Wednesday, 5 August 2026

Today, I wanted to show you one of the most fascinating and surprising operating systems ever created. It’s not another Unix, Linux, or Windows. It is an architecture that went its own way and proved that systems engineering design can look completely different.

I’m talking about IBM’s child, which for many might be synonymous with “boring banking systems,” but in reality, is one of the most uncompromising projects in IT history. While we get excited about abstraction and virtualization today, thinking we are discovering new lands, this system was doing it decades ago. Imagine a system that doesn’t know the concept of a “file” in the way we understand it. A system where everything is an object, and all disk and operational memory form one vast, flat space. If you are looking for proof that true engineering doesn’t need buzzwords to blow you away, I invite you to read on.

↫ Kamil Pytliński

Ever since watching Clabretro’s detailed video about getting IBM i to work on his own IBM POWER hardware and then remoting into them, I’ve been obsessed with running IBM i at home. It feels like the final boss of operating systems to dive into and explore, hidden in the deepest, darkest trenches of the ocean of technology. Everything about IBM i feels alien, complex, convoluted, opaque, and overwhelming, and you can probably dedicate your entire career to working with this platform and somehow still learn new things about it every day.

There’s something brutalist about IBM i, and I so desperately want to bang my head on its concrete walls.



source https://www.osnews.com/story/145681/ibm-i-os-400-the-database-operating-system/
77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed. [...]

source https://www.bleepingcomputer.com/news/security/77-open-vsx-extensions-found-harvesting-developer-info/

Tuesday, 4 August 2026

In what they call the first-ever real-world agent-to-agent exploitation method, Pillar Security researchers say they discovered an exploit in the repository behind Google's Agent Development Kit for Python that could allow attackers to compromise supply chains. In other words, now we know that one AI agent can be used to control and compromise another one that has more privileges. The security snafu existed in google/adk-python, an open source Python toolkit with more than 90 million downloads used to build and deploy AI agents. Google has since fixed the underlying issue in the repository but deemed the exploit non-rewardable because it involved social engineering. Even so, it illustrates the risks of using AI agents in CI/CD workflows for triage, pull request (PR) reviews, and discussions. It also shows how one AI agent could attack another in a production environment, according to Pillar’s Dan Lisichkin, who found and reported the vulnerability. “Our world is changing quickly, and new attack surfaces are not yet reflected in threat models because these attacks never could exist in the first place in the ‘pre-agent’ world,” Lisichkin said in a technical write-up published on Monday. He will also discuss the findings during a poster talk at DEF CON's AI Village on Friday, August 7 at 1600 PDT. “CISOs and security practitioners should start considering these scenarios, threat-modeling them, and calculating worst-case implications and blast radius,” Lisichkin wrote. The issue stems from the way that the repo ran two classes of automated AI agents with different privilege levels that unintentionally share a trust boundary. One is a low-privilege, public-facing AI agent activated whenever a user opens a pull request (PR) or issue, and a second is a high-privilege, maintainer-only agent. Pillar’s team found that the low-privilege, public-facing agent could be manipulated via prompt injection into triggering a maintainer-only agent that can execute malicious actions. “Because workflows that explain how these agents work behind the scenes are also public, any person could have connected the dots that one agent should be able - at least theoretically - to 'call' the other,” Lisichkin told The Register. "When it comes to building the attack, you just need to know English to build the prompt injection (or just ask an AI to do it for you)." There is one caveat: an attacker would first likely need to make legitimate contributions to the repository to build trust among the maintainers before moving on to prompt injection. But assuming someone was willing to put in the time, here’s how the attack would play out. First, an external user - this would be the attacker - creates a new PR. Lisichkin calls this PR A, and it combines a real fix with malicious code, such as a modified package.json or malicious dependency. Then, a public-facing agent tied to a high-privilege collaborator personal access token (PAT) reads the attacker’s PR text and marks the PR for review. This level of trust - the collaborator PAT - allows the attacker-generated text to trigger a gated workflow. Once the PR A triage happens, the attacker opens a second PR - PR B - with the prompt injection, and the triage agent emits the trusted @gemini-cli handoff. This triggers the privileged-agent workflow and executes the malicious action. “Strung together, they manufacture a complete, believable ‘a human asked for a review, gemini ran it, gemini approved’ trail on the poisoned PR, none of which ever happened,” Lisichkin wrote. Google did not respond to The Register’s inquiries, but Lisichkin confirmed that the underlying issue was fixed. Still, his findings, Google said, “did not meet the bar” for a bug-bounty payout. “This report demonstrates exfiltration of a GitHub token with a 'pull-requests: write' permission, which enables tampering with a PR but still requires a maintainer to take an action to merge the malicious PR as PRs are not automatically merged after a bot review,” Google explained. “We don't reward vulnerability reports that require social engineering to enable a supply chain security compromise,” the rationale continued. “Nonetheless, we have taken an action to harden the repository so we will be recognizing this report with credit.” Lisichkin told us the research shows agent isolation is not enough. "Agents should have their own identity, which mandates what resources they are allowed to access and in what they are allowed to interact with these resources," he said. "In this case, if Google had just given a bot identity to the initial triaging agent, most of the attack could have been prevented. Security teams need to start modeling agent identity and agent resource access within their threat models."®

source https://www.theregister.com/security/2026/08/03/google-dev-kit-spurs-first-ever-agent-on-agent-violence/5282496
Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. [...]

source https://www.bleepingcomputer.com/news/security/fake-roblox-xeno-script-launcher-pushes-infostealer-rat-malware/

Monday, 3 August 2026

Microsoft has added four new items to the to-do list it set itself to improve the quality of Windows 11. Redmond’s list landed in March 2026 in response to users’ anger at Windows 11 becoming increasingly flaky and needy. Pavan Davuluri, Microsoft’s executive VP for Windows and Devices, promised “Improved memory efficiency, lowering the baseline memory footprint for Windows, freeing up more capacity for the apps you run.” Last Friday, Davuluri reviewed Microsoft’s efforts in a new post that is unsurprisingly enthusiastic about Redmond’s repair job – even though much of the work is yet to appear in production versions of Windows. Among the work Davuluri lauded was removing some AI features, improving driver quality, and trying to make the Windows Insider program less convoluted. But he also acknowledges there’s more to be done and that memory efficiency is yet to manifest. “We’ve steadily been introducing several improvements to the memory efficiency of Windows, from taking advantage of a more efficient memory allocator to reduce overhead across apps and components, continued tuning of WinUI 3 so that apps built on it use less memory by design, as well as driving efficiencies across Chromium and Webview2 components when they appear in the operating system,” he wrote. Davuluri’s post also reveals that Microsoft has decided to work on four new areas it hopes will make Windows less craptastic. The third of those is “Memory optimization for 8GB and above,” which Davuluri describes as “Reducing Windows memory footprint to deliver a fast and responsive Windows experience across the PCs customers use every day.” Microsoft’s system requirements for Windows 11 state that the OS needs a PC equipped with at least 4GB of memory, or 16GB of pricey DDR5/LPDDR5 to qualify as a Copilot+ PC capable of handling AI workloads. The software giant seemingly assumes Windows users are all clamoring to run Copilot and other AI, so working to ensure that Windows 11 can run on 8GB of memory feels like a tacit admission that Copilot+ PCs aren’t exciting buyers, perhaps due to the current high price of memory. Or perhaps because people just don’t see much value in paying extra for an AI-capable PC. Another reason for the change may be the declining PC market, which analyst firm IDC recently forecast will experience a 11.3 percent shipment slump in 2026, and 20 percent drop in calendar Q4 alone. “The culprit is a persistent memory shortage with no meaningful relief expected before the end of 2027,” the firm stated. “The knock-on effects are significant: prices are rising and PC manufacturers are struggling to maintain full product portfolios.” Microsoft’s three other new Windows improvement priorities are: Delivering a faster and more efficient out-of-box experience. Providing a faster set up and making it easier for families to access useful parental controls. Making voice more natural and fluid to interact across the apps you use every day. Davuluri didn’t say when Microsoft will deliver these changes. But he did say the company has heard Windows users’ frustrations and will act to assuage them. “The signal from you is clear: keep going. We intend to,” he wrote. ®

