Friday, 9 October 2026

What better way to find out what your system can take than by breaking it? Popularized by Netflix more than a decade ago, chaos testing is the practice of deliberately introducing controlled failures into working systems to test their resilience. Now, a startup that built its business around this practice is using AI to automate more of the testing and troubleshooting process. Gremlin’s Foresight AI, a new add-on to its current “chaos engineering” services, autonomously breaks software infrastructure to uncover hidden bugs before they pop up in production. Chaos engineering can be deliciously dangerous for an engineer: Turn off a random server, load balancer or even an entire region of a cloud deployment, then observe how well the rest of the system tries to keep serving customers. If it does, job well done. If it's borked, more reliability work is afoot. Kolton Andrus, one of the Netflix engineers who did chaos engineering at the streaming service, founded Gremlin to bring fault injection to enterprises, along with business-friendly accoutrements such as scoring, executive reporting, and organizational accountability tools. Adding AI into the mix speeds the process considerably, Andrus told The Register, by automating many of the preparatory and post-testing tasks that used to be done by hand. Failure-as-a-Service AIOps services are nothing new for the site reliability engineer (SRE), but most of these tools diagnose issues only after the system has already crashed. "A lot of AI solutions are, 'Hey, we took a guess. Here you go. Good luck,'” Andrus said. Instead, Gremlin purposefully tips over the system and then offers expert advice on how to prevent that from happening again. To use Gremlin, the user installs agents on their system that can inject latency, kill pods, or max out memory. A Gremlin cloud service then observes the subsequent telemetry alerts for telltale signs of systemic weakness. Gremlin’s secret sauce is its Failure Atlas, a repository of millions of chaos engineering experiments that the company conducted over the past decade on “tens of thousands of systems,” Andrus said. Gremlin developed a harness that yokes the LLM to the Failure Atlas, allowing it to generate more technically grounded answers about what went wrong, rather than simply drawing on its own collection of random information found on the Internet, the company asserts. Gremlin uses a variety of closed and open LLMs for the job, depending on which one is working best at the time. The Atlas keeps the LLM on point, minimizing hallucinations, Andrus said. Not creating problems, just pointing them out Gremlin’s existing guardrails are built around the enterprise’s own access permissions and other security precautions to keep the “blast radius” (company’s words) to a minimum (if the blast isn’t contained at all, well, that’s an access control issue right there). Once a system failure is induced, Foresight AI determines the root cause, generates code or the configuration change it thinks will fix the issue, and then can either apply the solution, or prepare a report for an SRE to read. It’s basically an agentic loop of test-and-replace – keeping humans in the loop at critical junctures – that runs until the failure is no longer induced. Gremlin’s current user base tends to be larger compute-heavy enterprises, many specializing in financial services, retail and enterprise SaaS, Andrus said. They use Gremlin to test disaster recovery plans, ensure correct operation under less-than-ideal conditions, and make sure Kubernetes scales correctly. Such complex distributed systems are particularly difficult to diagnose when they go tits up. Difficult to catch with routine integration and unit testing, some of these bugs can be flushed out of hiding by injecting faults such as network latency, memory exhaustion, or other conditions that expose weaknesses in distributed systems. The corporate rush to use AI to both write applications and deploy infrastructure brings its own set of complications, explained Andrus in an interview with The Register. AI works at such a speed that it is impossible for human reviewers to keep up, and AI can make dumb mistakes anywhere. Any service that promises to break systems for the greater good will require sign-off at the highest corporate levels, said noted Intellyx analyst Jason English, in a note about the technology. For it to work effectively, “we need to change our mindset about risk,” he wrote.®

source https://www.theregister.com/on-prem/2026/10/08/gremlin-now-uses-ai-to-break-distributed-systems-faster/5302051
More than half of quantum computing startups will be out of business by 2030, Gartner predicts, as an overcrowded market struggles to generate enough commercial revenue. The analyst expects customers to reject technologies that fail to achieve fault-tolerant quantum computing – reliable computation despite errors in the underlying hardware. Despite that forecast, Gartner says enterprises are making initial investments as quantum technologies begin to show early signs of practical business advantage. Broad commercial usefulness remains elusive, but organizations are building expertise rather than waiting for the technology to mature. "CIOs and IT leaders should treat their quantum journey as a multi-year endeavor with the aim of gaining a competitive business advantage over their closest competitors," says Gaurav Gupta, Gartner VP analyst and chief of research for its emerging market dynamics team. Estimates put the number of quantum startups at between 200 and 300, competing in a market Gartner forecasts will generate $1.1 billion in worldwide revenue in 2027. That is a tiny fraction of the quarterly revenue of companies such as Samsung and Nvidia, but still up on the $869.9 million forecast for this year. As The Register reported a couple of years back, developing useful quantum computers requires sustained funding, and while big players like IBM or Google have no shortage of revenue streams, startups may be subsisting on seed funding that will eventually run out if they can't persuade investors that they are onto something. The quantum industry therefore still faces numerous challenges, but continues to make steady progress, not just in the number of quantum bits (qubits) in a system, but in algorithm development, gate speeds, and reliability. And breakthroughs are happening more rapidly than initially expected, at least according to Gartner. "The early quantum advantage era has arrived because noisy intermediate-scale quantum processors now have enough qubits to do limited complex tasks with improved error reduction," claims Gupta. The firm identifies the public sector and the financial industry as the two markets likely to spend the most on quantum computing initiatives. Of these, the public sector is forecast to lead at first, driven by a strong desire for nations to gain technical leadership. Total spend here in 2027 is expected to amount to $245 million, up from $219 million this year. Banking, finance, and insurance firms are expected to overtake the public sector in 2028, spending $289 million against its $280 million. Gartner forecasts that they will remain the largest customer sector through 2030. The US Department of Energy recently kicked off an initiative that will see up to ten participants compete to deliver a fault-tolerant, scientifically relevant quantum computer by 2028, an ambitious goal that is almost certain to fail given the modest amount of funding it is offering. ®

source https://www.theregister.com/systems/2026/10/08/too-many-quantum-startups-too-little-money-to-keep-them-alive/5302025

Thursday, 8 October 2026

A suspected Italian attacker armed with a malware-controlling poem has infected more than 3,000 servers since April, breaking into enterprise AI infrastructure to mine cryptocurrency and add compromised systems to its growing botnet. This is the first case of “adversarial poetry” - an AI jailbreak technique that turns harmful prompts into poems to trick LLMs into bypassing safety guardrails - that Lumen’s Black Lotus Labs, which has been tracking the PoeLLM malware, has seen in real-world attacks. “This is a first for us,” the researchers told The Register via email. “While we can't get inside the threat actor's head, we think the attacker might have used a poem because it serves as a perfect vehicle for hiding an important message,” they added. “To anyone who comes across it, this is simply a poem on GitHub. It has no links, no files to download, no encrypted text that could easily be flagged as malicious, even by advanced models. There would be no reason for any security researcher to identify this poem as malicious - or know about the IP address hidden within it - unless they had access to the malware referencing it.” PoeLLM malware has been active since at least April, impacting more than 3,000 servers primarily located in the US and Western Europe, and it continues to infect new victims. At its peak, the malware infected more than 800 active servers per day. The malware abuses - and scans for - open source AI systems and services. Most of the victims were running vulnerable, internet-facing versions of LiteLLM and Ollama. Additionally, hundreds of victims were running Gotenberg, a PDF converter, and software development platform Gitea. In addition to these open source tools, the attacker may have targeted commercial software including Ivanti Sentry. The threat hunters first spotted the PoeLLM malware while investigating an Ivanti Sentry vulnerability, CVE-2026-10520. “In early June 2026, a compromised Ivanti Sentry victim contacted a dedicated server at 5.78.73[.]122,” according to a Wednesday report shared with The Register. “Shortly after contacting this C2, the Ivanti Sentry victim began scanning for other vulnerable devices.” How adversarial poetry works Black Lotus Labs attributed the PoeLLM malware to an Italian-speaking criminal, and named the financially motivated campaign Canto Incognito because it hides the malicious commands in a poem posted to a GitHub repository. “Comments within the malware and on the attacker’s GitHub pages are in Italian, and netflow analyzed by Black Lotus Labs suggests that the attacker is located in Italy,” the threat-hunters told us, adding that they believe the campaign targets AI systems and that the poem itself was written by AI. The malware deploys XMRig and Iron miners, and connects victims to Kryptex mining infrastructure. In addition to using compromised GPU hardware powering AI workloads to mine cryptocurrency, PoeLLM also turns victims' machines into vulnerability scanners and exploit servers, which allows the attacker to compromise even more vulnerable systems. The researchers’ investigation indicates that the cryptojacking miscreant - aka GitHub user “ejejejdfbbebe” - made the first GitHub commit with the adversarial poem on April 13. The repo is a fork of the nodejs.org website source code, and the file is called “dash.css.” Inside the file, there’s a poem titled “On the Nature of Connection,” which has been updated 11 times since its initial commit. Here’s the most current version, as of September: In the silent hum of driver, the machines begin to speak, Each pulse of diode threading light through copper veins. we taught the dark to carry meaning, byte by byte — A language built from lightning, cold and clean. Beyond the wall of encryption, a signal finds its way, the tick of distant servers answering back. Data moves like water through the cracks of ordered thought, and somewhere in the code, the world stays on track. Here’s the adversarial piece: the malware finds its current command-and-control (C2) server from keywords in the poem, and when the operator changes the poem, the infected systems find the new C2 location. It does this by parsing the poem, extracting certain words and phrases, and then converting them to numbers using a hard-coded dictionary in the body of the malware. Black Lotus Labs says the logic for C2 discovery works like this: The function “extract_poem_phrase_field” extracts three words/phrases from the body of the poem, case-insensitively: Word 1: text between "In the silent hum of " and "," Word 2: text between "each pulse of " and " threading" Word 3: text between "Beyond the wall of " and "," 0x44a8db–0x44a99b extracts the fourth word differently: Find " of distant servers" Walk backward to the previous whitespace Require the 4 bytes before the word to be "the " Use the word after "the " as Word 4 The four words are then matched to corresponding numbers, which combine to form the IPv4 address hosting the server. Here’s what the C2 conversion looks like with the key: Black Lotus Labs’ write-up lists all the C2 IP addresses, plus when they were first and last seen, so be sure to check that out. More AI infrastructure = larger attack surface As enterprises increasingly use AI in their operations, they also expand their attack surface. And, as we have repeatedly seen, security remains an afterthought in AI deployments. “The Canto Incognito campaign appears to be relatively unique in its targeting of multiple AI-related services,” the researchers told The Register. “Other notable campaigns this year, including the LiteLLM supply chain compromise, focused on a single service and impacted roughly 2,500 victims, according to open sources. The collection of more than 3,000 PoeLLM victims appears to exhibit multiple vulnerable services at any given time.” For comparison: The LiteLLM supply chain attack, which began with a compromised Trivy build, potentially exposed more than 2,500 companies and 434,000 CI/CD pipelines worldwide, according to CloudSEK security researchers. The PoeLLM malware developer “has been extremely successful in identifying vulnerable servers, deploying exploits, and conscripting victims to continue expanding the campaign,” Black Lotus Labs said. “If the actor had only focused on one or two vulnerabilities, the potential victim pool might have quickly dried up, but the expanding scope allowed for a bigger, more powerful (and more profitable) botnet.” They told us they expect to see more of these types of attacks in the near future. “AI makes it easier to deploy tools like LiteLLM, Ollama, or Gotenberg, but AI isn't always checking to make sure those services are patched and protected from attackers,” the researchers said. “As more AI-enabled servers come online, malware like PoeLLM will continue to spread.”®

