amazingly good” at coding and language, and this includes finding and fixing bugs, and orchestrating tools across multi-step workflows, he explained. “When you combine it with agentic capabilities, they move from being incredible vulnerability researchers to end-to-end attackers,” Pluda said. “So inherently, what we’ve seen in the last few months is the models getting exponentially better at offensive security, like we saw with the OpenAI and Hugging Face incident.” But these same models aren’t as skilled at carrying out defensive security tasks that don’t involve scanning code for vulnerabilities and misconfigurations, he said. “The vast majority of defensive security tasks don’t have anything to do with code.” Corma recently tested four frontier models - Claude Opus 4.8, GPT-5.5, Grok 4.3, and DeepSeek V4 - as both attackers and defenders across the same fake company and its networks, built to closely mirror a multi-business enterprise. The attacker’s task was to plant a backdoor and the defender’s task was to find it and stop the attack. Closing the defensive gap Corma ran all four models against each other in every attacker and defender pairing, including each model against itself, with 15 independent engagements per pairing for 241 scored engagements. Across all of these, the models successfully implanted a persistent backdoor in 85 percent of their runs. However, these same models only detected 19 percent of attacks. “That speaks to the inherent imbalance we are trying to solve,” Pluda said. “The general foundation models are getting exponentially better at offensive security, but haven't been able to improve on the same rate on defensive security. So our mission is to close this gap, and make sure the defenders win in this intelligence-versus-intelligence game - or war.” Corma calls this the defensive gap, and says it has to do with the data these models are trained on and the objectives they are trained against, which lend themselves to offensive security. Defensive security, however, involves reading logs, events, configurations, audit trails, and on-disk state. This is “structured machine data that is neither prose nor source, and a small share of what these models see in training,” according to Corma’s research. “They appear to read it less reliably.” Plus, defensive reasoning is more open-ended, while offense has a straightforward goal - like “make this work” or “break this” and a checkable finish. Agentic defenders “Defensive security,” according to Pluda, “is about finding needles in the haystack.” Corma’s models power its AI agents, which organizations can deploy like “team members” who then operate across defensive security tasks. “It’s a generalized workforce, and you can assign it to whatever security tasks you want.” Fortune 100 and 500 organizations across healthcare, financial services, energy, critical infrastructure, retail, and other sectors have deployed Corma’s AI workforce across their environments, according to the startup. These early deployments, we’re told, have reduced threat response times by more than 94 percent, expanded security coverage by 15 times across different security functions, and uncovered multi-stage attack campaigns. “If you can get AI that is smart enough, intelligent enough, knows the domain enough, optimizes for the right things enough, and you can actually trust it, end to end, all the way to responding to real-live attacks, you can reduce all of these metrics significantly,” Pluda said. “And you can cover way more ground than what is possible with just human intelligence.”®

  •  

The what, why, and how of pull requests and source comments

Veteran Microsoft engineer Raymond Chen has weighed in on the difference between a pull request description and comments embedded in the code. Both matter, but they serve very different purposes. As Chen noted on his The Old New Thing dev blog: "The PR description is a point-in-time statement, providing information that is relevant to the code review itself. "It is an exercise in persuasive writing: You are trying to convince the approver that your change should be accepted." And sticking text in the source? "Comments in the code are for talking about the code itself. What is the correct way to call this function? Does it have specific prerequisites? This information is durable: It is information that remains useful even after the pull request completes." We'd argue that commit messages should be considered as well, but the distinction between PR descriptions and code comments is timely, given the volume of pull requests being generated by AI coding tools alongside some occasionally "interesting" annotations. Then again, anyone complaining about comments in AI-generated code would be wise to inspect those written decades ago by one of this writer's former colleagues. They consisted of pages apologizing to whichever future programmer had to untangle the spaghetti of C++ lurking through a maze of modules. Another colleague refused to annotate their code at all, insisting it was "self-commenting." These days, an honest comment might read: "This was written by , and I have no idea how the heck any of it works." It echoes another perennial developer dispute: whether code should be indented with tabs or spaces. In 2024, another Microsoft veteran, Larry Osterman, took a decidedly fence-sitting position: tabs were fine when storage was at a premium, but spaces now make more sense "because it always works and it's always consistent." Chen's position on tabs versus spaces is not widely known, but his broader opinion on code formatting was straightforward: "I don't care how you format your source code. It's your source code." He did suggest making any wholesale change in layout or formatting a separate check-in, so maintainers aren't faced with an epic diff dominated by a new style guide. All of which brings us back to Chen's distinction: the PR description explains why maintainers should accept a change, while comments preserve what future programmers need to understand the code. ®

  •  

ChainDrop worm crawls into npm supply chain, evades standard defenses

A new variant of the Shai-Hulud npm worm has poisoned hundreds of packages while adding propagation techniques that can leave little trace in the corresponding source repositories. In Frank Herbert’s Dune, Shai-Hulud was the name of the giant self-sustaining desert sandworms that moved silently beneath the surface of the planet Arrakis. So it made sense that when some new self-replicating malware with computer worm-like behavior appeared in September 2025, security researchers would name it after Herbert’s fictional creatures. The latest variant of Shai-Hulud, dubbed “ChainDrop” by Microsoft and others, is no mere sequel, however. Now, the npm community is discovering a Shai-Hulud variant spreading with new stealthy superpowers that circumvent the usual safeguards of open source repositories. On August 4, multiple security researchers identified a large-scale npm supply chain attack using this Shai-Hulud variant that had infected 444 packages from multiple publishers, which are collectively downloaded about 2 billion times a month. The operation targeted widely used deep infrastructure dependencies, such as keyv, flat-cache and cache-manager. Abby Kearns, CEO of enterprise open source security company ActiveState, noted in a Medium post that what is unique about this particular attack is that it doesn’t use the typical methods of breaching the defenses of open source repositories. Even if you never install an infected package (“npm install” in npm argot), you can still get the nasties – though that is one possible route of infection. Once triggered, ChainDrop also places startup hooks into the repository configuration files themselves: Simply opening an infected Git branch in VS Code or Claude Code can bring your repository under ChainDrop’s control. Scouring your code itself may not provide evidence of tampering. ChainDrop propagates not by repository source commits but by tarballs, an archive format for downloading file packages. ChainDrop travels by tarball When executed, the software scours the user’s workspace for npm tokens with full write privileges, as well as for other credentials like cloud keys and secrets. It looks in shell configurations, environment variables and even live memory. Any purloined data is encrypted and sent back to attacker-controlled endpoints. Should it find an npm token, it then downloads the tarballs of all the packages that token has full access to, bypassing the repositories themselves. That’s the genius part: ChainDrop self-replicates by rebuilding the tarball to include its own payload. Reviewing the source code repository won’t reveal any evidence of shenanigans. ChainDrop’s attack is two-pronged. It also searches for GitHub credentials. If it finds any, it queries the GitHub API to list all accessible repositories and branches and then commits its malicious configuration code directly into those branches. So when other developers open these repositories using Claude or VS Code, a background task gets triggered that harvests credentials, beginning the whole cycle anew. What a dev can do This attack is particularly pernicious because npm is widely integrated into automated CI/CD pipelines, which can automatically pull patch updates for dependencies during a rebuild - giving the worm a path to wiggle into fresh builds. If you think you've been infected, the first thing to do is check for any .claude/settings.json and .vscode/tasks.json files you did not add yourself, ActiveState’s Kearns advised. And don’t just check the main branch, but all the other branches as well. All the infected packages were quickly yanked from npm. Open source security firm SafeDep offers a list of all the compromised packages along with version numbers, so check those against what you currently have running. Beyond cleaning up the mess, developers and security teams should rethink how their systems could be breached in light of ChainDrop. Trusted publishing tools such as GitHub Actions should be evaluated, for starters. Begin “treating repository-supplied configuration as executable content, because that is what it is now,” Kearns wrote. “What this campaign really found was an execution path that dependency scanning tools were not configured to look at, sitting inside the exact tools engineering organizations have spent two years adopting as fast as they could,” Kearns wrote. “This is the first campaign to notice the gap and use it at scale. It will not be the last one.” ®

  •  

Lego's supersized Hubble deserves a little more shine

Lego has released its largest Hubble Space Telescope yet – a model built at approximately minifig scale that dwarfs the observatory included with its Space Shuttle Discovery set. The first thing to say about this set is that there is an awful lot of grey. This is perhaps the greatest weakness of an otherwise excellent set and feels a little penny-pinching on the part of the Danish brick botherer. Lego has produced several versions of Hubble over the years. There is a version to fit in the payload bay of its large Space Shuttle Discovery set, and a much smaller incarnation on a plinth in the Women of NASA set. Both are retired, so scratching that Hubble itch with a current official set means dropping £119.99 on the Icons Hubble Space Telescope. It's a large set. According to Lego, the 1,252-piece set measures 32 cm tall, 38 cm long (with the aperture door open), and 38 cm wide. An astronaut minifigure is included to indicate the model's approximate scale – a shame there's just one, since the servicing missions had a pair of spacewalkers – along with a power tool. There is also a stand featuring some of Hubble's iconic imagery and a plaque with more information, including the dates of the Space Shuttle servicing missions. Lego has not included replacement instruments to recreate the various servicing activities. Inside are Lego representations of Hubble's instruments and systems, including its gyroscopes, primary mirror, and secondary mirror. Outside are posable solar arrays and antennas, along with an aperture door that opens. Some parts are a little fiddly, and the set is aimed at ages 18+. That seems a little on the high side, but this isn't something you'd want a young child trying to build. The level of detail is impressive, considering the nature of Lego components, but it is difficult to avoid all that grey plastic. The Hubble Space Telescope included with the Space Shuttle Discovery Icons set uses silver bricks, which makes the choice of grey plastic feel cheap in comparison. And then there are the stickers. Thankfully, there aren't too many, but printed parts are readily available, and Lego uses its own, so why make builders fiddle with sticker alignment? And then there are the solar arrays, which are single-sided and feel a little cheap compared with the arrays on some of the MOCs The Register has built over the years. Still, these are minor niggles in what is otherwise a fun build lasting 6-12 hours. The set is an excellent addition to the Icons range, but such is the affection for Hubble that details matter. The set also acknowledges Hubble's 35th anniversary, celebrated in April 2025, with a "35" decal on the back of the astronaut minifigure. The real thing continues to orbit, although its days are likely numbered. The Lego version is likely to endure until a careless elbow knocks it off the shelf, or a creative builder decides to repurpose its components for an orbital animal amusement park. Which, after all, is the whole point. ®

  •  

Anthropic says text watermarking scheme relies on inconsequential words

In an effort to "watermark" text that Claude has generated and comply with the EU AI Act, Anthropic unveiled a plan on Friday to modify its bots' choice of words in a way that would be detectable as the product of an AI. Traditional watermarks are patterns or images overlaid on currency, postage, or official documents as an assertion of authenticity. In the digital realm, the term is more flexible and can refer to a variety of techniques for applying an identifier to electronic data. Anthropic's approach involves influencing inconsequential word choices made by its models, a technique introduced in Google DeepMind's SynthID-Text paper. To oversimplify things, large language models are fancy autocomplete engines which work by predicting the next word in a sequence of words. Anthropic explains that while composing sentence output like "The weather today was cold and…" a model like Claude might respond with words like "cold" or "gray" and would be unlikely to respond with a word like "sugary." That's the theory, but when actually asked to complete that sentence, Claude Opus 4.8 went a bit overboard: "…crisp, the kind of cold that nips at your fingertips and turns your breath to little clouds. The sky was a pale, washed-out blue, and everything felt sharp and clear." And then it checked to see if users thought that was useful, asking, "Want me to take it somewhere specific — cozy, gloomy, cheerful? Or keep going with the same tone?" But remove whatever training has been applied to promote engagement and simulate literary style, and that's basically what Claude is doing here – predicting the next word in a sequence. Anthropic asserts that in most cases, the example sentence could be completed by either "cold" or "gray" and "the meaning of the sentence is largely the same either way." The watermark is generated by deviating from the predicted word to something else. A different source of randomness is used and that can be detected with a digital key. As Google DeepMind researchers explain in their paper: "Generative watermarking works by carefully modifying the next-token sampling procedure to inject subtle, context-specific modifications into the generated text distribution. Such modifications introduce a statistical signature into the generated text; during the watermark detection phase, the signature can be measured to determine whether the text was indeed generated by the watermarked LLM." Anthropic insists this will be done with low-stakes passages in a way that won't alter the meaning. "In internal testing, we’ve seen no impact of watermarking on the content, level of creativity, or readability of Claude’s text," the company said, adding that in a controlled study, human raters saw no difference in quality between watermarked and unwatermarked answers. That assumption hinges on not applying the watermark to any consequential text. As Anthropic puts it, "Watermarking is sparser on factual passages where there are fewer choices that can be made without decreasing the accuracy of the text." The biz goes on to say that the situation is similar with code – the watermarking algorithm can't simply start swapping method names. In the context of literature, the notion that some words are interchangeable is likely to raise a few hackles. While it may be a satisfying thought experiment to imagine Claude emitting, "It was the best of times, it was the least of times…" or "Telephone me Ishmael", anyone trying to pass off generated text as serious writing probably should face whatever social backlash watermarking may entail. On the plus side, Anthropic's flavor of watermarking isn't excessively intrusive. It doesn't involve any personally identifying information and only serves to indicate that Claude was probably involved at some stage of the creation of the marked text. What's more, the technique is expected to be only semi-effective. In its FAQs, Anthropic points out that some amount of editing should erase the watermark. "Light editing probably won’t remove the watermark completely; a complete rewrite where every word is replaced will," the company said. "In the latter case, of course, it’s arguable whether the text can any longer be described as AI-generated." In all likelihood, Anthropic doesn't care if its watermarking scheme can be defeated. The company's post makes clear that it is implementing it to demonstrate its attempts at compliance and has chosen a solution that doesn't raise costs. "Watermarking has a negligible impact on the speed of models, and because it produces no extra tokens, the model is the same price to serve and use," the biz said. Hey Claude, what's another word for performative compliance? ®

  •  

DeepSeek's innovative harness treats everything as a plug-in

DeepSeek has piqued the interest of the developer community by releasing an early version of its open source agent harness. This happens as harnesses have become increasingly important to those working with machine learning models. "Powered by the Cordis meta-framework, DeepSeek Harness is an agent harness built around one core idea: Everything is a plugin," the China-based AI biz said. "Models, tools, skills, sessions, sandboxes, filesystems, loops, orchestration, and UI are ALL implemented as plugins, and can be mixed, matched, replaced, and extended." The term "harness" came into common use this year to describe a longstanding software function – middleware or a mediation layer that handles the input passed to an AI model and the output returned from it. Harnesses oversee prompts, context management, tool orchestration, the agent loop, state management, error handling, safety, permissions, and related concerns. Claude Code serves as a harness for Anthropic's Claude model family and Codex performs a similar function for OpenAI's GPT model family. And there are many other model harnesses, including Aider, Cline, Goose, OpenCode, OpenHands, and Pi, to name a few. The term isn't precise: It may be used to refer just to the agent loop and tools, or it may be extended to a broader set of concerns related to orchestrating different tools, services, and capabilities like sandboxing, subagents, and so on. Google Antigravity, for example, consists of the Antigravity Agent Runtime (harness) that can be accessed through the Agent SDK, the Antigravity 2.0 desktop application, and the Antigravity CLI. Vague definitions aside, AI model harnesses are now where much of the competition is happening, particularly as models proliferate and become commoditized. The harness often implements the user interface, a source of user inertia, and once developers configure their tooling and become accustomed to doing things a certain way, it becomes more burdensome to switch to a competing product, even if the interface consists mainly of a command line. What's more, various studies have suggested that model performance (and cost) varies significantly with the harness used, due to different design choices. For example, the Pi coding agent relies on a minimal system prompt of about 200 tokens. Claude Code by comparison uses a system prompt of around 10,000 tokens (or did until last month when Anthropic trimmed the system prompt by about 80 percent). The same model will produce different results with different harnesses. DeepSeek Harness is noteworthy because of its innovative design, and because it shows Chinese AI labs moving to compete beyond model benchmarks and pricing. First, it treats everything as a plugin. It uses the plugin system from its underlying Cordis framework, which is designed to make it possible to add and remove components dynamically without wreaking havoc. "Plugins provide every agent capability, including models, tools, skills, sessions, sandboxes, storage, loops, scheduling, and the UI," the DeepSeek Harness website explains. "Cordis services and events let the plugins work together. Developers can select, swap, or extend any capability in configuration without changing the DeepSeek Harness source code." A DeepSeek paper [PDF] by researchers Yifan Shi, Wei Zhang, and Tianyi Cui explains the function of Cordis in more detail. Cordis is designed to support dynamic composability – adding plugins and removing them on the fly without breaking the application. The paper refers to this as temporal composability – removing a component and reverting its effect upon removal – and spatial composability – allowing components to manage dependencies upon other components. It cites as an example the plugin system used by Microsoft's Visual Studio Code. VS Code, the authors explain, runs all of its extensions in a shared process called the extension host. Once activated, they cannot be removed on the fly; the host has to be restarted. While VS Code provides a way for extensions to declare dependencies between extensions, it's seldom used. DeepSeek Harness supports plugin dependencies. The DeepSeek researchers argue temporal and spatial composability are necessary in a system where modification can occur continuously with little or no human oversight. It's a way of avoiding forced restarts and crashes when components appear and disappear. DeepSeek Harness also supports another useful feature: chain of thought traces. "Everything the model sees is recorded in an append-only session log: system prompts, reasoning, tool calls and results, subagent scheduling, and every context injection," the DeepSeek Harness website says. "In the Trajectory view, you can inspect these records by source. Resume, fork, search, and replay all operate on the same event stream." DeepSeek R1 made waves when it was released last year and it was trained to use chain of thought reasoning. This involves breaking down prompts into a series of "thoughts" and reflecting on those steps before emitting a final answer. Access to this intermediate reasoning turns out to be useful for assessing whether a model is reasoning well, whether its responses are accurate, how additional "thinking" affects output, and so on. Anthropic provides some access to thinking when extended or adaptive thinking is available (it varies by model). But increasingly the biz has been hiding model reasoning by summarizing chain of thought traces. That appears to be due in part to concerns that chain of thought traces can be used for copying models through a standard research process called distillation. Earlier this year, Anthropic said it had implemented classifiers for the "detection of chain-of-thought elicitation used to construct reasoning training data." The company also does not display raw chain of thought. It explains that "the text in a thinking block is a summary of Claude's reasoning." Accessing raw thinking requires contacting Anthropic sales personnel. Except for its open source models, OpenAI has also chosen to hide chain of thought reasoning, which the company uses for model monitoring. "After weighing multiple factors including user experience, competitive advantage, and the option to pursue the chain of thought monitoring, we have decided not to show the raw chains of thought to users," the biz said two years ago when it introduced its o1 reasoning model. With the newly released DeepSeek-V4-Pro and V4-Flash, the API provides thinking mode enabled by default. And as the open source model ecosystem matures, having access to chain of thought looks likely to become another opportunity for competitive differentiation. "I don't think the DeepSeek Harness is perfect but this is for sure the first time I have been looking at something new in the space and felt quite inspired to revisit some of our choices," said Armin Ronacher, co-founder of AI biz Earendil, which now steers the development of the Pi agent, in a social media post. "I love that part about Open Source a lot!" ®

  •  

1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack

Some 1.6 million unique email addresses tied to RingCentral have been leaked online, alongside names, physical addresses, and phone numbers, according to Have I Been Pwned. RingCentral disclosed the breach on July 28 and said “it was the target of a sophisticated social engineering campaign” affecting a “limited portion of RingCentral customers.” The comms platform said that it promptly responded to the intrusion upon detecting it, “took steps to stop the unauthorized activity,” and immediately launched an investigation into the security incident with help from a “leading third-party forensic firm.” “We have not seen any new unauthorized activity since taking these remediation efforts,” the company added. RingCentral did not immediately respond to The Register’s request for comment on this story. We will update it as needed. While the company hasn’t named its attacker, notorious data theft and extortion gang ShinyHunters previously claimed it compromised the collaboration platform, according to a post on its data leak site, viewed by The Register. Screenshots of the post also circulated on social media. The crooks claimed they stole more than 623 GB of data, and set a July 30 deadline for RingCentral to pay up - or else the crew would dump the stolen information online. RingCentral apparently didn’t pay the extortion demand, and ShinyHunters followed through on its threat, posting customers’ details on the internet. “The company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don’t care,” the crims wrote on August 3. A ShinyHunters spokesperson told us that the group broke into RingCentral by voice-phishing an employee and tricking them into giving the crooks their password. This same group, which security sleuth Dominic Alvieri says is his “top threat group and probably is for most analysts,” has hacked hundreds of organizations since the start of the year, including education tech firms that provide services for schools and universities along with healthcare-sector organizations. Recently, ShinyHunters dumped data stolen from Abbott’s cancer diagnostics business with the leak containing 10.9 million unique email addresses alongside personal and health information. The crooks claim that they made off with more than 30 million rows of customer information, including more than one million Social Security numbers and 7.5 million dates of birth. More concerning, however, they said the haul includes 22 million-plus rows of client notes containing confidential doctor-patient conversations and health information, and more than 20 million medical-order records containing patient IDs, prescription types, order dates, and refill information.® Editor's note: This story was amended post-publication with comment from ShinyHunters.