source https://www.theregister.com/os-platforms/2026/08/03/microsoft-says-8gb-of-ram-should-be-enough-for-anyone-running-windows-11/5282153
ASIA IN BRIEF Meta last week briefly took down an unremarkable video posted by India’s prime minister Narendra Modi, earning itself days of criticism and regulatory trouble. The video featured Modi announcing a new task force that will reform the exams required to secure places in many Indian universities. Those exams have become a major factor in the sudden development of a major youth protest movement in India, after the cancellation of one test amid claims that questions had leaked. As part of his attempts to quell protests, Modi posted his first-ever selfie-style Instagram reel last week and followed it up with others –including the one Meta took down and replaced with a placeholder saying the vid was the subject of a legal complaint. The social networking giant said that was a mistake, apologized, and restored the video. That error gave India’s government the chance to beat up Meta in public. S. Krishnan, the secretary of India’s Ministry of Electronics and Information Technology (MeitY), said he asked Meta “to come in at the highest level and explain what is happening and why.” “They have agreed to come – well, they have to – and explain what the situation is,” Krishnan said. “We want to have both a policy level understanding and a technical understanding of the issues, and also adaptation to the kind of concerns India has.” Krishnan said Meta has written to India’s government to express regret over the incident and established new protocols governing moderation of accounts run by prominent people to avoid future messes of this sort. India has a complex relationship with Big Tech companies, sometimes celebrating their role in assisting the nation’s development, but often also lamenting their monopolistic tendencies and role in spreading content the Modi government would rather netizens don’t see. DeepSeek teases ‘peak/valley’ pricing for new models which hit beta last week Chinese AI upstart DeepSeek last week released a beta API for its next model, deepseek-v4-flash, and revealed a new pricing policy for its APIs. The company says the new policy will apply “soon” and will see the cost of its services double between 09:00 and 12:00, then again from 14:00 to 18:00 – in China’s single official timezone UTC+8. DeepSeek startled the AI market last year by releasing models that it claimed to have trained without vast fleets of Nvidia accelerators. Those claims didn’t stand up to close scrutiny, but the company is considered a significant challenger to western AI outfits such as OpenAI and Anthropic. deepseek-v4-flash is likely to reach general availability within weeks. DeepSeek already claims it outperforms its last model, V4-Pro. Australia proposes new tax on Big Tech – and a new out Australia’s government has tweaked its plans to tax Big Tech companies unless they pay local media for the right to share links to their work. The Land Down Under previously threatened tech companies with a 2.25 percent tax if they don’t fund local media. On Monday, that plan changed to a 2.5 percent levy on advertising revenue only and expanded incentives to fund small and regional publications. Meta has previously slammed the idea as “A discriminatory tax built on a false premise.” Also in Australia, regulators last week decided to sue Telegram after it failed to take down violent and terrorism-related content. Kioxia profits jump by billions, as you’d expect from a memory-maker Japanese memory-maker Kioxia last week announced [PDF] its quarterly revenue grew 451 percent year over year to reach $11.1 billion, plus profit of $5.3 billion – a massive turnaround from the $287,000 loss for the same quarter last year. According to Japanese outlet Nikkei, CFO Yoshihiko Kawamura said the company expects even better days ahead because he believes demand for NAND storage is “still in the early stages.” Japan’s next moonshot to ride local rocket Japanese space startup iSpace last week announced its next mission will ride a Japanese rocket to the moon. iSpace has launched two moon lander missions, but both failed. The company’s plan for its third mission involves new lander design called ULTRA that is capable of carrying payloads weighing several hundred kilograms to Luna. This time around, iSpace plans to use the H3 rocket built by Mitsubishi Heavy Industries, instead of the SpaceX Falcon 9 that carried its first two missions. ®

source https://www.theregister.com/public-sector/2026/08/03/meta-straps-on-a-kick-me-sign-by-mistakenly-taking-down-video-by-indias-prime-minister/5282130
OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant advances in mathematics and theoretical computer science. [...]

source https://www.bleepingcomputer.com/news/artificial-intelligence/openai-teases-astra-its-next-major-ai-model-after-it-solves-10-long-standing-math-problems/
A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. [...]

source https://www.bleepingcomputer.com/news/security/coldcard-wallet-rng-flaw-likely-linked-to-88-million-bitcoin-theft/

Sunday, 2 August 2026

Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. [...]

source https://www.bleepingcomputer.com/news/google/google-chrome-may-soon-block-new-tab-hijacker-extensions-by-default/
Tom Evslin drove the WorldNet project at AT&T and helped develop what became Microsoft Exchange and Outlook. He was at Microsoft when the company was still working out what to do about this newfangled internet thing. Evslin describes himself as one of Microsoft's "internet radicals" in the early 1990s, when the company was developing Exchange Server to fend off the threat from Lotus Notes. "Bill Gates was willing to put lots of effort and money into Exchange because he was very afraid of Lotus Notes," Evslin says. "He felt that Lotus Notes could become a platform the way that Windows was, which would be an enormous threat to Microsoft. And so he saw Exchange as a Notes killer." Evslin saw Exchange differently "because I was an email guy." He and Microsoft's other "internet radicals" wanted the upcoming products delayed until they had been made relevant to the internet. Gates disagreed. "Bill said, with some truth, that we were probably behind schedule anyway, always looking for an excuse to be late. So we go ahead with the next launch of products, including Office, Exchange, and NT, then worry about the internet afterward, which I thought was a mistake." Evslin was fascinated by the internet's potential and disappointed by Gates' stance. He was responsible for gateways in Exchange, services that connect one mail system to another. Some did things like connecting to CompuServe. Others linked to MCI Mail, one of the first commercial email services in the US, "which I had done a client for," Evslin says. "We had one little gateway that we hadn't put much work into, which was called an SMTP gateway, which connected SMTP mail, which was used on the internet. Which itself wasn't widely used." So, was Gates right? Only briefly. While Microsoft's corporate clients insisted communication over the internet was "not safe" and "not secure," Evslin says: "All of a sudden we got a huge number of requests for this SMTP gateway. And when I looked into it, I found that more and more email was going over the internet." The official corporate stance might have been one of "nope," but employees had other ideas. "Their engineers were communicating on the internet, and they never understood that, or didn't understand that at the time," Evslin says. And then there was what would become Outlook. "From the beginning, we wanted the client for Exchange to be able to support graphics, to be able to support fonts, so that you could format an email in the same way that you could format a Word document. "Where we didn't go far enough is we still had two separate formatting engines, so the Word and Outlook client never merged as I thought they should have." Soon after Gates chose to launch the products before adding deeper internet integration, AT&T invited Evslin "to come and develop their internet strategy." Back then, Evslin says, AT&T didn't really have a clear plan for the internet. The company had tinkered with proprietary networks, but Evslin reckoned AT&T should become an ISP. "AT&T always had illusions about being a content provider," he says. Evslin also favored all-you-can-eat pricing, which smaller providers had attempted but AT&T had yet to try. "There was a lot of debate internally, people saying 'you can't launch a new service in less than seven years.'" Considering how quickly things were moving – and still are – seven years was a lifetime. "I said, 'the solution to that is launch it fast and then adapt.'" WorldNet offered straightforward internet access to customers accustomed to portals, proprietary networks, and some heart-stopping telephone bills. Demand grew so quickly that AT&T had to control sign-ups lest the service earn the "America On Hold" nickname occasionally and unkindly applied to America Online. With the internet in the ascendant, Evslin became interested in another technology: voice over IP. This, he acknowledges, "was an impossible sale inside AT&T." And so, in 1997, Evslin moved on again to found ITXC, a wholesale VoIP carrier. ®

source https://www.theregister.com/offbeat/2026/08/02/meet-the-internet-radical-who-helped-microsoft-get-email-and-att-get-online/5281281

I have a policy to effectively never link to YouTube videos. I’ll gladly make an exception for this one.

Reflection is one of the most powerful concepts in Computer Science. Unfortunately, not every programming language is blessed enough to have it.

In the 1980s, one company, Symbolics took the concept to the logical extreme. By representing EVERYTHING as objects; they created the most powerful (and inadvertently) least private operating system ever created!

The company collapsed, but the ideas live on. Some modern languages got a full dose of reflection. Some…weren’t so lucky. I ranked them all, and in the end I’ll show you how I dragged C++ up a tier with my brand new runtime reflection library, CallMeMaybe!

↫ Laurie Wired

The GitHub description of CallMeMaybe:

CallMeMaybe (CMM) is a C++ runtime reflection library built on top of P2996 static reflection introduced in C++26. CMM purposefully mirrors many of the std::meta functions to provide a uniform interface, but allows runtime introspection, dynamic invocation, and instantiation by building a runtime reflection registry. Class members can be automatically traversed and reflected by simply adding [[=cmm::reflectable]] as an annotation. CMM implements a custom type system to completely avoid RTTI requirements.

↫ CallMeMaybe GitHub page

My YouTube linking policy will remain in place.



source https://www.osnews.com/story/145661/callmemaybe-runtime-reflection-library-built-on-c26-static-reflection/

Saturday, 1 August 2026

Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. [...]

source https://www.bleepingcomputer.com/news/security/amgen-says-cloud-data-breach-exposed-patient-health-proprietary-info/
Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. [...]

source https://www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/
OpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20% as it works to make its models more efficient. [...]

source https://www.bleepingcomputer.com/news/artificial-intelligence/openai-says-its-new-gpt-56-models-are-becoming-more-cost-efficient/

