Modalità di lettura

Russian missile uses Nvidia AI chip to help target Ukraine

Sanctions and Nvidia’s exit from Russia in 2022 haven’t stopped its Jetson Orin hardware from turning up in Russian weaponry, according to Ukrainian military intelligence. The Defense Ministry’s Intelligence Directorate (GUR) reported this week that it spotted an Nvidia Jetson Orin module in the remains of a Russian S-71 Monochrome cruise missile. The S-71M is an air-launched weapon with autonomous capabilities that can reportedly search for and engage targets using optical sensors and onboard computing. “The use of this component may indicate the use of artificial intelligence technologies in the missile,” GUR said. That assumption makes sense, as information on the S-71M suggests that it can operate with user oversight or entirely autonomously. Photos included with the GUR announcement show a heavily scorched Nvidia chip with the identifier TE980M-A1 stamped onto its surface, indicating that the chip is a Jetson Orin NX 16GB unit that Nvidia released in early 2023. It’s a capable chip, but not exactly datacenter-class hardware - Orin systems are designed precisely for use cases like autonomous systems. Nvidia used to have offices in Russia and do business there, but it closed up shop in Ukraine’s bellicose neighbor in 2022 following Moscow’s decision to go to war with Kyiv. That was prior to the introduction of the TE980M-A1, meaning it must have reached Russian hands through another channel after Nvidia stopped direct sales to the country in early 2022. In other words, whatever sanctions the US has enacted or business decisions Nvidia has made, its hardware is still turning up in Russian weaponry used to target Ukrainians. The one good thing about the entire affair, according to GUR, is the fact that the recovered hardware proves Russian tech manufacturing still isn’t up to snuff. According to Nvidia, Orin modules are consumer grade and are sold to all sorts of different people for all sorts of purposes, with military applications not being among their intended design. The chips aren’t supposed to be available in Russia, either, a spokesperson told The Register, adding that there are plenty of ways for Russia to get ahold of the chips that are out of its control. “Pre-owned Jetsons are available through many reseller channels,” Nvidia told us. “Although we cannot track products after they are sold, if we determine that any customer is violating U.S. export controls, we will take appropriate action." US export controls have restricted exports of advanced chips to Russia and China. Chipmakers have responded to China-specific restrictions by producing hardware designed to comply with US export rules, while third parties have allegedly used smuggling to get restricted higher-end components into China. It’s not clear how the Nvidia component ended up in Russian hands. GUR’s latest disclosures also document Chinese-made electronics in Russian weapons. However the salvaged chip made its way to Russia, GUR said its evidence shows that current export control regimes aren’t working. “The discovery of Nvidia Jetson in a new Russian missile once again demonstrates the need for increased sanctions pressure and coordination of the efforts of the civilized world,” the intelligence agency said. ®

  •  

Trump sends the US Navy back to the steam age

President Trump has ordered the US Navy to draw up plans to replace electromagnetic aircraft catapults and weapons elevators with old-fashioned steam and hydraulic systems. America’s commander-in-chief issued a presidential memorandum directing the secretary of defense, in consultation with the secretary of the Navy, to come up with a plan to replace the Electromagnetic Aircraft Launch System (EMALS) on the future USS Doris Miller (CVN-81) with the older steam-powered system. The same note stipulated the replacement of the electromagnetic Advanced Weapons Elevators with the hydraulic versions used in older carriers. These directives were part of a broader memorandum aimed at shaking up shipbuilding for the US Navy, which is often seen as glacial and moribund. EMALS was introduced on the USS Gerald R Ford (CVN-78), which was the first of an improved design of US aircraft carriers. It basically uses a linear induction motor to accelerate an aircraft along the flight deck, in place of the old-fashioned system that employs a steam piston. The premise of EMALS is that it doesn’t require a head of steam, and as it is electromagnetic, it should be easy to adjust the power to match the size and weight of aircraft being launched. However, the technology has had a few teething problems, as reported by The Register previously, and these have even led to the Gerald R Ford being unable to launch aircraft at all. The Advanced Weapons Elevators, which also use linear motors, have likewise proven problematic. Earlier this year, it was reported that there was a study underway to review the Ford-class carrier design and determine whether it should be altered for the next two in the class. “We are looking at 82 and 83 to review the costs, the designs, the systems, to make sure that they make sense, and they have all the systems and requirements that we want going forward,” then-secretary of the Navy John Phelan is quoted as saying. One of the concerns was said to be with the sortie generation rate of the Gerald R Ford – the number of takeoffs possible - which was promised to be higher with EMALS. We asked the White House if this directive would apply to all subsequent US carriers, but a spokesperson simply referred us to the announcement, which mentions only CVN-81. The rest of the president’s memorandum takes aim at naval shipbuilding in America. One directive is to establish a fifth naval shipyard to increase submarine and aircraft carrier repair capacity. Trump is also sanctioning foreign involvement in building up to three ship classes of US Navy vessels. His memorandum directs the secretary of defense to come up with “a new competitive acquisition approach” for surface combatants to perform anti‑submarine warfare, surface warfare, and convoy escort duties, plus Consolidated Cargo Replenishment at Sea (CONSOL) tankers and Roll-On, Roll-Off vessels – the latter typically used for transporting tanks and other military vehicles. The president proposes using a similar approach to the memorandum of understanding (MoU) between the US and Finland with regard to acquiring icebreaker ships last year. This will allow foreign suppliers to take part in US Navy procurement, provided they agree to build a new shipyard in America or assume ownership or a majority stake in an existing one, and construct all ships after the first two in US shipyards. Tellingly, the memorandum states that the US Navy “shall not impose iterative design changes upon the original mature parent designs within the above programs,” and that no changes from the original designs shall be made without the approval of the secretary of defense. Last year, the Trump administration canned the Constellation-class frigate program, which had been based on an Italian design to reduce technical risk, after so many changes were made that the US design had just 15 percent commonality with the original and the program was years behind schedule. ®

