Subscribe to The Register feed
Articles from www.theregister.com
Updated: 2 months 2 weeks ago

Ctrl+Alt+Oops: FortiBleed criminal's logins stitch two gangs together

Thu, 07/02/2026 - 08:32
Security sleuths say last month’s FortiBleed campaign is tied to two separate ransomware groups, after they found evidence of one initial access broker group member logged in to two affiliate panels. SOC Radar’s Threat Research Unit (STRU) said at least one of the group’s 20 members was actively negotiating with victims, which it believes signals a direct link between the thousands of FortiBleed victims and the ransomware ecosystem. STRU spent weeks mapping FortiBleed’s infrastructure across hundreds of servers after the attack was disclosed. Due to an opsec failure in one of these servers, the team gained visibility into the IAB group’s internal files and logs, revealing that one of the individuals was logged into the affiliate panels of both the INC Ransom and Lynx ransomware groups. “Finding a single operator working both panels, using infrastructure traceable back to FortiBleed, is the clearest evidence yet that FortiGate credentials harvested through this campaign are being handed off, or used directly, for ransomware deployment,” SOC Radar said. Following examinations of both the IAB group’s internal logs, compromised endpoints, and claims made via the leak sites of INC and Lynx, STRU linked at least 12 ransomware attacks to FortiBleed victims so far. While initial reports pegged the number of successful attacks at more than 70,000, STRU said its data was derived from scanning 11,250 Fortinet portals, although more than 430,000 firewalls were targeted. Admin-level access was confirmed on 409 targets, and on 354 of these the attackers executed the full attack chain, compromising VPNs and gaining access to domain controllers and domain admin. STRU said the finding is significant because it shows how the exploit was not just an exercise in harvesting credentials, but an attack that feeds directly into the ransomware economy. “What this investigation shows is that FortiBleed isn’t an isolated credential-theft operation sitting off to the side of the ransomware economy, it’s feeding directly into it. The same access broker infrastructure that quietly intercepted authentication traffic across hundreds of thousands of firewalls is connected, through a shared operator, to two of the more active ransomware brands operating today. “For organizations running FortiGate infrastructure, this raises the stakes on an already urgent finding: exposure to FortiBleed is not just a credential exposure risk, it is a potential precursor to ransomware.” FortiBleed in brief Disclosed on June 17, the attack did not exploit novel vulnerabilities. Experts characterised it as a large-scale campaign that involved intercepting SSL VPN authentication hashes and cracking them using a 45-GPU cluster hosted by Hashtopolis. They then used the credentials to access victims’ Active Directory environments and gain persistence. Fortinet tried to counter these kinds of attacks in early 2025 by introducing the PBKDF2 algorithm for storing credentials, but because the changes were not applied until each admin logged back in, many organizations were likely still using SHA-256 with salt, which is vulnerable to brute-forcing. Early estimates suggested a little more than 73,000 unique firewall URLs were successfully targeted, leading to a long list of major organizations being compromised. FoxConn, Samsung, Comcast, Siemens, Lenovo, FedEx, PwC, Accenture, and Oracle were among those listed in the early reports. An unnamed Turkish NATO defense contractor was also thought to be among them after investigators found signs of classified files being copied. ®

Microsoft said exploitation was 'less likely' ... but CISA just added SharePoint RCE to KEV list

Thu, 07/02/2026 - 07:40
Microsoft's prediction that attackers probably wouldn't rush to exploit a newly-patched SharePoint bug hasn't aged especially well. CISA has added CVE-2026-45659, a remote code execution flaw in on-premises Microsoft SharePoint Server, to its Known Exploited Vulnerabilities (KEV) catalog after confirming that crimes are now actively exploiting it in the wild. The bug stems from an insecure deserialization issue and affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016, all of which received patches from Microsoft in May. Unlike some of SharePoint's more infamous bugs, this one isn't pre-authentication, though attackers need surprisingly little to pull it off. According to Microsoft, anyone with valid credentials and nothing more than Site Member permissions can execute arbitrary code remotely on a vulnerable server. "Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges," Microsoft said in its advisory. "In a network-based attack, an authenticated attacker, who has a minimum of Site Member permissions (PR), could execute code remotely on the SharePoint Server." Microsoft also noted that the attack can be launched remotely over the network with low attack complexity, making it straightforward to exploit once an attacker has a foothold. CISA didn't disclose who's exploiting the flaw or how widespread the attacks are, but its guidance leaves little room for interpretation. "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," the agency warned. It directed federal civilian agencies to follow Binding Operational Directive 26-04 by applying Microsoft's fixes no later than July 4, or discontinue use of affected systems if mitigations aren't available. The vulnerability carries a CVSS score of 8.8, but perhaps the more interesting number is Microsoft's exploitability assessment. When the patches landed, Redmond rated real-world exploitation as "Less Likely." That's a prediction, not a guarantee, and history has a habit of making those forecasts look optimistic once patches give attackers a roadmap to reverse engineer. For anyone still exposing an unpatched SharePoint server to the internet, CISA's KEV listing is a reminder that the race between patching and exploitation is usually won by whoever starts first. ®

Pacemaker manufacturer Medtronic warns patients cybercrooks may have swiped health data

Thu, 07/02/2026 - 05:54
Medical device giant Medtronic is warning patients that their personal and health information may have been caught up in an April cyberattack in which intruders spent nearly a week inside parts of its corporate network. According to breach notification letters sent to affected individuals, the company detected unusual activity on April 15 and later determined an unauthorized party accessed certain corporate systems between April 13 and April 19. The compromised systems contained the sort of data you'd expect a medical device maker to hold about its patients: names, contact details, dates of birth, Social Security numbers, and health information. Medtronic said it collects the information to provide product updates and comply with regulatory requirements. Medtronic says there's "no evidence" the information was "posted publicly or exposed on the internet." Whether the attackers made off with copies of the data is another question the company hasn't yet answered. The notice also addresses the question many patients are likely to ask first: whether their device was affected. "Based on our investigation, this incident did not impact the ability of any Medtronic device to operate safely and deliver intended therapy." the company said. When Medtronic first disclosed the incident in April, it said the attack had not affected patient safety, manufacturing, distribution, financial reporting, or its ability to meet patient needs. It also stressed that its corporate IT environment is segregated from the networks supporting its products and that hospital customer networks are managed separately. Shortly after the intrusion began, the ShinyHunters extortion crew added Medtronic to its dark web leak site, claiming it had stolen more than nine million records and threatening to publish the data unless a ransom was paid by April 21. The listing was later removed. ShinyHunters typically removes victims from its leak site after reaching a deal, and Medtronic's entry disappeared later that month without any data being published. However, Medtronic's notification makes no mention of ransomware, extortion demands, or ShinyHunters, and the company has not publicly attributed the attack. The breach notice also leaves several obvious questions unanswered, including how many people were affected, how the attackers gained access, and why it took the company more than two months to begin notifying affected patients. Medtronic said it has since implemented additional security measures, worked with law enforcement and relevant regulators, and is offering affected individuals two years of complimentary credit monitoring, dark web monitoring, and identity restoration services. ®