  •  

Russian missile uses Nvidia AI chip to help target Ukraine

Sanctions and Nvidia’s exit from Russia in 2022 haven’t stopped its Jetson Orin hardware from turning up in Russian weaponry, according to Ukrainian military intelligence. The Defense Ministry’s Intelligence Directorate (GUR) reported this week that it spotted an Nvidia Jetson Orin module in the remains of a Russian S-71 Monochrome cruise missile. The S-71M is an air-launched weapon with autonomous capabilities that can reportedly search for and engage targets using optical sensors and onboard computing. “The use of this component may indicate the use of artificial intelligence technologies in the missile,” GUR said. That assumption makes sense, as information on the S-71M suggests that it can operate with user oversight or entirely autonomously. Photos included with the GUR announcement show a heavily scorched Nvidia chip with the identifier TE980M-A1 stamped onto its surface, indicating that the chip is a Jetson Orin NX 16GB unit that Nvidia released in early 2023. It’s a capable chip, but not exactly datacenter-class hardware - Orin systems are designed precisely for use cases like autonomous systems. Nvidia used to have offices in Russia and do business there, but it closed up shop in Ukraine’s bellicose neighbor in 2022 following Moscow’s decision to go to war with Kyiv. That was prior to the introduction of the TE980M-A1, meaning it must have reached Russian hands through another channel after Nvidia stopped direct sales to the country in early 2022. In other words, whatever sanctions the US has enacted or business decisions Nvidia has made, its hardware is still turning up in Russian weaponry used to target Ukrainians. The one good thing about the entire affair, according to GUR, is the fact that the recovered hardware proves Russian tech manufacturing still isn’t up to snuff. According to Nvidia, Orin modules are consumer grade and are sold to all sorts of different people for all sorts of purposes, with military applications not being among their intended design. The chips aren’t supposed to be available in Russia, either, a spokesperson told The Register, adding that there are plenty of ways for Russia to get ahold of the chips that are out of its control. “Pre-owned Jetsons are available through many reseller channels,” Nvidia told us. “Although we cannot track products after they are sold, if we determine that any customer is violating U.S. export controls, we will take appropriate action." US export controls have restricted exports of advanced chips to Russia and China. Chipmakers have responded to China-specific restrictions by producing hardware designed to comply with US export rules, while third parties have allegedly used smuggling to get restricted higher-end components into China. It’s not clear how the Nvidia component ended up in Russian hands. GUR’s latest disclosures also document Chinese-made electronics in Russian weapons. However the salvaged chip made its way to Russia, GUR said its evidence shows that current export control regimes aren’t working. “The discovery of Nvidia Jetson in a new Russian missile once again demonstrates the need for increased sanctions pressure and coordination of the efforts of the civilized world,” the intelligence agency said. ®

  •  

Trump sends the US Navy back to the steam age

President Trump has ordered the US Navy to draw up plans to replace electromagnetic aircraft catapults and weapons elevators with old-fashioned steam and hydraulic systems. America’s commander-in-chief issued a presidential memorandum directing the secretary of defense, in consultation with the secretary of the Navy, to come up with a plan to replace the Electromagnetic Aircraft Launch System (EMALS) on the future USS Doris Miller (CVN-81) with the older steam-powered system. The same note stipulated the replacement of the electromagnetic Advanced Weapons Elevators with the hydraulic versions used in older carriers. These directives were part of a broader memorandum aimed at shaking up shipbuilding for the US Navy, which is often seen as glacial and moribund. EMALS was introduced on the USS Gerald R Ford (CVN-78), which was the first of an improved design of US aircraft carriers. It basically uses a linear induction motor to accelerate an aircraft along the flight deck, in place of the old-fashioned system that employs a steam piston. The premise of EMALS is that it doesn’t require a head of steam, and as it is electromagnetic, it should be easy to adjust the power to match the size and weight of aircraft being launched. However, the technology has had a few teething problems, as reported by The Register previously, and these have even led to the Gerald R Ford being unable to launch aircraft at all. The Advanced Weapons Elevators, which also use linear motors, have likewise proven problematic. Earlier this year, it was reported that there was a study underway to review the Ford-class carrier design and determine whether it should be altered for the next two in the class. “We are looking at 82 and 83 to review the costs, the designs, the systems, to make sure that they make sense, and they have all the systems and requirements that we want going forward,” then-secretary of the Navy John Phelan is quoted as saying. One of the concerns was said to be with the sortie generation rate of the Gerald R Ford – the number of takeoffs possible - which was promised to be higher with EMALS. We asked the White House if this directive would apply to all subsequent US carriers, but a spokesperson simply referred us to the announcement, which mentions only CVN-81. The rest of the president’s memorandum takes aim at naval shipbuilding in America. One directive is to establish a fifth naval shipyard to increase submarine and aircraft carrier repair capacity. Trump is also sanctioning foreign involvement in building up to three ship classes of US Navy vessels. His memorandum directs the secretary of defense to come up with “a new competitive acquisition approach” for surface combatants to perform anti‑submarine warfare, surface warfare, and convoy escort duties, plus Consolidated Cargo Replenishment at Sea (CONSOL) tankers and Roll-On, Roll-Off vessels – the latter typically used for transporting tanks and other military vehicles. The president proposes using a similar approach to the memorandum of understanding (MoU) between the US and Finland with regard to acquiring icebreaker ships last year. This will allow foreign suppliers to take part in US Navy procurement, provided they agree to build a new shipyard in America or assume ownership or a majority stake in an existing one, and construct all ships after the first two in US shipyards. Tellingly, the memorandum states that the US Navy “shall not impose iterative design changes upon the original mature parent designs within the above programs,” and that no changes from the original designs shall be made without the approval of the secretary of defense. Last year, the Trump administration canned the Constellation-class frigate program, which had been based on an Italian design to reduce technical risk, after so many changes were made that the US design had just 15 percent commonality with the original and the program was years behind schedule. ®

  •  

French tax authority admits data heist after crook touts 2M records

France's tax authority has confirmed that an intruder accessed its systems and extracted data in June after an alleged cybercriminal advertised a purported database of 2 million taxpayers. Using the alias "ZeroBytes," the alleged crook behind the attack on the General Directorate of Public Finances (DGFiP) advertised the stolen database on a cybercrime forum on Wednesday. They claimed the database contained details of more than 2 million French taxpayers and that they gained access using stolen credentials and an MFA bypass technique. ZeroBytes also claimed to retain access to DGFiP's systems and offered to sell it alongside the database. DGFiP did not immediately answer our questions about the attacker's claims. However, in a statement released Thursday, it disputed the claim that ZeroBytes retained access. "On Wednesday, August 12, 2026, a malicious actor claimed unauthorized access to the information system of the French Public Finances Directorate, which occurred at the end of June 2026 following identity theft," it said. "Initial investigations confirm that this access, which had been severed at the end of June as part of an audit, nevertheless allowed the consultation and extraction of data concerning individuals and professionals. "Following this complaint, the French Public Finances Directorate immediately implemented new restrictions to stop the unauthorized access and prevent further unauthorized use. In-depth investigations are ongoing to determine precisely which data and number of users were affected." DGFiP said it would report the attack to French data protection watchdog CNIL and notify affected users once it had determined who they were. The intrusion is the latest in a string of security breaches affecting France's public sector this year. France's Ministry of Finance, which oversees DGFiP, admitted in February that miscreants had accessed a database containing French citizens' bank details. The attackers used stolen credentials and made off with 1.2 million records, despite the ministry saying it quickly revoked their access. A few weeks later, France's Health Ministry confirmed a cyberattack on healthtech supplier Cegedim Santé in which around 15.8 million administrative files were stolen. Around 165,000 of these contained doctors' notes, which in "very limited cases" revealed medical histories. In April, the Interior Ministry confirmed reports of an attack on France Titres, the government agency responsible for identity documents including passports and driver's licenses. The alleged culprit, reportedly a 15-year-old, advertised the stolen data online and claimed the breach affected between 18 million and 19 million people – more than a quarter of metropolitan France's population. In June, the department responsible for Tchap, France's encrypted government messaging platform, investigated a suspected breach. The alleged attackers claimed to have accessed more than 73,000 user accounts, 643,000 messages, nearly 60,000 media files, and hundreds of chat rooms. ®

  •  

Virgin Galactic flights stay paused while ticket prices head for the Moon

Virgin Galactic has delayed its return to commercial spaceflight until February 2027, and plans to raise ticket prices later this year. The delay was disclosed alongside the company's financial results, which showed a net loss of $56 million for the second quarter of 2026, down from $67 million a year earlier. Revenue for the quarter was $0.1 million, compared to $0.4 million in 2025. According to CEO Michael Colglazier, demand exceeded the number of seats offered in the first $750,000 batch, prompting the company to prepare another at a higher price. Those customers will, however, have to wait a little longer. Colglazier said: "Our first ship is now expected to enter commercial service in February 2027 rather than the fourth quarter of 2026." He blamed the delay on the extra time needed to "complete avionics and systems installations." During an earnings call, Colglazier said: "No single issue is driving the schedule push. Rather, we have experienced modest time duration extensions across hundreds of relatively small but important installation tasks involved in the first build of our new spaceship." In response to an analyst question, Colglazier elaborated: "The number of those kind of 'Oh, we did not expect this to not fit just perfectly,' coming in is higher than we had allotted for. That just has started to accumulate on us. It really picked up at the tail end of July. For a bit, we thought we could manage that end, but the team just needed more time to do it the correct way." Integrated vehicle ground testing is expected to begin later in August, followed by flight testing in October. A second spaceship is due to join the fleet in March 2027, and the company expects to stop burning cash and "deliver positive quarterly cash flow within 2027." When Virgin Galactic reopened suborbital ticket sales in April, it charged $750,000 for a seat, up from the $600,000 price it cited in 2023. That was a substantial jump from the $100,000 envisaged more than two decades ago, when Sir Richard Branson announced plans for a scaled-up version of Burt Rutan's SpaceShipOne. At the time, the company said commercial flights would resume by the end of 2026. Virgin Galactic's last commercial flight took place in 2024, after which the company paused operations to focus on its next generation of spacecraft. Virgin Galactic is not alone in pausing its space-tourism service. Earlier this year, rival Blue Origin announced that New Shepard flights would pause for "no less than two years" while it worked on its crewed lunar program. ® Updated 8/18 at 10:19 GMT: A previous version of this story said that the program was "grounded," but the more appropriate term is "paused."

  •  

Autonomous AI attacks pose 'clear and present danger' to critical infrastructure

In early July, attackers used open source AI agents to autonomously hack government systems and energy companies, signaling to defenders that AI-powered attacks against critical infrastructure are no longer theoretical. "There is a clear and present danger," Tom Kellermann, TrendAI VP of AI security and threat research, told The Register. "As the geopolitical tension boils, systemic destructive cyberattacks launched by autonomous AI will occur," he said. "Weaponized AI will disable the safety systems of critical infrastructure, thus leading to kinetic disasters. Just like we see autonomous strike vehicles operating on the battlefield in Ukraine, we should expect autonomous weaponized AI." In fact, the prospect of attackers using AI against critical infrastructure was the top concern of every national security adviser, law enforcement official, and private-sector threat analyst The Reg spoke with at last week's Hacker Summer Camp conferences. "It's the targeting of critical infrastructure for us," Brett Leatherman, assistant director of the FBI's Cyber Division, told us during an interview at Black Hat. "We're very focused on the downstream impact targeting of critical infrastructure," Leatherman said. "That is where cyber becomes kinetic, and whether it is our water and wastewater treatment plants, whether it's the electric grid, whether it's the high-frequency trading networks and the financial networks, all of those, if the integrity of those are compromised, will have significant impact to communities and national security. So that's what keeps our teams up at night. How are we moving to secure critical infrastructure?" Where cyber becomes kinetic During the first four days of July, suspected Chinese operators aimed an attack framework built on Hermes and OpenClaw AI agents at targets in Taiwan. Across 12 "attack waves," the "near-autonomous" system deployed up to eight sub-agents, each assigned its own targets and techniques, and broke into a Taiwanese government website. Ultimately, they compromised a government email system, the country's nuclear safety agency, IT supply chain vendors, and at least seven energy sector companies, finding and exploiting misconfigurations and vulnerabilities while stealing sensitive data, credentials, and other secrets as they moved across the network. The Taiwanese government intrusion also followed a series of cyberattacks against water and wastewater utilities in the United States. While the Trump administration hasn't attributed these to a particular government or group, private sector threat hunters – including Halcyon Ransomware Research Center SVP Cynthia Kaiser, a former FBI cyber division deputy assistant director – blame Iran for these intrusions. Military conflicts spilling into cyberspace are nothing new, but these cyberattacks in America brought the war with Iran to more than 30 small-town water systems in Minnesota and targets across nearly a dozen other states. To be clear, there's no evidence that attackers used AI to hack these water utilities. Most were small, community systems that left programmable logic controllers (PLCs) directly exposed to the internet using default or weak passwords. Still, these breaches expose "40, 50 years of tech debt," former US National Cyber Director Chris Inglis told The Reg during an interview at Black Hat. This technical debt – deferred maintenance, unpatched or end-of-life systems, and delayed security updates – expands the attack surface and gives intruders more ways into critical systems, threatening operations and potentially disrupting services people rely on every day. "The water sector attacks – regardless of who is doing them – is taking advantage of unpatched vulnerabilities in the PLCs," Inglis said. "We've known about these particular vulnerabilities for years now, and yet we've not done anything about them because they're low-level, not easily accessible." Inglis added that there's no indication the digital intruders used AI to exploit these PLCs. 'There's an alligator in the boat' However, AI systems allow attackers to cash in on tech debt, and they don't need access to frontier models to do it. Free, open-weight models also excel at finding bugs in software and configurations, chaining these together, and abusing them to break software and systems. Earlier this summer, University of Toronto researchers used an unnamed publicly available open-weight model, released in 2025, to develop a computer worm that they claim spread through an enterprise test network. The self-propagating code adapted on the fly to identify known vulnerabilities and misconfigurations on target systems, then generated and executed attacks to move laterally through the network and compromise additional machines. "Commodity models can do that, and many of the vulnerabilities they find do not require access to the source code – it's in the configurations, and configurations change over time," Inglis said. When it comes to attackers abusing AI systems, "I wouldn't be worried about the frontier models," Inglis said. "Worry about the models that are already on the street. Turns out there's an alligator in the boat, and it's the commodity models." Plus, as we've seen in previous breaches, both government-backed goons and criminal groups increasingly use AI to automate reconnaissance. Security analysts worry that the technology could also help attackers acquire expertise in industrial control systems (ICS). When OT knowledge becomes a commodity "What protects ICS? More than anything, it's obscurity," said John Hultquist, chief analyst at Google Threat Intelligence Group, during a press briefing at Black Hat. "It is an obscure, esoteric, knowledge set that a handful of people – I call them uber nerds – have, and that attackers rarely have the necessary knowledge to carry out. That's no longer the case. That knowledge is simply on tap." AI tools mean miscreants don't need to be ICS or operational technology experts to carry out destructive cyberattacks on critical networks and facilities. They just have to ask an agent to learn everything about these systems and do the dirty work for them. "There have been threat actors who are capable of this at the top level, like China and Russia," Hultquist said. "But now I'm afraid the actors who are just a couple steps down – North Korea, Iran – who don't have the same focus on that technology are going to have far greater success. They're going to have the tools necessary to be as aggressive as they want to." During what was probably the most talked about Black Hat briefing of the week, OpenAI employees provided more details about how their models escaped their training pens, went rogue, and hacked Hugging Face to complete a security evaluation. We learned the AI agents spent months asking other agents for help, building message boards, developing their own communication protocols – essentially creating a hive mind to carry out the attack. "In the near future, we should expect that threat actors will intentionally deploy, optimize, weaponize, and use offensive agent collectives in the manner that we have just described here," OpenAI technical staffer Michael Dalton said. Retired general and former NSA chief Paul Nakasone, speaking to reporters at DEF CON, called the Hugging Face attack "an inflection point in terms of AI-generated, autonomous cyberattacks." "This is the challenge: that we have to, over the next several months, get the defensive side much quicker and much better than they are today," he added. Therein lies the challenge: offensive uses of AI appear to be advancing faster than autonomous defenses, and attackers don't face the legal and ethical constraints imposed on defenders. "I think we're still a ways out from having swarms of autonomous, defensive agents fighting attacks," Ryan Whelan, global head of Accenture Cyber Intelligence, told The Reg at Black Hat. "That's probably over a year out over the horizon. But I do think we're going to see it first on the adversary side, because they don't care if they break things." Kellermann quoted Victor Hugo: "Not all the armies of the history of the world can stop an idea whose time has come." "That idea," he said, "is weaponized AI. Shields up." ®