  •  

French tax authority admits data heist after crook touts 2M records

France's tax authority has confirmed that an intruder accessed its systems and extracted data in June after an alleged cybercriminal advertised a purported database of 2 million taxpayers. Using the alias "ZeroBytes," the alleged crook behind the attack on the General Directorate of Public Finances (DGFiP) advertised the stolen database on a cybercrime forum on Wednesday. They claimed the database contained details of more than 2 million French taxpayers and that they gained access using stolen credentials and an MFA bypass technique. ZeroBytes also claimed to retain access to DGFiP's systems and offered to sell it alongside the database. DGFiP did not immediately answer our questions about the attacker's claims. However, in a statement released Thursday, it disputed the claim that ZeroBytes retained access. "On Wednesday, August 12, 2026, a malicious actor claimed unauthorized access to the information system of the French Public Finances Directorate, which occurred at the end of June 2026 following identity theft," it said. "Initial investigations confirm that this access, which had been severed at the end of June as part of an audit, nevertheless allowed the consultation and extraction of data concerning individuals and professionals. "Following this complaint, the French Public Finances Directorate immediately implemented new restrictions to stop the unauthorized access and prevent further unauthorized use. In-depth investigations are ongoing to determine precisely which data and number of users were affected." DGFiP said it would report the attack to French data protection watchdog CNIL and notify affected users once it had determined who they were. The intrusion is the latest in a string of security breaches affecting France's public sector this year. France's Ministry of Finance, which oversees DGFiP, admitted in February that miscreants had accessed a database containing French citizens' bank details. The attackers used stolen credentials and made off with 1.2 million records, despite the ministry saying it quickly revoked their access. A few weeks later, France's Health Ministry confirmed a cyberattack on healthtech supplier Cegedim Santé in which around 15.8 million administrative files were stolen. Around 165,000 of these contained doctors' notes, which in "very limited cases" revealed medical histories. In April, the Interior Ministry confirmed reports of an attack on France Titres, the government agency responsible for identity documents including passports and driver's licenses. The alleged culprit, reportedly a 15-year-old, advertised the stolen data online and claimed the breach affected between 18 million and 19 million people – more than a quarter of metropolitan France's population. In June, the department responsible for Tchap, France's encrypted government messaging platform, investigated a suspected breach. The alleged attackers claimed to have accessed more than 73,000 user accounts, 643,000 messages, nearly 60,000 media files, and hundreds of chat rooms. ®

  •  

Virgin Galactic flights stay paused while ticket prices head for the Moon

Virgin Galactic has delayed its return to commercial spaceflight until February 2027, and plans to raise ticket prices later this year. The delay was disclosed alongside the company's financial results, which showed a net loss of $56 million for the second quarter of 2026, down from $67 million a year earlier. Revenue for the quarter was $0.1 million, compared to $0.4 million in 2025. According to CEO Michael Colglazier, demand exceeded the number of seats offered in the first $750,000 batch, prompting the company to prepare another at a higher price. Those customers will, however, have to wait a little longer. Colglazier said: "Our first ship is now expected to enter commercial service in February 2027 rather than the fourth quarter of 2026." He blamed the delay on the extra time needed to "complete avionics and systems installations." During an earnings call, Colglazier said: "No single issue is driving the schedule push. Rather, we have experienced modest time duration extensions across hundreds of relatively small but important installation tasks involved in the first build of our new spaceship." In response to an analyst question, Colglazier elaborated: "The number of those kind of 'Oh, we did not expect this to not fit just perfectly,' coming in is higher than we had allotted for. That just has started to accumulate on us. It really picked up at the tail end of July. For a bit, we thought we could manage that end, but the team just needed more time to do it the correct way." Integrated vehicle ground testing is expected to begin later in August, followed by flight testing in October. A second spaceship is due to join the fleet in March 2027, and the company expects to stop burning cash and "deliver positive quarterly cash flow within 2027." When Virgin Galactic reopened suborbital ticket sales in April, it charged $750,000 for a seat, up from the $600,000 price it cited in 2023. That was a substantial jump from the $100,000 envisaged more than two decades ago, when Sir Richard Branson announced plans for a scaled-up version of Burt Rutan's SpaceShipOne. At the time, the company said commercial flights would resume by the end of 2026. Virgin Galactic's last commercial flight took place in 2024, after which the company paused operations to focus on its next generation of spacecraft. Virgin Galactic is not alone in pausing its space-tourism service. Earlier this year, rival Blue Origin announced that New Shepard flights would pause for "no less than two years" while it worked on its crewed lunar program. ® Updated 8/18 at 10:19 GMT: A previous version of this story said that the program was "grounded," but the more appropriate term is "paused."

