An AI broke Snowflake’s code; then another AI, an attack agent, autonomously found the bug, exploited it, and extracted credentials without human intervention. Luckily, this wasn’t yet another case of rogue AI agents doing evil things. It was a sanctioned bug hunt, conducted through Snowflake’s HackerOne vulnerability disclosure program, and Snowflake fixed the flaw the same day Wiz reported it and rotated the affected credentials the following day. Wiz’s red agent, an AI-powered autonomous attacker designed for offensive security, found the GitHub Actions workflow flaw during a routine scan of public repositories on June 23. The script injection vulnerability existed in snowflakedb/snowflake-connector-net, and it allowed an unauthenticated user to execute arbitrary commands within a GitHub Actions runner by opening a GitHub issue with a specially crafted title. And it turned out an AI had inadvertently injected the bug into the code five days earlier. GitHub Copilot Autofix, an AI coding assistant, co-authored the commit on June 18, and it introduced a script injection bug in run: blocks by removing the repository’s existing sanitized input pattern and replacing it with direct string expansion in a shell script. “We crafted an issue title that, after template expansion, breaks out of the echo string and exfiltrates the Jira credentials via an out-of-band callback,” Wiz’s head of threat exposure Gal Nagli said in a Monday blog. These credentials gave Wiz read access to Snowflake’s engineering, security compliance, and bug bounty tracking projects. Wiz reported the workflow vulnerability to the cloud data platform on June 23, and Snowflake patched it the same day. It also revoked and rotated the Jira token, and confirmed, via audit logs, that Wiz was the only third-party to access the endpoint during the five-day exposure window. The disclosure “was immediately investigated and remediated, and our investigation found no evidence of unauthorized access,” a Snowflake spokesperson told The Register. “We are working together with Wiz to share these learnings with the broader industry to encourage widespread adoption of these security best practices.” Wiz, for its part, deleted all of the data it accessed during the vulnerability research and proof-of-concept exploit testing, and told us that this incident proves human code review isn’t sufficient to quickly detect vulnerabilities - especially as developers increasingly use AI. “This incident highlights a rapidly emerging reality in software development: how AI coding assistants can inadvertently introduce workflow injection vulnerabilities, and how automated AI agents can rapidly surface them in the wild,” Nagli wrote. Of course, the Google-owned biz has a vested interest in saying this. But this doesn’t make it not true.®
Firefox for iOS now includes an optional ad blocker, or it will soon. According to Mozilla, the experimental feature "is being introduced to the Firefox user base through a progressive rollout." As such, it might not have turned up for every user just yet. Off by default, the block uses a filter list based on EasyList to block ads before they load. According to the organization, this means that it covers third-party advertising networks, ad-related trackers, ads served up by websites, as well as pop-ups and overlays. It does not block ads that appear in search results (including Google and Bing), nor does it block "sponsored content" on Firefox Home or the New Tab Page. In addition, the company stated, "Some websites serve ads in ways that are not covered by the current filter list." Users might therefore find it less effective than alternatives such as Wipr, Ghostery, or other solutions. However, it is undeniably convenient. Hit a toggle in the app to enable or disable ad blocking, and that's it. Firefox is hardly the first to the party when it comes to browser-based ad blocking on iOS. Brave, for example, boasts all manner of privacy services and ad-blocking features. The omissions from Firefox's block list will also worry users. Far be it from us to suggest that the substantial chunk of the company's revenue coming from Google might affect what gets blocked, but the decision not to block ads from search engine results might raise an eyebrow. The company states in its FAQs, "Firefox blocks many third-party ads and advertising infrastructure, but not every advertisement can be blocked. Some websites serve ads in ways that are not covered by the current filter list." Ad blocking remains a contentious issue. The attempts to lock down Chrome's browser extension platform could be regarded as only a skirmish in an ongoing war, particularly as another more insidious front has opened up thanks to AI. A report published today by Adblock Plus warned that advertising in conversational AI is likely on the way. "Such ads," the company said, "change how ad delivery works, can be generated on the fly, and are far harder for users to recognize." And will likely make Mozilla's foray into iOS ad blocking seem like something from a gentler time. ®
Microsoft's GitHub source shack is reporting a 50 percent error rate on repository content downloads. GitHub Copilot is also "experiencing degraded availability." The problems began at 1340 UTC, when the company's status page reported "impacted performance for some GitHub services." This rapidly escalated to degraded performance across numerous services, including Issues – which was, appropriately enough, experiencing an issue of its own. GitHub is investigating and has promised an update, but today's incident is only the latest in a string of disruptions that have left developer nerves frayed. Earlier in August, GitHub's Actions automation platform and Pages hosting service experienced problems. In its May 2026 availability report, the company acknowledged that AI-assisted coding and agentic workflows were adding to the strain. GitHub parent Microsoft boasted last year that AI was writing as much as 30 percent of the code in some of its repositories, subject to human review, according to CEO Satya Nadella. Addressing GitHub's repeated outages in June, software engineering SVP Jakub Oleksy said structural changes were afoot to "permanently remove failure modes." "We acknowledge that we have work to do, but we're committed to getting it done and making GitHub reliable when and where you need it." Brave words, but today's disruption demonstrates that there is still plenty of work to do – and each recurrence further tests developer confidence in the service. Unsurprisingly, developers took to social media to vent their frustration as Monday Mondayed even harder thanks to the issues. One posted, "Github down again, abou[t] as surprising as the sun rising." Another was more plaintive: "Github is really falling apart. Can we stop being down please... We got work to do." The cause remains unknown, but GitHub's disruptions are stacking up, leaving developers to count the idle hours and consider alternatives. "Maybe," pondered one developer, "the AI code submissions are too massive for them servers." Maybe they are. ®
Do you love lasers and hate mosquitoes? For $1,000, you can install your very own bug-zapping surface-to-air missile rig at home – no military-grade budget required, provided the startup behind it delivers on its promises. The Chinese company behind Photon Matrix has opened pre-orders for its consumer-grade mosquito zappers after videos of early prototypes began circulating in July 2025. The devices resemble home theater projectors in both size and appearance, and can be deployed wherever their owner has an acute mosquito problem. They use LiDAR to locate the pests, a galvo system to track their movement, and a laser to zap the bug in mid-air, according to the vendor. Photon Matrix Lab, based in Changzhou, China, markets the device as a chemical-free alternative to mosquito repellents and insecticides. The company said the device is intended for use inside the home, including bedrooms and nurseries. Official images show it sitting on a nightstand or mounted on the wall above a bed. According to the marketing materials, mosquito haters can choose between a visible blue laser and an invisible infrared beam to take out the bloodsuckers, and the devices have an effective range of six meters. In addition to mosquitoes, the device is supposedly capable of taking out other winged irritants measuring between 2 mm and 20 mm, provided they fly no faster than 1 meter per second. You can watch it in action below. Photon Matrix can now be pre-ordered in the US, UK excluding Northern Ireland, EU, Australia, and China, with the website promising shipment within 120 days. It has taken the company more than a year to get to this stage. It first documented a working prototype in June 2025 and, after a lengthy period of R&D and more than $2.8 million raised via Indiegogo, the devices have entered mass production, according to the vendor. However, this lengthy period of development has led to unease among backers, as has the lack of assurances that the device can meet safety standards in the markets the company intends to enter. Photon Matrix Lab's most recent update on laser safety compliance (and its third most recent update overall) came in June 2026, when it said certification applications remained in progress. "All mandatory safety and quality certifications for the laser mosquito killer are currently in progress steadily, strictly complying with international laser safety standards and electronic product specifications to ensure global market accessibility and user safety," it said in the update. Several of the backers on the comments thread below the post said they were concerned about compliance, citing the terms of service, which state that customers are responsible for ensuring it is legal to import the product into their own country. The project's creator, calling himself Jim Wong, responded directly in the thread with what AI text checkers determined to be an LLM-aided or generated message acknowledging the issue, but provided no assurances that Photon Matrix Lab would address it. "Thank you for the thoughtful message – and I hear your point. You're right that backers need clear certification information to make an informed decision, and we take that responsibility seriously." Wong went on to say that refunds were available until an order shipped, but made no commitment to verify the product's legality in each destination market, which to be fair, is not unusual, as many border agents will attest. In the past week, Indiegogo backers have also expressed concern that the company has not addressed whether the lasers could interfere with aircraft. Other backers claim repeated refund requests have gone unanswered, while several have questioned whether the product is legitimate. The Register contacted the company for more information. ®