Friday, 31 July 2026

Virtually every high-end GPU and AI accelerator relies on high bandwidth memory (HBM), which can shuffle data around at multiple terabytes a second but can only reach into the gigabytes, with models often needing to be shared across multiple processors. However, an emerging storage technology could change that, boosting accelerator memory capacity from hundreds of gigabytes to terabytes. The technology, called high-bandwidth flash (HBF), is being developed by Sandisk and SK Hynix and aims to provide SSD-like capacities at HBM-like speeds. Peeling back HBF’s layers Conceptually, high-bandwidth flash looks and sounds a lot like HBM. It’s assembled by stacking multiple layers (16 in the case of Sandisk’s first-gen modules) of memory together, which boosts capacity and bandwidth. But where HBM uses DRAM, HBF aims to use NAND flash. Sandisk claims its first generation of high-bandwidth flash will supposedly achieve read bandwidths up to 1.6 TB/s [PDF], making it a bit faster than HBM3e but significantly slower than HBM4, which is already hitting 2.5 TB/s per 12-high stack. Future HBF generations are expected to push bandwidth to over 2 TB/s and eventually 3.2 TB/s. While bandwidth makes HBF interesting as an alternative to HBM, its real party trick is capacity. Because it’s built using NAND, Sandisk says it can achieve capacities up to 256 Gb per die, which translates to 512 GB per 16-high module. That’s more than 14 times the capacity of the HBM4 used in AMD and Nvidia’s latest accelerators. Continuing with the similarities, HBF modules share similar packaging requirements to HBM, which means you can expect them to be fused to the GPU die using advanced packaging techniques like TSMC’s CoWoS, or Intel’s EMIB and Foveros tech. Nothing particularly exotic as AI accelerators go. What’s more, the storage vendor doesn’t expect the modules to come at a power or price premium over HBM. And from a bits per dollar standpoint, HBF looks like a stellar option. If all this sounds a bit too good to be true, that’s because for all of HBF’s benefits, it comes with some rather significant compromises. NAND still isn’t DRAM The main trade off, as we understand it, is write endurance and access latency. HBF may perform like HBM on paper, but it’s still using NAND, which has a finite write endurance before it wears out and has access latencies measured in microseconds as opposed to tens of nanoseconds for DRAM. If you were to swap HBM for HBF, it (probably) wouldn’t perform very well and it’d wear out pretty quickly, rendering that $50,000-plus GPU of yours a paperweight — not ideal for a product that’s being asked to serve longer to suit hyperscalers' depreciation schedules. Instead, Sandisk and SK Hynix propose using HBF to supplement HBM to make inference more cost effective. HBM handles all the write intensive stuff while HBF takes care of the read heavy parts of the pipeline. While we talk about inference as one job, it's really a collection of many that can broadly be broken into two categories, one that’s compute intensive and another that’s bandwidth bound. The first of these phases, called prefill, involves tokenizing and embedding prompts, feeding them through the model in one big forward pass, generating the key value caches used to track state, and outputting the first token. The second, called decode, reads the entirety of the model's weights, or in the case of a mixture of experts (MoE) models, their active parameters, from memory over and over again for each token generated. Because of this, how quickly an AI system can churn out tokens is directly proportional to how fast its memory is. Prefill is comparatively write heavy, so it makes sense to do as much of that in HBM as possible. But the decode phase is almost entirely read, which makes HBF an ideal medium for storing model weights as write endurance really isn’t a factor. It becomes a sort of write-once, read-many scenario, which is perfect for NAND flash since reads are essentially free. You could almost think about HBF a bit like a rewritable ROM cartridge for models. And because HBF is non-volatile, it becomes a bit like Intel’s Optane persistent memory. There is no need to wait for weights to reload from storage into GPU memory; they’re already there and ready to go. Sandisk’s slides propose a couple of different options including one that would feature 3.12 TB of memory across two stacks of HBM and six stacks of HBF. Oh the things you can do with all that memory That much memory has implications for model and inference architectures. Most frontier models at this point employ a mixture-of-experts (MoE) architecture, which means the model is really a collection of routed sub-models called experts, a small selection of which are used to generate each token. This has allowed model devs to build models larger than would otherwise be practical to serve due to memory bandwidth constraints. Because HBM’s capacity is so limited, these experts usually have to be spread across multiple GPUs connected by extremely high-speed interconnects. But with high-bandwidth flash, even multi-trillion-parameter models, like Kimi K3, could be packed into a single accelerator, mitigating any of the performance bottlenecks induced by the chip-to-chip interconnects. On the flip side, HBF could allow a 72-GPU rack to run some truly massive models measuring hundreds of trillions of parameters. Training such a model presents its own unique set of challenges, and the number of active experts/parameters would be limited by HBF’s bandwidth, but it could work. So when? So when can we expect to see HBF deployed in datacenters? If Sandisk is to be believed, the first samples should go out later this year with the first AI inference devices based on HBF available early next year. But for a variety of reasons previously highlighted by our sibling site Blocks and Files, we’re not holding our breath. One of the biggest factors is standardization. Memory is a commodity business and blazing your own trail with a proprietary technology rarely pans out — just look at Optane if you need evidence of that. Sandisk and SK Hynix officially kicked off this process earlier this year under the auspices of the Open Compute Project. “The key to AI infrastructure is to go beyond the performance competition of individual technologies and to optimize the entire ecosystem,” Ahn Hyun, president and chief development officer at SK Hynix, said at the time. There are also manufacturing considerations to be made. HBF is going to require a lot more dies per module than your typical flash storage device. What’s more, from what we understand, the specific kind of NAND used to make these modules is different from the kind used to make SSDs and other flash storage. Those modules will need to be copackaged with accelerators, which means SK Hynix and Sandisk will need to get buy-in from GPU and ASIC makers, which is going to take time. In fact, it wouldn’t be surprising for these modules to be ready years before the first chips designed to take advantage of them enter production.®

source https://www.theregister.com/storage/2026/07/30/gpus-could-explode-to-multiple-tb-with-new-storage-inspired-memory-tech/5281363
If you don't want AI scrapers training themselves on your website, there's a new way to stop them that doesn't involve server-side blocking or praying they respect your instructions in robots.txt. A team of creatives have teamed up with a typography company to create a new type of font that’ll trick LLM scrapers into ingesting poisoned gibberish. Dubbed ShieldFont, the open-source project almost seems like magic if you're not familiar with the ins and outs of computer fonts. Look at a web page written using a ShieldFont font and it’ll appear exactly as one would expect: All the content words (the nouns, verbs, adjectives and adverbs that give a sentence meaning) are the same as the writer originally wrote. Inspect the raw HTML that a scraper reads from a ShieldFonted page, however, and you’ll see a sentence that’s essentially gibberish. Typing “good luck reading this, you useless robot” in the online demo version, for example, turns it into “good comfort reading this, you yellow barrier.” The goal, as outlined in the ShieldFont white paper, is not to get a scraping bot to reject the text as garbage, but to convince it that the text on the page is unusual but sensible. A noun will never be swapped for a verb, for example, and a verb will never be swapped for an adjective: Swaps only come from the same grammatical pool. It goes even more distinct than that, The ShieldFont creators noted. “Not just noun for noun: plural abstract noun about communication for plural abstract noun about communication,” the white paper explains. “There are about 250 such pools, built by crossing part of speech with sense category, concreteness, singular or plural, verb transitivity, verb inflection and adjective degree.” Around a quarter of words in a chunk of text end up replaced, the creators noted, with the hope the copy still gets ingested. Even if it doesn't, and the group notes scrapers do sometimes reject it, that still means your writing doesn’t get sucked up to train an AI – a win either way. How does this black magic work? This all seems a bit mystical unless you’re versed in the functions of fonts – specifically fonts in the OpenFont family, which ShieldFont is designed to work with. First off, you may be familiar with typographic ligatures, which combine two letters into a single character for the sake of making text look a bit neater, or conveying meaning in some languages but not others. Æ is one classic example in Latin script used in some languages but not others; there's also fi, which combines a lower case F and I in a way that prevents the top curve of the F from bumping into the I’s dot. OpenType fonts all come with ligature tables that define how single glyphs or glyph sequences get substituted automatically by a word processor in a process known as glyph substitution, or GSUB. Even Google Docs supports user-configurable GSUB to an extent - you can fairly easily configure a substitution to automatically fill in for frequently used special words or characters. ShieldFont works on largely the same premise, but extends GSUB to entire words instead of letters or character pairs. So for example, a word like "daughter" in raw HTML might be rendered as "journalist" when it actually shows up to human viewers on the page. Here's what a paragraph written in the ShieldFont looks like as viewed on a web page (above), as opposed to what the raw HTML actually says (below): Even with that extended GSUB format, the font files are still quite small. We spoke with Amsterdam design studio Seneda & Abrucio, founded by Isaque Seneda and Gabriel Abrucio, the team behind ShieldFont, and they told us that the document/desktop fonts that are ShieldFonted are only around 5 MB, while compressed web fonts that include the entire GSUB dictionary still only come in at around 800 KB - large for your average font, S&A explained, but still considerably smaller than the desktop version. There’s more than one GSUB dictionary too - ShieldFont is shipping with three of them, and the GitHub repository explains how users can create their own to prevent reverse-engineering. But why poison a few words instead of just scrambling text altogether? S&A told us that they want a deterrent to scraping by introducing uncertainty and chaos into training data, not just a way to get scrapers to ignore some pages. “Pure scrambling fonts already existed,” the pair explained. “We wanted a mechanism with actual consequences: scrape without asking, and you can't tell if what you took was real. Concealment alone just gets you dropped and forgotten.” The default font that ships with ShieldFont is a modified version of Optik from Copenhagen typography shop Playtype, who partnered with S&A on the project. Like other scraping deterrents, it's not perfect Speaking of reverse-engineering, ShieldFont isn’t perfect by a long shot. As the team notes in their white paper, it can be defeated with relative ease. A screenshot of a page that’s run through OCR avoids the poisoned HTML, as does any other method that a scraper might use to scrape user-viewed pages instead of raw code. Targeted AI that downloads its own copy of ShieldFont and runs through all three GSUB dictionaries can also decode a page. SheildFont could also impose an SEO penalty on people who use it, as search engines, like AI scrapers, read the raw HTML to look for content, as do translation apps and the copy/paste function built into computer operating systems. Screen readers used for those with visual impairment also have trouble with it too, though there is a feature built in to ensure screen readers can get the user-displayed text, albeit slowly. “[ShieldFont’s] purpose is not to stop a determined actor, but to slow unauthorized mass scraping by adding cost, friction and uncertainty,” S&A said in a press release. “Scrapers cannot know in advance whether a site uses ShieldFont or which mapping it uses.” As for whether ShieldFont is just an experiment or something S&A hope gets widely adopted, the pair told us it’s a bit of both. “ShieldFont is real and working today, but it's v0/alpha, so still improving,” S&A explained. “Longer term, it's a bet on collective pressure,” the ShieldFont designers added. “Nothing currently makes bypassing a publisher's requests costly. If enough sites make scraping expensive, scrapers have to change how they operate. That's the point where negotiation becomes possible.” ShieldFont is now available to try. The online demo encoder can be used to generate protected HTML for embedding in a website, and it’s also available as a React component and for CSS and CDN integration, all of which is explained on the project’s GitHub page and the ShieldFont website. ®

source https://www.theregister.com/ai-and-ml/2026/07/30/open-source-project-fools-ai-scrapers-with-poisoned-font/5281303
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. [...]

