When backups aren't enough: the case for real disaster recovery
Ask most IT teams whether they're protected against a major outage or ransomware attack, and the answer will almost certainly be yes, because the backups are in place and the box marked 'disaster recovery plan' has been ticked. But there's a difference between having a backup and recovering from a disaster, and that gap tends to reveal itself at the worst possible moment. The backup problem nobody talks about Backups were built for a different era. When the biggest threat was hardware failure or accidental deletion, copying files to tape or a secondary disk made sense, because the workflow was simply to preserve the data, restore from the copy, and carry on. Modern threats operate differently. Ransomware operators do not just encrypt production systems; they target backup infrastructure first. By the time an attack becomes visible, malicious code may have lain dormant in the environment for weeks, so backup jobs from that window are already tainted. IBM's 2025 Cost of a Data Breach Report found that 76 percent of organizations needed more than 100 days to recover from a cyberattack, including those that believed their backups were intact. For organizations with on-premises backup infrastructure, the arithmetic is brutal. Systems sit offline, staff cannot work, and customers feel the impact while IT teams scramble to find a clean recovery point that may or may not exist. The gap between RTO goals and reality Recovery time objectives (RTO) and recovery point objectives (RPO) are the core metrics of any disaster recovery plan. RTO defines how long systems can be offline before the business is materially harmed; RPO defines acceptable data loss. Both look reasonable on paper, yet practice tends to expose them as aspirational more often than IT teams care to admit. Legacy backup tools were designed to protect data, not to deliver fast recovery at scale. Restoring a full server takes hours or days, especially when the target hardware differs from what was lost. Testing rarely happens rigorously, which leaves edge cases unexplored, so when disaster strikes the recovery plan turns out to have been theoretical. Among businesses with 20 to 100 employees, 57 percent report downtime costs exceeding $100,000 per hour. For an SMB earning $10 million in annual revenue, a single day offline can cost $55,000 in direct losses. One in five SMBs would go out of business if the attack cost them as little as $10,000 in damages. The market is responding. The global Disaster Recovery as a Service (DRaaS) sector was valued at $18.89 billion in 2025 and is projected to reach $83.15 billion by 2034, a trajectory that reflects how many organizations are moving beyond backup-only thinking. What DRaaS changes Disaster Recovery as a Service is a different proposition. Rather than copying data and hoping restoration goes smoothly, DRaaS maintains a live, continuously updated replica of the protected environment and provides the cloud infrastructure to run it within minutes of a failure. In a ransomware scenario, the architecture matters. Immutable, offsite cloud storage keeps backup data beyond the reach of an attacker who has compromised the local environment, while automated failover removes the dependency on a manual process that has rarely been rehearsed. Because the replica runs in the cloud, recovery time is counted in minutes rather than days. Cove Data Protection's DRaaS is built on this model. The architecture is cloud-native by design rather than an appliance-based product with a cloud layer retrofitted. Backup data lives in N-able's private cloud , physically separated from customer infrastructure, with immutability applied by default. Tested failover to the cloud comes as a core feature rather than a premium add-on. Cove is built for the modern era and requires minimal babysitting, with multi-tenant management, automated testing, and a single interface across the entire environment. That contrasts with enterprise platforms that demand heavy customization before they work. Testing as a feature, not an afterthought How DRaaS providers approach recovery testing is one of the sharpest differentiators in the market. Most backup products leave it as a manual exercise that IT teams plan but rarely complete, because spinning up a recovery environment is disruptive. Cove automates recovery verification, with tests that run against backed-up workloads and confirm restoration succeeded. Administrators see evidence that the systems they protect would come back online as expected. The benefit extends beyond compliance to the difference between a plan that works and one that merely exists. For businesses and MSPs that handle dozens or hundreds of clients or employees, tested and verified recoverability at scale has become central to the value proposition and a genuine differentiator in a market where backup is now a commodity. Cove Data Protection, part of the N-able portfolio, provides cloud-native backup and disaster recovery as a service for organizations. Learn more at n-able.com/products/cove-data-protection. Contributed by N-able.
Microsoft lets Azure Linux 4 out of the cloud in downloadable ISO form
Microsoft's Fedora-derived Azure Linux 4 has hit a new milestone: you can now run it outside of Azure. The project's GitHub page now offers ISO file downloads in addition to its Azure Marketplace page. We covered the Azure Linux 4 announcement in May, and it is still in preview. You should not deploy this in production just yet. The availability of ISO files for installation in a local VM is a welcome step forward, though. They are not where you might expect to find them for a FOSS project on GitHub, under Releases – there are just some kernel builds there. You need to scroll down to the section headed Using Azure Linux and then expand the section headed ISO Installer. Both x86-64 and Arm64 images are available. Azure Linux 4 is the successor to the older Microsoft CBL-Mariner distro we looked at in 2022, which in 2024 transformed into Azure Linux 3. Now, configuration is mostly in TOML files, while older releases used .spec files inherited from VMware Photon OS, which was mentioned on The Register a decade ago. This build, which reports its name as "Four Beta," uses kernel 6.18 and systemd 258.4. It derives most of its package sources and packaging metadata from Fedora, but that does not mean this is a rebadged edition of Fedora Server, and you should not expect it to be compatible with Fedora packages. Only two repositories are configured by default: azurelinux-base and azurelinux-microsoft, both on packages.microsoft.com/azurelinux/. There isn't a great deal in them yet, or in the distro itself: for instance, we were surprised to find the less command missing, and htop was not available to install. The good news is that you do get the dnf package manager command, though. Azure Linux 4 is not some immutable dedicated container host. This is because Microsoft has one of those too – Azure Container Linux – which is intended to serve as a container host for the Azure Kubernetes Service, and it's on GitHub. So don't expect to find GNOME or any other nice graphical desktop in Azure Linux 4: this is a distro intended to run in an Azure VM, although it works fine inside a local Hyper-V VM. The preview is only a 1 GB download, and takes 1.1 GB of disk and 359 MB of RAM. The installation program is a very basic command-line tool, and, by default, it creates and installs into an LVM config, with memory ballooning enabled. All this highlights that this is not some general-purpose PC OS, intended to replace Windows, or Windows Server, or anything of the kind. This is not the "Microsoft Linux" that was parodied at the turn of the century (although we do like the "Gates Private License, which means you can freely use this Software on a single machine without warranty after having paid the purchase price and annual renewal fees"). Azure Linux 4 isn't really meant for humans to install at all, let alone on bare metal. Its typical role would be to be automatically provisioned by some deployment pipeline. The ISO file is just for testing purposes. There are some reports of a two-year update cycle, but the published lifecycle doesn't mention that, only that it will use LTS kernels and get monthly security updates. Azure Linux 4 reflects that Microsoft is bringing some more of its toolchain in-house. Two years ago, we reported that it moved LinkedIn to Azure Linux, thus removing a dependency on an external product that was end of life: the CentOS Linux distribution, replaced by the rather different CentOS Stream. Now, with the move to Fedora as its upstream source, it's removing another dependency on the aging VMware Photon OS. As The Reg has reported recently, other VMware customers are moving away from Broadcom, including international supermarket chain Tesco and telco giant T-Mobile. ®
Cloudflare to block cynical search-and-scrape bots from ad-supported web pages