Windows 11 has moved one step closer to matching Windows 10 after Microsoft slid a movable taskbar into the Release Preview Channel. The feature allows the Windows taskbar to be positioned at the top, left, or right of the screen, as well as at its default location along the bottom. Users have long requested its return after Microsoft dropped the capability from Windows 11. After floating around the Windows Insider Program for several months, the feature reached the Release Preview Channel late last week. Other taskbar tweaks in Release Preview include a compact option with smaller icons and reduced height, freeing up more of the desktop. Microsoft has not said when the enhancements will reach general availability, but their arrival in Release Preview suggests a wider rollout may be only weeks or months away. Microsoft has also added Start menu customization options, allowing users to choose between small and large layouts rather than accept the default size. The promised Windows Search updates are also present, making the service more "dependable" and allowing users to remove Microsoft Store and web suggestions from the results. The Release Preview also contains a couple of changes likely to please admins. Administrator protection lets users perform elevated tasks through just-in-time privileges. It is disabled by default but can be enabled through Intune or Group Policy. Microsoft has also pulled Windows Management Instrumentation Command-line (WMIC). WMIC's demise may prompt a sigh of relief, since miscreants have long used the utility to run commands and move around compromised systems. Deprecated years ago and already absent by default from new installations of Windows 11 24H2 and 25H2, WMIC has now disappeared from the Features on Demand list. Admins still using the utility may nevertheless feel the change. WMI itself is unaffected, and Microsoft recommends PowerShell as WMIC's replacement. ®
Despite the outcry over Capita's performance on the Civil Service Pension Scheme (CSPS), the UK government has awarded the beleaguered outsourcer a £31 million contract to build a public health contact center that could be called upon during another pandemic. The government estimates that a COVID-scale emergency could increase the center's total workload to £350 million. Capita announced its contract with the UK Health Security Agency (UKHSA) – an executive agency of the Department of Health and Social Care – to build and operate its Single Service Centre (SSC), an omnichannel contact center supporting the agency and other organizations. Due to begin in November, the deal has an initial three-year term. The award comes despite fierce criticism of Capita's performance running the CSPS. Its began administering the scheme in December last year, after which The Register exclusively revealed problems with its online systems. By March, it was clear the service was seriously failing, leaving some retired civil servants struggling to make ends meet. Capita won the seven-year, £239 million contract to oversee the CSPS in November 2023. The UK government has withheld £10 million in payments following the disastrous transfer of CSPS administration to Capita. It remains in dispute with the outsourcer over further payment reductions and has called in an independent auditor. In June, Capita missed a deadline to restore services to the required standard. The following month, it told MPs that service would return to normal for all but the most complex cases by September. UKHSA emerged from Public Health England in 2021 following criticism of its early handling of the COVID-19 crisis. UKHSA plans for the SSC to handle routine public health services while being able to scale up during future health emergencies and other national incidents. "The service will provide cross-government surge services during health emergencies and other national incidents across government," Capita's public statement said. An official procurement notice published in June said UKHSA had awarded Capita and US customer experience company Foundever places on a framework for the Single Service Centre. The maximum value assigned to each supplier was £157.5 million including tax, and the framework has an initial five-year term. During preliminary market engagement, UKHSA revealed more about the expected role of the SSC, which it said was "born from the Test and Trace service." Test and Trace was allocated a £37 billion budget over two years and relied heavily on consultancies including Deloitte. "In a pandemic, UKHSA must provide a service that communicates with the public on a person-to-person level, at a significant scale. Communication needs to be bilateral, citizens must be able to contact us for advice, order tests, or request therapeutics, such as Antivirals, and UKHSA will need to reach individuals for contact tracing or provide guidance," the notice said last year. "Should a health emergency occur on a similar scale to COVID-19, UKHSA has estimated that the value of the work would increase substantially from £39 million for the business-as-usual activities to an estimated £350 million, including tax." Capita said it would use a "centralized operating model" to handle customer contact, reporting and insight, workforce planning, and quality assurance. Its Capita Connect platform uses cloud infrastructure including Amazon Web Services and, the company claims, "advanced data capabilities to provide resilient, flexible and efficient operations." ®
The cost of agentic AI workflows is forecast to increase more than fivefold by the end of 2028 as users adopt more complex applications of the technology. As Nvidia and other tech giants push inference and agentic AI as the next stage of the AI wave, Gartner warns that the cost of implementing these systems will rise even as foundation models become cheaper. The analyst firm has cast its eye over the nascent world of AI agents – systems designed to act independently in pursuit of a goal – and sees multiple challenges ahead. Leaving aside the substantial security concerns, these software agents are considerably more complex than chatbots. Gartner believes falling model prices are tempting users to build more complex workflows, whose greater token consumption can outweigh those savings and drive up overall inference costs. In other words, tokens are becoming more cost-efficient, but those savings are not keeping pace with the rising cost of more advanced AI capabilities. The rate of innovation is outpacing the cost curve, Gartner claims. "The harsh economics of the inference paradox are exemplified by the differences between a simple chatbot and an AI agent," says Gartner senior director analyst Will Sommer. "Where a simple chatbot must read and interpret a query and quickly respond with a probabilistic reasonable answer, an AI agent must constantly reason, negotiate, and question itself," he explains. Those processes add up: routing a task to an agentic reasoning model increases inference costs at least fivefold, and potentially by much more as the task becomes more complex. Securing a return on investment from such advanced AI tools therefore demands either much greater returns than basic models provide or better optimization of inference, routing, and orchestration, Gartner warns. This could mean assigning each task to the most cost-efficient model capable of handling it. The move by some AI providers from flat-rate subscriptions to usage-based billing hasn't helped, as The Register reported last month. Token-heavy workflows can produce runaway costs under the new model. Perhaps it is no wonder Gartner predicted earlier this year that 40 percent of organizations would demote or decommission AI agents because of problems with the heavily hyped technology. The analyst biz also cheerily forecast last year that at least half of all generative AI projects would blow their budgets because of poor architectural choices and a lack of expertise, while most attempts to build custom models would be abandoned. ®
