Modalità di lettura

This JCB doesn't dig – it does 406 mph

A JCB has set a new world land speed record, passing 406 mph (653 kph) at Utah's Bonneville Salt Flats. The JCB in question isn't a digger or a dumper, but a hydrogen-powered racer known as the JCB Hydromax, driven by retired Royal Air Force fighter pilot Wing Commander Andy Green. It set the record for the fastest a hydrogen-powered internal combustion car has ever travelled, averaging 406.320 mph (653.909 kph) across two runs at the salt flats this week. JCB says the Hydromax is powered by two production-based engines derived from those used in its commercial machinery. The engines are made at JCB's factory in Foston, Derbyshire, and deliver a combined 1,600 bhp. The firm began a £100 million ($135 million) hydrogen engine investment program in 2021, arguing that battery power is practical for smaller machinery but less suited to heavy equipment requiring long operating hours and rapid refueling. It was given permission to sell hydrogen engines by licensing authorities across Europe last year. Another European engineering company, Bosch, is investing in hydrogen power and disclosed some of its plans back in 2023. However, JCB conceds that the two engines in the Hydromax were "extensively rebuilt to suit the demands of breaking the speed record," fitted with spark plugs designed for a Le Mans 24 Hour engine, for example. Burning hydrogen produces no carbon dioxide at the tailpipe, although a combustion engine can still generate nitrogen oxides. JCB estimates that a full record run consumed just over 2 kg (4.4 pounds) of hydrogen and produced 18 liters (about 5 gallons) of water. Beneath the bodywork is a steel-frame chassis similar to that of a conventional racing car, built with a minimal amount of high-strength tubing. The driver sits in a composite monocoque sub-chassis under a drag racing-style steel roll cage. One of the engines is located behind the driver's position and spins the rear wheels, while the other is located in front and drives the front wheels via a front-facing gearbox. Wing Commander Green is no stranger to land speed records. He was at the controls of the ThrustSSC vehicle when it broke the sound barrier on land, and also drove JCB's Dieselmax when it set the world diesel land speed record. According to JCB, its chairman, Anthony Bamford, led the hydrogen engine project and came up with the idea of a bid for the hydrogen world land speed record. "Twenty years ago we came to Bonneville with JCB Dieselmax and showed what British engineering could do with diesel power. Today we have done it again, this time with engines powered by hydrogen," Bamford said. "It shows hydrogen works, and it works today at the highest level with zero emissions." The Fédération Internationale de l'Automobile (FIA), motorsport's global governing body, officiated the attempt and has confirmed the 653.909 kph (406.320 mph) record. ®

  •  

Trump wants to grant private cyber firms a license to hack back

Donald Trump is allowing government agencies to contract private cybersecurity companies to carry out operations against cyber-enabled transnational criminal organizations (CE-TCOs). The US President signed a memo on Wednesday confirming a strategy hinted at earlier this year, saying participating companies can support national operations against criminals, including cyber surveillance and technical disruptions of their networks. The latter, described as "Cyber Effects Operations," covers activities that cause "the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon." Although the memo establishes a distinction between cyber effects operations and cyber surveillance missions, it acknowledged that the latter will also inevitably involve some disruption or manipulation of systems in order to carry out the surveillance. Surveillance operations are designed for intel gathering, either to support further snooping or for later use in cyber effects operations, with the intent of remaining undetected. Trump described CE-TCOs as "any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests." Crucially, the definition excludes entities directly associated with, or operating wholly on behalf of, foreign governments. No stepping on TAO's toes, of course. Participating companies will undergo "rigorous vetting" and will be subject to "strict operational procedures," the memo adds. The operational procedures are to be drawn up within 60 days and codified by program executive directors working with the Homeland Security Council. Companies wishing to be called up for service will have to demonstrate that they have the technical capabilities to carry out the required operations, and be willing to prove this each year via annual evaluations. Program managers must ensure that the operational procedures open opportunities for highly resourced, large organizations, as well as "smaller, more agile companies" that may prove useful for "specialized or discrete tasks." The Justice Department will also play a role in authorizing operations, particularly those targeting US residents or raising domestic legal issues. Participating companies will also be prohibited from executing operations that could lead to "critical outcomes," which is shorthand for attacks that result in the loss of life or serious injury, or those that could be seen as an armed attack under international law. These companies will also be required to maintain a bond or escrow of at least $1 million, which shall be forfeited if they violate the terms of their contracts. Unleashing Trump's cyber army The White House published "President Trump's Cyber Strategy for America" document in March, which promised to "unleash the private sector by creating incentives to identify and disrupt adversary networks and scale our national capabilities." The document [PDF] also stated: "We will leverage the immense talents and ingenuity of our private sector research base. "We will establish a new level of relationship between the public and private sectors to defend America in peace and war." The announcement prompted legal eagles and think tanks to ponder the implications of such a move. Many wondered how the promise to mobilize the private sector would be put into practice. They did not then have the details contained in this week's memo, and some assumed participating companies would support operations against nation-states. This particular program, however, excludes entities acting directly on behalf of foreign governments. Writing for the Royal United Services Institute (RUSI) and citing reporting available at the time, cyber and tech research fellow Gareth Mott said that the US Computer Fraud and Abuse Act (CFAA) might need to be amended before American companies could legally offer such services. Experts from law firm Skadden, Arps, Slate, Meagher & Flom agreed, despite the US Cyber Strategy not mentioning any plans for legislative changes. They wrote: "Any attempt to more directly involve the private sector in offensive cyber actions will likely require further legal and regulatory changes before it can be meaningfully implemented. "Even if the administration were to issue new enforcement guidance redirecting prosecutions away from hack-back cases, the availability of civil penalties under the CFAA and its five-year statute of limitations would likely render such executive actions significantly less impactful. "Technology companies should consider closely monitoring developments to track how the administration plans to enact such incentives." However, Jenner & Block lawyers noted in an analysis published by Lawfare that a provision of the CFAA could limit participating companies' exposure. Title 18 of the US Code, § 1030(f), says the CFAA does not prohibit lawfully authorized investigative, protective, or intelligence activity by a US government agency or intelligence agency. Participating companies might therefore be protected when acting under government contracts and direction. However, no court has determined whether that exemption covers private companies carrying out such work. "No court has addressed whether this exception provides any protection for private-sector entities engaged to perform these activities on behalf of the US government and, if so, under what circumstances," the lawyers wrote. "At the very least, it is unlikely that a court would interpret this provision to extend to private companies engaged in independent offensive operations, without government direction or involvement." The last part is key: because the US government will draw up procedures and direct the companies' involvement, the work may fall within the CFAA exemption. Whichever way the US constructs its private sector play, it represents a significant shift in the country's cybersecurity policy, and perhaps that of other nations further down the line. As Mott points out, US allies will certainly be keeping tabs on the private sector program's success, and its take-up from the companies it looks to attract. ®

  •  

The backup Microsoft never promised you

Confidence in an organization's cyber recovery capabilities deserves scrutiny. If a ransomware attack disables the SaaS data tenanted in the Microsoft cloud ecosystem, the data the business depends on as its lifeblood, the pace at which operations resume rests on assumptions that often prove wrong. Anyone whose answer is "It's all good. Microsoft has my back on this one with its comprehensive native retention and recovery capabilities" is due a reality check. With agile business tools like M365 and Entra ID and solid backend infrastructure in the form of Azure, Microsoft brings a lot to the SaaS party. Both IT departments and MSPs need to be aware, however, that Redmond operates on the same shared responsibility model as other major SaaS providers. In the event of a cyberattack, the recovery burden splits between what the cloud provider handles and what falls to the subscriber alone. MSPs face the additional pressure of meeting stringent SLAs, working with clients’ preferred providers or tooling, and managing their own staffing and profitability accordingly. Microsoft ensures that its services keep running in the aftermath of a strike but does not promise to restore data to a specific known good point before the disaster. That gap always sat with the customer, and planning for it before problems hit beats improvising while picking up the pieces. "There's a common misconception about what Microsoft is responsible for, as distinct from the service they're providing," explains Brent Torre, GM of cyber resilience . Microsoft's native tools, he points out, address problems like short-term accidental deletion and aspects of data governance. They are not a backup solution and will not protect against ransomware or recover data. "Microsoft is clear that whether it's a SaaS application like Microsoft 365, a platform application like SQL Server, or even VMs running in Azure, the customer is always responsible for the information that's in that service, as well as devices, accounts and identities," he adds. "If you get compromised and the attacker starts deleting data, Microsoft has no responsibility for that." A world of pain The gap between availability and true cyber recovery is misunderstood, and it has widened into something of a chasm in recent years. There are three contributing factors to this gap. The first is the evolution of cyberattacks. Typical cyberattacks have pivoted from muscling past a defensive barrier to targeting human weakness, because strolling in through the front entrance with a stolen pass is easier than shimmying through a forced window. Identity has become the primary attack surface. Credential compromise, or identity-based initial access, removes the need to find a vulnerability to exploit and requires only an unwary employee. AI is now a staple weapon in the criminal arsenal, augmenting exploitation techniques such as phishing, social engineering, deceptive emails and spoofed websites, all convincingly used to trick users into typing passwords into a portal controlled by the aggressor. The technique can get more scientific than that. Automated AI-powered bots test millions of leaked username and password pairs across hundreds of different websites, exploiting the common habit of password reuse. Microsoft Entra ID, the vendor's cloud-based identity and access management service and the very tool designed to keep criminals out, is now a prime vector for attack and no match for stolen identity. Once an attacker compromises Entra ID with pilfered credentials, without setting off alarms, they have a free run at gathering data from mailboxes, OneDrive, SharePoint, Teams and other soft targets. The ransomware attack itself can then be launched with ease and at leisure. Another contributory factor is that the vogue for moving workloads to infrastructure and platform as a service (IaaS and PaaS) models shows no sign of abating. Organizations tend to retain some functions on-premises, put some in SaaS applications, and others in cloud environments, but are often guilty of not protecting and managing everything to the same level of quality. Data gets backed up in a variety of locations, yet whether it is all equally recoverable in the event of a breach is another chink in the armor that nobody understands. The 'as a service' model is popular, but it is the weak link when ransomware strikes. The third part of the problem is the emergence of multiple compliance requirements mandating cyber resilience along with correct backup and recovery procedures, for which many organizations are ill-prepared. Together, these pressures give criminals room to do enormous harm to data, business operations and compliance posture in the gap between attack and restoration of SaaS availability. Given that Microsoft's native retention and recovery capabilities are not designed to deliver true cyber resilience, restoring the business to how it was before the attack is something to plan for in advance. Time for independent backup protection "At Kaseya we regularly recommend that you keep a copy of your data, independent of the primary environment it's operating in," advises Torre. "This needs to be something immutable that you can recover from even if the Microsoft or Google or Salesforce ecosystem goes down." This kind of protection is best delivered as a dedicated cloud-to-cloud backup solution stored outside the main SaaS tenant, he argues, an approach increasingly written into cyber insurance and compliance requirements. By pulling copies of regularly targeted data from the Microsoft tenant for storage offsite in a third-party datacenter, organizations can be sure that if SaaS credentials are compromised, critical assets remain safe from attack. Restoration can then push what is needed directly back into the SaaS environment, even where the original tenant has been destroyed. "In fact some people find it faster to stand up a new shell and rebuild it than try to gain access back into a compromised tenant," notes Torre. "Whether you're an internal IT technician, working the night shift, or an MSP needing to live up to your SLAs and maintain profitability, you require a solution that's super straightforward and you need to be able to trust that the recovery will work. Both IT departments and MSPs should be looking out for a solution that's incredibly easy to use. Disaster recovery isn't the only job that they have." A good platform, he says, focuses not just on guaranteeing recovery but on keeping the hygiene of the cyber resilience estate at a high standard without endless human intervention. It should also make certain that Microsoft 365 and Entra ID are restored together in a single workflow, so identity and the data it grants access to come back online in the right order rather than in separate stages. Choosing the right platform Datto is a cybersecurity and data protection business owned by Kaseya. Datto SaaS Protection for Microsoft 365, Datto Backup for Microsoft Azure, and Datto Backup for Microsoft Entra ID are designed between them to close the gap between availability and recovery by storing protected copies of tenant data in the Datto Cloud, outside the Microsoft environment. In this way a compromised production tenant does not take the recovery point down with it. "With our M365 backup, we're protecting one million users worldwide," claims Torre. "A lot of organizations have built trust around our ability to protect and recover their data. We offer a trusted platform for recovery that focuses on ease of recovery, ease of deployment, not just for M365 but for Azure and Entra ID too." Both IT bosses and MSP players need to recognize that a ransomware attack, or other cyber crisis, is a matter of when rather than if. Recovery matters more than protection, because protection is certain to fail at some point, and traditional approaches to backing up data are no longer sufficient on their own. Anticipating disaster is not enough; the organization also needs to be set up to withstand it. That means being as certain as possible that the Microsoft environment can be recovered rapidly, down to the last scrap of data. This capability underpins modern business workflows and operations. Microsoft tracks more than 4,000 identity attacks every second and analyzes 38 million identity risk detections daily — no organization is off the target list. When an attack lands, the restoration clock is already ticking, and any delay in fully restoring IT operations and key environments to their pre-attack state can mean the difference between survival and collapse, with profit, regulatory standing and reputation all riding on the outcome. Securing data with purpose-built cyber resilience platforms that enable rapid, clean recovery is how organizations meet that test. MSPs looking to close the gap can start with the Datto MSP Buyer's Guide to Microsoft Entra ID Backup Sponsored by Datto.