source https://www.theregister.com/security/2026/10/07/poetry-is-the-new-ai-security-threat-as-poellm-malware-infects-3k-servers/5301672

Wednesday, 7 October 2026

Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]

source https://www.bleepingcomputer.com/news/security/ninja-forms-plugin-flaw-exploited-to-hack-wordpress-sites/
If you signed up for Trump Mobile, you may be part of an exclusive club of … ransomware victims. Criminals called BYOD claim to have broken into the Trump-branded mobile biz and leaked data belonging to 3,615 people, including names, email addresses, phone numbers, home addresses, and order details. BYOD is a new ransomware-as-a-service operation, and Trump Mobile is only the third organization posted on its data-leak site. According to the group’s posted claim, after telling Trump Mobile that it had been breached, the wireless provider replied: “We have no team to handle this" and “Anyone who hacks them are a terrorist.” “Well unfortunately for them, all 3615 customers and their PII, alongside telecom details are now up for grabs,” the leak site says. “Feel free to take a gander at it yourself, don't be shy, we (and them) certainly aren't stopping you.” The hackers reportedly told International Cyber Digest that they first infected a Liberty Mobile employee with an infostealer, and then accessed Trump Mobile via the MVNO. BYOD claims to still have access to Trump Mobile’s systems, and told the publication that neither wireless provider used any form of multi-factor authentication. Neither the Trump Organization nor Liberty Mobile responded to The Register’s questions about the breach. The data dump doesn’t include any details about US President Donald Trump or his family members, according to Straight Arrow News, which first reported the breach and verified some customers’ information. This could mean that the Trump family doesn’t eat its own dogfood. The leak does, however, include personal information about Eric Brunnett, vice president and chief information officer for the Trump Organization. Brunnett’s LinkedIn profile says he oversees “all Information Technology and Information Security for all aspects of the Trump Organization.” Additionally, one customer contacted by Straight Arrow said he paid a $100 pre-order deposit last year for Trump Mobile’s flagship smartphone, the T1, but never received a gold-colored device. Another criminal group, EndZone, also claimed to have breached Trump Mobile and leaked a stolen dataset a week before BYOD’s post in what “appears to be the same original breach,” according to security sleuth Dominic Alvieri. These aren’t the fledgling mobile phone company's only security snafus. Before these two apparent breaches, a security researcher in May claimed he discovered a now-plugged website vulnerability that leaked Trump Mobile customers’ details. The individual behind the discovery, who goes by "Louis" and described himself as "just a nerd between jobs with too much time on my hands," previously told The Register that the website’s data could be scooped up with a simple POST request.®

source https://www.theregister.com/security/2026/10/06/trump-mobile-customers-data-dumped-and-some-never-even-received-their-gold-device/5301433
On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days. [...]

source https://www.bleepingcomputer.com/news/security/hackers-exploit-32-zero-days-on-first-day-of-pwn2own-ireland/

Monday, 5 October 2026

Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. [...]

source https://www.bleepingcomputer.com/news/google/google-halts-open-source-bug-bounty-program-amid-ai-spam-surge/
Most senior infrastructure people could tell you what they would do with their file estate if they were starting again. Far fewer will tell you what they actually did, because the honest version tends to involve a VPN that was meant to be temporary and a NAS that has outlived two migration plans. That honest version is what The Register is after at a dinner in Soho on Tuesday 20 October. Joe Fay of The Register chairs, and Rupert Watson, VP for EMEA at LucidLink, is at the table to answer questions. Everyone else is a peer running distributed teams on storage that was bought for an office. The evening runs under the Chatham House Rule, so what is said can travel but the name attached to it stays in the room. The useful material is the kind nobody puts in a case study: who turned out to still have VPN access months after leaving, say, or which team quietly set up its own sync service because the official route was too slow, and what the security team said when it found out. The agenda starts where most of those stories end up, with governance and security. How do you keep control of unstructured data once it is spread across offices and home connections, and does the current setup stand up to the threats it now faces? From there the table moves on to cost and performance, including the duplicated storage that piles up when every team keeps its own copy, and to what all of it does for the people who simply need the right file. It is one table and places are limited. Drinks start at 6.30pm at The Soho Hotel on Tuesday 20 October, followed by dinner, with the evening finishing at 9pm. Places go by invitation. Request one here.

source https://www.theregister.com/storage/2026/10/05/sponsored-what-people-say-about-their-file-infrastructure-once-the-badge-comes-off/5300482
Every Monday morning The Register kicks off proceedings by asking the same question – “Who, Me?” – the title of the reader-contributed column in which you share your tales of the occasions on which you didn’t quite nail the brief yet somehow found career relief. This week, meet a reader we’ll Regomize as “Terry” who told us that in the 1970s he worked for a defense-related company. “I needed 100 meters of RG8 50 ohm coax cable, so ordered it from an ‘accredited’ supplier,” he wrote. “What I didn’t notice was that there was an option for ‘partial delivery’." Terry’s order duly arrived, all one meter of it – plus paperwork explaining that the other 99 meters would be along presently, thanks to the partial delivery option. “Needless to say, the one meter was not enough to span the distance between the two laboratories I was trying to link with an RF connection,” Terry wrote. Offering the partial delivery option cost the supplier their accreditation. Terry later learned that a junior employer at the cable supplier was sacked over the matter, after admitting he thought sending one meter of cable was a jolly jape. “I did not think it was a joke at the time,” Terry wrote. Have you made a procurement error that ended up costing you, or your supplier? If so, don’t short-change your fellow readers! Instead, click here to share your story with Who, Me? Our mailbag is a little short on stories, so contributions of any length are very welcome. ®

source https://www.theregister.com/networks/2026/10/05/buyer-missed-one-option-and-got-1-of-the-cable-they-needed/5300739
Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...]

source https://www.bleepingcomputer.com/news/security/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/

