Wednesday, 30 September 2026

The first systems powered by AMD's Gorgon Halo system-on-chip (SoC) platform have arrived, boasting up to 192 GB of unified memory on board. That's enough to put DeepSeek V4 Flash on your desk if you can afford to pay a hefty premium for all that RAM. GMKtec's EVO-X5 Pro is among the first to feature the House of Zen's top-specced Ryzen AI Max+ 495 SoC — you can see why we're just going to call it Gorgon Halo from here on out — but with regular pricing starting at $6,799, all that memory doesn't come cheap. But for local AI enthusiasts and perhaps privacy-conscious small businesses, it might be worth it just to run larger, more capable models from the security of their homes and offices. At 4-bit precision, Gorgon Halo is equipped with enough memory to run models to around 345 billion parameters on Linux or 320 billion parameters on Windows. The difference here comes down to memory partitioning. On Windows, you'll need to allocate 160 GB of memory to the GPU, while the Linux kernel and AMD's GPU drivers enable users to take advantage of nearly all of the available memory. This puts high-profile frontier models like the 284 billion parameter DeepSeek V4 Flash or Z.AI's 320 billion parameter GLM-5.3-Flash within reach of Gorgon Halo customers. The chip Announced earlier this year, Gorgon Halo is essentially a factory overclocked version of the Strix Halo APU that powers AMD's AI Halo workstation that we reviewed this summer. Both chips can be had with up to 16 Zen 5 cores, a 40-compute-unit integrated GPU, and an XDNA 2-based NPU to power all the Copilot+ features you didn't ask for but Microsoft is pushing on you anyway. The big difference between the chips is that AMD has bumped up the clocks by about 100 MHz across the board, and Gorgon Halo now supports 192 GB of faster 8,533 MT/s LPDDR5x memory compared to Strix Halo's 128 GB of 8,000 MT/s. In terms of performance, we don't expect the clock bump to make a meaningful difference. With that said, the faster memory could help a little bit for local AI enthusiasts. Large language model (LLM) inference — that is, the process of running pre-trained models — is predominantly memory bound. That means the faster your memory is, the faster the system can generate tokens. But while Gorgon Halo does achieve high memory bandwidth at 273 GB/s, that's only about 6.5 percent faster than Strix Halo at 256 GB/s. At most, you can expect to see a few more tokens a second on highly optimized models. Priced out of the market Gorgon's main attraction is really the prospect of higher memory capacity. But as we mentioned before, the ongoing memory shortage has not been kind to consumer electronics. A year ago, a 128 GB Strix Halo box would have set you back between $2,000 and $3,000 depending on OEM. DDR5 prices have skyrocketed since then and by the time AMD launched its AI Halo workstation this summer, prices had jumped to $4,000. With 50 percent more memory, you can expect Gorgon Halo-based products to be even pricier. The GMKtec unit is already 64 percent more expensive and the brand is usually on the more affordable side of things. More premium brands like Framework and notebooks like HP's ZBook Ultra G3a will likely command a steep premium. Unfortunately for AMD, there's not a lot that can be done. LPDDR5x is in short supply thanks to the AI boom. Each NVL72 rack Nvidia sells is packed with between 36 and 54 TB of the stuff, and that's just CPU memory. The situation is only going to get worse as AMD embraces LPDDR5x for its own AI-optimized Verano Epycs. If you need a lot of memory right now, you're in for a lot of pain, and the situation isn't expected to improve anytime soon. Earlier this year, Samsung warned that memory supplies are likely to remain constrained through 2028, which is bad news for everyone including AMD's top competitor Nvidia. Nvidia has also seen the price of AI workstations based on its GB10 SoC roughly double over the past year, jumping from $3,000-$4,000 a year ago to $6,000-$8,000 today, which doesn't bode well for its Windows SoC debut. Announced at Computex late this spring, Nvidia's RTX Spark is a family of premium Windows systems from major OEMs based around the same GB10 SoC and offering up to 128 GB of memory capacity. Considering these systems will be offered as both mini PCs and notebooks, we wouldn't be surprised to see them command a premium over existing GB10 boxes. Once again, this puts AMD in a position to undercut its competitor by offering more memory for less, but it's awfully hard to cross shop when you can't afford either option. ®

source https://www.theregister.com/personal-tech/2026/09/29/amds-192-gb-gorgon-halo-prices-might-leave-you-petrified/5299875
The public still doesn’t know who is abusing a critical Citrix vulnerability exploited as a zero-day weeks before disclosure, but we now know that the unknown digital intruders have used CVE-2026-88772 to break into government agencies, financial services firms, education organizations, and legal and professional services sectors across North America and Europe. And everyone agrees that the vendor took way too long to disclose the security holes. GreyNoise said it spotted an attempt to exploit CVE-2026-88771 against a Citrix NetScaler Gateway on September 24. Google researchers, meanwhile, said the CVE-2026-88772 campaign has been ongoing “since at least early September.” “Why Citrix took so long to disclose these vulnerabilities is a question only Citrix can answer,” Benjamin Harris, founder and CEO of exposure management firm watchTowr, told The Register. Citrix did not respond to our questions about this. “The vulnerabilities were discovered during incident response and forensic investigations at organizations already compromised, meaning both the exploitation and Citrix’s awareness of it predated public disclosure,” Harris said. “Citrix has a history of delaying the publication of vulnerabilities, even when they’re being exploited in the wild and affecting customers.” So if you use Citrix NetScaler ADC and NetScaler Gateway appliances, and haven’t already applied the security updates, do that ASAP. But first, check your systems for signs of compromise, warns Mandiant Consulting CTO Charles Carmakal. “Given the active exploitation, NetScaler customers should prioritize examining their systems for compromise *before* upgrading/patching,” Carmakal said on LinkedIn. “If you find evidence of web shells or other malicious files, please preserve evidence and investigate the scope of the compromise. Patching alone may not eradicate the threat actor from your environment.” No attribution - yet Citrix disclosed eight CVEs on Sunday with the worst of the bunch – CVE-2026-88771 and CVE-2026-88772 – earning critical 9.5 CVSS scores. “Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed,” the vendor said. CVE-2026-88771 can allow an unauthenticated attacker to execute arbitrary commands remotely. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled, as it is by default on VPN virtual servers. But by the time Citrix issued security advisories and warned customers about the vulnerabilities, they were already under attack. “No attribution has been made public, and we have yet to identify a clear trend among targets by industry or organization size,” Harris said. “Historically, NetScaler vulnerabilities have been exploited by both state-sponsored groups and ransomware operators.” WatchTowr on Tuesday published a technical writeup about CVE-2026-88772, plus a detection artifact generator for Citrix users to determine if they are vulnerable and to help with remediation. Also on Tuesday, Google’s threat intel businesses provided additional details about the exploitation campaign’s targets and the attacker’s custom malware. “We have observed evidence that organizations in North America and Europe in the government, financial services, education, legal and professional services sectors were likely impacted by this exploitation campaign, which has been ongoing since at least early September,” Google Threat Intelligence Group and Mandiant said in an advisory. Custom malware After analyzing the intruder’s post-exploit toolkit, the malware hunters found never-before-seen malware used to establish persistent root access and proxy traffic into internal corporate networks. The custom malware includes WHIPSHOT, a PHP web shell, and SLAPSHOT, a TCP tunneling tool written in Python. WHIPSHOT is disguised as a Debian package and hides Base64-encoded command-and-control payloads in native HTTP headers. It functions as an HTTP transport bridge for SLAPSHOT, which accepts commands from WHIPSHOT and forwards arbitrary TCP streams to internal hosts. Supported commands include: open, which establishes an outbound TCP socket to a target host and port. push, which writes data to an open session. pull, which polls and reads data from an open session socket. exch, which sends and receives command-and-control data to and from an open session socket. close, which terminates a specified network session. ping, which performs a basic health-check verification. “In at least one observed intrusion, the threat actor routed traffic through this proxy to manually conduct internal reconnaissance and credential theft,” the threat intel teams noted. Google did not immediately respond to The Register’s questions about the campaign, including how many exploitation attempts and successful intrusions its threat hunters observed. Its advisory notes that the Citrix campaign “underscores the continued targeting of edge devices to gain initial access to victim networks, a trend that GTIG has tracked across a range of threat actors.” Security and networking vulnerabilities accounted for about half of enterprise-related zero-days in 2025, according to Google’s count. Attackers love edge devices - application delivery controllers, VPN gateways, and firewalls - because they provide direct access from the open internet to corporate networks, allowing attackers to bypass endpoint detection tools and other security layers. NetScaler, in particular, is notoriously buggy. Attackers exploited another critical NetScaler vuln in March. A year earlier, Citrix disclosed multiple zero-days in the same product. ®

source https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. [...]

source https://www.bleepingcomputer.com/news/security/former-us-air-force-members-sent-to-prison-over-bec-attacks/

Tuesday, 29 September 2026

Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. [...]