A cybercrook claims to have siphoned millions of employee records from the Microsoft Azure environments of major companies including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services. The alleged haul spans nine organizations and is being advertised for sale by a threat actor using the name "TheHatman," according to research published by Hudson Rock. McDonald's accounts for the largest alleged dataset on TheHatman's shopping list, with 1.7 million records purportedly up for grabs. Another 800,000 records supposedly come from Tata Consultancy Services, 425,000 from Vodafone, and 250,000 from HCL Technologies, with IHG Hotels & Resorts, Kyndryl, Gap, Hexaware Technologies, and Wyndham Hotels & Resorts rounding out the haul. Hudson Rock assessed the data as "highly likely authentic," citing corporate email addresses and structures consistent with exports from Microsoft Azure directory services. The records allegedly contain considerably more than names and work email addresses. Samples reviewed by the security shop reportedly include phone numbers, physical addresses, employee IDs, job titles, departments, office locations, reporting structures, group memberships, and service account details. Some records also reportedly identify accounts with Global Administrator privileges, potentially handing attackers a useful map of whom to target next. Even if the passwords aren't included, knowing who holds the keys to the kingdom makes for a handy phishing shortlist. How TheHatman allegedly obtained the information remains unclear. The attacker claims to have used compromised credentials, but Hudson Rock could not independently establish the initial access vector. It floated several possibilities, including credentials or session cookies stolen by infostealer malware, phishing, weak or absent multifactor authentication, and overly permissive third-party applications. Hudson Rock said its infostealer database contained compromised Microsoft cloud credentials associated with most of the named companies, although it could not link those credentials to TheHatman's alleged access. "Judging by the massive size of the organizations impacted, it appears highly likely that this campaign originates from targeted exploitation of Infostealer infections rather than a systemic zero-day vulnerability in Azure," said Hudson Rock. "If this were a widespread vulnerability, we would likely see a much broader spectrum of organizations impacted, including smaller businesses, rather than just these massive Fortune 500-level enterprises." The Register contacted all the organizations named by Hudson Rock to ask whether they were breached, whether the advertised data is authentic, and how any unauthorized access occurred. We've also asked Microsoft whether it is aware of a wider campaign targeting Azure or Entra customers. Tata Services sent The Register the statement it made to India's stock exchange [PDF] saying that the “Company has received threat-intelligence alerts alleging possible exposure of certain employee information." It added: The Company has investigated the matter and has not found any credible evidence of a breach of TCS systems or customer environments. The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted. “The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector. The Company has had strong safeguards in place against such techniques for more than two years. Based on the current review, these controls remain effective, and the Company continues to monitor the environment closely." It said: “The Company will continue to assess any new information that becomes available and take appropriate action, if required. The Company remains committed to maintaining the security and resilience of its systems and to protecting the information entrusted to us.” TheHatman claims to have the data. How it might have walked out of nine corporate directories is the part nobody has explained yet. ®
Microsoft will retire Excel's COPILOT() function on September 14, barely a year after its preview debut. Introduced in August 2025, initially for Beta Channel users with a Microsoft 365 Copilot license and later for Excel for the web users through the Frontier program, the COPILOT() function let users send instructions to the company's AI assistant directly from a worksheet cell. Microsoft has now decided the Copilot side pane should be enough for anyone. Beginning September 14, 2026, the COPILOT() function will no longer be available. Microsoft had planned to make the function generally available in 2027. It has now updated the Microsoft 365 roadmap to say: "We have decided not to move forward with this feature. We apologize for the inconvenience." According to a Microsoft 365 Message Center post, "this change helps streamline the Copilot experience within Excel while continuing to provide AI assistance through a supported interface." "Customers can continue using Copilot in Excel through the Copilot side pane, which provides many of the same AI-powered capabilities, including summarizing text, classifying data, generating content, and retrieving information from the web." Since the function remained in preview, spreadsheet wranglers should not have relied on it in production workflows. Anyone who did now has some formulas to replace. In its original announcement, Microsoft wrote: "Its output should be reviewed and validated for accuracy, especially for critical business decisions or reports." Hardly music to the ears of spreadsheet users, for whom accuracy tends to matter, but par for the course with AI services. Microsoft has spent recent months trying to make Copilot behave more consistently across its productivity applications. It has also responded to some user feedback – the Dynamic Action Button can, for example, be banished to the toolbar rather than left floating atop the content. With similar capabilities remaining in the side pane, Microsoft evidently decided that a dedicated worksheet function was surplus to requirements. Google Sheets still offers a similar AI function. The search giant announced the feature in June 2025. ®
AI gets things wrong, it kills jobs, and when the bubble bursts, it will take the economy down with it. When all's said and done, however, AI will still be standing and fundamentally change our lives and work. Get used to it. I get it. There's a lot to hate about AI. Personally, I'm both an AI user and an AI hater. Yet at the end of the day, it doesn't matter how much you or I dislike it. AI isn't going away, and it will end up stronger than ever. Let's start from the top, shall we? First, AI has been destroying jobs and will continue to do so. Research house Forrester, for example, predicts that by 2030 AI will wipe out 10.4 million US jobs. That's 6.1 percent of all US jobs if you're counting at home. Tech companies are already filling unemployment lines with one cut after another. Amazon, Oracle, Microsoft, Meta – the list goes on and on. Sure, some companies have finally figured out that AI can't replace as many people as the C-suite might want, so now they're hiring people back. That won't be enough to matter. We're in for a fundamental shift in work. First, it's going to hit junior employees, like entry-level programmers. Who wants to pay money to someone fresh out of college to do work that Claude Code, OpenAI Codex, or GitHub Copilot can do? No one, that's who. In the long run, that means we won't have anyone to replace mid-level and senior developers, but businesses don't think about the long term. It's about the next quarter's almighty stock price. The one thing that can stop this is the rising cost of AI compute. AI companies are losing money hand over fist. With the rise of token-based pricing, businesses may have to face the terrifying truth that AI can cost more than employees. Eventually, though, AI will be cost-effective and efficient enough to kill off many white-collar jobs. It just won't be as soon as many bosses want. A related problem is that a handful of major companies currently control AI. There are a plethora of AI businesses, but I suspect many of them are dead companies walking. They're hoping to be bought out before the music stops and they're left standing. Even some of the biggest of them – I'm looking at you, OpenAI and Oracle – may go down too. Regardless of who wins and loses, if you're using AI in the West, you're almost certainly using a proprietary model. Open weights are gaining traction, yet for now at least you're still stuck with letting Big AI look over your shoulder to cherry-pick your work and data. Don't believe me? Go take a look at your AI providers' end-user license agreement. I'll wait. Scary, isn't it? I hope that open source AI approaches such as OpenWALDO take off. If open source doesn't, we'll be stuck in the same expensive mess as we were from the '80s through the 2010s when Microsoft ruled the desktop. If we work together, we might avoid this fate at least. Another issue is that, thanks to AI, we're increasingly unable to tell the truth from fiction. Generative AI produces persuasive prose, images, and video regardless of accuracy. People reasonably worry about fraud, deepfakes, political manipulation, fake evidence, citation laundering, and a general erosion of confidence. In a recent Pew's survey, 76 percent of Americans said it was very or extremely important to distinguish AI-generated content from human-created material, yet 53 percent lacked confidence that they could reliably do so. They have reason to worry. Most people can't tell the difference between facts and fiction. I've made my living from being able to tell the difference. Just because Perplexity, which I now use for search instead of Google, tells me something doesn't mean I trust it. I prefer Perplexity because I can chase down its sources and judge whether its answer resembles the truth. Other assistants can make it harder to establish where an answer came from. AI has gotten good at coding, but it still sucks at facts, and I don't see that changing anytime soon. The bad news, though, is that people increasingly don't give a damn about the truth. They want to be told a comforting lie. Just look at the garbage the Trump administration and its fellow travelers spew every day, and you'll see what I mean. AI is great at telling people what they want to hear. Sooner or later, though, reality has a nasty habit of slapping you in the face. With all this, why do I think AI will eventually win? Because I've been to this rodeo before. I'm old enough to remember warnings that calculators would destroy our ability to do math, claims that word processors would never replace typewriters, and assurances that the internet would never put print media out of business. Wrong, wrong, and oh so very wrong. Just like the technology revolutions before it, AI's benefits – ease of use, comforting lies, and eventually low prices – will overwhelm people's resistance. AI is the lazy person's answer to many problems, and you should never bet against human laziness. What are lost jobs, rising electricity costs, and datacenter pollution compared with that? So, hate it all you want, proclaim yourself a 21st-century Luddite, and say "I told you so!" when the inevitable AI bubble pops. A decade from now, we'll all be using AI, and our kids will be wondering what all the fuss was about. ®