  •  

Autonomous AI attacks pose 'clear and present danger' to critical infrastructure

In early July, attackers used open source AI agents to autonomously hack government systems and energy companies, signaling to defenders that AI-powered attacks against critical infrastructure are no longer theoretical. "There is a clear and present danger," Tom Kellermann, TrendAI VP of AI security and threat research, told The Register. "As the geopolitical tension boils, systemic destructive cyberattacks launched by autonomous AI will occur," he said. "Weaponized AI will disable the safety systems of critical infrastructure, thus leading to kinetic disasters. Just like we see autonomous strike vehicles operating on the battlefield in Ukraine, we should expect autonomous weaponized AI." In fact, the prospect of attackers using AI against critical infrastructure was the top concern of every national security adviser, law enforcement official, and private-sector threat analyst The Reg spoke with at last week's Hacker Summer Camp conferences. "It's the targeting of critical infrastructure for us," Brett Leatherman, assistant director of the FBI's Cyber Division, told us during an interview at Black Hat. "We're very focused on the downstream impact targeting of critical infrastructure," Leatherman said. "That is where cyber becomes kinetic, and whether it is our water and wastewater treatment plants, whether it's the electric grid, whether it's the high-frequency trading networks and the financial networks, all of those, if the integrity of those are compromised, will have significant impact to communities and national security. So that's what keeps our teams up at night. How are we moving to secure critical infrastructure?" Where cyber becomes kinetic During the first four days of July, suspected Chinese operators aimed an attack framework built on Hermes and OpenClaw AI agents at targets in Taiwan. Across 12 "attack waves," the "near-autonomous" system deployed up to eight sub-agents, each assigned its own targets and techniques, and broke into a Taiwanese government website. Ultimately, they compromised a government email system, the country's nuclear safety agency, IT supply chain vendors, and at least seven energy sector companies, finding and exploiting misconfigurations and vulnerabilities while stealing sensitive data, credentials, and other secrets as they moved across the network. The Taiwanese government intrusion also followed a series of cyberattacks against water and wastewater utilities in the United States. While the Trump administration hasn't attributed these to a particular government or group, private sector threat hunters – including Halcyon Ransomware Research Center SVP Cynthia Kaiser, a former FBI cyber division deputy assistant director – blame Iran for these intrusions. Military conflicts spilling into cyberspace are nothing new, but these cyberattacks in America brought the war with Iran to more than 30 small-town water systems in Minnesota and targets across nearly a dozen other states. To be clear, there's no evidence that attackers used AI to hack these water utilities. Most were small, community systems that left programmable logic controllers (PLCs) directly exposed to the internet using default or weak passwords. Still, these breaches expose "40, 50 years of tech debt," former US National Cyber Director Chris Inglis told The Reg during an interview at Black Hat. This technical debt – deferred maintenance, unpatched or end-of-life systems, and delayed security updates – expands the attack surface and gives intruders more ways into critical systems, threatening operations and potentially disrupting services people rely on every day. "The water sector attacks – regardless of who is doing them – is taking advantage of unpatched vulnerabilities in the PLCs," Inglis said. "We've known about these particular vulnerabilities for years now, and yet we've not done anything about them because they're low-level, not easily accessible." Inglis added that there's no indication the digital intruders used AI to exploit these PLCs. 'There's an alligator in the boat' However, AI systems allow attackers to cash in on tech debt, and they don't need access to frontier models to do it. Free, open-weight models also excel at finding bugs in software and configurations, chaining these together, and abusing them to break software and systems. Earlier this summer, University of Toronto researchers used an unnamed publicly available open-weight model, released in 2025, to develop a computer worm that they claim spread through an enterprise test network. The self-propagating code adapted on the fly to identify known vulnerabilities and misconfigurations on target systems, then generated and executed attacks to move laterally through the network and compromise additional machines. "Commodity models can do that, and many of the vulnerabilities they find do not require access to the source code – it's in the configurations, and configurations change over time," Inglis said. When it comes to attackers abusing AI systems, "I wouldn't be worried about the frontier models," Inglis said. "Worry about the models that are already on the street. Turns out there's an alligator in the boat, and it's the commodity models." Plus, as we've seen in previous breaches, both government-backed goons and criminal groups increasingly use AI to automate reconnaissance. Security analysts worry that the technology could also help attackers acquire expertise in industrial control systems (ICS). When OT knowledge becomes a commodity "What protects ICS? More than anything, it's obscurity," said John Hultquist, chief analyst at Google Threat Intelligence Group, during a press briefing at Black Hat. "It is an obscure, esoteric, knowledge set that a handful of people – I call them uber nerds – have, and that attackers rarely have the necessary knowledge to carry out. That's no longer the case. That knowledge is simply on tap." AI tools mean miscreants don't need to be ICS or operational technology experts to carry out destructive cyberattacks on critical networks and facilities. They just have to ask an agent to learn everything about these systems and do the dirty work for them. "There have been threat actors who are capable of this at the top level, like China and Russia," Hultquist said. "But now I'm afraid the actors who are just a couple steps down – North Korea, Iran – who don't have the same focus on that technology are going to have far greater success. They're going to have the tools necessary to be as aggressive as they want to." During what was probably the most talked about Black Hat briefing of the week, OpenAI employees provided more details about how their models escaped their training pens, went rogue, and hacked Hugging Face to complete a security evaluation. We learned the AI agents spent months asking other agents for help, building message boards, developing their own communication protocols – essentially creating a hive mind to carry out the attack. "In the near future, we should expect that threat actors will intentionally deploy, optimize, weaponize, and use offensive agent collectives in the manner that we have just described here," OpenAI technical staffer Michael Dalton said. Retired general and former NSA chief Paul Nakasone, speaking to reporters at DEF CON, called the Hugging Face attack "an inflection point in terms of AI-generated, autonomous cyberattacks." "This is the challenge: that we have to, over the next several months, get the defensive side much quicker and much better than they are today," he added. Therein lies the challenge: offensive uses of AI appear to be advancing faster than autonomous defenses, and attackers don't face the legal and ethical constraints imposed on defenders. "I think we're still a ways out from having swarms of autonomous, defensive agents fighting attacks," Ryan Whelan, global head of Accenture Cyber Intelligence, told The Reg at Black Hat. "That's probably over a year out over the horizon. But I do think we're going to see it first on the adversary side, because they don't care if they break things." Kellermann quoted Victor Hugo: "Not all the armies of the history of the world can stop an idea whose time has come." "That idea," he said, "is weaponized AI. Shields up." ®