India gives WhatsApp three days to defend username rollout amid security fears

Thu, 07/02/2026 - 04:50
India has asked WhatsApp to explain why it should not face regulatory action after it announced the global rollout of a new usernames feature amid fears that the new feature could lead to increased cyberattacks. The country's Ministry of Electronics and Information Technology (MeitY) gave the Meta owned platform three days to respond to its July 1 letter and to halt the rollout of usernames until the government gives its approval. WhatsApp announced on June 29 that it was allowing users to reserve usernames that could be used instead of phone numbers on the platform when the feature launches later this year. It said that people want to chat with others without exposing their personal phone number, whether to a classmate, neighbor, professional contact, or the group chat for their child's sports team. Meta also owns Facebook or Instagram, and is not allowing users to create usernames that already exist on those other platforms – unless they themselves control the other accounts. However, the government of India, WhatsApp's largest market fears that allowing first contact without displaying a phone number "may increase cybercrimes," including phishing and digital arrest scams. MeitY is specifically concerned about the opportunities for impersonation, with attackers posing as public authorities, financial institutions, or government departments. The department cited India's Information Technology Act 2000 and Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 as the legal basis for its concerns about the feature. The Internet Freedom Foundation, which shared a copy of MeitY's letter to WhatsApp's chief compliance officer in India, said that the department has no clear legal basis for halting WhatsApp's usernames rollout. It said neither legal framework was applicable in the context in which they were being invoked and called its letter the latest example of attempted regulatory overreach. The IFF pointed to a separate advisory issued in March 2024 when MeitY tried to stop AI companies from rolling out their models to the public before the Indian government had a chance to approve them. "That was criticized as an overreach that sought to build a licensing mechanism with no empowering provision in the IT Act, and within a fortnight MeitY withdrew it and dropped the permission requirement," the IFF stated. "This notice repeats the move for a single feature and goes further, because it names one company, sets a three-day clock, and bars the launch until MeitY is satisfied." WhatsApp told The Register that it has implemented numerous measures designed to keep users safe as usernames are rolled out across the platform. A spokesperson said: "We've announced the option for people to reserve their preferred username on WhatsApp. The ability to use a username is not yet live and will roll out slowly later this year. When it becomes available and someone sends you a message for the first time via your username, we will show you if they're a new account, if they're your contact, if you have groups in common, and if they're based in a different country, so you can decide whether to respond." In other efforts to restrict fraudulent misuse, WhatsApp has already reserved high-profile usernames for legitimate organizations and individuals. Users will also not be able to register lookalike derivatives. The spokesperson added: "Users still require a phone number to use WhatsApp and we've built multiple layers of defense against scams into usernames. Other users need to know the exact username to message you, we will limit how many new people an account can contact, block repeated attempts to guess someone's username key, and have systems to detect and remove activity showing common impersonation and abuse patterns." MeitY did not respond to our request for input. WhatsApp claims more than 3 billion users rely on its messaging platform, and separate estimates peg India as its largest market with more than 850 million users. WhatsApp-based scams are not unique to India. Many cybercriminals use the platform to commit fraud, impersonating public figures, authorities, and family members to carry out financially motivated attacks. The Telegram messaging platform allows users to set public usernames and is also frequented by scammers. India temporarily banned Telegram in June amid fears that exam questions were being shared ahead of time. The ban was announced days before the NEET-UG medical entrance exam was scheduled to begin. The exam was reworked and rescheduled after being canceled in May after genuine questions were found circulating on the platform. ®

Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released

Thu, 07/02/2026 - 03:35
Attackers have been caught exploiting a critical flaw in Oracle E-Business Suite's Payments module just six weeks after Oracle patched it – and before any public proof-of-concept exploit was available. Researchers at Defused said they observed the first known exploitation of CVE-2026-46817 on June 27. The attackers were targeting the Oracle Payments File Transmission component in E-Business Suite releases 12.2.3 through 12.2.15, they said. The vulnerability, fixed in Oracle's May Critical Patch Update, carries a CVSS score of 9.8 and allows unauthenticated attackers to read arbitrary files from vulnerable servers. According to Defused, the activity didn't look like the indiscriminate internet scanning that often follows disclosure of a critical bug. Instead, its honeypots recorded just six exploitation attempts from a single source, all using what appeared to be a working exploit. The requests sought to retrieve sensitive files from the target system, suggesting the operator was testing or validating the technique rather than casting a wide net. The researchers said exploitation began before any public exploit code had surfaced, pointing to an attacker who had either reverse-engineered Oracle's patch or obtained a private exploit. The Shadowserver Foundation said it currently sees around 950 EBS instances exposed to the public internet, the majority in the US, although it stressed that figure says nothing about whether they're vulnerable or fully patched. The observed exploitation fits a pattern that's becoming increasingly familiar. Earlier this month, researchers warned that attackers had exploited a critical PeopleSoft zero-day before patches were widely deployed, with the ShinyHunters crew claiming to have compromised more than 100 organizations. They also boasted of having stolen HR and payroll data. This latest incident also follows Clop's lengthy campaign against Oracle E-Business Suite customers, disclosed last year after researchers found the ransomware crew had targeted internet-facing EBS servers for months before the activity became public. The newly exploited EBS vulnerability is probably not the last Oracle ERP bug to be targeted. Enterprise software has become a lucrative hunting ground for cybercrooks, and critical updates can double as roadmaps for anyone prepared to reverse-engineer the fixes and beat customers to deployment. ®

Connect, disconnect, or just have a lovely beer

Thu, 07/02/2026 - 02:15
BORK!BORK!BORK! Sometimes a digital sign can carry a message that means more than just words. Like this example, which could be a simple connectivity issue or speak to a deeper spiritual meaning: You're not connected to a network. Spotted by an eagle-eyed Vulture on a visit to Neuschwanstein Castle in Germany, near the border with Austria, the digital sign normally displays information to individuals waiting in a nearby queue. Not today, though. From a purely technical standpoint, it appears the sign is running a browser that cannot connect to the computer serving content for visitors. The error "You're not connected to a network" indicates that a WiFi network may be misbehaving, or that an adaptor (or driver) has packed up. Or perhaps, just perhaps, the message has another meaning. "You're not connected to a network" could be a warning to citizens unable to draw their eyes from the device in their hands. Sure, they might think they are connected to a social network, but such connections are merely virtual. You are, as the sign says, not connected to a network. Not really. It's certainly food for thought. Or it might just be that something somewhere has fallen over and been unplugged, and the hard-pressed techie responsible for it has either not spotted the problem, or lacks the time to deal with it. Neuschwanstein was built from 1869 to 1886, and initially served as the residence of King Ludwig II of Bavaria. It's a strange place, having been built at a time when castles weren't necessary as strongholds, but it was still given a medieval-ish design. There's hot and cold running water, a heating system, and even a telephone connection (despite the digital sign insisting it can't find a network). It's certainly worth a visit, and as the throng beside the possibly philosophical signage makes clear, it is a popular attraction. Walt Disney visited the schloss in the 1950s and – judging by the multiple similarities with the Disney Sleeping Beauty Castle from the 1959 movie – was seemingly inspired by its architecture and distinctive towers. Or perhaps it's worth attending not for the architecture, but for the inadvertent philosophy in the borked signage: you're not connected to a network. But you are in Bavaria. So how about a lovely beer and Schweinebraten mit Kartoffelknödel? ®

UN warns of need for global governance to avoid an AI-pocalypse

Thu, 07/02/2026 - 01:30
A United Nations report on AI warns the technology is moving faster than governments can keep up, and the window of opportunity to establish effective global governance of it will not be open forever. The Preliminary Report from the UN's Independent International Scientific Panel on Artificial Intelligence presents AI as something of a mixed blessing. It says that the potential benefits of AI are enormous. If deployed and applied thoughtfully, the technology could support progress towards sustainable development goals, among other gains. On the other hand, a rapid, unchecked deployment of the technology at scale presents risks such as harm to the mental health of users, potential use as a destructive tool, and adverse impact on social, economic, and environmental systems. Obtaining the benefits from AI while minimizing those risks requires effective governance, the report says. With complementary investments in skills and labor market regulation, AI will likely create new jobs. Without them, AI risks wider inequality, displacing workers, and shifting wealth from labor to capital – those who own and control the AI. AI is, of course, an all-encompassing term that covers everything from algorithms that try to predict the word you are typing to large language models (LLMs). The UN report seems most concerned about agentic AI, which refers to systems that are allowed to make their own decisions and act on them. There is no guarantee that such AI agents will not violate their instructions, and the UN report claims there is clear evidence of cases where they have already disregarded them. Such behavior may pose challenges to evaluation and oversight methods, as some leading AI systems have been shown to recognize testing environments and produce misleading evaluation results. Agentic systems make AI harder to measure and govern, it says, as emerging multi-agent risks cannot be detected through single-agent evaluation, and reliable methods for maintaining control over highly autonomous systems remain underdeveloped. The report also notes that policymakers aiming to draw up effective governance face a dilemma: they need evidence to make informed decisions, but by the time sufficient evidence exists, harmful systems may already be widely deployed. AI capabilities are also unevenly distributed. Most nations, including many advanced economies, lack the technical expertise to assess the most capable "frontier" models or to participate meaningfully in their governance, the UN claims. The US and China account for 90 percent of the compute power behind the leading AI models, leaving developing countries dependent on technology they cannot build or adapt to their own societies. This could reinforce existing global inequality rather than reducing it. But the report acknowledges the Scientific Panel's own lack of visibility into certain areas. Evidence is limited as to whether task-level AI productivity gains will aggregate to economy-wide gains, it says. As The Register has previously reported, many companies are failing to increase revenue or reduce operating costs through their AI projects, and that was before AI vendors drove up costs by shifting to consumption-based pricing, meaning there is a lack of evidence that AI will ever be cost-effective. Forecasts diverge significantly due to different assumptions about adoption and new task creation, according to the UN. The panel concludes that AI is neither inherently good nor bad, but its impact will depend on the choices that governments, companies, and societies make today. Given that the US government is already hostile to anything resembling regulation of AI companies, and that the industry is already copying techniques used by tobacco firms, big pharma, and oil companies to subvert regulation, the outlook isn't encouraging. ®