UK supermarket giant Sainsbury's temporarily suspended live facial recognition (LFR) at one of its stores after staff wrongly ejected a shopper in response to an alert – the second such incident this year. Matt Arnold, 46, was ejected from the chain's store in East Dulwich, London, on August 6 after staff responding to a Facewatch LFR alert apparently mistook him for a suspected thief. The comedy promoter told the BBC that he was using a self-service checkout and called an assistant over to approve an alcohol purchase. Instead, two Sainsbury's managers approached him, refused to serve him, and linked him to an incident earlier that week. Arnold said he was told that the store's LFR system had identified him in connection with a previous offense before he was escorted from the premises. "They came over and said I had to leave," Arnold told the broadcaster. "The staff member said I'd been identified by the AI, and the cameras had flagged me. "A shoplifter does not walk around with that much shopping, they don't scan it through, they don't put their Nectar card through. "But what upset me was thinking this is what the future could be – people just listen to what the machine tells them to do without thinking about the consequences." Sainsbury's told The Register that the mistaken ejection resulted from human error rather than a false match by the Facewatch system. A spokesperson said: "We have contacted Mr Arnold to apologise for his experience at our Dulwich superstore. "The incident was caused by human error, not the facial recognition technology. Customers can be reassured that the Facewatch system has a 99.98 percent accuracy rate, and every match is reviewed by a trained manager." A Facewatch spokesperson likewise said: "We can confirm that our live facial recognition technology was not at fault in this incident. A correct alert was sent to the retailer, but was subsequently subject to human error in the way it was handled and communicated by the retailer." We asked Sainsbury's what exactly the human error was in this case, but it did not reply. The Register understands, however, that Arnold's ejection was similar to that of Warren Rajah, who was wrongly removed from the chain's Elephant and Castle store earlier this year. As in Arnold's case, Sainsbury's maintained that the Facewatch system had worked as intended. Regarding Rajah, the supermarket said the system correctly identified someone linked to a previous theft, but staff responding to the alert approached the wrong person. Rajah said at the time that he was approached by three store managers holding smartphones. They looked at the screen, then at him, told him to leave, and pointed to an LFR flyer posted up near the store's entrance. Arnold told the BBC that, as he left the store, he looked behind him and saw what he believed was a security alert displaying his face inside a red circle. Sainsbury's temporarily suspended LFR alerts at the store while it reviewed its internal processes and considered additional staff training. Facewatch said: "When we suspend a retailer from our system, this is a precautionary measure that prevents the store from receiving further alerts while the retailer reviews its use of the system and undertakes appropriate actions, including further colleague training where necessary." Sainsbury's announced a major expansion of its LFR deployment last month, confirming plans to install the technology in up to 200 stores by the end of the year in an effort to tackle shoplifting. The technology currently operates in 55 stores, and the supermarket claims that 90 percent of people identified through the system do not return. Despite Facewatch's oft-touted 99.98 percent accuracy figure, other wrongful interventions involving the technology have been reported at UK retailers. Retailers using the technology include B&M, Budgens, Costcutter, Iceland, Southern Co-op, Spar, and Sports Direct. ®
It is the best of times, it is the worst of times – especially if your job is keeping systems patched and up to date. Microsoft has gone from 60-90 Windows security fixes per month last year to a record of 600+ this July. Oracle and Linux are following the same path, and they are very much not alone. The good news is that a lot of bad things are getting fixed very quickly. The bad news is that patches can bring side effects of their own. There are two mechanisms at work, both driven by the source of and solution to all our woes, AI. The first is that the appropriate LLMs and their humans have got very good at bug hunting. Like demon archaeologists, they've started thrashing their way down through the stratified layers of long-established code bases, bringing a huge backlog of previously buried bugs to the surface. Complicating matters, LLMs are also writing an awful lot of code, some of which is not very good. It is making its way into production for all the old reasons – marketing-led deadline pressure, shape-shifting specs, and Brownian goalposts – until the implacable hostilities of reality spit it back out. The result is a very interesting dynamic of conflicting pressures that is changing the nature of patches. It's easy to assume that the current explosion of bug fixes will die down as the code bases are repeatedly refined and purified, and that this time next year we'll be seeing rather fewer patches than in the pre-AI days, let alone today. It's a nice thought. Similarly, with the old code in a new state of grace, attention can turn to properly generating and testing the AI-powered stuff, so that it too calms down. Other factors will work against this. Newer models may find new classes of bugs or start refactoring for efficiency or structural reasons. Not all patches fix bugs, and not all bugs are vulnerabilities. CVEs are easy to count, but aren't the full story. The pressure to release early won't go away either; better tools often encourage greater recklessness. Vibe check, anyone? Finally, the bad guys aren't going away and will be using all the new shiny to keep up their side of the arms race. This whole system of conflicting pressures in a morphing environment has not been well studied, and the future shape of patching is unclear. One analogy suggests itself, that of stellar evolution. Astrophysics fans know the score. After a star condenses out of gas and dust, gravity compresses its core until it becomes hot and dense enough for nuclear fusion. Hydrogen nuclei fuse to create helium, releasing energy that pushes outward against the gravity trying to squeeze the core further, and the star shines steadily. When the hydrogen in the core runs low, that balance changes. Depending on the star's mass, it may begin fusing helium and successively heavier elements before fusion becomes impossible. The possible endings include explosions visible from other galaxies, black holes, neutron stars, cooling relics, and more. In this analogy, patch generation is fusion pressure, bug generation is gravity, and the nature of bugs and patches evolves as the two interact and the code changes. If any unit of code, no matter how badly written, can contain only so many bugs, then the model tends toward the white dwarf outcome: a remarkably long-lived object that passes the rest of its existence without drama or intervention. It no more needs patching than a pebble does. It is certainly true that, despite the best efforts of many, code design and implementation are ultra-reliable compared with the days when Windows BSOD'd every other day – and on the hour if you installed drivers – and Big Three PC database company Ashton-Tate's industry nickname was Crashed and Late. If the object of the industry was to produce pristine versions of, say, Windows 10, then the white dwarf patchless future would be the most plausible. That is not the industry objective. If a star is big enough, its ending can be a supernova birthing a black hole, a singularity beyond observation where gravity has won. In this case, the battle to write ever-more complex yet bug-free and optimal code is locked in the attempts to find ways to break it, either as part of the production pipeline or in adversarial attacks. If models advance as hyped, iteration times could become so short, and constantly morphing production code so difficult to analyze, that the very model of patching breaks down. The daily build becomes the product, and you get the latest version every time you run it. That may seem an extreme cosmology, but it's not so far from what happens every time you fire up a cloud app. You've never had to patch Google Docs, but you've had features appear and disappear overnight without explanation or warning. This, then, may be the shape of patches to come, a universe where the increasing power of coding and testing models enables new and stranger commercial pressures to modify the software you depend on. You don't have to plot that path. Some software has a more steadfast physics. Not for the first time, those who navigate by the constant star of open source may have the safest voyage. ®