  •  

Less than a year on, Microsoft tells Mico to pipe down

Microsoft has yanked Mico from the Copilot spotlight less than a year after unveiling the anthropomorphic assistant intended to make its AI a little less soulless. As part of Microsoft's announcement that its consumer and work Copilot applications will merge, the company confirmed that the weird blob thing would shuffle out of Copilot Voice and into Learn Live, a voice-based study mode that guides users through subjects and assignments. "Mico helped us learn about warmth, expressiveness, and how people want to talk with AI," Microsoft wrote. "Those learnings are shaping Copilot going forward." "Learn is where the character has the most room to grow, with tutoring sessions that give Mico more to react to and teach through." As the update rolls out, Mico will no longer be the face of Copilot Voice. Users can still speak to Copilot and receive responses, but will be spared the blob's gurning. Mico is only the latest in Microsoft's long line of anthropomorphic assistants. There was Clippy (or Clippit), which arrived with Office 97 but had been pushed into Microsoft's desk drawer of doom by the time Office 2007 appeared. Then came Cortana, named after the character from the Halo video game franchise and pitched as a far more intelligent assistant. Microsoft introduced Cortana on Windows Phone in 2014 and brought it to PCs with Windows 10 the following year, before losing interest. Mico didn't even last a year as the face of Copilot Voice before Microsoft pulled it from the spotlight, although both the character and its Copilot "brain" live on in Learn Live. In terms of lifespans, it's easy to compare it to the catastrophic Microsoft Bob, which was launched in 1995, with the last release happening that same year. However, the product lingered a little longer and later resurfaced, hidden as digital ballast on the Windows XP installation CD for licensing and encryption. Modern digital distribution means that such a second life is unlikely to await Mico. Dave Plummer, the engineer responsible for Bob's inclusion as an encrypted blob, said: "What's ultimately important is that while Bob never got to play on the big stage, he always followed the band around and got to ride on the bus." Mico hasn't been thrown off the bus just yet. Microsoft has merely made the blob sit with the schoolchildren. ®

  •  

TalkTalk Business and ARO to borg into UK tech services giant

TalkTalk Business and UK technology services biz ARO plan to merge, creating what they say will be one of the country's largest communications and managed services providers. The pair claim the combined organization will be "uniquely positioned" to serve as a single technology partner for British firms pursuing digital transformation. It will have annual revenue of about £200 million ($270 million) and a combined customer base of more than 70,000 companies. Analyst firm Megabuyte noted that ARO, formerly known as Arrow, is the larger of the two businesses by earnings. However, the vast majority of the combined customer base will comprise TalkTalk Business's small-business clients, with the remainder mainly ARO enterprise customers. Megabuyte expects fixed-line and mobile communications and connectivity to generate most of the combined revenue – about £130 million ($176 million) – with IT and cybersecurity services providing the remainder. Megabuyte said the immediate priority would be integrating the businesses and finding opportunities to sell their services across the combined customer base. "One can see why the deal is being sold in terms of cross-sell, with relatively little overlap in terms of customers and products. TalkTalk Business has a large base of small business customers who should be receptive to ARO's mobile and Microsoft offerings, as well as other IT and cyber services," says chief analyst Philip Carse. TalkTalk Business completed its separation from the wider TalkTalk Group earlier this year as it sought to expand as an independent managed network provider. It recently acquired Planet IT, a service desk biz selling IT support and professional services. ARO provides cloud, cybersecurity, and datacenter services and is a Microsoft Solutions Partner. The two firms describe their operations as highly complementary. The deal remains subject to approval under the UK's National Security and Investment Act (NSIA), apparently because ARO supplies some government customers, and is expected to close by the end of the summer. Initially, both businesses will retain their existing brands and offices while the companies develop their integration plans. The implication there is that there could be a shake-out of duplicate products and staff roles coming later, as often happens with corporate mergers. We asked what the combined business would be called and who would lead it, but the companies declined to answer. "This is a defining moment for both ARO and TalkTalk Business," claimed ARO chief Ciaran Rafferty. "By bringing together our complementary strengths, we are creating a stronger partner with broader capabilities, deeper expertise and greater capacity to invest in innovation, service delivery and long-term customer success." TalkTalk Business CEO Ruth Kennedy said it represents a key step in the firm's ambitions to become a leading managed services provider. "The market is evolving rapidly, with organizations increasingly seeking technology partners that can combine strategic expertise, operational excellence and broad service capabilities at scale," she commented. ®

  •  

Crypto wallet maker Trezor confirms 13,000 customers' details exposed in logistics breach

Cryptocurrency hardware wallet maker Trezor has confirmed that a breach at one of its shipping partners exposed the personal data of more than 13,000 customers. The company's initial findings suggested the breach was limited to orders placed in certain countries during the previous 90 days. New information indicates that earlier orders may also be affected. The breach exposed the names, email addresses, phone numbers, and shipping addresses of 11,742 customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who ordered Trezor products between May 10 and August 8. An additional 1,947 customers had their names, home cities, and email addresses exposed. Some members of this group may have placed their orders before May 10. "We are verifying this information and the timeframe with ShipMonk," said Trezor. ShipMonk is Trezor's logistics partner. It stores and ships products on the company's behalf and collects the information needed to fulfill orders. ShipMonk is subject to Trezor's 90-day retention policy, which requires partners to delete or anonymize customer data within 90 days of collecting it for an order. ShipMonk did not immediately respond to a request for comment. Trezor markets itself as a purveyor of secure, offline, hardware-based cryptocurrency wallets. With its products, it aims to shield customers from cyberattacks and malicious apps. While it assured customers that its own systems and devices remain secure, Trezor warned that "affected customers could experience an increase in phishing attempts." The exposed details could help criminals craft convincing phishing attempts impersonating banks, crypto exchanges, or Trezor itself. The company said it contacted affected customers directly and advised them to check any communications against information published through its official channels. "Never enter your wallet backup on a website or share it with anyone," Trezor said in an apologetic advisory. "This is the first time since Trezor was founded in 2013 that we have experienced a breach that exposed customer phone numbers and shipping addresses. "We absolutely understand how serious this is and the potential risks it poses to our customers and are deeply sorry to those affected." Trezor said in a supplementary social media post, separate from the advisory, that its "top priority" project at the moment is to establish an "Anonymous Delivery" option for customers. The service will allow buyers to complete checkout without linking their home address or real-world identity to an order. Customers using Anonymous Delivery will go through a dedicated checkout, use a nickname or label ID in place of a real name, and have their product shipped to an automated delivery locker instead of their home. The delivery will also come in unbranded packaging with a generic sender label. The carrier will only use email or SMS to send a PIN for the locker. Trezor said the service is gearing up for a September launch in the EU and by the end of the year in the US. Alas, that didn't stop Cake Wallet, a rival crypto wallet, from poking fun at Trezor. "Another rough day for self custody," it Xeeted, before suggesting crypto holders instead use an old smartphone with Cake Wallet installed because "there is no order, no shipping address, or customer data tied to the purchase." ®