Cloudflare on Wednesday said it will soon prevent mixed-use crawlers from accessing ad-supported customer websites by default, part of its ongoing efforts to give site publishers more control over how they engage with AI services. Apple, Google, and Microsoft's Bing operate crawlers that could fall afoul of Cloudflare's decision, although each of the tech giants offers an AI opt-out that may allow them to escape sanctions. Web crawlers make automated network requests to websites for various purposes. Google has used them for decades to visit websites for inclusion in its search index. Over the past few years, many crawlers have started visiting sites to harvest content for training AI models. This has prompted various countermeasures – publishers feel they're not being fairly compensated for the content AI companies scrape to feed into their models. But since Google's crawler, Googlebot, combines crawling for search indexing and content harvesting for AI training, site publishers have tended to accept the bot's presence because they fear blocking could mean they disappear from Google Search results. The situation is similar for Microsoft's Bingbot. And Apple also has enlisted its Applebot crawler to handle AI data gathering in addition to its indexing duties. The iBiz in June said: "The data crawled by Applebot may also be used to help train Apple foundation models powering generative AI features across Apple products, including Apple Intelligence, Services, and Developer Tools." Apple and Google support robots.txt directives that allow publishers to opt out of AI data harvesting (via Applebot-Extended and Google-Extended). Bing supports a content="noarchive" attribute for the robots meta tag that also blocks data harvesting. Other crawler operators, however, often ignore the voluntary robots.txt. Cloudflare therefore aims to provide site owners with a declarative content gate. "Now that the majority of traffic on the Internet is non-human, we must go further and act faster so that a sustainable ecosystem can emerge," said Matthew Prince, co-founder and CEO of Cloudflare, in a statement. "Cloudflare's new tools and partnerships give website owners increased visibility and commercial opportunities and reward AI companies that have bots with clear and transparent intent. We hope that our proposed default changes encourage mixed use crawlers to separate out search from agent use and training." Starting September 15, 2026, new Cloudflare customers and new sites for existing customers will default to allowing search crawling but blocking training and agents from pages with ads. The changes will also be applied to free tier customers who have not changed their settings. As the company puts it: "This ensures that content that drives revenue cannot be crawled without explicit permission of those content owners." Between humans running ad blockers and Cloudflare blocking bots from pages with ads, a lot of marketing material may be consigned to oblivion. Cloudflare customers, however, can readmit crawlers to their ad-supported pages by changing their default site settings. Cloudflare is also making two other changes. Its "Pay Per Crawl" tollbooth is being rebranded "Pay Per Use." The idea is to reward publishers when their content creates value instead of just when it's fetched. To make that happen, Cloudflare is partnering with Ceramic.ai, an API-based search biz, so that publishers get paid whenever their content appears in a Ceramic.ai search result. It's also working with You.com, a search engine for AI agents, to generate content payments whenever there's demand from an agent. A company spokesperson didn't immediately respond when asked about Pay Per Crawl uptake. Finally, Cloudflare is introducing a new Business Insights Dashboard to give publishers more visibility into how bots are consuming content and how much traffic AI models send. ®
DRAM it! Cheap PCs being priced out of existence as memory cost bites
Fewer Americans are buying PCs as rising component costs mean the sub-$500 bracket is rapidly disappearing, with laptop makers favoring higher-end machines – and things are likely to deteriorate throughout the year. According to stats compiled by Omdia, unit sales to US distributors plunged 7 percent year-on-year in Q1 to 15.8 million units. HP was hit hardest, shrinking by more than a fifth and losing its spot as the most purchased PC brand stateside. The decline reflects supply constraints and cost pressures from memory and storage prices, "compounded by a hangover following the Windows 11 refresh cycle," which the analyst said exhausted much of the near-term commercial pipeline. A strong comparison period from a year ago – when consumers and businesses pulled forward purchases to avoid Trump's tariffs – didn't help. As Reg readers know, memory makers are diverting production capacity to chips used in higher-priced AI servers, which is squeezing supplies of DRAM and NAND for PCs and smartphones. Rising component costs are eroding vendor margins on entry-level devices, making them commercially unviable. Unit sales of sub-$500 PCs dropped 18.7 percent in Q1. Supply is not likely to improve and US PC shipments for 2026 are forecast to shrink 14.4 percent compared with 2025. Consumers led the decline: the segment fell 9.5 percent year-on-year in Q1 and is expected to drop 11.2 percent for the calendar year. "Many consumers delayed purchase decisions amid higher price tags and challenging economic conditions," said Scott Braverman, senior analyst at Omdia. Omdia reckons memory costs are likely to "keep entry-level prices elevated through 2027, suppressing consumer demand." Biz PC shipments fell 5 percent, a better performance than the market overall, as some enterprises continued to replace Windows 10 machines and brought forward purchase orders in anticipation of further price hikes. The average selling price of a US PC surpassed $1,000 during the quarter, up 4 percent from a year ago, though it is expected to rise by up to 12 percent by December due to "supply-side headwinds" and a growing share of AI PCs. Ticket prices on business machines are estimated to grow 12 percent this year. Dell leapfrogged HP to become top dog in the US PC shipment stakes after it grew 1.1 percent. Lenovo closed the gap in third place on the back of 1.2 percent growth in shipments. ®
Citrix says it's back as a mainstream server virtualization player that won't send scary bills
Citrix says it has returned to the mainstream server virtualization market with the release of XenServer 9. The hypervisor was a contender in the early 2010s but struggled to compete with VMware and Microsoft. By 2014, analyst firm Gartner suggested Citrix had stopped trying to compete for workloads other than its own desktop virtualization and network security products. Citrix kept the product alive without much fanfare for years and rebranded it Citrix Hypervisor. After a pair of private equity firms acquired Citrix in 2022 and folded it into an outfit called Cloud Software Group (CSG), XenServer became the name of both the product and a CSG business unit that announced its intention to return to the mainstream virtualization market. XenServer didn't do much as a standalone entity other than to create a trial three-host version of its product to show off its smarts and tease more profound offerings. Last week, XenServer used its LinkedIn presence to reveal that XenServer is "back under the Citrix umbrella." The Register's virtualization desk understands that was effectively an announcement that XenServer as a business unit is no more. On July 1, Citrix released XenServer 9. A statement about the release sent to The Reg opens with the assertion that the software "is built for organizations actively reassessing their virtualization strategy under cost pressure." That's code for people considering an alternative to VMware. "While cost is often the initial driver for evaluation, long-term platform decisions are ultimately determined by operational impact," Citrix added. "XenServer 9 is designed to reduce that burden by simplifying lifecycle management, upgrades, and ongoing system maintenance." There's a more detailed summary of changes here that lists the "core enhancements" in the new release as improved performance on NUMA hosts, support for secure boot, a new OS for the control domain, and use of the recently released open source Xen 4.21 hypervisor. Supported guest OSes include Windows 10 and 11, Windows Server back to 2016, RHEL, SUSE, Debian, Rocky Linux, and Ubuntu. Gooroom 2 – a Linux distribution developed by South Korea's Ministry of Science and Technology – also makes the list. Citrix says the new release supports "any workload" and "also enhances operational alignment in Citrix DaaS environments." That sounds a lot like the same stance Citrix took in the mid-2010s – and it's trying to make a virtue of the fact. "XenServer 9 is a pragmatic response to the pressure infrastructure teams are facing today," Citrix proclaims. "It reflects a market reality in which cost, operational simplicity, and stability are tightly interconnected requirements that must be addressed together." "In this context, platforms are no longer defined by feature breadth, but by their ability to deliver predictable economics and operational stability over time." Those "predictable economics" derive in part from Citrix including an entitlement to use XenServer in several of its licenses. Those licenses, however, are typically bundles of many products – including some that users don't always use or want – and can involve big price hikes. Citrix justifies its licensing as simpler than buying individual products, and claims bundles mean customers get better value and easier operations. VMware uses the same arguments, and that hasn't always gone down well with customers. Michael Warrilow, an independent analyst who specializes in server virtualization, told The Register buyers are wary of Citrix's licenses, and won't forgive its long neglect of XenServer. "XenServer is a viable hypervisor, but Citrix has been missing in action in server virtualization for years," Warrilow said, adding that he would only recommend XenServer for users who intend to persevere with Citrix's desktop virtualization products. The analyst argued that forks like Xen Orchestra represent more interesting and significant virtualization platforms. Speaking of which, version 6.6 of Xen Orchestra dropped on Tuesday, bringing scoped storage and network admin roles in the REST API, automatic snapshots before updates, and more work to smooth VM migrations between different hypervisors. ®
Brit competition cops fast-track £2B borging of Netomnia into Openreach challenger