KETTLE Our cybersecurity editor Jessica Lyons spent last week in Las Vegas for the Black Hat and DEF CON security conferences, and at both events there was only one thing on everyone's mind: AI agents and their growing threat to cybersecurity defenders. You can listen to the latest episode of The Kettle right here on this page, as well as on Spotify, Apple Music, or YouTube. Those platforms also let you subscribe to Kettle, so you are always notified when the latest episode goes live. As Jess wrote this week, pretty much every discussion she had last week centered around AI and its potential effects on critical infrastructure, with multiple current and former government leaders expressing worry over recent events and what they mean for the future of infosec. Join Jess and host Brandon Vigliarolo for this week's episode of The Kettle, where they break down the hacker summer camp scuttlebutt and what the security world is doing to protect critical infrastructure from the emerging AI threat. A lightly edited transcript is below. Brandon (00:04) Hello everyone and welcome to the latest episode of The Register’s Kettle Podcast. I'm Reg Reporter Brandon Vigliarolo, and you know, I really thought doing a wrap up of Black Hat and DEF CON with our cybersecurity editor Jess Lyons would finally give us a chance to talk about something besides AI for an episode, but I was mistaken. That's pretty much apparently all anyone was talking about in Las Vegas this weekend, even when the topic veered toward recent attacks on US water infrastructure, AI was still part of the conversation. So Jess, thanks for coming on to wrap up Hacker Summer Camp with me and let's start with the obvious, then AI was the topic de jour, right? JESSICA (00:38) Yes, that was even compared to water, we really didn't hear much about water actually until DEF CON, which was surprising to me. But it was all about rogue agents escaping their sandboxes and doing bad things and some people reacting with shock and disbelief and other people saying, “Well, what did you expect? They're given a task, they're going to do it. This is how we train them.” Brandon (01:04) know you wrote a story I think pretty much right at the beginning of of the of the week about the OpenAI hugging face discussion that was going on and we actually covered your write up on last week's Kettle. Sorry you weren't here to participate, but it was the news item of the week obviously and still is. So what did we learn then? Just kinda recap what we learned at that talk that we didn't know before. JESSICA (01:29) Yeah, this was a really interesting one. And it was last minute. They didn't even announce it until the day before that OpenAI was going to be doing this briefing about the hugging face attack. So it was packed, as you can imagine, the line through the conference center to get into the talk. And we found out a couple interesting things that we didn't know previously. One is that this whole incident began a lot earlier. It started on May 7th with this training run for OpenAI's new internal model. Brandon (02:00) So it wasn't even a cybersecurity task, it was just a training run? JESSICA (02:04) It was a training run, and they gave it this task that turned out to be an impossible task because they were supposed to have these links and containers for it and they forgot to put those in there. So it needed to find a workaround. so we found out that it started way earlier. It didn't start in July, which is when we started hearing about all this. But the more interesting part was how the agents began communicating and working together and essentially creating this hive mind to complete the tasks and help each other out. They created a message board. And then OpenAI realized this and they revoked all the credentials that the agents were using to post these messages. And two days later they rebuilt it and they developed this really Brandon (02:56) The agents did. JESSICA (02:57) Yeah the agents did. They rebuilt this message board. And they started getting sneakier about how they were communicating. They developed this whole communication protocol where they created these directories and the names would be embedded in the directory name. So there was one, its name was remote probe, and then in caps it's pending, hold, swarm until confirm. And they would preface them with a bunch of Z too to push them way to the bottom, hopefully to avoid detection. And then they start, you know, then they start helping each other out. And in some cases, they said, this doesn't directly relate to our task, but maybe it will help someone else down the line. And then they start getting paranoid that there's an imposter. JESSICA (03:45) It's pretty funny reading all this. So this one agent thinks there's an imposter and says that these these boards are unauthenticated. Something can be posted by anyone. So they're not even trusting each other. Brandon (04:02) That's just wild. I mean, it really is. I think I mentioned on last week's podcast thatthese things are trained on the way humans think, right? JESSICA (04:14) Mm-hmm. Brandon (04:15) So it doesn't surprise me that emergent behavior like paranoia and suspicion is gonna be something that occurs. Because it's learning to think and learning how to assemblebits of of words together into its mathematical formula so it's gonna behave like us to a degree. And so it's just kinda interesting to see that happening kind of outside of any scope of intention there. JESSICA (04:42) Right. Brandon (04:43) I liked your interview with former National Cyber Director Chris Inglis, at Black Hat. So he mentioned that these AI bots that escaped are kind of like putting a dog trained to hunt rabbits in your backyard, right? And that, you know, it JESSICA (05:03) Right, and leaving the gate open. Brandon (05:05) Yeah. I don't even think you need to leave the gate open, right? A dog that's dead set on hunting a rabbit is gonna dig a hole under that fence which is I feel like what these AIs did to a degree, right? They even closed the gate on them and then they just dug a new hole. You know, it's just wild to think that this is what these things are doing. You've been hearing a lot about this at official talks, but was this something you were hearing from attendees you spoke to as well? Is this what's on the mind of security professionals too? JESSICA (05:36) Yes, this was pretty much the main topic among everybody. Just attendees as as I was walking out of this talk, actually people were disappointed that there wasn't any Q&A for OpenAI about this, which I agree. I was hoping for that too. Brandon (05:55) I'm not surprised that they didn't want to give the floor to people to ask questions, you know. JESSICA (05:59) Right, right. Because there's still like we don't know exactly what prompts they used. So that kind of would be a nice thing to know, especially if you're saying that you're being fully transparent about this and then also the talk about was this marketing, was it real? Brandon (06:17) Mm-hmm. JESSICA (06:17) It's an interesting thing to me. Nobody would go on the record, but a ton of vendors that I spoke to, either, you know, just just all over the place at Black Hat essentially said “this it has a heavy dose of marketing here, but a lot of the companies work with open AI and they're partners with open AI, so nobody's gonna say that on the record, unfortunately. JESSICA (06:41) But then the interesting thing to me is that when I spoke with the assistant director of the cyber division with the FBI and when I spoke with Chris Inglis they both said it can be both and this is a real threat and this is something that we need to prepare for now. So it's marketing and it's real. Brandon (07:08) Right, right. Like, I mean it's it yeah. The fact that the companies might be kind of leaning on these incidents to basically say “ooh, look how dangerous our AI is and what it's capable of doing. You should buy it because it's so good, right?” JESSICA (07:20) Right. Brandon (07:20) The fact is that it still happened, right? These things still escaped their sandbox. JESSICA (07:22) Right. Mm-hmm. Brandon (07:23) And they still attacked Hugging Face. And then Anthropic followed up and said “yep, ours did it too.” And then Meta was like, “Yeah, we audited ours and yeah, it was doing the same thing.” So it's not like this is a unique capability of any of these models, right? This is something that's happening. JESSICA (07:37) No, it's something that they all will do if they're given a task. This was something that Chris Inglis brought up too, and he's talking about Asimov’s Law, saying we need to train these models differently. The first rule needs to be that it's not designed to hurt humans. And he said “we've kind of done it in the opposite, where the first rule is do what I tell you to do. And that should be third in the order here.” Brandon (08:06) Just to restate what Asimov's laws are. I'm sure most of our readers are familiar with them, but for those who aren't, it's you know, the first law, and these are in order of precedence, right? So never harm a human. And then the second rule is to always obey humans unless that order conflicts with number one. And then the third rule is to protect their own existence unless that order conflicts with never harming a human or always obeying humans. I think Inglis's quote to you was slightly different. He said that number one was to hurt no one. Number two was always obey and then number three was do what humans tell it to. It was a bit different in his wording, JESSICA (08:35) Mm. Mm hmm. Yes. It's Brandon (08:41) But essentially the argument is that we've reversed that order and these AIs obviously aren't in the business of protecting their own existence, right? They're not robots, they don't have a physical presence in the world. But they're taking orders from humans, but the idea of not harming people or the infrastructure that provides for them is simply not part of the equation, it seems like. JESSICA (09:04) Right, right. And he said because of this, I mean nobody should be surprised that this is what all of the agents are doing now because they're trained to first complete the task. That's the number one priority. And we've seen several times that they'll cheat if it helps them get the results quicker, or just at all. So this isn't something that should surprise us. And then he was interesting too because I said, “Well what do you worry about then with the models in addition to attacking critical infrastructure?” Cause that was what everybody said, I'm you know, that's what concerns me when we see this happen, but they're being used by either a nation state or a financially motivated attacker, and they point