Saturday, 8 August 2026

Scientists at the UK Atomic Energy Authority (UKAEA) say that they have overcome plasma instability issues standing in the way of commercial fusion power plants. The boffins overseeing the MAST (Mega Amp Spherical Tokamak) Upgrade installation at UKAEA's Culham Campus in Oxfordshire conducted a fifth series of experiments on it during 2025 and 2026 and produced more than 1,100 fusion plasmas. During these experiments, the team demonstrated the highest pressure ever achieved with the MAST Upgrade machine, without the super-hot plasma destabilizing, they say. One of the challenges they set out to address is to figure out how to suppress instabilities known as Edge Localised Modes or ELMs. These are described as “sudden bursts at the plasma’s outer edge” that can cause a loss of plasma pressure and also lose up to a tenth of its stored energy in a single event. Over time, these occurrences will damage the tokamak’s inner wall and exhaust components, and were therefore seen as a serious obstacle to commercial viability. To cure this, the team adopted two techniques already previously tested to avoid these damaging heat bursts; Quasi-Continuous Exhaust mode (QCE-mode) and Resonant Magnetic Perturbations (RMP). With QCE, the plasma edge experiences high-frequency, low-amplitude filaments that act to bleed off pressure before it can build to a destructive level. Likewise, RMPs use a magnetic field to induce small perturbations at the edge of the plasma that bleed off the pressure leading to ELMs. The team also accessed two additional stable operating regimes known as Quiescent H-mode (QH-mode) and I-mode (Intermediate-mode), improved plasma confinement techniques that deliver better energy confinement while mitigating issues associated with large ELMs. QH-mode is understood to tackle ELM using an edge electromagnetic instability called the Edge Harmonic Oscillation (EHO) to steadily remove excess heat, while I-mode is a confinement technique that features a steep thermal barrier at the edge that allows particles to escape, again preventing the buildup of pressure. The Culham scientists also claim to have developed a technique for controlling the plasma’s position. This involves measuring visible light created by deuterium emitted from the machine’s upper and lower outer divertors (the exhaust system), allowing minute positional imbalances to be detected in real-time. Detecting changes in position is a step towards automated, real-time control systems that future commercial power plants will need to operate without constant manual intervention, according to the team. The series of experiments also explored “negative triangularity” plasma shapes that allow high-power operations without ELMs. This is said to be an approach being closely watched by the international fusion community. This MAST Upgrade installation is set to get further enhancements this year. These will include two new neutral beam injectors, doubling the machine’s heating capacity, and the installation of an Electron Bernstein Wave (EBW) system that will provide an additional 1.6 MW of heating power. Following this further upgrade, a sixth series of experiments is planned for 2028. EBW systems use high-frequency, electrostatic plasma waves to heat and drive currents in dense fusion plasmas, and the technology is planned for use in STEP, (Spherical Tokamak for Energy Production), the UK’s pilot fusion power plant to be built at the site of a former coal power station in Nottinghamshire. “These findings take us another step closer to practical fusion energy,” claimed James Harrison, head of MAST Upgrade science at UKAEA. “The results genuinely shape the design of future fusion power plants. Accessing four stable high-performance plasma regimes demonstrates that MAST Upgrade is producing science at the leading edge of what is possible.” Earlier this year, the UKAEA published a roadmap of targets it wants scientists to hit before the end of the decade, in order to drive forward development of working commercial fusion reactors. Reg readers will no doubt be aware of the old chestnut that working fusion power is perpetually 30 years away, but there have been developments in recent years, such as “ignition” being achieved at the National Ignition Facility (NIF) at Lawrence Livermore National Laboratory (LLNL) in California, while UK fusion firm Tokamak Energy said it expected to deliver commercial fusion energy in the next decade. ®

source https://www.theregister.com/science/2026/08/07/brit-boffins-boast-of-beating-barriers-to-building-fusion-power/5284882
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]

source https://www.bleepingcomputer.com/news/security/framework-tally-disclose-metabase-data-theft-attacks/
Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. [...]

source https://www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/

Friday, 7 August 2026

Not content with nuclear reactors on land, the US is backing an international push to put atomic power plants aboard civilian ships and floating platforms. The US will host the launch of the International Atomic Energy Agency's (IAEA) Atomic Technologies Licensed for Applications at Sea (ATLAS) initiative in Washington, DC, on August 26 and 27. ATLAS aims to tackle the legal, regulatory, safety, security, and liability problems that stand between maritime reactors and commercial deployment. Ahead of the launch, the US will hold an "Industry Day" on August 25 to showcase technology from American nuclear and maritime companies hoping to take a share of any future market. US Secretary of Energy Chris Wright linked the event to the Department of Energy's broader drive to deliver oodles of extra atomic power for AI datacenters and other industries. "DoE remains focused on unleashing American energy dominance, accelerating innovation, and advancing sources of energy that are affordable, reliable, and secure for the American people," he said. "Hosting the launch of ATLAS supports this critical mission, positioning the US nuclear and maritime sectors at the forefront of advanced energy innovation, while promoting safety and security for the United States and the world." The initiative covers civilian nuclear-powered ships and floating power plants, with the latter potentially supplying coastal communities or energy-hungry industrial processes such as desalination. The DoE is pinning its hopes on small modular reactors (SMRs), whose high energy density and long operating cycles could suit ships and offshore power installations. America is no stranger to reactors afloat. Every active US Navy aircraft carrier is nuclear-powered, giving it almost unlimited range without frequent refueling. The US Navy also used to operate nuclear-powered cruisers, such as the Virginia class, but these were retired after the end of the Cold War because they were costly to run. Civilian nuclear ships are also not entirely new. NS Savannah was the first nuclear-powered merchant ship when it was launched back in 1959, but again proved costly to run. Perhaps the IAEA hopes that SMRs will make atom-driven civilian ships more economical. Russia operates the world's only floating nuclear power plant. The Akademik Lomonosov is a barge-like vessel whose two KLT-40S reactors can generate a combined 70 MW of electricity. Putting a reactor on water changes the risks rather than making them disappear. The surrounding sea provides a vast heat sink for cooling, but a plant moored in a remote location may have limited access to emergency backup power, according to one assessment. However, any accident might also see radioactive contamination of the marine environment near the damaged reactor, which could seriously affect the coastal community the nuke was meant to be serving. "The global maritime sector is at a critical turning point, facing urgent pressure to sustain long-distance, high-speed operations while ensuring reliability and energy security," said IAEA Director General Rafael Mariano Grossi. "Small modular reactors offer a safe and viable option for maritime transport and offshore energy systems – delivering high energy density and long operating cycles that eliminate the need for frequent refueling." ®

source https://www.theregister.com/science/2026/08/06/uncle-sam-aims-to-help-nuclear-energy-find-its-sea-legs/5284179
Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. [...]

source https://www.bleepingcomputer.com/news/security/new-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes/

Thursday, 6 August 2026

Nearly a dozen flaws, some critical, in major AI agent frameworks that enterprises use to build apps reveal a security failure that extends beyond prompt injection - or any single model - according to Check Point researchers. “Our research shows a deeper failure: in many agentic frameworks, prompt-controlled content can cross the boundary into trusted framework logic itself,” Yarden Porat and Shahar Tal note in a write-up about a Wednesday Black Hat talk on post-injection exploitation across AI agent frameworks, which they also discussed with The Register. “A bug in an agent framework isn't a bug in one product - it's a bug in the layer a whole category of AI apps runs on,” Tal told us. “And the agent needs no dangerous tools to be turned against you: reading the wrong document is enough. We’re building this layer faster than we know how to defend it.”
 The researchers spent a year trying to break various frameworks that enterprises use including LangChain, LangGraph, CrewAI, AutoGen, Microsoft Agent Framework, and Google ADK. And across these frameworks, the team found and disclosed 11 vulnerabilities. “Almost none of it was a completely new bug class,” Tal said. “That's insecure deserialization, server-side request forgeries, path traversals, use-after-free. These are bugs that we learned to fix 20 years ago, and they're sitting underneath agents that now read your inbox, or update your database.” These are old types of threats, and the model isn’t the weak link, he added. The failure exists in the “plumbing around the model, and we think this has been overlooked,” Tal told us. “There’s a lot of research going into prompt injection and defenses, which are important, but that’s just the beginning.” Defenders should assume prompt injection, according to the researchers. The bug is what the framework does with the injection - and in these cases, the threat hunters found that the frameworks often fail to keep attacker-controlled content in the data plane. This allows it to influence trusted orchestration, memory, state, routing, and system instructions. For example, the duo found a critical checkpoint deserialization bug in Microsoft Agent Framework that led to remote code execution. “Agents have checkpoints, which are a way for them to save their state or rewind to an earlier point,” Tal explained. These checkpoints are saved snapshots of an agent's state, or task progress at a specific moment, and they serialize data - such as conversation history - into persistent storage, so if an error occurs, the system reloads this saved state instead of starting from scratch. In this case, Check Point’s team found an insecure deserialization issue where, via prompt injection, the agent loaded untrusted checkpoint data, and this could allow attackers to execute malicious code on the system. “One person's message plants the payload, and then a different person rewinds their own session, which triggers the payload, and now the attacker has a shell on that server,” Tal said. Microsoft recognized the researchers’ findings, paid a $10,000 bug bounty and fixed the issue. But because the framework wasn’t a generally available product when Check Point found the flaw, Microsoft did not issue a CVE. Microsoft told us that it appreciated the researchers reporting the vulnerability. “We have released protections to harden the Agent Framework and prevent the concrete exploitation path demonstrated in the proof of concept,” a spokesperson told The Register. “In addition, we updated the specific checkpoint file with additional language to define the security boundary.” The duo also found flaws in Google ADK (agent development kit). However, Google responded differently, the researchers told us, and did not completely fix the vulnerability or issue a CVE. “ADK ships a built-in development assistant that can write files, and it stays reachable over the HTTP API even though it is hidden from the app listing,” Porat told us. To break this trust boundary, an attacker opens a session, asks ADK to write an agent whose Python code runs at import time, and then asks the server to run the agent, he explained. The server then imports the file and executes the attacker’s code. “There is no authentication on that API by default, and adk deploy cloud_run publishes the same API, so on a default Cloud Run deployment it is reachable without credentials,” Porat said. “From there it reaches the environment's API keys and the container's Google Cloud service account." Google did not respond to The Register’s inquiries. But according to Check Point, Google initially deemed the issue not a bug. “We argued the consequence rather than the mechanism: code execution on that container reaches the environment's API keys and the container's Google Cloud service account, which is secret theft, not a developer inconvenience,” Porat said. Google ultimately paid a $3,133.70 bounty and issued a partial fix, we’re told. In total, the bug hunters received $17,133.70 in rewards for their efforts. And this isn’t a story about one vendor or framework doing a “particularly bad job,” Tal said. “If one was an outlier, this would be a story about that one vendor,” he added. “Our finding is that the same bug classes turn up in all of them.” ®

