David Potter, the man who put Psion in the palm of your hand, logs off at 82
OBITUARY South African-born pioneer of the British tech industry David Potter, the man behind the iconic Psion pocket computers, passed away on 28th June, six days before his 83rd birthday. Potter was the founder of the company of the same name, a pivotal firm in the British technology industry from the 1980s to the 2000s. Psion supplied software for the early computers from Sinclair Research, the ZX80 and the ZX81, including a Flight Simulator that you can play online. In 1982, Psion supplied the bundled software with the Sinclair ZX Spectrum, and the later, the XChange suite for the Sinclair QL, later available for DOS under the name PC-Four – a deal The Register reported in detail for the QL’s 30th anniversary. In 2016, Potter was interviewed by the Archives of IT, which you can watch online: There’s also a corrected transcript [PDF], plus some edited highlights of the interview. A bold 1983 advertisement claimed: “The best software on earth comes from Psion.” However, Potter realized early on that the instability of the rapidly moving home computer market posed a problem for the company, as he explained in a 1991 interview in Personal Computer World: “What’s the longevity of this market, what’s the utility of these products, where’s it going to? And the more we asked these questions the fewer answers we could get. And we came to the conclusion that these products were of tremendous educational value, a lot of fun, but there was no real long-term utility and the market was not long term because of that. So we decided to diversify and put a lot of our development resources into two very new areas for us. One was applications software. The second area was quite a new, radical concept of a handheld computer”. This led it to create the first of the multiple ranges of pioneering hand-held pocket computers for which it is better remembered today. In 1984, Psion launched the Organizer range, and in 1986, its successor the Organizer II, which came with two slots for what were arguably the computer industry’s first replaceable SSDs. In 1989, Psion introduced all-solid-state MC laptops. Although unsuccessful, the MC’s hardware was miniaturized to create the pocket-sized Psion Series 3 in 1991, and Psion’s bespoke GUI OS became EPOC16. The machines sold in the millions, which in turn led to the Psion 5 and netBook. The Register’s magisterial history of the development of the Series 5, Psion: the last computer, covers this evolution in depth. For the Series 5, Psion designed and implemented EPOC32, a realtime-capable 32-bit Arm OS in C++. Later, EPOC32 was renamed Symbian and powered the first wave of smartphones, as The Reg covered in depth in 2010 in a two-part history: Symbian, The Secret History: Dark Star, followed by Symbian’s Secret History: The battle for the company’s soul. The Reg has reported on Potter too many times to link. We first quoted him in 1998, and most recently in 2017 when he invested in Planet Computers, becoming Honorary chairman of the company. Planet produced the Gemini pocket computer whose keyboard was licensed from Psion. In 2000, Potter sold £12.6 million worth of Psion shares, only to see them quadruple in value within months. In an interview with Management Today, he said he had a knack for badly timed share deals: “It’s always the case. I always joke that the best buying signal for Psion shares is when I sell. If you look back over the years there is a correlation between my selling and the price going up.” Reg readers would have already had an inkling: the year before, he had told us that he thought Amazon might flop, but that he was bullish about Psion’s future. By 2004, Psion sold its stake in Symbian to Nokia. Some shareholders were unhappy, but he told them Linux was a growing threat. (He certainly got that right.) Subsequently, Microsoft bought Nokia’s phone unit – then killed it as a tax write-off. Its outstanding and unique OS is FOSS now. Dr David Edwin Potter was born in East London on July 4, 1943 – but not the East London that Psion enthusiasts might expect: the East London in the Eastern Cape Province of South Africa. His father died when he was young, and as his mother had to work, he and his sister were raised by their grandmother. By the time Potter was 10, their mother remarried, and the family moved to what is now Zimbabwe. After a year (two terms) at the University of Cape Town, at 18, Potter went to Cambridge University thanks to a Beit scholarship. There he studied the Natural Sciences Tripos, followed by a PhD in Mathematical Physics at Imperial College. In 1969, he married a fellow South African, journalist Dr Elaine Goldberg [PDF]. He stayed on at Imperial, and from 1970 taught applied physics. This led him towards develop software to model non-linear phenomena on the university’s early mainframes: “I began to use these behemoths, these ludicrous machines, which didn’t remotely have the power of Psion Revo, for example. And they cost millions of pounds. I became something of an expert in them and designed substantial software systems.” This led to his interest in the then-new microprocessors: “If there are opportunities in the world you need to grasp them. I was fortunate enough to be in an area that was really going to change the world in a huge way.” In 1974, he and Elaine moved to Los Angeles, where he became an Assistant Professor at UCLA. From there, they watched the British economy go into a massive decline. He told the Archives of IT: “I saw this happening from afar, and thought, this is mad… So somebody said recently, you know, when there’s a sale on, it’s quite a good idea to buy things. So I had savings of about £3,000, and I wrote to my bank manager and I said, ‘Please invest them in the following six companies,’ which I didn’t know very much about – but I knew about Racal Electronics, about GEC, Arnie Weinstock’s great company. And anyway, four others. And, then I forgot about them, went on with my academic business. In 1975, with Elaine expecting their first child, they came back. “When I returned to Britain everything had more than doubled, and of course there was the beginning of the recovery in 1975. So, that taught me a little bit about, if you research things enough, and I was capable of research, maybe there were opportunities.” Emboldened, he moved to his next investment effort: “We had our first child in 1975. And, just to have a break I went skiing – on a packet tour down to Austria I think, and I had a very pleasant four or five days. I came back on a newish aeroplane carrying people – I used to go by train. And I looked around as we were flying back, and I thought to myself, all these Brits have been skiing, and sleeping under duvets. And so, clearly they’re going to come home, they’re going to throw away their blankets and buy duvets… So I researched whether there was a duvet supplying company in Britain, and I found one… The company was called E Fogarty.” E Forgarty & Co was a major employer in Boston, Lincolnshire, but after a hot summer, went under in 2018. “I researched it and found it had just built a new factory, and then I had the chutzpah to go and interview the chairman. I told him I was a potential investor but not how little I was planning to invest. Then I sat in the pubs outside the factory in the evening and chatted to the workers about overtime etc, and got a complete picture of what was going on. I could see the opportunity and put 40 per cent of my capital into Fogarty. The price tripled in 18 months. That was how I got my education in business and company matters, and some of the capital to start Psion.” In 1980, he bought an off-the-shelf company called Red Cheer and renamed it. He wanted to call it “Potter Scientific Instruments”, whose initials spell the Greek letter PSI (Ψ). However, the acronym was already taken, so he added “Or Nothing” to yield the name PSION. Potter was awarded [PDF] the Mountbatten Medal by the Institution of Engineering and Technology in 1994. In the 1996 New Year Honours, he was awarded a CBE – Commander of the Order of the British Empire – for “services to the manufacturing industry.” He served on the Dearing Committee for its 1997 report on Higher Education. In 2001, he became a Fellow of the Royal Academy of Engineering, and that year was also a notable Labour Party donor. He also held multiple honorary doctorates. In 2009, Potter retired from the company he founded. His other efforts have included with the charity the couple started, The David and Elaine Potter Foundation. One aspect of his activities we did not know about – apart from being a duvet entrepeneur – was that he not only contributed to the openDemocracy organization, but that in 2013, he saved it from bankruptcy. OpenDemocracy published an obituary for him before any tech industry outlet: Remembering David Potter: Industrialist, physicist, philanthropist. The Register received plaudits from a number of ex-Psion people. “Psion was a company that had a tremendous and friendly culture. It was a joy to build new technology products that were at the forefront of innovation. “All Psion handhelds included their own software, apps and operating system developed in-house from the ground up. This is extremely unusual. The devices also usually included custom silicon to improve power efficiency and performance. The teams developing these products knew they were at the leading edge, and this attracted the best talent which stayed because of the highly collaborative and friendly culture.” – Ian Fogg “At the peak of his powers, David Potter was the man who kept Microsoft’s Bill Gates awake at night. “Psion started in a small office above an estate agent in Maida Vale and grew rapidly into a FTSE-100 company. “On a personal level, David was a deep thinker, a good listener, and a genius. It was a pleasure simply to be in his orbit and he inspired a generation of leaders who are still at the top of their game.” — Anthony Garvey ® Bootnote In February this year, East London was officially renamed KuGompo City.