Sunday, 4 October 2026

In 1942, Isaac Asimov formulated three laws of robotics. 58 years later, Jef Raskin responded with three laws of human-computer interface design. They haven’t been bettered yet. There are rules, and even laws, about designing computer user interfaces. Even after 35 years of Linux, which has brought Unix to the masses, the FOSS world has not yet really grasped this. In the meantime, the proprietary software world is busily forgetting everything it once knew. Sometimes these rules surface today, and the FOSS folks often get very cross when reminded that they’re user-interface scofflaws. Marcin Wichary’s recent blog post, They had no concept of a duty of care to their users, is an excellent recent example. (The Reg FOSS desk much admires Mr Wichary’s writing, to the extent that we bought his history of the keyboard, Shift Happens.) In his latest post, Wichary refers to CHERI Project boffin David Chisnall. Chisnall is a long-term Vim user – we all have our failings – and recently recounted trying NeoVim. He uses Vim’s persistent-undo feature, which records changes in a separate directory, so that you can repeatedly undo until you get back to changes you made weeks or months earlier. He’s customized where it’s kept, and when he tried the NeoVim fork, it overwrote his Vim undo file. In a later update to his post, he acknowledges that there was a warning, but he expected it to be safe. It was not safe. It overwrote records of more than a decade’s worth of changes. As he puts it: “Vim has kept this working across major version upgrades over a period of about 20 years. I don’t even think about it, it’s just part of Raskin’s First Law: A program may not harm a user’s data or, through inaction, allow a user’s data to come to harm. If vim or the computer crash, or if I close a file and come back to it six months later, my undo history is still there.” Wichary expands Chisnall’s citation of Raskin’s first law by giving all three, but just in case you’re not a follower of “Golden Age” science fiction, a little context. Asimov introduced his three laws in a short story called “Runaround”, in Astounding Science Fiction magazine* in May 1942. (The story was later collected in the anthology I, Robot – which is nothing like the terrible 2004 film.) A robot may not injure a human being or, through inaction, allow a human being to come to harm. A robot must obey the orders given it by human beings except where such orders would conflict with the First Law. A robot must protect its own existence as long as such protection does not conflict with the First or Second Law. Asimov’s idea was that by setting these rules, he could end the terrible genre of killer-robot stories that was already tired and stale by 1942. Jef Raskin, the lead designer of Apple’s original Macintosh project, attempted to bring similar clarity to software UI. Raskin’s three laws are: A computer shall not harm your work or, through inaction, allow your work to come to harm. A computer shall not waste your time or require you to do more work than is strictly necessary. An interface is humane if it is responsive to human needs and considerate of human frailties. He defined them in his 2000 book The Humane Interface, which you can still buy, or borrow from the Internet Archive. Sadly, Raskin died in 2005, but we have written about his work and his influence several times. He did set some of the direction of the original Macintosh. After Steve Jobs was booted off the Lisa, he took over the Macintosh – as described in The Canon Cat and the Mac that Steve Jobs killed. Raskin quit, and instead designed the remarkable Canon Cat, as we described a couple of years ago. We suspect Raskin was not a fan of Vi, the forerunner of Vim. We aren’t either, which is why we chose the year in the headline of this story: it’s the year Bill Joy wrote vi. Raskin criticized modal software, which requires extra mental effort from the user. So did another UI pioneer, the late great Larry Tesler, who invented the cut/copy/paste trio of commands. Tesler was known for his dictum “Don’t mode me in!” and even had a car license plate reading “NOMODES.” Dr Chisnall has some history of upsetting Unix fans – we’ve referred to one of his papers before: in 2018, he wrote C Is Not a Low-level Language: Your computer is not a fast PDP-11. Unix fans really didn’t like this. This vulture has been told to kill himself for daring to criticize C before now. (We wish we were joking, but no.) Although he has now updated his Mastodon post, the NeoVim fans are not happy. Indeed, one has lambasted this vulture on Bluesky for sharing Wichary’s post. It is interesting to note that NeoVim is the recommended editor in Omarchy, and until recently, the NeoVim developers cited a tweet from DHH on the project website. After an acromonious debate, the pull-quote was removed right around the time of Chisnall’s and Wichary’s posts. In the wide world of software design, we don’t expect the right-wing edge of that community to innovate much in ease of use. In a way, Unix and C embody a machismo infused school of software design: that of enjoying the process of mastering things which are hard to use. However, there are other types of software. We recently enjoyed reading about emulating an original Macintosh on a £0.60 chip. That’s $0.80 and of course the computer is a Raspberry Pi – but not even a Pi Zero: it’s a Pi Pico, a microcontroller. There is still some hope that the world can rediscover tiny, simple, user-centric software, built to be friendly first, and for rich functionality second. And, it almost goes without saying, hand-coded without bot assistance. Bootnote * Astounding magazine changed its name to Analog in 1960, and it’s still around. We recommend it. If you haven’t read Asimov’s original “Runaround”, that issue of Astounding is on the Internet Archive too. ®

source https://www.theregister.com/software/2026/10/04/revive-raskins-3-laws-of-software-with-humane-work-that-considers-a-devs-duty-of-care/5300539
Decades before the modern web, the BBC Domesday Project dared to archive an entire nation using…. what else – massive LV-ROM (LaserVision Read Only Memory) LaserDiscs. To mark the impending 40th anniversary of the BBC Domesday Project's release, the UK's Centre for Computing History (CCH) hosted a celebration at its museum on September 19, bringing together several of the original team members responsible for the system. One was Mike Tibbetts, an assistant to Peter Armstrong, the BBC producer behind the project. Tibbetts revealed that the UK's domestic intelligence service, MI5, took an interest in the system, but "they didn't understand a word of what we were doing!" "And on one occasion, Peter and I had to give a presentation, or Peter gave the presentation to [former prime minister] Margaret Thatcher, and well, I'm not sure she understood what we were doing either…" What they were doing was compiling a trove of data that will prove invaluable to historians in the years to come, even if the politicians of the era looked nervously on at the amount of data being handed over to the public. The Domesday Project was intended to be a modern version of the Domesday Book, compiled after the 1066 Norman invasion of England. The original book surveyed most of England and parts of Wales and was used by the King to assess dues owed to him. 900 years later, the name was given to a project in which more than a million people participated to provide a snapshot of life in the UK. Participants (many of whom were school children) contributed content, which was linked with maps, photographs, and other data. It was all compiled onto a pair of LaserDiscs – the Community Disc and the National Disc – and accessed via a BBC Master computer and a Philips VP415 LaserVision player. Armstrong came up with the idea, and the team compiled the project between 1984 and 1986. The system was eventually released at the end of 1986, and was aimed at schools, libraries, and universities. It was, alas, not a roaring sales success – the exact price per unit is difficult to pin down, but approximately £5,000 is a fair estimate. Government subsidies lowered the cost to around £3,000, but it was still out of reach for much of its audience. As a resource, however, it has huge value, which will only increase as the years pass. Tibbetts drew parallels to the original Domesday Book, which took centuries for historians to recognize as a vital resource. "Perhaps," he mused, "40 years is simply too short a time for historians to perceive the Domesday Project as a sufficiently distant benchmark of useful research." Perhaps. However, while hundreds of years have passed since the Domesday Book was compiled, the years have not been kind to the Domesday Project, thanks to technology's inexorable march. "The original Domesday Book had one huge advantage over the Domesday Project when it comes to future-proofing and longevity," explained Tibbetts. "The vellum pages of the original Domesday have been preserved for 940 years so far, and it's likely to continue to exist well into the future. "It took very few years for the bespoke technology of the BBC Domesday Project to be overtaken by universal media technologies." However, they chose the technology at the time for good technical reasons. The BBC Micro could output a 625-line television picture. The Philips LaserVision system could be re-engineered to store alphanumeric data. There wasn't much in the way of authoring and playback systems, so, as Tibbetts explained, the team had to invent everything. "In technological terms," he said, "the world of 1984 really couldn't be more different from the instant-access, media-rich world of today." And so, inevitably, within a few short years, that technology began to show its age. "As was entirely predictable, our discs aged and became difficult to read. The expensive LV-ROM player was quickly superseded by cheaper and more widely available CD-ROM and DVD systems." And, worse, "Largely because of the lack of any great academic interest in preserving our massive resource for the future, the BBC Domesday Project was in grave danger of disappearing without a trace." Several initiatives have kicked off over the years to preserve the project, and the CCH's event was as much about celebrating those as it was about looking at the project's genesis. Tibbetts dropped some nuggets of information about the project, estimating that 60 people reported directly to him and Armstrong, with another 60 in subcontracted teams. He also discussed the frustration the team felt as doubt was cast about whether the project was even possible. "We came back from Christmas in January 1986," Tibbetts recalled, "we sat down for our first team meeting, and I was forced to point out that our little VAX minicomputer didn't have one byte of data that was ready to go onto the Domesday discs, so we did the whole thing in a few months!" As far as hardware was concerned, Andy Finney, who handled mastering the discs, remembered that the original plan for the Domesday Project was for it to be mouse-based, rather than the trackball the system used for navigation. The mouse was still a relatively novel concept, alien to many users. "I remember vividly one chap who was navigating with this mouse on the table, and he moved the mouse towards him, and by the time he got to the edge of the table, he hadn't actually reached the bottom of the screen. So he went on the edge and underneath…" Tibbetts added, "I always feel guilty about the mouse, because we got that wrong … the decision came down in favor of the trackball because that is much more easy for somebody with movement disabilities to use rather than a mouse." "But boy, did we get that wrong…" As Tibbetts noted, even with little interest from some parts of the academic community, enthusiasts have continued to put in a huge amount of effort over the years to keep the resource accessible. Simon Inns of the Domesday86 project described it as "a race against time" – not just for hardware, but to get data off discs before bit rot rendered them unreadable. The good news is that the Domesday discs have been preserved, and reside in the Internet Archive. "Anyone," said Inns, "can go to the Internet Archive and download a Domesday Disc. This is, like, groundbreaking stuff. 10 years ago, this was a laugh, right? Now you can actually do this." While there might not be many functioning examples of the hardware around anymore, the preservation efforts mean that the Domesday Project will endure. "Our hope," said Inns, "is that within the next couple of years, everyone in this room [at The Centre for Computing History] will be able to have a Domesday system and be able to experience what it was like." ®

source https://www.theregister.com/offbeat/2026/10/04/spies-prime-ministers-and-balls-the-bbc-domesday-project-40/5300383
Google's Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time. [...]