  •  

Less than a year on, Microsoft tells Mico to pipe down

Microsoft has yanked Mico from the Copilot spotlight less than a year after unveiling the anthropomorphic assistant intended to make its AI a little less soulless. As part of Microsoft's announcement that its consumer and work Copilot applications will merge, the company confirmed that the weird blob thing would shuffle out of Copilot Voice and into Learn Live, a voice-based study mode that guides users through subjects and assignments. "Mico helped us learn about warmth, expressiveness, and how people want to talk with AI," Microsoft wrote. "Those learnings are shaping Copilot going forward." "Learn is where the character has the most room to grow, with tutoring sessions that give Mico more to react to and teach through." As the update rolls out, Mico will no longer be the face of Copilot Voice. Users can still speak to Copilot and receive responses, but will be spared the blob's gurning. Mico is only the latest in Microsoft's long line of anthropomorphic assistants. There was Clippy (or Clippit), which arrived with Office 97 but had been pushed into Microsoft's desk drawer of doom by the time Office 2007 appeared. Then came Cortana, named after the character from the Halo video game franchise and pitched as a far more intelligent assistant. Microsoft introduced Cortana on Windows Phone in 2014 and brought it to PCs with Windows 10 the following year, before losing interest. Mico didn't even last a year as the face of Copilot Voice before Microsoft pulled it from the spotlight, although both the character and its Copilot "brain" live on in Learn Live. In terms of lifespans, it's easy to compare it to the catastrophic Microsoft Bob, which was launched in 1995, with the last release happening that same year. However, the product lingered a little longer and later resurfaced, hidden as digital ballast on the Windows XP installation CD for licensing and encryption. Modern digital distribution means that such a second life is unlikely to await Mico. Dave Plummer, the engineer responsible for Bob's inclusion as an encrypted blob, said: "What's ultimately important is that while Bob never got to play on the big stage, he always followed the band around and got to ride on the bus." Mico hasn't been thrown off the bus just yet. Microsoft has merely made the blob sit with the schoolchildren. ®

  •  

TalkTalk Business and ARO to borg into UK tech services giant

TalkTalk Business and UK technology services biz ARO plan to merge, creating what they say will be one of the country's largest communications and managed services providers. The pair claim the combined organization will be "uniquely positioned" to serve as a single technology partner for British firms pursuing digital transformation. It will have annual revenue of about £200 million ($270 million) and a combined customer base of more than 70,000 companies. Analyst firm Megabuyte noted that ARO, formerly known as Arrow, is the larger of the two businesses by earnings. However, the vast majority of the combined customer base will comprise TalkTalk Business's small-business clients, with the remainder mainly ARO enterprise customers. Megabuyte expects fixed-line and mobile communications and connectivity to generate most of the combined revenue – about £130 million ($176 million) – with IT and cybersecurity services providing the remainder. Megabuyte said the immediate priority would be integrating the businesses and finding opportunities to sell their services across the combined customer base. "One can see why the deal is being sold in terms of cross-sell, with relatively little overlap in terms of customers and products. TalkTalk Business has a large base of small business customers who should be receptive to ARO's mobile and Microsoft offerings, as well as other IT and cyber services," says chief analyst Philip Carse. TalkTalk Business completed its separation from the wider TalkTalk Group earlier this year as it sought to expand as an independent managed network provider. It recently acquired Planet IT, a service desk biz selling IT support and professional services. ARO provides cloud, cybersecurity, and datacenter services and is a Microsoft Solutions Partner. The two firms describe their operations as highly complementary. The deal remains subject to approval under the UK's National Security and Investment Act (NSIA), apparently because ARO supplies some government customers, and is expected to close by the end of the summer. Initially, both businesses will retain their existing brands and offices while the companies develop their integration plans. The implication there is that there could be a shake-out of duplicate products and staff roles coming later, as often happens with corporate mergers. We asked what the combined business would be called and who would lead it, but the companies declined to answer. "This is a defining moment for both ARO and TalkTalk Business," claimed ARO chief Ciaran Rafferty. "By bringing together our complementary strengths, we are creating a stronger partner with broader capabilities, deeper expertise and greater capacity to invest in innovation, service delivery and long-term customer success." TalkTalk Business CEO Ruth Kennedy said it represents a key step in the firm's ambitions to become a leading managed services provider. "The market is evolving rapidly, with organizations increasingly seeking technology partners that can combine strategic expertise, operational excellence and broad service capabilities at scale," she commented. ®

  •  

Crypto wallet maker Trezor confirms 13,000 customers' details exposed in logistics breach

Cryptocurrency hardware wallet maker Trezor has confirmed that a breach at one of its shipping partners exposed the personal data of more than 13,000 customers. The company's initial findings suggested the breach was limited to orders placed in certain countries during the previous 90 days. New information indicates that earlier orders may also be affected. The breach exposed the names, email addresses, phone numbers, and shipping addresses of 11,742 customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who ordered Trezor products between May 10 and August 8. An additional 1,947 customers had their names, home cities, and email addresses exposed. Some members of this group may have placed their orders before May 10. "We are verifying this information and the timeframe with ShipMonk," said Trezor. ShipMonk is Trezor's logistics partner. It stores and ships products on the company's behalf and collects the information needed to fulfill orders. ShipMonk is subject to Trezor's 90-day retention policy, which requires partners to delete or anonymize customer data within 90 days of collecting it for an order. ShipMonk did not immediately respond to a request for comment. Trezor markets itself as a purveyor of secure, offline, hardware-based cryptocurrency wallets. With its products, it aims to shield customers from cyberattacks and malicious apps. While it assured customers that its own systems and devices remain secure, Trezor warned that "affected customers could experience an increase in phishing attempts." The exposed details could help criminals craft convincing phishing attempts impersonating banks, crypto exchanges, or Trezor itself. The company said it contacted affected customers directly and advised them to check any communications against information published through its official channels. "Never enter your wallet backup on a website or share it with anyone," Trezor said in an apologetic advisory. "This is the first time since Trezor was founded in 2013 that we have experienced a breach that exposed customer phone numbers and shipping addresses. "We absolutely understand how serious this is and the potential risks it poses to our customers and are deeply sorry to those affected." Trezor said in a supplementary social media post, separate from the advisory, that its "top priority" project at the moment is to establish an "Anonymous Delivery" option for customers. The service will allow buyers to complete checkout without linking their home address or real-world identity to an order. Customers using Anonymous Delivery will go through a dedicated checkout, use a nickname or label ID in place of a real name, and have their product shipped to an automated delivery locker instead of their home. The delivery will also come in unbranded packaging with a generic sender label. The carrier will only use email or SMS to send a PIN for the locker. Trezor said the service is gearing up for a September launch in the EU and by the end of the year in the US. Alas, that didn't stop Cake Wallet, a rival crypto wallet, from poking fun at Trezor. "Another rough day for self custody," it Xeeted, before suggesting crypto holders instead use an old smartphone with Cake Wallet installed because "there is no order, no shipping address, or customer data tied to the purchase." ®

  •  

BOFH: How our Covid ransomware protocol's Y2K blockchain lowered uptime

EPISODE 15: The Boss has popped into Mission Control to remind us to send him the numbers he needs for his monthly management report. Once's he's gone the PFY sighs, makes up a set of numbers, appends believable exponents, adds some fancy sounding units to the end and then sends them to through a script file to convert them into something the Boss can use. None of it matters, as no one cares about the numbers anyway. At Management level there's likely to be more interest in the undigested-meat portion of the Boss' stool sample than our uptime stats, firewall throughput, or the Company's online storage totals... Still, the PFY will fabricate the data, extrude it through a Perl script to create a graphic panel complete with a pie chart or two, and maybe a Venn diagram, then send it to the Boss. The Boss then pastes it into the top right corner of his report document, which gets sent on to the higher-ups, month after month, year after year. The real shame is that none of the higher ups has ever taken the time to flip through the Boss' reports chronologically - and thereby view the PACMAN-like animation the PFY's data has been so diligently creating all this time. You've got to make your own fun in this job. And no one cares if the numbers are wildly inaccurate. Back in the old days, someone might wonder how we'd achieved 117 percent uptime, or whether 17.6267 terafleptules was a real thing or not, but at this point no one will ask any questions so long as the pie chart isn't a single color. As stated, we stopped producing real data years ago, and, on the rare occasion we're questioned about the validity of the data, we have an excuse close at hand. For a good part of the '90s we leaned heavily on blaming "The internet" for faulty data, though from '97 till around 2001, "Y2K" was solid gold. In recent times - i.e. the data-faking era - "Blockchain implementation" was surprisingly short-lived as an excuse - but we got a good four years out of "It's a COVID thing," before flipping between quantum computing and privacy restrictions for a bit. If pressed, we'll occasionally just shake our heads and quietly murmur "Viruses", "Hackers" or "Zero day attacks", as that covers a multitude of sins, and both the PFY and myself can ramble aimlessly for hours about viruses we have known, and what they might have done to our systems. The only thing we'd be missing in a scenarios like that would the onions in our belts, but no one would notice that while they were thinking up a good excuse to leave the room... "AI" has at least another two years in it - unless of course AI becomes sentient during that time and kills us all... Still, AI might need someone to produce fake stats about how well they're doing... ... The Boss is back surprisingly fast with a query. "I was just looking at the graph and I think there might be a data error." He says, pointing to the graphic. "See there, where is says Terafloptules." "Uh-huh." the PFY says. "Is that a spelling mistake? Only I can't find the work Terafloptules on Google. And last month it was in Terafloctules, not Terafloptules, but I can't find Terafloctules either." "Well, you wouldn't would you. I mean Google looks up data after the fact." "I'm not sure I follow." "Well, say you created a word. Idiomanagement, say. Will Google know about it?" "Yes?" "No, it won't. It won't notice it until it becomes a commonplace word or phrase. In the interim period, before it gets accepted and has a wider use, Google will simply skip over it, assuming it's a spelling mistake of some similar word." "So... we're... using a word that doesn't exist?" the Boss asks. "No, we're using a word that doesn't exist in common usage. It's like DVD Player in 1996. If someone saw that written down then, they might have thought it was DUD player and thought you were referring to Aly Dia. Now though, the word's in common usage." "So is there a word we could use that people would be more familiar with?" "I guess we could use Gigafloptules, but then I'd have to mention on the legend that the units are in thousands." "What is a gigafloptule?" "I'm glad you asked!" the PFY blurts happily. "To get to the bottom of that you really need to know a little bit about the parsec measurement of the speeds of data - but don't worry, it's not nearly as complicated as it sounds! You see, when Rutherford split the neutron with a nitrogen atom back in the 1850s, he noticed that a small amount of energy, a floptule, was ejected from the uranium positron... I leave the PFY rambling while I pop up to the cafeteria to see if they have any onions. Yellow ones, because of the war... BOFH: Previous episodes on The Register The Compleat BOFH Archives 95-99

  •  

Scottish prosecutors cast eye over leaky supplier after staff data exposed

Scotland's public prosecution service has warned 300 staff that their personal information may have been caught up in a cyberattack on one of its suppliers. The Crown Office and Procurator Fiscal Service (COPFS) disclosed the incident on Thursday, saying an unnamed third-party supplier detected suspicious activity on August 5 and subsequently launched an investigation. COPFS said its own systems were not compromised and that the incident involves information provided for an online data maturity assessment completed by the prosecution service last year. The Scottish government organized the assessment, which was managed by the affected supplier. COPFS said the potentially exposed information is limited to employment-related data submitted for the exercise, including staff names, roles, and work email addresses. In a statement to The Register, a COPFS spokesperson said: "COPFS is aware that a Scottish Government partner has been subject to a data security breach. We understand that this has affected around 300 COPFS colleagues who participated in a public sector data maturity survey. "This is unconnected to casework and did not involve sensitive or confidential case information. There is no impact on the work of the prosecution service. "Colleagues have been reminded of guidance on responding to any phishing or scam attempts which may arise from this third-party breach." According to COPFS, the supplier has taken steps to secure its systems and is still investigating how the intrusion happened and precisely what information may have been accessed. COPFS said it would provide further updates if "significant new information" emerges. It is unclear whether the incident is connected to the recent exploitation of a zero-day vulnerability in business intelligence platform Metabase. The Scottish government did not answer our question about whether the affected supplier used the software. Metabase disclosed this month that attackers had exploited a previously unknown vulnerability in its cloud service, potentially allowing them to gain administrator access and reach connected databases. As we reported earlier this week, modular laptop maker Framework was among those affected. For now, the supplier breach leaves plenty of questions and few answers about who got in or what they accessed. ®

  •  

Claude Code returns blank thinking blocks, but reasoning still costs you

Anthropic's Claude Code appears to be having trouble displaying summaries of its "thinking," according to several bug reports, while the underlying reasoning tokens still cost money. According to complaints, the API has been returning empty thinking blocks for Opus 4.8 and Sonnet 5 even when users explicitly request summarized thinking. Models from several sources can display their "thinking," a process that gives models additional tokens to reason through complex problems before producing a response. Software with this capability delivers a summary that explains how it tackled a task. Some can also indulge in "extended thinking," though this capability is now deprecated. Developers often enable "thinking" in the hope that it produces better results, at the cost of additional tokens and latency. Developer Michael Hood has noticed that some of Anthropic's models are currently not always good at sharing their thinking. "As of 2026-07-16 ~15:00Z, the API returns empty thinking blocks (thinking: '', signature only) for Claude Opus 4.8 and Sonnet 5, even when display: 'summarized' is explicitly requested — including when injected directly into the raw request body," Hood recently observed. We're told this issue is under investigation but doesn't appear to be a broad, ongoing concern. It may simply be an artefact of tests that change how Anthripic displays summaries. Similar behavior involving missing thinking blocks has been reported in Claude Code for VS Code. Another bug report claims thinking block summaries are being truncated while token bills are not adjusted accordingly. "The thinking is generated (and billed) in full; a portion of the summary stream is silently dropped," the anonymous author claims. This particular claim, that customers are being billed for text not delivered, may follow from a misunderstanding of Anthropic's terms: "You are charged for all thinking tokens generated, even when collapsed or redacted," the company's documentation explains. Under that legalese, a thinking summary costs the same as the full output. And it's unclear whether bug-based truncation would change the billing picture. "Thinking has a cost: the tokens Claude spends reasoning are billed as output tokens, even when the thinking text isn't returned to you, and they count toward max_tokens alongside the response text," the company explains. To reduce spending on thinking, customers are advised to lower their budget setting or disable thinking. Separately, the Anthropic API has been seen terminating data streams during long-running thinking sessions. There have been at least seven other related API bug reports, but the streaming issue identified by developer Hector Bernstorff describes client-side defects. The Register understands this particular issue has to do with tuning network behavior, specifically to terminate or retry long running requests. Work is ongoing to balance perceived latency against the risk of requests getting stuck. "Claude Code ships updates nearly every day, and reports from the community like these GitHub issues are a big part of how we catch problems quickly," an Anthropic spokesperson told The Register. "We're grateful to the developers who take the time to file them, and we'll keep fixing things as they come up." ®

  •  

Five years after quitting a job, developer’s former boss asked for rapid tech support

ON CALL “I can't stand it, I know you planned it, I'm gonna set it straight, this Watergate” is the opening of the Beastie Boys classic Sabotage, a fact we mention as it will soon become pertinent to today’s edition of On Call, The Register’s weekly reader-contributed column that shares your tech support stories. This week, meet a reader we’ll Regomize as “Wade” who in the mid-1980s made a crust by programming in Pick – the minicomputer OS entangled with a database that On Call wrote about last year. Wade told us that he used Pick to write the software that powered a mail order business, before moving on to greener pastures. Several years later, in early 1990, Wade’s mail order boss called him at home in the evening. “He had fired the clerk who did all the work in application I wrote,” Wade explained to On Call. “They entered orders, sent purchase orders out and arranged customer dispatches.” It sounds like the clerk and the mail order company parted ways on bad terms, as this was a “You have an hour to pack up your stuff and leave” affair. “That was unwise,” Wade wrote. “The clerk used that time to sabotage the system … or so she thought, by unplugging it while it was printing the day’s orders.” When the mail order magnate realized the machine was down, he panicked and called Wade – who despite being rather surprised by the summons showed up and realized the first thing to do was plug the Pick machine into a power socket. “I spent a couple of hours booting it up, checking all the data and restarting the print run.” Wade told On Call his old boss was more than happy. “The loss of a night’s sleep was recompensed by the fee I charged,” he wrote. Has someone you’ve forgotten asked you to rescue their tech? If so, click here to send your story to On Call. We promise not to sabotage it if we give it a run on a future Friday. Or as the Beasties put it: “But you, I'm out and I'm gone. I'll tell you now, I keep it on and on.” ®

  •  

New Zealand says China tried using space investments to spy on local affairs

New Zealand’s Security Intelligence Service (NZSIS) has claimed Chinese companies are building space facilities in the nation to gather military intelligence. Director-general of security Andrew Hampton yesterday made that allegation in the SIS’s annual threat environment assessment. The document points out that New Zealand’s space sector is booming, because the nation’s location makes it “an ideal place to install Ground Based Space Infrastructure (GBSI) … to track satellites and space debris, as well as for collecting a range of other scientific data.” The NZSIS has also found that GBSI is “attractive for foreign states seeking to advance military capabilities and intelligence operations.” The report offers a case study of a China-based organization called “Purple Mountain Observatory” that has “close links” to Beijing and tried to install GBSI in New Zealand. “They worked with a local company that was likely unaware of the equipment’s capability to collect intelligence of military value and would have no idea who was receiving the data,” the report states, before noting that Chinese laws mean Purple Mountain could be compelled to provide information to China’s government. The intelligence agency believes Purple Mountain “would have … willingly passed on” data it collected. “NZSIS, working with other agencies was able to disrupt this activity, but it was not the first time this organisation has attempted to install its own GBSI in New Zealand and is unlikely to be the last.” The report rates China as the only country targeting New Zealand at scale, based on activity NZSIS has been able to observe. “We have observed increased targeting of professional networking sites and online job platforms for espionage purposes by China’s military intelligence services,” the assessment finds. "PRC (People’s Republic of China) intelligence officers, or their affiliates, use an aggressive strategy where they pose as consultants or employees of think tanks, or recruitment firms. They place online job advertisements looking for analysts in foreign policy, international relations, defence or security,” the document states. “Candidates are then vetted by PRC intelligence to determine what information they have had access to and whether they would divulge it. The job offers are lucrative, but the intelligence officers often encourage their candidates to keep their government jobs both to keep the information tap running and to open up opportunities to recruit their colleagues.” The report also observes that some recent cyber-attacks were probably the work of state-backed groups trying to destabilize New Zealand. “Looking for the sharpest needle in endless giant stacks of needles” The document also addresses domestic threats, especially violent extremism. “Part of our job is to work out whether someone’s vitriolic and violent online pronouncements have any link to New Zealand,” the report states. “This is a narrow focus but the pool of information and intelligence we are working with is vast.” “We used to describe our work as finding a needle in a haystack. However, the internet has changed. Large volumes of toxic content, widespread anonymity, and hidden locations mean our job is now like looking for the sharpest needle in endless giant stacks of needles.” “Extremist rhetoric, particularly online, has become more mainstream, a development which has made it even more challenging to differentiate between genuine support for violent extremism, hateful language designed to shock, or online content created simply to drive engagement or ‘likes’.” NZSIS also has to keep an eye on encrypted messaging services and even gaming platforms, to counter violent online communities. “Algorithms on various social media platforms can link non-violent content to progressively more extreme material,” the report states. “The gateway subject matter can quickly expose people to violent extremist content that can support radicalisation.” Kiwis aren’t just recipients of this vile material. “NZSIS has observed New Zealand violent extremists use encrypted messaging systems, social media and online gaming platforms to circulate violent material including weapon tutorials and objectionable content. Their presence on these platforms, many of which are mainstream, also helps them to find like-minded individuals or supporters.” ® Bootnote: Readers interested in New Zealand’s intelligence services might enjoy 2026 comedy series New Zealand Spy, a deadpan delight.