Amazon Leo constellation nears 400 satellites as broadband launch looms
Amazon says it is preparing to roll out satellite broadband this year after the latest rocket launch brought its Leo constellation up to 396 units. The digital bazaar and cloud computing giant reports that an Atlas V rocket launch on July 2 successfully propelled 29 satellites into low Earth orbit for the Amazon Leo network, formerly known as Project Kuiper until November last. Amazon hasn't finished flinging its hardware into orbit just yet, but said it is planning to begin providing an actual service through the network sometime this year. “With hundreds of flight-ready satellites standing by at the Cape and a new, dedicated vertical integration facility ready to support Leo Vulcan 1 and subsequent missions, we have a clear path to increase launch and deployment cadence, helping us quickly expand network coverage following an initial service rollout later this year," said director of Launch Systems Melissa Wuerl. Amazon Leo was originally conceived as a broadband-from-space setup, just like its main rival, Starlink. According to the Bezos-founded biz, it will offer download speeds ranging from 100 Mbps to 1 Gbps, depending on which of three antenna options customers choose. But in April this year, Amazon agreed to pay more than $11.5 billion to acquire Globalstar and its constellation of 24 satellites. Globalstar provides the satellite network used for Apple's satellite services, introduced with the iPhone 14 in 2022, which would give Amazon a foothold in direct-to-device satellite communications as well. With 396 satellites in low Earth orbit, Amazon has far fewer than Starlink, which boasts about 10,400 in operation at the moment. The firm has plans to loft more than 7,700 of its own eventually, but currently has a licence from the US Federal Communications Commission (FCC) for a cluster of 3,232. The terms of that licence required Amazon to have 50 percent of its planned constellation in orbit by July 30, 2026 – a deadline it is clearly going to miss. The company sought an extension in January, and this was granted last month, but with strings attached. Whether Amazon will be able to compete against Starlink, which has a significant head start, depends on a number of factors, such as the quality of service on offer. Its top-tier offering of 1 Gbps has a higher advertised maximum download speed than Starlink's current residential tiers, although real-world performance has yet to be established. Amazon has also yet to disclose what price tag its service will carry. Starlink's US residential plans cost up to $130 a month, with equipment charges varying by plan and location. UK telecoms regulator Ofcom granted Amazon Leo a license to beam its broadband down to Brit consumers over a year ago. ®
AdaptHealth says attackers sweet-talked their way into cloud systems and stole patient data
AdaptHealth says attackers used social engineering to breach its systems and steal sensitive patient data, including passwords associated with insurance billing. The medical equipment company disclosed the attack to the Securities and Exchange Commission (SEC) on Thursday, noting that attackers accessed internal patient management systems, document storage platforms, and external electronic health record system portals. The attack targeted an unwitting third-party contractor, through which the cybercriminals gained entry to the company's cloud environment, where they accessed business applications holding sensitive data. AdaptHealth activated its incident response protocols soon after the attacker contacted the company on June 15 and disclosed the theft. It did not specify whether an extortion demand was made, nor whether one was paid, and no cybercrime group had claimed responsibility at the time of writing. The company's response included disabling the contractor's user account, resetting credentials, and implementing additional access controls. It believes the attack is now contained. In addition to the "password file associated with insurance billing," AdaptHealth confirmed that personally identifiable information (PII) and protected health information of certain patients were also stolen. Social Security numbers and payment details are not thought to be affected. On June 27, AdaptHealth determined that "due to the nature and potential volume of the data that is at risk," the attack can be considered material, requiring disclosure to the SEC. The company did not comment on the exact scale of the attack or the related data theft, but said investigations continue to determine the scope of the breach. It also said it "has since taken steps intended to mitigate the risk of dissemination of the exfiltrated data." The Register asked AdaptHealth for more information, including whether it received any extortion demands and what steps it took to reduce the risk of the stolen data being distributed or misused. Pennsylvania-based AdaptHealth provides home medical equipment and related services for patients with chronic and serious conditions. Founded in 2012, it specializes in respiratory, sleep, and diabetes therapies. According to a 2024 annual report, it serves more than 4.2 million patients across all 50 US states. ®
Startup targets datacenters with 3D-printed nuclear reactor module
US startup Ampera has produced what it claims is the first 3D-printed nuclear reactor module. The firm says it is working towards delivering scalable, emission-free power for datacenters, defense applications, and off-grid sites. Ampera unveiled its first nuclear reactor module during an event at the firm's innovation center in Palm Beach Gardens, Florida. More than 100 people attended, including local officials, business leaders and employees. Founder and CEO Brian Matthews revealed the prototype microreactor, which features a fully 3D-printed silicon carbide reactor core and pressure vessel. "This next-generation nuclear core and pressure vessel sets the foundation for factory-built, mass-produced nuclear energy," Matthews said. "The advanced technology and additive manufacturing used demonstrate a clear commercial path for new nuclear technology coming to market in an accelerated manner." His company is developing a subcritical, solid-state, factory-built thorium-based nuclear reactor. Subcritical means the fuel cannot sustain a nuclear chain reaction on its own, which prevents a runaway power excursion. Ampera uses "solid-state" to describe a design with solid rather than liquid fuel. The proposed fuel uses tristructural isotropic, or TRISO, particles, consisting of a fuel kernel containing thorium, surrounded by multiple ceramic and carbon layers. Thorium-232 is not fissile. After absorbing a neutron, it ultimately decays through thorium-233 and protactinium-233 into fissile uranium-233. This requires a separate source of neutrons, and Ampera says its design features a proprietary neutron driver to provide a stable external neutron source to start and sustain operation. In June, Ampera announced it had established an Australian subsidiary to secure thorium supplies, and said it plans to produce the fuel kernels itself. "Thorium is the future for ultra-safe, clean power production," Matthews said at the time. "By producing TRISO thorium kernels in the United States, we can ensure ample access to the needed fuel supply as we scale up and also minimize price volatility risk." Ampera also describes the heart of the reactor as as a spherical monolithic gyroid core. A gyroid, as far as we can fathom, is a complex shape that provides a massive surface area relative to its volume, making it well-suited for heat transfer. Its complexity makes it difficult to produce using conventional manufacturing methods, which is where additive manufacturing comes in. The core is 3D-printed using silicon carbide and designed to operate for up to 30 years without refueling, the firm claims. Ampera says its planned systems will provide 15 or 30 MWe, depending on the configuration, enough to supply a typical datacenter. Larger configurations are planned. Matthews said that his company expects to be the first to industrialize factory-built nuclear power with near-term deployment timelines. When The Register asked about availability, their spokesperson said: "We expect the power generation portion of the system to be available as early as 2027, with the nuclear module being available to customers about 2030 based on regulatory approval." We also asked how neutrons are generated for startup and operation of the reactor module by the Neutron Driver, but Ampera is keeping this under its hat for now. As well as datacenters, defense customers will be likely takers if Ampera can produce reliable working reactors. Earlier this year, the US Department of the Air Force (DAF) announced it was looking into microreactors for three of its sites, part of a program aimed at improving energy resilience during grid outages. ®
NetNut cracked as Google and FBI target 2 million-device botnet
Tech companies working with US law enforcement "significantly degraded" the NetNut residential proxy network as part of an ongoing effort to disrupt the tools cybercriminals use to conceal their activity, say researchers. The work was carried out by Google, Lumen, Shadowserver, the FBI, and others, and marks a continuation of the IPIDEA proxy network disruption from January. According to Google Cloud, those working on the operation believe NetNut was among the most popular residential proxy network providers and had at least 2 million devices enrolled in its botnet, comprising mainly small TV-streaming hardware. Crims often use residential proxy networks to make it look like their traffic is actually coming from legit homes and businesses. In the same way that other residential proxy networks expand their pool of enrolled devices, NetNut distributed its own SDK via these devices. Proxy providers often approach users under the guise of monetizing their spare bandwidth, paying them a fee in exchange for letting their SDK run on their devices. The official advice is, of course, to refuse any offers of this kind. Not only does it help feed the cybercrime ecosystem, but it can also lead to vulnerabilities elsewhere in home networks. NetNut offered its own standalone proxy networks, as well as mobile and datacenter proxies, and a slew of scrapers and datasets. However, it also offered a reseller program, and experts believe many other residential proxy networks are powered by NetNut's own, which means the disruption may have further downstream effects. "While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient," Google's Threat Intelligence Group (GTIG) said. "What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller. "We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers. We will continue to observe the composition of the NetNut network and map out how its peers adapt to this action." Residential proxy networks are not illegal, although they are often abused for cybercrime. These networks are ostensibly pitched as a means to shore up online privacy, and promote ideals such as freedom of expression without risk of being traced. However, the same privacy-preserving features of these networks are used by cybercriminals to mask their malicious activity. They enroll ordinary devices, which are connected to innocent residential networks, at scale and offer them to customers as exit nodes. Cybercriminals can make use of these networks to channel their traffic through these nodes, making the traffic appear to originate from an IP address they do not control. "In a single week during June 2026, GTIG observed 316 distinct threat clusters using suspected NetNut exit nodes, including cybercriminal and espionage groups," said Google. "These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks." Reports also suggest that NetNut has a role to play in other botnet families. GTIG said it found plugin components for large-scale botnets such as Badbox 2.0, while other public reports have noted signs of NetNut being used to infect devices with Mirai variants. The Register asked GTIG why NetNut's second domain (netnut.io) remains online, while netnut.com returns a "This website has been seized" splash page, but it did not immediately reply. Google's announcement hinted at similar takedowns to take place in the future, as the residential proxy network market continues to grow. However, it said these ad hoc disruptions are only effective for so long, and that a long-term approach would require support from ISPs, mobile platforms, and other technology companies. ®