Britain's competition watchdog wants to cast a close eye over the proposed takeover of Substantial, owner of Netomnia, by a consortium that includes Virgin Media O2 owners Liberty Global and Telefónica. The Competition and Markets Authority (CMA) has referred the acquisition for an in-depth investigation under its fast-track procedure at the merging parties' request. It notified the parties earlier this week that it was launching an inquiry, and today's decision means it is fast-tracking the case to Phase 2 rather than conducting a full Phase 1 assessment. The inspection will determine whether it would lead to a "substantial lessening of competition" in the market for fiber broadband networking. The deal was announced in February, when Liberty Global, Telefónica, and InfraVia disclosed their intention to snap up Substantial Topco Limited (Substantial) in a transaction that valued it at £2 billion ($2.65 billion) through their existing joint venture company, nexfibre. Liberty Global and Telefónica are the joint owners of Virgin Media O2 and, together with InfraVia, joint owners of nexfibre. The trio said at the time they were looking to combine Substantial's fiber network concern (Netomnia) with nexfibre. Along with the 2.1 million premises served by Virgin Media O2, this would create a challenger to BT Openreach with a full fiber footprint of around 8 million premises by the end of 2027. The resulting entity would provide internet service providers with "a highly attractive wholesale alternative to the incumbent," the trio stated. The CMA will now test those claims against the possible loss of competition resulting from the consolidation, as it would reduce the number of fiber network operators and create a giant with the scale to take on BT, the UK's former state-owned telecoms monopoly. This is not the first time VMO2's owners have attempted such a move. Back in 2024, Virgin Media wanted to spin out its fixed-line broadband networks into a separate business (provisionally named NetCo) that would be open to other internet service providers for the first time. This proposal did not include nexfibre. But this ambition was canned last year amid an ongoing review at Telefónica that aimed to deal with the company's debt burden. To complicate matters, Liberty Global also has a 5 percent stake in another British telecoms operation, Vodafone, which it acquired three years ago, making for a tangled web of ownership in the UK comms market. The CMA investigation has a statutory deadline of December 15, 2026, which means its report will be out just in time to deliver a nice Christmas present for the investors – or perhaps not. Rival biz CityFibre is one organization opposed to the merger. "VMO2/nexfibre's planned acquisition of Netomnia would remove a successful challenger and reduce choice for consumers. With 80 percent overlap between the two networks, the deal raises significant questions and the CMA is right to take an in-depth look at its impact on UK digital infrastructure and the competition that policymakers, regulators and the altnets are working so hard to establish," commented CEO Simon Holden. However, CCS Insight director of Consumer and Connectivity Kester Mann told The Register that further consolidation within the UK telecoms market is inevitable. "With dozens of altnets in the market, including many that are struggling, further consolidation is inevitable. After many likely rounds of future deals, the market may eventually evolve into one with three major infrastructure providers, mirroring the situation in the mobile industry," he said. "But amid concerns over competition, it is right that the CMA carefully investigates the deal. It is unlikely to be blocked but there is a chance that some remedies are put in place to allow it to proceed." "The move straight to Phase 2 is both logical and expected, fast-tracking an investigation that would unlikely have been approved at the first stage." ®
Purism launches supersized 16-inch laptop for buyers who put privacy before price
Purism has launched the Librem 16, a privacy-focused Linux laptop with a 16-inch display and hardware controls designed to disable potentially intrusive components. The machine runs Coreboot firmware and disables Intel's Management Engine. Founder and CEO Todd Weaver told The Register about doing this back in 2017. Purism also offers privacy-centric smartphones. The new laptop has two hardware kill switches located in the strip between the keyboard and the screen hinge. One of them disconnects the Bluetooth and Wi-Fi controllers, and the other similarly neuters the webcam and microphone. The spec is reasonable. It has an Intel Core i7-13620H CPU with ten cores – six performance cores and four efficiency ones – which can boost up to 4.9 GHz. You can customize the specification to taste, but the base model has 16 GB of DDR4 RAM and a single half-terabyte M.2 SSD. The machine also has four USB ports (two USB-C and two USB 3 Type-A), HDMI, Ethernet, a headphone jack, and a memory card slot. It's available to order now for $2,899. It can handle up to 64 GB RAM and two M.2 SSDs, and the company has two pre-configured models: the Librem 16 Plus has 32 GB of RAM and a 2 TB SSD for $4,199, and the Librem 16 Max is maxed out with 64 GB of RAM and twin 8 TB SSDs for a hefty $9,799. All rely on the CPU's integrated GPU. There are some other options, though, including completely removing the wireless card, a special USB key that can verify the firmware hasn't been tampered with, extended warranties, and an optional anti-interdiction service. This is not a cheap laptop, but then this is not a machine for anyone looking either for an absolutely top-end spec or for the best bang for the buck. There are plenty of other companies happy to help if that's what you want, and we've reported on some of them, such as Tuxedo Computers' Stellaris AMD Gen 4 and the Slimbook range. The It's FOSS portal has a whole list of vendors of Linux laptops. By default, the machine comes with Purism's own distro, PureOS. This is one of the few Free Software Foundation-approved Linux distributions: it contains no proprietary code at all. The company has a page introducing it. You can download it for free and run it on your own hardware – although the chance of some components not working because of missing firmware is quite high. Since even Debian began including non-free firmware with version 12, you may well find that if you install PureOS, things like Wi-Fi or the webcam may not work. Speaking of Debian "Bookworm," the latest PureOS release is version 11, which was released in May. We took a quick look at the latest version in a VirtualBox VM. It uses kernel 6.1 and GNOME 43.9 – which is a clue that PureOS 11 is based on Debian 12, which shipped with these versions. A GNOME Wayland session is the default, although X11 is an option, as is GNOME Classic. Thanks to the Calamares installer, it's easy to install PureOS, although unusually, it uses full-disk encryption by default. It comes with Flatpak support preinstalled, but no Flatpak packages, and offers only the Purism Store to get more – which has a restricted selection of pure-FOSS apps. PureOS looks great and it's easy to get it going, but it's limited by design and a little dated. It is extremely impressive that Purism's Librem phones run the same OS, though. PureOS is emblematic of Purism more broadly: these are products aimed at buyers for whom privacy, security, and strict Free Software principles matter more than price, convenience, or performance. Purism's Librem 16 is available now. The company also offers a 14-inch laptop, a mini PC, a server, and an Atom-based tablet, the Librem 11. Alongside the Librem 5 phone, we also reported on Purism's LapDock docking station in 2023, which lets the phone act as a laptop. ®
Boffins peg narcissistic leadership as the real driver behind 'return to office' demands
OPINION Bosses say working from the office is all about productivity, but the truth is it's just a power trip driven by fear and narcissism. Executives who insist on people working from the office like to say it's all about productivity, culture, collaboration, and mentoring. Pull the other one; it has bells on. When executives demand that we "return to the office," they usually lean on a familiar set of talking points: remote work hurts productivity, people collaborate better in the office, and corporate culture only happens in the office. If you look closer, you'll see it's all malarkey. Recent research by Professor Adam Grant, an organizational psychologist at the Wharton School of the University of Pennsylvania, and two of his grad students found that one reason some bosses resist remote work may be a desire to preserve authority and status. Or, as the paper title so neatly puts it, "Worship me at the office altar: Why narcissistic leaders resist remote work." Over the decades, I've met and covered many top leaders, especially in tech, and I've found that all too many of them have narcissistic tendencies. Now, thanks to this study, I see this isn't just my experience. The paper is based on three studies that included Fortune 500 leaders. The researchers found: "Because in-person work offers richer channels for controlling and commanding reverence from employees, in their pursuit of authority and admiration, narcissists are likely to resist remote work." These managers argue that spontaneous hallway chats, whiteboard sessions, and faster decision cycles require colocation, especially for teams used to in‑person workflows. They insist that company culture only happens in the office and that loyalty, engagement, and shared identity are impossible to sustain remotely. They also frequently say juniors cannot be effectively trained without being in the office near seniors to absorb knowledge and norms. In my experience, leaders who teach are vanishingly rare. Companies talk a good game. The reality is something else. According to Gallup's latest American Job Quality Study, only 28 percent