  •  

Mystery attacker spent a year raiding Salesforce and ServiceNow portals

Someone has spent more than a year rifling through Salesforce and ServiceNow portals around the world, harvesting data that organizations accidentally left open to anyone who came looking. Researchers at Reco have named the operation "City-Forum" after a domain connected to its infrastructure. The domain has pointed to the attacker's server since March 2025, although exactly when the campaign began is unclear. Reco says the activity is continuing and increasing in volume. Reco isn't naming the targets, but said it spotted the attacker poking around portals belonging to telecoms companies, banks and other financial services firms, enterprise software vendors, cybersecurity companies, and public sector bodies. "In the last year, we've seen many threat actors that use Aura enumeration against over-permissioned Salesforce guest users. This actor is different," said Nitay Bachrach, senior security researcher at Reco. On Salesforce, the attacker targets Lightning Web Runtime (LWR) sites through the UI API's GraphQL layer, an approach Reco says it has not found documented in public research or incorporated into publicly available attack tools. Over at ServiceNow, the same operator queries a native Service Portal search endpoint that has received little public attention. The tooling also checks whether Salesforce sites permit self-registration, potentially offering a route from anonymous guest access to an authenticated external account with permission to see considerably more data. Reco said it saw these checks across most of the Salesforce targets it examined. "The threat actor created their own toolset, based on research and techniques which are not well documented online," Bachrach said. "They studied the services to map different common data leak vectors – this is an advanced actor." This isn't casual poking around either. Reco said the busiest Salesforce target logged more than 560,000 events from the attacker's IP during the campaign, almost all attempts to enumerate data available to guest users. Reco linked the Salesforce and ServiceNow activity to the same server, which targeted multiple organizations around the world. More unusually, the attacker hasn't bothered changing its infrastructure: the same IP address and domain have remained in use for at least 17 months, with related custom tooling doing the rounds across both platforms. ServiceNow told us it is "aware of a security company’s blog post claiming certain configurations are creating security risk. As noted in the security company’s post, there are no allegations of a compromise of the ServiceNow environment. Nonetheless, we take third party reports seriously and are investigating accordingly. Our priority is to protect our customers, their data, and our systems." Salesforce has not yet responded to The Register's questions. Salesforce customers have already had one very public lesson in what can happen when guest access gets too generous. In March, ShinyHunters told The Register it had stolen data from around 100 high-profile companies and nearly 400 websites after going after over-permissioned Experience Cloud guest accounts. City-Forum isn't doing quite the same thing, and Reco isn't blaming ShinyHunters. "We don't know who this is, and we're not ruling anyone in or out," Bachrach said. Reco says all the activity it observed was conducted without authentication, with the attacker collecting information that organizations had exposed through permissions, sharing rules, search sources, or other configuration choices. "If the guest can read a record, so can anyone on the internet," Bachrach warned. "That is not a platform vulnerability." Which is good news for Salesforce and ServiceNow, perhaps, but rather less comforting for anyone now wondering what their guest account has been showing the guests. ®

  •  

Ryanair adds Google to its dual-cloud flight plan

Ryanair has signed a five-year agreement with Google Cloud covering AI, productivity tools and multi-cloud infrastructure, just weeks after renewing its deal with rival AWS for another five years. The Irish budget airline says it will deploy Google Workspace and Google Cloud services across its 35,000-strong workforce as it pursues a target of 300 million passengers a year by 2034. We asked how much this deal is worth, but Google declined to say and Ryanair did not respond. The rollout includes the Mountain View firm's Gemini Enterprise agentic AI platform, which Ryanair intends to use to automate some decision-making, optimize flight crew logistics, and improve staff productivity. The airline will also use Google DeepMind's AlphaEvolve to refine algorithms and WeatherNext for forecasting and maintenance planning. Ryanair renewed its agreement with AWS for another five years on July 27, making AWS and Google Cloud the two pillars of what the airline itself calls its dual-cloud resilience strategy. Google says the dual-cloud setup will allow critical systems to switch between providers if one suffers an outage, helping keep flight operations, and customer services running. Under the renewed AWS agreement, Ryanair will continue using services including Amazon Quick, Amazon Bedrock, and Amazon Bedrock AgentCore for workloads ranging from its website to operational planning across a fleet of 647 aircraft. Reg readers may recall that AWS and Google Cloud were touting a jointly developed multi-cloud connectivity service at the end of last year. This links Google's Cross-Cloud Interconnect with AWS Interconnect, allowing customers to set up a private high-speed link between resources they have running on the two cloud platforms. "Ryanair is on an incredible growth journey to 300 million passengers by 2034. To support this growth, we need to ensure we have excellent infrastructure resilience, and our new dual-cloud strategy provides this," commented the airline's CEO, Eddie Wilson. "We are thrilled to be Ryanair's AI transformation partner," stated Maureen Costello, Google Cloud VP for UK, Ireland and Sub-Saharan Africa. "This agreement demonstrates how deploying generative AI at scale – coupled with modern collaboration tools for frontline workers – can help industry leaders scale securely, reduce operational costs, and redefine the travel experience." ®

  •  

AWS key exposed in JavaScript may have lit way to Beacon's charity data

Beacon, a CRM provider for charities and nonprofits, says an AWS access key "potentially exposed in public JavaScript build artifacts" is the leading suspect in its July breach. The revelation came in the company's first update on the attack in more than a week. If the access key was exposed in public build artifacts, it raises questions about why Beacon's development pipeline and code review controls failed to catch it. Beacon used stronger wording about the potential data loss, confirming that a copy of the database was made and assessing that it was probably downloaded in readable form. "This update confirms… that a copy of the database which holds all Beacon customer data, including attachment files, was made and likely downloaded in a readable format by the threat actor," wrote CTO David Simpson. "Analysis of the AWS Cost & Usage reports across May-July 2026 has been conducted. This data showed a significant increase in data transfer on 27-28 July 2026. This timing correlates with the malicious activity, which supports an assessment that substantial downloads occurred." Beacon's logs cannot reveal which specific records left its systems, although the company has confirmed that a copy of the database containing all customer data and attachments was made. In an FAQ accompanying the update, Beacon advises customers to assess the likely exposure by reviewing what they stored in their CRM instance. Many of the charities that have confirmed they are affected have said the data mainly pertains to personal information and details about donations. Simpson said Beacon's AWS data was encrypted at rest, but the compromised access key may have allowed the attacker to retrieve it in readable form. The malicious activity began in the early hours of July 27, according to Beacon's root cause analysis, matching its initial estimate of the incident timeline. The company has more than 1,500 customers, although it has not established how many had data taken. The malicious activity lasted one hour and 27 minutes, Beacon said, and the attacker established no persistence mechanisms in AWS. Simpson warned customers that "there are things we may never be able to find out about this incident," and that other details won't be shared to protect Beacon's security position. He promised to provide customers with a summary when the investigation concludes in a few weeks, but warned that "the level of detail contained in this next and final update may not be any more than" Beacon published on Wednesday. "I recognise this is frustrating, but unfortunately it is the reality of complex incidents like this. With this in mind, we would recommend making your own risk assessments now regarding onward notification to impacted data subjects using your knowledge of the data you process and store with Beacon." Since Beacon disclosed the attack on August 4, the number of high-profile charities confirming they are affected has grown every day. Early confirmations came from the likes of Molly Rose Foundation, Macmillan Cancer Support Jersey, and English National Ballet. Sheffield Hospitals Charity, Shrewsbury and Telford Hospital Charity, the British Deaf Association, and Lincoln Cathedral are among those that have since joined the list. The Charity Commission said that "a number of charities have submitted serious incident reports," and that the volume of these reports is causing delays to responses. "We appreciate your patience and understanding as we prioritise instances of the greatest risk," it said. ®