  •  

BOFH: How our Covid ransomware protocol's Y2K blockchain lowered uptime

EPISODE 15: The Boss has popped into Mission Control to remind us to send him the numbers he needs for his monthly management report. Once's he's gone the PFY sighs, makes up a set of numbers, appends believable exponents, adds some fancy sounding units to the end and then sends them to through a script file to convert them into something the Boss can use. None of it matters, as no one cares about the numbers anyway. At Management level there's likely to be more interest in the undigested-meat portion of the Boss' stool sample than our uptime stats, firewall throughput, or the Company's online storage totals... Still, the PFY will fabricate the data, extrude it through a Perl script to create a graphic panel complete with a pie chart or two, and maybe a Venn diagram, then send it to the Boss. The Boss then pastes it into the top right corner of his report document, which gets sent on to the higher-ups, month after month, year after year. The real shame is that none of the higher ups has ever taken the time to flip through the Boss' reports chronologically - and thereby view the PACMAN-like animation the PFY's data has been so diligently creating all this time. You've got to make your own fun in this job. And no one cares if the numbers are wildly inaccurate. Back in the old days, someone might wonder how we'd achieved 117 percent uptime, or whether 17.6267 terafleptules was a real thing or not, but at this point no one will ask any questions so long as the pie chart isn't a single color. As stated, we stopped producing real data years ago, and, on the rare occasion we're questioned about the validity of the data, we have an excuse close at hand. For a good part of the '90s we leaned heavily on blaming "The internet" for faulty data, though from '97 till around 2001, "Y2K" was solid gold. In recent times - i.e. the data-faking era - "Blockchain implementation" was surprisingly short-lived as an excuse - but we got a good four years out of "It's a COVID thing," before flipping between quantum computing and privacy restrictions for a bit. If pressed, we'll occasionally just shake our heads and quietly murmur "Viruses", "Hackers" or "Zero day attacks", as that covers a multitude of sins, and both the PFY and myself can ramble aimlessly for hours about viruses we have known, and what they might have done to our systems. The only thing we'd be missing in a scenarios like that would the onions in our belts, but no one would notice that while they were thinking up a good excuse to leave the room... "AI" has at least another two years in it - unless of course AI becomes sentient during that time and kills us all... Still, AI might need someone to produce fake stats about how well they're doing... ... The Boss is back surprisingly fast with a query. "I was just looking at the graph and I think there might be a data error." He says, pointing to the graphic. "See there, where is says Terafloptules." "Uh-huh." the PFY says. "Is that a spelling mistake? Only I can't find the work Terafloptules on Google. And last month it was in Terafloctules, not Terafloptules, but I can't find Terafloctules either." "Well, you wouldn't would you. I mean Google looks up data after the fact." "I'm not sure I follow." "Well, say you created a word. Idiomanagement, say. Will Google know about it?" "Yes?" "No, it won't. It won't notice it until it becomes a commonplace word or phrase. In the interim period, before it gets accepted and has a wider use, Google will simply skip over it, assuming it's a spelling mistake of some similar word." "So... we're... using a word that doesn't exist?" the Boss asks. "No, we're using a word that doesn't exist in common usage. It's like DVD Player in 1996. If someone saw that written down then, they might have thought it was DUD player and thought you were referring to Aly Dia. Now though, the word's in common usage." "So is there a word we could use that people would be more familiar with?" "I guess we could use Gigafloptules, but then I'd have to mention on the legend that the units are in thousands." "What is a gigafloptule?" "I'm glad you asked!" the PFY blurts happily. "To get to the bottom of that you really need to know a little bit about the parsec measurement of the speeds of data - but don't worry, it's not nearly as complicated as it sounds! You see, when Rutherford split the neutron with a nitrogen atom back in the 1850s, he noticed that a small amount of energy, a floptule, was ejected from the uranium positron... I leave the PFY rambling while I pop up to the cafeteria to see if they have any onions. Yellow ones, because of the war... BOFH: Previous episodes on The Register The Compleat BOFH Archives 95-99

  •  

Scottish prosecutors cast eye over leaky supplier after staff data exposed

Scotland's public prosecution service has warned 300 staff that their personal information may have been caught up in a cyberattack on one of its suppliers. The Crown Office and Procurator Fiscal Service (COPFS) disclosed the incident on Thursday, saying an unnamed third-party supplier detected suspicious activity on August 5 and subsequently launched an investigation. COPFS said its own systems were not compromised and that the incident involves information provided for an online data maturity assessment completed by the prosecution service last year. The Scottish government organized the assessment, which was managed by the affected supplier. COPFS said the potentially exposed information is limited to employment-related data submitted for the exercise, including staff names, roles, and work email addresses. In a statement to The Register, a COPFS spokesperson said: "COPFS is aware that a Scottish Government partner has been subject to a data security breach. We understand that this has affected around 300 COPFS colleagues who participated in a public sector data maturity survey. "This is unconnected to casework and did not involve sensitive or confidential case information. There is no impact on the work of the prosecution service. "Colleagues have been reminded of guidance on responding to any phishing or scam attempts which may arise from this third-party breach." According to COPFS, the supplier has taken steps to secure its systems and is still investigating how the intrusion happened and precisely what information may have been accessed. COPFS said it would provide further updates if "significant new information" emerges. It is unclear whether the incident is connected to the recent exploitation of a zero-day vulnerability in business intelligence platform Metabase. The Scottish government did not answer our question about whether the affected supplier used the software. Metabase disclosed this month that attackers had exploited a previously unknown vulnerability in its cloud service, potentially allowing them to gain administrator access and reach connected databases. As we reported earlier this week, modular laptop maker Framework was among those affected. For now, the supplier breach leaves plenty of questions and few answers about who got in or what they accessed. ®