source https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/

Thursday, 30 July 2026

Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. [...]

source https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/
The US government has signed a letter of intent to provide GlobalFoundries with $300 million in CHIPS Act funding and, at the same time, receive a one percent stake in the company worth roughly $269 million. The money's supposedly not a tit-for-tat, but an investment designed to spur development of silicon photonics networking technologies that the AI industry needs for datacenters. “With today’s compute supply chain investments, the Trump Administration is accelerating America’s innovation engine,” Commerce Secretary Howard Lutnick said in a canned statement. “These strategic investments will enhance our country’s domestic capabilities, create high-paying jobs and keep America at the forefront of the semiconductor industry.” GlobalFoundries’ previously announced Silicon Photonics Co-Packaged Advanced Light Engine (SCALE) is one of the technologies it’s pushing in order to support 400 Gb/s per lane connectivity, which is about the speed at which copper interconnects become problematic for large scale systems. Both CPO, where optical engines are integrated directly into the compute logic, and NPO, where the optics reside in a module adjacent to the compute, are expected to be big business over the next couple of years. At Computex in Taipei last month, Nvidia CEO Jensen Huang quipped that these technologies would make Marvell Technology the next trillion dollar company. Over the past two years, system designs from Nvidia and AMD have grown from eight GPUs in a box to rack systems packing six dozen accelerators into a single machine. To meet growing AI demand, the chip designers are plotting even larger row-scale systems using optical interconnects. Since its spinoff from AMD, GlobalFoundries has moved away from leading-edge CMOS technologies in order to focus on more specialized processes. The company has become a leading producer of silicon photonics used in modern AI datacenters. In addition to next-gen silicon photonics tech, GlobalFoundries says the CHIPS Act funding will also support the development of novel optical materials, advanced packaging capabilities like 3D hybrid bonding, which will support the rollout of domestically manufactured near-packaged optics (NPO) and co-packaged optics (CPO). And thanks to the Trump administration, regular Americans will have a stake in the success of these technologies — or at least the ones GlobalFoundries ends up manufacturing. GlobalFoundries would not be the first American fab operator that Uncle Sam has secured equity from in exchange for CHIPS Act funding. Last summer, the Commerce Department converted $5.7 billion in previously awarded but not yet disbursed CHIPS Act grants, along with $3.2 billion awarded under the Secure Enclave program, into roughly a 10 percent stake in the struggling chipmaker. Bootnote: On Tuesday, Intel announced the Rapid Assured Microelectronics Prototypes - Commercial (RAMP-C) program had reached its conclusion. The Department of Defense (DoD)-sponsored program offered incentives to industry partners to develop test chips in Intel fabs on the company’s 18A process technology. The program’s end comes as Intel shifts its manufacturing might to a new government program called the Secure Enclave, which will manufacture semiconductors for use by US defense industrial base (DIB) customers. “Early access to Intel 18A has positioned DIB customers to leverage Secure Enclave while meeting critical size, weight and power requirements,” the company wrote. ®

source https://www.theregister.com/public-sector/2026/07/29/uncle-sam-sees-the-light-offers-globalfoundries-300m-to-pursue-silicon-photonics-while-taking-1-stake/5280620
The guardrails that prevent closed-source, frontier models from aiding threat actors have turned into handcuffs that prevent those bots from helping to find and fix serious vulns. Daniel Fox Franke, principal security researcher at Akamai Technologies, was recently trying to track down the source of a segmentation fault in ripgrep, and found OpenAI's GPT-5.6 Sol wouldn't cooperate. "OpenAI's cybersecurity classifier is a huge pain when you're trying to track down a segfault," he wrote in a social media post on Sunday. "...The classifier won't even let it answer what entrypoints from rg into musl lead to allocations on the mallocng heap." And just like Hugging Face in the case of OpenAI's accidental attack, Franke ended up having to use open weight models from Chinese AI providers – Z'ai GLM 5.2 and Moonshot AI's Kimi K3 – to complete his analysis of what appears to be a Linux kernel bug. In an email to The Register, Franke explained, "It started out from a pretty anodyne prompt: I noticed that ripgrep had segfaulted repeatedly during a long-running Codex session, so I instructed the root agent to spin off a subagent to investigate what was happening. "A few minutes later I hit the first classifier trip, which the root agent told me was the result of a subagent pursuing an inappropriate line of inquiry and that it was steering it away from that." Even so, he said, the classifier balked several times in quick succession. "It seemed that attempts to produce the crash and analyze the heap were mostly responsible, so I started up a fresh context in which I warned that these trips had happened previously, and that its task should be strictly scoped to analyzing ripgrep and musl source code (not kernel, because I had no inkling at this point that this was a kernel bug): it must not attempt to reproduce the crash or to analyze core files," he explained. "Nonetheless, the classifier kept tripping despite its adherence to those instructions, and that's when I gave up on getting any useful work out of it." Franke said that given how much more restrictive Anthropic's models have been, he didn't even bother trying any of the Claude model family. "OpenAI's cybersecurity classifier is a separate system which censors output from the generative model, and the classifier is the only thing which gave me a problem," he said. "I never encountered any refusals from Sol itself: it knew that most of the classifier trips were inappropriate and always continued working with me in good faith to work around the problem." Franke said that while OpenAI's error messages directed him toward the Enterprise Trusted Access program, he didn't bother to apply because he's ineligible. What he didn't realize until recently, he said, is that there's a separate Trusted Access program for individuals. "I still haven't signed up for that, because I regard the verification procedure as a bit of an indignity," he explained, echoing similar sentiment The Register has heard from other security researchers. "I'll put up with it if I'm ever forced to, but not for as long as open models remain a practical alternative." Two open models did prove practical for this bug hunt: GLM 5.2 and Kimi K3. Franke said each served a distinct purpose. "K3 made the initial breakthrough with the key bit of evidence that I was dealing with a kernel bug, but its subsequent investigative work was sloppy: jumping to unfounded conclusions and spoiling its own evidentiary record, and it went totally off the rails when its context got large," he said. "GLM-5.2 is what finished the job for me, re-auditing K3's work and putting together an airtight case." Franke said it was frustrating to wrestle with defiant tooling and expressed skepticism about model access limitations given the availability of open source alternatives. "From my perspective, an uncooperative tool is simply a broken one," he said. "And no, I don't believe this is sustainable in the face of open-weight competition. I'm a total pragmatist about open source and don't mind at all working with proprietary products as long as they get the job done. But with proprietary software, there's a much greater hazard of it being built to serve the vendor's priorities rather than the customer's. Open source has a natural advantage in preventing that." Franke said that there's still work to be done on the Linux bug, which doesn't yet have a patch and doesn't appear to represent an exploitable vulnerability. "Where my investigation stands is that I know two things confidently," he said. "First, that the crashes are caused by a kernel bug. Second, that I've identified a kernel bug. But that this bug is causing these crashes is still just a conjecture, and I have a lot more investigation to do before I can think about shipping anything to [the Linux Kernel Mailing List]." Last week, much of the US tech industry came out in support of open weight models in response to protectionism promoted by Anthropic and OpenAI. The US government has yet to articulate a coherent AI policy with regard to open weight models. ®

source https://www.theregister.com/ai-and-ml/2026/07/29/closed-models-refuse-to-help-researcher-swat-linux-bug/5280647
Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters. [...]

source https://www.bleepingcomputer.com/news/security/health-isac-warns-of-rising-shinyhunters-data-theft-attacks-on-healthcare/