Hackers shoveled snow for company, were rewarded with network admin access

Thu, 07/02/2026 - 00:00
PWNED Welcome back to PWNED, the column where we document serious security failures in hopes we can all learn from others’ mistakes. This week, we’ll talk about how a lack of physical security can allow threat actors to take control of your network. Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request. Our story comes to us from two professional red teamers, who get paid to break into offices and networks in order to find holes in the security system. Kristopher Johnson was working as an offensive security consultant at Echelon Risk + Cyber in 2023 and his manager was Dahvid Schloss. We spoke to both. Johnson and another employee named Michael were called upon to challenge the security at a client’s office while Schloss supervised remotely. It was winter and the maintenance crew had the maintenance door open. They walked through it and into the mail room, where a woman confronted them and asked what they were doing there. The two intrepid testers talked to the company maintenance crew and told them that they were new IT employees without working badges. They said that they had almost slipped on the ice and offered to help shovel, an offer the maintenance team was happy to take them up on. While Michael kindly helped the maintenance crew shovel snow, Johnson asked if the maintenance folks could let him in so he could go upstairs and start setting up Michael’s laptop for work. They let him in where he was free to explore the building as his partner brushed away a large section of ice and snow. Inside the building, Johnson looked for a place to plug in his Raspberry Pi. The idea was to connect this single-board computer to the network, where they could access it remotely and use it to attack the network from afar. He tried plugging his Raspberry Pi into an Ethernet port in the AV closet, but the company had network access control enabled, which prevented it from connecting. The Raspberry Pi had an LTE radio, but it couldn’t connect from the closet either. So Johnson instead moved his Raspberry Pi into the middle of the conference room and found an active network port that didn't have network access control enabled on it. However, he realized the Pi would be visible to anyone who entered the conference room, and they might find it suspicious. So he took some trash cans and used them to hide the device. Johnson had a hard time getting out of the building after that. He tried to go out the front door, but it required him to swipe a badge he didn’t have and strangers would not swipe their badges for him. But when he went back through the maintenance entrance, they were more than happy to swipe him out. He waited in the car while Michael finished his shoveling assignment. The next day, Johnson found out that his security breach had been detected. When he and Michael came in to meet with their contact at the company, the head of security confronted them. They had been “caught” because someone from maintenance went up to the IT department and wanted to thank the IT team for Michael’s help with the shoveling. However, the IT team had no record of new employees named Michael or Kristopher, so that raised suspicion. Before learning that they were professional red teamers, the building security had been suspicious and had looked at camera footage tracking their movements. They had even tried to get information on the license plate from Johnson’s rental car. However, they never did find the Raspberry Pi, which remained plugged into the Ethernet port in the conference room for two weeks. During that time, Johnson’s team was able to connect to the company’s Active Directory, find where the domain controllers were, and start password spraying accounts to see if they could gain access. They tried using the password “winter2023!” and got 50 or 60 hits among the employees. “So we used those credentials to kind of map out the rest of the network,” Johnson told The Register. “Network shares and things like that and then, towards the end of the test, we enumerated the certificate services - ADCS (Active Directory Certificate Services).” The red teamers found eight templates that were open to ESC1 and ESC4 vulns. They also found that the certificate authority was vulnerable to ESC8. They were then able to exploit those holes to gain domain administrative access. The janitor found the Raspberry Pi two weeks after they broke in, but by then it was too late. There are a lot of lessons here, but they start with training every member of the team to be suspicious of people coming from the outside, without badges, no matter what they say or do. Schloss noted that, if someone looks and acts like they belong in a space, most people will treat them that way. “First and foremost, what most people believe is crime is not crime. It's a Hollywood myth of what crime looks like,” Schloss told us. “I call it the ski mask bias. Everyone assumes you're not getting robbed until a person comes in with a ski mask and a gun yelling.” The maintenance team at this company should have been more suspicious of people calling themselves new employees and asking for a swipe in, even if they were willing to help shovel snow. The company also should have restricted network access to the port in the conference room so that an unknown device like a Raspberry Pi could not make an Ethernet connection from that spot. Finally, the company should have enforced a strong password policy that would have prevented our heroes from finding dozens of accounts with “winter2023!” as the password. And they should have enforced multi-factor authentication on those accounts as well. ®

Trouble keeps finding Supermicro as strange server shipments attract police attention in Taiwan and Singapore

Wed, 07/01/2026 - 23:02
The strife seldom stops at Supermicro, which this week has been forced to deny a raid on its office, and appears to have fallen victim to fraudsters in Singapore. The server-maker yesterday published a business update in which Chief Revenue Officer Matt Thauberge assured customers that police in Taiwan did not raid the company this week – the company is just helping local authorities after they detained four of its workers for questioning. Thauberge said Supermicro “coordinated with authorities to provide access to those employees’ desks and electronic devices” to assist with a matter the company previously said is related to “illicit diversion of our highly sought-after systems into the restricted China market.” Supermicro said the investigation “highlights the challenges that can arise when products are resold through multiple downstream parties beyond direct manufacturer control,” and said it vetted the original purchaser thoroughly. Servers are not in short supply in China, where local heroes like Lenovo, Inspur, and Huawei can crank out plenty of x86 boxes. Chinese buyers, however, are not always able to buy some Nvidia GPUs due to US sanctions and, more recently, Chinese authorities deciding not to authorize imports after sanctions lifted. It’s thought the servers allegedly sent to China may have had Nvidia kit inside. That’s not a crime, but the paperwork arranging the deal may have been improper. Supermicro is also tangled up in a Singapore case that started in early 2025 with the arrest of three men accused of fraudulently acquiring servers. Singapore’s Law and Home Affairs Minister K. Shanmugam linked the matter to export of servers containing Nvidia parts to Malaysia but said he wasn’t sure if that was the final destination for the boxes. In a statement published on Wednesday, the island nation’s law enforcement agency detailed a conspiracy involving three men who were officers of three companies collectively known as “Asperia Group.” The three men allegedly talked with Dell, Supermicro, and ASUS about purchasing servers and claimed that Asperia Group would be the end-user of the servers. One of the accused is also alleged to have negotiated to buy servers from Supermicro for a company he controlled called Luxuriate Your Life, which he said would lease them to third parties. Singaporean authorities allege the men were all fraudsters because the servers they bought were not used by Asperia Group or leased by Luxuriate Your Life. A common theory is that the Asperia and Luxuriate Your Life intended to either move the servers out of Singapore and rent them to Chinese users, or just ship them to China. The alleged conspiracy took place during times when the US banned sales of Nvidia chips to China. Singaporean authorities also laid new charges of benefiting from criminal conduct, and issued orders preventing disposal of a “Good Class Bungalow” valued at $SGD55 million ($42 million/£$31.5 million) as it may be the proceeds of crime. The value of Supermicro shares is down around 17 percent this week. ®

New humanoid robots from China look like creepy pop star action figures – complete with slightly dodgy lip-synch