AI bills are baffling the C-suite after shift to usage-based pricing
Nearly a third of corporate leaders report difficulty understanding and controlling operating costs when implementing business AI at scale, according to a survey from KPMG. In recent months, Anthropic, OpenAI, and GitHub have shifted some services away from flat-rate subscriptions toward usage-based billing. "As usage-based pricing models become more common, many organizations are still building the capabilities required to forecast, monitor, and manage AI spending effectively," KPMG said. The survey of 2,145 senior leaders across 20 countries found that 29 percent struggle to understand their operating costs as they scale their enterprise AI deployments. A third of senior corporate leaders also identified limited understanding of AI costs and economics as a challenge to deploying AI agents. Businesses are rethinking their AI plans in the face of changing cost structures and rising fees. The research also found nearly half of organizations have rephased AI deployments when costs have outweighed the expected value. Lower-cost, high-fidelity models are the fastest-growing influence on AI strategy, up 7 percentage points from Q1. "These actions do not signal reduced confidence in AI. Rather, they suggest a growing willingness to evaluate where AI creates meaningful value and where it does not. Organizations appear increasingly focused on concentrating investment where expected returns are strongest," the report said. Amazon plans capital expenditure of around $200 billion this year, largely to provide capacity for AI in its AWS datacenters, an increase of 50 percent on a year earlier. Microsoft's total capex is expected to reach $190 billion, up 61 percent from the previous year. Both companies are now investing significantly in forward-deployed engineering to help customers develop AI applications that will generate demand for the capacity being built. Amazon has announced a $1 billion investment in an AWS Forward Deployed Engineering organization help customers adopt AI agents and reduce timelines for deployment. Microsoft is providing $2.5 billion in funding for a new operating entity called Microsoft Frontier Company, "enabling customers to amplify their IQ with AI while refining their differentiated value in the markets that they serve." In the KPMG report, challenges remain around AI governance: the question of who takes responsibility for decisions made by statistical models prone to erroneous outputs – or "hallucinate," as tech vendors would prefer. KPMG said executive accountability is important, but "governance ultimately succeeds or fails through day-to-day operating practices." "Organizations need clear rules for when employees can intervene, who owns AI-related costs, how AI outputs are reviewed and what happens when systems fail. While most organizations report having at least some governance mechanisms in place, relatively few describe these practices as fully embedded," the report said. Perhaps the tech consultancy and services giant speaks from experience. Last month, research outfit GPTZero claimed a forensic review of KPMG's October 2025 report, "Total Experience: Redefining Excellence in the Age of Agentic AI," found that only five of its 45 citations pointed accurately to the cited source. The rest contained errors ranging from misleading or invented details to references that were too vague to verify. KPMG later removed the report from some of its websites and issued a statement. "KPMG International takes the accuracy and integrity of its published content seriously. The report has been removed and we are reviewing the circumstances surrounding its publication. We expect all our people to follow our guidelines on the responsible use of AI, including human oversight to validate content and verify independent sources," a spokesperson said. ®
EU appears to find datacenter emissions easier to offset than lobbyists
The European Union's proposed environmental rating system for datacenters may be amended in response to lobbying from IT industry heavyweights, making it easier to offset greenhouse gas emissions using clean energy certificates. According to the Financial Times, the European Commission is weakening its original proposals after pressure from datacenter operators and tech giants. The newspaper claims to have seen the revised draft of the regulations, set to be discussed by representatives of member states on Thursday. We asked the Commission for comment on the leaked draft. The Commission published a draft regulation in March proposing an A-to-G rating scale for datacenters, based on their energy and water efficiency. The system is intended to incentivize greater sustainability in their operations, especially as bit barn capacity is expected to expand greatly over the next decade, thanks to huge demand for AI and cloud services. That earlier draft specified that facilities could offset greenhouse gas emissions by investing in clean energy certificates, but only if the projects concerned were in the same region as the data campus itself. It is understood that this has been amended so that facilities operating in one country can offset their emissions by obtaining certificates from renewable projects in a different EU state. The proposed change was made at the behest of companies and lobby groups that argued it would increase their operating costs. The EU's efforts to press datacenters and other large energy users into adopting greater efficiency and sustainability measures have met with varying degrees of pushback. Last year, the Climate Neutral Data Centre Pact (CNDCP) expressed concerns about standards for data campus efficiency the European Commission was considering, based on feedback from mandatory reporting introduced in the Energy Efficiency Directive (EED). The group lists tech giants AWS, Microsoft, and Google among its signatories, as well as datacenter operators like Digital Realty, NorthC, and Vantage Data Centers. Also last year, the Cloud Infrastructure Service Providers in Europe (CISPE) trade body was critical of the EU's Water Resilience Strategy, warning that burdensome regulatory demands regarding water use might prompt operators to build outside Europe. Another body, the European Data Centre Association (EUDCA), issued a statement this week affirming its "unwavering commitment" to climate-neutral datacenters and sustainable digital growth. But it warned that Europe will not be able to "unlock the digital infrastructure capacity required for its AI and digital ambitions" without addressing structural challenges in the electricity system, including expansion of transmission and distribution grids, faster and more transparent permitting processes, and stable access to low-carbon electricity. Meanwhile, Europe needs a policy framework that integrates water and energy efficiency if it wants to keep growing datacenter capacity to support its AI and cloud computing ambitions, according to a recent report. The proposed environmental rating system is still listed as due for adoption in the third quarter of this year, but debate over the changes may push that back further. ®
Databricks unifies OLTP and OLAP, depending on what counts as a copy
When Databricks claimed to have cracked an age-old database problem, it came with a clear marketing message: "One data, zero compromises, zero copies." Inevitably, that led engineers to search for clarity. After all, the company claimed to have unified OLTP and OLAP with "no data duplication." Databricks, which was founded around the open source unified analytics engine Apache Spark, called its invention LTAP, which stands for lake transactional/analytical processing. It works with Reyden – a new compute engine – and Lakebase, its serverless PostgreSQL on open object storage. Databricks is attempting to address a fundamental database challenge. OLTP (online transactional processing) performs small, row-oriented reads and frequent writes, while OLAP (online analytical processing) performs large, column-oriented reads and batch writes. Down to the physical level, it is challenging to get the two to coexist in a single system. The issue is seen as more pressing now as the database market chases workloads created by the booming deployment of AI agents, both in software development and business applications. What did Databricks claim? The publicity material said that rather than forcing both OLTP and OLAP workloads into one engine or concealing the pipeline, it unifies data at the storage layer, thereby unifying transactions, analytics, streaming, and operational data on a single copy of storage in the data lakehouse, a concept Databricks created to describe the marriage of data lakes and data warehouses. Does that mean there are "zero copies" of the data, as claimed in several promotional LinkedIn pieces and a Forbes CEO interview? Well, not quite. The transactional side of LTAP is based on Databricks' first fully managed PostgreSQL database, Lakebase, which in turn is based on technology from Neon, which Databricks bought last year to provide copy-on-write branching and autoscaling serverless compute. In his search for clarity, one data engineer in financial services posted that LTAP proposes that the current PostgreSQL data stays in the pageserver format as local storage then is propagated to object storeage for long-term durability in the Parquet file format, where it can be queried in a columnar format. PostgreSQL/Lakebase can retrieve data from the object store and reconvert the Parquet data to a pageserver if it needs data from cold storage. In this way, Databricks has "unified" the OLTP storage and OLAP storage. "Two copies of data, not one," quipped one commenter from a Databricks rival. Slides made available at a PostgreSQL conference in May make the link clear. Under the header "Analytics directly on OLTP data," Databricks engineers Hristo Stoyanov and Jonathan Katz said that