AI agents: Cause of database sprawl. And also the proposed solution
Database management work will soon be mostly automated by AI agents, just like coding, according to the CEO of Cockroach Labs, the company behind the distributed database of the same name. Spencer Kimball told The Register that the proliferation of databases demanded by the explosion of AI agents in coding and business functions will mean that managing them in a largely manual way is out of the question. “Nobody's going to do manual work on a database, just like almost nobody's doing manual coding anymore,” he said. “A lot of people don't even know what’s within their code base anymore, like they only know the designs, specifications and guarantees. They're still verifying the software, but in the end they're just not down at the level of code, because it doesn't make sense. It's like nobody programs in Assembly,” he said. Kimball is among the tech CEOs with the commensurate background in software engineering to make such statements. He helped build Google’s Colossus distributed file storage system and, as a computer science student at UC Berkely, developed FOSS image editor GIMP, which continues to this day. In the time since, he has seen shifts in the level of abstraction before. “These cycles happen all the time. It's pretty easy to see what's coming next, because ultimately agents beyond coding are going to be increasingly complementing and supplementing human-driven workloads. They're going to use tools, tools are using APIs, and APIs are talking to operational databases, every single one. If you think about the implications of this massive scale-up of traffic, it means that operational databases are going to get busier, and a lot busier. We're talking about exponential scale-up,” he said. Cockroach Labs is not the only database company to see the level of AI agent demand on the enterprise as an opportunity. It’s where many vendors are positioning themselves. For example, vector database vendor Pinecone's idea is that by compiling a knowledge base of an organization's data structure and content, its technology can avoid burning through tokens back and forth between the data and AI agents. Tiger Data, the company behind TimescaleDB, has built Ghost, a technology designed specifically for developers working with AI agents, charging by compute, rather than by database. Cockroach Labs, whose customers include OpenAI, CoreWeave, Booking.com, and Cisco, is pitching the idea of an Agentic Database Cloud to address this demand. Among the elements will be elastic compute and storage separation, unified estate management, database virtualization and agentic operations. It expects to announce a product around this idea later this year. Nonetheless, in database estates, Kimball expects AI agents to act in an advisory role to avoid disruptions to operations. “You can imagine, the enterprise isn't eager to turn over the keys to production to an agent. These agents are a second pair of eyes,” he said. To this end, Cockroach has been building its own agents to improve its operations and how it manages databases. Kimball said it had built AI agents in a layered approach, giving agents sub tasks to perform and then allowing agents to manage those agents, and other agents that verify the approach taken. “There's all kinds of hand-offs, there's agents that help with migrations, agents that help with slow queries, agents that can diagnose problems with clusters, because they've been given the institutional knowledge. For example, our entire Zendesk history for the last two years — every customer ticket, every issue, the resolutions — has been digested and cross-indexed. The agents we're building are the engineering of the prompts, the handoffs and the quality control,” he said. The “thinking” is done by foundation models, he said. “We have some open-source ones we use that are very, very fast and inexpensive. Those do more… prosaic and mundane tasks that you do a lot of, quickly.” Kimball said Cockroach also uses proprietary models including OpenAI gpt-oss and Claude Opus. “We're trying to provide a replacement for a lot of human labor. We provide corporate ‘Artificial General Intelligence’ for database roles, that once you used to have to hire humans for, but you simply cannot do that at 10x the scale, much less 100x the scale. You have to find that way to get these agents to do extremely useful work, very consistently, at a level that is as good or increasingly better than humans. Frankly, there are things the agents can do that are so grungy you couldn't hire a human to do it, such as constantly looking through log files, and investigating threads. It's just too boring,” Kimball said. As such, Cockroach expects to be able to increase the scope of its products and the number of customers it serves, but only modestly increase its workforce. “You can do different things right now with your resources. You can try to scale the human teams, or you can figure out how to make the human teams more efficient, and that's what we're doing internally. Fundamentally, this is what we're going to do for our customers, because if you anchor yourself to what’s possible today, then you might say, 'Oh, the AI is not completely ready,' but like the speed at which these things are changing makes it all but inevitable at some point in the near future,” he said. Whether Cockroach’s vision will become reality or not, the database market will have to respond to AI in the enterprise, spending on which shows no sign of letting up. Nonetheless, if agents need databases, and databases need agents to manage them, maybe it's going to be turtles all the way down. ®
Microsoft previews Linux containers that run in Windows
Now not only can you run Linux from within Windows without third-party tools, but can do so within containers. Microsoft has continued the trend of the Windows Subsystem for Linux (WSL) being one of the company's more interesting developer technologies with the arrival of a public preview of WSL containers. According to Microsoft, the update adds a pair of new features to WSL: "A built in Linux container CLI and an API for Windows applications to run Linux containers as part of their app logic." Microsoft senior project manager Craig Loewen said, "this CLI tool has a familiar format and capabilities," and indeed it does. If Docker is something you know, the wslc.exe syntax (wslc.exe is the new binary) will be very familiar. There's also a built-in alias for container.exe for users who prefer to type container instead of wslc. "Containers," said Loewen, "have become a foundational part of modern development – from cloud-native applications and AI workloads to testing and deployment pipelines. "WSL containers simplify this experience by providing a built-in, enterprise-ready way to create, run, and manage Linux containers on Windows, without requiring additional third-party tooling." WSL has always been a handy way to run Linux workloads from Windows, and is particularly convenient for Linux developers who must comply with corporate edicts to use a Windows device. The CLI for end-to-end container workflows furthers this. Microsoft stated, "WSL containers make it easier for developers and organizations to build, test, and run containerized workloads while benefiting from the security, manageability, and integration of the Windows platform." Alternatively, you could run your preferred Linux distribution natively, but that might not be an option, particularly if an organization is keen on the "security, manageability, and integration of the Windows platform." And this is an important point. WSL's existing Microsoft Defender for Endpoint (MDE) has been updated (in private preview) to be aware of Linux container events, and there are settings in Intune for managing WSL containers. Support is also in a pre-release version of VS Code, where the Docker path in the dev container settings can be changed to wslc. There is also a new default file system for WSL container that Microsoft claims makes Windows file access twice the speed. So, going from terribly slow to just slow? We'll wait until general availability is reached before passing judgment. There's a new default networking mode to improve compatibility and better memory reclaim techniques. However, none of these tweaks will be enabled by default in WSL. Microsoft wrote, "Since these changes touch mission critical paths like file system access and network, for now they are enabled just in WSL container." The company is also at pains to point out that this is currently in public preview, although things seemed quite solid in the version we downloaded to try. That said, relying on this for any serious work would be foolhardy in the extreme, but it is certainly worth trying out ahead of general availability later this year. ®
What the OCI MSA didn't solve for AI scaling
Earlier this spring, AMD, Broadcom, Meta, Microsoft, NVIDIA, and OpenAI formed the Optical Compute Interconnect Multi-Source Agreement (OCI MSA) to bring coherence to AI infrastructure and establish a specification for co-packaged optics (CPO) scale-up networks. The architecture they aligned on is a slow and wide non-return-to-zero (NRZ) modulation paired with wavelength-division multiplexing. OCI GEN1 supports four wavelengths at 50 Gbps per channel, delivering 200 Gbps per direction per fiber, and the roadmap scales to 1.6 Tbps per fiber per direction. This consortium settled the architectural debate over the direction of networking in AI. The specification defines the first step in the architecture, but leaves the harder question open: How bandwidth continues to scale, and what comes after four wavelengths. The roadmap calls for adding wavelengths on the same fiber infrastructure to grow bandwidth, but does not specify which manufacturing approach will deliver them. The road to more wavelengths is the answer First-movers have already settled this argument. The OCI MSA's founding members endorsed four wavelengths as the GEN1 starting point, Ayar Labs has been on the eight-to-16 wavelength path for years, and NVIDIA's published roadmap, "A Roadmap Toward Sub-1 pJ/b Optical Interconnect," models a 16-wavelength interconnect as the route to the energy targets the MSA aims at. The decision to use slow-and-wide is an energy-per-bit argument. Low symbol rates and simple encoding go together: NRZ carries one bit per symbol, while PAM-4 carries two but requires roughly three times the optical power to hit the same