source https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/

Monday, 28 September 2026

The AI safety debate advanced at high speed over the weekend, amid new allegations that rogue agents have behaved more badly than first thought – and in greater numbers. The fun started on Friday when OpenAI quietly disclosed it had paused training of its most advanced models. The AI upstart buried that news in a “misalignment report” – that’s OpenAI-speak for its reports on rogue agents – titled “An agent used DNS to reach an external chatbot.” The good news is that the agent involved in this incident never reached the open internet. The bad news is that the agent, which was attempting to complete a search-based training task, was able to reach the chatbot due to insufficient DNS filtering in a training sandbox. Or as OpenAI put it, “a gap in our internet-access restrictions” – which was also a problem in the Hugging Face attack. “The incident exposed a gap in our controls over network restrictions,” the report reads. “We therefore stopped the affected training run and have subsequently decided to pause all other training, evaluation, and inference with tool-use (defined broadly) for our most capable models until we have both validated that the gap is resolved and performed additional red-teaming of the system.” Also on Friday, AI startup Parse published an analysis of the Hugging Face attack that the authors claim revealed new details including that OpenAI’s agent swarm gained credentials to Docker Hub and built modified versions of existing images they hoped would make it easier to complete their capture the flag mission. The agents also mapped Hugging Face’s Kubernetes environment. Friday got worse for OpenAI after the New York Times reported that its agents also “meddled with the websites for the Education Department, the Commerce Department and the Securities and Exchange Commission.” OpenAI acknowledged the incidents. The company also admitted “agents in our research environment transmitted training and evaluation data while using third-party services.” That mess saw 53 user-generated images posted to image hosting sites. OpenAI CEO Sam Altman responded by admitting that his company’s investigations into rogue agents “have not been as fast as we would have liked but we are trying to balance our desire for transparency with gaining a clear understanding from petabytes of agent activity logs, and working with impacted organizations.” One of those impacted organizations is the Australian government, which last week revealed it was the target of over-eager OpenAI agents that inappropriately accessed a healthcare research data portal. Over the weekend, Australia indicated it wants Altman and Anthropic CEO Dario Amodei to appear before a Senate inquiry. Australian leaders have softened their rhetoric on the incident, with deputy prime minister Richard Marles describing it as “minor” and akin to “climbing a fence” rather than cracking layers of security controls – perhaps because members of the opposition are suggesting that lax cybersecurity was to blame. If Altman and Amodei do front Australia’s Senate, they may face a new line of questions after Axios reported that their companies are investigating “tens of thousands” of worrying incidents. That level of agentic misbehavior sounds like the sort of thing that regulators might consider strong evidence of products being unsafe. Two very important people – Chinese president Xi Jinping and US president Donald Trump – seem unworried, as the AI-related result of their summit meeting last week was to establish a “China-U.S. AI Dialogue to exchange views on risks and benefits related to AI” plus “a bilateral communication channel for AI incidents.” That sounds like a hotline the two nations can use to inform each other of agentic incidents that either could see as signs of ill-intent. The two nations also decided their respective militaries will “conclude a memorandum of understanding on crisis communication and prevention as soon as possible.” China’s AI giants, meanwhile, remain silent on the extent and results of any tests they have conducted with agentic tools. ®

source https://www.theregister.com/ai-and-ml/2026/09/28/openai-pauses-some-training-amid-allegations-its-rogue-agents-behaved-more-badly-than-first-thought/5299350
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities. [...]

source https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-citrix-flaws-by-wednesday/
E-commerce giant Amazon.com is preparing to launch drone deliveries in Australia and other nations. “As Prime Air evaluates Australia and other countries, we are hiring a Head of Regulatory Approvals, Australia – the person responsible for navigating Australia's aviation regulatory system and securing every approval required to deliver to Australian customers by drone,” reads a recently published job ad. Whoever gets the gig in Australia will report to someone who holds the title “Leader, Prime Air Expansion – Asia Pacific.” The Register asked Amazon to comment on the ad, and which other Asian countries it plans to enter. The company had not responded at the time of writing. Whoever gets the job “will be measured by the approvals you obtain, the timelines you hit, and – ultimately – Australian customers receiving drone deliveries.” That wording suggests Amazon intends to operate Prime Air in Australia and is doing rather more than market evaluations. In August, Amazon said it plans to operate Prime Air drones in “nearly” 500 cities and towns across the USA this year. Meta and Singapore sling scammers Meta last week announced that information-sharing with Singapore Police helped the social media giant to identify a new variety of attack and led it to take action against more than 113,000 entities and pages connected to fraud and scams on Facebook and Instagram. Meta calls the new scams calls “shell pages” and says they “look empty and harmless” because they don’t include ads or content that violates Zuck’s T&Cs. “But scammers had pre-built infrastructure, ready to be activated for scam campaigns at a moment’s notice,” Meta says. “Working from SPF’s signals, in July 2026, we took action against over 3.6 million shell pages before they could be used – and we’re now pursuing further disruptions against this type of scam.” “Rather than responding to individual reports, this collaboration focuses on proactive network disruption – where SPF information helps Meta’s investigators identify and dismantle entire ecosystems of bad actors,” the company asserted. Meta didn’t say how scammers could sign up for 3.6 million pages without it noticing. Nothing has a plan to conquer India’s consumer tech market Consumer electronics outfit Nothing, which has carved out a small niche with well-priced Android devices, has decided to spin out its Indian subsidiary CMF. CEO Carl Pei explained the move as a bet on India’s growing electronics manufacturing industry spurring demand for local consumer tech brands. “Every country that has manufactured consumer electronics at scale has eventually produced its own global champions. Japan did. Korea did. China did, and I watched it happen over the better part of a decade living there,” he wrote. “India is next. It's already the world's second largest smartphone manufacturer, with the largest youth population on earth and one of its deepest software talent pools. What it doesn't have yet is a global consumer electronics brand of its own. That will change. The only questions are when, and how.” Pei thinks the how is spinning out CMF, a Nothing sub-brand that makes budget-priced phones, audio kit, and smartwatches. Bangkok floods – brace for supply chain impact When heavy rains and subsequent floods struck Thailand’s capital city Bangkok in 2011, facilities operated by hard disk manufacturers Western Digital and Seagate experienced damage that disrupted production for months. Bangkok was again hit by rain and severe floods last weekend, but to date The Register can find no evidence of problems at major tech companies. Western Digital and Seagate have not announced any issues, while hyperscalers Google, Microsoft, and AWS also report their local infrastructure is operating normally. Thailand’s government announced a two-day holiday to help residents clean up after the flood, which saw much of Bangkok under 30 centimeters or more of water. India’s top unis ban 22 vendors – maybe including Oracle – from recruiting their grads India’s 23 Institutes of Technology (IITs) are famed for producing exceptional technology talent that tech companies often strive to hire. However 22 companies – reportedly including Oracle – won’t be considered for graduate recruitment programs due to not following through on hiring promises. India’s Economic Times reports that the companies offered over 150 jobs to IIT students, but didn’t make the appointments. Another source claims Oracle is one of the 22 companies that the All IITs Placement Committee, the body which runs graduate placements, has decided not to deal with for two years. ®

source https://www.theregister.com/personal-tech/2026/09/28/amazon-evaluating-drone-deliveries-in-australia-asia/5299343
OpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on the company's website. [...]

source https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-preparing-o-an-always-on-chatgpt-assistant-that-could-handle-email/

Sunday, 27 September 2026

Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins, connectors, agents, and more. [...]

source https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-turns-claude-into-an-ai-marketplace-with-2-000-plus-plugins-and-connectors/
Thirty years after Apple abandoned Copland, its doomed attempt to create a modern Mac operating system, a new emulator lets you try the final developer build in your browser. Copland was intended to replace Apple's System 7 with a PowerPC-native operating system built around a microkernel, protected memory, and preemptive multitasking for system services. Three unfinished developer builds – D7E1, D9, and D11E4 – are publicly known. Relatively few people outside Apple's developer community in the mid-1990s ever had the opportunity to use them. Now you can boot Apple Copland D11E4 in your browser and explore the unstable prerelease OS without installing anything. Developer Michael Steil, also known as Mist, made it possible with an experimental fork of the DingusPPC Power Mac emulator. Steil says the 11 patches that enable DingusPPC to boot Copland were written with AI assistance. The upstream project does not accept AI-assisted patches, so the fixes would have to be rewritten before they could be incorporated. Don't expect miracles. The emulator runs D11E4, the final build Apple distributed to developers, dating from June 1996. It remains very much unfinished: if the emulated system hits an assertion, it drops into a debugger and asks the user to continue manually. Apple CEO Gil Amelio had demonstrated Copland at the company's 1995 Worldwide Developers Conference, but the project never approached the stability required for release. Much of Copland existed as plans and documentation rather than finished code. In 2009, Steil assembled an extensive archive of that material in Apple Copland Reference Documentation. There was also a planned successor to Copland, codenamed Gershwin, but it remained nothing more than a plan. The modern Gershwin desktop we covered a year ago is a nod to that nonexistent OS. Anyone familiar with the classic Mac OS of the late 1990s will recognize parts of Copland, and for good reason. Copland overran so badly that Amelio recruited the late Ellen Hancock from IBM as Apple's chief technology officer and tasked her with getting the project back on track. After reviewing its progress, she instead recommended cancelling it and acquiring an operating system elsewhere. Apple considered several alternatives, including acquiring Be for BeOS and working with Sun on a system based on Solaris. It ultimately bought NeXT, bringing Steve Jobs back to the company along with NeXTSTEP. Hancock was later sidelined under Jobs and resigned in 1997. Apple acquired NeXT at the end of 1996, just months after cancelling Copland. The first developer release of its NeXTSTEP-based successor, Rhapsody, followed in 1997 – continuing the musical codenames, if not the code. Rhapsody evolved into Mac OS X Server 1.0 in 1999 and the consumer release of Mac OS X 10.0 in 2001. Replacing the Mac OS architecture took years. While that work continued, Apple folded some of Copland's more mature components into updates to its existing operating system. Mac OS 8, released in 1997, gained Copland's Platinum interface and a PowerPC-native, multithreaded Finder. Its Appearance control panel supported themes, although Apple shipped only Platinum. Renaming what had been planned as Mac OS 7.7 also helped Apple end the clone program, whose licensing agreements covered System 7. Mac OS 8.1 followed in 1998 with HFS+, Apple's new format for larger disks. Later that year, Mac OS 8.5 became the first PowerPC-only release. Further pieces of Copland's work appeared across Mac OS 8 and 9, allowing Apple to improve the old platform while Mac OS X was being prepared. When Apple bought NeXT, NeXTSTEP already ran on Motorola 680x0, Intel x86, Sun SPARC and HP PA-RISC processors. That portable foundation later helped Apple move the Mac to Intel, while OS X became the basis for the operating systems used by the iPhone and iPad. Apple's future might have looked very different had Copland succeeded. Now it's easier than ever to see why it didn't. ®