source https://www.theregister.com/security/2026/08/05/prompt-injection-isnt-the-bug-ai-agent-frameworks-are/5283585
AI webpage crawlers are now being served their very own ads that ordinary visitors never see, with one firm's boss openly describing a strategy to influence what chatbots say about brands. The next time you ask Claude about where to bank, its answer may have been influenced by this bot-targeted content. We only have one documented example so far, and that's Time serving AI-only ads to selected AI crawlers, as spotted by Germany-based freelance software developer Vincent Schmalbach. In a Wednesday blog post, Schmalbach detailed how he found sponsored content embedded in markdown versions of some Time pages that are served to AI crawlers but not ordinary browsers. Those pages also contained advertising tags from adtech vendor Mobian ahead of extensive FAQs for online-only bank Ally. The FAQs include brand "facts," such as the number of fee-free ATMs associated with the branchless bank, alongside claims that Ally is "the only bank built for life today," putting it in "a category of one." Key “brand fact” statements that make for great regurgitable facts are also included in the AI-only advertisement, as are answers to questions like “is Ally good for everyday banking,” “can you deposit cash at Ally Bank,” and the like. The FAQ is flagged as sponsored content on the markdown page, but it doesn’t change the fact that the entire thing is written like it was designed to be spit back out by a chatbot in response to specific questions. Not all web crawlers are getting these markdown ads either. Per Schmalbach, Google’s standard search indexing bot doesn't see the ads, as it just gets the same HTML that a human gets. “Only the [chatbot] assistant crawlers get the forked version,” he wrote. That means user-agents including ClaudeBot, OAI-SearchBot, and PerplexityBot receive the sponsored markdown, while Google's standard search crawler gets the same HTML served to ordinary browsers. GPTBot and ChatGPT-User, which OpenAI uses for model training and user-initiated retrieval respectively, return HTTP 406 errors in Schmalbach's tests, while OAI-SearchBot receives the markdown version used to support ChatGPT Search. These AI ad-infused markdown versions of stories should be viewable by humans who change the User-Agent header sent as part of HTTP requests, which is how Schmalbach said he spotted them. The Register tested several articles from Time to see for ourselves, and we were able to replicate the results using the crawler simulator provided by search engine optimization firm Encited. When viewed as ClaudeBot, Time’s Best Inventions of 2025 list includes the Ally Bank ad, as do stories about Time’s top content creators of 2026, as does a gallery of photos from a creators' party held in New York recently to honor the list. The markdown ads don’t appear on newsier stories that we checked, suggesting the ads may be part of more evergreen content rather than articles with a shorter shelf life. As Schmalbach points out in his writeup, this could be “the first clear look at what the web starts to become when the main audience is AI models,” which is a threshold we’ve already crossed. Why advertise to humans when you can make AI do it for you? It’s not clear whether Time’s strategy of advertising to AI crawlers has been adopted by other publishers, but it’d be a shock if others weren’t at least considering it. As noted above, AI crawler traffic has already begun to surpass human visits to webpages, making it potentially more lucrative for advertisers to target those crawlers than the humans who made them. With half of the US consumers surveyed saying they use AI to search the web, the potential to reach consumers by influencing AI responses is incredibly powerful, and that is what Time and its advertising partner Mobian appear to be banking on. When we asked the publication to verify Schmalbach’s report and the results we found, they didn’t answer questions, instead pointing us to a story in media and marketing outlet Digiday from last week that verified not only what we saw but our fears about the scheme, too. Per Digiday, Time started converting its web pages to markdown in order to make them more appealing to AI crawlers in June, and a partnership with Mobian was included in that rework. Time COO Mark Howard told Digiday that the publication’s sales team is pitching agent ads to brands that have also converted their websites to markdown, as it suggests those brands are thinking about reaching AI bots. It’s a quote from Mobian CEO and co-founder Jonah Goodhart that makes the objective clear, however: The company's aim is to shape what AI assistants say about the brands paying for the service. “When you influence ChatGPT, you’re influencing potentially all of ChatGPT. If ChatGPT changes what it says about [a brand], it’s massive and it’s more than any one campaign could ever do,” Goodhart told Digiday. “With a human you influence one person.” So far, the pair confirmed to Digiday that Ally Bank and the Project Management Institute were the first brands trying to influence AI search results, matching the ads Schmalbach and The Register found in AI crawler versions of Time's pages. Time and Mobian told Digiday that the partnership marks the first time a publisher has served ads directly targeting AI crawlers, but that “more are already being lined up.” In other words, you soon may not be able to tell which results in an AI powered search are legitimately being surfaced because of being good products, and which are just gaming the system. It’s the early days of the SEO race all over again, only this time fooling the indexers is as easy as handing any old idiot the same pamphlet over and over again until its content becomes truth. ®

source https://www.theregister.com/ai-and-ml/2026/08/05/time-magazine-has-a-separate-version-of-its-website-with-ads-only-ai-can-see/5283640
Nvidia commands about 85 percent of the datacenter GPU market today, and if Elon Musk has his way, the AI infrastructure giant will have a virtual monopoly over the stars. On Tuesday, Musk wrote on the social media network he owns that “SpaceX has committed to using Nvidia GPUs exclusively because they are the best.” The collab should surprise absolutely no one. It’s not like AMD or anyone else out there is making hardened versions of their GPUs for orbital datacenters. Why, you might ask? Well, to quote one Gartner analyst, the idea that space-based datacenters will ever be economically viable is “peak insanity.” Nvidia just happens to have $13.2 billion in cash to burn on pipe dreams like these. Specifically, SpaceX says that it will be deploying Nvidia’s Space-1, a specialized version of its upcoming Vera Rubin compute platform designed to operate high above the Earth’s atmosphere where no one can hear you scream because the LLM is hallucinating again. In a separate X post Tuesday, SpaceX announced it was “partnering with Nvidia to design the Starmind AI1 satellite compute payload,” and that “Each of the Starmind satellites will include Nvidia Rubin GPUs and Vera CPUs for datacenter class space compute.” According to SpaceX’s website, when fully deployed, the Starmind AI1 will measure 30 meters tall, have a wingspan of 75 meters from solar array to solar array, and support a compute payload of 250 kW. That might sound like a lot of power, but to put that in perspective, that’s only enough power for roughly a single Vera Rubin NVL72 rack. So, if you thought Nvidia’s rack systems were expensive, just wait till you have to loft them into orbit. Speaking of orbit, before any of this can happen, SpaceX needs to get its super heavy rocket, Starship, into orbit, which still hasn’t happened. An even bigger challenge is making it cost-effective to lob the 3.33 ton satellites into orbit. It currently costs about $7,000 to put a kilogram into orbit aboard a Falcon 9 rocket. That puts the current price of launching the AI1 at north of $23 million, assuming you manage to pack the thing into a Falcon 9 in the first place. For orbital datacenters to be cost-effective, Starship is going to need to get the cost per kilogram down to Elon’s stated goal of $10, Ortibal CEO told El Reg earlier this year. That would bring the cost to orbit to about $33,300, assuming the target is anything more than aspirational. Now is probably about the time we remind folks that Elon doesn’t exactly have the greatest track record of following through on his “commitments.” Remember how SpaceX was going to put humans on Mars by 2022 or how Tesla would field a million robo-taxis by 2020? But even if they don't go to space, Musk still might get something valuable out of Starmind AI1’s development. In yet another X post, Elon opined that the satellite's architecture was so efficient that SpaceX properties would be deploying them, sans solar and thermal management systems, in their terrestrial datacenters. “It’s a major improvement in data center efficiency,” he wrote. The notes came on the heels of SpaceX's first earnings report as a public company, during which it said that capital expenditures grew by a factor of 6x versus a year ago to $18.4 billion as the company goes into overdrive building out xAI, the company's artificial intelligence offering. The company posted a quarterly net loss of $541 million on revenues of $7.81 billion. The stock was down more than 10% in mid-day trading on Wednesday, and is down 17% from its listing price of $135 in June. ®

source https://www.theregister.com/systems/2026/08/05/elon-pledges-to-give-nvidia-a-virtual-monopoly-over-the-stars/5283605
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. [...]

source https://www.bleepingcomputer.com/news/security/hackers-run-khunt-post-exploitation-toolkit-from-oracle-database/

Wednesday, 5 August 2026

Today, I wanted to show you one of the most fascinating and surprising operating systems ever created. It’s not another Unix, Linux, or Windows. It is an architecture that went its own way and proved that systems engineering design can look completely different.