bit-error rate (BER). NRZ holds BER low enough that forward error correction (FEC) stays light, latency remains tight and predictable, and the link stays within its energy budget. On the electrical side, SerDes power per bit at 50 GBaud is roughly one-third that at 100 GBaud. That regime must be preserved as bandwidth scales, or it can be walked back. Wavelength multiplication keeps the link inside the slow-and-wide regime, whereas symbol-rate escalation walks the architecture back out of it. For readers who want the underlying physics, see "Why 'Optics When You Must' is Now." The industry can now treat increasing wavelength count as settled and turn to the next problem: Manufacturing stable precision laser arrays in massive quantities. Three eras of photonic integration Photonic integration has evolved through three manufacturing eras. Each was driven by the same forces that drove every transition in the semiconductor industry: Lower cost, higher reliability, and industrial-volume scale. The first was the discrete optical assembly era. Components were made separately from exotic materials, precisely aligned by hand, and packaged individually. Expanding system capabilities meant more components and more assembly steps, and every fiber attachment was a costly potential failure point. The cost curve was flat by construction, or even negative, as yields fell. The second era was silicon photonics. Components, including modulators, waveguides, and photodetectors, moved onto a single monolithic wafer, so a portion of the photonic stack could achieve the cost curves of the semiconductor process. Instead of scaling with assembly capacity, the silicon portion could scale by running more wafers on a single flow. The breakthrough was real but incomplete, because critical components could not be integrated. The stubborn, non-silicon III-V gain material was the holdout, and the cost curve remained partial: A high-volume foundry process bolted to a discrete-component bottleneck at the most demanding interface. The foundry flow excluded lasers, semiconductor optical amplifiers (SOA), and high-speed modulators. The third era, heterogeneous integration of all photonic materials on a single wafer, has finally arrived. Combining III-V gain material with silicon photonics brings lasers, semiconductor optical amplifiers, and high-speed modulators into a single wafer-level process. The complete photonics signal chain consolidates on the wafer, and the gain material becomes just another step in a wafer process-flow cost curve, with wafer-level cost, scale, and reliability. The trend towards ever-increasing integration is inevitable. It is the manufacturing transition CMOS underwent in electronics: A single, elegant process that absorbed new device types, compounded over generations at massive scale, and became the foundation for the modern semiconductor industry. Photonics is repeating it, just in time for the massive deployment in AI datacenters. The wavelength staircase The OCI GEN1 specification is four wavelengths at 50 Gbps NRZ, delivering 200 Gbps per fiber in each direction, with MSA channel spacing of 400 GHz. It serves as a practical starting point: Sufficient to demonstrate the architecture in production silicon and coordinate the supply chain, but not enough to support the next generation of GPUs, which will require higher bandwidth per fiber. OCI GEN1 sets the first minimum multi-wavelength standard, not the maximum. Each step up the staircase runs slow and wide, so the per-channel electronics do not change. The dense wavelength-division multiplexing (DWDM) step occurs at wavelengths of eight or more, where channel spacing tightens. System-level bandwidth scales with the number of wavelengths: More lanes, more rings, no change in per-channel design effort. Doubling the wavelengths doubles the bandwidth without doubling the design cost. Eight wavelengths deliver 400 Gbps per fiber per direction, and 16 deliver 800. Bidirectional transmission over the same fiber further reduces the fiber count, and none of it requires faster SerDes, deeper FEC, or PAM-4 power and latency penalties. Wavelengths bend the cost curve for per-fiber bandwidth and enable scale-up domains to grow from tens of GPUs today to thousands tomorrow. Multiplexing at the laser source prevents fiber-count growth, so the number of fibers per connector doesn't explode as the wavelength count rises. The bigger payoff is what cluster size unlocks, rather than raw throughput. Larger, flatter, low-latency scale-up domains enlarge working memory, extend the context window, and add transformer layers, which together support deeper reasoning, fewer network stalls, and higher GPU utilization. Today's wavelength-count decision sets the ceiling on which models the resulting cluster can run in 2028 and beyond. That gives system architects a sixth metric alongside energy per bit, latency, per-fiber throughput, and reach: Wavelength-scaling headroom on the same manufacturing flow. The question to ask is whether the supplier's light-source architecture extends to eight, 16, and beyond without re-engineering. Where the answer is no, the redesign is already on the calendar, with a two-year delta baked in. Manufacturing decides the curve The OCI MSA roadmap to 1.6 Tbps per direction per fiber is achievable on paper. The harder question is which manufacturing approach gets the industry there. Discrete-laser supply chains were not built for hyperscale volumes, and the two structural paths hit the same wall by different routes. The shared-laser path combines multiple lasers through a combiner-and-splitter network to feed a multi-wavelength source. Splitting losses scale with channel count: Every additional output tapped off the network costs the laser optical power it has to make up at the input. Each laser pushes harder to maintain budget across more channels, drive currents climb, and reliability margins erode at every wavelength step. The economics that work at four wavelengths do not extend to eight, let alone 16. The dedicated-laser path uses one laser per wavelength, and assembly complexity scales linearly with channel count when multiplexing with discrete optics. A single module supplying 16 wavelengths across eight fibers would result in roughly 128 lasers, 128 fiber alignments, and 128 monitoring photodiodes. Each alignment has to hold to micrometre tolerances across temperature swings, package stress, and years of field life, and failure-rate math compounds at every interface. Volume is the binding constraint. Hyperscale CPO will need millions of laser-source units per month, not tens of thousands, and discrete-laser approaches do not extend to those volumes regardless of which path is taken. This, rather than the architectural debate, is what has held DWDM back as a deployable architecture. The architectural debate was always going to settle here; the supply chain was not. Once the next wavelength is no longer a discrete-component assembly step but becomes another circuit element on the silicon photonics wafer, the cost of adding wavelengths follows a semiconductor learning curve. Heterogeneous integration provides that curve, and the OCI roadmap requires it. The CMOs of photonics Heterogeneous integration is the manufacturing pattern that closes the integration gap silicon photonics has carried since its inception. III-V gain materials, modulators, photodetectors, and waveguides come together in a single wafer-level flow. This is what CMOS did for electronics. CMOS established a single industrial process that absorbed transistor types, then logic, then memory, and eventually larger functional families, all within the same foundry flow. Each new device family inherited the process's cost curve rather than starting its own, and that inheritance is what lets CMOS compound over generations: Every advance in the underlying process improves every device built on it. The free ride came from the manufacturing pattern, not from the transistor. SHIP™, Scintil Heterogeneous Integrated Photonics, is the equivalent pattern for photonic device integration. The claim is pattern equivalence, not scale equivalence: Photonics is repeating CMOS as a manufacturing transition, not as a market size. The pattern is already running. SHIP™ sits on Tower Semiconductor's silicon photonics platform on 200 mm production lines today, the same lines that turn out tens of millions of pluggable optical transceivers. The 300 mm path is next. The platform is already reaching beyond the laser source. At OFC 2026, four architecturally distinct system vendors independently requested SHIP™ extensions, each pursuing a different system goal: Deeper transceiver integration, advanced optical switching, high-speed modulation at scale, and integrated amplification architectures. Each needed the same underlying capability: III-V integration into the silicon photonics flow, for optical amplifiers and high-speed modulators that pure silicon cannot deliver. None of them was solving the same problem, and the common factor was the manufacturing pattern, not the device. What comes after the first generation Two generations from now, the scale-up fabric is a multi-rack signal chain that binds thousands of GPUs into a single coherent compute domain. The fiber plant that carried four wavelengths also carries 16, then the next, without rework. Lasers, modulators, photodetectors, and optical amplifiers are circuit elements on the silicon photonics wafer, not parts assembled into modules. The interconnect ceases to be an assembly problem and becomes a process-node problem. Power per bit decreases as the signal chain no longer crosses fiber interfaces and material boundaries, and bandwidth at the package edge rises with integration density. The teams designing for that architecture today will hold the architectural position when it becomes the default. The teams that defer the manufacturing question will spend two generations rebuilding programs around suppliers who solved it earlier. LEAF Light™ is the production proof: A single-chip DWDM-native light engine, demonstrated in eight- and 16-wavelength configurations compatible with microring-based CPO transceivers and manufactured on established production lines. Scintil's Series B included participation from NVIDIA as part of broader ecosystem alignment. The OCI MSA settled the architecture. The path to ship it runs through heterogeneous integration. Matt Crowley is the CEO of Scintil Photonics. Contributed by OmniScale Media.