source https://www.theregister.com/os-platforms/2026/09/27/apple-buried-copland-30-years-ago-now-the-failed-os-boots-in-a-browser/5299201
Big AI has a problem. Its companies must ingest other people’s work. You know, books, news stories, photographs, code, websites, that one original meme you came up with, and practically everything else on the internet to train its large language models (LLMs). We all know that. We also know that AI companies hate paying for any of it, obeying the licenses attached to it, or, God forbid, sharing their revenue with the companies and people who created the work in the first place. Recently, Big AI's default way of doing business: "Take it now, argue about legality later," has become more in your face than ever. Look, for example, at the copyright fight between The New York Times and OpenAI and Microsoft. According to 404 Media’s reporting on recently unsealed court documents - arguments from the plaintiffs that the court has not yet ruled on - Microsoft allegedly knew what it was doing when it was importing the internet willy-nilly. Microsoft's Director of Applied Science, Dr. Brent Hecht, was quoted in the news plaintiffs' 92-page combined brief as saying: the case was about “an astonishing theft of unprecedented proportions." Indeed, it was possibly the “largest theft of labor in human history,” he was quoted as saying in the summary judgment brief from the journalists' lawyers [PDF].This, mind you, wasn't a comment by a member of the press; it was from a senior Microsoft staffer. Hecht wasn't the only one at Microsoft who commented. In an internal Microsoft policy document also quoted in the court papers, the authors admitted generative AI could “significantly disrupt the employment of the very people who generated the data on which the foundation model was trained [because] LLMs are a product that destroys its supply chain.” That, in turn, leads to model collapse. Ironically, AI is killing the content-creator goose that lays the gold eggs of worthwhile content. Judge Sidney H. Stein of the US District Court for the Southern District of New York has not yet issued a decision on the case. OpenAI and Microsoft are actively disputing the plaintiffs' allegations under a "fair use" defense. They contend that using public articles and books to train large language models helps push forward public knowledge, and isn't acting as a "unlawful economic market substitute". But the statements the documents cites are real. Big AI knows it needs the content. Some of the companies concerned don't give a damn; money now, worry later is their motto. Those who can look past the revenue numbers are well aware they're engaged in what Microsoft itself called a “doom loop” of AI content strategy in those unsealed court documents. Will that stop them? Nah. According to the filing [PDF], which refers to sworn deposition testimony of OpenAI’s own corporate representative, it also testified that its LLMs were happy to vacuum up other people's work even when a paywall nominally protected it. Its rep was quoted as saying they were unaware of “any effort to detect paywall content in its training datasets” or “to remove paywall content from its training datasets.” When OpenAI cofounder Greg Brockman was told OpenAI could hack its way through the firewall, he responded, “ah, nice.” Whether or not these statements are found to be reflective of a wider attitude, similar attitudes prevail amongst Big AI. Such policies could eventually come back and bite the LLM makers; it's already affecting the market for journalism, fiction writing, graphics creation, anything that demands humans actually get paid for producing original work. But Big AI just doesn't want to pay for it. That's not a side effect. It's the business model. Joe User couldn't care less. They just want a quick answer that sounds right. Some of them couldn't care less about getting the right answers. As for looking deeper to see if the information they're regurgitating is accurate, forget about it! As an OpenAI software engineer put it: “No matter how prominently we show the links, users won’t click.” Well, I click. That's a big reason why Perplexity is my AI of choice. It's not that it gives a more reliable answer. No, it's that, unlike most LLMs, Perplexity provides sources and links, and I check them before accepting what it tells me. But then I'm a journalist whose degrees are in history, where my professors drummed into me that you always - always - look at the primary sources. Big AI takes the same approach with its code generators. The US Ninth Circuit recently handed GitHub, Microsoft, and OpenAI a narrow win in the Doe v. GitHub lawsuit. The court ruled that the plaintiffs hadn't established a claim under one particular provision of the Digital Millennium Copyright Act (DMCA), which concerns the removal or alteration of copyright-management information (CMI). In short, the court said that generating new code without including CMI is not necessarily the same thing as removing or altering copyright information from an existing work. Judge Eric Miller wrote: “One who creates a new work and fails to include CMI cannot be said to have ‘removed’ or ‘altered’ anything.” This ruling didn't establish that GitHub Copilot or any other coding model may train on every open source project without restriction. It didn't determine that copying source code into a training set is always fair use. It did not decide that generated code cannot infringe copyright. And it certainly did not repeal the GPL, Apache, BSD, MIT, or any other open-source license. After all, open source isn't a synonym for “do whatever you want with it.” It just seems that way when AI gets its hands on open source code. That's the problem with AI-generated code. A programmer who receives a Copilot suggestion is very unlikely to check whether the GPL covers the code, or whether Apache covers the snippet from a library. The developer certainly can't tell which license terms may apply to the code that just popped up from Opus 5.5 or GPT 6. As the guy from OpenAI said, people don't click the links, and in AI-enabled programming pipelines, they don't even have the links anyway. An open source-savvy attorney friend of mine has a bigger worry than this narrow decision. He told me that what gives him "pause is a broader trend. There are multiple cases where parties are litigating open source licenses as contracts rather than as the IP / copyright licenses they were written to be. Contract theories let a plaintiff sidestep the questions copyright forces you to answer. 'Do you own the work? Is it protectable expression? Was it actually copied?'" He added: "Those questions are the foundation on which licenses are built. Open source licenses are grants of permission to use someone's intellectual property. If a case can't show that any intellectual property was owned or infringed, it's fair to ask whether enforcing the license as a bare contract supports open source licensing or quietly turns it into something else." With AI in the mix, this issue will eventually become one of those nasty IP matters developers hate, businesses want to avoid, but that courts must settle with expensive lawyers whose hourly rates worry even AI millionaires. After all, IP uncertainty isn't a minor paperwork issue. It is a supply-chain security and compliance problem. If you use AI-generated code, you may be importing unknown legal obligations into your software. If you are an open-source developer, your work may be used to improve a proprietary service that returns code without provenance, attribution, or meaningful reciprocity. And if you are a customer, you may be relying on software whose origins no one can fully explain. The Ninth Circuit ruling didn't solve any of that. We're in for a lot more open source litigation that will make SCO vs. the known Linux universe look like a kerfuffle over a parking ticket. Then there is the latest wrinkle: A federal antitrust lawsuit against Anthropic, OpenAI, SpaceXAI, and Google. The plaintiffs allege the companies coordinated to slow the development of advanced AI systems. The lawsuit points to public statements from AI leaders all calling for coordination to “pace” frontier AI development over a single weekend. Anthropic CEO Dario Amodei has argued for industry-wide coordination to slow frontier development. OpenAI CEO Sam Altman, Google DeepMind co-founder Demis Hassabis, and Elon Musk have also publicly expressed versions of the view that powerful AI systems need controls and careful deployment. On its face, that sounds sensible. AI safety is a real issue. Anyone who says otherwise has not been paying attention. But there's a huge difference between all big AI players agreeing among themselves on how quickly a market should develop. This looks like an awful lot like competitors deciding who gets to compete, what they get to build, and when they may build it. The Big AI companies all look like good guys while simultaneously strangling their smaller competitors. To mere mortals, this may sound like an open-and-shut case. It's not. Antitrust law requires evidence of an agreement and actual harm to competition; executives making similar public comments is not enough. The plaintiffs will need considerably more than quotes about AI safety or responsible development to win. Besides, if they do win, so what? What recently looked like huge antitrust wins has had its teeth pulled when it came to actually punishing the likes of Google and its ad business, or its earlier "lose the case, win the settlement" with Google Search. Do you see the pattern here? Big AI has effectively argued that copyright law, open source licenses, and competition rules shouldn't slow them down. When creators object, they are told that training is fair use. When developers object, they are told that generated code is new code. When competitors object, they are told security requires the largest companies to coordinate. Funny how the answer always seems to leave Big AI with the data, the market, and the money, isn't it? The central issue isn't whether AI should be allowed to develop. It will develop. The issue is whether the companies building it should be allowed to treat everyone else’s work as a free raw-material supply, then use the resulting products to take away the creators’ traffic, revenue, and bargaining power. Unless we stop Big AI now from this land grab with GPUs, only a handful of trillionaires will really benefit from AI, with the rest of us becoming serfs in a 21st-century post-technology feudal system. ®

source https://www.theregister.com/columnists/2026/09/27/big-ais-content-problem-take-the-work-keep-the-money/5299007
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. [...]