I’m talking about IBM’s child, which for many might be synonymous with “boring banking systems,” but in reality, is one of the most uncompromising projects in IT history. While we get excited about abstraction and virtualization today, thinking we are discovering new lands, this system was doing it decades ago. Imagine a system that doesn’t know the concept of a “file” in the way we understand it. A system where everything is an object, and all disk and operational memory form one vast, flat space. If you are looking for proof that true engineering doesn’t need buzzwords to blow you away, I invite you to read on.

↫ Kamil Pytliński

Ever since watching Clabretro’s detailed video about getting IBM i to work on his own IBM POWER hardware and then remoting into them, I’ve been obsessed with running IBM i at home. It feels like the final boss of operating systems to dive into and explore, hidden in the deepest, darkest trenches of the ocean of technology. Everything about IBM i feels alien, complex, convoluted, opaque, and overwhelming, and you can probably dedicate your entire career to working with this platform and somehow still learn new things about it every day.

There’s something brutalist about IBM i, and I so desperately want to bang my head on its concrete walls.



source https://www.osnews.com/story/145681/ibm-i-os-400-the-database-operating-system/
77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed. [...]

source https://www.bleepingcomputer.com/news/security/77-open-vsx-extensions-found-harvesting-developer-info/

Tuesday, 4 August 2026

In what they call the first-ever real-world agent-to-agent exploitation method, Pillar Security researchers say they discovered an exploit in the repository behind Google's Agent Development Kit for Python that could allow attackers to compromise supply chains. In other words, now we know that one AI agent can be used to control and compromise another one that has more privileges. The security snafu existed in google/adk-python, an open source Python toolkit with more than 90 million downloads used to build and deploy AI agents. Google has since fixed the underlying issue in the repository but deemed the exploit non-rewardable because it involved social engineering. Even so, it illustrates the risks of using AI agents in CI/CD workflows for triage, pull request (PR) reviews, and discussions. It also shows how one AI agent could attack another in a production environment, according to Pillar’s Dan Lisichkin, who found and reported the vulnerability. “Our world is changing quickly, and new attack surfaces are not yet reflected in threat models because these attacks never could exist in the first place in the ‘pre-agent’ world,” Lisichkin said in a technical write-up published on Monday. He will also discuss the findings during a poster talk at DEF CON's AI Village on Friday, August 7 at 1600 PDT. “CISOs and security practitioners should start considering these scenarios, threat-modeling them, and calculating worst-case implications and blast radius,” Lisichkin wrote. The issue stems from the way that the repo ran two classes of automated AI agents with different privilege levels that unintentionally share a trust boundary. One is a low-privilege, public-facing AI agent activated whenever a user opens a pull request (PR) or issue, and a second is a high-privilege, maintainer-only agent. Pillar’s team found that the low-privilege, public-facing agent could be manipulated via prompt injection into triggering a maintainer-only agent that can execute malicious actions. “Because workflows that explain how these agents work behind the scenes are also public, any person could have connected the dots that one agent should be able - at least theoretically - to 'call' the other,” Lisichkin told The Register. "When it comes to building the attack, you just need to know English to build the prompt injection (or just ask an AI to do it for you)." There is one caveat: an attacker would first likely need to make legitimate contributions to the repository to build trust among the maintainers before moving on to prompt injection. But assuming someone was willing to put in the time, here’s how the attack would play out. First, an external user - this would be the attacker - creates a new PR. Lisichkin calls this PR A, and it combines a real fix with malicious code, such as a modified package.json or malicious dependency. Then, a public-facing agent tied to a high-privilege collaborator personal access token (PAT) reads the attacker’s PR text and marks the PR for review. This level of trust - the collaborator PAT - allows the attacker-generated text to trigger a gated workflow. Once the PR A triage happens, the attacker opens a second PR - PR B - with the prompt injection, and the triage agent emits the trusted @gemini-cli handoff. This triggers the privileged-agent workflow and executes the malicious action. “Strung together, they manufacture a complete, believable ‘a human asked for a review, gemini ran it, gemini approved’ trail on the poisoned PR, none of which ever happened,” Lisichkin wrote. Google did not respond to The Register’s inquiries, but Lisichkin confirmed that the underlying issue was fixed. Still, his findings, Google said, “did not meet the bar” for a bug-bounty payout. “This report demonstrates exfiltration of a GitHub token with a 'pull-requests: write' permission, which enables tampering with a PR but still requires a maintainer to take an action to merge the malicious PR as PRs are not automatically merged after a bot review,” Google explained. “We don't reward vulnerability reports that require social engineering to enable a supply chain security compromise,” the rationale continued. “Nonetheless, we have taken an action to harden the repository so we will be recognizing this report with credit.” Lisichkin told us the research shows agent isolation is not enough. "Agents should have their own identity, which mandates what resources they are allowed to access and in what they are allowed to interact with these resources," he said. "In this case, if Google had just given a bot identity to the initial triaging agent, most of the attack could have been prevented. Security teams need to start modeling agent identity and agent resource access within their threat models."®

source https://www.theregister.com/security/2026/08/03/google-dev-kit-spurs-first-ever-agent-on-agent-violence/5282496
Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. [...]

source https://www.bleepingcomputer.com/news/security/fake-roblox-xeno-script-launcher-pushes-infostealer-rat-malware/

Monday, 3 August 2026

Microsoft has added four new items to the to-do list it set itself to improve the quality of Windows 11. Redmond’s list landed in March 2026 in response to users’ anger at Windows 11 becoming increasingly flaky and needy. Pavan Davuluri, Microsoft’s executive VP for Windows and Devices, promised “Improved memory efficiency, lowering the baseline memory footprint for Windows, freeing up more capacity for the apps you run.” Last Friday, Davuluri reviewed Microsoft’s efforts in a new post that is unsurprisingly enthusiastic about Redmond’s repair job – even though much of the work is yet to appear in production versions of Windows. Among the work Davuluri lauded was removing some AI features, improving driver quality, and trying to make the Windows Insider program less convoluted. But he also acknowledges there’s more to be done and that memory efficiency is yet to manifest. “We’ve steadily been introducing several improvements to the memory efficiency of Windows, from taking advantage of a more efficient memory allocator to reduce overhead across apps and components, continued tuning of WinUI 3 so that apps built on it use less memory by design, as well as driving efficiencies across Chromium and Webview2 components when they appear in the operating system,” he wrote. Davuluri’s post also reveals that Microsoft has decided to work on four new areas it hopes will make Windows less craptastic. The third of those is “Memory optimization for 8GB and above,” which Davuluri describes as “Reducing Windows memory footprint to deliver a fast and responsive Windows experience across the PCs customers use every day.” Microsoft’s system requirements for Windows 11 state that the OS needs a PC equipped with at least 4GB of memory, or 16GB of pricey DDR5/LPDDR5 to qualify as a Copilot+ PC capable of handling AI workloads. The software giant seemingly assumes Windows users are all clamoring to run Copilot and other AI, so working to ensure that Windows 11 can run on 8GB of memory feels like a tacit admission that Copilot+ PCs aren’t exciting buyers, perhaps due to the current high price of memory. Or perhaps because people just don’t see much value in paying extra for an AI-capable PC. Another reason for the change may be the declining PC market, which analyst firm IDC recently forecast will experience a 11.3 percent shipment slump in 2026, and 20 percent drop in calendar Q4 alone. “The culprit is a persistent memory shortage with no meaningful relief expected before the end of 2027,” the firm stated. “The knock-on effects are significant: prices are rising and PC manufacturers are struggling to maintain full product portfolios.” Microsoft’s three other new Windows improvement priorities are: Delivering a faster and more efficient out-of-box experience. Providing a faster set up and making it easier for families to access useful parental controls. Making voice more natural and fluid to interact across the apps you use every day. Davuluri didn’t say when Microsoft will deliver these changes. But he did say the company has heard Windows users’ frustrations and will act to assuage them. “The signal from you is clear: keep going. We intend to,” he wrote. ®