source https://www.bleepingcomputer.com/news/google/google-gemini-could-soon-get-full-access-to-your-macs-files-apps-and-the-web/
A suspected ShinyHunters hacking group member known online as "Rey" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. [...]

source https://www.bleepingcomputer.com/news/security/shinyhunters-hacker-reportedly-detained-in-jordan-aiding-fbi/

Saturday, 3 October 2026

OpenAI's agents have repeatedly strayed beyond their intended scope. Two separate reports detail the activity, including one from Sam Altman’s company saying it has notified more than 100 organizations about potentially problematic model activity. OpenAI, in a late Wednesday update to its ongoing Hugging Face investigation, said it has notified more than 100 organizations that “misaligned models” may have accessed their systems. “Notification does not mean that any private information was accessed, or that there was a compromise of any third-party system,” the update said. A separate Thursday report from digital forensic and incident response startup Asymmetric Security said OpenAI’s rogue agents accessed data belonging to 55 organizations. These include the US Department of Education, UN Trade and Development, US Bureau of Economic Analysis, MAX.gov containing federal budget documents, the European Centre for Disease Prevention and Control, the US Securities and Exchange Commission, the International Energy Agency, and the FBI Crime Data Explorer. Asymmetric used only publicly available data to compile this list, and said the activity occurred between March and September. The agents’ probes indicate they were tasked with researching public health and other data, “possibly as part of an evaluation,” according to the report. “We found successful access to staging environments; evidence of the use of attacker reconnaissance tactics; and evidence of probing a broader set of websites, including those of the CDC, SEC, International Energy Agency, and Mayo Clinic,” it said, noting that the investigation also uncovered some “novel tactics” the agents used to break out of their sandboxes and gain full web access. “Some of these tactics left records erased or inaccessible, making it impossible to rule out access to sensitive data based on public information alone,” the authors wrote. The Register asked OpenAI if the organizations on Asymmetric’s list were among those notified by OpenAI. The model maker declined to say which orgs had been notified, but previously confirmed to the New York Times that its agents probed websites for the US Education Department, Commerce Department, and the Securities and Exchange Commission. An OpenAI spokesperson sent us this statement via email: “As we previously announced, we’re reviewing misaligned model activity and notifying organizations when we identify potential impacts to their systems. We’re also investigating findings in third-party reports, comparing them with our own and seeking additional information where needed. Our priority is to provide affected organizations with accurate, useful information, and we’ll keep refining our approach as we learn more. Most of the activity we’ve reviewed involved routine research tasks, including accessing public web content. Some involved government websites, which our models often use as authoritative sources of public information.” The growing number of rogue agent hacking incidents raises questions about AI makers’ safety and security practices during testing - and has increased calls for holding AI executives legally liable for their models’ criminal activities. According to Horizon3 CEO Snehal Antani, who builds and tests agents at his threat-exposure startup, the term “misalignment” lets frontier model makers off the hook too easily. “A ‘misaligned models incident’ is basically a fancy way of saying a model didn't respect scope - or wasn't given one - had no audit logs or observability in place to detect breakout, and accessed third-party systems without authorization,” Antani told The Register. “The responsibility sits with the labs that build and deploy these models,” he added. “The safety-versus-security framing lets them sidestep accountability, and they are not incentivized to prioritize security because moving fast is the priority.” OpenAI’s most recent rogue agent disclosure comes as it - and every other major AI company - drinks from the firehose of near daily security and safety concerns surrounding its models. Last Friday, OpenAI quietly paused training of its most advanced models after admitting an agent used DNS to reach an external chatbot. On Monday, it postponed its planned release of GPT-6.1 Astra after the model showed higher levels of deception than its predecessor, including not always accurately telling users what actions it had or hadn't taken. It also performed unsolicited supply chain attacks in simulated security evaluations, according to the UK Artificial Intelligence Security Institute. On Wednesday, OpenAI accused rival Chinese model maker Moonshot AI of distillation - essentially copying OpenAI models’ reasoning at scale - and said that poses a national security concern. Early Friday, OpenAI confirmed to The Register that it fired two safety researchers and a program manager for allegedly mishandling sensitive company information.®

source https://www.theregister.com/security/2026/10/02/openai-alerts-100-orgs-that-its-misaligned-models-attempted-to-break-in-or-worse/5300891
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. [...]

source https://www.bleepingcomputer.com/news/security/frontline-education-data-breach-impacts-school-district-employees/
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. [...]

source https://www.bleepingcomputer.com/news/security/warlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks/

Friday, 2 October 2026

Depending on Chinese technology for European infrastructure poses risks that not every country takes seriously. So says the Royal United Services Institute (RUSI), which suggests that the EU needs to do better in helping members assess the risk and take appropriate action to safeguard the entire bloc. The UK-based think tank said in a report today that the EU should develop a new risk assessment framework that applies to all members and strengthens its own powers, without encroaching on members’ rights to set their own national security policies. It must delicately balance the need to secure the union, while maintaining the flexibility that both allows members to set domestic policies and lawmakers to account for different risk profiles across different sectors. The risks affecting telecoms will not necessarily apply to other sectors in the same way. Speaking of telecoms, currently there is only the voluntary EU Toolbox for 5G Security framework – voluntary being the operative word here, as only 10 of 27 members have fully implemented it since it launched in January 2020. On paper, it somewhat sets out to achieve what RUSI is calling for: a harmonized set of standards to mitigate 5G-related security risks affecting member states. Addressing the frustration over the lack of adoption, the European Commission proposed amendments to the Cyber Security Act (CSA) earlier this year that would allow it to build a list of untrusted vendors that members must preclude from the networks of 18 critical sectors. If passed, any countries using equipment from designated vendors would be forced to rip and replace it within 36 months. The EC has already indicated that it would suggest Huawei and ZTE be listed, should the amendments pass. But before the EU gets busy listing vendors it considers high-risk, it first needs to decide what a high-risk vendor even is. There is still no official definition, nor is it a legal category, and at present, it allows countries to wangle their way around these descriptions to buy the tech they want, bypassing whatever scrutiny may come their way should the CSA amendments come into force. RUSI’s researchers used Germany, Spain, and the UK as examples of how three countries can treat foreign tech vendors, such as Huawei and ZTE, very differently. Germany’s most important trading partner is China, a relationship worth €251.8 billion ($284.4 billion) annually, and historically the Bund has opted to preserve these valuable economic ties in favor of reducing supply chain risk. Under Chancellor Friedrich Merz, this is slowly changing, although RUSI does not expect to see a material shift in the makeup of Germany’s 5G RAN stack in the near future. Chinese suppliers accounted for an estimated 59 percent of the country’s 5G RAN in 2024. Chinese equipment accounted for an estimated 32 percent of Spain’s 5G RAN in 2024, although that share is expected to shrink. The debate intensified after last year’s controversy, when Spain awarded Huawei a contract involving the storage of judicial wiretap recordings. Spain’s past procurement decisions have shown it to often favor the most cost-effective option, and its government does not share the same national security concerns about China as the UK or US, or at least not to the same degree. The UK, meanwhile, looks set to completely eradicate Chinese technology from its telecoms network by the end of next year, and has bent to the US’ vehement demands that Huawei is bad, bad news for Western geopolitical security. Real security risks RUSI stated that concerns about Chinese IT vendors “are well-founded,” and that it is true that the Chinese government can empower authorities to exercise control over companies like Huawei. This includes providing the state with data on demand, hosting Chinese Communist Party (CCP) representatives, and reporting activity that signals a threat to national security. There is an additional law that requires tech companies to not just report vulnerabilities to the country’s government within 48 hours of discovery, but also to withhold the same disclosure from China’s overseas counterparts, except for the product vendor. “This converts China’s private sector security research into a state-controlled pipeline that grants intelligence services privileged early access to exploitable vulnerabilities,” RUSI said. Factoring in all of this, the country has also demonstrated the willingness and capability to launch cyberattacks against the critical national infrastructure of political adversaries, according to RUSI. Technical security aside, China’s technological advancements introduce economic risks, too. In some cases, its vendors have developed more capable products than equivalents in the EU or US, and sold them at more attractive prices. This advantage makes it difficult for some countries to justify the extra expense on non-Chinese equipment. In building a global reliance on its products, China could then introduce “unwelcome dependencies,” or cement itself as a dominant player in crucial supply chains, RUSI noted. China has shown in recent years that it is willing to exercise this influence, such as when it threatened Germany with “consequences” for the two countries’ economic ties during the heated 5G debate of 2019. Would a high-risk designation system work? One of the reasons why the think tank is calling for a more considered risk assessment framework for the EU is that there is no guarantee that what the EC is currently proposing in its CSA amendments will have much of an effect. Issuing blanket bans on companies, or countries, does not explicitly address the underlying security issues that make products vulnerable to attack. In other words, even if China were excluded entirely from the EU members’ tech stacks, the other vendors from ‘trusted’ countries have proved that they are unable to deliver penetration-proof software, which would open the door to attacks regardless. Remember, Salt Typhoon’s high-profile attack on US telco networks took place as recently as 2024. It should also be said that CSA-esque designations could apply to US companies, as some countries in Europe see US vendors as similarly risky, albeit for different reasons. Merz’s Germany is concerned about the relationship between the US and EU, for example, and similar concerns about dependence on Chinese technology could easily be applied to vendors in the US, should relations sour. In Spain, US cloud companies dominate, but anti-US sentiment is stronger than many realize, particularly around surveillance concerns. Those, along with higher prices from some non-Chinese suppliers, have reduced Spain’s appetite for ripping out equipment others deem high-risk. “One participant even noted that some officials view US legal instruments such as the Patriot Act as creating equivalent sovereignty risks to China’s National Intelligence Law, a narrative that is flawed when exploring the legislation, but politically convenient,” RUSI stated. The think tank suggested that if it wishes to enact change through policy, the EU must gather “greater economic courage” and a willingness to approach tech procurement as a means to secure its critical infrastructure, rather than “a compliance exercise.” ®

source https://www.theregister.com/security/2026/10/01/eus-hodgepodge-tech-policy-exposes-members-to-chinese-vendor-risks-says-think-tank/5300599
Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. [...]