Wednesday, 29 July 2026

Two agentic bug-hunting systems from Microsoft and Google-owned Wiz show that when it comes to finding and remediating software vulnerabilities, at least two models’ minds work better than one - and Wiz tells us it’s adding a third. Wiz on Monday said Project Atlas, its bug-hunting AI agent, bested Anthropic’s Mythos Preview and OpenAI’s GPT-5.5 Cyber with its vulnerability-analysis skills, achieving a 90.9 percent success rate on CyberGym, and uncovering more than 200 zero-day security holes in widely used open-source code. Meanwhile, Microsoft boasted its MDASH bug-hunting harness scored a 95.95 percent success rate on CyberGym, also beating Mythos, Gemini and GPT on the same benchmark for evaluating how well AI systems find real vulnerabilities in the code. For comparison, OpenAI’s GPT-5.5 Cyber scored 85.6 percent on CyberGym, and its GPT-5.6 Sol scored 83.6 percent. Anthropic’s Mythos 5 reproduced the target vulnerability on 83.8 percent of CyberGym challenges. And Google’s Gemini 3.5 Flash Cyber in CodeMender achieved an 83.2 percent success rate. The secret to both Atlas and MDASH’s success, according to the vendors, is that they use the right model for the right security job. Atlas uses Claude Opus 4.6 with GPT-5.5, Nir Ohfeld, head of vulnerability research at Wiz, told The Register. “We're now working to incorporate Gemini, which is well timed given Wiz's recent work with DeepMind on Gemini Flash Cyber,” he added. Microsoft’s MDASH - a combination of red-team agents that find and simulate real, exploitable vulnerabilities and attack paths, and green-team agents that remediate the issues - combines MAI-Cyber-1-Flash, based on Microsoft AI (MAI)’s internally developed MAI-Thinking-1 reasoning model, and GPT-5.4. MAI-Cyber-1-Flash is designed to handle up to 90 percent of all tasks, with MDASH detecting, patching, and validating vulnerabilities before handing the remaining 10 percent of more complex tasks to the larger GPT-5.4. “We were able to take an off-the-shelf model, within our harness, a multi-agent and multi-model implementation, and we achieved the best results you could have,” Hayete Gallot, executive vice president of Microsoft Security, said on Monday. Atlas isn’t commercially available yet - it’s used internally, and stems from Wiz’s efforts to understand how frontier models can be used for advanced code scanning. But it’s proof that “no single model is best at everything, and none stays state of the art for long,” Ohfeld and fellow Wiz kid Yuval Avrahami wrote in a Monday blog. The cloud security biz evaluates every new model using its internal benchmarking tool, Cyber Model Arena, which scores each one on its success at completing various security-investigation tasks: threat modeling, hunting, validation, and proof generation. “The results are rarely uniform: the model that reasons best through a complex exploit chain is often not the one that triages most precisely,” the duo wrote. “Atlas routes each stage to whichever model wins on that task.” In addition to doing a better job of finding and fixing vulnerabilities, a multi-model system also saves customers’ money, according to Microsoft and Wiz. Combining its much smaller, in-house model with GPT-5.4 halves customers’ costs, according to Mustafa Suleyman, CEO of Microsoft AI. “As the models hand off between each other, they are not just able to deliver better performance than all of the other models combined, they do so at 50 percent of the cost,” he said on Monday. And while “each new generation of models expands what is possible,” they are also expensive, Ohfeld told us. “We have also learned that pointing a frontier model at a codebase once is not a sustainable security strategy: deep scans are expensive, their results become stale as code changes by the minute, and a point-in-time analysis cannot provide the continuous coverage organizations need across every repository,” he said. In fact, the real question for code security shouldn’t be which model a scanner uses, Ohfeld added. It’s this: “How does your system take advantage of the best model available today, continuously and economically, and what continues to work when a better one arrives,” he said. “That is the bet behind Atlas: frontier-model depth where expert reasoning is required, an architecture that improves as models evolve, and rigorous validation so every finding arrives with evidence, not just a plausible answer.” ®

source https://www.theregister.com/security/2026/07/28/microsoft-and-wiz-mind-meld-agents-catch-more-than-90-of-bugs/5279914
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [...]

source https://www.bleepingcomputer.com/news/security/vbulletin-fixes-critical-pre-auth-rce-flaw-with-public-exploit/

Tuesday, 28 July 2026

Your GPU dashboard says 70% utilization. On paper, the cluster is busy. In practice, a large chunk of that time is spent with your $40,000 accelerators sitting idle, waiting on a file that lives three network hops away on a NAS box. The compute queue is empty, and the pipeline is fine. The problem is that data is just somewhere else. This is the awkward truth underneath most stalled AI projects. The constraint in modern AI infrastructure stopped being storage capacity years ago. Now, it's more about data placement and access. What matters is where files live and how they get to GPUs, along with how much copying happens in between. In that sense, AI infrastructure has become less of a storage capacity problem and more of an operational data problem. The Hammerspace Data Platform takes that as its starting point. It sits between your compute and the storage you already own, from NAS to object stores and even the NVMe drives bolted into your GPU servers. It makes all of that data addressable through a single global namespace. Instead of moving data to wherever the GPUs are, the architecture makes the compute aware of where the data already lives. As a result, rather than treating each storage system as its own operational silo, Hammerspace separates the data layer from the underlying infrastructure, allowing heterogeneous storage, sites, and clouds to operate as part of the same coordinated data environment. Applications and AI pipelines access that data through standard protocols such as NFS, SMB, and S3, without proprietary clients or application rewrites. Fragmentation is the bottleneck, not bandwidth Data fragmentation is a big problem for enterprises embarking on an AI journey. Training sets are scattered across departments, sites and clouds. "The data is in disparate groups and disparate orgs and disparate silos within a company," says Jonathan Flynn, director of applied systems at Hammerspace. "Having the data in a curated data set for you just to go train is rare. It has to be collected. It has to be moved around from system to system, and then the curation needs to happen in order to actually do the training on it." The fragmentation often leaves pipelines copying and staging files between systems that were never designed to talk to each other. None of this shows up on a storage IOPS chart, but it will visibly affect training velocity. According to Gartner, 57% of organizations believe that their data isn't AI ready. Alarmingly, two thirds of executives believe that no one in their organization understands all of the data they've collected and how to access it. That seems hard to swallow, until you recall that Facebook's engineers have admitted the same thing. You can't orchestrate what you can't see. Mike Bloom, who covers AR architecture at Hammerspace, says the default vendor response makes the problem worse. "They'll go to a vendor that will promise them that if they sweep the floor and throw out all of their legacy storage arrays, their brand will solve the problem," he says, adding that's like throwing the baby out with the bath water. "Those data sets that are all over the place? They're not sitting in a corner. They're sitting on legacy storage arrays." The NVMe you already paid for There is also a less obvious idle resource in most AI environments: the NVMe inside the GPU servers themselves. A modern HGX or DGX box ships with eight to sixteen NVMe drives, each hanging off four lanes of PCIe. Almost every orchestration layer treats that capacity as local scratch space, used by one server and invisible to the rest of the cluster. Hammerspace calls this "stranded" capacity, and it is now meaningful. It amounts to hundreds of terabytes per server, with two-petabyte GPU servers on the roadmap. Pull all of it into a shared namespace and you have a new layer that Hammerspace calls Tier 0. It uses storage you already paid for, attached to a network you already deployed. Flynn argues this layer is structurally faster than anything sold as a separate appliance. "Tier one is typically oriented around storage capacity. A 2U box, 24 NVMe, or 40 NVMe with some of the Dell systems in there," he calculates. "That's 96 lanes or 192 lanes of PCI Express, with maybe one or two 400 gigabit NICs, which gives you 16 or 32 lanes. So the over subscription just in the one box is massive." His more provocative claim is that it is also the cheapest tier in the rack. The compute and the network are already there. The drives (at least in the case of customers buying GPU servers) are already in the bill of materials. Compared with racking and stacking a dedicated all-flash array, adding metadata servers and a few data movers to existing GPU nodes barely registers as a procurement event. Assimilating what you already own Ripping and replacing infrastructure takes time most teams don't have. The Hammerspace approach is assimilation, which the company describes as a metadata-only operation: scan the existing NAS, ingest the directory tree into the global namespace, and redirect mounts. The bytes never move. Hammerspace says that fast deployment is a key benefit of this approach. Data access is restored almost immediately, even while assimilation continues in the background. Underneath this, the source-of-truth NetApp, Qumulo or VAST array keeps serving the bytes, while Hammerspace presents a unified view on top. That has practical consequences. If something tagged as a training input changes from being a tier-two archive file to a hot input, a policy (Hammerspace calls this an "objective") can trigger an instance copy onto tier 0 without users having to do anything. "Nobody's running a copy. Nobody's running an rsync command," Flynn says. "It's all orchestrated based in the file system." That same orchestration layer can also support retrieval-augmented generation (RAG), inference, and agentic AI workflows, where distributed enterprise data needs to be continuously curated, governed, and made accessible without relying on large-scale data copying. Once the training job finishes, that tier 0 copy is automatically vacated. The clean-up matters because the alternative (letting a hot tier fill up) creates a quality-of-service problem for everything else trying to land there. "Other architectures that have a hot tier and a cold tier often have an issue where the hot tier becomes congested and that endangers the quality of service for the pipeline," Bloom says. “Rather than requiring organizations to rebuild infrastructure around AI, the Hammerspace approach is designed to operationalize the storage, cloud, and compute environments enterprises already have in place. Standards-based, with some asterisks Hammerspace's positioning leans heavily on the word "standard". The Samsung-Hammerspace submission that landed inside the top 10 of the IO500 10-Node Production benchmark in November 2025 used standard Linux, the upstream NFSv4.2 client, standard NVMe SSDs and IP-over-InfiniBand. There was no proprietary client, and no custom kernel modules. The company submitted its own results to MLPerf Storage v2.0 showing linear scaling out to 420.8 GB/s across 140 GPUs on five nodes with GPU utilisation above 96%. That kind of performance is not achievable with traditional NFS architectures, which struggle with the parallel access patterns common in large-scale AI environments. Instead, Hammerspace runs on parallel NFS (pNFS). Instead of letting a single server handle file metadata transfer alongside data transfer, it creates a layout map that the client can then use to transfer data from multiple servers in parallel. That became the RFC 5661 standard in 2010. Hammerspace was also instrumental in extending pNFS in NFSv4.2 in 2018, introducing the Flex Files extension. This is what lets pNFS work with real-world hetergeneous storage across cloud tiers, legacy files, and multi-site deployments. The larger implication is that open, standards-based infrastructure is no longer inherently at odds with AI-scale performance, challenging the assumption that enterprises must adopt proprietary storage stacks to support large-scale AI workloads. "With the performance improvements that we contribute into the upstream, we're actually seeing a decades-old file system transmute into a parallel access system that can rival WEKA, Lustre, and GPFS," Flynn says. Multi-site and sovereign by default Once a single global namespace spans on-prem arrays, cloud object stores and the NVMe inside GPU boxes, the next questions are jurisdictional. Where can a given file legally live? Who is allowed to copy it? The platform handles this through the same objectives mechanism used for performance tiering. Tag a dataset as EU-only and the orchestration layer will exclude it from North American volumes. Tag it as HIPAA-bound and write-once-read-many rules apply. Because those policies operate at the data layer rather than within individual storage silos, governance persists even as data moves across clouds, sites, and performance tiers. That is becoming increasingly important as AI pipelines, inference workflows, and agentic systems operate across distributed infrastructure rather than within a single environment. That matters more in 2026 than it did two years ago, since such operational flexibility also changes the economics of AI infrastructure expansion. The SSD supply situation has tightened. NAND and DRAM prices climbed through 2024 and into 2025, driven by AI build-out and hyperscaler hoarding. Buying your way out of a data-movement problem by adding another all-flash array is harder when the flash is harder to get. A control plane that understands workload, location and policy together is now a valuable procurement workaround. Real-world usage The most useful data point about whether any of this matters at scale is Meta. The company runs two 24,576-GPU clusters used to train Llama 3 and deploys Hammerspace specifically to enable live job debugging and real-time code propagation across the training pipelines. If a company with effectively unlimited engineering resources still hits a data-movement ceiling at that scale, the enterprises running a fraction of the workload are almost certainly hitting it too, and the standard answer of "buy more GPU" does not address a problem one layer below the compute plane. Flynn put the underlying joke about NFS politely. "The joke I always heard was, NFS is not for speed." That used to be true. The newer claim, that an open, standards-based file system can sit underneath an AI factory and feed it, casts the venerable file protocol in a new light. ICustomers will likely want to see an independent benchmark of this system's performance against the likes of VAST, WekaIO and NetApp in heterogeneous customer environments, using test systems not designed by the vendor. Nevertheless, it looks promising. In the meantime, the data placement architecture conversation is certainly the right one to be having. Sponsored by Hammerspace.