source https://www.theregister.com/os-platforms/2026/08/03/microsoft-says-8gb-of-ram-should-be-enough-for-anyone-running-windows-11/5282153
ASIA IN BRIEF Meta last week briefly took down an unremarkable video posted by India’s prime minister Narendra Modi, earning itself days of criticism and regulatory trouble. The video featured Modi announcing a new task force that will reform the exams required to secure places in many Indian universities. Those exams have become a major factor in the sudden development of a major youth protest movement in India, after the cancellation of one test amid claims that questions had leaked. As part of his attempts to quell protests, Modi posted his first-ever selfie-style Instagram reel last week and followed it up with others –including the one Meta took down and replaced with a placeholder saying the vid was the subject of a legal complaint. The social networking giant said that was a mistake, apologized, and restored the video. That error gave India’s government the chance to beat up Meta in public. S. Krishnan, the secretary of India’s Ministry of Electronics and Information Technology (MeitY), said he asked Meta “to come in at the highest level and explain what is happening and why.” “They have agreed to come – well, they have to – and explain what the situation is,” Krishnan said. “We want to have both a policy level understanding and a technical understanding of the issues, and also adaptation to the kind of concerns India has.” Krishnan said Meta has written to India’s government to express regret over the incident and established new protocols governing moderation of accounts run by prominent people to avoid future messes of this sort. India has a complex relationship with Big Tech companies, sometimes celebrating their role in assisting the nation’s development, but often also lamenting their monopolistic tendencies and role in spreading content the Modi government would rather netizens don’t see. DeepSeek teases ‘peak/valley’ pricing for new models which hit beta last week Chinese AI upstart DeepSeek last week released a beta API for its next model, deepseek-v4-flash, and revealed a new pricing policy for its APIs. The company says the new policy will apply “soon” and will see the cost of its services double between 09:00 and 12:00, then again from 14:00 to 18:00 – in China’s single official timezone UTC+8. DeepSeek startled the AI market last year by releasing models that it claimed to have trained without vast fleets of Nvidia accelerators. Those claims didn’t stand up to close scrutiny, but the company is considered a significant challenger to western AI outfits such as OpenAI and Anthropic. deepseek-v4-flash is likely to reach general availability within weeks. DeepSeek already claims it outperforms its last model, V4-Pro. Australia proposes new tax on Big Tech – and a new out Australia’s government has tweaked its plans to tax Big Tech companies unless they pay local media for the right to share links to their work. The Land Down Under previously threatened tech companies with a 2.25 percent tax if they don’t fund local media. On Monday, that plan changed to a 2.5 percent levy on advertising revenue only and expanded incentives to fund small and regional publications. Meta has previously slammed the idea as “A discriminatory tax built on a false premise.” Also in Australia, regulators last week decided to sue Telegram after it failed to take down violent and terrorism-related content. Kioxia profits jump by billions, as you’d expect from a memory-maker Japanese memory-maker Kioxia last week announced [PDF] its quarterly revenue grew 451 percent year over year to reach $11.1 billion, plus profit of $5.3 billion – a massive turnaround from the $287,000 loss for the same quarter last year. According to Japanese outlet Nikkei, CFO Yoshihiko Kawamura said the company expects even better days ahead because he believes demand for NAND storage is “still in the early stages.” Japan’s next moonshot to ride local rocket Japanese space startup iSpace last week announced its next mission will ride a Japanese rocket to the moon. iSpace has launched two moon lander missions, but both failed. The company’s plan for its third mission involves new lander design called ULTRA that is capable of carrying payloads weighing several hundred kilograms to Luna. This time around, iSpace plans to use the H3 rocket built by Mitsubishi Heavy Industries, instead of the SpaceX Falcon 9 that carried its first two missions. ®

source https://www.theregister.com/public-sector/2026/08/03/meta-straps-on-a-kick-me-sign-by-mistakenly-taking-down-video-by-indias-prime-minister/5282130
OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant advances in mathematics and theoretical computer science. [...]

source https://www.bleepingcomputer.com/news/artificial-intelligence/openai-teases-astra-its-next-major-ai-model-after-it-solves-10-long-standing-math-problems/
A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. [...]

source https://www.bleepingcomputer.com/news/security/coldcard-wallet-rng-flaw-likely-linked-to-88-million-bitcoin-theft/

Sunday, 2 August 2026

Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. [...]

source https://www.bleepingcomputer.com/news/google/google-chrome-may-soon-block-new-tab-hijacker-extensions-by-default/
Tom Evslin drove the WorldNet project at AT&T and helped develop what became Microsoft Exchange and Outlook. He was at Microsoft when the company was still working out what to do about this newfangled internet thing. Evslin describes himself as one of Microsoft's "internet radicals" in the early 1990s, when the company was developing Exchange Server to fend off the threat from Lotus Notes. "Bill Gates was willing to put lots of effort and money into Exchange because he was very afraid of Lotus Notes," Evslin says. "He felt that Lotus Notes could become a platform the way that Windows was, which would be an enormous threat to Microsoft. And so he saw Exchange as a Notes killer." Evslin saw Exchange differently "because I was an email guy." He and Microsoft's other "internet radicals" wanted the upcoming products delayed until they had been made relevant to the internet. Gates disagreed. "Bill said, with some truth, that we were probably behind schedule anyway, always looking for an excuse to be late. So we go ahead with the next launch of products, including Office, Exchange, and NT, then worry about the internet afterward, which I thought was a mistake." Evslin was fascinated by the internet's potential and disappointed by Gates' stance. He was responsible for gateways in Exchange, services that connect one mail system to another. Some did things like connecting to CompuServe. Others linked to MCI Mail, one of the first commercial email services in the US, "which I had done a client for," Evslin says. "We had one little gateway that we hadn't put much work into, which was called an SMTP gateway, which connected SMTP mail, which was used on the internet. Which itself wasn't widely used." So, was Gates right? Only briefly. While Microsoft's corporate clients insisted communication over the internet was "not safe" and "not secure," Evslin says: "All of a sudden we got a huge number of requests for this SMTP gateway. And when I looked into it, I found that more and more email was going over the internet." The official corporate stance might have been one of "nope," but employees had other ideas. "Their engineers were communicating on the internet, and they never understood that, or didn't understand that at the time," Evslin says. And then there was what would become Outlook. "From the beginning, we wanted the client for Exchange to be able to support graphics, to be able to support fonts, so that you could format an email in the same way that you could format a Word document. "Where we didn't go far enough is we still had two separate formatting engines, so the Word and Outlook client never merged as I thought they should have." Soon after Gates chose to launch the products before adding deeper internet integration, AT&T invited Evslin "to come and develop their internet strategy." Back then, Evslin says, AT&T didn't really have a clear plan for the internet. The company had tinkered with proprietary networks, but Evslin reckoned AT&T should become an ISP. "AT&T always had illusions about being a content provider," he says. Evslin also favored all-you-can-eat pricing, which smaller providers had attempted but AT&T had yet to try. "There was a lot of debate internally, people saying 'you can't launch a new service in less than seven years.'" Considering how quickly things were moving – and still are – seven years was a lifetime. "I said, 'the solution to that is launch it fast and then adapt.'" WorldNet offered straightforward internet access to customers accustomed to portals, proprietary networks, and some heart-stopping telephone bills. Demand grew so quickly that AT&T had to control sign-ups lest the service earn the "America On Hold" nickname occasionally and unkindly applied to America Online. With the internet in the ascendant, Evslin became interested in another technology: voice over IP. This, he acknowledges, "was an impossible sale inside AT&T." And so, in 1997, Evslin moved on again to found ITXC, a wholesale VoIP carrier. ®

source https://www.theregister.com/offbeat/2026/08/02/meet-the-internet-radical-who-helped-microsoft-get-email-and-att-get-online/5281281

I have a policy to effectively never link to YouTube videos. I’ll gladly make an exception for this one.

Reflection is one of the most powerful concepts in Computer Science. Unfortunately, not every programming language is blessed enough to have it.

In the 1980s, one company, Symbolics took the concept to the logical extreme. By representing EVERYTHING as objects; they created the most powerful (and inadvertently) least private operating system ever created!

The company collapsed, but the ideas live on. Some modern languages got a full dose of reflection. Some…weren’t so lucky. I ranked them all, and in the end I’ll show you how I dragged C++ up a tier with my brand new runtime reflection library, CallMeMaybe!

↫ Laurie Wired

The GitHub description of CallMeMaybe:

CallMeMaybe (CMM) is a C++ runtime reflection library built on top of P2996 static reflection introduced in C++26. CMM purposefully mirrors many of the std::meta functions to provide a uniform interface, but allows runtime introspection, dynamic invocation, and instantiation by building a runtime reflection registry. Class members can be automatically traversed and reflected by simply adding [[=cmm::reflectable]] as an annotation. CMM implements a custom type system to completely avoid RTTI requirements.

↫ CallMeMaybe GitHub page

My YouTube linking policy will remain in place.



source https://www.osnews.com/story/145661/callmemaybe-runtime-reflection-library-built-on-c26-static-reflection/

Saturday, 1 August 2026

Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. [...]

source https://www.bleepingcomputer.com/news/security/amgen-says-cloud-data-breach-exposed-patient-health-proprietary-info/
Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. [...]

source https://www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/
OpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20% as it works to make its models more efficient. [...]

source https://www.bleepingcomputer.com/news/artificial-intelligence/openai-says-its-new-gpt-56-models-are-becoming-more-cost-efficient/