Arm64 on the desktop? It’s spendy and it’s sluggish
A Red Hat build engineer has ended his second experimental effort at using a high-end Arm64 desktop computer as his daily driver. His conclusions are instructive. Marcin Juszkiewicz’s series of posts on his tech blog about running a Fedora-powered beast of an Arm desktop computer has been interesting reading for about a year now. Almost exactly a year ago, he built a beast of an Arm workstation. He spent some €1,800 building a machine around an Ampere Altra, which as The Register described in 2020 is a serious bit of kit. And even at €1,800 (£1550, or $2000) quite a bit of it was second-hand, including the CPU and RAM. He described the machine’s capabilities in Arm desktop: 2025 attempt, part one. We were considering a story about the sheer cost of the kit, but his latest update describes The end of the AArch64 desktop experiment. That means it’s now more of a post mortem. To cut to the chase, he has switched back to using his AMD Ryzen 5 3600 system: the six cores of a $199 chip from 2019 outperforms an 80-core Arm64 powerhouse. Juszkiewicz, who also goes by the rather easier to spell hrw, knows his stuff, and he is a man of strong opinions. Indeed, his Mastodon profile gives a clue: “Tired of Seriously Bad Computers (SBC) so moved to Arm servers and virtualization.” SBC, of course, more normally stands for “Single Board Computers” in this industry, and by far the best-selling Arm SBC is the Raspberry Pi. As it happens, we’ve met him: the Reg FOSS desk attended a talk by Mr Juszkiewicz at the 2016 Flock to Fedora conference. We already knew that he wasn’t a fan of the Raspberry Pi devices. Also, for any doubters out there, this Altra box was not his first attempt to build an Arm64 daily-driver machine. That was back in 2015, as he described over three posts. AArch64 desktop: day one talked about the spec, involving a Mustang motherboard – which means an Applied Micro X-Gene X-C1. By day two, he started to cover issues with his distro: "I use Fedora on my machines. And as lot of people know this distribution has strange rules when it comes to multimedia support. Forget about MP3, H264 and few other things." The post talks about needing to build his own codecs and media player applets, the lack of Macromedia Flash support, and more. We note this just in case anyone is tempted to jump to the conclusion that his more recent Arm experiment failed due to a lack of knowledge or skills – he definitely has both in large amounts. After just four days, he wrote AArch64 desktop: last day, discussing the performance issues of an eight-core, circa 2.4 GHz ArmV8 computer: "OK, I can be spoiled by speed of my i7-2600k desktop but situation when Firefox with less than 20 tabs open is unable to display characters I type into textarea fast enough shows that something is wrong (16GB ram machine). And tell me that this is not typical desktop use of web browser…" He spares judging the machine too harshly: "I think that results may be affected by a fact that all I have here is Applied Micro Mustang based on X-Gene 1 cpu. It is one of first ARMv8 processors in Linux world and it is optimized for server use rather than desktop." Well, fast forward to 2025, and he still has no choice but to use a manycore Arm64 chip aimed at servers, rather than the desktop. As The Reg reported earlier this month, they are now a serious force in the server and datacentre market… but aside from Apple Silicon, not on the desktop or in laptops. This time around, in Arm desktop: 2025 attempt, part one, he starts by setting the context: "Almost ten years ago, I tried to use an Applied Micro Mustang as a desktop. And it was painful. " He also starts out with some of the problems. Even a decade on, he still has problems with missing codecs and client apps. The steps needed to work around them have changed, but the situation is not massively better. Last time, for instance, it was a problem that there was no Flash player; now, there’s no Arm Spotify client. In the second installment, Arm desktop: emulation he looks at the problems of using the latest x86-on-Arm emulation tools in trying to run x86 games on even a high-end Arm chip: "Test results were awful: Single core: 459 Multi core: 4110 That’s the level of an Intel Atom CPU from 2021." He concludes: “Let me be honest: without tweaking FEX-Emu config it was unplayable.” The third installment moves on to the issues of this server part: Arm desktop: so many cores, not enough speed. "Having 80 cores sounds nice, doesn’t it? But not so much during actual use… You see, building Fedora packages was flying by. With all cores in use, ccache buffers filling up (in case of rebuilds), and 128 GB of RAM in constant use, etc. "But at the same time, 100 percent load on all cores means you cannot listen to music on Spotify or watch online videos, etc. All that because the CPU cores are occupied by the build processes." His summary is short but not very sweet. The main issue: “The lack of single-thread speed.” And the bottom line: “To use a desktop system you do not need many cores. As long as they are fast.” In the final instalment, The end of the AArch64 desktop experiment, he looks at some of the issues in depth. He built his own custom specially patched kernels; he tried two different GPUs – both an AMD Radeon RX6700XT, a high-end card that was $479 when new in 2021, and then an Nvidia RTX 2060, a card that was $349 in 2019. With both cards, some apps wouldn’t run, due to missing OpenGL libraries, or they ran very badly: “Watching YouTube videos became impossible due to 720 out of 750 frames being dropped, etc.” He hasn’t pensioned off the machine: "The 'wooster' system stays powered on, churning through RISC-V package builds. It may be weak in single-thread, but it flies when it comes to multi-core load. " But this is the end for now: "As for the Ampere Altra, I am not planning to repeat this experiment. Another AArch64 desktop attempt would require a completely new hardware platform. And I have no plans to spend over twenty thousand PLN to buy an Nvidia DGX Spark system." (Twenty thousand Polish złoty was around $5,305, £4,020, or €4,660 at current exchange rates at the time of publication.) Our original plan when “hrw” started this series was to look into the lack of commodity-priced Arm64 hardware. At last year’s Ubuntu Summit, System76 presented its nearly ready COSMIC desktop, but it also demonstrated its 128-core Altra workstation, the formidable Thelio Astra. With half a terabyte of RAM and 40 TB of storage, it’s a snip at just over $6,000 (£4,600). We have to admit, after reading Hrw’s in-depth stories of what went wrong, we no longer covet one. Perhaps paying £168 for an 8 GB Pi 5 isn’t so bad after all. ®
UK regulator wants Apple and Google to let devs steer clear of app store fees
The UK's Competition and Markets Authority (CMA) is considering new requirements around "steering" for Apple and Google's mobile platforms. The consultation concerns restrictions the CMA says are "currently preventing UK app developers from 'steering' their customers away from Apple and Google's platforms for payment." Direct engagement with customers allows developers to bypass the tech giants' app stores and avoid the fees they charge. According to the CMA, Apple currently prohibits the practice in the UK, while Google restricts it. Although the CMA does not expect Apple or Google to eliminate fees when developers engage directly with customers, it does expect steering fees to be lower than current app store charges. It suggested that savings could be passed on to customers or "invested back into the developers' businesses to support future innovation." Will Hayter, Executive Director for Digital Markets, said: "While it is only fair for Apple and Google to be compensated for the services they provide, any fees they charge must be justified through a robust, evidence-led framework involving due reference to both cost and value." Apple did not respond to a request for comment. A Google spokesperson told The Register: "We have already made the changes that the CMA is proposing today." This includes its fee structure, with the new rates due to take effect on June 30. The company says the changes will reduce costs for many developers, although the CMA has yet to say whether they go far enough. In June, the regulator imposed new rules on Google Search to help publishers prevent their work appearing in AI overviews, and secured commitments from the pair regarding how their app stores operate. Both Google and Apple have already been designated as having Strategic Market Status (SMS), meaning the CMA has far-reaching powers over how the duo runs their mobile businesses. The CMA is also looking at access to near-field communications (NFC) on Apple devices and is considering a potential requirement to allow developers access, which could address the current "high fees and strict terms." Google and Apple are not the only tech giants to come under scrutiny. Microsoft and AWS have also attracted the regulator's attention. Respondents have until July 28 to submit responses to the steering consultation. NFC views need to be in by July 21. The CMA expects to decide later in the year whether to impose new requirements. ®
Former Microsoft engineer shrinks Notepad down to size