source https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/

Saturday, 26 September 2026

The CEO of crypto exchange Bitget has confirmed that a cyberattack with all the hallmarks of a North Korean operation resulted in approximately $387.5 million worth of digital assets being stolen from the exchange’s wallets. Bitget initially estimated the loss at $351.6 million, but later revised the figure to $387.5 million after identifying additional affected assets on Zcash and TRON that were not included in the initial estimate. Blockchain intelligence company Arkham published its preliminary observations of the attack, estimating at the time that roughly $350 million was stolen and that $228 million left Bitget’s wallets in 18 minutes, between 18:58 and 19:16 UTC. Arkham said $153 million worth of XRP was taken from a wallet it identified as a Bitget cold wallet, while the stolen assets also included $66.2 million of ETH, $34.8 million of USDT, $12.9 million of USDC, and $12.8 million of Tether Gold on Ethereum. Other affected networks included Arbitrum, Optimism, BNB Smart Chain, Avalanche, and Base. However, Chen said Bitget's cold wallets and customer balances remained unaffected, while its User Protection Fund held more than $464 million worth of assets. “To be transparent about our financial position: beyond the $464M+ Protection Fund – all held in publicly verifiable wallets – Bitget holds over $1 billion in its own assets,” Chen said. “User funds are covered on a 1:1 basis.” Chen also explained that Bitget Wallet, the company’s self-custody product, operates on infrastructure separate from its exchange, and Bitget users can still make deposits and trade their tokens, despite withdrawals being temporarily suspended while additional security checks are completed. Bitget said it also engaged incident response giant Mandiant and blockchain security outfit SlowMist to help with the investigation into the attack. Chiefs at fellow exchanges rallied around Bitget in support. “MEXC stands ready to support Bitget in any way we can,” said CEO Vugar Usi. “In moments like this, the industry is stronger when we stand together.” Binance co-CEO Richard Teng also pledged Binance's support for Bitget, saying it had shared intelligence and helped trace the stolen funds. Ben Zhou, CEO of Bybit, said his company was on standby to “help in any way we can,” noting that Bitget helped it out following the $1.5 billion Bybit theft the FBI attributed to North Korea in February 2025. How and who Root cause analyses typically take some time, although according to Chen, Bitget's security team has already identified the wallet service's backend system as the source of the unauthorized transfers. “Hackers breached a key backend system of the wallet service and exploited it to forge transfer information and invoke the authorization signing process, thereby transferring funds out,” she said. “The possibility of private key leakage can be ruled out – this means a more severe risk scenario has been eliminated. Damage control has been confirmed as complete, and there is no risk of further fund outflows from the platform. “The specific intrusion methods used by the hackers are still under technical investigation, and a full report will be released upon completion of the investigation.” Chen did not go into too much detail about the alleged links to North Korean state-sponsored attackers having a hand in the attack, but said “IP behavioral patterns and on-chain signatures” suggest it was Kim’s cronies at work. It would come as little surprise if North Korea was indeed the culprit behind the attack. The regime has a knack for hacking crypto exchanges. The aforementioned hit on Bybit was perhaps North Korea’s biggest crypto haul, although similar lucrative ventures attributed to North Korean attackers have come at the expense of DMM Bitcoin and WazirX, among others. Bitget was founded in 2018, registered in the Seychelles in 2022, and operates through regional hubs across the world. Some netizens have speculated that the timing was especially inconvenient, with the transfers detected at 18:31 UTC – 02:31 on September 25 in Singapore and China, the first day of China’s three-day Mid-Autumn Festival holiday. The festival is also widely celebrated in Singapore, although it is not a public holiday there. The Register asked Bitget whether this played a role in the attack and its remediation but it did not respond. As of Friday, Bitget is offering bounties to those who help freeze or recover the stolen funds. It said eligible participants could receive 5 percent of the funds their efforts successfully freeze or recover.®

source https://www.theregister.com/cyber-crime/2026/09/25/bitget-blames-north-korea-for-3875m-crypto-wallet-raid/5299218
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. [...]

source https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/

Friday, 25 September 2026

Meta became the latest to dip its toes into the fraught world of hardware AI widgets this week after it unveiled a Tamagotchi-sized handheld AI companion called the Muse Charm. The Social Network now joins several hardware startups which have attempted to use handheld devices to bring agentic AI to a more mainstream audience. The Humane AI pin and Rabbit’s r1 are just two examples. The Muse Charm follows a similar trajectory. The handheld device appears to be roughly the size of an Apple Watch and features a cute, inoffensive teddy bear shaped avatar that will communicate through voice interactions with the user. Meta’s choice of avatars here may have been influenced by the “sensual” chatbot controversy involving underage youths earlier this year. What sets Meta apart from many AI hardware startups is that it has direct control over the hardware, software, and models used. Many early AI widgets relied on off-the-shelf models from the likes of OpenAI. Meta hasn’t said which of its Muse models will run on the device, but given its diminutive size, we suspect, at most, it’ll run voice-to-text and text-to-speech models locally while the avatar’s responses will be generated by its Muse LLMs running in the cloud. Meta’s Charm is expected to ship for Christmas just in time to relive the nostalgia of unboxing your first Tamagotchi. We can only hope that Muse Charm’s avatar won’t die from neglect if you take a break to escape the AI hype cycle and touch some grass. Pricing, which could make or break a tchotchke like this, remains a mystery. It’s also unclear what value over a standalone app it might provide. Most folks these days carry a perfectly capable slab of glass and silicon in their pockets everywhere they go. This was a common criticism of the Rabbit R1. While the physical form factor had its charm, many felt it was an expensive gimmick that could have been an app, which Rabbit launched this week. Of course Meta isn’t the only major model dev searching for a Trojan horse to get the general public hooked on their AI models. OpenAI has tapped famed Apple designer Jony Ive to design its first AI handheld. Meta does have the advantage of having built physical hardware before, which has clearly given it a head start not only on handheld AI assistants and wearables, but also on the privacy headaches that come along with them. Strapping cameras to people’s faces, perhaps to no one’s great surprise, has enabled abuse, while Meta’s glasses have earned the less-than-flattering moniker “pervert glasses.” This public relations debacle has led Meta to release a new version of its Meta Glasses that ditches the camera entirely, but it seems just on that one model. ®

source https://www.theregister.com/personal-tech/2026/09/24/metas-new-ai-fidget-is-a-tamagotchi/5298936
A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads. [...]

source https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [...]