  •  

Twitch feeds your streams to Amazon's AI unless you tell it to stop

Twitch has given streamers a switch to stop their channel content being fed into Amazon's generative AI machinery, but naturally it is turned on by default. The Amazon-owned streaming platform has added a "Training for Generative AI" control to channel settings, allowing streamers to opt out of having their content used for future GenAI model improvements. With the setting enabled, Twitch says channel content – including livestreams, videos on demand, clips, highlights, text, images, and chat messages – may be used to train Amazon's generative AI models. The benefits aren't confined to Twitch either, as the company says the resulting models may also be used elsewhere in the Amazon empire. For example, Twitch says audio from streams could be used to refine speech-to-text models, improving captions on Twitch as well as "across Amazon." Streamers who would rather not contribute their channels to Amazon's AI ambitions can opt out, but they'll need to do it themselves. Twitch has helpfully enabled the setting by default. Twitch chief product officer Mike Minton offered a refreshingly uncomplicated explanation for that decision during a livestream discussing the changes: "If it was opt-in, nobody would opt in," he said. "That's honestly the answer. So it's going to be on by default." The new control also doesn't mark the beginning of Amazon using Twitch material to build AI. According to Ars Technica, Minton confirmed at an event hosted by The Information in 2024 that Amazon was already using Twitch data to train AI models. What's changed is that Twitch users now have a dedicated way to tell it to stop using their content for future generative AI training. There are some wrinkles, naturally. The channel owner's setting determines whether messages posted in its chat can be used, so opting out on your own channel does not protect what you type in somebody else's if that streamer leaves training enabled. And Twitch's wording is conspicuously forward-looking: opting out means content won't be used for "future" GenAI model improvements. The company doesn't say that flicking the switch somehow extracts anything that has already made its way into a model. The Register has asked Amazon which of its AI models have been trained on Twitch content, how long it has been using the data, and whether opting out has any effect on material already used for training. We've also asked whether models trained on Twitch content are used in products available to Amazon customers or third parties. For now, Twitch creators finally have a way to keep their content off Amazon's generative AI training menu. All they have to do is find the switch Amazon would plainly rather they left alone. ®

  •  

Everything is better with pickles... except Windows

BORK!BORK!BORK! "Everything is better with pickles," trumpets a Wendy's sign. Everything is also better with a helping of bork, if the screen is to be believed. Spotted by an eagle-eyed Register reader in Vancouver, the display shows something amiss with Windows Phone Link – although why a PC encouraging customers to drop dollars on a Dill Pickle Chicken Sandwich needs the app is anyone's guess. The error itself usually comes up when something running Windows has been a bit careless with stack memory. Perhaps there's been a stack overflow, a software conflict, or a memory shortage. The usual fix is to reach for the power button or perform a restart. The more technically minded might try to diagnose the whoopsie and fix it without a boot cycle, although had a more technically minded person set up the system in the first place, it's unlikely that the PhoneExperienceHost.exe application would have reared its ugly head in this way. Phone Link connects a Windows PC to an Android phone or iPhone. The theory goes that users can keep track of mobile notifications, send and receive messages, or deal with calls from their Windows desktop. It arrived with Windows 10 as Your Phone before Microsoft renamed it Phone Link and continued adding features. Ordinarily, the service doesn't use much in the way of memory or CPU. However, something has clearly upset the instance here, much as an excess of dill pickles might disagree with the customer. While we're sure the foodstuffs on offer are excellent (although our reader told us they were only popping in for a Frosty Dairy Dessert rather than anything slapped with a dill pickle), we might give the chicken sandwich a miss this time. Even Windows appears less than keen. ®

  •  

Passwords stored in public Google Doc then showed up in search results

PWNED Welcome, once again, to PWNED, the weekly column where we highlight others’ security failures. Hopefully, there’s a lesson in all this, but it could just be “stop shooting yourself in the foot.” Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request. Our story today comes courtesy of Siim Kostabi, co-founder of Pageloot, a company that provides QR codes businesses can use for marketing. Kostabi’s tale of tech terror reminds us that credentials, even for a staging server, have a lot of value in the wrong hands. He explains that his company brought in a contractor to help with some API integrations on the back end. That developer had the credentials for the staging environment and wanted to be able to view them across different devices they were using for the job. So what was the developer’s solution to the very common problem of keeping track of usernames and passwords? They could have chosen a password manager. They could have written the passwords down in a paper notebook and kept it hidden from prying eyes. They could have gotten a password tattoo. They could even have emailed the passwords to themselves and it would have been smarter than what they did. Instead, the outside developer decided to store their password in a Google Doc. And they set that Google Doc to be viewable by anyone on the internet who had the link. And then, one day, an employee at the company found the Google Doc with the staging credentials in it because Google Search had indexed it and offered it as a search suggestion. “A developer on our team was debugging something unrelated and typed our domain into Google Search,” Kostabi recalls. “The autocomplete surfaced one of our staging hostnames followed by what looked like a credential string. We checked, and there was a publicly accessible Docs URL.” Yikes! Just imagine that not only are your company’s credentials available to anyone online, but they are indexed in Google Search for the world to find! Once they discovered the problem, Kostabi’s company immediately cut access for that contractor and rotated all of its exposed credentials. They also set a new rule: no storing passwords on Google Docs, Slack, Notion, or other collaboration tools. In a separate incident, Kostabi heard from a Pageloot customer, a mid-size retailer, whose QR codes were suddenly directing users to a competitor’s site. After investigating, he found that a disgruntled ex-employee’s credentials had not been revoked and that the former employee had used that access to redirect all of the retailer’s URLs, costing it customers. The takeaway from both of these problems is that you need to carefully control access. Former employees should immediately lose access to everything and current contractors should be reasonably intelligent people you can trust. “Both situations were completely avoidable with basic hygiene,” Kostabi said. “Proper offboarding, access reviews, and not treating shared docs like private vaults.” ®

  •  

Cisco thinks Mythos means instant death for unsupported networking kit

Cisco CEO Chuck Robbins says “The Mythos Effect” will see customers scour their networks for unsupported devices and replace them ASAP. Mythos is Anthropic’s bug-finding model and has proven so effective that vendors and open source projects are now finding more security flaws and pushing more patches. Speaking on Cisco’s Q4 earnings call yesterday, Robbins said customers he speaks to are aware of Mythos, and fearful that the model and others like it will mean that unsupported devices become too risky to operate once patches stop flowing. “I had one of my CEO friends who runs a major manufacturer in the US … their team called early on in the Mythos wave and just said: ‘Hey, listen, we got to get some of this stuff that is past LDOS’ [last day of support].” Robbins said other Cisco customers have done likewise. “We’ve seen the pipeline increase meaningfully as a result of Mythos, which is really showing up as a network refresh,” he said. The CEO thinks some customers might be paying for new Cisco kit with their security budgets rather than cash allocated to networking expenses. He’ll take it either way. CFO Mark Patterson said buyers who need rapid replacements for their kit won’t have to wait. “We really do not have any significant lead time issues that we are seeing,” he said, before indulging in a little competitive sniping by adding “unlike we have heard a number of different peers talk about.” Robbins said The Mythos Effect is one of three factors contributing to a “supercycle” of network spending. One is the need to prepare for quantum computing, either with quantum-safe networks or quantum-resistant decryption. The other is, of course, AI. Robbins thinks agentic AI will take off, and see Cisco sell bucketloads of fresh kit to hyperscalers, and replacement kit to businesses that want to implement AI and realize their existing networks aren’t up to the job. Cisco reported $17.3 billion revenue for the quarter, and $63.3 billion for the year, increases of 17 percent and 12 percent respectively. Net income rose 51 percent to $3.9 billion for Q4, while the full-year result of $13.27 billion was a 30 percent jump. “We delivered the highest revenue, operating margin, and earnings per employee in thirty years,” Robbins crowed. “In FY27, we expect all these metrics to continue to improve.” Investors appear to have been a little confused by what they heard, as Cisco’s share price spiked after its earnings announcement, before settling four percent lower than its closing price. Robo-support revealed Robbins also touched on Cisco’s own use of AI, which he said saw 145,000 support cases “resolved entirely by AI with zero human intervention” during FY26. If you’re a Cisco customer, let us know how that works for you. The CEO also revealed that Cisco operates an in-house AI Assistant called “Circuit” that he said “is fully embedded in how Cisco operates” and handled over 75 million prompts in Q4 alone. “Circuit runs on our Secure AI Factory infrastructure which improves GPU utilization and automatically routes each task to the appropriate large language model, allowing us to manage token consumption,” he said. ®

  •  

Tencent says it could make instant profits on $53B hardware splurge by renting it for AI workloads

Chinese tech giant Tencent has turned its back on instant profits, betting that a new business unit that creates its own AI and embeds that in its products will pay off to a greater extent than cashing in on demand for computing resources. During the company’s Q2 earnings call yesterday, Bernstein analyst Robin Zhu asked when Tencent expects to see a return on investment from the $53 billion capital expenditure it made in the quarter. Chief Strategy Officer James Mitchell said demand for compute resources is so strong that Tencent could recover its depreciation costs “almost immediately” if it rented its infrastructure. Company president Martin Lau said if Tencent behaved like a neocloud it would “achieve a decent return in an immediate timeframe” as the company has offers for its compute capacity “at more than 30 percent profit compared to the price that we paid just a few months ago.” Lau said Tencent is instead “playing a different game or executing a larger strategy in that we are allocating a very substantial proportion of the new compute to building our own models to state-of-the-art status, and also to deploying, popularizing, and bringing our own AI applications to market leadership in China.” He said Tencent believes that if Tencent can provide “superior intelligence that we can achieve through state-of-the-art models, through market-leading AI applications … we can then convert into superior economic returns over the longer term.” Those returns will come from selling tokens for services like WorkBuddy, which Tencent says is an agent swarm that can “plan, execute, and run tasks in parallel, handing back complete deliverables end-to-end in one flow.” Tencent also offers CodeBuddy, a code generation tool that Mitchell said is accelerating cloud migration projects and therefore creating more business for Tencent cloud. Tencent released its latest model, the 295-billion open-weight Hunyuan-3 in July. Lau described it as “a very small model” and promised that the forthcoming Hunyuan-4 will be bigger – and more capable than larger models from other companies. He also said Tencent is designing its products specifically to work with Hunyuan-4, and that mutual optimization will make those products more powerful than would be the case if they relied on other models. The company also plans a fifth version of Hunyuan, and Lau said at some point Tencent will deliver a state-of-the-art model. Tencent is already producing thoroughly modern results for a tech giant: Revenue for Q2 grew 11 percent to reach $30.3 billion. Net profit rose nine percent to $10.3 billion. The company’s flagship messaging apps, Weixin and WeChat, saw average monthly active users rise seven million to 1.349 billion. Advertising-related revenue rose 22 percent, and the company’s gaming biz grew 17 percent in China alone. Investors aren’t sure what to make of this. The company’s share price has trended down since Wednesday and dipped around three percent since the company’s earnings announcement. ®