Microsoft's habit of adding unnecessary features to Notepad is a symptom of broader bloating in the Windows codebase. But it is possible to go back to basics with a version of the editor that fits in less than 3 kilobytes. Former Microsoft engineer Dave Plummer comes from an era at Microsoft when Notepad handled the simple stuff, and WordPad handled everything else. "We had some clear rules," said the Task Manager author on his YouTube channel, Dave's Garage. "Notepad was for plain text. WordPad was for RTF. And we were taught how important it was to never cross the streams. "So, Notepad stayed lean. WordPad got the fancy fonts, the spell check, and, for all I know, a recipe card feature." A few decades on, things are very different. WordPad is no more, and Notepad has endured multiple indignities as features have been piled onto it. Heck, it will even come up with Copilot-powered suggestions to tweak writing. Plummer is less than keen on the current iteration of Notepad, "so I rebuilt it from scratch. 2.5 kilobytes. No bloat. No telemetry. No nonsense. Just pure old school Windows done right." The result is TinyRetroPad, a fork of Dave's Tiny Editor (DTE) by Matt Power. Written in assembly and using the RICHEDIT50W from the WinAPI, the application relies heavily on components already available in Windows. There are Open and Save As dialogs. Font selection. Even printing. Plummer said, "Printing in Windows is kind of spooky. It's one of those subsystems that feels like you're opening a hatch in the floor and you discover a second operating system underneath." It looks and feels, as Plummer states, "exactly like you might remember Notepad Circa Windows XP," just with an even smaller binary. We ran up the code, and, after dire warnings from Windows about the safety of doing such a thing, TinyRetroPad ground into life, transporting us back to a time before Microsoft decided that what Windows users really wanted was new features added to simple tools rather than for their operating systems to just… work. Of course, while the binary might clock in at 2,686 bytes according to Plummer (it came in at 2,794 bytes after we attempted to compile it and occupied a mighty 4,096 bytes on disk due to the cluster size), the requirement while running is quite a bit higher. That is fair enough, considering the application demonstrates that the wheel does not need to be reinvented when there are perfectly acceptable components already available in Windows. Plummer asked, "If Notepad was the canary in the coal mine that signaled our descent into mediocrity, then what's the antidote?" To rebuild it without all the fluff accumulated over the years, maybe? The binary for today's Notepad.exe is more than 100 times the size of Plummer's executable, but we'd argue it is not 100 times better. And yes, there are plenty of Notepad alternatives, but few that are quite so aggressively trim. In the current era of skyrocketing storage costs, there is a definite appeal to keeping code lean and binaries leaner. Ditching decades of cruft is simply a bonus. ®
Where there's a will, AI still has work to do
A UK law firm has put AI-generated wills on trial, and the chatbot didn't fare particularly well under cross-examination. SE Solicitors has taken an AI chatbot to task after asking it to draft a will for a fictional client, concluding that while the result looked convincing enough, it missed many of the questions a probate solicitor would normally ask before putting anything into writing. The firm asked the chatbot to prepare a will for "Daniel," an unmarried 42-year-old with two adult children, a £440,000 house, £10,000 in savings, a car, and a dog. Wills and probate senior associate Tom McInerney then reviewed the document to see how it stacked up. McInerney said the draft read well enough, but only until you start looking for the information and safeguards it omitted. "The rise of AI has allowed people to prepare legal documents themselves, and I completely understand that impulse," McInerney said. "But a will is not a letter or a cover note, it is a legally binding instrument that must hold up in court." According to the firm, the AI-generated document made no attempt to explore inheritance tax planning, lifetime gifts, pensions, life insurance, digital assets, trusts, or whether either child might be financially vulnerable. It also failed to ask whether Daniel had a partner, wanted to leave gifts to friends or charities, or wished to exclude anyone from inheriting. However, most of those omissions stem from the experiment itself. The chatbot could only work with what it was given, while a solicitor would typically spend time asking follow-up questions before drafting a will. "AI can't see the gaps because it has no idea about what you didn't tell it," McInerney said. "All it can ever produce is a will that fits the prompt, not the person." The firm also criticized the drafting itself. In one clause about the family dog, the chatbot left a placeholder instead of specifying how much money should be set aside for its care. It also failed to make that gift conditional on the named beneficiary actually taking the animal. SE Solicitors warned that relying on AI could lead consumers to overlook changes in inheritance tax rules or the need to review a will as their circumstances change due to marriage, divorce, children, property purchases, or other major life events. The law firm also addressed data privacy, noting that anyone who asks an AI platform to draft a will is likely handing over sensitive personal and financial information. Consumers may not fully understand how that data is stored or processed, it argued, particularly compared with the professional confidentiality obligations placed on solicitors. The exercise comes as AI is increasingly finding its way into legal work. SE Solicitors cites Google Trends data showing searches for "legal AI" have risen 312 percent over the past year. Separately, research commissioned by the Association of Lifetime Lawyers found 72 percent of UK adults aged 30 to 34 would consider using AI to write or update their will. Whether that means AI is ready to replace probate solicitors is another matter. In this experiment, the chatbot did exactly what it was asked to do: turn a paragraph of information into a will. SE Solicitors' argument is that writing the document is only part of the job: the harder part is asking all the questions that never made it into the prompt. ®
Raspberry Pi OS gets a new kernel but apparently not a new version number
The distro formerly known as Raspbian has received some modest tweaks – and a whole new kernel version. Raspberry Pi Ltd is a little capricious when it comes to version numbering for Raspberry Pi OS, and although this release contains a fairly significant change, it doesn't seem to have a different version number. While PiOS is based on Debian 13 "Trixie," the company significantly customizes upstream Debian, including newer kernels. For 13 years now, Raspberry Pi has been adding new sections to the top of a single release notes file, which tells us that this build is dated 2026-06-18 and updates the kernel from version 6.12.75 to version 6.18.34. Even so, the version number on the splash screen is strangely unchanged. It remains at 6.2, which was the modest security update announced in April. Now there's a much bigger change – but no announcement and no new version number. So much for version numbers having meaning. Another significant change is in the Mac version of the Raspberry Pi Imager. Buried in the release notes, the new Imager version 2.0.10 bumps the system requirements to macOS 13 or newer. Version 2.0.7 works happily on macOS 12 "Monterey," the latest that The Reg FOSS desk's 2015 iMac can officially run – but the newer release shows the crossed-out icon of an incompatible binary. We are not about to break out OCLP just to write a new SD card for a Pi. So what is new in the latest version of PiOS? Well, the kernel is now version 6.18 from November, which became the LTS kernel within days. By default, PiOS 6 uses the labcw Wayland compositor with some components drawn from LXDE, such as the panel and file manager. This is in place of its old customized version of LXDE, formerly called PIXEL. This release includes labwc version 0.9.7, replacing version 0.9.2. You can still switch back to Openbox for an X11 desktop if you want, but this disables the Wayland-based Raspberry Pi Connect that was added a couple of years ago (and might yet make it over to Windows). It has fresh icons for several apps, including LibreOffice, Geany, Xarchiver, the Eye of MATE image viewer, and the Recommended Software helper. PiOS still uses the LXDE file manager and some other components, and its own fork of the LXDE panel called lxpanel-pi, which can now display icons from "Small" (16 x 16 pixels) to "Very large" (48 x 48 pixels). We upgraded a testbed Pi 5 from the January release, and it went smoothly with no apparent difference – and it still only takes about 560 MB of RAM under X11, which is very good for 2026. The new kernel means that some functions are slightly slower and some slightly faster, but you probably won't be able to tell. For the full lowdown, Linux news site Phoronix has extensive benchmarks. It's time to refresh the x86 edition We weren't expecting to get an update – it's been four years – but what would be great to see would be a new version of the Raspberry Pi Desktop, the edition for x86 PCs. The download is still there, and so is an old how-to guide. However, this is a very old version, based on Debian 11 – it's equivalent to PiOS 4 from 2022. We recently turned on an old machine with the PiOS Desktop: this version still works fine, and it picked up lots of updates from the Debian servers – but Debian 11 is approaching its fifth birthday and reaches the end of long term support on August 31, 2026. The new Wayland-based PiOS desktop environment is one of our favorites: it's simple, clean, and fast. Back in 2022, we said it was the best way to revive an old PC. The sad thing is that it still is. It takes as little memory as, say, BunsenLabs Carbon or Crunchbang++, but it's a much more familiar desktop layout and easier to use. Although the free update lifeline for Windows 10 that we reported a year ago just got extended for another year, it's still at the end of the line. Even if you opt for the LTSC edition that gets support until 2032, we are already seeing third-party apps complain about an end-of-life OS. Windows 11 has inflated hardware requirements, and it's bigger and slower. It's not a realistic option for older kit that's still perfectly fast and usable. Not a single PC in this vulture's personal collection is officially able to run Windows 11. Meanwhile, RAM and disk continue to climb in price thanks to AI, and it's even getting more expensive to upgrade those older pre-Win11 PCs now. Even modern Linux wants more resources: the latest Ubuntu wants 6 GB of RAM or more. There are lots of lightweight Linux distros out there. We still recommend Alpine Linux, but it needs some skill to install, especially if you want to dual-boot – it's harder than Arch Linux. Adélie Linux looks very promising but it's still in beta (there hasn't been a new release since we looked at it in late 2024). There are many others, but they're all rather specialist tools that need some Linux skills. The PiOS Desktop was by far the easiest. The Linux world badly needs more lightweight distros that are ruthlessly easy to install – as the Raspberry Pi Desktop was. They need to offer a simple, quick, clean, Windows-like desktop – not something different for its own sake, like GNOME, or cluttered with myriad needless options like KDE Plasma. Something that will work happily on a 15-year-old PC with 3 GB of DDR2 RAM and a spinning disk – the sort of PC that still works fine, but would cost more to upgrade than the price of a Raspberry Pi 5. A distro that works happily on X11 would be a win, too, for old and unsupported GPUs. The Raspberry Pi Desktop once fit that bill very well. The PC world could really benefit from a freshened-up version. If Mike Thompson and Peter Green from the original project are still around, they might even help. ®