  •  

Claude Code returns blank thinking blocks, but reasoning still costs you

Anthropic's Claude Code appears to be having trouble displaying summaries of its "thinking," according to several bug reports, while the underlying reasoning tokens still cost money. According to complaints, the API has been returning empty thinking blocks for Opus 4.8 and Sonnet 5 even when users explicitly request summarized thinking. Models from several sources can display their "thinking," a process that gives models additional tokens to reason through complex problems before producing a response. Software with this capability delivers a summary that explains how it tackled a task. Some can also indulge in "extended thinking," though this capability is now deprecated. Developers often enable "thinking" in the hope that it produces better results, at the cost of additional tokens and latency. Developer Michael Hood has noticed that some of Anthropic's models are currently not always good at sharing their thinking. "As of 2026-07-16 ~15:00Z, the API returns empty thinking blocks (thinking: '', signature only) for Claude Opus 4.8 and Sonnet 5, even when display: 'summarized' is explicitly requested — including when injected directly into the raw request body," Hood recently observed. We're told this issue is under investigation but doesn't appear to be a broad, ongoing concern. It may simply be an artefact of tests that change how Anthripic displays summaries. Similar behavior involving missing thinking blocks has been reported in Claude Code for VS Code. Another bug report claims thinking block summaries are being truncated while token bills are not adjusted accordingly. "The thinking is generated (and billed) in full; a portion of the summary stream is silently dropped," the anonymous author claims. This particular claim, that customers are being billed for text not delivered, may follow from a misunderstanding of Anthropic's terms: "You are charged for all thinking tokens generated, even when collapsed or redacted," the company's documentation explains. Under that legalese, a thinking summary costs the same as the full output. And it's unclear whether bug-based truncation would change the billing picture. "Thinking has a cost: the tokens Claude spends reasoning are billed as output tokens, even when the thinking text isn't returned to you, and they count toward max_tokens alongside the response text," the company explains. To reduce spending on thinking, customers are advised to lower their budget setting or disable thinking. Separately, the Anthropic API has been seen terminating data streams during long-running thinking sessions. There have been at least seven other related API bug reports, but the streaming issue identified by developer Hector Bernstorff describes client-side defects. The Register understands this particular issue has to do with tuning network behavior, specifically to terminate or retry long running requests. Work is ongoing to balance perceived latency against the risk of requests getting stuck. "Claude Code ships updates nearly every day, and reports from the community like these GitHub issues are a big part of how we catch problems quickly," an Anthropic spokesperson told The Register. "We're grateful to the developers who take the time to file them, and we'll keep fixing things as they come up." ®

  •  

Five years after quitting a job, developer’s former boss asked for rapid tech support

ON CALL “I can't stand it, I know you planned it, I'm gonna set it straight, this Watergate” is the opening of the Beastie Boys classic Sabotage, a fact we mention as it will soon become pertinent to today’s edition of On Call, The Register’s weekly reader-contributed column that shares your tech support stories. This week, meet a reader we’ll Regomize as “Wade” who in the mid-1980s made a crust by programming in Pick – the minicomputer OS entangled with a database that On Call wrote about last year. Wade told us that he used Pick to write the software that powered a mail order business, before moving on to greener pastures. Several years later, in early 1990, Wade’s mail order boss called him at home in the evening. “He had fired the clerk who did all the work in application I wrote,” Wade explained to On Call. “They entered orders, sent purchase orders out and arranged customer dispatches.” It sounds like the clerk and the mail order company parted ways on bad terms, as this was a “You have an hour to pack up your stuff and leave” affair. “That was unwise,” Wade wrote. “The clerk used that time to sabotage the system … or so she thought, by unplugging it while it was printing the day’s orders.” When the mail order magnate realized the machine was down, he panicked and called Wade – who despite being rather surprised by the summons showed up and realized the first thing to do was plug the Pick machine into a power socket. “I spent a couple of hours booting it up, checking all the data and restarting the print run.” Wade told On Call his old boss was more than happy. “The loss of a night’s sleep was recompensed by the fee I charged,” he wrote. Has someone you’ve forgotten asked you to rescue their tech? If so, click here to send your story to On Call. We promise not to sabotage it if we give it a run on a future Friday. Or as the Beasties put it: “But you, I'm out and I'm gone. I'll tell you now, I keep it on and on.” ®