  •  

Chinese Loongson processors have leaky caches, researchers find

Researchers from Germany’s Helmholtz Center for Information Security have found processors made by China’s Loongson have leaky caches that attackers could use to seek specific data. Loongson has developed its own LoongArch instruction set architecture (ISA) that blends approaches used by MIPS and RISC-V. On a site called LoongLeakAttack.com, the researchers explain that they found the leaky cache using a fuzzer, then noticed that the LoongArch ISA manual mentions an instruction that leaves 32 bits of a memory register in an “uncertain” state. “Our analysis reveals that under certain circumstances, the ‘uncertain’ data originates from the L1 data cache,” the four researchers wrote. “Since this cache is not isolated between applications, LoongLeak can leak data from other applications and the operating system. Even worse, an attacker can prime the CPU’s internal state to target the leakage to a specific cache set.” In a paper [PDF] explaining their research, authors Lorenz Hetterich, Tristan Hornetz, Fabian Thomas, and Michael Schwarz share case studies that “include recovering full-disk AES keys from the kernel, partial root password hashes from user-space, and bypassing traditional software defenses such as ASLR and stack canaries, all within seconds.” In case that’s not scaring you enough, they also point out “LoongLeak can be exploited from unprivileged user space, containers, or virtual machines.” The flaw even means “LoongLeak can cross the virtual machine boundary and leak host data from inside a VM.” “As the leakage is architectural, it requires neither high-resolution timers nor traditional sidechannel amplification, and it grants the attacker precise control over cache set and line offset,” they add. And the cherry on top is that software mitigations aren’t possible. Users with chips that possess the flaw either need to replace them or make sure they don’t allow any private data to enter or remain in the L1 cache. Making that happen can require turning off one thread per core, effectively disabling hyperthreading. The news isn’t all bad, because Loongson fixed the flaw in an update to its model 3A6000 processor, and the mitigation of evicting cache data slows performance by just 1.4 percent in the worst case. The blast radius of this flaw is also likely to be limited, because Loongson chips are hardly used outside China. The company offers chips for PCs, servers, and appliances such as printers. China’s government promotes use of Loongson chips as part of its plan to reduce dependence on imported tech. Lenovo makes laptops that use Loongson chips but only sells them in China. The Register has discussed the company’s chips with other major PC-makers, who told us they would adopt Loongson product if users want them, or if doing so becomes necessary to participate in the Chinese hardware market. But we’ve not seen a non-Chinese company adopt the processors. China’s government, however, may be nervous about this research as it has instructed public sector buyers to buy local products. Perhaps some government agencies are running vulnerable devices? If that’s the case, Beijing has its work cut out spotting any attacks, because the researchers could find “no specific tools or methods to detect if LoongLeak is being exploited.” ®

  •  

OpenAI ad service can bill customers for up to one day after they pause campaigns

OpenAI appears to be serving ads after buyers have halted their campaigns, and charging them for the privilege. OpenAI began testing ad sales in ChatGPT in the US back in February and has been gradually expanding the service in other regions, including the United Kingdom, Mexico, Brazil, Japan, and South Korea as of Tuesday. Given that a substantial minority of ChatGPT's user base pays for the service (50 million out of 900 million weekly users as of February 2026), advertising revenue appears to be an important part of OpenAI's plan to defray the cost of providing its service and to convince investors that it has a path to profitability ahead of a future initial public offering. Online ad-marts from the likes of Google and Facebook give advertisers control over when and where their ads will appear, but don't always stick to instructions. The AI biz's ad service appears to have similar ad timing and billing accuracy issues. Ed Bolton, managing director of UK-based Excel4Business, told The Register that his company encountered "an odd billing practice" when it started experimenting with ChatGPT Ads in the US and Canada. "We were running campaigns in the US and Canada … and noticed ads were being delivered through the night/morning on paused campaigns," he explained. When Bolton pointed this out in a support message thread, an OpenAI customer service representative initially acknowledged the failure. "We have now confirmed that your campaigns continued serving after they were paused," said an OpenAI support specialist in an email provided to The Register. "This was not a reporting delay. The campaign was marked as paused, but the separate ad-level status used by the serving system did not refresh promptly, so an ad that was still active at the ad level continued to run. Our Ads Engineering team has escalated this defect and is working on an additional production fix." The support reply goes on to state: "Our review has confirmed £60.72 in invalid charges from the original occurrence and approximately £6.47 from the August 4–5 recurrence. We are extending that reconciliation to the additional activity you reported on August 6. We are preparing the confirmed invalid charges for billing review, but I cannot confirm the final refund or credit amount until the latest activity has been reconciled and that review is complete." Bolton responded that the acknowledged problem – ads being served after he disabled the campaign – had been occurring for a longer period of time and requested a more complete reconciliation of ad billing. Several days later, OpenAI's support rep reversed the prior determination and declined to offer any refund or credit because the company's Advertising Terms state that ChatGPT Ads may be delivered even after a customer cancels a campaign and the advertiser still has to pay for those unwanted ads. "Section 11.1 of our Advertising Terms provides that ads may continue running for up to one business day after a campaign is canceled or changed, and advertisers remain responsible for ads delivered during that period," the support message explains. "Pausing a campaign constitutes a campaign change and does not guarantee that delivery or associated charges stop immediately." A spokesperson for OpenAI confirmed that's the case, explaining that it can take a business day to cancel or change a campaign and that this doesn't represent an intentional effort to run ads after an advertiser has disabled a campaign. Based on the times cited in the support message thread, the most delayed ChatGPT ad ran about 94 minutes after Excel4Business paused a campaign. Bolton said unwanted ads appeared for a far longer period — more than 10 hours after campaigns were paused. OpenAI isn't the only ad provider that allows itself a business day to turn off its ad spigot for a particular customer. Other advertising services impose similar terms. "So the terms … seem to be a standard which is used in digital advertising, which some legal team wrote at some point, saying that we've got a 24-hour grace period if you stop a campaign," Bolton said - before adding that he has run Google AdWords campaigns for 17 or 18 years and has never had that issue. If ad buyers were not able to stop an AdWords campaign quickly, you could easily spend half a million dollars, he said. Nonetheless, some Google advertising customers have complained about post-pause ad serving. Why it might take so long to stop serving ads at a time when applications and servers can be spun up and torn down in seconds isn't immediately clear. One can order and receive physical goods from Amazon.com in less than one business day. It may be that there's no financial incentive or regulatory pressure to tackle the problem, and a significant financial incentive to ignore it. "My understanding is that such a clause is included in terms and conditions so as to cover issues with latency, and not to allow them to run ads for 24 hours longer than instructed," said Bolton. "Regardless, they cannot retroactively apply a clause from terms and conditions after making a written settlement offer." ®

  •  

Rent-a-GPU outfit Nebius promises rapid 1 GW powerup plan isn't nebulous

Rent-a-GPU cloud Nebius plans to bring online over a gigawatt of datacenter capacity every year starting in 2027, but doing so will require playing the margins and juggling a mountain of debt. “Our future capacity pipeline effectively makes Nebius one of just a few companies in the world able to build more than a gigawatt of new capacity a year and we plan to do so in 2027,” CEO Arkady Volozh boasted on Wednesday’s earnings call. The endeavor won’t be cheap. In 2026, Nebius says it expects to burn between $20 billion and $25 billion on capital expenditures to bring between 800 and 1,000 MW worth of bit barn capacity online. A big chunk of that will be covered with customer prepayments — essentially deposits for future capacity. According to Nebius CFO Dado Alonso, the firm is on track to exceed $9 billion in customer prepayments this year. But this alone won’t be enough. So like most big rent-a-GPU rackets, including CoreWeave and Lambda, Nebius is taking on debt to finance its expansion. Specifically, the company is using its GPUs and contracted cash flows as collateral to secure favorable interest rates on the coveted accelerators. Nebius landed its first asset-backed debt facility valued at $775 million in July, and Alonso says the company will continue leaning on the financing scheme going forward. No surprise. Along with debt financing, the company is also exploring an asset-light model where “partners finance, build, and operate the facilities, whereas Nebius brings the full-stack platform and demand,” Volozh told analysts. In other words, Nebius gets to claim deployed capacity it didn’t have to front the cash for, but that relies on the company's ability to rent capacity for less than it can resell it for. While hitting a gigawatt of capacity a year won’t be cheap, Volozh is confident the investment will pay off in the long run. He claims that for every megawatt deployed, Nebius will bring in between $20 million and $25 million in revenues for medium-term leases, and $40 million to $50 million for short term leases up to six months. On the low end of the scale, that implies $20 billion a gigawatt, although Nebius Chief Product and Infrastructure Officer Andrey Korolenko notes that while the company expects to have up to a gigawatt of connected power by year’s end, not all of it will be active and generating revenue until 2027. “You have to commission the datacenter, build the network, build the clusters, deploy the platform, then onboard the customers, and then the revenue generation starts,” he said. “That takes a few months.” “In terms of our guidance from 800 megawatts to a gigawatt… I would think about that being active throughout the first half of 2027,” he added. But even if Nebius has to wait until 2027 to pull a full gigawatt of capacity, that still implies a massive uplift in revenue, which is forecast to hit $3 billion to $3.4 billion for fiscal year 2026. The past quarter accounted for just $582 million, which suggests Nebius will bring in more than $2 billion over the next two quarters if you believe its projections. There are a lot of faithful among the investor community, as its share price surged more than 30 percent on Wednesday following the report. While revenues are expected to increase dramatically over the next few quarters, it's easy to sell dollar bills for 70 cents apiece. Whether the company actually manages to turn a profit renting the shovels of the AI gold rush is another matter entirely. In Q2, the company posted an operating loss of $176 million, a jump from the $111 million operating loss it booked in the year-ago quarter. ®