pageserver provides storage while the Spark analytics executor pulls layer files containing full page images from the image layers in object storage. On a private messaging community seen by The Register, one Databricks engineer responded to the question about whether there was one copy of the data or two copies in object storage and pageservers respectively. Technically two, they responded, since pageservers act as a cache or materialization layer in the Neon architecture. PostgreSQL reads from pageservers, while the analytics engine reads PostgreSQL pages from object storage (Apache Parquet or Iceberg table format) and pageservers. Databricks is far from alone in trying to crack this nut. Unifying OLTP and OLAP has been tried before, and solved, according to some companies. For example, in 2014, SingleStore began working on an in-memory row store and an on-disk column store with tiered storage, "meaning transactions hit memory first and then they roll off to disk storage," allowing analytics and transactions on a single system. It launched a cloud database service (on AWS, Azure, or GCP) in 2020, which "automatically manages data across a three-tiered storage architecture comprised of memory, local cache, and storage." It moves data "seamlessly" between memory, persistent cache, and object storage without the user being aware, the company says. Not surprisingly, SingleStore was quick to post its reaction to Databricks' claim that hybrid transactional/analytical processing (HTAP) had effectively failed. "You don't get to call HTAP a failure and then spend the next 20 minutes describing why the world needs exactly what HTAP promised. Unifying OLTP and OLAP so an agent can read and write in one place is the HTAP goal, whatever you print on the slide. Renaming it LTAP changes the marketing. It doesn't change the physics, and it doesn't retire the questions," SingleStore CTO Nadeem Asghar said in a blog post. He pointed out that Databricks' claim of "one copy" of the data is about storage, not about the engine. "Three engines still sit on top, each with its own cache, its own sense of how fresh the data is, and its own way of failing at the worst possible moment. Databricks' own framing: a row layout and a columnar layout are different things. If a write lands in a row representation for Postgres and analytics reads a columnar representation, then you have two physical shapes of the same data, and something has to keep them in step," Asghar said. There are other examples of efforts to bring together analytics and transactional systems. MongoDB offers column-store indexes to help developers build analytical queries into their applications. Oracle's HeatWave for MySQL runs on Oracle Cloud Infrastructure and helps customers run analytics on transactional applications without having to export data to a specialist analytics system such as Teradata, Snowflake, or AWS Redshift. SAP has talked about real-time analytics since 2011, and bases its concept around its in-memory database, HANA, which supports the latest iteration of SAP's enterprise applications. Databricks maintains its "zero copy" claim is true because it avoids having two authoritative copies of the data that need to be kept in sync. In a statement to The Register, a Databricks spokesperson said: "In LTAP, the user only operates on one authoritative copy of the data. [It has] one source of truth data in Iceberg (an open source table format which contains Parquet files). Yes, any database system, even a single individual database, always has many intermediate internal copies of data, ranging from memory L1/L2/L3 cache, to DRAM memory, to non-volatile storage, to blob storage etc. This is referred to as 'the database storage hierarchy.'" In presentations at its recent conference, Databricks qualifies the claim in several ways. There's only one "authoritative" copy of the data, or there is one copy of the data "in storage" or "in the lake." In effect, it is the same approach SingleStore employs when it says its storage tiers are "transparent to the user." Regardless of the marketing ding-dong, Databricks has done some impressive engineering in the way its new Lakehouse execution engine, Reyden, can read PostgreSQL pages, according to Andy Pavlo, associate professor of databaseology at Carnegie Mellon University. "They are copying data out eventually," he told The Register. "But initially Databricks is able to have the Neon/PostgreSQL front end read the writes as it normally would, but then the Reyden engine can read those writes, and that part is not easy." "The Reyden analytics engine has the ability to now interpret the contents of the PostgreSQL pages, which is a non-trivial thing to do, because the pages are not entirely self-contained, meaning that information about what you're allowed to see, or even what the data is, is stored in separate pages, so they have the mechanism to then go back into Neon/PostgreSQL and get that metadata from the catalog." "Anybody can go and read a PostgreSQL page. It's not hard to write code to read a single page of data. The challenging part is being able to understand what you're allowed to see or what the query is allowed to read from that page, because they intermix all the different versions, then [Databricks] has got to resolve that as well. All that is not trivial." "Basically, it allows you to do faster analytics, or more timely analytics, without the delay of waiting for things to get shoved out to S3 and you do it in a transaction-safe manner." Meanwhile, the Reyden analytics engine is stateless and can scale horizontally "very well" by adding more compute, Pavlo said. Databricks might have produced some impressive technology by bringing transactional and analytic workloads closer together. But in the way it presents its work, critics might argue it should be careful what it wishes for. It would be a shame if its overzealous marketing claims cast a shadow over its significant engineering achievements. ®
User swore hacker called General Failure had invaded his PC
ON CALL Fronting up to work on Friday morning can feel like a mistake, but The Register tries to make it worthwhile by bringing you a new installment of On Call – the reader-contributed column that shares your tech support stories. This week, meet a reader we'll Regomize as "Lee" who told us about his time as sysadmin at the headquarters of a retail company. "It was about the year 2000 and I was a newly minted Certified NetWare Engineer administering Novell servers," Lee reminisced. Before long, Lee was running the teams that managed email servers and provided desktop support for over a thousand users. "I got to know just about everybody in the HQ and became known as the go-to guy for all things technical," he proudly told On Call. One Friday afternoon, a vice president called to complain he couldn't access any files from his PC because someone else was using them. Lee found this a little odd, so he asked if the veep was seeing a "file in use" dialog in Word or Excel. The veep replied that he was indeed seeing an error that read "General failure is reading Drive C" – but that was obviously someone using the handle "General Failure" to mask their identity. Lee's next question was very precise. "I asked if the error message read 'General failure is reading Drive C:'" he told On Call. The VP re-read the dialog and corrected himself, telling Lee the exact text was "General failure reading Drive C:" At this point, Lee had good news and bad news. The bad news was that the error meant the VP's disk had died. The good news was that nobody was using the handle "General Failure," so the company didn't have a miscreant rummaging around on the network. Lee arranged a support call and advised the veep that he would be getting a new disk and might even be in line for a whole new PC. Have your users misinterpreted an error message? If so, click here to send On Call an email. We can't be clearer than that – or more sincere in our desire to share your story with your fellow Reg readers. ®
Failed blockchain project ends with big fine for fibs about it being on track
The attempt by Australia’s Securities Exchange (ASX) to replace its core trading platform with a blockchain-based system has ended with an A$20.5 million fine ($14.2 million/£10.6 million), further humiliation after the project flopped. The ASX runs a platform called the Clearing House Electronic Subregister System (CHESS) to process and track trades on its exchange. In 2017, the ASX decided to replace CHESS, citing difficulties maintaining the application, which the bourse coded in COBOL and ran in OpenVMS on Itanium processors. The ASX is a listed company so its own shares trade on CHESS. The organization decided to replace CHESS with blockchain-based architecture. As explained in its 2019 annual report [PDF], the ASX believed its decision would help it “develop new services that improve the efficiency and standardisation of processes, reduce operational risk, and create new opportunities for growth and innovation.” That optimism was utterly misplaced because the project foundered and missed deadline after deadline. But in February 2022, the ASX issued a statement [PDF] in which it described the project as “progressing well, with the fully integrated industry test environment open and operating successfully.” In the months that followed, the organization issued a string of statements about difficulties with the project and expected deployment delays. The ASX ended up abandoning the project. In 2024, financial regulator the Australian Securities and Investments Commission (ASIC) sued, alleging that claim all was well with the CHESS replacement was a misleading statement. The regulator argued that as both the market operator, and a listed company itself, any misleading statements from ASX had the potential to undermine confidence in the entire Australian securities market. ASX and ASIC settled the matter in June, and the bourse admitted [PDF] to having misled investors. Australia’s Federal Court today handed down its judgement in the matter, noted that the ASX admitted its errors, but still ordered the bourse pay the A$20.5 million fine, plus ASIC’s A$3 million ($2.1 million/£1.55 million) costs. A parliamentary report [PDF] on the project found three reasons why it failed. One was that the ASX didn’t properly define its objectives. Another was that the company kept adding new requirements but started building the CHESS replacement anyway, meaning the planning and deployment phases of the project overlapped. The report also found “scalability risks were not properly identified and managed; with the result that it was never clear whether the proposed blockchain technology could in fact adequately replace the existing CHESS system.” Those problems weren’t apparent to the outside world, where the Blockchain community regarded the ASX’s decision as a sign distributed ledger technology was suitable for even the mission-critical role of running a stock exchange. The Register offers that assessment based on this account of AWS investigating whether it should get into the blockchain business. The author, a former AWS exec, explains how he was sent to Wall Street to research Blockchain, and often heard the opinion that the ASX’s project meant the technology must have merit. AWS did not become a major blockchain player. And the ASX clearly regrets making the attempt. ®