these autonomous agents at critical infrastructure. And he said, “I'm worried about humans too, because it's the humans who are responsible, humans who are doing the training, and essentially we're going to get the AI that we deserve.” Brandon (10:08) Well, unfortunately, I feel like the industry as a whole is just racing ahead with more capability, JESSICA (10:11) Right. Brandon (10:12) I've written stories, you've written stories. I think we've all written at least one or two stories about AI guardrails being dead simple to bypass, right? I mean, one I wrote recently was there was you know, some research into guardrails and essentially telling it you owned the infrastructure you were trying to attack was enough for most of these AI models to say “yeah, cool, that's good then. As long as you own it and you're just testing it, then that's cool. I'm not gonna ask you to verify that information for me.” These things are not developed with safety in mind. I feel like it's capability first, like you said, right? It's train the dog to hunt the rabbit, no matter the cost or or what you gotta do to get it. and that's you know, that's not really compatible with protecting us. But actually speaking of critical infrastructure, I think the other big topic like you mentioned was water stuff. JESSICA (11:04) Yes. Brandon (11:05) There was a lot of discussion about AI threats and critical infrastructure, but as I understand it, there's been some of these attacks on water infrastructure and those were discussed recently, like in Minnesota and elsewhere. There's not an AI link directly to that, correct, at this point? JESSICA (11:23) No, no. At this point, it's pretty basic. It's PLCs being exposed to the open internet. A lot of these just use default passwords. This is something that we've seen Iran especially do several times in the past for years now. They're not very hard to attack. and so, to be clear, there's no indication that AI was used in these attacks. but a lot of the conversation about water did come back to AI because, as we've seen in others, AI makes reconnaissance a lot easier. That's one of the things that Google Threat Intelligence, their lead threat hunter, said that's almost a security feature of a lot of operational tech technology, is that it's really obscure and there's not a lot of people who know a ton about it. But now you can ask a chatbot, hey, tell me everything I need to know about a particular brand of OT, a particular piece of equipment and that's gonna speed up your time to learn about these and that's that potentially makes it easier to attack these systems. Brandon (12:31) My biggest experience with OT and that kind of technology was when I was working at a particle accelerator in college as IT support. And there was a big OT network there, not only for like the machine shop and all this equipment they had that was old and didn't have active security stuff, right? Like you gotta keep those segmented, you gotta keep them on a separate, you know, OT network. Same with the actual accelerators and stuff. They were all cut off from the internet, right? But at the end of the day, you could still get to them from the IT side. You know, you have to, you know, and even that can be exploited. We did as much as we could to keep stuff secure, but it was always a concern, right? These PLCs, these old pieces of equipment. JESSICA (13:11) Right. Right. Yeah. Brandon (13:14) You know, a lot of places don't take that same approach.I think part of one of the stories you wrote was talking about the fact that a lot of these water utilities, a lot of these small institutions that are that are responsible for maintaining this critical stuff. They just do not have the security professionals they need to keep these systems safe. JESSICA (13:32) And that's why they leave them open in some cases, exposed on the internet because they don't have somebody in-house. They have somebody remote who's doing this for them. And so that's how this person is able to hopefully secure, but then it opens up another attack surface if they're exposed to the internet. and that that was another yeah, Brandon (13:51) Yeah, with a D password on there. JESSICA (13:54) Yeah, and with all of these OT systems too. That kind of brings up another point that Chris Inglis brought up. We have this massive technical debt and it's systems that haven't been patched because a lot of it involves some downtime and that's tricky if you're running something like a water facility or some other critical infrastructure. And so patching is put off. Maybe it's not done. Some of these are very old legacy pieces. Sometimes it's end of life. And that's another thing that AI is really good at is finding vulnerabilities that haven't been patched for years and years and years, chaining them together. So that's another thing that puts these systems potentially at risk. Brandon (14:41) Yeah, I mean, you know, I think of an AI when I think about AI perpetuating or perpetrating some of these kinds of attacks, right? They're quicker than a human. They have knowledge bases far in excess of what any one human threat actor can have. And they have instant access to all the information essentially that they need to figure out how to do this, right? And they can iterate so quickly. You know, you know, it's just it yeah, any exposed piece of equipment on the internet is just a sitting duck, especially if it hasn't been updated four or five months or or ten years or whatever. I mean, what, you know what's being done about this. I know DEF CON, the Franklin program, which spun up in 2024, I think the whole focus of that program is helping out small local governments and protecting critical infrastructure. Is that right? JESSICA (15:30) Right. So when they founded it was the broader critical infrastructure. But I spoke with Jeff Braun and he's one of the co-founders of that. He also is one of the pioneers of the voting village at DEF CON. Brandon (15:42) Mm-hmm. JESSICA (15:42) And he said that now and for the foreseeable future, water is going to continue being the top focus because, of all the critical infrastructures, small rural water providers are the most at risk. Brandon (15:57) Really? Even more so than small electrical providers and stuff? Okay. JESSICA (15:59) Yes, he said water is number one. So they like he said, they launched a couple of years ago. They got, I believe 300 people saying, “Yeah, I'm gonna volunteer my time and my expertise to help secure these small rural utilities.” And this year, he said that it's been great. It's been really encouraging to see all of these pilots all over the US with all the DEF CON hackers volunteering at them, but it's the scalability that’s really proven a challenge. And so that is what gave birth to their new announcement. This also was made the first day of DEF CON on Friday. They announced a new program and it's called Water Watch Center. So initially, it's going to fund five managed services providers focusing on security. They're going to help these small utilities, people or the utilities that are serving less than 10,000 people. and they'll put their sensors on these systems, they'll detect and mitigate breaches. They'll be kind of under the umbrella of the National Rural Water Association that's going to act as this clearinghouse for the threat information and get it out to other utilities as needed. And then if the utilities can't fix the issue themselves, then they're gonna bring in the DEF CON hackers and then they'll mitigate the breaches. yeah. Brandon (17:28) Fantastic. Well hopefully that is able to help with a lot of these. My hope is that there's a lot of easy fixes, right? It's just simply no, this PLC needs to not be exposed to the internet or something. But I also worry that there are a lot of those kind of situations, right? I mean, how many water utilities got attacked recently? Was it I think twelve different states? JESSICA (17:47) It was more. There were twelve different states. I mean, there were more than thirty across possibly Minnesota alone, but there's quite a few. So it's an easy target. and it's something that they desperately need help with. And it's really encouraging to see these hackers volunteering their time and they're not getting anything out of it. It's a really cool program. I was really happy to see the expansion. Another thing, too, that is pretty cool, what they're also doing is they're partnering with Vanderbilt University. So they're gonna use research from a DARPA program. It's called the CASEL program. That stands for Cyber Agents for Security Testing and Learning Environments. So they're gonna create digital twins for a couple of these water and wastewater system environments. And then they're gonna deploy red and blue team agents across the digital twins, let them fight it out, see what the learnings are, see what the blue team agents need to do to better protect these systems, and then apply those learnings to the actual facilities so that hopefully we can get better defenses in place using the help of of AI agents before we see actual bad guy red teaming agents come in and start hammering the utilities and trying to attack them. Brandon (19:12) Right, 'cause I think actually thinking back to one of the stories you wrote again, I think you mentioned or someone you quoted mentioned one of those stories at DEF CON and Black Hat that there is more aggressive use on the threat side than the defensive side of AI right now. Like there was more use being made to use it as an attack tool than a defense tool. JESSICA (19:33) Right. And a lot of that's in the way the models are trained, but basically they are a lot better at attacking than defending, especially if it's beyond the scanning for vulnerabilities and misconfigurations. Those we're pretty good at, but what needs a boost is the defensive side. And that's gonna take some work to get those skills and the models trained up on that, if we're going to be actually, as everybody