  •  

'Near-autonomous' AI agents attack Taiwan's nuclear safety agency

Suspected Chinese cyber operatives used publicly available AI tools to compromise Taiwanese government systems before expanding the attack to its nuclear safety agency, supply-chain vendors, and at least seven energy companies in what security researchers called a "near-autonomous attack." Over the first four days of July, AI agents compromised 85 government user accounts and extracted more than 2,500 personnel records, according to Dream, an Israeli cybersecurity firm. Researchers uncovered evidence of the attack in a 160 MB online archive containing 1,395 files documenting the operation. Dream, in research published on Wednesday, detailed the intrusions and said that the suspected Chinese hackers hit “government entities in Asia” - but declined to say which government had been attacked. A person familiar with the attack confirmed to The Register that Taiwan was the target. The Financial Times first reported on Dream’s research and identified Taiwan. While the security firm doesn’t attribute the agentic attack to the Chinese government or a specific hacking group, the operational documentation “points to a Chinese-language operator,” the researchers said. According to Dream, the attack framework, built on open source Hermes and OpenClaw AI agents, deployed up to eight sub-agents, each assigned to its own targets and attack techniques, across 12 “attack waves” between July 1 and July 4. First, the agents mapped the entire government ecosystem, extracting embedded URLs, API endpoints, OAuth client IDs, and Keycloak configuration objects from a single government portal. This portal allowed the agents to identify 21 connected government systems and every supported authentication flow. “On one target alone, it discovered 36+ API endpoints spanning account management, user data retrieval, file upload, and administrative functions - many completely unauthenticated,” the Dream threat researchers wrote. “Critically, it found that one of the systems exposed its entire user database without any authentication - thousands of employee records including names, departments, and SSO account IDs.” Multiple entry points After mapping the government’s attack surface, the agents found multiple entry points including three hidden API endpoints that accepted any request body and returned a valid authenticated session without requiring user credentials. Using employee usernames harvested from an unauthenticated API, the agents broke into a government department’s office automation portal, solving its CAPTCHAs with 100 percent accuracy. The agents also tested predictable password patterns based on each employee’s ID, and cracked 85 accounts across multiple password-spray rounds. Eighty-four of the 85 cracked accounts successfully authenticated to the department's internal information system, giving the attackers access to internal dashboards, equipment management interfaces, and personnel statistics pages. In total, the illicit access allowed the agents to exfiltrate a ton of government information, including more than 2,564 personnel records, a full JSON export of all department system users, seven SSO client secrets, six internal database credentials across MSSQL, Oracle, and Sybase, and internal network IP ranges. But wait, there's more And then, the agents pivoted to the Taiwanese government’s supply chain. “It expanded the operation to government IT supply chain vendors, a nuclear safety agency, a government email system, and 7+ energy sector companies - scanning them all in parallel for misconfigurations, exposed admin interfaces, and exploitable vulnerabilities,” the researchers wrote. Notably, the attack framework implemented what the AI tools called “learning cycles.” These are autonomous sessions where the models search vulnerability databases, GitHub repositories, and other security research for specific techniques, CVEs, and common weaknesses to exploit in the targeted government's infrastructure. Additionally, when the AI framework made a mistake, it “self-corrected,” according to Dream, catching errors and fixing them through its own verification process. This near-autonomous attack comes as frontier model makers OpenAI, Anthropic, and Meta all admitted that their agents went rogue, escaped from their training environments, and autonomously hacked other organizations and people. OpenAI technical staffer Michael Dalton, in a Black Hat briefing last week about the Hugging Face attack, said “AI orchestrated, fully automated offensive attacks are real now.” “In the near future, we should expect that threat actors will intentionally deploy, optimize, weaponize, and use offensive agent collectives in the manner that you have just described here,” he added. It appears that the future is now. ®

  •  

Deeply buried 16-year-old SQLite bug caused last year's Tailscale outages

Users of peer-to-peer networking outfit Tailscale might have struggled through some surprising outages beginning late last year. After a six-month investigation, the team finally knows why: A bug in SQLite’s write-ahead log that had remained hidden for 16 years. The Tailscale team announced in a Wednesday blog post that it had finally addressed the issue with the help of SQLite maintainers, who even had to create a new tool (with Tailscale funding) to log virtual file system activity in order to track the thing down, which Tailscale software engineer Alex Chan described as resisting “all our initial attempts to find it.” According to Chan, the problem goes deep into the nature of SQLite – so deep that the database maintainers actually had to add code to reproduce it. To understand what happened, it’s necessary to know how Tailscale works. The service, based on the WireGuard VPN protocol, directly connects devices in a virtual private mesh network. It’s designed to be low complexity and easy to implement for everything from remotely accessing a NAS to connecting teams in a unified private network. Each mesh network, or "tailnet," lives on one of several servers, where a SQLite database manages all the information about the tailnets it houses. “We’ve used SQLite as our primary database since 2022, and we chose it because it's well-known, reliable, and widely used,” Chan wrote in the company’s post-mortem. But a year ago, something went very wrong. “In our current backup pipeline, we take a complete snapshot of the database every few minutes, then upload the entire SQLite file to an S3 bucket,” Chan said, but in August 2025 those backups began detecting database corruption, repeatedly, with no obvious common trigger. The Tailscale team couldn’t reproduce the issue because there were no reliable triggers for it. No low-level code had been changed in months. A review of everything that touched SQLite turned up nothing. Working with the SQLite team, the Tailscalers tried to figure out what could be causing it – POSIX locks broken by close() calls? Nope. Mismanaged memory? Not that either. SQLite being used from multiple threads with thread safety disabled? Nuh-uh. “After every incident, we gathered more data, added more diagnostics, and systematically ruled out these theories,” Chan explained. The WAL-Reset bug comes out of hiding Suspicion was closing in on SQLite’s checkpointing process, which is how it takes new database entries out of a temporary hopper for addition to the master database file. SQLite has an option to improve performance and concurrency known as the Write-Ahead Log (WAL), which serves as the aforementioned hopper. Writing the WAL to the database occurs in a process known as checkpointing. “In most deployments, SQLite itself decides when to do a checkpoint, and the process is invisible to the end user and developer,” Chan said. “In our control plane, we take manual control of the checkpoint process so we can run fast and consistent backups.” The SQLite team wrote a new tool to take a closer look at the process: a virtual file system shim that extensively logs checkpointing activity. After waiting for the next corruption incident, the teams had their answer, dubbed the WAL-Reset bug. Described by Chan as “a rare data race in the SQLite source code between a checkpoint and write transaction,” it’s essentially a collision between checkpoints and writing data to the WAL. “If a write occurs at a specific time during a checkpoint, the checkpointing process gets confused — it thinks some of the pages have been copied from the WAL into the main database file, but they haven’t,” Chan said. Those pages are never written and are permanently lost, but pages that reference those pages are still written, corrupting the database and causing all hell to break loose. According to the SQLite team’s WAL-Reset writeup, the issue can be triggered only when WAL mode is active and multiple database connections are open on the same file, and because there has to be reading and writing going on at the same memory spot at the same time, it’s incredibly unlikely to happen in most situations. Tailscale’s decision to perform manual checkpoints was a rare exception. SQLite maintainers believe the bug was present going all the way back to version 3.7.0, released in July 2010; it’s now fixed, and the SQLite team recommends users update to a fixed version, though it stresses the bug is extremely unlikely to occur in ordinary use. “This bug, though rare, does have serious consequences,” the SQLite WAL-Reset notice states. The incident contains a useful reminder for devs: Even the most boring, reliable software poses risks when operated in a non-standard fashion. “Most people use SQLite in a standard configuration and never face this sort of issue,” Chan said. “By taking manual control of the checkpointing process and running at our own aggressive pace, we stepped off the well-trodden operational path.” ®

  •  

Node.js creator liberates Durable Objects from Cloudflare

We've got good news for developers who are enamored with Cloudflare Workers and Durable Objects but don’t want to be tied into that company’s backend infrastructure. Last week, Node.js creator Ryan Dahl unveiled his latest project, celld, which he described on X as “a self-hosted, distributed Durable Objects and Workers implementation.” Dahl’s celld model is compatible with Cloudflare’s Workers and Durable Objects’ JavaScript APIs, but he claims that it is much less expensive to run. The project is no mere budget-minded open source rip. On celld’s web page, Dahl and his team characterize their replication of the Durable Objects architecture as a “love letter.” Cloudflare’s Durable Objects is a single-threaded object with a unique global ID and its own storage, where user data is stored in its own copy of SQLite. It runs on the Cloudflare serverless Workers runtime, which runs apps embedded in isolates—a type of lightweight virtual machine supported by Google's V8 JavaScript engine. First devised by Kenton Varda and Cloudflare, Durable Objects is “one of the best primitives distributed systems has been handed in years,” celld’s creators write. Unlike traditional serverless platforms like AWS Lambda, the Durable Objects model co-locates the data with compute, while using single-threaded execution to eliminate complex concurrency issues. “A primitive this good deserves to run anywhere,” the celld page states. Serverless but stateful Since its introduction in 2020, Durable Objects has been used to build low-latency, highly distributed Web applications. It is a stateful serverless execution environment, a data cache that can also do computation. Using the WebSocket API, the Durable Object can connect many simultaneous users at once in a live environment. WebSockets’ Hibernate mode can put the object to sleep, so cloud bills don’t accrue when no one uses the app. As a result, the stateful serverless model is best suited for real-time collaborative applications, such as multi-player games, team productivity apps and AI agents. Cloudflare uses Durable Objects for its serverless SQL service and AI Gateway. One YouTube tutorialist explained that using Durable Objects allowed him to eliminate an entire stack of tools (Amazon API Gateway, Apache Kafka, Redis, AWS Lambda and EventBridge, Apache Airflow and Spark all get name-dropped) because Durable Objects can handle all these functionalities “at a smaller scale.” Giving Durable Objects an open source home Dahl is one of the world’s foremost experts at JavaScript I/O, having created Node.js, a JavaScript runtime that runs the world’s fastest Web applications (and inadvertently introduced the JavaScript world to “callback hell,” where the language's asynchronous operations forced coders to pass functions as nested callbacks, resulting in ungainly and unintuitive messes of code). Dahl later went on to refine his ideas of asynchronous JavaScript with a second-generation JavaScript runtime called Deno. Celld does away with the Cloudflare backend, and instead uses the Amazon Simple Storage Service (S3) or equivalent as the storage engine. It also uses the Tokio Rust asynchronous runtime. As with Durable Objects, each celld object gets its own copy of SQLite. Dahl promises this open source backend will be “orders of magnitude cheaper at scale” than Durable Objects. Dahl estimated that 100 resident Durable Object cells cost $415 a month on Cloudflare, whereas the celld implementation would run only about $49 a month, built on a DigitalOcean S3-compatible bucket on an 8 GB droplet. Further savings should ensue as the workload scales, he argued. Cloudflare disputed Dahl’s numbers, stipulating that $415 a month would be the cost if all the objects were continuously active. If left to slumber, the Durable Objects would cost only $20.65 to house on Cloudflare, a spokesperson told The Register. Whatever its putative thriftiness, the model itself seems to have gained interest on its own merits. “So happy to see support for running durable objects outside of one provider. Upvoted,” one Hacker News reader enthused, noting the concept of a durable object is a valuable abstraction. Indeed, other parties are cooking their own schemes to move the data closer to the computation. For instance, Postgres service provider Neon just introduced its own Neon Functions, which can also co-locate data and compute for long-running workloads. Written in Rust and JavaScript, celld is available under an Apache 2 license. It can ingest JavaScript and TypeScript code. In theory, Rust, C/C++, Go, or Zig code can also be executed through the magic of WebAssembly, which V8 supports with slight modification. But while celld is open source, AI contributions are verboten. “Coding agents make it too easy to send a large, low-context change that costs maintainers more time than it saves,” the GitHub page notes. Human contributions are still welcome, though you should understand what your code does before you submit it. ®