of workers get any mentoring. Even if you consider that a somewhat successful number, a closer look reveals that much of this mentoring consisted of a few early meetings, followed by the mentor putting off the junior employee as "real work" got in the way. Mentoring is a good idea, but without follow-through, it's a waste of time. The main reason self-absorbed bosses like to give is that remote work is less productive. For instance, Jamie Dimon, JPMorgan Chase's CEO, has long argued that remote work does not work well for people who want to "hustle" and advance. David Solomon, Goldman Sachs' CEO, famously called remote work an "aberration" that the firm would "correct as quickly as possible." You'll find this attitude in tech companies as well. Former Google CEO Eric Schmidt, for example, said in 2024 that Google was losing the AI race because "Google decided that work-life balance and going home early and working from home was more important than winning. And the reason startups work is that people work like hell. I'm sorry to be so blunt, but the fact of the matter is… you're not going to let people work from home and only come in one day a week if you want to compete against the other startups." Schmidt later rowed back on that opinion, admitting his "error" amid something of a backlash. I am so sick of that "startup" BS. Google, AWS, Microsoft, Meta, IBM, and all the rest that like to say they're rebuilding a startup work-from-the-office culture, are full of crap. Multiple billion-dollar companies are promising today's workers a shot at making millions from an IPO. They're working for a paycheck. Oh, and today, Google looks to be just fine in the AI race. Ego-driven management also relies on the old factory mentality that holds that the best workers are the ones who arrive early, work late, and are seen hustling by the bosses. Putting in 80-hour workweeks may be necessary at a startup, but in most businesses, that's as stupid as measuring programmers' productivity by lines of code or, more recently, by how many AI tokens they use. The simple truth is that, except for cherry-picked studies, such as the WFH Research's report, which found that fully remote work is associated with roughly 10 to 20 percent lower productivity, most studies find that people who work from home are happier and tend to be as productive, if not more so, than those stuck in the office. Staff forced to work from the office don't even make their employers more profitable. The bottom line is that many people love working from home – I'm one of them – and bosses who insist you must work from the office tend to be narcissistic jerks. If you have bosses like that and you're a worker bee, I encourage you to look for another, more remote-friendly employer. If you're in charge of a company and you have middle managers like that, I encourage you to look to AI to replace them. Yeah, I said it. These days, another reason such managers may want to keep people under their thumb is they know that while AI can't replace good managers, most managers can be dumped. Many of them are scared to death that someone will realize they're just messengers and meeting‑makers who contribute nothing to the company's bottom line. Worse still, from where they sit, they fear, with reason, that AI-driven services such as Jira, Asana AI, and ServiceNow can replace them in a heartbeat. I think that's a fine fate for narcissistic bosses. Fire them all and let unemployment sort them out! ®
ZTE honored with two GeSI DWP Global Awards for Signal Reach Program in Africa
ZTE has received two prestigious Digital with Purpose (DWP) honors - the Smart Cities Award and the Global Award - for its Signal Reach Program in Africa at the DWP Global Summit Shenzhen 2026. The awards span three core categories: Climate, Smart Cities, and Health & Wellbeing. In addition, the event presents the coveted Global Award as its supreme annual honor. Dubbed the Award of the Awards, it is the year's sole top overall prize, selected from outstanding entries across all category divisions. The Signal Reach Program in Africa distinguished itself among a competitive field of global submissions for its innovation, impact, and alignment with the values of purposeful digital transformation. These honors underscore ZTE's large-scale efforts to drive digital transformation in remote regions and highlight its significant contribution to advancing global sustainable development and closing the digital divide. Hosted by the Global Enabling Sustainability Initiative (GeSI), the summit brought together global leaders from government, business, academia, and research to explore the pathway of digital technology for good. As one of the most influential international awards under the framework of the United Nations Sustainable Development Goals (SDGs), the DWP Global Awards celebrate exemplary global projects that leverage digital technology innovation to promote social equity, environmental sustainability, and inclusive growth. Chen Zhiping, Chief International Ecosystem Representative of ZTE, accepted the awards on behalf of the company, underscoring ZTE's commitment to advancing global sustainable development and digital inclusion. She emphasized that the Signal Reach Program in Africa is not merely a communication technology initiative, but a locally rooted social responsibility project. Winning the two awards is a strong recognition of ZTE's long-standing commitment to the Tech for Good principle. ZTE will continue to leverage its technological strengths and collaborate with customers, NGOs, and partners across local communities to contribute to the realization of the UN SDGs. Addressing the pain point of weak infrastructure in remote and rural areas of Africa, the program is driven by the core philosophy of "ubiquitous connectivity, green energy, and inclusive sharing". It features the innovative "Rural Ecosystem" end-to-end solution, integrating "EcoSite + EcoEnergy + EcoDevice" to build a comprehensive digital ecosystem covering infrastructure, energy supply, and terminal access. The Rural EcoSite solution utilizes highly integrated equipment and various backhaul options, supporting flexible evolution from 2G/3G/4G to 5G. During construction, the innovative Lego-type modular tower drastically simplifies and accelerates deployment, shortening the average construction time by over 60% and reducing overall construction costs by 70%. To overcome the bottleneck of a lack of grid power in some remote areas, the Rural EcoEnergy solution provides a 100% solar-powered system equipped with high-efficiency PV panels and smart lithium batteries, managed by the iEnergy platform to realize dynamic load adjustment and remote monitoring. In actual deployments, some sites can even provide electricity for local villagers. For operation and maintenance (O&M), the solution supports end-to-end network management, with remote O&M simplifying processes and improving maintainability. The Rural EcoDevice solution delivers cost-effective smartphones, MiFi, and CPE terminal devices tailored for the African market, significantly lowering the barrier to digital access. Coupled with customized low-tariff data packages and digital skills training provided by operators, this solution successfully bridges the "last mile" of digital services. To date, the program has been deployed at scale in more than 20 African countries, including Liberia, Ethiopia, Cameroon, Algeria, South Africa, and Egypt. In Liberia, Orange Liberia and ZTE have delivered inclusive digital, financial, and energy services to over one million users in more than 200 low-density rural communities. In Ethiopia, Ethio Telecom and ZTE have brought stable network services to over 100 low-density areas, fostering the wide application of digital technologies in livelihood sectors such as electronic payments, remote education, and environmental protection. In the central-southern and eastern regions of Cameroon, the large-scale deployment of rural base stations and a 360-kilometer backbone microwave link has built a systematic rural communication reinforcement network, significantly enhancing mobile coverage density and quality to serve nearly 15 million people. In Egypt, high-speed broadband networks have been built for over 1,500 villages, covering nearly 10 million people. These achievements have not only realized extensive coverage of communication infrastructure but also effectively driven the inclusive development of digital technology in livelihood sectors. During the summit, Chen Zhiping joined the roundtable forum "Digital - The Backbone for a Sustainable Future", engaging with global leaders in digital sustainability. Drawing on ZTE's extensive practices in global ICT infrastructure development, she shared insights on how digital technologies can provide a solid foundation for sustainable development worldwide. Chen Zhiping highlighted, "Sustainable development is not only about carbon reduction, but more importantly about ensuring universal access to digital opportunities. Affordable, green, and inclusive digital infrastructure is the cornerstone of a sustainable future". She also emphasized ZTE's commitment to open collaboration, noting that the company actively shares its experiences while advancing its own digital and sustainable transformation, and expressed ZTE's readiness to work with global enterprises and international organizations to co-create a digital-for-purpose ecosystem. Guided by its people-centric philosophy, ZTE is dedicated to ensuring that people across different regions enjoy equal communication rights and digital opportunities. Moving forward, ZTE will continue to deepen its commitment to green communications, digital inclusion, and low--carbon operations, driving the ICT industry toward greater inclusiveness, intelligence, and sustainability, and jointly building a brighter digital future. Contributed by ZTE.