source https://www.theregister.com/ai-and-ml/2026/07/27/ai-has-changed-data-architecture-but-storage-hasnt-caught-up/5255880

Monday, 27 July 2026

Google has created a new taxonomy to describe cybercrime outfits, seemingly abandoning a Microsoft-led effort to create consistent names. The Big G announced its new schema on Saturday in a post that notes its 2022 acquisition of Mandiant and its subsequent incorporation into a new team called the Google Threat Intelligence Group (CTIG). Now that two have become one, Google reckons they need consistent naming conventions to describe cybercrime crews. The result is a two-word schema in which the first word “is a unique and memorable term chosen to represent the specific actor.” If security folk have already applied a particular moniker Google will use it, otherwise it will randomly generate a word “to remove bias.” Google says the second word “categorizes threat clusters by motivation, attribution, or activity type based on which category we consider to be most important for defense and response strategies.” More on that later. Google has decided on the following names: CASTLE to describe crews from the People’s Republic of China ION for threats from Iran NEPTUNE for North Korean attackers RELIC for Russians COMET for cybercrims who aren't backed by a state Google’s post notes that other infosec industry players have developed their own schemas for describing threat actors and says the web giant is therefore “intentionally seeking to keep this system as simple as possible to streamline operations and facilitate mapping to other naming taxonomies.” That’s an odd position, given that in 2025 Microsoft and CrowdStrike tried to spark an industry-wide effort to apply consistent names to threat actors. As we noted at the time, the existence of multiple naming schemas means that researchers often refer to the same group by ten different names. Researchers use the names Seashell Blizzard, IRIDIUM, VOODOO BEAR, BE2, UAC-0113, Blue Echidna, PHANTOM, BlackEnergy Lite, and APT44 to refer to the same entity – Russia's Military Intelligence Unit 74455. With most orgs using multiple security tools and therefore receiving threat intelligence security info from many vendors, users must try to understand which crews they’re trying to defend against. At the time, sources told us Google and Mandiant were keen to adopt the Microsoft-led scheme. Google’s new announcement suggest the relationship either wasn’t consummated or didn’t last. Back to the issue of possible bias, as in 2024 China's National Computer Virus Emergency Response Center (CVERC) complained that western companies choose names like “Typhoon,” “Panda,” or “Dragon” to describe Chinese cybercrime groups. CVERC suggested names that reflect English language idioms, such as “Hurricane” or “Koala” are more appropriate. For what it’s worth, “Koala” is a word from the language spoken by the Darug people, the indigenous tribe who lived around Sydney, Australia, prior to British colonization. Koalas are utterly supine creatures that sleep 18 to 22 hours a day, and a mention of the marsupials may therefore not spur defenders to action, even if the creatures’ habits do perhaps describe the behavior of some sleeper malware. ®

source https://www.theregister.com/security/2026/07/27/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy/5278749
WHO, ME? Mistakes happen, and when readers of The Register make them, we like to share those tales of woe in a Monday column we call "Who, Me?" It's our guide on how not to get ahead in the modern workplace. This week, meet a reader we'll Regomize as Clay, who in the 1980s was the most junior member of the management team on a Swedish construction site. "We had two site engineers, and they were the only ones with computers," he explained to The Register. This was a time before PCs had become ubiquitous, so Clay was curious about the machines. "One lunch break, I asked the junior engineer if I could try his PC," he told us. The junior had little choice but to comply, so Clay sat down at the machine and used the only command he knew. "It worked," he told Who, Me? "But unfortunately, that command was 'DEL *.*'" Clay had therefore deleted everything in whatever directory the engineer had allowed him to access. "Thankfully, my colleague was very relaxed and forgave me, so I got to keep my job," he told The Register. "But 'DEL *.*' still haunts me!" The moral to this story seems clear: do not under any circumstances let a suit take control of computers! Have you let a user wreak havoc on your machine? If so, click here to send an email to this column, so we can show readers how not to cause chaos on some future Monday. ®

source https://www.theregister.com/software/2026/07/27/manager-showed-off-his-dos-prowess-with-a-command-that-wiped-data/5278057
The 13th flight of SpaceX’s Starship made it off the launchpad on Friday and ticked off just about everything on the company’s to-do list. After delays and engine replacements, Elon Musk’s colosso-launcher took to the skies at beer-o’clock on Friday evening – 5:51PM Texas time. One hour, five minutes and 21 seconds later, Starship made a controlled splashdown in the Indian Ocean, where it floated after landing. SpaceX says it was able to gather critical data on the performance of Starship’s heatshield, and that the craft made “a dynamic banking move to mimic the trajectory that future missions returning to Starbase will fly.” Gathering data on Starship’s heatshield performance will help SpaceX ensure the craft is re-usable. Simulating missions that land at Starbase, SpaceX’s Texas home, builds toward future missions that launch and land at the same facility, speeding turnarounds for re-usable hardware. The test flight also saw SpaceX test a new routine for de-orbiting the Super Heavy booster used to hoist Starship into space. “The booster successfully completed the high thrust portion of the boostback burn with all 33 engines, the first time with a Super Heavy V3, before ending the burn early,” SpaceX said. “It attempted to relight its engines for the landing burn, with a subset successfully igniting before experiencing a hard splashdown in the Gulf.” That part of the mission didn’t go perfectly, as SpaceX hoped for a softer landing and more engines lighting to make it possible. Once Super Heavy and Starship separated, the latter vehicle used its six Raptor engines to reach desired speed and orbit. It then deployed 20 Starlink V3 satellites. SpaceX crew verified the sats worked and half a dozen of them got a look at Starship’s heatshield. While the satellites were functional, SpaceX did not intend them to form part of the Starlink constellation and allowed them to re-enter Earth’s atmosphere. Or as the company’s mission report put it, the satellites “demised upon reentry approximately 20 minutes after deployment.” Starship performed one more trick on its way back to Earth, by starting one of its Raptor engines while coasting through space. The success of that test again demonstrated tech that will be needed for future missions, in this case flights that push Starship into sustainable orbit – or allow it to reach a trajectory capable of reaching the Moon, as NASA envisages will be the case for future Artemis missions that land humans on Earth’s permanent natural satellite. SpaceX boss Elon Musk said he hopes the next Starship test flight will see the Super Heavy booster caught by robot arms at Starbase, another step towards improved reusability and turnaround times between flights. ®