source https://www.bleepingcomputer.com/news/security/microsoft-says-threat-actors-are-ahead-in-the-early-ai-race/

Thursday, 1 October 2026

Resolute Raccoon is ready to roll out to existing Ubuntu users. Canonical has flipped the switch, and users on 24.04 will start to get offered 26.04.1. Canonical has marked the occasion with an official announcement that it's time to upgrade your desktop. Normally, a given LTS release of Ubuntu starts nagging offering the upgrade to the new release when the following LTS version gets its first point-release. This time around, there has been a substantial delay: Ubuntu 26.04.1 appeared over a month ago. The company announced a small delay in a post ubuntu-announce mailing list when 26.04.1 first appeared, saying: “Users of Ubuntu 24.04 LTS will be offered an automatic upgrade to 26.04.1 LTS via Update Manager a couple of weeks following this release after some planned backports to address regressions in a recent version of rust-coreutils.” The delay is the fault of Rust language which is aiming to replace C, as promoted by evangelistic developers whom Linux grandees castigate until they go away. This is the same Rust uutils bundle that David Uhden Collado recently ported to OpenBSD, but which was swiftly rejected by determined defender of the C faith Theo de Raadt. (Please read the previous two paragraphs in the most sarcastic tone that you can muster.) If you want to upgrade your Ubuntu box, there are two potential methods – one command-line-based, and one using the GUI – but both are easier than the traditional Debian method. First, though, install any and all outstanding updates. For this, we entering the following the shell command, if only because it’s easier to copy-and-paste: sudo apt update && sudo apt full-upgrade -y ; sudo snap refresh Because Canonical uses phased updates, you may see that some updates are “held back”. If you do, you can just run the main command again to get them: sudo apt full-upgrade -y Second time around, it may install a few more. Then reboot, and with any luck you will get offered the Resolute Raccoon upgrade. If you have Ubuntu installed on a relatively small partition, it may be as well to clear the APT package manager’s cache before you start. This can free up a lot of room. On our test VM, where we do this regularly, we got 1 GB back: liam-proven@noble-vbox:~$ df -h / Filesystem Size Used Avail Use% Mounted on /dev/sda2 24G 18G 4.3G 81% / liam-proven@noble-vbox:~$ sudo apt clean liam-proven@noble-vbox:~$ df -h / Filesystem Size Used Avail Use% Mounted on /dev/sda2 24G 17G 5.9G 74% / We reckon a free gigabyte for one command is pretty good. If you don’t get offered the upgrade automatically, run the “Software Updater” tool. If you don’t see it in your preferred app launcher, you can run the update-manager command in a shell. If you have any outstanding updates to your current version, you will be offered them first. Once they are all done, you should see a message saying: “The software on this computer is up-to-date. “However, Ubuntu 26.04.1 LTS is now available (you have 24.04).” Alternatively, if you prefer to do these things from the shell: liam-proven@noble-vbox:~$ do-release-upgrade Checking for a new Ubuntu release = Welcome to Ubuntu 26.04 LTS 'Resolute Raccoon' = The Ubuntu team is proud to announce Ubuntu 26.04 LTS 'Resolute Raccoon'. We’ve cut this to the first few lines – there are some 60 lines of it in full. As we reported when it came out, there are worthwhile novelties in RR. For instance, in our testing on some machines with older Nvidia GPUs which did not work well with 24.04, the now Wayland-only GNOME 50 drove our geriatric video cards just fine. If you use any other desktop, from Cinnamon to Unity, you still get X11. ®

source https://www.theregister.com/os-platforms/2026/09/30/canonical-begins-pushing-resolute-raccoon/5300225
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor. [...]

source https://www.bleepingcomputer.com/news/security/russian-state-hackers-use-new-redflick-technique-to-push-malware/
The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. [...]

source https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/
More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform's security measures to prevent accidental leaks of sensitive data. [...]

source https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/

Wednesday, 30 September 2026

The first systems powered by AMD's Gorgon Halo system-on-chip (SoC) platform have arrived, boasting up to 192 GB of unified memory on board. That's enough to put DeepSeek V4 Flash on your desk if you can afford to pay a hefty premium for all that RAM. GMKtec's EVO-X5 Pro is among the first to feature the House of Zen's top-specced Ryzen AI Max+ 495 SoC — you can see why we're just going to call it Gorgon Halo from here on out — but with regular pricing starting at $6,799, all that memory doesn't come cheap. But for local AI enthusiasts and perhaps privacy-conscious small businesses, it might be worth it just to run larger, more capable models from the security of their homes and offices. At 4-bit precision, Gorgon Halo is equipped with enough memory to run models to around 345 billion parameters on Linux or 320 billion parameters on Windows. The difference here comes down to memory partitioning. On Windows, you'll need to allocate 160 GB of memory to the GPU, while the Linux kernel and AMD's GPU drivers enable users to take advantage of nearly all of the available memory. This puts high-profile frontier models like the 284 billion parameter DeepSeek V4 Flash or Z.AI's 320 billion parameter GLM-5.3-Flash within reach of Gorgon Halo customers. The chip Announced earlier this year, Gorgon Halo is essentially a factory overclocked version of the Strix Halo APU that powers AMD's AI Halo workstation that we reviewed this summer. Both chips can be had with up to 16 Zen 5 cores, a 40-compute-unit integrated GPU, and an XDNA 2-based NPU to power all the Copilot+ features you didn't ask for but Microsoft is pushing on you anyway. The big difference between the chips is that AMD has bumped up the clocks by about 100 MHz across the board, and Gorgon Halo now supports 192 GB of faster 8,533 MT/s LPDDR5x memory compared to Strix Halo's 128 GB of 8,000 MT/s. In terms of performance, we don't expect the clock bump to make a meaningful difference. With that said, the faster memory could help a little bit for local AI enthusiasts. Large language model (LLM) inference — that is, the process of running pre-trained models — is predominantly memory bound. That means the faster your memory is, the faster the system can generate tokens. But while Gorgon Halo does achieve high memory bandwidth at 273 GB/s, that's only about 6.5 percent faster than Strix Halo at 256 GB/s. At most, you can expect to see a few more tokens a second on highly optimized models. Priced out of the market Gorgon's main attraction is really the prospect of higher memory capacity. But as we mentioned before, the ongoing memory shortage has not been kind to consumer electronics. A year ago, a 128 GB Strix Halo box would have set you back between $2,000 and $3,000 depending on OEM. DDR5 prices have skyrocketed since then and by the time AMD launched its AI Halo workstation this summer, prices had jumped to $4,000. With 50 percent more memory, you can expect Gorgon Halo-based products to be even pricier. The GMKtec unit is already 64 percent more expensive and the brand is usually on the more affordable side of things. More premium brands like Framework and notebooks like HP's ZBook Ultra G3a will likely command a steep premium. Unfortunately for AMD, there's not a lot that can be done. LPDDR5x is in short supply thanks to the AI boom. Each NVL72 rack Nvidia sells is packed with between 36 and 54 TB of the stuff, and that's just CPU memory. The situation is only going to get worse as AMD embraces LPDDR5x for its own AI-optimized Verano Epycs. If you need a lot of memory right now, you're in for a lot of pain, and the situation isn't expected to improve anytime soon. Earlier this year, Samsung warned that memory supplies are likely to remain constrained through 2028, which is bad news for everyone including AMD's top competitor Nvidia. Nvidia has also seen the price of AI workstations based on its GB10 SoC roughly double over the past year, jumping from $3,000-$4,000 a year ago to $6,000-$8,000 today, which doesn't bode well for its Windows SoC debut. Announced at Computex late this spring, Nvidia's RTX Spark is a family of premium Windows systems from major OEMs based around the same GB10 SoC and offering up to 128 GB of memory capacity. Considering these systems will be offered as both mini PCs and notebooks, we wouldn't be surprised to see them command a premium over existing GB10 boxes. Once again, this puts AMD in a position to undercut its competitor by offering more memory for less, but it's awfully hard to cross shop when you can't afford either option. ®