UK.gov vows to cut consultancy spending, then hands up to £350M to consultancies
The UK's Home Office has awarded two global consultancies contracts worth up to £350 million for data and analytics services, despite the government's commitment to spend less on consultants. Deloitte has won a four-year deal worth up to £200 million to offer "strategic multifunctional teams" for data analytics, data matching and data insight services. PA Consulting has won a contract for up to £150 million for the same services over the same period, according to procurement documents published last week. In November 2024, the UK government promised new controls on the use of consultancies across the public sector to cut unnecessary spending and save £1.2 billion by 2026. The Cabinet Office and Crown Commercial Service said the controls were expected to provide far greater oversight, with ministerial sign-off required for any consultancy spend over £600,000, or for contracts lasting more than nine months. Consultancy spending over £100,000 was to be signed off by the relevant permanent secretary. The Register has asked the Home Office whether the above contracts were subject to these controls and, if so, why they were approved. It has yet to respond. In November 2025, the National Audit Office, a spending watchdog, said His Majesty's Treasury (HMT) lacked comprehensive data on government consultancy expenditure, potentially delaying progress toward "ambitious targets" to cut costs. The Public Accounts Committee (PAC) said in March that departments were not complying with Cabinet Office directives on consultancy spending, and compliance was not being monitored. The committee called for a list of departments not complying with Cabinet Office requests on consultancy procurement, and a detailed breakdown of what each department spends on individual private contractors, categorized by type of service. The Science, Innovation and Technology Committee recently published a report stating that government spending on contractors was one impediment to achieving its digital transformation goals. It said contractors in central government cost three times as much per year as civil servants, and across the public sector, contractors accounted for roughly 18 percent of headcount but 40 percent of staffing costs. It called for publication of departmental plans to reduce the proportion of their workforce made up of contractors and the associated cost in digital and technology roles. Meanwhile, the government should create a digital workforce strategy to "deliver on the Prime Minister's commitment for one in 10 civil servants to be in technology and digital roles by 2030, as well as a definition of what constitutes a technology and digital role in the civil service," the committee said. The government has long been told that lack of internal tech skills is a real problem. In 2023, the PAC reported on the barriers to achieving greater efficiency through digital transformation. Dame Meg Hillier MP, chair at the time, said the government's digital ambitions were "hobbled by staff shortages and a lack of support, accountability and focus from the top." "The government talks of its ambitions for digital transformation and efficiency, while actively cutting the very roles which could help achieve them," she said. ®
Portuguese restaurant kiosk software gives Windows indigestion
Restaurant kiosks are hazardous places, and not only on the side of the screen where patrons jab greasy fingers. On the other side of the glass, things can also go wrong when Windows starts working against the kiosk software. Spotted in a Portuguese restaurant chain by eagle-eyed Register reader Mário, the screen shows Windows 10 - though it could possibly be Windows 8.x - turning its nose up at a kiosk application. Either way, the sight of it would be enough to put even the most cast-iron sysadmin off their lunch.. In this instance, the WinRestKioskWPF.exe file is apparently lacking a digital signature to verify its publisher. It has therefore failed the Windows 10 sniff test, and a warning is on display. The problem is that this is a kiosk, so rather than being able to select and enjoy a Portuguese specialty (most likely something with a fried egg on it – if you know, you know), the hungry customer is presented with a baffling dialog. They could press Run (assuming the touchscreen passes input through to the desktop), or they could do the sideways shuffle of shame to a working kiosk. The software appears to be part of the WinRest suite of Point of Sale software. According [warning: this is an HTTP URL] to the company's website, its tools are "ultra-secure and affordable." The suffix, WPF, indicates it is a version written with the Windows Form replacement, the Windows Presentation Foundation (WPF). WPF is an interesting choice for a modern application. It is, after all, very much Windows-only (yes, it was one of the inspirations for Avalonia), but since this kiosk is running Windows, it's not a terrible choice. Unless, of course, WPF means something different in this instance. We Prefer Frying? It's a possibility. And perhaps also why a clean-living installation of Windows 10 has rejected the application. ®
Japan wants 10 million more robots by 2040, some providing medical care
Japan has updated its national robotics strategy with a goal to adopt 10 million robots by the year 2040, with some intended to provide medical care. Minister for the Economy, Trade and Industry Ryosei Akazawa yesterday announced the amended strategy, which envisions more robots working to provide medical care, or taking on roles in the food and beverage manufacturing sectors. To make it happen, Akazawa announced investments in models for AI-powered robots and other forms of physical AI. As is often the case in Japan, this effort will bring together a handful of industrial giants to share their expertise. That collaboration will take place within a new organization called “Noetra” that will be majority-owned by SoftBank, NEC, Sony Group, and Honda. Fujitsu and Rakuten are apparently pondering participation. The minister said Japan already has a lot of robotics expertise gained from using machines in healthcare for the elderly, disaster response, manufacturing, and even decommissioning the Fukushima Daiichi Nuclear Power Plant. He hopes to use that experience to turn Japan into a robotics powerhouse that serves domestic needs and creates world-leading products. One reason Japan is keen on robots is the combination of its ageing population and restrictive migration policies means it is hard to find workers. Robots therefore supplant humans in some roles – and often do so without much complaint because they’re not taking jobs but instead are filling jobs humans aren’t available or willing to perform. South Korea announced a similar plan to become a robotics powerhouse on Monday, so let battle be joined! Hopefully not giant robot battle – an aspect of robotics that’s a notable feature of Japanese popular culture. ®
Former Indonesian minister and startup hero jailed for Chromebook buys
An Indonesian corruption court has sentenced the nation’s former education minister Nadiem Makarim, who is also a hero of the nation’s tech startup scene, to ten years in jail for his role in buying a stack of Chromebooks. Nadiem is a co-founder of Gojek, a so-called superapp that offers ride share, food delivery, digital payments, and even logistics services. In 2021, Gojek merged with its rival Tokopedia. The combined entity became a ubiquitous part of daily life in Indonesia and other southeast Asian nations. In 2019, Gojek’s success and prominence saw then-Indonesian-president Joko Widodo ask Nadiem to become Education Minister, with a remit to improve the nation’s schools. Nadiem took the job but kept a minority stake in Gojek during his time in government. During his time as minister, Nadiem oversaw a $600 million program to acquire laptops for use in schools. Departmental officials compared Chromebooks to Windows laptops and found the latter performed better, because Google’s machines need constant internet access which isn’t available in much of the sprawling Indonesian archipelago. The Ministry nonetheless decided to order Chromebooks because they are cheaper than Windows machines. As the laptop program rolled out, observers noted that Google has invested in Gojek, and that the two companies had collaborated on various projects. Some saw that as suggesting a possibility that the decision to acquire Chromebooks might not have been motivated by technical merit and cost factors alone. Prosecutors eventually decided to pursue a case on the basis that the decision to acquire Chromebooks cost Indonesia over $100 million in avoidable costs. The matter went to trial and was decided on Tuesday, when a majority of judges found Nadiem guilty of improper conduct as minister – but not of personally profiting from the Chromebook procurement. The former minister has vowed to appeal and described the judgement as deeply flawed given that the decision to purchase Chromebooks was made at arm’s length and because he did not personally benefit from the program. Some see the affair as an example of established power brokers in Indonesia flexing their muscle against an emerging bloc of technocratic reformers. That bloc has lost influence since Widodo’s term as President ended. Under that interpretation, prosecuting the Singapore-born, Harvard-educated Nadiem is a significant exercise of old guard power. Another view is that the affair is so tawdry, it shows Indonesia remains a very difficult nation in which to do business and that if even a local hero can be brought low, foreign tech companies may struggle to make inroads. ®
T-Mobile appears to be quitting VMware – and fighting a very familiar battle for support rights on the way out
Telco giant T-Mobile appears to be transitioning away from VMware and fighting a court battle for support it says Broadcom is bound to provide, according to court documents seen by The Register. The dispute relates to a deal T-Mobile struck with VMware in August 2023, which saw the telco acquire perpetual licenses and two years of support for some software, plus the option for a further year of support. When Broadcom acquired VMware in 2023, it stopped selling perpetual licenses and standalone support deals for customers with those licenses. Broadcom also reduced the virtualization giant’s product range from over 150 products to two subscription-only bundles. Broadcom now mostly sells its Cloud Foundation (VCF) private cloud suite. Customers including AT&T and Tesco tried to exercise their right to extended support, but Broadcom declined to do so. AT&T settled on confidential terms. Tesco is pursuing the matter in the courts. When customers exercise their option for extended support, Broadcom argues it can’t deliver because the products covered by the contract don’t exist anymore, its contracts allow it to deny support for dead products, and subscriptions are now the industry standard. T-Mobile started using VMware’s products in 2008 and, per court documents, runs it on at least 303,000 CPU cores. In one hearing, the carrier’s counsel described T-Mobile’s VMware implementation as “the base of the entire internal network” and “the place where 1,000 applications reside.” Court documents allege that in 2024 Broadcom notified T-Mobile it would not renew support after the initial two-year deal expired in 2025. The two parties kept talking about possible new arrangements. T-Mobile also sought an injunction that would compel