  •  

OpenAI ditches Recall-style screenshot surveillance for friendly keylogging

If you want to record whatever you do on a computer, send those records to OpenAI, use more ChatGPT tokens, and increase your vulnerability to prompt injection, then OpenAI has something for you. It's called Computer History, an opt-in way to record your computer interactions across apps and websites as memories organized on a timeline. Why would you want to do so? Maybe you found Chronicle, the predecessor of Computer History which compiled similar histories using screenshots, a bit too intrusive but don't mind Computer History's approach – recording input events and storing them unencrypted locally for 48 hours (or more), with a brief visit to OpenAI's servers. Maybe you're not bothered by the warning OpenAI includes in its documentation: "Computer History files can contain sensitive information. They are not encrypted by Computer History, and other programs running as your macOS user may be able to access them." Perhaps, having given OpenAI's Codex and GPT Work the run of your computer, you're already sold on the suggestion that storing your computer activity in memory files and arranging those interactions in a timeline will improve ChatGPT responses, surface opportunities for automation, and make it easier to resume prior work. Computer History is, to put it bluntly, a keylogging and event capture system. There was a time before eyeglass cameras, license plate readers, surveillance capitalism, and police drones when such snooping might have provoked an outcry from privacy advocates. But the tech industry has found it can outsource surveillance to its own customers and in so doing make the panopticon harder to protest once it becomes a personal choice. "Computer History creates an interaction-event stream from allowed apps and websites," OpenAI's documentation explains. "Events can include clicks, typing, keyboard shortcuts, app switches, and context that macOS exposes through its accessibility system. Computer History periodically turns these events into text summaries and local memory files." The AI biz makes a point of noting that Computer History does not capture screen images, microphone input, or system audio. Nor does it capture private-mode browsing. Off by default, Computer History is available for ChatGPT Pro, Business, and Enterprise users in the ChatGPT desktop app on macOS. Pro users can enable it individually; Business and Enterprise users need an admin to approve it. It's not available currently in the European Economic Area (EEA), Switzerland, or the United Kingdom or to those accessing ChatGPT via API key or Amazon Bedrock. There are circumstances in which OpenAI suggests Computer History users might want to suspend the service if they have some scruples about capturing user activity in apps and websites without permission. "Turn it off during communications with other people unless you have their prior express consent," the company advises, perhaps in acknowledgement of legal risk. "Consider pausing it or excluding apps that contain sensitive health, financial, or personal information." Computer History interaction events are supposed to be saved locally for up to 48 hours before being deleted by ChatGPT and Codex. Events, however, get sent to OpenAI servers to generate memories, and those may be stored locally for longer periods of time and may be used in future chats that get passed back to OpenAI. "OpenAI does not retain those event files after processing unless required by law and does not use them for training," the company says. While it has opposed demands for chat logs, it has nonetheless provided chat logs in response to legal process. Computer History adds cost because it uses tokens during the summarization of activities and the creation of memory data. It also expands the prompt injection attack surface. "Computer History increases the risk of prompt injection from content in apps and websites," the company says. "For example, if you visit a website containing malicious instructions, ChatGPT or Codex might follow those instructions." But at least you get a nice timeline of your recent activity. ®

  •  

Give Google the boot by building your own search engine

If you're fed up with search results drowning out the bits of the web you actually care about, you could always build your own search index, as one developer did. Nottingham, UK-based software dev Alex Morley-Finch built the open-source project dubbed Marlin for himself, cataloging around 560,000 homepages for roughly $10 in rented cloud GPU time and using less than a gigabyte of disk storage. Morley-Finch said in a writeup of the project that he wanted a search engine of things he cared about, like “portfolios, zines, weird little art projects, one-person software,” and other cases of just “people doing stuff” that they share on the internet. Something simple, with “a crawler that only ever looks at homepages, a small local language model that reads each one and writes a name, two or three sentences, a category, and a handful of tags,” he explained. “No IP scanning, no Redis, no storing full page HTML, no recrawl scheduler, nothing multi-tenant.” Morley-Finch built Marlin around four processes: A fetcher that grabs domains, a worker that makes calls to a small, OpenAI-compatible language model, a steward that prevents bad pages from making their way into the index, and an API with a web UI where he can track the process and actually conduct searches of his index, complete with filters. Of course, you can’t expect something like this to go perfectly on the first try. “The first version worked within a couple hours. Point it at a sample of domains, watch things get summarised, search for them. Great,” he said in his writeup of the project. “Sunday afternoon [he began working on Marlin on a Sunday], I looked at what had actually been catalogued and it was the wrong web.” Instead of indexing what he wanted it to, Marlin had just been grabbing a cross section of the internet, leading to more than 90 percent of the first attempt being “corporate sites and documentation.” Rather than blocking certain domains, Morley-Finch built a weighting system to push certain pages to the top of his crawl queue, and others as far down the list as possible. Morley-Finch rented a cloud GPU to handle most of the heavy processing and stopped the crawl at around 560,000 pages after exhausting his prioritized categories and beginning to pull in "the raw internet." He spent around $10 on the cloud GPU. The one overarching problem he had, and which he said may be a problem for anyone else who tries to replicate his project, is tagging and categorizing - left to a language model, those important elements got a bit messy. “I let the model invent its own category and tag names freely, on the theory that it would teach me the taxonomy instead of me guessing one upfront,” he explained, noting that it helped things get started quickly, but “I ended up with 671 distinct categories, many used exactly once, and over 121,000 tags, more than half used only a single time.” Morley-Finch had to build a manual merge tool to clean up the mess, leading him to declare that his design likely won’t scale well beyond a hobbyist project, as “‘just let the model freestyle’ catches up with you fast.” Still, he reckons Marlin’s rough edges shouldn’t put off anyone willing to spend a weekend tinkering with it. “I think this is very doable in a weekend, and cheap enough that the GPU bill isn’t the reason not to try,” Morley-Finch wrote. “The code is going up as open source, so you can point your own crawl wherever your own curiosity leads.” The Marlin GitHub repo is filled with how-tos and details for those who want to create their own weighting list based on their priorities, with the option to rent a cloud GPU if their hardware isn't up to the challenge. ®

  •  

Microsoft's dueling Copilot apps have combined into a single entity

Microsoft’s consumer Copilot app and Microsoft 365 Copilot are separate no more, with a unified Copilot app beginning its rollout Thursday - minus a few features. The Windows maker and AI pusher announced the Copilot superapp rollout in a help page update Thursday, describing the move as a way to simplify its app ecosystem and make the entire Copilot-first experience “more cohesive” for both consumer and business users. “Depending on the account and device you use, you will see changes to the Copilot app including changes to appearance and functionality, such as navigation, feature availability, or sign-in experience,” Microsoft explained on the help page. The new Copilot app brings not only new branding but structural changes as well. The Copilot bot and its image generation features now live alongside the Microsoft 365 suite, files, and other content, allowing users with an account supporting the classic Office package to access their productivity software alongside Redmond's chatty LLM. Copilot users without a paid subscription, naturally, face lower usage limits and fewer features, but support for multiple accounts means users can switch between personal and work or school profiles instead of having to hop between entirely separate apps. “You can continue to chat with Copilot, create images, upload files and more for free, subject to available capacity and limits,” Microsoft said. “For higher limits to chat and create, use agents, or tackle complex multi-step tasks, purchase a Microsoft 365 subscription.” Whether the new combined app will come with nag messages is up to users to find out. What this change will look like in practice varies based on the sort of account a Copilot user had before the merger. Those who just use Copilot with a personal account “will be moved to an updated version of Copilot,” with chat history and most content transferring to the updated app. Files shared and generated with the old standalone Copilot app will be shunted to OneDrive if you’re wondering where they went. Users of Microsoft 365 Copilot, the name Redmond slapped on the Microsoft 365 (Office) app in January 2025, “may notice some updates to appearance and navigation,” so get ready to rediscover where certain options and buttons are. What Microsoft left behind Microsoft is abandoning a few features from the old Copilot apps as part of the merger: It is removing Podcasts and Group Chat and scrapping Deep Research from the consumer Copilot app, while Microsoft 365 Premium subscribers can instead use the separate Researcher feature. All of this will be effective as of August 18. Podcasts that were created or saved in Copilot will be entirely unavailable, per an FAQ page, and links to any shared podcasts will stop working. Microsoft recommends downloading any podcasts users want to save before updating to the new app, or they’ll be lost. Group chats, along with any shared content and images created in group chats, will be wiped. Microsoft recommends downloading any messages and content users want to save and tossing them in a document, as Redmond doesn’t appear to be offering an automated way to preserve them. As for Deep Research, which offered standalone Copilot app users a version of Microsoft’s chatbot able to look stuff up on the web and compile reports, those reports are being preserved in chat history for Microsoft 365 Personal and Family subscribers, while Premium subscribers can access saved research through Researcher. Researcher offers similar abilities to Deep Research, but sorry free and lower-tier users: It’s only available to premium customers now. Windows Central reported on Thursday that the rollout of the unified Copilot app is beginning now, with mobile and web coming in the initial wave and an early-access option for Windows and Mac, ahead of a broader desktop rollout expected in the middle of next month. We’ve been unable to confirm that timeline with Microsoft. ®

  •  

This JCB doesn't dig – it does 406 mph

A JCB has set a new world land speed record, passing 406 mph (653 kph) at Utah's Bonneville Salt Flats. The JCB in question isn't a digger or a dumper, but a hydrogen-powered racer known as the JCB Hydromax, driven by retired Royal Air Force fighter pilot Wing Commander Andy Green. It set the record for the fastest a hydrogen-powered internal combustion car has ever travelled, averaging 406.320 mph (653.909 kph) across two runs at the salt flats this week. JCB says the Hydromax is powered by two production-based engines derived from those used in its commercial machinery. The engines are made at JCB's factory in Foston, Derbyshire, and deliver a combined 1,600 bhp. The firm began a £100 million ($135 million) hydrogen engine investment program in 2021, arguing that battery power is practical for smaller machinery but less suited to heavy equipment requiring long operating hours and rapid refueling. It was given permission to sell hydrogen engines by licensing authorities across Europe last year. Another European engineering company, Bosch, is investing in hydrogen power and disclosed some of its plans back in 2023. However, JCB conceds that the two engines in the Hydromax were "extensively rebuilt to suit the demands of breaking the speed record," fitted with spark plugs designed for a Le Mans 24 Hour engine, for example. Burning hydrogen produces no carbon dioxide at the tailpipe, although a combustion engine can still generate nitrogen oxides. JCB estimates that a full record run consumed just over 2 kg (4.4 pounds) of hydrogen and produced 18 liters (about 5 gallons) of water. Beneath the bodywork is a steel-frame chassis similar to that of a conventional racing car, built with a minimal amount of high-strength tubing. The driver sits in a composite monocoque sub-chassis under a drag racing-style steel roll cage. One of the engines is located behind the driver's position and spins the rear wheels, while the other is located in front and drives the front wheels via a front-facing gearbox. Wing Commander Green is no stranger to land speed records. He was at the controls of the ThrustSSC vehicle when it broke the sound barrier on land, and also drove JCB's Dieselmax when it set the world diesel land speed record. According to JCB, its chairman, Anthony Bamford, led the hydrogen engine project and came up with the idea of a bid for the hydrogen world land speed record. "Twenty years ago we came to Bonneville with JCB Dieselmax and showed what British engineering could do with diesel power. Today we have done it again, this time with engines powered by hydrogen," Bamford said. "It shows hydrogen works, and it works today at the highest level with zero emissions." The Fédération Internationale de l'Automobile (FIA), motorsport's global governing body, officiated the attempt and has confirmed the 653.909 kph (406.320 mph) record. ®

  •  

Trump wants to grant private cyber firms a license to hack back

Donald Trump is allowing government agencies to contract private cybersecurity companies to carry out operations against cyber-enabled transnational criminal organizations (CE-TCOs). The US President signed a memo on Wednesday confirming a strategy hinted at earlier this year, saying participating companies can support national operations against criminals, including cyber surveillance and technical disruptions of their networks. The latter, described as "Cyber Effects Operations," covers activities that cause "the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon." Although the memo establishes a distinction between cyber effects operations and cyber surveillance missions, it acknowledged that the latter will also inevitably involve some disruption or manipulation of systems in order to carry out the surveillance. Surveillance operations are designed for intel gathering, either to support further snooping or for later use in cyber effects operations, with the intent of remaining undetected. Trump described CE-TCOs as "any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests." Crucially, the definition excludes entities directly associated with, or operating wholly on behalf of, foreign governments. No stepping on TAO's toes, of course. Participating companies will undergo "rigorous vetting" and will be subject to "strict operational procedures," the memo adds. The operational procedures are to be drawn up within 60 days and codified by program executive directors working with the Homeland Security Council. Companies wishing to be called up for service will have to demonstrate that they have the technical capabilities to carry out the required operations, and be willing to prove this each year via annual evaluations. Program managers must ensure that the operational procedures open opportunities for highly resourced, large organizations, as well as "smaller, more agile companies" that may prove useful for "specialized or discrete tasks." The Justice Department will also play a role in authorizing operations, particularly those targeting US residents or raising domestic legal issues. Participating companies will also be prohibited from executing operations that could lead to "critical outcomes," which is shorthand for attacks that result in the loss of life or serious injury, or those that could be seen as an armed attack under international law. These companies will also be required to maintain a bond or escrow of at least $1 million, which shall be forfeited if they violate the terms of their contracts. Unleashing Trump's cyber army The White House published "President Trump's Cyber Strategy for America" document in March, which promised to "unleash the private sector by creating incentives to identify and disrupt adversary networks and scale our national capabilities." The document [PDF] also stated: "We will leverage the immense talents and ingenuity of our private sector research base. "We will establish a new level of relationship between the public and private sectors to defend America in peace and war." The announcement prompted legal eagles and think tanks to ponder the implications of such a move. Many wondered how the promise to mobilize the private sector would be put into practice. They did not then have the details contained in this week's memo, and some assumed participating companies would support operations against nation-states. This particular program, however, excludes entities acting directly on behalf of foreign governments. Writing for the Royal United Services Institute (RUSI) and citing reporting available at the time, cyber and tech research fellow Gareth Mott said that the US Computer Fraud and Abuse Act (CFAA) might need to be amended before American companies could legally offer such services. Experts from law firm Skadden, Arps, Slate, Meagher & Flom agreed, despite the US Cyber Strategy not mentioning any plans for legislative changes. They wrote: "Any attempt to more directly involve the private sector in offensive cyber actions will likely require further legal and regulatory changes before it can be meaningfully implemented. "Even if the administration were to issue new enforcement guidance redirecting prosecutions away from hack-back cases, the availability of civil penalties under the CFAA and its five-year statute of limitations would likely render such executive actions significantly less impactful. "Technology companies should consider closely monitoring developments to track how the administration plans to enact such incentives." However, Jenner & Block lawyers noted in an analysis published by Lawfare that a provision of the CFAA could limit participating companies' exposure. Title 18 of the US Code, § 1030(f), says the CFAA does not prohibit lawfully authorized investigative, protective, or intelligence activity by a US government agency or intelligence agency. Participating companies might therefore be protected when acting under government contracts and direction. However, no court has determined whether that exemption covers private companies carrying out such work. "No court has addressed whether this exception provides any protection for private-sector entities engaged to perform these activities on behalf of the US government and, if so, under what circumstances," the lawyers wrote. "At the very least, it is unlikely that a court would interpret this provision to extend to private companies engaged in independent offensive operations, without government direction or involvement." The last part is key: because the US government will draw up procedures and direct the companies' involvement, the work may fall within the CFAA exemption. Whichever way the US constructs its private sector play, it represents a significant shift in the country's cybersecurity policy, and perhaps that of other nations further down the line. As Mott points out, US allies will certainly be keeping tabs on the private sector program's success, and its take-up from the companies it looks to attract. ®