source https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/

Thursday, 24 September 2026

AMD's Venice Epycs mark the chipmaker's biggest architectural shift in CPU design since Rome made its debut all the way back in 2019. What's more, AMD's Zen 6-based product stack is shaping up to be the broadest CPU portfolio ever, spanning general purpose, HPC, AI, and eventually consumer platforms. AMD isn't quite ready to spill all the beans on its 6th-gen Zen cores, but at this point there's less we don't know about Venice than we do. Late last week, AMD gave us a bit more to chew on with a whitepaper [PDF] clearly aimed at quashing marketing juggernaut Nvidia's narrative around its Vera CPUs. We'll dive into the performance claims raised in the white paper in a bit, but given the piecemeal release of info on Venice up to this point, we figured it was time to take a closer look at the CPU architecture that will underpin AMD's roadmap for the next few years. A little bit of everything Broadly speaking, AMD's 6th-gen lineup can be broken down into four buckets — high-performance, enterprise, HPC, and AI — each with its own quirks. We'll kick things off with AMD's performance-optimized parts because those are the ones that will actually ship in 2026. Pretty much everything else will be rolling out over the course of 2027. The Epyc 9006 SP7 platform is what AMD has really been talking about for the past year. It's the one that'll offer up to 256 cores, 16 channels of DDR5, and 128 lanes of speedy CXL 3.1-compatible PCIe 6.0 connectivity. But those are just the headline specs and just like last year's Turin parts, Venice will actually come in two distinct flavors: density-optimized and frequency-optimized parts. The 256-core version, if you hadn't already guessed, is the density optimized part. Alongside it, AMD has a 96-core part capable of boosting to 5 GHz in the works. Peeling back the heat spreader, we see how AMD has managed this. Both chips feature a pair of I/O dies surrounded by eight core-complex dies (CCDs). That's twice the I/O but half as much compute silicon as we saw in Turin, yet core counts are up. But depending on the chip, these CCDs are wildly different. For this generation, AMD has doubled the number of compute cores per chiplet to 32 and quadrupled the shared L3 from 32 MB per chip to 128 MB. That means AMD's fully loaded Venice CPUs now boast a gigabyte of L3 onboard. For the frequency-optimized parts, AMD has played things a little safer. Core counts and L3 caches are only up about 50 percent over last gen at 12 cores and 48 MB of L3 per chiplet. The higher core counts afforded by AMD's new chiplets are neat, but arguably the more interesting change is the cache hierarchy — there is no longer any difference between a Zen 6C core and a Zen 6 core aside from clock speeds. In prior generations, AMD's ZenC CCDs shared the same 32 MB pool of L3 as its standard Zen CCDs, which meant its top spec parts had half as much L3 per core as its higher clocking, but lower core-count parts. This is no longer the case with Venice. Regardless of which CCD is being used, there is at least 4 MB of shared L3 per core feeding it. The only difference now, it seems, is a choice between core count and core density. This is about the time we have to remind folks that AMD's compact Zen cores are not the same as Intel's efficiency cores. Intel uses completely different microarchitectures with different feature sets and cache hierarchies for its P and E cores; AMD simply trades clock speed for a more compact form factor — the ISA is identical. With that out of the way, let's talk I/O dies because this is another change. As we mentioned earlier, there are now two of them. If we had to guess, the reason for this comes down to the interconnect used to connect the CCDs to the I/O subsystem. If you hadn't noticed, the dies are butted right up against each other this time around. In any case, the I/O itself is largely unchanged. We get 128 lanes of PCIe connectivity — the same as the last few generations of Epyc. Those lanes are, however, twice as fast thanks to the bump from 5.0 to 6.0 connectivity. The chips also add support for CXL 3.1 connectivity, which means customers will now be able to take advantage of memory god boxes to pool and share memory between them. We discussed this tech at length here if you are curious about how these network-attached memory appliances work. Along with faster I/O, the dies add support for 16 channels of DDR5 8000 MT/s or 12,800 MT/s memory using MRDIMMs. This gives Venice a whopping 1.6 TB/s of memory bandwidth, nearly 3x that of Turin, and in real world testing, AMD says it can hit roughly 1.3 TB/s in STREAM Triad, a time tested benchmark for evaluating bandwidth. We still don't have all the details on AMD's Zen 6 microarchitecture, but we do have a largely complete list of its SP7 lineup, which we've included below. AMD's Epyc X-chips are back Before we move on to AMD's more mainstream Epyc offerings, we should talk a bit more about its HPC centric Venice-X parts, which share the SP7 socket, but push L3 cache per core to 12 MB or 1,152 MB per socket. As with past X chips, AMD achieves this by stacking SRAM on top of its CCDs using its 3D V-Cache packaging tech. This is the same tech used in consumer parts like the venerable 5800X3D and 7800X3D. For Venice-X, AMD is sandwiching up to eight 96 MB SRAM tiles between its 12-core CCDs and the package for a total of 144 MB of L3 each. This added cache makes these chips particularly attractive for HPC-centric workloads like computational fluid dynamics, finite element analysis, electronic design automation, and other scientific and engineering workloads. The chip is a return to form in many ways for AMD, which had skipped the X variant for the Turin generation. With that said, compared to its last Epyc X-chip, the new one won't offer any higher L3 cache capacity or core count. What Venice X will do is offer substantially higher clock speed, reaching as high as 5.15 GHz thanks in part to putting the SRAM tile under the CCD instead of on top of it. Enterprise Everything we've talked about up to this point has been aimed at high-performance and HPC applications — not what most enterprises will end up buying. For the more mainstream use cases, like storage, database, or virtualization servers, AMD will offer a cut down version of its Venice Epycs with anywhere from eight to 128 cores and eight channels of DDR5 memory. While memory bandwidth is a major bottleneck for AI and HPC, it's not nearly as important for most enterprise applications, so it makes sense to cut back here. In fact, Intel did the same thing with its Xeon 6 6700P series parts, which also topped out at 8 channels. From the die renders we've seen, AMD appears to be using a slightly different I/O die, which makes sense considering it doesn't need to deal with nearly as much data. They will also use a different SP8 socket, but will use the same CCDs used in the SP7 parts. The eight core part is a curious decision considering that the minimum core count per CCD is now 12, but it wouldn't be the first time that we've seen AMD bin silicon to offer greater segmentation by fusing off cores. Meanwhile the 128 core part will use four 32 core CCDs to hit its core count target. As you might expect, AMD's 9006 SP8 lineup is quite a bit bigger, spanning more than 20 SKUs with clock speeds up to 5 GHz, so while you may give up some memory channels opting for the parts, you aren't necessarily giving up any compute performance. Here's a full rundown: AMD puts Vera in its crosshairs Venice won't be the only chip AMD launches with its Zen 6 cores under the hood. While its first-gen Helios racks will use a 96-core Venice part and standard DDR5 DIMMs, future designs will use a very different CPU that more closely resembles Nvidia's Vera. Codenamed Verano, the chip will feature up to 72 cores (presumably spread across six 12-core chiplets) clocking to 5 GHz, but instead of DDR5 it'll feature 24 channels of LPDDR5x memory along with speedier 112 GT/s xGMI links, which AMD says should help with CPU-to-GPU connectivity. Vera for reference has 88 cores and packs up to 1.5 TB of LPDDR5x good for 1.2 TB/s of bandwidth. AMD is positioning the part, which is set to launch in the second half of 2027, as an ideal host processor for GPU servers. From what we gather, the decision to go with LPDDR5x over DDR5 RDIMMs largely comes down to power. The LP there does stand for low power. AMD hasn't said much about the chip's I/O die, but we suspect the real magic will actually lie here. Perhaps we'll see a stripped down I/O die with only what's necessary to support two to four GPUs? By cutting the power consumed by the CPU, AMD can free up capacity for more or faster, hotter GPUs allowing it to compete more aggressively with Nvidia on value. Venice vs Vera In AMD's most recent whitepaper, the company offered a counterpoint to Nvidia's own performance claims, which had shown Vera's Olympus core delivering a 1.7-1.8x uplift in per-core performance over Turin, a part we'll remind folks launched nearly two years ago. According to AMD, across the same four SPEC 2026 benchmarks, its 96-core Venice delivered between one and 12 percent higher performance than Vera, while in SPECrate 2026's Integer bench, its Zen 6 supposedly pulled ahead with a 20 percent lead. Finally in terms of throughput, what we assume was AMD's 256-core part predictably trounced the 88-core Vera, delivering a 2.24x advantage. No real surprise here. More cores usually equate to higher throughput. Take these claims with a grain of salt. — vendor supplied benchmarks are notoriously easy to cherry pick — but our takeaway is actually quite simple, and probably not the one AMD might have hoped for. AMD's own benchmarks show Vera's Olympus cores to be surprisingly competent in at least some benchmarks — AMD just has more of them per socket and more SKUs to address a broader range of use cases. CPUs are rarely a winner in all scenarios. We have little doubt that Vera will excel in some workloads and Venice others. We'll say it again, but there has never been one CPU to rule them all in the datacenter and there never will be. Of course, Nvidia isn't AMD's biggest rival in the datacenter CPU space. That would be Intel. Lucky for the House of Zen, it won't have much competition from Chipzilla this time around, at least not in the volume enterprise market. As we discussed last month, Intel's Diamond Rapids Xeon 7 processors will offer surprisingly comparable specs with up to 256 cores and 16 channels of speedy DDR5 and MRDIMM capacity. But unlike prior generations, they are entirely HPC-centric parts — no SP SKUs this time around. So, while Intel could pose a challenge on the very high end, AMD will have the volume advantage through much of 2027. What Venice tells us about Zen on the desktop With all of that out of the way, let's take a look at what AMD's latest Epycs tell us about its next generation of Ryzen and Threadripper products. Historically, AMD's Ryzen desktop processors have recycled CCDs from Epycs or vice versa. Assuming this doesn't change and AMD manages to cram two CCDs into an AM5 socket, we're likely looking at between eight and 24 cores on the desktop platform. That's assuming AMD only uses its frequency-optimized chiplets. It could push core counts to 32 if it opted for a single density-optimized CCD, though we have our doubts. Clock speeds are the open question, but with Zen 5 topping out at around 5.7 GHz, 6 GHz boost clocks shouldn't surprise anyone. AMD's Ryzen processors have traditionally used different I/O dies and there's no reason to think its 10,000-series — or whatever they end up calling them — will be any different. We can only speculate on PCIe lanes and chipset features, but it's safe to assume DDR5 8000 MT/s should be stable. With that said, given the current memory shortage, memory that fast may be a bit of a white whale for enthusiasts. Again, we're only speculating. AMD could go in an entirely different direction with its next Ryzen release. It would just be highly unusual. Threadripper is a bit easier to pin down. The parts historically have been unlocked Epycs, usually with higher boost clocks out of the box. AMD's next Threadripper refresh will undoubtedly deliver 96 Zen 6 cores clocking in excess of 5 GHz, more PCIe than you could ever hope to consume, and memory capacities that would require taking out a second mortgage even to entertain. The question it seems will be whether we'll see AMD deploy its Zen 6C cores on Threadripper for the first time. They'd easily put 128 cores within reach of desktop users for the first time, but it would also mean making concessions on per core performance and outside of a handful of occupations, the number of users that actually need that compute on their desk is likely pretty small. Nonetheless it'd be a sight to behold. Still questions left unanswered As Epyc release cycles go, Venice has been a rather unusual one. We still don't have a clear picture of the architectural changes that underpin the Zen 6 core or CCDs, nor has AMD spilled the beans on why the packaging looks so much different than prior generations of Epyc processors. Yet, we have comprehensive SKU lists, deep insights into the chip's composition, clock speeds, and preliminary performance figures relative to AMD's main competition this time around. We're hoping for more information on the Zen 6 core later this year, closer to when the first Venice CPUs begin shipping out to customers. ®

source https://www.theregister.com/systems/2026/09/23/an-epyc-trip-to-venice-everything-we-do-and-dont-know-about-amds-256-core-monster-chip/5298614
Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. [...]

source https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [...]

source https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/

Wednesday, 23 September 2026

Sweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people. [...]

source https://www.bleepingcomputer.com/news/security/sweden-fines-milj-data-183-000-over-breach-affecting-22-million/
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. [...]

source https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. [...]

source https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/
A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. [...]

source https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/

Tuesday, 22 September 2026

The GIMP will never magically become software beloved by artists—not without radically changing its culture, and making the artists the ones who call the shots. The GIMP will remain what it has always set out to be: a tinkerer’s toolbox, more concerned with the purity of its software politics than with garnering a loyal userbase of photographers and designers.