Friday, 31 July 2026

Virtually every high-end GPU and AI accelerator relies on high bandwidth memory (HBM), which can shuffle data around at multiple terabytes a second but can only reach into the gigabytes, with models often needing to be shared across multiple processors. However, an emerging storage technology could change that, boosting accelerator memory capacity from hundreds of gigabytes to terabytes. The technology, called high-bandwidth flash (HBF), is being developed by Sandisk and SK Hynix and aims to provide SSD-like capacities at HBM-like speeds. Peeling back HBF’s layers Conceptually, high-bandwidth flash looks and sounds a lot like HBM. It’s assembled by stacking multiple layers (16 in the case of Sandisk’s first-gen modules) of memory together, which boosts capacity and bandwidth. But where HBM uses DRAM, HBF aims to use NAND flash. Sandisk claims its first generation of high-bandwidth flash will supposedly achieve read bandwidths up to 1.6 TB/s [PDF], making it a bit faster than HBM3e but significantly slower than HBM4, which is already hitting 2.5 TB/s per 12-high stack. Future HBF generations are expected to push bandwidth to over 2 TB/s and eventually 3.2 TB/s. While bandwidth makes HBF interesting as an alternative to HBM, its real party trick is capacity. Because it’s built using NAND, Sandisk says it can achieve capacities up to 256 Gb per die, which translates to 512 GB per 16-high module. That’s more than 14 times the capacity of the HBM4 used in AMD and Nvidia’s latest accelerators. Continuing with the similarities, HBF modules share similar packaging requirements to HBM, which means you can expect them to be fused to the GPU die using advanced packaging techniques like TSMC’s CoWoS, or Intel’s EMIB and Foveros tech. Nothing particularly exotic as AI accelerators go. What’s more, the storage vendor doesn’t expect the modules to come at a power or price premium over HBM. And from a bits per dollar standpoint, HBF looks like a stellar option. If all this sounds a bit too good to be true, that’s because for all of HBF’s benefits, it comes with some rather significant compromises. NAND still isn’t DRAM The main trade off, as we understand it, is write endurance and access latency. HBF may perform like HBM on paper, but it’s still using NAND, which has a finite write endurance before it wears out and has access latencies measured in microseconds as opposed to tens of nanoseconds for DRAM. If you were to swap HBM for HBF, it (probably) wouldn’t perform very well and it’d wear out pretty quickly, rendering that $50,000-plus GPU of yours a paperweight — not ideal for a product that’s being asked to serve longer to suit hyperscalers' depreciation schedules. Instead, Sandisk and SK Hynix propose using HBF to supplement HBM to make inference more cost effective. HBM handles all the write intensive stuff while HBF takes care of the read heavy parts of the pipeline. While we talk about inference as one job, it's really a collection of many that can broadly be broken into two categories, one that’s compute intensive and another that’s bandwidth bound. The first of these phases, called prefill, involves tokenizing and embedding prompts, feeding them through the model in one big forward pass, generating the key value caches used to track state, and outputting the first token. The second, called decode, reads the entirety of the model's weights, or in the case of a mixture of experts (MoE) models, their active parameters, from memory over and over again for each token generated. Because of this, how quickly an AI system can churn out tokens is directly proportional to how fast its memory is. Prefill is comparatively write heavy, so it makes sense to do as much of that in HBM as possible. But the decode phase is almost entirely read, which makes HBF an ideal medium for storing model weights as write endurance really isn’t a factor. It becomes a sort of write-once, read-many scenario, which is perfect for NAND flash since reads are essentially free. You could almost think about HBF a bit like a rewritable ROM cartridge for models. And because HBF is non-volatile, it becomes a bit like Intel’s Optane persistent memory. There is no need to wait for weights to reload from storage into GPU memory; they’re already there and ready to go. Sandisk’s slides propose a couple of different options including one that would feature 3.12 TB of memory across two stacks of HBM and six stacks of HBF. Oh the things you can do with all that memory That much memory has implications for model and inference architectures. Most frontier models at this point employ a mixture-of-experts (MoE) architecture, which means the model is really a collection of routed sub-models called experts, a small selection of which are used to generate each token. This has allowed model devs to build models larger than would otherwise be practical to serve due to memory bandwidth constraints. Because HBM’s capacity is so limited, these experts usually have to be spread across multiple GPUs connected by extremely high-speed interconnects. But with high-bandwidth flash, even multi-trillion-parameter models, like Kimi K3, could be packed into a single accelerator, mitigating any of the performance bottlenecks induced by the chip-to-chip interconnects. On the flip side, HBF could allow a 72-GPU rack to run some truly massive models measuring hundreds of trillions of parameters. Training such a model presents its own unique set of challenges, and the number of active experts/parameters would be limited by HBF’s bandwidth, but it could work. So when? So when can we expect to see HBF deployed in datacenters? If Sandisk is to be believed, the first samples should go out later this year with the first AI inference devices based on HBF available early next year. But for a variety of reasons previously highlighted by our sibling site Blocks and Files, we’re not holding our breath. One of the biggest factors is standardization. Memory is a commodity business and blazing your own trail with a proprietary technology rarely pans out — just look at Optane if you need evidence of that. Sandisk and SK Hynix officially kicked off this process earlier this year under the auspices of the Open Compute Project. “The key to AI infrastructure is to go beyond the performance competition of individual technologies and to optimize the entire ecosystem,” Ahn Hyun, president and chief development officer at SK Hynix, said at the time. There are also manufacturing considerations to be made. HBF is going to require a lot more dies per module than your typical flash storage device. What’s more, from what we understand, the specific kind of NAND used to make these modules is different from the kind used to make SSDs and other flash storage. Those modules will need to be copackaged with accelerators, which means SK Hynix and Sandisk will need to get buy-in from GPU and ASIC makers, which is going to take time. In fact, it wouldn’t be surprising for these modules to be ready years before the first chips designed to take advantage of them enter production.®

source https://www.theregister.com/storage/2026/07/30/gpus-could-explode-to-multiple-tb-with-new-storage-inspired-memory-tech/5281363
If you don't want AI scrapers training themselves on your website, there's a new way to stop them that doesn't involve server-side blocking or praying they respect your instructions in robots.txt. A team of creatives have teamed up with a typography company to create a new type of font that’ll trick LLM scrapers into ingesting poisoned gibberish. Dubbed ShieldFont, the open-source project almost seems like magic if you're not familiar with the ins and outs of computer fonts. Look at a web page written using a ShieldFont font and it’ll appear exactly as one would expect: All the content words (the nouns, verbs, adjectives and adverbs that give a sentence meaning) are the same as the writer originally wrote. Inspect the raw HTML that a scraper reads from a ShieldFonted page, however, and you’ll see a sentence that’s essentially gibberish. Typing “good luck reading this, you useless robot” in the online demo version, for example, turns it into “good comfort reading this, you yellow barrier.” The goal, as outlined in the ShieldFont white paper, is not to get a scraping bot to reject the text as garbage, but to convince it that the text on the page is unusual but sensible. A noun will never be swapped for a verb, for example, and a verb will never be swapped for an adjective: Swaps only come from the same grammatical pool. It goes even more distinct than that, The ShieldFont creators noted. “Not just noun for noun: plural abstract noun about communication for plural abstract noun about communication,” the white paper explains. “There are about 250 such pools, built by crossing part of speech with sense category, concreteness, singular or plural, verb transitivity, verb inflection and adjective degree.” Around a quarter of words in a chunk of text end up replaced, the creators noted, with the hope the copy still gets ingested. Even if it doesn't, and the group notes scrapers do sometimes reject it, that still means your writing doesn’t get sucked up to train an AI – a win either way. How does this black magic work? This all seems a bit mystical unless you’re versed in the functions of fonts – specifically fonts in the OpenFont family, which ShieldFont is designed to work with. First off, you may be familiar with typographic ligatures, which combine two letters into a single character for the sake of making text look a bit neater, or conveying meaning in some languages but not others. Æ is one classic example in Latin script used in some languages but not others; there's also fi, which combines a lower case F and I in a way that prevents the top curve of the F from bumping into the I’s dot. OpenType fonts all come with ligature tables that define how single glyphs or glyph sequences get substituted automatically by a word processor in a process known as glyph substitution, or GSUB. Even Google Docs supports user-configurable GSUB to an extent - you can fairly easily configure a substitution to automatically fill in for frequently used special words or characters. ShieldFont works on largely the same premise, but extends GSUB to entire words instead of letters or character pairs. So for example, a word like "daughter" in raw HTML might be rendered as "journalist" when it actually shows up to human viewers on the page. Here's what a paragraph written in the ShieldFont looks like as viewed on a web page (above), as opposed to what the raw HTML actually says (below): Even with that extended GSUB format, the font files are still quite small. We spoke with Amsterdam design studio Seneda & Abrucio, founded by Isaque Seneda and Gabriel Abrucio, the team behind ShieldFont, and they told us that the document/desktop fonts that are ShieldFonted are only around 5 MB, while compressed web fonts that include the entire GSUB dictionary still only come in at around 800 KB - large for your average font, S&A explained, but still considerably smaller than the desktop version. There’s more than one GSUB dictionary too - ShieldFont is shipping with three of them, and the GitHub repository explains how users can create their own to prevent reverse-engineering. But why poison a few words instead of just scrambling text altogether? S&A told us that they want a deterrent to scraping by introducing uncertainty and chaos into training data, not just a way to get scrapers to ignore some pages. “Pure scrambling fonts already existed,” the pair explained. “We wanted a mechanism with actual consequences: scrape without asking, and you can't tell if what you took was real. Concealment alone just gets you dropped and forgotten.” The default font that ships with ShieldFont is a modified version of Optik from Copenhagen typography shop Playtype, who partnered with S&A on the project. Like other scraping deterrents, it's not perfect Speaking of reverse-engineering, ShieldFont isn’t perfect by a long shot. As the team notes in their white paper, it can be defeated with relative ease. A screenshot of a page that’s run through OCR avoids the poisoned HTML, as does any other method that a scraper might use to scrape user-viewed pages instead of raw code. Targeted AI that downloads its own copy of ShieldFont and runs through all three GSUB dictionaries can also decode a page. SheildFont could also impose an SEO penalty on people who use it, as search engines, like AI scrapers, read the raw HTML to look for content, as do translation apps and the copy/paste function built into computer operating systems. Screen readers used for those with visual impairment also have trouble with it too, though there is a feature built in to ensure screen readers can get the user-displayed text, albeit slowly. “[ShieldFont’s] purpose is not to stop a determined actor, but to slow unauthorized mass scraping by adding cost, friction and uncertainty,” S&A said in a press release. “Scrapers cannot know in advance whether a site uses ShieldFont or which mapping it uses.” As for whether ShieldFont is just an experiment or something S&A hope gets widely adopted, the pair told us it’s a bit of both. “ShieldFont is real and working today, but it's v0/alpha, so still improving,” S&A explained. “Longer term, it's a bet on collective pressure,” the ShieldFont designers added. “Nothing currently makes bypassing a publisher's requests costly. If enough sites make scraping expensive, scrapers have to change how they operate. That's the point where negotiation becomes possible.” ShieldFont is now available to try. The online demo encoder can be used to generate protected HTML for embedding in a website, and it’s also available as a React component and for CSS and CDN integration, all of which is explained on the project’s GitHub page and the ShieldFont website. ®

source https://www.theregister.com/ai-and-ml/2026/07/30/open-source-project-fools-ai-scrapers-with-poisoned-font/5281303
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. [...]