  •  

Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible

If you thought that the famous Spectre security vulns were a relic of 2018, think again. Certain RISC-V chips are still very much subject to this hair-raising hole, researchers say. Spectre refers to a family of vulnerabilities related to speculative execution, a performance optimization technique based on predicting the flow of data before instructions have been executed. Incorrect predictions get rolled back without affecting running applications but nonetheless leave traces that can be recovered and exploited to violate memory protections and access secrets. Spectre flaws have dogged x86 and ARM chips for years, leading computer scientists to develop a series of defenses, including Indirect Branch Restricted Speculation (IBRS), Indirect Branch Prediction Barrier (IBPB), and Single Thread Indirect Branch Predictor (STIBP). Researchers affiliated with academic institutions in Belgium and Germany say that it's been popular to assume that the RISC-V chip architecture isn't affected by Spectre vulnerabilities because it's too simple. That assumption is incorrect, according to a paper accepted at the 35th Usenix Security Symposium, "Spectre on RISC-V Silicon: Attacks and Defenses on Commercial Out-of-Order Processors." It says that commercially available out-of-order RISC-V processors (SiFive P550 and T-Head Xuantie C910/C920) are vulnerable to all major Spectre variants. RISC-V processors that process instructions in-order (SiFive U74, Xuantie C906, C908) do not appear to be vulnerable. Prior research has shown that RISC-V processors used for academic research (e.g. BOOM, RiscyOO, RSD, Proteus, NaxRiscv, and NutShell) can be affected by one or more of the Spectre variants, but hasn't addressed commercial silicon. "We demonstrate proof-of-concept attacks on both processors using Spectre-PHT, Spectre-BTB, SpectreRSB, and Spectre-STL, achieving up to 100 percent recall with more than 97 percent precision," the paper states. Spectre-PHT involves mistraining the Pattern History Table; Spectre-BTB poisons the Branch Target Buffer; Spectre-RSB attacks the Return Stack Buffer; and Spectre-STL (Store To Load) exploits mispredicted store-to-load forwarding. To demonstrate the risk to RISC-V, they created a proof-of-concept Spectre exploit that leaks arbitrary Linux kernel memory on the Xuantie C910 at a rate of 338 B/s. Software-based defenses have been developed for these vulnerabilities on x86 and ARM hardware. Unfortunately, the researchers say, these don't necessarily transfer. They also call out RISC-V hardware for its lack of introspection interfaces, necessary to observe and reason about microarchitectural features. In addition, the authors argue, the diversity of the RISC-V hardware ecosystem means that no single mitigation strategy is likely to be effective across all systems. "RISC-V inherits the software and threat model of mature architectures without their accumulated hardening," the authors conclude. "Closing this gap is not a matter of porting individual mitigations, but of building the architectural primitives, hardware transparency, and ecosystemwide tooling that effective Spectre defense presupposes." The authors say they disclosed their findings responsibly last December. Three of their patches have been merged into mainline Linux and two others are under review. SiFive is said to have dealt with P550-specific findings and T-Head (Alibaba) is said to have committed to publishing ad-hoc speculation barriers for their processors at some point. The authors say they decided not to delay publication because Spectre has been around for eight years now. The paper was written by Lukas Gerlach (CISPA Helmholtz Center for Information Security), Marton Bognar, (DistriNet, KU Leuven), Daniel Weber and Michael Schwarz, (CISPA Helmholtz Center for Information Security), and Jo Van Bulck (DistriNet, KU Leuven). ®

  •  

Nvidia's latest solution to soaring enterprise AI costs is...a router?

Soaring AI infrastructure costs and model pricing, combined with uncertain returns on investment, threaten to stall enterprise adoption. To make enterprise AI spend a bit more manageable, Nvidia this week unveiled a new software platform that blurs the line between expensive proprietary models and open weights alternatives. Announced alongside Nemotron 3.5-30B-A3B-Lightning, Nvidia’s latest open weights model, NeMo Switchyard is the GPU giant’s latest overture to enterprise. So what exactly is it? Well, it’s a router. The idea is simple. Switchyard essentially functions as a proxy that sits between the inference server’s API endpoint and the models. But rather than sending every request to the same model, Switchyard can be configured to route prompts to different models in order to optimize for cost, latency, or output quality. By routing some requests to smaller, cheaper, and potentially locally hosted AI models, Nvidia claims Switchyard can cut job completion costs by 74 percent relative to using Claude Opus 4.8 alone, albeit with an approximately six-point accuracy tradeoff. The right tool for the job The key metric in all of this is completion cost rather than price per token. A model might cost one-tenth as much as OpenAI’s or Anthropic’s top model, but if it requires 10x the tokens to complete the request, it isn't actually cheaper. Certain elements of an AI workload may benefit from a larger, smarter model, but not all do. For example, it’d be overkill to ask Claude Opus to generate a title card or summarize a website. It’ll certainly work, but it’ll also cost a fortune compared to Haiku or a locally hosted model that’s been fine tuned just for that purpose. The fewer tokens you burn on the big smart model, the less expensive your API bill is going to be. Nvidia software teams have spent the last several years developing models for this reason. The Lightning model announced this week is only its latest. The 30 billion-parameter MoE model is positioned as a low-latency, general purpose model that can either be used on its own or in conjunction with a larger, smarter model via a router like Switchyard. The company has also developed several application-specific models. Nemotron Parse is one such example. “It’s a small model, one billion parameters, and it’s really good at one task, which is taking a PDF in and then explaining the context inside that PDF whether it’s charts or graphs or tables,” Joey Conway, senior director of AI software and models at Nvidia, explained in a recent interview with The Reg. Many frontier models struggle with this task because PDFs are designed by humans for humans, so by offloading that work to task-specific models, enterprises can not only improve the accuracy of their AI apps, but also reduce costs in the process. This all might sound familiar: It's not the first time we’ve seen model routers employed as a cost-saving measure. Back when OpenAI launched GPT-5, ChatGPT would dynamically route prompts to different versions of the model based on their complexity. As we wrote at the time, OpenAI’s router was likely implemented to reduce the number of compute cycles spent on mundane tasks like rewording emails to sound more professional ("not only … but also"). OpenAI wasn't alone in using routers to reduce model costs. The Wall Street Journal recently reported that AT&T has implemented a “smart router” of its own to automatically select which model to use. Switching from proprietary to open-weight models has reportedly saved the telecommunications giant between 80 and 90 percent in certain applications. Today about 25 percent of the company’s AI workloads are powered by open models. The company’s leadership expects that over the next few years that’ll climb to 70-80 percent. The implementation challenge While the idea of offloading simpler requests to smaller, cheaper-running models sounds intuitive, it’s easier said than done. Title cards and web summaries are relatively straightforward to implement. Open source chatbots like Open WebUI have supported this kind of functionality for more than a year now because it just makes sense. However, sometimes it’s not obvious when and where these task models should be used. Switchyard is Nvidia’s latest attempt to simplify this by automatically routing requests to the right model for the job. However, it’s not the only approach Nvidia is exploring. AI agents and code assistants have the ability to work through problems and then generate skills — essentially standard operating procedures — documenting the process for future reference. Through this iterative process, Conway suggests, agents could essentially teach themselves when and where they can get away with using a smaller, cheaper task model, and where a larger frontier model may be required. “We’re starting to see signs of this sort of agent and subagent type workflow,” Conway said, describing how a frontier model might function as an orchestrator that farms out work to smaller models that are faster and more specialized. It reflects the way companies are structured, he said. “We have people who are specialists and then we have people who help orchestrate that and understand the complexity of the problem.” As an added step, it’s possible for the agents to generate training data on the fly, which could then be used to fine-tune the models to operate more efficiently. Regardless of which approach ultimately wins out, anything that promotes enterprise AI adoption is a win for Nvidia. ®

  •  

Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows

Nightmare Eclipse, the serial zero-day hunter who has an axe to grind with Microsoft, published a new Defender zero-day, ShieldBreak, that apparently bypasses Redmond’s RoguePlanet patch (CVE-2026-50656), allowing attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. According to at least one other researcher, the exploit works. “I've tried it, it works on latest Windows 11,” former Microsoft employee and security expert Kevin Beaumont said. Beaumont also published three detections and hunting queries for ShieldBreak to help defenders rapidly find any stealthy threats. So until Microsoft fixes this latest zero-day, we’d highly suggest using these queries. ShieldBreak is the 10th zero-day from Nightmare Eclipse since they began their scorched-earth strategy against Microsoft in early April. The prolific bug finder and exploit developer is suspected to be a former, very disgruntled, Microsoft employee. And in typical fashion, this latest zero-day drop occurred just hours after Redmond’s monthly Patch Tuesday that fixed 421 security problems in its products - but ShieldBreak isn't one of them. It’s a local privilege-escalation exploit that, according to Nightmare, allows attackers to gain SYSTEM-level privileges. “The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate. Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well,” they said. While Nightmare claims that the new exploit is a patch bypass for the earlier RoguePlanet vulnerability, CVE-2026-50656, which Microsoft quietly fixed in July, Beaumont pointed out that the two flaws operate very differently. “RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files,” he posted. “ShieldBreak user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API).” A Microsoft spokesperson told us the company "is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims." The spokesperson added: "Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible. Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public." This latest zero-day comes a month after Nightmare Eclipse published its previous vulnerability along with partial exploit code. Nightmare’s July drop, called LegacyHive, is a local privilege escalation flaw that targets Windows’ user hives - the section of the Windows Registry that stores a user's specific desktop settings, application preferences, and environment configurations. It's patched with CVE-2026-62832. There's also a June zero-day called GreatXML that Nightmare developed. The researcher claims the flaw allows a local attacker with administrator rights to bypass BitLocker encryption by manipulating the Windows Recovery Environment. But it has been patched with CVE-2026-50661. The prolific zero-day hunter’s earlier seven Windows bugs do have patches. These include BlueHammer (CVE-2026-33825), RedSun (CVE-2026-41091), UnDefend (CVE-2026-45498), YellowKey (CVE-2026-45585), GreenPlasma (CVE-2026-45586), MiniPlasma (CVE-2020-17103), and RoguePlanet (CVE-2026-50656). After threatening legal action against Nightmare Eclipse in May, and then facing rapid backlash from just about every other security researcher on the planet, Microsoft walked back its talk of siccing its Digital Crimes Unit on people who don’t follow its vulnerability disclosure rules.® Correction: There are patches for GreatXML and Legacy Hive.