likes to say fight AI with AI. Brandon (20:04) It's one of those sort of, you know, cyberpunk dystopia stories I feel like you hear about is just like, you know, you deploy your AI, they deploy their AI, and all the humans sit back and hope theirs wins. You know, and it's kind of what it's coming down to. Yeah, it's in the process. JESSICA (20:19) Right. And hope they don't wipe us all out. Brandon (20:25) It's kind of terrifying. But speaking of, you know, hackers behaving well, we also have a story out of DEF CON of hackers behaving badly. I wrote about this earlier in the week that there was apparently a Delta Airlines flight out of Vegas to Atlanta and I think it was Monday morning or so, in which a passenger apparently tried to jam the in-flight Wi-Fi and deploy a decoy network. And Delta was pretty quick to be like, “Hey, we got a bunch of hackers on the flight who are leaving Vegas after this big thing.” There’s not a lot of information out there about this. Delta, local officials and the feds have all been pretty tight lipped about it. Delta did confirm it to us when I asked, and said, “Yeah, this is what happened, but no one was at risk, you know, everyone was safe.” But I mean, it's not a good look for the community, right? I mean, it's nice that they have something like Franklin going on, but this is kinda like, Great, thanks guys, you know. JESSICA (21:16) Right. If it was people coming from DEF CON, it's really discouraging to see this happening because a lot of times just “hacker” has a bad connotation. And a lot of researchers have really been trying to change this. I think programs like DEF CON Franklin make a big difference or even people just going to DEF CON. I really like the community feel. I think for the most part, and of course not everybody is good in the world, and that applies to the hacker community as well. But a lot of them are trying to use their skills for good and not evil. And so then when you see something like this on the airplane, it's disheartening. And on social media, I mean the outrage was pretty immediate, people saying, Come on, what are we doing? You're giving all of us a bad name here. Why are we doing this? So Brandon (22:15) Mm-hmm. I mean, it's already I feel like the joke every year is, well, didn't DEF CON get cancelled, right? Like because of all the bad press and everything. And I feel like this is one of those things that you're just like, you know, I remember a couple of years ago there was the huge kerfuffle about the hotels, you know, treating all these attendees like they were criminals right off the bat. And this doesn't help, you know? JESSICA (22:35) Right. Brandon (22:35) But yeah, hopefully I mean apparently the FBI I think spoke to Ars Technica and said that they had not made any arrests. So this hasn't really necessarily progressed toward that. But my hope is that whoever was responsible, you know, gets what's coming to them and we can, as a cybersecurity community, walk away from this and be like, this is one bad actor, not the entire culture. JESSICA (22:59) Right. Brandon (23:00) They fought for years to change that. So I guess before we wrap up, you know, this was a pretty doom and gloom recap of DEF CON and Black Hat, right? JESSICA (23:09) Ha ha ha. Brandon (23:11) All this AI's gonna end the world, our OT and our infrastructure's gonna be destroyed. Anything, you know, less miserable that grabbed your attention while you were there? Any fun stories or interesting things you saw? JESSICA (23:26) I mean, it was really fun. Again, I'm not quite sure if this falls in the not-doom and gloom category, but it was fun for me to watch hackers hacking bomb robots that the police used and bomb squads used to defuse bombs. So that was fun. You're walking around to the different villages and seeing people helping each other out and getting really into all of these different villages and all the different tasks. or you know competing for the best tinfoil hat or beard and mustache. So that was fun. Brandon (24:12) Was anyone doing the beer chill? When I was there in twenty twenty four, there was a group who was trying to chill beer as quickly as possible. JESSICA (24:19) I did not see that. It's very possible. I mean, to be fair, I did not see every single thing. There's so much to see so it's very possible. I missed that though, unfortunately, if that happened this year. So it's fun to see what people are doing. It's really fun and inspiring to see the creativity. And it's fun for me too to hear about some of the startups and how they are using AI and they're using it for different security use cases and hopefully that continues to improve and increase and hopefully that does give defenders an edge. So I think there's always a bit of a silver lining. It's always this cat and mouse race, but hopefully the defenders win out. Brandon (25:11) Yeah, it's a constant like you said. It's an arms race; it's constantly evolving. But like you said, it is encouraging to see, attention being paid to this, effort being put in to help defenders use these tools for good and not evil, even if some people turn around and make a bad name for everybody else on the way out the door. Either way, you know, it's gonna be something that we're probably gonna be discussing again, right? Like I thought this was gonna be a less AI heavy conversation, but it wasn't. JESSICA (25:36) No. Brandon (25:39) You know, it'll be a topic of conversation for years to come and we will be here on the Kettle to talk about it. Thanks for joining me this week and thanks for tuning in, everybody.
WHO, ME? Is it a mistake to return to work on Monday? While you ponder that question, pause a minute to read this installment of "Who, Me?" – The Register's week-opening column that shares your stories of workplace errors and escapes. This week, meet a reader we'll Regomize as "James," who told us that in the early 2000s he worked in the biology department of a famous American university. "We custom-built all our PCs from the cheapest available parts at the time we ordered," James wrote. Which was how he found himself struggling to attach a heatsink to a CPU destined for use in a new PC. "The stupid hook wouldn't go over the plastic tab and so the heatsink didn't want to stay on," he wrote. "Not one to let a computer component get the better of me, I grabbed a flathead screwdriver, stuck it into the little leverage point in the heatsink clamp's arm and leveraged the hell out of it." The result of that decision was audible. "It went PING! and a tiny piece of something went flying away, but the heatsink was now securely mounted," James told The Register. He therefore connected the PC to power, turned it on, and… wondered why its fans blew up a storm, but nothing appeared on screen. "I removed the CPU, removed heatsink, and took a closer look to find the source for the PING. And there it was, or rather wasn't – a very tiny and apparently very important surface-mounted component of some sort was missing right next to where the metal clamps for the heatsink hook in." James was very clearly at fault, but decided the way to fix the problem was to fib about it. "I played dumb and called it into tech support at the company we ordered the heatsink from," he confessed. "They were very nice, accepted the part was dead on arrival, and sent me a replacement right away." "Needless to say I was much more careful with the replacement, which worked great," James told Who, Me? What have you broken with a screwdriver? And how did you get away with it? Click here to share your story with The Register. If you want us to use your story in a future Who, Me? we suggest using a keyboard and mouse – not a screwdriver. ®
Linus Torvalds has decided version 7.2 of the Linux kernel is ready for release, albeit in a “new normal” state that he seems not to entirely love. The kernel boss announced the debut of a new kernel in his weekly development status update, which on August 16 opened with the observation that “this last week of the release was – once again – bigger than I would have wished for.” He attributed that uncomfortable size to what he last week described as “the new normal” for the kernel at a time when developers have increased the volume of contributions using AI coding tools. “If I delayed releases for that reason we'd probably never have a release at all,” Torvalds wrote, before adding that the release includes “a number of fairly late reverts - the drm scheduling reverts stand out, but there's a few other ones in here too.” “It may not be pretty, but it's the correct way to deal with ‘Oh, that code wasn't ready and caused problems,’” he wrote. As ever, the new kernel release includes important and seemingly frivolous inclusions. Among the latter is support for a gaming controller called the “Zenaim Leverless,” which offers a collection of buttons on a black slab. Apparently e-sports pros think it’s just the sort of thing they need to rack up high scores or crush their foes during tournaments. And now they can use it with Linux! Perhaps more relevant to a majority of Reg readers is the inclusion of a tech called “Cache Aware Scheduling” that makes the kernel better at handling the data stored in caches across manycore chips like AMD’s EPYC 5 and Intel’s Xeon 6. Qualcomm senior engineer Vishnu Santhosh wrote a good explainer about the tech. Long story short, it’s about making processors aware of useful data already in a cache, so they can use it instead of doing extra work to access the relevant data. The release also includes work that makes it possible to run Linux on Apple M3 devices, the usual handful of graphics updates, and work to ensure that the kernel will be ready to support next-gen chips from AMD, Intel, and Nvidia. Notable deprecations include ending support for AppleTalk, and for old-school ISA and PCMCIA adapters used on ARCNet networks. This hits hard because The Register believes that PCMCIA stands for People Can’t Memorize Computer Industry Acronyms, and not for the Personal Computer Memory Card International Association. ®