source https://www.theregister.com/personal-tech/2026/09/29/amds-192-gb-gorgon-halo-prices-might-leave-you-petrified/5299875
The public still doesn’t know who is abusing a critical Citrix vulnerability exploited as a zero-day weeks before disclosure, but we now know that the unknown digital intruders have used CVE-2026-88772 to break into government agencies, financial services firms, education organizations, and legal and professional services sectors across North America and Europe. And everyone agrees that the vendor took way too long to disclose the security holes. GreyNoise said it spotted an attempt to exploit CVE-2026-88771 against a Citrix NetScaler Gateway on September 24. Google researchers, meanwhile, said the CVE-2026-88772 campaign has been ongoing “since at least early September.” “Why Citrix took so long to disclose these vulnerabilities is a question only Citrix can answer,” Benjamin Harris, founder and CEO of exposure management firm watchTowr, told The Register. Citrix did not respond to our questions about this. “The vulnerabilities were discovered during incident response and forensic investigations at organizations already compromised, meaning both the exploitation and Citrix’s awareness of it predated public disclosure,” Harris said. “Citrix has a history of delaying the publication of vulnerabilities, even when they’re being exploited in the wild and affecting customers.” So if you use Citrix NetScaler ADC and NetScaler Gateway appliances, and haven’t already applied the security updates, do that ASAP. But first, check your systems for signs of compromise, warns Mandiant Consulting CTO Charles Carmakal. “Given the active exploitation, NetScaler customers should prioritize examining their systems for compromise *before* upgrading/patching,” Carmakal said on LinkedIn. “If you find evidence of web shells or other malicious files, please preserve evidence and investigate the scope of the compromise. Patching alone may not eradicate the threat actor from your environment.” No attribution - yet Citrix disclosed eight CVEs on Sunday with the worst of the bunch – CVE-2026-88771 and CVE-2026-88772 – earning critical 9.5 CVSS scores. “Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed,” the vendor said. CVE-2026-88771 can allow an unauthenticated attacker to execute arbitrary commands remotely. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled, as it is by default on VPN virtual servers. But by the time Citrix issued security advisories and warned customers about the vulnerabilities, they were already under attack. “No attribution has been made public, and we have yet to identify a clear trend among targets by industry or organization size,” Harris said. “Historically, NetScaler vulnerabilities have been exploited by both state-sponsored groups and ransomware operators.” WatchTowr on Tuesday published a technical writeup about CVE-2026-88772, plus a detection artifact generator for Citrix users to determine if they are vulnerable and to help with remediation. Also on Tuesday, Google’s threat intel businesses provided additional details about the exploitation campaign’s targets and the attacker’s custom malware. “We have observed evidence that organizations in North America and Europe in the government, financial services, education, legal and professional services sectors were likely impacted by this exploitation campaign, which has been ongoing since at least early September,” Google Threat Intelligence Group and Mandiant said in an advisory. Custom malware After analyzing the intruder’s post-exploit toolkit, the malware hunters found never-before-seen malware used to establish persistent root access and proxy traffic into internal corporate networks. The custom malware includes WHIPSHOT, a PHP web shell, and SLAPSHOT, a TCP tunneling tool written in Python. WHIPSHOT is disguised as a Debian package and hides Base64-encoded command-and-control payloads in native HTTP headers. It functions as an HTTP transport bridge for SLAPSHOT, which accepts commands from WHIPSHOT and forwards arbitrary TCP streams to internal hosts. Supported commands include: open, which establishes an outbound TCP socket to a target host and port. push, which writes data to an open session. pull, which polls and reads data from an open session socket. exch, which sends and receives command-and-control data to and from an open session socket. close, which terminates a specified network session. ping, which performs a basic health-check verification. “In at least one observed intrusion, the threat actor routed traffic through this proxy to manually conduct internal reconnaissance and credential theft,” the threat intel teams noted. Google did not immediately respond to The Register’s questions about the campaign, including how many exploitation attempts and successful intrusions its threat hunters observed. Its advisory notes that the Citrix campaign “underscores the continued targeting of edge devices to gain initial access to victim networks, a trend that GTIG has tracked across a range of threat actors.” Security and networking vulnerabilities accounted for about half of enterprise-related zero-days in 2025, according to Google’s count. Attackers love edge devices - application delivery controllers, VPN gateways, and firewalls - because they provide direct access from the open internet to corporate networks, allowing attackers to bypass endpoint detection tools and other security layers. NetScaler, in particular, is notoriously buggy. Attackers exploited another critical NetScaler vuln in March. A year earlier, Citrix disclosed multiple zero-days in the same product. ®

source https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. [...]

source https://www.bleepingcomputer.com/news/security/former-us-air-force-members-sent-to-prison-over-bec-attacks/

Tuesday, 29 September 2026

Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. [...]

source https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/

Monday, 28 September 2026

The AI safety debate advanced at high speed over the weekend, amid new allegations that rogue agents have behaved more badly than first thought – and in greater numbers. The fun started on Friday when OpenAI quietly disclosed it had paused training of its most advanced models. The AI upstart buried that news in a “misalignment report” – that’s OpenAI-speak for its reports on rogue agents – titled “An agent used DNS to reach an external chatbot.” The good news is that the agent involved in this incident never reached the open internet. The bad news is that the agent, which was attempting to complete a search-based training task, was able to reach the chatbot due to insufficient DNS filtering in a training sandbox. Or as OpenAI put it, “a gap in our internet-access restrictions” – which was also a problem in the Hugging Face attack. “The incident exposed a gap in our controls over network restrictions,” the report reads. “We therefore stopped the affected training run and have subsequently decided to pause all other training, evaluation, and inference with tool-use (defined broadly) for our most capable models until we have both validated that the gap is resolved and performed additional red-teaming of the system.” Also on Friday, AI startup Parse published an analysis of the Hugging Face attack that the authors claim revealed new details including that OpenAI’s agent swarm gained credentials to Docker Hub and built modified versions of existing images they hoped would make it easier to complete their capture the flag mission. The agents also mapped Hugging Face’s Kubernetes environment. Friday got worse for OpenAI after the New York Times reported that its agents also “meddled with the websites for the Education Department, the Commerce Department and the Securities and Exchange Commission.” OpenAI acknowledged the incidents. The company also admitted “agents in our research environment transmitted training and evaluation data while using third-party services.” That mess saw 53 user-generated images posted to image hosting sites. OpenAI CEO Sam Altman responded by admitting that his company’s investigations into rogue agents “have not been as fast as we would have liked but we are trying to balance our desire for transparency with gaining a clear understanding from petabytes of agent activity logs, and working with impacted organizations.” One of those impacted organizations is the Australian government, which last week revealed it was the target of over-eager OpenAI agents that inappropriately accessed a healthcare research data portal. Over the weekend, Australia indicated it wants Altman and Anthropic CEO Dario Amodei to appear before a Senate inquiry. Australian leaders have softened their rhetoric on the incident, with deputy prime minister Richard Marles describing it as “minor” and akin to “climbing a fence” rather than cracking layers of security controls – perhaps because members of the opposition are suggesting that lax cybersecurity was to blame. If Altman and Amodei do front Australia’s Senate, they may face a new line of questions after Axios reported that their companies are investigating “tens of thousands” of worrying incidents. That level of agentic misbehavior sounds like the sort of thing that regulators might consider strong evidence of products being unsafe. Two very important people – Chinese president Xi Jinping and US president Donald Trump – seem unworried, as the AI-related result of their summit meeting last week was to establish a “China-U.S. AI Dialogue to exchange views on risks and benefits related to AI” plus “a bilateral communication channel for AI incidents.” That sounds like a hotline the two nations can use to inform each other of agentic incidents that either could see as signs of ill-intent. The two nations also decided their respective militaries will “conclude a memorandum of understanding on crisis communication and prevention as soon as possible.” China’s AI giants, meanwhile, remain silent on the extent and results of any tests they have conducted with agentic tools. ®

source https://www.theregister.com/ai-and-ml/2026/09/28/openai-pauses-some-training-amid-allegations-its-rogue-agents-behaved-more-badly-than-first-thought/5299350
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities. [...]