  •  

OpenWALDO aims to blow the doors off proprietary AI training models

A new project aims to build a shared, open source AI training dataset that anyone can contribute to, much like an open source software project. It aims to make training data more transparent than that of many open-weight models that have recently taken the industry by storm. CentOS and Rocky Linux founder Gregory Kurtzer is behind the effort, dubbed Open Weights, Artifacts, Licenses, Data, Origins (OpenWALDO), and it's funded by CIQ, his AI infrastructure company, which also sponsors Rocky Linux. Kurtzer described the effort as trying to bring the open-source ethos to AI model design, which has yet to be truly open – even downloadable open-weight models still have closed-source training data that is unknown to users, alongside other limitations that make them less than truly open source. “I’ve spent my career watching open source turn users into builders, competitors into collaborators, and shared problems into common infrastructure that operates at massive scale,” Kurtzer said in the announcement. “OpenWALDO brings that proven model to AI. Let’s work together, build its foundation in the open, and collaboratively take AI to the next level.” CIQ, which authored the announcement, argues that open-weight models keep that foundation a secret because of where it comes from: Copyrighted data, responses distilled from other models, user-generated content that may not have been given in a truly open manner, and the like. “There is often no way to know what data trained a given model, under what license, or with what consent,” CIQ said, adding that hidden training data content could taint models, putting customer software stacks at risk. In addition to that, there’s the simple fact that, when everyone is training their AI models in secret, a lot of duplicate work is happening that wastes lots of time and computing resources. A single, shared set of public training data, the OpenWALDO team argues, would not only make training more efficient across the industry, but also mean that every improvement to the dataset could benefit future models trained on it. “A lab or company can take the corpus and its bill of materials as a verified baseline, add its own proprietary data, build, and ship, with a clear, auditable line back to its sources,” CIQ explained. With prices steep and ROI still largely absent, open AI models (not to be confused with OpenAI models) have risen to prominence in the AI zeitgeist lately. Models out of the home of open-weight AI, China, are closing in on the capabilities of closed-source frontier lab models like ChatGPT and Claude, leaving many businesses wondering why they ought to pay through the nose for AI services they don’t own, can’t truly control, and have no visibility into. Some frontier labs have warned that open-weight models pose security and misuse risks. Kurtzer argues that open source software faced similar concerns. “Open source has won this argument before,” he said, pointing to similar arguments made about open code, namely that it’s insecure, impossible to trust, and the like. “Linux didn't win by being certified safe. It won by being inspectable, forkable, and community validated.” “AI is missing that same property, and OpenWALDO is how we build it,” Kurtzer said. Turning to open-source training datasets is a big ask for an industry already so far down the closed training data path, of course, and only time will tell if OpenWALDO is a revolution or another obscure OSS project that gets minimal attention from the AI community. So far, the OpenWALDO dataset contains 167.3 billion reference tokens pulled from things like government records, open-source academic papers, mailing lists, and public domain literature - a drop in the bucket next to the tens of trillions of tokens used to train frontier AI models and their open-weight counterparts. We asked if anyone has trained a model on the OpenWALDO set yet, but CIQ didn’t respond. Those interested in contributing to, or making use of, OpenWALDO can find more on the project’s website (linked above) and its GitHub page. ®

  •  

CoreWeave revenue doubles as debt pile reaches $35.6B

Neocloud operator CoreWeave remains bullish about its prospects, claiming that changing patterns of AI use will create sustained demand for its cloud services. The New Jersey firm is among the most prominent rent-a-GPU businesses spawned by demand for AI training infrastructure, but is now attempting to move up the technology stack – a shift consultants at McKinsey said neoclouds would need to make to survive. "AI is no longer confined to frontier model labs. It is becoming embedded in software, industrial systems, financial markets, enterprise workflows, and national security missions," claims CoreWeave co-founder and CEO Michael Intrator. Intrator also claimed that deploying AI applications is turning compute from a large upfront requirement into a recurring expense. "For the last several years, many organizations treated a model like a deliverable. Train it, deploy it, and move on. Enterprises no longer operate that way," Intrator told analysts on a conference call for CoreWeave's financial results for the second quarter ended June 30. "Training, inference, evaluation, and improvement now form a single continuous loop. Models and agents in production generate real-world data. That data informs evaluation, driving new experiments, which improve the model or application before being redeployed into production." CoreWeave's pitch is that this continuous cycle is changing both the demand curve and the economics of AI. "Compute is no longer a one-time requirement concentrated at the beginning of a model's life. It becomes an ongoing requirement that grows with every application in production and every cycle of improvement," Intrator said, adding: "Our AI native platform was built for this." CoreWeave expects its managed inference services, launched only a few months ago, to reach an annual recurring revenue run rate of at least $250 million by the end of 2026. Yet all is not rosy. Revenue rose 112 percent year-on-year to $2.575 billion, but operating expenses reached $2.624 billion, resulting in a $49 million operating loss. Interest and other costs helped widen the net loss to $626 million. Most of that growth also came from existing clients rather than new ones. According to CoreWeave's Form 10-Q [PDF] filed with the SEC, approximately 93 percent of the revenue increase was attributable to expansion within its existing customer base, with the remainder attributable to new customers. In fact, the firm concedes that just three customers accounted for 36 percent, 26 percent, and 10 percent of quarterly revenue respectively – 72 percent between them. It also warns that "while we have historically experienced significant growth in revenue over the last three years, we cannot predict whether we will maintain this level of growth or when we will achieve positive net income." The company is also carrying substantial debt. As of June 30, total indebtedness stood at $35.6 billion, helping to push quarterly net interest expense up 140 percent to $640 million. CoreWeave also had $10 billion available to borrow under its revolving credit and delayed-draw term loan facilities, according to its Form 10-Q. Nor can it stop spending on infrastructure. CoreWeave expects 2026 capital expenditure of between $35 billion and $39 billion. CoreWeave also warned that it faced competition from much larger and more established cloud operators, such as AWS, Microsoft Azure, and Google, "a number of which are also our current customers," which it may not be able to compete with because of the resources they can bring to bear on building infrastructure and AI development. Investors nevertheless welcomed the results, sending CoreWeave's shares up almost 19 percent in early Wednesday trading, according to MarketWatch. "The opportunity ahead is generational. CoreWeave is the essential cloud for AI," stated Intrator. "Our conviction in our strategy has never been stronger, and our execution continues to reinforce it." ®

  •  

Smooth-talking fraudsters clone contactless cards, authorize payments in just 13 minutes

A new social engineering and malware campaign targets Android users, stealing card details to make payments or withdraw cash. Group-IB discovered the campaign, calling it WindRelay, and found that several successful attacks were carried out on European victims within the space of a 13-minute phone call. The attack relies on a skilled social engineer walking the victim through the process and two malware strains: An NFC relay malware called WindRelay, first discovered in August 2025, and SpyNote, a remote access trojan (RAT) that was leaked on cybercrime forums as far back as 2016. It goes like this: The attacker calls the target while posing as a helpdesk employee at their bank, convincing the victim-in-waiting that there is a problem with their payment card. While still on the phone, the attacker gets the target to install a version of SpyNote on their Android device. The file name includes the target's name, which the researchers said could suggest that each target is singled out specifically, and a degree of reconnaissance has to be carried out prior to the attack. Once installed, the attacker quickly uses the RAT's remote access to quietly install WindRelay on the attacker's device without their knowledge or input, all while the call was ongoing. The attacker then instructs the target to tap their payment card on their NFC-enabled smartphone and, when prompted, enter their PIN. WindRelay then captures the data from that interaction between the card's chip and the reader, similarly to how genuine point-of-sale machines authorize contactless payments. This is known as a live EMV APDU exchange. In order to fraudulently make payments using this data – without physical access to the payment card or the cardholder – the attacker must have a second device capable of using this data to authorize a payment. This could be a second Android smartphone capable of loading this data and transmitting it to an attacker-controlled POS terminal, which is linked to a fraudulent merchant bank account, or an ATM. The attacker then uses the captured live exchange data to execute fraudulent charges on the victim's card, authorized using the PIN they entered during the call. Group-IB said in its write-up: "In effect, the victim's card and the real terminal are still talking directly to each other – the fraudster's setup is just an invisible relay in between, passing the exchange back and forth across a distance. "Because the terminal is genuinely completing a live handshake with a real card, the transaction goes through and processes the withdrawal or purchase as normal." Doubling down on their access, Group-IB also noted that the attackers in one instance used their RAT access to access the victim's banking app and take out loans in their name. The researchers also said they observed 23 WindRelay-related samples uploaded to VirusTotal between November 2025 and July 2026, with signs pointing toward targeting victims in Czechia, Slovakia, and Slovenia. They were not able to pin down the attacker(s) behind the malware, although they said it was independently developed and the samples they saw uploaded to VirusTotal all contained unique UI elements, such as the victim's name, just like with the RAT. "This suggests the threat actor behind these campaigns most likely has the capability to dynamically build malicious applications tailored to individual victims," said Group-IB. "This case shows that modern fraud rarely relies on one technique," it added. "Here, the fraudster combined three capabilities in a single session – a live social engineering call, a personalized RAT for remote device control, and an NFC relay malware for physical cash-out. "The fraudster also used these capabilities to hit two separate payout channels – a digital loan and card-present purchases – before the bank or victim could react." The attack is similar to previous NFC relay-related campaigns, such as NGate in 2024 (and more recently in 2026), and Ghost Tap, the techniques involved in which closely align with WindRelay. Ghost Tap, also discovered in 2024, relies on a Chinese malware sold throughout the country's cybercrime Telegram communities, and according to Group-IB, it was responsible for losses exceeding $355,000 between November 2024 and August 2025 alone. ®

  •  

Sovereign AI overcomes compliance challenges and feeds innovation in public sector and other regulated industries, say HPE and NVIDIA

Enterprises must "feed" their AI ventures with reliable, well-curated data if they want worthwhile returns. But new mandates governing AI deployments also require them to act as careful custodians of their data, along with the infrastructure, supply chain, software and other aspects of their IT landscape. Sovereign AI gives an enterprise, or even a nation state, complete control over how its AI systems are built, deployed, operated, and governed. It emphasizes control over data, infrastructure, models, operations, and policies, often within specific legal, regulatory, or geographic boundaries. Sovereign AI matters for organizations and governments that need AI environments aligned with their own security, compliance, privacy, and governance requirements. For some, that means keeping sensitive data in-country. For others, it means controlling who can access systems, where workloads run, how models are governed, and which local laws apply. The HPE Sovereign AI Factory lets customers in highly-regulated industries keep sensitive data, models, and operations under strict local control, using customized, validated infrastructure integrated with HPE services from deployment to operational support that helps customers with security, compliance, and control across infrastructure, data, and AI models. In this Hot Seat, James Hayes hears from Thierry Pienaar, HPE fellow, Chief Technology Officer for HPC & AI worldwide at HPE, and Kaushik Shirhatti, VP, AI factory at NVIDIA, on how HPE and NVIDIA work together to help customers meet the latest sovereign AI mandates. Pienaar and Shirhatti sit on the frontline of this shift in AI development. In the video they cut through market hype and misunderstandings to identify the key considerations for any organization's sovereign AI program. You will learn: Why a sovereign AI strategy has become a priority so quickly, as governments and highly-regulated sectors seek greater control over their AI systems, data, and innovation plans. The key drivers for sovereign AI, and how it differs from at-scale standard AI workloads. How sovereign AI introduces new rigors of security, such as air-gapping and identity federation. How agentic AI plays into sovereign AI requirements, and how agents can be protected while retaining the freedom to deliver useful results. How HPE and NVIDIA partner to deliver sovereign AI factories that let customers build and run AI models while retaining complete control over sensitive data, infrastructure, and compliance boundaries within their defined borders. Learn more about how the HPE AI factory with NVIDIA addresses the main challenges organizations face when they run AI at-scale here. Sponsored by HPE.