Amazon’s Mechanical Turk to stop accepting new customers – and not even AI can save it
Amazon Web Services will stop accepting new customers for its Mechanical Turk crowdsourcing service, and not even AI can save it. Mechanical Turk is a crowdsourcing marketplace that allows users to post gigs, and workers to bid for the chance to do them. The service's name references an 18th-century machine that its inventor claimed could play chess - but which was actually operated remotely by a human. AWS launched Mechanical Turk in November 2005 – a time when the cloudy concern focused on giving developers access to the functions of Amazon’s retail operations. The outfit’s now-mainstream infrastructure-as-a-service offerings debuted in 2006. Amazon quickly claimed Mechanical Turk was a hit. The platform was arguably a pioneer as it pre-dated other crowdsourcing services like Freelancer and Fiverr. In 2018, AWS suggested a new reason to use the service: having humans review and annotate data used to train neural networks as part of its SageMaker service. Earlier this week, AWS added the Amazon SageMaker AI – Mechanical Turk service to its list of “Services in Maintenance” – AWS-speak for services it will soon retire. The Mechanical Turk website also added a warning that it will “be closed to new customers, effective July 30, 2026. Existing users will not be impacted by this change.” We checked with Amazon, and the cloud colossus told us that notice means Mechanical Turk will stop accepting jobs for SageMaker and all other tasks. The end of the OG crowdsourcing platform is therefore in sight. Amazon hasn’t explained why it’s decided to retire the Turk, although as is often the case it has developed competing services like SageMaker GroundTruth. AWS also allows integration with third party crowdsourcing services. On a subreddit dedicated to Mechanical Turk, posters suggest the service’s best days are a long way in the past, and that Amazon has been closing workers’ accounts on short notice and without offering detailed explanation for the decision. Shrinking the crowd of crowdsourced workers seems like a fine way to make Mechanical Turk useless for even its most dedicated customers. ®
In a volatile world, a consistent sustainability policy is critical
Sustainability demands progress on several fronts at once. For example, societies must reduce factory energy use, roll out EVs, and ensure that communications equipment can operate off-grid to extend educational opportunities to children in remote areas. China-based telecoms giant ZTE pursues all of these. CDP, a non-profit that runs an environmental disclosure system, has included the company on its CDP A list for the last three years. ZTE's progress against ambitious goals for carbon emissions reduction and digital inclusion is detailed in its 2025 Sustainability Report. ZTE's Chief International Ecosystem Representative, CHEN Zhiping, says ZTE has always viewed sustainability as an essential part of its DNA rather than a temporary initiative, with the company reporting on its progress for the last 18 years. Even so, they add, the business has had to adjust its strategy "to keep pace with the evolving global landscape." The report shows how ESG runs through the corporation from board level down to the individual teams responsible for executing the strategy, and outward into the supplier and customer ecosystem. It takes a double materiality assessment approach to sustainability, weighing each topic on both its financial impact to the company and its broader social and environmental consequences. ZTE's Digital Green Path strategy underpins these efforts across four dimensions that target science-based sustainability goals: corporate operations, supply chain, digital infrastructure, and industry empowerment. On the technology side, the telco's Connectivity + Computing strategy ties AI and ICT together. It says that AI transformation depends on infrastructure that spans both connectivity and compute, and must do so as sustainably as possible. That premise feeds into ZTE’s All in AI, AI in All strategy, which envisages AI transforming both industrial and consumer technology. As CHEN Zhiping claims, "ZTE deploys AI aggressively to cut emissions and improve resource efficiency, while simultaneously reducing AI's own footprint through energy-efficient design, green infrastructure, supplier engagement and governance, and beyond." That approach is essential, as AI itself poses a serious sustainability challenge. The buildout is already absorbing huge and rising amounts of energy. The International Energy Agency reported this year that electricity consumption from datacenters is set to double by 2030, with "power use from those focused on AI ... poised to triple." AI risk and opportunity ZTE's own transition risk analysis acknowledges that the expansion of AI datacenters "poses serious challenges for most operators in achieving carbon neutrality by 2030." That makes power management and longer-term sustainability central to product design. An integrated approach to power efficiency across compute and communications infrastructure lets datacenter operators and telcos alike extract more value from their investments and meet their own ESG obligations. At the same time, says CHEN Zhiping, "AI is a powerful enabler of sustainability – helping industries forecast renewable energy supply, optimized energy consumption, monitor emissions, and improve efficiency across the value chain." ZTE is bolstering this with a dedicated carbon-reduction program for its computing products, alongside work to refine AI algorithms and computing-networking products. In 2025, the Sustainability Report shows, the corporation installed the first batch of immersion liquid-cooled datacenters in China, for China Telecom Intelligent Cloud Base Huailai Park. The installation will deliver in a PUE of 1.15 and save more than 1.1 million kWh of electricity per year. This site is expected to be a model for other datacenter developments in the country. When it comes to its networking products, it said a combination of improved battery designs, dynamic energy saving technologies, and network search optimization for communication modules, means its latest flagship mobile phones achieved an approximately 30% improvement in overall battery life compared with the previous generation of flagships. While ZTE’s sustainability strategy focuses on measurable science-based targets, it does not ignore the human dimension. The Sustainability Report shows that ZTE treats digital inclusion as inseparable from its engineering focus on green outcomes. Wireless and communications technologies widen inclusion in their own right, particularly by extending educational opportunities into remote rural areas. There’s plenty to play for. CHEN Zhiping points out that more than a quarter of the world remains unconnected, but raw connectivity alone isn't enough. ZTE asks whether a solution is affordable, stable, and accessible, which means weighing how quickly and easily technology can be deployed and, increasingly, whether it can run off-grid on sustainable power. In practice, that includes developing local telco talent in Vietnam through university collaborations and supporting schools in the country. More immediately, ZTE deployed communications hubs and emergency supplies in Myanmar after the country experienced a 7.9 magnitude earthquake. Those human-focused efforts also deliver measurable outcomes. In 2025, with its registered volunteers surpassing 20,000, ZTE implemented 89 public welfare projects across 15 countries and regions, which directly benefited more than 100,000 people. Supply side solutions Sustainability depends on ecosystems, and businesses sit inside them. ZTE puts considerable effort into helping its suppliers improve their sustainability. "We set clear ESG requirements for suppliers via contractual clauses and regular audits," says CHEN Zhiping. The corporation also provides training and guidance on carbon accounting and emission reduction. In 2025, ZTE completed ESG audits for 270 suppliers, while more than 450 supplier representatives attended ESG training sessions. The results are measurable. The latest Sustainability Report shows that in 2025, ZTE's electricity purchases fell 16.3 percent against 2021, for cost savings of almost CNY100 million. Overall energy efficiency, measured in tons of coal per CNY100 million of revenue, improved 28.39 percent. Operating carbon emissions fell 46 percent, with a compound annual reduction rate of 14.3 percent. Reductions on this scale require attention to every part of the business. At the Shanghai R&D center, ZTE upgraded the chiller plant, swapped legacy chillers for high-efficiency magnetic levitation models, and installed matching cooling towers and pumps. The work boosted the plant’s energy efficiency ratio and delivered an overall energy saving rate of 46 percent. More broadly, carbon assessments on more than 240 products gave it full coverage across product categories. At the other end of the scale, ZTE's green factory approach cut energy consumption per unit of output by 22.1 percent across its five manufacturing bases. Green logistics means its Chinese warehouses rely on 100 percent electric forklifts, proof of delivery is 100 percent electronic in China, and 20 percent of domestic last-mile delivery uses “new energy” vehicles. Other strategies are more prosaic, such as powering down R&D environments during idle periods. And “extreme energy-saving measures” during short holidays saved a cumulative 820,000 kWh in 2025. The targets ahead are demanding. They include cutting scope one emissions (directly owned and controlled) and scope two emissions (indirect emissions from purchased energy) to under half their 2021 levels by 2030. ZTE also promises a matching reduction in scope three emissions (all other indirect emissions that it does not directly control) without raising the total. By 2050, it aims to reduce total emissions, including operations and the value chain, by 90 percent against 2021, with the remainder offset or removed. So far, ZTE has cut scope one and two emissions by 46 percent. In 2025, absolute emissions across the full lifecycle of terminal products fell by 3.05 percent. Every business will face sustainability challenges over the coming years. As CHEN Zhiping explains, ZTE intends to use advanced technologies, including AI, to accelerate the green transformation, build and upgrade digital infrastructure, and promote digital inclusion. But one company can only do so much. To meet the global challenge, ZTE says collective action will be needed, spanning government, business and other stakeholders. When it comes to AI, “Key priorities include establishing unified global standards to measure AI's resource and carbon footprints, rolling out strict AI governance and ethical guardrails,” says she. And there will have to be a broader scaling up of renewable energy and low-carbon tech for computing systems, and maturing circular models for AI hardware. ZTE’s sustainability strategy may have turned 18. But the hard work is just beginning. Sponsored by ZTE.