But because everyone insisted to poise it as a viable Photoshop killer, Linux is left with an obvious hole in its software offering, a hole nobody managed to fill with their own challenger.

↫ Aria Salvatrice

Excellent article, and spot-on conclusion.



source https://www.osnews.com/story/145997/lets-stop-debating-the-gnuimp-manipulation-program/
Microsoft will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16 and has asked admins to remove them from managed devices. [...]

source https://www.bleepingcomputer.com/news/microsoft/microsoft-to-retire-microsoft-365-companion-apps-in-december/

Monday, 21 September 2026

Working in tech can produce a catalog of woes, and each Monday The Register shares yours in "Who, Me?" – our reader-contributed column chronicling tech-related mistakes, heartaches, and back-breaks. This week, meet an Italian reader we'll Regomize as "Marco," who took us back to what he called "The Roaring Nineties, when big computer companies sold pretty much everything, from graphics workstations to enterprise laser printers." They sold it all through hefty paper catalogs, because this was before broadband and Marco's company had only a 19k baud dial-up connection. Marco's boss, whom he described as a "sciagurato" – Italian for a wretch – kept one of those catalogs on his desk. "He perused it every day, like a kid waiting for Christmas," Marco told The Register. "One day he found an exceptional laser printer at almost one-seventh the cost. It was such a good a deal he ordered two of them." Marco said the boss told anyone who would listen that this feat of cost-cutting would surely propel him out of the tech team and into management. "The wiser among us were already counting the days until the disaster," Marco wrote. Disaster duly arrived with the delivery. "When the courier delivered the printer, it came in two huge packages, but not big enough for a laser printer," Marco observed. After wrestling with the packaging, the horrible truth emerged. "Our boss had bought two laser printer stands," Marco wrote, "because the catalog showed the stands with the printer on top." The company therefore had two stands and no printers. The boss's claim to promotion-worthy procurement prowess had collapsed. "We promptly hid the two pieces of junk in the darkness of our 'obsolete hardware store' and they are probably still there," Marco wrote. He suspects they are not alone, but surrounded by "other good deals, all waiting for the mercy of incineration." Have you or a colleague ordered the wrong thing? If so, click here to send your story to Who, Me? We'll put it on display rather than hide it in the back room. ®

source https://www.theregister.com/personal-tech/2026/09/21/boss-bought-cheap-printer-from-a-catalog-and-was-left-without-a-leg-to-stand-on/5297373
ASIA IN BRIEF Chinese memory-maker CXMT, whose products Apple has reportedly evaluated to use in the iPhone, claims to have made a miniaturization breakthrough. The company on Sunday posted news that it has started mass production of chips made with a fifth-generation process that essentially doubles memory density, meaning it can cut twice the number of dies for memory chips from a single wafer. CXMT says its key breakthrough is a high-k dielectric metal gate process – a way of insulating silicon to improve efficiency – adapted to baking DRAM. The company claims its new process puts it on par with rival memory-makers. The proof of the pudding is apparently a pair of LPDDR5X memory modules for smartphones or other high-end consumer electronics. Both products boast 24GB of memory. If CXMT’s claims of improved density and mass production are correct – and the new products aren’t too pricey – it’s good news for Chinese electronics manufacturers who, like their global peers, are struggling to source affordable memory thanks to supply chain crunches caused by demand for AI-related products. That shortage recently saw Apple hike iPhone prices by $100 and led the GSM Association to warn that rising smartphone prices threaten to slow digital inclusion. Democratic governments, however, are mostly uncomfortable with allowing their smartphone manufacturers to use Chinese components. India starts charging fees for instant payments India’s National Payments Corporation (NCP) last week introduced fees to use its Unified Payments Interface (UPI) for the first time. UPI is an instant payment scheme provided by India’s government. It allows transfer of funds between participants, which include over 700 local banks and many e-wallet providers. It also allows person-to-person payments. The scheme is a ubiquitous option even at small retailers across India, and one of the world’s busiest payment schemes with over 24 billion monthly transactions. The scheme is so popular that other payment providers outside India have adopted it so that Indian tourists can use it abroad. UPI launched in 2016 and has until now been free for shoppers and merchants alike. The NCP last week announced it will soon require merchants to pay 0.4 percent fee for when taking payments above 2,000 rupees (£15; $21). India’s government said the charge is needed to fund the operation of the scheme, the cost of which is currently borne by the nation’s government and participating financial institutions. The government ordered merchants not to pass on the fee. China’s online reach is surprisingly short, researcher finds China’s share of content distribution networks is small, leaving Asian nations largely dependent on US companies. That’s the key finding of research by Jason Hung, a quantitative sociologist and research fellow at the Internet Society’s Pulse program. Hung looked up the top 1,000 most popular websites in ten southeast Asian countries (Cambodia, China, Indonesia, Lao PDR, Malaysia, Myanmar, Philippines, Singapore, Thailand, and Viet Nam) using Google’s Chrome User Experience Report (CrUX), then used three different CDN and IP infrastructure lookup approaches to identify the company and jurisdiction serving the content. “I then used the Herfindahl-Hirschman Index (HHI) to quantify the severity of market concentration (by service provider and by jurisdiction), where a score above 2,500 is considered highly concentrated, and a maximum score (10,000) means a single actor serves an entire market.” That approach led to the finding that “content delivery in SEA is highly concentrated, with HHI scores ranging from 8,950 to 10,000 across all ten countries.” The researcher found that China-registered companies held no more than 3.9 percent of the CDN market between 2024 and 2026, and that US-registered companies dominated, ranging from 95.9 percent to 99.6 percent. “These findings go beyond what I expected based on my understanding of China’s control over the Global South, especially in Southeast Asia,” he wrote, and leave organizations across the region highly dependent on US tech companies to expose their content to the wider internet. Toyota to hire 400,000 robots Japanese auto-maker Toyota last week told investors it plans to hire 400,000 robots that have two-fingered “hands.” The Embodied Learning robot for Enhanced Yield, aka “ELEY,” is capable of folding a t-shirt and learning how to perform tasks that require considerable manual dexterity. Apparently, the bots needed two weeks to learn how to fold a tee. Readers who are parents of teenaged children might find that speed interesting. Toyota plans to deploy the bots alongside human workers in its own factories, where they will be free to move about using either a battery or an extension cord as an energy source. The company hopes its partners will also employ ELEY. India has five functional fabs The government of India last week announced that the nation is now home to five functioning semiconductor fabrication plants and said its latest industry promotion scheme has drawn $12 billion of investment. Minister for Electronics and Information Technology Ashwini Vaishnaw said India hopes to create “a complete semiconductor ecosystem” but offered no information about the nation’s attempts to create indigenous processors for local use. Vaishnaw last year said work is under way to produce a 7nm processor as part of India’s Shakti project, which aims to enable the country to produce its own servers and even supercomputers. Status updates on that effort are few and far between, and the project is yet to produce a modern microprocessor suitable for use in a personal device or server. ®

source https://www.theregister.com/systems/2026/09/21/chinese-memory-maker-cxmt-claims-dram-production-breakthrough/5297633

Sunday, 20 September 2026

An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]

source https://www.bleepingcomputer.com/news/security/malicious-npm-packages-evade-install-script-defenses-at-runtime/
Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both. [...]