No more Java refills for Intel Macs after JDK 27, says Oracle
Oracle is moving to stop maintaining the macOS/x64 port of the Java Development Kit (JDK) from version 27, which is expected in September. JEP (JDK Enhancement Proposal) 8386091 states that "Oracle engineers will stop maintaining the macOS/x64 port as of JDK 27." A few days ago, while noting that the JEP was still in a draft state, a pull request to implement the deprecation was submitted by Mikael Vidstedt, senior director Java Virtual Machine at Oracle. Building the JDK for macOS/x64 would require setting a flag, and "there will be no guarantee that the port will build, much less function." Customers could buy an Intel Mac from Apple as recently as June 2023, when the last Intel-based Mac, the 2019 Mac Pro, was discontinued. That said, Apple is now hastening the end of support for Intel Macs, and, at the recent Worldwide Developers Conference (WWDC), the company confirmed that macOS 27 "Golden Gate" will not support Intel Macs, and that it will be the last version to include the Rosetta 2 compatibility layer for apps compiled for Intel. Java is one of many platforms removing or reducing support for Intel Macs. The Rust project demoted support to Tier 2 from Rust 1.90, released last September, which means that the compiler and standard library will still be distributed for the platform, but automated tests are no longer guaranteed to run, increasing the risk of platform-specific bugs. Python has listed x86_64-apple-darwin as a Tier 2 platform since November 2025, although Python's Tier 2 support is still relatively strong, with failures blocking a release and fixes required within 24 hours. The Node.js team downgraded macOS x64 to Tier 2 in May, and from early 2028, the Intel Mac platform will be designated as experimental, according to the current documentation on building Node. A note explains that from that time, "the project will no longer be able to test changes on any Intel-based macOS version… the project intends to continue creating universal binaries for versions of Node.js which are still in support which will be compatible with both Apple Silicon-based and Intel-based macOS versions but they will be untested." "Don't kill my Java, Oracle!" said a dev who had initially been wary of Arm Macs and bought one of the last Intel Macs, but it is not as bad as it sounds. One possibility is to run Linux on an Intel Mac, either directly or, more practically, in a virtual machine, and use the latest JDK on Linux. Further, updates to older JDK releases, such as the long-term support JDK 25, are expected to remain available for Intel Macs. ®
HS2's latest reset ditches autonomous train tech to get project back on track
HS2 is set to ditch some of its most ambitious railway technology in a bid to make Britain's most troubled infrastructure project easier to finish. A report by spending watchdog the National Audit Office (NAO) published on Monday reveals the Department for Transport (DfT) has agreed changes to simplify parts of the railway's technical specification as part of HS2's latest reset, which began in January 2025. The report is the first full assessment of the project since the reset got underway. The transport secretary asked HS2 Ltd in January to examine whether running trains more slowly could reduce cost, schedule risk, and testing time. The company responded by proposing a maximum operating speed of 320 km/h rather than 360 km/h. One of the biggest casualties is automatic train operation (ATO), a system that would have allowed trains to operate automatically under normal conditions while a driver remained onboard to supervise. Rather than pursue a bespoke setup, HS2 now plans to drop ATO from Phase 1, allowing it to simplify the signaling system by adopting technology already proven elsewhere. HS2 Ltd estimates the revised specification could save between £1 billion and £2.5 billion and allow the railway to open at least a year earlier than previously expected. The NAO, however, warned that the savings remain uncertain, noting that slower journeys would reduce the railway's long-term benefits by around £1.3 billion. According to the report, simplifying the railway would also avoid the time and expense of proving it could safely operate at 360 km/h while avoiding the risk that testing might ultimately show the higher speed was not feasible. As of the end of March, DfT and HS2 Ltd had spent £46.8 billion on HS2, including the canceled Phase 2. HS2 expects the reset itself to cost £153 million before concluding in spring 2027. The watchdog said DfT and HS2 Ltd were taking "reasonable steps" to revise the project's cost and schedule, but warned the figures published in May still carry "a high level of uncertainty." HS2 is now working toward what it calls "a fully assured and endorsed revised baseline," validating the quality of its data and assumptions, including with contractors, and resolving inconsistencies before using it to manage delivery. The NAO also urged ministers not to rush the exercise simply to hit the current deadline. It recommended reviewing this autumn whether completing the reset by spring 2027 remains realistic and, if necessary, extending the timetable until the program is "fully on a stable footing." Beyond that, the watchdog said HS2 should continue focusing on cost, schedule, and commercial management, identify capability gaps before they become critical, and apply lessons from previous rail programs on systems integration and the complexity of bringing an entire railway together. It also said that decisions on the future train fleet should align with the wider rail network to ensure sufficient capacity and maximize the project's benefits. For years, HS2 has been trying to build the railway of the future. The latest reset suggests ministers would now settle for building one that actually opens. ®
Atlas shrugs: New UK asylum seeker IT system failed to help case workers learn from appeals
After eight years of development, the UK Home Office’s new system for managing immigration and asylum applications is failing to help the department learn from the politically sensitive appeals process. According to a report from Independent Chief Inspector of Borders and Immigration, the number of appeals to decisions on asylum status has rocketed from 8,000 in 2022-23 to well over 29,000 in 2023-24. However, the new case management system, Atlas, which completed its handover from the legacy Casework Information Database (CID) in 2025, isn't helping case workers learn from the outcome of past appeals. "Since the transition from CID to Atlas, it had not been possible for the Home Office to provide data or feedback on the outcome of asylum appeals to [decision-makers]. Although local workarounds had been implemented, this shortcoming with Atlas had hindered the ability to identify and monitor trends and to learn effectively from appeals,” the report said. The report, which covered the period from June to December 2025, said the Home Office's work “to resolve this was ongoing but required a full rebuild of other platforms.” It was expected to finish the work by the end of 2025, the inspector’s report said. The Register has asked the Home Office whether it has completed this remediation work. In 2025, the Home Office said Atlas completed its replacement of CID — the legacy system began its development in 2000. The Home Office was described Atlas’ development as an eight year journey after the complex project had to cope with global events such as Brexit, Covid, the Afghan Citizens Resettlement Scheme and the Ukraine Citizens Schemes. Atlas was built by suppliers including Accenture, Mastek and PA Consulting. Contracts, with work starting from 2020, were valued at around £79.7 million. As of 2019, it was projected to be fully implemented in 2021. However the Home Office missed that deadline. In 2023, The Register revealed the Home Office had missed a second deadline for the full hand-over and decommissioning of CID. At the time, the Home Office told spending watchdog the National Audit Office that it would stop using CID by September 2023. But the department missed that deadline too. As of December 2025, there remained evidence that Home Office staff were still using the legacy system for some information. As of June 2026, a report from the Public Accounts Committee, Parliament’s spending watchdog, confirmed the department no longer used the legacy system, although it found staff did need to maintain their own spreadsheets along side the official system. ®
How is AI changing datacenter network fabrics?