source https://www.theregister.com/science/2026/07/27/spacex-just-about-nails-starship-test-flight-13/5278725
ASIA IN BRIEF Taiwanese mega-manufacturer Foxconn has adopted Singaporean hyperconverged infrastructure vendor (HCI) Arcrfra for some GPU virtualization workloads and to replace VMware in some remote offices. Arcfra launched in 2024 and the next year earned a place on analyst firm Gartner’s Market Guide for Full-Stack HCI Software. Last week, Arcfra launched an update to its Neutree model-as-a-service platform, adding native GPU virtualization and model governance capabilities. The company said Foxconn has adopted Neutree “to modernize distributed factory infrastructure and improve how AI models were delivered, managed, and observed across environments.” The Taiwanese giant has also used Neutree to “accelerate model deployment, improve operational visibility, and build a scalable foundation for future AI and intelligent manufacturing workloads.” Foxconn considers AI a critical part of its plans: The Register last year heard chairman Young Liu hail generative AI’s potential to vastly improve the company’s factories. The Register asked Arcfra to detail its relationship with Foxconn and the HCI upstart pointed us to this case study that states “Foxconn's global branch companies relied on traditional VMware virtualization for their IT systems. This legacy setup was becoming increasingly difficult to manage and scale across a distributed global footprint [and] led to high construction costs and a significant increase in operations and maintenance overhead.” Foxconn apparently deployed Arcfra “across its branch factories in Mainland China, Taiwan, Vietnam, and North America” and uses the Singaporean platform for critical intranet, manufacturing management, ERP and production line management systems. Arcfra also hosts Foxconn's DevTest environments and Virtual Desktop Infrastructure workloads. “The legacy VMware virtualization + SAN storage architecture was successfully replaced, providing a modern, scalable foundation ready to accommodate future business growth and technology adoption,” Arcfra claims. The Register asked Foxconn for further information about its decision, but has not received a response at the time of publication. VMware’s owner, Broadcom, changed strategy to target large entities like Foxconn. Broadcom says the overwhelming majority of its target customers have adopted its flagship Cloud Foundation suite, but The Register has also noted many big-name dissenters, among them Tesco, Western Union, Allstate Insurance – and now Foxconn. Better news for Broadcom In better news for Broadcom, the chip design side of the business has struck a $200 billion deal with Samsung’s memory and foundry businesses. “On the memory front, Samsung and Broadcom plan to pursue a strategic collaboration for the supply of industry-leading memory solutions, including High Bandwidth Memory (HBM), supporting Broadcom’s next-generation AI accelerators,” states Samsung’s announcement of the deal. “In foundry, the companies’ collaboration focuses on Samsung’s 2-nanometer (nm) and below process technologies for Broadcom’s products, including Wireless Broadband Communications (WBC) solutions. The collaboration is expected to extend to advanced packaging technologies built on Samsung’s 2nm process, including 2.3D and 2.5D integration, to enable higher-performance and more power-efficient AI and networking silicon.” “By combining Samsung’s memory and foundry expertise with Broadcom’s AI and connectivity leadership, we aim to continue to deliver technologies that power the next generation of AI infrastructure,” said Charlie Kawwas, the president of Broadcom’s Semiconductor Solutions Group. Broadcom has a huge order book for custom accelerators and needs foundry capacity to build those products and its other offerings. Given the global shortage of fabrication capacity, and Samsung’s status as arguably the world’s second-most-sophisticated fab operator, Broadcom has every reason to be happy it has secured access to the manufacturing resources it needs. Infosys names next CEO Indian tech services giant Infosys last week named Ashiss Kumar Dash as its next CEO. Infosys says Dash is currently “global head for a business portfolio that comprises over 12 industry verticals.” He will replace current Managing Director and CEO Salil Parekh on April 1, 2027. Parekh led the company for nine years. The change is an orderly handover rather than a vote of no confidence in Parekh, although Infosys last week posted [PDF] its Q1 results which included a forecast of revenue growth of between 1.5 and 3 percent, down from previous guidance of possible 3.5 percent growth for the full financial year. The company said its previous guidance assumed an economic upswing that hasn’t happened. India orders takedown for Jack Dorsey’s Bluetooth social network Twitter founder Jack Dorsey has used the renamed platform to share an order from the government of India that requires GitHub to take down BitChat – the decentralized peer-to-peer messaging app that can use Bluetooth mesh networks for offline communication. The order Dorsey shared justifies the takedown request on grounds that Delhi has powers to compel communications services providers to cease service to prevent public disorder, riots, or terrorism, but that authorities can’t act against decentralized messaging infrastructure. At the time of writing, The Register was able to access the BitChat repo. “The government of India does not like technologies like BitChat and wants it taken down,” Dorsey wrote. China fines Trip.com operator $770m for monopoly practices China’s State Administration for Market Regulation on Saturday announced it has fined the Trip.com Group $770 million for monopolistic practices. Beijing went after Trip.com for the behavior of its Ctrip brand, which targets Chinese-speaking customers. The regulator alleged that Ctrip “forced hotel merchants to accept exclusive cooperation agreements and manipulated hotel prices through technological means, thus exacerbating the industry's ‘involutionary’ competition.” The fine may interest regulators around the world, because Trip.com and its sub-brand Skyscanner are popular outside China. ®

source https://www.theregister.com/virtualization/2026/07/27/foxconn-drops-vmware-adopts-hyperconverged-upstart-arcrfra-for-workloads-including-ai/5278684

Sunday, 26 July 2026

GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. [...]

source https://www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/
President Trump has expanded his Ratepayer Protection Pledge to include power companies, datacenter developers, cooperatives, and state governments, saying the move will shield consumers from rising energy costs driven by the datacenter boom. In a speech at the Environmental Protection Agency (EPA) HQ in Washington, Trump said the pledge will now extend across the full chain of parties whose decisions determine household bills. This includes the utilities that supply power, the developers that build the facilities, and the state authorities that regulate energy rates and infrastructure. "We're here today to continue the incredible progress we're making in communities nationwide to ensure that as new datacenters go up, and they're going up all over, electricity bills for American families will actually come down," he declared. The Ratepayer Protection Pledge was created earlier this year, partly as a response to growing anti-datacenter sentiment among ordinary Americans, especially those who were seeing their utility bills jump. Much of the concern stems from the need for energy firms to invest heavily in new generation capacity and grid upgrades to serve the facilities being built, many for the AI market. The original signatories of the pledge – the "Munificent 7" of Amazon, Google, Meta, Microsoft, OpenAI, Oracle, and xAI – agreed to cover the full cost of any extra resources required to satisfy their energy demands. But as was pointed out at the time, these hyperscalers do not set the rates ultimately paid by consumers; utilities and state regulators play crucial roles there. The expanded pledge now brings those parties into the tent. According to the White House, more than 200 additional utilities, datacenter developers, cooperatives, and states have now joined the pledge. The White House claims the pledge covers roughly 80 percent of the power delivered to American homes and businesses, supposedly protecting 263 million people when a datacenter is built nearby. Trump went on to say that many datacenter developers will have to generate their own power on site, effectively turning themselves into utilities. "It's hard to believe, but you need double the electricity that we have right now, maybe even more than that, to really fulfill what you want to do," Trump said. "We're leading China [in AI] by a lot, and using our old grid would not have worked. And I came up with the idea that you build your own plant. This way nobody can complain," he added. The Reg believes many datacenter operators were already generating their own on-site power before Trump claimed responsibility for the idea. "We're insisting that AI datacenters and big tech companies pay their own way. And that's what they're doing, and they're happy to do it, because this way, they're going to be able to function, and function brilliantly. They're going to have a lot of electricity left over and they'll put that into the grid, so we'll actually end up with more electricity," Trump claimed. But as The Register pointed out previously, the text of the Ratepayer Protection Pledge makes no mention of enforcement. There are no apparent penalties should any of the signatories fail to prevent consumer bills rising because of demand from AI datacenters, so this appears to be very much a voluntary agreement. We asked the White House and the EPA what actions might be taken if signatories to the pledge were found to be failing in their commitments, and will update if we get a response. The measure seems likely to be put to the test, as the latest data from Synergy Research estimates the total capacity of US datacenters will double over the next three years, driven by an aggressive build-out by hyperscale operators. The pipeline of future large facilities known to the research biz currently stands at almost 1,500 worldwide, with almost half of those in America. That represents around 45 gigawatts of extra IT capacity set to be added over the next few years. Synergy chief analyst John Dinsdale says that availability of power and rising local concerns over server farms are crimping many new plans for facilities. "But it is also clear that datacenter developers will continue to find ways around those issues and that booming demand will continue to drive aggressive capacity growth. Over the next five years, the US will continue to account for well over half of the world's operational datacenter capacity." ®

source https://www.theregister.com/on-prem/2026/07/26/trump-expands-voluntary-pledge-to-keep-datacenter-costs-off-household-power-bills/5278346
This week marks 15 years since a Space Shuttle last returned from orbit and the end of NASA's Space Shuttle program. Space Shuttle Atlantis landed at the Shuttle Landing Facility (SLF) at Kennedy Space Center 15 years ago this week, marking the final mission for the program. STS-135 was originally designated STS-335, the Launch On Need (LON) mission for the previous STS-134 flight of Space Shuttle Endeavour. LON missions had been a feature of the Space Shuttle program following the Columbia disaster. If a Space Shuttle was damaged, another could be launched at short notice to rescue the crew. NASA assigned Launch On Need flights separate STS-3xx designations, so the rescue mission for STS-116 was STS-317, STS-117 was STS-318, and so on. There were exceptions (a notable one was the STS-125 Hubble servicing mission, which had STS-400 ready to go if anything went wrong), but the Space Shuttle program should have ended with STS-134. However, lawmakers and NASA managers opted to make STS-135 the final Space Shuttle mission. There could be no Launch On Need mission waiting in the wings this time around – the Space Shuttle program was being wound down – so the crew would have had to come down from the International Space Station (ISS) aboard Soyuz capsules if Atlantis could not return to Earth safely. There were also only four crew members, a figure not seen since the STS-6 mission of Challenger in 1983. The crew was commanded by Christopher Ferguson, who would later join Boeing's Commercial Crew Program and was assigned to (although did not fly) Boeing's calamity capsule, the Starliner. The pilot for STS-135 was Douglas Hurley, who went on to fly the first crewed test flight of SpaceX's Crew Dragon in 2020. Rounding out the crew were mission specialists Sandra Magnus and Rex Walheim. The launch occurred on July 8, 2011, and Atlantis returned from orbit on July 21, bringing the Space Shuttle program to a conclusion. It wasn't, however, the end of crewed spaceflight for the US, although the gap that followed was considerably greater than expected or hoped. After the Space Shuttle retired, the US was dependent on Russia for getting its astronauts to and from the ISS. NASA later awarded Commercial Crew contracts to SpaceX and Boeing to restore launches from US soil, but it took SpaceX until 2020 to get the first humans to the outpost, and Boeing until 2024. The latter's mission was marked by ignominy due to failures and faults during the mission that meant managers opted to send the capsule back to Earth empty from the ISS and have the Starliner flight test crew return in 2025 aboard a SpaceX vehicle. NASA and Boeing have yet to set a definitive date for when a crew might venture to the ISS once again aboard Starliner. All of which, 15 years after a Space Shuttle returned from orbit for the last time, has left the US space agency in a bit of a pickle. Instead of depending on the Space Shuttle, the plan was to reduce risk and add redundancy to US capabilities with two providers, but things haven't worked out that way. To make matters worse, there is uncertainty about how much longer SpaceX will continue to fly the Crew Dragon beyond its contracted missions. The vehicle is reusable, but no more are planned to be manufactured, and SpaceX reckons that each should be good for 15 flights, with some refurbishment. This should be enough to get through to the end of the ISS program and beyond, but in the longer term an alternative will be required. For SpaceX, this will likely be Starship. The fate of the Space Shuttles themselves is also not completely set. Atlantis has been staged in a facility at Kennedy Space Center as if in orbit, and the California Science Center has mounted Space Shuttle Endeavour on an external tank and solid rocket boosters, as though ready for launch. The fate of Space Shuttle Discovery is, however, uncertain. Certain lawmakers would very much like to transport the retired orbiter from the Smithsonian's Steven F. Udvar-Hazy Center in Virginia to Houston, Texas. For others, well, there's always a used Orion capsule. ®