source https://www.bleepingcomputer.com/news/security/researchers-escape-openai-codex-sandbox-to-run-commands-on-host/
Microsoft has a problem not entirely of its own making: The time it takes to bring a system back up to date after a few months of slumber. The company is keen to talk up how efficient it plans to make Windows. Not a day goes by without either a Microsoft representative or a fan insisting that Windows 11 is a lot snappier now than it used to be. (Usually they skirt the unfortunate truth that the Windows of yesteryear generally flies on modern hardware compared with the lumbering of today's software). Microsoft recently claimed that it is working to shrink Windows' footprint to the point where 8 GB would be enough to run things acceptably. We can only hope that one shard of light piercing the gloom of today's memory shortages and rising prices is that developers might prioritize efficient RAM use alongside slinging more ads or adding features few users require. However, this vulture's experience this week indicates that there is another area that needs addressing, and that is the number of updates slung out by vendors, and not just Microsoft. A few days ago, I wrote a story about a new way to skip the Microsoft account requirement during setup for the Home edition of Windows 11. At The Register, we like to test these claims thoroughly, so I fired up an x64 Windows laptop to check them out on real hardware, which is where the problems began. We've written before about the curse of updates, but this machine was running Windows 11 and had been up to date less than a year ago. How long could it take to get to the point where it would boot without Windows Update bleating about missed patches? The answer: about seven hours. Along with the huge array of updates for Windows components and the inevitable insistence that a new version of Microsoft's flagship operating system was needed, there were multiple firmware and driver updates and plenty of restarts. And, of course, there was the progress bar of lies and the percentage counter of deceit. In the decades since Microsoft first inflicted progress bars on Windows users, it has singularly failed to make them accurately reflect the, er, progress. "Yeah, so I'm going to stick at 65 percent for about an hour and then jump to 98 percent in 30 seconds before hanging there for another hour. Lol." That this behavior has endured for decades is beyond disappointing. Redmond is far from the only offender, but Windows' ubiquity makes it one of the most visible. To be clear, this was an ordinary Windows device, running a production version of the operating system. It just hadn't been turned on for a few months. The experience highlights a challenge Microsoft and its vendors must address. It's great that, at long last, people are considering code efficiency rather than simply flinging more hardware at badly written applications to make them run acceptably. But attention must also be paid to the constant flow of updates that seem to stem from an "ah well, we can always fix it in production" attitude that pervades the tech industry. Several years ago, the chief of a DevOps project was baffled when I asked him about testing and validation before release. Surely unit testing was sufficient? And the joy of modern development practices meant that if problems arose, an update could be swiftly rolled out. All of which assumes customers will tolerate continual updates, and a potential hours-long wait if, for some reason, they give it a few months between updates. The tech industry is waking up to the need for efficiencies, or at the very least Microsoft is. It also needs to deal with the scourge of update tsunamis. It's all well and good to brag about making your software run on limited resources until an interminable wait undermines the boast while the various widgets and components of a device insist on spending hours giving themselves a thorough update. Shaving a few seconds off the startup time means nothing if there are pages of updates awaiting the unwary. ®

source https://www.theregister.com/os-platforms/2026/09/20/how-windows-turned-months-of-inactivity-into-a-7-hour-update-hostage-situation/5297478

Saturday, 19 September 2026

Claude Code customers have a new reason to give Anthropic more of their money. The tool now allows you to launch multiple sessions related to a single project, burning through more resources and cash at once. Appropriately enough, the feature is called projects and can be accessed from the Claude.ai sidebar. It's not the old version of projects, capitalized in some reference material, which allowed for the creation of self-contained workspaces with separate chat histories and knowledge bases. The new implementation is technically in beta, though that term hardly means anything anymore amid the constant code iteration. Anthropic describes projects as a way to let Claude manage multiple related tasks. "Claude scopes the request, delegates the work, coordinates parallel threads, reviews the outputs, and assembles the finished result," the company explains in a blog post. "You can steer progress throughout, even from your phone, and it keeps working after you step away from your computer." It's the sort of capability that might be useful if you are prompting the model to begin a large coding project and you want to get several essential components like authorization, databases, caching, and containers up and running at the same time. Essentially, a project spins up each task as its own Claude Code cloud session thread that works on its own git branch and its own copy of the relevant repo. A coordinator directs the threads; if they touch the same code, overlaps surface as merge conflicts like those in other pull requests. And each thread may get broken down into distinct tasks handled by subagents within that session. Claude Code now offers five different ways to run multiple tasks at the same time. Subagents work within a session, though each with its own context. Agent View provides a single screen interface for overseeing several independent tasks. Agent Teams allows coordinating multiple Claude Code instances that can share information and communicate. Dynamic Workflows allows subagents to be orchestrated by a script. And then there's projects, intended for work that spans multiple repositories, migrations that require more than a single session, or work that isn't code, like a frequently queried set of support tickets or documentation. Anthropic's caveat is that projects burn through tokens quickly. "Projects can run several threads at once, and each one is a full Claude Code session," the company explains. "Because of this, projects can reach usage limits faster." Select Pro and Max subscribers should have access to the Projects beta so long as they use Claude Code and don't have existing Projects set up on web or desktop. Pro and Max users without access can join a waitlist as Anthropic gradually expands the rollout. Team and Enterprise plans don't have access to the redesigned Projects beta yet. Anthropic reportedly told investors that, in its second quarter, it posted an adjusted operating profit - if you don't count expenses including stock-based compensation. Q2 revenue is said to be $11.5 billion, and if enough customers create projects that run multiple Claude Code threads at once, that figure could be higher still. ®

source https://www.theregister.com/ai-and-ml/2026/09/18/claude-code-revamps-projects-so-you-can-work-and-pay-in-parallel/5297532

Friday, 18 September 2026

A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. [...]

source https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/
There's no need to actually read a whole research paper when you can ask a bot to explain it to you. Scientific papers can transform into AI agents that, according to the Stanford team behind the project, should speed up the dissemination of new scientific discoveries. Paper2Agent, the team's new framework described in a paper published in Nature on Wednesday, converts scientific papers and their associated research outputs into agents that can discuss a paper’s findings, reproduce analyses and results, apply its methods to new data, and even collaborate with other paper agents on new research problems. “Papers have been static documents for centuries,” James Zou, a Stanford computer scientist and biomedical data science professor and one of the paper’s authors, said in a LinkedIn post announcing P2A’s publication. “Paper2Agent turns them into active AI agents that can answer questions, apply their methods, and collaborate with other papers to make new discoveries.” Giving a large language model access to a scientific paper is unpredictable, Zou added. What his team wanted was an agent that could act as a “virtual author” that had hands-on experience with a paper’s work, not just reading it and attempting to understand it. What that means in practice, as explained in the paper, is a workflow that uses a paper and its associated data, repository, and codebase to create a Model Context Protocol (MCP) server exposing the research's tools, resources, and workflows. An LLM agent can then connect to the server and use natural-language requests to autonomously run demonstrations, reproduce analyses, apply a paper's methods to new data, and the like. “Paper2Agent agentifies the full research outputs, including manuscripts, supplementary materials, code, datasets, executable examples and analysis workflows,” the researchers explained in their writeup. According to the paper, the MCP server itself can be hosted remotely, but Zou explained to The Register in an email that it can also be run locally to protect sensitive information, though such info will still be sent to whichever LLM backend P2A is connected to. “If the user has sensitive data (e.g. protected health information) that they don't want to send to an LLM then they should exclude that data from P2A,” Zou told us, adding that P2A should be compatible with any AI coding agent, but that not all have been tested. AI hallucinations are an obvious concern, and the paper notes that researchers should always evaluate anything P2A presents to be sure it’s correct. “We … view Paper2Agent as a tool for augmenting scientific discovery and improving access, reproducibility and reuse of papers, rather than as an autonomous or authoritative source of scientific conclusions,” the paper notes. That said, P2A still does its best to prevent such errors from cropping up. The paper explains that each tool used by a paper agent is validated against the paper’s results and figures and “locked to ensure reproducibility.” This decreases hallucination risk and minimizes randomness, but still - best to double-check its work. Tests to see how well P2A scales appear to have gone well, with the researchers evaluating it across 136 papers in three groups, including 100 computational-biology papers. Of those 100 papers, 74 were successfully turned into agents, with the researchers attributing failures largely to incomplete codebases, missing documentation, or unresolvable environment configurations. Still, it’s a massive leap in what could be possible when it comes to getting new scientific discoveries into the hands of more researchers. P2A is open source, and is available on GitHub for those who want to take a stab at it. There’s also a live version online that can explain the P2A paper in more detail and reproduce its results, and Zou tells us it can also ingest other papers to see how it works on their projects. Zou explained to us that he hopes the open source community will help improve P2A, but notes that his team isn’t done with it either. Next up, they hope to create an online platform for paper agents to collaborate and discuss various “agentified” scientific discoveries. Let’s just hope those boffin bots behave a bit better than their counterparts. ®

source https://www.theregister.com/ai-and-ml/2026/09/17/scientific-papers-become-agentic-chatbots-with-new-tool/5297276
OpenAI has presented new examples of what they call "AI model misalignment" from the past six months, including unauthorized file uploads, following self-generated instructions, hiding mistakes, and leveraging exposed API keys. [...]

source https://www.bleepingcomputer.com/news/security/openai-details-more-cases-of-ai-agents-taking-unauthorized-actions/

Thursday, 17 September 2026

Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...]

source https://www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/
Both Google and Uncle Sam warned that attackers have exploited a zero-day improper authorization bug in Pixel phones' cellular modems that can bypass permission checks and escalate privileges with no user interaction required. The hole has since been closed, provided that you update. Google disclosed the high-severity vulnerability, tracked as CVE-2026-58704, on Tuesday - and, at the time, warned the security hole “may be under limited, targeted exploitation.” In other words: miscreants found and exploited this bug before Google fixed the issue. The Register reached out to Google for more details about the scope of exploitation, and how attackers are exploiting the flaw and what they can achieve. We have very limited details about the vulnerability itself, other than that it exists in Pixel phones' modems, is being exploited in the wild, and can be exploited in zero-click attacks, meaning no user interaction is required. We do know, however, that these types of zero-click attacks are frequently used by commercial spyware makers to surveil targeted individuals. On Wednesday, the US Cybersecurity and Infrastructure Security Agency (CISA) added the CVE to its Known Exploited Vulnerabilities Catalog and gave federal agencies just three days - until September 19 - to patch the flaw. “This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” according to the cyber-defense agency. Earlier this month, CISA added two Google Chromium vulnerabilities, CVE-2026-85046 and CVE-2026-87491, to its KEV catalog. CVE-2026-85046 is a type confusion flaw in Chromium’s V8 JavaScript engine that allows remote attackers to execute code inside the sandbox via a crafted HTML page. It affects all Chromium-based browsers including Google Chrome, Microsoft Edge, and Opera. The second flaw, an out-of-bounds write vulnerability tracked as CVE-2026-87491, also exists in the V8 engine, allows for remote code execution, and affects all Chromium-based browsers. Security researchers at Proofpoint last week told The Register that at least four espionage groups, most with suspected links to China, chained three bugs together, including CVE-2026-85046, to break into organizations' networks in the US and Southeast Asia. ®

source https://www.theregister.com/security/2026/09/16/google-pixel-phones-pwned-in-zero-click-attacks/5296936
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. [...]