Broadcom to provide extended support. Broadcom opposed the injunction, arguing that T-Mobile deliberately waited too long to seek it. At one point T-Mobile suggested a $20 million deal for another two years of support. An affirmation filed last week by T-Mobile vice president of technology Kevin Luu says the carrier sought that arrangement “to be able to complete T-Mobile’s transition away from VMware at a more deliberate pace.” The court eventually granted the injunction forcing Broadcom to offer support beyond August 2025, but required T-Mobile to pay $5.28 million and post a $500,000 undertaking. Broadcom continued to provide support but also sought damages on grounds that the injunction meant it missed out on a new deal with T-Mobile. The telco has rubbished that argument in part because the two parties were still talking about a new deal. Broadcom later proposed to charge $24 million for extended support covering six products, a sum it said would cover over 20 staff needed to support T-Mobile. The carrier fired back by pointing out that it has made just two support calls in 2026, which hardly justifies such a massive staff and expense. The matter is now somewhat urgent because the injunction expires on August 3, 2026, so T-Mobile may soon be unable to get support for its very substantial VMware estate. We’ve asked the carrier how it will cope if it can’t get support but haven’t received a response at the time of writing. One fascinating wrinkle in the case is that the presiding judge, The Honorable Jennifer G. Shecter, also heard the case between VMware and AT&T. The parties reached a confidential settlement in that case, but in in an October 2025 hearing Shecter said she thinks T-Mobile’s case is stronger than AT&T’s. “I think this case is even more compelling and to be sure I was very compelled both in AT&T and very convinced,” she said. VMware’s counsel argued that the cases differ because AT&T acted quickly, but T-Mobile waited many months before seeking extended support and an injunction. “Just to give some perspective, there are 10,000 customers. Thousands upon thousands have successfully migrated to subscription,” VMware’s counsel argued. “T-Mobile is the outlier here that is in litigation. AT&T is the other outlier. Thousands upon thousands of customers have already transferred under these sorts of provisions and accepted and understood that end of availability applies.” VMware last week named one of those customers that signed up for VCF: the UK’s Nationwide Building Society. But Judge Schecter was not convinced by the argument that T-Mobile and AT&T are outliers, suggesting that some customers “don’t just want to fight Broadcom. I don't know. Or it's not worth it and maybe they're smaller scale and transitioning is easier.” Broadcom argues that customers who move to VCF subscriptions emerge with a more efficient infrastructure that can help to improve overall business performance, and points to strong revenue growth for VMware as evidence its strategy is appreciated and working. ®
Claude Code users complain their chat records are being mysteriously wiped out
Claude Code users are reporting that the app is silently deleting conversation transcripts – yours may even already be gone if you don’t know to change a default setting that the platform never bothers to tell users about. Claude Code’s GitHub repo features multiple open issues from the past couple of months, as users of the coding tool are finding their conversation transcripts gone. The problem appears to come down to the cleanupPeriodDays configuration option, which defaults to 30 days and runs every time Claude Code starts up, wiping out any .jsonl file it finds that isn’t fresh enough. Anthropic suggested the blame lies with users for not checking the documentation, telling The Register that the 30-day erasure policy has been there since Claude's launch as a security measure, and is documented. "Keeping plain text transcripts of coding sessions on disk indefinitely creates real security and privacy risks, since they can contain source code, credentials, and other sensitive material," the company said in a statement. "The 30-day default balances the ability to resume recent work against not holding that data on disk longer than needed. This has been part of Claude Code's design since launch as a security measure." This might not be such a huge deal if Claude Code bothered to inform 8naware users that their 30-day-old conversations with the bot would be wiped out the next time they opened the application, or informed them that the setting exists. But users are saying that's not the case. “Cleanup runs out of the box with no install-time disclosure or first-run dialog,” GitHub user FTSBrand wrote in his original post, which has since become the issue of record. “Users who treat their conversation history as durable working knowledge are silently mistaken about the persistence model.” Another user in their own issue thread reports that code and git history for a project remained after the cleanup wipe, “but the reasoning trail - design discussions, debugging context, analysis - is gone.” “For research work that context is the artifact,” GitHub user joekhochstetter said. This cleanup feature appears to bypass any form of recovery, with no soft-deletion option, grace period, or option to restore. User reports also suggest there’s no log of what’s deleted either, leaving people with no way to confirm what’s been wiped after it happens. Moreover, one might assume that simply changing the retention period to a higher number would render the issue irrelevant, but several users say setting a large value for retention isn’t working properly. GitHub user ojura’s root cause analysis suggests that’s because deletion is keyed to a transcript’s mtime (modification time) rather than its actual last activity timestamp. "Because mtime is externally mutable, anything that touches it flips the outcome: a restore, a sync client, or a script that sets mtimes to a session's true (old) last-activity date makes a present session look old, and it is silently deleted on the next sweep,” ojura explained. The only solution in the thread is to ensure Claude Code transcripts are backed up, with several different iterations of such a workaround suggested. That hasn’t been enough to satisfy some Claude Coders - they want it fixed. “Backups are good hygiene, but they don't replace product-level disclosure/provenance for a destructive retention sweep,” writes GitHub user caioribeiroclw-pixel. ®
Qualcomm's proposed solution to catch up in AI infra: Bury the compute under the DRAM
Qualcomm is finally getting serious about AI infrastructure, but its push into the datacenter hinges on the success of an ambitious near-memory compute architecture designed to deliver better inference economics than today's GPUs. Announced during its 2026 investor day last week, the tech will see Qualcomm stack layer upon layer of DRAM on top of its XPUs to form a single unified compute and memory module it's calling high-bandwidth compute (HBC). “We offer all of the performance advantages of SRAM, but with the density and the memory capacity that HBM (high-bandwidth memory) stacks offer,” Tony Pialis, Qualcomm’s EVP of datacenter, claimed during last week's investor presentation. This technology is set to launch next year as part of Qualcomm’s AI250-series of Dragonfly rack systems, and marks a distinct shift in Qualcomm’s AI infrastructure strategy. The handset giant is no stranger to AI accelerators. Essentially every Snapdragon processor sold today ships with an NPU on board. But in the datacenter, the company has struggled to garner the same excitement as Nvidia, AMD, and even startups like Cerebras. Compared to the big two’s GPUs, Qualcomm’s AI-series accelerators haven’t compared that favorably, but that could soon change as the company looks to make its mark on the datacenter. With the AI250, the SoC maker is claiming 768 GB of memory capacity and up to 133 TB/s of effective memory bandwidth per card. For reference, Nvidia's Groq 3 LPUs offer just 500 MB of SRAM and 150 TB/s of bandwidth. If that seems too good to be true, that’s because it is. Qualcomm is leaning heavily on the word “effective.” We know that because for the AI200-based Dragonfly systems rolling out this year, they claimed 414 TB/s of “effective” memory bandwidth across all 56 chips. On its face, that seems more realistic, but actually achieving that with 8800 MT/s LPDDR5x alone would require a 6,720-bit-wide bus, which it almost certainly does not possess. Qualcomm insists that this is the "pure physical bandwidth of the LPDDR interface," but declined to offer any specifics as to how it's somehow managed to achieve what Nvidia needed eight HBM3e stacks to do. In any case, according to Qualcomm’s marketing materials, with the move to HBC, the AI250 will offer 18x the effective bandwidth of the AI200, while the forthcoming AI300 will deliver 54x the bandwidth. Given the context, these seem like outlandish claims, but these "effective" multipliers are really a feature of Qualcomm's HBC architecture. Unpacking high-bandwidth compute Amplifying “effective” bandwidth isn’t the only party trick from these HBC-based accelerators. Qualcomm claims that by moving some of the XPU’s compute under the DRAM, it can significantly reduce the amount of power its chips consume. On a conventional datacenter GPU, data is rapidly shuffled between HBM and the compute dies. Even using advanced packaging technologies like TSMC’s CoWoS, the power required to move this data back and forth is significant. By stacking the DRAM directly on top of some of the logic and connecting them using through-silicon vias (TSVs), the path from compute to memory is shortened considerably. "Imagine working in the same building that you live in so you only travel up and down," Pialis said. "What does that mean for the highways and the roads that connect the suburbs to the city? Guess what? The roads are clear. The value this brings to the industry is lower power consumption, less heat, and that expensive road of silicon interposer that HBM solutions use is no longer needed." Performing bandwidth-bound operations on the base die also has the benefit of reducing the amount of data that needs to be shuttled to and from the HBC to the SoC. In effect, memory bandwidth is amplified. This is why Qualcomm is using “effective bandwidth" so liberally. Compared to doing all of that work on a conventional GPU or XPU with distinct HBM and compute dies, the effective bandwidth would be significantly higher, which also achieves better density than SRAM-only designs, like Nvidia’s LPUs or Cerebras’ dinner plate sized accelerators. With that said, Qualcomm probably won’t be running its entire AI software stack on HBC. Higher memory bandwidth primarily benefits decode, when the entirety of the model’s active weights are streamed autoregressively from memory one token after another. Decode isn’t particularly compute-intensive. As such, doing decode partially or entirely in HBC starts to make a lot of sense because it also avoids the thermal constraints associated with burying the compute under multiple layers of DRAM. Qualcomm tells us that the AI250 can be used as a standalone AI accelerator, but notes it is heavily optimized around addressing bandwidth bottlenecks. So, in addition to being a dedicated inference chip, it can be used in disaggregated inference architectures that use GPUs or other Qualcomm parts for prompt processing and the AI250 to speed up memory intensive decode