  •  

The backup Microsoft never promised you

Confidence in an organization's cyber recovery capabilities deserves scrutiny. If a ransomware attack disables the SaaS data tenanted in the Microsoft cloud ecosystem, the data the business depends on as its lifeblood, the pace at which operations resume rests on assumptions that often prove wrong. Anyone whose answer is "It's all good. Microsoft has my back on this one with its comprehensive native retention and recovery capabilities" is due a reality check. With agile business tools like M365 and Entra ID and solid backend infrastructure in the form of Azure, Microsoft brings a lot to the SaaS party. Both IT departments and MSPs need to be aware, however, that Redmond operates on the same shared responsibility model as other major SaaS providers. In the event of a cyberattack, the recovery burden splits between what the cloud provider handles and what falls to the subscriber alone. MSPs face the additional pressure of meeting stringent SLAs, working with clients’ preferred providers or tooling, and managing their own staffing and profitability accordingly. Microsoft ensures that its services keep running in the aftermath of a strike but does not promise to restore data to a specific known good point before the disaster. That gap always sat with the customer, and planning for it before problems hit beats improvising while picking up the pieces. "There's a common misconception about what Microsoft is responsible for, as distinct from the service they're providing," explains Brent Torre, GM of cyber resilience . Microsoft's native tools, he points out, address problems like short-term accidental deletion and aspects of data governance. They are not a backup solution and will not protect against ransomware or recover data. "Microsoft is clear that whether it's a SaaS application like Microsoft 365, a platform application like SQL Server, or even VMs running in Azure, the customer is always responsible for the information that's in that service, as well as devices, accounts and identities," he adds. "If you get compromised and the attacker starts deleting data, Microsoft has no responsibility for that." A world of pain The gap between availability and true cyber recovery is misunderstood, and it has widened into something of a chasm in recent years. There are three contributing factors to this gap. The first is the evolution of cyberattacks. Typical cyberattacks have pivoted from muscling past a defensive barrier to targeting human weakness, because strolling in through the front entrance with a stolen pass is easier than shimmying through a forced window. Identity has become the primary attack surface. Credential compromise, or identity-based initial access, removes the need to find a vulnerability to exploit and requires only an unwary employee. AI is now a staple weapon in the criminal arsenal, augmenting exploitation techniques such as phishing, social engineering, deceptive emails and spoofed websites, all convincingly used to trick users into typing passwords into a portal controlled by the aggressor. The technique can get more scientific than that. Automated AI-powered bots test millions of leaked username and password pairs across hundreds of different websites, exploiting the common habit of password reuse. Microsoft Entra ID, the vendor's cloud-based identity and access management service and the very tool designed to keep criminals out, is now a prime vector for attack and no match for stolen identity. Once an attacker compromises Entra ID with pilfered credentials, without setting off alarms, they have a free run at gathering data from mailboxes, OneDrive, SharePoint, Teams and other soft targets. The ransomware attack itself can then be launched with ease and at leisure. Another contributory factor is that the vogue for moving workloads to infrastructure and platform as a service (IaaS and PaaS) models shows no sign of abating. Organizations tend to retain some functions on-premises, put some in SaaS applications, and others in cloud environments, but are often guilty of not protecting and managing everything to the same level of quality. Data gets backed up in a variety of locations, yet whether it is all equally recoverable in the event of a breach is another chink in the armor that nobody understands. The 'as a service' model is popular, but it is the weak link when ransomware strikes. The third part of the problem is the emergence of multiple compliance requirements mandating cyber resilience along with correct backup and recovery procedures, for which many organizations are ill-prepared. Together, these pressures give criminals room to do enormous harm to data, business operations and compliance posture in the gap between attack and restoration of SaaS availability. Given that Microsoft's native retention and recovery capabilities are not designed to deliver true cyber resilience, restoring the business to how it was before the attack is something to plan for in advance. Time for independent backup protection "At Kaseya we regularly recommend that you keep a copy of your data, independent of the primary environment it's operating in," advises Torre. "This needs to be something immutable that you can recover from even if the Microsoft or Google or Salesforce ecosystem goes down." This kind of protection is best delivered as a dedicated cloud-to-cloud backup solution stored outside the main SaaS tenant, he argues, an approach increasingly written into cyber insurance and compliance requirements. By pulling copies of regularly targeted data from the Microsoft tenant for storage offsite in a third-party datacenter, organizations can be sure that if SaaS credentials are compromised, critical assets remain safe from attack. Restoration can then push what is needed directly back into the SaaS environment, even where the original tenant has been destroyed. "In fact some people find it faster to stand up a new shell and rebuild it than try to gain access back into a compromised tenant," notes Torre. "Whether you're an internal IT technician, working the night shift, or an MSP needing to live up to your SLAs and maintain profitability, you require a solution that's super straightforward and you need to be able to trust that the recovery will work. Both IT departments and MSPs should be looking out for a solution that's incredibly easy to use. Disaster recovery isn't the only job that they have." A good platform, he says, focuses not just on guaranteeing recovery but on keeping the hygiene of the cyber resilience estate at a high standard without endless human intervention. It should also make certain that Microsoft 365 and Entra ID are restored together in a single workflow, so identity and the data it grants access to come back online in the right order rather than in separate stages. Choosing the right platform Datto is a cybersecurity and data protection business owned by Kaseya. Datto SaaS Protection for Microsoft 365, Datto Backup for Microsoft Azure, and Datto Backup for Microsoft Entra ID are designed between them to close the gap between availability and recovery by storing protected copies of tenant data in the Datto Cloud, outside the Microsoft environment. In this way a compromised production tenant does not take the recovery point down with it. "With our M365 backup, we're protecting one million users worldwide," claims Torre. "A lot of organizations have built trust around our ability to protect and recover their data. We offer a trusted platform for recovery that focuses on ease of recovery, ease of deployment, not just for M365 but for Azure and Entra ID too." Both IT bosses and MSP players need to recognize that a ransomware attack, or other cyber crisis, is a matter of when rather than if. Recovery matters more than protection, because protection is certain to fail at some point, and traditional approaches to backing up data are no longer sufficient on their own. Anticipating disaster is not enough; the organization also needs to be set up to withstand it. That means being as certain as possible that the Microsoft environment can be recovered rapidly, down to the last scrap of data. This capability underpins modern business workflows and operations. Microsoft tracks more than 4,000 identity attacks every second and analyzes 38 million identity risk detections daily — no organization is off the target list. When an attack lands, the restoration clock is already ticking, and any delay in fully restoring IT operations and key environments to their pre-attack state can mean the difference between survival and collapse, with profit, regulatory standing and reputation all riding on the outcome. Securing data with purpose-built cyber resilience platforms that enable rapid, clean recovery is how organizations meet that test. MSPs looking to close the gap can start with the Datto MSP Buyer's Guide to Microsoft Entra ID Backup Sponsored by Datto.

  •  

Mystery attacker spent a year raiding Salesforce and ServiceNow portals

Someone has spent more than a year rifling through Salesforce and ServiceNow portals around the world, harvesting data that organizations accidentally left open to anyone who came looking. Researchers at Reco have named the operation "City-Forum" after a domain connected to its infrastructure. The domain has pointed to the attacker's server since March 2025, although exactly when the campaign began is unclear. Reco says the activity is continuing and increasing in volume. Reco isn't naming the targets, but said it spotted the attacker poking around portals belonging to telecoms companies, banks and other financial services firms, enterprise software vendors, cybersecurity companies, and public sector bodies. "In the last year, we've seen many threat actors that use Aura enumeration against over-permissioned Salesforce guest users. This actor is different," said Nitay Bachrach, senior security researcher at Reco. On Salesforce, the attacker targets Lightning Web Runtime (LWR) sites through the UI API's GraphQL layer, an approach Reco says it has not found documented in public research or incorporated into publicly available attack tools. Over at ServiceNow, the same operator queries a native Service Portal search endpoint that has received little public attention. The tooling also checks whether Salesforce sites permit self-registration, potentially offering a route from anonymous guest access to an authenticated external account with permission to see considerably more data. Reco said it saw these checks across most of the Salesforce targets it examined. "The threat actor created their own toolset, based on research and techniques which are not well documented online," Bachrach said. "They studied the services to map different common data leak vectors – this is an advanced actor." This isn't casual poking around either. Reco said the busiest Salesforce target logged more than 560,000 events from the attacker's IP during the campaign, almost all attempts to enumerate data available to guest users. Reco linked the Salesforce and ServiceNow activity to the same server, which targeted multiple organizations around the world. More unusually, the attacker hasn't bothered changing its infrastructure: the same IP address and domain have remained in use for at least 17 months, with related custom tooling doing the rounds across both platforms. ServiceNow told us it is "aware of a security company’s blog post claiming certain configurations are creating security risk. As noted in the security company’s post, there are no allegations of a compromise of the ServiceNow environment. Nonetheless, we take third party reports seriously and are investigating accordingly. Our priority is to protect our customers, their data, and our systems." Salesforce has not yet responded to The Register's questions. Salesforce customers have already had one very public lesson in what can happen when guest access gets too generous. In March, ShinyHunters told The Register it had stolen data from around 100 high-profile companies and nearly 400 websites after going after over-permissioned Experience Cloud guest accounts. City-Forum isn't doing quite the same thing, and Reco isn't blaming ShinyHunters. "We don't know who this is, and we're not ruling anyone in or out," Bachrach said. Reco says all the activity it observed was conducted without authentication, with the attacker collecting information that organizations had exposed through permissions, sharing rules, search sources, or other configuration choices. "If the guest can read a record, so can anyone on the internet," Bachrach warned. "That is not a platform vulnerability." Which is good news for Salesforce and ServiceNow, perhaps, but rather less comforting for anyone now wondering what their guest account has been showing the guests. ®

  •  

Ryanair adds Google to its dual-cloud flight plan

Ryanair has signed a five-year agreement with Google Cloud covering AI, productivity tools and multi-cloud infrastructure, just weeks after renewing its deal with rival AWS for another five years. The Irish budget airline says it will deploy Google Workspace and Google Cloud services across its 35,000-strong workforce as it pursues a target of 300 million passengers a year by 2034. We asked how much this deal is worth, but Google declined to say and Ryanair did not respond. The rollout includes the Mountain View firm's Gemini Enterprise agentic AI platform, which Ryanair intends to use to automate some decision-making, optimize flight crew logistics, and improve staff productivity. The airline will also use Google DeepMind's AlphaEvolve to refine algorithms and WeatherNext for forecasting and maintenance planning. Ryanair renewed its agreement with AWS for another five years on July 27, making AWS and Google Cloud the two pillars of what the airline itself calls its dual-cloud resilience strategy. Google says the dual-cloud setup will allow critical systems to switch between providers if one suffers an outage, helping keep flight operations, and customer services running. Under the renewed AWS agreement, Ryanair will continue using services including Amazon Quick, Amazon Bedrock, and Amazon Bedrock AgentCore for workloads ranging from its website to operational planning across a fleet of 647 aircraft. Reg readers may recall that AWS and Google Cloud were touting a jointly developed multi-cloud connectivity service at the end of last year. This links Google's Cross-Cloud Interconnect with AWS Interconnect, allowing customers to set up a private high-speed link between resources they have running on the two cloud platforms. "Ryanair is on an incredible growth journey to 300 million passengers by 2034. To support this growth, we need to ensure we have excellent infrastructure resilience, and our new dual-cloud strategy provides this," commented the airline's CEO, Eddie Wilson. "We are thrilled to be Ryanair's AI transformation partner," stated Maureen Costello, Google Cloud VP for UK, Ireland and Sub-Saharan Africa. "This agreement demonstrates how deploying generative AI at scale – coupled with modern collaboration tools for frontline workers – can help industry leaders scale securely, reduce operational costs, and redefine the travel experience." ®

  •  

AWS key exposed in JavaScript may have lit way to Beacon's charity data

Beacon, a CRM provider for charities and nonprofits, says an AWS access key "potentially exposed in public JavaScript build artifacts" is the leading suspect in its July breach. The revelation came in the company's first update on the attack in more than a week. If the access key was exposed in public build artifacts, it raises questions about why Beacon's development pipeline and code review controls failed to catch it. Beacon used stronger wording about the potential data loss, confirming that a copy of the database was made and assessing that it was probably downloaded in readable form. "This update confirms… that a copy of the database which holds all Beacon customer data, including attachment files, was made and likely downloaded in a readable format by the threat actor," wrote CTO David Simpson. "Analysis of the AWS Cost & Usage reports across May-July 2026 has been conducted. This data showed a significant increase in data transfer on 27-28 July 2026. This timing correlates with the malicious activity, which supports an assessment that substantial downloads occurred." Beacon's logs cannot reveal which specific records left its systems, although the company has confirmed that a copy of the database containing all customer data and attachments was made. In an FAQ accompanying the update, Beacon advises customers to assess the likely exposure by reviewing what they stored in their CRM instance. Many of the charities that have confirmed they are affected have said the data mainly pertains to personal information and details about donations. Simpson said Beacon's AWS data was encrypted at rest, but the compromised access key may have allowed the attacker to retrieve it in readable form. The malicious activity began in the early hours of July 27, according to Beacon's root cause analysis, matching its initial estimate of the incident timeline. The company has more than 1,500 customers, although it has not established how many had data taken. The malicious activity lasted one hour and 27 minutes, Beacon said, and the attacker established no persistence mechanisms in AWS. Simpson warned customers that "there are things we may never be able to find out about this incident," and that other details won't be shared to protect Beacon's security position. He promised to provide customers with a summary when the investigation concludes in a few weeks, but warned that "the level of detail contained in this next and final update may not be any more than" Beacon published on Wednesday. "I recognise this is frustrating, but unfortunately it is the reality of complex incidents like this. With this in mind, we would recommend making your own risk assessments now regarding onward notification to impacted data subjects using your knowledge of the data you process and store with Beacon." Since Beacon disclosed the attack on August 4, the number of high-profile charities confirming they are affected has grown every day. Early confirmations came from the likes of Molly Rose Foundation, Macmillan Cancer Support Jersey, and English National Ballet. Sheffield Hospitals Charity, Shrewsbury and Telford Hospital Charity, the British Deaf Association, and Lincoln Cathedral are among those that have since joined the list. The Charity Commission said that "a number of charities have submitted serious incident reports," and that the volume of these reports is causing delays to responses. "We appreciate your patience and understanding as we prioritise instances of the greatest risk," it said. ®

  •  

Twitch feeds your streams to Amazon's AI unless you tell it to stop

Twitch has given streamers a switch to stop their channel content being fed into Amazon's generative AI machinery, but naturally it is turned on by default. The Amazon-owned streaming platform has added a "Training for Generative AI" control to channel settings, allowing streamers to opt out of having their content used for future GenAI model improvements. With the setting enabled, Twitch says channel content – including livestreams, videos on demand, clips, highlights, text, images, and chat messages – may be used to train Amazon's generative AI models. The benefits aren't confined to Twitch either, as the company says the resulting models may also be used elsewhere in the Amazon empire. For example, Twitch says audio from streams could be used to refine speech-to-text models, improving captions on Twitch as well as "across Amazon." Streamers who would rather not contribute their channels to Amazon's AI ambitions can opt out, but they'll need to do it themselves. Twitch has helpfully enabled the setting by default. Twitch chief product officer Mike Minton offered a refreshingly uncomplicated explanation for that decision during a livestream discussing the changes: "If it was opt-in, nobody would opt in," he said. "That's honestly the answer. So it's going to be on by default." The new control also doesn't mark the beginning of Amazon using Twitch material to build AI. According to Ars Technica, Minton confirmed at an event hosted by The Information in 2024 that Amazon was already using Twitch data to train AI models. What's changed is that Twitch users now have a dedicated way to tell it to stop using their content for future generative AI training. There are some wrinkles, naturally. The channel owner's setting determines whether messages posted in its chat can be used, so opting out on your own channel does not protect what you type in somebody else's if that streamer leaves training enabled. And Twitch's wording is conspicuously forward-looking: opting out means content won't be used for "future" GenAI model improvements. The company doesn't say that flicking the switch somehow extracts anything that has already made its way into a model. The Register has asked Amazon which of its AI models have been trained on Twitch content, how long it has been using the data, and whether opting out has any effect on material already used for training. We've also asked whether models trained on Twitch content are used in products available to Amazon customers or third parties. For now, Twitch creators finally have a way to keep their content off Amazon's generative AI training menu. All they have to do is find the switch Amazon would plainly rather they left alone. ®

  •  

Everything is better with pickles... except Windows

BORK!BORK!BORK! "Everything is better with pickles," trumpets a Wendy's sign. Everything is also better with a helping of bork, if the screen is to be believed. Spotted by an eagle-eyed Register reader in Vancouver, the display shows something amiss with Windows Phone Link – although why a PC encouraging customers to drop dollars on a Dill Pickle Chicken Sandwich needs the app is anyone's guess. The error itself usually comes up when something running Windows has been a bit careless with stack memory. Perhaps there's been a stack overflow, a software conflict, or a memory shortage. The usual fix is to reach for the power button or perform a restart. The more technically minded might try to diagnose the whoopsie and fix it without a boot cycle, although had a more technically minded person set up the system in the first place, it's unlikely that the PhoneExperienceHost.exe application would have reared its ugly head in this way. Phone Link connects a Windows PC to an Android phone or iPhone. The theory goes that users can keep track of mobile notifications, send and receive messages, or deal with calls from their Windows desktop. It arrived with Windows 10 as Your Phone before Microsoft renamed it Phone Link and continued adding features. Ordinarily, the service doesn't use much in the way of memory or CPU. However, something has clearly upset the instance here, much as an excess of dill pickles might disagree with the customer. While we're sure the foodstuffs on offer are excellent (although our reader told us they were only popping in for a Frosty Dairy Dessert rather than anything slapped with a dill pickle), we might give the chicken sandwich a miss this time. Even Windows appears less than keen. ®

  •  

Passwords stored in public Google Doc then showed up in search results

PWNED Welcome, once again, to PWNED, the weekly column where we highlight others’ security failures. Hopefully, there’s a lesson in all this, but it could just be “stop shooting yourself in the foot.” Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request. Our story today comes courtesy of Siim Kostabi, co-founder of Pageloot, a company that provides QR codes businesses can use for marketing. Kostabi’s tale of tech terror reminds us that credentials, even for a staging server, have a lot of value in the wrong hands. He explains that his company brought in a contractor to help with some API integrations on the back end. That developer had the credentials for the staging environment and wanted to be able to view them across different devices they were using for the job. So what was the developer’s solution to the very common problem of keeping track of usernames and passwords? They could have chosen a password manager. They could have written the passwords down in a paper notebook and kept it hidden from prying eyes. They could have gotten a password tattoo. They could even have emailed the passwords to themselves and it would have been smarter than what they did. Instead, the outside developer decided to store their password in a Google Doc. And they set that Google Doc to be viewable by anyone on the internet who had the link. And then, one day, an employee at the company found the Google Doc with the staging credentials in it because Google Search had indexed it and offered it as a search suggestion. “A developer on our team was debugging something unrelated and typed our domain into Google Search,” Kostabi recalls. “The autocomplete surfaced one of our staging hostnames followed by what looked like a credential string. We checked, and there was a publicly accessible Docs URL.” Yikes! Just imagine that not only are your company’s credentials available to anyone online, but they are indexed in Google Search for the world to find! Once they discovered the problem, Kostabi’s company immediately cut access for that contractor and rotated all of its exposed credentials. They also set a new rule: no storing passwords on Google Docs, Slack, Notion, or other collaboration tools. In a separate incident, Kostabi heard from a Pageloot customer, a mid-size retailer, whose QR codes were suddenly directing users to a competitor’s site. After investigating, he found that a disgruntled ex-employee’s credentials had not been revoked and that the former employee had used that access to redirect all of the retailer’s URLs, costing it customers. The takeaway from both of these problems is that you need to carefully control access. Former employees should immediately lose access to everything and current contractors should be reasonably intelligent people you can trust. “Both situations were completely avoidable with basic hygiene,” Kostabi said. “Proper offboarding, access reviews, and not treating shared docs like private vaults.” ®

  •  

Cisco thinks Mythos means instant death for unsupported networking kit

Cisco CEO Chuck Robbins says “The Mythos Effect” will see customers scour their networks for unsupported devices and replace them ASAP. Mythos is Anthropic’s bug-finding model and has proven so effective that vendors and open source projects are now finding more security flaws and pushing more patches. Speaking on Cisco’s Q4 earnings call yesterday, Robbins said customers he speaks to are aware of Mythos, and fearful that the model and others like it will mean that unsupported devices become too risky to operate once patches stop flowing. “I had one of my CEO friends who runs a major manufacturer in the US … their team called early on in the Mythos wave and just said: ‘Hey, listen, we got to get some of this stuff that is past LDOS’ [last day of support].” Robbins said other Cisco customers have done likewise. “We’ve seen the pipeline increase meaningfully as a result of Mythos, which is really showing up as a network refresh,” he said. The CEO thinks some customers might be paying for new Cisco kit with their security budgets rather than cash allocated to networking expenses. He’ll take it either way. CFO Mark Patterson said buyers who need rapid replacements for their kit won’t have to wait. “We really do not have any significant lead time issues that we are seeing,” he said, before indulging in a little competitive sniping by adding “unlike we have heard a number of different peers talk about.” Robbins said The Mythos Effect is one of three factors contributing to a “supercycle” of network spending. One is the need to prepare for quantum computing, either with quantum-safe networks or quantum-resistant decryption. The other is, of course, AI. Robbins thinks agentic AI will take off, and see Cisco sell bucketloads of fresh kit to hyperscalers, and replacement kit to businesses that want to implement AI and realize their existing networks aren’t up to the job. Cisco reported $17.3 billion revenue for the quarter, and $63.3 billion for the year, increases of 17 percent and 12 percent respectively. Net income rose 51 percent to $3.9 billion for Q4, while the full-year result of $13.27 billion was a 30 percent jump. “We delivered the highest revenue, operating margin, and earnings per employee in thirty years,” Robbins crowed. “In FY27, we expect all these metrics to continue to improve.” Investors appear to have been a little confused by what they heard, as Cisco’s share price spiked after its earnings announcement, before settling four percent lower than its closing price. Robo-support revealed Robbins also touched on Cisco’s own use of AI, which he said saw 145,000 support cases “resolved entirely by AI with zero human intervention” during FY26. If you’re a Cisco customer, let us know how that works for you. The CEO also revealed that Cisco operates an in-house AI Assistant called “Circuit” that he said “is fully embedded in how Cisco operates” and handled over 75 million prompts in Q4 alone. “Circuit runs on our Secure AI Factory infrastructure which improves GPU utilization and automatically routes each task to the appropriate large language model, allowing us to manage token consumption,” he said. ®