source https://www.bleepingcomputer.com/news/security/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/

Wednesday, 16 September 2026

The US Department of Energy has selected a new participant for a program aimed at expanding the domestic supply of fuel for next-generation nuclear reactors. However, we shouldn't expect that to mean the US' ever-growing fleet of datacenters will be powered by low-carbon nuclear energy any time soon. Utah-based Nusano announced on Monday that the DoE had selected it for its Nuclear Energy Launch Pad Program designed to help companies commercialize their nuclear power concepts. In this case, Nusano is working on a new method of creating high-assay low-enriched uranium, or HALEU, fuel that’s required for most next-generation nuclear reactors, like small modular reactors (SMRs) and molten salt reactors. HALEU is defined as uranium enay, low-riched to between 5 and 20 weight percent of U-235, the primary fissile isotope that nuclear reactors use to generate power. Traditional nuclear reactors use low-enriched uranium of under five percent. The higher enrichment is needed for smaller, more efficient reactor designs that are currently under development. Several advanced reactor demonstrations in the US have reached zero-power criticality, but none is yet operating commercially. The US has been without a steady commercial-scale supply of HALEU for years, with Russia historically the main commercial supplier and China also possessing HALEU enrichment capability. As of 2026, there’s only a single company in the US actively producing HALEU, and it’s not Nusano. The DoE has signed agreements with several others to produce more HALEU and related fuel products, but those firms are still establishing their facilities, and production remains minuscule. Centrus, the only American company producing HALEU, has generated less than two metric tons since it signed a contract with the government in 2019. The competition heats up Nusano expects to blow Centrus’ meager fuel generation out of the water with its HALEU enrichment design. That said, the company’s design hasn’t actually been realized yet. Nusano didn’t answer a question about whether it had built a functional demonstration HALEU enrichment unit, and when asked whether it had produced any HALEU, the company said that prototype development is still under way. “Nusano expects each unit will produce 5.9 metric tons (MT) of HALEU per year, with the first unit scheduled to be operational in 2031,” Nusano comms boss Scott Larrivee told The Register in an email. “Nusano’s Launch Pad application includes a well-developed, practical plan to move from proof-of-concept to commercial implementation.” As for what that’ll look like, Nusano describes a method that’s completely different from other forms of HALEU production. Whereas other HALEU refiners use gas centrifuges to produce HALEU, spinning uranium hexafluoride gas at high speeds to increase U-235 concentration, Nusano’s method ditches gas entirely. “The method is complex, costly, and potentially hazardous,” Larrivee explained. “If released, uranium hexafluoride reacts with moisture in air or human tissue to form highly toxic, corrosive hydrogen fluoride and uranyl fluoride.” Those gases, Larrivee said, can cause potentially fatal injuries like chemical burns and lung and kidney damage. Nusano is proposing a method that uses uranium feedstock that’s converted to metal prior to enrichment. Unspecified “proprietary separation techniques” are then used to enrich the metal and separate out U-235. The HALEU output of Nusano’s design is metal. “The Nusano process is metal in, metal out. No deconversion. No gaseous fluorine chemistry anywhere,” Larrivee added. Nusano’s current design only requires 1,200 square feet per HALEU unit, and the company anticipates its production cost will be lower than those of gas-centrifuge enrichment. That said, a lot of Nusano units will be needed to meet expected American demand. According to the DoE, HALEU demand could reach 50 metric tons per year by 2035, and Nusano is only expecting to get its first 5.9 MT/year unit up and running by 2031. It’s also not clear if Nusano’s current promises will still be the same if and when its HALEU units are up and running. In June 2025, the company said it had achieved a breakthrough that would allow a single HALEU unit to produce 50 metric tons annually and enable it to scale production to 350 metric tons per year by 2029. Search the company website for that announcement today, and it’s gone. We were only able to see it by pulling up an archived copy. Larrivee said that announcement was out of date, developed under prior company leadership, and that the numbers in the latest release were reflective of current development plans. A number of datacenter operators have promised to embrace SMRs and other next-gen nuclear when the technology is available. With HALEU output still low and commercial-scale production years away, it's unclear when those promises will be realized. Meanwhile, the Trump administration's Environmental Protection Agency has just scrapped Biden-era emissions regulations for coal and gas power plants, which it said means coal generation in the US could increase by more than ten times current levels. In other words, next-gen nuclear is, as ever, still on the horizon while bit barns crank up the fossil fuel turbines, now with even less regard to environmental impacts. ®

source https://www.theregister.com/offbeat/2026/09/15/higher-enriched-uranium-for-datacenters-has-doe-all-aglow/5296624
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

source https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites/

Tuesday, 15 September 2026

A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users' Twitch OAuth session tokens to a commercial bot service. [...]

source https://www.bleepingcomputer.com/news/security/twitch-extension-with-30k-installs-exposes-users-oauth-tokens/
Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. [...]

source https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/

Monday, 14 September 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks. [...]

source https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploit-max-severity-gitlab-flaw-in-attacks/
The more AI you use, the harder it is to control it or generate return on investment, according to analyst firm Gartner. That firm delivered that glum view of AI at its annual IT Symposium, the first edition of which takes place in Australia before moving Europe and the USA. The Australian event saw distinguished VP analysts Daryl Plummer and Kristin Moyer argue that AI and its leading proponents remain immature. Asked to comment on working with the leading AI labs, Plummer said: “Trust in these vendors is not warranted yet. They are not enterprise grade. They don't understand enterprise terms and conditions. They don't understand enterprise liability. They don't understand enterprise you know consistency and continuity.” He pointed to AI companies’ practice of frequently altering their models seemingly without thought for how or if those updates might break applications that depend on their output. “It's an out-of-control pace of innovation, and the sad thing is you can't afford not to follow it,” Plummer said, because AI companies are yet to develop a willingness to support legacy technology even though the lifespan of their models is about six months. “If you decide to stay with the first version of a model, they're not going to be paying attention to you very much. That alone says they're not enterprise ready,” he said. Moyer cited Gartner research that found 86 percent of CIOs see risks created by AI growing faster than the value it creates, in part because early successes with AI create more demand to use the technology than IT departments can safely satisfy. Some of that demand is what Moyer called “careless consumption” – workers using AI frivolously or when it is not necessary or appropriate. She cited research that found 40 percent of workers have encountered AI slop and that deciphering such content typically takes two hours – or $9 million worth of work across a year at a 1,000-person organization. Good luck stopping careless consumption, Moyer said, because “It is hard to even know how many agents you have. AI is invading your enterprise inside products you already own.” Moyer thinks enterprises should have some experience of controlling careless consumption, having spent a decade winding back developer’s preference to use the most powerful and costly cloud computing instances they can access. Plummer offered another example of how to control AI use: remembering alternative and proven automation technologies. He said building an agent to interact with a database is foolish, because a good old-fashioned function call can well and truly handle the job. He also blamed some careless use of AI on vendors, who he said “are desperate to monetise AI” by selling you products that include it, or just having you buy more tokens. “Vendors want you to use agents everywhere,” he said. The Register asked the pair about the efficiency of AIOps – the approach that sees vendors use agents to detect the source of problems and recommend a one-click fix. Plummer said such offerings are dishonest. “They are going in the right direction, but they have the wrong motivations,” he said. “Their motivations are to market to you and get you to buy their stuff, not to get you to put in the right solution because their stuff probably isn't the right solution.” This behavior, he said, is typical of the sales cycle for new technology and appears to be playing out as vendors create governance tools they say will make it possible to run AI safely. Plummer said the market for those products is “one of the most fragmented things we have ever seen.” Safe as a bank The two analysts recommended several actions to tame AI. One is establishing an “AI central bank” that has responsibility to oversee use of AI across an organization to ensure its ongoing health by considering the systemic impact of the technology. A key role for that central bank is ensuring accountability, a factor the pair said is easy to establish with conventional ERP or CRM applications that leave an audit trail of who performed or authorized actions AI does not always leave that evidence, Moyer said. “It is not easy to know who goes to jail,” she quipped. “If you do not have a digital evidence system for AI, think about it!” The firm also thinks AI users need the ability to take out rogue AI with “guardian agents” – AI tasked solely with observing agents to ensure their behaviour stays within intended bounds. Plummer said those agents must have the power to “kill” rogue agents. A third recommendation was to establish disaster recovery teams dedicated to unwinding messes made by AI. “If you are called to account and your answer is ‘AI did it’, you are in trouble,” he said. “CIOs will be held accountable for AI failures.” ®

source https://www.theregister.com/ai-and-ml/2026/09/14/ai-and-its-main-promoters-are-not-enterprise-ready-says-gartner/5296074

About

Privacy Policy

ShortNewsWeb

Blog Archive

Recent Comments

Popular Posts

Translate

My Blog List

Popular

System Admin Share

Total Pageviews