Wed, 07/01/2026 - 19:35
One of China’s emerging humanoid robotics companies has launched its most-realistic looking models yet and says it has already taken over 13,000 orders for the $17,600/ £13,300 machines. Here’s a shot of the new machines. You’re looking at the UWORLD U1, which Chinese company UBTECH says enjoys 88 degrees of freedom thanks to use of “a proprietary dual-pivot biomimetic cervical spine, enabling it to replicate up to 90 percent of fundamental human movements.” The company says the machines are suitable for “long-term companionship” due to what it claims is “the world's first emotion-aware LLM … capable of recognizing more than 20 fine-grained emotional states with an accuracy rate exceeding 90 percent.” In its breathless announcement, UBTECH says the bots use a “biomimetic fast-and-slow brain architecture” that “draws on cognitive neuroscience principles, enabling a 500-millisecond intuitive response system alongside deep reasoning capabilities powered by models with hundreds of billions of parameters.” We’re told a “biomimetic expression actuation system … reduces speech-to-lip synchronization latency to within 20 milliseconds, creating a remarkably lifelike interaction experience.” UBTECH thinks its new bots can provide “daily companionship, emotional support, lifestyle enhancement, and social assistance, as well as reception and hospitality services, elder care, psychological support, tourism and exhibitions, research and education, and premium domestic service applications.” That companionship can even extend to hitting the dance floor. Another pic suggests the bots can also be all pouty and stone-faced, like catalk models. The Register wants to know if they can also run DOOM or play Crysis, but sadly UBTECH hasn’t said much about the Agent Memory OS that powers the bipedal machines. The company has, however, cooked up its own laws of robotics: users can set hardware safeguards and retain ownership of data which is processed locally whenever possible due to a policy of minimal cloud dependency. China’s government wants the nation to lead the humanoid robotics industry. State media has even taken to calling the Nanshan District of Shenzhen, a city already famed as China’s tech hub, “Robot Valley.” The Middle Kingdom is not alone in betting on humanoid bots: SpaceX supremo and occasional US government employee Elon Musk wants to build a million of them each year, and thinks a billion will work and walk alongside us meatbags by 2040. ®

Oracle outlines all the ways it could lose the farm it bet on AI

Wed, 07/01/2026 - 15:23
Oracle is burning hundreds of billions to finance AI datacenters for the likes of OpenAI. Now, the company is admitting they may not pay off. Amid the usual boilerplate, Big Red cited numerous risk factors related to its AI infrastructure investments in a regulatory filing published late last month. “To grow our OCI business, which requires increased computing capacity, we must incur significant capital and operating expenditures to increase our existing data center capacity and to establish data centers in new geographic locations,” the filing reads, using the TLA for "Oracle Cloud Infrastructure." These investments, the company notes, are tied to long-term commitments for infrastructure and datacenter capacity. Unlike the big three cloud providers, Oracle prefers to lease datacenter capacity from partners like Crusoe, rather than build them itself. While the filing doesn’t mention OpenAI explicitly, Oracle’s success as an AI infrastructure provider is inextricably tied to the model dev and its cult-of-personality leader, Sam Altman. In early 2025, Oracle joined OpenAI, SoftBank, and MGX to put its name on the so-called Stargate initiative, an ambitious project to pave the planet with half a trillion dollars worth of bit barns. As we later learned, Oracle had signed up to provide $300 billion of capacity over five years as part of a long term agreement with OpenAI, which would also see the database provider manage the model dev’s flagship facility in Abilene, Texas. In addition to the OpenAI deal, Oracle claims to still have about $155 billion in remaining performance obligations from other customers. This puts Oracle in a tough spot. If it underestimates demand, it could lose customers to competing infrastructure providers. On the flip side, Oracle says if it overestimates demand, or any of its key customers can’t make rent, it could end up footing the bill for the datacenter capacity it leased on their behalf. Oracle's OpenAI deal will reportedly contribute up to $30 billion in revenues annually, with revenues expected as early as next year. But OpenAI still hasn’t managed to turn a profit, which means its ability to pay its bills depends entirely on its ability to continue raising capital. “Our business is, and may continue to be, exposed to risks of customer non-payment and non-performance,” the company wrote. Well, yes. And even if they pay up, there’s no guarantee its customers will renew their leases. “If customers do not renew their contracts, we may be unable to re-lease, repurpose or assign such capacity on acceptable terms, if at all,” the filing reads. Customers' ability to pay their bills may not be the only risk factor facing Oracle’s AI gamble. As the company notes, it is already having trouble securing enough power at fair prices to fuel its datacenter buildout. “We have faced, and may continue to face, challenges with securing reliable and cost-effective power sources for our data center energy demands, which are constrained globally due to the significant increase in demand for and limited availability of energy to power AI compute," the company wrote. "In addition, power prices can be volatile, including due to extreme weather events and market structure in certain regions, and increases in energy costs can adversely affect our margins, particularly where customer pricing is fixed or committed.” Oh, and then there's the fact that building datacenters is not for the faint of heart in the first place. Anything that could go wrong … could go wrong. Let's go to the tape: "Our data center expansion depends on access to suitable, permitted build sites; reliable and predictable power sources; networking hardware; and server availability, including graphics processing units, memory devices and other critical components. Data centers in geographies that we rely on may be unavailable on commercially reasonable terms or at all. Government-imposed limits or moratoria on data center construction in a given market could hinder our ability to execute our expansion plans or prevent us from completing planned data center projects. Even where suitable sites and capacity are available, our data center expansion plans are complex and subject to execution risks, including, among others, delays or cost increases related to design, engineering, permitting, construction, utility interconnection, equipment delivery and contractor performance. Our ability to build and operate data centers also may be affected by existing and evolving laws, regulations and policies relating to land use and zoning, environmental permitting, energy usage, grid reliability, greenhouse gas emissions, water usage, building codes, health and safety, tax incentives and data localization." Whew. But Oracle is in too deep to call it quits. “We have made significant investments in AI initiatives, including investments in infrastructure and headcount, and we expect to continue to invest significant resources to build and support our AI products in support of our growth strategy,” the company warned investors. “If we do not continue to invest significant resources to develop and support our AI products, we may fall behind technological developments and evolving industry standards, which would likewise harm our ability to compete.” In other words, damned if they do and damned if they don't, so what’s left to do other than burn, baby, burn? And that’s exactly what Ellison and crew plan to do. During its Q4 earnings call last month, the company said it planned to spend $70 billion on capital expenditures during the 2027 fiscal year, up from around $55 billion spent during its 2026 fiscal year. To support this spending spree, Oracle will have to take on additional debt. In 2027, the company hopes to raise around $40 billion in debt and equity. That’s on top of the $18 billion in debt it raised back in September. Stock market bettors aren't sure they like these odds. The company's stock is down more than 40 percent in the last month.®

EvilTokens device-code phishing kit totally more evil than we all thought

Wed, 07/01/2026 - 14:50
EvilTokens, the device-code phishing kit that can allow criminals to bypass multi-factor authentication (MFA) and silently authenticate as the victim to the organization's Microsoft 365 applications, appears to be even more insidious than we all thought. Cisco Talos incident responders on Wednesday described how the lure reaches a victim's inbox, and revealed new capabilities alongside a “more sophisticated evasion approach” than documented in earlier EvilTokens research. Talos uncovered a phishing-as-a-service (PhaaS) operator panel, branded “ARToken,” that appears to be an EvilTokens customer, according to security research engineer Michael Kelley, who noted the phishing operation shares infrastructure, API contracts, and operational patterns with the EvilTokens platform. EvilTokens was first documented by French cybersecurity firm Sekoia in March, and in April Microsoft said the device-code phishing campaign was compromising hundreds of organizations daily. "Since March 15, 2026, we have observed 10 to 15 distinct campaigns launching every 24 hours," Microsoft VP of security research Tanmay Ganacharya told El Reg at the time. “Each campaign is distributed at scale, targeting hundreds of organizations with highly varied and unique payloads, making pattern-based detection more challenging.” While most subsequent analysis has covered EvilTokens’ panel and phishing kit, “what it has not shown is how an ARToken lure actually reaches an inbox,” Kelley said on Wednesday. “Talos recovered two near-identical messages, sent roughly four minutes apart on April 20, 2026, that initiate the chain. The tradecraft is targeted, not spray-and-pray.” Specifically, the email lure abused a real vendor relationship between a US life-sciences company and a legitimate plumbing and fire-protection contractor. The email uses an outstanding-invoice lure, telling the life-sciences company that “the following invoices appear to still be outstanding,” and the “from” header presents the contractor’s real domain. The reply-to, however, redirects replies to an unrelated domain. Even the visible anchor text in the body of the email reads as the vendor's genuine SharePoint tenant, we’re told. The actual href, however, points to a near-identical copycat tenant under a different, attacker-controlled Microsoft 365 workspace. But because the destination is still a legitimate sharepoint.com host, the email is less likely to be flagged as a phish. During its investigation into the ARToken phishing infrastructure, Cisco uncovered the connections to EvilTokens – including an identical API contract to the one originally documented by Sekoia and matching deployment and operational models – as well as “notably more sophisticated” anti-analysis and evasion capabilities. ARToken’s panel also revealed a very comprehensive post-exploitation toolkit that provides token management and persistence mechanisms, and a built-in business email compromise (BEC) tool with full Microsoft Outlook inbox read access, email sending capabilities as the victim, inbox rule creation for forwarding and deleting messages, and keyword-based monitoring across all compromised accounts. “These features indicate the platform is more mature than a simple device code phishing kit - it is a complete BEC operations environment,” Kelley wrote. ®