source https://www.theregister.com/science/2026/07/26/the-last-space-shuttle-returned-to-earth-15-years-ago/5277279
Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. [...]

source https://www.bleepingcomputer.com/news/security/steam-forum-clickfix-attacks-infect-gamers-with-xmrig-cryptominers/

Saturday, 25 July 2026

OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. [...]

source https://www.bleepingcomputer.com/news/security/ontrac-notifies-customers-of-data-breach-after-network-hack/
A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

source https://www.bleepingcomputer.com/news/security/hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry/
The FreeBSD project froze its ports repository on Wednesday. The reason turns out to be a slightly embarrassing Git-related oopsie where a version of Copilot got uploaded somewhere it should not have been. The announcement of the 2026 Ports Repository Freeze went out on July 21 and remained in effect the following day, as explained in a message on the freebsd-announce mailing list. The mail delicately skirted around exactly what happened: « The commit in question severed our ports tree mirroring to github.com due to their filesize hard limit of 100MB, and introduced a blob of questionable licensing into the repository history. » The offending commit is this one. It’s not a disaster; the problem is that the Ports repository is automatically mirrored to various places, including a read-only Github mirror – and as Github’s docs say, “GitHub blocks files larger than 100 MiB.” There is already an official FreeBSD port of Copilot, but FreeBSD terminology is slightly confusing here: the “port” is effectively a sort of package that allows the Linux binary to run inside FreeBSD’s Linux emulation, called the Linuxulator. It isn't a native FreeBSD version of Copilot, and the package is not meant to include the actual Copilot CLI binary – partly because that is under its own custom license. That’s what FreeBSD’s Kyle Evans meant by “questionable licensing”. We don’t blame anyone for using any available resources to help with using GitHub. Navigating Linux, FreeBSD, and worst of all Git is hard, especially the last one. Git is aptly named – it’s not an acronym, it’s a real word: someone annoying or unpleasant. It is, however, now more or less the de facto standard version control system of the FOSS world. Despite not being a developer, the Reg FOSS desk worked with Git on a daily basis for over four years – blame the Docs as Code philosophy – and developed a deep and abiding dislike for it. It’s not just us: it’s in an XKCD comic, so it must be true. (This vulture has directly lived the experience described in that comic.) Personally, we always found Git much harder work than the tar command. It should come as no surprise that multiple teams are working on compatible alternatives. A Game of Thrones Trees Just the day before some FreeBSD developer’s regrettably public mishap, a new version of one of those alternatives appeared: Game of Trees version 0.127. Game of Trees, known as Got for short, is a Git-compatible version control system (VCS) developed by contributors to the OpenBSD Project. It’s been in development since 2019, and we feel that the project has a nice line in self-deprecation – starting with the homepage’s project description: “a version control system which prioritizes ease of use and simplicity over flexibility.” This is, we suspect, in response to Git’s self-description, which says that it is “designed to handle everything from small to very large projects with speed and efficiency.” We also like the Got project goals and especially the FAQ, which really does not beat about the bush: « Does Got aim to replace Git? No. Got does not aim to replace Git. Got can be used instead of Git (for some tasks), or in addition to Git. If you are already using Git and are happy with it, you don’t need Got. » And even more succinctly, under the anchor “pointless”: « What’s the point of all this? Why not just use Git? If you are wondering why Got even exists, you can just ignore it. » Got isn’t the only tool that aims to remain compatible with Git, but simplify the experience. Gitless is another, which describes itself as “a simple version control system built on top of Git,” and says that it’s “easy to learn and use.” Unfortunately, development seems to have gone quiet: the last release appeared the same year that Got appeared. Another (and even younger) Git-compatible VCS is Jujutsu, often called just “Jj”, and not to be confused with the traditional Japanese martial art Jiu Jitsu. Jujutsu the VCS has lots of documentation, but if it has a weakness, it's that it rather assumes that you already know your way around VCS use in general and Git in particular. If that’s not the case for you, you might find Jujutsu for Everyone by Remo Senekowitsch more helpful. ®

source https://www.theregister.com/os-platforms/2026/07/24/dev-accidentally-commits-copilot-binary-to-freebsd-ports-repo/5278458
Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

source https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/

Friday, 24 July 2026

A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. [...]

source https://www.bleepingcomputer.com/news/security/new-dolphin-x-malware-uses-ai-to-rank-high-value-targets/
You can take your vibe-coded project elsewhere. Codeberg, a volunteer-run code hosting community, has decided that AI-authored software is no longer welcome. On Thursday, Codeberg announced that the members of Codeberg e.V., the Berlin-based non-profit overseeing the code hosting service, had voted to ban "vibe-coded projects" and declared that Codeberg would not use users’ code or data for AI training due to its impact on Free, Libre and Open Source Software (FLOSS). The vote follows ongoing efforts by Codeberg to prevent automated software (bots) from taxing its infrastructure with excessive network requests. Authors Bastian Greshake Tzovaras, Otto Richter, and William Zijl argue that AI companies are shifting costs to others and damaging online communities in the process. "LLMs are so costly that companies externalize the costs on a massive scale – on those who don't use them and society at large," they wrote in a blog post. "Increased hardware prices, energy use and environmental damage – we all pay for it!" They point to the cost of Codeberg's SSD and memory hardware as an example, noting that a drive that only a few years ago cost €700 (~$800) now costs €3,700 (~$4,200) – if it's even in stock. The result is that Codeberg has been forced to raise prices. The authors also call out the proliferation of projects that often involve a solo developer "working with a statistical machine that turns energy into code." They fault these folks for not having any community and argue it's unreasonable for Codeberg to spend its limited CI/CD and storage resources on ghost projects. But the vote isn't simply about unfair resource consumption. It reflects broader unease among Codeberg members about the damage AI coding models are doing to the FLOSS community. AI-driven price hikes, they contend, are broadening the digital divide by making personal computers less affordable, forcing more people toward corporate-owned cloud services. And beyond the environmental harm of increased water and energy use, the Codeberg authors argue that LLM use is undermining the foundation of trust and community that makes FLOSS work. "The widespread use of LLMs in FLOSS is instead becoming a multidimensional attack on the trust between contributors and the very idea of convivial collaboration itself," they state. LLMs magnify maintainers' workloads, create confusion around whether projects will be maintained, and "lead to 'license laundering', where copyleft code is stripped of its reciprocity requirements by 'generating' it out of the training data." "As we want to center on human collaboration, we will not actively support or engage in the creation of LLMs and will not put our limited resources to use for storing single-use software that would pollute our FLOSS commons," the authors conclude. As a consequence of the community vote, projects developed and maintained mostly by an AI agent are no longer welcome at Codeberg and are urged to move to other hosting options. This is reflected in amended Terms of Use language: "You must not share projects that mostly consist of code written by 'generative AI'-tools (including services such as Claude, OpenAI Codex). Such projects having an unclear copyright status … and furthermore have little safeguards to ensure that they do not include harmful code." Enforcement of the ban seems unlikely, however, unless a project draws attention to itself, given Codeberg's statements about limited resources and its overburdened workforce. Support for the vibe-coding ban was substantial but not overwhelming, with some celebrating the decision and others condemning it. Among Codeberg members, 358 voted in favor, 144 voted against, and 14 abstained. About half the active members voted. "I think this is a very bad move, and the people behind Codeberg should re-consider their stance," said Armin Ronacher, creator of Flask and one of the co-founders of AI agent biz Earendil. On its way toward Free, Libre, and Open Source Software equilibrium, Codeberg also decided to ban cryptocurrency projects, citing a similar move by SourceHut in 2023. A proposed amendment to make it Codeberg's stated purpose "to oppose discrimination and promote a diverse FOSS community" passed with a two-thirds vote but is not yet merged. The protection extended to philosophical outlook does not cover belief in AI. ®

source https://www.theregister.com/ai-and-ml/2026/07/23/codeberg-gives-vibe-coded-projects-the-toss-promotes-human-floss/5277717

About

Privacy Policy

ShortNewsWeb

Blog Archive

Recent Comments

Popular Posts

Translate

My Blog List

Popular

System Admin Share

Total Pageviews