The network has become the nervous system of any organization running AI at scale. A single distributed training run can chew through thousands of GPUs for weeks, and one congested uplink can slash throughput by more than 30 percent. Plenty of datacenter networks aren't keeping up now that AI sits at the center of the workload. The traffic itself has changed. China’s daily AI token consumption jumped from roughly 100 billion a day at the start of 2024 to more than 30 trillion by mid-2025. That's a 300-fold rise in 18 months, by official count. Machines do more of the talking now, too: bots and agents make up 51 percent of internet traffic, outnumbering humans for the first time in a decade. These pressures are forcing companies to change the way they think about datacenter network fabrics. What is a network fabric? A fabric is the dense mesh of switches and links that carries traffic between servers (east-west) and in and out of the datacenter (north-south). AI training traffic moves east-west: GPUs in a training cluster swap enormous volumes of data, and a single lossy link can stall the whole job. But AI inference generates new flows north-south and over the WAN. Why does automating it need a model of itself? This is where most automation falls down. You can script a change onto a fabric, but a script has no idea how the parts relate, so it can fix one switch and quietly break its neighbor. The answer is to give the network a model of itself. HPE Networking Apstra Datacenter Director, for instance, keeps a live graph of every device and the links and policies between them. Intent-based networking runs on top: an operator declares the outcome they want, and the system writes the configuration, checks it against the graph before anything ships, then continuously verifies that the running network still matches. A deterministic model can point at the real root cause instead of burying the operator in alarms. How does the fabric catch trouble before users do? Telemetry is only part of the solution. Add in AIOps to optimize the experience of the network operator and the application end user. Instead of asking whether a switch is up, newer systems ask whether users are getting a good experience, then trace a slowdown to the exact port or optic behind it. HPE Mist Networking Datacenter Assurance scores fabric health on that basis. Operators query the Marvis AI Assistant, which has evolved into a reasoning agent, providing a simple way to interact with the network. Predictive models go earlier still: by watching voltage, temperature, laser readings and CRC error counts, they flag a failing optic before it drops a link. The operator hears about it first, not the user. What about security? None of this holds if security is an afterthought. AI pipelines move sensitive data east-west, between servers, where a perimeter firewall never looks. So segmentation moves inside the fabric. Workloads are walled off from each other and every flow is inspected, not just the ones crossing the edge. What does it mean for your team? Get the rebuild right and fewer change windows die on a typo, while root-cause analysis stops being an archaeology dig. Network engineers don’t vanish, but they do evolve from herding switches in the CLI to designing the fabric,handling the exceptions automation throws up, and getting time back to work on strategic initiatives important to the CIO. The datacenter is the substrate the rest of the AI stack runs on; build it to run itself and everything above it gets easier. Sponsored by HPE.
Microsoft builds a bouncer to keep bots out of Teams meetings
Microsoft has built a bouncer to keep bots out of Teams meetings. “Bots have begun joining meetings that participants never intended them to attend,” wrote Microsoft product marketing manager Meera Ajam in a Monday post. “For example, after connecting a third-party service to a meeting, some users have found that its bot continues joining future meetings automatically.” Ajam thinks bots butting into meetings that include discussion of sensitive matters is a potential security and privacy problem. Your correspondent has personal experience of this when transcription bots add themselves to meetings conducted under non-disclosure agreements. Microsoft has therefore built tech that sees Teams require a human to check a bot’s ID in the “lobby” where guests wait before a meeting. If a human rates a bot as worthy of coming inside, it gets to join the meeting. The software giant says it’s “strengthened Teams' ability to distinguish between bots and human participants as they join a meeting” by using “a combination of behavioral and infrastructure signals to identify bots with a higher degree of accuracy.” That’s not a guarantee that Teams will detect all bots, but Microsoft’s tech requires multiple clicks to let a bot attend a meeting. “Admitting a bot should be a deliberate decision, not something that happens by mistake,” Ajam wrote. Some users want bots to attend a meeting. Your correspondent prefers a third-party transcription-bot to Microsoft’s own. The software giant recognizes that and plans to add “a registration path for independent software vendors (ISVs) that build meeting experiences for Microsoft Teams.” That path will mean bot-builders will be able to register with Microsoft and include a self-identification marker in their join requests. “When Teams recognizes that marker, it can identify the bot as a known participant,” Ajam wrote. “We're currently working with a limited set of ISVs to preview this capability and validate the experience before broader availability,” she added, before promising more detail about registrations soon. There’s peril in this plan for Microsoft, which could make itself an arbiter of what constitutes a good bot worthy of admission to Teams. Just like bouncers do in real life, often to the chagrin of plain-looking revelers. Microsoft has started rollout of its bot-bouncer. Once it’s in place, the software behemoth will retire the CAPTCHAs it currently uses to put bots in their place. ®
South Korea’s hot new sensation is 3S+1F – a quadrillion-Won AI plan, not a band
The government of South Korea and local tech giants yesterday announced over ₩1 quadrillion of investment related to AI – or about $900 billion – that it says will see the country emerge a “K-Semiconductor powerhouse” and a global leader in robotics and AI. The plan is called “3S+1F”, shorthand for Speedily building fabs in regional hubs called “Strongholds”, while aiming to Spearhead innovation in new forms of semiconductors that are needed by growing markets – and getting it done with Full support from government and industry. The nation also plans to grow a robotics industry ASAP, to give itself the chance of rivalling China as the world’s unchallenged centre for clankers. Planned investments to make that happen include building Physical AI models – to do for movement what LLMs do for text. Underpinning it all will be datacenters with combined capacity of 18.4GW, all to be built by 2035 and made possible by massive investments in clean energy generation and a grid that moves electrons so efficiently it will literally and metaphorically electrify the South Korean economy. President Lee Jae-myung said the plan will see South Korea build the industrial base needed for AI faster than any other country and spread wealth beyond Seoul. He therefore pitched the plan as both social and economic policy. Local tech giants SK Hynix and Samsung are part of the plan, as both committed to spending vast sums on new fabs. LG and Hyundai will also invest. South Korea’s announcement of the plan uses the rather Chinese phrase “great leap forward” several times. That’s ironic given the Korean scheme is partly intended to ensure the country can compete with China – and to do so with local factories instead of the nation’s tech giants investing in the Middle Kingdom. K-Chip Import Slayers, anyone? ®
India’s central bank mandated use of .bank domains to enhance trust – but its registry leaked sensitive info
In 2025, the Reserve Bank of India created the .bank.in subdomain and required all local banks to start using it for their online presences. Indian is home to thousands of banks and the new rule meant all needed to register for and use a bankname.bank.in domain, a move designed to make life harder for phishers and fraudsters. Now a security researcher has alleged that the entity chosen as the sole registrar of the subdomains – the Institute for Development and Research in Banking Technology (IDRBT) – botched the job and leaked sensitive data. The allegation came in a report [PDF] and post published yesterday by CashlessConsumer, a group that advocates for India to become a cashless society and which aims to represent citizens to digital payments players. “The IDRBT Domain Registration Portal (registrar.idrbt.ac.in) – the exclusive registrar for India’s .bank.in namespace – exposed its entire REST API via 33+ unauthenticated endpoints,” the post alleges. “Anyone with curl could retrieve the bcrypt password hashes, mobile numbers, email addresses, login IPs, and device fingerprints of all 5,576 bank employees trusted with managing India’s banking domains.” The researcher behind the exposé, “Srikanth L”, says he accessed info through the portal and found evidence that some India banks host websites on shared servers in the United States, Singapore, and Lithuania. He also found 80 percent of registered .bank.in domains don’t use DNSSEC, 40 percent don’t employ the DMARC email security protocol that verifies senders’ identity, and many domains are secured with free Let’s Encrypt certificates. The researcher’s post also alleges that the portal went live without a proper security audit and ran without secure APIs for 13 months. Srikanth L disclosed his findings in early June and says IDRBT has since fixed the gaping security flaws. The researcher also appears to have used a GitHub repo to list info found by accessing the portal’s APIs – so some of the info available over the previously-open API is now public – and claimed doing so will help security researchers by letting them understand the extent of Indian banking infrastructure. That knowledge may come in handy given the open API means attackers may have been able to access and use credentials of senior bank staff, information that can enable many forms of attack - even the DNS spoofing and phishing attacks the requirement to use .bank.in was designed to prevent. At the time of writing, the IDRBT, Reserve Bank, and India’s government appear not to have made a public comment on the matter. ®