operations. Peak FLOPS are notably missing from Qualcomm’s AI250 disclosures — the company declined to share specifics upon our request. Is HBC actually a competitive advantage? While Qualcomm is early among chip designers to make a fuss about near-memory or HBC, it’s not the first, nor is the technology beyond the means of Nvidia or AMD. In fact, both Nvidia and AMD are rumored to be working with HBM suppliers and TSMC to develop custom base dies to boost the performance of their next-gen chips, though it's still not clear how much, if any, compute has been integrated into them. Qualcomm tells us its HBC "uses LPDDR memory in a purpose-built near-memory computing architecture that combines compute and highly-accelerated memory bandwidth within a 3D-stacked silicon design. While both HBC and HBM use stacked-memory concepts, HBC is a distinct architecture designed to address AI’s data-movement bottleneck by bringing compute and memory closer together, increasing memory bandwidth efficiency and improving energy efficiency for AI inference workloads. HBM has more stacks of DRAM, uses 2.5D interposer to route more wires, and does not do computing in the base logic die." AI chip startup d-Matrix is also developing accelerators that will use 3D stacked DRAM to extend their in-memory compute capabilities. The underlying technology described by Pialis may not be as unique as Qualcomm would like investors to believe, but it shows the company hasn’t missed the boat. However, Qualcomm’s ability to work with Nvidia and AMD may end up doing more to sell customers on its tech than anything. As we previously wrote, in a disaggregated AI world, Nvidia can be both a friend and an enemy. Qualcomm finds its Mojo In addition to teasing its upcoming AI250 and AI300 accelerators, Qualcomm’s investor day also coincided with the acquisition of AI software startup Modular. Modular was founded by Tim Davis and Chris Lattner, the latter of whom you may recognize as the creator of LLVM, Clang, the Swift programming language, and the multi-level intermediate representation (MLIR) compiler infrastructure. At Modular, Lattner and crew developed Mojo, a low-level programming interface for GPUs, which offered a high-performance alternative to Nvidia’s CUDA or AMD’s HIP and ROCm stacks. The big idea is that users should be able to write highly performant AI apps that’ll run regardless of the underlying hardware. For Qualcomm, Mojo presents an opportunity to sidestep the CUDA moat, which has dogged AMD for so long. With Mojo, Qualcomm’s customers won’t need to choose one platform; they can develop their apps and run them on whatever compute is handy at the time. It’s not all or nothing either. Modular should help to support heterogeneous deployments similar to what Nvidia is doing with Groq’s LPU tech, where GPUs might be used for prefill and AI250s are used for decode in whatever ratio makes the most sense for that specific application. However, the acquisition doesn’t just buy Qualcomm a vendor-neutral programming model. The folks buying these systems are primarily concerned with one AI workload in particular: LLM model serving. For this, Modular developed a serving platform called Max. Max is a bit like SGLang or vLLM in that it’ll run interchangeably on AMD or Nvidia hardware, but because it’s built atop Mojo, it, at least in theory, shouldn’t require nearly as much hand tuning. The offering should help Qualcomm compete in a landscape where software has become even more important than the hardware it runs on, if it manages to close the acquisition this year without regulators stepping in. In any case, we won’t have to wait much longer to see the HBC in action. After launching its AI200-series racks later this year, Qualcomm plans to push its first-gen HBC-based AI250 out the door beginning in 2027, while its second-gen HBC platform is slated for 2028. While you wait, why not read up on Qualcomm’s new datacenter CPU, which we explored in more detail last week. ®
Changing AI math could reduce the hardware burden, researchers show
Sophisticated AI models tend to require a lot of memory and take up a lot of storage space. One of the ways to reduce that footprint involves a process called quantization, which changes how model weights are represented and stored. But quantization has its drawbacks. Andrés Mac Allister, CEO and founder of The SEMQ Group, believes there's another way to make machine learning more efficient and less resource intensive. Instead of compressing model weights (specifically embeddings), he contends you can separate the semantics (the meaning) from how that meaning is represented. Model weights, including embeddings (which map tokens to vectors), are the numbers in a machine learning model that determine how strongly one piece of information relates to another. Taken all together, they reflect learned behavior. These parameters are commonly represented in Full-Precision (FP32), which requires 4 bytes per parameter. A 7B parameter model at FP32 would need about 28 GB of disk space and memory. To save space, the model might be quantized at FP16/BF16, which requires 2 bytes per parameter. The resulting model would need about 14 GB of disk space and memory. And there are smaller quantization options like FP8, INT8/Q8, Q6, Q5, Q4, Q3, and Q2, each of which reduces the storage and memory footprint while also reducing precision – the answers get worse. SEMQ stands for Symbolic Embedding Multi-Quantization. As described in a paper published earlier this year, SEMQ "replaces raw vectors with fixed-dimensional symbolic structures that preserve relational properties, such as relative similarity ordering and neighborhood structure, while decoupling representation from metrics, indexing, and execution semantics." Essentially, Mac Allister has devised a way to construct a semantic abstraction layer that decouples the meaning captured in embeddings – vectors representing data – from the way that data is represented. The operative idea is that semantic relationships depend primarily on the relative orientation of embedding vectors, so the absolute magnitude of those vectors becomes less important to preserve. That's less data to store. The potential impact to businesses running AI workloads depends on the portion of infrastructure costs attributable to semantic state. "An embedding is usually represented as a long vector of floating-point numbers," Mac Allister explained in an email to The Register. "In conventional embedding systems, semantic state is typically stored as a sequence of high-precision numerical coordinates. Those coordinates jointly encode both magnitude and direction in the embedding space. "Our original question was whether a substantial part of the useful semantic information could instead be represented through the structural relationship among components, how they move relative to one another, which regions they occupy and what directional configuration they form in the overall space." To this end, SEMQ aims to represent relative geometry rather than an enumeration of independent floating-point magnitudes. "That matters because semantic systems generally care about relationships, similarity, neighborhood, continuity, retrieval behavior, change over time, rather than only about preserving each raw numeric value in isolation,' said Mac Allister. "The result is a portable representation of semantic state that can be reproduced, audited, compared and transferred across processes." According to Mac Allister, initial validation tests that focused on converting the embedding-based semantic state into a deterministic .semq representation, restoring it, and evaluating the stability of retrieval and classification operations have shown good results. "For example, in one benchmark using the Banking77 dataset from MTEB and the all-MiniLM-L6-v2 embedding model, the FP32 baseline achieved 92.26 percent accuracy. SEMQ achieved 92.27 percent effectively matching the FP32 baseline within 0.03 percentage points." SEMQ thus did substantially better than 4-bit quantization, which registered 56.05 percent accuracy, 36.22 percentage points less than FP32. "These are not claims that conventional quantization is universally ineffective but they show that, in this particular semantic classification setting, preserving the relevant semantic structure is materially different from simply reducing numerical precision," said Mac Allister. Applying SEMQ can be done at the point of data ingestion – organizations can use the SDK on the vectors generated by their embedding model on their documents to encode that data as an .semq artifact – or at query time to load, query, compare, restore, and verify that encoding. "That means a team can adopt SEMQ without replacing its LLM, embedding model, vector database or agent framework," said Mac Allister. "It can initially run alongside the existing stack as a sidecar layer, then become the representation used for selected retrieval or memory workloads." Potential use cases, he said, include making embeddings or memory state portable across systems, reproducing semantic state across different runs or machines; auditing model changes; reducing dependence on opaque or hard-to-reproduce stateful pipelines; and diffing semantic state. He added that the SEMQ can be extended to runtime cognitive state. "In our research, .semq files have been used to snapshot and restore transformer KV-cache state across process boundaries," he said. "That is not a pre-training workflow either: but a runtime-state workflow for pausing, transferring and resuming an active model session." Mac Allister isn't yet ready to talk about specific customers. He said his company is working through a Founding Design Partnership Program with organizations exploring applications in enterprise AI, retrieval, agent memory, and auditable AI workflows. This includes some AI infrastructure hyperscalers and some companies operating at the AI application layer. "We signed NDAs with all of them, so I cannot name all of the organizations publicly yet," he said. "What I can say is that the interest has come from teams dealing with AI systems where reproducibility, state, lower infrastructure overhead, and the ability to inspect semantic behavior are operationally important. So this is a big problem for big companies." ®
Infosec professionals sour on automated pentesting tools