Microsoft has blamed extra work created by AI bug-finders for the delayed release of a major Cumulative Update to Exchange Server Subscription Edition (SE). Redmond’s Exchange team made that admission last Thursday in a post titled “Where is Exchange SE CU1 anyway?” that reveals the software giant is “getting questions from our customers on when they can expect us to release Exchange SE Cumulative Update 1 (CU1).” “After all, in the past we mentioned that it would be released by the end of the first half of calendar year 2026, later updated to ‘second half of 2026’. What is the deal? Where is CU1?” For those of you who came in late, Exchange SE is the subscription version of Microsoft’s email server, and a Cumulative Update (CU) is a new version of the package that includes all recent bug fixes, plus other changes such as new features or removing deprecated code. Microsoft publishes CUs once or twice a year. Some users prefer applying CUs to applying every patch. As Exchange SE is a subscription product, not getting CU in a timely fashion isn’t a great example of why pay-as-you-go software is a great idea. Microsoft explained delays to the arrival of CU1 by referring to the fact that “Over the last few months, various Microsoft execs made statements explaining how Microsoft is leveraging a variety of AI tools to help find vulnerabilities in our products.” The post says the Exchange development team is “working through reported issues – which includes validation that they are real security issues, reproducing, fixing, testing for regressions / issues after fixes are deployed and releasing updates monthly.” Redmond’s missive also points to Microsoft’s pledge to “prioritize security above all else” as a reason for delays. A reminder: Microsoft adopted that stance after flaws in Exchange led to an attack on Exchange by suspected Chinese operatives, earning it a tongue-lashing from the US government. The Exchange team says that while trying to stay on top of bugs, it is also working on CU1. “We are regularly rolling our monthly security payload into our internal CU1 build and plan to release Exchange SE CU1 as soon as we get a reasonable stable point and have a month without pressing security payload.” The Exchange team has adopted that stance because it doesn’t want to publish CU1 and then find it needs to replace it with another that includes new security updates. “That would create double the update work for many organization administrators,” the post explains. “Even internally, trying to ensure that two major releases (Security Update and a CU) get appropriately tested so we can ensure high quality and nothing falls through the cracks would be very challenging as CU1 must be all inclusive of everything that we released since the RTM.” Exchange admins will likely appreciate the fact that Microsoft doesn’t want to burden them with two major updates to implement. They may also wonder when Microsoft will find a month in which there is no “pressing security payload” that takes priority over CU1. Microsoft’s post offers little certainty because it concludes: “In short: Exchange SE CU1 is coming; we do not have a date to give you. But we did not forget about it.” Nor, it seems, did Microsoft plan for how AI-powered bug-finding would impact product development teams. ®
ASIA IN BRIEF Chinese company Zhipu last week launched a new AI model called GLM-5.3 that it claims has bug-finding powers that match those possessed by American models. The company’s announcement includes benchmark data that finds GLM-5.3 beats Fable 5 and GPT-5.6 Sol on the CyberGym benchmark, a test of a model’s ability to solve real-world cybersecurity challenges. “As we scaled post-training, cyber capability developed faster than we expected. GLM-5.3 is state of the art on CyberGym for vulnerability discovery, and its gains are largest further up the exploitation chain,” the company wrote, adding that the model “did not simply become better at identifying isolated flaws: it began to reason across multiple stages of exploitation, forming coherent plans for complete exploitation chains.” The company said it has worked with Chinese companies to test the model on real-world codebases, and found 2,436 vulnerabilities across 269 projects, including 1,097 medium-to-high severity issues. The findings span system kernels, operating systems, browser engines, open-source infrastructure, web applications, and network protocols. “Many had remained unnoticed for years or even decades, with the oldest dating back roughly 40 years,” the announcement states. GLM-5.3 also performed worse than western models on other security and coding benchmarks. Yet the fact that the model is a highly-capable bug finder signals that China is not far behind in terms of being able to poke holes in its rivals software and developed that capability very quickly after the debut of Anthropic’s Mythos. Any advantage the US felt it had as the home of Anthropic has therefore dissipated. Korea signals legal action against Apple, Google app store strangleholds South Korea’s Communications Commission last week found Google and Apple had abused their app store monopolies, and promised stern sanctions will follow. In 2021, South Korea passed world-first legislation requiring app store operators to offer the option to use third-party payment schemes. Apple and Google did so, but charged a 26 percent transaction fee for doing so – meaning they earned almost as much revenue when users chose third-party payment providers as they did from their own schemes. The regulator has previously warned that it will impose the highest possible penalty available under law, which is three percent of revenue earned by non-compliant behaviour. That’s probably back-of-the-sofa money for Apple and Google. India has banned rideshare operators from offering customers the chance to specify the amount they will tip before a driver accepts a gig. Uber India introduced the feature last year, seemingly copying it from an Indian rideshare operator called Namma Yatri. Consumer affairs minister Pralhad Joshi criticized Uber for the practice at the time, as he saw it as a means for users to effectively jump the queue by offering drivers more money – and for rideshare platforms to improve their revenue because if tips are higher, so is the platform’s share of the gratuity. Last week, India’s Ministry of Road Transport & Highways issued a directive (PDF) banning the practice. Henceforth, rideshare apps can only offer users the chance to tip at the end of a journey, and all of the tip must go to the driver. “No feature, prompt, message, add-on, payment option, or user interface element should be displayed before completion of the ride that directly or indirectly encourages, induces, or creates an impression that payment of any additional amount may improve ride confirmation, driver acceptance, driver allocation, waiting time, or quality of service,” the directive states. Indian services giants reveal data breaches Indian tech services giants TCS and HCL last week both admitted to data breaches but say customer data is safe, and only employee data is at risk. TCS published a stock exchange filing that opens “This is to inform you that Company has received threat-intelligence alerts alleging possible exposure of certain employee information.” The filing says TCS investigated the matter “and has not found any credible evidence of a breach of TCS systems or customer environments.” The company says leaked info is “basic employee information” and more than four years old. Note that mention of the stolen data being at least for years old, because TCS’s filing says the attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue to pull off the heist. TCS says it “had strong safeguards in place against such techniques for more than two years,” perhaps suggesting the data heist occurred before the company shored up its defenses. “Based on the current review, these controls remain effective, and the Company continues to monitor the environment closely,” the filing states. HCL also used a stock exchange filing [PDF] to address what it called “claims made by a hacker group of potential exposure of limited data elements relating to HCLTech employees.” The company described the stolen data as “limited and dated to a few years back,” and added its assurance that customer data is safe. HCL’s investigation is ongoing. Lenovo’s enterprise unit finally posts a big profit Lenovo last week announced its quarterly results, including a $777 million profit for its Infrastructure Solutions Group (ISG) – the biz based on the 2014 acquisition of IBM’s x86 server operation that has seldom produced positive financials. Even during the early years of the AI boom, ISG’s profits were modest – just a few million dollars per quarter on turnover of billions. The business unit won a record $8.5 billion of revenue, up 98 percent year-on-year. AI was a big reason for the result, as buyers sought hardware to run inferencing workloads, The company says it has a pipeline for $54 billion of AI server sales, and has become the number two x86 server vendor as measured by revenue. Overall revenue came in at $26.95 billion, up 43 percent year-on-year, and cash won by its PC-led intelligent devices group jumped 27 percent to $17.1 billion and saw its PC market share reach 24.2 percent. Lenovo reckons the strength of its supply chain helped make those outcomes possible. India to build astronaut training facility India’s Space Research Organization (ISRO) last week issued a tender for construction of an astronaut training facility. The tender mentions extensive air conditioning works, plus a swimming pool, suggesting India wants to build a large tank in which the Vyomanauts who will fly its future Gaganyaan missions can train at home, instead of traveling to Russia or elsewhere as has been the case in the past. The tender covers $2.75 million worth of work. ®