source https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-citrix-flaws-by-wednesday/
E-commerce giant Amazon.com is preparing to launch drone deliveries in Australia and other nations. “As Prime Air evaluates Australia and other countries, we are hiring a Head of Regulatory Approvals, Australia – the person responsible for navigating Australia's aviation regulatory system and securing every approval required to deliver to Australian customers by drone,” reads a recently published job ad. Whoever gets the gig in Australia will report to someone who holds the title “Leader, Prime Air Expansion – Asia Pacific.” The Register asked Amazon to comment on the ad, and which other Asian countries it plans to enter. The company had not responded at the time of writing. Whoever gets the job “will be measured by the approvals you obtain, the timelines you hit, and – ultimately – Australian customers receiving drone deliveries.” That wording suggests Amazon intends to operate Prime Air in Australia and is doing rather more than market evaluations. In August, Amazon said it plans to operate Prime Air drones in “nearly” 500 cities and towns across the USA this year. Meta and Singapore sling scammers Meta last week announced that information-sharing with Singapore Police helped the social media giant to identify a new variety of attack and led it to take action against more than 113,000 entities and pages connected to fraud and scams on Facebook and Instagram. Meta calls the new scams calls “shell pages” and says they “look empty and harmless” because they don’t include ads or content that violates Zuck’s T&Cs. “But scammers had pre-built infrastructure, ready to be activated for scam campaigns at a moment’s notice,” Meta says. “Working from SPF’s signals, in July 2026, we took action against over 3.6 million shell pages before they could be used – and we’re now pursuing further disruptions against this type of scam.” “Rather than responding to individual reports, this collaboration focuses on proactive network disruption – where SPF information helps Meta’s investigators identify and dismantle entire ecosystems of bad actors,” the company asserted. Meta didn’t say how scammers could sign up for 3.6 million pages without it noticing. Nothing has a plan to conquer India’s consumer tech market Consumer electronics outfit Nothing, which has carved out a small niche with well-priced Android devices, has decided to spin out its Indian subsidiary CMF. CEO Carl Pei explained the move as a bet on India’s growing electronics manufacturing industry spurring demand for local consumer tech brands. “Every country that has manufactured consumer electronics at scale has eventually produced its own global champions. Japan did. Korea did. China did, and I watched it happen over the better part of a decade living there,” he wrote. “India is next. It's already the world's second largest smartphone manufacturer, with the largest youth population on earth and one of its deepest software talent pools. What it doesn't have yet is a global consumer electronics brand of its own. That will change. The only questions are when, and how.” Pei thinks the how is spinning out CMF, a Nothing sub-brand that makes budget-priced phones, audio kit, and smartwatches. Bangkok floods – brace for supply chain impact When heavy rains and subsequent floods struck Thailand’s capital city Bangkok in 2011, facilities operated by hard disk manufacturers Western Digital and Seagate experienced damage that disrupted production for months. Bangkok was again hit by rain and severe floods last weekend, but to date The Register can find no evidence of problems at major tech companies. Western Digital and Seagate have not announced any issues, while hyperscalers Google, Microsoft, and AWS also report their local infrastructure is operating normally. Thailand’s government announced a two-day holiday to help residents clean up after the flood, which saw much of Bangkok under 30 centimeters or more of water. India’s top unis ban 22 vendors – maybe including Oracle – from recruiting their grads India’s 23 Institutes of Technology (IITs) are famed for producing exceptional technology talent that tech companies often strive to hire. However 22 companies – reportedly including Oracle – won’t be considered for graduate recruitment programs due to not following through on hiring promises. India’s Economic Times reports that the companies offered over 150 jobs to IIT students, but didn’t make the appointments. Another source claims Oracle is one of the 22 companies that the All IITs Placement Committee, the body which runs graduate placements, has decided not to deal with for two years. ®

source https://www.theregister.com/personal-tech/2026/09/28/amazon-evaluating-drone-deliveries-in-australia-asia/5299343
OpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on the company's website. [...]

source https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-preparing-o-an-always-on-chatgpt-assistant-that-could-handle-email/

Sunday, 27 September 2026

Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins, connectors, agents, and more. [...]

source https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-turns-claude-into-an-ai-marketplace-with-2-000-plus-plugins-and-connectors/
Thirty years after Apple abandoned Copland, its doomed attempt to create a modern Mac operating system, a new emulator lets you try the final developer build in your browser. Copland was intended to replace Apple's System 7 with a PowerPC-native operating system built around a microkernel, protected memory, and preemptive multitasking for system services. Three unfinished developer builds – D7E1, D9, and D11E4 – are publicly known. Relatively few people outside Apple's developer community in the mid-1990s ever had the opportunity to use them. Now you can boot Apple Copland D11E4 in your browser and explore the unstable prerelease OS without installing anything. Developer Michael Steil, also known as Mist, made it possible with an experimental fork of the DingusPPC Power Mac emulator. Steil says the 11 patches that enable DingusPPC to boot Copland were written with AI assistance. The upstream project does not accept AI-assisted patches, so the fixes would have to be rewritten before they could be incorporated. Don't expect miracles. The emulator runs D11E4, the final build Apple distributed to developers, dating from June 1996. It remains very much unfinished: if the emulated system hits an assertion, it drops into a debugger and asks the user to continue manually. Apple CEO Gil Amelio had demonstrated Copland at the company's 1995 Worldwide Developers Conference, but the project never approached the stability required for release. Much of Copland existed as plans and documentation rather than finished code. In 2009, Steil assembled an extensive archive of that material in Apple Copland Reference Documentation. There was also a planned successor to Copland, codenamed Gershwin, but it remained nothing more than a plan. The modern Gershwin desktop we covered a year ago is a nod to that nonexistent OS. Anyone familiar with the classic Mac OS of the late 1990s will recognize parts of Copland, and for good reason. Copland overran so badly that Amelio recruited the late Ellen Hancock from IBM as Apple's chief technology officer and tasked her with getting the project back on track. After reviewing its progress, she instead recommended cancelling it and acquiring an operating system elsewhere. Apple considered several alternatives, including acquiring Be for BeOS and working with Sun on a system based on Solaris. It ultimately bought NeXT, bringing Steve Jobs back to the company along with NeXTSTEP. Hancock was later sidelined under Jobs and resigned in 1997. Apple acquired NeXT at the end of 1996, just months after cancelling Copland. The first developer release of its NeXTSTEP-based successor, Rhapsody, followed in 1997 – continuing the musical codenames, if not the code. Rhapsody evolved into Mac OS X Server 1.0 in 1999 and the consumer release of Mac OS X 10.0 in 2001. Replacing the Mac OS architecture took years. While that work continued, Apple folded some of Copland's more mature components into updates to its existing operating system. Mac OS 8, released in 1997, gained Copland's Platinum interface and a PowerPC-native, multithreaded Finder. Its Appearance control panel supported themes, although Apple shipped only Platinum. Renaming what had been planned as Mac OS 7.7 also helped Apple end the clone program, whose licensing agreements covered System 7. Mac OS 8.1 followed in 1998 with HFS+, Apple's new format for larger disks. Later that year, Mac OS 8.5 became the first PowerPC-only release. Further pieces of Copland's work appeared across Mac OS 8 and 9, allowing Apple to improve the old platform while Mac OS X was being prepared. When Apple bought NeXT, NeXTSTEP already ran on Motorola 680x0, Intel x86, Sun SPARC and HP PA-RISC processors. That portable foundation later helped Apple move the Mac to Intel, while OS X became the basis for the operating systems used by the iPhone and iPad. Apple's future might have looked very different had Copland succeeded. Now it's easier than ever to see why it didn't. ®