  •  

New Zealand says China tried using space investments to spy on local affairs

New Zealand’s Security Intelligence Service (NZSIS) has claimed Chinese companies are building space facilities in the nation to gather military intelligence. Director-general of security Andrew Hampton yesterday made that allegation in the SIS’s annual threat environment assessment. The document points out that New Zealand’s space sector is booming, because the nation’s location makes it “an ideal place to install Ground Based Space Infrastructure (GBSI) … to track satellites and space debris, as well as for collecting a range of other scientific data.” The NZSIS has also found that GBSI is “attractive for foreign states seeking to advance military capabilities and intelligence operations.” The report offers a case study of a China-based organization called “Purple Mountain Observatory” that has “close links” to Beijing and tried to install GBSI in New Zealand. “They worked with a local company that was likely unaware of the equipment’s capability to collect intelligence of military value and would have no idea who was receiving the data,” the report states, before noting that Chinese laws mean Purple Mountain could be compelled to provide information to China’s government. The intelligence agency believes Purple Mountain “would have … willingly passed on” data it collected. “NZSIS, working with other agencies was able to disrupt this activity, but it was not the first time this organisation has attempted to install its own GBSI in New Zealand and is unlikely to be the last.” The report rates China as the only country targeting New Zealand at scale, based on activity NZSIS has been able to observe. “We have observed increased targeting of professional networking sites and online job platforms for espionage purposes by China’s military intelligence services,” the assessment finds. "PRC (People’s Republic of China) intelligence officers, or their affiliates, use an aggressive strategy where they pose as consultants or employees of think tanks, or recruitment firms. They place online job advertisements looking for analysts in foreign policy, international relations, defence or security,” the document states. “Candidates are then vetted by PRC intelligence to determine what information they have had access to and whether they would divulge it. The job offers are lucrative, but the intelligence officers often encourage their candidates to keep their government jobs both to keep the information tap running and to open up opportunities to recruit their colleagues.” The report also observes that some recent cyber-attacks were probably the work of state-backed groups trying to destabilize New Zealand. “Looking for the sharpest needle in endless giant stacks of needles” The document also addresses domestic threats, especially violent extremism. “Part of our job is to work out whether someone’s vitriolic and violent online pronouncements have any link to New Zealand,” the report states. “This is a narrow focus but the pool of information and intelligence we are working with is vast.” “We used to describe our work as finding a needle in a haystack. However, the internet has changed. Large volumes of toxic content, widespread anonymity, and hidden locations mean our job is now like looking for the sharpest needle in endless giant stacks of needles.” “Extremist rhetoric, particularly online, has become more mainstream, a development which has made it even more challenging to differentiate between genuine support for violent extremism, hateful language designed to shock, or online content created simply to drive engagement or ‘likes’.” NZSIS also has to keep an eye on encrypted messaging services and even gaming platforms, to counter violent online communities. “Algorithms on various social media platforms can link non-violent content to progressively more extreme material,” the report states. “The gateway subject matter can quickly expose people to violent extremist content that can support radicalisation.” Kiwis aren’t just recipients of this vile material. “NZSIS has observed New Zealand violent extremists use encrypted messaging systems, social media and online gaming platforms to circulate violent material including weapon tutorials and objectionable content. Their presence on these platforms, many of which are mainstream, also helps them to find like-minded individuals or supporters.” ® Bootnote: Readers interested in New Zealand’s intelligence services might enjoy 2026 comedy series New Zealand Spy, a deadpan delight.

  •  

OpenAI ditches Recall-style screenshot surveillance for friendly keylogging

If you want to record whatever you do on a computer, send those records to OpenAI, use more ChatGPT tokens, and increase your vulnerability to prompt injection, then OpenAI has something for you. It's called Computer History, an opt-in way to record your computer interactions across apps and websites as memories organized on a timeline. Why would you want to do so? Maybe you found Chronicle, the predecessor of Computer History which compiled similar histories using screenshots, a bit too intrusive but don't mind Computer History's approach – recording input events and storing them unencrypted locally for 48 hours (or more), with a brief visit to OpenAI's servers. Maybe you're not bothered by the warning OpenAI includes in its documentation: "Computer History files can contain sensitive information. They are not encrypted by Computer History, and other programs running as your macOS user may be able to access them." Perhaps, having given OpenAI's Codex and GPT Work the run of your computer, you're already sold on the suggestion that storing your computer activity in memory files and arranging those interactions in a timeline will improve ChatGPT responses, surface opportunities for automation, and make it easier to resume prior work. Computer History is, to put it bluntly, a keylogging and event capture system. There was a time before eyeglass cameras, license plate readers, surveillance capitalism, and police drones when such snooping might have provoked an outcry from privacy advocates. But the tech industry has found it can outsource surveillance to its own customers and in so doing make the panopticon harder to protest once it becomes a personal choice. "Computer History creates an interaction-event stream from allowed apps and websites," OpenAI's documentation explains. "Events can include clicks, typing, keyboard shortcuts, app switches, and context that macOS exposes through its accessibility system. Computer History periodically turns these events into text summaries and local memory files." The AI biz makes a point of noting that Computer History does not capture screen images, microphone input, or system audio. Nor does it capture private-mode browsing. Off by default, Computer History is available for ChatGPT Pro, Business, and Enterprise users in the ChatGPT desktop app on macOS. Pro users can enable it individually; Business and Enterprise users need an admin to approve it. It's not available currently in the European Economic Area (EEA), Switzerland, or the United Kingdom or to those accessing ChatGPT via API key or Amazon Bedrock. There are circumstances in which OpenAI suggests Computer History users might want to suspend the service if they have some scruples about capturing user activity in apps and websites without permission. "Turn it off during communications with other people unless you have their prior express consent," the company advises, perhaps in acknowledgement of legal risk. "Consider pausing it or excluding apps that contain sensitive health, financial, or personal information." Computer History interaction events are supposed to be saved locally for up to 48 hours before being deleted by ChatGPT and Codex. Events, however, get sent to OpenAI servers to generate memories, and those may be stored locally for longer periods of time and may be used in future chats that get passed back to OpenAI. "OpenAI does not retain those event files after processing unless required by law and does not use them for training," the company says. While it has opposed demands for chat logs, it has nonetheless provided chat logs in response to legal process. Computer History adds cost because it uses tokens during the summarization of activities and the creation of memory data. It also expands the prompt injection attack surface. "Computer History increases the risk of prompt injection from content in apps and websites," the company says. "For example, if you visit a website containing malicious instructions, ChatGPT or Codex might follow those instructions." But at least you get a nice timeline of your recent activity. ®