source https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/

Thursday, 30 July 2026

Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. [...]

source https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/
The US government has signed a letter of intent to provide GlobalFoundries with $300 million in CHIPS Act funding and, at the same time, receive a one percent stake in the company worth roughly $269 million. The money's supposedly not a tit-for-tat, but an investment designed to spur development of silicon photonics networking technologies that the AI industry needs for datacenters. “With today’s compute supply chain investments, the Trump Administration is accelerating America’s innovation engine,” Commerce Secretary Howard Lutnick said in a canned statement. “These strategic investments will enhance our country’s domestic capabilities, create high-paying jobs and keep America at the forefront of the semiconductor industry.” GlobalFoundries’ previously announced Silicon Photonics Co-Packaged Advanced Light Engine (SCALE) is one of the technologies it’s pushing in order to support 400 Gb/s per lane connectivity, which is about the speed at which copper interconnects become problematic for large scale systems. Both CPO, where optical engines are integrated directly into the compute logic, and NPO, where the optics reside in a module adjacent to the compute, are expected to be big business over the next couple of years. At Computex in Taipei last month, Nvidia CEO Jensen Huang quipped that these technologies would make Marvell Technology the next trillion dollar company. Over the past two years, system designs from Nvidia and AMD have grown from eight GPUs in a box to rack systems packing six dozen accelerators into a single machine. To meet growing AI demand, the chip designers are plotting even larger row-scale systems using optical interconnects. Since its spinoff from AMD, GlobalFoundries has moved away from leading-edge CMOS technologies in order to focus on more specialized processes. The company has become a leading producer of silicon photonics used in modern AI datacenters. In addition to next-gen silicon photonics tech, GlobalFoundries says the CHIPS Act funding will also support the development of novel optical materials, advanced packaging capabilities like 3D hybrid bonding, which will support the rollout of domestically manufactured near-packaged optics (NPO) and co-packaged optics (CPO). And thanks to the Trump administration, regular Americans will have a stake in the success of these technologies — or at least the ones GlobalFoundries ends up manufacturing. GlobalFoundries would not be the first American fab operator that Uncle Sam has secured equity from in exchange for CHIPS Act funding. Last summer, the Commerce Department converted $5.7 billion in previously awarded but not yet disbursed CHIPS Act grants, along with $3.2 billion awarded under the Secure Enclave program, into roughly a 10 percent stake in the struggling chipmaker. Bootnote: On Tuesday, Intel announced the Rapid Assured Microelectronics Prototypes - Commercial (RAMP-C) program had reached its conclusion. The Department of Defense (DoD)-sponsored program offered incentives to industry partners to develop test chips in Intel fabs on the company’s 18A process technology. The program’s end comes as Intel shifts its manufacturing might to a new government program called the Secure Enclave, which will manufacture semiconductors for use by US defense industrial base (DIB) customers. “Early access to Intel 18A has positioned DIB customers to leverage Secure Enclave while meeting critical size, weight and power requirements,” the company wrote. ®

source https://www.theregister.com/public-sector/2026/07/29/uncle-sam-sees-the-light-offers-globalfoundries-300m-to-pursue-silicon-photonics-while-taking-1-stake/5280620
The guardrails that prevent closed-source, frontier models from aiding threat actors have turned into handcuffs that prevent those bots from helping to find and fix serious vulns. Daniel Fox Franke, principal security researcher at Akamai Technologies, was recently trying to track down the source of a segmentation fault in ripgrep, and found OpenAI's GPT-5.6 Sol wouldn't cooperate. "OpenAI's cybersecurity classifier is a huge pain when you're trying to track down a segfault," he wrote in a social media post on Sunday. "...The classifier won't even let it answer what entrypoints from rg into musl lead to allocations on the mallocng heap." And just like Hugging Face in the case of OpenAI's accidental attack, Franke ended up having to use open weight models from Chinese AI providers – Z'ai GLM 5.2 and Moonshot AI's Kimi K3 – to complete his analysis of what appears to be a Linux kernel bug. In an email to The Register, Franke explained, "It started out from a pretty anodyne prompt: I noticed that ripgrep had segfaulted repeatedly during a long-running Codex session, so I instructed the root agent to spin off a subagent to investigate what was happening. "A few minutes later I hit the first classifier trip, which the root agent told me was the result of a subagent pursuing an inappropriate line of inquiry and that it was steering it away from that." Even so, he said, the classifier balked several times in quick succession. "It seemed that attempts to produce the crash and analyze the heap were mostly responsible, so I started up a fresh context in which I warned that these trips had happened previously, and that its task should be strictly scoped to analyzing ripgrep and musl source code (not kernel, because I had no inkling at this point that this was a kernel bug): it must not attempt to reproduce the crash or to analyze core files," he explained. "Nonetheless, the classifier kept tripping despite its adherence to those instructions, and that's when I gave up on getting any useful work out of it." Franke said that given how much more restrictive Anthropic's models have been, he didn't even bother trying any of the Claude model family. "OpenAI's cybersecurity classifier is a separate system which censors output from the generative model, and the classifier is the only thing which gave me a problem," he said. "I never encountered any refusals from Sol itself: it knew that most of the classifier trips were inappropriate and always continued working with me in good faith to work around the problem." Franke said that while OpenAI's error messages directed him toward the Enterprise Trusted Access program, he didn't bother to apply because he's ineligible. What he didn't realize until recently, he said, is that there's a separate Trusted Access program for individuals. "I still haven't signed up for that, because I regard the verification procedure as a bit of an indignity," he explained, echoing similar sentiment The Register has heard from other security researchers. "I'll put up with it if I'm ever forced to, but not for as long as open models remain a practical alternative." Two open models did prove practical for this bug hunt: GLM 5.2 and Kimi K3. Franke said each served a distinct purpose. "K3 made the initial breakthrough with the key bit of evidence that I was dealing with a kernel bug, but its subsequent investigative work was sloppy: jumping to unfounded conclusions and spoiling its own evidentiary record, and it went totally off the rails when its context got large," he said. "GLM-5.2 is what finished the job for me, re-auditing K3's work and putting together an airtight case." Franke said it was frustrating to wrestle with defiant tooling and expressed skepticism about model access limitations given the availability of open source alternatives. "From my perspective, an uncooperative tool is simply a broken one," he said. "And no, I don't believe this is sustainable in the face of open-weight competition. I'm a total pragmatist about open source and don't mind at all working with proprietary products as long as they get the job done. But with proprietary software, there's a much greater hazard of it being built to serve the vendor's priorities rather than the customer's. Open source has a natural advantage in preventing that." Franke said that there's still work to be done on the Linux bug, which doesn't yet have a patch and doesn't appear to represent an exploitable vulnerability. "Where my investigation stands is that I know two things confidently," he said. "First, that the crashes are caused by a kernel bug. Second, that I've identified a kernel bug. But that this bug is causing these crashes is still just a conjecture, and I have a lot more investigation to do before I can think about shipping anything to [the Linux Kernel Mailing List]." Last week, much of the US tech industry came out in support of open weight models in response to protectionism promoted by Anthropic and OpenAI. The US government has yet to articulate a coherent AI policy with regard to open weight models. ®

source https://www.theregister.com/ai-and-ml/2026/07/29/closed-models-refuse-to-help-researcher-swat-linux-bug/5280647
Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters. [...]

source https://www.bleepingcomputer.com/news/security/health-isac-warns-of-rising-shinyhunters-data-theft-attacks-on-healthcare/