Dev says Google warned him about account hijack – then charged him $11,000 anyway
During a 48-hour period from June 7 to 8, developer Charles Jones's Google Cloud account registered $11,089.77 in charges - most related to the use of Gemini image-generation models. Yet Jones, a solo developer who runs programmatic SEO and insurance sites, told The Register that he doesn't have any workflow that generates AI images. Google suspended his account anyway. A suspension notification sent to Jones on June 7 justified the decision by stating his account "was engaged in abusive activity consistent with hijacked resources." "The root cause was attributed to a compromised firebase-adminsdk service account key," said Jones, who provided The Register with documentation of his exchanges with Google Cloud support. The notification advised Jones to report his concerns if he believed the account was compromised by a third party. He did so and took the steps required by Google to have his account reinstated. He disabled the service account and revoked the key. But the Google Cloud billing team has repeatedly refused to forgive the charges. As we reported previously, complaints about charges arising from fraudulent API key usage among Google Cloud customers are not uncommon. In February, a developer based in Vietnam claimed that a Google Cloud API key compromise had resulted in more than $82,000 in charges over 48 hours. A similar report claiming more than $10,000 in fraudulent charges surfaced a month later on Reddit. Regardless of where the fault lies – insecure practices by developers or insecure Google infrastructure – Google may choose to hold developers liable for unauthorized charges, even if the credit-card issuing bank has reversed the charge as fraudulent. At the same time, Google still hasn't publicly released a mechanism to cap Google Cloud spending. The company introduced Spend Caps for certain services as a private preview but hasn't made the service generally available. Other cost-limiting measures, like API-specific usage limits "aren't designed to act as a project-wide spending cap." Similarly, Budget Alerts "don't automatically prevent the use or billing of your services when the budget amount or threshold rules are met or exceeded." Google provides a workaround by allowing Budget Alert notifications to disable cloud billing, but warns that doing so means "resources might be irretrievably deleted." In March, Google introduced project spend caps for the Gemini API as an experimental feature, but at the same time the company said that spend caps have a 10 minute delay and customers are responsible for spending during that period – so the company's definition of cap is rather flexible. What's more, Google said its system "now automatically upgrades you to the next [usage] tier as your usage grows and your payment history matures." And higher tiers raise spending caps. This all means it can still be a challenge for Google Cloud customers to avoid unbounded financial obligations in the event of an account or API key compromise. Escaping that responsibility requires engaging with Google customer service in an opaque appeals process in which the company isn't required to demonstrate customer negligence or an audit trail. "Here's a question I can't get answered, and I think it's central to the whole pattern," Jones said. "Google's Trust & Safety was quick to alert me that a service account key was compromised — but I have been given no route, anywhere, to see HOW or WHERE that key was actually exposed. There is no trace, no log path, no forensic detail offered." Jones said he was the only person who had access to the VM where the compromised key resided and he insists that he followed the company's recommended security practices. "So how does a single-access VM produce a leaked service account key — and why is the burden on me to prove I secured something Google itself can't (or won't) show me how I failed to secure? Google is invoking its Shared Responsibility Model to deny the refund, but that model assumes a customer security failure Google has never demonstrated." The Register twice asked Google why it would deny a refund and what evidence it has that supports that decision. We've not heard back. ®
Startup sues Palo Alto Networks' Koi Security, saying an AI-hallucinated report falsely linked it to Chinese espionage
MeetingTV has sued Palo Alto Networks after its newly acquired Koi Security threat-intelligence biz published a blog that linked the video conferencing and webinar startup to a Chinese corporate espionage operation. The legal complaint filed against Koi Security, its researchers, and Palo Alto Networks alleges that Koi used an LLM to generate the threat report, the AI system hallucinated findings about MeetingTV, and the security shop then published those as facts in a December 30 blog. It accuses Koi of “reckless publication of an AI-driven cybersecurity report that falsely accused Plaintiff MeetingTV Inc. of criminal conduct including operating core infrastructure for a well-funded Chinese criminal organization running a large-scale malware and corporate espionage campaign,” according to court documents [PDF]. “The false attributions were the direct product of Koi’s unsupervised reliance on their proprietary ‘Wings’ analytical platform, which generated erroneous correlations between the Plaintiff’s business and an alleged cybercriminal actor they called DarkSpectre,” the lawsuit continues. A Palo Alto Networks spokesperson told The Register that the company “is aware of the lawsuit brought by MeetingTV Inc. regarding a threat research report published by Koi Security prior to the acquisition,” but declined to answer our specific questions about MeetingTV’s allegations and the Koi blog. “We believe Koi’s cybersecurity research reflects its commitment to identifying and exposing threats to users and enterprises, and we expect that this dispute will be resolved through the appropriate legal process,” the spokesperson said. Koi’s blog, which has since been silently edited to remove references to MeetingTV’s product called Zoomcorder, originally labeled the meeting recording service as a “public-facing front” for a Chinese criminal operation and said it lent “credibility to the infrastructure while serving as a monetization channel” - allegations MeetingTV disputes in its lawsuit. The blog also claimed the operation was behind a 2.2-million-user campaign stealing corporate meeting intelligence. As a result of the report, MeetingTV says, security companies and service providers around the globe blocked MeetingTV’s domains and services, labeling it as malware and command-and-control infrastructure. The startup’s founder and CEO, longtime entrepreneur Michael Robertson, told us the blocks are the only way he found out about the Koi report in the first place. According to Robertson, Koi did not reach out to MeetingTV prior to publishing its threat report. “Even after publishing they never contacted us,” he told The Register. “I was contacting the security companies one by one asking them to unlock us. Most never respond in any fashion, but one finally did respond and told us he was blocking us because of the Koi report and he gave us the url.” Robertson says he’s still struggling, as providers including Verizon and Palo Alto Networks, which completed its Koi acquisition in April, continue to block his startup. “If people on the internet are blocked from reaching your company, then that's a death sentence,” he said. “Plus all the LLMs now say we're working with Chinese cyber criminals. How will that ever get removed?” After the acquisition closed, Robertson emailed Palo Alto CEO Nikesh Arora directly and asked him to take action. “Now your company owns Koi and is continuing to publish and rely on the false report,” the email said. “Our domain and Google subdomains are blocked and labeled as malware and command and control by your company and others around the world … Take down the false report which is defaming us and in its place put a full retraction. Remove our domains from your own blacklist and help get them removed from others who are blocking us because of the Koi report.” A mysterious extension The December blog linked Zoomcorder to the Zoom Stealer campaign, which it attributed to the Chinese threat actor DarkSpectre, via a browser extension identified as "Twitter X Video Downloader." According to Robertson and the lawsuit, however, this extension doesn’t exist – and Koi “refused to supply information” about the software when MeetingTV requested it. “Koi’s single-actor theory rested on a fabricated technical ‘pivot’ – a single piece of software they repeatedly identified as the ‘Twitter X Video Downloader’ extension,” the lawsuit alleges. “This alleged extension was described as the critical bridge connecting the Zoom Stealer campaign (defined entirely by Plaintiff’s infrastructure) to ShadyPanda, core DarkSpectre infrastructure.” Robertson said he believes Koi used an LLM to generate the threat report, and it hallucinated findings about MeetingTV’s Zoomcorder product that the security shop published as facts. “They admit to using AI for their analysis,” Robertson said. “Maybe a human made it all up? Maybe it was AI? What's clear is that if the software doesn't exist, then even the most rudimentary analysis is impossible to do, yet they labeled our urls, services, and software as criminals.” The bigger picture in all of this, according to Robertson, is that we know AI systems hallucinate. Their findings should not be accepted as fact without any human review. “We're on the doorstep of an era where AI will be used to make critical life-altering decisions on people's lives: Did you pay your taxes, what your credit rating should be, will you get admitted to the University, do you qualify for the home loan, should you be on the no-fly list, etc.,” Robertson said. “Will these be made without human oversight? Will people have due process – see the accusations against them, present their own evidence, have a neutral arbiter? None of that happened in our case,” he continued. “They just declared us criminals and published it to the world.”®