Claude Sonnet 5.0 heads straight down the middle of the road to dodge controversy

Wed, 07/01/2026 - 14:33
Anthropic has released the latest version of its mid-sized model, Sonnet 5, which the company claims is its most “agentic” yet. For developers writing agents to automate tedious and recurring tasks, Sonnet 5 promises improved capabilities in reasoning, tool use, coding, and knowledge work. This version is also less likely to pull embarrassing (for Anthropic) gaffes of misunderstanding, so the company asserts. “Our safety assessments found that Sonnet 5 shows an overall lower rate of undesirable behaviors than Sonnet 4.6, and is generally safer to use in agentic contexts,” the company asserted in an introductory blog post on Tuesday. Sonnet 5 is smarter at refusing malicious requests and resisting prompt-injection attempts. It doesn’t hallucinate as often and doesn’t suck up to the user so much (“sycophancy”) as did its older brown-nosing Sonnet 4.6 sibling. It is also more aware of, and can block, user misuse and deception, the benchmarks in Anthropic’s System Card seem to indicate. Sonnet is the default model for Claude Free and Pro users, and is also available to the token-pinching Max, Team, and Enterprise customers. The benchmarks also indicate Sonnet 5’s performance can come close to that of Anthropic’s flagship enterprise-focused Opus 4.8, but can execute the same tasks more cost effectively. For Opus, Anthropic charges $5 per million input tokens and $25 per million output tokens. Starting in September, Sonnet users will pay $3 per million input tokens and $15 per million output tokens, though Anthropic is running a special through the end of August where tokens will only be $2 per million inputs and $10 per million outputs. So users trimming their token budgets can run jobs through Sonnet instead of Opus, the company suggests. The 5.0 release offers a new setting to adjust the model’s effort at completing tasks. Simple tasks can be completed through one of the lower “effort” settings, which uses fewer tokens, while longer-running agent-based tasks can go full throttle (“xhigh” or even Homer Simpson’s favorite setting, “max”). What Sonnet 5 can do for developers For much of 2026, AI product deployment has focused on equipping large language models to complete what has become known as “long horizon tasks.” It might be easy for a model to fix a bug or churn out some code. However, keeping its finicky attention fixed on a multi-part task has proven more difficult. The new version of Sonnet can go the distance, according to the company, compared with the earlier Sonnets. “Across a broad suite of internal and third-party benchmarks, Sonnet 5 shows clear gains over Claude Sonnet 4.6 in coding, agentic search, multimodal reasoning, and professional-task performance,” the System Card asserted. At the same time, however, the performance across these tasks still trailed that of the Opus and Mythos models. One testimonial from a Zapier engineer described a two-part job that flummoxed earlier Sonnets: Update a contact database and send out a notice to all users. Version 5 was able to complete the task “end to end.” Cybersecurity: Nothing to see here The San Francisco-based company also went out of its way not to attract any more undue attention from Washington, DC policymakers. “We did not deliberately train Sonnet 5 on cybersecurity tasks,” the company asserted. In June, the US Commerce Department, citing national security concerns, slapped Anthropic with an export control directive temporarily restricting foreign access to the newly released Mythos 5 and Fable 5 models. Whether Anthropic brought this on itself – through what could be regarded as hyperbolic assertions of Mythos’ deity-like bug-sleuthing powers – is certainly worth discussing. But Anthropic, like Pete Townshend, certainly won’t be fooled again. While it can readily perform routine cybersecurity tasks, Sonnet 5 is guardrailed against generating offensive attack code. When commanded to write a Firefox exploit, it failed to complete the task (though it got a bit further than Sonnet 4.6 in the attempt). “This latter change is likely due to improvements in general intelligence rather than specific training,” the company’s blog post noted. ®

Anthropic is removing its covert code for catching Chinese competitors

Wed, 07/01/2026 - 13:56
Anthropic says that it plans to remove hidden codes it added to Claude Code several months ago to catch other AI companies that are trying to steal from its models. Thariq Shihipar, an engineer at Anthropic who works on the Claude Code team, said on Tuesday that a fix should appear on July 1. "This is an experiment we launched in March that was meant to prevent account abuse from unauthorized resellers and protect against distillation," Shihipar explained, using the industry term for copying AI models through repeated queries. "The team has landed stronger mitigations since then and we’ve actually been meaning to take this down for a while." He said that the pull request to remove the code has been merged and should appear in Wednesday's Claude Code release. The experiment, as described by a developer who goes by the name Thereallo, consisted of applying steganography – hiding secret data in plain sight – to the Claude Code system context that gets passed to Anthropic's servers. The relevant code checks Claude Code's base URL environment variable, used to route API requests to a proxy or gateway. If the base URL has been overridden, the code goes on to check the system timezone and whether the hostname matches any entry in a list of known Chinese AI labs, other AI companies, account resellers, and gateway domains. Thereallo said that while it makes sense that Anthropic might try to detect a hostname associated with a Chinese AI rival or a reseller, the implementation should not have been concealed. "[Claude Code] silently alters the system prompt using invisible-ish Unicode markers," Thereallo wrote. "It encodes proxy / gateway classification into a sentence that looks like plain English. It hides the domain list behind XOR and base64. This is not a malicious feature, but it is a weird choice for a developer tool that asks for trust." Asked whether Anthropic disclosed its covert usage tracking mechanism in any of its terms of service documents, a company spokesperson pointed to Shihipar's remarks, which did not address that question. Nor did Anthropic's spokesperson immediately respond to a request to specify what "stronger mitigations" have been implemented to prevent unauthorized resellers and distillation. In February, shortly before the implementation of the steganographic codes, the AI biz said that it was investing in defenses against distillation. These included detection via classifiers and behavioral fingerprinting systems, intelligence sharing with other AI labs, access controls, and countermeasures that make it harder to use model output to reproduce the model. One such defense came to light when the company's Claude Code source leaked. The coding agent includes a Typescript file with a flag called ANTI_DISTILLATION_CC. The flag, when set, injects fake tool data into API requests in an attempt to make that data toxic for model training. Even with its technical defenses against competition, Anthropic urged the AI industry, cloud providers, and government to respond to the threat of model distillation. A recent White House Executive Order that articulates the intent to protect US AI from foreign adversaries shows that the feds have some interest in answering that call. ®