  •  

Tencent says it could make instant profits on $53B hardware splurge by renting it for AI workloads

Chinese tech giant Tencent has turned its back on instant profits, betting that a new business unit that creates its own AI and embeds that in its products will pay off to a greater extent than cashing in on demand for computing resources. During the company’s Q2 earnings call yesterday, Bernstein analyst Robin Zhu asked when Tencent expects to see a return on investment from the $53 billion capital expenditure it made in the quarter. Chief Strategy Officer James Mitchell said demand for compute resources is so strong that Tencent could recover its depreciation costs “almost immediately” if it rented its infrastructure. Company president Martin Lau said if Tencent behaved like a neocloud it would “achieve a decent return in an immediate timeframe” as the company has offers for its compute capacity “at more than 30 percent profit compared to the price that we paid just a few months ago.” Lau said Tencent is instead “playing a different game or executing a larger strategy in that we are allocating a very substantial proportion of the new compute to building our own models to state-of-the-art status, and also to deploying, popularizing, and bringing our own AI applications to market leadership in China.” He said Tencent believes that if Tencent can provide “superior intelligence that we can achieve through state-of-the-art models, through market-leading AI applications … we can then convert into superior economic returns over the longer term.” Those returns will come from selling tokens for services like WorkBuddy, which Tencent says is an agent swarm that can “plan, execute, and run tasks in parallel, handing back complete deliverables end-to-end in one flow.” Tencent also offers CodeBuddy, a code generation tool that Mitchell said is accelerating cloud migration projects and therefore creating more business for Tencent cloud. Tencent released its latest model, the 295-billion open-weight Hunyuan-3 in July. Lau described it as “a very small model” and promised that the forthcoming Hunyuan-4 will be bigger – and more capable than larger models from other companies. He also said Tencent is designing its products specifically to work with Hunyuan-4, and that mutual optimization will make those products more powerful than would be the case if they relied on other models. The company also plans a fifth version of Hunyuan, and Lau said at some point Tencent will deliver a state-of-the-art model. Tencent is already producing thoroughly modern results for a tech giant: Revenue for Q2 grew 11 percent to reach $30.3 billion. Net profit rose nine percent to $10.3 billion. The company’s flagship messaging apps, Weixin and WeChat, saw average monthly active users rise seven million to 1.349 billion. Advertising-related revenue rose 22 percent, and the company’s gaming biz grew 17 percent in China alone. Investors aren’t sure what to make of this. The company’s share price has trended down since Wednesday and dipped around three percent since the company’s earnings announcement. ®

  •  

Chinese Loongson processors have leaky caches, researchers find

Researchers from Germany’s Helmholtz Center for Information Security have found processors made by China’s Loongson have leaky caches that attackers could use to seek specific data. Loongson has developed its own LoongArch instruction set architecture (ISA) that blends approaches used by MIPS and RISC-V. On a site called LoongLeakAttack.com, the researchers explain that they found the leaky cache using a fuzzer, then noticed that the LoongArch ISA manual mentions an instruction that leaves 32 bits of a memory register in an “uncertain” state. “Our analysis reveals that under certain circumstances, the ‘uncertain’ data originates from the L1 data cache,” the four researchers wrote. “Since this cache is not isolated between applications, LoongLeak can leak data from other applications and the operating system. Even worse, an attacker can prime the CPU’s internal state to target the leakage to a specific cache set.” In a paper [PDF] explaining their research, authors Lorenz Hetterich, Tristan Hornetz, Fabian Thomas, and Michael Schwarz share case studies that “include recovering full-disk AES keys from the kernel, partial root password hashes from user-space, and bypassing traditional software defenses such as ASLR and stack canaries, all within seconds.” In case that’s not scaring you enough, they also point out “LoongLeak can be exploited from unprivileged user space, containers, or virtual machines.” The flaw even means “LoongLeak can cross the virtual machine boundary and leak host data from inside a VM.” “As the leakage is architectural, it requires neither high-resolution timers nor traditional sidechannel amplification, and it grants the attacker precise control over cache set and line offset,” they add. And the cherry on top is that software mitigations aren’t possible. Users with chips that possess the flaw either need to replace them or make sure they don’t allow any private data to enter or remain in the L1 cache. Making that happen can require turning off one thread per core, effectively disabling hyperthreading. The news isn’t all bad, because Loongson fixed the flaw in an update to its model 3A6000 processor, and the mitigation of evicting cache data slows performance by just 1.4 percent in the worst case. The blast radius of this flaw is also likely to be limited, because Loongson chips are hardly used outside China. The company offers chips for PCs, servers, and appliances such as printers. China’s government promotes use of Loongson chips as part of its plan to reduce dependence on imported tech. Lenovo makes laptops that use Loongson chips but only sells them in China. The Register has discussed the company’s chips with other major PC-makers, who told us they would adopt Loongson product if users want them, or if doing so becomes necessary to participate in the Chinese hardware market. But we’ve not seen a non-Chinese company adopt the processors. China’s government, however, may be nervous about this research as it has instructed public sector buyers to buy local products. Perhaps some government agencies are running vulnerable devices? If that’s the case, Beijing has its work cut out spotting any attacks, because the researchers could find “no specific tools or methods to detect if LoongLeak is being exploited.” ®

  •  

OpenAI ad service can bill customers for up to one day after they pause campaigns

OpenAI appears to be serving ads after buyers have halted their campaigns, and charging them for the privilege. OpenAI began testing ad sales in ChatGPT in the US back in February and has been gradually expanding the service in other regions, including the United Kingdom, Mexico, Brazil, Japan, and South Korea as of Tuesday. Given that a substantial minority of ChatGPT's user base pays for the service (50 million out of 900 million weekly users as of February 2026), advertising revenue appears to be an important part of OpenAI's plan to defray the cost of providing its service and to convince investors that it has a path to profitability ahead of a future initial public offering. Online ad-marts from the likes of Google and Facebook give advertisers control over when and where their ads will appear, but don't always stick to instructions. The AI biz's ad service appears to have similar ad timing and billing accuracy issues. Ed Bolton, managing director of UK-based Excel4Business, told The Register that his company encountered "an odd billing practice" when it started experimenting with ChatGPT Ads in the US and Canada. "We were running campaigns in the US and Canada … and noticed ads were being delivered through the night/morning on paused campaigns," he explained. When Bolton pointed this out in a support message thread, an OpenAI customer service representative initially acknowledged the failure. "We have now confirmed that your campaigns continued serving after they were paused," said an OpenAI support specialist in an email provided to The Register. "This was not a reporting delay. The campaign was marked as paused, but the separate ad-level status used by the serving system did not refresh promptly, so an ad that was still active at the ad level continued to run. Our Ads Engineering team has escalated this defect and is working on an additional production fix." The support reply goes on to state: "Our review has confirmed £60.72 in invalid charges from the original occurrence and approximately £6.47 from the August 4–5 recurrence. We are extending that reconciliation to the additional activity you reported on August 6. We are preparing the confirmed invalid charges for billing review, but I cannot confirm the final refund or credit amount until the latest activity has been reconciled and that review is complete." Bolton responded that the acknowledged problem – ads being served after he disabled the campaign – had been occurring for a longer period of time and requested a more complete reconciliation of ad billing. Several days later, OpenAI's support rep reversed the prior determination and declined to offer any refund or credit because the company's Advertising Terms state that ChatGPT Ads may be delivered even after a customer cancels a campaign and the advertiser still has to pay for those unwanted ads. "Section 11.1 of our Advertising Terms provides that ads may continue running for up to one business day after a campaign is canceled or changed, and advertisers remain responsible for ads delivered during that period," the support message explains. "Pausing a campaign constitutes a campaign change and does not guarantee that delivery or associated charges stop immediately." A spokesperson for OpenAI confirmed that's the case, explaining that it can take a business day to cancel or change a campaign and that this doesn't represent an intentional effort to run ads after an advertiser has disabled a campaign. Based on the times cited in the support message thread, the most delayed ChatGPT ad ran about 94 minutes after Excel4Business paused a campaign. Bolton said unwanted ads appeared for a far longer period — more than 10 hours after campaigns were paused. OpenAI isn't the only ad provider that allows itself a business day to turn off its ad spigot for a particular customer. Other advertising services impose similar terms. "So the terms … seem to be a standard which is used in digital advertising, which some legal team wrote at some point, saying that we've got a 24-hour grace period if you stop a campaign," Bolton said - before adding that he has run Google AdWords campaigns for 17 or 18 years and has never had that issue. If ad buyers were not able to stop an AdWords campaign quickly, you could easily spend half a million dollars, he said. Nonetheless, some Google advertising customers have complained about post-pause ad serving. Why it might take so long to stop serving ads at a time when applications and servers can be spun up and torn down in seconds isn't immediately clear. One can order and receive physical goods from Amazon.com in less than one business day. It may be that there's no financial incentive or regulatory pressure to tackle the problem, and a significant financial incentive to ignore it. "My understanding is that such a clause is included in terms and conditions so as to cover issues with latency, and not to allow them to run ads for 24 hours longer than instructed," said Bolton. "Regardless, they cannot retroactively apply a clause from terms and conditions after making a written settlement offer." ®

  •  

Rent-a-GPU outfit Nebius promises rapid 1 GW powerup plan isn't nebulous

Rent-a-GPU cloud Nebius plans to bring online over a gigawatt of datacenter capacity every year starting in 2027, but doing so will require playing the margins and juggling a mountain of debt. “Our future capacity pipeline effectively makes Nebius one of just a few companies in the world able to build more than a gigawatt of new capacity a year and we plan to do so in 2027,” CEO Arkady Volozh boasted on Wednesday’s earnings call. The endeavor won’t be cheap. In 2026, Nebius says it expects to burn between $20 billion and $25 billion on capital expenditures to bring between 800 and 1,000 MW worth of bit barn capacity online. A big chunk of that will be covered with customer prepayments — essentially deposits for future capacity. According to Nebius CFO Dado Alonso, the firm is on track to exceed $9 billion in customer prepayments this year. But this alone won’t be enough. So like most big rent-a-GPU rackets, including CoreWeave and Lambda, Nebius is taking on debt to finance its expansion. Specifically, the company is using its GPUs and contracted cash flows as collateral to secure favorable interest rates on the coveted accelerators. Nebius landed its first asset-backed debt facility valued at $775 million in July, and Alonso says the company will continue leaning on the financing scheme going forward. No surprise. Along with debt financing, the company is also exploring an asset-light model where “partners finance, build, and operate the facilities, whereas Nebius brings the full-stack platform and demand,” Volozh told analysts. In other words, Nebius gets to claim deployed capacity it didn’t have to front the cash for, but that relies on the company's ability to rent capacity for less than it can resell it for. While hitting a gigawatt of capacity a year won’t be cheap, Volozh is confident the investment will pay off in the long run. He claims that for every megawatt deployed, Nebius will bring in between $20 million and $25 million in revenues for medium-term leases, and $40 million to $50 million for short term leases up to six months. On the low end of the scale, that implies $20 billion a gigawatt, although Nebius Chief Product and Infrastructure Officer Andrey Korolenko notes that while the company expects to have up to a gigawatt of connected power by year’s end, not all of it will be active and generating revenue until 2027. “You have to commission the datacenter, build the network, build the clusters, deploy the platform, then onboard the customers, and then the revenue generation starts,” he said. “That takes a few months.” “In terms of our guidance from 800 megawatts to a gigawatt… I would think about that being active throughout the first half of 2027,” he added. But even if Nebius has to wait until 2027 to pull a full gigawatt of capacity, that still implies a massive uplift in revenue, which is forecast to hit $3 billion to $3.4 billion for fiscal year 2026. The past quarter accounted for just $582 million, which suggests Nebius will bring in more than $2 billion over the next two quarters if you believe its projections. There are a lot of faithful among the investor community, as its share price surged more than 30 percent on Wednesday following the report. While revenues are expected to increase dramatically over the next few quarters, it's easy to sell dollar bills for 70 cents apiece. Whether the company actually manages to turn a profit renting the shovels of the AI gold rush is another matter entirely. In Q2, the company posted an operating loss of $176 million, a jump from the $111 million operating loss it booked in the year-ago quarter. ®

  •  

'Near-autonomous' AI agents attack Taiwan's nuclear safety agency

Suspected Chinese cyber operatives used publicly available AI tools to compromise Taiwanese government systems before expanding the attack to its nuclear safety agency, supply-chain vendors, and at least seven energy companies in what security researchers called a "near-autonomous attack." Over the first four days of July, AI agents compromised 85 government user accounts and extracted more than 2,500 personnel records, according to Dream, an Israeli cybersecurity firm. Researchers uncovered evidence of the attack in a 160 MB online archive containing 1,395 files documenting the operation. Dream, in research published on Wednesday, detailed the intrusions and said that the suspected Chinese hackers hit “government entities in Asia” - but declined to say which government had been attacked. A person familiar with the attack confirmed to The Register that Taiwan was the target. The Financial Times first reported on Dream’s research and identified Taiwan. While the security firm doesn’t attribute the agentic attack to the Chinese government or a specific hacking group, the operational documentation “points to a Chinese-language operator,” the researchers said. According to Dream, the attack framework, built on open source Hermes and OpenClaw AI agents, deployed up to eight sub-agents, each assigned to its own targets and attack techniques, across 12 “attack waves” between July 1 and July 4. First, the agents mapped the entire government ecosystem, extracting embedded URLs, API endpoints, OAuth client IDs, and Keycloak configuration objects from a single government portal. This portal allowed the agents to identify 21 connected government systems and every supported authentication flow. “On one target alone, it discovered 36+ API endpoints spanning account management, user data retrieval, file upload, and administrative functions - many completely unauthenticated,” the Dream threat researchers wrote. “Critically, it found that one of the systems exposed its entire user database without any authentication - thousands of employee records including names, departments, and SSO account IDs.” Multiple entry points After mapping the government’s attack surface, the agents found multiple entry points including three hidden API endpoints that accepted any request body and returned a valid authenticated session without requiring user credentials. Using employee usernames harvested from an unauthenticated API, the agents broke into a government department’s office automation portal, solving its CAPTCHAs with 100 percent accuracy. The agents also tested predictable password patterns based on each employee’s ID, and cracked 85 accounts across multiple password-spray rounds. Eighty-four of the 85 cracked accounts successfully authenticated to the department's internal information system, giving the attackers access to internal dashboards, equipment management interfaces, and personnel statistics pages. In total, the illicit access allowed the agents to exfiltrate a ton of government information, including more than 2,564 personnel records, a full JSON export of all department system users, seven SSO client secrets, six internal database credentials across MSSQL, Oracle, and Sybase, and internal network IP ranges. But wait, there's more And then, the agents pivoted to the Taiwanese government’s supply chain. “It expanded the operation to government IT supply chain vendors, a nuclear safety agency, a government email system, and 7+ energy sector companies - scanning them all in parallel for misconfigurations, exposed admin interfaces, and exploitable vulnerabilities,” the researchers wrote. Notably, the attack framework implemented what the AI tools called “learning cycles.” These are autonomous sessions where the models search vulnerability databases, GitHub repositories, and other security research for specific techniques, CVEs, and common weaknesses to exploit in the targeted government's infrastructure. Additionally, when the AI framework made a mistake, it “self-corrected,” according to Dream, catching errors and fixing them through its own verification process. This near-autonomous attack comes as frontier model makers OpenAI, Anthropic, and Meta all admitted that their agents went rogue, escaped from their training environments, and autonomously hacked other organizations and people. OpenAI technical staffer Michael Dalton, in a Black Hat briefing last week about the Hugging Face attack, said “AI orchestrated, fully automated offensive attacks are real now.” “In the near future, we should expect that threat actors will intentionally deploy, optimize, weaponize, and use offensive agent collectives in the manner that you have just described here,” he added. It appears that the future is now. ®

  •  

Deeply buried 16-year-old SQLite bug caused last year's Tailscale outages

Users of peer-to-peer networking outfit Tailscale might have struggled through some surprising outages beginning late last year. After a six-month investigation, the team finally knows why: A bug in SQLite’s write-ahead log that had remained hidden for 16 years. The Tailscale team announced in a Wednesday blog post that it had finally addressed the issue with the help of SQLite maintainers, who even had to create a new tool (with Tailscale funding) to log virtual file system activity in order to track the thing down, which Tailscale software engineer Alex Chan described as resisting “all our initial attempts to find it.” According to Chan, the problem goes deep into the nature of SQLite – so deep that the database maintainers actually had to add code to reproduce it. To understand what happened, it’s necessary to know how Tailscale works. The service, based on the WireGuard VPN protocol, directly connects devices in a virtual private mesh network. It’s designed to be low complexity and easy to implement for everything from remotely accessing a NAS to connecting teams in a unified private network. Each mesh network, or "tailnet," lives on one of several servers, where a SQLite database manages all the information about the tailnets it houses. “We’ve used SQLite as our primary database since 2022, and we chose it because it's well-known, reliable, and widely used,” Chan wrote in the company’s post-mortem. But a year ago, something went very wrong. “In our current backup pipeline, we take a complete snapshot of the database every few minutes, then upload the entire SQLite file to an S3 bucket,” Chan said, but in August 2025 those backups began detecting database corruption, repeatedly, with no obvious common trigger. The Tailscale team couldn’t reproduce the issue because there were no reliable triggers for it. No low-level code had been changed in months. A review of everything that touched SQLite turned up nothing. Working with the SQLite team, the Tailscalers tried to figure out what could be causing it – POSIX locks broken by close() calls? Nope. Mismanaged memory? Not that either. SQLite being used from multiple threads with thread safety disabled? Nuh-uh. “After every incident, we gathered more data, added more diagnostics, and systematically ruled out these theories,” Chan explained. The WAL-Reset bug comes out of hiding Suspicion was closing in on SQLite’s checkpointing process, which is how it takes new database entries out of a temporary hopper for addition to the master database file. SQLite has an option to improve performance and concurrency known as the Write-Ahead Log (WAL), which serves as the aforementioned hopper. Writing the WAL to the database occurs in a process known as checkpointing. “In most deployments, SQLite itself decides when to do a checkpoint, and the process is invisible to the end user and developer,” Chan said. “In our control plane, we take manual control of the checkpoint process so we can run fast and consistent backups.” The SQLite team wrote a new tool to take a closer look at the process: a virtual file system shim that extensively logs checkpointing activity. After waiting for the next corruption incident, the teams had their answer, dubbed the WAL-Reset bug. Described by Chan as “a rare data race in the SQLite source code between a checkpoint and write transaction,” it’s essentially a collision between checkpoints and writing data to the WAL. “If a write occurs at a specific time during a checkpoint, the checkpointing process gets confused — it thinks some of the pages have been copied from the WAL into the main database file, but they haven’t,” Chan said. Those pages are never written and are permanently lost, but pages that reference those pages are still written, corrupting the database and causing all hell to break loose. According to the SQLite team’s WAL-Reset writeup, the issue can be triggered only when WAL mode is active and multiple database connections are open on the same file, and because there has to be reading and writing going on at the same memory spot at the same time, it’s incredibly unlikely to happen in most situations. Tailscale’s decision to perform manual checkpoints was a rare exception. SQLite maintainers believe the bug was present going all the way back to version 3.7.0, released in July 2010; it’s now fixed, and the SQLite team recommends users update to a fixed version, though it stresses the bug is extremely unlikely to occur in ordinary use. “This bug, though rare, does have serious consequences,” the SQLite WAL-Reset notice states. The incident contains a useful reminder for devs: Even the most boring, reliable software poses risks when operated in a non-standard fashion. “Most people use SQLite in a standard configuration and never face this sort of issue,” Chan said. “By taking manual control of the checkpointing process and running at our own aggressive pace, we stepped off the well-trodden operational path.” ®