Wednesday, 29 July 2026

Two agentic bug-hunting systems from Microsoft and Google-owned Wiz show that when it comes to finding and remediating software vulnerabilities, at least two models’ minds work better than one - and Wiz tells us it’s adding a third. Wiz on Monday said Project Atlas, its bug-hunting AI agent, bested Anthropic’s Mythos Preview and OpenAI’s GPT-5.5 Cyber with its vulnerability-analysis skills, achieving a 90.9 percent success rate on CyberGym, and uncovering more than 200 zero-day security holes in widely used open-source code. Meanwhile, Microsoft boasted its MDASH bug-hunting harness scored a 95.95 percent success rate on CyberGym, also beating Mythos, Gemini and GPT on the same benchmark for evaluating how well AI systems find real vulnerabilities in the code. For comparison, OpenAI’s GPT-5.5 Cyber scored 85.6 percent on CyberGym, and its GPT-5.6 Sol scored 83.6 percent. Anthropic’s Mythos 5 reproduced the target vulnerability on 83.8 percent of CyberGym challenges. And Google’s Gemini 3.5 Flash Cyber in CodeMender achieved an 83.2 percent success rate. The secret to both Atlas and MDASH’s success, according to the vendors, is that they use the right model for the right security job. Atlas uses Claude Opus 4.6 with GPT-5.5, Nir Ohfeld, head of vulnerability research at Wiz, told The Register. “We're now working to incorporate Gemini, which is well timed given Wiz's recent work with DeepMind on Gemini Flash Cyber,” he added. Microsoft’s MDASH - a combination of red-team agents that find and simulate real, exploitable vulnerabilities and attack paths, and green-team agents that remediate the issues - combines MAI-Cyber-1-Flash, based on Microsoft AI (MAI)’s internally developed MAI-Thinking-1 reasoning model, and GPT-5.4. MAI-Cyber-1-Flash is designed to handle up to 90 percent of all tasks, with MDASH detecting, patching, and validating vulnerabilities before handing the remaining 10 percent of more complex tasks to the larger GPT-5.4. “We were able to take an off-the-shelf model, within our harness, a multi-agent and multi-model implementation, and we achieved the best results you could have,” Hayete Gallot, executive vice president of Microsoft Security, said on Monday. Atlas isn’t commercially available yet - it’s used internally, and stems from Wiz’s efforts to understand how frontier models can be used for advanced code scanning. But it’s proof that “no single model is best at everything, and none stays state of the art for long,” Ohfeld and fellow Wiz kid Yuval Avrahami wrote in a Monday blog. The cloud security biz evaluates every new model using its internal benchmarking tool, Cyber Model Arena, which scores each one on its success at completing various security-investigation tasks: threat modeling, hunting, validation, and proof generation. “The results are rarely uniform: the model that reasons best through a complex exploit chain is often not the one that triages most precisely,” the duo wrote. “Atlas routes each stage to whichever model wins on that task.” In addition to doing a better job of finding and fixing vulnerabilities, a multi-model system also saves customers’ money, according to Microsoft and Wiz. Combining its much smaller, in-house model with GPT-5.4 halves customers’ costs, according to Mustafa Suleyman, CEO of Microsoft AI. “As the models hand off between each other, they are not just able to deliver better performance than all of the other models combined, they do so at 50 percent of the cost,” he said on Monday. And while “each new generation of models expands what is possible,” they are also expensive, Ohfeld told us. “We have also learned that pointing a frontier model at a codebase once is not a sustainable security strategy: deep scans are expensive, their results become stale as code changes by the minute, and a point-in-time analysis cannot provide the continuous coverage organizations need across every repository,” he said. In fact, the real question for code security shouldn’t be which model a scanner uses, Ohfeld added. It’s this: “How does your system take advantage of the best model available today, continuously and economically, and what continues to work when a better one arrives,” he said. “That is the bet behind Atlas: frontier-model depth where expert reasoning is required, an architecture that improves as models evolve, and rigorous validation so every finding arrives with evidence, not just a plausible answer.” ®

source https://www.theregister.com/security/2026/07/28/microsoft-and-wiz-mind-meld-agents-catch-more-than-90-of-bugs/5279914
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [...]

source https://www.bleepingcomputer.com/news/security/vbulletin-fixes-critical-pre-auth-rce-flaw-with-public-exploit/

Tuesday, 28 July 2026

Your GPU dashboard says 70% utilization. On paper, the cluster is busy. In practice, a large chunk of that time is spent with your $40,000 accelerators sitting idle, waiting on a file that lives three network hops away on a NAS box. The compute queue is empty, and the pipeline is fine. The problem is that data is just somewhere else. This is the awkward truth underneath most stalled AI projects. The constraint in modern AI infrastructure stopped being storage capacity years ago. Now, it's more about data placement and access. What matters is where files live and how they get to GPUs, along with how much copying happens in between. In that sense, AI infrastructure has become less of a storage capacity problem and more of an operational data problem. The Hammerspace Data Platform takes that as its starting point. It sits between your compute and the storage you already own, from NAS to object stores and even the NVMe drives bolted into your GPU servers. It makes all of that data addressable through a single global namespace. Instead of moving data to wherever the GPUs are, the architecture makes the compute aware of where the data already lives. As a result, rather than treating each storage system as its own operational silo, Hammerspace separates the data layer from the underlying infrastructure, allowing heterogeneous storage, sites, and clouds to operate as part of the same coordinated data environment. Applications and AI pipelines access that data through standard protocols such as NFS, SMB, and S3, without proprietary clients or application rewrites. Fragmentation is the bottleneck, not bandwidth Data fragmentation is a big problem for enterprises embarking on an AI journey. Training sets are scattered across departments, sites and clouds. "The data is in disparate groups and disparate orgs and disparate silos within a company," says Jonathan Flynn, director of applied systems at Hammerspace. "Having the data in a curated data set for you just to go train is rare. It has to be collected. It has to be moved around from system to system, and then the curation needs to happen in order to actually do the training on it." The fragmentation often leaves pipelines copying and staging files between systems that were never designed to talk to each other. None of this shows up on a storage IOPS chart, but it will visibly affect training velocity. According to Gartner, 57% of organizations believe that their data isn't AI ready. Alarmingly, two thirds of executives believe that no one in their organization understands all of the data they've collected and how to access it. That seems hard to swallow, until you recall that Facebook's engineers have admitted the same thing. You can't orchestrate what you can't see. Mike Bloom, who covers AR architecture at Hammerspace, says the default vendor response makes the problem worse. "They'll go to a vendor that will promise them that if they sweep the floor and throw out all of their legacy storage arrays, their brand will solve the problem," he says, adding that's like throwing the baby out with the bath water. "Those data sets that are all over the place? They're not sitting in a corner. They're sitting on legacy storage arrays." The NVMe you already paid for There is also a less obvious idle resource in most AI environments: the NVMe inside the GPU servers themselves. A modern HGX or DGX box ships with eight to sixteen NVMe drives, each hanging off four lanes of PCIe. Almost every orchestration layer treats that capacity as local scratch space, used by one server and invisible to the rest of the cluster. Hammerspace calls this "stranded" capacity, and it is now meaningful. It amounts to hundreds of terabytes per server, with two-petabyte GPU servers on the roadmap. Pull all of it into a shared namespace and you have a new layer that Hammerspace calls Tier 0. It uses storage you already paid for, attached to a network you already deployed. Flynn argues this layer is structurally faster than anything sold as a separate appliance. "Tier one is typically oriented around storage capacity. A 2U box, 24 NVMe, or 40 NVMe with some of the Dell systems in there," he calculates. "That's 96 lanes or 192 lanes of PCI Express, with maybe one or two 400 gigabit NICs, which gives you 16 or 32 lanes. So the over subscription just in the one box is massive." His more provocative claim is that it is also the cheapest tier in the rack. The compute and the network are already there. The drives (at least in the case of customers buying GPU servers) are already in the bill of materials. Compared with racking and stacking a dedicated all-flash array, adding metadata servers and a few data movers to existing GPU nodes barely registers as a procurement event. Assimilating what you already own Ripping and replacing infrastructure takes time most teams don't have. The Hammerspace approach is assimilation, which the company describes as a metadata-only operation: scan the existing NAS, ingest the directory tree into the global namespace, and redirect mounts. The bytes never move. Hammerspace says that fast deployment is a key benefit of this approach. Data access is restored almost immediately, even while assimilation continues in the background. Underneath this, the source-of-truth NetApp, Qumulo or VAST array keeps serving the bytes, while Hammerspace presents a unified view on top. That has practical consequences. If something tagged as a training input changes from being a tier-two archive file to a hot input, a policy (Hammerspace calls this an "objective") can trigger an instance copy onto tier 0 without users having to do anything. "Nobody's running a copy. Nobody's running an rsync command," Flynn says. "It's all orchestrated based in the file system." That same orchestration layer can also support retrieval-augmented generation (RAG), inference, and agentic AI workflows, where distributed enterprise data needs to be continuously curated, governed, and made accessible without relying on large-scale data copying. Once the training job finishes, that tier 0 copy is automatically vacated. The clean-up matters because the alternative (letting a hot tier fill up) creates a quality-of-service problem for everything else trying to land there. "Other architectures that have a hot tier and a cold tier often have an issue where the hot tier becomes congested and that endangers the quality of service for the pipeline," Bloom says. “Rather than requiring organizations to rebuild infrastructure around AI, the Hammerspace approach is designed to operationalize the storage, cloud, and compute environments enterprises already have in place. Standards-based, with some asterisks Hammerspace's positioning leans heavily on the word "standard". The Samsung-Hammerspace submission that landed inside the top 10 of the IO500 10-Node Production benchmark in November 2025 used standard Linux, the upstream NFSv4.2 client, standard NVMe SSDs and IP-over-InfiniBand. There was no proprietary client, and no custom kernel modules. The company submitted its own results to MLPerf Storage v2.0 showing linear scaling out to 420.8 GB/s across 140 GPUs on five nodes with GPU utilisation above 96%. That kind of performance is not achievable with traditional NFS architectures, which struggle with the parallel access patterns common in large-scale AI environments. Instead, Hammerspace runs on parallel NFS (pNFS). Instead of letting a single server handle file metadata transfer alongside data transfer, it creates a layout map that the client can then use to transfer data from multiple servers in parallel. That became the RFC 5661 standard in 2010. Hammerspace was also instrumental in extending pNFS in NFSv4.2 in 2018, introducing the Flex Files extension. This is what lets pNFS work with real-world hetergeneous storage across cloud tiers, legacy files, and multi-site deployments. The larger implication is that open, standards-based infrastructure is no longer inherently at odds with AI-scale performance, challenging the assumption that enterprises must adopt proprietary storage stacks to support large-scale AI workloads. "With the performance improvements that we contribute into the upstream, we're actually seeing a decades-old file system transmute into a parallel access system that can rival WEKA, Lustre, and GPFS," Flynn says. Multi-site and sovereign by default Once a single global namespace spans on-prem arrays, cloud object stores and the NVMe inside GPU boxes, the next questions are jurisdictional. Where can a given file legally live? Who is allowed to copy it? The platform handles this through the same objectives mechanism used for performance tiering. Tag a dataset as EU-only and the orchestration layer will exclude it from North American volumes. Tag it as HIPAA-bound and write-once-read-many rules apply. Because those policies operate at the data layer rather than within individual storage silos, governance persists even as data moves across clouds, sites, and performance tiers. That is becoming increasingly important as AI pipelines, inference workflows, and agentic systems operate across distributed infrastructure rather than within a single environment. That matters more in 2026 than it did two years ago, since such operational flexibility also changes the economics of AI infrastructure expansion. The SSD supply situation has tightened. NAND and DRAM prices climbed through 2024 and into 2025, driven by AI build-out and hyperscaler hoarding. Buying your way out of a data-movement problem by adding another all-flash array is harder when the flash is harder to get. A control plane that understands workload, location and policy together is now a valuable procurement workaround. Real-world usage The most useful data point about whether any of this matters at scale is Meta. The company runs two 24,576-GPU clusters used to train Llama 3 and deploys Hammerspace specifically to enable live job debugging and real-time code propagation across the training pipelines. If a company with effectively unlimited engineering resources still hits a data-movement ceiling at that scale, the enterprises running a fraction of the workload are almost certainly hitting it too, and the standard answer of "buy more GPU" does not address a problem one layer below the compute plane. Flynn put the underlying joke about NFS politely. "The joke I always heard was, NFS is not for speed." That used to be true. The newer claim, that an open, standards-based file system can sit underneath an AI factory and feed it, casts the venerable file protocol in a new light. ICustomers will likely want to see an independent benchmark of this system's performance against the likes of VAST, WekaIO and NetApp in heterogeneous customer environments, using test systems not designed by the vendor. Nevertheless, it looks promising. In the meantime, the data placement architecture conversation is certainly the right one to be having. Sponsored by Hammerspace.