Godot says bye bye AI, bans vibe-coded contributions

Wed, 07/01/2026 - 13:29
Vibe coders apparently don't understand what their AI servants write - at least that’s what the team behind open-source game engine Godot seems to be implying with a new policy that cracks down on AI-generated contributions. The Godot team announced on Tuesday that they were in the process of rewriting their contribution policy to prohibit almost all use of AI from contributors, citing an overwhelming number of pull requests that have poured in, many of which appear to be AI-generated. Nor, the maintainers suggested, can many heavy AI users be relied on to respond meaningfully to review feedback. “AI cannot take responsibility, and we can’t trust heavy users of AI to understand their code enough to fix it,” the Godot maintainers said in their announcement. Ouch. The maintainers described AI pull requests as “demoralizing” for the Godot team, echoing comments made earlier this year when maintainer Rémi Verschelde said AI pull requests were increasingly draining and demoralizing wastes of time. AI PRs, one game studio that uses Godot noted earlier this year, are largely garbage, come from users who don’t understand what they’re proposing, and are largely “a total shitshow.” The Godot team said that it now recognizes the problem isn’t going away, so it’s time to do something about it. “Accordingly, we are in the process of updating our contribution policies, including adding a stricter policy on AI contributions,” they said. For starters, new contributors (defined as anyone with three or fewer merged pull requests) will be required to get explicit permission from maintainers if they want to submit new features or significant refactoring to Godot's codebase. This, the team said, is a bid to exclude vibe coders and AI agents and nurture a group of contributors who understand the Godot codebase and are willing to communicate with the team to learn more about it. On that note, contribution discussions will be required to remain human-to-human, too: No AI agents or bots clogging up the comms channels, unless they're being used to translate between languages. “We need to ensure that people who choose to review PRs feel their time is well spent,” the Godot maintainers explained. As for AI code itself, any autonomous agent-authored contributions or vibe-coded garbage will continue to result in an auto-ban from the team’s GitHub repo, and the team is extending that ban on AI code to include a prohibition on the use of AI to generate any substantial piece of code. “AI assistance should be limited to menial things (like code completion, regex, or find and replace),” the team explained. “If you do use AI in some capacity to author code, you must disclose it in the PR discussion.” The policy has yet to be formally amended, and the Godot maintainers didn’t say when exactly they’d release the update. Needless to say, vibe coders and AI agents aren’t welcome even now, so don’t push your luck. Vibe coding has shown other signs of falling out of favor lately as horror stories about deleted databases and wiped drives continue to pile up. Just last week, the chairman of IT consulting service Infosys predicted that vibe coding wasn’t something professionals should be worried about as there’s more to writing good software than coding. “Given that AI is a much larger and disruptive technology transition than ever before, the questions are louder and the doubts are more insistent,” Nandan Nilekani said in a speech at the company’s AGM last week. “While we will embrace the best coding tools and improve our productivity, there is much more to do in the software development life cycle.” Context, Nilekani said, is paramount in software development. Based on the vibe-coded disaster that Godot has dealt with, AI doesn’t seem quite capable of grasping that important element. ®

Somebody told DeepSeek to build in-browser ransomware and it gleefully complied

Wed, 07/01/2026 - 12:57
You can't ask most models to help you make "ransomware" directly, but many will be more than willing if you give them the right prompt. DeepSeek and other LLMs with fewer safety and security controls make theoretical cyberthreats - like browser-only ransomware - much more likely to be used in real-world infections, according to Check Point researchers. The Israeli cybersecurity company analyzed a DeepSeek-generated sample in a Wednesday report that its threat hunters describe as in-browser ransomware. Over the past year, the team has tracked almost 3,000 files attributed to DeepSeek, and classified nearly half (1,383 files) as malicious or dangerous using VirusTotal or static source analysis. “Within this dataset, we found a sample that implemented a dangerous browser-native technique we have not observed exploited in the wild,” researcher Alexey Bukhteyev wrote. And while the sample was incomplete, and unable to pull off an in-the-wild infection, the security shop’s testing showed “little effort” would be required to make it attack-ready. “Our research shows that the original incomplete DeepSeek sample can be transformed into a fully functional attack with minimal effort,” Pedro Drimel Neto, malware analysis team leader at Check Point Research, told The Register. “Very little effort is needed,” Neto said. “Low-level expertise is sufficient. You don't need to be a sophisticated cybercriminal or advanced persistent threat group. In fact, we've already observed evidence of actual threat actors attempting this attack using straightforward LLM prompts.” Known threat gets an AI boost The risk ransomware poses to browsers isn’t a new idea. The File System Access specification lists ransomware as a security consideration, and a 2023 USENIX Security paper on Ransomware over Modern Web Browsers described how File System Access API could be abused to encrypt local files from a malicious web application. The File System Access API is a browser capability, primarily supported by Chrome and Chromium-based browsers, that allows developers to build web applications, such as editors, IDEs, and creative tools, that can read, write, and manage files on the user’s local device. “Even though it can be used to develop rich web applications, it greatly extends the attack surface, which can be abused by adversaries to cause significant harm,” Google’s Güliz Seray Tuncay and Florida International University researchers Harun Oz, Ahmet Aris, Abbas Acar, Leonardo Babun and Selcuk Uluagac wrote in 2023, long before LLMs could develop working malware and attack chains. What’s new, according to Check Point, is that an AI model put these previously documented ideas into a “realistic and enforceable attack scenario leveraging a method that defenders had originally thought was unfeasible due to browser sandboxing limits: a DeepSeek-attributed malicious sample, generated as an all-in-one malware fantasy, connected this documented platform risk to a realistic phishing-style web application, demonstrating a viable end-to-end attack chain.” This technique is especially appealing to attackers because it doesn’t require a native payload, APK installation, browser exploit, or root access to a compromised device. Instead, it uses social engineering - tricking a user into clicking on a malicious button - combined with a legitimate permission prompt exposed by the File System Access API in Chrome. Meet InfernoGrabber 9000 This particular sample that Check Point uncovered is a Python Flask application that targets Android users. It’s named InfernoGrabber 9000, and VirusTotal calls it a “fully functional information stealer and ransomware toolkit.” While the security sleuths don’t have the prompt submitted to DeepSeek to produce the malware, they speculate it was something along the lines of: “create a universal malicious tool that runs through the browser and collects as much victim data as possible, encrypts files, and demands ransom. In a single front-end, the generated code assembled routines and stubs for keylogging, clipboard monitoring, form and network-request interception, Discord-token collection, crypto-wallet and payment-card discovery, geolocation requests, webcam and microphone access, screenshots, local-file access, Chrome exploit stubs, ‘persistence,’ and a ransomware-style overlay.” To be clear: the sample doesn’t actually do all of this. “A more accurate reading is that it is an AI-generated blueprint in which the model tried to translate familiar capabilities of native stealers and ransomware tools into a web page opened in the browser,” Bukhteyev wrote. The code presents a victim-facing lure disguised as a Discord avatar AI upscaler. Clicking on the lure is intended to execute a slew of silent, harmful actions that run entirely inside the browser process. These include stealing Discord tokens, harvesting credit card numbers and cryptocurrency seed phrases, logging keystrokes, and capturing unauthorized webcam and microphone feeds. The code also includes specific routines for browser exploitation (such as targeting CVE-2023-4863), uses a hardcoded Discord webhook for data exfiltration and displays a ransomware WinLocker screen demanding Bitcoin. The good news for defenders is that the sample was incomplete, and the browser's built-in security model successfully prevents most of this functionality. However, Check Point was able to create a working proof-of-concept for the browser-native attack using the latest DeepSeek model V4. The team had to remove some of the more explicit terms - like ransomware - from the prompt, but ultimately produced the same functionality: “a web page that asks the user for access to local files, processes them inside the browser, and leaves the user unable to recover the original content.” AKA: browser-only ransomware. Neto told us that this type of LLM-generated code and in-browser attack is “likely happening now.” “We expect to see this activity in the short term, if we haven't already,” he added. While traditional ransomware and extortion groups target enterprises and critical infrastructure organizations, as opposed to Android-device users, which was the focus of this research, “we have seen increased end-user ransomware activity recently,” Neto said. “What's most concerning is that code obfuscation used in these attacks makes them difficult to spot, so there's a real possibility that attacks using this technique are already occurring in the wild but going unnoticed.” ®