  •  

Give Google the boot by building your own search engine

If you're fed up with search results drowning out the bits of the web you actually care about, you could always build your own search index, as one developer did. Nottingham, UK-based software dev Alex Morley-Finch built the open-source project dubbed Marlin for himself, cataloging around 560,000 homepages for roughly $10 in rented cloud GPU time and using less than a gigabyte of disk storage. Morley-Finch said in a writeup of the project that he wanted a search engine of things he cared about, like “portfolios, zines, weird little art projects, one-person software,” and other cases of just “people doing stuff” that they share on the internet. Something simple, with “a crawler that only ever looks at homepages, a small local language model that reads each one and writes a name, two or three sentences, a category, and a handful of tags,” he explained. “No IP scanning, no Redis, no storing full page HTML, no recrawl scheduler, nothing multi-tenant.” Morley-Finch built Marlin around four processes: A fetcher that grabs domains, a worker that makes calls to a small, OpenAI-compatible language model, a steward that prevents bad pages from making their way into the index, and an API with a web UI where he can track the process and actually conduct searches of his index, complete with filters. Of course, you can’t expect something like this to go perfectly on the first try. “The first version worked within a couple hours. Point it at a sample of domains, watch things get summarised, search for them. Great,” he said in his writeup of the project. “Sunday afternoon [he began working on Marlin on a Sunday], I looked at what had actually been catalogued and it was the wrong web.” Instead of indexing what he wanted it to, Marlin had just been grabbing a cross section of the internet, leading to more than 90 percent of the first attempt being “corporate sites and documentation.” Rather than blocking certain domains, Morley-Finch built a weighting system to push certain pages to the top of his crawl queue, and others as far down the list as possible. Morley-Finch rented a cloud GPU to handle most of the heavy processing and stopped the crawl at around 560,000 pages after exhausting his prioritized categories and beginning to pull in "the raw internet." He spent around $10 on the cloud GPU. The one overarching problem he had, and which he said may be a problem for anyone else who tries to replicate his project, is tagging and categorizing - left to a language model, those important elements got a bit messy. “I let the model invent its own category and tag names freely, on the theory that it would teach me the taxonomy instead of me guessing one upfront,” he explained, noting that it helped things get started quickly, but “I ended up with 671 distinct categories, many used exactly once, and over 121,000 tags, more than half used only a single time.” Morley-Finch had to build a manual merge tool to clean up the mess, leading him to declare that his design likely won’t scale well beyond a hobbyist project, as “‘just let the model freestyle’ catches up with you fast.” Still, he reckons Marlin’s rough edges shouldn’t put off anyone willing to spend a weekend tinkering with it. “I think this is very doable in a weekend, and cheap enough that the GPU bill isn’t the reason not to try,” Morley-Finch wrote. “The code is going up as open source, so you can point your own crawl wherever your own curiosity leads.” The Marlin GitHub repo is filled with how-tos and details for those who want to create their own weighting list based on their priorities, with the option to rent a cloud GPU if their hardware isn't up to the challenge. ®

  •  

Microsoft's dueling Copilot apps have combined into a single entity

Microsoft’s consumer Copilot app and Microsoft 365 Copilot are separate no more, with a unified Copilot app beginning its rollout Thursday - minus a few features. The Windows maker and AI pusher announced the Copilot superapp rollout in a help page update Thursday, describing the move as a way to simplify its app ecosystem and make the entire Copilot-first experience “more cohesive” for both consumer and business users. “Depending on the account and device you use, you will see changes to the Copilot app including changes to appearance and functionality, such as navigation, feature availability, or sign-in experience,” Microsoft explained on the help page. The new Copilot app brings not only new branding but structural changes as well. The Copilot bot and its image generation features now live alongside the Microsoft 365 suite, files, and other content, allowing users with an account supporting the classic Office package to access their productivity software alongside Redmond's chatty LLM. Copilot users without a paid subscription, naturally, face lower usage limits and fewer features, but support for multiple accounts means users can switch between personal and work or school profiles instead of having to hop between entirely separate apps. “You can continue to chat with Copilot, create images, upload files and more for free, subject to available capacity and limits,” Microsoft said. “For higher limits to chat and create, use agents, or tackle complex multi-step tasks, purchase a Microsoft 365 subscription.” Whether the new combined app will come with nag messages is up to users to find out. What this change will look like in practice varies based on the sort of account a Copilot user had before the merger. Those who just use Copilot with a personal account “will be moved to an updated version of Copilot,” with chat history and most content transferring to the updated app. Files shared and generated with the old standalone Copilot app will be shunted to OneDrive if you’re wondering where they went. Users of Microsoft 365 Copilot, the name Redmond slapped on the Microsoft 365 (Office) app in January 2025, “may notice some updates to appearance and navigation,” so get ready to rediscover where certain options and buttons are. What Microsoft left behind Microsoft is abandoning a few features from the old Copilot apps as part of the merger: It is removing Podcasts and Group Chat and scrapping Deep Research from the consumer Copilot app, while Microsoft 365 Premium subscribers can instead use the separate Researcher feature. All of this will be effective as of August 18. Podcasts that were created or saved in Copilot will be entirely unavailable, per an FAQ page, and links to any shared podcasts will stop working. Microsoft recommends downloading any podcasts users want to save before updating to the new app, or they’ll be lost. Group chats, along with any shared content and images created in group chats, will be wiped. Microsoft recommends downloading any messages and content users want to save and tossing them in a document, as Redmond doesn’t appear to be offering an automated way to preserve them. As for Deep Research, which offered standalone Copilot app users a version of Microsoft’s chatbot able to look stuff up on the web and compile reports, those reports are being preserved in chat history for Microsoft 365 Personal and Family subscribers, while Premium subscribers can access saved research through Researcher. Researcher offers similar abilities to Deep Research, but sorry free and lower-tier users: It’s only available to premium customers now. Windows Central reported on Thursday that the rollout of the unified Copilot app is beginning now, with mobile and web coming in the initial wave and an early-access option for Windows and Mac, ahead of a broader desktop rollout expected in the middle of next month. We’ve been unable to confirm that timeline with Microsoft. ®

  •  
❌