Perhaps bots aren't the answer to everything when it comes to finding flaws. Fully automated pentesting has been a letdown for many security teams, according to offensive security firm Cobalt, as support for the approach has fallen sharply over the past year. Cobalt’s recent 2026 State of Pentesting report found, among other things, that security practitioners are rapidly ditching autonomous pentesting tools, in large part because they’re simply failing to detect critical vulnerabilities. Cobalt reported that 78 percent of respondents to its survey for the 2026 report experienced “critical false negatives” from automated scanning tools, with the tools quite bad at detecting the sort of vulnerabilities its AI ilk inflicts on environments in which it’s prevalent. “Automated scanners are brilliant at finding known, signature-based vulnerabilities. But they fail miserably at AI security,” the company said in a release summarizing the report’s findings. “Prompt injection exploits and excessive agency flaws require creative, multi-turn interaction chains [and] adversarial psychology,” Cobalt continued. “These logic flaws are entirely invisible to tools that test using single-shot automated queries.” A year of disappointment with automated scanning tools has led to a considerable decline in the number of organizations considering a purely automated security scanning approach, with just 9 percent of respondents saying that they were open to the idea, compared to 29 percent last year. It’s worth noting that the number of respondents to Cobalt’s survey was small - just 450 folks - but even with so few data points, the numbers are still bad news for automated pentesting vendors, but good news for infosec professionals, says Cobalt. “The drop in reliance on fully automated pentesting is actually a healthy sign,” the company said in its report summary. “It proves that practitioners are seeing through the vendor hype and demanding actual assurance rather than just coverage.” Those practitioners may also be simply overwhelmed by the number of vulnerabilities that non-security AI tools are introducing into their spaces: Per Cobalt, around 12 percent of the vulnerabilities detected in traditional environments are classified as high or critical severity. In AI and LLM environments, that number climbs to 32 percent, and that's not a new number, either. That 32 percent figure has held for the past two years, Cobalt said of its pentesting data, suggesting AI is introducing a lot more vulnerabilities. Combine those increased severity odds with automated pentesting bots that miss the sort of vulnerabilities that AI often introduces and it’s a recipe for disaster. Cobalt says the solution is hybrid security in which most systems are allowed to be automatically scanned by AI, while the most critical systems are left up to humans to protect and manage. The company sells such a solution, naturally, but it’s worth pointing out that its findings on the uptick in vulnerabilities introduced by AI aren't exactly a unique claim. Application security firm Veracode reported earlier this year that AI-assisted software development is creating more vulnerabilities than security teams can keep up with, leaving more vulnerabilities left unresolved for longer periods of time. Per Veracode, some 82 percent of companies are leaving known vulnerabilities unresolved for more than a year, while the number of high-risk vulnerabilities as a share of all discovered is rising as well. That said, not everyone is as skeptical of automated pentesting as Cobalt and its survey respondents. According to Amazon security chief CJ Moses, AI pentesting tools have made Amazon security teams 40 percent more efficient, though Moses’ measure for that figure isn’t clear. Moses still wasn’t keen on handing the entire security project off to AI, however. He told us at the RSA Conference in April that AI pentesting still needs a human in the loop to ensure it doesn’t muck something up. "AI is very good at doing things, especially when you have large amounts of data and need that big view,” Moses said in an April interview. “But from a decision-making capability, it isn't something that we're ready to rely on." ®
Huntress CEO says threat hunter used 'poor judgment' in alerting ransomware crim about law enforcement probe
Huntress CEO Kyle Hanslovan said he is aware of “questionable, long-term threat actor communications” between a threat hunter who is still employed with the security firm and a cybercriminal, and called this “poor judgment.” “In one particular exchange, our current teammate disclosed to a threat actor that law enforcement had reached out to them about the threat actor,” Hanslovan said in a blog post, addressing a former employee’s accusations that the current Huntress analyst is an insider threat to the company. “While this disclosure was not illegal, it reflected poor judgment,” he wrote. The incident came to light last week when former Huntress security operations analyst Ben Folland, who left the company in February, alleged that “another Huntress employee passed communications from US law enforcement to a cybercriminal, Devman, who is actively and publicly targeting my family and me.” Devman is a ransomware operator, believed to be located in Russia, who uses modified DragonForce code built on top of the leaked Conti source code. Folland alleged that this insider, still employed by Huntress, was “caught by the FBI,” and that their involvement with Devman “would cause significant reputational damage to Huntress and, in my view, continues to put clients at risk.” “If you are an employee at a cybersecurity company, you should not be helping cybercriminals,” Folland said. “You should not be informing them of active investigations. You should not be engaging in cybercriminal activity yourself.” At the time, Hanslovan said he “firmly disagree[d]” with Folland’s accusations – but declined to provide additional details about what happened between the employee and the criminal. In the Tuesday blog post, Hanslovan elaborated further and said that he believed that the communications did not constitute insider activity. “As a result of the investigation, my team implemented more robust policies for our researchers, coached teammates on engaging with threat actors, and took appropriate administrative actions,” he wrote. “While we haven't found evidence of illegal conduct, insider activity, or additional disclosures, we are continuing our investigation. Due to the privacy rights of our teammates, we will not comment further on the investigation.” Folland disagrees. In a Tuesday LinkedIn post responding to Hanslovan’s blog, he asserted that the communications between the Huntress analyst and Devman “meet the definition of an insider threat.” When the FBI reached out to the Huntress employee for intel on Devman, “She immediately forwarded the exact FBI communications to the threat actor, including screenshots containing FBI agent names,” Folland claimed in his post on LinkedIn. “She informed Devman that law enforcement was actively looking into him. She also refused to cooperate because they wanted Devman.” According to Folland, the FBI notified him of this incident with the current Huntress analyst. The Register reached out to the FBI for comment and did not receive a response. “This was not just ‘poor judgment,’” Folland wrote. “This was a Huntress employee taking sensitive knowledge about a law enforcement approach and passing it directly to the person being investigated. If someone inside a bank warns a fraudster that police are investigating them, nobody would describe that as merely ‘poor judgment.’ They would call it what it is – an insider.” Huntress declined to comment further. ®
Meta's non-surgical mind reading machine improves on prior projects, but still isn't great
For those who can't move their fingers to type, a brain-computer interface that can help them communicate by decoding neural activity is a lifeline. Researchers at Meta have been working on a noninvasive - no surgery required - brain-computer interface that is better than its predecessors, but still far from practically usable after more than a year of work. Meta announced the second iteration of its system designed to pick up and decode brain signals that fire when users are typing, called Brain2Qwerty, on Monday. The researchers explained in a pair of papers released alongside the announcement that B2Q v2 was able to achieve an average word accuracy of 61 percent (78 percent for the best-performing participant), which they said was a considerable improvement over previous noninvasive BCI systems that typically achieved only single-digit word accuracy. B2Q v2 was trained on some 22,000 sentences typed by nine participants over the course of 10 hours, each of whom was outfitted with a magnetoencephalography (MEG) headset while typing. Meta then routed their brain signals through end-to-end deep learning algorithms and large language models trained to separate brain signals from brain noise. Non-surgical BCIs typically suffer from limited signal-to-noise ratios that make decoding difficult, and B2Q tested both MEG and electroencephalography (EEG) signals. EEG is more common in noninvasive BCI experiments, but Meta found MEG was far more effective at correctly decoding typed sentences due to its higher signal-to-noise ratio. “A central objective of this study was to quantify the impact of the recording modality on decoding performance,” the team wrote in one of their papers on the experiment. “While we expected MEG to surpass EEG, the magnitude of the observed difference was substantial.” According to the team's research paper published in Nature Neuroscience on Monday, the Brain2Qwerty system achieved an average character error rate of 29 percent using MEG, whereas EEG recordings produced an average character error rate of 65 percent. The large language models that were trained to decode the MEG data into comprehensible sentences that (ideally) mimicked the ones the participants typed were the final part of the equation, Meta’s researchers explained. “Fine-tuning large language models on neural data allows the system to leverage semantic context, bridging the gap between noisy brain recordings and coherent language,” Meta said in its B2Q v2 announcement. “We also deployed AI agents to explore optimizations for the decoding pipeline, with final training configurations selected manually by engineers.” That’s definitely an upgrade in performance, but it’s not exactly a promising, commercially viable pathway when recent surgical BCI systems are reaching 92 percent sentence-level accuracy in other experiments. Meta researchers argue the system's performance should continue improving as more training data becomes available, despite it still correctly decoding only around 61 percent of words on average. According to the team, B2Q v2’s accuracy “improves log-linearly with data volume,” which should mean that shoveling more data into the AI models behind B2Q v2 would continually narrow the gap. More data won’t fix the fact that training AI models to pick out typed words from brain activity is a bit useless when the target market doesn’t have the ability to type, which the Meta minds admit in the conclusion of their paper. The current design may work for patients with limited mobility, they note, but locked-in individuals unable to use their bodies in any way are unlikely to benefit. “Bridging the gap to locked-in individuals will likely involve adapting our task into a motor imagery paradigm and designing AI systems capable of robust generalization across participants,” the team explained. Additionally, the current B2Q system remains confined to the lab because it still isn't practical for real-time communication. Per the researchers, the transformer and language model B2Q uses require a trial to conclude before they can produce output, meaning there’s no feedback from B2Q until a participant is done being prompted with sentences and has typed them all out. Then there's the fact that B2Q "currently requires MEG segments to be aligned to specific keystroke onsets," which means the system still needs to know when users are pressing keys on a keyboard. Meta isn't sure it can get around that either, with the researchers noting that "the path toward achieving continuous decoding without these explicit triggers remains uncertain." In other words, what we have here is a neat experiment with some impressive improvements over prior noninvasive BCIs, but nothing that’s going to transform the landscape anytime soon. If Zuck is thinking he has another possible pivot to medical tech in the form of B2Q, he’s just as likely to beat the competition as he was when he decided to go all-in on the metaverse and crypto. ®