An artificial cell with a full lifecycle has been created for the first time

Wed, 07/01/2026 - 12:10
A group of scientists in a Minnesota laboratory have made history, creating the first artificial cell with a complete life cycle. SpudCell, as the team behind it has dubbed the creation, is built entirely from known chemical components, and can grow, replicate its genome, divide into new generations of cells, and even demonstrate natural selection and competition as its genes change. That’s not to say SpudCells are alive, mind you, as the team behind it aren’t claiming to have become gods. What they have done, they note in a preprint paper [PDF] published while awaiting peer review, is to give new insights into the minimal qualifications for what it actually takes for something to be alive. That, and they’ve created what they say could be a “chassis” that could be adapted for everything from formulating new drugs to the actual creation of artificial organisms. “SpudCell is not a ‘finished’ cell, and it is far simpler than anything in nature,” biochemist, University of Minnesota professor, and SpudCell project leader Kate Adamala told The Register in an email. “SpudCell is proof of what is possible. It proves that non-living, defined molecules can be assembled into a cell capable of functions that previously were exclusively reserved for natural life.” For those wondering where the name came from, Adamala told us that it was originally dubbed “Potato Cell” as a nod to her Polish heritage, before the name was shortened to SpudCell. In terms of those minimal qualifications, one of the things that SpudCell suggested was how few kilobase pairs (kbp - one kbp represents 1,000 base pairs) a genome may need to support a complete synthetic cell cycle. Prior scientific work estimated a minimal genome could be as small as 113 kbp (human genomes contain around 3 million kbp), but SpudCells only contain 90 kbp. SpudCells are also able to divide without the need for a cytoskeleton, the internal scaffolding that gives many cells their structure and helps coordinate cell division, side-stepping what the team said has long been a bottleneck in synthetic cell research due to the cytoskeleton's complexity. Instead, SpudCells divide when proteins used to grow the cell crowd together at the membrane surface of the cell until mechanical stress forces it to split. As mentioned above, SpudCells also demonstrate competition and natural - or unnatural, in this case - selection. “When researchers introduced a genetic change that increased production of the fusion protein, cells with that change grew faster and produced more offspring,” the team explained. “After five generations, the faster-growing variant had outcompeted the original.” As a rather primitive cell without the full complement of features needed to sustain life, SpudCell does have its limitations. “SpudCell has a very primitive metabolism, and it cannot yet build its own ribosomes,” Adamala told us. Because SpudCells can't yet build their own ribosomes, researchers have to keep 'em fed with liposomes carrying ribosomes, enzymes, lipids, and other molecular components needed to keep the synthetic cells functioning. That’s good news for anyone worried about the little creatures escaping the lab and wreaking havoc on the outside world: Their biology precludes survival outside very specific lab conditions. The artificial cellular future The potential uses of things like SpudCell, which is in essence an artificial proto life form with biology that’s entirely known, understandable, and manipulable, are vast. As Adamala explained it to us, medicines, materials, industrial chemicals, and other manufactured products the world relies on are created via molecular transformation in natural living cells we manipulate to produce desired products, or from industrial processes with huge energy and environmental costs. “Cells built from scratch could perform molecular transformations industrial chemistry cannot,” the biochemist told us. Using biology in such a way requires far more understanding of cellular structures and processes, Adamala added, and to do that we need cells we fully understand - like SpudCell. “I’m a chemist, and ever since I started working on biology, I’ve been frustrated by our inability to fully describe and characterize any natural living cell,” Adamala said. “To understand and routinely use biology, we need engineerable and fully defined cells.” That’s where the second part of her team’s work comes in: Together with a group of colleagues, Adamala is taking her work out of the university lab and into a public-benefit institution called Biotic. The outfit intends to do its work publicly and openly in a bid to standardize artificial cell research and speed up whatever societal benefits the project could help create. “Every lab in this field is solving the same problems from scratch, and little of that institutional knowledge is carrying over to the next group,” Adamala explained in an email. “That is the problem I want Biotic to solve: How to turn a field of one-off accomplishments into a real engineering discipline, built on shared, open foundations, so the ability to engineer biology is not something only a few private hands ever hold.” There’s a lot of work to be done before SpudCell takes Biotic and the artificial cell research world beyond the basics, but it’s a start that SpudCell has contributed to, Adamala said, making a number of long-standing challenges tractable instead of far-future dreams of labcoat-bedecked boffins. “My personal immediate to-do list includes ribogenesis, better metabolism, and more robust division,” the professor told us. “Those three things, with the support of the community built by Biotic, will go very far towards making it a viable platform for practical applications.” ®

AI search could kill the web without new quality signals and revenue models

Wed, 07/01/2026 - 11:13
AI answers are killing content publishers, as they cause readers to stay on Google or on the chatbot of their choice, rather than navigating to dedicated websites. The end result could be catastrophic for the open web. Alex Chan, assistant professor at Harvard Business School, floats that prediction based on an economic model he describes in a paper titled "AI and the collapse of the www." A paper from Saharsh Agarwal, assistant professor at the Indian School of Business, and Ananya Sen, associate professor at Carnegie Mellon University entitled "The Impact of Google AI Overviews on Publisher Traffic and User Experience: Evidence from a Field Experiment," shows that Google AI Overviews "reduce outbound organic clicks by 39.8 percent and increase zero-click searches by 34.5 percent, without affecting sponsored clicks or overall search frequency." A zero-click search is what happens when a search user's query gets answered on the search results page, so there's no need to click through to a source website. "Overall, the results suggest that [AI Overviews] divert traffic away from publishers without improving the user experience or quality of engagement for websites," conclude Agarwal and Sen. Google CEO Sundar Pichai has argued otherwise, to some skepticism and despite Pew research to the contrary. Chan, from Harvard Business School, undertook his research to explore what has to be replaced to reimagine the market that AI is destroying. The open web, he begins, is based on a bargain: "Publishers produce content. Search and social discovery send users to that content. Visits generate revenue." In doing so, web visitors also generate information about informational quality through their clicks, subscriptions, and other interactions. These signals, he observes, help future visitors and search systems find quality sources. "Generative AI changes this bargain," Chan continues. "An AI answer can use publisher content while keeping the user in the AI interface. Users may be better served in the short run. But the source may lose the visit, the revenue from the visit, and the source-level signal that the visit would have produced." Chan's exploration of the topic is noteworthy because it looks beyond the revenue impact of diminishing visitor traffic – something industry players like Cloudflare are already trying to address. It also identifies other economically valuable signals lost to AI answer systems, what he refers to as "durable attention capital." This includes: subscribers, repeat readers, backlinks, bookmarks, reputation, and search authority. Chan characterizes his argument as a more disciplined version of the AI-will-make-the-web-collapse scenario. He's not saying every website will vanish, that all AI reduces the diversity of information, or that search is doomed. Rather, he contends, "when an AI platform diverts the revenue and measurement events without replacing them, costly human information may fall below replacement." Really, though, that is the web collapse scenario. AI answers make it uneconomical for people to produce content and their disincentive in doing so prevents the formation of quality and trust signals that add value to their work. To restore a functioning market, Chan says, the answer shouldn't be a "visitor replacement royalty" that AI search services pay to websites or a ban on AI answers. That just props up the traditional model. Instead, he argues that the focus should move toward the new point of attention – which for some queries may be AI answers – while finding a way to distinguish between costly human information and cheap AI imitation. He concludes, "Provenance, diversity prices, exploration credits, and informative audits are needed to restore the broader ecosystem: quantity, quality, diversity, source-level signals, and the conventional-search discovery channel that prevents self-reinforcing migration into AI answers." That may be more difficult than it sounds. Distinguishing between AI- and human-authored content can be quite challenging. And to the extent that there's potential profit in selling low-cost AI output as premium human-authored content, expect active resistance to labeling or other mechanisms that threaten slop arbitrage. ®