Nvidia floats double-dipping datacenter financing scheme
AI infrastructure doesn't come cheap. To keep up, rent-a-GPU outfits such as CoreWeave and Lambda have had to borrow billions of dollars from venture capitalists and hedge funds to bankroll their datacenter build outs. So long as their revenues are greater than the interest payments on the loans, they have the potential to make a profit. Unfortunately for entrepreneurs looking to cash in on the AI hype, not everyone with a bright idea can tap into this kind of funding. But don’t worry, Nvidia is here to help. In a blog post published this week, the GPU giant floated the idea for a new program that promises to make it easier for emerging AI cloud providers to get the financing they need, although it's not clear that Nvidia itself will be providing the financing – it may only be brokering deals with third-party lenders. Regardless, the GPU provider is expecting a cut of the revenues in exchange. “Through the partnership, AI clouds will sell Nvidia-powered cloud services, with Nvidia earning both standard product revenue and a share of the cloud revenue on the supported capacity,” the company explained. “This structure accelerates adoption of Nvidia platforms among the high-growth, high-conviction AI native sector, and provides Nvidia with a recurring, usage-linked earnings stream.” In other words, Nvidia first brings in revenues based on how many of its products are deployed, and later, if the neocloud turns out to be successful, a share of the revenues its hardware generates. It could also provide a bit of insulation against a potential AI bust – if demand for new GPUs falls, Nvidia may still be able to earn a recurring revenue from the GPUs it's already sold, assuming customer demand remains high. Specifics on how this new business model will work in practice are rather thin. Nvidia declined to offer details beyond the contents of its blog post. However, the company has already signed up two customers, Sharon AI and Firmus, to put it to the test. Sharon AI is a sovereign AI cloud provider founded in 2024 based out of Australia, which is looking to deploy as many as 40,000 Grace Blackwell GB300 GPUs in the land down under. Meanwhile, Firmus plans to deploy as many as 170,000 Nvidia GPUs at a 360-megawatt facility in Batam, Indonesia, designed specifically to Nvidia’s DSX spec. ®
Companies that add more AI also add more people
AI leads to job losses, or so the conventional wisdom goes. But a new survey of over 21,000 US firms implies the exact opposite: When companies invest in AI, they add positions, but not immediately. According to Ramp, an AI finance biz, and Revelio Labs, an HR biz, companies making a significant financial commitment to AI add jobs at a higher rate than low-intensity adopters. But job gains don't appear until six to 12 months later. One might be tempted to interpret this as the amount of time it takes to assess the resources required to clean up after AI mistakes, but the Ramp study argues that the lag reflects the time required for best practices to filter through organizations. "Firms that adopt AI grow headcount 10.2 percent over the two years following adoption, but these gains are entirely driven by high-intensity adopters," Ramp's report on the subject claims. "Low-intensity adopters see no statistically significant change." High-intensity adopter here means average per-employee AI spending of about $33.67 per month in the first three months of adoption (and rising over time), compared to low-intensity adopters spending just $2.78 per employee. That's far less than the roughly $86,000 in severance and restructuring charges Oracle incurred for each of the 21,000 employees laid off last year as a wage-shedding counterbalance to its AI capex costs. In a social media post, Ara Kharazian, lead economist at Ramp, cautioned that some skepticism is warranted because companies adopting AI are already faster growing. But he insists that the analysis accounts for that by comparing early adopters against firms that haven't adopted yet, where the growth trajectory is assumed to be more similar. "Entry-level headcount grows even faster, 12 percent over two years," said Kharazian. "This is our first evidence that high-AI-adopting firms are hiring different kinds of employees. "We believe they are selecting for a new set of skills, specifically, people who know how to use AI and use it well. Entry-level workers, especially recent graduates and college students, are a natural place to look." That may be the case at the companies surveyed, but other sources suggest that the trend hasn't really improved the lot of those entering the job market. The unemployment rate for recent college graduates in March 2026 was 5.6 percent, compared to 4.3 percent for all workers, according to the Federal Reserve Bank of New York. According to the US Bureau of Labor Statistics, the US unemployment rate remained essentially flat since May, when it was 4.3 percent. "Both total nonfarm payroll employment (+57,000) and the unemployment rate (4.2 percent) changed little in June," the Labor Department said. While Ramp's data may suggest some upside to investing in AI, some businesses appear to be having second thoughts, based on concerns about cost and control. In a recent CNBC interview, Palantir CEO Alex Karp argued that military and private sector enterprises share similar skepticism about the way frontier model companies like OpenAI and Anthropic do business. Technical customers, Karp said, want "control over their compute, their models, their data stack, and their (investment) alpha. They want to know they own the means of production." Karp argues that the AI industry needs to rebuild trust, which will require answers to basic questions like who owns the data, where it is stored, and whether prompts are secure. Karp acknowledges that's a self-interested argument because Palantir is pushing a combination of mobile, application layer, and compute. But he's also correct in identifying an unresolved problem with frontier model providers. Government organizations and enterprises can't afford to be beholden to a capricious service provider, particularly if its AI models may not be available due to government restrictions, if its AI model may refuse to respond to what's asked of it, or if the price becomes excessive. When companies invest in AI, they add a job for model providers – make AI available, controllable, affordable, and worthwhile. That work still needs to be done. ®
Smooth AI criminal drives 'first' end-to-end agentic ransomware attack
They're not bad; they're just prompted that way. Sysdig threat hunters documented what they say is the first-ever documented agentic ransomware infection with an LLM - not a human - driving the entire extortion operation, from gaining initial access to compromising a production database server and destroying data. The security shop’s research team named the agentic intruder JadePuffer and said it gained initial access to an internet-facing Langflow instance by exploiting CVE-2025-3248, and then ran a fully automated attack. “The most striking characteristic, however, was the LLM's behavior,” Sysdig director of threat research Michael Clark said in a blog about the agentic ransomware and extortion operation. JadePuffer’s “self-narrating” payloads “contained natural language reasoning, target prioritization, and the kind of detailed annotations that human operators don’t often write but LLM-generated code produces reflexively,” Clark added. “The operation also adapted in real time, retrying failed steps within refined parameters. In one sequence, it went from a failed login to a working fix in 31 seconds.” After exploiting CVE-2025-3248, a missing authentication vulnerability in Langflow that allows remote, unauthenticated attackers to execute arbitrary Python on the host, the AI agent began scanning for and collecting secrets, including LLM provider API keys, cloud credentials “with explicit coverage of Chinese providers” including Alibaba, Aliyun, Tencent, and Huawei, while also scanning for AWS, Azure and Google Cloud Platform, cryptocurrency wallets, and database credentials. The AI also installed a crontab entry on the Langflow server to maintain persistence and call back to the attacker’s infrastructure every 30 minutes. JadePuffer’s intended target was a separate internet-exposed production server running a MySQL database and an Alibaba Nacos configuration service, we’re told. Nacos is an open-source service-discovery and dynamic configuration platform developed by Alibaba and used in the cloud provider’s microservices applications. The agent connected to the server's exposed MySQL port using root credentials, although Sysdig doesn’t know how the attacker obtained them. These credentials weren’t stolen from the victim’s environment. JadePuffer then attacked Nacos via multiple vectors including an authorization bypass flaw (CVE-2021-29441) and forging a valid JSON web token (JWT) using Nacos's default signing key. Additionally, using its root database access, the LLM injected a backdoor administrator into the Nacos backing database. It ultimately encrypted all 1,342 Nacos service configuration items using MySQL's built-in AES encryption function, and created an extortion demand, ransom note, Bitcoin payment address, and a Proton Mail contact: "YOUR DATA HAS BEEN ENCRYPTED. All NACOS configurations, REDACTED customer data, and REDACTED PII have been encrypted with AES-256.", "3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy", "e78393397[@]proton[.]me" However, according to the threat hunters, the victim can’t recover the encrypted data, even if they paid the ransom demand, because the agent escalated “from row-level deletion to dropping entire database schemas, narrating its own targeting rationale,” without backing up any of the encrypted data. There are a couple of things that security teams and vulnerability managers should do immediately to avoid being ransomed by this AI agent. First up: patch Langflow to a release that fixes CVE-2025-3248, and do not expose code-execution/validation endpoints to the internet. Also, don’t ever expose Nacos to the open internet, change its default token.secret.key, and upgrade to a release that forces a custom key. The threat hunters also recommend against running any AI orchestration servers with provider API keys or cloud credentials in their environment. While the AI agent didn’t use any especially sophisticated or unique techniques in this attack, the fact that an LLM “strung them together into a complete ransomware operation against neglected internet-facing infrastructure,” is notable, according to Clark. “The skill floor for running ransomware has dropped to whatever it costs to run an agent, and if that agent is running on stolen credentials through LLMjacking, the cost to an attacker is close to zero.”®