source https://www.theregister.com/ai-and-ml/2026/07/27/ai-has-changed-data-architecture-but-storage-hasnt-caught-up/5255880

Monday, 27 July 2026

Google has created a new taxonomy to describe cybercrime outfits, seemingly abandoning a Microsoft-led effort to create consistent names. The Big G announced its new schema on Saturday in a post that notes its 2022 acquisition of Mandiant and its subsequent incorporation into a new team called the Google Threat Intelligence Group (CTIG). Now that two have become one, Google reckons they need consistent naming conventions to describe cybercrime crews. The result is a two-word schema in which the first word “is a unique and memorable term chosen to represent the specific actor.” If security folk have already applied a particular moniker Google will use it, otherwise it will randomly generate a word “to remove bias.” Google says the second word “categorizes threat clusters by motivation, attribution, or activity type based on which category we consider to be most important for defense and response strategies.” More on that later. Google has decided on the following names: CASTLE to describe crews from the People’s Republic of China ION for threats from Iran NEPTUNE for North Korean attackers RELIC for Russians COMET for cybercrims who aren't backed by a state Google’s post notes that other infosec industry players have developed their own schemas for describing threat actors and says the web giant is therefore “intentionally seeking to keep this system as simple as possible to streamline operations and facilitate mapping to other naming taxonomies.” That’s an odd position, given that in 2025 Microsoft and CrowdStrike tried to spark an industry-wide effort to apply consistent names to threat actors. As we noted at the time, the existence of multiple naming schemas means that researchers often refer to the same group by ten different names. Researchers use the names Seashell Blizzard, IRIDIUM, VOODOO BEAR, BE2, UAC-0113, Blue Echidna, PHANTOM, BlackEnergy Lite, and APT44 to refer to the same entity – Russia's Military Intelligence Unit 74455. With most orgs using multiple security tools and therefore receiving threat intelligence security info from many vendors, users must try to understand which crews they’re trying to defend against. At the time, sources told us Google and Mandiant were keen to adopt the Microsoft-led scheme. Google’s new announcement suggest the relationship either wasn’t consummated or didn’t last. Back to the issue of possible bias, as in 2024 China's National Computer Virus Emergency Response Center (CVERC) complained that western companies choose names like “Typhoon,” “Panda,” or “Dragon” to describe Chinese cybercrime groups. CVERC suggested names that reflect English language idioms, such as “Hurricane” or “Koala” are more appropriate. For what it’s worth, “Koala” is a word from the language spoken by the Darug people, the indigenous tribe who lived around Sydney, Australia, prior to British colonization. Koalas are utterly supine creatures that sleep 18 to 22 hours a day, and a mention of the marsupials may therefore not spur defenders to action, even if the creatures’ habits do perhaps describe the behavior of some sleeper malware. ®

source https://www.theregister.com/security/2026/07/27/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy/5278749
WHO, ME? Mistakes happen, and when readers of The Register make them, we like to share those tales of woe in a Monday column we call "Who, Me?" It's our guide on how not to get ahead in the modern workplace. This week, meet a reader we'll Regomize as Clay, who in the 1980s was the most junior member of the management team on a Swedish construction site. "We had two site engineers, and they were the only ones with computers," he explained to The Register. This was a time before PCs had become ubiquitous, so Clay was curious about the machines. "One lunch break, I asked the junior engineer if I could try his PC," he told us. The junior had little choice but to comply, so Clay sat down at the machine and used the only command he knew. "It worked," he told Who, Me? "But unfortunately, that command was 'DEL *.*'" Clay had therefore deleted everything in whatever directory the engineer had allowed him to access. "Thankfully, my colleague was very relaxed and forgave me, so I got to keep my job," he told The Register. "But 'DEL *.*' still haunts me!" The moral to this story seems clear: do not under any circumstances let a suit take control of computers! Have you let a user wreak havoc on your machine? If so, click here to send an email to this column, so we can show readers how not to cause chaos on some future Monday. ®

source https://www.theregister.com/software/2026/07/27/manager-showed-off-his-dos-prowess-with-a-command-that-wiped-data/5278057
The 13th flight of SpaceX’s Starship made it off the launchpad on Friday and ticked off just about everything on the company’s to-do list. After delays and engine replacements, Elon Musk’s colosso-launcher took to the skies at beer-o’clock on Friday evening – 5:51PM Texas time. One hour, five minutes and 21 seconds later, Starship made a controlled splashdown in the Indian Ocean, where it floated after landing. SpaceX says it was able to gather critical data on the performance of Starship’s heatshield, and that the craft made “a dynamic banking move to mimic the trajectory that future missions returning to Starbase will fly.” Gathering data on Starship’s heatshield performance will help SpaceX ensure the craft is re-usable. Simulating missions that land at Starbase, SpaceX’s Texas home, builds toward future missions that launch and land at the same facility, speeding turnarounds for re-usable hardware. The test flight also saw SpaceX test a new routine for de-orbiting the Super Heavy booster used to hoist Starship into space. “The booster successfully completed the high thrust portion of the boostback burn with all 33 engines, the first time with a Super Heavy V3, before ending the burn early,” SpaceX said. “It attempted to relight its engines for the landing burn, with a subset successfully igniting before experiencing a hard splashdown in the Gulf.” That part of the mission didn’t go perfectly, as SpaceX hoped for a softer landing and more engines lighting to make it possible. Once Super Heavy and Starship separated, the latter vehicle used its six Raptor engines to reach desired speed and orbit. It then deployed 20 Starlink V3 satellites. SpaceX crew verified the sats worked and half a dozen of them got a look at Starship’s heatshield. While the satellites were functional, SpaceX did not intend them to form part of the Starlink constellation and allowed them to re-enter Earth’s atmosphere. Or as the company’s mission report put it, the satellites “demised upon reentry approximately 20 minutes after deployment.” Starship performed one more trick on its way back to Earth, by starting one of its Raptor engines while coasting through space. The success of that test again demonstrated tech that will be needed for future missions, in this case flights that push Starship into sustainable orbit – or allow it to reach a trajectory capable of reaching the Moon, as NASA envisages will be the case for future Artemis missions that land humans on Earth’s permanent natural satellite. SpaceX boss Elon Musk said he hopes the next Starship test flight will see the Super Heavy booster caught by robot arms at Starbase, another step towards improved reusability and turnaround times between flights. ®

source https://www.theregister.com/science/2026/07/27/spacex-just-about-nails-starship-test-flight-13/5278725

About

Privacy Policy

ShortNewsWeb

Blog Archive

Recent Comments

Popular Posts

Translate

My Blog List

Popular

System Admin Share

Total Pageviews