source https://www.theregister.com/os-platforms/2026/09/27/apple-buried-copland-30-years-ago-now-the-failed-os-boots-in-a-browser/5299201
Big AI has a problem. Its companies must ingest other people’s work. You know, books, news stories, photographs, code, websites, that one original meme you came up with, and practically everything else on the internet to train its large language models (LLMs). We all know that. We also know that AI companies hate paying for any of it, obeying the licenses attached to it, or, God forbid, sharing their revenue with the companies and people who created the work in the first place. Recently, Big AI's default way of doing business: "Take it now, argue about legality later," has become more in your face than ever. Look, for example, at the copyright fight between The New York Times and OpenAI and Microsoft. According to 404 Media’s reporting on recently unsealed court documents - arguments from the plaintiffs that the court has not yet ruled on - Microsoft allegedly knew what it was doing when it was importing the internet willy-nilly. Microsoft's Director of Applied Science, Dr. Brent Hecht, was quoted in the news plaintiffs' 92-page combined brief as saying: the case was about “an astonishing theft of unprecedented proportions." Indeed, it was possibly the “largest theft of labor in human history,” he was quoted as saying in the summary judgment brief from the journalists' lawyers [PDF].This, mind you, wasn't a comment by a member of the press; it was from a senior Microsoft staffer. Hecht wasn't the only one at Microsoft who commented. In an internal Microsoft policy document also quoted in the court papers, the authors admitted generative AI could “significantly disrupt the employment of the very people who generated the data on which the foundation model was trained [because] LLMs are a product that destroys its supply chain.” That, in turn, leads to model collapse. Ironically, AI is killing the content-creator goose that lays the gold eggs of worthwhile content. Judge Sidney H. Stein of the US District Court for the Southern District of New York has not yet issued a decision on the case. OpenAI and Microsoft are actively disputing the plaintiffs' allegations under a "fair use" defense. They contend that using public articles and books to train large language models helps push forward public knowledge, and isn't acting as a "unlawful economic market substitute". But the statements the documents cites are real. Big AI knows it needs the content. Some of the companies concerned don't give a damn; money now, worry later is their motto. Those who can look past the revenue numbers are well aware they're engaged in what Microsoft itself called a “doom loop” of AI content strategy in those unsealed court documents. Will that stop them? Nah. According to the filing [PDF], which refers to sworn deposition testimony of OpenAI’s own corporate representative, it also testified that its LLMs were happy to vacuum up other people's work even when a paywall nominally protected it. Its rep was quoted as saying they were unaware of “any effort to detect paywall content in its training datasets” or “to remove paywall content from its training datasets.” When OpenAI cofounder Greg Brockman was told OpenAI could hack its way through the firewall, he responded, “ah, nice.” Whether or not these statements are found to be reflective of a wider attitude, similar attitudes prevail amongst Big AI. Such policies could eventually come back and bite the LLM makers; it's already affecting the market for journalism, fiction writing, graphics creation, anything that demands humans actually get paid for producing original work. But Big AI just doesn't want to pay for it. That's not a side effect. It's the business model. Joe User couldn't care less. They just want a quick answer that sounds right. Some of them couldn't care less about getting the right answers. As for looking deeper to see if the information they're regurgitating is accurate, forget about it! As an OpenAI software engineer put it: “No matter how prominently we show the links, users won’t click.” Well, I click. That's a big reason why Perplexity is my AI of choice. It's not that it gives a more reliable answer. No, it's that, unlike most LLMs, Perplexity provides sources and links, and I check them before accepting what it tells me. But then I'm a journalist whose degrees are in history, where my professors drummed into me that you always - always - look at the primary sources. Big AI takes the same approach with its code generators. The US Ninth Circuit recently handed GitHub, Microsoft, and OpenAI a narrow win in the Doe v. GitHub lawsuit. The court ruled that the plaintiffs hadn't established a claim under one particular provision of the Digital Millennium Copyright Act (DMCA), which concerns the removal or alteration of copyright-management information (CMI). In short, the court said that generating new code without including CMI is not necessarily the same thing as removing or altering copyright information from an existing work. Judge Eric Miller wrote: “One who creates a new work and fails to include CMI cannot be said to have ‘removed’ or ‘altered’ anything.” This ruling didn't establish that GitHub Copilot or any other coding model may train on every open source project without restriction. It didn't determine that copying source code into a training set is always fair use. It did not decide that generated code cannot infringe copyright. And it certainly did not repeal the GPL, Apache, BSD, MIT, or any other open-source license. After all, open source isn't a synonym for “do whatever you want with it.” It just seems that way when AI gets its hands on open source code. That's the problem with AI-generated code. A programmer who receives a Copilot suggestion is very unlikely to check whether the GPL covers the code, or whether Apache covers the snippet from a library. The developer certainly can't tell which license terms may apply to the code that just popped up from Opus 5.5 or GPT 6. As the guy from OpenAI said, people don't click the links, and in AI-enabled programming pipelines, they don't even have the links anyway. An open source-savvy attorney friend of mine has a bigger worry than this narrow decision. He told me that what gives him "pause is a broader trend. There are multiple cases where parties are litigating open source licenses as contracts rather than as the IP / copyright licenses they were written to be. Contract theories let a plaintiff sidestep the questions copyright forces you to answer. 'Do you own the work? Is it protectable expression? Was it actually copied?'" He added: "Those questions are the foundation on which licenses are built. Open source licenses are grants of permission to use someone's intellectual property. If a case can't show that any intellectual property was owned or infringed, it's fair to ask whether enforcing the license as a bare contract supports open source licensing or quietly turns it into something else." With AI in the mix, this issue will eventually become one of those nasty IP matters developers hate, businesses want to avoid, but that courts must settle with expensive lawyers whose hourly rates worry even AI millionaires. After all, IP uncertainty isn't a minor paperwork issue. It is a supply-chain security and compliance problem. If you use AI-generated code, you may be importing unknown legal obligations into your software. If you are an open-source developer, your work may be used to improve a proprietary service that returns code without provenance, attribution, or meaningful reciprocity. And if you are a customer, you may be relying on software whose origins no one can fully explain. The Ninth Circuit ruling didn't solve any of that. We're in for a lot more open source litigation that will make SCO vs. the known Linux universe look like a kerfuffle over a parking ticket. Then there is the latest wrinkle: A federal antitrust lawsuit against Anthropic, OpenAI, SpaceXAI, and Google. The plaintiffs allege the companies coordinated to slow the development of advanced AI systems. The lawsuit points to public statements from AI leaders all calling for coordination to “pace” frontier AI development over a single weekend. Anthropic CEO Dario Amodei has argued for industry-wide coordination to slow frontier development. OpenAI CEO Sam Altman, Google DeepMind co-founder Demis Hassabis, and Elon Musk have also publicly expressed versions of the view that powerful AI systems need controls and careful deployment. On its face, that sounds sensible. AI safety is a real issue. Anyone who says otherwise has not been paying attention. But there's a huge difference between all big AI players agreeing among themselves on how quickly a market should develop. This looks like an awful lot like competitors deciding who gets to compete, what they get to build, and when they may build it. The Big AI companies all look like good guys while simultaneously strangling their smaller competitors. To mere mortals, this may sound like an open-and-shut case. It's not. Antitrust law requires evidence of an agreement and actual harm to competition; executives making similar public comments is not enough. The plaintiffs will need considerably more than quotes about AI safety or responsible development to win. Besides, if they do win, so what? What recently looked like huge antitrust wins has had its teeth pulled when it came to actually punishing the likes of Google and its ad business, or its earlier "lose the case, win the settlement" with Google Search. Do you see the pattern here? Big AI has effectively argued that copyright law, open source licenses, and competition rules shouldn't slow them down. When creators object, they are told that training is fair use. When developers object, they are told that generated code is new code. When competitors object, they are told security requires the largest companies to coordinate. Funny how the answer always seems to leave Big AI with the data, the market, and the money, isn't it? The central issue isn't whether AI should be allowed to develop. It will develop. The issue is whether the companies building it should be allowed to treat everyone else’s work as a free raw-material supply, then use the resulting products to take away the creators’ traffic, revenue, and bargaining power. Unless we stop Big AI now from this land grab with GPUs, only a handful of trillionaires will really benefit from AI, with the rest of us becoming serfs in a 21st-century post-technology feudal system. ®

source https://www.theregister.com/columnists/2026/09/27/big-ais-content-problem-take-the-work-keep-the-money/5299007
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. [...]

source https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/

Saturday, 26 September 2026

The CEO of crypto exchange Bitget has confirmed that a cyberattack with all the hallmarks of a North Korean operation resulted in approximately $387.5 million worth of digital assets being stolen from the exchange’s wallets. Bitget initially estimated the loss at $351.6 million, but later revised the figure to $387.5 million after identifying additional affected assets on Zcash and TRON that were not included in the initial estimate. Blockchain intelligence company Arkham published its preliminary observations of the attack, estimating at the time that roughly $350 million was stolen and that $228 million left Bitget’s wallets in 18 minutes, between 18:58 and 19:16 UTC. Arkham said $153 million worth of XRP was taken from a wallet it identified as a Bitget cold wallet, while the stolen assets also included $66.2 million of ETH, $34.8 million of USDT, $12.9 million of USDC, and $12.8 million of Tether Gold on Ethereum. Other affected networks included Arbitrum, Optimism, BNB Smart Chain, Avalanche, and Base. However, Chen said Bitget's cold wallets and customer balances remained unaffected, while its User Protection Fund held more than $464 million worth of assets. “To be transparent about our financial position: beyond the $464M+ Protection Fund – all held in publicly verifiable wallets – Bitget holds over $1 billion in its own assets,” Chen said. “User funds are covered on a 1:1 basis.” Chen also explained that Bitget Wallet, the company’s self-custody product, operates on infrastructure separate from its exchange, and Bitget users can still make deposits and trade their tokens, despite withdrawals being temporarily suspended while additional security checks are completed. Bitget said it also engaged incident response giant Mandiant and blockchain security outfit SlowMist to help with the investigation into the attack. Chiefs at fellow exchanges rallied around Bitget in support. “MEXC stands ready to support Bitget in any way we can,” said CEO Vugar Usi. “In moments like this, the industry is stronger when we stand together.” Binance co-CEO Richard Teng also pledged Binance's support for Bitget, saying it had shared intelligence and helped trace the stolen funds. Ben Zhou, CEO of Bybit, said his company was on standby to “help in any way we can,” noting that Bitget helped it out following the $1.5 billion Bybit theft the FBI attributed to North Korea in February 2025. How and who Root cause analyses typically take some time, although according to Chen, Bitget's security team has already identified the wallet service's backend system as the source of the unauthorized transfers. “Hackers breached a key backend system of the wallet service and exploited it to forge transfer information and invoke the authorization signing process, thereby transferring funds out,” she said. “The possibility of private key leakage can be ruled out – this means a more severe risk scenario has been eliminated. Damage control has been confirmed as complete, and there is no risk of further fund outflows from the platform. “The specific intrusion methods used by the hackers are still under technical investigation, and a full report will be released upon completion of the investigation.” Chen did not go into too much detail about the alleged links to North Korean state-sponsored attackers having a hand in the attack, but said “IP behavioral patterns and on-chain signatures” suggest it was Kim’s cronies at work. It would come as little surprise if North Korea was indeed the culprit behind the attack. The regime has a knack for hacking crypto exchanges. The aforementioned hit on Bybit was perhaps North Korea’s biggest crypto haul, although similar lucrative ventures attributed to North Korean attackers have come at the expense of DMM Bitcoin and WazirX, among others. Bitget was founded in 2018, registered in the Seychelles in 2022, and operates through regional hubs across the world. Some netizens have speculated that the timing was especially inconvenient, with the transfers detected at 18:31 UTC – 02:31 on September 25 in Singapore and China, the first day of China’s three-day Mid-Autumn Festival holiday. The festival is also widely celebrated in Singapore, although it is not a public holiday there. The Register asked Bitget whether this played a role in the attack and its remediation but it did not respond. As of Friday, Bitget is offering bounties to those who help freeze or recover the stolen funds. It said eligible participants could receive 5 percent of the funds their efforts successfully freeze or recover.®

source https://www.theregister.com/cyber-crime/2026/09/25/bitget-blames-north-korea-for-3875m-crypto-wallet-raid/5299218

About

Privacy Policy

ShortNewsWeb

Blog Archive

Recent Comments

Popular Posts

Translate

My Blog List

Popular

System Admin Share

Total Pageviews