  •  

Node.js creator liberates Durable Objects from Cloudflare

We've got good news for developers who are enamored with Cloudflare Workers and Durable Objects but don’t want to be tied into that company’s backend infrastructure. Last week, Node.js creator Ryan Dahl unveiled his latest project, celld, which he described on X as “a self-hosted, distributed Durable Objects and Workers implementation.” Dahl’s celld model is compatible with Cloudflare’s Workers and Durable Objects’ JavaScript APIs, but he claims that it is much less expensive to run. The project is no mere budget-minded open source rip. On celld’s web page, Dahl and his team characterize their replication of the Durable Objects architecture as a “love letter.” Cloudflare’s Durable Objects is a single-threaded object with a unique global ID and its own storage, where user data is stored in its own copy of SQLite. It runs on the Cloudflare serverless Workers runtime, which runs apps embedded in isolates—a type of lightweight virtual machine supported by Google's V8 JavaScript engine. First devised by Kenton Varda and Cloudflare, Durable Objects is “one of the best primitives distributed systems has been handed in years,” celld’s creators write. Unlike traditional serverless platforms like AWS Lambda, the Durable Objects model co-locates the data with compute, while using single-threaded execution to eliminate complex concurrency issues. “A primitive this good deserves to run anywhere,” the celld page states. Serverless but stateful Since its introduction in 2020, Durable Objects has been used to build low-latency, highly distributed Web applications. It is a stateful serverless execution environment, a data cache that can also do computation. Using the WebSocket API, the Durable Object can connect many simultaneous users at once in a live environment. WebSockets’ Hibernate mode can put the object to sleep, so cloud bills don’t accrue when no one uses the app. As a result, the stateful serverless model is best suited for real-time collaborative applications, such as multi-player games, team productivity apps and AI agents. Cloudflare uses Durable Objects for its serverless SQL service and AI Gateway. One YouTube tutorialist explained that using Durable Objects allowed him to eliminate an entire stack of tools (Amazon API Gateway, Apache Kafka, Redis, AWS Lambda and EventBridge, Apache Airflow and Spark all get name-dropped) because Durable Objects can handle all these functionalities “at a smaller scale.” Giving Durable Objects an open source home Dahl is one of the world’s foremost experts at JavaScript I/O, having created Node.js, a JavaScript runtime that runs the world’s fastest Web applications (and inadvertently introduced the JavaScript world to “callback hell,” where the language's asynchronous operations forced coders to pass functions as nested callbacks, resulting in ungainly and unintuitive messes of code). Dahl later went on to refine his ideas of asynchronous JavaScript with a second-generation JavaScript runtime called Deno. Celld does away with the Cloudflare backend, and instead uses the Amazon Simple Storage Service (S3) or equivalent as the storage engine. It also uses the Tokio Rust asynchronous runtime. As with Durable Objects, each celld object gets its own copy of SQLite. Dahl promises this open source backend will be “orders of magnitude cheaper at scale” than Durable Objects. Dahl estimated that 100 resident Durable Object cells cost $415 a month on Cloudflare, whereas the celld implementation would run only about $49 a month, built on a DigitalOcean S3-compatible bucket on an 8 GB droplet. Further savings should ensue as the workload scales, he argued. Cloudflare disputed Dahl’s numbers, stipulating that $415 a month would be the cost if all the objects were continuously active. If left to slumber, the Durable Objects would cost only $20.65 to house on Cloudflare, a spokesperson told The Register. Whatever its putative thriftiness, the model itself seems to have gained interest on its own merits. “So happy to see support for running durable objects outside of one provider. Upvoted,” one Hacker News reader enthused, noting the concept of a durable object is a valuable abstraction. Indeed, other parties are cooking their own schemes to move the data closer to the computation. For instance, Postgres service provider Neon just introduced its own Neon Functions, which can also co-locate data and compute for long-running workloads. Written in Rust and JavaScript, celld is available under an Apache 2 license. It can ingest JavaScript and TypeScript code. In theory, Rust, C/C++, Go, or Zig code can also be executed through the magic of WebAssembly, which V8 supports with slight modification. But while celld is open source, AI contributions are verboten. “Coding agents make it too easy to send a large, low-context change that costs maintainers more time than it saves,” the GitHub page notes. Human contributions are still welcome, though you should understand what your code does before you submit it. ®

  •  

Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible

If you thought that the famous Spectre security vulns were a relic of 2018, think again. Certain RISC-V chips are still very much subject to this hair-raising hole, researchers say. Spectre refers to a family of vulnerabilities related to speculative execution, a performance optimization technique based on predicting the flow of data before instructions have been executed. Incorrect predictions get rolled back without affecting running applications but nonetheless leave traces that can be recovered and exploited to violate memory protections and access secrets. Spectre flaws have dogged x86 and ARM chips for years, leading computer scientists to develop a series of defenses, including Indirect Branch Restricted Speculation (IBRS), Indirect Branch Prediction Barrier (IBPB), and Single Thread Indirect Branch Predictor (STIBP). Researchers affiliated with academic institutions in Belgium and Germany say that it's been popular to assume that the RISC-V chip architecture isn't affected by Spectre vulnerabilities because it's too simple. That assumption is incorrect, according to a paper accepted at the 35th Usenix Security Symposium, "Spectre on RISC-V Silicon: Attacks and Defenses on Commercial Out-of-Order Processors." It says that commercially available out-of-order RISC-V processors (SiFive P550 and T-Head Xuantie C910/C920) are vulnerable to all major Spectre variants. RISC-V processors that process instructions in-order (SiFive U74, Xuantie C906, C908) do not appear to be vulnerable. Prior research has shown that RISC-V processors used for academic research (e.g. BOOM, RiscyOO, RSD, Proteus, NaxRiscv, and NutShell) can be affected by one or more of the Spectre variants, but hasn't addressed commercial silicon. "We demonstrate proof-of-concept attacks on both processors using Spectre-PHT, Spectre-BTB, SpectreRSB, and Spectre-STL, achieving up to 100 percent recall with more than 97 percent precision," the paper states. Spectre-PHT involves mistraining the Pattern History Table; Spectre-BTB poisons the Branch Target Buffer; Spectre-RSB attacks the Return Stack Buffer; and Spectre-STL (Store To Load) exploits mispredicted store-to-load forwarding. To demonstrate the risk to RISC-V, they created a proof-of-concept Spectre exploit that leaks arbitrary Linux kernel memory on the Xuantie C910 at a rate of 338 B/s. Software-based defenses have been developed for these vulnerabilities on x86 and ARM hardware. Unfortunately, the researchers say, these don't necessarily transfer. They also call out RISC-V hardware for its lack of introspection interfaces, necessary to observe and reason about microarchitectural features. In addition, the authors argue, the diversity of the RISC-V hardware ecosystem means that no single mitigation strategy is likely to be effective across all systems. "RISC-V inherits the software and threat model of mature architectures without their accumulated hardening," the authors conclude. "Closing this gap is not a matter of porting individual mitigations, but of building the architectural primitives, hardware transparency, and ecosystemwide tooling that effective Spectre defense presupposes." The authors say they disclosed their findings responsibly last December. Three of their patches have been merged into mainline Linux and two others are under review. SiFive is said to have dealt with P550-specific findings and T-Head (Alibaba) is said to have committed to publishing ad-hoc speculation barriers for their processors at some point. The authors say they decided not to delay publication because Spectre has been around for eight years now. The paper was written by Lukas Gerlach (CISPA Helmholtz Center for Information Security), Marton Bognar, (DistriNet, KU Leuven), Daniel Weber and Michael Schwarz, (CISPA Helmholtz Center for Information Security), and Jo Van Bulck (DistriNet, KU Leuven). ®

  •  

Nvidia's latest solution to soaring enterprise AI costs is...a router?

Soaring AI infrastructure costs and model pricing, combined with uncertain returns on investment, threaten to stall enterprise adoption. To make enterprise AI spend a bit more manageable, Nvidia this week unveiled a new software platform that blurs the line between expensive proprietary models and open weights alternatives. Announced alongside Nemotron 3.5-30B-A3B-Lightning, Nvidia’s latest open weights model, NeMo Switchyard is the GPU giant’s latest overture to enterprise. So what exactly is it? Well, it’s a router. The idea is simple. Switchyard essentially functions as a proxy that sits between the inference server’s API endpoint and the models. But rather than sending every request to the same model, Switchyard can be configured to route prompts to different models in order to optimize for cost, latency, or output quality. By routing some requests to smaller, cheaper, and potentially locally hosted AI models, Nvidia claims Switchyard can cut job completion costs by 74 percent relative to using Claude Opus 4.8 alone, albeit with an approximately six-point accuracy tradeoff. The right tool for the job The key metric in all of this is completion cost rather than price per token. A model might cost one-tenth as much as OpenAI’s or Anthropic’s top model, but if it requires 10x the tokens to complete the request, it isn't actually cheaper. Certain elements of an AI workload may benefit from a larger, smarter model, but not all do. For example, it’d be overkill to ask Claude Opus to generate a title card or summarize a website. It’ll certainly work, but it’ll also cost a fortune compared to Haiku or a locally hosted model that’s been fine tuned just for that purpose. The fewer tokens you burn on the big smart model, the less expensive your API bill is going to be. Nvidia software teams have spent the last several years developing models for this reason. The Lightning model announced this week is only its latest. The 30 billion-parameter MoE model is positioned as a low-latency, general purpose model that can either be used on its own or in conjunction with a larger, smarter model via a router like Switchyard. The company has also developed several application-specific models. Nemotron Parse is one such example. “It’s a small model, one billion parameters, and it’s really good at one task, which is taking a PDF in and then explaining the context inside that PDF whether it’s charts or graphs or tables,” Joey Conway, senior director of AI software and models at Nvidia, explained in a recent interview with The Reg. Many frontier models struggle with this task because PDFs are designed by humans for humans, so by offloading that work to task-specific models, enterprises can not only improve the accuracy of their AI apps, but also reduce costs in the process. This all might sound familiar: It's not the first time we’ve seen model routers employed as a cost-saving measure. Back when OpenAI launched GPT-5, ChatGPT would dynamically route prompts to different versions of the model based on their complexity. As we wrote at the time, OpenAI’s router was likely implemented to reduce the number of compute cycles spent on mundane tasks like rewording emails to sound more professional ("not only … but also"). OpenAI wasn't alone in using routers to reduce model costs. The Wall Street Journal recently reported that AT&T has implemented a “smart router” of its own to automatically select which model to use. Switching from proprietary to open-weight models has reportedly saved the telecommunications giant between 80 and 90 percent in certain applications. Today about 25 percent of the company’s AI workloads are powered by open models. The company’s leadership expects that over the next few years that’ll climb to 70-80 percent. The implementation challenge While the idea of offloading simpler requests to smaller, cheaper-running models sounds intuitive, it’s easier said than done. Title cards and web summaries are relatively straightforward to implement. Open source chatbots like Open WebUI have supported this kind of functionality for more than a year now because it just makes sense. However, sometimes it’s not obvious when and where these task models should be used. Switchyard is Nvidia’s latest attempt to simplify this by automatically routing requests to the right model for the job. However, it’s not the only approach Nvidia is exploring. AI agents and code assistants have the ability to work through problems and then generate skills — essentially standard operating procedures — documenting the process for future reference. Through this iterative process, Conway suggests, agents could essentially teach themselves when and where they can get away with using a smaller, cheaper task model, and where a larger frontier model may be required. “We’re starting to see signs of this sort of agent and subagent type workflow,” Conway said, describing how a frontier model might function as an orchestrator that farms out work to smaller models that are faster and more specialized. It reflects the way companies are structured, he said. “We have people who are specialists and then we have people who help orchestrate that and understand the complexity of the problem.” As an added step, it’s possible for the agents to generate training data on the fly, which could then be used to fine-tune the models to operate more efficiently. Regardless of which approach ultimately wins out, anything that promotes enterprise AI adoption is a win for Nvidia. ®

  •  

Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows

Nightmare Eclipse, the serial zero-day hunter who has an axe to grind with Microsoft, published a new Defender zero-day, ShieldBreak, that apparently bypasses Redmond’s RoguePlanet patch (CVE-2026-50656), allowing attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. According to at least one other researcher, the exploit works. “I've tried it, it works on latest Windows 11,” former Microsoft employee and security expert Kevin Beaumont said. Beaumont also published three detections and hunting queries for ShieldBreak to help defenders rapidly find any stealthy threats. So until Microsoft fixes this latest zero-day, we’d highly suggest using these queries. ShieldBreak is the 10th zero-day from Nightmare Eclipse since they began their scorched-earth strategy against Microsoft in early April. The prolific bug finder and exploit developer is suspected to be a former, very disgruntled, Microsoft employee. And in typical fashion, this latest zero-day drop occurred just hours after Redmond’s monthly Patch Tuesday that fixed 421 security problems in its products - but ShieldBreak isn't one of them. It’s a local privilege-escalation exploit that, according to Nightmare, allows attackers to gain SYSTEM-level privileges. “The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate. Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well,” they said. While Nightmare claims that the new exploit is a patch bypass for the earlier RoguePlanet vulnerability, CVE-2026-50656, which Microsoft quietly fixed in July, Beaumont pointed out that the two flaws operate very differently. “RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files,” he posted. “ShieldBreak user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API).” A Microsoft spokesperson told us the company "is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims." The spokesperson added: "Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible. Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public." This latest zero-day comes a month after Nightmare Eclipse published its previous vulnerability along with partial exploit code. Nightmare’s July drop, called LegacyHive, is a local privilege escalation flaw that targets Windows’ user hives - the section of the Windows Registry that stores a user's specific desktop settings, application preferences, and environment configurations. It's patched with CVE-2026-62832. There's also a June zero-day called GreatXML that Nightmare developed. The researcher claims the flaw allows a local attacker with administrator rights to bypass BitLocker encryption by manipulating the Windows Recovery Environment. But it has been patched with CVE-2026-50661. The prolific zero-day hunter’s earlier seven Windows bugs do have patches. These include BlueHammer (CVE-2026-33825), RedSun (CVE-2026-41091), UnDefend (CVE-2026-45498), YellowKey (CVE-2026-45585), GreenPlasma (CVE-2026-45586), MiniPlasma (CVE-2020-17103), and RoguePlanet (CVE-2026-50656). After threatening legal action against Nightmare Eclipse in May, and then facing rapid backlash from just about every other security researcher on the planet, Microsoft walked back its talk of siccing its Digital Crimes Unit on people who don’t follow its vulnerability disclosure rules.® Correction: There are patches for GreatXML and Legacy Hive.

  •  

OpenWALDO aims to blow the doors off proprietary AI training models

A new project aims to build a shared, open source AI training dataset that anyone can contribute to, much like an open source software project. It aims to make training data more transparent than that of many open-weight models that have recently taken the industry by storm. CentOS and Rocky Linux founder Gregory Kurtzer is behind the effort, dubbed Open Weights, Artifacts, Licenses, Data, Origins (OpenWALDO), and it's funded by CIQ, his AI infrastructure company, which also sponsors Rocky Linux. Kurtzer described the effort as trying to bring the open-source ethos to AI model design, which has yet to be truly open – even downloadable open-weight models still have closed-source training data that is unknown to users, alongside other limitations that make them less than truly open source. “I’ve spent my career watching open source turn users into builders, competitors into collaborators, and shared problems into common infrastructure that operates at massive scale,” Kurtzer said in the announcement. “OpenWALDO brings that proven model to AI. Let’s work together, build its foundation in the open, and collaboratively take AI to the next level.” CIQ, which authored the announcement, argues that open-weight models keep that foundation a secret because of where it comes from: Copyrighted data, responses distilled from other models, user-generated content that may not have been given in a truly open manner, and the like. “There is often no way to know what data trained a given model, under what license, or with what consent,” CIQ said, adding that hidden training data content could taint models, putting customer software stacks at risk. In addition to that, there’s the simple fact that, when everyone is training their AI models in secret, a lot of duplicate work is happening that wastes lots of time and computing resources. A single, shared set of public training data, the OpenWALDO team argues, would not only make training more efficient across the industry, but also mean that every improvement to the dataset could benefit future models trained on it. “A lab or company can take the corpus and its bill of materials as a verified baseline, add its own proprietary data, build, and ship, with a clear, auditable line back to its sources,” CIQ explained. With prices steep and ROI still largely absent, open AI models (not to be confused with OpenAI models) have risen to prominence in the AI zeitgeist lately. Models out of the home of open-weight AI, China, are closing in on the capabilities of closed-source frontier lab models like ChatGPT and Claude, leaving many businesses wondering why they ought to pay through the nose for AI services they don’t own, can’t truly control, and have no visibility into. Some frontier labs have warned that open-weight models pose security and misuse risks. Kurtzer argues that open source software faced similar concerns. “Open source has won this argument before,” he said, pointing to similar arguments made about open code, namely that it’s insecure, impossible to trust, and the like. “Linux didn't win by being certified safe. It won by being inspectable, forkable, and community validated.” “AI is missing that same property, and OpenWALDO is how we build it,” Kurtzer said. Turning to open-source training datasets is a big ask for an industry already so far down the closed training data path, of course, and only time will tell if OpenWALDO is a revolution or another obscure OSS project that gets minimal attention from the AI community. So far, the OpenWALDO dataset contains 167.3 billion reference tokens pulled from things like government records, open-source academic papers, mailing lists, and public domain literature - a drop in the bucket next to the tens of trillions of tokens used to train frontier AI models and their open-weight counterparts. We asked if anyone has trained a model on the OpenWALDO set yet, but CIQ didn’t respond. Those interested in contributing to, or making use of, OpenWALDO can find more on the project’s website (linked above) and its GitHub page. ®