  •  

Uber Freight keeps on trucking after extortion crew breaks in

Uber Freight says it is investigating a "data security incident" days after the Helix extortion group listed the company on its data leak site on August 6. Helix claims to have stolen nearly 1 million files from mailboxes, OneDrive accounts, the accounts receivable department, and other repositories. An Uber Freight spokesperson told The Register that the incident was under investigation but had not disrupted the company's daily operations. "We are investigating a data security incident involving unauthorized access to a portion of Uber Freight's systems and repositories. The incident was identified, contained, and remediated, and we promptly engaged federal law enforcement. "There has been no impact to Uber Freight's business operations, which continue in the normal course without disruption. Our systems are secure and fully operational." Uber Freight is the ubiquitous ride-sharing company's lesser-known logistics arm, which describes itself as "one of North America's largest managed transportation and multimodal capacity networks." Its website claims that it manages 18 million shipments carrying more than $17 billion worth of goods each year. The Register did not download the files Helix released in stages, and Uber Freight neither confirmed nor denied that the material was authentic. Helix is one of several recently established extortion brands linked by researchers to infrastructure associated with BlackFile, which retired its name in May. According to Google Threat Intelligence Group (GTIG), Helix shares infrastructure with the Pink, Redact, and Falcon brands. Google tracks the wider cluster of activity as UNC6671. Operators associated with UNC6671 often use vishing to gain an initial foothold, posing as IT helpdesk staff overseeing mandatory security migrations, Google said. They contact employees on their personal phones and use device code phishing to obtain credentials and authenticated sessions before siphoning data from cloud services such as Microsoft 365. They have also targeted Okta identity infrastructure. Researchers believe the UNC6671-linked brands have recently shifted toward organizations in higher-value sectors. Since June, they have favored technology, transportation, and hospitality targets after focusing on manufacturing, real estate, healthcare, and insurance during April and May. Why multiple brands emerged after BlackFile shut down is unclear. GTIG said the strategy could "compartmentalize operations, hide overall breach volumes, and isolate any negotiation fallout," although other plausible explanations exist. Internal disagreements over matters such as handling finances and operational security could have led to the fragmentation of UNC6671, GTIG speculated. The core members may also be looking to retain control over the intrusion and data theft aspects of the attack, while outsourcing negotiations and extortion. The different groups may also just be using the same commoditized phishing tools. ®

  •  

Exposed: Woeful security at UK criminal records office that led to sensitive data leak

The UK's criminal records office, ACRO, has escaped a fine and received a regulatory reprimand after security failings potentially exposed highly sensitive data belonging to nearly 11,000 people. ACRO disclosed the "cybersecurity incident" in April 2023, and said at the time that it had no evidence to suggest that any data was compromised. However, it has now emerged that attackers maintained persistent access to ACRO's website and content management system for more than seven months, and staged sensitive data for possible exfiltration. According to the Information Commissioner's Office (ICO), which reprimanded ACRO rather than imposing a financial penalty, the breach was uncovered in March 2023 only because ACRO was investigating a separate intrusion. The watchdog said that while investigating an SQL injection attack that compromised 15 sets of credentials, most belonging to ACRO staff, investigators found evidence of separate intrusions dating back to July 8, 2021. The incidents fell into three categories, the ICO said. Some did not affect personal data, while others exposed only a small number of account credentials. The most serious involved ACRO's website and its Kentico content management system. The intrusion began on August 5, 2022, and the attackers maintained persistent access, without being detected, until March 14, 2023. The ICO found that ACRO ran version 12.0.0 of Kentico CMS from September 2019 until March 2023 without applying the patches and hotfixes released during that period, leaving known vulnerabilities unresolved. The ICO blamed poor communication between ACRO and its managed service provider. The supplier did not learn that patching was its responsibility until February 2020 and continued to assume that it was not required to monitor actively for security updates. "The ambiguity around who was accountable for identifying necessary Kentico CMS patches created a gap where patches and hotfixes were missed, which ultimately left ACRO's website vulnerable," the ICO said. Further, ACRO did not have a documented policy that covered patching Kentico CMS, nor could it demonstrate how vulnerabilities were identified or prioritized. ACRO's Trend Micro antivirus generated alerts, but nobody appears to have been minding them. The records office told the ICO that, for reasons redacted from the postmortem, it was "unable to establish what business processes existed for the assessment or handling of security alerts at the relevant time." It also could not identify which roles were responsible for reviewing these alerts at the time, ultimately resulting in them going unread. ACRO's poor logging means that, despite an extensive investigation by a third-party cybersecurity outfit, it remains impossible to determine whether the affected data was exfiltrated. Investigators did establish that the attackers staged the data for possible exfiltration between February 15 and 16, 2023. The potentially exposed material included: Police Certificate Applications Subject Access Request (SAR) forms and International Child Protection Certificate forms Names Dates of birth Addresses National Insurance numbers Passport and driving licence details Bank account information Biometric data Highly sensitive criminal offence and special category information ACRO notified 84,048 people of the breach, although investigators later determined that data relating to no more than 10,920 individuals had potentially been staged for exfiltration. Of these, ACRO received 35 formal complaints citing personal distress and concern about the risk of identity theft and financial loss, according to the ICO's reprimand document [PDF]. "Complainants included those connected to Police Certificates, International Child Protection Certificates, and victims of domestic violence." The ICO also received six complaints citing similar concerns. ACRO's saving grace was its network segmentation, which prevented the attackers from straying beyond the CMS into other systems, the ICO noted. Since the attack was discovered, ACRO has made a number of improvements to its security, including decommissioning the compromised infrastructure (although not until June 2023), implementing a SIEM, improving visibility, monitoring, and network segmentation, hardening systems, and migrating to Salesforce Experience Cloud. Jonathan Balmforth, group manager of civil and cyber investigations at the ICO, said: "This case highlights how basic cyber security failings can create significant risks for thousands of people, particularly where organizations process large volumes of highly sensitive personal information. "Organizations must ensure there is clear accountability for identifying, assessing and applying security updates. They must also have effective monitoring in place so that warning signs of cyberattacks are identified, investigated and acted upon promptly. "The lessons from this incident are clear. Having the right policies, responsibilities and oversight arrangements in place is just as important as having the right technology. "We welcome the improvements ACRO has made since these incidents. We hope other organizations will use this case as an opportunity to review their own processes and responses to ensure personal information remains properly protected." ACRO welcomed the reprimand from the ICO and highlighted the steps it has taken since to bolster its security. A spokesperson told The Register: "Since the cybersecurity incident was identified in March 2023, we have worked hard to strengthen our systems and safeguards. "In particular, we immediately took the previous website offline and subsequently decommissioned it. We also took steps to protect customers, including making sure anyone potentially affected was informed at the earliest possible stage." They went on to say: "We accept the ICO's findings of the infringements. We are grateful for the recognition from the Information Commissioner of the multiple remedial steps ACRO has taken in light of this incident and are committed to maintaining high standards of data protection and information security in future." ®

  •  

Akira ransomware scum blocked victim's security tools – and broke their own encryptor

An Akira ransomware affiliate rebooted a victim’s computer into Safe Mode to kill its security tools – and in the process sabotaged their own malware when the limited-function startup mode also broke their encryptor. “Akira's encryptor is engineered for speed, relying on concurrent worker threads and heavy memory mapping rather than simple sequential read-and-write operations. That high-performance design is likely what caused it to break in Safe Mode,” Huntress security operations analyst James Northey told The Register. “Safe Mode loads a minimal driver set, which can restrict storage controllers and pagefile availability,” he added. “A heavy, multi-threaded encryptor strains that constrained environment far more than the lighter, streamed-I/O designs used by other ransomware families.” But the ending wasn't entirely happy for the victim. The attacker had already stolen credentials and data from file shares before Safe Mode prevented the ransomware from doing its job. Northey detailed the incident in a Wednesday blog and cautioned that this was more likely a memory-configuration issue, and shouldn't be taken as a practical defense to prevent Akira ransomware from locking up valuable files. “Ultimately this could be a case of winning the battle, but not the war,” Northey wrote. “It’s possible that a host with more physical memory or a larger page file might give akira.exe enough virtual memory to encrypt the endpoint in Safe Mode,” Northey added. “Akira’s developers or affiliates could retool the encryptor to reduce its memory demands or make its Safe Mode launch sequence more reliable, meaning that the same failure may not occur in a future intrusion.” Nonetheless, there's one big lesson here: For the love of all that is holy, turn on multi-factor authentication (MFA). Here’s a closer look at what happened, and how to prevent it from happening to you. How it started… In early August, Huntress responded to an incident that began, as most Akira intrusions do, with a SonicWall SSL VPN. On August 4, the VPN logged a credential-spray attack: a burst of failed logins using bad credentials that it denied. But then, seven minutes later, one of them succeeded when the attacker used a valid VPN account that wasn’t protected by MFA. Once they had gained access, the criminal accessed the domain controller via Remote Desktop Protocol (RDP) and queried Active Directory to hoover up detailed information about the network, users, groups, computers – essentially everything an attacker needs to know about who and what to target for lateral movement and mass encryption in a ransomware attack. “The enumeration was a full-property dump of every user and every computer in the domain,” Northey wrote. The Akira ransomware affiliate then moved to the application server to start collecting stolen data, downloading WinRAR and using that tool to archive mapped file shares before sending the stolen data to cloud storage using s5cmd, a fast S3 transfer utility. They also installed remote desktop software AnyDesk, configured to start with Windows, and abused this legitimate tool as a remote-access trojan, giving the attacker hands-on keyboard control. They also used it as a command-and-control channel to drop more malware, including the very cleverly named akira.exe ransomware binary – because no one would guess what that executable could be, right? Then came the Safe Mode reboot Here’s where things went sideways for the ransomware scumbag. About three hours into the intrusion, the attacker forced the computer to reboot into Safe Mode with Networking, a boot mode that only loads essential drivers and services, blocking most third-party software. Attackers, especially ransomware gangs, do this to disable endpoint detection and response products and other security tools that would otherwise detect and stop their malware from infecting victims’ machines. While some ransomware crews, including Snatch and AvosLocker, have abused Safe Mode for this purpose for years, Huntress has never seen Akira do it until now. In this case, the reboot stopped the Huntress agent and disabled Microsoft Defender's real-time protection, preventing Defender from quarantining the malicious file. “The attacker got their blind window,” Northey wrote. “What they didn't get was a clean detonation.” Thirteen seconds after the reboot, the computer started spewing memory errors. Safe Mode boots with constrained virtual memory, and it didn’t have sufficient memory to encrypt the endpoint. Essentially, Safe Mode not only acted as an EDR killer, but also borked the ransomware. In addition to the obvious recommendations – like make sure you receive alerts on bursts of failed VPN logins against multiple usernames from one source, and require MFA on every VPN account – Huntress suggests organizations keep an eye out for this Safe Mode play. Specifically, “alert on boot-configuration changes and Safe Mode boots: msconfig.exe / bcdedit activity, Kernel-Boot EID 27 with a SAFEBOOT load option, Kernel-General EID 12 BootMode=2, and third-party security services stopping (System EID 7036),” Northey wrote. Also, “watch for tooling being added to the Safe Mode minimal-service registry list.” ®

  •  
❌