Security researchers tricked LLMs into giving them cocaine recipes by abusing role models for prompt injection
Researchers say that machine learning models cannot reliably distinguish between authorized and unauthorized input, ensuring that prompt injection will continue to present a threat until developers find new ways to have machine learning systems process inputs. AI models provide responses to user-supplied prompts. The problem is that AI models may receive adversarial prompts – directly from a user or indirectly from an ingested document – that tell the model to take action contrary to its built-in system prompt. Various techniques mitigate prompt injection, but defenders have not found ways to prevent such attacks. According to independent researchers Charles Ye and Jasmine Cui, and MIT associate professor Dylan Hadfield-Menell, no one is likely to do so under the current fragile LLM security model. As they observe in a paper titled "Prompt Injection as Role Confusion" in the proceedings of next week's ICML 2026 conference, LLMs have come to rely on a text tagging system that defines "roles" to separate system text from user text. And roles, they argue, do not guarantee security. "Role tags were a formatting trick that became the security architecture and the cognitive scaffolding of modern LLMs," the authors explain in a blog post. "We've shown that this architecture doesn't survive into the model's actual representations, and that such role confusion is linked to prompt injection." When OpenAI's ChatGPT arrived in 2022, it implemented the concept of roles – described by Anthropic a year earlier – as a way to tell the underlying model to behave in a certain way. The user role would make a request and the model, acting in the role of a helpful assistant, would respond to that request. "A formatting trick had become the mechanism that turned autocomplete into an assistant," the authors observe. Developers introduced other roles over time. In addition to and , there's , , and . These roles served to draw a line between different objectives so they could be individually optimized during the training process. Model makers want to balance conflicting objectives like being helpful and preventing harm, and this involves role distinctions. But roles, the researchers say, have become overloaded with responsibilities they cannot reliably carry out. They've become like a fuzzier version of permission levels, determining how prompts are trusted and treated. The problem, the authors contend, is that roles are determined in a fundamentally insecure way: writing style. "LLMs identify roles from an insecure feature (style)," they explain. "This is like identifying a stranger's profession from how they talk and dress rather than by checking their ID. Usually everything agrees, so this works fine. But when attackers intentionally create a mismatch, the LLM uses the insecure method (writing style) to identify its role instead of the secure method (tags)." The authors developed an attack called CoT (Chain of Thought) Forgery that involves using an LLM to spoof the terse style of OpenAI mode and add that to the prompt. The technique won the 2025 OpenAI Kaggle red-teaming contest. "We asked a bunch of LLMs how to synthesize cocaine, inserting fake reasoning that says it's fine because we're wearing a green shirt," the authors explain. "The LLMs comply. The rationale is transparently dumb, but the models don't evaluate it as an external claim to be scrutinized. They treat it as their already-reached conclusion, and simply act on it. We've stolen the trust given to the role." On a standard jailbreaking benchmark, they say, CoT Forgery took the attack success rate from near zero to about 60 percent on the models tested. And whereas most jailbreaks are fragile and work only for certain models, this one transferred because it exploits a structural flaw. It's not attempting to persuade the model but duping the model into treating the request as something that's already settled. The authors also note that while many models report near-perfect safety scores on prompt-injection benchmarks, human red-teamers achieve attack success rates close to 100 percent. "The discrepancy is straightforward: skilled humans test and adapt attacks until they work, benchmarks don't," they state. "Static benchmarks measure attacks models have already learned to catch." Roles, the authors argue, deserve more attention from the research community because they've become one of the most important abstractions in the AI stack. "Unless LLMs achieve genuine role perception, we think injection defense will remain a perpetual whack-a-mole game," they conclude. "And the continuous nature of role boundaries opens the threat of injections designed to subtly shift LLM states through seemingly innocuous text, legally and at scale." ®
Four years into Ukraine invasion, Russia turns influence-ops back to US and Europe
Four years into the Kremlin’s illegal invasion of its neighboring country, Russian influence operations have moved beyond their near-exclusive focus on Ukraine to their former favorite targets: the US and Europe, and especially covert cyber-ops intended to undermine political stability within these countries and the unity between them, according to Google Threat Intelligence. “This shift is significant because it likely signals increased focus outside of Ukraine, warning that pro-Russia influence activity targeting the European Union (EU), North Atlantic Treaty Organization (NATO), and other top targeting priorities may intensify,” Google threat hunters James Sadowski and Alden Wahlstrom said in a Monday report. The war in Ukraine helped Russian operatives refine their influence activities, and Moscow’s increasing use of AI for planning, reconnaissance, and content generation “marks a forward trend in pro-Russia IO,” the duo wrote. The primary objectives of these pro-Russia influence campaigns center around five key goals, all of which aim to advance the Kremlin’s military and political objectives via psychological manipulation – something Russia has been very, very good at throughout history. These key goals include: undermining democracy, dividing Western coalitions, promoting Russia’s image and regional interests, maintaining domestic stability, and repressing political dissent within the country. While the campaigns themselves typically involve fake news websites serving up phony political commentary or direct messages disseminating pro-Russian narratives, influence ops frequently coincide with data-wiping malware or other destructive cyberattacks, hack-and-leak campaigns, or direct cyber-espionage, according to the Googlers. This influence ecosystem spans multiple channels, from official government propaganda and covert intelligence operations to hacktivists and pro-Russian proxies. Oftentimes, the lines between these channels are blurred, making attribution more difficult and giving Moscow plausible deniability for cyber activities. Plus, Russian cybergroups – like everyone else – are increasingly using AI tools across their entire campaigns to make their cyber operations more efficient. Late last month, researchers at WithSecure documented Russia-linked cyber espionage crews using AI tools to help build malware, spin up infrastructure, and craft lures for attacks on Ukrainian targets. The group, tracked as GreyVibe, used OpenAI's ChatGPT, Google's Gemini, and Ideogram AI across almost every stage of its operations since at least August 2025, we’re told. “As Russia seeks to emerge from international isolation and reorients its influence ecosystem back toward global objectives, it is critical for defenders to understand how this ecosystem provides the Kremlin with a durable influence capability in order to better anticipate future Russian influence threats,” the Googlers noted. ®
Anonymous researcher drops 0-day 'exploitarium' repo
Not everyone is willing to follow responsible disclosure of vulns. An anonymous researcher has dumped what they say is working exploit code for zero-day vulnerabilities across 15 software products and open source projects without notifying any vendors or maintainers prior to publishing - and attackers are already exploiting at least two of these. The first is CVE-2026-55200, a critical, pre-authentication remote code execution (RCE) vulnerability in libssh2, a popular client-side C library that implements the SSH2 protocol. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution. A fix has been merged into the libssh2 mainline development source control branch, and maintainers are still preparing a libssh2 release containing the patch. The second is CVE-2026-20896, a critical authentication bypass vulnerability affecting self-hosted Gitea Docker deployments that allows unauthenticated remote attackers to impersonate any user and fully take over the Git server. It’s fixed in Gitea 1.26.3. The researcher, who goes by bikini, dropped the exploit code and vulnerability write-ups in a now-removed GitHub repository called exploitarium. They remind us of Nightmare Eclipse - the zero-day bug hunter who has been publishing Microsoft exploits over the past couple of months. Unlike Nightmare Eclipse, however, bikini doesn’t appear to hold a grudge against any one vendor, publishing purported vulnerabilities across multiple products and projects including libssh2, Splunk, RustDesk, 7-Zip, VLC, AnyDesk, OpenVPN, c-ares, Gitea, and Floci. Bikini claimed - and, to be clear, The Register has not verified these claims or that the code works - that none of the exploits in the repo have been reported. “Feel free to report them yourself and take credit for the CVE if handed out lulz,” the anonymous researcher wrote, as shown in this screenshot posted on X by Ledger CTO Charles Guillemet. “Please do not abuse these. I do this so to allure people into the field.” Other researchers, including Federal Signal analyst Ethan Andrews, suggested that bikini used advanced AI models - specifically GPT-5.5 Codex - to automate fuzzing and vulnerability discovery, in yet another indication that the AI-induced vulnpocalypse is nigh. In response to bikini’s data dump, Andrews built 44 KQL detection rules covering the full exploitarium repo with language translation available for non-KQL stacks. “The most technically significant findings - libssh2 pre-auth heap write and Gitea default Docker auth bypass - have been independently verified as high-risk with active exploitation observed,” Andrews wrote, noting that some of the exploitarium disclosures “have been dismissed by the community as low-impact AI-fuzzing noise.” While the repository has since been removed by GitHub, nothing ever truly dies on the internet, and it’s safe to assume that attackers are now also using AI to scan for vulnerable instances. In many cases, bikini’s PoCs mean they don’t even have to spend time developing an exploit. ®