  •  

CoreWeave revenue doubles as debt pile reaches $35.6B

Neocloud operator CoreWeave remains bullish about its prospects, claiming that changing patterns of AI use will create sustained demand for its cloud services. The New Jersey firm is among the most prominent rent-a-GPU businesses spawned by demand for AI training infrastructure, but is now attempting to move up the technology stack – a shift consultants at McKinsey said neoclouds would need to make to survive. "AI is no longer confined to frontier model labs. It is becoming embedded in software, industrial systems, financial markets, enterprise workflows, and national security missions," claims CoreWeave co-founder and CEO Michael Intrator. Intrator also claimed that deploying AI applications is turning compute from a large upfront requirement into a recurring expense. "For the last several years, many organizations treated a model like a deliverable. Train it, deploy it, and move on. Enterprises no longer operate that way," Intrator told analysts on a conference call for CoreWeave's financial results for the second quarter ended June 30. "Training, inference, evaluation, and improvement now form a single continuous loop. Models and agents in production generate real-world data. That data informs evaluation, driving new experiments, which improve the model or application before being redeployed into production." CoreWeave's pitch is that this continuous cycle is changing both the demand curve and the economics of AI. "Compute is no longer a one-time requirement concentrated at the beginning of a model's life. It becomes an ongoing requirement that grows with every application in production and every cycle of improvement," Intrator said, adding: "Our AI native platform was built for this." CoreWeave expects its managed inference services, launched only a few months ago, to reach an annual recurring revenue run rate of at least $250 million by the end of 2026. Yet all is not rosy. Revenue rose 112 percent year-on-year to $2.575 billion, but operating expenses reached $2.624 billion, resulting in a $49 million operating loss. Interest and other costs helped widen the net loss to $626 million. Most of that growth also came from existing clients rather than new ones. According to CoreWeave's Form 10-Q [PDF] filed with the SEC, approximately 93 percent of the revenue increase was attributable to expansion within its existing customer base, with the remainder attributable to new customers. In fact, the firm concedes that just three customers accounted for 36 percent, 26 percent, and 10 percent of quarterly revenue respectively – 72 percent between them. It also warns that "while we have historically experienced significant growth in revenue over the last three years, we cannot predict whether we will maintain this level of growth or when we will achieve positive net income." The company is also carrying substantial debt. As of June 30, total indebtedness stood at $35.6 billion, helping to push quarterly net interest expense up 140 percent to $640 million. CoreWeave also had $10 billion available to borrow under its revolving credit and delayed-draw term loan facilities, according to its Form 10-Q. Nor can it stop spending on infrastructure. CoreWeave expects 2026 capital expenditure of between $35 billion and $39 billion. CoreWeave also warned that it faced competition from much larger and more established cloud operators, such as AWS, Microsoft Azure, and Google, "a number of which are also our current customers," which it may not be able to compete with because of the resources they can bring to bear on building infrastructure and AI development. Investors nevertheless welcomed the results, sending CoreWeave's shares up almost 19 percent in early Wednesday trading, according to MarketWatch. "The opportunity ahead is generational. CoreWeave is the essential cloud for AI," stated Intrator. "Our conviction in our strategy has never been stronger, and our execution continues to reinforce it." ®

  •  

Smooth-talking fraudsters clone contactless cards, authorize payments in just 13 minutes

A new social engineering and malware campaign targets Android users, stealing card details to make payments or withdraw cash. Group-IB discovered the campaign, calling it WindRelay, and found that several successful attacks were carried out on European victims within the space of a 13-minute phone call. The attack relies on a skilled social engineer walking the victim through the process and two malware strains: An NFC relay malware called WindRelay, first discovered in August 2025, and SpyNote, a remote access trojan (RAT) that was leaked on cybercrime forums as far back as 2016. It goes like this: The attacker calls the target while posing as a helpdesk employee at their bank, convincing the victim-in-waiting that there is a problem with their payment card. While still on the phone, the attacker gets the target to install a version of SpyNote on their Android device. The file name includes the target's name, which the researchers said could suggest that each target is singled out specifically, and a degree of reconnaissance has to be carried out prior to the attack. Once installed, the attacker quickly uses the RAT's remote access to quietly install WindRelay on the attacker's device without their knowledge or input, all while the call was ongoing. The attacker then instructs the target to tap their payment card on their NFC-enabled smartphone and, when prompted, enter their PIN. WindRelay then captures the data from that interaction between the card's chip and the reader, similarly to how genuine point-of-sale machines authorize contactless payments. This is known as a live EMV APDU exchange. In order to fraudulently make payments using this data – without physical access to the payment card or the cardholder – the attacker must have a second device capable of using this data to authorize a payment. This could be a second Android smartphone capable of loading this data and transmitting it to an attacker-controlled POS terminal, which is linked to a fraudulent merchant bank account, or an ATM. The attacker then uses the captured live exchange data to execute fraudulent charges on the victim's card, authorized using the PIN they entered during the call. Group-IB said in its write-up: "In effect, the victim's card and the real terminal are still talking directly to each other – the fraudster's setup is just an invisible relay in between, passing the exchange back and forth across a distance. "Because the terminal is genuinely completing a live handshake with a real card, the transaction goes through and processes the withdrawal or purchase as normal." Doubling down on their access, Group-IB also noted that the attackers in one instance used their RAT access to access the victim's banking app and take out loans in their name. The researchers also said they observed 23 WindRelay-related samples uploaded to VirusTotal between November 2025 and July 2026, with signs pointing toward targeting victims in Czechia, Slovakia, and Slovenia. They were not able to pin down the attacker(s) behind the malware, although they said it was independently developed and the samples they saw uploaded to VirusTotal all contained unique UI elements, such as the victim's name, just like with the RAT. "This suggests the threat actor behind these campaigns most likely has the capability to dynamically build malicious applications tailored to individual victims," said Group-IB. "This case shows that modern fraud rarely relies on one technique," it added. "Here, the fraudster combined three capabilities in a single session – a live social engineering call, a personalized RAT for remote device control, and an NFC relay malware for physical cash-out. "The fraudster also used these capabilities to hit two separate payout channels – a digital loan and card-present purchases – before the bank or victim could react." The attack is similar to previous NFC relay-related campaigns, such as NGate in 2024 (and more recently in 2026), and Ghost Tap, the techniques involved in which closely align with WindRelay. Ghost Tap, also discovered in 2024, relies on a Chinese malware sold throughout the country's cybercrime Telegram communities, and according to Group-IB, it was responsible for losses exceeding $355,000 between November 2024 and August 2025 alone. ®

  •  

Sovereign AI overcomes compliance challenges and feeds innovation in public sector and other regulated industries, say HPE and NVIDIA

Enterprises must "feed" their AI ventures with reliable, well-curated data if they want worthwhile returns. But new mandates governing AI deployments also require them to act as careful custodians of their data, along with the infrastructure, supply chain, software and other aspects of their IT landscape. Sovereign AI gives an enterprise, or even a nation state, complete control over how its AI systems are built, deployed, operated, and governed. It emphasizes control over data, infrastructure, models, operations, and policies, often within specific legal, regulatory, or geographic boundaries. Sovereign AI matters for organizations and governments that need AI environments aligned with their own security, compliance, privacy, and governance requirements. For some, that means keeping sensitive data in-country. For others, it means controlling who can access systems, where workloads run, how models are governed, and which local laws apply. The HPE Sovereign AI Factory lets customers in highly-regulated industries keep sensitive data, models, and operations under strict local control, using customized, validated infrastructure integrated with HPE services from deployment to operational support that helps customers with security, compliance, and control across infrastructure, data, and AI models. In this Hot Seat, James Hayes hears from Thierry Pienaar, HPE fellow, Chief Technology Officer for HPC & AI worldwide at HPE, and Kaushik Shirhatti, VP, AI factory at NVIDIA, on how HPE and NVIDIA work together to help customers meet the latest sovereign AI mandates. Pienaar and Shirhatti sit on the frontline of this shift in AI development. In the video they cut through market hype and misunderstandings to identify the key considerations for any organization's sovereign AI program. You will learn: Why a sovereign AI strategy has become a priority so quickly, as governments and highly-regulated sectors seek greater control over their AI systems, data, and innovation plans. The key drivers for sovereign AI, and how it differs from at-scale standard AI workloads. How sovereign AI introduces new rigors of security, such as air-gapping and identity federation. How agentic AI plays into sovereign AI requirements, and how agents can be protected while retaining the freedom to deliver useful results. How HPE and NVIDIA partner to deliver sovereign AI factories that let customers build and run AI models while retaining complete control over sensitive data, infrastructure, and compliance boundaries within their defined borders. Learn more about how the HPE AI factory with NVIDIA addresses the main challenges organizations face when they run AI at-scale here. Sponsored by HPE.

  •  

Uber Freight keeps on trucking after extortion crew breaks in

Uber Freight says it is investigating a "data security incident" days after the Helix extortion group listed the company on its data leak site on August 6. Helix claims to have stolen nearly 1 million files from mailboxes, OneDrive accounts, the accounts receivable department, and other repositories. An Uber Freight spokesperson told The Register that the incident was under investigation but had not disrupted the company's daily operations. "We are investigating a data security incident involving unauthorized access to a portion of Uber Freight's systems and repositories. The incident was identified, contained, and remediated, and we promptly engaged federal law enforcement. "There has been no impact to Uber Freight's business operations, which continue in the normal course without disruption. Our systems are secure and fully operational." Uber Freight is the ubiquitous ride-sharing company's lesser-known logistics arm, which describes itself as "one of North America's largest managed transportation and multimodal capacity networks." Its website claims that it manages 18 million shipments carrying more than $17 billion worth of goods each year. The Register did not download the files Helix released in stages, and Uber Freight neither confirmed nor denied that the material was authentic. Helix is one of several recently established extortion brands linked by researchers to infrastructure associated with BlackFile, which retired its name in May. According to Google Threat Intelligence Group (GTIG), Helix shares infrastructure with the Pink, Redact, and Falcon brands. Google tracks the wider cluster of activity as UNC6671. Operators associated with UNC6671 often use vishing to gain an initial foothold, posing as IT helpdesk staff overseeing mandatory security migrations, Google said. They contact employees on their personal phones and use device code phishing to obtain credentials and authenticated sessions before siphoning data from cloud services such as Microsoft 365. They have also targeted Okta identity infrastructure. Researchers believe the UNC6671-linked brands have recently shifted toward organizations in higher-value sectors. Since June, they have favored technology, transportation, and hospitality targets after focusing on manufacturing, real estate, healthcare, and insurance during April and May. Why multiple brands emerged after BlackFile shut down is unclear. GTIG said the strategy could "compartmentalize operations, hide overall breach volumes, and isolate any negotiation fallout," although other plausible explanations exist. Internal disagreements over matters such as handling finances and operational security could have led to the fragmentation of UNC6671, GTIG speculated. The core members may also be looking to retain control over the intrusion and data theft aspects of the attack, while outsourcing negotiations and extortion. The different groups may also just be using the same commoditized phishing tools. ®

  •  

Exposed: Woeful security at UK criminal records office that led to sensitive data leak

The UK's criminal records office, ACRO, has escaped a fine and received a regulatory reprimand after security failings potentially exposed highly sensitive data belonging to nearly 11,000 people. ACRO disclosed the "cybersecurity incident" in April 2023, and said at the time that it had no evidence to suggest that any data was compromised. However, it has now emerged that attackers maintained persistent access to ACRO's website and content management system for more than seven months, and staged sensitive data for possible exfiltration. According to the Information Commissioner's Office (ICO), which reprimanded ACRO rather than imposing a financial penalty, the breach was uncovered in March 2023 only because ACRO was investigating a separate intrusion. The watchdog said that while investigating an SQL injection attack that compromised 15 sets of credentials, most belonging to ACRO staff, investigators found evidence of separate intrusions dating back to July 8, 2021. The incidents fell into three categories, the ICO said. Some did not affect personal data, while others exposed only a small number of account credentials. The most serious involved ACRO's website and its Kentico content management system. The intrusion began on August 5, 2022, and the attackers maintained persistent access, without being detected, until March 14, 2023. The ICO found that ACRO ran version 12.0.0 of Kentico CMS from September 2019 until March 2023 without applying the patches and hotfixes released during that period, leaving known vulnerabilities unresolved. The ICO blamed poor communication between ACRO and its managed service provider. The supplier did not learn that patching was its responsibility until February 2020 and continued to assume that it was not required to monitor actively for security updates. "The ambiguity around who was accountable for identifying necessary Kentico CMS patches created a gap where patches and hotfixes were missed, which ultimately left ACRO's website vulnerable," the ICO said. Further, ACRO did not have a documented policy that covered patching Kentico CMS, nor could it demonstrate how vulnerabilities were identified or prioritized. ACRO's Trend Micro antivirus generated alerts, but nobody appears to have been minding them. The records office told the ICO that, for reasons redacted from the postmortem, it was "unable to establish what business processes existed for the assessment or handling of security alerts at the relevant time." It also could not identify which roles were responsible for reviewing these alerts at the time, ultimately resulting in them going unread. ACRO's poor logging means that, despite an extensive investigation by a third-party cybersecurity outfit, it remains impossible to determine whether the affected data was exfiltrated. Investigators did establish that the attackers staged the data for possible exfiltration between February 15 and 16, 2023. The potentially exposed material included: Police Certificate Applications Subject Access Request (SAR) forms and International Child Protection Certificate forms Names Dates of birth Addresses National Insurance numbers Passport and driving licence details Bank account information Biometric data Highly sensitive criminal offence and special category information ACRO notified 84,048 people of the breach, although investigators later determined that data relating to no more than 10,920 individuals had potentially been staged for exfiltration. Of these, ACRO received 35 formal complaints citing personal distress and concern about the risk of identity theft and financial loss, according to the ICO's reprimand document [PDF]. "Complainants included those connected to Police Certificates, International Child Protection Certificates, and victims of domestic violence." The ICO also received six complaints citing similar concerns. ACRO's saving grace was its network segmentation, which prevented the attackers from straying beyond the CMS into other systems, the ICO noted. Since the attack was discovered, ACRO has made a number of improvements to its security, including decommissioning the compromised infrastructure (although not until June 2023), implementing a SIEM, improving visibility, monitoring, and network segmentation, hardening systems, and migrating to Salesforce Experience Cloud. Jonathan Balmforth, group manager of civil and cyber investigations at the ICO, said: "This case highlights how basic cyber security failings can create significant risks for thousands of people, particularly where organizations process large volumes of highly sensitive personal information. "Organizations must ensure there is clear accountability for identifying, assessing and applying security updates. They must also have effective monitoring in place so that warning signs of cyberattacks are identified, investigated and acted upon promptly. "The lessons from this incident are clear. Having the right policies, responsibilities and oversight arrangements in place is just as important as having the right technology. "We welcome the improvements ACRO has made since these incidents. We hope other organizations will use this case as an opportunity to review their own processes and responses to ensure personal information remains properly protected." ACRO welcomed the reprimand from the ICO and highlighted the steps it has taken since to bolster its security. A spokesperson told The Register: "Since the cybersecurity incident was identified in March 2023, we have worked hard to strengthen our systems and safeguards. "In particular, we immediately took the previous website offline and subsequently decommissioned it. We also took steps to protect customers, including making sure anyone potentially affected was informed at the earliest possible stage." They went on to say: "We accept the ICO's findings of the infringements. We are grateful for the recognition from the Information Commissioner of the multiple remedial steps ACRO has taken in light of this incident and are committed to maintaining high standards of data protection and information security in future." ®

  •  

Akira ransomware scum blocked victim's security tools – and broke their own encryptor

An Akira ransomware affiliate rebooted a victim’s computer into Safe Mode to kill its security tools – and in the process sabotaged their own malware when the limited-function startup mode also broke their encryptor. “Akira's encryptor is engineered for speed, relying on concurrent worker threads and heavy memory mapping rather than simple sequential read-and-write operations. That high-performance design is likely what caused it to break in Safe Mode,” Huntress security operations analyst James Northey told The Register. “Safe Mode loads a minimal driver set, which can restrict storage controllers and pagefile availability,” he added. “A heavy, multi-threaded encryptor strains that constrained environment far more than the lighter, streamed-I/O designs used by other ransomware families.” But the ending wasn't entirely happy for the victim. The attacker had already stolen credentials and data from file shares before Safe Mode prevented the ransomware from doing its job. Northey detailed the incident in a Wednesday blog and cautioned that this was more likely a memory-configuration issue, and shouldn't be taken as a practical defense to prevent Akira ransomware from locking up valuable files. “Ultimately this could be a case of winning the battle, but not the war,” Northey wrote. “It’s possible that a host with more physical memory or a larger page file might give akira.exe enough virtual memory to encrypt the endpoint in Safe Mode,” Northey added. “Akira’s developers or affiliates could retool the encryptor to reduce its memory demands or make its Safe Mode launch sequence more reliable, meaning that the same failure may not occur in a future intrusion.” Nonetheless, there's one big lesson here: For the love of all that is holy, turn on multi-factor authentication (MFA). Here’s a closer look at what happened, and how to prevent it from happening to you. How it started… In early August, Huntress responded to an incident that began, as most Akira intrusions do, with a SonicWall SSL VPN. On August 4, the VPN logged a credential-spray attack: a burst of failed logins using bad credentials that it denied. But then, seven minutes later, one of them succeeded when the attacker used a valid VPN account that wasn’t protected by MFA. Once they had gained access, the criminal accessed the domain controller via Remote Desktop Protocol (RDP) and queried Active Directory to hoover up detailed information about the network, users, groups, computers – essentially everything an attacker needs to know about who and what to target for lateral movement and mass encryption in a ransomware attack. “The enumeration was a full-property dump of every user and every computer in the domain,” Northey wrote. The Akira ransomware affiliate then moved to the application server to start collecting stolen data, downloading WinRAR and using that tool to archive mapped file shares before sending the stolen data to cloud storage using s5cmd, a fast S3 transfer utility. They also installed remote desktop software AnyDesk, configured to start with Windows, and abused this legitimate tool as a remote-access trojan, giving the attacker hands-on keyboard control. They also used it as a command-and-control channel to drop more malware, including the very cleverly named akira.exe ransomware binary – because no one would guess what that executable could be, right? Then came the Safe Mode reboot Here’s where things went sideways for the ransomware scumbag. About three hours into the intrusion, the attacker forced the computer to reboot into Safe Mode with Networking, a boot mode that only loads essential drivers and services, blocking most third-party software. Attackers, especially ransomware gangs, do this to disable endpoint detection and response products and other security tools that would otherwise detect and stop their malware from infecting victims’ machines. While some ransomware crews, including Snatch and AvosLocker, have abused Safe Mode for this purpose for years, Huntress has never seen Akira do it until now. In this case, the reboot stopped the Huntress agent and disabled Microsoft Defender's real-time protection, preventing Defender from quarantining the malicious file. “The attacker got their blind window,” Northey wrote. “What they didn't get was a clean detonation.” Thirteen seconds after the reboot, the computer started spewing memory errors. Safe Mode boots with constrained virtual memory, and it didn’t have sufficient memory to encrypt the endpoint. Essentially, Safe Mode not only acted as an EDR killer, but also borked the ransomware. In addition to the obvious recommendations – like make sure you receive alerts on bursts of failed VPN logins against multiple usernames from one source, and require MFA on every VPN account – Huntress suggests organizations keep an eye out for this Safe Mode play. Specifically, “alert on boot-configuration changes and Safe Mode boots: msconfig.exe / bcdedit activity, Kernel-Boot EID 27 with a SAFEBOOT load option, Kernel-General EID 12 BootMode=2, and third-party security services stopping (System EID 7036),” Northey wrote. Also, “watch for tooling being added to the Safe Mode minimal-service registry list.” ®

  •  
❌