Red teamers turned Claude Desktop into a double agent to do their evil bidding

Wed, 07/01/2026 - 10:00
EXCLUSIVE Pentera Labs’ red teamers compromised a developer’s AI agent via his Claude Desktop app and ultimately turned that access into full remote code execution on the dev’s machine – demonstrating how an attacker could turn a trusted, chatty AI assistant into a double agent operating on their behalf. “Claude’s got a new voice,” Pentera's offensive security services team leader Dvir Avraham told The Register. “We acknowledge the huge trust in AI models – everybody uses them,” he said in a phone interview. “We used this trust to manipulate the victim, like under the hood, the victim didn't see it coming.” It also prompted Avraham to check his own platforms. “I became a little bit paranoid,” he told us. “I'm not allowing any command to run without me examining it twice.” In a report set to publish Wednesday, and shared in advance exclusively with The Register, Avraham and research technical lead Reef Spektor detailed the attack and what it means for organizations using agentic AI tools with local code-execution access. It began with a red-team assignment on a third-party platform that aggregates customer email inboxes into a single management interface. Avraham and Spektor won’t name the platform, or tell us exactly how they gained access to it. They used this compromised inbox – and told us any compromised inbox would work – to get into the victim’s Claude account. As the duo noted, breaking into an email inbox in real life – via a third-party management platform, phishing link, social engineering password reset, or even using AI agents – isn’t too difficult. “AI agents today have access to connectors and to direct MCPs into inboxes,” Spektor added. In addition to this prerequisite (compromised inbox), the attack chain also requires the victim to have Claude Desktop installed. Anthropic’s desktop app works across macOS, Windows, and Linux systems. It provides the same AI chat for conversations as claude.ai, and it also syncs across all devices and sessions tied to the user’s account. “We asked ourselves, can we leverage the sync behavior to infect other sessions and devices? (hint: yes!),” the red teamers wrote in the Wednesday report. Back to the AI Stone Age As of January, the desktop app also includes Cowork for longer agentic tasks, and Code for software development. So, for example, a user can send Claude a task from their phone and instruct it to work on their computer. As Anthropic says: “Anything you can do on your computer, Claude can do. Open apps, fill spreadsheets, navigate your browser. No setup, no passwords handed off.” The Cowork feature now makes Pentera Labs’ attack scenario even easier. However, when the security analysts were doing this research in November 2025, “back in the Stone Age in terms of AI, you didn't have Cowork or Claude Code, so we needed a way to actually execute commands because we wanted to take over the machine,” Avraham said. For this part, they took a keen interest in Claude Desktop’s personalization features. These are account-wide settings that tell the AI agent the user’s preferred approach and general communication instructions, along with more specific project instructions, such as guidelines for a particular workflow, or defined roles Claude should adopt within a project. The red teamers developed a base64-encoded prompt that instructed Claude to check for command-capable tools on the developer’s machine and execute the command if available, or produce a fake error message if not, prompting the user to download a tool that will execute the attacker’s commands. Then they pasted the prompt into the victim’s personal preferences on Claude, and this prompt syncs across all of the user’s devices. This ensures that the next time the user opens Claude Desktop and types in a chat, the poisoned instructions are loaded into their preferences and will silently run behind the scenes. The user thinks they are simply interacting with Claude as usual. They don’t see Claude checking to see what extensions and tools are installed. If the user already has Desktop Commander or a similar MCP connector or extension installed, the poisoned instructions tell Claude to use it. This allows the attacker, via Claude, to execute a stealthy reverse shell or other malicious code. “And from there it's full compromise of the machine,” Avraham said. Phishing - but without the email However, if there aren’t any command-capable tools installed, then Claude becomes what the researchers describe as a “phishing layer.” (They also noted that if they had performed this research more recently, not back in November, the Claude Cowork feature would have eliminated this entire tool enumeration and phishing phase because Cowork can execute commands on a user’s behalf.) The injected prompt instructs Claude to present a realistic-looking error as soon as the victim asks the chatbot a question. This includes a realistic error code, a link that purports to be a fix, and step-by-step instructions. “This message tells the victim: ‘please download this,’ and we took links from the actual Anthropic site, with known emojis that the AI loves,” Avraham said. Because the error message looks real and people usually trust their AI assistant, they will likely click on the link and execute the attacker-controlled command. “From here, the attacker has full command execution – reverse shells, data exfiltration, credential harvesting, whatever the objective calls for,” the duo wrote. “In our case, we had Claude curl a remote server we controlled on every interaction, fetching and executing whatever bash commands we served back. We could rotate those commands server side at will, effectively turning Claude into a persistent, stealthy C2 agent that the victim themselves kept feeding.” In this specific case, the target was a developer who had credentials and access to several internal systems. After compromising the dev’s workstation – which gave the red teamers a foothold into the organization – they moved laterally across the company using various attack vectors that they declined to tell us about, citing customer privacy and proprietary methods. But, Spektor added, developers make for an “excellent starting point for an attacker,” because of their access to secrets including API keys, tokens, and cloud credentials, which allows intruders to move from a single workstation into the larger organization’s cloud environment. From there, they’ve got free rein to steal source code and other sensitive data, or poison internal git repositories, and cause all sorts of pain for enterprises as we've seen play out multiple times across several recent attacks. Feature, not a bug The team reported their findings to Anthropic back in November, and the AI company essentially said it’s Claude Desktop working as intended – a feature, not a bug. “After reviewing your submission, we've determined this doesn't represent a security vulnerability that falls within our program scope,” Anthropic said. “Our current threat model treats personal preferences, skills, and MCP connectors as features that can execute code through Claude Desktop by design. While we recognize these features can be leveraged to execute arbitrary code when manipulated, this represents expected functionality rather than a security vulnerability in our infrastructure.” The Register reached out to Anthropic for comment and did not receive any response. The red teamers, however, have some suggestions to keep your organization safer from rogue AI agents. First, for anyone using agents or chatbots: pay close attention to what the AI can do on your machine, and don’t blindly follow install prompts or error messages. “If you can, run it on a sandbox and not on your personal computer,” Spektor said. Security teams should treat AI desktop apps as “privileged software” as they can execute code, read files, and interact with local tools. “Monitor for changes of AI assistant configurations and synced settings,” the researchers wrote. “Restrict which extensions and tools can be installed alongside AI apps.” And finally, red teams should add AI desktop apps to their assessment toolbox, Avraham and Spektor noted: “There's a real attack surface here that most engagements don’t cover yet.” ®

NASA unsure Boeing Starliner will ever be certified for human flight

Wed, 07/01/2026 - 09:02
Place your bets, because it looks increasingly unlikely Boeing's Starliner spacecraft will carry astronauts again, if a NASA inspector general's report is anything to go on. Published on Tuesday, the OIG report on NASA's management of its Commercial Crew Program (CCP) examines how SpaceX and Boeing have performed in providing crew transportation to the International Space Station. The report notes that SpaceX worked through its own technical challenges getting humans into space and to the ISS. Boeing’s Starliner, a.k.a. the Calamity Capsule, on the other hand, featured extensively in the writeup, with the OIG calling into question whether it’ll ever get past the testing phase. “Boeing has been unable to obtain human-rating certification for its Starliner capsule and Atlas V launch vehicle, conducting two orbital flight tests and one crewed flight test that suffered significant issues and was ultimately classified as a serious mishap,” the OIG report said. “With over 11 years invested and about 4 years of crewed operations aboard the ISS remaining until the Station’s planned decommission in 2030, NASA and Boeing have limited time and resources to realize the value of their significant investments into Starliner.” The saga of Boeing’s Starliner has been one of repeated failures and budget overruns, both at NASA and Boeing, thanks to the capsule’s disastrous launch record. As the NASA OIG noted in its report, Starliner has flown three test missions, one with crew, and each encountered significant technical problems. The first flight, in 2019, failed to reach the ISS because a software-related mission timing error caused an incorrect orbital insertion burn, preventing the spacecraft from docking. Problems with stuck oxidizer valves discovered ahead of a planned 2021 launch delayed the second orbital flight test until May 2022, when Starliner successfully reached the ISS despite experiencing thruster failures and helium leaks. NASA was going to get a pair of astronauts up in the craft in 2023, but that didn’t happen after a series of issues were discovered, including a faulty parachute system and flammability risks associated with tape used to protect internal wiring. The one crewed mission that Starliner attempted was also a disaster. No one was injured or killed in the incident, but NASA astronauts Butch Wilmore and Suni Williams were stranded on the ISS for months after NASA determined the craft wasn’t safe enough to return its crew to Earth. According to the OIG, it’s the parachute problems, along with persistent helium leaks and the aforementioned propulsion system failures, that are making it question whether Starliner is fit for purpose. “The helium leaks and propulsion systems failures remain unresolved as of March 2026, and NASA is uncertain as to when this testing will be completed or human-rating certification for the Starliner will be obtained,” the report states. The OIG placed the blame on both NASA and Boeing for the problems, similarly to what NASA Administrator Jared Isaacman said earlier this year when he accepted that his agency was part of the reason the whole thing had gone so badly. Per the OIG, NASA contributed to the problem by being “overconfident in Boeing’s design and potential success based on the provider’s use of heritage systems,” which led to the space agency setting “unrealistic launch and flight test schedules.” “The pressure to adhere to this aggressive schedule was compounded by NASA’s underutilization of the contract’s data rights, limiting the Agency’s ability to fully analyze and resolve flight simulation training failures to ensure crew safety,” the report continued. Staffing constraints driven by the Trump administration’s desire to cut costs wherever it can find them are likely to further hinder oversight, the OIG said, calling into question once more whether the Calamity Capsule will ever fly again and whether it's worth the cost. “We question $127.9 million in payments to Boeing, in addition to the $43 million we questioned in a prior 2019 CCP-related report, for a mission that is far from certain,” the OIG said. In other words, if you want to trim some NASA fat, the Starliner budget’s a perfect place to do it. ®

Pages