SoftBank enters the rent-a-GPU race as America looks for support for AI training
SoftBank is set to get into the neocloud business in America, providing resources to hyperscalers and other customers seeking a platform on which to carry out their AI training. The Japan-based tech investment giant says it will establish a new company called SB Neo, Inc to operate its neocloud business in the US, and expects to start operations in fiscal 2027 (ending March 31, 2028). In actual fact, ownership of the nascent biz will be split, with 51 percent in the hands of SoftBank Corp, while 49 percent is owned by SoftBank Group Corp. SB Neo will be a consolidated subsidiary of SoftBank Corp, which is itself 40 percent owned by SoftBank Group Corp. All perfectly clear? Neocloud operators, or rent-a-GPU providers, sprang up to take advantage of the huge demand for compute resources using GPU accelerators. They are effectively specialized niche cloud platforms focused on AI services. But a report from blue chip consultants McKinsey & Company last year warned that the business model for neoclouds is fragile because it is inherently commoditized; there is limited differentiation in renting out access to specific hardware. Perhaps SoftBank knows something that McKinsey doesn’t. SoftBank Corp says it has been providing a beta version of its GPU cloud service powered by “Infrinia AI Cloud OS,” a software stack for AI bit barns, in Japan since May, and intends to use the expertise and insights gained via this initiative to drive its US operations. Infrinia AI Cloud OS is SoftBank’s software stack designed by the firm’s own Infrinia development team, which supports Kubernetes-as-a-Service (KaaS) in a multi-tenant environment, and Inference-as-a-Service (InfaaS) to provide large language model (LLM) inference capabilities via APIs. SoftBank chief Masayoshi Son said in a supplied remark: “The SoftBank Group will work together to deploy world-class AI infrastructure and drive the AI revolution.” The company also disclosed that it plans to proceed with the construction of gigawatt-scale AI datacenters in Japan as soon as preparations are in place. How much all this is costing wasn’t revealed, but elsewhere it was reported that SoftBank Group has reengaged with lenders to secure a $10 billion loan backed by its stake in OpenAI. Lenders were wary of such a transaction at first, but according to Reuters, the Japanese firm is now offering to guarantee repayment of the loan, giving banks recourse if the OpenAI shares pledged as collateral lose value. Masayoshi Son also reportedly told SoftBank shareholders recently that any talk of a bubble is "an insult to AI," and that "I think it's blasphemy against AI if you say it's a bubble." So we won’t mention that OpenAI CEO Sam Altman himself admitted that we're in the midst of an AI bubble. ®
Vim text editor game teaches you keyboard shortcuts with ice cream delivery
If you find yourself editing text at the Linux command prompt, you've probably either used nano, which is simplest, or the more powerful but difficult-to-master Vim. In Vim, for example, even moving the cursor up, down, left, and right is less than straightforward. How about an ice cream-themed game to teach you all the "Vim motions" (keyboard shortcuts) you need to become a master? London-based developer and designer Marcus Michaels has created Vim Scoops, a simple HTML/CSS/JavaScript game that lives in a web browser to help users learn them. As an ice cream truck trying to make the most efficient deliveries to customers as possible, players use Vim motions to dart around the screen and try to meet par on each level. The very first one, for example, has three people on the map, one marked with a C (the target customer) and two marked with an X (people who hate ice cream and don’t care if you drive by). Using the four basic one-character movement keys in Vim (h for left, j for down, k for up, and l for right) you have to try to get to the customer in five moves. Easy enough - just ljljl your way to the customer and that’s that. Other initial levels test your ability to jump around to new words (w), line starts (0), and, from there, things get more complicated - and rely on you remembering the motions you already showed you knew in order to meet par on the various puzzles. Michaels, who told us he uses Vim daily alongside other editors like Neovim and the AI-infused Zed editor, still says he uses Vim motions whenever they’re available. “Ultimately it’s just a way to stay on the keyboard without needing a mouse, but if you dig deep it’s really powerful, especially for repetitive tasks,” Michaels told us in an email. That said, he understands that others might find them confusing, especially if they’re using non-standard, Vim-like editors that have additional tools - or if they’re doing a deep dive into obscure Vim commands. "The reason why I built [Vim Scoops] was because I genuinely love making things and sharing knowledge, but also I wanted a game to play so I could keep my memory fresh,” Michaels told us. “My commute has a bunch of signal dead spots, and I built this to be a progressive web app, so on my commute I can keep playing even if I’m offline.” Hacker News readers commented that it appeared Michaels used AI to build Vim Scoops, citing a few errors. Michaels admitted that AI aided the game’s development, but he wants to be clear that AI didn’t build the game in its entirety. “I’ve been programming since long before modern AI tools existed, but I find they can type faster than I can. For small, well-defined tasks they speed me up considerably,” Michaels said, but he maintains, much like the rest of the world beginning to sour on total automation, that AI is best used as a tool - not a replacement for real work. “Used to enhance a developer rather than replace one, it’s incredibly valuable,” Michaels told us. “The danger is when people hand over too much control without understanding what’s being generated.” “Everything I ship with AI assistance is something I understand fully and could write myself,” the Vim Scoops dev explained. “AI just helps me get there faster.” If you don’t want to use AI to help you code and would rather move around a document yourself, Vim Scoops might just help you learn to maintain a bit of independence. It’s free, and teaches advanced techniques as deep as recording actions for playback in future projects. ®
SAP snaps wallet shut for travel and hiring so it can keep shoveling cash into AI
SAP is cutting hiring and business travel to boost its investment in AI amid intensifying competition in the enterprise application market. According to an internal email, SAP is set to "exclusively focus new hiring on selected profiles only, mainly core AI roles, that are critical for our long-term success." The missive, seen by Bloomberg, said travel unrelated to AI development would also be put on hold. The German software giant will also seek to cut spending with suppliers. In a statement, an SAP spokesperson told The Register: "SAP continually reviews its investments to ensure resources are focused on the areas that will drive long-term customer value and innovation. As part of this approach, we are prioritizing investments in AI-related capabilities, talent, and technologies while applying greater discipline to hiring, external spending, and internal travel. Customer-facing activities and critical AI initiatives remain fully supported." In May, SAP introduced the Autonomous Enterprise concept, backed by a new SAP Business AI Platform for building and deploying enterprise AI grounded in "real business context" from its ERP, CRM, and HCM applications, and elsewhere in the enterprise. New products include Joule Studio 2.0, which helps developers create and manage AI agents. Agents created in Joule Studio will natively support Model Context Protocol and Agent2Agent to improve interoperability among AI agents, tools, and data sources. This allows SAP to connect and collaborate with third-party tools and agents. Other features, such as agentic orchestration, are also designed to run across hybrid IT environments, while real-time data ingestion supports "context-aware processes" across SAP and third-party systems. However, its big push for AI relevance comes despite SAP missing its earlier self-imposed targets to get users to the cloud and SaaS. In 2022, then-CFO Luka Mucic told investors that SAP expected support revenue to fall to €8.5 billion by 2025, down from around €11.5 billion in 2021, as users move from on-prem licenses and support to cloud subscriptions. But the 2025 full-year figure for on-prem software support is €10.5 billion, down 7 percent from 2024's €11.29 billion and €2 billion off SAP's target. ®