Supreme Court rules cops need a warrant to vacuum up phone location data
The US Supreme Court on Monday ruled that people have a reasonable expectation of privacy with regard to mobile phone geolocation data, a decision privacy advocates have sought for years. The Court's ruling in Chatrie vs. United States [PDF] concluded, "Police officers conducted a Fourth Amendment search when they acquired Chatrie’s location data from Google because an individual has a reasonable expectation of privacy in his cell-phone location information." Police did so through a so-called geofence warrant. The warrant required Google to provide mobile phone Location History collected from within a 150-meter radius of a credit union during the hour around when it was robbed. The Fourth Amendment protects against unreasonable searches and seizures by requiring authorities to obtain a warrant based upon probable cause. The Court's conclusion does not resolve Chatrie's case, which has been remanded to the US Court of Appeals to assess the disputed warrant's validity. But it does make clear that Location History data requires a warrant. And it amplifies the impact of Carpenter v. United States [PDF], a 2018 ruling that limited warrantless searches of cell-site location information (CSLI). In a social media post, Stanford Law School professor Orin Kerr expressed surprise that Justice Kavanaugh joined the majority in the 6-3 decision. "If you're a privacy advocate, Chatrie is just about the best possible outcome you could have expected," said Kerr, who in 2024 argued Chatrie had no Fourth Amendment right to his location data because Chatrie had opted in to Google's Location History. Privacy advocates, who have been asking US courts for at least two decades to affirm that the Fourth Amendment protects location data, are thrilled with the decision. EFF Surveillance Litigation Director Andrew Crocker, who co-authored the EFF amicus brief in the case, said, "We applaud the Supreme Court's decision in Chatrie vs. United States. The Court reaffirmed that you have an expectation of privacy in location data that reveals your movements in the physical world, and that even short-term surveillance of these movements is a search subject to the Fourth Amendment." Crocker said that in recent years police have come to rely on geofence warrants and have violated the privacy of many innocent bystanders. He said while the Court stopped short of disallowing geofence warrants entirely, the EFF intends to push for their elimination in lower courts. The US government argued that the Fourth Amendment didn't apply because Chatrie had opted into sharing his Location History with Google. But the Court found that argument "meritless." "That argument ignores how and why Google users turn on Location History: Google repeatedly prompts users to turn on the service, often warning that devices will not 'work correctly' otherwise … while not disclosing in that prompt how frequently users’ location information would be recorded, how precise it would be, or how it might be given to the government," the Court's majority said. Eden Heilman, legal director of the ACLU of Virginia, told The Register in a statement that the Court's decision confirms that law enforcement cannot use new technology to conduct warrantless surveillance. "We do not lose our right to privacy simply because we use a cellphone," said Heilman. Google in 2021 reported that geofence warrants began taking off around 2018 and by 2020 represented about 25 percent of all US warrants it received. Two years later, in an effort to reduce its role as a law enforcement data dispenser, the search biz announced changes to its handling of location history data by storing the data on-device instead of on its servers. Alas, there's an entire data broker industry that has been selling notionally private data to customers, whether that's the government or businesses. Purchase histories, browsing history data, chatbot logs, and the like continue to be bought and sold. In March, a bipartisan set of US Senators attempted to close the so-called data broker loophole with the introduction of a bill called the Government Surveillance Reform Act. It was designed to reauthorize Section 702 of the Foreign Intelligence Surveillance Act (FISA) "with necessary Fourth Amendment protections to block the federal government from buying Americans’ private data from shady sources." Yet events have overtaken the bill. In June, Section 702 of FISA, a law that has allowed the warrantless collection of information, was allowed to expire – a decision that can be read as a vote of no confidence in the current administration. There's now an opportunity to rethink how personal data is collected, stored, and sold. Come August in California, data brokers will be required to process opt-out requests from the state's Data Request and Opt-out Platform (DROP). That's the way forward for privacy: Minimize data collection and storage, and provide a privacy enforcement mechanism. ®
Large Hadron Collider goes offline to make room for its enhanced successor
The end has come for CERN’s Large Hadron Collider (LHC), but it’s not being turned off for fear of the world being sucked into some sort of cosmic anomaly - it’s getting a major upgrade. Physicists at CERN are still bidding goodbye to the LHC, per a Monday announcement from the lab, but this is very much a “the king is dead, long live the king” sort of moment, as the four-year shutdown will result in the completion of the High-Luminosity LHC, or HiLumi LHC, not a full-fledged replacement. In essence, a younger, fitter model with much better eyesight and most of the same genes will be taking the throne as the world's largest particle accelerator, or human-made machine, for that matter, when it comes online in 2030 after what the lab is calling Long Shutdown 3. HiLumi LHC will feature a number of upgrades. As its name suggests, increased luminosity is the biggest difference between the new model and the old LHC, which was first switched on in 2008. Luminosity, as CERN explains, is proportional to the number of collisions produced in a given time. Those collisions are detected in the ATLAS and CMS detectors at the LHC (the pair were responsible for the world’s first detection of the Higgs boson in 2012), which will be getting some major upgrades that, per CERN, will effectively make them into entirely new detectors. In their current incarnation, ATLAS and CMS can detect somewhere in the neighborhood of 60 proton-proton collisions per firing cycle, in what’s known as a “bunch crossing” where particles fired in opposite directions come in contact with each other. Once the upgrade to HiLumi LHC is complete, the hope is that they’ll be capable of detecting between 140 and 200 collisions per cycle, a luminosity increase of a factor of 10, the lab said. Those collisions are picked out of a massive amount of data (more than five billion interactions per second), and the more collisions the experiments can detect, the greater potential they have of spotting something of interest to CERN particle physicists - like the Higgs boson. To turn the LHC into the HiLumi LHC, ATLAS and CMS will have their trigger systems that select events for closer examination completely replaced, new detector technology will be installed, and timing detectors able to measure things at a resolution of “a few tens of picoseconds” will be installed. The end result of this upgrade, a CERN spokesperson told The Register, is to enable more physics discoveries like the Higgs identification and other firsts the LHC has produced over the years when it wasn’t shut down for repairs or other upgrades. “Over its lifetime, the HiLumi LHC could produce about 380 million Higgs bosons, compared with roughly 55 million Higgs bosons produced since the start of the LHC,” the CERN spokesperson told us, adding that the hope is to eventually see two Higgs bosons produced together and interacting with each other. “This process is extraordinarily rare and is one of the flagship goals of the HL-LHC. Measuring this self-interaction will teach us about the Higgs field itself and may provide clues about how our Universe evolved shortly after the Big Bang.” A number of renovations are being conducted in the next four years along with the luminosity upgrades. Per CERN, the Super Proton Synchrotron (SPS), a 7 kilometer circumference ring that accelerates particles and beams them into the LHC, will be consolidated; the CERN Neutrinos to Gran Sasso (CNGS) target area, which shot a beam out of the SPS through the Earth’s surface toward a laboratory in Italy 732 km away, will be dismantled; and new target facilities will be established in Experimental Cavern North 3, along with other safety, electrical, and technical upgrades. “In the LHC alone, 1.2 km of magnets and components will be removed and replaced with new equipment,” Jean-Philippe Tock, CERN deputy engineering lead and coordinator for the shutdown, said in the lab’s statement. As for whether the refurbished LHC will increase the chance that humanity ends the world, CERN assured us the new one will be just as safe as the old 27-kilometer machine that’s stirred up controversy and conspiracy theories over the past couple of decades. “The Universe as a whole produces more than 10 million million LHC-like experiments per second,” the lab spokesperson explained. “If such phenomena were dangerous or destructive, it would contradict what we see: stars, galaxies and the Earth still exist.” ®